Time to examine the anatomy of the British Library ransomware nightmare
- Reference: 1711359010
- News link: https://www.theregister.co.uk/2024/03/25/opinion_column/
- Source link:
Hands up if you said it was burned to the ground by barbarians. That's almost entirely wrong – we'll get to that in a bit – and that's not important. What matters is we think such a thing is so tragic, so emblematic of cultural collapse, that we've told ourselves that story for nearly two thousand years.
The Rhysida ransomware attack on the British Library last October didn't have the visceral physical aspect that creates a folk memory, but it should for anyone who makes enterprise IT. Five months on, not only are significant systems not restored, they've gone forever. Remedial work and rebuilding is going to drain cash reserves intended to last seven years. It was and is bad. What makes it even more exceptional is that we now know what happened and why.
[1]
The gories are all in a [2]substantial, detailed report released by the British Library itself. It's a must-read if your life involves any risk of a 2am phone call demanding you drive to the datacenter, even more so if it's the CEO pulling up the Teams meeting in ten minutes. Truth is, it's worth much more than a read, once you realize what the report represents. To get there, let's look at what the institution actually represents.
A Magna Carta of fail
The British Library has many personalities. It has a unique, complex set of roles, which are uniquely regulated by law. Looked at another way, it is typical of national and other large institutions, in that IT infrastructure competes for resources against long-established core services, often unsuccessfully. In yet another light, that's true to some extent for all organizations. The British Library's situation is also merely a magnificent example of what can go wrong. All these perspectives are true, but the last has the widest implications.
If you have any years on you in this game, you will have first-hand experience of some of the factors identified in the report as enabling the disaster. Legacy systems too old to be safe, too expensive in time and money to replace, while more pressing needs exist. People who are asked to do too much with too little. The deadly inertia of complexity. New projects that leave older systems to wither in the shade. Security that rigorously defends against the wrong thing. The report is, as befits the institution itself, a comprehensive catalogue of important stories.
[3]
[4]
We are, as an industry, very lucky to have such a document. The reputational and commercial pressure to keep post-disaster dirty laundry out of sight leaves lessons unlearned, in general and often within the afflicted organization itself. The bigger the org, the harder the laundry.
Not here. You can call it commendable candour, or the proper response for a public service provider, it doesn't matter. The enterprise IT infrastructure industry worldwide has been given a chance to audit its own practices as they really are, and the consequences that really flow. Internal reports can be written and cases made at all levels to plan, rebuild, manage and prioritize with wisdom and awareness.
[5]
Fat chance. The best we can hope for is the recomposting of the report into endless webinars, case studies and white papers by people with something to sell. There may be decent talks at industry conferences, chapters in textbooks and Youtube videos, none of which will be seen by the top-level policymakers who are the ultimate power brokers in how an organization perceives its infrastructure responsibilities.
[6]That runaway datacenter power grab is the best news for net zero this century
[7]Space nukes: The unbelievably bad idea that's exactly that ... unbelievable
[8]The last mile's at risk in our hostile environment. Let's go the extra mile to fix it
[9]How to Netflix Oracle's blockbuster audit model
This should be a near-criminal case of mismanagement. If a report of an air accident investigation revealed anything like the scope and systemic misadventure of the British Library report, it would shake up the aviation world so hard its rivets would pop. Lacking an external regulator with teeth like the FAA or CAA, and with no taste for self-regulation, there is no engine for reform, no roadmap of responsibility.
It's not as if it doesn't matter . Nobody dies at the moment of a major failure of systemic integrity such as the British Library experienced. Yet hospitals, safety-critical services and physical infrastructure are also regularly attacked, and they share the same bad practices that are the wrong sort of industry standard. The calculus of harm from delay or diverted resources in such cases is impossible to quantify: they may not be counted, but there are always victims who relied on things not breaking, things that we let break.
In the absence of sustainable organizational sanity in how it sees IT, the British Library report can still be useful through subversion. Write that internal report drawing parallels between the evidence it contains and what's going on around you. Make it savagely to the point, keep it short, print it out, highlight the good bits with an old school yellow pen, and leave anonymous copies around the place. Slip one under the CEO's office door. Be as creatively mischievous – or not – as your corporate culture deserves. Just don't pass up the opportunity to use the power of a damned good story.
