Story image

Healthcare organisations buckle under pressure of cyber attacks

02 Mar 16

The healthcare sector is slow to update technology and as such is woefully unprepared for an oncoming onslaught of cyber attacks, according to a recent report.

The ESET and the Ponemon Institute report 'The State of Cybersecurity in Healthcare Organisations in 2016', suggests healthcare agencies currently average about one cyber attack per month. Furthermore, almost half (48%) of respondents say their organisations have experienced an incident involving the loss or exposure of patient information during the last 12 months. However, despite these incidents, only half indicated their organisation has an incident response plan in place, the study shows.

"The concurrence of technology advances and delays in technology updates creates a perfect storm for healthcare IT security," says Stephen Cobb, ESET senior security researcher.

"The healthcare sector needs to organise incident response processes at the same level as cyber criminals to properly protect health data relative to current and future threat levels. A good start would be for all organisations to put incident response processes in place, including comprehensive backup and disaster recovery mechanisms.

“Beyond that, there is clearly a need for effective DDoS and malware protection, strong authentication, encryption and patch management,” Cobb says.

Key findings of the survey are as follows:

Exploiting existing software vulnerabilities and web-borne malware attacks are the most common security incidents. According to 78% of respondents, the most common security incident is the exploitation of existing software vulnerabilities greater than three months old.

On average, organisations have an advanced persistent threat (APT) incident every three months. Respondents experienced an APT attack about every three months during the last year. In fact, 63% said the primary consequences of APTs and zero-day attacks were IT downtime followed by the inability to provide services (46% of respondents), which create serious risks for patient treatment.

Hackers are most interested in stealing patient information. The most attractive and lucrative target for unauthorised access and abuse can be found in patients' medical records, according to 81% of respondents.

Healthcare organisations worry most about system failures. The study found 79% of respondents said that system failures are one of the top three threats facing their organisations. This is followed by cyber attackers (77%) and unsecure medical devices (77%).

Technology poses a greater risk to patient information than employee negligence. The majority (52%) of respondents said legacy systems and new technologies to support cloud and mobile implementations, big data and the Internet of Things increase security vulnerabilities for patient information. Respondents also expressed concern about the impact of employee negligence (46%) and the ineffectiveness of HIPAA-mandated business associate agreements designed to ensure patient information security (45%).

DDoS attacks have cost organisations on average $1.32 million in the past 12 months. The survey showed 37% of respondents say their organisation experienced a DDoS attack that caused a disruption to operations and/or system downtime about every four months. These attacks cost an average of $1.32 million each, including lost productivity, reputation loss and brand damage, the study found.

Healthcare organisations need a healthy dose of investment in technologies. On average, healthcare organisations represented in this research spend $23 million annually on IT; 12 percent on average is allocated to information security. Since an average of $1.3 million is spent annually for DDoS attacks alone, a business case can be made to increase technology investments to reduce the frequency of successful attacks.

"Based on our field research, healthcare organisations are struggling to deal with a variety of threats, but they are pessimistic about their ability to mitigate risks, vulnerabilities and attacks," says Larry Ponemon, The Ponemon Institute chairman and founder.

"As evidenced by the headline-grabbing data breaches over the past few years at large insurers and healthcare systems, hackers are finding the most lucrative information in patient medical records. As a result, there is more pressure than ever for healthcare organisations to refine their cybersecurity strategies,” he says.

Cylance makes APIs available in endpoint detection offering
Extensive APIs enable security teams to more efficiently view, enrich, and contextualise real-time intelligence collected at the endpoint to keep systems secure.
SolarWinds adds SDN monitoring support to network management portfolio
SolarWinds announced a broad refresh to its network management portfolio, as well as key enhancements to the Orion Platform. 
JASK prepares for global rollout of their AI-powered ASOC platform
The JASK ASOC platform automates alert investigations, supposedly freeing the SOC analyst to do what machines can’t. 
Pitfalls to avoid when configuring cloud firewalls
Flexibility and granularity of security controls is good but can still represent a risk for new cloud adopters that don’t recognise some of the configuration pitfalls.
Securing hotel technology to protect customer information
Network security risks increase exponentially as hotels look to incorporate newer technologies to support a range of IoT devices, including smart door locks.
Why total visibility is the key to zero trust
Over time, the basic zero trust model has evolved and matured into what Forrester calls the Zero Trust eXtended (ZTX) Ecosystem.
Gartner names Proofpoint Leader in enterprise information archiving
The report provides a detailed overview of the enterprise information archiving market and evaluates vendors based on completeness of vision and ability to execute.
WatchGuard appoints new channel distributors in A/NZ
The appointments will enable WatchGuard to expand its regional channel reseller footprint.