What can be learned from Austin-based CrowdStrike's outage? Photo via Getty Images

Airlines, banks, hospitals and other risk-averse organizations around the world chose cybersecurity company CrowdStrike to protect their computer systems from hackers and data breaches.

But all it took was one faulty CrowdStrike software update to cause global disruptions Friday that grounded flights, knocked banks and media outlets offline, and disrupted hospitals, retailers and other services.

“This is a function of the very homogenous technology that goes into the backbone of all of our IT infrastructure,” said Gregory Falco, an assistant professor of engineering at Cornell University. “What really causes this mess is that we rely on very few companies, and everybody uses the same folks, so everyone goes down at the same time.”

The trouble with the update issued by CrowdStrike and affecting computers running Microsoft's Windows operating system was not a hacking incident or cyberattack, according to CrowdStrike, which apologized and said a fix was on the way.

But it wasn't an easy fix. It required “boots on the ground” to remediate, said Gartner analyst Eric Grenier.

“The fix is working, it’s just a very manual process and there’s no magic key to unlock it,” Grenier said. “I think that is probably what companies are struggling with the most here.”

While not everyone is a client of CrowdStrike and its platform known as Falcon, it is one of the leading cybersecurity providers, particularly in transportation, healthcare, banking and other sectors that have a lot at stake in keeping their computer systems working.

“They’re usually risk-averse organizations that don’t want something that’s crazy innovative, but that can work and also cover their butts when something goes wrong. That’s what CrowdStrike is,” Falco said. “And they’re looking around at their colleagues in other sectors and saying, ‘Oh, you know, this company also uses that, so I’m gonna need them, too.’”

Worrying about the fragility of a globally connected technology ecosystem is nothing new. It's what drove fears in the 1990s of a technical glitch that could cause chaos at the turn of the millennium.

“This is basically what we were all worried about with Y2K, except it’s actually happened this time,” wrote Australian cybersecurity consultant Troy Hunt on the social platform X.

Across the world Friday, affected computers were showing the “blue screen of death” — a sign that something went wrong with Microsoft's Windows operating system.

But what's different now is “that these companies are even more entrenched,” Falco said. "We like to think that we have a lot of players available. But at the end of the day, the biggest companies use all the same stuff.”

Founded in 2011 and publicly traded since 2019, CrowdStrike describes itself in its annual report to financial regulators as having “reinvented cybersecurity for the cloud era and transformed the way cybersecurity is delivered and experienced by customers.” It emphasizes its use of artificial intelligence in helping to keep pace with adversaries. It reported having 29,000 subscribing customers at the start of the year.

The Austin, Texas-based firm is one of the more visible cybersecurity companies in the world and spends heavily on marketing, including Super Bowl ads. At cybersecurity conferences, it's known for large booths displaying massive action-figure statues representing different state-sponsored hacking groups that CrowdStrike technology promises to defend against.

CrowdStrike CEO George Kurtz is among the most highly compensated in the world, recording more than $230 million in total compensation in the last three years. Kurtz is also a driver for a CrowdStrike-sponsored car racing team.

After his initial statement about the problem was criticized for lack of contrition, Kurtz apologized in a later social media post Friday and on NBC's “Today Show.”

“We understand the gravity of the situation and are deeply sorry for the inconvenience and disruption,” he said on X.

Richard Stiennon, a cybersecurity industry analyst, said this was a historic mistake by CrowdStrike.

“This is easily the worst faux pas, technical faux pas or glitch of any security software provider ever,” said Stiennon, who has tracked the cybersecurity industry for 24 years.

While the problem is an easy technical fix, he said, it’s impact could be long-lasting for some organizations because of the hands-on work needed to fix each affected computer. “It’s really, really difficult to touch millions of machines. And people are on vacation right now, so, you know, the CEO will be coming back from his trip to the Bahamas in a couple of weeks and he won’t be able to use his computers.”

Stiennon said he did not think the outage revealed a bigger problem with the cybersecurity industry or CrowdStrike as a company.

“The markets are going to forgive them, the customers are going to forgive them, and this will blow over,” he said.

Forrester analyst Allie Mellen credited CrowdStrike for clearly telling customers what they need to do to fix the problem. But to restore trust, she said there will need to be a deeper look at what occurred and what changes can be made to prevent it from happening again.

“A lot of this is likely to come down to the testing and software development process and the work that they’ve put into testing these kinds of updates before deployment,” Mellen said. “But until we see the complete retrospective, we won’t know for sure what the failure was.”

