I'm Mary Ann Colbus, Executive Editor at Information Security Media Group. I'm at HIMS in Orlando speaking with Assistant Deputy Director Natarajan. Welcome. Welcome.
Great to be here. Good to see you here. Yeah, indeed. Thanks so much for doing this.
So over the last several months or years now, what have been some of the most concerning developing trends that we've been seeing involving cyber threats facing the health care sector? Any new or emergent developments that are especially worrisome for the health care sector right now and why? I think the largest concern is that we're continuing to see significant amount of tax targeted at health care institutions across the nation. We're seeing in urban America.
We're seeing in rural America. And we're seeing with the population in health care that traditionally was never attacked. Right? Traditionally, we've protected health care institutions.
We would never attack health care institutions that would have an impact on civilians or an impact on patient safety or loss of life. We're seeing a continuing to see that level of attack against health care institutions across the nation and that within itself is very concerning. When we look at anyone's top three list, top five list, whether we're talking about ransomware or other types of attacks, health care is always on that list. And I think that's to me is what's very concerning right now.
So in recent days and weeks, we've seen some major cyber incidents on the health care sector and the most recent being the changed health care opt-in cyber attack that's proved to be very disruptive for many entities in the health care sector, what lessons are emerging from this so far? It's still kind of early in. Anything in terms of indicators of compromise or of being prepared, the lessons, what lessons are most important at this point? So I think it's still a little bit early to tell a lot of details.
We've tried to be transparent and share information that we do have available. A lot of our partners have shared information as well, the health ISAC and others. So we want to continue to make sure people know what we know, especially in the early stages of an incident. I think when we look more broadly, a lot of it comes down to basic cyber hygiene.
It comes down to patching. It comes down to knowing what software or hardware you're purchasing comes down to in terms of phishing and those things not clicking on the links and on the email. I think it reinforces our need to message a lot of these basics and I think a lot of organizations look past the basics. They go, oh, that's too simple.
Or that's not going to be the vector of attack. But what we see time and time again in sectors, as we look at all 16 critical instructors sectors, is that those are the vectors of attack and those basic fundamental elements that we need people to continue to focus on. They're going to make a large difference in our general cybersecurity across the nation, whether that's multi-factor authentication, whether that's patching and updating and those types of things really do make a difference across the nation. So we also have seen some attackers that are actually going after the patience, who say that they extort any sort of advice for entities in terms of dealing with these sort of evolving threat, you know, attackers who are just kind of being very novel and how they try to shake down either an organization or the patience.
What can organizations do to kind of buffer that a bit? A lot of it comes down to knowing what software hardware you have, knowing what potential vulnerabilities you have, reacting to those vulnerabilities and addressing those vulnerabilities as quickly as possible. I think there's a lot of lack of awareness as to what people are buying these days and we need to do more, we need people to take a deeper dive into their software, but frankly on the other side we need to get industry to build software that is more secure by design and more secure by default. So the only shouldn't be on us as the end user to understand every aspect of what we're buying, especially given that a lot of those providers may not have a deep technical knowledge, but really on getting industry to pivot and to be able to build software and hardware that is more secure, that allows us to build more resilience across the nation.
I've also said for a while now that to me healthcare facilities are one-stop-shops. It's not just about intellectual property, there's PII, there's billing information, there's all this type of data that frankly you're not going to find in a lot of other sectors concentrated in this single place. And so if I were somebody who wanted to cause more, if I were somebody who wanted to ex-vail information and then sell that or potentially grant it, it's a one-stop-shop and I think that also makes healthcare a prime target. You mentioned a good point about the one-stop-shop and also vendors, the big vendors, whether it was change healthcare or other vendors that are not healthcare specific being targeted.
Any lessons in terms of healthcare sector entities being prepared for if one of their major vendors gets hit and it not only disrupts them but it disrupts their partner supply chain sort of things? I think that's one of the lessons I think we'll see coming out of the current incident is that need for resilience. We've really been trying to make sure people understand how to build resilience. We're never going to prevent every incident from happening, we're never going to protect every organization until we have a magic bubble that can protect us.
So the question is how do we bounce back? How do we build resilience in our system that allows us to recover from backups much sooner, that allows us to understand our supply chain vulnerabilities, to know that we're dependent upon a product or a chip or an envy coming from this location, whether in the United States or internationally, and being able to mitigate that potential vulnerability and risk. I don't think we've spent enough time really understanding our supply chains, especially in healthcare when you look at the volume of products that healthcare institutions dependent upon both hardware software but, frankly, just day-to-day medical equipment and supplies and making sure that you understand those vulnerabilities and that you have the redundancies built in to mitigate risks if you want to entity where to go down. So now the Biden administration has been focused on strategies for strengths with the cybersecurity and critical infrastructure sectors.
What are the most important aspects of this strategy that you think the healthcare sector should be focused on implementing out there organizations right now? What is it that they sometimes fall back on, they lag on, but they really need to kind of pump it up? I think one of the biggest things is reporting. It's making sure that we understand what an incident has happened.
