Security leaders share thoughts on Microsoft-Crowdstrike outage
Briefly

When I used to work at Goldman Sachs, the policy was to get tools from multiple vendors. This way, if one firewall goes down by one vendor, you have another vendor who may be more resilient. Today's global outage is a reminder of the fragility and systemic 'nth-party' concentration risk of the technology that runs everyday life...
An outage is just another form of a security incident. Antifragility in these situations comes from not putting all your eggs in one basket. You need to have diverse systems, know where your single points of failure are and proactively stress-test through tabletop exercises and simulations of outages...
This disruption creates a fertile ground for exploitation, as attackers prey on the vulnerability of users seeking solutions. Threat actors may use social engineering tactics to disguise malware...Vigilance is paramount, as organizations must not only address the outage but also fortify defenses against opportunistic attacks...
The CrowdStrike outage highlights the risks associated with entrusting software updates to external partners or services, something unima...
Read at Securitymagazine
[
|
]