Ad Placement 300x100
Ad Placement 300x600

CultureMap Emails are Awesome

Rice University lands $18M to revolutionize lymphatic disease detection

fresh funding

An arm of the U.S. Department of Health and Human Services has awarded $18 million to scientists at Rice University for research that has the potential to revolutionize how lymphatic diseases are detected and help increase survivability.

The lymphatic system is the network of vessels all over the body that help eliminate waste, absorb fat and maintain fluid balance. Diseases in this system are often difficult to detect early due to the small size of the vessels and the invasiveness of biopsy testing. Though survival rates of lymph disease have skyrocketed in the United States over the last five years, it still claims around 200,000 people in the country annually.

Early detection of complex lymphatic anomalies (CLAs) and lymphedema is essential in increasing successful treatment rates. That’s where Rice University’s SynthX Center, directed by Han Xiao and Lei Li, an assistant professor of electrical and computer engineering, comes in.

Aided by researchers from Texas Children’s Hospital, Baylor College of Medicine, the University of Texas at Dallas and the University of Texas Southwestern Medical Center, the center is pioneering two technologies: the Visual Imaging System for Tracing and Analyzing Lymphatics with Photoacoustics (VISTA-LYMPH) and Digital Plasmonic Nanobubble Detection for Protein (DIAMOND-P).

Simply put, VISTA-LYMPH uses photoacoustic tomography (PAT), a combination of light and sound, to more accurately map the tiny vessels of the lymphatic system. The process is more effective than diagnostic tools that use only light or sound, independent of one another. The research award is through the Advanced Research Projects Agency for Health (ARPA-H) Lymphatic Imaging, Genomics and pHenotyping Technologies (LIGHT) program, part of the U.S. HHS, which saw the potential of VISTA-LYMPH in animal tests that produced finely detailed diagnostic maps.

“Thanks to ARPA-H’s award, we will build the most advanced PAT system to image the body’s lymphatic network with unprecedented resolution and speed, enabling earlier and more accurate diagnosis,” Li said in a news release.

Meanwhile, DIAMOND-P could replace the older, less exact immunoassay. It uses laser-heated vapors of plasmonic nanoparticles to detect viruses without having to separate or amplify, and at room temperature, greatly simplifying the process. This is an important part of greater diagnosis because even with VISTA-LYMPH’s greater imaging accuracy, many lymphatic diseases still do not appear. Detecting biological markers is still necessary.

According to Rice, the efforts will help address lymphatic disorders, including Gorham-Stout disease, kaposiform lymphangiomatosis and generalized lymphatic anomaly. They also could help manage conditions associated with lymphatic dysfunction, including cancer metastasis, cardiovascular disease and neurodegeneration.

“By validating VISTA-LYMPH and DIAMOND-P in both preclinical and clinical settings, the team aims to establish a comprehensive diagnostic pipeline for lymphatic diseases and potentially beyond,” Xiao added in the release.

The ARPA-H award funds the project for up to five years.

Houston doctor wins NIH grant to test virtual reality for ICU delirium

Virtual healing

Think of it like a reverse version of The Matrix. A person wakes up in a hospital bed and gets plugged into a virtual reality game world in order to heal.

While it may sound far-fetched, Dr. Hina Faisal, a Houston Methodist critical care specialist in the Department of Surgery, was recently awarded a $242,000 grant from the National Institute of Health to test the effects of VR games on patients coming out of major surgery in the intensive care unit (ICU).

The five-year study will focus on older patients using mental stimulation techniques to reduce incidences of delirium. The award comes courtesy of the National Institute on Aging K76 Paul B. Beeson Emerging Leaders Career Development Award in Aging.

“As the population of older adults continues to grow, the need for effective, scalable interventions to prevent postoperative complications like delirium is more important than ever,” Faisal said in a news release.

ICU delirium is a serious condition that can lead to major complications and even death. Roughly 87 percent of patients who undergo major surgery involving intubation will experience some form of delirium coming out of anesthesia. Causes can range from infection to drug reactions. While many cases are mild, prolonged ICU delirium may prevent a patient from following medical advice or even cause them to hurt themselves.

Using VR games to treat delirium is a rapidly emerging and exciting branch of medicine. Studies show that VR games can help promote mental activity, memory and cognitive function. However, the full benefits are currently unknown as studies have been hampered by small patient populations.

Faisal believes that half of all ICU delirium cases are preventable through VR treatment. Currently, a general lack of knowledge and resources has been holding back the advancement of the treatment.

Hopefully, the work of Faisal in one of the busiest medical cities in the world can alleviate that problem as she spends the next half-decade plugging patients into games to aid in their healing.