HordeHit: The Insurance Leader’s Guide to Doomsday Prepping for Cyber Outages

It’s time for the C-suite to reflect: are employees at every level of the organization up-to-date on emergency protocols for their position should a cyber disaster occur? If they’re not, how can management deploy training that sticks if communication goes offline?

(Image credit: Greg Rosenke/Unsplash.)

When the CrowdStrike outage struck on July 19, stakeholders feared the cybersecurity firm had been hacked. A reasonable concern: Cyberattacks rose by 72 percent between 2021 and 2023, and cyberterrorism is an ever-evolving, ever-present threat.

But it turned out the CrowdStrike outage wasn’t an attack; it was an unintentional inside job, a software update gone wrong.  “Problematic content data” within the software update triggered the largest single-insured loss event in the last 20 years of the affirmative cyber insurance industry.

With Munich Re valuing the cyber insurance market at approximately $15 billion, the outage represents a potential 10-point hit to the combined ratio, with an estimated cost of $1.5 billion to cyber insurers specifically—and that’s on top of the astonishing $5 billion in lost revenue estimate from the outage.

Commentators across the internet have floated many names for the CrowdStrike outage. For this article, let’s call it HordeHit.

Besides the parallel of “crowd” to “horde” and “strike” to “hit,” HordeHit evokes a fictional reckoning with calamity in the form of descending zombie hordes. In the real world, the C-suite must contend with the prospect of internal and external fallout from cyber crises. Business leaders might take some inspiration from doomsday preppers.

Maybe that seems far-fetched. But in an increasingly online, AI-powered world, once-implausible cyber scenarios are happening. Leaders must learn from HordeHit in preparation for—or, better yet, to sidestep—their own potential calamities.

Productive pessimism and the 10th person rule

If decades of zombie media have taught us anything, it’s that the world laughs off impending doom until the last survivor is left saying, “I told you so.”

For leaders to plan for the worst, the organization must facilitate productive pessimism. Enter the “10th man” (or 10th person) rule featured in the zombie franchise World War Z.

The 10th person idea is as follows: If nine people in a group of 10 agree, the 10th person must assume and argue as though the other nine are wrong. This helps the collective break from groupthink and plan for unexpected threats.

In World War Z, the threat addressed by the 10th person rule is that the world could be overrun by the undead, and massive walls should be built to keep them out. When this comes to pass, the countries that entertained and prepared for the prospect of disaster come out intact.

In our world, the outage of the world’s most popular cybersecurity firm seemed beyond belief. Until it happened.

Productive pessimism is valuable to strategically plan for cyber incidents. Echo chambers in meetings and the boardroom can force creative thinkers to stifle concerns; and avoiding argument with top leadership can prevent managers from floating those concerns to the top.

Leaders must facilitate open discussion and allow for respectful opposition and contrarian viewpoints. Employees should be encouraged to creatively answer the question: “What could go wrong?”

Dry runs for digital disaster

What’s the organizational value of rehearsing an outage, or any other corporate catastrophe? While we don’t (yet) have statistics on those most likely to survive the zombie apocalypse, consider another emergency: an airplane crash.

Only 4 percent of people are thought to actually read the safety cards airlines offer to passengers. During the “Miracle on the Hudson” plane landing in 2009, a mere 30 percent of those onboard reported watching the safety video, and only 10 of the 150 passengers evacuated as recommended, with life vests on.

It’s time for the C-suite to reflect: are employees at every level of the organization up-to-date on emergency protocols for their position should a cyber disaster occur? If they’re not, how can management deploy training that sticks if communication goes offline?

Prioritizing people as a resilience measure

Nearly all executives (97 percent, according to a recent SAS survey) believe corporate resiliency is important, yet fewer than half perceive their company as resilient. Closing this resiliency gap requires open communication, as well as treating employees like what they are: a company’s greatest asset.

Just as a chain is only as strong as its weakest link, an organization is only as consistent as its most burned-out employee. Humans aren’t machines. When they’re tired, hungry or stressed, they make mistakes.

Per a 31,000 person survey of employees across 31 countries, 68 percent reported struggling with the pace and volume of their work, and 46 percent felt burned out. On average, employees had to read four emails for every one they sent.

Imagine an employee, 187 emails in, after four hours of meetings. Is it so hard to imagine that human making a mistake that leads to an event like HordeHit? Combating employee burnout is a disaster preventative and a resilience measure.

Cutting back on meetings and discouraging exchanging work messages outside of business hours—with the C-suite and management leading by example—is an evidence-backed start. A Harvard Business Review survey revealed employee productivity was 71 percent higher when meetings were reduced by 40 percent.

Additionally, developing a blame-free policy can help bake mistake prevention and rapid diagnosis into the company culture. The blame-free approach, recommended by McKinsey for organizational resilience, teaches management to encourage early communication of mistakes and team problem-solving over pointing fingers.

Hope for the best, but plan for your HordeHit

Fortunately, CrowdStrike fixed HordeHit very quickly. Most organizations were down for only a few hours, and cybersecurity firms worldwide are planning for how to respond to future incidents.

As organizations develop contingency plans for tech outages, some will have to continue operations (like hospitals) and may need to consider a plan to manually write down information to continue providing services. For other companies, a few hours where the business doesn’t function isn’t life or death, but will result in lost time and revenue.

Let’s say that, with an average salary of $52,000 a year, half a day’s wage comes to $100, pre-tax. Multiplied by the personnel manning 8.5 million Microsoft Windows machines, and that’s a conservative $850 million in lost time.

Unfortunately, this loss isn’t insurable; a cyber insurer will not reimburse lost productivity. Therefore, insurers and organizations of every stripe should have a plan for when employees can’t get online or communicate with one another, and there’s no resolution time for these issues.

A proposal: Encourage personnel who aren’t essential to solving a HordeHit scenario to pick up a book, engage in personal development or rest. When leaders let the workforce recharge, they may just meet employees refreshed and ready to contribute—as opposed to logging back on with the living dead.

Lessons from the Crowdstrike Meltdown

CrowdStrike Outage: Policyholder Guidance and Insurance Implications

Reflecting on CrowdStrike: Disaster, Recovery—The Day After

Insurance and IT Outages: What Can We Do After the CrowdStrike Incident?

Franklin Manchester //

Franklin Manchester, CPCU, is a principal global insurance advisor at data and AI company SAS (Cary, N.C.), where he connects insurers with technology that powers future-forward decisions. He is a 20-year veteran of the insurance industry, beginning his career at Allstate as an associate agent. In 2005, he joined Nationwide Insurance as a personal lines underwriter, going on to manage personal lines and commercial lines underwriters, portfolio analysts, sales support teams and sales managers.

Leave a Comment

(required)