Tips on Protecting Hospitals From Nation-State Attacks episode artwork

EPISODE · Jan 22, 2020

Tips on Protecting Hospitals From Nation-State Attacks

from Info Risk Today Podcast · host InfoRiskToday.com

In light of rising tensions between the U.S. and Iran, the Association of Executives in Healthcare Information Security recently issued new data security guidance to help the healthcare sector prepare for potential nation-state attacks, says CISO Christopher Frenz, one of the document's authors.

Episode metadata supplied by the publisher feed · Published Jan 22, 2020

Embed this episode

NOW PLAYING

Tips on Protecting Hospitals From Nation-State Attacks

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary Ann Cole-Bissack-Migay, Executive Editor at Information Security Media Group. Today I'm speaking with Christopher Friends, who is Assistant Vice President of Information Security for Interfaith Medical Center in New York. Chris is also Chair of the Incident Response Committee of the Association for Executives and Healthcare Information Security. Chris will be describing new guidance material that A has issued to help the healthcare sector prepare for potential nation-state attacks against the U.S.

critical infrastructure, especially in the wake of tensions between the U.S. and Iran. So Chris, I understand that the new guidance covers 17 recommendations highlighting best practices and security controls that are critical in helping organizations mitigate the potential damage a state-sponsored cyber attack could do on a healthcare organization. The controls spotlighted in the guidance include patching, geo-blocking, utilizing threat intelligence, network segmentation, two-factor authentication, and about a dozen other security measures.

Now many of these recommendations are security controls and best practices that healthcare sector as well as organizations across other sectors should be taking anyway. So what stands out to you about the recommendations and the guidance in terms of common weaknesses among healthcare entities that overall put the sector at risk for nation-state cyber attacks. One of the reasons the guidance was trusted is that if we read the news recently or anything else, we see that hospitals are constantly falling victim to ransomware attacks and other types of cyber attacks. And one of the things you wanted to do was actually highlight why it's important for hospitals to focus on certain controls, what they can do to actually prepare if a nation-state-type cyber attack would actually hit.

Because at the end of the day hospitals are a critical infrastructure, and it's of key importance that the healthcare they provide, they continue to be provided in order to promote patient safety, to prevent the loss of life, and other things from happening. So in order to give hospitals an edge-op you wanted to begin the conversation of things hospitals could do to actually prepare for such an attack. So Chris, when it comes to the healthcare sector, what kinds of nation-state attacks are you most concerned about right now? You mentioned ransomware.

What other sort of attacks? In general hospitals have fallen victim to quite a bit of ransomware. One of the common mechanisms for ransomware is through vectors such as phishing, with malicious attachments or links or sent out to hospitals. That's a fairly common attack factor.

Another one I seen by the Samsung ransomware group, which is actually an Iran-based group. They actually used remote access, things like RDP and other public-facing services to gain entry to the systems. So if you look at some of the guidance, some of the things I recommend for the malicious attachments is controls like splitting sandboxes in place. Things that can actually execute any mail attachments or links within email, prior to actually getting for the user's inbox in order to determine if it's malicious or not.

That's a great way to discover threats that there's no AV signature for yet. So that's one of the recommended controls for things like the RDP mechanisms and other stuff that hospitals have, been exploited at hospitals to gain access to their systems and promote ransomware attacks. We do recommend things like geo-blocking to limit the number of IP addresses that can connect to your systems, controls like auditing your public-facing systems, see what actually needs to be public-facing, remove anything that's not necessary to public-facing, as well as controls that are basic cyber-aging, things like touching, things like two-factor authentication, the guidance goes through virus controls like that to help mitigate the attacks that are commonly used against hospital infrastructure. Now Chris, in the healthcare environment, there are so many systems that can potentially be impacted by cyber attacks that could impact patient care, ranging from electronic health records, picture archiving, and communication systems, and other medical device gear and systems.

What worries you the most in terms of the potential cyber threats we're facing and potential risk to patient care and safety? And what do you see as some of the biggest vulnerabilities? What worries you most is that I can cause a delayed patient care, particularly certain types of patient care. For example, if you have a stroke patient coming to an emergency room, they have a certain amount of time to do the CT scan, have the CT scan read, diagnose as a stroke, in order to provide the correct treatment.

And if that's certain window of time elapses and treatments are provided properly, the damage from that stroke can become permanent. So anything that can result in a delayed patient care like that can have direct adverse effects on the patient. So one of the things that I'd be very concerned with is hospitals really testing and vetting their downtime procedures, make sure they can actually get re-knowledge images read, make sure they can perform tests and other stuff in the absence of some of these electronic systems, because as mentioned, anything that causes that delay in patient care, that's where the problems really come in. So my advice possible would be to actually, and prep, run through your incident response plans, actually see tested downtime procedures, make sure that you can actually provide care in the absence of many of these systems.

So if healthcare sector entities CISOs and other healthcare security leaders examine the 17 recommendations outlined in the guidance and recognize glaring holes in their own organizations, what's your advice for addressing those issues sooner rather than later? Once it comes down to taking a risk assessment approach, assessing for the risk to figure out which risks are going to be the greatest, no organization can pose 100% of their security holes. There's only going to be holes. The question is, are those holes big enough holes that are going to have a very adverse impact on our environment or are the holes where we can tolerate the risk?

And that's the main thing I recommend to a lot of organizations is it was actually go through, assess the security data in place. Are they needing actual recommendations in the A-HIS guidance, go ahead and in line with industry standards best practices? In what way does the organization differ from those best practices? What could they do to improve?

Figure out what the highest risks are first and then figure out the controls they can put in place to mitigate those particular risks? Now Chris, as far as 2020 goes in the bigger picture, any emerging security technologies or evolving best practices that you think needs more consideration by the health care sector and why? In terms of emerging technologies, I think a lot of emerging technologies like AI, machine learning, machine life systems come forward with those and they definitely have some interesting security benefits. Where I think a lot of organizations run into problems with a lot of new technologies is they often assume that new technologies are going to be a silver bullet and solve a lot of their security problems.

I think a lot of hospitals and organizations fall apart in that area where they want to put one of these high-end appliances in, one of these new technologies expecting to solve all the problems and then they let a lot of the basics go. I think yes new technologies are great to adopt. It's very important to consider that the same time that organizations need to remember that they can't forget the basics. Things like patching, things like two-factor authentication and network segmentation, various security controls like that that have been around for a long time, very well established.

This is a very, very long way towards keeping organizations secure. So I think a lot of the technologies definitely offer a lot of promise, but the same time organizations need to really not forget about the basics. And finally, Chris, what about your security organization at Interfaith Medical Center? What is on the top of your security priority list for 2020 and why?

Right now what I mean focuses on is anything that increases visibility. Visibility into the endpoints, technologies like EDR, visibility into network traffic, anything that would help us basically detect threats that might be going through our network. We were one of the first hospitals to actually take a zero-trust approach to security, so we heavily mapped out a lot of our network data flow, things like that. And anything that can provide increasing visibility into how traffic flows through the network, what's going on are endpoints, things like that.

That has been a very major focus within us because it really helps us to detect anything that might be suspicious before it becomes a bigger problem. Thanks, Chris. I've been speaking to Chris friends. I'm Marianne Colbusak-McGhee of Information Security Media Group.

Thanks for listening.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on January 22, 2020.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!