Tech News : Data Centres Now ‘Critical National Infrastructure’

Prompted by the effects of the global IT outage caused by CrowdStrike, the UK has moved to protect UK data-centres by classing them as ‘Critical National Infrastructure’ (CNI).

CrowdStrike 

Back in July, a global IT outage caused by a faulty update (impacting Windows systems) from the cybersecurity firm CrowdStrike significantly affected multiple sectors in the UK, including data-centres, the NHS, and the financial industry. It led to widespread disruptions and, although it was not a cyberattack, it does appear to be a motivating factor for the UK government’s announcement of a change classification of UK data-centres.

Not Just Protection Against Cyber Criminals 

Although the CrowdStrike effects may have been a major catalyst for the new classification of data centres, their classification as CNI should also help create provision to give them more protection from major environmental disasters and other IT blackouts.  This new classification is part of a wider movement to give them the special protection they merit. As highlighted in the government’s announcement, much of the data housed and processed in UK data-centres, such as photos taken on smartphones to patients’ NHS records and sensitive financial investment information, could be considered as “powering the economy”.

How Does The New Classification Compare? 

The idea to now classify UK data-centres as ‘Critical National Infrastructure (CNI)’ will mean that in terms of added protection, they have been put on an equal footing to water, energy and emergency services systems. This means that they can, as the government says: “now expect greater government support in recovering from and anticipating critical incidents, giving the industry greater reassurance when setting up business in UK and helping generate economic growth for all.” 

Also, as Technology Secretary Peter Kyle says: “Bringing data-centres into the Critical National Infrastructure regime will allow better coordination and cooperation with the government against cyber criminals and unexpected events.” 

More specifically, the government says this “support” will mean:

– The setting up of a dedicated CNI data infrastructure team of senior government officials who will “monitor and anticipate potential threats, provide prioritised access to security agencies including the National Cyber Security Centre, and coordinate access to emergency services should an incident occur”. 

– The government intervening in the event of (for example) an attack on a data-centre hosting critical NHS patients’ data. In this event, with the new classification of data-centres, the government says it will “ensure contingencies are in place to mitigate the risk of damage or to essential services, including on patients’ appointments or operations.” 

– The UK is already home to the highest number of data-centres in Western Europe. Giving CNI status to data-centres in the UK could increase business confidence in investing in data-centres in the UK, an industry which already generates an estimated £4.6 billion in revenues a year.

Deterrent? 

It appears that the government believes that the status will also deter cyber criminals from targeting data-centres that may house vital health and financial data, minimising disruption to people’s lives, the NHS, and the economy. Presumably, this deterrent effect would come from increased penalties, greater cybersecurity investment, and enhanced monitoring / better threat detection efforts.

Just In Time 

With the UK government recently welcoming a proposed £3.75 billion investment in Europe’s largest data centre (for DC01UK in Hertfordshire) and with it expected to create over 700+ local jobs and support 13,740 data and tech jobs across the country, the new CNI status for data-centres appears to have been given just in time.

The Cyber Security and Resilience Bill Too

As an additional measure, earlier this summer (during the King’s Speech), the government’s Department for Science, Innovation and Technology (DSIT) also announced it will be introducing the Cyber Security and Resilience Bill. It’s thought this will strengthen the country’s cyber defences by enhancing incident reporting requirements, helping safeguard vital sectors such as healthcare and finance, ensuring stronger protections against cyber threats like ransomware, and “mandating that providers of essential infrastructure protect their supply chains from attacks”. 

Support 

Support for the re-classifying of data-centres as CNI has come from several key data-centre industry players. For example, Bruce Owen, UK Managing Director of digital infrastructure provider Equinix, said: “We welcome today’s announcement by the government which recognises the critical nature of data centres and digital infrastructure to the economy and society.” 

What Does This Mean For Your Business? 

The reclassification of UK data-centres as Critical National Infrastructure (CNI) is a strategic response to immediate threats (like the CrowdStrike outage) and a forward-looking move to secure the country’s digital infrastructure. By placing data-centres on par with essential services like energy and emergency systems, the government appears to be trying to recognise their pivotal role in supporting the digital economy and vital public services such as the NHS.

As CNI, data-centres now gain access to increased government resources, including the support of the National Cyber Security Centre (NCSC), and a dedicated CNI data infrastructure team to monitor and anticipate threats. This could ensure quicker responses to vulnerabilities and a stronger defence against cyberattacks, particularly for centres hosting critical data, such as health and financial information. The new classification also aims to protect against broader risks, such as natural disasters or IT blackouts, which could severely impact businesses and public services alike, thereby trying to provide protection that takes account of any serious eventuality.

