The Lombard Review

CrowdStrike's outage: who pays?

City of London skyscrapers viewed from Tower Bridge.
City of London skyscrapers viewed from Tower Bridge. Photo: The wub/Wikimedia Commons · CC BY-SA 4.0

A flawed software sensor update pushed by cybersecurity firm CrowdStrike crashed an estimated 8.5 million Microsoft Windows systems worldwide on 19 July, paralyzing global airlines, hospital networks, and financial institutions. As corporate boardrooms survey the multibillion-dollar economic disruption, the legal and financial battle over liability is just beginning.

Intel's headquarters in Santa Clara, California.
Intel's headquarters in Santa Clara, California. Photo: Sixflashphoto/Wikimedia Commons · CC BY-SA 4.0

The Contractual Liability Shield

While commercial clients absorbed staggering operational losses, CrowdStrike’s standard enterprise software licensing contracts contain strict clauses capping direct legal liability to a multiple of subscription fees paid. This contractual reality shifts the operational financial loss directly onto corporate and insurer balance sheets. The incident exposed the extreme, unhedged vulnerability of global critical infrastructure to concentrated software monopolies.

A Microchip 24LC512 serial EEPROM on an Extron DMP 128 board.
A Microchip 24LC512 serial EEPROM on an Extron DMP 128 board. Photo: Raimond Spekking/Wikimedia Commons · CC BY-SA 4.0

CrowdStrike’s global IT meltdown demonstrated that while software monopolies can paralyze global commerce, their contractual liability caps leave corporate clients to bear the ultimate financial bill.

Write to The Lombard Review at contact@thelombardreview.com

More From The Lombard Review