Balancing internal innovation and risks from external suppliers

As a former FBI Special Agent in the Los Angeles Cyber ​​Crime Squad, I’ve seen my fair share of flawed software updates. However, the recent global technical outage caused by a flawed CrowdStrike software update has truly captured the world’s attention. The shock and awe of such a respected cybersecurity vendor causing a major security incident has brought to light a previously overlooked area of ​​third-party risk.

Given CrowdStrike’s reputation and trusted position, many companies automatically allowed their software update package into their systems without fully considering the possibility of failure. As a result, no CISO anticipated that the update would result in a global technical outage, leading to systemic disruption of interconnected systems.