
On July 19, 2024, a single content update crashed about 8.5 million Windows computers. No attacker was involved. A configuration file for the CrowdStrike Falcon sensor, Channel File 291, contained problematic content, and a logic error in CrowdStrike's validation process let it through. Airlines grounded flights, hospitals postponed procedures and some 911 services went down. CrowdStrike reverted the file within 80 minutes, but recovery took days because many machines had to be fixed by hand. Delta Air Lines alone put its costs at about USD 500 million, and insurers estimated USD 5.4 billion in direct losses for U.S. Fortune 500 companies.
Most coverage treated this as an IT story. It was also an OT story, and the lessons still apply.
BAS front-ends, SCADA HMIs, airport check-in and baggage systems, and access control servers all run on Windows workstations and servers. Some of them run endpoint security agents that update without the operations team knowing. Find out which of your OT machines run such agents and who controls their updates.
OT teams test changes before they touch production. Vendor-pushed content updates skip that step. After the incident, CrowdStrike committed to staged deployments and to giving customers more control over when updates reach their machines. Ask every OT vendor which components update automatically, and whether you can stage those updates on a test group before they reach critical systems.
Each affected machine had to be booted into safe recovery mode so the bad file could be deleted, and encrypted machines needed their BitLocker recovery keys. Now picture that across a portfolio of buildings or a network of remote stations. Do you know where your recovery keys and local administrator credentials are kept? Can a qualified technician reach every site within your tolerance for downtime?
Airline agents wrote boarding passes by hand. In September 2025, a ransomware attack on Collins Aerospace's passenger processing software forced Berlin, Brussels, Dublin and London Heathrow back to manual check-in for days. Your operators should know how to run the plant, the building or the terminal in hand, and they should practise it before they need it.
One vendor's mistake reached thousands of organizations at once. The same is true for your BMS platform, your remote access tool and your cloud analytics provider. Map where a single product or provider sits beneath many of your sites.
Delta's dispute with CrowdStrike turned on liability terms. Review your OT vendor agreements for update practices, notification duties, recovery support and limits of liability before you need them.
Resilience planning in OT has long focused on attackers. The CrowdStrike outage showed that a trusted vendor doing routine work can produce the same result. Your incident response plan should cover both.
A single content update to the CrowdStrike Falcon sensor, Channel File 291, crashed about 8.5 million Windows computers on July 19, 2024. No attacker was involved. CrowdStrike reverted the file within 80 minutes.
BAS front-ends, SCADA HMIs, airport check-in and baggage systems, and access control servers all run on Windows, and some of them run endpoint security agents that update without the operations team knowing.
Find out which OT machines run endpoint agents and who controls their updates. Ask vendors whether updates can be staged on a test group. Know where recovery keys and local administrator credentials are kept. Practise running the site by hand. Map where one vendor sits beneath many sites, and review your vendor contracts.
Actimeta is an OT cybersecurity company focused on smart buildings and critical infrastructure.