Tech Tip : Use Windows 11 Point-In-Time Restore To Recover From Problem Updates

If a Windows update, driver, application or settings change leaves your PC unstable or unable to start properly, Windows 11 now includes a built-in Point-in-Time Restore feature that can roll your computer back to an earlier working state in just a few minutes.

Unlike the older System Restore feature, Point-in-Time Restore automatically creates full restore points every 24 hours by default. These include Windows, installed applications, settings and local files, making it much easier to recover from software problems without rebuilding your PC.

To Check Whether The Feature Is Enabled

– Open “Settings”.

– Select “System > Recovery > Point-in-Time Restore”.

– Confirm that the feature is turned on. On many Windows 11 Home and Pro PCs with drives of 200GB or larger, it is enabled automatically.

If Your PC Develops A Serious Problem

– Restart your PC into the “Windows Recovery Environment”.

– Select “Troubleshoot > Point-in-Time Restore”.

– Enter your “BitLocker recovery key” if prompted.

– Choose a restore point created before the problem occurred.

– Confirm the restore and allow Windows to roll your PC back to that earlier state.

Before using Point-in-Time Restore, remember that any applications, settings or local files created after the selected restore point will be removed. Files stored in OneDrive or another cloud service remain safe, although they may need to synchronise again afterwards.

Point-in-Time Restore provides an excellent safety net when updates or software changes go wrong, but it’s still important to keep your important files backed up to the cloud or another secure location.

Tech Insight : Problems With Windows 11 Updates Reported

Many MSPs have been reporting that Windows 11 updates are increasingly causing upgrade failures, BitLocker lockouts and unexpected behaviour, and here we look at what may be going wrong, why it is happening now, and what can realistically be done to prevent it.

The Pattern Many MSPs Are Seeing on the Ground

It has been reported across organisations supported by MSPs that Windows 11 feature updates and security patches are failing in ways that feel inconsistent, hard to predict and difficult to explain. In practical terms, this has included devices that meet Microsoft’s published requirements not receiving updates at all, updates failing part way through installation, and systems rebooting directly into BitLocker recovery screens.

What has made this particularly frustrating is that many of the affected machines appear otherwise healthy. For example, disk space is available, policies are applied correctly, and in some cases manual upgrades succeed. At scale, however, manual intervention doesn’t translate into a sustainable approach, particularly when large numbers of devices behave differently. As a result, for MSPs, Windows updates are increasingly becoming a visible support issue rather than a background maintenance task.

Issues Acknowledged

This experience appears to align with wider reporting beyond MSP communities. For example, back in November this year (2025), Microsoft acknowledged issues with specific Windows 11 security updates that caused devices to enter BitLocker recovery mode after installation. These incidents affected supported business versions of Windows 11 and prompted follow-up guidance and remediation updates.

Updates That Refuse to Install or Fail Without Warning

One of the most frequently reported problems is Windows 11 feature updates either not being offered to eligible devices or failing without presenting a clear error message.

A recurring technical factor appears to be the EFI system partition (a small hidden disk area that helps Windows start). Many devices originally deployed with Windows 10 were created with EFI partitions of around 100 MB. While this was sufficient under earlier Windows servicing models, it is increasingly inadequate for modern recovery and update processes.

For many now it seems that when Windows attempts to stage a feature update and can’t write the required boot or recovery components to the EFI partition, the update may fail silently or be blocked entirely. Windows Update does not always highlight this limitation clearly, so investigation often focuses on policies, drivers or hardware compatibility, when the underlying cause is actually related to disk layout and boot configuration.

It’s been reported that this lack of visibility has added complexity to diagnosing update failures, particularly in mixed hardware environments.

Why BitLocker Is So Often Involved

BitLocker, a built in Windows tool that encrypts a device’s data to protect it if lost or stolen, has featured prominently in many reported update issues, not because encryption itself is malfunctioning, but because of how closely it is now integrated into the Windows boot process.

For example, many Windows 11 devices ship with BitLocker or device encryption enabled by default, especially where users sign in using Microsoft or Entra ID accounts during setup. While this improves baseline data protection, it also means that updates interact directly with encrypted boot components.

In mid November, Microsoft confirmed that certain Windows 11 security updates could trigger BitLocker recovery prompts after installation, even when no obvious configuration changes had been made. Users were presented with requests for 48 digit recovery keys, leading to a noticeable increase in support calls where keys were not immediately available.

In some reported cases, recovery environments were also affected, with peripherals such as USB keyboards and mice not responding at the recovery prompt. Microsoft subsequently issued emergency fixes to restore recovery environment functionality, underlining the seriousness of the issue.

Windows 11 Upgrades and the End of Windows 10 Support

These update problems are occurring against the backdrop of a wider transition to Windows 11. Windows 10 reached the end of mainstream support in late 2025, prompting many organisations to accelerate upgrade plans. While extended security updates remain available in limited scenarios, Microsoft has positioned Windows 11 as the primary supported desktop platform going forward.

