- Ransomware. Healthcare organizations are a huge target for cybercriminals, because unlike other industries that have invested in cybersecurity, medical facilities have not. They also cannot afford to have their systems shut down since it could literally be a matter of life and death. More importantly they have the money to pay ransoms, and often do. Ransomware is a low risk high profit scam and as long as hospitals remain unprepared to deal with it and continue to pay off hackers, the threat will continue to grow. At the bare minimum these facilities need to have a robust backup system, limiting permissions, and have all their software up to date.
- Phishing awareness. While ransomware may be how cyberthieves attack, phishing is how they get into an organization’s systems. Everyone needs to be trained on how to recognize a phishing attack, but especially executives so they don’t become a victim of “whaling”. Executives have greater access to a medical facilities systems, so when they are targeted and fall victim to phishing, hackers can do everything from transfer funds to install ransomware.
- Executives need to be up to date on cybersecurity. Unfortunately, when it comes to security most executives aren’t sufficiently knowledgeable when it comes to threats. This leads to security being a low priority and a strategy that is more reactionary and less about preparedness. It’s up to executives in charge of IT to give out security information and threat assessments in ways other executives can understand. Security needs to be prioritized to the extent that at every board meeting should have a security report in the same way you’d have a financial report.
- Application security. When people think about encrypting data, they’re thinking about when it is stored or transmitted, but very few consider what happens when that data is being used by an application. During that time, data is decrypted and can be exposed not only to the general public, but to unauthorized users. In the financial industry, this is a priority, but in healthcare it isn’t. While application security tends to be a step above, it is an inevitable one.
- IoT is coming. The Internet of Things (IoT) is a term used to describe the interconnectivity and often web enabled aspects of modern technology. While this offers a lot of convenience in our everyday lives, when it comes to medical devices, it is a potential nightmare. In most cases manufacturers are more concerned with convenience and ease of use than the security risk these devices carry. While most hackers are more interested in financial gain than causing physical harm, this area has not been adequately addressed. With the rise of internet driven global terrorism and proof of concept attacks on devices like insulin pumps, this is a concern than needs to be considered.
Free, practical, and specific to regulated environments. We will email it to you.
No spam. Unsubscribe anytime.