Realizing digital in wealth management | KPMG | TT

Global Ransomware attack - Is your Organization at risk?

Global Ransomware attack

Last Friday May 12, 2017, the unthinkable happened.

Is your Organization at risk?

Hundreds of thousands of computers in over 150 in countries experienced a ransomware attack where the WannaCry malware started taking over users' files, demanding USD 300 to restore access.

Among the organizations targeted worldwide have been Germany's rail network Deutsche Bahn, Spanish telecommunications operator Telefonica, US logistics giant FedEx and Russia's interior ministry. Also among some of the hardest hit on Friday was the UK National Health Service, where patient medical records were made inaccessible, forcing hospitals to divert patients and even cancel surgeries.

The cyber-attack has been attributed to the fact that hackers were able to exploit a vulnerability in the Microsoft Windows operating system, for which Microsoft had issued a patch back in March 2017.

At KPMG’s Cybersecurity breakfast seminar held in April 2017, “Missing the Basics”, for example, not applying a simple security fix on an overlooked server, was identified as one of the vulnerabilities that can negatively impact business operations. This reiterates the importance for organizations to maintain vigilance with respect to increasing their level of awareness and re-assessing their Cybersecurity strategies. 

What should be done immediately?

Organizations should ensure the following are performed in a timely manner:

  • Patch Windows systems in your environment (following proper testing for production servers, to ensure any changes do not cause any disruptions to business operations).
  • The patch was released in March 2017 as part of MS17-010 / CVE-2017-0147;   
  • Verify that all Windows systems have an anti-virus program and that it is up-to-date.
  • Inform staff to be on the lookout for emails with suspicious attachments and/or links.  Staff should notify IT Management if a suspicious email is received;
  • Maintain up-to-date backups of critical data.

 

How KPMG can help?

KPMG has dedicated Cybersecurity professionals and can help you identify your strengths, weaknesses and develop an action plan to thwart future attacks. We offer the following services to assist you:    

Incident Response: KPMG has developed a cyber operations and incident response program to help clients respond to cyber attack including services such as post breach investigations.

  • Cyber Maturity Assessment: KPMG professionals will assess and benchmark your organisation on six key areas of Cyber Security and will consider the security, availability and confidentiality of sensitive data.   
  • External Penetration testing: KPMG professionals will test your network perimeter and identify weaknesses before hackers do. We will examine your email systems, firewall, Web servers and other externally exposed systems. 
  • Employee awareness training sessions: KPMG professionals will provide your employees with knowledge on how to protect your assets and how to identify and thwart common attacks they may be subject to.
  • Business Continuity Management: KPMG professionals can assist you develop and implement sustainable business continuity programs that will evolve and adapt to address the ever-changing risk landscape with which we are faced. 

Connect with us

  • Find office locations kpmg.findOfficeLocations
  • kpmg.emailUs
  • Social media @ KPMG kpmg.socialMedia

KPMG's new digital platform

KPMG International has created a state of the art digital platform that enhances your experience, optimized to discover new and related content.

 
Read more

How we can help

We bring together diverse specialists to tailor a solution relevant to your risk appetite and the cyber threats your organization faces.

 
Read more

Cyber & e-Crime - Why KPMG

KPMG member firms are global, award-winning, committed to our clients and at the forefront of the cyber agenda.

 
Read more

Learn more about our Cyber Security Services.

Learn more about our Cyber Security Services.

 
Read more