To Recap
The British Library:
- used unsupported, unpatched software as critical infra
- used multiple IT vendors with varying levels of access
- lacked sufficient in-house staff to coordinate a proper security policy
- lacked resources (or leadership, probably) to appropriately fund an infrastructure refresh program
- launched remote access during COVID WITHOUT MFA
And although we cannot say for sure that the Terminal Server was the point of access, it's a good dang bet. Rhysida works smarter, not harder.
As usual, the reality of defense is not sexy malware research. It's not breathlessly shouting about patching 0-days. It's the quotidian work of getting the basics right, not taking shortcuts, and making security—across the CIA triad—a budget priority.
In cultural and educational institutions, it is very common to think of IT systems as an afterthought, or ancillary to the primary mission. These institutions maintain this mentality at their own considerable risk. This extends to the governments and organizations who fund these institutions.
Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
Taggart :donor: (mttaggart@infosec.town)'s status on Saturday, 09-Mar-2024 18:52:53 JSTTaggart :donor: