What actions is your organization taking to mitigate the risks and manage the impact of the CrowdStrike outage? (Select all that apply)

Recovery procedures: Activating recovery procedures and guiding help desk on increased calls45%

Employee Support: Assisting affected employees with alternative work methods and internal updates (intranet posts, email blasts)59%

Incident response: Activating in-depth security investigation and response procedures50%

External support: Seeking support from external consultants, tech vendors, and service providers22%

Security measures: Implementing additional security controls and notifications to protect our users33%

External communication: Providing updates to customers and external stakeholders29%

CrowdStrike communication: Communicating directly with CrowdStrike25%

Microsoft communication: Communicating directly with Microsoft19%

Other: Share in comments3%

115 PARTICIPANTS
1.6k viewscircle icon16 Upvotescircle icon9 Comments
Sort by:
CISO in Energy and Utilitiesa year ago

While not impacted we communicated what was going on with our various businesses to help them understand what was happening. The communication was greatly appreciated due to all of the media hype. 

Lightbulb on2
Clinical Supply Chain Leader in Healthcare and Biotecha year ago

We were not affected by this issue as CrowdStrike isn’t used as a security solution in the company.

Lightbulb on1
CIO in Finance (non-banking)a year ago

Luckily, we were not directly impacted, but we are monitoring closely the indirect impacts to our operation.

Lightbulb on1
Director of ITa year ago

This possibly raises questions on the levels of testing Crowdstrike do before releasing the patches.
Probably they need to explain what measures they are putting in place to not to repeat such issues. 
Also customers may want to explore any methods to ensure they're multi vendor and not putting all eggs in same basket. While that approach may give resilience it'll sure drive costs up, at least in the near term.

Lightbulb on3
Former CISO, VP in IT Servicesa year ago

Scheduling a review of the digital resilience of complex ecosystems and critical services.  Reviews of both technical resilience  with multiple cloud automatic failover configuration, operational QA times before updates applied, and associated business continuity plans.  

The "double whammy" of both a Microsoft 365 outage coupled with a Crowdstrike Falcon is driving a very deep and detailed review of the complete technical stack and continuity plans.  

Lightbulb on2

Content you might like

Finding data and putting it to good use13%

Controlling the security and privacy of data45%

Understanding how data is currently being used20%

All of the above19%

None of the above1%

View Results

HashiCorp (Terraform, Vault, Packer, etc.)22%

Cloud infra automation (Ansible, Puppet, Chef, etc.)56%

APM (Datadog, AppD, SignalFX, NewRelic, etc.)10%

Others?10%

View Results
What actions is your organization taking to mitigate the risks and manage the impact of the CrowdStrike outage? (Select all that apply) | Gartner Peer Community