24

 

Joint Committee on the National Security Strategy

Oral evidence: Ransomware

Monday 30 January 2023

4.30 pm

 

Watch the meeting

Members present: Margaret Beckett MP (The Chair); Baroness Anelay of St Johns; Lord Butler of Brockwell; Sarah Champion MP; Baroness Crawley; Lord Dannatt; Baroness Hodgson of Abinger; Dame Diana Johnson MP; Darren Jones MP; Stephen McPartland MP; Baroness Neville-Jones; Lord Snape; Bob Stewart MP; Viscount Stansgate.

Evidence Session No. 2              Heard in Public              Questions 15 - 34

 

Witnesses

I: Councillor Mary Lanigan, Leader, Redcar and Cleveland Borough Council; Sarah Stephens, Managing Director, International Head of Cyber and UK Cyber Practice Leader, Marsh Speciality; John Ward, Interim Chief Technology and Transformation Officer, Health Service Executive (HSE) of Ireland.

 

Examination of witnesses

Councillor Mary Lanigan, Sarah Stephens and John Ward.

Q15            The Chair: Welcome to this session of the Joint Committee, and thank you particularly to our three witnesses who are giving evidence to us today. This is the second evidence session for our new inquiry into ransomware, an inquiry that we launched in October. The whole idea of today’s session is to focus, or to seek to focus, on the experience of victims of ransomware and the state of the cyber insurance market, which may well be linked to some degree. We would also welcome your views on any areas for reform, particularly with regard to our Government’s approach to ransomware. May I also say, for your benefit and that of anybody watching, that this is a hybrid meeting, so some members of the committee will join it virtually?

The first question is specifically to Councillor Lanigan and Mr Ward, for reasons that will become obvious in a second. Both your organisations have experienced a ransomware attack in the last three years. Before the attack, what level of awareness did you have about the scale of a threat from ransomware?

Councillor Mary Lanigan: We were aware, as normal councillors, but we had had a clean bill of health only two months prior to the ransomware attack hitting us. We had followed all government guidelines, and we did not think that we were at risk. From my point of view as leader of the council, perhaps the council had been a bit lax in not making sure that all the elected members were up to speed and knew what they were looking at. That has since been sorted out, and now we are on the ball.

Our systems up at Redcar were all together, so we did not have separate children’s services or anything else. The ransomware attack hit us on a Saturday morning, and it was only because one of my IT staff had gone on to the system, thought, “This doesn’t look right”, and pulled the plug that we found out what was going on, which was that a virus had been in our systems for more than two weeks. It was triggered on that Saturday when he pulled the plug, and it was catastrophic, because we lost everything; we lost our telephone systems, our IT, the whole lot.

Not only that, but our partnerships, including Cleveland Police, pulled the plug on us because we had all this going on. GCHQ came up and helped us. It took us months and months to get that right. My staff from children’s services were writing on pieces of paper—things that had not been done for decades. My IT staff, who were working alongside GCHQ, stayed in the building; we put beds in for them to see how quickly we could move things forward.

It still took us months to do that, and the cost to the local authority was massive, not just with the overtime but with bringing in expertise and trying to put new telephone systems in. I contacted central government and we spoke to the Minister. He said, “Whatever it is, we’ll meet the cost”. Unfortunately, that does not always work as you go down the line; they want to know how much this was and how much that was. We lost about £7 million. Redcar and Cleveland Borough Council was not insured for this.

There are a lot of things that local authorities do not get insured for. I think it is the fact that the cost of the insurance is massive, and you do not think that this will happen to you. So perhaps it is because you take a chance. With hindsight, could we do something nationally in case this happens? We are not complacent up there, and although we have everything in place that we think will mitigate anything in the future, you can never say never.

The Chair: You refer to the massive cost. Were you not insured primarily because of the cost? Had you looked seriously at being insured, or was it that none of you had really appreciated—understandably—what the impact of an attack might be?

Councillor Mary Lanigan: I was new to the leadership; I had only been there for a few months when this happened. Looking back at that and speaking to senior staff at the council, the cost for us to insure against these things would have been astronomical, particularly with what was going on in other parts of the country and across the world.

Ministers did leave it to my discretion: “Are you going to pay this ransom, Mary?” No, we could not, first, because I did not know whether we would be able to get that virus out of our system; it was that catastrophic that there was not much left of it. Secondly, if I had paid it, would they have hit the other local authorities? Would they have thought, “We can do this to the other local authorities. This council’s paid, so the other councils will pay as well”? So we could not do that.

This was still going on when Covid hit us, which gave us a chance to look again at our systems and pull everything together. Middlesborough, the council next to us, paid the staff wages, Cleveland Police came in and took over Gold Command for us. So you can see that we had devastation right across the board. I have been on several calls to a lot of the other councils—we have had Zoom calls and so on—and a lot of them were in the same position as we were. All our systems were together. Now, we have split children’s services, adults’ services, payroll, and all of them now have back-up systems, so if they hit us again, only one particular section will go down. It was devastating, not just for staff but for residents. We were trying to keep them informed about what was going on.

It is not a criticism of the Government, but Ministers were saying, “Don’t talk about it, Mary”. The local press knew that this had happened to us, so they wanted to know what was going on, how much we knew about it, whether we knew who had done this to us, whether there was a ransom. What I was getting from central government was, “Don’t say anything”, which made it very difficult, and although my cabinet knew what was going on it seemed that we had to keep it really tight. Maybe it was because of security, I absolutely understand that, but in hindsight it caused us a lot of issues, because we could not go out there and say, “This is what has happened”.

The Chair: It would not meet with sympathy from your local media, I am sure. Mr Ward, were you aware of the scale of the potential impact?

John Ward: Yes, we were. If it is helpful, I might read a page or two of the report that I have here, because it gives you good context to the attack.

First, thank you for your invitation to meet you all to discuss this and to hear our experiences. I am the chief technology transformation officer at HSE. HSE is a geographically spread organisation that provides all of Ireland’s public health services to hospitals and communities across the country. HSE is the Irish state’s equivalent of the NHS. It consists of about 4,000 locations across Ireland, 54 acute hospitals and over 70,000 devices. Services are provided through community-delivered care and care provided through hospital systems as well as the national ambulance services.

