National Health Service in England
When patching gaps became front-line service disruption
WannaCry affected at least 80 of 236 NHS trusts in England and exposed gaps in patching, preparedness and national response coordination.
Documented impact
Authoritative findings
The documented event
The WannaCry ransomware attack affected NHS services in England from 12 to 19 May 2017. The NAO reported that at least 80 of 236 trusts were affected: 34 were infected and locked out of devices, while 46 were not infected but reported disruption. NHS England identified 6,912 cancelled appointments and estimated approximately 19,494 in total. Five accident and emergency departments diverted patients. Most infected NHS devices were unpatched supported Windows 7 systems; unsupported Windows XP devices were a minority of identified issues.
Hypothetical institutional scenario
How might the same control pattern appear?
Critical service providers receive security alerts and patches, but cannot demonstrate implementation across distributed estates, embedded devices and local organisations before a rapidly spreading incident tests the gap.
Stress-test questions
Questions for challenge and assurance
-
Risk committee
Can management prove critical patches are implemented, not merely distributed?
-
Operations
Which essential services depend on unpatchable or embedded devices?
-
Audit
Can the organisation coordinate safely when email and core systems are unavailable?
NFRisk practitioner interpretation
Control implication
NFRisk view: cyber resilience is an evidence problem as well as a technology problem. Boards need verified patch status, exception ownership, dependency visibility, workable isolation and tested service-continuity communications.
Evidence register
Primary and supporting sources
-
UK National Audit Office
Investigation: WannaCry cyber attack and the NHS (opens in a new tab) 27 October 2017 · Authoritative primary source
Publication note
A documented external event—not an NFRisk client engagement.
The named organisations are included because authoritative sources document the event. Their inclusion does not imply that they are or were NFRisk clients, that they endorse this analysis, or that NFRisk participated in the event or response. Framework relevance and NFRisk practitioner interpretation are analytical layers applied after the event.
Return to the Risk Scenario LibraryFrom scenario to mandate
Test the equivalent control assumption in your environment.
NFRisk can use this scenario as a starting point for a focused structural diagnostic, risk-architecture review or delivery-assurance discussion.