Another Cyber attack

Started by Mups, Yesterday at 12:08:19 PM

« previous - next »

Mups

This time on the NHS.   It has crippled blood test results being sent back.
Why are there so many evil people in this world now.


Quote:

"A patient has died after a cyber attack crippled NHS pathology systems in London - marking the first confirmed UK death linked to a ransomware attack on the health service.

The devastating revelation comes nearly a year after hackers infiltrated Synnovis, the company providing blood testing services for major NHS hospitals in south-east London. 
The breach caused chaos across the capital, leading to cancelled operations, missed diagnoses, and thousands of disrupted patient appointments."

Ashy

Seems that the NHS should have a back-up system, like a telephone or something.

klondike

Many of their systems rely on antiquated technology. It seems the previous attack exploited security weaknesses in Windows XP which was discontinued many many years ago and is riddled with vulnerabilities.

The problem was probably caused by outsourcing to the lowest bidder. The chances are that nobody has a clue how the system works and there is no decent documentation. The company that wrote the system handed it over, got paid, and those who actually wrote it are long gone. The bugs can't be corrected, nothing can be changed and the only option is to completely redevelop the system attempting to integrate it with other obsolete, undocumented, buggy systems.

When I started in IT each company had its own inhouse IT team that custom built and maintained systems  specific to the task. It still didn't entirely fix all the issues though. I worked in such a department in Ford in the 70's and early 80s before moving on to an IT company selling software for 10 years or so before becoming a self employed contractor. I took a contact with Ford after becoming disenchanted with better paying contracts in the city because of the abysmal experience of commuting by rail. They had outsourced their entire IT department but their core system was still pretty much the same as it had been back in the 70s/80s.

I recall many years ago when I was working for the American IT company that sold applications that ran on the main product which was a database. Apparently the way the Americans do accounting is different from the UK (and maybe Europe) Rather than keep the coding inhouse to make the necessary changes they decided to give the job to an Indian company who supplied coders to do the job.

To supposedly keep an eye on things a team of coders was shipped to the UK. The rumour was that they were sleeping on the office but I'm not sure how true that was. What was true was that they were getting paid per line of code. Nothing saleable resulted and it turned out that a high proportion of the "lines of code" they were paid for were actually comments added to the source code.