Crowdstrike was in front of Congress this week – while CEO George Kurtz declined to participate. CrowdStrike’s senior vice president, Adam Meyers, testified before lawmakers instead. Meyers explained during the hearing that a “perfect storm” of issues led to the incident, stemming from a mismatch in update parameters. CrowdStrike has since implemented new safeguards and committed $60 million in customer credits, while lawmakers demanded accountability for the outage’s impact on consumers. The company emphasized that the outage was not due to a cyberattack and updated its testing processes to prevent future occurrences.
Lawmakers emphasized the need for accountability in cybersecurity and discussed potential legal reforms to hold software providers liable for negligence. Jen Easterly, director of the Cybersecurity and Infrastructure Security Agency, said in an interview that she has been speaking to members of the Homeland Security Committee and others about a plan that would permit lawsuits to hold software providers legally liable for gross negligence, supplemented by significant “safe harbor” provisions that would exempt companies following good practices.
The scrutiny on CrowdStrike and the broader discussions about holding software providers legally liable for negligence reflect a pivotal moment in the cybersecurity landscape. The message is clear: accountability and transparency are no longer optional. Here’s the other insight – this isn’t a security incident. There’s no attacker to blame. This is all Crowdstrike, and it might just mean an actual change to liability.

