When it comes to ransomware, security professionals, law enforcement and the government consistently advise against paying the ransom. There’s good reason for this, not least that doing so offers no guarantee that you will get immediate access to your networks. Or that the perpetrators won’t sell or use your stolen data anyway.
Not that there aren’t formidable costs involved in dealing with the aftermath of a successful attack, some of which can best be filed under prevention is better than cure. That’s the situation that Advanced Computer Software Group Ltd finds itself in after getting hit with a £3.07 million fine for a ransomware attack almost three years ago.
LockBit NHS ransomware attack
If you’re British, you will probably remember the LockBit NHS ransomware attack. Back in August 2022, the NHS 111 non-emergency system became unavailable after Advanced, a managed service provider, was hit by the infamous ransomware group.
Advanced’s Adastra client patient management solution was used by more than 80% of the NHS 111 service. The impact was devastating and immediate, reaching as far as medical staff being unable to access patient data.
The longer term impact equally so: “The investigation found that personal information belonging to 79,404 people was taken,” the ICO said in a statement detailing the fine, “including details of how to gain entry into the homes of 890 people who were receiving care at home.”
This case highlights just how expensive it can be, financially and in terms of reputation, not to implement basic security controls to a proper standard.
The controls in question here were gaps in the deployment of multi-factor authentication, vulnerability scanning and patch management. “While Advanced had installed multi-factor authentication across many of its systems, the lack of complete coverage meant hackers could gain access, putting thousands of people’s sensitive personal information at risk,” said John Edwards, the Information Commissioner.
The £3.07 million fine
Following National Cyber Security Centre and National Crime Agency involvement, along with engagement with the NHS, the originally proposed ICO fine of £6.09 million was reduced to £3.07 under a voluntary agreement.
“The fine, while significantly reduced, is still substantial. It should serve as a wake-up call to all businesses that they cannot afford to neglect the basics,” said Trevor Dearing, Director of Critical Infrastructure at Illumio.
This is obvious but essential advice. Security controls like MFA, patch management and network segmentation really are non-negotiable: implementing them properly could have stopped LockBit from reaching critical data and systems.
“It’s also a reminder not to blindly trust suppliers’ security,” Dearing warned. “Complacency and overconfidence lead to successful attacks, and in today’s economy, no business can afford to lose money to cybercriminals or regulators.”
Ngoc Bui, a Cybersecurity Expert at Menlo Security, added that the “disruption from ransomware can be catastrophic, and organisations must prioritise protecting operations and stakeholders.
“Organisations that suffer a ransomware attack should also use it as a learning opportunity to adjust their security measures and ensure they are using actionable intelligence to do so.”
Advanced response to NHS ransomware fine
So what does Advanced have to say for itself? It provided me with the following statement:
“What happened over two and a half years ago is wholly regrettable. With threat actors operating with increasing sophistication it is upon all businesses to ensure their cyber posture is continually strengthened.
“Cyber security remains a primary investment across our business, and we have learned a great deal as an organisation since this attack.
“We reported the incident to the ICO in August 2022 and are pleased to see this matter concluded. Our focus remains steadfast on supporting our customers as they navigate the rapidly evolving technology landscape, ensuring they achieve their strategic growth and operational efficiency goals.”
Further reading