Blended Threats Whitepaper
In this informative paper, created from the
H-ISAC Blended Threats Exercise Series final findings report,
you’ll learn:
- – Actionable information for health care delivery organizations (HDOs), medical device manufacturers (MDMs) and healthcare information technology vendors to prepare for, exercise, and respond to black swan events.
- – 8 Best Practices for Blended Threat Mitigation
- – 4 areas of improvement within the Healthcare sector from a Whole-of-Organization approach
- – 10 areas to benchmark improvements toward Preparedness
- – An InfoSec wishlist to build capabilities for Healthcare sector resilience
- – Healthcare sector identified areas of challenge open for discussion
Key Takeaways:
Whole-of-Organization Approach
– Cybersecurity programs should be looked at as an important component of the whole business.
Plan Now to Prepare for a Threat
– Browse the nine topics identified for Preparation and Practice to see where your organization is lacking and where to start planning a best response.
Cyber and Physical Security Connection
– The Best Practices section and the Areas for Sector Improvement sections identify processes for cyber and physical security personnel to work together, which departments should be connected and how to keep the chief levels informed during an incident.
Abstract
Sharable outcomes aggregated from the Health-ISAC Blended Threats exercise series provide actionable information for the H-ISAC community to discuss, exercise, prepare for, and respond to black swan events. The six workshops enabled participants to focus on enterprise risk management. Exercise discussions yielded shared success strategies, identified opportunities to enhance security postures, and addressed several challenges from the viewpoint of healthcare delivery organizations (HDOs), medical device manufacturers (MDMs) as well as healthcare information technology (IT) vendors. This paper shares valuable ideas and considerations for the H-ISAC community to adapt and further develop to increase security and preparedness in a complex and blended threat environment.
- Related Resources & News
- Monthly Newsletter – October 2024
- Health ISAC leads effort to transform SBOM information sharing under CISA-facilitated community work
- CyberEdBoard Insights: Phil Englert and Errol Weiss
- Health-ISAC Hacking Healthcare 9-10-2024
- Strengthening Healthcare Cybersecurity: Lessons from Recent Supplier Attacks
- Specialize in Securing Critical Infrastructure
- How AI is transforming cybersecurity, on defense and offense
- Unveiling Hidden APIs and Securing Vulnerabilities in the Healthcare Sector
- 2024 Active Shooter Hostile Event Response (ASHER) Exercise Series – Report
- How to Address Healthcare’s Cybercrime Problem