Microsoft Recall and the New Class of AI Privacy Risk
June 14, 2024regreSSHion (CVE-2024-6387): Patch OpenSSH, Then Reduce Its Exposure
July 2, 2024In mid-June 2024, a ransomware attack against CDK Global, the dealer management platform used by thousands of car dealerships across North America, forced the company to take its systems offline. Dealerships in the United States and Canada suddenly could not process sales, service appointments, financing, or parts. Many reverted to pen and paper for days.
Why this matters for Canadian organizations
This was not a breach of one company so much as a single point of failure for an entire sector. When a critical SaaS provider goes dark, every customer inherits the outage. Canadian dealerships had no local fix available, no alternate system to fail over to, and little visibility into recovery timelines.
What defenders should learn
- Map your critical vendors. Know which suppliers, if unavailable, would halt operations within hours.
- Demand recovery commitments. Contracts should include recovery time objectives and evidence of tested backups.
- Build manual fallbacks. If your core platform disappeared for 72 hours, what is your paper-and-phone plan?
Takeaway: You cannot patch a vendor you do not control, but you can plan for their bad day. Inventory your concentration risk and test a manual continuity plan for each critical platform.
