
Five years after WannaCry ransomware wrought havoc with the UK’s NHS, Andy Swift at Six Degrees explores the design weaknesses that made WannaCry an international news story – and what lessons we should have learned since
May 2017 was when ransomware – a type of malware that blocks access to data until a ransom is paid – entered the national conscience. The reason? WannaCry. Despite existing in one form or another since 1989, ransomware news had, up until 2017, remained mainly the preserve of the tech press.
But when WannaCry impacted the NHS, resulting in the provision of some services to the public being interrupted, everything changed.
Ransomware has been perhaps the most prominent cyber threat in many peoples’ minds ever since WannaCry. In this article, I’ll explore the conditions in which WannaCry was able to flourish – and what lessons we can learn when it comes to protecting ourselves today.
My team and I have been working with large public sector organisations for some time now, carrying out penetration tests and more holistic red teaming exercises. Back in 2017, a common trait among many public sector organisations was the use of flat networks shared between multiple organisations.
These networks often had no segregation between areas or even organisations, meaning that a successful attack on one organisation could affect multiple others connected to the same network.
This is pretty far from best practice, but as a result of resource constraints and a lack of maturity it was surprisingly normal. In fact, in 2016 we carried out a penetration test in which we were able to access two organisations’ networks by targeting just one. This was as a result of the organisations using a single admin resource, and either a single domain or a limited selection of VLANs that didn’t segregate the networks.
Our candid take at the time was that ransomware would have a field day in these types of environments. The following year, it did.
It was the sheer scale of WannaCry that made it such big news. It didn’t make the hackers that launched it a great deal of money, though. Back in 2017 a lot of malware was highly automated, and that meant when organisations like the NHS failed to segregate things like servers, workstations, CCTV and phone networks, an automated malware like WannaCry could spread like wildfire.
Operationally this caused massive headaches for the NHS and many other organisations around the world. But for the hackers, WannaCry’s rapid expansion and impact actually made it harder to target the valuable data stores that would have allowed them to make large ransom demands.
Since 2017, organisations have generally improved their cyber security posture despite struggling to keep up with rapidly changing threats. Many more organisations are aware of the risks of things like using a single Active Directory domain for multiple organisations. Segregation has got a lot better – for example, keeping backup systems well away from the regular network.
This has made it harder for hackers to spread attacks across networks. However, the hackers have responded in kind. Manual intervention is far more common nowadays, with hackers being far more focused and tailored in their attacks in order to remain undetected for as long as possible.
WannaCry hit the headlines due to how disruptive it was. But given that most hackers have financial incentives in mind, this actually made it a pretty unsuccessful ransomware. Today’s ransomware is better designed to seek out that valuable data that as organisations we really don’t want to fall into the wrong hands.
Although many more cyber security best practices are in place at organisations today, there are still issues to be addressed. Patching is a big one. When my team and I test for Cyber Essentials Plus certifications, we find that smaller organisations find it easier to stick to patching schedules while larger organisations struggle to stick to the standard 14-day cycle mandated by Cyber Essentials.
The larger the organisation, the harder it is to adhere to a patching schedule. The complexity of large organisations’ environments, the significant inter-dependencies, and the lack of end-to-end visibility brought about by a disparate, third party and consultant-led design and build culture all result in a world where they simply can’t patch every two weeks for fear of critical services falling over.
What has helped in this regard is automation. Many organisations are quick to get their heads around automated solutions like email filtering and endpoint protection as the more they can automate, the more focus they can pay to actual incidents.
But moving forward, the best way for organisations to safeguard themselves in a meaningful way is to gain true end-to-end visibility and understanding of their entire infrastructure estates. You can’t protect what you don’t know, and this visibility is absolutely essential to enable a fit-for-purpose patching schedule that will deliver protection from the threats we continue to face every day.
Andy Swift is Technical Director of Offensive Security at Six Degrees, a leading secure cloud-led managed service provider
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543