• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Major Incident declared as NHS computer systems infected by ransomware

Status
Not open for further replies.

DarloRich

Veteran Member
Joined
12 Oct 2010
Messages
32,939
Location
Fenny Stratford
Did you note the large number number of countries that have been affected by this ransomware. Are you proposing to name the politicians in those other countries on whose "watch" this criminality occurred on?

I neither know nor care.

We (or at least those of us without the funds to buy personal health insurance) rely on the NHS and because of Tory penny pinching it wasnt there when needed it. Rudd & Hunt should go but wont and will instead blame the NHS trusts for the failings they created. Shameful really but then as the saying goes: Same old Tories, same old crap.
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

me123

Established Member
Joined
9 Jul 2007
Messages
8,510
We (or at least those of us without the funds to buy personal health insurance) rely on the NHS and because of Tory penny pinching it wasnt there when needed it. Rudd & Hunt should go but wont and will instead blame the NHS trusts for the failings they created. Shameful really but then as the saying goes: Same old Tories, same old crap.

We ALL rely on the NHS. There is very little in the way of private emergency care in the UK, and the few private emergency departments* cannot cover anywhere near the same range of services that a full A&E network can. No 999 ambulance in these isles will take you to a private hospital - they will take you to the most appropriate NHS A&E department.

If you rupture an aortic aneurysm, have a stroke, heart attack, cardiac arrest, seizure... you're going to and NHS A&E department regardless of how comprehensive your private insurance is.

*I can only find one; it's in London, is not open through the night, cannot look after people under the age of 18 and does not treat many common emergency department presentations, including cardiac chest pain.
 

DarloRich

Veteran Member
Joined
12 Oct 2010
Messages
32,939
Location
Fenny Stratford
We ALL rely on the NHS. There is very little in the way of private emergency care in the UK, and the few private emergency departments* cannot cover anywhere near the same range of services that a full A&E network can. No 999 ambulance in these isles will take you to a private hospital - they will take you to the most appropriate NHS A&E department.

If you rupture an aortic aneurysm, have a stroke, heart attack, cardiac arrest, seizure... you're going to and NHS A&E department regardless of how comprehensive your private insurance is.

*I can only find one; it's in London, is not open through the night, cannot look after people under the age of 18 and does not treat many common emergency department presentations, including cardiac chest pain.

I am well aware of that thank you.
 

me123

Established Member
Joined
9 Jul 2007
Messages
8,510
Sorry, wasn't intending to "correct" you, just to reinforce your point, as well as pointing out that the Conservatives really are shooting even their most affluent supporters in the foot with their mismanagement of the NHS.
 

DarloRich

Veteran Member
Joined
12 Oct 2010
Messages
32,939
Location
Fenny Stratford
Sorry, wasn't intending to "correct" you, just to reinforce your point, as well as pointing out that the Conservatives really are shooting even their most affluent supporters in the foot with their mismanagement of the NHS.

no worries :D
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,714
Location
Scotland
Since my posting was in direct response to posting # 49 by Dave1987 and to no other person, I was somewhat taken aback by your decision to answer it on his behalf...:roll:
Might I suggest then that you take advantage of the forum's private message feature for private conversations?
 

mbonwick

Established Member
Joined
26 Oct 2006
Messages
6,311
Location
Kendal
Apparently (source Any Questions, BBC R4) our nuclear submarines also run XP!

Vanguard SSBNs run on a stripped down & customised version of XP Embedded (which is still supported by Microsoft). Microsoft call it "Windows for Submarines". It's about as locked down as it can be, with patches being applied whenever boats return from patrol. (Google Microsoft Windows for Submarines)

Astute is slightly different (with major differences between Boats 1/2 and Boat 3-7).
 

47802

Established Member
Joined
6 Mar 2010
Messages
3,454
it was stopped because it was out of control, had a very poor specification, was badly managed and very poorly contracted. However that was a new national computer system designed to automate NHS records rather than a software upgrade. Private Eye has been vocal on the shambles of this procurement.

See Guardian:

https://www.theguardian.com/society/2013/sep/18/nhs-records-system-10bn

The outdated nature of the operating software should have been on a risk register somewhere with a replacement cycle in line with the widely published stopping of support dates. The government knew 2 years ago this was an issue when they stopped paying microsoft for extra support and then failed to deal with the issue:

( Guardian: https://www.theguardian.com/technol...en-to-hackers-as-paid-windows-xp-support-ends)

I know that post brexit we have had enough of experts but the fault lies with the invisible Hunt, the shifty Rudd and their Tory chums and their policy of cuts. They knew, did nothing and now try to blame the victims of their cuts.