As for the [10]Library of Alexandria , it may or may not have been burned down by Julius Caesar, although it might not have been deliberate and it may have been rebuilt. What really did for it was politics and a slow strangulation through lack of resources. True terror for the ages, right there. ®
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZgFZSCHeYyCbgUbBYCa6kgAAAAk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2024/03/11/british_library_slaps_the_cloud/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZgFZSCHeYyCbgUbBYCa6kgAAAAk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZgFZSCHeYyCbgUbBYCa6kgAAAAk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZgFZSCHeYyCbgUbBYCa6kgAAAAk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2024/01/29/the_datacenter_runaway_power_grab/
[7] https://www.theregister.com/2024/02/19/opinion_column/
[8] https://www.theregister.com/2024/03/18/opinion_networks/
[9] https://www.theregister.com/2024/03/11/how_to_netflix_oracles_blockbuster/
[10] https://en.wikipedia.org/wiki/Library_of_Alexandria
[11] https://whitepapers.theregister.com/
Force of Islam
As I understand it, the Lib. of A. was finally destroyed by the forces of Islam. Who needs any other source of information when you have their particular Holy Book? Mind you, it may have suffered cuts in government expenditure long before that.
Re: Force of Islam
Or a Chriistian mob who also took time away from their busy job of destruction to maim and lynch Hypatia.
Re: Force of Islam
That's very debatable due to the amount of time between the alleged incident happening and it coming to light (1200's AD), This was alleged to have happening in 642AD. Islam was only formed in 610AD and they didn't start burning libraries till 976AD (https://en.wikipedia.org/wiki/List_of_destroyed_libraries). Another point to consider is the Rashidun Caliphate under Umar which conquered Egypt in 642AD so you then have to question was this an act in relation to the Quran or just an invading force destroying things in battle? You would have thought it would have been documented at the time in Egypt.
Re: Force of Islam
You would have thought it would have been documented at the time in Egypt.
And maybe stored in a big library?
I think you've missed a key aspect of the rail/air investigation authorities in the UK: If there is an incident you have to report it. The authority then undertake a no-blame investigation on what can be learned from the incident and make the report public.
We need more organisations being open about A) Being attacked, and B), how they were hacked.
Until we stop seeing being attacked as something to be swept under the carpet, we can't learn from them.
Over the past couple of years I've come across two attacks: One was handled by the organisation's cyber insures who said "Don't speak to a soul about this or we wash our hands of you" and the other the NCC were involved with who also said "Keep quiet".
Reason #854637
... why I got out of security.
Figleaf and scapegoat. Circumvented over and over by besuited Big 4 consultants who couldn't configure the firewall on their home network modem.
Re: Reason #854637
Who'd want to work in IT security?
Average salaries for IT security roles in the UK are pretty poor (eg Reed reckon an average of £70k in London, Indeed quote £55k). There are some better paid roles, but they tend to be few in number, although if you want to go contracting then there's some decent - and some very poor - rates on offer. My favourite was an SC cleared cyber security role for a government SOC "in Buckinghamshire", so only a few likely candidates there, and that was paying £500 a day. WTF do they think they'll get for that?
Public or private sector, you'll be ignored before there's a problem, the big wigs will be too busy with their "urgent" but not important activity, with executive awaydays, and meetings with vendors and consultancies paid far more than you will be. Good practice will be sidelined if it is inconvenient for the execs or the sales teams; In the interest of low cost, vital business functions will have been outsourced and there's neither visibility or control over them.
And when the brown stuff splatters, it'll all be your fault.
The 21/22 annual report is instructive
Had a scan of the last annual report before the incident, and although digital risks are one of the eight top risks, and there's half a page of prattle about risks governance, it's also instructive that there nothing on how much BL spend on IT, or what actions they planned or were taking to better understand or mitigate those risks. A couple of paragraphs about migrating to a secure O365 environment, but nothing that gives an outsider any hint of the tangled clutter of obsolete systems we now know they were running. Also notable that the budget increased by 12.1% between 2020/21 and 2021/22, so they had more money but chose to do other things with it.
From the report, there's all the required-by-regulators corporate bilge about diversity, carbon reporting, sustainability, how much the board get paid and their pensions, but nothing about IT, or about IT security. The word "technology" appears eleven times, by comparison the word "paddington" appears seven times. Within the intended substance of the report, it's quite clear that the British Library functions operates as a temple for librarians, and I couldn't readily find a single source for the names and expertise of external board members. Put simply, it looks like nobody in senior positions properly understood IT, they didn't listen to the likely tiny handful of IT professionals they had, and acknowledged but then assumed the threat of cyber attacks was real, but not an urgent priority.
"If a report of an air accident investigation revealed anything like the scope and systemic misadventure of the British Library report, it would shake up the aviation world so hard its rivets would pop."
Nice sentence but Boeing's refusal to identify who replaced some door bolts or even if they were replaced at all would disagree.