Why Health Firms Struggle With Cybersecurity Frameworks episode artwork

EPISODE · Apr 18, 2024

Why Health Firms Struggle With Cybersecurity Frameworks

from Info Risk Today Podcast · host InfoRiskToday.com

Healthcare sector organizations often still struggle to implement security frameworks effectively, often not fully understanding the requirements or failing to integrate them into their overall cybersecurity strategy, said Keith Forrester of security firm Optiv, who offers tips to help.

Episode metadata supplied by the publisher feed · Published Apr 18, 2024

Embed this episode

NOW PLAYING

Why Health Firms Struggle With Cybersecurity Frameworks

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary-Ann Colb, Executive Editor at Information Security Media Group. Today I'm speaking with Keith Harister, Practice Manager for Strategy and Risk at Security Firm Optif. We're going to be speaking about some recent cybersecurity trends and issues in the healthcare sector. So Keith, as you know, the U.S.

Department of Health and Human Services recently began rolling out a strategy for beefing up cybersecurity in the healthcare sector. That includes new voluntary, essential, and enhanced cybersecurity performance goals, which are built upon existing best practices, such as those supported by the NIST cybersecurity framework. Based on what you're seeing in the healthcare sector with the surge in ransomware, attacks, data exfiltration, social engineering, and phishing, where are healthcare sector entities falling short the most in their security best practices, including in the areas that HHS described as essential and enhanced cybersecurity performance goals? Yeah, you know, that's a great question.

You know, what we're seeing is, and the healthcare in general is really at times, somewhat behind, you know, other industries doing a lot of blocking and attacking, trying to get things running and functioning. And, you know, it's, you think of it, you know, we're 20 years into HIPAA in HIPAA security. And we still have major issues. We've still got organizations that we're going and we work with that are way behind, that don't have controls in place, don't have the basics in place, and not just doing things.

But 2007, I think they did sort of this NIST CSF mapping to HIPAA and started working and providing these goals and best practices. But it's really, I haven't seen many organizations really address it. You know, if I look at it when we go out and work with our clients and we do assessments and, you know, work with them, I'd say as we go in and do security assessments, less than about 20% of those organizations that we're working with are going in and doing a NIST CSF maturity assessment together with their HIPAA requirements. So that's the type of thing we've seen that, you know, really is lacking and behind in organizations aren't really focusing in on their security programs and the controls that should be implemented and trying to look at how they build those programs and ensure that, you know, that they progress and they have a they build a maturity.

So Keith, with that said, you know, what are some of the areas that you've seen these healthcare sector entities already sort of falling short on that is leaving them vulnerable to the threats we've been seeing and how confident are you that these entities will then be able to, you know, suddenly implement the cybersecurity performance goals that HHS has said that is aimed at kind of pushing HIPAA forward. Yeah, I think both organizations haven't really adopted a specific security framework. They just, you know, running along trying to match and do, you know, an annual HIPAA assessment, which is not, you know, it's looking at safeguards and not looking at what you should have as far as the framework in place as a government structure in place and what we're seeing, you know, these organizations have got all the tools and all the processes out there, but they are lacking their times in fully implementing the tools correctly and properly. You know, we're seeing, you know, oftentimes we're seeing that things like breaches occurring and organizations are, you know, coming up and doing analysis of their breach and discovering that, yeah, it came in through credentialed or, you know, we credentialed and, you know, they look back and say, oh, well, would we have two-factor authentication?

But yeah, you know, has that two-factor authentication been implemented correctly and been across the organization? And oftentimes you find no, it hasn't. It's only been implemented in certain areas or what's been used as a stepping stone for organizations to roll out the single sign on, things like that. And we're not seeing that they are really adapting and addressing best practices and frameworks that should be put in place.

We look as well, but 2019, we came out with the hiccup requirements, the health care industry, cybersecurity practices. And I, you know, we still don't see many organizations adopting those. So it's great that HSS are bringing out these new programs and really are focusing more on cybersecurity. But I think there's a lot of education that we have to do in health care to bring the organizations and get them on board part as well, is that I think the staffing models within health care and, you know, people to support this and build out these programs is going to be difficult because people are just overworked, just trying to do the blocking and attacking today.

