UK government woefully unprepared for 'catastrophic' ransomware attack
- Reference: 1702540927
- News link: https://www.theregister.co.uk/2023/12/14/uk_jcnss_ransomware_report/
- Source link:
The Parliamentary select committee reached this conclusion in a scathing [1]report released December 13 that accused the government of failing to take ransomware seriously, and of providing "next-to-no support" to victims of ransomware attacks.
"There is a high risk that the government will face a catastrophic ransomware attack at any moment, and that its planning will be found lacking," the report concluded. "There will be no excuse for this approach when a major crisis occurs, and it will rightly be seen as a strategic failure."
[2]
Recent examples of ransomware infections at UK government institutions and critical private infrastructure are not hard to find.
[3]
[4]
[5]Manchester Police , [6]Royal Mail and the [7]British Library have all fallen victim to ransomware attacks since September 2023.
In July 2023, the Barts Health NHS Trust hospital group was [8]hit by the BlackCat ransomware gang. The NHS had already been taught a lesson about the vicious power of ransomware in 2017 when multiple Brit hospitals stopped taking new patients, other than in emergencies, after being [9]hobbled by WannaCry.
[10]
Third-party providers of NHS software systems have been hit as well, taking systems offline and forcing care providers to [11]revert to pen and paper .
In short, the situation with ransomware in the UK is already bad, and the JCNSS has predicted things will likely get worse.
"The UK has the dubious distinction of being one of the world's most cyber-attacked nations, lamented Dame Margaret Beckett, JCNSS chair. "The Government's investment in and response to this threat are not equally world-beating."
The Home Office, meanwhile, is busy chasing boats
The report calls out the Home Office and former home secretary Suella Braverman for "showing no interest" in ransomware, instead giving "clear political priority … to other issues, such as illegal migration and small boats."
Illegal migration is undoubtedly a significant policy challenge, the JCNSS concedes, "but there is a risk that ransomware is relentlessly deprioritized."
[12]Ransomware attacks register record speeds thanks to success of infosec industry
[13]US officials close to persuading allies to not pay off ransomware crooks
[14]Ransomware more efficient than ever, and baddies are still after your logs
[15]BYOD should stand for bring your own disaster, according to Microsoft ransomware data
One of the primary recommendations made by the JCNSS report is to reassign responsibility for ransomware from the Home Office to the Cabinet Office where it can be overseen by the deputy prime minister in partnership with the National Cyber Security Centre and National Crime Agency.
A new regulatory framework for addressing cyber crime is also needed, the report suggests, as the UK’s Computer Misuse Act (CMA) was introduced before the arrival of the internet.
[16]
Some of the other 27 recommendations in the report include setting up a central reporting mechanism for ransomware, and determining whether UK organizations should have an obligation to report ransomware attacks. Increased funding the NCSC and NCA to help victims negotiate with ransomware actors, recover and remediate future threats, is another recommendation.
Even King Charles gets a mention – and criticism for failing to mention CMA reform in his (government written) [17]speech at November's opening of Parliament.
"If the UK is to avoid being held hostage to fortune, it is vital that ransomware becomes a more pressing political priority, and that more resources are devoted to tackling this pernicious threat to the UK's national security," Beckett warned. ®
Get our [18]Tech Resources
[1] https://committees.parliament.uk/work/7017/ransomware/news/198995/a-hostage-to-fortune-ransomware-and-uk-national-security/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZXrgV3@9QQDde10zCjx8egAAAEA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXrgV3@9QQDde10zCjx8egAAAEA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXrgV3@9QQDde10zCjx8egAAAEA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2023/09/15/greater_manchester_police_breach_demonstrates/
[6] https://www.theregister.com/2023/11/16/royal_mail_recovery_from_ransomware/
[7] https://www.theregister.com/2023/11/20/rhysida_claims_british_library_ransomware/
[8] https://www.theregister.com/2023/07/11/barts_blackcat_theft/
[9] https://www.theregister.com/2018/02/02/nhs_wannacry_post_mortem/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXrgV3@9QQDde10zCjx8egAAAEA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2022/10/14/nhs_software_hosting_provider_advanced_ransomware_lockbit/
[12] https://www.theregister.com/2023/10/10/ransomware_attacks_register_record_speeds/
[13] https://www.theregister.com/2023/10/31/us_ransomware_payment_ban/
[14] https://www.theregister.com/2023/11/15/ransomware_more_efficient_than_ever/
[15] https://www.theregister.com/2023/10/05/microsoft_byod_ransomware/
[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXrgV3@9QQDde10zCjx8egAAAEA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[17] https://www.gov.uk/government/speeches/the-kings-speech-2023
[18] https://whitepapers.theregister.com/
Same old
A task force will be set up consisting of people with no technological knowledge whatsoever, and with meetings held in expensive venues.
Here, pie-in-the-sky statements will be formulated, over lush 'working' lunches.
Re: Same old
Where as if there was even the smallest bit of technical expertise....
User training.
Principal of least privilege.
Patching, pen testing, remediation
Functioning, tested backups and DR plans.
Can I have my £6 miilion consultancy fee now please?
Of course the old fashioned basics arent all flashy and dont have Cloud, AI or Blockchain anywhere near them but ime if you get the basics done well then youre normally winning.
Re: Same old
I assume the NCSC have the expertise and people to address this (I have never worked with them so I don't know). If so, then the proposal seems eminently sensible!
So, that's doomed then.
A quick thought experiment here - if someone were working on a political agenda of, for example, not providing these services with taxpayers' money directly, but having their friends start businesses to provide those services in exchange for lucrative consulting gigs after leaving frontline politics, then surely allowing ransomware attacks would make sense? After all, that would reinforce the narrative of "public sector bad, private sector good" that they'd be trying to push, wouldn't it?
Or am I just having a flashback to "Yes, Minister"?
'Yes, Minister' was a documentary.
Ditto 'Frontline' and 'Utopia' in Oz.
Expense
The problem is the cost and effort. Commercial organizations only have to have a single "The security of our customers' data is our highest priority" statement prepared whereas the government might need a dozen or so to cover the range of services under threat.