As a result, businesses that delayed upgrading are now moving in larger numbers, often across device fleets that include both new and older hardware. This has increased the volume of feature updates being deployed and exposed edge cases that may not have appeared as frequently during earlier, more gradual upgrade cycles.

Windows 11 itself has also followed a faster cadence of servicing updates, particularly during the rollout of later builds in 2025. While this approach enables quicker responses to security issues, it also increases the likelihood that update related problems will surface in real world environments before they are fully resolved.

Why These Issues Are Becoming More Common

These problems are becoming more common due to a combination of increased platform complexity, faster update cycles and stronger default security settings within Windows 11. For example:

– Growing platform complexity. Windows 11 is required to operate securely across a broad range of hardware, firmware versions and security configurations. Each update must account for UEFI behaviour (how the system firmware controls the boot process), TPM states (the status of the security chip that stores encryption keys), Secure Boot, encryption, device drivers and third party security software, all interacting simultaneously. As default security settings have been strengthened, the tolerance for inconsistency has narrowed. Relatively small changes in update handling can have disproportionately large effects once deployed at scale.

– Faster update cycles. Microsoft now releases updates more frequently than in previous Windows generations. While this improves responsiveness to vulnerabilities, it reduces the amount of time updates spend being exercised across the full range of business configurations before wide deployment. MSPs often encounter these edge cases early because they support diverse environments rather than uniform device fleets.

– Encryption as a default state. With encryption now widely enabled by default, the consequences of update failures have changed. When issues occur during boot related updates, devices may refuse to start without recovery credentials rather than reverting automatically. This has raised the operational impact of update failures, even where the underlying issue is relatively contained.

What Has Helped Reduce the Impact

Across wider industry reporting and real world experience, several patterns have now emerged around which measures have helped limit disruption when Windows 11 update issues occur.

For example, testing feature updates and major security patches on a small number of representative devices has helped surface issues early. Staged deployment, rather than immediate broad rollout, has allowed problems to be identified before they affect larger user groups.

Centralised storage of BitLocker recovery keys has also proven critical where recovery prompts occur, reducing downtime and support escalation. In environments where EFI partition limitations are known, addressing these during rebuilds or hardware refresh cycles has reduced repeated update failures.

Alongside these technical measures, clearer explanations of how modern Windows updates interact with security features and boot environments have become more important as businesses try to understand whether issues are isolated incidents or part of wider platform behaviour.

What Does This Mean For Your Business?

It seems that recently reported Windows 11 update problems are not just the result of a single fault or a sudden drop in quality, but the outcome of a more complex platform colliding with faster release cycles and a large, overdue upgrade push away from Windows 10. For MSPs, this has changed the nature of updates from something that could largely run in the background into an operational risk that needs closer attention, clearer communication and better preparation. For Microsoft and hardware vendors, it highlights how small changes at the boot or recovery level can have wide consequences once deployed at scale.

For UK businesses, the practical takeaway is that disruption linked to updates does not automatically indicate neglect or mismanagement. For example, many of the issues now being seen are tied to how modern Windows versions handle encryption, recovery environments and legacy device layouts during upgrades. Understanding that context matters, particularly as more organisations complete their move to Windows 11 and rely on it as their primary supported platform.

When update problems do arise, speaking to your IT support provider is often the safest and most effective first step. This is because they are best placed to confirm whether an issue is local or part of a wider pattern, to recover access without risking data, and to put measures in place that reduce the chance of repeat disruption. As Windows continues to evolve, that relationship between businesses, their IT support companies, and the platform itself is becoming more important, not less.

Tech News : WhatsApp To Show Ads

WhatsApp has announced it will begin showing adverts on its platform for the first time, with new features designed to monetise its Updates tab while keeping personal messages private.

Ads Appear Only in the Updates Tab

In a major shift for the Meta-owned app, WhatsApp will now allow businesses to promote content in two key areas of the Updates tab, i.e., Status and Channels. These features are separate from private chats and have been used by more than 1.5 billion people daily, according to Meta.

The new monetisation rollout includes three core features, which are:

1. Ads in Status – short-lived posts similar to Instagram Stories, where businesses can now place adverts that link directly to a chat.

2. Promoted Channels – businesses and creators will be able to pay to have their Channels suggested to users browsing the directory.

3. Channel Subscriptions – a new paid model allowing followers to access exclusive content for a monthly fee. WhatsApp will take a 10% commission.

“Today we’re introducing new features in WhatsApp’s Updates tab, which is home to both Channels and Status,” the company said. “We believe the Updates tab is the right place to introduce this, in a way that doesn’t interrupt personal chats.”