And Keith, along sort of that theme, for instance, the phishing is so a very common entry point for many of the health data breaches and other compromises that we see in health care. Why do you think that's not the case? Maybe the rapid pace that that health care have to work in, you know, you think it's a very stressful environment. You know, you're trying to, you're delivering care to patients and you're rapidly moving.

So maybe that's part of the reason why phishing is full of a big issue as well as we know that the phishing attacks is really becoming more and more sophisticated. So you've really got to change up how you go about your awareness training and your phishing and the point of your phishing programs to be pace with what's going on, especially with AR these days. You mentioned AI and machine learning and indeed these tools in the hands of the fraudsters and cyber criminals, they give them, you know, another advantage to do deep fakes and perhaps more strategic fishing and social engineering. Any advice to health care entities on kind of staying ahead of some of those trends while they're still dealing with some of the difficulties they've been dealing with for years?

I think it really is that you've just got to keep pace and understand where the adversity is going, you know, what new attacks are coming out with, keeping the breast with that, having the tools to monitor the environment and to monitor personal behavior, things like that, to try and detect. So yeah, you should know it's probably limiting your own AR tools to have better visibility and to use the behavior to try and stop some of those attacks or protect yourself from phishing. And when it comes to some of the cyber security performance goals that HHS sort of laid out as essential and then also enhance. Are there certain ones that sort of pop out to you as having the potential to make the biggest boost in healthcare, cyber security efforts organizations that are currently lacking in some areas?

Are there certain areas where, you know, these healthcare entities if they were just to focus on, you know, a few areas as sort of laid out by HHS that would make a big impact for them? Well, you know, if you look at the, you know, the essential goals, it's really is the basic, you know, go back to the blocking techniques that we should be doing, you know, mitigate known vulnerabilities. But we, you know, we look at that and we see how a lot of organizations are still battling to patch an update. And yeah, there's, inherently within healthcare, there are issues that, you know, you've got a lot of old applications in the environment that are at end of life, you know, sitting on end of life operating systems or and not being maintained.

You know, those things are still there, you know, you know, security, multi-act authentication, you know, training, awareness. So all of these things that form essential goals are what we should look at as basic stuff. If you look at then when you really get to the enhanced goals and you think of areas where they are saying, you know, things like network segmentation. Well, if you go back to the known vulnerabilities, you know, organizations should be looking more closely and implementing micro segmentation to isolate systems that can't be managed, that can't be updated and patched.

You know, a big one is obviously BioMed. You know, you've got a lot of medical devices in there that fall into their category as well that can't be updated or maintained. Or quite frankly, fall outside the bounds of standard IT to manage and maintain them and each by a separate organization most of the time. So those types of systems really need to be isolated and segmented off of your environment and really understand where your key data is, the data that you really got to protect and put those better guardrails around that data to protect it from systems that are, you know, vulnerable that are going to cause you pain.

So key finally, as healthcare sector entities sort of evaluate these cyber security performance goals from HHS, any advice on how they should be sort of looking at these goals to see, you know, what it is that they really should have as a top priority for their own organization. Any advice for how they can sort of vet these goals to see which ones they should be sort of focused on right now, considering that many of these organizations are stretched for resources when it comes to security, personnel, skills, expertise, funding, you know, so on and so forth. It really gets down to, it's all about risk management. So you've got to, you've got to be able to assess your environment and determine the risks that are out there and then define or develop and build out these goals, best practices based on your business and where you have got the most risk.

It's going to be different for all organizations. It's not a one size fits all. And you've got to look at these goals as to how, you know, a sexual organization affects your business operations and how you can implement them and, you know, design and develop them and then implement and maintain it. Because that's the key now is to ensure that yes, that you're able to maintain what you're going to put in place.

You know, it's the follow through that is key as well. Well, thank you so much, Keith. I've been speaking to Keith Barrester. I'm Mary-Ann Colbitt of Information Security Media Group.

Thanks for joining us.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on April 18, 2024.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!