It's a fact. Wannacry lives among us and continues to pose a significant threat to companies and organizations. Learn how you can effectively protect yourself.

Wannacry, also known as WannaCrypt, first came to our attention in May 2017, when it hit high-profile targets around the world in large numbers. Some of the first major attacks, on May 12, targeted the UK's National Health Service, shipping company FedEx , and Spanish mobile phone service Telefonica.
The Ransomware managed to wreak havoc by exploiting a significant Windows vulnerability, allowing attackers to gain access to systems, encrypt data, and demand a ransom payment in bitcoins for the decryption and recovery of said data.
Two years on, WannaCry is still a threat. Experts are now warning that a significant number of companies and organizations are still vulnerable to WannaCry, due to the use of older IT systems, a lack of investment in security, and a general lack of security skills.
As researcher Andrew Morrison points out, “WannaCry is clearly a threat to a large number of unpatched systems. Malicious actors can now easily detect unpatched systems and direct WannaCry to conduct targeted attacks.”.
But this is nothing new. In fact, WannaCry used the same system that its predecessor, NotPetya. The actual toolkit, which was used and stolen by the NSA, still poses a threat for creating new variants of the attack. “While patches have been released to successfully address the NSA toolkit and WannaCry, using them to find new vulnerabilities is still a threat. Users think they are safe because they patched everything they saw, but the threat evolved using the same toolkit and can strike again.”
According to data from Shodan, there are more than 400,000 devices in the US that are still vulnerable to Wannacry. Systems used primarily in manufacturing and industrial control systems are at particular risk, as many of them run on older versions of Windows (or generally run on Windows, which certainly increases the threat). Companies are wary of updating systems because the process could disrupt production capabilities.
What should companies do about this?
To stay one step ahead of the threat, organizations should conduct audits of their systems’ patching processes and then look for tools and policies to make this practice more effective. A good example of this is moving towards stronger automation of update processes.
The second part is recovery processes . Organizations try to prepare their systems, data , and business processes to withstand attacks through “ air-gapped ” recovery solutions so that there is an entry point that is clean and unaffected by threats.
The basic concept of an “air gap” model is simple. If the data cannot be accessed, then it cannot be corrupted or destroyed. A simple implementation of this model typically involves taking backup copies of the data to a secondary storage system that is offline and therefore cannot be connected to any public network.
This ensures that there are no vulnerabilities to exploit and data remains secure as malware cannot spread, allowing for the safe storage of critical data and the restoration of systems if necessary without loss.