We are the largest employer of the state, and at the time of the attack we had over 130,000 staff in direct employment and community care. We have a community that is increasingly dependent on the reliable delivery of information technology solutions. We are classified as a critical infrastructure operator on the EU NIS 2.0 directive and are known as an operator of essential services.

On the morning of 14 May 2021, HSE was hit with a Conti ransomware attack. Like Mary’s experience, here the attacker was in our environment from 16 March. The phishing email was sent on that date, someone clicked on the link and on 18 March it was activated in the environment. Between 18 March and 14 May the attacker was conducting lateral movements across the environment, gaining administrator credentials so that they could launch the attack on 14 May.

On 14 May, when that hit, we invoked our critical incident process, which began a sequence of events leading to the decision to switch off all HSE’s IT systems and to disconnect the national healthcare network. That network is how we connect with our hospitals. A number of national systems are completely dependent on the network to operate.

This immediately resulted in healthcare professionals losing access to all HSE-provided IT systems, including patient information, clinical care and laboratory systems. Non-clinical systems, such as financial systems and payroll, were also impacted, causing significant disruption. Many healthcare professionals had to revert to pen and paper. Normal communication channels­­, both the HSE’s national centre and within operational service, were also immediately hit. This included email and network phone lines. Staff switched to communicating using mobile and analogue phones, fax, and face-to-face meetings.

The aim of the attack was to disrupt the health service and IT systems, steal data and demand a ransom for non-publication of stolen information. Although the attacker posted a ransom note, the HSE and the Irish Government confirmed on the day of the attack that we would not engage in paying a ransom to the attacker, either directly or through a third party.

Despite that, a week after the attack, the attacker posted the decryption key on the dark web. Our incident responder tested this. It was considered to be viable. We used that decryption key to decrypt the services. Despite having the decryption key, it was a significant undertaking. We prioritised the systems in terms of patient administration systems—radiological, diagnostics—but despite having the key, it still took us four months to recover.[1] Priority 1 systems were recovered in the weeks and months after, but it took us four months to get to 99% of the systems being up and running. At this point, if we did not have the key, I cannot say how long this would have taken.

The experience has been a sobering one for us. The HSE went very public with a post-incident review. I recommend that all committee members read that review, a very detailed report of what happened and how it happened as well as the actions the HSE had to take to ensure that this did not happen again. They included investment in senior officers responsible for IT security. I am one of them. I was working with the HSE at the time of the attack, but I am now seconded to the HSE to help it to respond to this cyberattack by putting a multi-year programme in place to invest in the infrastructure and the team in order to ensure that this does not happen again.

In terms of the defences, we had a security operation centre, but it was not operating 24/7. If you are going to invest in one thing, it should be a 24/7 security operation centre, as well as a managed defence and response mechanism. That is a capability that monitors your environments for the typical behaviours. If someone gets a phishing email and clicks on a link that then tries to run a script on the computer, you can then identify that that is happening before an attacker can begin the lateral movements and before the most serious impacts of such attacks. Had we had this in place, we could have prevented the attack. We have them in place now, and I encourage everyone across the public and private sectors to look at this.

The Chair: I hesitate to ask this, but I cannot resist. Have you any idea at all why they posted the decryption key?

John Ward: I have no idea. However, at the time of the attack, we were probably the first victim of a national healthcare system ransomware attack. Other healthcare organisations had been impacted, but not at a national level. Although the ransomware gangs were claiming that they did not want to cause harm, they were causing harm. Also, the Irish state went very public. They said, “Were not paying the ransom, and this is putting lives at risk”. If someone had a change of heart, we were grateful, but these are criminals. It was helpful, but it still took us months to fully recover, even with the decryption key.

Q16            Lord Dannatt: By virtue of working for Marsh McLennan, Sarah Stephens, your clients have chosen to take insurance cover, so presumably they are very aware of the potential risks of cybersecurity attack. Notwithstanding that they have insurance cover, are they generally implementing strong protections and plans for their response or, perhaps because they have insurance cover, are they somewhat complacent?

Sarah Stephens: That is an interesting question. First, to clarify the role of Marsh McLennan in the insurance ecosystem, we are a risk adviser and insurance broker. We work on behalf of a council, a public entity or even individuals, to connect them with the best insurance provider, and we advise them on what steps they should take to be an attractive risk and how best to manage their risk. We also work with some companies that do not buy insurance at all. We are just advising them on the steps that they can take. It is important to clarify that we are not the risk-taker in that context, but we work with a lot of clients who are interested in transferring a portion of their cyber risk.

Our experience over the last few years has been of a big spike in incidents, which has led to this virtuous circle of information sharing, from insurers, back through brokers, to insured and uninsured entities. Through the examination of the correlation between certain cybersecurity controls and incidents that have occurred, we have a lot of rich data on what controls make a difference, how often companies are implementing them and how well, therefore, they are protected. We are constantly analysing that information.

The firms that can secure insurance at a price that they find reasonable and at limits that they find adequate are typically showing proficient implementation of about 12 key controls. I will not read them, but I can go into them in more detail in writing to the committee, if it is of interest. They are things like the proper implementation of endpoint detection and response, advanced anti-malware tools, practising an incident-response plan and awareness training for employees.

Most resilient entities have implemented most of those controls and in a very effective way. I would not say that insurance makes companies more complacent. If anything, the bar is a little higher for a company to be offered insurance in the first place.

Lord Dannatt: Thank you. The committee might be interested in seeing that list of controls. We will not ask you to go through it now.

You are saying that the level of resilience has risen in the organisations that you have been advising and having dialogue with. You may not be able to answer this, but what proportion of organisations that are at risk have engaged with you or with companies like you, have raised a level of resilience, and have taken out insurance?

Sarah Stephens: I probably cannot share any specific statistics about the uptake of insurance, because it really varies across geographies, across sectors, and absolutely across the size of companies, but, anecdotally, the cyber insurance industry measures itself based on gross written premium. That is the measure of the size of the market. Even some five years ago, that market was US$5 billion or US$6 billion globally in total. Today, our best estimate at the end of 2022 is that it is US$12 billion in gross written premium. That certainly means that many companies have paid more for their cyber insurance in recent years, which I can talk about in more detail. Also, more companies have purchased cyber insurance for the first time. The level of underinsurance is decreasing in this space, which ultimately increases resilience.

