The Lombard Review

CrowdStrike's outage: who pays?

Contract caps shift operational loss

City of London skyscrapers viewed from Tower Bridge
City of London skyscrapers viewed from Tower Bridge Photo: The wub/Wikimedia Commons · CC BY-SA 4.0

Key data~8.5m devices hit

A flawed software sensor update pushed by cybersecurity firm CrowdStrike crashed an estimated 8.5 million Microsoft Windows systems worldwide on 19 July, paralyzing global airlines, hospital networks, and financial institutions. As corporate boardrooms survey the multibillion-dollar economic disruption, the legal and financial battle over liability is just beginning.

Veldhoven, ASML
Veldhoven, ASML Photo: HHahn/Wikimedia Commons · CC BY-SA 3.0

The Contractual Liability Shield

While commercial clients absorbed staggering operational losses, CrowdStrike’s standard enterprise software licensing contracts contain strict clauses capping direct legal liability to a multiple of subscription fees paid. This contractual reality shifts the operational financial loss directly onto corporate and insurer balance sheets. The incident exposed the extreme, unhedged vulnerability of global critical infrastructure to concentrated software monopolies.

Sign of the Publix corporate headquarters, Lakeland, Florida
Sign of the Publix corporate headquarters, Lakeland, Florida Photo: John O'Neill/Wikimedia Commons · CC BY-SA 3.0

CrowdStrike’s global IT meltdown demonstrated that while software monopolies can paralyze global commerce, their contractual liability caps leave corporate clients to bear the ultimate financial bill.

Write to The Lombard Review at contact@thelombardreview.com

More From The Lombard Review