I'm Mary Ann Kolbe, executive editor at Information Security Media Group, today I'm speaking with Ryan Witt, who is healthcare cybersecurity leader of Security Firm Proofpoint, about a recent study conducted with research firm, the Ponemon Institute, examining the impact of ransomware and other cyber attacks on patient care and safety. So Ryan, for starters, just briefly describe for our audience what you examined in the research, what sorts of respondents participated in the survey, and when was it conducted? It's a survey to understand the connection that may exist between a cyber event and how cyber security is impacting overall patient care. So we worked with Ponemon to put together this survey, which took place for much of the last six months or so, analyzing the research responses to a whole range of questions.
I mean, Ponemon would have a very strong track record of putting surveys like this together. So we really wanted to measure, to what degree, cyber security was impacting healthcare, and if that impact was actually then making its way to the patient experience and the patient care continuum. And what we found, or what the survey I found, is that two-thirds of healthcare organizations surveyed experienced disruption patient care as a result of cyber attacks. So that's in line with what we found last year, with the first year we did this study with Ponemon.
So the day now we have two years data to pull from, but we are seeing similar sort of results that there is a connection to if a cyber event happens within a healthcare institution, there's a stronger probability that patient care will be disrupted in some way. So compared with the inaugural study last year examining these same issues, what were some of the biggest changes you saw this year and any surprises? I guess not surprises per se. It's always interesting when you have two years of data to reflect upon, I suppose, the one-year data.
We have definitely seen a rise in cloud compromise or concerns around cloud compromise. And so thought, again, not too surprising, healthcare has been a little slower to adopt the cloud compared to other industries, but they are now certainly are embracing it so that the fact that those that tell attacks are up or concerns about those attacks are up and not surprising. Ransomware did not feature quite as significant as it did last year. We find that to be very topical oriented.
So when a big ransomware event hits, it races to the top of everyone sort of mind, and that becomes a massive sort of consideration. Not that it ever goes away, but there hasn't been a noteworthy ransomware attack in recent time. I don't think certainly during the time the survey occurred. Probably the other thing that was interesting was that the vulnerability recognized from supply chain or imposter sort of style attacks on supply chain or business associates, that number has definitely has gone up as well.
So it's the health care industry recognizing that there are some threats in that area. So Ryan, you mentioned the cloud compromises being among the top threats this year identified and then also supply chain. Are those sort of linked together in any way? You have the third party vendors, the cloud vendors having incidents or software providers overall, or what sort of things are they concerned about the respondents?
I think that there quite possibly are linked. I don't know that the survey really can say that categorically, but I don't think it's a surprise or a coincidence that those numbers are up. So for sure, I mean, health care has a very strong supply chain network. Many covered entities are wholly reliant on their vast number of business associates to go help them provide all forms of patient care, some that are directly involved in the patient care process, others that are enabling functions that support the broader institution.
And it's no surprise as well that the threat actors understand that ecosystem more and more. I mean, they social more and more, they have an understanding of how the connection between the supply chain worked within healthcare and they try to exploit those relationships, especially possibly can, not forgetting, of course, that almost all cyber attacks have some sort of monetary aim to them. And this is, we talked about a vendor supply chain relationship with a healthcare entity. It's not too hard to find the monetizable activity or opportunity.
So not surprised that those things are linked. And of course, more and more, those institutions are relying on supply chain who are using the cloud to deliver their services or to invoice for their services or to have that sort of overall interaction, those are often now occurring in the cloud, of course. So when it comes to supply chain sorts of cyber attacks, are the worries around the physical suppliers that are dependent upon for medications and bandages and that sort of thing where an attack on one of their main suppliers could have a direct impact, eventually on these organizations that use these products or is it more of the sort of supply chain of software companies and other sort of tech companies that these organizations also depend upon or is it a little bit of both? I think it's kind of all of the above.
One of the things that we see at Proofpoint is to a threat actor or would be cyber criminal, not every email address is created equally, right? They look for people within their organization who offer and their eyes more opportunity for a monetizable event. So if you're in the supply chain, for example, at a healthcare institution, whatever part of that supply chain you're supporting, what it probably means is you have to interact with a third party supplier. It means you probably have to download invoices or download reports or other forms or proposals downloading a lot from from that supplier.
