Nation-State Attacks: Why Healthcare Must Prepare episode artwork

EPISODE · Jan 8, 2020

Nation-State Attacks: Why Healthcare Must Prepare

from Info Risk Today Podcast · host InfoRiskToday.com

As tensions between the U.S. and Iran continue to rise, healthcare organizations need to exercise extra vigilance in shoring up their security to defend against potential Iranian cyberattacks on critical infrastructure sectors, says Errol Weiss of the Health Information Sharing and Analysis Center.

Episode metadata supplied by the publisher feed · Published Jan 8, 2020

Embed this episode

NOW PLAYING

Nation-State Attacks: Why Healthcare Must Prepare

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Marianne Kolbusak McGee, executive editor at Information Security Media Group. As critical infrastructure sectors face the growing potential for nation state cyber attacks, what can the healthcare sector do to be better prepared? Today I'm speaking with Errol Weiss, Chief Security Officer at the Health Information Sharing and Analysis center about the threats and risks facing the healthcare sector. So Errol, in light of the escalating Iranian conflict with the us what cyber threats and cyber risks are you most worried about in terms of the healthcare sector and its critical infrastructure?

The health ISAC is providing awareness to our members to really take a cautious view of what is happening with the escalating tensions. And so as we know, Iran has definitely had a propensity to target their adversaries and launch various campaigns. And so we've got a lot of history that we can look upon. And while they may not have been directly targeting the healthcare sector, there are certainly occurrences where the healthcare sector has had collateral damage from attacks that Iran launched at other targets.

So Errol, with that said, what sorts of attacks are you most worried about in terms of the healthcare sector and its critical infrastructure? So when we look at the history of the attacks that we've seen from Iran, I was at the in the banking sector in 2011 through the 2013 timeframe and lived through the DDoS attacks where the Iranians were targeting many financial institutions with pretty advanced but sophisticated DDoS attacks that were impacting some of the customer facing websites. And so they've got a history of DDoS, there's other attacks that they've launched where they have taken over SCADA or ICS systems and then they have also shown a propensity to do destructive attacks against some of their adversaries, whether it's in Saudi Arabia or others. Even in the US we've seen attacks like that as well.

And finally I'd say the other thing that we've seen from them is a potentially also do some intellectual property theft. And so really all kinds of different aspects of attacks are on the table here. So Errol, with that said, what steps should the healthcare sector entities be taking right now to prepare for any potential cyber attacks that impact the sector and any lessons that can be learned from the financial sector in light of the DDoS attacks that we saw previously? Yeah, I think we come back to the lessons learned momentarily.

But I think a lot of this really comes down to remaining vigilant and really trying to make sure that our members and the institutions in the sector understand what the escalating threats and tensions are and what they mean and making sure people are aware of these things. So we've been notifying our members and we certainly appreciate having an opportunity to speak to our members here through this podcast to get the word out even further about the escalating threats and tensions. And so certainly awareness is one of them. And even looking at some of the papers and advisories that our partners and government organizations have put out here recently with the escalating intentions.

DHS and CISA put out a very good document here recently talking about some of the actions that organizations can take to protect themselves. And they mention things like doing backups, practicing incident response, making sure business continuity plans are in place, doing risk analysis, training your staff, protecting your accounts, doing vulnerability scanning, but even more importantly, making sure you're all patched and up to date with those advisories, monitoring your networks, and even considering things like application whitelisting. So there's some really good resources out there. You also asked me about some of the lessons learned, and I would say that from my experience living through the ZDOS attacks, the banking finance sector, that but the ISAC was a great place to be able to share information, learn about what attacks were happening and then even when the attacks were happening, learn about some of the really good countermeasures and controls that were working and what was effective in helping to stop or mitigate the attacks that were taking place.

So I think that I would also encourage our members to actively share with the health isac, even when they're working to prepare against these attacks, or if they see some suspicious activity or any kind of attack activity that they could share with the isac, and then we can use that to help make sure all of our members know about it as well. Now Errol, we talked a little bit about the DDoS attacks. Any other past cyber situations that we've seen perhaps in other sectors or perhaps even outside the US that you think the healthcare sector can draw from in order to sort of be better prepared and better defend themselves in sort of this uncertain time that we're in with nation state attacks in general. Again, I really think it comes down to proper cyber hygiene and just making sure that organizations are taking right steps when it comes to ensuring that their networks are secure, that they've implemented all those patches.

And really taking a look at all the things I mentioned earlier, when it comes to securing their own networks, a lot of this really comes down to making sure that you're secure, patch and up to date and not potentially an easy target. And in a lot of cases that's what it comes down to when we look at the adversary here. We're certainly worried about the Iranian regime and the nation state attacking capabilities of the Iranian government. But there's also plenty of pro Iranian hackivists that are out there.

We saw them last weekend, a few days ago, some website defacements that were probably attributed to those organizations. And while they may not be a serious attacks, they do take advantage of some of the older, easier vulnerabilities to exploit and erol. Aside from this recent Iranian conflict that's been developing here, what other sorts of cyber threats, cyber risks, you know, issues that you were most concerned about in terms of the healthcare sector in general. For instance, last year we saw a lot of ransomware attacks.

Do you think that's going to continue? Anything that you think that the healthcare sector can do to be better prepared against the sort of things that we have already been seeing? Yeah, absolutely. I'm going back and looking at a recent threat level update that we did.

So this is something that we share with our members and give them an idea of what the current threats are and what some of the major issues are that we're facing in the healthcare sector. So this is really based on input from other members. And so besides the rising tensions with Iran, we've also got continued issues with ransomware. One of the newer names on the scene here is called maze ransomware.

So we've seen a rise in that family of ransomware. We've also seen a good amount of attempts to deliver a remote access tool called Pixiret and that has been targeting healthcare and education sectors as well. And then we've also seen malicious email campaigns being delivered by some of the mass emailers out there that are known to be leveraged in these kinds of email attacks. Finally, the thing that we're seeing also quite a bit is retware infections that are impacting third party suppliers.

So where we have these trusted third party connections, those third parties are also being targeted by organizations and they could potentially have an impact on the organization due to critical processes or critical supplies that are being provided by that third party that could be impacted by ransomware that's delivered and impacts their third party supplier. So those are really the big ones that we saw from earlier in January and Errol, when it comes to the health isac. Anything that your organization is advising healthcare sector entities at this point in light of the Iranian situation as well as the continuation of the sorts of threats that we were just talking about? Yeah, I think it's really all of what we talk about.

We're really trying to raise the awareness level and make sure people know about the escalated intentions and threats and what the fallout could potentially be with a cyber attack targeted towards the healthcare sector. We're passing along some of the action plans and recommendations that we see from our partners at DHS and hhs, and we'll continue to remind our members about the threats and about these other resources pretty regularly over the next several days as we communicate with them for daily updates and other ad hoc threat reports. We will certainly make sure that we're providing all those resources on a regular basis. Thanks, Errol.

I've been speaking with Errol Weiss of H Isaac. I'm Marianne Culbisak McGheen of Information Security Media Group. Thanks for listening.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on January 8, 2020.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!