Maersk rebuilt hefty IT infrastructure a mere 10 days after NotPetya attack
The attack cost the company at least $250m, but was "an important wake-up call"
Shipping firm Maersk rebuilt its entire infrastructure in just ten days in order to recover from the NotPetya malware epidemic, the company has revealed.
Speaking at a panel as part of this week's World Economic Forum in Davos, the chairman of the logistics group Jim Hagemann Snabe said that the malware outbreak necessitated a full reinstallation of vast numbers of systems and applications.
"We basically found that we had to reinstall our entire infrastructure," he said. "We had to install 4,000 new servers, 45,000 new PCs and 2,500 applications - and that was done in a heroic effort over ten days."
"Normally - I come from the IT industry - you would say that would take six months; it took ten days. A heroic effort, and I can only thank the employees and partners we had on doing that."
The incident, he said, was "an important wake-up call". The company learned a number of important lessons, including the fact that Maersk was "basically average" when it came to cybersecurity. The company now has a plan to improve its security capabilities and transform them into a business asset, rather than a potential liability.
Snabe also spoke of the value of openness and collaboration in the area of cybersecurity, noting that what happened to Maersk can happen to other companies, and that a greater understanding of the problem is required.
The NotPetya outbreak had a huge impact on Maersk - the firm apparently lost between $250m and $300m as a direct result of the attack, and was forced to conduct its business manually without the aid of IT systems while the damage was repaired. Impressively, the company only saw a drop of around 20% in volume despite this.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Adam Shepherd has been a technology journalist since 2015, covering everything from cloud storage and security, to smartphones and servers. Over the course of his career, he’s seen the spread of 5G, the growing ubiquity of wireless devices, and the start of the connected revolution. He’s also been to more trade shows and technology conferences than he cares to count.
Adam is an avid follower of the latest hardware innovations, and he is never happier than when tinkering with complex network configurations, or exploring a new Linux distro. He was also previously a co-host on the ITPro Podcast, where he was often found ranting about his love of strange gadgets, his disdain for Windows Mobile, and everything in between.
You can find Adam tweeting about enterprise technology (or more often bad jokes) @AdamShepherUK.
-
Post-cloud strategy: Architecting the next enterprise stackAs enterprises rethink their dependence on hyperscale, hybrid architectures are emerging as the new foundation for resilient, AI-ready infrastructure
-
Anthropic just launched Claude Fable 5, its first Mythos-class AI modelNews The launch of Claude Fable 5 marks the first public release of a Mythos-class AI model
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments
-
Instructure chose to a pay ransom following the Canvas cyber attack – research shows more than half of security leaders would follow suitAnalysis Opting to pay ransoms creates huge risks for enterprises – you’re relying on the word of criminals
-
Ransomware negotiator sentenced for role in major cyber crime groupNews Deniss Zolotarjovs was a key player in a group associated with Conti
-
Threat actors ditch ‘spray and pray’ attacks in shift to targeted exploitationNews A dip in ransomware volumes points to a more targeted approach focused on vulnerability exploitation
-
Security leaders overconfident about ransomware recoveryNews Few manage to recover all their data, and many experience business disruption
-
German authorities want your help finding the hackers behind GandCrab and REvilNews Daniil Maksimovich Shchukin and Anatoly Sergeevitsch Kravchuk are believed to have made millions from ransomware as a service schemes
-
The rise of teen hackers ‘makes for a good headline’, but cyber crime activities peak later in lifeNews With family responsibilities and mortgages to pay, it's not teenagers dishing out malware or carrying out cyber extortion
