Not bothering doing basic, minimal testing - and other mitigation processes - before rolling out updates is absolutely terrible policy.
Comment on An angry admin shares the CrowdStrike outage experience
Entropywins@lemmy.world 3 months agoCompanies use crowdstrike so they don’t need internal cybersecurity. Not having automatic updates for new cyber threats sorta defeats the purpose of outsourcing cybersecurity.
ripcord@lemmy.world 3 months ago
hangonasecond@lemmy.world 3 months ago
Automatic updates should still have risk mitigation in place, and the outage didn’t only affect small businesses with no cyber security capability. Outsourcing does not mean closing your eyes and letting the third party do whatever they want.
kent_eh@lemmy.ca 3 months ago
It shouldn’t, but when the decisions are made by bean counters and not people with security knowledge things like this can easily (and frequently) happen.