• Free CIO-level whitepapers



    [ad] Check out these whitepapers published by IDC and HP to help you make tough decisions about your IT environment.

    Leveraging the Always On support experience for IT transformation: This IDC whitepaper outlines the importance of support services in IT environments. IT organisations are now required to support everything from legacy systems and storage to virtualised configurations and cloud-based computing in complex, heterogeneous environments. The increasingly critical role of vendor-supplied external support services is discussed and highlighted in addressing these emerging IT environments going forward.

    Conquering the challenges of data center complexity: Virtualisation and cloud are two popular IT trends that lower costs and make computing more secure and efficient. However, they also add complexity. Read this thought leadership paper and learn new ways to conquer your data center complexity challenges.

  • Great articles on other sites
  • RSS Delicious/delimiterau


  • Save up to $200 on ThinkPad laptops



    [ad] Lenovo ThinkPad Edge laptops boast best-in-class voice and video conferencing capabilities to help you stay in touch and HDMI, stereo speakers and a HD screen to keep you entertained on-the-go. Grab this coupon and save up to $200 each on each laptop.

  • 5 months FREE on phone system rental



    [ad] Rent a new phone system and connect your phone lines with Commander to receive 5 months rent free. Why rent with Commander?

    -Tailored complete solutions
    -Great offers from leading phone system brands
    -Rental & communication on a single bill
    -Renting systems conserves cash flow

    Hurry – act before 30 June!
  • Blog - Written by on Monday, February 14, 2011 8:14 - 14 Comments

    Virus attack: DR fails NSW ambulances?

    blog From NSW Opposition health spokesperson Jillian Skinner this weekend comes news of a dramatic new attack on the state’s health system — a “virus” that had infested the computer-aided dispatch system used by the Ambulance Service of New South Wales. Quoth Skinner:

    “There’s been a complete failure of the computer-aided dispatch system that allows ambulances to respond, sometimes to critically ill patients. This could potentially cost lives.”

    Now it is (mostly) completely understandable that a single system could have been taken down by a virus attack — large organisations have been dealing with this sort of thing for years, after all; especially since almost every system in existence became connected to the Wild West that is the Internet. And ambulances are still going out — using manual operations, according to general manager of operations Mike Willis.

    But what we’re really wondering here is why the Ambulance Service of NSW didn’t switch over straight away to its disaster recovery facility — you know, the one it built several years ago, presumably to cope precisely with this sort of of problem? Quoting from a Computerworld article in May 2007:

    “The Ambulance Service of New South Wales will procure new data centre facilities and services for the co-location of disaster recovery equipment for its mission-critical computer aided dispatch (CAD) platform.”

    Another question might be; what system did the virus actually attack? It is unlikely to be the VisiCAD software itself — after all, it seems unlikely that many people other than high-grade terrorists would bother writing a virus specifically to target an emergency services system. It’s far more likely that this was a general virus which attacked the underlying server platform which the dispatch system ran on; or the desktop systems which were used to access it.

    Which begs the question … why didn’t the Ambulance Service of NSW simply switch over to their backup systems?

    Image credit: Whrelf Siemens, royalty free

    Related posts:

    1. Tassie education dept wants Mac, Linux anti-virus
    2. Parliament wants mandatory anti-virus, firewalls on every PC
    3. DDoS attack knocks Atlassian offline
    4. Stallman slams filter as ‘human rights attack’
    5. Rudd backs Conroy in Google Wi-Fi attack
    submit to reddit Print Friendly and PDF

    14 Comments

    You can follow any responses to this entry through the RSS 2.0 feed. You can skip to the end and leave a response. Pinging is currently not allowed.

    1. Posted 14/02/2011 at 8:18 am | Permalink | Reply

      No, it’s not even remotely understandable.

      • Posted 14/02/2011 at 11:19 am | Permalink | Reply

        Are you saying virus attacks don’t happen and don’t get through? The security vendors have never been able to guarantee they can block everything … zero day attacks etc.

        • Posted 14/02/2011 at 2:00 pm | Permalink | Reply

          I believe that the ability of virus attacks to cause significant downtime and business interruption shows a lack of adequate governance and security policy. A virus outbreak should be limited in scope and impact if you have your systems and infrastructure well defined and properly planned.

          Also worth noting that we haven’t had a failure to detect and isolate viruses since dumping McAfee. I particularly believe in testing antivirus against competing products, and McAfee performed abysmally each time (http://www.autechheads.com/blogs/entryid/179/malware-prevention-it-needs-more-work). That said, we pay a lot of attention to our security, and especially malware. Sadly, I can’t say the same of other government agencies.

          I am however trying to be restrained in my assumptions until more is known about what happened, purely out of respect for their ICT staff.

    2. Thateus
      Posted 14/02/2011 at 9:04 am | Permalink | Reply

      I’d suspect that the virus (or likely a worm) just flooded their network or attacked services such as RPC/DCOM. While they might have had a backup application site – they probably didn’t have a backup network or backup network services.

      Some dill probably brought their laptop in to while away the time between call outs…

      • Posted 14/02/2011 at 11:21 am | Permalink | Reply

        Still … an internal virus attacking an internal network; surely they should be able to route around that fairly easily? It’s 2011 … this stuff shouldn’t be rocket science — especially for what should be a hardened emergency services organisation. And the actual terminals in the ambulances actually use radio — not 3G — to my knowledge, so network attacks wouldn’t be an issue there.

    3. Posted 14/02/2011 at 9:46 am | Permalink | Reply

      Two fundamental governance questions apply:

      What evidence exists to demonstrate that all critical business activities can be promptly restored in the event of any serious failure of IT systems?

      When was the last completely successful proof of prompt recovery and how frequently is this capability reconfirmed?

