This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…
>They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. That doesn't fit their claims on page 7 about reviewing the lost data and contacting affected users.
British Library cyber incident review [pdf]
11–20 of 70 posts
Re: British Library cyber incident review [pdf]
#12> These legacy systems will in many cases need to be migrated to new versions, substantially modified, or even rebuilt from the ground up, either because they are unsupported and therefore cannot be repurchased or restored, or because they simply will not operate on modern servers or with modern security controls.
> There is a clear lesson in ensuring the attack vector is reduced as much as possible by keeping infrastructure and applications current, with increased levels of lifecycle investment in technology infrastructure and security.
> Our reliance on legacy infrastructure is the primary contributor to the length of time that the Library will require to recover from the attack.
A lot of lines like the following, also indicate to me IT was increasingly were involved in fighting fires and maintining operational systems ("keeping the lights on") rather than deploying new infrastructure and automation, updating software etc.
> Some of our older applications rely substantially on manual extract (...) which in a modern data management and reporting infrastructure would be encapsulated in secure, automated end-to end workflows.
Modern business is IT, I know that I am preaching to the chior but this sounds a lot like their IT was seen as a cost.
Re: British Library cyber incident review [pdf]
#13"The Library utilises numerous trusted partners for software development, IT maintenance, and other forms of consultancy" ... "this terminal server was protected by firewalls and virus software, but access was not subject to Multi-Factor Authentication (MFA)" ¯\_(ツ)_/¯
Re: British Library cyber incident review [pdf]
#14This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…
At least they seem to have a plan moving forward that seems considered, though I think a lot of what they want to do is easier said than done effectively. I wish them the best of luck.
Re: British Library cyber incident review [pdf]
#15This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…
It's bad that they don't know what was taken, but as for paying the ransom, I wouldn't do it either: first, because it's danegeld; second, because you're just exposing yourself to even further risk by accepting files from criminals; third, because as others said, it would be UK tax money.
Re: British Library cyber incident review [pdf]
#16I object to the word "utilises" instead of just plain "uses", especially from a library.
Re: British Library cyber incident review [pdf]
#17This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…
As an organisation forming part of the UK State, they're not allowed to. Rightly, in my opinion.
Re: British Library cyber incident review [pdf]
#18This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…
I suspect they don't have the forensic evidence to determine the root cause. Chances are there are probably too many ways it could have happened, and the evidence was encrypted or simply wasn't being captured. At least they seem to have a plan moving forward that seems considered, though I think a lot of what they want to do is easier said than done effectively. I wish them the best of luck.
It said that. The terminal server entry point was completely scorched in the attack. Offsite rlogd would have helped.
Re: British Library cyber incident review [pdf]
#19"Jisc is the UK digital, data and technology agency focused on tertiary education, research and innovation."
State-owned quango asleep at the wheel. Unsurprising.
Re: British Library cyber incident review [pdf]
#20This report is a joke. No root cause. On other forums it is understood they were running very old and unpatched VMware os. Which is simply embarrassing and everybody within their IT team should be fired immediately for gross negligence. They can't inform people whos data has been compromised because they refuse to pay the ransom and have no other way to tell what was stolen. Farcical. Their ability to rebuild in a ti…
> they refuse to pay the ransom As an organisation forming part of the UK State, they're not allowed to. Rightly, in my opinion.
Since I dont trust the library to actually assess my impact, or track records of companies getting hacked often drag their feet making it up to victims. (equifax)