The Need to 'Streamline' Risk Management During the Pandemic episode artwork

EPISODE · May 14, 2020

The Need to 'Streamline' Risk Management During the Pandemic

from Info Risk Today Podcast · host InfoRiskToday.com

To keep up with security issues raised by the transition to a much larger remote workforce and expanded telehealth services during the COVID-19 crisis, healthcare entities should "streamline" their approach to risk management, says Dustin Hutchison of the security consultancy Pondurance.

Episode metadata supplied by the publisher feed · Published May 14, 2020

Embed this episode

NOW PLAYING

The Need to 'Streamline' Risk Management During the Pandemic

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary-Ann Kobusak-McGee, executive editor and information security media group. Today I'm speaking with Dustin Hutchinson, president of Security Services firm, Pundworenz, about some of the escalating cyber threats and challenges facing the health care sector as entities battle the COVID-19 crisis. So Dustin, for starters, as you work with health care sector organizations during the COVID-19 crisis, what kinds of escalating cyber challenges are they facing and how well prepared are they to deal with these challenges, especially while they're also responding to the pandemic? So it's been interesting continuing that mission to care for patients, the expected potential influx of patients, and then everyone's own personal changes to their ability to work and where they're working from has been a really interesting situation.

So remote work is the obvious change from the cyber standpoint. The existing infrastructure plus potentially needing to add the capacity for those additional remote workers has been a real change from the risk management and cybersecurity standpoint and then plus the downstream effect of their vendors also having to shift to this remote work mentality. It's definitely changed kind of the threat surface and how their responding has really been quick, but that's potentially part of the problem from the risk management and cybersecurity standpoint. It's been tough.

And so we've talked to a lot of clients and prospects and connections in the industry about what they're doing. And so it's not saying all right, smaller entities are having a harder time and larger entities are well equipped for this. It's really across the board different based on where that organization is in their cybersecurity maturity of their program. So in addition to where they are in their cybersecurity program, do you notice many differences also based on where they're based geographically?

If they're in a hotspot right now and they're dealing with a lot of the actual COVID pandemic cases that their resources are any more stretched thin than say in a region where maybe things are not as dire right now. Definitely, right? I mean, just even from the caregiver perspective of who's doing what and when and the hotspots are definitely getting hit the hardest, but on the inverse kind of the unexpected effect, especially critical access or rural hospitals where they're seeing a huge drop in people coming in like to the emergency room, for example, I spoke to a CFO the other day where they said they expected this influx of patients and people that would normally come in because I have chest pain or some other issues, aren't. And so that whole shift has been interesting to watch also from the technology standpoint where the actual staffing of entities and staffing of IT forces and the expectations of those third party vendors doing whatever they're doing, you weren't able to really trend out or imagine what was actually going to happen.

So now Dustin ransomware has been a big problem for healthcare sector entities even prior to COVID-19. What are you seeing in terms of these kinds of attacks right now? Are entities even less prepared to deal with these attacks since they're busy right now with COVID-19? Are they more inclined to pay because they're dealing with so much right now?

What is the situation that you're seeing? So we were really hopeful in the beginning. We saw a couple of posts by some of these ransomware actors that said they were not going to target healthcare entities that ultimately ended up not being true. So we have seen that influx.

One of the biggest is the maize ransomware, which is initially observed in May 2019. And it's different because the cycle is encrypt, exfiltrate, and extort and where they have a public outing of those targeted companies that they don't pay, which does lead to more of an incentive to pay right off the bat. They've got to be able to get back to work as soon as possible. And then plus the added pain of extortion is something that healthcare entities just can't deal with right now.

So it's sad that this is happening, but the bad guys are opportunistic right there after that quick payment. And so they're attacking the most vulnerable on purpose and back to the whole shift in the infrastructure and how people are connecting to these networks. They're less prepared than ever. The attack services has definitely changed and it's expanded.

And then so with more remote access and allowing that more and more to actually get work done, it's created more of a vulnerable organization than ever before. So Dustin, with that all said, what are the additional security steps that these organizations need to take in order to stay ahead of these lead us threats? What are some of the things that might be on the back burner right now just because they're dealing with so many other issues? Yeah, so I think focusing on streamlining the risk management practice is really going to be key.

So mostly organizations or the entities that we come in contact with have some risk management program that leads to operational cyber activities for cyber security activities. And so I think really understanding how you continue the mission and so healthcare entities still need to implement new systems. They still need to patch and they need to update, but they have this new caveat that that's in their world. This is their their workforces spread out.

So really understanding from not just the pure governance standpoint, but from the critical steps, those critical controls that need to happen in fast tracking that as much as possible, not just shoe warning systems in and saying, all right, we've got this pandemic we have to deal with. It's saying we've got this pandemic we have to deal with, but we still care about cyber security. So what can we do to fast track that as much as possible? So you had someone on a couple weeks ago, Brenda Peraro talked about governance and measurement versus risk management and incident response.

And so I want to echo some of those same concepts and ideas and think about the timelines related to implementing new technology or even allowing this new remote access. So getting down and understanding, maybe it's not the 100 some controls that are in the this cyber security framework, but really understanding multi factor authentication, encryption at rest and encryption and transit, and then how accounts are managed. But also the cyber security practices of that vendor, whether they have remote access or not is really, really key. And then backing that up with, do we have risk management steps towards incident response?

Do we know when something bad does happen? How are we going to respond in this new world? I think it's really key right now more than ever. So Dustin, we're also seeing shortages of some medical devices, including ventilators.

What's your advice to health care sector entities if they're suddenly forced to use equipment that's been either loaned to them from other facilities or equipment that they need to purchase from sources that they really haven't dealt with much before? What are the cybersecurity risks in doing this? And what steps should they be taking to address those and other medical device related security issues as they're dealing with COVID-19? In that situation, I really think treating the devices as needed, but not trusted is key.

So nearly assuming compromise. And so when you assume compromise, you don't necessarily want that coming old with the rest of your network. So network segmentation is going to be step number one, and then monitoring is step number two. And so the idea is that when you assume that compromise, but you know you still need to use the system, you're not going to let it come in everywhere else, and then you're going to watch it very, very closely.

And so back to the incident response cycle, going in without assumption and saying, all right, we're going to watch this, and we're going to be really vigilant on what's happening, but you still need to know what happens next. So prioritizing that. These are systems that from a risk standpoint, they are potentially more risky right off the bat. So bumping that up to the top of the list to watch and understand how they're working, I think it is really important.

And Dustin, finally, if there was one step that you would like to see health care sector entities at this point in time to take that is overlooked, or perhaps underutilized, what would that be right now to stay ahead of the threats that they're facing as they're dealing with this crisis? I really think network monitoring is key right now. So understanding what's happening and no one's infrastructure is baseline. You don't know what the normal is.

And so watching now more than ever of where the data is flowing is really important, understanding that as much as possible. But then as things shrink and compress back down to normal, keeping that practice in place and continually re-baselineing what is a normal behavior of our network. And then that makes it easier back to that incident response cycle of when something does happen that you're quick to action. Thanks, Dustin.

I've been speaking to Dustin Hutchinson Upon Dorns. I'm Marianne Colbusak-McGhee of Information Security Media Group. Thanks for listening.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on May 14, 2020.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!