yeah. They finally said "look, get off this thing" which is fair enough, but they then cut funding to the bone, and IT is always the first thing skimped on.
I'm told by a friend in IT in an NHS Trust that the NHS actually came off quite lightly - all the affected systems were front-end PCs that don't store patient data locally, the patient data was safe on back end databases, so he spent Saturday reimaging a few hundred PCs and not one satoshi of ransom was paid to the attackers. Hopefully they won't get complacent about the bullet they dodged. (Ahh, who am I kidding.)
https://www.theguardian.com/technology/2015/may/26/uk-govern...