The Council commissioned external contractors to assist with the recovery from the cyber attack, but they were general IT staff, not third-party specialists, and the critical IT systems were rebuilt on outdated equipment.
The report highlighted that Copeland did not know its equipment or if it was still supported, showing a lack of understanding of the risks due to weaknesses in its IT control environment.
Collection
[
|
...
]