WannaCry Ransomware and the NHS (2017): A GRC Case Study on Preventable Disruption

In May 2017, the WannaCry ransomware outbreak disrupted NHS services across the UK. This case study breaks down what happened, where governance and risk controls failed (patch SLAs, legacy systems, segmentation), and what a GRC-led prevention and containment plan should look like—plus student exercises.

Why this case study matters

Use this scenario to understand how SOC, GRC, and VAPT concepts apply in real organizational security work.