Lord Dannatt: Thank you. Other members want to talk about insurance later, but thank you for that overview.

Q17            Sarah Champion:  Councillor Lanigan and John Ward have both spoken very eloquently about the impact on the systems and the staff. Focusing on the impact on service users, Councillor Lanigan, you said that the attack was devastating on citizens. Can you give us some examples of how it impacted on them?

Councillor Mary Lanigan: It was not just our staff. We have children’s and adults’ services. Everything had been completely wiped out­—any reports coming in from members of the public regarding children and services. It was devastating. We could not even take in payments for rates or bills. We could not get any money out there. We had no records. When this happened, we had no telephone, no emails, no functioning computers, no laptops, the printers would not work and, crucially, there were no records or documents. We were advised not to go into a great deal of depth about what had happened. The public knew that we had been hit by a ransom attack, but they did not know how serious it was. We were trying to mitigate their concerns regarding children, children’s services, our fostering panels and so on.

John was saying that the HSE got some of that back within months. It took us eight and a half months. You can imagine the devastation. I had staff running about with pieces of paper. We brought in another telephone system that we could use, but that took time. It was catastrophic, for the council and for the residents we serve across the board.

Sarah Champion: Have there been any long-term impacts, such as child protection cases not going to court because you did not have documents, or people automatically having bailiffs coming round?

Councillor Mary Lanigan: Because GCHQ came in quite quickly, our major priority was to get the children’s services back up and running and cleaned, and to see how much of that we could recapture. GCHQ workers are experts in their field and they got that section cleaned as quickly as they could. It did not affect any of the court cases that we had, fortunately, but it could have done. It could have impacted on foster carers. We were lucky in that regard, but it was due to GCHQ that we got that section up first. The local authorities were paying salaries and bills and paying contractors and partnerships, but it was critical for children’s services and adult services to be up and running first in order to minimise the impact.

Sarah Champion: Turning to John, you say that you were down for four months and that the ransom attack was causing harm. Can you give us some examples of the sort of harm that it was causing your users?

John Ward: To clarify, the four months related to getting to 99%. We had an incremental approach in bringing key critical systems online in the weeks and months immediately after the cyberattack. We got 99% back in four months. Over time, we prioritised certain systems, such as the patient management systems and diagnostic systems, over weeks and months. That was done on a prioritised basis. We were not completely down for four months.

The impact in effect was that there was a higher risk to patient care. Access to scheduling appointments, who was coming in, access to their clinical notes, some of their radiology would all normally have been delivered electronically but was now no longer available. A lot of clinicians had to revert to pen and paper.

Sarah Champion: What did that do to elected surgery? Did it all have to be pushed back?

John Ward: It caused a lot of delays to appointments. People had to go away and come back. We already have queues at the best of times, so it impacted some of our waiting lists. Overall, it slowed down the system, and even after they were recovered there was a lot of remediation work to get a lot of those paper notes back into the system. That was very challenging. Our front-line staff, having gone through the pandemic, were very tired and had to deal with this. It was not great for them.

Sarah Champion: You both mentioned the financial impact of that. Did you have to divert resources from elsewhere to effectively back-fill? Councillor Lanigan, you mentioned that the Government said that they would give you support, but you then spoke of the problems that you had. Can you both say a little about that? Has HSE had ongoing financial issues because of this?

John Ward: At the time of the attack, a number of actions were taken that were probably slightly different from Councillor Lanigan’s experience. It was a very public response from the Irish state. A situation centre was established for the HSE response. We have an equivalent to the national cybersecurity centre which recommended that an incident responder was taken on to help the HSE. They were brought in on an emergency basis to help with the response. Additionally, a number of professional services firms were brought in to support the recovery exercise, which was conducted over the four months. There were increased costs and investment. Additional funds were provided through the Department of Health. I am not privy to whether that was taken from other areas.

Sarah Champion: Councillor Lanigan, can you give us a bit more detail too? You mentioned when opening that the Government said that they would support you, but that in reality you had problems.

Councillor Mary Lanigan: The financial cost of the cyberattack was absolutely huge. We knew that from the outset, because we had to bring in different services. We were in daily contact with central government. Initially, we were getting from Ministers that “It’s not an issue. This is a criminal act. Well make sure that this isn’t of your making”. When they actually looked at us, they said that we were more than adequate to sustain the cost, which of course we were not.

I will leave these figures for you. We were very grateful; they gave us £3.68 million. The cost of what happened was £11.3 million. I had to use reserves. When I first went into the council as leader our reserves were extremely low. We were trying to build them up. We used the reserves to do that. We have been frugal ever since, because that is what we have had to do. You cannot recover £8 million from 2020 until now, particularly with the financial situations that the councils are in at the moment, so that was difficult.

The Ministers were saying, “It’s okay”, but when we submitted the costs, they said, “We want to have another look at that. Where have you got these staff costs from?” It took my officers a considerable amount of time to go through that. Had we been a council with more funding, I would have challenged what central government paid, because it put us on the back foot. I still have not got the reserves back to where they need to be because of this.

Listening to what is being said about insurance, I would say that local authorities cannot afford insurance cover to that extent, particularly with cyber as it is across countries. I do not know whether there is a system that can be put in place, but if it had hit more than our council—I know that another one went down—we would not have recovered, and central government would not have been able to step in and help us as they did.

Stephen McPartland: It is very clear how devastating the attack was on you. I can see the impact it has had on you emotionally. I am sure it is the same for your officers and staff. Were you engaging with Ministers in the Home Office as well as in Levelling Up, or were you only engaging with the Minister in Levelling Up?

Councillor Mary Lanigan: In the Home Office as well.

Q18            Baroness Neville-Jones: I want to take you back to the moment when you discovered that this attack had taken place and find out how you went about trying to repair the situation. You said earlier that before the attack you felt that you were reasonably well placed with all your preparations on cybersecurity. Did you have a plan for what you would do in the event of an attack, or did you, like many, plan to make it up as you went along? When you turned to people for help, where did you go? Who did you ask for help? Did you find that the help you got was helpful?

