Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Getting smarter about protecting healthcare systems from cyberattacks in 2018

by The Gurus
June 17, 2020
in This Week's Gurus
Share on FacebookShare on Twitter

We often use similar terms in the security and healthcare. We talk about viruses and weaknesses and we put plans in place to reduce vulnerability, improve the health of the patient/network and protect it against attacks from external factors. We also act to mitigate the effects of attacks that do get through from the inside. As your doctor will tell you, to really improve overall health, we need a good monitoring regime and a system of preventive medicine and activity that keeps health threats at bay. A good security strategist will tell you the same about your network.

A vulnerable patient

The healthcare sector faces multiple points of pressure to get smarter when it comes to cybersecurity. First, the personal information that is held by healthcare systems commands a premium when offered for sale on the dark web, making it highly attractive to cybercriminals.

Second, the well-publicised WannaCry attack on the NHS in 2017 flagged up that this is a sector with vulnerabilities, offering a good chance of success for a determined cybercriminal. The sector saw a big spike in attack volume over 2017, with more than 50% of all cyberattacks being targeted at healthcare, up from 38% in 2016.

Third, the consequences of attacks on critical network infrastructure are severe – potentially life and death. The UK saw 19,000 appointments cancelled as a result of WannaCry. On top of the human cost, there is a huge financial cost associated with handling both immediate and longer-lasting effects of a breach. For a predominantly publicly funded sector this is a hard cross to bear.

Related to this are the increasingly strict regulations that are governing data protection and system security in healthcare. From HIPAA in the US to the GDPR in Europe, the security compliance burden and penalties for mishandling data breaches are growing. Healthcare organisations need to reduce their liability.

Finally, the growth of connected healthcare, incorporating remote monitoring devices and increasing IoT deployment, while it improves the level of care offered to patients, also means that the potential attack surface gets larger every single day.

All of this pressure is placed on a sector that is already overburdened and has limited budgets. It’s not surprising that security professionals are seeking streamlined defence that is both effective at keeping the bad guys out and also clearly demonstrates compliance.

The right prescription – inside and out

When we look at the anatomy of a typical cyberattack aimed at exfiltrating personal data, we see five key phases: initial unauthorised access to the network; delivery of the payload; command and control of the system by the attacker; data is stolen; attacker covers their tracks and remains on the system to enable future attacks – or “obfuscated persistence.” A good defence needs to understand how data is moving around the organisation and be able to detect these phases and alert defenders as early in the cycle as possible. It must also demonstrate that an attack has been found and report how it has been dealt with. Furthermore, you need to be able to conduct impact assessments of any breach using the data logged by the system.

There are two perspectives that work in tandem to create a strong security posture. First, we look at the network from the outside in. We prepare the network to recognise and act on external threats by implementing rules that prevent unauthorised software from running to stop attacks. By monitoring unfiltered data on endpoints, the system – in our case Cb Defense – detects activity that indicates an attack may be in progress. An example might be the use of PowerShell – which can be innocent – but which starts to look suspicious when it is used to launch unexpected files or applications. The context provided by the unfiltered data warns us that this activity is not as expected and should be automatically prevented and an alert is issued. Stopping this activity means the attackers can’t gain a foothold on the network from which to move laterally and steal data or disrupt the system. We saw this type of defence in action in the NHS WannaCry attack in 2017. The ransomware was uploaded to our client’s endpoint, but because of the rules set up in Cb Defense, the suspicious file was not permitted to run, so the network was protected.

The second perspective is to look at protecting your critical assets from the inside out. For this we use Cb Protection. When you have identified your critical data – patient records, for example – you set up a protection system that locks it down to prevent any changes to that data by unauthorised persons and automatically logs any attempt to do so. In this way we stop the attacker getting what they want. Recent reports are also indicating increased threats from internal sources, where employees are accessing and modifying sensitive data. The event logs show which credentials were used and help identify suspicious actors.

In both cases a critical aspect, when it comes to compliance, is the real-time nature of monitoring, alerting and mitigation. All regulations prioritise the early detection and notification of breaches on the basis that, the sooner you identify a breach, the quicker you can act to contain it. The comprehensive data collected on the endpoints is also invaluable in conducting subsequent investigations into the incident for reporting purposes. With this system in place, the time and cost required for compliance – as well as the overall liability – is reduced, which is welcome for overstretched security specialists.

This approach also hands an advantage to defenders when it comes to threat hunting and predicting which threats are likely to prove serious. The wealth of unfiltered data collected on endpoints can be interrogated in a bid to find out which tactics, techniques and procedures the attackers are using against your network. This is being active to keep your posture strong – just like the doctor advises!

The healthcare sector will remain a highly attractive target for attackers for the foreseeable future. It is therefore vital that there’s a good defensive and protective regime in place. Rather like the doctor, by observing the vulnerabilities from the outside, and checking for weaknesses in important systems on the inside, we can prescribe a system of preventive medicine that keeps infections under control and the patient – in this case the network – fighting fit.

Tags: CybersecurityTechnology
ShareTweet
Previous Post

UK Consumers Vow to Punish Businesses that Fail to Safeguard Their Data and Reward Those that Put Data Protection First

Next Post

Getting your company out of a crisis situation

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol