Tag Archives: Anti-Virus

The “NHS” Attack

15 May

The poor and inaccurate reporting of the NHS Ransomware incident over the weekend has irked CyberMatters into coming out of hibernation. With so much to say, it’s hard to know where to start.

WannaCrypt ransomware demand

Not targeted

First the NHS was not targeted by a Cyber Attack. The attack affected ANY system that was vulnerable; the sad fact is the NHS was vulnerable, as were many other global organisations thus the attack was able to succeed.

By Friday evening, and over the weekend, the media were taking interviews from various industry ‘experts’. Sadly, too many were using the opportunity to push their latest and greatest product feature that would provide protection. Let’s be clear, if any product supplier says their product would have prevented the incident, their comment should be taken with a pinch of salt. THERE IS NO MAGIC BULLET PROTECTION. (However, there were also some very good reports from proper experts).

Defence in Depth

A solution requires an organisation has a defence in depth strategy, as long promoted in this blog.

Protection measures are needed on all interfaces that can bring malware into the IT systems – email, web sites, CD & Memory sticks etc. These need to have multiple layers – e.g., both boundary and end point protection, and multi-faceted – e.g., anti-virus, sandboxing, limited user rights and advanced verification techniques.

A defence in depth strategy will then assume these measures have failed, and provide mitigations to prevent the spread. These typically include patching and network segmentation.

The next layer will then assume these have failed, and provide monitoring mechanisms to look for suspicious network behaviour, such as unusual network traffic.

If these protect and detect measures fail, you then need to enact pre-planned response measures.

The NHS scenario

NHS logo.pngIt is too early to tell, but it is my belief the NHS was so badly hit, as their defence in depth strategies were not effective.

Boundary protection systems let the malware in (and to be fair, this is likely in most organisations, unless excellent user training and advanced data verification tools are used), the lack of patching allowed the malware to spread.

Then, due to the lack of segmentation, the only response mechanisms were to shut all systems down until a more detailed assessment could be made.

Cyber Essentials

My first reaction on hearing of the way the malware was spreading is this would be a good advert for Cyber Essentials. To this end, I thought Amber Rudd, Home Secretary, presumably briefed by Ciaran Martin, head of NCSC, missed an opportunity to promote implementing Cyber Essentials as immunisation. But her detailed words reveal why…

She said there were three key mitigations, patching, anti-virus and backups. Cyber Essentials is a prevent strategy, and does not include the prepare element of backups. Maybe a lesson learnt that should feed into a revision of Cyber Essentials?

What went well?

Part of the NSCS’s £1.9bn is spent on the Cyber Information Sharing Partnership (CiSP) which incorporates information from the UK Computer Emergency Response Team. By 3pm, the incident was being discussed by experts, and by 4pm the relevant Microsoft patch identified. If you are not part of CiSP, I recommend including consulting CiSP as part of your incident response plans.

The NCSC were also quick to publish specific mitigation advice on gov.uk by Sunday.

Windows XP

Much of the press debate has centred on unpatched Windows XP systems. Irrespective of the rights or wrongs of Microsoft not providing updates, this issue has been known for a long time. For example, government departments running Windows XP would not be allowed to connect to the government public sector network, forcing departments to resolve the issue.

The NHS ‘defence’ is legacy applications do not work on newer Windows systems. Again, whether that is the full truth matters not. If you know this risk exists, then you MUST deploy defence in depth, and most importantly segmentation and isolation strategies to manage the risk.

Nexor – how did we react?

We became aware of the issue, via open source monitoring mid-afternoon on Friday. We convened an ad-hoc security incident response meeting, consulted CiSP to determine the nature of the issue, from where we were able to establish the March Microsoft patch provided immunity. Cyber Essentials demands we roll out the patches quickly, so we could be confident the immunity would be effective, but decided to double check our patch management records in any case. By 5pm we concluded we were OK this time.

Who to trust?

One of the hard parts of all this, is knowing who to trust. Who is given an accurate and balanced story, versus plugging a corporate position. This is hard to answer. The best I can come up with at the moment is other than word-of-mouth / reputation, check the person giving advice on the Trusted Security Advisors Register – not perfect, but the closest we have right now.

How can firms protect themselves from ransomware?

5 Oct

In a previous blog post I wrote about the rise of ransomware over the last year. In this post I will briefly outline what steps organisations should take to avoid becoming the next victim of ransomware. Continue reading

Top cyber crime threats to East Midlands businesses

20 Sep

I recently attended the East Midlands Cyber Crime Breakfast, where a panel of experts outlined what they saw as the principal cyber crime threats that were affecting organisations in the East Midlands. Continue reading

To Stop Data Theft, Disconnect From The Internet?

13 Jan

At the back end of 2014, Forbes published a great article “To Stop Data Theft, Let’s Start Disconnecting Computers From The Internet

The last paragraph says:

Some corporate and government data simply doesn’t belong on the Internet. Why is that so hard to understand?

A good question indeed. 
Continue reading

Validating the Payload

10 Nov

In the blog Secure Delivery of a Payload we discussed how secure information exchange consists of two distinct elements: the information you need to convey – the payload, and the technical method used to carry the payload – the protocol. Attackers wishing to break into your network can exploit either of these: the protocol or the payload.
Continue reading

Why have I got an Intruder Alarm?

28 Oct

At home, I have invested in good quality locks on my doors and windows, conforming to the standard required by my insurance company. In addition to that I have also invested in an intruder alarm.

Continue reading

Is there any point in using anti-virus software?

18 Aug

I recently attended a professional development event in Birmingham run by OWASP and the Institute of Information Professionals (IISP). One of the topics on the agenda was how to evade anti-virus (AV) software packages.

Shock horror. The breaking news is that AV software is not going to stop cyber attacks on your organisation, as has been blogged on before here on Cyber Matters.

However two aspects stood out for me.

Continue reading

Cyber Street Awareness Videos

3 Jul

Maybe I am slow on the uptake, but I have only just come across these 30-second YouTube videos hidden away on Cyber Street.

My favourite is this one…

Continue reading

IISP East Midlands: BIS Organisational Standards

1 Feb

On January 29, we held the second IISP meeting in the East Midlands, at the Institute of Directors in Nottingham, attended by close to 30 delegates.
The meeting was opened by Colin Powers with an introduction and explanation that some quick reshuffling of the agenda was in order as the main speakers train was running late. He also published the hash-tag #IISPEastMids, with delegates encouraged share their thoughts on the meeting live via twitter (these tweets are available as an archive).
Continue reading

Security Predictions

23 Dec

At this time of year, it seems that one of the duties of a CTO of a security company to make predictions about the year ahead.
My prediction is somewhat generic, followed by a wish list. Please help me with my wish list, so we can prevent my prediction!

Continue reading