The hearing was not left pending. The House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection scheduled—and held—its public hearing on the July 19, 2024, CrowdStrike outage on September 24, 2024, at 2 p.m. EDT in Room 310 of the Cannon House Office Building in Washington, D.C.
The hearing, titled “An Outage Strikes: Assessing the Global Impact of CrowdStrike’s Faulty Software Update,” examined how a defective security-software update caused widespread Windows crashes and what companies, critical-infrastructure operators and policymakers could do to limit a repeat.
What hearing did Congress schedule?
The event was a House Committee on Homeland Security hearing conducted by its Subcommittee on Cybersecurity and Infrastructure Protection. Congress.gov lists the hearing details, public record and related documents at the official hearing page.
| Detail | Verified information |
|---|---|
| Title | “An Outage Strikes: Assessing the Global Impact of CrowdStrike’s Faulty Software Update” |
| Date and time | September 24, 2024, at 2 p.m. EDT |
| Location | Room 310, Cannon House Office Building, Washington, D.C. |
| Committee | House Committee on Homeland Security |
| Subcommittee | Subcommittee on Cybersecurity and Infrastructure Protection |
| Public record | Hearing page, witness list and transcript available through Congress.gov |
The committee described it as the first congressional hearing focused on the outage. A contemporary report saying the hearing was “scheduled for September” was accurate when published on August 30, 2024, but is incomplete for a current article: the event already occurred.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
Why was the hearing called?
On July 19, 2024, a faulty CrowdStrike content or configuration update for Falcon Sensor caused Windows systems to crash around the world. The incident was not a malicious cyberattack and was not an update created by Microsoft. Committee materials and a Congressional Research Service analysis cite Microsoft’s estimate that approximately 8.5 million Windows devices were affected.
That figure is an estimate of devices, not a count of people, businesses or all computers running Windows. Disruptions also spread indirectly through services that depended on affected systems, including airlines, hospitals, banks, retailers, government agencies and public-safety operations.
House Homeland Security leaders requested public testimony from CrowdStrike CEO George Kurtz on July 22, 2024, three days after the outage. The request is documented in the committee’s letter and announcement.
Rank #2
- Six of Crows: Book 1
Who testified?
The official witness list named Adam Meyers, CrowdStrike’s senior vice president for counter adversary operations. The list is available as a Congress.gov PDF.
Lawmakers had initially sought Kurtz, but CrowdStrike designated Meyers as its witness. Kurtz did not testify at the September hearing. The committee’s post-hearing explanation appears in its September 26 summary.
What went wrong technically?
A security product update reached Windows systems
CrowdStrike’s Falcon Sensor runs on Windows endpoints. A defective channel file in a content update passed through a validation process that failed to detect the bug. The update reached a sensitive part of the operating system, producing system crashes rather than a deliberate intrusion.
The House committee’s technical description is in its opening statement. Lawmakers and others described the event as the largest IT outage in history, but that is a characterization rather than a universally defined technical measurement.
What did lawmakers examine?
The official hearing record and transcript show that members pressed CrowdStrike about:
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →- How the update was developed and tested.
- Why validation controls did not stop the defective file.
- How the update was deployed to customers at global scale.
- Why the failure produced widespread Windows crashes.
- What CrowdStrike changed after the incident.
- How organizations can pause, recover from or contain a similar failure.
The official transcript is also cataloged in the GovInfo hearing record.
Rank #4
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Compliant with new ATF regulations: Essential for Proving Compliance with ATF 27 C.F.R. Part 478.125 Federal Firearms Regulation for an ATF inspection
- Keep track of firearm purchases and sales: Whether you're a dealer, a collector of guns, or just want to keep track of your personal inventory, this book is for you! Keep track of the guns you acquire and sell for insurance and ATF regulations
- Plenty of space to write important information: Each page has enough space for 14 acquisitions - each transaction is covered over a two-page spread. There are spaces to track the type, model, serial number, and PMF (privately made firearm) number, caliber, name and address, date of acquisition and date of disposition.
- Professional quality book - This book comes in an 11” x 8.5” which gives you plenty of space to write in the appropriate and required information. This comes with a hard cover that keeps it looking new after every entry. This book is professional enough for manufacturers and importers to use and yet easy for the everyday person to use as well Reorder SKU: LOG-100-7LCW-T40(FFL-Gun-Log)
Why did one software update become a policy issue?
The outage raised questions beyond CrowdStrike’s engineering process:
- Concentration risk: airlines, health providers, financial institutions, retailers and public agencies can share dependencies on a small number of technology vendors.
- Third-party and supply-chain risk: an organization’s resilience depends partly on the release controls of suppliers it does not operate.
- Deployment safety: staged releases, automated rollback and the ability to stop distribution can reduce the blast radius of a bad update.
- Operational redundancy: critical services need tested alternatives when endpoint systems fail.
- Standards: Congress could consider minimum expectations for testing, release protocols and recovery, although the hearing itself did not enact such rules.
The Congressional Research Service discusses public-safety systems, emergency communications, critical infrastructure and possible congressional responses in its analysis.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What changes did CrowdStrike describe?
CrowdStrike told lawmakers it had adopted or was implementing enhanced testing, more gradual or staged rollouts and additional safeguards before broad deployment. Those are company-described measures intended to reduce recurrence risk, not an independently audited guarantee that another outage cannot happen.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsWhat the hearing did—and did not—establish
It established an oversight record
The hearing created a public account of the update, the validation failure, the scale of disruption and CrowdStrike’s stated corrective actions. It also highlighted how a non-malicious software defect can disrupt essential services at global scale.
It did not decide liability or impose a new standard
Congressional testimony is oversight. The September event did not itself determine legal liability, damages, regulatory violations or whether every affected organization had adequate safeguards. Those questions can be addressed separately by regulators, courts, customers and insurers.
It was not a Senate or joint-chamber hearing
The September 24 event was a House Homeland Security subcommittee hearing. A separate inquiry, such as Senator Chuck Grassley’s correspondence with federal officials and CrowdStrike, should not be described as the same event; that letter is available here.
Practical resilience questions for organizations
The hearing offers a useful checklist for businesses and public agencies reviewing their own exposure:
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
- Are endpoint-security updates released by controlled percentages, regions or business units?
- Can administrators immediately pause distribution?
- Is there a tested rollback path and a recovery image for critical systems?
- Can essential operations continue if Windows endpoints are unavailable?
- Are offline administrative credentials and recovery tools protected and accessible?
- Are third-party suppliers included in continuity and incident-response exercises?
- Does the organization maintain an accurate asset inventory and know which services share a common vendor dependency?
Timeline
- July 19, 2024: A faulty CrowdStrike update causes worldwide disruption.
- July 22, 2024: House Homeland Security leaders request public testimony from George Kurtz.
- August 30, 2024: The September hearing is reported as scheduled.
- September 24, 2024: The House subcommittee holds the hearing with Adam Meyers as witness.
- September 26, 2024: The committee publishes a post-hearing summary.
Primary documents
- Congress.gov hearing page
- Official witness list
- Official transcript
- GovInfo record
- Congressional Research Service analysis
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




