In May 2017, the WannaCry ransomware attack swept across the globe, hitting hospitals, businesses, and government agencies in over 150 countries. Christina Danforth of HR Jetpack invited me to join her for a Facebook Live Chat to answer questions and help HR professionals understand what WannaCry was, how it spread, and what organizations should do to protect themselves.
What Is WannaCry?
WannaCry is a type of ransomware — malicious software that encrypts files on a victim's computer and demands a ransom payment (in Bitcoin) in exchange for the decryption key. What made WannaCry particularly dangerous was its ability to self-propagate across networks using a Windows vulnerability called EternalBlue, originally developed by the NSA and later leaked by a hacking group.
Why It Spread So Fast
Organizations that hadn't applied a critical Windows security patch released by Microsoft in March 2017 were vulnerable. Many large institutions, including the UK's National Health Service, were running outdated operating systems and couldn't patch quickly enough. The result was tens of thousands of systems locked within hours.
What HR Professionals Should Know
Ransomware events like WannaCry aren't just IT problems — they're business continuity and people problems. When systems go down, payroll can't run, employee records become inaccessible, and onboarding grinds to a halt. HR professionals are on the front lines of the human impact.
Key takeaways from our live discussion:
- Keep systems patched and up to date — this is non-negotiable
- Back up critical data regularly and test that your backups actually work
- Train employees to recognize phishing attempts, which are often the initial entry point
- Have an incident response plan that includes HR's role in communicating with employees
The Bigger Picture
WannaCry was a wake-up call. Cybersecurity is no longer something organizations can treat as an afterthought. Every department, including HR, has a role to play in building a security-aware culture. The technical patch that would have prevented WannaCry had been available for two months before the attack. Patch management and organizational readiness are human problems before they're technology problems.