The government’s commitment to boosting this sector is clear, as evidenced by the approval of a £3.75 billion investment in Europe’s largest data-centre project in Hertfordshire. The new status, could, therefore encourage further investments, reinforcing business confidence and supporting sustainable growth in the tech industry. The Cyber Security and Resilience Bill, expected to be introduced soon, may also further strengthen these protections e.g., by enforcing stricter incident reporting and ensuring supply chain security for essential services.

Support from industry leaders reflects the importance of securing the country’s digital infrastructure, as more businesses rely on data-centres to manage sensitive information. This reclassification is not just a reactive measure, but many would argue it is a necessary step in ensuring the continuity of services that millions rely on daily.

By classifying data-centres as CNI, the UK is laying the groundwork for a more secure and resilient digital future. With increased investment, enhanced government support, and forthcoming legislative measures, this decision may help position the UK as a leader in digital infrastructure protection, helping to safeguard its economy, public services, and reputation as a global hub for technological innovation.

Featured Article : CrowdStrike : What Happened?

Following 8.5 million Microsoft devices being hit by a faulty software update from CrowdStrike causing global chaos, we look at what happened, how, and why.

The Worst Cyber Event In History 

The scale of effects of the disruption caused make this event, which began on 18 July (Microsoft) or 19 July (according to CrowdStrike), makes it the worst cyber event in history, beating the WannaCry cyber-attack in 2017 where 300,000 computers in 150 countries were affected.

Who Are CrowdStrike? 

Texas-based cybersecurity technology company, CrowdStrike, formed in 2011, provides an AI and machine learning powered, cloud-based enterprise endpoint protection platform (intelligent real-time antivirus) called Falcon which is used by a wide range of businesses and organisations.

What Caused The Problems? 

As part of the Falcon protection mechanisms, it receives regular software updates. However, the recent update which caused the outage was described as a “sensor configuration update to Windows systems”. In this case, the faulty sensor software update triggered a logic error which resulted in a system crash and blue screen (the ‘Blue Screen Of Death’ – BSOD) on impacted systems, i.e. the computer system for the companies that were running Microsoft operating systems and using CrowdStrike’s Falcon platform (those running Falcon sensor for Windows version 7.11 and above) were completely disabled.

The ‘sensor’ is a software agent installed on endpoint devices (such as Windows systems).

Only Windows Affected 

The faulty software update only impacted Microsoft because the Falcon sensor update was specifically designed specifically just for the Windows operating system and the logic error that triggered the system crashes and blue screens (BSOD) was tied to a component or function that is unique to Windows environments.

Enormous Impact 

The faulty CrowdStrike software update caused major disruptions across a wide variety of industries globally, which included:

Airlines

Airlines experienced severe operational disruptions, thousands of cancelled /grounded flights and causing delays and passenger queues at major airports, such as the UK’s Stanstead and Gatwick airports and Berlin’s BER and Newark International airports. Passengers faced long waits while the airlines struggled to manage schedules and customer service due to the system failures. Customers (many of whom only learned of the cancellation of their flight when they arrived at the airport) suffered delays, as well as the stress, disruption, and expense of having to find later alternative flights and alternative routes, and/or book hotels overnight, and pay more for overdue car parking back at home.

Healthcare 

Hospitals and healthcare systems were notably impacted, with some facilities facing delays in clinical procedures and disruptions in medical technology and communications. This situation forced many hospitals to implement manual restoration of systems and downtime procedures, which affected patient care and led to cancellations of some clinical services. Even pharmacies have been affected with customers unable to get their prescriptions.

Financial Services 

Many banks and financial institutions encountered issues processing transactions, leading to service interruptions. The outage affected ATMs and online banking services, causing inconvenience to customers and operational delays.

Media and Broadcasting

Broadcasters such as Sky News experienced temporary outages, affecting their ability to deliver news and updates to the public, thereby highlighting the apparent reliance of media companies on cybersecurity and IT infrastructure to maintain continuous service.

Emergency Services 

Emergency call centres also faced operational challenges, which impacted their ability to respond promptly to emergencies, leading to increased risk and delays in emergency response times, raising significant public safety concerns.

Retail 

Retailers also had difficulties, particularly in their point-of-sale systems and online platforms. This disruption led to transaction delays and affected inventory management, impacting both in-store and online sales.

Fix Issued 

CrowdStrike says it has issued a fix although this in itself may be time-consuming and disruptive because it involves having to apply the fix to each affected device separately and the need for a manual reboot in safe mode for affected computers, thereby creating considerable work and issues for IT departments everywhere.

