UnHacked Episode 24 - Summary
Main Topics Covered
- CrowdStrike Incident Analysis
- Described as historically the largest computer outage on record
- Caused by a problematic update that affected nearly every computer it was pushed to
- Estimated financial impact exceeding $1 billion, not including pending lawsuits
- Delta Airlines initiated legal action, claiming $500 million in damages
- Key technical issues:
-
- Update was pushed without proper testing
- Required manual fixes on individual workstations
- Could not be fixed remotely or in bulk
- Affected deep access into Microsoft's root systems
- Lessons Learned from CrowdStrike Incident
- Business Continuity Planning is crucial:
-
- Need manual processes as backup
- Must maintain ability to process payments
- Should have printed backup of critical information
- Important to maintain customer service during outages
- Insurance Considerations:
-
- Cyber insurance may not cover non-breach incidents
- Business interruption insurance might apply
- Important to know policy details and maintain relationship with insurance agent
- Policies may require manual backup systems
- Bank Fraud Protection
Key recommendations:
- Develop personal relationships with local bankers
- Configure proper account settings and alerts
- Implement dual approval systems for transactions
- Use commercial banking features when available
- Verify banking information changes verbally
- Train all employees on security procedures, including non-financial staff
- Choose banks offering robust security features
Schedule Your Free Security Assessment
- Business Tips
- Company Leadership:
-
- Be the face of your company
- Build personal connections with clients
- Maintain professional appearance and health
- Physical Health:
-
- Importance of maintaining physical health for business success
- Impact of health on energy levels and decision-making
- Connection between personal wellness and business performance
The UnHacked Formula for 100% Protection
- Implement cybersecurity best practices (prevents 97% of breaches)
-
- Protect technology
- Protect data
- Protect people
- Close the remaining gap with:
-
- Well-documented and regularly reviewed policies and procedures
- Comprehensive insurance coverage
- Strong relationships with insurance providers
- Regular employee training and updates
- Business continuity planning
Key Takeaway
The episode emphasizes that while technology protection is crucial, comprehensive business protection requires a combination of technical measures, human elements, and proper planning for continuity during incidents.