Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Top Stories > The challenge of securing healthcare organisations
    Top Stories

    The challenge of securing healthcare organisations

    The challenge of securing healthcare organisations

    Published by Jessica Weisman-Pitts

    Posted on March 16, 2022

    Featured image for article about Top Stories

    By Peter Draper, EMEA director at Gurucul

    Two years into a global pandemic, healthcare providers are just now starting to catch their breath. But if overworked staff and overpacked facilities weren’t enough, another threat loomed over hospitals in recent years: cyberattacks.

    Threat actors have certainly ramped up their efforts and started launching increasingly sophisticated and high-profile attacks that, in 2021 alone, impacted more than 22.64 million patients. In fact, SC Magazine reported this January that the 10 largest healthcare breaches that happened last year each impacted more than 1 million patients. These numbers only account for the incidents that fell under the Health Insurance Portability and Accountability act, so it’s likely that many more compromises happened and were simply dealt with internally, without involving authorities.

    More worrying than exposed patients data is the impact of ransomware, which, according to the Ponemon report “The Impact of Ransomware on Healthcare During COVID-19 and Beyond”, is leading to increased patient deaths. In fact, nearly one-fourth of the 597 surveyed institutions reported an increase in mortality rates, which is a reminder of how this type of cybercrime directed to hospitals and healthcare providers becomes a matter of life and death, rather than just economic and operational.

    According to the same Ponemon report, the confidence of Health Delivery Providers (HDOs) in their ability to mitigate and respond to the risks posed by ransomware has also decreased. Post-COVID, 61% HDOs said they are not sure their organisation is prepared against cyberattacks, as opposed to 55% before the pandemic.

    The impending threat of ransomware is reflected by the increased budgets that healthcare organisations are allocating to cybersecurity, which rose by 15% in 2022. But while increased spending is certainly a move in the right direction, it is equally important for this extra investment to be made towards tools that can simplify and streamline security operations and can provide visibility into the most common blind spots.

    Redefining “Normal”

    Behavioral Analytics approaches are based on a set baseline that represents normal activity and serves as a benchmark for IT staff and SOC analysts to identify deviations that might be considered suspicious. The pandemic, however, completely redefined what is normal and what is not. Some systems saw a significant increase in activity, which also translated into different traffic and data patterns.

    In situations of emergency, especially when it comes to people’s health, it’s normal for operations to come first, security second. However, this means that the shift in the patterns of activity can be exploited by threat actors to cover their tracks. Traffic patterns and activity on healthcare systems is very dynamic and constantly changing, based on infections, hospitalisations, and deaths. These constantly changing baselines make it hard for analysts to determine what is normal and what isn’t.

    The unique challenge of securing medical devices

    Securing medical devices represents a unique challenge for hospitals and healthcare providers. Medical devices run an operating system (OS), which is often locked in and can’t be updated. But while OS are designed to have a lifecycle spanning a couple of years, medical devices are often large investments made by hospitals with the intention of using the machine for decades.

    Many of these devices are connected to the hospital’s network, which represents a huge risk factor. An attacker could leverage those unsecured entry points to gain a foothold, move laterally through the network and eventually reach sensitive servers. ComputerWeekly recently reported recently that some 41% of NHS Trusts in the UK don’t have a real-time register relating to IoT assets, which further confirms how the issue of visibility and patching of medical devices is widespread.

    Insider Threat

    Much like in any other enterprise, employees are the first and the last line of defence against cyberattacks. But, by virtue of being human, they are prone to errors, or might be enticed by the prospect of making a quick profit.

    Whether it is a rogue employee looking to access the file of a famous patient or an employee’s identity being compromised through phishing and exploited to escalate privileges, healthcare organisations need to be cognisant of this threat and need to put the appropriate controls in place. One of the most effective solutions is User and Entity Behaviour Analytics (UEBA), which relies on a defined baseline pattern of behaviour to identify any deviation that should be considered suspicious.

    Ransomware looms large

    The motivation behind most of today’s ransomware attacks is economic. Threat actors look for potential targets that are likely to have a cyber insurance policy, or whose pockets are deep enough that they can afford to pay the ransom. They also look for organisations that can’t afford downtime, and that is definitely the case for healthcare providers, who will feel incentivised to pay up in order to be able to continue saving people’s lives. Locking personnel out of systems that provide essential information and care for patients usually requires an immediate capitulation, no matter what the price.

    Data for sale

    Patient information is incredibly valuable to attackers. Like most personal identifiable information (PII), medical data can be sold on the dark web for a profit, can be used as part of other types of attacks, or can be leveraged to extort a ransom.

    In some darker cases, medical information can also be used to blackmail individuals based on their medical condition. Fraudsters are also known to socially engineer sophisticated scams that gain the victim’s trust through the intimate knowledge of their health conditions.

    Prevention is better than the cure

    The extreme consequences that a successful cyberattack can have on healthcare providers make it paramount for those organisations to be even one step ahead of what attackers are doing today, but also what they will be doing tomorrow. This can be achieved with a risk-based approach.

    Signature-based models are reductive and rely on historical data and statistical models to detect individual events, which then need to be analysed and manually linked together. This is time-consuming and error-prone. For such a critical, but also resource-strapped sector, optimisation and precision are key, which is why it is essential to opt for tools that allow for events to be prioritised effectively, and for new threats and intrusion tactics to be discovered before they can cause harm.