Ongoing 

At the time of writing this, the many effects are ongoing, and are expected to last around one week.

Not A Cyber Attack, But Cyber Attack Risk Now Increased 

Although CrowdStrike Founder and CEO, George Kurtz, stressed in a statement that the outage was “not a cyberattack”, there are warnings that scams and cyberattacks should now be expected, e.g. cyber attackers setting up phishing websites and running scams under the guise of offering help / fixes for those affected. Secureworks, for example, has reported a spike in CrowdStrike-themed domain registrations (a sign of potential phishing websites being set up), and there have been reports of emails being circulated by scammers claiming to be ‘CrowdStrike Support’ or ‘CrowdStrike Security’. The advice, therefore, is for those affected to only use CrowdStrike’s website to source information and help.

Although not directly related, on the theme of online security and issues relating to antivirus software, Russian security company Kaspersky has just announced that it will be exiting the US market and consequently will be cutting staff ahead of a government-imposed sales ban. Kaspersky reports: “Starting from July 20, 2024, Kaspersky will gradually wind down its US operations and eliminate US-based positions” and that “The decision and process follows the Final Determination by the US Department of Commerce, prohibiting the sales and distribution of Kaspersky products in the US”.

Sorry! 

Following the CrowdStrike issue, the company’s CEO, George Kurtz, has issued an apology, saying: “I want to sincerely apologise directly to all of you for the outage. All of CrowdStrike understands the gravity and impact of the situation. We quickly identified the issue and deployed a fix, allowing us to focus diligently on restoring customer systems as our highest priority”. 

What Does This Mean For Your Business?

The catastrophic event involving CrowdStrike’s faulty software update serves as a stark reminder of the vulnerabilities that can arise from our reliance on advanced cybersecurity solutions. For businesses, this incident is a reminder of the critical importance of rigorous testing and validation processes for all software updates. It also highlights the need for robust contingency plans to ensure operational continuity in the face of unexpected system failures.

The extensive disruption across various industries, from airlines to healthcare, illustrates the interconnected nature of modern business operations and the potential widespread impact of a single point of failure. Companies must therefore try to prioritise not only their own cybersecurity measures but also closely scrutinise and manage the cybersecurity protocols of their service providers and partners.

The legal and financial ramifications of such events also can’t be ignored. The anticipated lawsuits and claims for damages resulting from operational disruptions and customer inconvenience could set significant precedents, influencing future legal standards and liability expectations in the cybersecurity sector. This legal landscape will likely demand that businesses enhance their insurance coverage and legal strategies to mitigate potential risks.

Also, the warning from CrowdStrike about the increased risk of cyber-attacks in the wake of this incident should prompt businesses to heighten their vigilance against phishing and other cyber threats. The surge in CrowdStrike-themed phishing websites shows the cruel and opportunistic nature of cybercriminals, and businesses should now ensure their employees are well-informed and equipped to recognise and respond to these threats.

While the disruption caused by CrowdStrike’s software update was not a cyber-attack, it has nonetheless amplified the need for businesses to adopt comprehensive cybersecurity strategies. This could include, for example, maintaining up-to-date security protocols, preparing for swift crisis management, and fostering a culture of continuous improvement in cybersecurity practices. Businesses that learn from this incident and proactively strengthen their cybersecurity frameworks will be better positioned to navigate the complexities of the digital age and safeguard their operations against future disruptions.

Tech Insight : Lessons Learned

Following the massive after-effects of the faulty CrowdStrike update, we take a look at the lessons learned so far in this ongoing situation.

What Happened? 

On July 19, a faulty software update from cybersecurity technology company CrowdStrike affected approximately 8.5 million Microsoft devices globally causing chaos across multiple industries globally as key systems were disabled. The faulty software update only impacted Microsoft because the update for CrowdStrike’s enterprise security platform was specifically designed just for the Windows operating system. The update caused a ‘logic error’, leading to widespread system crashes and blue screens of death (BSOD).

The worst cyber event in history (so far), it has surpassed the scale of the 2017 WannaCry attack and highlighted significant vulnerabilities in modern cybersecurity frameworks.

What Is CrowdStrike? 

CrowdStrike, founded in 2011 and headquartered in Texas, provides the Falcon platform, a cloud-based endpoint protection solution used by large businesses and organisations globally.

