Managing Supply Chain Challenges During the COVID-19 Crisis episode artwork

EPISODE · Mar 25, 2020

Managing Supply Chain Challenges During the COVID-19 Crisis

from Info Risk Today Podcast · host InfoRiskToday.com

While responding to the COVID-19 crisis, supply chain risks can be better managed if an organization continues to rely on its longtime vendors, says Daniel Bowden, CISO at Sentara Healthcare, who offers insights on third-party security risk management in the current environment.

Episode metadata supplied by the publisher feed · Published Mar 25, 2020

Embed this episode

NOW PLAYING

Managing Supply Chain Challenges During the COVID-19 Crisis

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Marianne Kolbesak-McGee, Executive Editor at Information Security Media Group. Today I'm speaking with Daniel Bowden, CISO of Sentara Healthcare in Virginia. So Dan, over the last year, we've seen quite a few major health data breaches and cyber attacks reported involving vendors that range from debt collection agencies to cloud-based EHR providers and other third parties. What are some of the key security and privacy lessons that you see emerging from these incidents for the healthcare sector?

Well, in healthcare, it's really challenging because we rely on suppliers and vendors and third-party services for so much of what we do. And what I've learned is you have to consider sort of all three aspects of what we consider good security programs, the confidentiality, integrity, and availability. And so we try to size up what are we getting from this particular service provider? Is it equipment?

Is it services? Is it both? And we've learned that you have to understand the threat vectors holistically, and then you need to understand what are the threat vectors that may be more specific or more likely to become something that is exploited with that particular vendor. And so we spend a lot of time into that and trying to figure out, well, what's the best recipe for assessing what they do and what are the threats and vulnerabilities that are most associated with that as we get started into our assessment process.

So Dan, with that said, depending on their size, healthcare organizations do deal with dozens or even thousands of vendors on a regular basis. What are some of the biggest challenges you see in managing all these assorted security-related risks that these various vendors do pose? I think the first thing is just internal health system governance. And this starts with an understanding from the board and executive leadership that it's important and we recognize these third parties as being a potential vulnerability or having potential vulnerabilities that can put our services and data at risk.

But I think that's the initial big picture understanding. Once that's established between then that governance is understood, now you've got this partnership that needs to play out among the security organization, general counsel, privacy, materials management, risk management, possibly others, so that you can understand, well, what is the total domain of services and products that we rely on through which if there was a loss of data, loss of equipment, service disruption would cause a material issue or incident for our organization. And then those organizations need to work together to determine how do we vet and onboard and make recommendations to the business about what should be put into contractual arrangements, what things should be monitored, and how do we basically hold this organization to task as per their responsibilities either as a business associate under HIPAA or as a partner that we may be sharing data with. And so it kind of starts, for me, at that governance level of very high-level understanding from the board and the executive leadership down to this partnership of organizations that, you know, one, some of us, you know, security, my job is to look out for the organization's assets, where general counsel's job is to look out for the interests of the organization.

So we all need to work together as well as with those other teams I mentioned to build a fabric and a process that our business units understand that they don't perceive as being overly burdensome or bureaucratic and that brings value and helps them see what the potential threats and vulnerabilities are and also provide them appropriate recommendations that they can act on whether they decide to go forward doing business with that organization or not. So Dan, what about supply chain issues involving COVID-19 and the possibility that you might be forced to bring on board connected medical devices and other equipment and supplies from vendors that the organization may not have worked with much or perhaps not at all in the past due to the various shortages that we're seeing? What sorts of security issues does that pose potentially and how will you address that? I've had the opportunity the last few days, last handful of days to work in our health system command center.

And all the health systems in the country right now, all of us are trying to figure out how are we going to build capacity. And really that's the purpose of all these social distancing and other measures in place are to slow down everyone's activity so health systems can build capacity and respond as more people are exposed and become ill. So to give you an example, you've got health systems in every major populated area trying to figure out how do we build another thousand bed hospital or three or four or 500 bed hospitals. And these all being dedicated to COVID-19 patients.

