Hi, I'm Marianne Koblesack McKee, executive editor at Information Security Media Group. I'm here at the HIMS conference speaking with Nitin Natarajan, who is Deputy Director at cisa. We're going to be discussing some of the top cyber issues facing the healthcare sector. Welcome, Deputy Director Narajan, great to meet you.
Glad to be here. Thank you so much for talking to us. So from your viewpoint at cisa, what are the top cyber threats to the healthcare sector right now that are most concerning to you and why? So let's say that the number one thing we're looking at is concerned ransomware.
We're seeing a lot of ransomware landscape change. We're seeing the potential, the volume of adversaries are changing, the complexity and attack is changing, and as well as the victim landscape is changing as well. So I think that's our largest challenges. We have organizations in the past weren't necessarily on the radar, so to speak, by a lot of our adversaries when we're talking about nation states, whether we're talking about cyber terrorists or talking about criminal organizations.
So the victim landscape is changing, our adversary landscape is changing because they're getting, well resourced, more complicated than their types of attacks and the increase in the frequency and volume of attacks. So that really is one of our largest concerns in the healthcare sector, because the potential to click on anything and to have a widespread impact across an IT system and healthcare facility and potentially resulting in things like ER diversions and potential patient safety issues, you know, really has us concern about making sure that we're doing all we can to stop ransomware attacks against the health care sector. And in terms of the ransomware attacks you're seeing in the healthcare sector, how are they evolving? Are they going downstream to smaller entities?
Are they becoming more sophisticated? And are there other sorts of attacks that also are disruptive, such as DDoS that are also worrisome at this point? It's a combination of all of those, I think. So.
There used to be a perception, I think in a lot of rural facilities that we're not the big city, we don't have to worry about it. Nobody knows we're even here, we're not concerned. But really what we're seeing across the nation and frankly even beyond the healthcare space to other sectors of critical infrastructure, is attacks against organizations large and small, against those public and private, rural and urban. So there's no longer organizations that are protected or exempted.
You know, we also talked about healthcare in the past where when it came to things like Warfare that health care was always protected, right. You never, you never bonded the tent that had the red cross on it. You never impacted healthcare because it was always kind of this protected neutral space. We're not seeing that anymore.
You know, healthcare is a potential target just as any other type of sector. So I think while ransomware on the table, we are concerned about other types of attacks, DDoS attacks as well, obviously concerns about medical device safety and other issues. So really looking across the board at what organizations are seeing across the nation, we're looking at taxi procedures globally and trying to prepare when could that reach the United States. And recognizing there's no borders, right.
We don't have to wait for an adversary to cross an ocean to cancel us. You know, it's a lot easier and quicker. It's not space in the chemic space. And so what are some of the common vulnerabilities that you see nation states and other bad actors exploiting in the healthcare sector that healthcare sector entities should be paying closer attention to?
We've really tried to focus on known exploited vulnerabilities. I think when we talk about vulnerabilities in general, we know that we're never going to be able to patch, mitigate every single vulnerability that's out there. So what we're trying to do is work our partners, both domestically and globally, in the public and the private sectors, to understand what is being exploited in the cyber arena and to be able to provide those notifications to facilities and to organizations. So in the healthcare space, for instance, we provide notifications over 63 healthcare entities based on exploitations that we've seen coming out of our known exploit vulnerabilities, what we call our CAV catalog, and that's a catalog that is updated regularly as we see more vulnerabilities being exploited to make sure that we can get that information out into the hands of those who might be impacted.
Now, President Biden recently released a national cybersecurity strategy that addresses many issues involving critical infrastructure sectors, including the healthcare sector. What do you think are some of the most important aspects for healthcare sector entities to consider in terms of President Biden's national cybersecurity strategy? I think one of the largest issues we're focusing on this is looking at things like secure design, secure by default. So how do we ensure that what we are purchasing, what manufacturers are developing, both in software and hardware, is secure out of the box?
Right. And that security features are not additional packages, you need to buy additional add ons, but the hardware software is secure by default and that's also secure by design that we're using memory safe languages. So we're using the right technology to ensure that we're building security upfront into what we're doing. And the onus really is on consumer to ensure that we're demanding that traffic from our partners as we look to invest.
But we're also looking at how we increase the awareness of cybersecurity and away from the CISOs and CSOs who believe, right, we don't have to sell them on this, but how do we get CEOs and boards to understand the risks that they're accepting? And the analogy, I always use this three legged tool. You know, we spend a lot of time in organizations talk about risk identification and we spend a lot of time talking about risk mitigation. We forget the third leg of that stool, which is any risk we've identified and we've not mitigated.
We've accepted and we accept risk every day what we do, especially in the healthcare space. But do we truly understand at the CEO and board level of the risks that they're accepting for that organization when it comes to cybersecurity? And I think we still have a ways to go there. And we're seeing this not just in the healthcare sector, but a lot like with those other sectors that we need to increase that CEO and board awareness.
And so I think the National Cybersecurity Strategy is a great document. It's something we've worked with the Austin National Cyber Director very closely on and we're excited to look at those and other elements that are going to help us really change the landscape and of cybersecurity procrastination and also make sure people understand the importance that this truly is a national security issue. This is not something we should just be leaving to CIOs and CISOs while they're very capable. And you know, this truly is going to take all of us together to help them solve very complex challenges that are only going to grow more complex in the days and months to come.