Councillor Mary Lanigan: It was a Saturday morning at 8.30 am. My managing director rang me and said, “Mary, we’ve been hit”. I had just got out of bed. He said, “We’ve been hit with a cyberattack and everything has been pulled”. I said, “Right, I’m on my way”. I went down, all the staff were called in, and we realised immediately the seriousness of it. We informed central government of what had happened.

Baroness Hodgson of Abinger: What bit of central government?

Councillor Mary Lanigan: They had contacted GCHQ immediately. We engaged with cyber response teams, who were very good, but we found at first that although we had informed central government that we were under attack, we were left to our own devices for the first week or so. We had to call in our own private security.

Baroness Neville-Jones: They did not give you any advice.

Councillor Mary Lanigan: No, they left us. I have the paperwork here, which I will leave for you. That is where we were. That delay, not getting on top of it straightaway with the help of central government, delayed us further down the road.

Baroness Neville-Jones: In the absence of help from central government, did you rely on your own resources and your own teams, or did you take some commercial help?

Councillor Mary Lanigan: We did at first. Then we brought a commercial team in to see whether they could help us, and then central government stepped in to see what they could do.

Baroness Neville-Jones: They did that because they realised that it was serious, or because you badgered them?

Councillor Mary Lanigan: A lot of it came from me saying, “What do you think you’re doing?” They then realised how serious our situation was and stepped in. We had about a week’s delay. Even though central government were very aware of what had happened to us, they took a step back.

Baroness Neville-Jones: How was the actual demand from the attackers communicated to you? What did they say about what they wanted, and how did you reply? Did you get advice on the reply?

Councillor Mary Lanigan: I was asked what I wanted to do. Being a Yorkshire woman, you tend to put your foot down. We got a communication from them saying that they wanted several million and how it had to be paid, and that if we did not do that­

Baroness Neville-Jones: How did they communicate that?

Councillor Mary Lanigan: It came to our security teams.

Baroness Neville-Jones: Presumably this was not through your normal systems, because they were down.

Councillor Mary Lanigan: No, they did not use our normal systems. They said that if we gave them the money, they would remove the virus. Having spoken to GCHQ and experts, that would not be possible. We did not have a key like they had. They were not prepared to do anything like that. The system was so devastated that we felt that it had gone beyond where we could pull anything back from what they had done. The Minister and central government said, “Are you going to pay this, Mary?” I said, “Absolutely not”.

Baroness Neville-Jones: So that was your decision?

Councillor Mary Lanigan: Yes, it was left to me to make that decision. Maybe in hindsight it saved some other councils. If we had paid, perhaps the attackers would have felt that this was easy. Also, the council was not able to pay. Had we done so, and they were already into our systems, would they have done it again? You do not know that, so you decide to say no.

Baroness Neville-Jones: The Government agreed with you, did they not, that you were doing the right thing?

Councillor Mary Lanigan: Yes, they did.

Baroness Neville-Jones: Looking at the experience that Mr Ward described and what you are telling us, on the Irish side the Government were very open and very clear. The blackmailers knew the position of the Irish Government and so did the public; it was a public affair. On the UK side, you describe a situation where there is a lot of secrecy, with the Government insisting on keeping it all undercover. Is that the more helpful way forward? Would you do that again, or would you want it out in the open?

Councillor Mary Lanigan: It was the first time this had happened, and perhaps there was inexperience on my part. With hindsight, if it happened again, I would go out there and say, “Were not doing this”. It did not make any difference. The secrecy annoyed some of the other councillors and partners who we were working with. I was told, “Say as little as possible, Mary. Don’t go to the press”. The press were all over this. They knew that this had happened, and they were badgering us for a press statement. If it happened to us again, we would go out with it.

Baroness Neville-Jones: What do you think the Government’s motive was?

Councillor Mary Lanigan: I am not sure. I think they thought that it might not have been a normal ransomware attack. That was investigated for a long time, as was where this virus had come from. I thought at the time that if it was a foreign power, not just someone sat in a room, maybe the Government needed to keep that under wraps.

Baroness Neville-Jones: Do you think they were just trying to save money?

Councillor Mary Lanigan: You are probably right.

Baroness Neville-Jones: Did you approach the police? Were they involved at all? Was there any law enforcement element in the assistance from, or in the dialogue with, central government?

Councillor Mary Lanigan: The police were in within 48 hours.

Baroness Neville-Jones: That bit of the police came in.

Councillor Mary Lanigan: It was not the normal police. They came in from outside our area; they were an international crime branch.

Baroness Hodgson of Abinger: Did you ask the Government why they were telling you to keep quiet? Also, did the police manage to trace anybody?

Councillor Mary Lanigan: I understand that the police and central government are aware of where this came from.

The committee suspended for a Division in the House of Lords.

On resuming—

The Chair: Although Lady Hodgson had just asked you a question, she has not got back from the vote yet, so could we take a question from Lady Crawley? We will then come back to Lady Hodgson.

Q19            Baroness Crawley: Councillor Lanigan, from your experience so far, how have you been able to assist other local authorities? Could the task and finish report that your council did be taken on by other local authorities? How best can local authorities be protected across the country?

Councillor Mary Lanigan: Given that this had happened to Redcar and Cleveland Borough Council, I have had several Zoom meetings involving councils across the country and Northern Ireland, in that I explained our situation. One of the councils, down in Surrey, told me that it was very concerned about it happening to them. They were going to put all their systems together. I said, “No, don’t. We did that and this is what happened to us. This is what we have done now”. That has been taken up by many of the councils. We videoed that and it went out to most UK councils, which have been back in touch to say, “We’re doing this. What do you feel about that?” There has been a lot of communication across councils since this happened to us. We are trying to help, and that will continue.

It is not just the councils but the task and finish group and our councillors who must be aware when they are opening their emails that we could have an issue. We cover this regularly with them. I have encouraged the other councils to do the same. Perhaps we were lax with that. Maybe you think that it will not affect you.

We have upped our game and a lot of other councils have done the same, but you can never say never.

Baroness Crawley: Yes. Thanks very much. The fact that you have been able to lead on splitting your systems is really important. Would you also say that you had advice to give to councils on their interaction with government departments? We talked about your being in touch with the Department for Levelling Up and with the Home Office. As far as I can see from your council’s report on this, you would say that one of the learnings is that any negotiation with government should be recorded and retained—

Councillor Mary Lanigan: Absolutely.