And so the supply chain obviously, and you all you have to do is turn on the news to hear some of the highlights. On one end, we've got, we're talking about ventilators and masks and gowns and ultimately, depending on what we're trying to provide service for, there could be medical devices and other services. I suspect this is just me suspecting right now because we haven't built anything yet. We're in the process of building it.

We haven't finished it, so I can't say what the final outcome was, but in terms of how we receive and treat potential COVID-19 patients, I'm hopeful that, and what we're trying to do because we need to respond so quickly, we're trying to keep all of those variables, both supply chain variables, very much known with suppliers and options we already use. And so that's the approach we are trying to take. And often that's going to be the fastest way to get things done. I've not yet run into a situation where we're, we're going into a situation with a brand new supplier that may bring a new risk vector to us in terms of confidentiality, integrity, or availability.

But when that happens, it'll be, I'm confident our organization will have the appropriate risk discussion, but as known, we're, we're now talking about saving people's lives. And so we want to make sure that the discussion is appropriate, but done in a way that we still allow our care providers get their job done as quickly as possible. And so I think we're having this conversation in four weeks. Maybe there's a little more to talk about there, but right now we're trying to keep with the known variables.

I suspect we will. And as you've heard, even with that, there's still massive shortages of things. And so even if we happen to find a new supplier, we're probably getting the same product. And, but we're trying to keep that clinical environment very much known and something that the technology organization will get rolled out for the care providers very quickly.

And so we, we won't be doing a lot of new custom solutions with custom suppliers and custom service providers. So Dan, what about managing the lifecycle risks that vendors pose with their services and their offerings? For instance, we hear a lot often about misconfigurations going awry when a vendor updates products or software potentially leaving patient data exposed or maybe even a lack of patching when there is a vulnerability. How can healthcare sector entities and vendors get a better handle on those sorts of issues?

This is interesting. And I think all of, all of us as CISOs, we're generally aligned. I think some of us maybe go a little bit different paths depending on our individual circumstances and experiences. So far, you know, it's a best help my organization today.

We take whatever the circumstances and we try to ultimately bring it back to vulnerability management. And sometimes I think when you try to manage too many things, it burdens the conversation and it's difficult to make progress. And for example, I don't see any sense in continually beating up the same device manufacturer over the same vulnerability that they haven't patched for two years and there's no evidence that they're ever going to patch it. As a CISO, I feel it's irresponsible for me to just keep pointing that out.

What I need to do is say, what can I and the IT organization do to block the applicable threats from exploiting that vulnerability? And then that's what I talk about. And I think that we're, you know, at this point in time in 2020, we're at a point where I believe the manufacturers understand the expectations are much different than they were five years ago. I believe they're trying to get on board.

I do believe there still needs to be a robust conversation between the health delivery organizations and the medical device manufacturers to find out how can we get new operating systems to market quicker or how can we make it more flexible so that patches can be more easily applied? Those are important conversations, but at the end of the day, the way I operate and the way my team operates, you're not going to see some big kind of wall of shame dashboard about which vendors don't work well with us and which vendors won't patch things. I sit down and show the organization, hey, these are the kind of vulnerabilities that are out there. If they're not getting patched with software, this is how they are getting patched, meaning how am I keeping the vulnerability from becoming exploited?

And so I think, as I mentioned, there's a lot of work to do there, but I'm confident that we're all on the right path and want to go to the same good place and make medical devices more easy to manage in the future. Dan, any promising or emerging security technologies that you're assessing these days that might be beneficial in the future? There's one in particular, and I don't know exactly which product I'm assessing, but what I'm calling it for my team is kind of next generation identity proofing and access. And I think with a lot of organizations, I'm not just talking health systems, I'm talking anywhere in life, any part of our life, the prevalence of scams and fraud and people kind of spoofing their way into an identity that's not theirs to perpetrate the crime is running rampant.

And so we're putting a lot of work into how do we get a level of identity proofing established when we have our very first encounter with Marianne to the point that with just a couple of factors that we see about Marianne, when she and or her device hit our network, we have a level of trust built up in that identity that maybe we go as far as not even asking Marianne for a password or maybe Marianne never has a password

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on March 25, 2020.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!