I'm Mary Ann Kolpasekke, executive editor at Information Security Media Group, today I'm speaking with Justin Foster, who is chief technology officer at security for scout about the security challenges faced by outpatient care facilities, especially as threat actors are increasingly focusing their attention on this segment of the healthcare sector. So Justin for starters, in the conversations that you've had with CISOs and other security leaders of outpatient care facilities, such as doctor practices and clinics versus the inpatient care entities, such as hospitals, how do their current cyber concerns and challenges compare and contrast? What are some of the top threats they're facing? I think right now what we're seeing in a post-COVID world is a real rationalization around tools and budget.
They're undergoing constraints in terms of, you know, do we have duplicate tools that are performing similar tasks in our environment? How could we reduce overall spending? Because, you know, there's less funding to access in this post-COVID world, whether it's inpatient or outpatient care. So how are healthcare systems and other security leaders within the outpatient facilities reassessing and evolving their XDR strategies in hopes of better protecting their networks?
And how mature are outpatient facilities in terms of adopting XDR overall? You know, you've got the patient care providers and then you also have, whether it's outpatient or inpatient, you have biomedical devices, you have building automation devices, you know, you have increasing amount of IPs. We find that the amount of unmanaged devices now in any organization is starting to exceed the amount of managed devices. And so when you look at threat detection and technology like XDR or SIM, you know, a lot of the problem comes from noise, too many alerts hitting your system, whether it's XDR or SIM.
And the other part with threat detection technologies is they're very endpoint-centric. An endpoint is important for the doctors and nurses and, you know, the general admin staff that are servicing these facilities, but it doesn't cover the devices that are not, you know, focused on users, like biomed devices or building automation or OT devices. So how do you then, you know, rationalize and cover that entire environment using existing technologies that were built largely around protecting users? And that's where we're seeing the difference, you know, in the inpatient side, we're seeing an increase use of ransomware threats or misuse of data or impacting the availability of patient care systems.
You know, on the outpatient side, they have to think about the same things, whether or not, you know, the patient is staying there. It's similar systems that are all internet connected, similar users, and then you've got things like shared workstations, right, where an nurse may check in a patient at a dozen different workstations throughout the day. Are you protecting them from misuse or plugging in devices that if a patient's left in their room before the consult? There's just a lot of concerns that they have, regardless of CISOs and healthcare system.
Justin, what do you see in terms of differences in how XDR strategies are evolving in outpatient care versus hospital environments? And in terms of what's being secured, you know, whether it's devices or, like you say, workstations, what are some of the main differences in the main challenges in one setting versus the other? So that's a great question, Marianne, and what I've seen in the CISOs that I've talked to, or the security leaders that I've talked to, is often when it's a smaller practice, a clinical practice. They can't obviously staff at 24-7 information security program.
They can't, you know, have a SOC and have it staffed around the clock. So they tend to turn to partners, like an MSP or a SOC as a service, or some type of monitoring partner. But the one problem there is, you know, they're often they're quite niche. And I've talked to many security leaders in healthcare that go with different niche providers for different areas.
Like they might have one monitoring the endpoint versus one monitoring the firewalls. Well, if something's happening according to attack, you know, how are those providers sharing information? The truth is they're probably not. And then, you know, there's the whole unmanaged space, right?
That all the devices that don't necessarily carry a standard footprint, like a desktop or laptop. And regardless of the setting, you know, the amount of these internet connected or smart devices is exploding. And so how do you take a comprehensive look at your threat detection and response strategy across all the devices? And I think that's where we've we've focused is that unmanaged is just as important as the managed devices.
And having that coverage across the entire state is becoming critical regardless of the size of a healthcare practice. When you look at how healthcare entities, you know, both the outpatient care providers as well as, you know, some of the larger healthcare systems that might have a network of hospitals, what sort of mistakes do you see that making in terms of how they're even approaching XDR at this point? For instance, are some of the less mature providers making some mistakes that perhaps, you know, the other larger entities have learned by now and what sort of mistakes should they be avoiding? No, I think a lot of security leaders are overwhelmed, right?
