[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

GLOBAL INCIDENT TRACKER

Every incident exposed the same recovery gap

Vendor insolvency. Faulty updates. Ransomware. Acquisition shock. Different causes, one recurring operational question: can the critical software be rebuilt, deployed and operated without the vendor when normal support disappears?

12 sourced incidents6 risk categoriesUpdated August 2026

£1.9B

JLR cyberattack — CMC modelled UK impact · 2025

$500M

Delta — reported CrowdStrike outage impact · 2024

$65M–$96M

Possible Synapse shortfall cited by US senators · 2024

1,050%

Proposed VMware increase cited in AT&T evidence · 2024

VERIFIED INCIDENT DATABASE

Operational failures, mapped to the evidence gap

Event facts and financial figures below are sourced. The recovery lesson is Castler's interpretation of what the incident reveals about continuity planning.

Showing 12 of 12

Faulty UpdateJuly 2024

CrowdStrike Global IT Outage

CrowdStrike

A faulty Falcon content update affected an estimated 8.5 million Windows devices across aviation, healthcare, banking and public services. Delta reported about 7,000 cancelled flights over five days.

Recovery lesson

Documented application-by-application recovery procedures matter when a shared platform fails.

$500M

Delta-reported impact

CyberattackAugust–October 2025

Jaguar Land Rover Cyberattack

Jaguar Land Rover IT systems

The attack halted production for more than a month and disrupted JLR's supplier network. The Cyber Monitoring Centre modelled £1.9 billion of UK impact across more than 5,000 organisations.

Recovery lesson

Restoring IT and operational systems is a supply-chain continuity problem, not only a security problem.

£1.9B

CMC modelled UK impact

Acquisition Shock2023–2024

Broadcom / VMware Pricing Crisis

VMware, acquired by Broadcom

After Broadcom's acquisition, VMware licensing and support changed materially. AT&T court evidence cited a proposed 1,050% annual increase; a survey of more than 110 customers found 98% were using, planning or considering alternatives.

Recovery lesson

Portability and independently tested operating procedures reduce switching risk and vendor leverage.

1,050%

Proposed AT&T annual increase

Vendor InsolvencyApril 2024

Synapse Financial Technologies Bankruptcy

Synapse Financial Technologies

Customers across partner fintechs lost access to funds while banks and counterparties reconciled ledger discrepancies after Synapse filed for bankruptcy. US senators cited a possible $65 million to $96 million shortfall.

Recovery lesson

Continuity depends on current software, records and tested reconstruction procedures—not only contractual access.

$65M–$96M

Possible shortfall cited by US senators

Vendor InsolvencySeptember 2013

Nirvanix Cloud Storage Shutdown

Nirvanix

More than 1,000 customers received roughly two weeks to move data from Nirvanix, including petabyte-scale enterprise estates. The deadline turned ordinary data migration into an emergency programme.

Recovery lesson

A migration plan must be tested before the provider's clock starts.

2 weeks

Initial customer migration window

CyberattackMay 2021

Colonial Pipeline Ransomware

Colonial Pipeline IT systems

Colonial shut down a pipeline carrying about 45% of US East Coast fuel after ransomware compromised its business network. The company paid $4.4 million and took six days to restart the pipeline.

Recovery lesson

IT dependencies can stop operational systems even when the physical system is intact.

6 days

Pipeline restart window

Support DiscontinuedDecember 2022

Southwest Airlines Holiday Meltdown

Southwest operational systems

The US Department of Transportation recorded 16,900 cancelled flights and more than two million stranded passengers during Southwest's holiday operational failure. Refunds, reimbursements and penalties exceeded $750 million.

Recovery lesson

Recovery capacity must be tested at operational scale, not assumed from normal-day performance.

16,900

Flights cancelled

Support Discontinued2023–2026

QuickBooks Desktop Support Changes

Intuit

Intuit ended support, updates or connected services for desktop products and versions while preserving varying levels of local access by licence and release. Businesses had to migrate workflows before payroll, banking and compliance integrations stopped updating.

Recovery lesson

Data portability and a replacement operating procedure need to exist before support ends.

