On 19 July 2024 CrowdStrike released a sensor configuration update that caused Windows machines running its Falcon agent to crash on boot. Because the fault stopped machines starting, remote tools couldn't fix it — each device needed a person, safe mode, and a file deletion. Some organisations were recovering for days.
What this means for a small business
Most small firms weren't running Falcon, so the direct hit was limited. The indirect hit wasn't: flights, deliveries, card payments and supplier systems all wobbled at once.
The wider point stands whatever endpoint product you use. Security agents run at the deepest level of the operating system by design. A bad update from your antivirus vendor has more power to stop your business than most cyber attacks.
What good looks like
- Staged rollouts. Where the product allows it, don't take vendor updates on every machine at the same moment.
- Recovery keys to hand. If your disks are encrypted with BitLocker, you need those keys available before an incident, not stored on the machine that won't boot.
- A known-good spare. One or two machines that can get someone back to work while others are being fixed.
- Backups you have actually restored from. A backup that's never been tested is a hope, not a plan.
We hold recovery keys and build documentation for the machines we manage, which is the difference between a bad morning and a bad week.