The CrowdStrike outage on July 19, 2024, marks a pivotal moment for the software industry and has triggered a redesign of software engineering practices as well as investments in personnel, processes, and technology. This is stated in a study by Adaptavist.
The CrowdStrike incident was a wake-up call for the software industry.
The study, which surveyed 400 software developers in companies with annual revenues of over $10 million in the UK, the USA, and Germany, found that the CrowdStrike incident will prompt companies to increase their investments in software development, testing, deployment practices, and tools, augment their workforce, and expand training offerings in several areas. It also became clear that companies worldwide are evolving their software engineering and testing procedures to improve resilience and minimize associated risks—during the CrowdStrike failure, an estimated 8.5 million devices were affected.
Massive impacts show that the industry was not prepared
According to Adaptavist's surveys, the impacts of the outage were devastating: 87 percent of organizations experienced downtime, and 38 percent of companies faced severe operational disruptions lasting more than 24 hours. In Germany, this was even more pronounced: 52 percent of companies suffered from significant operational interruptions.
The incident revealed a glaring lack of preparedness. 82 percent of organizations either had no adequate emergency response plans or had no plans at all before the incident occurred. Among those with emergency plans, only 16 percent found them effective during the crisis, while 40 percent noted that their plans were inadequate for an incident of this magnitude.
Since the outage, almost half (41%) of software developers worldwide are confident that their organization can prevent a similar outage from affecting their systems in the future. However, in Germany, only 24 percent share this confidence, indicating that more needs to be done here to strengthen IT resilience.
Positive change becomes apparent
This newfound confidence is due to remarkably proactive and positive changes following the incident. The study shows that despite widespread upheaval, many industry insiders believe this had a positive impact on their companies. 74 percent or more report positive outcomes in all categories.
It is particularly noteworthy that 81 percent have implemented more robust development practices, while 80 percent report increased cybersecurity awareness among employees. The incident also triggered a complete overhaul of development practices, with 35 percent placing a greater focus on redundancy systems and 33 percent completely restructuring their software update processes.
Perhaps most surprising is that the incident actually accelerated development in many organizations. 68 percent report shortened timelines and 32 percent note a reduction in delivery times by more than a month. This acceleration, combined with more stable processes, suggests that organizations are finding more efficient ways of working while still ensuring security.
The scale of the organizations' response is reflected in substantial budget increases. 86 percent are increasing the budget for software development, and 87 percent are investing in the enhancement of team skills and technology solutions following the outage. This includes:
88 percent of organizations plan to increase investments in cybersecurity training.
86 percent plan to increase budgets for incident response training.
86 percent plan to increase the hiring budget, with 14 percent of companies raising their investments by more than 20 percent.
Long-term strategic realignment
The industry's commitment to a sustainable transformation is evident both in hiring plans and in the restructuring of the supply chain. A remarkable 99.5 percent of companies plan to expand their technical teams, with quality assurance leading the hiring drive (36%), followed by IT operations (34%), software developers (32%), and DevOps engineers (31%).
This realignment is leading to fundamental changes in supplier relationships. 83 percent of companies are actively diversifying their vendors or planning to do so. This shift also extends to the adoption of open source. 34 percent of companies are increasingly relying on open-source solutions, while 37 percent are strengthening partnerships with their current providers, indicating a more differentiated approach to risk management.
Jon Mort, CTO of Adaptavist, comments: "The incident with CrowdStrike was a wake-up call for the software industry. Although the impact was worrying, with 98 percent of companies affected, what is truly remarkable is how the industry has responded. We are witnessing an unprecedented transformation—from massive investments in training and new hires to fundamental changes in how companies approach development and relationships with vendors. However, the data also reveal that this transformation is far from complete. With only twelve percent of organizations having great confidence in preventing similar incidents, it is clear that we must address deeper cultural and structural challenges to build true resilience. The fact that the majority of organizations report positive fallout from this crisis suggests that, painful as it may be, this incident could prove to be the catalyst our industry needs to build more resilient, efficient, and secure systems for the future."
Date: 08.12.2025
Naturally, we always handle your personal data responsibly. Any personal data we receive from you is processed in accordance with applicable data protection legislation. For detailed information please see our privacy policy.
Consent to the use of data for promotional purposes
I hereby consent to Vogel Communications Group GmbH & Co. KG, Max-Planck-Str. 7-9, 97082 Würzburg including any affiliated companies according to §§ 15 et seq. AktG (hereafter: Vogel Communications Group) using my e-mail address to send editorial newsletters. A list of all affiliated companies can be found here
Newsletter content may include all products and services of any companies mentioned above, including for example specialist journals and books, events and fairs as well as event-related products and services, print and digital media offers and services such as additional (editorial) newsletters, raffles, lead campaigns, market research both online and offline, specialist webportals and e-learning offers. In case my personal telephone number has also been collected, it may be used for offers of aforementioned products, for services of the companies mentioned above, and market research purposes.
Additionally, my consent also includes the processing of my email address and telephone number for data matching for marketing purposes with select advertising partners such as LinkedIn, Google, and Meta. For this, Vogel Communications Group may transmit said data in hashed form to the advertising partners who then use said data to determine whether I am also a member of the mentioned advertising partner portals. Vogel Communications Group uses this feature for the purposes of re-targeting (up-selling, cross-selling, and customer loyalty), generating so-called look-alike audiences for acquisition of new customers, and as basis for exclusion for on-going advertising campaigns. Further information can be found in section “data matching for marketing purposes”.
In case I access protected data on Internet portals of Vogel Communications Group including any affiliated companies according to §§ 15 et seq. AktG, I need to provide further data in order to register for the access to such content. In return for this free access to editorial content, my data may be used in accordance with this consent for the purposes stated here. This does not apply to data matching for marketing purposes.
Right of revocation
I understand that I can revoke my consent at will. My revocation does not change the lawfulness of data processing that was conducted based on my consent leading up to my revocation. One option to declare my revocation is to use the contact form found at https://contact.vogel.de. In case I no longer wish to receive certain newsletters, I have subscribed to, I can also click on the unsubscribe link included at the end of a newsletter. Further information regarding my right of revocation and the implementation of it as well as the consequences of my revocation can be found in the data protection declaration, section editorial newsletter.
About the study
The study was conducted by Censuswide on behalf of Adaptavist between October 8, 2024, and October 16, 2024. Censuswide surveyed 400 individuals responsible for software development in organizations with annual revenues of $10 million or more in the UK (100 respondents), the USA (200 respondents), and Germany (100 respondents). The demographic profile of the respondents was determined by natural selection, as no reliable data to represent the national population was available. All data is based on this survey unless otherwise stated.