Baroness Crawley: —because you thought they were telling you something about the financial assistance that you were going to get, but in fact it turned out to be substantially less than you wanted. Would that be one thing that you would say to other councils?

Councillor Mary Lanigan: Absolutely, and I have done. I have been quite frank about that, because the message coming from the Home Office and the Levelling Up Minister is, “There isn’t an issue”. We should have recorded that right from the word go. It should have been in black and white. Bear in mind that our systems were down, but I should have done something there, because then it went backwards. They just said, “Whatever it costs, we’ll deal with it”, which was not the case.

It took me months, even to the point where I was regularly ringing Ministers, as well as MPs up there who look after our area, and saying, “Look, you’ve got to help”. We were getting into a very desperate situation. So in the Zoom calls I have had with the councils I have said, “Make sure that if central government is involved, you get this written down somewhere and get an agreement as to what they’re going to cover and what they’re not”, because it cost a great deal of money that we could ill afford.

Baroness Crawley: Thank you very much.

The Chair: Baroness Hodgson, you were in the throes of a question to Councillor Lanigan, and then, I think, you have a question for Mr Ward.

Q20            Baroness Hodgson of Abinger: Yes. I apologise that I took time to get back from the Division.

I was asking you whether they were able to trace where this attack had come from, and you said that you thought it was international. Do you know whether they were able to do anything about that or hold anybody to account, or have you heard nothing?

Councillor Mary Lanigan: At the moment, they are telling me that they have no extradition powers or ways of bringing these people to account.

Baroness Hodgson of Abinger: It might be interesting to pick up on whether we have the right levers.

Mr Ward, have the lessons from the HSE attack been discussed with NHS leaders? What are the key lessons for them, and have you seen any evidence of this being picked up on?

John Ward: I am not party to any discussions with the NHS, but there are discussions with some of our colleagues in Northern Ireland. We meet regularly with Dan West, the chief digital information officer, and we have discussed some of these topics. So in terms of the NHS, there have been wide discussions.

In terms of learnings, for wider organisations, me being here is part of our wider consultation. We have gone very public with our findings. There is the post-incident review that I mentioned at the start. There are eight recommendations in that for other organisations; there are 245 recommendations for the HSE.

There are a few headings that I will read out, because it might be helpful. The first is “Learnings for other organisations”, which includes technology dependency and governance; ensuring that technology is a board-level priority; and ensuring that sufficient investment in technology is maintained, because cyber threats must be continuously mitigated with ongoing investments; reducing legacy in your estate; and making sure that you have modern software and not old software, which tends to be more prone to cyber intrusion.

The second is “Cybersecurity strategy and leadership”. The HSE did not have a CISO—a chief information security officer—in place, so cybersecurity was not dedicated to one individual who is accountable for protecting the organisation from cyber threats. If the organisation does not have that, someone should be appointed.

The third is “Ransomware-specific assessment”—testing your environment for simulated ransomware attacks and how you would respond. We have the playbooks on how you respond to those.

The fourth, which Sarah has also mentioned, is “Effective cybersecurity monitoring and response”. This is endpoint protection to secure every device on your network—as far as possible; there may be some hardware devices that cannot run this sort of thing, such as IoT devices, but 99%-plus of your environment must have endpoint protection that allows you to spot activity on the environment and any rogue actors running well-known attack vectors. This exists today and a lot of people have invested in it.

The fifth is “Testing of cybersecurity capability through simulated attacks”. There are organisations out there that do ethical hacking and will come in and simulate being threat actors and test your defences. They will do scoping; you do not know when they are going to hit, and they will effectively test that something is secure. I would encourage people to look at that.

The sixth and seventh are “Cybersecurity-specific incident response and crisis management plans” and “Business continuity planning and IT disaster recovery planning for a ransomware scenario”. A lot of organisations have them maybe for power outages and storms, but have you factored in the fact that cyberattacks are now critical business continuity events that you might have to respond to?

The last is “Retained incident and crisis support”—making sure that you have the right people on call and are not relying on the good will of others. There are organisations that are experts in this field and whose job is to protect you and help you go through and respond to a crisis in a very planned and co-ordinated way.

Those are the eight recommendations, at a summary level but a level that is quite detailed on what organisations should do.

The Chair: Can I alert the committee to the fact that Councillor Lanigan has to leave promptly at six o’clock in order to catch her train, so I ask people to be as succinct as they can?

Q21            Viscount Stansgate: Thank you for coming to give evidence, and I hope that you get your train back without any difficulty.

In the light of your experience and the experiences that you have lived through, do you now think, on reflection, that it should be mandatory to report the fact that you have had a ransomware attack rather than keeping it quiet? If it was mandatory, who would it be best to report it to? I would be interested to hear from all of you.

Councillor Mary Lanigan:  With hindsight, I do think it must be reported, because it helps your staff, your residents and everyone out there. We were getting children’s services and people phoning up who had not got their benefit payment, or whatever it was, because we had kept it under wraps. People knew that there had been an attack but not how serious it was—not that it had wiped out all our systems.

Local government needs to be open with residents. This was a criminal act and the police and everyone got involved, but if it happened to us again I would question why the Government were saying to me, “Don’t tell anybody, Mary”, because I do not think that was helpful. Going forward, I think we need to be more open.

As tight as our system is now, I cannot guarantee that this will not happen again; nor do not think that any local authority, business or anyone else can. We need to be out there saying that this has happened. The HSE did that and the Irish Government went out there and said what had happened. Perhaps if we had done that, we would have got a key. Would we have used it? I do not know. Would we have got some of the systems back sooner? We do not know, but if it ever happened to us again, I would go public.

Viscount Stansgate: Thank you. What about your experience? If you did report it, who should it be reported to, and in what order?

John Ward: In our case, the full transparency worked. We had a very good outcome. I cannot imagine us keeping it secret.

The other conversation around keeping it quiet is that it may impact your ability to get the investment in the mitigating controls that you need if this is brushed under the carpet. Do companies that are experts in these domains also go undercover, which then creates a non-transparent market? My view is to be transparent and open, making people aware of what is going on. It is criminality. You are a victim. My recommendation, if I was doing this all again, is to let people know that a crime has been committed against the organisation.

