Microsoft criticises NSA’s role in the global cyber-attack

  • 16 May 2017
Microsoft criticises NSA’s role in the global cyber-attack

Microsoft has come out in defence of its role in Friday’s on-going global cyber-attack, criticising the role of the US National Security Agency in creating tools that were subsequently leaked and then used in Friday’s attacks..

In a blog post, published by Brad Smith, president and chief legal officer at the company, on Sunday he said that the attack was enabled through National Security Agency (NSA) stockpiling exploits, rather than openly sharing discovered exploits so they could be fixed.

The cyber-attack has disrupted NHS services in parts of England and Scotland since Friday afternoon.

Smith said the malicious WannaCrypt software ā€œwere drawn from the exploits stolen from the National Security Agencyā€.

He added: ā€œThis attack provides yet another example of why the stockpiling of vulnerabilities by governments is such a problem.ā€

ā€œRepeatedly, exploits in the hands of governments have leaked into the public domain and caused widespread damage.ā€

The technology behemoth said that on 14 March it had released a security update to patch vulnerability, however many computers globally remained unpatched.

Questions are now being asked about the vulnerabilities caused by reliance of many parts of the NHS on ageing infrastructure and software.

Support for Windows XP was withdraw in April 2014 but according toĀ Digital Health IntelligenceĀ 2015 data on NHS infrastructure as many as 20% of NHS organisations could still be making use of it, and around 90% are thought to run something on it somewhere in their organisation, often in clinical systems or imaging equipment.

Dame Fiona Caldicott, speaking on Monday at the Caldicott Guardians National Annual Conference in London, referred to a letter and review sent last July on the nation’s cyber security.

It said ā€œcomputer hardware and software that can no longer be supported should be replaced as a matter of urgencyā€.

Alongside Dame Fiona’s review, the Care Quality Commission’s July 2016Ā Care Quality Commission review into cyber security ‘Safe Data, Safe Care’ also highlighted the risk posed by outdated IT systems.

In response, then life sciences minister George Freeman said: Ā ā€œWe are working with suppliers, including Microsoft, to help health and care organisations update their systems and make sure they are safe to use and store data.ā€

Smith said that Friday’s attack demonstrated how cyber security was becoming a shared responsibility between customer and supplier.

ā€œAs cybercriminals become more sophisticated, there is simply no way for customers to protect themselves against threats unless they update their systems. Otherwise they’re literally fighting the problems of the present with tools from the past.ā€

Smith compared an equivalent scenario as the US military having some of its Tomahawk missiles stolen.

ā€œThe governments of the world should treat this attack as a wake-up call.ā€

Subscribe to our newsletter

Subscribe To Our Newsletter

Subscribe To Our Newsletter

Sign up

Related News

Cyber attack cost Synnovis estimated £32.7m in 2024

Cyber attack cost Synnovis estimated £32.7m in 2024

The cyber attack on pathology provider Synnovis cost an estimated £32.7 million in 2024, company accounts filed on Companies House reveal.
Microsoft confirmed as Rewired 2025 co-headline sponsor

Microsoft confirmed as Rewired 2025 co-headline sponsor

Microsoft has been confirmed as the co-headline sponsor of Digital Health Rewired 2025, the UK’s biggest and best digital health conference.Ā 
2025 predictions: Health tech suppliers on what’s in store

2025 predictions: Health tech suppliers on what’s in store

Digital Health News asked suppliers to share their predictions about what lies ahead for the sector in 2025.

5 Comments

  • In IT getting the right people in place is far more important than the hardware and software. I use both software and DATA in clouds now, it’s awesome, it takes all the worry out of it and it’s … efficient.

    • You do know clouds can be hacked too?

      • set truthFlag=1;;

  • “Laid the blame at the NSAs backdoor”, surely…

    • Like

Comments are closed.