The British Library’s Legacy System Problem

β–Ά Watch (3:59)

The British Library holds 200 miles of books, adding 6 miles per year. Its collection includes Magna Carta, Beatles lyrics, and the Beowulf manuscript. The library grew by acquiring collections from different organizations, each with its own information systems. This history created a heterogeneous IT environment. The library had a security program with MFA and risk assessments, but its legacy systems could not meet the UK Cyber Essentials baseline after the 2022 update. They stopped recertifying.

How Rhysida Broke In: Stolen Credentials and a Missing MFA Exception

β–Ά Watch (9:40)

Rhysida uses legitimate credentials from vendors. On October 25, the attacker logged into a terminal server. The library had exempted that server from MFA for cost reasons. An alarm at 1:00 a.m. triggered account disablement. Morning staff re-enabled it. The attacker used living-off-the-land tools to move laterally and escalate privileges. For days, they searched files for keywords like β€˜confidential’. At 1:30 a.m. on Saturday, 440 GB was exfiltrated. The stolen data included staff PII and personal files. Ransomware encrypted files and backups.

Devastating Business Impact: Months of Pre-Digital Operations

β–Ά Watch (20:15)

After the attack, the library opened in a pre-digital state: no computers, paper only. All corporate laptops were repossessed and reimaged. Two weeks passed before a public statement on November 15. By January, only partial catalog access was restored. By March, half of physical collections were inaccessible. Digitization stopped. The 18-month recovery plan projected rebuilding infrastructure in the cloud at a cost of 40% of cash reserves. Even two years later, the library still maintains a cyber attack information page.

Root Causes and 16 Lessons Learned

β–Ά Watch (30:14)

The report identified root causes: legacy data operations remained manual, network segmentation was impractical, and attackers could access everything once inside. Attackers also destroyed servers beyond recovery, extending recovery time. The library listed 16 lessons. Almost all map to NIST 853 controls. Key items: manage system lifecycles, prioritize remediation, test resilience. Two unique lessons addressed staff wellbeing during long crises and revision of personal file storage policies. The report also noted that security had flagged the MFA exception in the risk register, but consequences were underappreciated.

New Risks After a Public Catastrophe

β–Ά Watch (38:09)

The report ended with a risk analysis acknowledging new threats. Publicity from the attack might attract chaos-driven attackers, not just ransom seekers. The 18-month rebuild creates pressure to take shortcuts. The library saw the crisis as an opportunity to address deep structural issues that would otherwise be too disruptive to fix. Myers urged the audience to spread the story and not let the lessons go to waste.

Notable Quotes

they say they were aware of the risk. It’s in the risk register but the consequences were perhaps underappreciated. Brian Myers Β· β–Ά 12:57

The destruction of servers had the most damaging impact on the library. Brian Myers Β· β–Ά 23:58

Estimated total cost, 40% of our cash reserves. Brian Myers Β· β–Ά 26:24

this was a substantial disruption and it gave us the opportunity to address structural issues, deep structural issues that otherwise would have been too disruptive to address. Brian Myers Β· β–Ά 38:16

Key Takeaways

  • Rhysida exploited a missing MFA exception on the British Library domain server.
  • 440 GB of data was exfiltrated; ransomware encrypted files and destroyed servers.
  • Recovery cost 40% of cash reserves and required an 18-month full infrastructure rebuild.

About the Speaker(s)

Brian Myers (PhD, CISSP, CCSK) has been Director of Information Security and HIPAA Security Officer for a division of WebMD; Senior Application Security Architect for a hypergrowth Silicon Valley startup; and Senior Security Advisor for Leviathan Security Group. He currently works as an independent contractor helping companies build security programs.