Frankly I cannot agree with some of your comments as someone who worked in corporate IT for over 20 years. The fact is any Windows upgrade can be a huge cost so much so that my company abandoned a formal Upgrade from Windows XP to Windows 7 as had happened in previous years and instead opted for an upgrade on an ad hoc basis when PC's were replaced. However when I left my company a year ago it still had around 40 PC's linked to specialist systems that were still running versions of Windows from Windows 95 up to Windows XP because the cost of upgrading these specialised system s was prohibitive in some cases it would required the replacement of the complete system, In the case of an environmental monitoring system they had the cost of eliminating the Windows 2000 PC it was linked to would have been £25000 because the entire system would need to be replaced. Many of their Process Control Systems were also still running XP because the Upgrade cost was prohibitive. Of course you have to assess risk verses cost and things that can be done to mitigate the risk but at the end of the day its a balance.
 

DarloRich

Veteran Member
Joined
12 Oct 2010
Messages
32,939
Location
Fenny Stratford
Frankly I cannot agree with some of your comments as someone who worked in corporate IT for over 20 years. The fact is any Windows upgrade can be a huge cost so much so that my company abandoned a formal Upgrade from Windows XP to Windows 7 as had happened in previous years and instead opted for an upgrade on an ad hoc basis when PC's were replaced. However when I left my company a year ago it still had around 40 PC's linked to specialist systems that were still running versions of Windows from Windows 95 up to Windows XP because the cost of upgrading these specialised system s was prohibitive in some cases it would required the replacement of the complete system, In the case of an environmental monitoring system they had the cost of eliminating the Windows 2000 PC it was linked to would have been £25000 because the entire system would need to be replaced. Many of their Process Control Systems were also still running XP because the Upgrade cost was prohibitive. Of course you have to assess risk verses cost and things that can be done to mitigate the risk but at the end of the day its a balance.

The NHS is "critical national infrastructure" that should be protected.The balance here was clearly wrong as software security failings led to that critical resource being unavailable. It is clear the government knew this was an issue but did nothing.

Personally I think the government (wounded by the cancelled IT project referred to above) simply didn't care or more likely understand the importance of this risk.

PS i have been involved in IT upgrade projects on a vast scale. They are expensive ( VERY expensive) but the cost of a failure similar to that discussed here is massive.
 

me123

Established Member
Joined
9 Jul 2007
Messages
8,510
Frankly I cannot agree with some of your comments as someone who worked in corporate IT for over 20 years. The fact is any Windows upgrade can be a huge cost so much so that my company abandoned a formal Upgrade from Windows XP to Windows 7 as had happened in previous years and instead opted for an upgrade on an ad hoc basis when PC's were replaced. However when I left my company a year ago it still had around 40 PC's linked to specialist systems that were still running versions of Windows from Windows 95 up to Windows XP because the cost of upgrading these specialised system s was prohibitive in some cases it would required the replacement of the complete system, In the case of an environmental monitoring system they had the cost of eliminating the Windows 2000 PC it was linked to would have been £25000 because the entire system would need to be replaced. Many of their Process Control Systems were also still running XP because the Upgrade cost was prohibitive. Of course you have to assess risk verses cost and things that can be done to mitigate the risk but at the end of the day its a balance.

As you have pointed out, it's a risk/benefit decision. But for the NHS, there has a been a massive cost associated with this malware attack that would have likely been prevented had the outdated Windows XP computers been replaced (I suppose there is the possibility that a loophole in a later OS could have been identified too). When you're dealing with critical data such as health records, I don't really think that you should be taking too many chances. Aside from the obvious potential cost in terms of patient morbidity and mortality (I would hope very low), the NHS will have lost millions over the course of a single day in restoring services, non-functioning elective services, and rescheduling said elective services in the future. So perhaps they've got that balance wrong in this instance. Lots of people advocate cutting money from the NHS by cutting "back room"/admin costs whilst protecting frontline care, but eventually everything comes back to the frontline care and this is a perfect example of this approach going wrong.

Then again, we still routinely use pagers and fax machines in the NHS, so Windows XP is like something out of "Tomorrow's World" by comparison :lol:
 

OneOffDave

Member
Joined
2 Apr 2015
Messages
453
Then again, we still routinely use pagers and fax machines in the NHS, so Windows XP is like something out of "Tomorrow's World" by comparison :lol:

The thing about pagers particularly on site, is there's not a lot of good alternatives out there for immediate alerting and very short messaging. For things like crash and fire calls I've not seen anything that works as well

I know fax machines got a good work out over the weekend. Having a fax machine on an analogue line is a very useful back up to e-mail and VOIP
 

