
An article from the Nikkei newspaper titled “Cyberattack That Was Bound to Happen After Warnings Were Ignored”1 came across my feed. It contains the following passage.
Of course, the primary responsibility lies with Microsoft in the United States. This is because it sold the Windows operating system targeted in this attack and has been criticized for security flaws for many years.
No, the primary responsibility lies not with Microsoft, but with the organizations that continued using the software after support ended and those that failed to apply patches even when they were released. This kind of irresponsible shifting of blame is putting the public at risk.
It is long past time to understand that purchasing software does not mean buying and owning it like physical goods; it merely means acquiring the right to use it for a certain period. Software providers, too, might want to consider supplying software in a form that stops working when support ends.
The article above cites the example of the United Kingdom’s NHS (National Health Service) having to suspend operations. Its equipment remained based on XP, for which support had ended long ago, and those systems were infected with WannaCry. With medical equipment, it is understandable that systems might remain on XP because the hardware does not support anything newer. But if it had been understood from the outset that the OS would stop working entirely when support ended, both medical institutions and equipment manufacturers would have responded, and I think they would have budgeted for it from the beginning.
I also think the continued, drawn-out use of unsupported software such as XP in cases like this is based on the myth that a network is safe if it is disconnected from the Internet. Even if people believe they have isolated a network, in most cases it has not remained isolated when viewed over time, so they fail to understand that perimeter security is no longer sufficient. This attack, too, did not arrive by email. The apparent infection route was probably a computer that became infected while connected to the Internet through tethering or a similar method and then spread the malware when connected to the internal LAN. After all, no infections originating from email have been observed.
The minimum security standards that organizations must meet should be properly addressed as a matter of national policy. This is because it has already become a public safety issue. Countries should work together to establish the minimum security standards that must be met, just as they set CO2 emissions standards. Management systems such as ISMS allow organizations to set their own levels, so minimum standards may not be maintained, and they are too burdensome for small and medium-sized enterprises. It could be said that a simple checklist-based approach is needed.
Footnotes
- “Cyberattack That Was Bound to Happen After Warnings Were Ignored,” The Nikkei (2017-05-19) <http://www.nikkei.com/article/DGXMZO16510220X10C17A5000000/>
Related posts

Anyone Who Thinks Identity Is Given by the State or Government Should Sit Up and Read This: Utah Digital ID Bill SB260 and the Transformation Brought by a User-Centric Digital ID System
As digital technology evolves, our dependence on personal information and data continues to grow. Yet many government-provided ID systems do not always give sufficient consideration to…

I Will Appear on the Okinawa Open Days Panel “Current and Future OSS Initiatives in Economic Security”
It is already the day of the event—in fact, I am writing this now (12/4 9:45) at my desk while preparing for the panel—but I will…

The “DS-511 Guidelines for Handling Digital Identity in Identity Verification for Administrative Procedures, etc.” Have Been Published
After 3 years of development, the Digital Identity Guidelines, to which I had the privilege of contributing as an expert (Expert Meeting on the Revision of…

You must be logged in to post a comment.