That often means interacting with their cloud, it means putting on links, it means downloading documents and the threat actors do know that. They have worked out that there are people within the organization who for no fault of their own but just work in a more vulnerable way and that vulnerability means that there are higher target, higher propensity of target attacks come their way. So if I make a distinction I should say between whether you're directly involved in the supply chain that aids patient care like supply of medication or bandages as you indicated or just more broadly, you're working with supply chain which is providing vending services or janitori services, whatever. I don't think they make that distinction.
They all offer opportunity for a monetizable event in the form of whatever, payment redirect or invoicing fraud or whatever. So now I know that the study also closely examined patient safety as a major concern and I understand that about 57% of respondents reported that cyber attacks led to poor patient outcomes due to delays in procedures and tests. 50% saw an increase in medical procedure complications and 23% experienced increased patient mortality rates and those numbers I understand were similar to last year's findings. So in terms of those responses were the respondents reporting that these examples of poor patient care resulted from actual attacks at their organizations or were they reporting their reception of the impact that cyber attacks have on patient care overall.
Good question and it's kind of hard to tell because you are for this survey is you are looking at somebody's perception and therefore you don't necessarily know how their perception is formed, whether they are reflecting upon their actual institution quite possibly or whether they are surveying the broader sort of landscape. So it's hard to know. I think the bigger takeaway here and the one that I find very interesting is that there's a growing recognition that there is a connection between a porous cybersecurity posture or challenges in a cybersecurity environment and how that directly can impact patient care in the form of the late procedures, longer states of the institution, increased probability of someone being diverted to a different facility, increased complication of medical procedures and most concerningly increase the mortality rate. You know I'm looking for the silver lining here.
To me the silver lining is very much if healthcare can kind of see that connection more and more that's more broadly accepted. That's a great driver and a great motivator for the industry to pivot and make the necessary investments in the cyber security posture to go help mitigate against this sort of an outcome. It's not that compliancy concerns or financial concerns, regulatory concerns, reputational brand concerns weren't a driver before but when you're talking about an outcome that directly is linked to their mission and their kind of reason for existence. I think that's a great motivator for hospitals, equity to teams and hospital boards to act accordingly.
And when it comes to potential impact on patient care, patient outcomes, etc. What sort of cyber attacks seem to be the biggest worry? Is it the ransomware attacks that disrupt access to patient records and often these organizations that are hit with ransomware end up taking their systems offline for an extended time. What sort of cyber attacks are the ones that are most concerning when it comes to the patient safety issues?
I mean ransomware attacks for sure are the ones that are most obviously, the connection is most obviously seen and partly because we've seen a number of noteworthy examples where a hospital has been essentially significantly inhibited from providing the patient care or any sort of patient care for weeks on end. So there's been a number of high-profile cases here that have been widely reported. So when you see those and you see like, you have a patient sorry going through an oncology sort of treatment, they're about to go embark on a whole sort of chemo sort of sessions and all of a sudden not only cannot enter the hospital because the systems are down, they can't actually have the treatment because don't can recall what the actual dosage is meant to be for chemo and they can't recall that because they can't get access to the systems. It's hard to transfer them to a different sort of facility because you have to go either do this from your memory or do it from pen and paper, try to re-basically recreate the patient record and so you can see the impact and how traumatic that will be for the institution, for the patient, et cetera and this process.
So the ransomware is for sure the one that's most top of mind and that connection is more obvious to see. That being said, I mean your example a little bit earlier of supply chain which we have also seen coming more strongly to the fore in this survey, if all of a sudden you're reliant on a business associate who's providing sort of key components or key aspects of the patient care process like bandages and medication and those are delayed for any reason and the supply chain attack is one of the reasons they are delayed that also definitely has an adverse outcome. And so Ryan you know based on some of the top findings in the study, are there any sort of top lessons that you see that could either advise healthcare sector entities to take certain steps to better prevent or blunt the impact of cyber attacks on their organizations, perhaps steps that either they tend to overlook or maybe don't focus enough on? I think for me on that front, I mean it's recognizing where healthcare is being attacked most frequently.