Targeting and Privacy

Meta says it has designed the new advertising features with “privacy as the core principle”. The company is keen to stress that end-to-end encryption still applies to all messages, calls and personal Status posts, meaning they cannot be accessed or used for ad targeting.

Instead, WhatsApp says it will use a limited set of data to decide which ads to show. This includes:

– The user’s country or city.

– App language settings.

– Channels followed.

– Interaction with other ads.

Those who have linked WhatsApp to Meta’s Accounts Centre (used to manage connected services like Facebook and Instagram) may also see more tailored ads, based on preferences or activity from across those platforms. But Meta insists phone numbers and private content will not be shared.

“We will never sell or share your phone number to advertisers,” WhatsApp stated. “Your personal messages, calls and groups you are in will not be used to determine the ads you may see.”

A Strategic Move Towards Business Monetisation

While this is WhatsApp’s first foray into advertising, the move aligns with Meta’s wider strategy to turn the messaging app into a multi-purpose business platform. With public social media engagement falling and users spending more time in private messages and small group updates, WhatsApp’s Status and Channels features represent prime digital real estate.

“We’ve been talking for years about how to build a business on WhatsApp in a way that doesn’t interrupt personal chats,” Meta said. “Now the Updates tab is going to be able to help Channel admins, organisations and businesses build and grow.”

WhatsApp’s Status feature is already used by millions of individuals and companies to post 24-hour content. Channels, meanwhile, offer a one-way broadcast model, popular with news outlets, influencers and service providers—that is now gaining commercial functionality.

By adding adverts and subscription models, Meta is following a monetisation blueprint more common in Asia, where super-apps like WeChat have long blurred the line between messaging, content, and e-commerce.

Businesses and Advertisers

For UK businesses using WhatsApp to communicate with customers, the change brings new opportunities to drive engagement and visibility directly within the app.

Ads in Status updates could, for example, allow a local retailer to post a promotion with a “click to chat” button that starts a WhatsApp conversation. Promoted Channels will enable brands to push their content to new audiences, while paid subscriptions may appeal to creators and media companies offering exclusive updates.

“By showing ads in Status, you can help your business get discovered by new customers and make it easy for them to start a conversation with you, all within WhatsApp,” the company explained.

Although detailed campaign tools are still limited compared to Facebook or Instagram, early reports suggest that WhatsApp will offer businesses insights into click-through rates and some performance data.

Meta says it will gradually roll out the new advertising features over the coming months, starting with select markets. It has not confirmed which countries will be first, but WhatsApp’s Updates tab is known to be more popular in Latin America, India, and Southeast Asia than in the UK or Europe, where adoption of Channels and Status has been slower.

A Careful Balancing Act for WhatsApp

While WhatsApp says personal chats will remain untouched, the introduction of adverts may be seen by some as a departure from the app’s original ethos. For example, WhatsApp was once strongly anti-ads, famously stating in a 2012 blog: “Advertising isn’t just the disruption of aesthetics… at every company that sells ads, the user becomes the product.”

That stance softened after Meta’s acquisition in 2014. With WhatsApp now home to billions of users but little direct revenue, monetisation has become a priority. For example, back in 2023, Meta introduced tools such as WhatsApp Business API, click-to-chat ads from Facebook, and shopping catalogues, but this is the first time that on-platform adverts will be shown within the app itself.

Optional

Meta has also confirmed that the new advertising and subscription options are optional for users. For example, if someone chooses not to follow Channels or browse Status updates, they won’t see any ads. “If you only use WhatsApp to chat with friends and loved ones, there is no change to your experience at all,” the company said.

Even so, some privacy experts have warned that the move could set a precedent. Marijus Briedis, CTO at NordVPN, has noted: “Ads in WhatsApp aren’t just a distraction—they’re a signal of what may come next. Meta’s so-called ‘optional’ data-sharing is rarely as optional as it sounds.”

Regulation

Regulators in the EU are also likely to take a close look at the rollout, especially in light of GDPR requirements and Meta’s ongoing legal challenges over data processing and consent.

More changes are expected as the advertising features evolve. For now, it seems that WhatsApp is just focusing on “ads in the right place”, limiting the impact on its core messaging service. “We also don’t want to have a service that has lots of settings… that’s complexity too,” the company said, confirming that core app tabs like Updates and Channels will remain fixed.

What Does This Mean For Your Business?

It has to be said that this first step into advertising marks a real turning point for WhatsApp and the direction of Meta’s wider messaging strategy. By ringfencing adverts within the Updates tab, the company is attempting to walk a careful line between unlocking new revenue streams and preserving user trust. Whether that balance holds will depend on how the rollout is received across different markets, particularly in Europe, where expectations around privacy and digital intrusiveness remain high.

