I'm Mary Ann Kolbasakmke, Executive Editor at Information Security Media Group. Today I'm speaking with Kate Pierce, who is Virtual Information Security Officer of Fortified Health Security. Kate is the former longtime CIO and CISO at Norfolk Country Hospital at 25-bed Community Hospital in Vermont. Hi, I'm Mary Ann.
How are you? Good. So Kate, as we know, the Department of Health Human Services has been promoting to the health care sector, recently published voluntary essential and enhanced cybersecurity performance goals. Those are part of an evolving strategy by the Biden administration to nudge the health care sector into stronger cybersecurity.
Also, the health sector coordinating council recently issued a call to action for the health care sector to take certain important steps in the next five years to raise its cybersecurity condition from critical to stable. So what do you think of these recent efforts and what will it take to have health care sector entities actually implement these recommendations? So I think the essential goals are just that. They're essential.
They're baseline goals at every hospital or health system should already have in place. They are specifically designed to be the minimum requirements for every health system. So I don't think that those are going to be hard to achieve. In fact, I would encourage everyone to strive towards the enhanced goals because that's where you're going to actually build your cyber resilience.
And in terms of the essential and enhanced goals, you know, based on what you see within health care sector entities that you work with that you're familiar with, what do they struggle with? I think people struggle with cybersecurity as a whole because, you know, obviously cybersecurity is an expense for organizations and especially smaller organizations often don't have the resources to invest in their cyber protections. They choose to take their limited resources and invest them in their primary mission, which is treating patients. And you can't really blame them there, but it's becoming more and more apparent that health care is a huge attack vector for our cyber criminals.
And they are, you know, it's more important than ever that they show up their cyber defenses in order to maintain their primary mission of taking care of patients. So you were the CIO instance of a small rural community hospital for a long time. There are many hospitals in the U.S. that are similar, that they are, you know, small, they're maybe under resource.
What particular challenges do they face in trying to raise the bar on cyber security at their organizations? And what's at stake if they don't do that? Well, I think they have a number of resource constraints there. They have a lot of competing priorities, as I mentioned earlier.
The other thing that they may suffer from is not having workforce talent in cybersecurity. It's hard to recruit and retain workforce to be able to implement these cybersecurity standards across the organization in addition to funding resources that they're struggling with now. So I was strongly encouraged yesterday as we heard that the FY 2025 federal budget had earmarked $1.3 billion toward improving cybersecurity in our health sector with about 800 million of that targeting our under-resourced organization. So that should give them a nice boost to get started with putting in these minimum standards.
When it comes to funding, what sorts of things would you like, you know, the funding to go towards? When it comes to the resources that, you know, these entities need, is it the equipment? Is it the talent? Is it everything, you know, and more?
I think that they need to look towards those essential goals and make sure that they're meeting all of those essential goals. I believe I've heard that there are some HHS personnel that are working towards building a way for them to enforce that these goals become, they move from voluntary to requirements over the next few years. So we'll see what that looks like, but I would encourage them all to start with these minimum goals that were identified and make sure that you're meeting all of those goals in your organization. Now we've seen how the change healthcare attack has had a wide impact on the healthcare sector for entities that depend on the company's many business and clinical IT solutions.
What lessons do you think are emerging in terms of business continuity, disaster response, emergency preparedness, when it comes to situations where a critical vendor that serves the healthcare ecosystem, suffers on outage, how can you prepare for that, now that we see what can happen? Well, I think it's important that organizations start looking at doing a business impact analysis within their, each of their departments. What are those systems that are critical to ensuring that your department can fully function without a particular vendor? And once you have your business impact analysis completed, you would build that into your business continuity planning so that as these attacks happen, that you have alternative methods in which you can still carry on your critical functions.
So what else are you keeping your eyes on these days? There's a lot of talk about ransomware, obviously, exfiltration attacks. What other things do entities need to be thinking about that perhaps they just don't have the time to dedicate attention to what they really should be? Well, I think, you know, historically, I think if we can ensure that everyone is doing those basic hygiene things, then we're all in this together.
It's not any one organization that's going to move the needle on this as a nation. We all need to work together to ensure that we're bringing up that minimum standard so that we can ensure that the health sector is no longer such an attractive target for our cyber criminals. If we look at doing those risk assessments that were originally mandated and haven't mandated for quite some time, take that risk assessment, build out a strat plan for all of those risks that are high risk for your organization and start working towards remediating those risks and improving your security overall. And we hear a lot about cyber attacks, obviously.
What about insider threats? Are there other things that kind of fall down to the wayside because they don't get as much attention in terms of, you know, the drama that's involved with the attacks, maybe there's other sorts of breaches that go on, whether it's malicious insiders or accidental, other things that are just more mainstream than having a day-to-day basis that maybe don't get as much of a headline, but they're still problems that these entities really need to be dealing with in a more aggressive way. Well, I think, you know, to your point, identity and access management is a huge part of your cyber, should be a huge part of your cyber program, especially when it comes to privileged access management, making sure that those users within your organization that have administrative access have separate accounts for that and are not using those administrative accounts for their day-to-day work usage. IAM is a big piece of how you provision and deprovision your staff is vitally important, especially if those insiders are terminated from your employment, you need to make sure that your immediate or walking those accounts immediately and, you know, it has to be part of your day-to-day business.
It can't be just a one-off for certain high-risk employees. You need to make sure that those accounts are disconnected as soon as the employee terminates. Well, thank you so much, Kate. I've been speaking to Kate Pierce.
I'm Mary Ann Kolbaseki of Information Security Media Group. Thanks for joining us.