#215 CrowdStrike Outage Exposes Cybersecurity Flaws

EPISODE · Jul 22, 2024 · 31 MIN

#215 CrowdStrike Outage Exposes Cybersecurity Flaws

from Embracing Digital Transformation

The CrowdStrike outage over the weekend exposed major flaws in our approach to CyberSeurity, Software Engineering and System Architecture. Darren is joined with returning guest Matthew Pulsipher to discuss the implications of this weekends events.In today's digital age, cybersecurity is not just a growing concern, it's an urgent and constant battle. Recent incidents like the CrowdStrike mishap serve as stark reminders of the immense implications of cybersecurity. This all-important subject was recently dissected on our highly insightful podcast 'Embracing Digital Transformation', where the vulnerabilities of our current systems and potential cybersecurity solutions were scrutinized.**The Achilles Heel of Client Computers**The conversation could have spent more time addressing one significant issue - the treacherous shores of client computer systems. While the centralized nature of server computers allows for stringent protection, client computers need to be more robust due to fragmented management and increased device variability. The podcast hosts underlined the pitfalls of general-purpose systems, exemplified by complete desktop systems running at airport check-ins. Ostensibly for a singular use case, these flexible systems present an attractive target for cyber threats. While it would be ideal to lock down such machines, the podcast suggested a reason not to do so: system and infrastructure consistency. Consistency is crucial for cost efficiency, effective training, and quality control.**The Apple Advantage**The next riveting point of discussion was the resilience of the Apple iOS system. The hope for superior security does exist, as exemplified by Apple, which steered clear of the recent CrowdStrike debacle. Apple’s defense mechanism lies in its gag on kernel-mode drivers, thereby raising the security bar on its system. Achieving kernel accessibility is possible, but it triggers compliance alarms that deter users. This additional firewall offers superior protection.However, the silver lining is that this model isn’t exclusive to Apple devices. Computers sticking to singular apps, like airline check-in systems, could strategically adopt these principles. Corporates could also learn from Android's security models, though manufacturers' responsibility for security updates is a crucial drawback.**Zero Trust: An Effective Paradigm Shift**The ever-evolving landscape of cyber threats has made the principle of zero trust increasingly important. Zero trust is based on the concept of not automatically trusting any user or device, even if they are inside the corporate network. This approach has gained traction as organizations seek to bolster their security measures.Legacy operating systems like Windows are facing challenges due to technical debt, which hinders swift updates and improvements. In contrast, more agile smartphone operating systems are able to adapt and update more quickly, potentially offering better protection from emerging cyber threats.**Regulating Future Actions**The conversation concluded with a contemplation of future regulatory measures. The hope for systemic change lies in a rehaul of dated system architectures. However, the idea of softening overly strict interpretations of compliance rules and focusing more on practical security was touted as the better way forward, emphasizing the need for change.In a nutshell, our latest podcast discussion was not just a wake-up call to the realities of today’s cybersecurity threats, but also a beacon of hope. We pointed towards potential solutions, offering a roadmap for navigating this digital age safely without compromising innovation. It's worth a listen for anyone interested in cybersecurity.See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

NOW PLAYING

#215 CrowdStrike Outage Exposes Cybersecurity Flaws

0:00 31:14

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Managing Next Generation Energy Systems Cambridge University Background Stakeholders working with energy systems have to make complex decisions formulated from risk-based assessments about the future. The move towards more renewables in our energy systems complicates matters even further, requiring the development of an integrated power grid and continuous and steady transformation of the UK power system. Network flows must be managed reliably under uncertain demands, uncertain supply, emerging network technologies and possible failures and, further, prices in related markets can be highly volatile. Mathematicians working with engineers and economists, can make significant contributions to address such issues, by helping to develop fit-for-purpose models for next generation energy systems. These interdisciplinary approaches are looking to address a range of associated problems, including modelling, prediction, simulation, control, market and mechanism design and optimisation. This knowledge exchange workshop was part of the four months Res The Digital Resilience Show David Wild Podcast by David Wild Solving for Change MOBIA Technology Innovations Solving for Change welcomes business and technology leaders to share stories of bold business transformation within complex organizations. In an era when technology and markets are changing around businesses, the key to staying competitive is to evolve in response to those changes.  MOBIA’s Mike Reeves and Marc LeBlanc investigate business transformation, deconstructing the challenges, ambitions, and market disruptions that drive companies to embark on transformation journeys, and exploring their unique approaches to achieving meaningful outcomes.  What sparks leaders to pursue business transformation? How do they overcome the challenges along the way? What are the keys to creating enduring change?  Through in-depth conversations with business and technology leaders, Mike and Marc answer these questions and explore how businesses evolve by pulling four key transformation levers: people, process, technology, and culture. Darknet Discussions Darknet Discussions Welcome to "Darknet Discussions," the podcast that gets into the shadows of the internet to bring you the most intriguing, enlightening, and sometimes unsettling stories from the dark web. Hosted by seasoned darknet aficionados, each episode of "Darknet Discussions" explores the intricate dynamics of darknet markets, cybersecurity threats, and the digital underworld. Join us as we interview experts, discuss the latest trends in cybercrime, and shed light on the technologies that operate beneath the surface of everyday internet use. Also, we occasionally go off on a tangent about something completely unrelated.
URL copied to clipboard!