For UK businesses, the changes bring a new channel for visibility, especially for those already using WhatsApp to handle customer enquiries or share updates. The ability to promote Status content or gain traction through sponsored Channels could offer low-friction ways to reach engaged users, with a direct path into conversation. It may also help smaller firms compete more easily with larger brands in a messaging-first environment. However, uptake will likely depend on how seamlessly these features integrate with the current business tools and how effective the targeting proves in practice.

Advertisers and creators also now have a fresh route into an app with over a billion daily users, but one that has historically resisted the very concept of commercialisation. Meta’s challenge is to prove that these new ad formats deliver value without compromising the simplicity and privacy that have long defined WhatsApp’s appeal. Meanwhile, competitors like Signal and Telegram are likely to be watching very closely and may well seize on any missteps to reinforce their own positioning as ad-free alternatives.

For users, the WhatsApp experience remains largely unchanged for now, provided they steer clear of Channels and Status. However, questions about long-term data use, the permanence of ad features, and the possible expansion of monetisation elsewhere in the app are unlikely to fade. WhatsApp’s keen to promote the message that ads will stay away from personal chats. However, the test will be whether that promise still feels true a year from now.

An Apple Byte : New macOS Update Disrupts Popular Cybersecurity Tools

Following its recent release, Apple’s latest macOS update, dubbed Sequoia (macOS 15), has disrupted the functionality of several widely used cybersecurity tools, including those from CrowdStrike, SentinelOne, and Microsoft.

Users and developers have voiced frustrations on social media and in Mac-focused forums about issues leaving many security applications non-operational. Reports highlight problems with tools like CrowdStrike, SentinelOne, Microsoft Defender, and ESET, alongside browser issues, particularly with Firefox, where the OS firewall sometimes blocks web access. The root cause is unclear, but the disruptions are creating significant challenges for both end-users and enterprise security teams.

The key issue seems to stem from changes Apple has made in Sequoia’s network stack, which cybersecurity firms say is interfering with their products. For example, CrowdStrike delayed support for Sequoia, citing complications in adapting their software. Similarly, SentinelOne warned users not to upgrade without ensuring proper support, while Microsoft’s Defender and ESET have faced similar difficulties. Despite SentinelOne and ESET eventually providing compatibility, significant disruption remains across the community.

Apple has yet to comment, leaving security firms and users to manage the situation. CrowdStrike is awaiting a Sequoia update to offer full support, while temporary workarounds are being shared to address issues like firewall settings and basic web browsing. For now, it may be advisable to delay upgrading to macOS Sequoia until Apple or security providers release compatible updates.

Featured Article : CrowdStrike : What Happened?

Following 8.5 million Microsoft devices being hit by a faulty software update from CrowdStrike causing global chaos, we look at what happened, how, and why.

The Worst Cyber Event In History 

The scale of effects of the disruption caused make this event, which began on 18 July (Microsoft) or 19 July (according to CrowdStrike), makes it the worst cyber event in history, beating the WannaCry cyber-attack in 2017 where 300,000 computers in 150 countries were affected.

Who Are CrowdStrike? 

Texas-based cybersecurity technology company, CrowdStrike, formed in 2011, provides an AI and machine learning powered, cloud-based enterprise endpoint protection platform (intelligent real-time antivirus) called Falcon which is used by a wide range of businesses and organisations.

What Caused The Problems? 

As part of the Falcon protection mechanisms, it receives regular software updates. However, the recent update which caused the outage was described as a “sensor configuration update to Windows systems”. In this case, the faulty sensor software update triggered a logic error which resulted in a system crash and blue screen (the ‘Blue Screen Of Death’ – BSOD) on impacted systems, i.e. the computer system for the companies that were running Microsoft operating systems and using CrowdStrike’s Falcon platform (those running Falcon sensor for Windows version 7.11 and above) were completely disabled.

The ‘sensor’ is a software agent installed on endpoint devices (such as Windows systems).

Only Windows Affected 

The faulty software update only impacted Microsoft because the Falcon sensor update was specifically designed specifically just for the Windows operating system and the logic error that triggered the system crashes and blue screens (BSOD) was tied to a component or function that is unique to Windows environments.

Enormous Impact 

The faulty CrowdStrike software update caused major disruptions across a wide variety of industries globally, which included:

Airlines

Airlines experienced severe operational disruptions, thousands of cancelled /grounded flights and causing delays and passenger queues at major airports, such as the UK’s Stanstead and Gatwick airports and Berlin’s BER and Newark International airports. Passengers faced long waits while the airlines struggled to manage schedules and customer service due to the system failures. Customers (many of whom only learned of the cancellation of their flight when they arrived at the airport) suffered delays, as well as the stress, disruption, and expense of having to find later alternative flights and alternative routes, and/or book hotels overnight, and pay more for overdue car parking back at home.

