Typically software like Crowdstrike is deployed on servers and automatically applies updates, and there ARE valid reasons for that:
their primary purpose is to protect systems from bad actors/malicious penetration attempts.
The defense is basically always a step behind.
These frequent updates are a way of staying just a step behind rather than a leap.
That said - it IS stupid to have critical production systems updated without control.
Just like any prudent enterprise has a lab/testing environment that can have patches applied and vetted before rolling out to production - even if for just a day or two - software that does endpoint protection should provide the same level of control.
But I have not seen any at THAT level that do so. They create their definition/code updates and just push them out.
This would be fine - IF they exercised proper due diligence and tested the code themselves before releasing but as we have seen this is not always the case.
Note that the Crowdstrike debacle did not cause me or my employer any direct issues - but it did for a number of our customers.
Some of whom will be paying us a lot of money to get local technician to their sites to get servers back online since a lot of them also think having centralized IT without local resources is a good idea.
Endpoint Protection has grown tremendously in recent years but is not a mature field and really - none of the companies doing it really do it "smart" and few of the CIOs out there know more than buzzwords so they just aren't aware of stuff like this.
Until now.