Risk register · entry
Q3 · EngineeredWannaCry ransomware attack
The fix shipped in March. In May the worm took 150 countries, on the machines nobody patched.
Tightly coupled systems where one small fault cascades and takes down the whole machine.
Why this quadrant
EternalBlue let the worm move between machines with nobody clicking anything, so one unpatched box inside a flat network was enough to take an entire estate down. Microsoft had shipped the patch 59 days earlier. At least 80 of 236 NHS trusts were infected or shut down as a precaution, and around 19,494 appointments were cancelled. What stopped it was not a designed control but a kill-switch domain a researcher registered on the first evening.
The record
- Microsoft published security bulletin MS17-010, rated Critical, on 14 March 2017; WannaCry was released worldwide on 12 May 2017, 59 days later.certain
- WannaCry affected at least 80 of the 236 NHS trusts in England, either through infection or precautionary shutdown, plus 603 further primary care and other NHS organisations including 595 GP practices.certain
- NHS England identified 6,912 cancelled appointments and estimated that around 19,494 appointments were cancelled in total; five accident and emergency departments were unable to treat some patients and diverted them elsewhere.certain
- Before the attack NHS Digital had carried out on-site cyber-security assessments at 88 of the 236 trusts and none had passed; NHS Digital had issued critical alerts in March and April 2017 telling organisations to patch.certain
- The widely-quoted USD 4 billion total loss is an estimate by the private cyber-risk modelling firm Cyence; other assessments put losses in the hundreds of millions. Europol estimated around 200,000 computers infected across 150 countries.medium
Sources
The newsletter
One risk story a week, taken apart the way this one was: what was known, what was ignored, and which quadrant it really belonged to.
No spam, one email a week.