It depends on the actual root cause, gross negligence won't save them, regardless of what they put in the contracts.
From my point of view, one of the greatest problem for them is that they bypassed customers deployment policies.
From my point of view, one of the greatest problem for them is that they bypassed customers deployment policies.
Caveat emptor. Falcon and other similar security products often push updates at-will, and they're fully transparent about this if you actually read the contract terms and understand the vendor's approach to operations. I have worked with many clients that elect not to use such tools in certain sensitive environments, specifically to mitigate the risk of being impacted by something like CrowdStrike's 7/19 event.
Do you really want to wait until for the weekly/monthly/quarterly deployment window to deploy a detection update for a 0day, or a new type of malware?