Preventing Another Wannacry

It’s been a year since the WannaCry ransomware variant crippled the UK’s National Health Service (NHS), but that was just the tip of the iceberg, the attack is said to have hit more than 300,000 computers in 150 nations.

Those who orchestrated the chaos weren’t targeting the NHS per se; rather, the healthcare service became victims of the ‘unsophisticated’ attack due to its lack of ‘basic IT security’. With surgeries cancelled, ambulances diverted and countless appointments postponed, a lot of damage was done, with a lot more unsubstantiated damage on top of it.

All of this could’ve been easily prevented had the NHS followed simple cybersecurity measures, it’s not beyond the realms of possibility that a single consultation with an ethical hacker could have exposed the vulnerability before it spread far and wide.

The Healthcare Risks
With stretched budgets, IT teams are too often short on the resource required to conduct manual patching. So, it doesn’t take long for hardware to become increasingly outdated, software to become increasingly unstable and IT training to be left by the wayside. The result is an environment where basic security practices are being forgotten.

It’s not just healthcare that is experiencing this, but it is the sector where the consequences are most life threatening. 
This lack of IT security awareness is in stark contrast with the number of technological advances we’ve witnessed in healthcare in recent years. For instance, there’s been a gradual increase in the number of connected medical devices being used.

Internet of Things-enabled trackers are making patient care easier for patients and doctors alike. However, they’re also making life easier for hackers with more entry points to exploit. Added to that, there’s been a recent trend for medical practitioners to share patient data via channels such as a Facebook, WhatsApp and even Snapchat channels that can be compromised by hackers with the right techniques. 

This is worrying news for a sector that handles some of our most private information. The price of a breach is high for medical practitioners. In fact, it’s one of the highest because of the sector’s highly regulated nature.

Figures from Ponemon Institute’s 2017 Cost of Data Breach Study ranks healthcare as the top industry when it comes to the cost of data breach per capita. Whereas the global average per capita cost of a data breach is $141, this figure rises to $380 for healthcare firms.

Prevention is Better than Cure
It’s a no-brainer that prevention is better than cure. It costs more to recover from a hack than to proactively prevent it from happening. This is both from a financial standpoint (where stolen medical records can be held at ransom) and a productivity point of view - it’s much more stressful to recover from a hack than to work at maintaining security on a day-to-day basis.  
Businesses should take a holistic approach to limiting their exposure and vulnerabilities in terms of network security. This includes ensuring all operating systems and virus definitions are kept up to date.

WannaCry made use of the EternalBlue exploit, which Microsoft patched on March 14th 2017. Note the time difference between the patch and the attack. All IT administrators want to make sure their machines are being updated, be it manually or automatically, with little delay.

The bigger challenge is that the process of patching has barely changed since 1995, meaning there can be extensive downtime for large organisations with complex networks. This leads to patching not taking place as quickly or as often as it should.

The solution lies in the industry and vendors looking at alternative methods which kill off bad processes and patch in an ongoing synchronous manner rather the current a-synchronic process involving a download to allow the patch to run and reboot machines.

It’s also important to have in place effective disaster recovery techniques such as keeping critical data backed up in a separate location, segregating data and the principle of least privilege. WannaCry operated by scrambling computer data and demanding payment of $300-$600 to restore access. If you have your data backed up, there’ll be no need for you to pay up.
WannaCry was a self-replicating virus, meaning it managed to quickly spread itself across connected computers. Storing backups in an isolated location would’ve prevented backup data from being encrypted as well. 

Next-Steps
The issue of cybersecurity goes beyond healthcare. According to the Department for Digital, Culture, Media and Sport’s Cyber Security Breaches Survey 2018, around 43% of UK businesses have experienced a cybersecurity breach in the past 12 months. 

A one-size approach will not suit all. Security processes must match the nature of your organisation. There is a need to expect the unexpected, as no one knows when the next attack will be. But you can be prepared as vulnerabilities are published regularly and WannaCry was a known problem for several months. 

This underlines the need to stay updated, be proactive with IT security and continue to learn from mistakes. It’s not a fail-safe strategy, but it is your best bet in deferring unwanted hackers. 

Infosecurity Magazine

You Might Also Read:

British Healthcare System Spends £150m Extra On Cybersecurity:

Re-Thinking The Threat Of Ransomware:

 

« An Iranian Hacker Confesses
Insurers Are Not Ready For IoT »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

HDI

HDI

HDI is the worldwide professional association and certification body for the technical service and support industry.

Computer Laboratory - University of Cambridge

Computer Laboratory - University of Cambridge

Computer security has been among the Laboratory’s research interests for many years, along with related topics such as cryptology

International Federation of Robotics (IFR)

International Federation of Robotics (IFR)

The International Federation of Robotics connects the world of robotics around the globe. Our members come from the robotics industry, industry associations and research & development institutes.

Tata Consultancy Services

Tata Consultancy Services

Tata Consultancy Services is a global leader in IT services, consulting & business solutions including cyber security.

Adzuna

Adzuna

Adzuna is a search engine for job ads used by over 10 million visitors per month that aims to list every job everywhere, including thousands of vacancies in Cybersecurity.

Tetrad Digital Integrity (TDI)

Tetrad Digital Integrity (TDI)

TDI is a world-class consulting firm offering cybersecurity services to government agencies and commercial clients around the world.

Outsource Group

Outsource Group

Outsource Group is an award winning Cyber Security and IT Managed Services group working with a range of SME/Enterprise customers across the UK, Ireland and internationally.

Def-Logix

Def-Logix

Def-Logix was founded in 2008 to help solve cyber threats being experienced by government agencies of the United States.

Extreme Networks

Extreme Networks

Since 1996, Extreme has been pushing the boundaries of networking technology, driven by a vision of making it simpler and faster as well as more agile and secure.

Verichains

Verichains

Verichains Lab is a pioneer and leading APAC blockchain security firm with extensive expertise in the areas of security, cryptography and core blockchain technology.

Europol - European Cybercrime Centre (EC3)

Europol - European Cybercrime Centre (EC3)

The European Cybercrime Centre (EC3) was set up by Europol to strengthen the law enforcement response to cybercrime in the EU.

Northdoor

Northdoor

Northdoor provides a comprehensive set of services around information security and works with leading global technology vendors to deploy and manage cyber security solutions.

Nullify

Nullify

Nullify is your automated security sentry that continuously finds and fixes security issues across your codebase.

Nortal

Nortal

Nortal is a strategic digital transformation partner for leading companies and governments around the world.

Auxilion

Auxilion

Auxilion is an award-winning provider of consulting and IT support services, technologies and consulting for public and private organisations in the UK and Ireland.

Twine Security

Twine Security

Twine is pioneering the creation of AI digital cybersecurity employees to help improve efficiency for cybersecurity teams.