{"id":46824,"date":"2022-08-08T10:45:00","date_gmt":"2022-08-08T10:45:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/46824"},"modified":"2022-08-08T10:45:00","modified_gmt":"2022-08-08T10:45:00","slug":"nhs-recovering-key-services-after-attack-on-supplier","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=46824","title":{"rendered":"NHS recovering key services after attack on supplier"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/08\/nhs-recovering-key-services-after-attack-on-supplier.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>NHS bodies around the UK are still restoring services after <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/supply-chain-attack\">a cyber attack hit one of its suppliers<\/a> before the weekend, <a href=\"https:\/\/www.bbc.co.uk\/news\/uk-wales-62442127\">taking out its 111 emergency advice<\/a> line and causing disruption to ambulance dispatch, emergency prescriptions, out-of-hours appointments and patient referrals.<\/p>\n<p>Details of the incident at <a href=\"https:\/\/www.oneadvanced.com\/\">Advanced Software<\/a> continue to emerge, and the precise nature of the attack is unconfirmed, although it bears the hallmarks of a <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/ransomware\">ransomware attack<\/a>, and some sources have already claimed it as such. It is known to have begun early on the morning of Thursday 4 August.<\/p>\n<p>The biggest impact seen was to Adastra, a clinical patient management software that underpins the majority of the NHS\u2019s 111 services, but also other Advanced Software services, including its Caresys care home management service, its Carenotes patient record management service and its Crosscare clinical management service, which is used in hospices and at private practices.<\/p>\n<p>\u201cA security issue was identified which resulted in loss of service on infrastructure hosting products used by our health and care customers,\u201d said Advanced chief operations officer Simon Short in a widely circulated statement.<\/p>\n<p>\u201cFollowing discovery of&nbsp;this incident, we immediately isolated all our health and care environments and no further issues have been detected,\u201d he added. \u201cEarly intervention from our incident response team contained this issue to a small number of servers representing an extremely small percentage of our health and care infrastructure. The protection of services and data is paramount in the actions we have and are taking.\u201d<\/p>\n<p>Short said Advanced was continuing to work with the NHS and its own technology and security partners to recover impacted systems.<\/p>\n<p>Health sector publication <em><a href=\"https:\/\/www.pulsetoday.co.uk\/news\/breaking-news\/gps-told-to-expect-influx-of-calls-from-patients-redirected-due-to-111-outage\/\">Pulse<\/a> <\/em>revealed that GPs were warned before the weekend to expect heightened volumes of patients being redirected from NHS 111 following the incident, as those staffing the service were forced to turn to pen and paper.<\/p>\n<p>NHS England declined to comment on the status of its services at the time of writing, although the organisation had previously <a href=\"https:\/\/www.bbc.co.uk\/news\/uk-wales-62442127\">told the BBC<\/a> the disruption was \u201cminimal\u201d. Services in Northern Ireland, Scotland and Wales were also impacted, and the NHS as a whole has been working with the National Cyber Security Centre on response.<\/p>\n<p>Kieran Bamber, director of strategic accounts for the healthcare sector at <a href=\"https:\/\/www.tanium.com\/\">Tanium<\/a>, an endpoint management service, said the impact of the attack on the UK\u2019s health services once again highlighted the risks that one must accept when engaging third parties.<\/p>\n<p>\u201cThe NHS has recently developed an increased reliance on third-party vendors and software to support everyday processes, meaning its IT environments are now inherently more complex \u2013 with a plethora of additional software and infrastructure that needs to be carefully managed,\u201d he said.<\/p>\n<p>\u201cAlthough only 2% of Advanced\u2019s services went down, its software is responsible for 85% of NHS 111 services, [and] as a result, this attack had a significant impact on the NHS over the weekend \u2013 with 111 downtime likely responsible for a surge in patients arriving at A&amp;E departments, increasing waiting times and issues related to ambulance prioritisation,\u201d said Bamber.<\/p>\n<p>Chris Butler, resilience and continuity consulting head at backup and disaster recovery specialist <a href=\"https:\/\/www.databarracks.com\/\">Databarracks<\/a>, said the incident brought to mind similar attacks on the likes of Kaseya and SolarWinds.<\/p>\n<p>\u201cTechnology companies provide cyber criminals with an avenue into hundreds or even thousands of organisations from a single breach; this incident did not just affect NHS 111 staff, but also services in all four home nations, the Welsh ambulance service, prescription services and a care home management system,\u201d he said. \u201cSecuring the supply chain is becoming increasingly vital. The NHS is better prepared than most for these kinds of incidents as it is governed by the <a href=\"https:\/\/www.ncsc.gov.uk\/collection\/caf\/nis-introduction\">Networks &amp; Information Systems Regulations<\/a>.\u201d<\/p>\n<p>However, he added: \u201cI\u2019m still not convinced that many companies spend enough time assessing the true resilience of their critical suppliers and vendors \u2013 this means asking deeper, more searching questions, and completing a proper assessment of their resilience capabilities.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>NHS bodies around the UK are still restoring services after a cyber attack hit one of its suppliers before the weekend, taking out its 111 emergency advice line and causing disruption to ambulance dispatch, emergency prescriptions, out-of-hours appointments and patient referrals. Details of the incident at Advanced Software continue to emerge, and the precise nature [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":46825,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-46824","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/46824","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=46824"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/46824\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/46825"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=46824"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=46824"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=46824"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}