Lessons Learned from the CrowdStrike Event 

Although (at the time of writing this), some of the after-effects are still being felt, the scale and severity of the event have already taught us some valuable lessons. For example:

– Businesses may have an over-reliance on the Cloud. The CrowdStrike incident has starkly highlighted our over-reliance on cloud services. Many businesses have embraced the cloud for its scalability, cost-effectiveness and convenience, often integrating critical operations and data storage into cloud platforms. However, this event demonstrated the potential risks of depending heavily on a single cloud provider or a homogeneous cloud environment.

– A re-evaluating of business cloud strategies may now be necessary. For example, the disruption caused by the faulty update has already led to some reconsidering their cloud strategies. Many businesses are now re-evaluating their cloud-first approaches to avoid single points of failure. Strategies being reported include moving away from a platform-centric approach to a more tailored, nuanced strategy which balances performance, costs, and security, and enhances efficiency and reduces risk. Also, adopting workload-specific strategies and determining the best platform for each application, e.g. a private cloud, industry cloud, on-premises data-centres, or a multi-cloud architecture, may now be a more attractive and less risky strategy.

Broadly speaking, building resilience through diversity (e.g. diversifying cloud providers and also implementing hybrid and multi-cloud strategies) plus ensuring all eggs aren’t just in one basket may now be the way forward (controversially) for some businesses. This approach could mitigate the risks associated with single points of failure, ensure greater operational continuity, perhaps even reduce (long-term) costs, and hopefully contain any cloud chaos in future.

– There is a need for rigorous software testing. The CrowdStrike incident emphasises the critical importance of thorough testing before deploying software updates, especially on a Friday! This event demonstrated that even minor configuration changes could have catastrophic consequences if not properly vetted. Comprehensive testing protocols must now be implemented to prevent such incidents from occurring in the future. Robust incident response plans are necessary. Businesses need to ensure they have comprehensive strategies in place to quickly address and mitigate the impact of IT failures. This includes regular drills and updates to incident response protocols to stay prepared for various scenarios.

– Enhanced employee security training and awareness is important. Increased vigilance against phishing and other cyber threats is crucial in the aftermath of such incidents. Businesses must invest in continuous employee training to recognise and respond to cybersecurity threats effectively. This proactive approach can significantly reduce the risk of successful cyberattacks exploiting the situation. For example, some of the reports of how cyber-criminals have already taken advantage of the situation include:

– Phishing campaigns, pretending to offer fixes and updates for the CrowdStrike-related issues. These campaigns are aimed to trick users into clicking on malicious links, leading to malware infections. The US The Department of Homeland Security’s Cybersecurity & Infrastructure Security Agency (CISA) reported that it had “observed threat actors taking advantage of this incident for phishing and other malicious activity”. People have been advised to avoid clicking links in any text or email related to the CrowdStrike or Windows disruption.

– Setting up fraudulent websites claiming to provide legitimate updates and solutions. These sites were designed to distribute malware under the guise of providing help. For example, cybercriminals distributed ZIP archives with names like “CrowdStrike-hotfix.zip” containing the HijackLoader payload (which loads malware) and was reportedly aimed at users and CrowdStrike customers in Latin America.

– Initiating ransomware attacks, taking advantage of the disruption.

– Stealing data. In some cases, attackers have exploited vulnerabilities exposed by the disruption to infiltrate systems and steal sensitive data, compounding the damage caused by the initial outage

– Continuous and transparent communication makes a big difference in a crisis. CrowdStrike’s swift communication and deployment of a fix were crucial in managing the incident’s fallout. Transparent and continuous updates helped affected organisations understand the issue and implement necessary measures. This event highlights the importance of maintaining open lines of communication between cybersecurity firms and their clients during crises to ensure timely and effective responses.

– Be cautious with third-party services. The CrowdStrike incident underscores the critical risks associated with relying on third-party services. Businesses learned that dependency on external providers for crucial functions can lead to widespread disruptions if those services fail. The incident highlighted the necessity of rigorous vetting processes to ensure third-party providers meet high security and reliability standards. Continuous monitoring and regular audits are essential to identify and mitigate risks promptly.

Diversifying service providers can reduce the risk of a single point of failure, enhancing overall resilience. Companies should ensure contracts with third-party providers include stringent security requirements and clear terms for liability and incident response. This approach helps maintain control and oversight over outsourced services, safeguarding operations and data integrity against potential vulnerabilities introduced by external partners.

Why Was The Aviation Sector So Badly Affected? 

