Tech Notes · Security

CrowdStrike outage takeaways for Macktez clients

Macktez does not deploy CrowdStrike, but we manage other security tools. Here is why a CrowdStrike-style outage is unlikely for our clients, and the risk tradeoffs.

July 31, 2024

On July 19, 2024, a buggy software update from cybersecurity vendor CrowdStrike crashed Windows computers worldwide, disrupting multiple industries. Macktez does not use or deploy CrowdStrike software, so none of our clients were directly affected.

Could this happen to our clients?

We do deploy other tools to our clients' computers as part of our managed service subscriptions (Workstation Management, Identity Management, and Server Management). These tools require high-level system permissions to set and manage policies and to detect and prevent cybersecurity attacks. We rely on the developers of these tools to run complete test deployments before making any updates, which are often rolled out automatically. So could a CrowdStrike-like event hit our clients' systems?

Why this specific failure is unlikely

There are critical differences between CrowdStrike's software and the tools Macktez uses. CrowdStrike interacts with Windows at an underlayer of the operating system called the kernel, where any error can short-circuit all other built-in security checks during startup and cripple the entire workstation. Kernel access used to be more common among third-party software, and Microsoft says it is still required by European Union antitrust rules in certain situations, but it is less and less common in software development specifically because it can cause so much damage.

The tools Macktez deploys for virus detection do not edit the system at the kernel. So if an update from one of our partners contained a bug, it would either be preempted during startup by Windows security or affect only the operation of its own features, rather than take down the whole operating system.

But some risk remains

The more direct answer is yes: it is possible for the tools we use to create unforeseen problems after an automatic update. We take precautions to prevent that. We research and test any managed service tools before adopting them for clients, including "eating our own dogfood" by deploying those tools to our own fleet of workstations. But for incremental security updates that developers push out automatically, we rely on their internal controls to make sure the update is safe. If they make a mistake, as CrowdStrike did, our clients downstream could be impacted.

Why take that risk at all?

Because the risk of not deploying security tools, and not regularly updating them to address vulnerabilities as they are discovered, is much greater and well documented. Extensively testing every update is beyond the reach of small- and medium-sized businesses, so trusting the software developer to do that testing is a necessary compromise for the sake of greater security.

Maybe that is not the unambiguous reassurance you are looking for, but it is the reality of the current cybersecurity landscape.

What Macktez brings to the table

Hiring Macktez to deploy and manage security tools offers real advantages over handling cybersecurity without our help:

  • We keep abreast of cybersecurity developments and new tools, and we are constantly looking for a better solution for our clients.
  • We have a large field of data to evaluate our currently deployed tools, and we change our lineup when appropriate.
  • We design and deploy systems with redundancies whenever our clients' budgets allow, to reduce the chance that a single incident creates a widespread outage.
  • When operational or security incidents do occur, we have a professional team ready to support our clients.

Every security solution needs to be balanced against cost and convenience. When we are part of those conversations with our clients, we help make those compromises clear and supportable. In particular, our Cybersecurity Assessment (now updated for NIST 2.0) provides a framework for that discussion and helps make the right decisions around security.

Work With Us

Have a project like this on the horizon?

If something here maps to what your organization is facing, let's talk it through — no pitch deck, just a senior technical perspective on your situation.