October 11, 2026

CrowdStrike Outage Lessons for OT and Facility Teams

CrowdStrike Outage Lessons for OT and Facility Teams

Looking at the CrowdStrike Outage with an OT Lens: Six Lessons for OT Teams

On July 19, 2024, a single content update crashed about 8.5 million Windows computers. No attacker was involved. A configuration file for the CrowdStrike Falcon sensor, Channel File 291, contained problematic content, and a logic error in CrowdStrike's validation process let it through. Airlines grounded flights, hospitals postponed procedures and some 911 services went down. CrowdStrike reverted the file within 80 minutes, but recovery took days because many machines had to be fixed by hand. Delta Air Lines alone put its costs at about USD 500 million, and insurers estimated USD 5.4 billion in direct losses for U.S. Fortune 500 companies.

Most coverage treated this as an IT story. It was also an OT story, and the lessons still apply.

Six lessons from the CrowdStrike outage for OT teams

1. Your OT runs on Windows too

BAS front-ends, SCADA HMIs, airport check-in and baggage systems, and access control servers all run on Windows workstations and servers. Some of them run endpoint security agents that update without the operations team knowing. Find out which of your OT machines run such agents and who controls their updates.

2. Automatic updates bypass your change management

OT teams test changes before they touch production. Vendor-pushed content updates skip that step. After the incident, CrowdStrike committed to staged deployments and to giving customers more control over when updates reach their machines. Ask every OT vendor which components update automatically, and whether you can stage those updates on a test group before they reach critical systems.

3. Recovery needed hands on keyboards

Each affected machine had to be booted into safe recovery mode so the bad file could be deleted, and encrypted machines needed their BitLocker recovery keys. Now picture that across a portfolio of buildings or a network of remote stations. Do you know where your recovery keys and local administrator credentials are kept? Can a qualified technician reach every site within your tolerance for downtime?

4. Manual operation is a control

Airline agents wrote boarding passes by hand. In September 2025, a ransomware attack on Collins Aerospace's passenger processing software forced Berlin, Brussels, Dublin and London Heathrow back to manual check-in for days. Your operators should know how to run the plant, the building or the terminal in hand, and they should practise it before they need it.

5. Concentration is a risk

One vendor's mistake reached thousands of organizations at once. The same is true for your BMS platform, your remote access tool and your cloud analytics provider. Map where a single product or provider sits beneath many of your sites.

6. Read your contracts

Delta's dispute with CrowdStrike turned on liability terms. Review your OT vendor agreements for update practices, notification duties, recovery support and limits of liability before you need them.

Plan for both kinds of failure

Resilience planning in OT has long focused on attackers. The CrowdStrike outage showed that a trusted vendor doing routine work can produce the same result. Your incident response plan should cover both.

Frequently asked questions

What caused the CrowdStrike outage?

A single content update to the CrowdStrike Falcon sensor, Channel File 291, crashed about 8.5 million Windows computers on July 19, 2024. No attacker was involved. CrowdStrike reverted the file within 80 minutes.

Why is the CrowdStrike outage an OT issue?

BAS front-ends, SCADA HMIs, airport check-in and baggage systems, and access control servers all run on Windows, and some of them run endpoint security agents that update without the operations team knowing.

How can OT teams improve OT resilience after the CrowdStrike outage?

Find out which OT machines run endpoint agents and who controls their updates. Ask vendors whether updates can be staged on a test group. Know where recovery keys and local administrator credentials are kept. Practise running the site by hand. Map where one vendor sits beneath many sites, and review your vendor contracts.

Related reading

Actimeta is an OT cybersecurity company focused on smart buildings and critical infrastructure.

References

‍

Author:
Team Actimeta