Articles & Research

Analysis

WannaCry: what a ransomware worm taught the profession about patching

A ransomware worm that exploited a known, already-patched Windows flaw disrupted hospitals worldwide and made patch management a governance issue.

Priya Nakamura

Cyber Policy Correspondent, American Computer Society

May 2017 · 7 min read

Analysts monitoring threat dashboards in a security operations centre
Analysts monitoring threat dashboards in a security operations centre

WannaCry spread to more than 150 countries in a matter of hours, and its severest real-world impact fell on health systems still running unpatched Windows machines. The Society revisits the incident as a lesson in operational responsibility.

A worm, not just ransomware

On Friday 12 May 2017 the WannaCry ransomware began spreading globally, encrypting files on infected Windows machines and demanding payment in bitcoin. Unlike most ransomware of the era, WannaCry propagated itself as a worm, using EternalBlue, an exploit targeting a Windows Server Message Block vulnerability that had been developed by the US National Security Agency and leaked by the group Shadow Brokers the previous month.

Microsoft had already released a patch for the underlying vulnerability, MS17-010, on 14 March 2017, two months before the attack. Machines that had applied it were not affected. The spread was halted within hours by security researcher Marcus Hutchins, who identified and registered a domain acting as the malware's kill switch, though variants without the same kill switch continued to circulate.

England's National Audit Office later reported that WannaCry disrupted at least a third of English NHS trusts, affecting appointments and, in some cases, forcing ambulances to divert and emergency departments to close, even though the NHS was not specifically targeted.

“WannaCry did not exploit an unknown flaw. It exploited the gap between a patch being released and a patch being applied.”

Why healthcare was hit hardest

The NAO's investigation, published in October 2017, found that the NHS had been warned about the risk of exactly this kind of attack in advance and that critical patches had not been applied consistently across trusts, many of which were still running older Windows versions on clinical equipment. The episode illustrated a familiar tension in safety-critical environments: patching can require taking devices offline, which clinical and operational staff are often reluctant to do without a maintenance window.

WannaCry's global cost has been estimated in the billions of dollars once lost productivity, remediation and disrupted services across manufacturing, logistics and healthcare organisations — including FedEx, Renault and Telefónica — are accounted for.

A known fix, an unpatched estate

The defining lesson of WannaCry is not that a novel technique defeated defenders, but that a fix existed and was not applied broadly enough, quickly enough, in environments where the consequences of compromise were most severe. That gap between patch availability and patch deployment remains among the most common vectors in large-scale breaches years later.

What the Society advises

The Society treats patch management as a matter of professional accountability, not merely IT hygiene, particularly in safety-critical and healthcare settings.

  • Maintain and act on an asset inventory of all networked systems, including legacy and clinical equipment.
  • Set patch deployment timelines proportionate to vulnerability severity, with executive sign-off on exceptions.
  • Build maintenance windows into operational planning rather than treating patching as an afterthought.
  • Report unresolved, high-severity vulnerabilities up the accountability chain, including to boards where risk is material.
CybersecurityPublic policy

Join the professional body behind this work

ACS members receive our research first, free CPD and ethics modules every year, and a route to professional registration assessed by their peers.

Become a member