Site navigation

NHS Cyber Attacks – Sacrificing Goats & Speaking Mokita

Colin Keltie

,

NHS Cyber Attacks
Friday the 12th of May 2017 will go down in the history of cyber security as a red letter day. This day which started so inauspiciously gave the world a taste of just how brutal acts of cyber aggression could be – when our NHS (and many other organisations worldwide) were attacked by a wave of crypto ransomware. This malware was a variant of the wannacryptor locker – a piece of software believed to have been developed by the NSA and released to the world through the Shadow Brokers breach in April of this year.

Why is this event more significant than any of the other recent acts of cyber aggression? Why is it more important than the brouhaha (real and imagined, perceived or exaggerated) that now surrounds state-sponsored influencing of elections using doxing, email disclosures and other cybercrime variants? Why does it outpace any financial services fraud or service disruption brought about by DDoS (including the most recent core Internet attacks which brought such widespread impact to social media, video streaming and online commercial services)? This attack stands head and shoulders above the rest because it brought into sharp public focus the human carnage that cyber assaults can bring. This one touched a lot of nerves outside the cloisters of our profession. This one made it out into the real world.

We understand how to analyse, repair and defend against these attacks.

The Islanders of Kiriwina, an island in Trobriand group, part of the Milne Bay Province of New Guinea, speak a language called Kilivila. In this fascinating language there is a word – mokita. A mokita (in Kilivila) is a truth which is universally known but it is agreed that nobody talks about. IT and Cyber Security professionals have been analysing the cyber threat in earnest now for approaching a quarter of a century. We understand denial of service attacks, we understand Layer 7 application attacks, we understand where weaknesses in OS or application code can be leveraged (and how). We understand the motives of the various threat actor groups – from teenage braggarts to hardened fraudsters to the highest levels of State. We understand how to analyse, repair and defend against these attacks. We have mapped a sophisticated ecosystem of threat, vulnerability, risk and remediation across an ever-developing landscape of technology. We have seen threats invade the personal compute space, the network, portable devices, embedded systems, the Internet of Things – we have worked very hard to understand the world we live in and how we can effectively apply this knowledge to protect the innocent and secure the valuable.

NHS Cyber Attacks

Why are we seeing weak services and default passwords being advertised directly onto the internet?

So why are we still seeing crippling denial of service attacks? Why are we still seeing teenagers launch devastating attacks on large corporate entities using code and information that is older than they are? Why are we seeing weak services and default passwords being advertised directly onto the internet? Why are we seeing exploits which should have been eradicated like smallpox as soon as we understood them still being successfully deployed? Why are we failing?

….we talk to each other in this insane codified language….

The reason we are failing is simple – we have failed to communicate. And this primary failure is our mokita. Within the Security community we have tried to connect, to exchange intelligence, to develop as an organism. To the outside world? We are creatures of mystery and magic. Wizards of digital smoke and mirror. Nobody out there has a clue what we are, what or how we do what we do or what we are up against. We talk in terms of exploits and vulnerabilities, zero-days, buffer overruns. We have acronyms and abbreviations for everything: WAFs, SoCs, SIEMs, OpSec, InfoSec. The detail of what we do is cloaked in binary, hexadecimal, codecs, ciphers. We don’t make a lot of sense to anyone but ourselves. We talk a lot, sure. But we talk to each other in this insane codified language and the rest of the world, the people we are supposed to protect, they scratch their heads in bewilderment and stumble from one attack to the next. That’s our mokita. We might be impressive, but we are far too often completely ineffective. Worse, we cloak the threat in political language for fear of being accused of scaremongering? We acquiesce to support disruptive innovation and rapid entry in the digital marketplace. We don’t want to give the impression that cyberspace is too risky or we may call into question the complete dependence we have on it for all communications, commerce, social fabrics – all depend on the sanctity, availability and security of our cloud of whizzing digits and blinking fibres. We are collectively responsible for a complacency that we should not have allowed to take root.

…..the mythical “hacker” tossed around like cavemen might mutter their horrors about where the big yellow sky ball goes at the end of the day.

That sounds a bit harsh, but consider the response to the NHS hacks. I watched as talking heads tried (and failed) to translate the simplest of concepts into useful, news-friendly soundbites. “Well this is code that is at its most effective amongst connected devices” said one advisor. I heard the tried and tested clichés of “cyber attack” and the mythical “hacker” tossed around like cavemen might mutter their horrors about where the big yellow sky ball goes at the end of the day. “Will it return?” “What do we do?”. I saw the same weary faces appear attempting to describe again “just what exactly crypto ransomware is?”. “Should we sacrifice a goat?” “well if you’d backed up your goat you would have been fine.”

