Healthtech Security Quotes Erik Weinick on CrowdStrike Outage

July 31, 2024

Otterbourg partner Erik Weinick has been quoted in the Healthtech Security story “What health IT pros can learn from the CrowdStrike outage.” The article reports on the recent unexpected CrowdStrike outage and how health IT security practitioners should focus on regaining business continuity and building resilience for future risk.

Weinick, co-founder of Otterbourg’s privacy and cybersecurity practice, says the CrowdStrike incident further demonstrated the need for organizations of all sizes to reevaluate their legal and technical risk protocols.

"Although initial reports indicate that the incident was an accident, not an attack, on the technical front, organizations should use this incident as motivation to conduct information audits and penetration testing, update system mapping/organization and software -- including most importantly security patches -- and issue reminders to users about best security practices, like multifactor authentication and frequent changing of difficult to guess passwords," Weinick said.

He added that "organizations should check their vendor agreements, to remind themselves of, among other things, their own obligations to others when it comes to privacy and data security, who their partners are doing business with and what obligations do and do not flow through those relationships, and what limitations there are on liability for incidents such as CrowdStrike."