The CrowdStrike outage was a wake-up call because it showed that a single vendor's mistake can take your business offline even when you did nothing wrong, and that a standard cyber policy may not respond to that kind of loss unless it was built to. When one software update rippled out and knocked systems offline worldwide, the lesson for business owners was not really about that one company. It was about how much every business now depends on a handful of outside providers, and what happens to your income when one of them goes dark.
That dependency is the real exposure, and it did not go away when the outage was fixed. Here is what it means for a business in Alpena, Petoskey, or Gaylord, and how coverage does or does not respond.
What actually happened, and why should I still care?
A cybersecurity vendor pushed a flawed software update, and machines running it crashed and would not restart on their own. Microsoft estimated the event affected about 8.5 million Windows devices, and it grounded flights, stalled banks, and disrupted hospitals for hours. Most of those businesses had done nothing wrong. They simply relied on a provider that had a bad day, and they had no way to keep operating while it was down. That is the part worth remembering, because the specific vendor changes but the pattern does not.
How dependent is my business on outside providers?
More than most owners realize until something breaks. Take a minute and map it out. If any one of these went down for a day, could you still take payments, reach customers, or get work done?
- Your point-of-sale or payment processor
- Your cloud accounting, scheduling, or records software
- Your email and calendar provider
- Your internet service provider
- Your website or online store host
- Your security or backup software vendor
- A key supplier whose systems your orders flow through
Every item on that list is a point where someone else's failure becomes your lost revenue. Knowing where those points are is the first step to protecting against them.
Will my cyber liability policy cover an outage like this?
Maybe, and this is exactly where the fine print matters. Many standard cyber policies are built to respond to a direct attack on your own systems, such as a breach or ransomware, and are not necessarily designed to respond when the disruption comes from a third-party provider or a botched update rather than a hacker. Two features change that picture:
- Contingent business interruption coverage is designed to respond when a vendor you depend on suffers a covered event that interrupts your income
- System failure coverage is designed to respond to an unplanned outage of your own systems that was not caused by an attack, such as a faulty update
Whether either applies to a given loss depends entirely on the policy language, the waiting period, and how the outage is classified. None of it is bound or altered until an authorized representative confirms it, and every policy is subject to underwriting. The point is not to assume you are covered for an outage because you carry a cyber policy. The point is to ask.
What should I actually do about it?
Pair better preparation with the right coverage. Neither one alone is enough. On the preparation side, keep backups of your critical data somewhere separate from your main systems, know how you would take payments or serve customers if your primary system went down, and write a simple plan for who does what during an outage. On the coverage side, sit down with an agent and go through your cyber policy specifically for third-party and outage exposure, not just breach response. Our guide to what cyber liability is explains how the coverage is built, and if cost is on your mind, how to save money on business insurance covers ways to manage the premium without cutting the protection you need.
How can Top O' Michigan help?
We have insured Northern Michigan businesses for 52 years, and we work with a panel of carriers so we can compare how different cyber policies handle outage and dependency risk rather than hand you a single template. If you want someone to read your current policy for the contingent business interruption and system failure language, an agent who knows the area will walk through it with you. Start on our cyber insurance page, or reach the office nearest you through the Petoskey or Gaylord location pages.
Call 800-686-8664 or email Service@TheSpireTeam.com to review your exposure before the next outage, not after. Coverage is subject to underwriting and is not bound until confirmed by an authorized representative.
.png)