Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

When InfoSec is life or death – finding a cure for ransomware

by The Gurus
February 7, 2017
in This Week's Gurus
ransomware
Share on FacebookShare on Twitter

Healthcare organisations are a prime target of cyber attackers because they are reliant on vulnerable legacy systems, medical Internet of Things (IoT) devices with weak security and have a life or death need for immediate access to information. The healthcare industry has remained a consummate laggard when it comes to cybersecurity. With the UK government setting its sights on a paperless NHS by 2020 and digitising all patient data, UK hospitals will increasingly become a juicy target for cybercriminals. Without robust security solutions in place, the digitised records and services are ripe for the picking. It’s the cart before the horse. To protect themselves from threats such as ransomware, hospitals need to realise that traditional perimeter defences are no longer enough.
So, what is the diagnosis?
It has a lot to do with complexity. Building a proactive defence is complex and many times tedious, especially threat hunting. Complexity requires highly skilled labour and can be expensive and time consuming to find and onboard.
Perhaps the biggest issue in healthcare information security is the lack of talent to fill existing needs. It isn’t just the cost of skilled cyber warriors; there simply aren’t enough of them. Other issues of concern include the cost to build an effective programme followed by the ability to respond to emerging threats with ransomware being the most prominent. 
Barriers to entry
The cybersecurity skills shortage continues to be a major concern. Finding complex threats requires exceptional knowledge. Security analysts must know about attackers, industry regulations and about the local healthcare environment. All this while watching the network 24/7.
It’s a tall order. But there exists technology such as sophisticated artificial intelligence software that augments existing staff to close the cybersecurity skills gap needed to automate threat hunting. This reduces the barrier to entry needed for Tier 1 analyst work.
On a related note, it’s important to remember that time equals money. When it comes to threat hunting, reducing the impact means the defender must be faster at finding threats than an attacker is at finding and stealing valuable information. Time-equals-money should be broken down into how much work an analyst can do in a single day and how many analysts you need.
Here’s the formula:
(cost) = (number of events) x (time to resolution) x (staff value)
Many healthcare organisations have leveraged artificial intelligence software to automate real-time threat hunting and reduce the time spent on threat investigations and remediation by 75-90% – without adding incident-response headcount. And the solution is specifically tuned to detect the ransomware threat that’s plaguing the industry.
Unfortunately, healthcare organisations have become high-value targets for ransomware. With lives at stake, medical teams can’t be denied access to systems and data critical to patient care.
Then there are medical IoT devices. These vulnerable, unprotected IP-enabled devices are an easy entry point for cyber attackers who can then move laterally through the network in search of personal health information (PHI) and other key assets.
The persistent, internally driven network attack has become the norm, and healthcare security teams, products and processes must adapt accordingly to head off disaster. Cybercriminals make things tougher by quickly and easily modifying their malware and launching a succession of advanced persistent threats (APTs). 
The bottom line
Healthcare organisations should start by automating the hunt for cyber attackers inside their networks. Working in real-time, it must provide visibility into attacker behaviours hidden in all network traffic and connected host devices, including IoT and BYOD. It must detect every phase in the cyber-attack kill chain like command-and-control communications, internal reconnaissance, lateral movement and data exfiltration behaviours.
 
Chris Morales, head of security analytics, Vectra Networks

ShareTweet
Previous Post

74% of CIOs say UK IT professionals are under skilled

Next Post

Turning Point: DDoS Attacks in Q4 2016

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol