Comment Re: Why were critical systems not replaced? (Score 2) 35
This wasn't such a big deal before everything had to be "JIT" with near zero inventory because you needed to reduce "days of supply" and improve your "working capital turns" because the consultants told you so.
On the other hand, six weeks is a very long time, though.
In a previous job, I had a customer that was hit by a ransomware attack. Once it was discovered they literally told everyone to unplug everything from the network and operate that way. Their ERP software was down so they couldn't even do basic accounting. The IT contractors who managed their data center were pretty incompetent, and used the corporate network AD for authentication on the vmware hypervisors, so once domain admin was achieved the attackers had absolute control at every level.
I was not part of the recovery effort, but it was about four weeks of absolute chaos from what I was told (and I was told very little).
Now, of course, they have overcorrected and added ridiculous policies everywhere that do little to improve security. You have to enter your credentials every day on any device that is not coming through the internal network or VPN. So users are being "trained" to use easier to remember / enter passwords, and to expect frequent requests for their login information. Not to mention that hacking a phone to steal credentials during entry is probably the easiest attack vector, so increasing the frequency of entry is harmful. Their "director of IT infrastructure" (who is a grade A asshole) will randomly have the domain admin reset the kerberos TGT 3x to invalidate all tickets, which sometimes locks us out of the servers we manage. The list goes on and on....