Version-led

Support and connected services ended

Vendor InsolvencyMarch 2024

Blueboard Abrupt Shutdown

Blueboard

The employee-rewards platform ceased operations immediately, disrupting customers and reward recipients. Blueboard's former CEO described the event as an abrupt, uncoordinated wind-down; reporting put the customer base at about 500.

Recovery lesson

Zero notice leaves only the recovery materials and procedures already held outside the vendor.

Immediate

Customer shutdown notice

Acquisition Shock2024–2025

OnTheMarket Software Closure

OnTheMarket Software / CoStar

After CoStar acquired OnTheMarket, a strategic review led to the software division closing on 30 June 2025. Lettings agencies received notice and support through the transition period.

Recovery lesson

Notice helps, but complex migrations still require accessible data, documentation and tested transition plans.

30 Jun 2025

Service closure date

Faulty UpdateAugust 2025

Microsoft August 2025 Update Issues

Microsoft Windows

Microsoft documented NDI streaming degradation and an enterprise WSUS installation issue following the August 2025 update. The scope was narrower than CrowdStrike, but the event still showed how shared platform updates can impair business services.

Recovery lesson

Tested rollback and application recovery plans constrain the blast radius of platform changes.

2 issues

Documented enterprise update problems

IndiaMarch 2020

Yes Bank Moratorium

Yes Bank financial infrastructure

A government moratorium capped withdrawals at ₹50,000 per depositor while a reconstruction plan was developed. It is a provider-continuity case rather than a software-vendor outage, showing how external intervention can make critical financial infrastructure temporarily unavailable.

Recovery lesson

Continuity planning must include provider-failure and external-intervention scenarios.

₹50,000

Temporary withdrawal cap per depositor

THE RECOVERY GAP

Protection is not the same as proof

A legal agreement defines rights. A backup preserves data. A source-code deposit preserves materials. None alone proves a critical application can be rebuilt and operated without the vendor.

WHAT ORGANISATIONS HAD

Protection on paper

  • A legal agreement
  • A data backup
  • A source-code deposit

WHAT REMAINED UNTESTED

The operating procedure

  • Independent rebuild
  • Clean-environment deployment
  • Evidence the board could examine

WHAT CASTLER PRODUCES

Signed Proof of Recovery

  • Per critical vendor
  • Per release
  • Reviewed and signed

THE MACRO PICTURE

Vendor change and disruption are accelerating

These measures describe different risks, but each increases pressure on continuity plans that depend on third-party software.

714

Software M&A transactions in Q1 2025 — up 36% YoY

Kroll

$4.44M

Global average cost of a data breach in 2025

IBM

Every acquisition can change pricing, packaging or support. Every insolvency can compress a planned migration into days. Every faulty update tests whether the recovery procedure exists outside the incident room. The response is not a stronger promise. It is current, independently tested recovery evidence.

FAQ

Questions about incidents and recovery

Do these incidents prove source-code escrow is enough?+

No. A deposit preserves access to materials; it does not prove the release can be rebuilt and operated. Verification must test the procedure, record exceptions and produce evidence for the exact release examined.

What is the difference between a backup and Proof of Recovery?+

A backup copies data. A Proof of Recovery documents that a specific application release was rebuilt, deployed and operated in a clean environment without the vendor present.

Would Proof of Recovery have prevented the CrowdStrike outage?+

No. It would not prevent a faulty update. It can give teams a tested application recovery procedure and evidence of what can be restored independently when a shared platform fails.

What did the Synapse collapse expose?+

It showed how difficult reconciliation becomes when software, ledgers and operating knowledge cannot be independently reconstructed across banks, middleware and customer-facing fintechs.

How does the VMware case relate to recoverability?+

Acquisition does not destroy software, but it can change pricing, packaging and support. Portability, current deposits and tested operating procedures improve an organisation's options.

PROOF OF RECOVERY

Build the procedure before the incident

Castler verifies each critical release and produces signed recovery evidence your board, auditor or regulator can examine.

Book a 15-min briefing
ISO 27001SOC 2 Type IIPCI DSS

No spam · Reply within one business day