Comment There was a simple way to aviod this (Score 1) 81
While Crowdstrike did screw the pooch on this one they do provide a simple way of preventing this or at the least reducing the changes of it. I woke up with everyone panicking and I didn't get a blip or alert.
The customer is responsible for setting up their sensor update schedules. You have to pick (again as the customer) when you are creating you update schedule to update to the "Auto Latest" update or "Auto N-1" release. Why would you have your production systems on the latest release? Test servers should get the Latest. It's not like you're not covered or monitored on anything but the latest. Everyone sends a bad update once in a while.
I'd say there is some shared responsibility here. Sys Admins need to be Sys Admins after all. My N-1 schedule meant I only spent my day explaining to Management why we were ok.