To say I'm extremely angry over all this is a huge understatement. I was in the middle east working on IT systems last week when it broke on the news.
To be honest, I nearly flew back home the next day. This was waiting to happen! It's senior execs and top level IT directors. Seriously, some people need to lose their jobs. When local services are closing and sending staff home, someone needs to go! It's that age old saying isn't it, rubbish people either get fired or promoted.
They will say it's roots are based in cost savings, I say they waste money and are not intelligent.
The NHS has thousands of client devices, not enough well trained IT engineers, poor platforms, poor services, poor processes, poor everything.
If you can't afford to look after your environment you have the wrong environment.
Sky News have just said IT Managers are struggling to understand the scale of this. If so, they need sacking as well.
I bet 90% of their clients are unpatched xp machines running office 2003. Windows XP launched in 2001. They will argue they can't afford to spend £500 per machine plus the resources required to replace them. What year is this, 2006! Do they run weekly reports showing percentage of clients unpatched, if not why not. If they do, what are they doing about it. Don't tell me "we dont have enough time", "we dont have enough people", "not my job", "nobody told me to do that". Heard it all before. If you can't do it, use NAP and stick all the nasties in another VLAN. Who cares who shouts, at least your safe.
I've just replaced 800 windows machines for £44k...there's no excuse
So tomorrow I go into a board meeting at 9am to discuss the outbreak. We're fine, a few years ago we probably wouldn't be, but with an IT department of less than 12 supporting thousands of client devices.....we soon moved to zero terminals and beefed up the data center. Now the IT engineers patch the servers and the clients are bullet proof. Cheap to buy, cheap to run, cheap to support. Where companies require windows desktops like the companies I advise in the middle east, we do something different but always safe. You can't carry on running old operating systems which are unpatched.
and if you do get a nasty in, are your policies good enough to get your network back up and running as it was before within 24 hours?
There is a part of me that is kinda glad this happened, what a wake up call....will anybody listen...who knows.