Frequent ransomware attacks in healthcare and public health sectors elevate security threats to OT/IoT environments
Industrial Cyber reached out to experts in the healthcare sector to assess the manner in which ransomware attacks affect the OT/IoT environments across the healthcare and public health sectors.
“For the most part, when it comes to ransomware in the OT/IoT space, the health sector has mainly been affected by attacks against third party suppliers,” Denise Anderson, president and CEO of the Health Information Sharing and Analysis Center (H-ISAC), told Industrial Cyber. “For example, during the COVID-19 pandemic, organizations that pharmaceutical manufacturers relied on for packaging vaccines and therapeutics experienced ransomware attacks, which halted operations and impacted packaging supply and ultimately the distribution of vaccines and therapeutics,” she added.
Organizations in the healthcare and public health sectors are facing an increasing number of ransomware attacks, often leaving hospital networks vulnerable. With these adversaries lurking around in the OT/IoT environments, they have become considerably more capable of executing significant attacks at scale while also taking advantage of the growing success of the ransomware-as-a-service (RaaS) model.
The healthcare and public health sectors remain a top attack vector for cybercriminals and ransomware threat groups. However, hackers are shifting their focus to smaller entities that truly have a deficit in cyber defenses, showing a huge change in victims and approach. Additionally, changes in government regulations, a massive revolution in connectivity of medical devices and mobile technology, and transformation in how care is delivered and consumed have come together to form a perfect storm of complexity and vulnerability, which cyber adversaries target.
Link to full article in Industrial Cyber:
- Related Resources & News
- Health-ISAC Hacking Healthcare 8-26-2024
- What is Threat Intelligence? A Comprehensive Overview
- Why Cybercriminals Target Healthcare Data and How Organisations Can Protect Themselves
- Federal Authorities Work to Boost Health-Care Cybersecurity
- Health-ISAC Hacking Healthcare 8-9-2024
- Health-ISAC Medical Device Blog – VEX
- Podcast: Health-ISAC Featured in Cyberwire Daily episode 2021
- Health-ISAC Hacking Healthcare 8-2-2024
- Protecting Healthcare Organizations with Human-Centric Email Security
- American Hospital Association and Health-ISAC Joint Threat Bulletin