The Containment Era is here. →Explore

Executive Summary

In June 2024, the Royal Borough of Kensington and Chelsea (RBKC) and Westminster City Council experienced operational disruption following a ransomware cyberattack on their shared IT provider, Westminster City Council Integrated IT (WCCIT). Attackers infiltrated municipal digital infrastructure, encrypted data, and impacted critical online services such as resident portals and payment processing. Public-facing platforms were taken offline as a precaution, and council operations shifted to manual workarounds, affecting both internal processes and citizen-facing services. The incident underscores the vulnerabilities within local government supply chains and highlights the ramifications of targeting shared service models in the public sector.

This attack is a sobering reminder of the increasing incidence of ransomware campaigns targeting public entities in the UK and globally. With local authorities managing sensitive citizen data and critical services, the urgency for robust cybersecurity controls and incident response processes has never been more acute.

Why This Matters Now

Municipal governments are increasingly being targeted by ransomware gangs, which can paralyze vital civic services and jeopardize citizen data. As local authorities rely more on shared or outsourced IT infrastructure, one breach can have cascading consequences, making aggressive, multi-layered defense and visibility across supply chains an urgent priority.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

A ransomware attack compromised Westminster City Council Integrated IT, leading to the shutdown of critical online services across multiple London boroughs.

Cloud Native Security Fabric Mitigations and ControlsCNSF

The use of zero trust segmentation, east-west traffic controls, egress filtering, and real-time threat detection would have constrained attacker movement, limited exposure, and enabled early detection prior to ransomware deployment. CNSF-aligned controls disrupt the attack across multiple kill chain stages by enforcing least privilege, visibility, microsegmentation, and robust egress management.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Blocked unauthorized external connections and reduced remote attack surface.

Privilege Escalation

Control: Multicloud Visibility & Control

Mitigation: Detected anomalous privilege changes and alerted for rapid investigation.

Lateral Movement

Control: Zero Trust Segmentation

Mitigation: Contained attacker movement by strictly enforcing least-privilege network access.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Detected and blocked known C2 traffic patterns and signatures.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevented or detected unauthorized outbound data transfers.

Impact (Mitigations)

Early detection of mass encryption or anomalous file activity limited ransomware spread.

Impact at a Glance

Affected Business Functions

  • Public Services
  • Customer Support
  • Financial Transactions
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Personal and financial data of residents, customers, and service users were potentially accessed and exfiltrated during the cyberattack.

Recommended Actions

  • Implement Zero Trust Segmentation to enforce least privilege across all workloads and cloud resources.
  • Deploy east-west traffic security controls to contain lateral attacker movement and enhance workload isolation.
  • Enforce strict egress filtering and real-time inspection to prevent command & control and data exfiltration.
  • Expand centralized visibility and anomaly response capabilities to detect emerging threats quickly.
  • Regularly review and harden identity and access policies, combining network controls with robust IAM governance.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image