I think when we look at reporting, it's not about telling the government, and we put it in some magic box and nothing ever happens with it. So this truly wants reporting from the basis of how do we take that information, how do we mix it with what we're seeing from partners around the globe, from academic researchers, from information from the intelligence community and others, how do we put that together to help understand and get information out about indicators of compromise and other types of information that are helpful not only to that victim, but frankly to the sector or sectors at large. Because that information is not just going to help that individuals can help other organizations protect themselves from a similar type of attack, and that really is the fundamental basis for what we want to receive that reporting for. And I think that's an area that we need to do better across all the sectors.
Rapid reporting will allow us to help you and to help your fellow healthcare sector partners to better respond to that type of an incident. And where are some of the most concerning vulnerabilities these days that the nation states and other bad actors are exploiting in healthcare that entities should also be paying more attention to whether it's patching or being aware that these systems are even in their environments? A lot of it is patching, and I recognize it's easy for us to sit here at the federal level and say, you should patch, and you should patch quickly and immediately, right? It's not always that simple.
In some cases, obviously there's doubt-type concerns and dys complexity and so patching and cascading impact from that, but I think really being able to understand the importance of patching rapidly, the importance of having your systems designed in a way that allows you to do that really can make a difference. I think it's also going back to the basics, you know, making sure that you're looking at things like multi-factor authentication, making sure that you have, you know the software hardware that you're buying, which often we don't. And so I think those are the types of things that we're seeing. Also IT modernization is a huge issue.
When we look at a lot of systems, a lot of attacks across all sectors, we're seeing a lot of very outdated and equated software hardware. I have been in a lot of places where people are very proud to show me Windows 95, and you know, the level of pride that is concerning, and I think that we need to invest in that as well, and it's hard. When you look at profit margins and healthcare institutions are not extremely high, and then when you look at where do we invest, it's not an easy decision to make. I think this is frankly also why we need to get this discussion out of just the CISO community and elevate that into CEOs and boards of directors.
When we look at risk, that risk acceptance shouldn't reside only with the CISO, that risk acceptance should be seen with the CEOs and boards, and they need to be aware of the risks that they're accepting in their organization due to the inability to invest in. We can't invest in everything, so I fully understand that, but that risk acceptance needs to be at that CEO and board level. We're hearing so much about AI-enabled healthcare, machine learning healthcare, and the advancements that these things could bring to healthcare. On the flip side, what's most concerning to you in terms of AI in the hands of the bad guys right now for healthcare?
So, those are the conversations we're currently having, as you know, CISO is looking at AI in three different ways. One, we're looking at how should we use AI, and how can AI be beneficial to our mission, and from a cyber defense perspective. We're trying to understand how the 16 sectors are going to use critical use of AI, especially healthcare and public health, and understanding where, how much AI are they going to use, what is that going to look like. But the third piece of that we're really focusing on is how are adversaries using AI potentially against us, and whether that's to escalate frequency in severity of attacks, whether that's to help with coding and that type of aspect, whether it's looking at some of the things such as ransomware, and being able to do it at a scale, utilizing AI that we can't.
Whether it's helping with being able to differentiate those phishing emails from being real or not because of the use of generative AI and language capability. So, we're really looking at that across the board, we're still in the early stages, but we want to really be able to understand what our adversaries are planning because we're going to do this. You know, the technology that's only going to be used for good, there is a potential for it to be used for bad, and we need to better understand when to say it out of the adversary. And finally, what are some of the latest or most critical SISA resources that the healthcare sector and they should be utilizing more maybe to help them combat these top threats that we're seeing and to just overall improve their posture?
So, if I had to pick one thing, the one thing would be our cyber hygiene scanning. You know, we have the ability to provide free cyber hygiene scanning and to help people understand what vulnerabilities are facing to get a report on a weekly basis to understand what vulnerabilities are their organizations exposed to, and then marrying that up with our known exploited vulnerabilities are kept listing to really help people understand what's being exploited by adversaries and to focus. But we've actually published last fall a toolkit with our partners at HHS and with partners in the private sector to actually share a whole list of tools and resources that are available for you to charge to help folks build their resilience within their organization and we encourage folks to look at that. We encourage folks to work with our regional teams.
We have cyber experts and physical security experts in communities across the country, encourage them to engage locally so we can get access to the services. But that enrollment, if I had to pick one thing, enrollment and cyber hygiene can really make a difference. We've heard organizations around the country how valuable it's been to help them identify where they need to focus efforts and they've been able to patch and remediate those vulnerabilities very quickly. Some of the data we've seen so far that is within the first three months of enrollment.
People are able to address 80% or more of their vulnerabilities, which is a significant change in their landscape. Well, thank you so much, Deputy Director. I've been speaking to Deputy Director Nitin Nadirajan. I'm Mary Ann Kolbasak-McGhee of Information Security Media Group.
Thanks for joining us. Thank you very much. Thank you.