Viscount Stansgate: Sarah, what is your view?

Sarah Stephens: Certainly it is for government to decide whether businesses or public sector entities should have to report an incident and to whom. Our observation is that most incident response professionals in the UK recommend that businesses report through Action Fraud and to local law enforcement in some cases. The response they get is mixed. In some cases, a local police officer turns up at the door of a small business in the middle of an incident offering to help but unable to offer any meaningful assistance. In some critical national infrastructure sectors, we see assistance from the NCSC and the NCA, which is helpful, but primarily private entities fend for themselves.

Q22            Viscount Stansgate: My brief follow-up question, knowing that you are pushed for time, is: what is your assessment of the UK Government’s response to the problems that you went through? Is there anything that they should have done differently?

Councillor Mary Lanigan: It was not good, financially or in terms of the secrecy. Things could be changed. It was the first time this had happened to us. You take advice from central government and the security guys who come in, but it did not work out very well for us. It was a criminal act. If central government is going to step in financially, make sure that you get that in writing. As for the other point, go public; get it out there.

Viscount Stansgate: That is very clear. Thank you very much.

Q23            Baroness Neville-Jones: The Department for Levelling Up, Housing and Communities has delegated responsibility for cybersecurity among councils like yours. Do you feel that you get any guidance? Do you have an active relationship with that department on cybersecurity matters, or do they just leave it to you?

Councillor Mary Lanigan: They tend to leave it to us through the LGA. We tend to liaise with all the other councils. Because of the cyberattacks that we have now, it would be helpful if central government gave further guidelines and a general view, so that we could discuss things going forward. I do not think central government is very helpful.

Baroness Neville-Jones: Is there any particular area where you would welcome the guidelines and the support?

Councillor Mary Lanigan: We got from them that we were fine. We passed all central government’s tick boxes saying that there was no issue, but there obviously was an issue. When they had a look at us, there were certain issues, particularly having everything clumped together in one place.

Baroness Neville-Jones: Your firewalls were increased, were they not?

Councillor Mary Lanigan: Yes, so when they hit you, they take the lot out. It would be beneficial for central government or some department to say that to mitigate what is going on you need your systems in different places, so that when you are hit, only one is affected. We have tried to get that out across the country. I do not think that central government and local authorities are at the top of their game.

Baroness Neville-Jones: What about recovery plans? Did you have one?

Councillor Mary Lanigan: Yes, they were excellent and talked us through everything. However, speaking to local authorities, I do not think they are all aware of the recovery plan and where to go when these things hit, or to make sure that they do not have systems such as those that Redcar and Cleveland Borough Council had, where they could have lost everything.

That needs to get out there more. Everybody needs to say, “Look at your systems. Do this, do that”. It has been a learning curve, but we can help everyone else through our experience, because it was absolutely devastating.

Baroness Neville-Jones: Thank you for being so open.

Q24            Lord Snape: Sarah, based on your dealing with your clients, can you share your reflections about the experiences of UK ransomware victims?

Sarah Stephens: I am really sobered by the reflections that Mary and John have shared about their experiences. Clearly, businesses and public sector entities struggle to marshal all the resources that are required to contain, investigate and recover from a ransomware incident. Often, as we have heard, it is not possible to do this with internal resources alone.

Our other observation is that many business leaders have not been through a ransomware incident before, so knowing what to do and having the muscle memory of having gone through an incident previously is not there. Entities that have a cyber insurance policy can lean on all those curated ecosystems of incident response providers to be right there for them.

We have seen that where you have a practised incident response plan and all the support in place, it is a smoother experience. You do not feel so alone, and the recovery can proceed. A relatively small percentage of our clients who are based in the UK in 2022 experienced ransomware incidents. The claims amounts are still developing, but, so far, we have found that about half of those who had a ransomware incident and had an insurance policy received a full limit pay-out from that insurance policy. With the others, it is not because there was a claim dispute, but because the size of the incident was not as large. Therefore, we can really see where having that insurance helps you not only with the mechanics of incident response but with the financial burden.

Lord Snape: Are most of your clients from the public or private sector?

Sarah Stephens: By and large, they are from the private sector. We have talked about the challenges for public sector clients in procuring cyber insurance. It is because of the ability to direct resources to implementing controls in a fulsome manner, and then to get the appetite of an insurance company. Because of the sensitivity of the services and the information they hold, it is more difficult for public sector clients to purchase cyber insurance that it is for private sector clients.

Lord Snape: You have heard the conflicting experiences of your two panel colleagues. Do you think that what happened to Councillor Lanigan’s council is typical in the public sector? I presume that it was the Home Office that you initially approached, Councillor Lanigan. In my experience, the Home Office resent the weather forecast, let alone going public on anything else. Councillor Lanigan’s council went through this experience and yet Mr Ward’s view is that the more open you are about these things the better. Is that a reasonable summing up of what you said?

John Ward: Yes, absolutely.

Lord Snape: In that case, what would you advise?

Sarah Stephens: We advise our clients to report to appropriate law enforcement. From there, it is up to their advisers to help them understand whether going public or continuing to maintain confidentiality will help them to achieve their desired outcome. Some of our clients, when they experience an incident, know immediately that they will never pay a ransom. Others are more open to that possibility if they see that as the best way to recover their business. I do not know that we have observed that transparency and being public about that decision-making process makes a major difference.

Q25            Baroness Anelay of St Johns: I thank all the witnesses for their graphic evidence. Sarah, you mentioned that your clients are predominantly from the private sector. Does that include the voluntary sector, charities, companies that are limited by guarantee? Have you had any experience of the impact on them?

Sarah Stephens: I do not have any anecdotal experience that I could share with you about that sector. We have some clients in that sector, but I would have to research it. I am happy to come back to you in writing.

Baroness Anelay of St Johns: I would be grateful, given the implications for the resources that one needs to be able to recover from an attack.

Lord Snape: Just one last question to Sarah. Would your advice in general be to keep schtum or to publicise?

