Key information
Request reference number: 28 September 2021
Date of response:
Summary of request
- In the past three years has your organisation:
- Had any ransomware incidents? (An incident where an attacker attempted to, or successfully, encrypted a computing device within your organisation with the aim of extorting a payment or action in order to decrypt the device? )
- If yes, how many?
- Had any data rendered permanently inaccessible by a ransomware incident (i.e. some data was not able to be restored from back up.)
- Had any data rendered permanently inaccessible by a systems or equipment failure (i.e. some data was not able to be restored from back up.)
- Paid a ransom due to a ransomware incident / to obtain a decryption key or tool?
- If yes was the decryption successful, with all files recovered?
- Used a free decryption key or tool (e.g. from https://www.nomoreransom.org/)?
- If yes was the decryption successful, with all files recovered?
- Had a formal policy on ransomware payment?
- If yes please provide, or link, to all versions relevant to the 3 year period.
- Held meetings where policy on paying ransomware was discussed?
- Paid consultancy fees for malware, ransomware, or system intrusion investigation
- If yes at what cost in each year?
- Used existing support contracts for malware, ransomware, or system intrusion investigation?
- Requested central government support for malware, ransomware, or system intrusion investigation?
- Paid for data recovery services?
- If yes at what cost in each year?
- Used existing contracts for data recovery services?
- Replaced IT infrastructure such as servers that have been compromised by malware?
- If yes at what cost in each year?
- Replaced IT endpoints such as PCs, Laptops, Mobile devices that have been compromised by malware?
- If yes at what cost in each year?
- Lost data due to portable electronic devices being mislaid, lost or destroyed?
- If yes how many incidents in each year?
- Does your organisation use a cloud based office suite system such as Google Workspace (Formerly G Suite) or Microsoft’s Office 365?
- If yes is this system’s data independently backed up, separately from that platform’s own tools?
- Is an offsite data back-up a system in place for the following? (Offsite backup is the replication of the data to a server which is separated geographically from the system’s normal operating location site.)
- Mobile devices such as phones and tablet computers
- Desktop and laptop computers
- Virtual desktops
- Servers on premise
- Co-located or hosted servers
- Cloud hosted servers
- Virtual machines
- Data in SaaS applications
- ERP / finance system
- Are the services in question 3 backed up by a single system or are multiple systems used?
- Do you have a cloud migration strategy? If so is there specific budget allocated to this?
- How many Software as a Services (SaaS) applications are in place within your organisation?
- How many have been adopted since January 2020?
Related documents
MGLA010921-1951 - FOI response