|
From the LGA's Chief Executive |
|
|
Dear colleague,
The LGA and ADASS convened a national call this afternoon (14 May) between NRS and councils impacted by the cyber attack NRS experienced over the Easter weekend. NRS updated us on the status of their response and we felt it helpful to write out to reiterate what was discussed.
NRS Healthcare are a provider of community equipment and technology-enabled care (TEC) services on behalf of councils, NHS Trusts and individuals. Their organisation supports two million people with care and support needs, with more than 50 councils as customers.
Following the cyber attack over Easter, NRS Healthcare lost access to all their systems and subsequently focused on restoring their digital operations with councils and customers. They communicated with council commissioners through daily and weekly updates as they restored services and implemented workarounds.
On 7 May, NRS Healthcare communicated to current council commissioners that data from their internal network had been taken. They stated it was possible that elements of this data related to customers. The attackers have since posted on RansomHub, which was reported online by Comparitech and THIIS.
LGA and ADASS convened a meeting with councils understood to be affected as current customers of NRS Healthcare on 13 May to discuss issues in advance of the call with NRS Healthcare this afternoon.
NRS are working with a forensic team to review each dataset, which is a complex process and may take four months.
-
The threat actor claims to have exfiltrated 578GB of data.
-
The exfiltrated data is from their internal NRS network, but not their core customer and client systems.
-
Data is likely to comprise of some personal data processed by NRS as a controller (their own records) and some processed by NRS as a processor (on behalf of councils).
NRS confirmed that they are aware of the ransom note and deadline of 15 May and are working on the assumption that the data will be published at some point. It is understood that this data may be personally identifiable and/or Council-level information. NRS have pre-prepared stakeholder PR communications and will open up communication avenues in this event. They do not believe that widespread communications are helpful at this stage as NRS do not yet understand the impact of the leaked data and therefore may not have answers to questions from the public.
If specific councils have concerns, NRS shared that advisors are available to try and support where possible and appropriate. NRS have agreed to set up a call with council DPOs to enable councils to support fully the ISO investigation. Please contact DPO@nrshealthcare.co.uk to be included. The weekly updates with commissioners will continue, with the next meeting being tomorrow (15 May).
Whilst this update from NRS has been helpful in clarifying certain facts, there remains a lot of uncertainty. The LGA would advise all councils with recent or historic contracts with NRS that involve the sharing of sensitive data to:
-
Ensure you are appraised of the situation, and work as an organisation, involving your Data Protection Officer to assess potential risks based on data shared with NRS.
-
Follow situational updates and continue to update your risk assessment.
-
Develop risk mitigation plans for how you will deliver your safeguarding duties, if and/or when you feel they are required.
All the usual guidance applies from regulators and government bodies. The following might be helpful:
This is a dynamic situation, so please continue to engage with NRS for up-to-date information on the status of the investigation.
Many thanks,
Joanna Killian Chief Executive Local Government Association @LGAChiefExec
|
|
|
|
|