RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Incident

Incident / From the archive · 12 May 2017 event · prepared 16 September 2026

WannaCry spread through a patched flaw the NHS had not applied

The National Audit Office found unpatched systems and unclear response roles let the ransomware disrupt care at 81 NHS trusts.

nao.org.ukprimary record

Investigation: WannaCry cyber attack and the NHS

Document
27 October 2017
Event
12 May 2017
Retrieved
16 September 2026
No visual was published with this record, so its primary document stands in its place.

What happened

On 12 May 2017, ransomware later named WannaCry began spreading using a flaw in older versions of the Windows file-sharing protocol that Microsoft had already patched two months earlier. Microsoft's critical bulletin, released on 14 March 2017, had fixed several remote-code-execution vulnerabilities in the affected protocol. The UK's National Audit Office investigation, published on 27 October 2017, found that at least 81 of 236 NHS trusts in England were affected, more than 19,000 appointments were cancelled or disrupted, and that all organisations infected by WannaCry shared the same vulnerability and could have taken relatively simple action to protect themselves, including applying the March patch or blocking the exposed network port at the firewall.

Confidence and limits

The National Audit Office is the UK's independent public-spending auditor, and its report is based on documentary evidence and interviews with the Department of Health and Social Care, NHS England and affected trusts; it is specific about the number of trusts affected and the timeline of warnings issued before the attack. The report is candid that it could not establish why individual trusts had not applied guidance the Department had issued since 2014 to migrate away from unsupported software, stating only that the Department had no formal mechanism to verify compliance, which leaves the precise local reasons for non-patching outside what the report itself can confirm.

Why it mattered

The audit found the NHS had a response plan, but it had never been tested locally, so it was not immediately clear who should lead the response, and staff fell back on personal mobile phones and encrypted messaging when email systems were affected. The report also credits a security researcher's discovery of a kill switch domain with halting further spread, a circumstance the report treats as fortunate rather than as a designed defense, meaning the outcome could have been substantially worse without it.

Defensive takeaway

Confirm that critical patches are deployed on a defined schedule with verification, not on a best-effort basis, and that your incident-response plan has been rehearsed by the people who would actually execute it during a real outage.

  • Can you confirm, with evidence rather than assumption, that a specific critical patch has been applied across every affected system?
  • Has your incident-response plan been tested in an exercise, or only written and filed?
  • If email and normal communications were unavailable during an incident, what backup channel would your response team actually use?

WannaCry's spread inside the NHS is a patch-latency story rather than a novel-exploit story, since the flaw involved had a fix available for two months before the outbreak. The audit office's account is notable for stopping short of blaming any single trust or individual, instead pointing to systemic gaps, unclear responsibility, untested plans and unverified patch compliance, as the conditions that let a known, fixed vulnerability cause a national disruption.

Defensive takeaway

Check that your organization can confirm, within days rather than months, whether a specific published patch has been applied across every affected system, and that your incident-response plan has actually been tested, not just written.

The National Audit Office's investigation, a UK government body, and Microsoft's own patch bulletin together establish the technical cause, patch timeline and organizational response gaps; the audit office's own report states it could not determine why individual trusts had not applied the patch or basic firewall controls, and this article does not go beyond that.

Sources & reading trail

Investigation: WannaCry cyber attack and the NHS ↗

UK National Audit Office investigation finding unpatched systems, untested response plans and unclear responsibilities across NHS trusts.

government-primary · Source published: 27 October 2017 · Retrieved: 16 September 2026

Microsoft Security Bulletin MS17-010 - Critical ↗

Original patch, released two months before the outbreak, for the SMB vulnerabilities WannaCry exploited.

vendor-primary · Source published: 14 March 2017 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.