The Lombard Review
Business

CrowdStrike's outage: who pays?

Contract caps shift operational loss

Lower Manhattan seen from Jersey City
Lower Manhattan seen from Jersey CityPhoto: King of Hearts / Wikimedia Commons, CC BY-SA 4.0

A flawed software sensor update pushed by cybersecurity firm CrowdStrike crashed an estimated 8.5 million Microsoft Windows systems worldwide on 19 July, paralyzing global airlines, hospital networks, and financial institutions. As corporate boardrooms survey the multibillion-dollar economic disruption, the legal and financial battle over liability is just beginning.

The New York Stock Exchange on Wall Street
The New York Stock Exchange on Wall StreetPhoto: Carlos Delgado / Wikimedia Commons, CC BY-SA 3.0

The Contractual Liability Shield

While commercial clients absorbed staggering operational losses, CrowdStrike’s standard enterprise software licensing contracts contain strict clauses capping direct legal liability to a multiple of subscription fees paid. This contractual reality shifts the operational financial loss directly onto corporate and insurer balance sheets. The incident exposed the extreme, unhedged vulnerability of global critical infrastructure to concentrated software monopolies.

Brokers on the floor of the New York Stock Exchange
Brokers on the floor of the New York Stock ExchangePhoto: Thomas J. O'Halloran / Wikimedia Commons, Public domain

CrowdStrike’s global IT meltdown demonstrated that while software monopolies can paralyze global commerce, their contractual liability caps leave corporate clients to bear the ultimate financial bill.