{"id":68,"date":"2017-05-23T16:18:23","date_gmt":"2017-05-23T16:18:23","guid":{"rendered":"http:\/\/www.patchadvisor.com\/blog\/?p=68"},"modified":"2017-05-23T16:21:44","modified_gmt":"2017-05-23T16:21:44","slug":"ransomware-wannacry-and-the-problem-of-legacy-systems","status":"publish","type":"post","link":"http:\/\/www.patchadvisor.com\/blog\/?p=68","title":{"rendered":"Ransomware, WannaCry and the Problem of Legacy Systems"},"content":{"rendered":"<p>The use of ransomware can be traced back to 1989, with the last peak in attacks recorded in 2013, until this past week.\u00a0 WannaCry has impacted people, companies and governments in more than 150 countries and proven that the ease of deployment plays a role in the rash of <a href=\"http:\/\/www.reuters.com\/article\/us-britain-security-hospitals-idUSKBN18820S\">security breaches<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-75\" src=\"http:\/\/www.patchadvisor.com\/blog\/wp-content\/uploads\/2017\/05\/globalassault.-e1495548431817.jpg\" alt=\"\" width=\"911\" height=\"596\" \/><\/p>\n<p>At PatchAdvisor, we advise you to keep your operating systems and applications up to date with patches.\u00a0 Without regular attention to system maintenance your systems will remain extremely vulnerable.\u00a0 And, the sheer number of older unpatched\/unpatchable computers still in use was proven out across the globe this week.\u00a0 Microsoft Windows XP hadn\u2019t been supported with security patches since 2014, but is still used around the world.<\/p>\n<p>Chris Goggans, the CTO of PatchAdvisor, points out that there are a number of reasons for these older machines to still be in service:<\/p>\n<ul>\n<li>The organization doesn\u2019t want to spend the money to upgrade to a newer OS.<\/li>\n<li>The organization is paying for extended support.<\/li>\n<li>The OS is required for some kind of specialty application.<\/li>\n<li>The OS is embedded.<\/li>\n<\/ul>\n<p>Many PatchAdvisor customers find they have all types of legacy systems that won\u2019t work on anything past XP.\u00a0 Applications that manage laboratory devices, for example, need to be certified by external organizations prior to general release, and this can cause a slowing of the upgrade process.<img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-73\" src=\"http:\/\/www.patchadvisor.com\/blog\/wp-content\/uploads\/2017\/05\/patch.jpg\" alt=\"\" width=\"913\" height=\"672\" srcset=\"http:\/\/www.patchadvisor.com\/blog\/wp-content\/uploads\/2017\/05\/patch.jpg 913w, http:\/\/www.patchadvisor.com\/blog\/wp-content\/uploads\/2017\/05\/patch-300x221.jpg 300w, http:\/\/www.patchadvisor.com\/blog\/wp-content\/uploads\/2017\/05\/patch-768x565.jpg 768w\" sizes=\"(max-width: 913px) 100vw, 913px\" \/><\/p>\n<p>Sometimes the wisdom is in looking at the devices on the network that you do not suspect to be an issue, like printers.\u00a0 Many devices running \u201cXP embedded\u201d have had automatic updates turned off for years because of fears that the updates would affect primary applications.\u00a0 Because of this fear, ATM screens and medical devices took the hit from WannaCry this past week.<\/p>\n<p>At \u00a0PatchAdvisor, we tell our customers to not expose weak protocols to the Internet, and keep software patched.\u00a0 There\u2019s nothing special in this \u2018best practice,\u2019 however it can be difficult to get management to implement, even if logical.\u00a0 If you can\u2019t patch, we suggest segregating your devices and minimize your network traffic to\/from them and the rest of the network.<\/p>\n<p>Improving cyber defensive postures for corporations and US government entities has never been more important.\u00a0 In the wake of targeted attacks, and connected computing with the Internet of Things, the projections on the national spend have skyrocketed.<\/p>\n<p>In terms of cyber-attack related damages for enterprises and governments, we anticipate that there will be upwards of $6 trillion through 2022 despite the heavy investment in cybersecurity, according to the Research and Markets, <a href=\"http:\/\/www.researchandmarkets.com\/research\/jsz54f\/global\">&#8220;Global Cybersecurity Market Outlook and Forecasts 2017 &#8211; 2022&#8221;<\/a>.<\/p>\n<p>Certain sectors are calling on government and industry groups to take action with their own <a href=\"http:\/\/www.modernhealthcare.com\/article\/20170503\/NEWS\/170509952\">frameworks<\/a> outside of the popular <a href=\"http:\/\/thehill.com\/policy\/cybersecurity\/333921-nist-workshop-discusses-debates-new-cybersecurity-framework\">NIST<\/a> approach, including the healthcare sector.\u00a0 Specifically, healthcare professionals, via a recent <a href=\"https:\/\/chimecentral.org\/2017-chime-klas-cybersecurity-report\/\">KLAS-CHIME study<\/a>, are calling for amendments to the Physician Self-Referral Law (Stark Law) and the Anti-Kickback Statute to allow healthcare organizations to assist physicians with cybersecurity.<\/p>\n<p>Other countries have faced similar discussions. <a href=\"https:\/\/www.wsj.com\/articles\/cyberattack-not-unexpected-for-englands-national-health-system-1494620794\">England\u2019s National Health Service<\/a> has long prepared for the kind of cyberattack that crippled several of its hospitals last Friday.\u00a0 NHS Digital took the step in October 2015 of establishing the Care Computer Emergency Response Team, or CareCERT, an intelligence service that manages national cybersecurity attacks.<\/p>\n<p>With U.S. President Donald Trump\u2019s signing of the cybersecurity order earlier this month, more responsibility is being placed internally in government agencies on departmental secretaries and agency directors to secure digital assets, starting with the use of the NIST framework for risk management.<\/p>\n<p>Particularly critical in the U.S. is\u00a0 the energy grid, and assessing electricity disruption incident response capabilities, as cited in the executive order.<\/p>\n<p>Improving resilience across all global ecosystems is a vaunted goal that requires proactive risk management, including assessing the vulnerability of legacy systems and taking the steps necessary\u00a0to mitigate those risks. \u00a0Otherwise, there will be significant breakdowns, like the most recent WannaCry ransomware attacks.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The use of ransomware can be traced back to 1989, with the last peak in attacks recorded in 2013, until this past week.\u00a0 WannaCry has impacted people, companies and governments in more than 150 countries and proven that the ease of deployment plays a role in the rash of security breaches. At PatchAdvisor, we advise [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":84,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[19,14,10,6,17,7],"_links":{"self":[{"href":"http:\/\/www.patchadvisor.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/68"}],"collection":[{"href":"http:\/\/www.patchadvisor.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.patchadvisor.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.patchadvisor.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"http:\/\/www.patchadvisor.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=68"}],"version-history":[{"count":9,"href":"http:\/\/www.patchadvisor.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/68\/revisions"}],"predecessor-version":[{"id":81,"href":"http:\/\/www.patchadvisor.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/68\/revisions\/81"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.patchadvisor.com\/blog\/index.php?rest_route=\/wp\/v2\/media\/84"}],"wp:attachment":[{"href":"http:\/\/www.patchadvisor.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=68"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.patchadvisor.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=68"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.patchadvisor.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=68"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}