I'm Marianne Kolbasack-McGee, Executive Editor at Information Security Media Group. Today I'm speaking with Chris Henderson, who is Senior Director of Threat Operations at cybersecurity firm Huntress. We're going to be talking about cyber threat trends in healthcare. So Chris, from your perspective as Senior Director of Threat Operations, what are some of the most disturbing cyber threat trends that you're seeing in the healthcare sector right now and why?
The healthcare sector is getting hit with a lot of the same threats that we see facing most private industry. You have a combination of state-sponsored threat attacks, you have cybercriminal groups, and you also have criminals of opportunity just looking for the quickest buck. In all of these cases, unfortunately, healthcare is such an attractive target just due to the duty of care that they have around patient care and health and safety. But additionally, with the massive acquisition and mergers going on and consolidation within the industry, you have a lot of middle targets that aren't direct healthcare providers, but in their supply chain and the impact that they can make from a one-to-many standpoint makes them very attractive targets.
Being able to take down somebody that serves many healthcare organizations and put the pressure on that organization to pay is increasing the likelihood that those threat actors have a positive monetary outcome from the attack. So when you look at the threats facing healthcare, not only is it state-sponsored attacks trying to disrupt local healthcare efforts, but also opportunistic criminals looking for quick paydays, as well as more organized crime groups that are going after the large centers likely to pay. So Chris, what sorts of cybersecurity weaknesses are commonly getting healthcare sector entities in the most trouble from what you see and why? The health organizations that Huntress covers, last year, predominantly, we were seeing Trojans doing the most damage, at least from initial access.
You also have remote access Trojans as well, a little bit different, but these are typically threats that are, they're taking advantage of people who have momentary lapses in judgment, right? Either through phishing campaigns or other social engineering attacks. You have employees that are rushing around trying to do important jobs, such as saving lives. And we see threat actors really taking advantage of that and hoping to jump on the momentary lapse of judgment and getting them to either click a link via an email or some other means of delivery, but really hoping that people are moving too fast to really be cautious and take their time to inspect either links or other artifacts to make sure that they're safe before engaging with them.
So Chris, often healthcare sector entities hope that cyber insurance will provide a level of protection for the organization in case they do fall victim to some of these trends that we were just discussing. With that said, what are cyber insurance providers emphasizing these days when it comes to the cybersecurity controls and practices that they do expect from prospective healthcare sector clients? Yeah, cyber insurance is looking now for things such as help desk authentication. When your help desk is serving a request for an MFA reset or an account reset, what are the steps that they're going through to verify that the person making that request is legitimate and who they say that they are?
We see last year the groups like Lapis really made a name for themselves by compromising some of the most major names in the Fortune 100. And the tactics that they used primarily were just social engineering. These were not exploits of vulnerabilities or unpatched. They were largely not even technical in nature.
It was humans convincing other humans to provide them access because they asked and convinced them that they were somebody of importance. And so now you see the cyber insurance industry pivoting and their risk right underwriters are asking about the practices that the healthcare industry is taking in order to ensure that these steps are being followed to ensure that requesters for admin accounts are who they say they are. Additionally, you still see them looking for things like multifactor authentication on accounts. How many administrators do you have?
How do you lock down those administrative accounts? It's interesting looking at the, almost the lag time of the underwriting versus when the threat reports came out. We really see the underwriting questionnaires today asking about the threat intelligence that most of the community was talking about six months to a year ago. So Chris, what other trends are evolving in terms of potentially stricter cyber insurance requirements when it comes to new coverage types and emerging cybersecurity threats?
From the underwriting perspective, cyber insurance is one of the only insurance vehicles in which the risk that you're insuring against is actively trying to thwart you. Fire is not trying to constantly figure out better ways to burn. Cars are not figuring out better ways to hit each other. And so what we're seeing is sort of forward-looking questions, but policies are being underwritten with risk models that are understanding that they're likely already wrong.
And so as cybercriminals are pivoting and actively moving to circumvent the controls that the cyber insurance industry is asking for us to deploy, those cyber insurance underwriters are needing to pivot even faster as well. And so I think, you know, forward-looking, we're likely going to start seeing shorter-term limits on policies so that they're underwriting can pivot faster and be more reactive to the threat intelligence that's being provided to the community. So Chris, when it comes to cyber insurance requirements, how are they aligning with increased regulatory pressure on the healthcare sector when it comes to protecting data in healthcare? Thus far, I've seen those two tracking independently, but not largely influencing each other.
I think you see the regulatory environment looking to put stricter pressures on the consolidation of the industries and care of the technology through that. But you also see the cyber insurance industry almost self-regulating just due to the loss that they had last year and the previous year. And so while government regulation is definitely coming to step in and help make this problem better, I think private industry is attacking it from a separate angle as well, using the financial vehicles in order to drive better security practices. And when it comes to cyber insurance premiums, what are you seeing in terms of healthcare sector trends?
Yeah, I mean, those are increasing as well as everybody else's. The cyber insurance industry, like I mentioned a little earlier, it's waging a war in which the risk that it is holding for you is actively changing. And so most other insurance vehicles, they allow sort of a finite risk model. And so when you transfer the risk to the insurance agency and pay them for that privilege, they understand largely the risk that they're purchasing.
What we see is the healthcare industry, cyber insurance industry, for the larger cyber insurance industry, they're now requiring premiums that are buying an unknown risk. And so as you see the payouts get larger and larger and the cyber insurance becoming even less profitable, these premiums are simply increasing because they're being forced to hold an unknown risk that is actively trying to defeat the controls that they are putting in place to balance that risk for you. And finally, Chris, what else are you watching these days when it comes to emerging cyber trends in healthcare? Yeah, I mean, we are watching any of the alerts that come through our desk for new players in the game.
When we look at healthcare, it's a very soft target. And while we do see advanced persistent threats and some of the more mature players, we also see brand new affiliates, brand new actors spinning up and using healthcare almost as a testing ground. We only saw roughly 40% of the ransomware that was deployed last year was from named players. A lot of it was new, almost being tested out.
And so I think we'll see, we'll continue to see novel attacks against healthcare just due to the speed at which they need to work and the unfortunate lack of time they have to really inspect some of the digital assets that they engage with. And we'll continue to see sort of the cyber insurance industry struggle to balance the risks. Well, thank you so much, Chris. I've been speaking to Chris Henderson.
I'm Marianne Kolbesak-McGee of Information Security Media Group. Thanks for joining us.