Every crisis leaves lessons behind.
In our monthly Crisis Series, Phoenix Resilience examines real-world events and the decisions that influenced their outcomes.
This month we are talking about Technological Crises.
The Crisis Series: Technological
October 1, 2026
In our never-ending pursuit for efficiency, we have embedded technology in every aspect of our lives and work. Critical infrastructure is becoming increasingly automated, while supply chains depend on software that spans multiple countries and thousands of organisations. Every advance creates new opportunities and vulnerabilities.
As systems become more advanced, they also become more inter-connected and specialised, meaning a single issue can result in a cascading series of failures. When these breakdowns occur, the consequences can result in unavailability of essential services, communication disruptions and even deaths.
What do we mean by technological crisis?
A technological crisis is a failure in complex technical systems that causes harm to people, widespread disruption and flow on environmental, financial, legal, and/or reputational consequences. It occurs when tightly coupled or complex technological infrastructure break down as a consequence of human design, implementation, or management errors, or malicious intent.
In this article, we look at three major examples of technological crisis across history: the 1986 Chernobyl disaster, the 2024 CrowdStrike IT outage and the 2025/2026 Australian telecommunications outages.
We explore opportunities to prevent crises from occurring and, in the unfortunate event that they do, respond effectively.
Chernobyl Disaster (1986)
What happened:
On the night of 26 April 1986, a safety test became one of history’s worst industrial disasters.
Operators were testing if a turbine could keep emergency cooling pumps running during a blackout.
To do this test, operators disabled critical automatic power-regulating and emergency safety systems while running the reactor at an unstable, very low power level.
When operators pressed the emergency shutdown button (SCRAM), the control rods were inserted.
However, these rods had graphite tips. Instead of slowing the reaction immediately, the graphite tips caused a massive, instantaneous power spike that cracked the core, melted the fuel, and triggered a steam explosion.
Consequences:
The blast tore the roof from the reactor building and released enormous quantities of radioactive material across Europe and beyond (radioactive material was detected as far as Canada).
More than 100,000 people were forced to leave their homes and many never returned, leaving entire towns empty.
This crisis happened as a result of known critical engineering vulnerabilities, ongoing safety management failures and poorly planned/executed tests.
The delays and mishandling of the crisis response exacerbated the disaster.
Crowdstrike Global IT Outage (2024)
What happened:
The CrowdStrike outage of July 2024 saw millions of computers struck with the “blue screen of death.”
CrowdStrike’s Falcon Sensor security software (CSagent.sys) runs with deep, trusted privileges inside the Windows operating system kernel to monitor system activities and block threats. In the late hours of 24 July 2024, the American cybersecurity company deployed a faulty software update and all Windows computers that received it were sent into recovery mode or a boot loop. The outage’s impact was exacerbated by concurrent issues with Microsoft’s Azure platform.
Consequences:
Airports and ports struggled to operate. Airlines cancelled thousands of flights. Hospitals delayed appointments and procedures. Banks, retailers and government agencies suddenly found themselves unable to carry out routine operations.
Modern businesses increasingly rely on the same cloud services, operating systems and software vendors. This creates extraordinary efficiencies during normal operations, but also builds extraordinary vulnerabilities and single point sensitivities. CrowdStrike was just one company’s mistake but it spread throughout organisations across almost every continent.
When one widely used platform experiences problems, it doesn’t take long to get out of control. The CrowdStrike outage became one of the clearest demonstrations that a simple mistake can cause global disruption and is made worse by ever-decreasing societal and organisational resilience.
Few people carry or even possess cash, spare medication, food and essential supplies. The same goes for organisations. Most do not have adequate and sustainable workarounds for their critical dependencies, such as Microsoft365, AWS and other essential systems.
Optus & Telstra Communications Outages (2025/2026)
Two major incidents demonstrate how easily situations can develop.
What happened:
On 18 September 2025, Optus bungled a routine firewall upgrade resulting in a 13-hour period in which emergency calls were blocked. Out of 605 Triple Zero (000) calls attempted during the failure window, 75% failed to connect, leaving roughly 455 callers stranded without an immediate connection to emergency services. The failure was linked to at least two confirmed deaths (initial reports suggested up to four).
The incident duration was drawn out when several customer reports were not properly investigated or escalated. It wasn’t until South Australian Police raised concerns and the upgrade was stopped. This delay in detection, escalation, notification and warning significantly increased the community, legal, financial and reputational consequences of this event.
On 8 July 2026, a major nationwide Telstra network outage occurred. It began at 2:50 am after workers replaced a faulty network power supply at a primary exchange in Melbourne. When the new hardware booted up, an unpatched software bug on a GPS timing card reset the server’s network clock back to 2006.
Consequences:
The incident caused massive nationwide disruption, crippled transport networks, knocked out EFTPOS payment systems, and crucially, blocked more than 600 emergency 000 calls from connecting.
Common Themes in Technological Crises
The underlying issue is often a design, infrastructure or process failure.
Subsequently, the failure is not detected in time due to inadequate monitoring or faulty governance programs.
Once a disruption eventuates, common causes for escalation include:
- Delays in notification or warning
- Insufficient clarity on response coordination or communication arrangements between agencies
- Inadequate or untested processes and guidance in place
Mitigating a Technological Crisis
It’s impossible to prevent every outage or incident or that failures won’t compound. However, it is possible to mitigate disruption, adapt quickly or keep functioning when a technological crisis occurs.
Preparing for technological crises begins with accepting an uncomfortable reality: every critical system can fail and due to their design, complex and connected systems can result in cascading failures.
Below are technological crises causes and their relevant mitigation strategies:
Cause: Design, infrastructure or process failure
- Have methods in place for regular review of processes, infrastructure design
- Have a culture where people can speak up and raise any concerns
- Organise discussion exercises where multiple stakeholders reflect on vulnerabilities
- Be clear on what your Prioritised Activities are and subsequently, what their dependencies are (Business Impact Analysis ISO 22317)
- Ask yourself constantly, what do we do if..?
- Implement adequately resourced and practiced redundancies and workarounds
- Enable easy access to alternate suppliers, including telecommunications providers.
- Have the ability to operate manually when Operational Technology is affected
Cause: Delayed detection
- Use technology to enhance the ability to detect issues
- Have a 24/7 monitoring capability
- Have methods, tools and technology to actively screen for threats
- Implement clear escalation pathways when a detection occurs
Cause: Response failures
- Be clear on who tells who when an issue is detected
- Ensure that the right people are told within the right timeframe; every delay can increase the consequences
- Have clarity on roles and responsibilities and how each agency will work together.
- Have pre-developed holding statements and a well-practiced and resourced communication plan to manage ingoing communication.
The Next Failure
The next major technological crisis might not look like Chernobyl or CrowdStrike. It is looking more likely the next crisis will be AI-related. We are handing over considerable decision-making power to AI and store all our data in data centres. This may be to our detriment.
Next month, we will cover the influence of AI in crisis management.
© Phoenix Resilience 2026
More Articles From Phoenix Resilience