---
title: WannaCry About Skipping Updates
description: At CBOSS, we preach what we practice; updates should be vendor evaluated whenever they are released, and should be installed no more than 30 days out if possible. Furthermore, critical systems should always be on supported software versions. When this isn’t possible, businesses should consider avoiding connecting unsupported systems to their network or the internet. This can reduce their risk of infection, and prevent further spreading in the event a system is compromised.
image: https://blog.cboss.com/hubfs/bigstock--186645649.jpg
---

[Skip to content](https://blog.cboss.com/wannacry-about-skipping-updates#main-content)

[![g24](https://blog.cboss.com/hs-fs/hubfs/CBOSS%20Logos/g24.png?width=375&height=183&name=g24.png "g24")](https://cboss.com/)

Search

- [About Us](https://cboss.com/about/)
- Industries
  
  Show submenu for Industries 
  
    - [Governemnet](https://cboss.com/government/)
    - [Healthcare](https://cboss.com/healthcare/)
    - [Service Industries](https://cboss.com/service-industries/)
- Services
  
  Show submenu for Services 
  
    - [Omnichannel Payments](https://cboss.com/omnichannel-payments/)
    - [Reporting & Reconciliation](https://cboss.com/reporting-reconciliation/)
    - [Onboarding & Support](https://cboss.com/onboarding-support/)
    - [PointClickPay](https://cboss.com/pointclickpay/)
- Business
  
  Show submenu for Business 
  
    - [Integration](https://cboss.com/integration/)
    - [Partners](https://cboss.com/partners/)
- Resources
  
  Show submenu for Resources 
  
    - [Blog](https://blog.cboss.com/)
    - [Case Studies & White Papers](https://cboss.com/casestudies-whitepapers/)
- Contact
  
  Show submenu for Contact 
  
    - [Contact Us](https://cboss.com/contact/)
    - [CPP Support](https://cboss.com/cppsupport/)

- [About Us](https://cboss.com/about/)
- Industries
  
  Show submenu for Industries 
  
    - [Governemnet](https://cboss.com/government/)
    - [Healthcare](https://cboss.com/healthcare/)
    - [Service Industries](https://cboss.com/service-industries/)
- Services
  
  Show submenu for Services 
  
    - [Omnichannel Payments](https://cboss.com/omnichannel-payments/)
    - [Reporting & Reconciliation](https://cboss.com/reporting-reconciliation/)
    - [Onboarding & Support](https://cboss.com/onboarding-support/)
    - [PointClickPay](https://cboss.com/pointclickpay/)
- Business
  
  Show submenu for Business 
  
    - [Integration](https://cboss.com/integration/)
    - [Partners](https://cboss.com/partners/)
- Resources
  
  Show submenu for Resources 
  
    - [Blog](https://blog.cboss.com/)
    - [Case Studies & White Papers](https://cboss.com/casestudies-whitepapers/)
- Contact
  
  Show submenu for Contact 
  
    - [Contact Us](https://cboss.com/contact/)
    - [CPP Support](https://cboss.com/cppsupport/)

# WannaCry About Skipping Updates

 May 15, 2017 3:44:06 PM

Starting the end of last week, computer systems in over 70 countries across the globe were hit by virulent strain of malware going by the names Wanna Decryptor, Wcry, or Wanna Cry. Included in innumerable victims of this attack were many systems at the British National Health Service. The malware spread quickly through affected networks, encrypting all personal data and demanding a ransom in bitcoin equivalent to $300 per affected system.

Wcry spread further and wider than many similar ransomware attacks, because unlike others, it required no user interaction to spread. Wcry made use of a vulnerability in Microsoft's SMB file sharing protocol. This vulnerability was one of many in the NSA toolkit exposed by the Shadow Brokers earlier this year. The unfortunate thing about this vulnerability is that Microsoft patched it on all supported platforms back in March. The vast majority of systems hit by Wcry either hadn't been patched in months or worse, were running software that's end of life.

At CBOSS, we preach what we practice;  vendor updates should be evaluated whenever they are released, and should be installed no more than 30 days from the release date, if possible. Furthermore, critical systems should always be on supported software versions. When this isn’t possible, businesses should consider avoiding connecting unsupported systems to their network or the internet. This can reduce their risk of infection, and prevent further spreading in the event a system is compromised.

The outbreak of Wcry has brought to light the cost of running out of date, or unsupported software. There are many reasons why software stays out of date. They range from concerns over compatibility and lost productivity to simple lack of time and the low perceived priority of the task. In a busy business world, it can seem like there’s no good time to devote to this kind of routine maintenance. The situation gets even more complicated when specialized systems, like those in industrial and healthcare settings, run obsolete software with no security updates available. There frequently seems to be a cost in both time and money with updates. But with the spread of Wcry, we see there’s cost to inaction also.

We don’t yet know the full effect that this malware will have on healthcare, telecommunications, and industry. But with critical systems brought to a halt in hospitals and telecoms, if the final cost is measured only in bitcoin, we can count ourselves lucky.

Sources:

[https://arstechnica.co.uk](https://arstechnica.co.uk/security/2017/05/what-is-wanna-decryptor-wcry-ransomware-nsa-eternalblue/)

[https://krebsonsecurity.com](https://krebsonsecurity.com/tag/wanna-cry-ransomware/)

## Read More from CBOSS, Inc.

[![Computer with personal data on it.](https://blog.cboss.com/hs-fs/hubfs/Resized%20Social%20Image/1.png?width=352&name=1.png)](https://blog.cboss.com/prioritizing-pci-part-2-protecting-yourself)

### [Prioritizing PCI - Part 2: Protecting Yourself](https://blog.cboss.com/prioritizing-pci-part-2-protecting-yourself)

PCI Compliance can be daunting for new merchants or service providers. The PCI-DSS contains 12...

[![bigstock-178602982-Converted-01_ab91e89a053e5ce9ed5a565095b33d46](https://blog.cboss.com/hs-fs/hubfs/bigstock-178602982-Converted-01_ab91e89a053e5ce9ed5a565095b33d46.png?width=352&name=bigstock-178602982-Converted-01_ab91e89a053e5ce9ed5a565095b33d46.png)](https://blog.cboss.com/integrated-payments-101-how-can-software-companies-benefit-from-payment-integrations)

### [ONBOARDING BLOG SERIES - Integrated Payments 101: How Can Software Companies Benefit from Payment Integrations?](https://blog.cboss.com/integrated-payments-101-how-can-software-companies-benefit-from-payment-integrations)

First thing’s first, let’s set the stage by giving you our best definition of an ISV. An ISV is the...

[![](https://blog.cboss.com/hs-fs/hubfs/CBOSS_Blog2.jpg?width=352&name=CBOSS_Blog2.jpg)](https://blog.cboss.com/prioritizing-pci-part-1-watching-what-you-store)

### [Prioritizing PCI - Part 1: Watching What You Store](https://blog.cboss.com/prioritizing-pci-part-1-watching-what-you-store)

PCI Compliance can be daunting for new merchants or service providers. The PCI-DSS contains 12...

[Follow us on Facebook](https://www.facebook.com) [Follow us on LinkedIn](https://www.linkedin.com) [Follow us on Twitter](https://www.twitter.com) [Follow us on Instagram](https://www.instagram.com)

© 2026 All rights reserved.