‘Hug your IT folks’: The CrowdStrike outage turned technicians into heroes (2024)

It was 3 a.m. Friday when Tyson Morris got a wake-up call that would send him into crisis mode for days. Atlanta’s trains and buses were expected to be running in two hours, but all systems were down, showing the dreaded “blue screen of death.”

“It’s the one phone call a chief information officer never wants to get,” said Morris, CIO for the Metropolitan Atlanta Rapid Transit Authority. “I jumped out of bed, and my wife was wondering what was going on. She thought someone had died.”

Morris sprang into action to mobilize his team of 130 for an all-hands-on-deck operation. Was it a hack? Had an employee gone rogue and brought down their operations? For hours, no one knew.

The outage, caused by a faulty update from security software firm CrowdStrike, was the kind of event IT staff train for but hope never happens. The incident brought down an estimated 8.5 million Windows devices around the globe, paralyzing operations at hospitals, airlines, 911 call centers and more. Insurers estimate the outage cost companies more than $1 billion in revenue, with Fortune 500 companies potentially losing more than $5 billion.

Advertisem*nt

While the outage made it difficult to impossible for many to work, IT technicians were toiling overtime — some spending the night at the office, feverishly trying to get systems back up and running through the weekend. It also revealed vulnerabilities that companies can use as lessons for the next big outage.

“It was a heightened sense of stress that I haven’t experienced,” said Morris, who’s been in the industry for more than two decades. “Every second counts.”

The event shined a bright light on the importance of IT workers, said Eric Grenier, an analyst who covers endpoint security for market research firm Gartner. CrowdStrike sent out a fix to users, but it required people to manually fix each system. Later, CrowdStrike released an automated repair. The only other time Grenier recalls a massive outage that came close to this was the buggy McAfee update in 2010.

“The fact that we’re seeing reports of hundreds of thousands of devices that were remediated over the weekend, that’s huge,” Grenier said. IT workers were “the superheroes of this.”

Advertisem*nt

On the ground, it was a mad dash. Kyle Haas, a systems engineer for IT consulting firm Mirazon in Louisville, spent Friday driving across the city to help clients get back online. During the car rides and in between clients, he shot off emails and took phone calls to help others. For nine hours straight, Haas was in overdrive.

“I skipped my coffee that morning,” he said, adding that he woke up to panicked emails and messages from clients who didn’t know what was happening. “It was touch as many things as you can. Fix it all.”

Haas said his team of about 40 people spent 12 hours ensuring all their clients were back up and running. Though the day was intense and stressful, he said he was grateful that the issue was purely due to a bad update, and the fix was relatively easy. That meant he wouldn’t have to fight off bad actors or try to recover lost data, which are common in ransomware attacks or system failures.

Advertisem*nt

His big save of the day? Helping one of the water companies that was an hour away from having to go into manual override, which would have prevented it from testing water quality.

Jiayang Li, who goes by plumsoju on TikTok and said he was part of the IT team at his company, showed what his day was like by unmuting his computer. Inbound messages from colleagues were dinging continuously — something he said had been happening for hours. He compared the experience to the viral meme of a dog drinking coffee while the house is on fire saying, “this is fine.” Li, who’s been on-call for his tech employer since Friday, said that the continuous dings stemmed from team conversations about how the outage might affect them.

“It was a lot of anxiety,” Li said. “I was worried I’d have to wake up at midnight. Can I even go out this weekend?”

For Morris, the event was a big shock. He had been CIO of the transit agency for only three months. Fortunately, the IT department had a preexisting emergency plan, which included a phone tree and dedicated channels for communication. But that didn’t mean it was easy. Morris, who was on a family trip in Tennessee, drove down to Atlanta to help. Meanwhile, the team was working around-the-clock, with some members pulling 18-hour shifts and sleeping at the office.

Advertisem*nt

By 9 a.m. Friday, buses and trains were rolling again, and by Monday morning every last laptop had been fixed.

“We were getting positive feedback. … A lot of thank-you’s came in,” Morris said. “That continued to help boost morale.”

On the West Coast, signs of the outage started to appear late the night before, giving IT workers a head start at identifying the problem. Jerry Leever, IT director at accounting, tax and advisory firm GHJ in Los Angeles, said he received an email from the company’s outsourced IT members at 10:30 p.m. Pacific time, which was quickly followed by server system detector alerts.

Leever was brushing his teeth and checking his email before bed when he saw the message. His stomach dropped.

“I had a moment of worry and then a moment of understanding that we are trained to handle this situation,” Leever said. “You don’t have a lot of time to stay in the panic because you have to get things online as soon as possible.”

