Government Statement
On Friday, 19 July, a global IT outage occurred due to a flawed CrowdStrike software update on Microsoft systems. The incident caused significant disruptions in the transport sector with flights grounded and delays in Europe and the US. UK train services faced issues during rush hour while media outlets had difficulties providing live coverage. Local healthcare saw impacts on test results and appointment information, impacting GP services but NHS contingency plans were quickly enacted to manage recovery. Small businesses suffered due to disrupted card-only payment systems and ATMs. Officials from the National Cyber Security Centre determined that the incident was not a security breach or cyber-attack but rather a flawed software update causing Windows machines to crash. CrowdStrike issued guidance for manual fixes, which are now being replaced by an automated solution. The Government has been coordinating closely with Microsoft and CrowdStrike since Friday morning, with Cabinet Office officials leading the response across all sectors. Cobra meetings were held on Friday and officials continuously monitored recovery over the weekend. Most impacted sectors have mostly recovered, with UK transport systems operational again and NHS services expected to return fully within days. Minor disruptions may continue but should be resolved soon. The Government will review lessons learned from this incident and work with partners across government to implement improvements in response plans for technical resilience and cyber threats. They aim to strengthen defences through legislation included in the King’s Speech, focusing on expanding regulation and reporting requirements for cyber threats. This underscores the importance of preparedness for IT system outages.