      These are universal questions that apply in any organisation. They demand an understanding of how the business activities depend on IT, of exactly what aspects of IT are essential for critical business activities and of the success criteria for a test.

      Unclear or equivocal answers should result in at least a formal review of policy and capability and may be cause for obtaining independent advice.

      Any answers that transfer responsibility to an outside organisation (“that’s the outsourcer’s responsibility” or “we use the cloud so that’s no longer an issue”) should be regarded as indications of complete failure to understand the fundamental issues in business continuity and should most certainly be a trigger for obtaining independent advice.

      • Posted 14/02/2011 at 11:23 am | Permalink | Reply

        I agree Mark — these are the questions that it looks like the Ambulance Service of NSW was asking itself several years ago … I am just curious as to why their systems didn’t stack up in the event of a real-life issue. They clearly were not able to maintain business continuity.

        • Posted 14/02/2011 at 11:35 am | Permalink | Reply

          Indeed we should all be curious. Its not enough to ask the questions once in a blue moon. These are questions that should be asked regularly and relatively frequently. Every three months should be the norm in an essential service. There should also be supplimentary questions to prevent the development of “routine answers to routine questions”. An independent validation at least once per year is probably a good idea.

          Another angle for governance questioning is to understand what nature of failures are actually covered by the BCP and DR arrangements. Disturbingly often the focus is on catastrophic loss of the primary data centre, with very little attention given to the much more likely scenarios of software malfunction, data corruption and loss of access.

          • Posted 14/02/2011 at 2:03 pm | Permalink | Reply

            Absolutely Mark. The message that ICT has to communicate to executives is that security isn’t a one-off project, it’s an ongoing process of improvement and review – and both the exec and ICT are responsible. Need more emphasis on good governance.

    4. Posted 14/02/2011 at 9:56 am | Permalink | Reply

      Let’s just hope that, whatever it was, they learn from this particular incident and install a better BCP for next time something like this happens.

      • Posted 14/02/2011 at 11:23 am | Permalink | Reply

        Well, at least they now have the Minister’s clear and undivided attention, if they want to pitch for funding ;)

    5. Posted 14/02/2011 at 1:31 pm | Permalink | Reply

      I hope this guy does not work for Ambulance Service of New South Wales.

      Thread dated dec ’10
      http://forums.whirlpool.net.au/archive/1597477

      • Posted 14/02/2011 at 2:06 pm | Permalink | Reply

        Heh, no .. it’s spam, but would be funny if there was a thread about anti-malware.

    Leave a Comment

    Comment

    Get our daily newsletter

    Get our new articles every day by signing up to our daily newsletter.

    Email address:



  • Anonymous tips

    Got some inside information on something that should be made public? Use our anonymous tips form. Even Delimiter won't have a clue as to your real identity.

  • Most Popular Content


  • Three lessons ING's private cloud teaches us
    sponsored post ING Direct recently implemented a private cloud solution to virtualise its entire banking platform, allowing it to provision a new copy of itself -- a so-called 'bank in a box' -- within minutes. Here's three things other organisations can learn from this interesting deployment.
  • Enterprise IT news & views

    • Microsoft beats Salesforce to utility CRM deal microsoft1

      Energy retailer Australian Power & Gas has picked Microsoft’s Dynamics CRM system over rivals Salesforce.com and Right CRM as the base platform for a customer relationship management overhaul to tackle incoming email complaints.

    • NSW finalises colossal datacentre consolidation cableguy

      The New South Wales State Government this week announced the Leighton subsidiary Metronode as the winner of its long-running and wide-ranging datacentre overhaul project, with the company to construct two new substantial facilities which will allow the state to consolidate its IT operations drastically.

    • Two good Australian CIO interviews IT-manager-cio

      There have been a couple of good interviews with Australian chief information officers done by various media outlets over the past couple of days — good enough that we thought them worth highlighting to readers on Delimiter.

    • Three lessons ING’s private cloud teaches us Cloud computing

      If you could provision a new copy of your organisation’s entire internal application environment for development purposes in just ten minutes, and you could do whatever you liked with it, what sort of new systems and processes would you build?

    • SAP considers Aussie datacentre sap1

      The Financial Review has reported that German software giant SAP is likely to build an Australian datacentre to provide services to Australian organisations, should new privacy legislation pass that could affect vendors’ ability to sell cloud computing services locally from global facilities.

    • How much more do servers cost in Australia? 1RUrackmountserver

      How much more do the hardware servers used by small businesses and large organisations cost in Australia? Quite a lot more than in the US, according to a report by small business technology media outlet BIT, in yet another case of the Australian technology tax striking fear into Australian wallets.

    • NSW agencies push very hard for SaaS rollouts Cloud computing

      Several major New South Wales Government agencies have unveiled major and wide-ranging plans to imminently purchase Software as a Service-style IT solutions, in moves which have the potential to re-cast the dynamics of the perceived relationship between Australia’s public sector and the burgeoning class of SaaS-delivered IT packages.

    • Technology and planned obsolescence lightbulbs

      Very insightful blog post here by Longhaus managing director Peter Carr, who has made a sophisticated argument regarding planned obsolescence with respect to implementing technology in organisations.

  • Enterprise IT, News - May 17, 2012 15:20 - 0 Comments

    Microsoft beats Salesforce to utility CRM deal

    More In Enterprise IT


    Photo Galleries, Telecommunications - May 17, 2012 12:14 - 23 Comments

    Pristine Telstra network photos: We sourced our own

    More In Telecommunications


    Blog, Gadgets - May 17, 2012 15:38 - 0 Comments

    Will Telstra skip Nokia’s Lumia 900?

    More In Gadgets


    Reviews - May 7, 2012 18:16 - 2 Comments

    Telstra Mobile Wi-Fi 4G: Review

    More In Reviews