Healthcare 

Hospitals and healthcare systems were notably impacted, with some facilities facing delays in clinical procedures and disruptions in medical technology and communications. This situation forced many hospitals to implement manual restoration of systems and downtime procedures, which affected patient care and led to cancellations of some clinical services. Even pharmacies have been affected with customers unable to get their prescriptions.

Financial Services 

Many banks and financial institutions encountered issues processing transactions, leading to service interruptions. The outage affected ATMs and online banking services, causing inconvenience to customers and operational delays.

Media and Broadcasting

Broadcasters such as Sky News experienced temporary outages, affecting their ability to deliver news and updates to the public, thereby highlighting the apparent reliance of media companies on cybersecurity and IT infrastructure to maintain continuous service.

Emergency Services 

Emergency call centres also faced operational challenges, which impacted their ability to respond promptly to emergencies, leading to increased risk and delays in emergency response times, raising significant public safety concerns.

Retail 

Retailers also had difficulties, particularly in their point-of-sale systems and online platforms. This disruption led to transaction delays and affected inventory management, impacting both in-store and online sales.

Fix Issued 

CrowdStrike says it has issued a fix although this in itself may be time-consuming and disruptive because it involves having to apply the fix to each affected device separately and the need for a manual reboot in safe mode for affected computers, thereby creating considerable work and issues for IT departments everywhere.

Ongoing 

At the time of writing this, the many effects are ongoing, and are expected to last around one week.

Not A Cyber Attack, But Cyber Attack Risk Now Increased 

Although CrowdStrike Founder and CEO, George Kurtz, stressed in a statement that the outage was “not a cyberattack”, there are warnings that scams and cyberattacks should now be expected, e.g. cyber attackers setting up phishing websites and running scams under the guise of offering help / fixes for those affected. Secureworks, for example, has reported a spike in CrowdStrike-themed domain registrations (a sign of potential phishing websites being set up), and there have been reports of emails being circulated by scammers claiming to be ‘CrowdStrike Support’ or ‘CrowdStrike Security’. The advice, therefore, is for those affected to only use CrowdStrike’s website to source information and help.

Although not directly related, on the theme of online security and issues relating to antivirus software, Russian security company Kaspersky has just announced that it will be exiting the US market and consequently will be cutting staff ahead of a government-imposed sales ban. Kaspersky reports: “Starting from July 20, 2024, Kaspersky will gradually wind down its US operations and eliminate US-based positions” and that “The decision and process follows the Final Determination by the US Department of Commerce, prohibiting the sales and distribution of Kaspersky products in the US”.

Sorry! 

Following the CrowdStrike issue, the company’s CEO, George Kurtz, has issued an apology, saying: “I want to sincerely apologise directly to all of you for the outage. All of CrowdStrike understands the gravity and impact of the situation. We quickly identified the issue and deployed a fix, allowing us to focus diligently on restoring customer systems as our highest priority”. 

What Does This Mean For Your Business?

The catastrophic event involving CrowdStrike’s faulty software update serves as a stark reminder of the vulnerabilities that can arise from our reliance on advanced cybersecurity solutions. For businesses, this incident is a reminder of the critical importance of rigorous testing and validation processes for all software updates. It also highlights the need for robust contingency plans to ensure operational continuity in the face of unexpected system failures.

The extensive disruption across various industries, from airlines to healthcare, illustrates the interconnected nature of modern business operations and the potential widespread impact of a single point of failure. Companies must therefore try to prioritise not only their own cybersecurity measures but also closely scrutinise and manage the cybersecurity protocols of their service providers and partners.

The legal and financial ramifications of such events also can’t be ignored. The anticipated lawsuits and claims for damages resulting from operational disruptions and customer inconvenience could set significant precedents, influencing future legal standards and liability expectations in the cybersecurity sector. This legal landscape will likely demand that businesses enhance their insurance coverage and legal strategies to mitigate potential risks.

Also, the warning from CrowdStrike about the increased risk of cyber-attacks in the wake of this incident should prompt businesses to heighten their vigilance against phishing and other cyber threats. The surge in CrowdStrike-themed phishing websites shows the cruel and opportunistic nature of cybercriminals, and businesses should now ensure their employees are well-informed and equipped to recognise and respond to these threats.

While the disruption caused by CrowdStrike’s software update was not a cyber-attack, it has nonetheless amplified the need for businesses to adopt comprehensive cybersecurity strategies. This could include, for example, maintaining up-to-date security protocols, preparing for swift crisis management, and fostering a culture of continuous improvement in cybersecurity practices. Businesses that learn from this incident and proactively strengthen their cybersecurity frameworks will be better positioned to navigate the complexities of the digital age and safeguard their operations against future disruptions.

Tech Insight : Lessons Learned

Following the massive after-effects of the faulty CrowdStrike update, we take a look at the lessons learned so far in this ongoing situation.

What Happened? 