Sarah Stephens: I would have to understand the goals of the particular client and what they hope to achieve in response to that incident. In the US, for example, we have seen mandatory data breach reporting, so there is an element of sunshine in every major data breach incident in the United States. Yet they continue to occur. Again, anecdotally, I would not say that public reporting requirements have reduced the underlying crimes. Have they then allowed more information to be shared with other potential victims so that they can learn from those case studies? Absolutely.

Q26            Baroness Crawley: Picking up on what you have just said, Sarah, we have been given figures in our briefings showing that the number of cyberattacks in the United States has plateaued compared with Europe and the Far East. Maybe there is something in this transparency argument.

Sarah Stephens: There might be. I would also posit that there is a virtuous circle in risk management that can be driven by the cyber insurance industry. We know that the take-up of that type of insurance is much higher in the United States, so the security maturing of organisations tends to be higher as well. Therefore, another plausible explanation could be that this information, through understanding claims and understanding how to harden security defences, has something to do with that too.

Q27            Lord Butler of Brockwell: Going on to the general state of the availability of insurance and the profitability of it, can I throw a couple of statistics at Sarah? We have been told that in the United States, the loss/premium ratio has increased. In other words, losses have been going up in relation to premiums, largely as a result of ransomware. Also, certainly until 2019 there was a limit on the amount of insurance that the industry was prepared to advise. The figure that we have been given is $750 million. I do not know whether that is still the figure.

Given those two statistics, can you give us your general observations on the state of the industry and the insurance services that are available?

Sarah Stephens: Yes, absolutely. The background is that cyber insurance in some form has been available on the commercial market since about 2000. It is not brand new, but, as I said, initially it was more prevalent in the US. Since then, it has expanded to most regions in the world.

Over the first 15 years or so of this product being available to customers, we saw a relatively steady expansion of coverage. It started off as really niche insurance that was available for businesses that were engaged in this new thing called e-commerce. It then continued to get broader and broader.

The advent of data breach disclosure laws and the response of the plaintiffs bar in the United States to those disclosures—making data breach claims really expensive, and the proliferation of those data breach notification laws—started to expand the market further. The increasing digitisation of every industry then made business interruption and ransomware relevant again.

We saw the premium volume grow and grow. Then, in 2018 and 2019, there was a real change in the underlying threat as ransomware variants started to explode, particularly the prevalence of ransomware as a service, meaning that anybody could get into the ransomware game without needing the technical skills. We suddenly saw a spike in cyber insurance claims related to ransomware incidents. They were more frequent and more severe.

There are levers that an insurance company can pull when they see a spike in claims. They can change their focus on the controls that they require from insurers, they can reduce the capacity that they give out, they can require a higher deductible, and they can make the prices higher.

We started to observe the change in the market for cyber insurance in the fourth quarter of 2019 in response to that change in the types of claims and the underlying threat. We look at our data and measure each quarter. Did companies that bought or renewed their insurance in that quarter have a price increase or a price decrease? For every quarter since the last quarter of 2019, we have observed a steady price increase year on year.

We do not have data for the fourth quarter of 2022 available yet, but when I look at the third quarter of 2022, 90% of our clients paid more for their cyber insurance than they did the year before, and the average price increase that they paid was 50% more than it was the previous year. Believe it or not, that was better than the quarter before, when the average price increase was 70%.

I can answer any other questions about the market, but we are starting to see some indicators, which typically precede a softening market, in the form of more competition and more capital flowing into the market. Although I would not speculate on what prices might do in the future—those are subject to the threat and the types of claims that come in—we are seeing signs that the insurance market might soften for this type of insurance.

The Chair: Councillor Lanigan, as you have to get a train, would you like to slip out now while we are in the middle of a question about insurance? Thank you very much for coming. The committee has much appreciated it. Your evidence has been very interesting and very pertinent.

Councillor Mary Lanigan: Thank you very much for letting me explain to you what was happening. If you do not mind, I will go, because it will be 11 pm before I even get within striking distance of home.

Q28            Lord Butler of Brockwell: Are there particular sectors that have great difficulty in getting insurance or for which the cost is particularly high?

Sarah Stephens: There are, and there is considerable variation, even within a particular sector—in the cybersecurity maturity, the claims experience, in the resources that can be dedicated to preventing cyberattacks. However, a few sectors are typically perceived as harder to insure, for a variety of reasons.

I would say that the top five most difficult sectors—in the perception of the risk takers, which again is not us; it is the insurance companies—are: the public sector, for some of the reasons that we have already talked about; communications, media and technology, again because of the critical infrastructure nature of a number of those firms; healthcare, because of the need for open infrastructure, the criticality of the availability of systems and, of course, the sensitivity of data; aviation—the difficulty is often attributed to a lot of legacy technology that might not be as reliable as more modern technology; and, finally, hospitality and gaming, often again because of the sensitivity of information.

Lord Butler of Brockwell: These are the sectors where insurance is more difficult. Are there any for which it is simply not available?

Sarah Stephens: The only sectors where insurance in this segment is almost completely unavailable are things like pornography. An insurer may have a complete prohibition against a particular segment. It is the sort of sin sectors, I would say, that are often uninsurable.

Q29            Lord Butler of Brockwell: I am going to ask a question that I do not understand myself. It is about cyber reinsurance. Is that currently sufficient to meet the impact of a major systemic event? I hasten to say that I do not know what cyber reinsurance is.

Sarah Stephens: Shall I offer a small primer on that before I answer the question?

As I said, I am part of Marsh, which is part of Marsh McLennan, which is a larger organisation that specialises in risk, strategy and people. One of the sister businesses to Marsh is Guy Carpenter, which is one of the largest reinsurance brokers in the world, so in anticipation of your question I consulted with my colleagues in Guy Carpenter.

Generally, insurers, when they are providing capacity to a bank, another insurance company or a retailer, buy some form of reinsurance. There are two types of reinsurance. One is called facultative, which means that when a particular risk is really challenging, they want to reinsure part of that risk; they do not want to take it all net.

The other type is called treaty, which means that across their whole book of business they put various instruments in place to transfer on some of that risk. There are a couple of types of treaty reinsurance. A lot of insurers now buy for their cyber insurance portfolio a specific treaty that is dedicated to transferring on some parts of the cyber risk portfolio. There are different ways of doing that, but a lot of insurers renew that programme on 1 January, so that has just happened.

