Story image

Healthcare organisations buckle under pressure of cyber attacks

02 Mar 2016

The healthcare sector is slow to update technology and as such is woefully unprepared for an oncoming onslaught of cyber attacks, according to a recent report.

The ESET and the Ponemon Institute report 'The State of Cybersecurity in Healthcare Organisations in 2016', suggests healthcare agencies currently average about one cyber attack per month. Furthermore, almost half (48%) of respondents say their organisations have experienced an incident involving the loss or exposure of patient information during the last 12 months. However, despite these incidents, only half indicated their organisation has an incident response plan in place, the study shows.

"The concurrence of technology advances and delays in technology updates creates a perfect storm for healthcare IT security," says Stephen Cobb, ESET senior security researcher.

"The healthcare sector needs to organise incident response processes at the same level as cyber criminals to properly protect health data relative to current and future threat levels. A good start would be for all organisations to put incident response processes in place, including comprehensive backup and disaster recovery mechanisms.

“Beyond that, there is clearly a need for effective DDoS and malware protection, strong authentication, encryption and patch management,” Cobb says.

Key findings of the survey are as follows:

Exploiting existing software vulnerabilities and web-borne malware attacks are the most common security incidents. According to 78% of respondents, the most common security incident is the exploitation of existing software vulnerabilities greater than three months old.

On average, organisations have an advanced persistent threat (APT) incident every three months. Respondents experienced an APT attack about every three months during the last year. In fact, 63% said the primary consequences of APTs and zero-day attacks were IT downtime followed by the inability to provide services (46% of respondents), which create serious risks for patient treatment.

Hackers are most interested in stealing patient information. The most attractive and lucrative target for unauthorised access and abuse can be found in patients' medical records, according to 81% of respondents.

Healthcare organisations worry most about system failures. The study found 79% of respondents said that system failures are one of the top three threats facing their organisations. This is followed by cyber attackers (77%) and unsecure medical devices (77%).

Technology poses a greater risk to patient information than employee negligence. The majority (52%) of respondents said legacy systems and new technologies to support cloud and mobile implementations, big data and the Internet of Things increase security vulnerabilities for patient information. Respondents also expressed concern about the impact of employee negligence (46%) and the ineffectiveness of HIPAA-mandated business associate agreements designed to ensure patient information security (45%).

DDoS attacks have cost organisations on average $1.32 million in the past 12 months. The survey showed 37% of respondents say their organisation experienced a DDoS attack that caused a disruption to operations and/or system downtime about every four months. These attacks cost an average of $1.32 million each, including lost productivity, reputation loss and brand damage, the study found.

Healthcare organisations need a healthy dose of investment in technologies. On average, healthcare organisations represented in this research spend $23 million annually on IT; 12 percent on average is allocated to information security. Since an average of $1.3 million is spent annually for DDoS attacks alone, a business case can be made to increase technology investments to reduce the frequency of successful attacks.

"Based on our field research, healthcare organisations are struggling to deal with a variety of threats, but they are pessimistic about their ability to mitigate risks, vulnerabilities and attacks," says Larry Ponemon, The Ponemon Institute chairman and founder.

"As evidenced by the headline-grabbing data breaches over the past few years at large insurers and healthcare systems, hackers are finding the most lucrative information in patient medical records. As a result, there is more pressure than ever for healthcare organisations to refine their cybersecurity strategies,” he says.

Industrial control component vulnerabilities up 30%
Positive Technologies says exploitation of these vulnerabilities could disturb operations by disrupting command transfer between components.
McAfee announces Google Cloud Platform support
McAfee MVISION Cloud now integrates with GCP Cloud SCC to help security professionals gain visibility and control over their cloud resources.
WatchGuard announces A/NZ partners awards
Four Australian companies were named partner award winners at the WatchGuard conference in Vietnam.
Telstra’s 2019 cybersecurity report
Cybersecurity remains a top business priority as the estimated number of undetected security breaches grows.
Why AI and behaviour analytics should be essential to enterprises
Cyber threats continue to increase in number and severity, prompting cybersecurity experts to seek new ways to stop malicious actors.
Scammers targeting more countries in sextortion scam - ESET
The attacker in the email claims they have hacked the intended victim's device, and have recorded the person while watching pornographic content.
Cryptojacking and failure to patch still major threats - Ixia
Compromised enterprise networks from unpatched vulnerabilities and bad security hygiene continued to be fertile ground for hackers in 2018.
Why cybersecurity remains a top business priority
One in two Australian businesses estimated that they will receive fines for being in breach of new legislation.