RAN0002

Written evidence submitted by Andy Jones

 

Introduction

I am the former Chief Information Security Officer for the Danish company Maersk and was in post when Maersk was attacked by NotPetya in 2017. Since that time, I have regularly presented to various industries on how to manage an attack of this nature, including most of the UK banks, the insurance sector, transport, and many other sectors. I have also published articles, podcasts[1] and contributed to academic literature[2] on this topic.

I continue to do so, even five years after the incident.

I am currently a senior visiting lecturer in cyber security for a UK university.

Background

While NotPetya is technically not ransomware, it has most of the ransomware characteristics, and this experience will be relevant to the scope of the committee.

The NotPetya attack in 2017 was noted by industry commentators as “the single most expensive computer incident in the world.”[3] and impacted several corporates in the UK, as well as Ukraine. While Maersk is a global company headquartered out of Denmark, the IT and cyber security functions were based largely in the UK and the technical aspects of the incident were managed out of the UK office.

This submission is a personal reflection of the first-hand experience of a significant cyber attack that disabled a major multinational for several weeks.

Summary

Inevitably the focus of a ransomware attack is on the technical aspects of the attack and recovery. I contend that this is the least important aspect of a ransomware attack and that an assumption should be made that technology will ultimately fail to stop these attacks.

While core cyber hygiene remains important, attention should be redirected to establishing true resilience in core systems and on being well versed in recovery procedures. In short, assume that an attack is likely to succeed.

Technology

The sophistication of ransomware attacks usually exceeds the sophistication of corporate defences. In the case of NotPetya, the origins of the attack lie with nation states, including the USA and Russia, whose skills and resources exceed those of any corporate. They are often based on zero-day principles, but even those that exploit known vulnerabilities can be successful in attacking large corporates.

Large corporates are complex. They may have hundreds of thousands of devices and complete 100% patching of those devices is simply not achievable, with even the most diligent corporate having many hundreds of devices on their network that may be vulnerable to an attack.

Criminals are also able to purchase ransomware as a service, and do not need a high level of technical competent to launch a substantial and sophisticated attack.

The most typical question that I get asked about from a technical point of view is “What (technical item) did you put in place after the attack?” My answer is that that is irrelevant, and with hindsight, you could put in place perfect technical defences that would have prevented the attack. However, the next attack will use a different novel method, and you would have wasted your money.

The corporate impact of an attack

An attack is only partially a technical event. There are significant business operations implications which extend far beyond the IT environment. This is amplified by a rush to digitise operations through Internet of Things connectivity and creates a critical dependence between functioning IT and Operational Technologies such as production facilities.

However, an attack also poses significant challenges to legal and communication functions and these areas need active management during and after an attack.

From the legal point of view, at the time of the attack many legal and regulatory obligations will have been breached. Many financial controls will have been rendered inoperable and potentially vulnerable to exploit by opportunists. Managing those breaches (potentially across the globe) is a significant legal task, added to the potential legal impact of breaches to commercial contracts. This requires close cooperation between cyber security and the legal function, as the nature of the attack and implications may be alien to the legal function.

Communication during an attack is vital to protecting the reputation of the company and there many examples of poor communication making an attack worse for a company. Transparency and honesty are often the best strategies. Managing communications, when your own communication mechanisms may have been rendered inoperable by the attack, is an active task requiring engagement with the cyber security function, who can help to build an understandable picture of the attack.

People

The recovery of Maersk from the NotPetya attack is often described as being people-led. This was partially out of necessity as this was the main resource that we had, but also because large organisations are really run by people who really know how the business works and how to keep it afloat in the case of adversity. This important aspect is eroded by the ongoing rush to digitalisation.

Jim Snabe, the Chair of A. P. Moller-Maersk, speaking about the NotPetya attack, noted that “…in the near future, as automation creates near-total reliance on digital systems, human effort won’t be able to help such crises”.

 

An attack of this nature can be traumatic for people, as it is sudden and absolute, taking a large corporate from the modern day, back to a pre-compute era of the 1950s in mere minutes, and give the workforce real uncertainty in their employment prospects. All this needs to be managed, especially in the recovery centre, where employees will be working long and unusual hours.

Some employees will be taking decisions that are beyond their normal pay grade, and attitudes to risk will be significantly different during an attack. Some people will excel, some will fail and again this all needs to be managed carefully and sensitively.

Ransom payment

While the NotPetya attack proved not to be ransomware, it did initially appear to be as such. For a large corporate paying a ransom is not usually an attractive option. Aside from the moral and ethical issues the practicality of obtaining tens of thousands of decryption keys and applying them to devices spread across the globe is simply not practical or effective. Additionally, there would be ongoing doubt about whether the data had been accurate restored, or whether malware remained within it.

Paying a ransom will inevitably invite other copycat attacks, and some sectors that have paid ransoms see this as an ongoing trend[4]. Whether payment of a ransom should be made illegal is an ongoing debate but would undoubtedly reduce the attractiveness of ransom attacks to criminal enterprises – noting that they would likely find an alternative method to preserve revenues.

The role of intelligence

There was no intelligence related to the possibility of the NotPetya attack. Indeed, Danish intelligence had issued a report before the attack, noting the likelihood as low. Intelligence services were not useful during the attack for the simple reason that, for a zero-day attack, the victim is the most knowledgeable entity about the attack (barring the attackers).

Cyber insurance

Cyber insurance is a young market and evolving significantly. Of interest are the occasions related to NotPetya (Mondalez vs Zurich insurance and Merck vs Ace American Insurance), which have only resolved some five years after the incident. Notably neither policy was classified as cyber insurance.

Learnings

There is a propensity to believe that technology and standards are the solution to the ransomware menace and they both have a role in reducing the impact of attacks. However, particularly for a large company the sheer complexity and dynamic nature of a modern business means that they will never be 100% compliant with standards or with patching, and there will always be points of weakness.

Some observations:

 

30 November 2022


[1] https://soundcloud.com/andy-jones-55

[2] Cyber Security and Supply Chain Management – World Scientific 2021

[3] Mikko Hypponen in The Register 2018

[4] https://news.sophos.com/en-us/2022/06/01/the-state-of-ransomware-in-healthcare-2022/