On July 19, a faulty software update from cybersecurity technology company CrowdStrike affected approximately 8.5 million Microsoft devices globally causing chaos across multiple industries globally as key systems were disabled. The faulty software update only impacted Microsoft because the update for CrowdStrike’s enterprise security platform was specifically designed just for the Windows operating system. The update caused a ‘logic error’, leading to widespread system crashes and blue screens of death (BSOD).

The worst cyber event in history (so far), it has surpassed the scale of the 2017 WannaCry attack and highlighted significant vulnerabilities in modern cybersecurity frameworks.

What Is CrowdStrike? 

CrowdStrike, founded in 2011 and headquartered in Texas, provides the Falcon platform, a cloud-based endpoint protection solution used by large businesses and organisations globally.

Lessons Learned from the CrowdStrike Event 

Although (at the time of writing this), some of the after-effects are still being felt, the scale and severity of the event have already taught us some valuable lessons. For example:

– Businesses may have an over-reliance on the Cloud. The CrowdStrike incident has starkly highlighted our over-reliance on cloud services. Many businesses have embraced the cloud for its scalability, cost-effectiveness and convenience, often integrating critical operations and data storage into cloud platforms. However, this event demonstrated the potential risks of depending heavily on a single cloud provider or a homogeneous cloud environment.

– A re-evaluating of business cloud strategies may now be necessary. For example, the disruption caused by the faulty update has already led to some reconsidering their cloud strategies. Many businesses are now re-evaluating their cloud-first approaches to avoid single points of failure. Strategies being reported include moving away from a platform-centric approach to a more tailored, nuanced strategy which balances performance, costs, and security, and enhances efficiency and reduces risk. Also, adopting workload-specific strategies and determining the best platform for each application, e.g. a private cloud, industry cloud, on-premises data-centres, or a multi-cloud architecture, may now be a more attractive and less risky strategy.

Broadly speaking, building resilience through diversity (e.g. diversifying cloud providers and also implementing hybrid and multi-cloud strategies) plus ensuring all eggs aren’t just in one basket may now be the way forward (controversially) for some businesses. This approach could mitigate the risks associated with single points of failure, ensure greater operational continuity, perhaps even reduce (long-term) costs, and hopefully contain any cloud chaos in future.

– There is a need for rigorous software testing. The CrowdStrike incident emphasises the critical importance of thorough testing before deploying software updates, especially on a Friday! This event demonstrated that even minor configuration changes could have catastrophic consequences if not properly vetted. Comprehensive testing protocols must now be implemented to prevent such incidents from occurring in the future. Robust incident response plans are necessary. Businesses need to ensure they have comprehensive strategies in place to quickly address and mitigate the impact of IT failures. This includes regular drills and updates to incident response protocols to stay prepared for various scenarios.

– Enhanced employee security training and awareness is important. Increased vigilance against phishing and other cyber threats is crucial in the aftermath of such incidents. Businesses must invest in continuous employee training to recognise and respond to cybersecurity threats effectively. This proactive approach can significantly reduce the risk of successful cyberattacks exploiting the situation. For example, some of the reports of how cyber-criminals have already taken advantage of the situation include:

– Phishing campaigns, pretending to offer fixes and updates for the CrowdStrike-related issues. These campaigns are aimed to trick users into clicking on malicious links, leading to malware infections. The US The Department of Homeland Security’s Cybersecurity & Infrastructure Security Agency (CISA) reported that it had “observed threat actors taking advantage of this incident for phishing and other malicious activity”. People have been advised to avoid clicking links in any text or email related to the CrowdStrike or Windows disruption.

– Setting up fraudulent websites claiming to provide legitimate updates and solutions. These sites were designed to distribute malware under the guise of providing help. For example, cybercriminals distributed ZIP archives with names like “CrowdStrike-hotfix.zip” containing the HijackLoader payload (which loads malware) and was reportedly aimed at users and CrowdStrike customers in Latin America.

– Initiating ransomware attacks, taking advantage of the disruption.

– Stealing data. In some cases, attackers have exploited vulnerabilities exposed by the disruption to infiltrate systems and steal sensitive data, compounding the damage caused by the initial outage

– Continuous and transparent communication makes a big difference in a crisis. CrowdStrike’s swift communication and deployment of a fix were crucial in managing the incident’s fallout. Transparent and continuous updates helped affected organisations understand the issue and implement necessary measures. This event highlights the importance of maintaining open lines of communication between cybersecurity firms and their clients during crises to ensure timely and effective responses.

– Be cautious with third-party services. The CrowdStrike incident underscores the critical risks associated with relying on third-party services. Businesses learned that dependency on external providers for crucial functions can lead to widespread disruptions if those services fail. The incident highlighted the necessity of rigorous vetting processes to ensure third-party providers meet high security and reliability standards. Continuous monitoring and regular audits are essential to identify and mitigate risks promptly.