    Related Posts
    Inside the World’s First Collection Industry Conglomerate: PCA Global’s Platform Strategy
    Inside the World’s First Collection Industry Conglomerate: PCA Global’s Platform Strategy
    Chase Buchanan Private Wealth Management Highlights Key Autumn 2025 Budget Takeaways for Expats
    Chase Buchanan Private Wealth Management Highlights Key Autumn 2025 Budget Takeaways for Expats
    PayLaju Strengthens Its Position as Malaysia’s Trusted Interest-Free Sharia-Compliant Loan Provider
    PayLaju Strengthens Its Position as Malaysia’s Trusted Interest-Free Sharia-Compliant Loan Provider
    A Notable Update for Employee Health Benefits:
    A Notable Update for Employee Health Benefits:
    Creating Equity Between Walls: How Mohak Chauhan is Using Engineering, Finance, and Community Vision to Reengineer Affordable Housing
    Creating Equity Between Walls: How Mohak Chauhan is Using Engineering, Finance, and Community Vision to Reengineer Affordable Housing
    Upcoming Book on Real Estate Investing: Harvard Grace Capital Founder Stewart Heath’s Puts Lessons in Print
    Upcoming Book on Real Estate Investing: Harvard Grace Capital Founder Stewart Heath’s Puts Lessons in Print
    ELECTIVA MARKS A LANDMARK FIRST YEAR WITH MAJOR SENIOR APPOINTMENTS AND EXPANSION MILESTONES
    ELECTIVA MARKS A LANDMARK FIRST YEAR WITH MAJOR SENIOR APPOINTMENTS AND EXPANSION MILESTONES
    Hebbia Processes One Billion Pages as Financial Institutions Deploy AI Infrastructure at Unprecedented Scale
    Hebbia Processes One Billion Pages as Financial Institutions Deploy AI Infrastructure at Unprecedented Scale
    Beyond Governance Fatigue: Making ESG Integration Work in Financial Markets
    Beyond Governance Fatigue: Making ESG Integration Work in Financial Markets
    Why I-9 Verification Matters for Financial Institutions: Building a Culture of Compliance and Trust
    Why I-9 Verification Matters for Financial Institutions: Building a Culture of Compliance and Trust
    Curvestone AI partners with The White Rose Finance Group to enhance compliance file reviews
    Curvestone AI partners with The White Rose Finance Group to enhance compliance file reviews
    LinkedIn Influence in 2025: Insights from Stevo Jokic on Building Authority and Trust
    LinkedIn Influence in 2025: Insights from Stevo Jokic on Building Authority and Trust

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    More from Top Stories

    Explore more articles in the Top Stories category

    Should You Take the Dealer’s Bike Insurance or Buy Online Yourself? Here’s the Real Difference

    Should You Take the Dealer’s Bike Insurance or Buy Online Yourself? Here’s the Real Difference

    ID-Pal Unveils ID-Detect Enhancements to Counter Surge in Digital Manipulation and Deepfakes

    ID-Pal Unveils ID-Detect Enhancements to Counter Surge in Digital Manipulation and Deepfakes

    TRUST TAKES THE LEAD: HALF OF UK SHOPPERS HAVE ABANDONED ONLINE PURCHASES OVER SECURITY CONCERNS

    TRUST TAKES THE LEAD: HALF OF UK SHOPPERS HAVE ABANDONED ONLINE PURCHASES OVER SECURITY CONCERNS

    Why Choose Premium Driver Service in Miami Over Rideshare Apps for Business Travel and Special Events?

    Why Choose Premium Driver Service in Miami Over Rideshare Apps for Business Travel and Special Events?

    Over 30 Million Users Benefit From Ant International’s Bettr Credit Tech Solutions

    Over 30 Million Users Benefit From Ant International’s Bettr Credit Tech Solutions

    Side-Hustle Economics: How Part-Time Service Work Can Strengthen Your Financial Plan

    Side-Hustle Economics: How Part-Time Service Work Can Strengthen Your Financial Plan

    London to Host Major Summit on “New Horizons” for Islamic Economy in the UK

    London to Host Major Summit on “New Horizons” for Islamic Economy in the UK

    BLOXX Launches World’s First Home Equity Subscription, Creating a New Residential Asset Class

    BLOXX Launches World’s First Home Equity Subscription, Creating a New Residential Asset Class

    LiaFi Addresses Gap Between Business Transaction and Savings Accounts

    LiaFi Addresses Gap Between Business Transaction and Savings Accounts

    Ant Group Chairman Eric Jing Outlines Strategy for Inclusive AI, Collaboration on Tokenised Settlement

    Ant Group Chairman Eric Jing Outlines Strategy for Inclusive AI, Collaboration on Tokenised Settlement

    Deeply Cultivating the Syndicated Loan and Cross-Border Financing Fields: Empowering Chinese Banks’ Global Expansion with Professional Excellence

    Deeply Cultivating the Syndicated Loan and Cross-Border Financing Fields: Empowering Chinese Banks’ Global Expansion with Professional Excellence

    Ant International’s Antom Launches AI‑Powered MSME App for Finance and Business Operations

    Ant International’s Antom Launches AI‑Powered MSME App for Finance and Business Operations

    View All Top Stories Posts
    Previous Top Stories PostTurkey’s Bayrak says to bid for Chelsea, seeks Abramovich nod
    Next Top Stories PostNickel market in disarray after chaotic London return