They have the physical computers in their environment, then they have a bunch of software as a service, and then they have a bunch of unmanageable devices. And those devices lack serviceability or can't have agents installed or lack firmware updates or have recalls that they can't address because limited stack. We have a research department called Vary Labs inside Of Force Code, and we test non-managed devices all the time. And we find many of these have weak TCP IP stacks.
So simply running a scan of these environments, you know, if somebody comes into that clinical setting and plugs in their hacker device or laptop into an empty ethernet port, they could be taking down devices and that could affect things like, you know, uptime of their devices or patient care. It's a real challenge to cover all these. They have a wide variety of protocols as well. If you think about BioMed, you know, we bought a company called CyberMDX, a small Israeli startup last year to expand our classification of medical devices.
You know, it may look like Windows, but it's really a medical imaging device, or it may look like a Linux stack, but it's really, you know, an infusion pump. Understanding and protecting those type of devices in healthcare has become a new frontier for these providers where it used to just be the desktop laptop firewall. You know, you put AV, but firewall, you're good. The attack surface size really exploded.
And I do feel for these info security leaders in healthcare, it's a giant challenge. So, Justin, you mentioned medical devices. What are some of the XDR challenges when it comes to medical devices and specialty VR? That's used in healthcare.
And, you know, as you know, there's like so much legacy devices in healthcare, they're often, you know, separately segmented on, you know, separate networks. What's their challenges, you know, do they create? I think the first thing is visibility. If you talk about XDR, most XDR grew from an EDR background, EDR meaning endpoint detection response agent.
You install primarily on desktops, laptops, and servers. And so that naturally already doesn't cover devices that you can't go and install an agent. And that covers the wide variety of, say, BioMed devices that are out there. So first, providing visibility.
And that can come in different forms. You know, your firewall gives you some ability to do segmentation. And that's good practice, right? To segment out weaker or more vulnerable devices from the general network that you may be running.
But it also makes sense to have specific sensors that can detect threats against these. And these are very niche protocols as well. You know, our OT network sensor covers 270 different unique protocols, not just TCP. These are using different communication methods to share information, share updates, send out alerts.
And so understanding when someone is actively trying to exploit those. Also, then things like recalls or understanding when a firmware update is available and should be applied to avoid some of these potential issues. And I do see, you know, especially in the outpatient setting, that the network segmentation isn't strong enough. You know, understanding how to apply and what devices are and what is talking to what.
There's a long way to go in that front. And so understanding your segmentation policies, understanding what devices are, even if they have a footprint that, you know, again, it looks like Windows or Linux. Their actual critical role may be something in, you know, required for patient care that can't go down. And so understanding what devices are talking to what is really important.
Because you can't do that via agent. Doing that at the network level is the main way you can protect a complex medical environment. So, Justin, with that said, what would be your top piece of advice for security teams in healthcare entities that are sort of new or early in terms of implementing XDR and then also a piece of advice for those that are more mature and have, you know, been going down this path, but they want to make more of what they're doing. Yeah, I think that the key is starting with sensing what you can, right?
So you want to have email security, you want to have endpoint security, you want to have cover your SAS productivity solutions, you want to have firewalls, IDS, IPS for unmanageable devices, you want to have specific security that can sense threats against those type of devices. And there are many. Then it's about monitoring. And again, especially in an outpatient, they often can't have a SOC or 24-7 SOC.
So it's picking a provider who can watch that. And that's two parts. That's a platform, whether that's a SAM or an XDR, that should cover the entire state, not be niche and just, you know, hire a firewall monitoring service and call it a day. But it also should be a service provider if they can't do it in-house that can cover the wide variety in spectrum of devices in healthcare.
And they do things like store logs for seven years or for HIPAA compliance. And understand unique threats against healthcare. And understand when things should be escalated in terms of maintenance or patching or recalls to help protect the environment. So it's really that foundational, you know, understand what you have, then assess it, what it's doing, what risks are there, what threats are there, and then be able to govern that environment.
That's really the healthy security program any CSO should be following. Well, thank you so much, Justin. I've been speaking to Justin Foster. I'm Mary Ann Colbicek McGee of Information Security Media Group.
Thanks for joining us.