Diversifying service providers can reduce the risk of a single point of failure, enhancing overall resilience. Companies should ensure contracts with third-party providers include stringent security requirements and clear terms for liability and incident response. This approach helps maintain control and oversight over outsourced services, safeguarding operations and data integrity against potential vulnerabilities introduced by external partners.

Why Was The Aviation Sector So Badly Affected? 

The aviation sector experienced severe operational disruptions. Thousands of flights were cancelled or delayed, affecting major airports worldwide. The aviation and travel sectors were heavily affected by the CrowdStrike issue due to their reliance on real-time IT systems for critical operations. The system crashes disrupted flight scheduling, booking, and check-in processes, leading to thousands of cancellations and delays. Additionally, the outage compromised safety and security monitoring systems, exacerbating the operational chaos and inconvenience for passengers.

Why Was The Healthcare Sector Also Badly Affected? 

Hospitals and healthcare systems faced critical disruptions, delaying clinical procedures, and impacting patient care. The incident forced many institutions to revert to manual processes, highlighting the vulnerability of healthcare systems to IT failures. Healthcare and hospitals are particularly vulnerable to IT issues like the CrowdStrike incident (and cyberattacks) due to their reliance on IT systems for critical patient care functions, such as electronic health records (EHRs), medical devices, and communication systems. Also, the complex IT infrastructure in hospitals, often a mix of legacy and modern systems, creates additional vulnerabilities, as securely integrating these diverse systems is challenging.

This event demonstrates the urgent need for healthcare providers to invest in robust IT infrastructure and emergency protocols to ensure patient safety and continuity of care during technological crises.

What Does This Mean For Your Business? 

The CrowdStrike incident is a stark reminder of the inherent vulnerabilities in modern cybersecurity frameworks and the critical importance of robust IT management strategies. For businesses, the event offers many lessons, such as the need for rigorous testing and validation processes for all software updates. Ensuring that updates are thoroughly vetted before deployment can prevent similar catastrophic failures in the future.

Also, the incident highlights the necessity of developing comprehensive contingency plans to maintain operational continuity during IT disruptions. Businesses should conduct regular drills and update their incident response protocols to prepare for various scenarios, ensuring they can quickly address and mitigate the impact of unexpected failures.

The extensive disruption across various industries illustrates the interconnected nature of modern business operations and the potential widespread impact of a single point of failure. Businesses should, therefore, take a good look not only their own cybersecurity measures but also closely scrutinise and manage the cybersecurity protocols of their service providers and partners. This includes implementing stringent vetting processes, continuous monitoring, and regular audits of third-party services to ensure high security and reliability standards are maintained.

The legal and financial ramifications of such events also cannot be ignored. The anticipated lawsuits and claims for damages resulting from operational disruptions and customer inconvenience could set significant precedents, influencing future legal standards and liability expectations in the cybersecurity sector. That said, many businesses in the aviation and travel sector may decide to risk arguing that this was an exceptional event, thereby hoping to limit their legal/financial liabilities. Businesses may, however, need to enhance their insurance coverage and legal strategies to mitigate potential similar risks in the future.

Also, the increased risk of cyber-attacks following this incident (and other incidents in the past) should prompt businesses to heighten their vigilance against phishing and other cyber threats. The surge in CrowdStrike-themed phishing websites, for example, demonstrates the opportunistic nature of cybercriminals. Businesses must ensure their employees are well-informed and equipped to recognise and respond to these threats, investing in continuous security training and awareness programs.

While the disruption caused by CrowdStrike’s software update was not a cyber-attack, it nonetheless highlights the need for comprehensive cybersecurity strategies. Businesses that learn from this incident and proactively strengthen their cybersecurity frameworks will be better positioned to navigate the complexities of the digital age and safeguard their operations against future disruptions. By diversifying their cloud dependencies, implementing robust incident response plans, and maintaining stringent oversight of third-party services, companies can build a more resilient and secure operational environment.

Featured Article : WhatsApp Updates

Here we look at some of the latest WhatsApp updates and the value and benefits they deliver to users.

Search Conversations By Date For Android 

The first of three new updates of significance for WhatsApp is the “search by date” function for individual and group chats on Android devices. Previously, this function had been available on other platforms (iOS, Mac desktop and WhatsApp Web).

As featured on Meta’s Mark Zuckerberg’s WhatsApp channel (Meta owns WhatsApp), WhatsApp users on Android can now search for a chat on a particular date (not just within a range). For example, one-on-one or group chat details can be date searched by tapping on the contact or the group name, tapping on the search button, and then tapping the calendar icon (right-hand side of the search box), and selecting the individual date. This feature is likely to deliver a better user experience by giving greater precision and control and potentially saving time in locating specific messages.

