RAN0035
Written evidence submitted by DXC Technology
Introduction
DXC Technology makes public services possible. We are proud to deliver data-driven innovation and insights across the UK public sector, including for the UK Government. We enable sustainable answers, at scale, to some of society's greatest challenges. We deliver key public services across government departments across the world, for all communities and citizens. Our public service work is underpinned by a commitment to social value and environmental responsibility.
DXC helps global companies run their mission-critical systems and operations while modernising IT, optimising data architectures, and ensuring security and scalability across public, private and hybrid clouds. The world's largest companies and public sector organisations trust DXC Technology to deploy services that drive new levels of performance, competitiveness, and customer experience across their IT estates. With 130,000 people in over 70 countries, we are well-placed to solve some of the most complex challenges.
We ourselves experienced a ransomware attack in July 2020, and we are happy to share our experience with the Joint Committee on the National Security Strategy’s call for evidence. It is worth noting that, as a global company, we were compromised through the exploitation of a vulnerable system abroad. UK legislation in this area is notably weak. We also assist number organisations in dealing with the consequences of such attacks and therefore these topics are a summary of both our own and those experiences.
The following topics will be addressed:
• The extent and nature of the ransomware threat, modes of extortion, and how the threat could evolve
• Levels and sources of vulnerability of UK organisations
• The UK victim experience
• The response effectiveness by Government and other agencies
• Reforms that might enhance resilience
• The scope for international cooperation
• Lessons that can be learned from international approaches and responses
DXC Ransomware Attack
Our responses will be addressed through two primary mechanisms: the lived experience of our own ransomware attack in 2020, and by the lessons we have learned to keep our supply chain protected since that event.
On July 4th, 2020, a subsidiary of DXC, Xchanging, was subject to a ransomware attack. Xchanging provides technology-enabled business services to the commercial insurance industry. Indeed, it plays an essential role in UK Critical National Infrastructure due to significant work with the London Markets. While their business is segregated from DXC’s larger IT network, our specialists were concerned about whether the incident would have operational impacts on Xchanging and the wider company. The attack took place on a Saturday, with a very real risk of operational impacts to customers when the offices opened on Monday.
Our team of specialists and experts worked through the weekend to verify that no data had been stolen, that only a handful of non-critical systems had been accessed, and that we were able to rapidly neutralise the threat. The attacker had sent the following message: “We have your data. We’ve encrypted your files. If you want to negotiate, we can talk on a secure tool or chat session”. Our work ensured that engaging with the attackers was not necessary.
On Sunday, we were able to fully clean and restore the impacted environment. By Monday morning, Xchanging was able to open as planned and process insurance policies. Critical to our success was our early engagement of the appropriate authorities and of our customers. Too often, companies suffer ransomware attacks and engage with the attackers whilst withholding the fact from the authorities and their customer base. Legal counsel often advises this caution. Transparency is vital for creating trust for the wider supply chain and ensures that other companies can learn best practice from our steps to resolve the incident.
Our President of Security, Mark Hughes, wrote a blog post shortly after the incident outlining the five key lessons we learned. These are summarised below; we will explore these in more detail.
The lessons outlined were important responsive actions. However, equally important is the need to act preventatively and proactively. For companies like DXC, we are reliant on our entire supply chain (including SMEs and government departments) implementing appropriate hygiene in their work.
Call for Evidence
The extent and nature of the ransomware threat
The cybercriminal ecosystem is becoming increasingly saturated and sophisticated. UK public services have become the victims of high-profile ransomware attacks in recent years: WannaCry, in 2017, infected over 230,000 computers in over 150 countries and had a significant impact on the NHS (exacerbated by NHS devices running the supported, but unpatched, Microsoft Windows 7 operating system). In 2022, a ransomware attack on a software supplier (One Advanced) again impacted the NHS. More broadly, on May 7th, 2021, DarkSide ransomware took down the US Colonial Pipeline and earned the attackers US$5m. In May 2022, an attack in Costa Rica resulted in government agencies declaring a national emergency after hospitals were forced to close. Microsoft, in their 2022 Digital Defence report, describes ransomware as a “nation-level threat”.
Ransomware is a threat on a global scale. Increasingly cyber-aware groups and individuals can source ransomware models with ease online and deploy them against companies and individuals en-masse. Public services across the world are especially at risk due to often running legacy IT and employing staff who, naturally, have responsibilities that preclude them from upskilling themselves digitally.
Perhaps most alarming, however, is the potential for nation-state attacks. The Ransomware Threat Assessment Model (NCSC-A/R/1197-22) identifies the 10 most prolific and dangerous ransomware strains. 8 are likely based in Russia (including Conti, regarded as responsible for the 2022 NHS attack). 7 of the 10 have hit UK sectors in the past six months, including: technology, education, manufacturing, charities, transport, legal, financial, and academia. It has long been speculated that these attacks are endorsed by the Russian Government, highlighted by increased attacks in the build up to the invasion of Ukraine (none more notable than the 2017 NotPetya attack which caused havoc for Ukrainian critical national infrastructure). Indeed, NotPetya has been described by multiple outlets as an act of cyberwar. It had worldwide impacts as unpatched systems were vulnerable to EternalBlue (an exploit also used in the WannaCry attack).
