中文

Despite 'Unprecedented' Outage, Customers Say They Will Continue Using Kronos

In December 2021, Kronos Private Cloud was hit by a ransomware attack, causing payroll and attendance disruptions for multiple employers. Although the outage was described as 'unprecedented,' most surveyed customers said they would continue using Kronos, but the incident also sparked discussions about vendor dependency, backup plans, and legal risks.

2022-03-2910views
Despite 'Unprecedented' Outage, Customers Say They Will Continue Using Kronos

A cybersecurity and HRIS analyst was blunt about the severity of the ransomware attack on the workforce management platform Kronos in December of last year.

"This event is unprecedented and unparalleled," said Richard Pemberton, senior HRIS analyst at MHI Shared Services Americas, a former Kronos employee. "It was basically a nuclear bomb."

"This is certainly the most prominent, recent example of [ransomware] creating challenges for HR teams," said Allie Mellen, security infrastructure and operations analyst at Forrester, adding that this event likely won't be the last. "Honestly, unfortunately, I think this is only going to become more common over time."

The resulting outageleft HR teams scramblingfor workarounds. Some teamsspent more than a monthusing alternative processes for payroll, timekeeping, and other critical services.

The event affected customers using Kronos Private Cloud, a product of UKG. The company said the first phase of its recovery processwas completed on January 22, restoring access to core Private Cloud functions. Work to restore other applications used by some customers as part of UKG solutions is still ongoing.

Of the six employers that responded to HR Dive's request for comment, most said they plan to continue their relationship with the company. But the fallout may manifest in several ways in the months and years to come.

Companies that stuck with Kronos

Three of the companies HR Dive spoke with represent healthcare organizations. Dan Leveton, media relations manager at University of Florida Health Jacksonville, said in an email that the organization's Kronos system was "down for approximately three payroll cycles but is now back up and running normally." Although UF Health used manual time sheets during that period, employees still clocked in and out as usual, with that information stored locally on the organization's time clocks. The outage "only affected some overtime pay, etc.," Leveton said.

Penn Highlands Healthcare, a regional health system in northwestern Pennsylvania, praised Kronos' response. "Yes, Penn Highlands Healthcare is still using the Kronos timekeeping system," Chief Financial Officer Heather B. Schneider said in an email. "The parent company of Kronos [UKG] handled a very difficult situation with grace and urgency."

Additionally,in a previously reported interview, Sergio Melgar, CFO of UMass Memorial Health in Massachusetts, said the health system plans to continue using Kronos while implementing new backup processes to prepare for future events.

9174f5ca2d907636cc4039a9ebca920c02e4256050c6a350597579c39d8c8f3d.jpg
The Kronos Private Cloud outage may serve as a wake-up call for employers about the importance of ransomware attacks on HR vendors, said Allie Mellen, security infrastructure and operations analyst at Forrester.
katleho Seisa via Getty Images

Meanwhile, Massachusetts-based grocery chain Stop & Shop also implemented "alternative processes" for payroll and scheduling when its Kronos timekeeping system went down, said external communications manager Caroline Medeiros; "ensuring our associates are paid accurately and on time remains a top priority. Yes, we continue to use Kronos."

Keolis Commuter Services, a passenger transportation service that operates and maintains the commuter rail service of the Massachusetts Bay Transportation Authority, said in an email from Stephan Oehler, vice president of finance, strategy and transformation, that "companies like Kronos are expected to have effective business continuity plans in place in the event of any disruption, just as we do."

"While the nature of this situation required us to dedicate significant time, effort, and resources to manage and mitigate the negative impact on our employees, Keolis continuously works to strengthen and improve our own systems to minimize the vulnerability of our systems and protocols, even as we rely on external vendors for critical services," Oehler continued.

How did Kronos respond?

However, customers were not without complaints. Pemberton, whose organization lost access to Kronos-provided time clocks during the outage, said he was "disappointed" with the company's initial response; he said the company failed to provide a backend solution that would allow customers to continue using its products with minimal disruption.

"We have about 100 time clocks. These clocks are not cheap. They basically became bricks for two months."

— Richard Pemberton, senior HRIS analyst at MHI Shared Services Americas

He also criticized the company's early communication around the event. Pemberton said MHI Shared Services contacted Kronos' response team to open a case after realizing an outage had occurred, but he "initially got no feedback."

As word spread that the broader outage was affecting multiple employers, Pemberton, who previously served as an incident response representative at Kronos, said his impression was that "even Kronos itself didn't understand what was happening."

"Unfortunately, after the attack, there was a lack of communication from Kronos, and early on there was a lot of frustration about how long the outage would actually last," Forrester's Mellen said. "That created early friction and frustration."

In an email, a UKG spokesperson provided a statement about the company's response: "Core functionality for customers affected by this incident was restored on January 22. To achieve this, we organized teams to bring as many customers online as quickly as possible. Given the global pandemic, we had dedicated teams for healthcare, first responders, and similar customers. These teams worked alongside separate teams that were concurrently handling other customer groups. Since the incident, we have focused on communicating with these customers in a transparent and timely manner."

The timing of the event "caused a lot of pain for some of these organizations," Mellen said. For example, healthcare providers affected by the outage may have been dealing with outbreaks of the omicron variant.

But sources also acknowledged that the company's response improved over time. "They became more transparent," Pemberton said of UKG, adding that the company eventually provided more frequent estimated recovery timelines.

Pemberton noted that UKG was "sometimes generous" in financial negotiations after the event, but he said he would have liked compensation beyond more than two months of service credits. "We have about 100 time clocks. These clocks are not cheap. They basically became bricks for two months," Pemberton said. "I would have liked at least to be compensated."

Nevertheless, Pemberton said MHI Shared Services will also continue with Kronos, planning to migrate from the Private Cloud product to UKG's Dimensions product, which Pemberton described as a more secure alternative, partly because it is hosted on Google's cloud platform rather than Kronos' platform.

"There is no other vendor on the market that can provide Kronos' capabilities in timekeeping, and we would have to train a lot of people," Pemberton said.

What precedent will the outage set?

Among the more immediate challenges from the Kronos ransomware attack, lawsuits filed by affected employees and others may come into focus.

Media reports have already begun to note lawsuits filed by employees claiming they are owed back pay due to errors caused by the outage. In February, a New York City transit employeefiled a putative class action lawsuit, accusing their employer of illegally delaying payment of earned overtime wages beyond the normal payday. In addition to employee-driven lawsuits, Mellen said UKG could face lawsuits from employers.

While Mellen said she is not familiar with the specific language in typical contracts between payroll vendors like UKG and their clients regarding cybersecurity liability, "I wouldn't be surprised if it's limited or fairly vague." She added that some clients may seek to switch vendors to avoid the risk of similar events in the future.

According to Pemberton, the more important long-term lesson may be that employers need to have their own plans in place to recover payroll data in similar events. Employers "should not rely on the vendor as a one-size-fits-all solution. You always need to have a backup plan," he said.

Mellen offered similar advice, adding that security teams and HR operations should prioritize strategies for communicating with employees around such events.

"I don't think conversation alone will solve the problem, but ongoing communication with employees is important," she said. "Communication must be combined with action to ensure employees receive the pay they are owed."

Additionally, Mellen said this event may serve as a wake-up call for employers about the importance of ransomware attacks targeting vendors and the "existential" threat such attacks can pose to business. She suggested HR teams work with IT and security teams to develop backup solutions so that if a vendor does not provide its own backup, employers can continue running payroll.

Vendors are also paying attention. "UKG learned a painful lesson, but it was a hard lesson to learn," Pemberton said.