All articles

Backup and continuitySeptember 22, 20262 min read

The CrowdStrike case: lessons on business continuity

In July 2024 a faulty update crashed millions of Windows PCs. The lessons for companies on business continuity, recovery and emergency planning.

Technician with his hands on his head in front of the racks of a server room

19 July 2024 became a case study for anyone working in IT. A faulty update to the CrowdStrike Falcon security software for Windows crashed the computers it was installed on, leaving them stuck on a blue screen at every reboot. According to Microsoft’s estimates, about 8.5 million devices were affected worldwide: airlines, hospitals, banks, broadcasters, retail chains.

It was not a cyberattack. It was an error in an update distributed automatically by a trusted security vendor. And that is exactly what makes it instructive.

Lesson 1: the incident can come from whoever protects you

Companies rightly invest in defending themselves against attacks. But business continuity must also take into account failures, human error and supplier problems: a faulty update, an unavailable cloud service, a configuration mistake.

The right question is not “how do I avoid every problem?”, but “how do I keep working when a problem arrives?”.

Lesson 2: manual recovery does not scale

Many affected PCs could only be fixed one by one, by booting into safe mode and deleting a file. Easy on one computer, a huge task across hundreds of workstations spread over offices and remote workers. Many companies also needed their BitLocker recovery keys, which were not always easy to find.

The practical conclusion: emergency procedures, encryption keys and recovery credentials must be documented, stored securely and accessible even when the main systems are down.

Lesson 3: backups matter even without an attack

Companies with up-to-date system images and tested recovery procedures got back to work faster. A good backup does not only protect against ransomware: it is the universal tool for returning to a working state, whatever caused the problem.

Lesson 4: update, but with method

The incident is not an argument against updates: an unpatched system is far more at risk. It is, however, an argument for staged updates, rolled out first to a small group of systems and then to the rest, where possible.

Lesson 5: communication is part of the response

Customers and staff need to know what is happening, how long it will last and what to do in the meantime. A communication plan prepared in advance is worth as much as the technical one.

A checklist for your company

  1. Is there a business continuity plan that also covers failures and supplier problems?
  2. Are recovery keys (for example BitLocker) stored securely and within reach?
  3. Are there full system backups, not just file backups, and has recovery been tested?
  4. Are critical updates rolled out in stages where possible?
  5. Is it clear who communicates what, and to whom, during an emergency?

How we help

7dBackup protects workstations, servers and virtual environments with full backups and bare-metal restore, so you can return to a working system even starting from scratch. With 7dCloud you can replicate critical servers in a second data center and restart from there. And our managed services support you in defining your continuity plan and in recovery tests.

Want to talk it through?

Tell us about the needs of your company or your customers: we will propose the right solution, with no obligation.

Contact us

Related articles