The CrowdStrike-Microsoft global technology outage, which disrupted operations across multiple industries, including emergency services and grounded airlines, serves as a cautionary tale against over-reliance on a single vendor, but how about vendor consolidation?
Triggered by a single update from cybersecurity vendor CrowdStrike, the outage affected around 8.5 million devices running Microsoft Windows. CrowdStrike said in a recent statement that it had brought a significant number of those devices back online.
“CrowdStrike just created the best argument against consolidation and platformization: widespread outages,” Jeff Pollard, VP and principal analyst at Forrester, told SDxCentral.
However, Eric Grenier, director analyst at Gartner, argues, “I'm not sure that this [incident] is indicative of a failure because of platform consolidation or vendor consolidation.”
The promise and downside of consolidation
Consolidation and platformization are appealing to many organizations for several reasons.
“Most CISOs feel that their technology stack is too complex, they have too many vendors, and too many tools,” Forrester's Pollard noted. “They want to go with a more consolidated approach. They want to reduce the number of vendors that they have operating in their environment.”
This consolidation approach promises efficiency gains, cost reductions, and streamlined operations. However, the CrowdStrike incident highlights a downside: concentration risk.
“One of the challenges that comes as a result of that is concentration risk, and that's what that platform and consolidation story can lead to when you put a lot of your security controls into one vendor's basket, so to speak,” Pollard said. “To some extent, I think that CrowdStrike has sort of introduced potentially the best evidence against platformization or consolidation in the form of this widespread outage, because this is what happens when you do overly concentrate your security controls.”
Too early to tell if this incident is killing vendor consolidation
Gartner's Grenier echoed that there is a desire among organizations and security leaders for vendor consolidation, but he added a different perspective.
“I'm sure that there are going to be organizations out there who have zero tolerance and will start to explore other options,” Grenier told SDxCentral. “But I think it's too early to speculate that this is going to kill vendor consolidation.”
However, Grenier argues organizations shouldn’t target consolidating into one or two vendors in the security realm. “I don't think that's a good idea,” Grenier said. “I do think that having this ‘anchor vendor’ is a good strategy.”
An anchor vendor should be the security platform provider that offers a set of tools that meet the organization's needs, while having the ability to plug in third-party capabilities and data where they don't, so that the data can all be correlated together, Grenier explained, emphasizing vendor consolidation is not an easy process.
“It's the risk acceptance, understanding the risks that come with that vendor consolidation, and understanding what's going to happen and what can happen, and maybe developing some of those mitigations before vendor lock-in happens,” Grenier said.
Lessons learned from CrowdStrike-Microsoft outage
The CrowdStrike incident illustrates the dangers of relying too heavily on a single vendor, as one problematic update can cause widespread disruption. Pollard highlighted the importance of examining the concentration risks.
“If you're going with a vendor consolidation strategy, make sure that you understand exactly how you're going to recover from an incident like this,” Pollard said. “Conduct business continuity and resilience exercises to understand if something like this happens, you know what to do about it. I think a lot of companies are learning that this needs to be something that they consider in those tabletop scenarios for their business resilience.”
On top of understanding how the security platform works, Grenier noted organizations should have discussions with security vendors to understand the controls for preventing downtime and not blindly trust that quality assurance (QA) testing is sufficient.
“The biggest lesson here is that just blindly trusting that vendors are doing QA, it's probably not a good thing, and that we, as any IT organization, should be doing some kind of testing before deploying blindly to our devices,” Grenier said.
“From a certain perspective, [the CrowdStrike-Microsoft outage] shows how many organizations put their trust into CrowdStrike, and that is also the unfortunate part, right? It's because so many organizations trust CrowdStrike, one bad update really screws up and becomes a global phenomenon,” Grenier said.
Comments