Modes of extortion are also becoming more challenging. The rise of cryptocurrency as an alternative payment, and one which is not tethered to any central bank of national currency, has created a ransom that is incredibly difficult to trace. This encourages gangs and individuals to target as many computers as possible in attacks, to maximise revenue. Extortion methods are, in turn, becoming more complex. Our personal experience, in 2020, saw the attacker gain access to a subsidiary’s minor database and use that to attempt a negotiation. The WannaCry attack saw computers themselves locked out in exchange for a payment. These forms of extortion encourage business to “lockdown” and not communicate externally, which then feeds into a cycle of success for the attacker. At DXC, we encourage businesses to learn from our experience: appropriate, prompt communication and transparency was key to our success. Indeed, we recommend this blog series on our approach to security.
Sources of vulnerability in the UK
Public and private sector organisations in the UK share wide-ranging risks. These include:
• Digital skills: There is a significant digital skills gap in the UK. At the extreme end, TechNation estimates that there two million “difficult to fill” vacancies in the UK tech sector last year. The field employed five million people in 2019. This highlights an alarming gap at even the most skilled end of technology. The same report estimates that over 12 million people in the UK lack basic digital skills. This means that employers are relying on people in their general workforce to be undertaking basic digital hygiene without even the most basic skills, creating a significant risk pool.
• Legacy technology: This is perhaps more a risk for the public sector, though cost-conscious SMEs are also at risk. Running out-of-date software on ageing hardware creates substantial risk. Indeed, computers that were still running the discontinued Windows operating system were at the centre of the WannaCry attack in the NHS. In 2020, the National Audit Office described digital transformation in the NHS as “inadequate”. Investment in IT infrastructure is needed to remove this risk, rather just focussing on mitigation by patching end-of-life hardware. These risks are increased when computers are being shared by multiple individuals with a single and shared login credential, which is often the case in public sector and manufacturing organisations where recording information is secondary to the delivery of services (an assembly plant, face-to-face appointments in a ward, etc.)
• Supply chain hygiene: As our example demonstrates, the supply chain itself is a risk for any organisation. As organisations embrace technology, which is to be welcomed, it is essential that all parts of the integrated supply chain operate effectively. The 2022 NHS attack originated in the supply chain rather than the parent organisation. Sharing training, materials, and best practice is important these situations, as well as engaging at a senior leadership team level to escalate to everyone in the organisation.
• Multifactor Authentication: Organisations may have multifactor authentication on their devices and secure portals, but it is not always enabled effectively. Whitehall departments, for instance, often have an authentication process where a provided telephone number is called once every week (in some cases every fortnight, in others once per month). This is not effective digital hygiene. Where the private sector supplies government, it is encouraged to have the highest standards of digital hygiene. However, government can be a significant risk to the private sector supply chain. We encourage government departments to consider whether they themselves are following best industry practice.
• Preventative action: Action taken by organisations and the public sector is often in response to an attack and leads to much stronger digital hygiene and processes. Phishing attacks are straightforward, with training, to defend. DXC’s PhishEd programme runs simulated attacks to educate the workforce. However, it is important to move towards a proactive approach. Incident management and contingency preparations are useful to test and rehearse. Ensuring default passwords are changed, that staff are accessing appropriate sites, have appropriate training, regular multifactor authentication, etc., will go some way to preventing ransomware attacks.
Victim Experience
Our experience is highlighted at the start of this call for evidence. Our experience is perhaps down to three key factors: hiring specialists from across industry to focus on preventative measures, but who were able to respond quickly to an emerging threat; engaging senior leadership internationally to ensure effective buy in; and being transparent to our customers and governments. Most importantly: without Endpoint Detection and Response, we encourage organisations to learn from this transparency.
Response of UK Government
Our ransomware attack was challenging for many reasons. Taking place on Independence Day weekend in the US, and a weekend in the UK when lockdown restrictions were still lifting, could have had a very real impact on Xchanging and wider DXC. However, we knew who we needed to contact in both governments, and we were supported by respective administrations. Crucially, because of our proactive relationship building, the authorities knew who contact at DXC.
International Lessons and Co-operation
This response has focussed on attacks from criminal gangs and individuals. The OECD and the UN are effectively at co-ordinating governments and large private sector companies to discuss emerging threats and how to respond effectively. The UK Government has, in turn, empowered the GCHQ, and others to engage with the private sector to continue sharing those lessons. Sharing best practice is a core part of that work; however, organisations need to ensure messages are cascaded appropriately and the wider public sector is still too much a high-profile target and risk. Current data suggests that the following order for incident rates: UK Government, IT, Health, and Finance. Organisations are prepared to accept greater risk (legacy IT, etc.) and have a higher number of incidents.
NATO has also been increasingly effective at co-ordinating lessons since the Russian invasion of Ukraine. The threat of four nations (Russia, North Korea, Iran, and China) has been apparent for some time. Other countries are, however, using their purchasing power to secure cyber weapons without the necessary controls in place. The role of nation states in cybercrime, or even nation-backed criminal enterprises, presents a much more sophisticated threat for private and public sector organisations around the world. It is essential that, however long the Ukraine conflict takes to resolve, the current goodwill in this space continues.
20 December 2022