What Happened
On Friday, July 19, 2024, a faulty software update from cybersecurity vendor CrowdStrike crashed roughly 8.5 million Windows computers worldwide, sending them into repeated reboot loops. The disruption hit airlines, hospitals, and banks first, which is where most of the headlines went. But CrowdStrike’s customer base extends well past the Fortune 500, and the damage reached far smaller operations that had nothing to do with the mistake and no way to route around it.
In Manhattan, Tsvetta Kaleynska runs a small consulting firm called RILA Global Consulting. When the outage hit, she couldn’t pay her employees, missed a Friday contract deadline, and lost a prospective client worth roughly a quarter of her annual earnings because Docusign was unreachable. “If I were part of a big company, then I would be able to delegate and get support from computer science or security services,” she told the Associated Press. “But as a small business owner, I am depending only on myself.”
The pattern repeated across industries. In Melbourne, Australia, locksmith Chris Seabrook lost the ability to send or receive email, access his files, manage his schedule, or create invoices. In Maryland, a virtual mental health practice called Telapsychiatry had therapists locked out of the computers and phone systems they needed to see patients, and had to improvise with Zoom and Ring Central to keep appointments running. A Manhattan restaurant group, Handcraft Hospitality, couldn’t reach its cloud-based accounting software to view receipts, process invoices, or run employee paychecks.
None of these businesses had installed CrowdStrike themselves in any meaningful sense, and none of them had done anything wrong. They were simply downstream of a single vendor’s mistake, with no second system, no offline process, and no alternative way to reach the tools their business ran on. Days after the outage was fixed, many were still working through the backlog.
Why This Matters If You’re Not a Big Company
The gap the AP kept surfacing in its reporting was resources, not fault. A large enterprise IT department can often fail over to a different tool, work from paper temporarily with a plan already in place, or throw a team of specialists at getting critical systems back online within hours. A one-person locksmith shop or a three-location restaurant group typically has none of that in reserve. As one expert quoted in the coverage put it, big companies have a “sizable number of experts on their payroll,” while small businesses face an “uphill battle” with far fewer technical resources to draw on when something like this happens.
That imbalance is exactly why single points of failure matter more, not less, for smaller operations. If your business runs on one cloud provider, one accounting platform, and one email system, with no fallback for any of them, an outage anywhere in that stack becomes an outage in your entire business. You don’t need to be targeted by an attacker or make a mistake yourself to lose a day of revenue, a client, or your ability to pay employees. You just need to be a customer of whoever had the bad day.
What Actually Would Have Stopped This
No single business could have stopped CrowdStrike’s update from shipping, and that’s the point: the fix here isn’t preventing the outage, it’s surviving it. That starts with knowing which of your systems are true single points of failure, the ones where, if they go down, your business simply stops, and building even a basic manual workaround for each one. For the businesses in this story, that would have meant a documented way to process payroll without the primary software, an offline or alternate method for signing contracts, and a backup line of communication with clients that didn’t depend on one platform staying up.
It also means treating “the cloud provider will keep it running” as a plan you never actually wrote down. A short, practical continuity plan, who does what, using what alternate tool or process, when a core system goes dark, turns a chaotic scramble into a known set of steps your team can execute in the first hour instead of the third day.
Security Checklist for Your Business
Map your single points of failure. List every system that, if it went down for a day, would stop the business entirely, and start there.
Write down a manual fallback for payroll, invoicing, and client communication, even a simple one, so a platform outage doesn’t mean a full stop.
Diversify where it’s cheap to. Don’t route every critical function, email, e-signature, payments, through the same single vendor when a second option exists.
Test your plan before you need it. A continuity plan nobody has walked through is just a document, not a capability.
The businesses in this story weren’t breached, careless, or slow to patch. They were simply one vendor away from being unable to operate, and had no plan for that day. MSP Today’s trusted tech partner is JK Computer Solutions. If you want a second set of eyes on your setup, get in touch.
Source: Associated Press via PBS NewsHour, “Many small businesses struggle to resume normal operations days after global tech outage”.



