Three questions to ask

August 2017 Healthcare (Industry), Information Security

In the all-out war for data, the healthcare industry is getting hit the hardest. Experian’s fourth annual 2017 Data Breach Industry Forecast1 states that healthcare organisations will be the most targeted sector for attack, with new and sophisticated attacks emerging. If healthcare organisations and their IT teams aim to keep data safe, they need to take a step back to assess the overall security landscape and the security processes currently in place on a macro level.

Here are a few critical questions that all health IT professionals should ask themselves as they think about data security now and in the future.

1. Have we created a culture of security awareness?

Healthcare data security professionals generally agree that the most vulnerable point in a security framework is the users accessing and handling data on a daily basis. Whether it is data loss as a result of a phishing scam, hacked devices brought in from the outside or general carelessness when accessing sites or apps while on the network, there are a number of different ways employees can jeopardise patient data.

For this reason, health IT professionals should first build up cyber-awareness within the organisation to minimise future threats. That being said, successfully instilling cyber-awareness can be a challenge, as human nature leads individuals to believe they’re impervious to attacks. IT teams can attempt to change this mindset by educating and training the workforce.

While there are a variety of ways healthcare organisations can work to establish a more secure workplace culture, here are a few steps all should take:

• Lead by example: executives and directors should be a model for the rest of the organisation.

• Regularly schedule data training and education sessions throughout the year to provide the latest security trends to the organisation and to remind everyone that protecting data is everyone’s responsibility.

• Hold unscheduled inspections. Look for unattended and logged-in devices, usernames and passwords posted near (or under) devices, disabled security tools, unapproved network devices (such as wireless routers) and the use of proper protocols when logging in and out of multi-user devices.

• Recognise security success and remediate failure. Offer gift cards or other small incentives to those who pass an inspection or a phishing test while requiring additional security awareness training for those who don’t. Some organisations start with short remedial training that requires a 100 percent score on the follow-up quiz, then progressively longer training sessions for those who continue to fail. A formal reprimand in the employee’s yearly review is also an option at this point.

2. Are our current data security solutions equal to the threat?

Employee awareness is critical, but without cybersecurity solutions in place, deterring threats and minimising the number of attacks on your organisation will be next to impossible. To help lay the foundation for data security, organisations should first think about conducting a cyber threat assessment. This assessment will allow your organisation to validate the network’s current security accuracy, analyse traffic across the environment and monitor network performance.

Once this assessment has been completed, your organisation will have a better understanding of its current security posture and what steps to take next. Evaluating the data security systems and processes in place should be a recurring process. This is essential, as changes in healthcare networks and the threat landscape often happen at a rapid rate.

3. Are we in sync with health tech transformation?

The healthcare industry is in the midst of a technological transformation with the goal of improving patient care, and IT needs to be ready to support this progression.

More specifically, the Internet of things (IoT)2 has had a significant impact on the industry, forcing organisations to seamlessly connect both wired and wireless devices to their network. It’s also important to know whether legacy systems and technology are keeping pace with security changes and whether they’ll be protected against the next wave of attacks.

For these reasons (and more), healthcare IT professionals looking to improve data security should consider a security solution that hosts a centralised architecture and an established advanced threat protection (ATP) framework that can be accessed and managed in one place. Next-generation security solutions can help keep healthcare data protected and allow for the expansion of new patient care delivery models.

A strategy for success

The healthcare industry is making great technological strides to offer exceptional patient care, convenience and comfort, but these strides often create greater cyber vulnerability.

As we move through 2017, healthcare data will remain a top target within the cybercriminal community. However, if you and your team address the above questions and establish a robust cybersecurity defence plan, threats can be effectively reduced and attacks can be mitigated in a timely manner.

1 www.experian.com/assets/data-breach/white-papers/2017-experian-data-breach-industry-forecast.pdf

2 blog.fortinet.com/2016/09/12/healthcare-cybersecurity-risks-in-the-internet-of-medical-things





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Most wanted malware
News & Events Information Security
Check Point Software Technologies unveiled its Global Threat Index for June 2025, highlighting a surge in new and evolving threats. Eight African countries are among the most targeted as malware leaders AsyncRAT and FakeUpdates expand.

Read more...
SMARTpod talks to Sophos and Phishield
SMART Security Solutions Technews Publishing Sophos Videos Information Security News & Events
SMARTpod recently spoke with Pieter Nel, Sales Director for SADC at Sophos, and Sarel Lamprecht, MD at Phishield, about ransomware and their new cyber insurance partnership.

Read more...
Cybersecurity and insurance partnership for sub-Saharan Africa
Sophos News & Events Information Security Security Services & Risk Management
Sophos and Phishield Announce first-of-its-kind cybersecurity and insurance partnership for sub-Saharan Africa. The SMARTpod podcast, discussing the deal and the state of ransomware in South Africa and globally, is now also available.

Read more...
Corporate and academic teams can register for Kaspersky contest
Kaspersky News & Events Information Security
Kaspersky has announced the registration opening for its new Kaspersky{CTF} (Capture the Flag) competition, inviting academic and corporate teams from around the globe to compete in a battle of skill, strategy and innovation.

Read more...
Continuous security optimisation.
News & Events Information Security
Cymulate has announced its partnership with SentinelOne, a threat exposure validation and AI-powered cybersecurity platform. The collaboration delivers self-healing endpoint security that empowers businesses to increase protection for every endpoint on their network.

Read more...
Protect your smart home devices
Kaspersky IoT & Automation Information Security Smart Home Automation
Voice assistants, kitchen robots, smart lights and many other intelligent devices have become part of our everyday life. However, with the rise of smart technology comes the need for robust protection against potential vulnerabilities.

Read more...
ISPA’s take-down process protects from local scams
News & Events Information Security
During the recent school holidays, parents could rest a little easier knowing that ISPA, SA’s official internet industry representative body, is removing an average of three to four problematic websites from the local internet every week.

Read more...
SA’s strained, loadshedding-prone grid faces cyberthreats
Power Management Information Security
South Africa’s energy sector, already battered by decades of underinvestment and loadshedding, faces another escalating crisis; a wave of cyberthreats that could turn disruptions into catastrophic failures. Attacks are already happening internationally.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.