When you go to cyber security conferences that focus on healthcare, we hear lots of different vulnerabilities, lots of sort of attack networks that get discussed, things like internet medical things or those sort of attacks that are never the vulnerability of medical devices generally have never too far removed from our mindset and they shouldn't be. The reality today though is that almost all attacks occur on people. People are being attacked mostly on email or other sort of messaging platforms. They're being attacked with sophisticated social engineering alerts that compel them to interact with a threat actor.
And so if there's an industry that is constantly faced with resource constraints and technology constraints, I would try to focus my energy and marshal my resources on where that attack vector is most prevalent and it is on email. It is on people being attacked. And so that's to me the largest sort of candidate for where the controls need to be layered and need to be more pronounced to mitigate against that style attack. As an example, five, six, seven years ago, we were having this discussion, we talked about vulnerability of networks and we were talking about a lot of zero data attacks.
Well, over the last that time period, networks have been hardened quite significantly and we don't see those attacks as prevalent as they used to be. Not that they should go away or we should focus on them, but I'm saying maybe that similar sort of investment in attention now needs to be focused on protecting people. Look, it's all against that and then we worry about what happens next. I know it's still early in the situation.
Are there any issues that healthcare sector entities in the US should be paying closer attention to based on the turmoil that we're seeing right now in Israel, perhaps a surge in phishing or other sorts of attacks or threats that healthcare entities really should be focusing more on because of the situation? I think the big lesson here or the big one thing we should take note of here is how strongly threat actors, cyber criminals, follow the news cycle. So the lures they're sending out on email will be closely aligned to whatever the news topic is of the day. Given what's happened over the weekend, undoubtedly, you'll see a tremendous amount of email traffic referencing this topic and help provide aid, help provide funding, donate to this charity, things that as often the case with these sort of lures and these sort of emails, they tuck at your emotions and tuck at your heartstrings.
They tried to get you to interact with that email based on something that's hot button topic and whatever is currently in the news is often not that hot button topics. I'd be very aware of that and I'd also be very aware of they're not always wanting you to just interclip this link or download this file and there's an exploit attached to that and it's easy. I mean, if life was that easy cyber criminals, they would be overjoyed and sometimes those things occur, of course, but more frequently, they're just trying to befriend their target. They're trying to start a conversation with that target and sometimes just the most innocuous piece of information is a jigsaw puzzle piece and that's much larger sort of puzzle that they're trying to put together about that institution, that person, that job function, that department.
And so just be on guard for emails that reference what's going on right now and and how they will use lures and emotive language in their emails to try to get you to interact with them. So I think that's the key takeaway. And finally, Ryan, going back to the research, what's next for this research? Are there certain action items that entities should take or what's next in terms of the survey?
Will there be another next year? What can you tell us? The idea is we would keep doing this survey. We've been trying to push for a long time now, a different sort of thought process about how healthcare should think about cybersecurity.
We went through and you and I've had conversations through what I call the medical use era where we were all trying our institutions were trying to obtain grant funding to roll up the medical record, digitize medical record. And that was a time when security was very compliancy led. Well, we went through that period and yes, we were compliant, but as we have found out, we're not necessarily secure. So we're trying to change the conversation and make it much more about that correlation and connection to to patient care.
And this is not a peer review study. This is a survey. And so, you know, admittedly, we can't necessarily talk about causation correlation per se. We do want to, however, make this much more part of the discussion topic.
And so we want to keep reinforcing this point time and time again. So we will come back with the survey. Ponymont has a long reputation of doing things like cost of the breach study. They've been doing that for 10 plus years now.
And that's these sort of surveys and this sort of data becomes a significant part of the, you know, the very large, admittedly cybersecurity sort of threat research landscape, but certainly data points that we all tend to point to and say how is this industry trending, how are things changing? So we will definitely come back with this study and try to measure and see what's going to how it will evolve going forward. Thanks, Ryan. I've been speaking to Ryan Witt.
I'm Mary Ann Cobus at McGee of Information Security Media Group. Thanks for joining us.