As we see things like AI machine learning, it seems like it's exploding tenfold. Every morning we wake up, it seems like it's made the progress, how we work together to stay ahead of those that wish us harm utilizing these new technologies. And so the President Biden's National Cybersecurity Strategy also emphasizes the need for minimum security standards for critical infrastructure sectors as well as accountability for third party sellers of software and hardware to take more responsibility for the security of these products. How do you think that impacts the healthcare sector?
Are there areas that the healthcare sector sort of needs to be paying more attention to when it comes to third parties and minimum security standards? And, you know, we have kepa, but that's not as strong as perhaps the other things that maybe the NIST framework requires. What are your thoughts on that? So I think we look at the healthcare space, there's a lot of things that can happen.
One of things is knowing what you're buying and understanding how that technology goes into your broader health care ecosystem. I think it's also looking at it not as an isolated entity within our healthcare facilities, but really understanding that broader landscape of both IT as well as ot, as well as mental health and patient safety, and not treating them separately, but really looking at the IT ecosystem within our facilities, understanding what bringing in new technology is going to impact more broadly across that entity. So think of a lot of those types of steps and working with industry to make sure that we are raising our standards as buyers, to make sure we are investing adequately. You know, often, you know, the most secure model may not be the cheapest opportunity.
So how do we make those decisions on where we need to invest and that we understand what we're buying, how we're buying, and how that integrates to our broader safety acceptance and security acceptance within our institutions. And in terms of cisa, what sorts of resources are available to the healthcare sector from the agency that might help them with some of the cyber challenges that we're just discussing? So I think the first step is really our regional team. So CISA really wants to make sure we have expertise in your communities throughout the nation.
So we have a regional footprint of over 600 people in your communities across the nation who can help address a wide swath of issues, everything from physical security to cybersecurity, emergency communications and others. These are advisors in local communities that can work with your institutions to help access CISA services. And whether we're talking about scalable services like cyber hiking, vulnerability scanning, others where we can just skyrocket enrollment in a very short amount of time to some of our more complex capabilities, look at penetration testing and other capabilities which we again, can't necessarily scale heavily, but we have available for infrastructure partners, I think also being able to help convey the messaging and being able to bridge that gap, often between our technical experts and some of our CEOs and boards. So tapping into those regional teams can be extremely helpful.
Tapping into the services that are available on our website, making sure we get the right service, the right individuals and Making sure that we're pairing frankly, the material of an agency or organization with the right tools and resources truly is critical. Going into an organization that is cybersecurity, that it's new in cybersecurity, immature, say, and coming with a very complex analysis and saying you need to do these 50 things at $8 billion is unviable. So how do we pair those right tools and services and capabilities with how do we make sure we're looking at guidance that speaks both to the technical community and to non technical community? And we only do that by getting feedback.
And especially when we talk about the health sector, we want to make sure that what we're putting out there speaks that community. And the way we do that is through dialogue, through persistent collaboration and feedback. And in terms of collaboration between federal agencies and the healthcare sector, what might improve cyber readiness of a sector if there's more collaboration? I think the reason is communication and understanding that building that comfort and that trust, that we can have an honest conversation when a cyber incident occurs, that we can have that technical dialogue and not necessarily legal dialogue, and that we're able to share indicators of compromise, we're able to share ttps and what folks are saying.
So we can then go back and help the broader sector and not just help the institutions reporting to us, but helping their neighbors and their partners directly throughout the globe to help protect themselves. Trust takes time. So we want to continue to build that dialogue, continue to build that trust and collaboration with our partners at hhs. And I think that's really how we're going to move this together.
We're not going to move this in a transactional manner. We're not going to stay ahead of the adversary if we just keep a lot of things kind of over the fence, so to speak, like we're playing tennis, you know, we need to play something more collaborative maybe. I'm not sure if I think we're able to work together throughout this process versus again, just kind of loving something over the fence with each other. And finally, I was reading over your bio and saw that earlier in your career you were a first responder in New York, including service as a flight paramedic.
What sort of experience did that bring to you as you work with healthcare sector entities that are dealing with cyber challenges in that sort of urgent to respond? I think your background really helped me understand kind of the fragility, frankly, our health care system. I think understanding the complexity of our health care system and that this isn't simple to do. And if I offered it easy everybody would be doing it and that this really is a complex challenge.
But also watching the inner workings of hospital and seeing all the different parts that go together to treat that patient, everything from the supply chain through it, through clinical care at bedside, and then looking beyond the borders of that institution to understand, you know, facility supplies, again medical supplies and equipment, helps me understand kind of how do we better ensure that we're looking at this from a system perspective and not an institution perspective. That's really our approach at CISA is not just to look at healthcare system but frankly as a system of systems. Because an attack against the energy gridor against water treatment plant also has a cascade impact in the downstream analysis. Understanding that the loss of water has an impact of possible not from a portable perspective, but from a sterilization perspective and how we make sure that we're taking some of these complexities to heart as we look at how we better protect the industry and nation.
Thank you so much, Deputy Director Natarajan. I was speaking Natarajan of sessa. I'm Marian of Information Security Media Group. Thanks for joining us.