Advertisem*nt

By 3 a.m. Pacific, Leever and his teammates had the servers up and running. They had an automated email set to send at 5 a.m., informing their 200-plus colleagues about what happened and how to fix the issue. They also had a 6 a.m. call set up for colleagues who needed IT to guide them step-by-step. By about 10:30 a.m. Pacific, everyone was back online, a feat Leever credits to their communication plan and early warnings.

All the IT people who spoke with The Washington Post admitted there were lessons that came from the CrowdStrike outage. It helped magnify the importance of having an up-to-date business continuity plan that emphasizes communication procedures, which can get complicated if systems are down. And it left some leaders questioning whether they have enough contingencies in place so that operations can continue when something goes down.

It also left some to question whether they should diversify providers more so that the entire operation doesn’t suffer because of a problem with one. Some organizations are evaluating if they are staffed properly for emergencies or whether they need to have outsourced help on standby. And it also highlighted the importance of storing key data like recovery codes for encrypted systems in different places in case a server goes down.

For Leever, who characterized this outage as the worst incident he’s dealt with, the end of the day Friday couldn’t come soon enough. He headed straight to his favorite restaurant bar for a burger and an Aperol spritz.

“Just hug your IT folks,” he said. “It helps when folks are understanding and gracious in times of crisis.”

‘Hug your IT folks’: The CrowdStrike outage turned technicians into heroes (2024)
Top Articles
Jordon Toyota
101 Park Street, Easley, SC 29640 | Compass
Wnem Radar
Social Security Administration Lawton Photos
Die Reiseauskunft auf bahn.de - mit aktuellen Alternativen gut ans Ziel
Health Stream Kaiser
Dirty South Swag Review | BatDigest.com
Suppression du CESE et du HCCT au Sénégal : L'Assemblée nationale vote contre la suppression de ces deux institutions - BBC News Afrique
Royal Bazaar Farmers Market Tuckernuck Drive Richmond Va
Petco Westerly Ri
Celebrity Guest Tape Free
The Ports of Karpathos: Karpathos (Pigadia) and Diafani | Greeka
UK HealthCare EpicCare Link
Fatshark Forums
Momokun Leaked Controversy - Champion Magazine - Online Magazine
Localhotguy
Sarah Dreyer Obituary
Mifflin County 24 Hour Auction
Ilovekaylax
Fk Jones Obituary
Fandango Movies And Shows
Theramed Junior Strawberry 6+ Tandpasta 75 ml - 12 stuks - Voordeelverpakking | bol
Auto-Mataru
Death Valley National Park: The Complete Guide
Ihub Kblb
Configuring TPM 2.0 on a 6.7 ESXi host
Skechers Outlet Greensboro Nc
Wells Fargo Holiday Hours
Ringcentral Background
Circuit Court Peoria Il
Horoscope Daily Yahoo
Erfolgsfaktor Partnernetzwerk: 5 Gründe, die überzeugen | SoftwareOne Blog
VMware accompagne ses partenaires et soutient leur transformation en faisant évoluer son programme « VMware Partner Connect » - Broadcom News & Stories - Français
Trailmaster Fahrwerk - nivatechnik.de
Fanart Tv
Zip Tv Guide
Whatcom County Food Handlers Permit
Craigslist Lake Charles
Enterprise Car Sales Jacksonville Used Cars
Www.1Tamilmv.cfd
Yuba Sutter Craigslist Free Stuff
Smoque Break Rochester Indiana
Zmeenaorrxclusive
Sun Massage Tucson Reviews
Pinellas Fire Active Calls
Unintelligible Message On A Warning Sign Crossword
Craigslist West Valley
The Hardest Quests in Old School RuneScape (Ranked) – FandomSpot
Salmon Fest 2023 Lineup
Grayson County Craigslist
Samanthaschwartz Fapello
Lharkies
Latest Posts
Article information

Author: Catherine Tremblay

Last Updated:

Views: 6039

Rating: 4.7 / 5 (47 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Catherine Tremblay

Birthday: 1999-09-23

Address: Suite 461 73643 Sherril Loaf, Dickinsonland, AZ 47941-2379

Phone: +2678139151039

Job: International Administration Supervisor

Hobby: Dowsing, Snowboarding, Rowing, Beekeeping, Calligraphy, Shooting, Air sports

Introduction: My name is Catherine Tremblay, I am a precious, perfect, tasty, enthusiastic, inexpensive, vast, kind person who loves writing and wants to share my knowledge and understanding with you.