833-847-3280
Schedule a Call

The Wannacry Infection … not a problem if you practice cyber hygiene.

The Wannacry Infection: What it is

I am sure that, over the weekend, you were inundated with news about the latest worldwide, The Wannacry Infection, cyber attack, infecting hundreds of thousands of systems around the world. Encryption occurred in the files of the affected computers and servers. From a hacker’s perspective, the infection was a complete success, affecting major corporations, government agencies and business worldwide.

If you didn’t read too deeply, you would think that The Wannacry Infection was the end of the world. You would think that some secret NSA developed virus was taking over businesses, government entities and personal computers. You would think that there was no way to stop it. But a deeper dive into the infection demonstrates once again, why proper cyber and IT hygiene is critical in preventing such serious infections.

The Wannacry Infection: How it Works

The Wannacry Infection works by taking advantage of a flaw in older Microsoft operating systems. A hacking group called Shadow Brokers released the infection. They are allegedly tied to hacks that were stolen from the NSA. Regardless of its origin or the effectiveness of the hack, basic IT and cyber hygiene would have prevented these infections. Why? Microsoft released a fix in February. IT managers should have updated their IT systems.

Additionally, most Anti-Virus programs have the update contained in them as well, as a simple search will reveal. This infection could have been preventable if IT managers kept their operating systems updated.

How to Prevent

I don’t want to get on my soapbox again but, as proponents of businesses small and large, we have often stressed the most affordable ways to prevent hackers from gaining access and control of critical IT systems that are critical to the operations of any sized corporation. It is critical that stakeholders ensure that their IT managers are doing their jobs. There are ways to ensure that they are doing their jobs, one of them being vulnerability scanning.

Vulnerability Scans

A vulnerability scan is a very inexpensive way to get a look at your IT architecture and to determine how up-to-date and/or secure it is. By using a variety of open source or proprietary tools, a provider obtains access to your network (through your IT POC) and “scans” the network for missing updates, open ports and other areas where hackers may enter your network.

The reports are simple to read and demonstrate what vulnerabilities exist, allowing the business owner to make informed decisions and can determine if s/he is secure or not. Repeated scans offer the owner the ability to track the progress that their IT personnel are making on addressing these vulnerabilities.

Other areas where business owners and private citizens can increase their security:

Update and Update again: too often we ignore those “update” messages that come up on our computer. More importantly, when you see them, act.

Download File: This goes back to training and preventing your employees from clicking on those blue links of chaos that come in emails promising things that are just too good to be true (they aren’t). Ensure they are aware of simple social engineering approaches: changed email addresses, modified URLs, etc.

Use Anti-Virus Programs: AV programs usually get frowned upon. Most people rely on their computer firewalls to prevent viruses. AV programs are kept up-to-date. They usually include information from application and system providers on hacks that affect their programs.

Back up your system: Sometimes a business cannot control everyone that touches their IT systems and even the most rigorous training program will not prevent someone from downloading an infection. Back up your systems. Above all, store them off site and on a different system/server than the one your company operates on.

These simple tactics can help prevent such a calamity from affecting your business. Practice good IT and cyber hygiene and you have a stronger chance of surviving a global cyber-attack.

Latest Posts

A transparent image used for creating empty spaces in columns
In the ever-evolving world of cybersecurity, penetration testing (pen testing) stands out as a critical component of an effective defense strategy. For MSPs (Managed Service Providers) and MSSPs (Managed Security Service Providers), the value of pen testing goes beyond identifying vulnerabilities—it’s about proving value to…
A transparent image used for creating empty spaces in columns
 With less than three months remaining until the deadline for PCI DSS 4.0 compliance, now is the time to assess your business’s status and determine what steps you need to take. The Payment Card Industry Data Security Standard (PCI DSS) sets security requirements to…
A transparent image used for creating empty spaces in columns
In today’s increasingly digital world, organizations face a growing number of threats from cybercriminals seeking to exploit weaknesses in systems, networks, and even human behavior. Understanding your attack surface—the totality of vulnerabilities and entry points an attacker could exploit—is essential for protecting your business. Whether…
A transparent image used for creating empty spaces in columns
 The Payment Card Industry Data Security Standard (PCI DSS) has long been a cornerstone for protecting cardholder data against theft and fraud. With the introduction of PCI DSS 4.0, organizations handling payment card information must implement several significant updates to enhance security and provide…
A transparent image used for creating empty spaces in columns
Yes, penetration testing is a proactive approach to cybersecurity. It involves simulating attacks on systems, networks, or applications to uncover vulnerabilities and weaknesses before malicious actors can exploit them. By identifying and addressing these security issues early, penetration testing strengthens an organization’s defenses and reduces…
A transparent image used for creating empty spaces in columns
  March 31st, 2025, is fast approaching, and it’s a pivotal date for businesses handling payment card data. This marks the deadline for full compliance with PCI DSS 4.0, the latest version of the Payment Card Industry Data Security Standard. If your organization processes, stores,…
contact

Our Team

Name(Required)
This field is for validation purposes and should be left unchanged.
On Load
Where? .serviceMM
What? Mega Menu: Services