JamesT

Established Member
Joined
25 Feb 2015
Messages
4,893
Frankly I cannot agree with some of your comments as someone who worked in corporate IT for over 20 years. The fact is any Windows upgrade can be a huge cost so much so that my company abandoned a formal Upgrade from Windows XP to Windows 7 as had happened in previous years and instead opted for an upgrade on an ad hoc basis when PC's were replaced. However when I left my company a year ago it still had around 40 PC's linked to specialist systems that were still running versions of Windows from Windows 95 up to Windows XP because the cost of upgrading these specialised system s was prohibitive in some cases it would required the replacement of the complete system, In the case of an environmental monitoring system they had the cost of eliminating the Windows 2000 PC it was linked to would have been £25000 because the entire system would need to be replaced. Many of their Process Control Systems were also still running XP because the Upgrade cost was prohibitive. Of course you have to assess risk verses cost and things that can be done to mitigate the risk but at the end of the day its a balance.

Though in the case of these specialised systems, like the oft-quoted machine connected to an X-ray machine, the risk can be mitigated in other ways.
It almost certainly doesn't need internet access, so put it on a segregated network away from the general purpose computers. Don't allow users to use these machines as their desktop. If it's a GUI application then people access it through remote desktop or similar which reduces the scope for malware to hop between systems.

But Windows XP may be a red herring. We don't know at this point whether it was XP being infected, or more recent versions which hadn't been patched by NHS IT staff.
 

Peter Mugridge

Veteran Member
Joined
8 Apr 2010
Messages
17,849
Location
Epsom
But Windows XP may be a red herring. We don't know at this point whether it was XP being infected, or more recent versions which hadn't been patched by NHS IT staff.

There was one NHS person talking on the BBC news last week saying their ( infected ) system was up to date.
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,714
Location
Scotland
There was one NHS person talking on the BBC news last week saying their ( infected ) system was up to date.
I suppose that could be true. Which means they opened an email attachment that they shouldn't have as the malware could only spread over the network to unpatched machines.
 

MikeWh

Established Member
Associate Staff
Senior Fares Advisor
Joined
15 Jun 2010
Messages
8,579
Location
Crayford
There was one NHS person talking on the BBC news last week saying their ( infected ) system was up to date.

It may well have been. Up to date XP was vulnerable. It still would be if Microsoft hadn't decided to issue an emergency patch in the wake of the attack.
 

Barn

Established Member
Joined
3 Sep 2008
Messages
1,487
It may well have been. Up to date XP was vulnerable. It still would be if Microsoft hadn't decided to issue an emergency patch in the wake of the attack.

Yes, or to put it another way, XP can never really be considered up to date.
 

me123

Established Member
Joined
9 Jul 2007
Messages
8,510
The thing about pagers particularly on site, is there's not a lot of good alternatives out there for immediate alerting and very short messaging. For things like crash and fire calls I've not seen anything that works as well

Could be a lot better. Pagers can be a royal PITA, and can be very much subject to interference I find (particularly if you carry multiple pagers).

Better solutions? Internal telephones - they have capability for text messages as well as telephony and I'm sure you could programme them to activate as an emergency pager (loudspeaker message that would interrupt telephony as needed). They also have dial-out capability. Better yet, a smartphone on an internal network. All of the above plus internet connectivity, which could be used to access clinical systems, useful apps/tools (potentially an integrated planning system/task list) and relevant evidence based resources.
 

Busaholic

Veteran Member
Joined
7 Jun 2014
Messages
14,671
Regrettably, it's not only cyber attacks that can cause havoc in NHS hospitals. I had rare cause to visit an A&E Dept a couple of weeks ago, about 300 miles from home, and all systems were 'down', which I gathered was not an uncommon experience there, so no X-rays, let alone more seriously needed stuff. Even the automatic doors to the Dept had a worn sign saying they were out of action (somebody had scrawled 'for some months'). Pity the citizens of Croydon who have to endure the Mayday (now named Croydon University Hospital, or some such rubbish, to try and disguise its chronic lack of resources). In the end, a couple of days later I was in the back of an ambulance to King's College, having had a relapse, and all credit to them. Luckily for me, this was 24 hours before the cyberattack.
 

northwichcat

Veteran Member
Joined
23 Jan 2009
Messages
32,692
Location
Northwich
However, before we start blaming the NHS, let's be clear that responsibility for this attack almost certainly lies with one group of people, and one group of people only: The criminals who write malware and use it to extort money without any thought for the effect their actions have on their victims. They are the people responsible for this. Just as you wouldn't normally blame a victim of assault or robbery for being assaulted or robbed, let's not fall into the trap of blaming the victim (the NHS) for the atrocious actions of the real culprits: The cyber-criminals.

Yes the fault of a crime is always that of a criminal. However, you should always do your best to prevent yourself from being a victim of a crime e.g. you wouldn't leave your wallet and phone on an unattended table in a pub.
 
Status
Not open for further replies.

Top