Risk

12/7/2017
10:30 AM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
50%
50%

Ransomware Meets 'Grey's Anatomy'

Fictional Grey Sloan Memorial Hospital is locked out of its electronic medical records, but in the real world, healthcare organizations face even greater risks.

Like many couples, my wife and I enjoy watching TV dramas together. However, the recent winter finale of the long-running Grey's Anatomy really hit home. It was about how the debilitating effects of a ransomware attack could leave a hospital and its patients at the mercy of attackers.

Natalie, my wife, is a pediatric intensivist (a doctor who works at an intensive care unit for children) and the chief medical information officer at Stanford Children's Hospital. I am the chief risk officer and chief security officer at Neustar, a company that is responsible for Internet and telecommunication services, as well as solutions that prevent and mitigate the types of attacks depicted in Grey's Anatomy.

Spoiler Alert!
Can hospitals really be taken offline, leaving critical support systems vulnerable and completely exposed to malicious actors? Or is this typical television hyperbole?

The harsh reality is that the producers of Grey's Anatomy did their research and delivered a dramatized description of a threat that multiple different types of businesses, including healthcare organizations, have come to know all too well. We saw a real-life example of the potential danger with the WannaCry ransomware attack that crippled a hospital in the UK last May. No one is immune to ransomware attacks, but you can fend them off, defend your critical infrastructure, and prepare for emergencies like this through preventive measures and training.

As a CMIO and CRO/CSO couple, we both immediately thought about the extensive work our organizations undertake to prevent these types of attacks and to mitigate the effects if they happen. Proper patch management is key to preventing known attacks. A solid Web application firewall (WAF) can ensure that you have the latest patches, and it also prevents most types of attacks.

But what if this isn't a known attack — what then? Business continuity management and disaster recovery are needed in that instance. Hospitals (and any IT system) should have backups and test these backups regularly. It is absolutely critical that health information technology departments closely monitor all of their critical systems, have backup copies of key information and systems, and have mitigation plans in place should any of those systems fail for any reason, including a cyberattack. In fact, many hospitals have complete duplicate copies of their entire electronic media record system in a location separate from the primary data storage site.

As we saw on television, Grey Sloan Memorial Hospital was locked out from accessing its electronic medical records. It could easily have been hit with a distributed denial-of-service (DDoS) attack as well. We have seen larger and larger DDoS attacks with the compromise of Internet of Things bots through Mirai. The hospital should ensure it has proper DDoS mitigation and a secondary DNS provider (should its primary DNS provider be attacked), and make sure that critical systems do not rely on third-party Internet access.

How Should a Hospital Respond in Real Life?
While Grey's Anatomy was significantly overdramatized, this type of crisis can and does happen (as in the UK hospitals hit by the WannaCry attack). A cyberattack is an emergency that hospitals need to be prepared for as much as they are for any other type of emergency, such as natural disasters and mass casualties. Our healthcare information systems have become tightly integrated into patient care, so — just as on Grey's Anatomy — younger physicians and staff members may not remember a time when they had to deliver care without these systems.

How does a health system prepare and respond? Planning, training, and practice. A hospital's office of emergency management works closely with the IT department to ensure that it is prepared for exactly these types of emergencies. Alternative workflows must be identified ahead of time. Staff members must be routinely trained on how to use the downtime systems. Regular, planned system downtimes can be used for training, practice, and testing of the downtime systems. In severe emergencies, prioritization schemas should be used to ensure that critical resources are going to the most appropriate patients and that patients are diverted to other facilities when necessary.

We all love a good television drama to get our minds off of work and the stress of our everyday lives. However, Grey's Anatomy is a stark reminder of the critical roles we play in our organizations and how important it is for everyone to prepare for the worst, so that we can be at our best if and when it happens.

Related Content:

Tom serves as the CRO and CSO at Neustar, Inc. Prior to this role, he served as chief risk 0fficer and chief information security officer at DocuSign. While at JPMorgan Chase, Tom served as the deputy CISO, where he led cybersecurity, fraud prevention, and protective ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
'PowerSnitch' Hacks Androids via Power Banks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/8/2018
Higher Education: 15 Books to Help Cybersecurity Pros Be Better
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-20102
PUBLISHED: 2018-12-12
An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding to an AAAA record from the non-initialized part of the buffer, possibly accessing...
CVE-2018-20103
PUBLISHED: 2018-12-12
An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid pointers resulting in stack exhaustion.
CVE-2018-1480
PUBLISHED: 2018-12-12
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the 'HttpOnly' attribute on authorization tokens or session cookies. If a Cross-Site Scripting vulnerability also existed attackers may be able to get the cookie values via malicious JavaScript and then hijack the user sessi...
CVE-2018-1481
PUBLISHED: 2018-12-12
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 140763.
CVE-2018-1484
PUBLISHED: 2018-12-12
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent...