Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

12/13/2017
02:20 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Healthcare Faces Poor Cybersecurity Prognosis

Experts say the healthcare industry is underestimating security threats as attackers continue to seek data and monetary gain.

For attackers looking to steal valuable data with minimal effort, the healthcare industry is a prime target. The critical role of medical facilities, combined with poor security practices and lack of resources, make them vulnerable to financially and politically motivated attacks.

"Healthcare is clearly an attractive target and becoming more attractive," says Viktors Engelbrehts, director of threat intelligence at eSentire. The company today released its Industry Threat Report for healthcare, one of several recent reports on the troubling state of security.

"Any attacks on healthcare can lead to loss of life," he continues. "That's something that a significantly higher risk than in any other industries."

Threat actors rarely attack with the intent of causing physical harm, Engelbrehts points out. Most are looking for financial gain. eSentire reports patient records are worth between $0.05 and $2.42 USD each. Attackers can sell them on the Dark Web, use them for tax fraud or blackmail, or for conducting spearphishing campaigns.

Still, some may seek to cause physical harm. Well-known terrorist organizations are significantly improving their cyber capabilities and the idea of attacking healthcare providers to cause harm, while not imminent, "cannot be excluded in the very near future," he says.

The threat to healthcare organizations will grow with each successful breach. But where are the biggest security holes, and how are attackers taking advantage?

Diagnosing risk

Cybersecurity is a tough enough problem for businesses to solve, and decentralized data-sharing and network-integrated medical equipment both broaden the attack surface for the healthcare industry. Most IT funds go toward business functions; only a small fraction is allocated to cybersecurity.

"Healthcare is a unique industry in the sense there are a lot of devices talking to each other all the time," Engelbrehts says. "There is huge data traffic across different computer assets." Medical devices are constantly sharing data, and reliance on them increases access points.

While the FDA requires security compliance in medical products, those rules are more for patient health and don't consider the possibility of someone stealing information stored on these devices, or using them as access points into organizations.

Spence Hutchinson, threat intelligence team leader at eSentire, points out that remote access to medical data also increases risk. In his firm's research, he says, the team noticed a lot of exposure tied back to data sharing and providing access for both patients and external contractors.

"IT resources are often outsourced, and in order to facilitate that, there's a need for remote access into these networks," Hutchinson explains.

How attackers take aim

Opportunistic attacks are common because of the amount of vulnerable devices. "With these, they're generally not targeting you as an organization, they're targeting you because you're vulnerable," says Engelbrehts. These attacks require no effort on the user's part; attackers need only to find exposed devices and run the exploit.

The low security posture of most healthcare organizations may prove a target demographic for which these attacks are successful, the report states. Businesses need to be harder targets.

Engelbrehts points out the danger of ransomware, which has become a bigger part of the security conversation following major attacks this year. The downside of the publicity is it serves as a "negative commercial" for cybercriminals: if they know it's successful, they'll try it.

"Phishing is a big one," he adds. "It also links to our assumption that education on cybersecurity is lacking in the industry overall." These attacks are also opportunistic; malicious emails are spammed to thousands of email addresses, which can be found on the Dark Web.

Research from Mimecast and HIMSS emphasizes the danger of email as an attack vector. Providers say email is the biggest potential area for a breach; 9 of 10 respondents said email was critical their organizations. Of those, 43% report email is mission-critical and downtime cannot be tolerated. Attackers know email is a weak spot and are likely to take advantage.

And a new report from Positive Technologies, which focuses on Web application attacks, points out SQL injection attacks fell this quarter for the healthcare sector compared with previous quarters. However, other types of attacks including OS Commanding and Arbitrary Code Execution have grown. Attackers commonly use local file inclusion vulnerabilities, which let them take over a Web app and alter its content.

Bring it to the board

"Healthcare providers need to start realizing the cybersecurity threat for them is imminent," says Engelbrehts. "It's not something that might happen in time, it's something that's happening now in the healthcare sector."

If cybersecurity is not top-down; if it's not a talking point on the board of directors, it's difficult for security teams to achieve their goals. "Each healthcare provider taking cyber seriously should have a CISO," he adds.

Hutchinson advises adopting a threat intelligence sharing policy, something that has grown in the financial industry but doesn't yet exist for healthcare providers. This "would definitely improve the reaction time for new and emerging threats," he says.

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
awpiii
50%
50%
awpiii,
User Rank: Apprentice
12/14/2017 | 8:55:40 PM
Poor Cybersecurity prognosis? How about we look beyond the obvious to real solutions instead.
Not accurate:"...While the FDA requires security compliance in medical products, those rules are more for patient health and don't consider the possibility of someone stealing information stored on these devices, or using them as access points into organizations..."   

The FDA's Cybersecurity fact sheet, Premarket, and Postmarket Cybersecurty guidelines address these issues. Here are the links: 

 

hxxps://www.fda.gov/downloads/MedicalDevices/DigitalHealth/UCM544684.pdf

 

hxxps://www.fda.gov/downloads/medicaldevices/deviceregulationandguidance/guidancedocuments/ucm356190.pdf

 

hxxps://www.fda.gov/downloads/medicaldevices/deviceregulationandguidance/guidancedocuments/ucm482022.pdf

We need to be actively addressing the issues from within the industry rather than just Kicking Puppies from the outside. The experts I know are actively engaged in the Medical Device industry helping to fix these decades old design, implementation, and operational issues, rather than regurgitating that which has been published over and over again by a variety of boutique research companies.  Yes – the problems with medical devices, products, and the HDOs who consume them, can be extremely serious denending on the situaton.  This cannot be overstated enough.  WannaCry clearly highlighted this in a huge way this past year.  But stating that the "healthcare industry is underestimating security threats", without addressing what is actually being done to address it by both the HDOs and device manufacturers, presents a very lopsided picture and does the overall effort a significant injustice.

My comments are my own.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/14/2020
Omdia Research Launches Page on Dark Reading
Tim Wilson, Editor in Chief, Dark Reading 7/9/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-10287
PUBLISHED: 2020-07-15
The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well documented functionality that helps customer set up however, out of our research, we found multiple production systems running these exact default cre...
CVE-2020-10288
PUBLISHED: 2020-07-15
IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can input whatever you like. As long as the field isn't empty it will be accepted.
CVE-2020-15780
PUBLISHED: 2020-07-15
An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be used by attackers to bypass lockdown and secure boot restrictions, aka CID-75b0cea7bf30.
CVE-2019-17639
PUBLISHED: 2020-07-15
In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or destination array can, in certain specially crafted code patterns, cause the current method to return prematurely with an undefined return value. This...
CVE-2019-20908
PUBLISHED: 2020-07-15
An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for the efivar_ssdt ACPI variable could be used by attackers to bypass lockdown or secure boot restrictions, aka CID-1957a85b0032.