NHS Cyber Attacks

But you probably didn’t.

The thing is – we’ve been telling EVERYBODY what crypto ransomware is and what to do to avoid becoming the victim of an attack for years. We have sagely advised about patching vulnerable systems, recommended detective and preventative controls, trained our users in best practice, strategized about regular backups, undertaken phishing exercises and yet still I see in the face of a large scale event that some are now advising the victims to “Pay up. Try it and see.”. I don’t read that as a glowing endorsement of our efforts thus far.

We are way past the point of thinking that any of us could survive an effective strike at our digital heart.

The coverage of the events as they unfolded made an already depressing story even more dispiriting. “Yes, well it is extremely difficult to decrypt files unless you have the key” said one pundit on television (a security specialist). No it isn’t – it’s nigh on impossible. Tell the truth – it’s what the people need to hear. It’s not “difficult” or “challenging”. Neither is it “inconvenient” if your systems are locked. It’s a disaster to most and yes I’ll say it – impossible to remediate without those keys. So why are we still dancing around these ugly truths? Why are we cloaking the real risk of cyber attack in euphemism and soft language? I know we don’t want to start any unnecessary panic, but really the current proliferation of digital devices, the dependence that the individual, the organisation and the infrastructure and security providers of our and every other nation have developed upon the availability of these systems? We are way past the point of thinking that any of us could survive an effective strike at our digital heart. Our digital dependence is now, and has for quite some time been total. Our relationship is no longer symbiotic, but utterly and critically dependent.

Time will tell as to how many, but people have suffered here in the real world because of this.

The NHS’ ability to carry out scheduled operations on Friday was seriously impacted. Time will tell as to how many, but people have suffered here in the real world because of this. More will suffer because of this. Some may even die. “Who would attack the NHS? Why?” cries everyone in unified lament. I sadly reply – “Anyone who has assessed the landscape and has rightly identified an easy target. Critical yet antiquated systems, under provision of support at even the most basic technology level (let alone IT security), minimal to zero-tier separation from critical data objects and repositories and a fresh batch of weaponised malwares recently made available to the whole world? Nobody should be surprised that this has happened. Nobody should feign shock at the timing. Any Security professional worth his or her salt could have set their watch by this attack.”

In fact, it could be said that it’s to the credit of the threat actors that they have demanded such meagre capital to unlock and restore these systems. Wealthier targets that succumb to this attack are often shown far less financial clemency. In a perverse sort of a way it could demonstrate a bit of conscience on the part of the baddies? I personally doubt it though.

They are at best misguided opportunists and at worst extremely dangerous criminals and wholly without conscience.

So I’ll ask again – why is this attack such a Damascene moment in the history of Cyber Security? It’s the point at which the people who really needed to have been told the truth were shown the truth. The people we have been failing for all these years with our gobbledegook and soft language and mokitas. Hackers and threat actor groups are not anti-heroes. They are not Fighters For Freedom and Truth. They are not fighting for you against Big Government, Big Finance, Big Anything. They are at best misguided opportunists and at worst extremely dangerous criminals and wholly without conscience. They attacked the NHS because they could – Financial Services and other Enterprise and National verticals have learned and invested over the years – their systems are pretty effective at protecting them from this kind of malware. They can recover even if successfully attacked. The NHS did not learn in time, did not invest enough, and will likely face a long and painful path to recovery. Perhaps they will learn, perhaps the investment will come? Perhaps it won’t. However, be sure of one thing – the target is always the weakest spot. The lovely, caring, benign NHS that everybody holds dear to their heart was judged to be the weakest spot this time, and this analysis proved to be correct. The service will suffer, criminals will profit and the Cyber Crime and warfare machine will adjust its sights and go hunting for its next target. First they came for the banks, then the TelCos, then the service providers, then the infrastructure providers.

Then they saw the masses huddled.

Are you huddled securely?

Colin Keltie

CTO - Barrier Networks

Latest News

Cybersecurity Featured Security

Proposed Police Scotland Cyber Centre Raises Duplication Questions

Cybersecurity Editor's Picks Events

Microsoft, NBCUniversal and Admiral Group Experts Set for CymruSec 2026

AI Business Editor's Picks

Salesforce Agentforce Bugs Exposed Wider AI Agent Risk, Research Finds

AI Cybersecurity

Despite AI Hype, Traditional Identity Fraud Prevails