In January 2016 we wrote a blog post highlighting the lack of Continuous Development in Business Infrastructure , this was prompted by our experiences of going into organisations and finding unsupported, out of date servers and Operating Systems acting as the main backbone of the organisation! When an organisation has such a lack of understanding of the risks of servers, software’s and OS’s being unpatched for up to 7 years, this really highlights the failure at Executive level to understand the potential disaster it can deliver to any organisation. We were even more frustrated to learn that these same companies had been able to pass the government’s own Cyber Security Certification and pass ISO 27*** accreditations and the enormity of the knowledge gaps in the U.K.’s current crop of Cyber “experts” and practices we have in place suddenly took on new meaning.
And so last week the ransomware WannaCry took advantage of a so called vulnerability in Microsoft Windows. Now, it is simple to blame Microsoft, but the blame actually sits with individual organisations and their own Cyber Hygiene processes. This attack was absolutely avoidable, Microsoft released a security patch for the vulnerabilities in March. But many organisations don’t automatically update their systems because Windows updates can cause issues with their legacy software programs. The phenomenon of companies failing to update their systems has been a persistent security problem for years. Playing with fire finally caught up with these organisations.
Who is vulnerable
Anyone who hasn’t updated their Windows PC recently.
Microsoft said it had taken the “highly unusual step” of releasing a patch for computers running older operating systems including Windows XP, Windows 8 and Windows Server 2003. So even people with older computers should update them and then thank Microsoft for some excellent Customer Service.
How to prevent being attacked
1. Disable your computer’s Server Message Block service.
2. Install Microsoft’s patch.
3. Back up your data on an offline hard drive such as our own linux based InstaCloud
4. Install all Windows updates.
5. Use a reputable security software to prevent attacks in the future.
For more details on how to stay safe click here!
The fact that so many computers remained vulnerable two months after the release of a patch illustrates this aspect. As cybercriminals become more sophisticated, there is simply no way for customers to protect themselves against threats unless they update their systems. Otherwise, they’re literally fighting the problems of the present with tools from the past. This attack is a powerful reminder that information technology basics like keeping computers current and patched are a high responsibility for everyone, and it’s something every top executive should support.
It really is the week that every organisation should dust off their risk register and take a look on whether this is a working document or a tick boxing exercise, if failing to patch and legacy systems are not highlighted and red flagged then your answer is clear.
For more information on Ransomeware please visit our blog posts !
2017 Malware Threats are here: Ransomworm Is Waking, Are You Ready?
If you are running Windows Servers the Insta Digital Team highly recommend the following: https://fsrm.experiant.ca/







