Hi, I'm Mary Ann Kolpasek, the executive editor at Information Security Media Group, and I'm here at the HIMS Cyber Forum in Boston speaking with John Regie, who is National Advisor for Cybersecurity and Risk at the American Hospital Association. So John, we're continuing to see a surge in ransomware and data exfiltration attacks against hospitals and other healthcare sector entities. We also see DDoS attack campaigns hitting healthcare entities. On top of that, we've also seen major hacking incidents involving third party vendors that have affected organizations across many industries, but including the healthcare sector.
With all of that said, when you talk to hospital security leaders, what are they most concerned about? And how do their worries compare with what you're seeing in the broader cyber perspective in healthcare? Thanks, Mary Ann. Great to talk to you again.
So healthcare leaders are absolutely very concerned about cyber risk as a major risk that they're facing. So they understand the nature of the threat, they understand the impact, especially with these high impact ransomware attacks, which are disrupting healthcare delivery and potentially creating risk-to-patient safety. So they're concerned about bolstering their defenses, but they're also concerned about how we're going to pay for this. Big, big issue.
There is obviously a financial shortage and pressure that healthcare organizations are facing is a workforce shortage across all entities and in cyber security. That's all in some. They understand the threat, they're trying to position against the threat. So ultimately the leadership understands the nature of the threats, they understand they have to better prepare against these advanced threats, but they're also concerned about resources that need to be devoted against these threats and where they're going to come from.
And patient care and saving lives is still job one. So John, what's your advice to hospitals in keeping up with what they need to do to defend against these threats given the source constraints and all the other pressures they're dealing with? So I think it's really incumbent upon the cybersecurity teams to provide up-to-date threat briefings to the leadership. The non-technical leadership and the boards to prioritize cyber risk just as they would prioritize any other enterprise risk facing the organizations and really request those briefings and demand if they don't understand the technical aspects, demand that it be translated in a way that they understand it and understand what the impact to the organization would be.
So really it's got to be a team fight from every leader with every leader in the organization. Understanding the threat. So John, what's your advice in terms of some of the best practices and or security areas when it comes to technology that needs more attention from hospitals that are full and victim? I think they really, hospitals really need to think about how are the bad guys succeeding in their attacks against health care organizations, email, course, phishing, all those technical aspects, culture of cyber security, but also understanding that the bad guys are exploiting commonly known vulnerabilities.
So patch management becomes a very significant issue, but also there's a whole host of recommended recognized best practices either from NIST or the health care industry cybersecurity practices that have been recommended. They've known as hiccup. Folks should take a look at that and really implement all those standard practices. But ultimately be prepared not only to defend against, but respond to how do we recover from the impact of these attacks.
So that means the integration of emergency management planning with cyber incident response planning for an outage that could last up to four weeks. So now John, as you know, generative AI and AI in general is getting a lot of attention. How might the emerging use of generative AI in health care factor into the kinds of breaches and cyber attacks we might be seeing in the future? Well, AI is being used by everyone these days it seems.
So unfortunately the bad guys are using AI as well, these foreign based cyber criminals and spies from hostile nation states using AI to develop very advanced malware and very convincing phishing emails that might be accompanied by deep fake video and audio messages as well and really to identify vulnerabilities in organizations and quickly develop malware and exploits to attack those vulnerabilities. Same time we have AI being used by cyber security providers to help defend against these attacks, to make their cyber security solutions better and ultimately to be able to more quickly identify penetration of malware so that it can be contained again to help minimize the impact of these attacks. And finally, John, as we look ahead to 2024, what are your predictions about cyber threat, landscape sort of issues that will be facing health care sector that might not be the same as we see right now? So I think we really have to keep an eye on AI, one of the issues, how will AI be used by the bad guys?
The trend line that I'm seeing on the number of attacks and the scope of the impact of data theft and ransomware attacks is quite frankly not encouraging. So we have to keep an eye on that and ultimately we have to keep an eye on geopolitics with Russia and China and see how tensions with both those nations might manifest into direct cyber threats against the US healthcare directly or as collateral damage as a result of these geopolitical tensions. Great. Well, thank you, John.
I've been speaking with John Regie of AHA. I'm Mary Ann Kolbasak-McGhee of Information Security Media Group. Thanks for joining us.