The reality is the industry wants its cake and eat it too. No one forced Delta to buy a software which could force upgrades in their production fleet. They're a billion dollars company, and should put their big boys pants on.
The reality is the industry wants its cake and eat it too. No one forced Delta to buy a software which could force upgrades in their production fleet. They're a billion dollars company, and should put their big boys pants on.
In my mind, a quick test run of the update on a VM before letting it roll out globally would have revealed the BSOD boot loop.
Crowdstrike should have done a better job, but Delta chose them (to offload the responsibility and work) and now they're claiming foul. They knew the risk. This is a classic executive play of claiming the fault lies in the consultants/vendor and taking no responsibility.
I guess you're saying they shouldn't have outsourced in the first place? Which does sound like the correct conclusion in this case...
Except this update was one from CrowdStrike that would ignore Delta's stated update policy.
And they literally said "Oh, yeah, we can configure some updates to bypass your policy". I wonder how well this was communicated to those customers.
The update policy may work for the client version updates, but not for the "policy definition", otherwise delta won't get the sweet "all vulns mitigated with a 4h SLA" they crave.
lol.