Privacy Boost From User Profile Change 

Another potentially beneficial boost to the privacy aspect of what is already an end-to-end encrypted messaging app is (in the beta version) closing the loophole on sharing profile pictures without consent, impersonation, and harassment by preventing users from taking screenshots within the app. If users try to screenshot a profile picture, for example, WhatsApp now displays a warning message. Although the ability to download profile pictures was stopped 5 years ago, it was still possible to take screenshots. Closing this loophole in the latest update should, therefore, contribute to greater user privacy and safety.

Minimum Age Lowered To 13 

One slightly more controversial change to WhatsApp’ T&C’s’s terms and conditions however is the lowering of the minimum age of users in Europe (and the UK) to 13 from 16. This brings the service in line with its minimum age rules in the US and Australia, and the move by WhatsApp was taken in response to new EU regulations, namely the Digital Services Act (DSA) and the Digital Markets Act (DMA), and to ensure a consistent minimum age requirement globally. The two new regulations have been introduced both to tackle illegal and harmful activities online and the spread of disinformation, and to help steer large online platforms toward behaving more fairly.

In addition to the minimum age change, WhatsApp is also updating its Terms of Service and Privacy Policies to add more details about what is or is not allowed on the messaging service and to inform users about the EU-US Data Privacy Framework. The framework is designed to provide reliable mechanisms for personal data transfers between the EU and the US in a way that’s compliant and consistent with both EU and US law, thereby ensuring data protection.

Criticism 

However, although the minimum age change (which may sound quite young to many parents) will be good for WhatsApp by expanding its user base and good for users by expanding digital inclusion and family connectivity, it has also attracted some criticism.

For example, the fact that there’s no checking/verification of how old users say they are (i.e. it relies on self-declaration of age and parental monitoring) has led to concerns that more reliable methods are needed. The concern, of course, also extends to children younger than 13 accessing online platforms (e.g. social media) despite the set age limits.

In Meta’s (WhatsApp’s) defence, however, it already protects privacy with end-to-end encryption and has resisted calls and pressure for government ‘back doors’. It has also taken other measures to protect young users. These include, for example, the ability to block contacts (and report problematic behaviour), control over group additions, the option to customise privacy settings, and more.

Competitors 

Regarding compliance with new EU regulations, the European Commission has been actively engaging with large online platforms and search engines, including Snapchat, under the Digital Services Act (DSA). Also, given the widespread impact of these regulations on digital platforms and their emphasis on data privacy and security, it is likely that Signal (a competitor), and other messaging and social media platforms, are taking steps to align with these new requirements.

Some people may also remember that Snapchat came under scrutiny last summer from the UK’s data regulator to determine if it is effectively preventing underage users from accessing its platform. The investigation was in response to concerns about Snapchat’s measures to remove children under 13, as UK law required parental consent for processing the data of children under this age.

What Does This Mean For Your Business? 

The latest WhatsApp updates, alongside the broader implications of new EU and UK regulations, herald potentially significant shifts for businesses, messaging app users, and the industry at large. These changes, encompassing enhanced search functionalities, privacy safeguards, and adjustments to user age limits, will reshape some user experiences and offer both challenges and opportunities.

The “search by date” function for Android users should enhance user convenience and accessibility, save time, facilitate precise and efficient message retrieval, plus improve user engagement and satisfaction. Businesses leveraging WhatsApp for customer service or internal communications, for example, could find this feature particularly beneficial, i.e. by enabling quicker access to pertinent information, and streamlined interactions.

The extra privacy enhancements essentially reflect a growing industry-wide focus on user security and digital safety and will strengthen individual privacy (always welcome). They also emphasise the importance of user-consent and control over personal information and should remind businesses of the need to prioritise and manage user data both in line with (evolving) regulatory standards and today’s consumer expectations.

The adjustment of WhatsApp’s minimum user age in Europe and the UK presents a bit more of a nuanced landscape. While aiming to broaden digital inclusion and connectivity, this change also highlights the complexities of age verification and online safety. Messaging and other platforms, however, must find ways to navigate these complexities, ensuring compliance while fostering a safe and inclusive digital environment for younger users.

The broader context of the DSA and DMA, along with similar regulatory efforts in the UK, signal the transformative period that digital platforms are now in and although we can all see the benefit of curtailing harmful online activities, there’s also an argument for resisting pressure to go as far as giving governments back doors (thereby destroying the privacy and exposing to other risks). Messaging apps and social media platforms, including WhatsApp and its competitors (e.g. Snapchat, Signal, and others) have known regulations were coming, probably expect more in future, and are now having to adapt to enable compliance and retain trust while introducing other features valued for users at the same time.

Businesses using apps like WhatsApp (which also has a specific business version) are likely to already value its privacy features, e.g. its end-to-end encryption, for data protection. As such, they are unlikely to oppose any more helpful privacy-focused, or improved user experience changes, as long as they don’t interfere with the ease of use of the app (or result in extra costs).