The aviation sector experienced severe operational disruptions. Thousands of flights were cancelled or delayed, affecting major airports worldwide. The aviation and travel sectors were heavily affected by the CrowdStrike issue due to their reliance on real-time IT systems for critical operations. The system crashes disrupted flight scheduling, booking, and check-in processes, leading to thousands of cancellations and delays. Additionally, the outage compromised safety and security monitoring systems, exacerbating the operational chaos and inconvenience for passengers.

Why Was The Healthcare Sector Also Badly Affected? 

Hospitals and healthcare systems faced critical disruptions, delaying clinical procedures, and impacting patient care. The incident forced many institutions to revert to manual processes, highlighting the vulnerability of healthcare systems to IT failures. Healthcare and hospitals are particularly vulnerable to IT issues like the CrowdStrike incident (and cyberattacks) due to their reliance on IT systems for critical patient care functions, such as electronic health records (EHRs), medical devices, and communication systems. Also, the complex IT infrastructure in hospitals, often a mix of legacy and modern systems, creates additional vulnerabilities, as securely integrating these diverse systems is challenging.

This event demonstrates the urgent need for healthcare providers to invest in robust IT infrastructure and emergency protocols to ensure patient safety and continuity of care during technological crises.

What Does This Mean For Your Business? 

The CrowdStrike incident is a stark reminder of the inherent vulnerabilities in modern cybersecurity frameworks and the critical importance of robust IT management strategies. For businesses, the event offers many lessons, such as the need for rigorous testing and validation processes for all software updates. Ensuring that updates are thoroughly vetted before deployment can prevent similar catastrophic failures in the future.

Also, the incident highlights the necessity of developing comprehensive contingency plans to maintain operational continuity during IT disruptions. Businesses should conduct regular drills and update their incident response protocols to prepare for various scenarios, ensuring they can quickly address and mitigate the impact of unexpected failures.

The extensive disruption across various industries illustrates the interconnected nature of modern business operations and the potential widespread impact of a single point of failure. Businesses should, therefore, take a good look not only their own cybersecurity measures but also closely scrutinise and manage the cybersecurity protocols of their service providers and partners. This includes implementing stringent vetting processes, continuous monitoring, and regular audits of third-party services to ensure high security and reliability standards are maintained.

The legal and financial ramifications of such events also cannot be ignored. The anticipated lawsuits and claims for damages resulting from operational disruptions and customer inconvenience could set significant precedents, influencing future legal standards and liability expectations in the cybersecurity sector. That said, many businesses in the aviation and travel sector may decide to risk arguing that this was an exceptional event, thereby hoping to limit their legal/financial liabilities. Businesses may, however, need to enhance their insurance coverage and legal strategies to mitigate potential similar risks in the future.

Also, the increased risk of cyber-attacks following this incident (and other incidents in the past) should prompt businesses to heighten their vigilance against phishing and other cyber threats. The surge in CrowdStrike-themed phishing websites, for example, demonstrates the opportunistic nature of cybercriminals. Businesses must ensure their employees are well-informed and equipped to recognise and respond to these threats, investing in continuous security training and awareness programs.

While the disruption caused by CrowdStrike’s software update was not a cyber-attack, it nonetheless highlights the need for comprehensive cybersecurity strategies. Businesses that learn from this incident and proactively strengthen their cybersecurity frameworks will be better positioned to navigate the complexities of the digital age and safeguard their operations against future disruptions. By diversifying their cloud dependencies, implementing robust incident response plans, and maintaining stringent oversight of third-party services, companies can build a more resilient and secure operational environment.

An Apple Byte : Microsoft Suggest EC Laws Make Apple Less Vulnerable To CrowdStrike

Following CrowdStrike’s faulty update only affecting Microsoft Windows systems (because the update was specific to the Windows operating system), it’s been reported that Microsoft claims that an agreement with the EU means it’s not allowed to protect its operating system (OS) in the same way as Apple. The agreement with the EU relates to Microsoft not being able to give its own security software an unfair advantage over third-party apps.

Following a complaint (antitrust) to the European Commission in 2009, Microsoft says it agreed to give security software makers the same level of access to Windows that Microsoft itself gets. This, says Microsoft, contrasts with Apple’s situation.

Although Apple doesn’t allow security apps to have the same deep-level access to its OS, the macOS does the same type of monitoring as CrowdStrike for itself.

However, critics may say that CrowdStrike’s tools can’t operate at the same depth on a Mac as they can on Windows because Apple’s Endpoint Security Framework prevents it from doing so. Microsoft could have taken the same approach. Also, it could be argued by some, that Microsoft may only have itself to blame to an extent having only been made to make agreements following the outcome of antitrust cases and investigations relating to unfair advantages as judged by the EC.