We have seen a lot of consternation in the insurance market and the reinsurance market over a number of issues. At 1 January, insurers were largely able to purchase the amount and the type of reinsurance that they wanted, so this is not a market that is near failure or collapse. However, many insurers are concerned—based on scenario modelling, which is generally a combination of objective data and expert judgment, because these are newer sorts of scenarios; we do not have hundreds of years of past data to look back on—about the possibility that a catastrophic cyber incident could exceed the value of the books of business and therefore lead to failure.

So there is a lot of discussion in the reinsurance market about how insurers are protecting their portfolios from those perceived catastrophic risks. One of those risks is state-backed cyberattacks, which has got some press in the UK insurance market recently.

Lord Butler of Brockwell: Thank you for that very lucid explanation.

Q30            Stephen McPartland: Sarah, are there any levers that the Government could use or implement to help the insurance market to develop it?

Sarah Stephens: There are three things that we would encourage and support. Number one is greater use of the cyber insurance market itself. I say that, because it is an efficient mechanism for delivering risk management advice and creating an incentive for companies to put that advice into practice, and for supporting particularly smaller businesses in incident response and making sure that they have everything they need to get through the incident. Ultimately, if there was to be a catastrophic incident that affected many UK businesses, the insurance industry is an effective vehicle to get liquidity back into the economy and, ultimately, improve resilience.

The second thing is more transparency around the size and scope of incidents. One idea that has been posited recently by those in the insurance market is the need for an event classification system, so that there is an objective view of how bad a cyber incident has been across various businesses or across a segment, or indeed across a country. Support for such a scheme could pave the way for two-way communication that is greatly improved between government and UK businesses as they experience incidents.

Thirdly, Marsh would be supportive of a well-constructed government cyber reinsurance or back-stop mechanism that was extremely targeted to the aspects of cyber-risk scenario which the private markets currently think or might think are uninsurable in the future. Right now, we have seen relatively broad support from the reinsurance market to give insurers what we call the back-to-back coverage that they want. However, if that gap starts to widen and insurers cannot purchase enough reinsurance for the most concerning scenarios that ultimate buyers want to buy coverage for, we might see confidence drop a bit. So we think that is a possible way of really fuelling the future growth of the insurance sector and therefore getting the real benefits of cyber insurance in the hands of more UK businesses.

Q31            Stephen McPartland: I will quickly come back to some of the things you said, and then ask a supplementary.

On the cyber market, there is a suggestion, although there is not enough research to state this, that some companies are concerned about having cyber insurance because they feel that that would put them on a target list; that if those insurers have paid out in the past, the companies could then be targeted because the insurers know they will get a claim.

On transparency, there are lots of arguments about the figures, but around 50% of all crime in this country is economic crime and only 1% of police resources are used to deal with it. So there is a feeling among businesses, as has been evident from the evidence today, that they are very much on their own and that it is seen very much as a civil rather than a criminal situation unless it is an attack on a major infrastructure. So when you talk about transparency in the cyber market, you are dealing with businesses in a customer portfolio that do not really trust anybody to help them.

Sarah Stephens: It is important to build trust. When a company goes through a cyber incident for the very first time, it has to put quite a lot of trust in the advisers it is connected to via its insurer, and, often, put a lot of trust in the insurer itself. That trust is forged by speaking with those third parties and getting comfortable. We often sit around a table and practise an incident before it happens. That trust is often there, and it is forged in the midst of an incident, but unfortunately our experience has been that our private sector clients’ trust and their expectation of support from the UK Government have not been there.

Q32            Stephen McPartland: On the gap that you mentioned, how effectively do our regulators, such as Ofcom and the FCA, help to shape cyber resilience?

Sarah Stephens: Again, the resilience of the insurance market itself and the ability to continue on as a sector that can support companies when they have an incident and to drive the best risk-management practices are, in part, the function of regulators: that is, to ensure that there is a vibrant industry that can function exactly as it is supposed to to provide a lot of that intelligence.

Q33            Lord Dannatt: This is probably the shortest question, and you may already have answered it. Did the HSE have insurance before the attack, and have you taken it out since?

John Ward: The HSE is covered by the state, so, in relation to the response to cyber, I do not think we had specific cyber insurance. I am not privy to whether we have insurance now. I may come back with a written answer to that.

Lord Dannatt: I feel that I am slightly prying, but it is an obvious question. I would have asked Councillor Lanigan, but she is on a train.

John Ward: I can come back in writing to confirm.

Q34            The Chair: We can probably hazard a guess as to what Councillor Lanigan’s answer to this question would have been, because of what she did.

There has been a call in some quarters for the Government to ban ransom payments. I would be grateful if you could each give your view on such a call. Would that be a good idea?

John Ward: Every situation probably requires a different response. On the day of our attack, our Taoiseach clearly said that there would be no ransom payments. In other circumstances, who knows? An outright ban would be difficult to enforce and might create a black market in ransomware, pushing people down a criminal route in doing things that they know are against the law. I cannot imagine a circumstance where the Irish state would do that, but it is a very complicated situation.

Our situation was very transparent because people were visiting healthcare settings and it was obvious that something was wrong. We were very public in our response. However, the circumstances for private companies and individuals might be very different.

Sarah Stephens: Banning the payment of ransoms is for government, not us, to advise on. I would frame the issue slightly differently and ask whether cyber insurance encourages more crime and encourages more criminals to attack companies that they know have or might have a policy.

Our view is that cyber insurance and the knowledge that it exists helps companies so much with the preparation and to think through what criteria we would use to decide whether to pay a ransom. That itself makes companies more resilient and potentially less likely to be forced into a corner where they think that they must pay the ransom.

Furthermore, because cyber insurance also covers all the incident response costs and the business interruption, which, as we have heard, can be really significant—it can take up to a year for the business to fully recover—the insured entity knows that it can fall back on that insurance to ensure that its business continuity is a bit smoothed financially. It is therefore less likely to pay that ransom, even when the ransomware bad actor says, “I’ve seen your insurance policy and I know that you can pay.”

The Chair: Thank you all for giving evidence to us today. It has been very helpful.


[1] Note by witness: It took HS four months to recover to 99%.