UK's NHS Could Have Avoided WannaCry Hack With 'Basic IT Security', Says Report (theguardian.com)
An anonymous reader shares a report: The NHS could have avoided the crippling effects of the "relatively unsophisticated" WannaCry ransomware outbreak in May with "basic IT security," according to an independent investigation into the cyber-attack. The National Audit Office (NAO) said that 19,500 medical appointments were cancelled, computers at 600 GP surgeries were locked and five hospitals had to divert ambulances elsewhere. "The WannaCry cyber-attack had potentially serious implications for the NHS and its ability to provide care to patients," said Amyas Morse, the head of the NAO. "It was a relatively unsophisticated attack and could have been prevented by the NHS following basic IT security best practice. There are more sophisticated cyber-threats out there than WannaCry so the Department and the NHS need to get their act together to ensure the NHS is better protected against future attacks."
The problem is there are a lot of things under basic IT security and it is nearly impossible to checklist them all.
Health Care tends to be at least a decade behind in technology and implementing new technology is a big deal, because breaking a downstream system, could cost someones life. So there is nearly always a big queue of things that should be done that you just can't get business approval to do.
If something is so important that you feel the need to post it on the internet... It probably isn't that important.
I wonder who got paid ££££ to come to THAT conclusion
Time for bed, said Zebedee - boing
I know it is fashionable to bust on MS -- always has been here. I will say that from a security standpoint (if not a privacy standpoint, which is related but not the same), they have gotten better. That aside, the fact remains that if you don't do the first 5 of the CIS critical security controls, doing the remaining 15 doesn't really matter.
https://www.cisecurity.org/con...
Of course throwing blinkin-light boxes, doing pen tests, etc. is all the "sexy" parts of security, but here's the deal -- MS patched the vuln over a month before WannaCry hit and the crisis could have been averted by asset control and patch management before any signatures were released either for the vulnerability itself, or for specific threats such as WannaCry.
Within a day of ShadowBrokers dumping the haul which contained EternalBlue, nearly everyone in the security field that was paying attention understood that a patch already existed, MS had released it without fanfare as they usually do for this sort of thing, and that due to lack of attribution in the release notes that it was almost certainly NSA working on it with MS once they had reason to believe that EternalBlue was taken and would be burned by SB.
So, yeah "Don't use Microsoft" -- but if you go around not patching RedHat, you're not actually going to be that much better off. Unpatched software is still unpatched software, email has the quality of turning local exploits into remote exploits, and office workers whom you stick on an Ubuntu or RedHat box are still going to click whatever they're going to click. DAC and the Unix permissions model only goes so far, and most sites I've worked at have a tendency to have a "disable SELinux because it's hard and we're lazy" item in their deployment guide.
No one thing is the end-all/be-all of security. Layered defense and understanding that it is a constant arms race wherein blue team isn't likely to prevent a dedicated adversary from gaining a foothold but needs to do what is possible to increase the cost of success and extend operational time for the attacker to increase the likelihood of detection before exfiltration or destruction of data is it.
Dental outcomes, however, do not bear this out.
> it seems like the only government-run places where you'll see even halfway decently managed IT is in agencies that handle state secrets relating to subjects like defense and diplomacy.
You might be surprised at the crap you see at those agencies too. "Defense and diplomacy" you say, so for example the State Department. Can you imagine if the top-level head of the State Department, the Secretary of State, was handling "subjects like defense and diplomacy" by using an out-of-date, unpatched mail server set up in her house by some idiot whose education in the field consisted of asking basic questions on Reddit, a guy who apparently couldn't even be bothered to read the manual? Yeah, that's the IT security we get for " state secrets relating to subjects like defense and diplomacy".
doctors independent contractors / own offices have to do there own IT. Other times they are stuck on old apps that may need ADMIN rights and even only run in windows XP.
This wasn't the case though. The majority of infections were in unpatched Win7 machines. And for the specific issue one of the major reasons for NOT patching was the need to communication with SMB1 servers. Most frequently these server run Linux.
Probably the larger problem is that this is indicative of the type of problem that we will start to see with nationalized health care
Way to politicize the issue. In the most unproductive manner possible.
Americans hospitals were affected by ransomware outbreaks too. We didn't hear much about it because they are private organizations that don't need to report to the public. If you think IT in American health care is much better then NHS, I have some very bad news for you. Health care IT security was a joke until the government stepped in.
There was some improvement in the wake of HIPAA, but even now it is hit-and-miss. As it stands, government is the sole reason for the existence of any meaningful security. Hopefully, some massive HIPAA fines will straighten out the slackers.
we continue down this dangerous, dangerous road
We're already on the dangerous road. US health care has been ranked behind most European nations for over a decade.
Maybe a billionaire can fly in and get better service in the US, but overall we're behind. This isn't true for regular people like you and me---people who have jobs and need that salary to live. We are not better off with the current system.
And don't even go into Obamacare, because we're behind the curve with or without it. It was too little of a change to do much, in spite of the political shouting match it provoked.
---
According to the latest ruleset, this post should be modded as Vorpal Flamebait +5.
Samba 3.6 added basic support for SMB2.0. This support was essentially complete except for one big item:
durable file handles (Added in Samba 4.0.0).
Release Notes for Samba 3.6.0
August 9, 2011
So more unpatched software is what you are saying?
Which leads ultimately to outsourcing and service based view on the IT. If the business experts don't understand accounting, physical security, cleaning or legal services, they buy those from the providers as well. Then they can fulfill any compliance requirements to the monitoring authorities or courts, whatever they might be.
It doesn't solve the fundamental problem, which is that a lot of medical software is sold with some very specific system requirements and they're not certified to work on anything else. Part of it is that the liability is huge, part of it is that the vendors know they got the clients over a barrel. So you got a hodgepodge of outdated and obsolete configurations and it's not like a hospital will shut down a million dollar MRI machine or operating theater equipment simply because the OS is out of support or only supports SMBv1. You can red-flag it in a compliance report but unless there's actually money in the budget for a replacement system it's just CYA documentation. Worse yet if the product is EOL or the vendor has quit or if the new system is such a big change it's not really an upgrade anymore.
Microsoft actually used to be best in class here with their 5+5 support on client desktops. With their new "life of device" who knows, as vendors tend to not give a shit when the warranty has expired. But I think there will be a demand for like really long term support, I mean XP lived for well over 10 years and Win7 is still king of the hill, if only you got security patches I think many could run the same OS for decades. Particularly in a business context where you might only run a few vertically integrated applications and the OS is almost invisible.
Live today, because you never know what tomorrow brings