Risk

12/7/2017
10:30 AM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
50%
50%

Ransomware Meets 'Grey's Anatomy'

Fictional Grey Sloan Memorial Hospital is locked out of its electronic medical records, but in the real world, healthcare organizations face even greater risks.

Like many couples, my wife and I enjoy watching TV dramas together. However, the recent winter finale of the long-running Grey's Anatomy really hit home. It was about how the debilitating effects of a ransomware attack could leave a hospital and its patients at the mercy of attackers.

Natalie, my wife, is a pediatric intensivist (a doctor who works at an intensive care unit for children) and the chief medical information officer at Stanford Children's Hospital. I am the chief risk officer and chief security officer at Neustar, a company that is responsible for Internet and telecommunication services, as well as solutions that prevent and mitigate the types of attacks depicted in Grey's Anatomy.

Spoiler Alert!
Can hospitals really be taken offline, leaving critical support systems vulnerable and completely exposed to malicious actors? Or is this typical television hyperbole?

The harsh reality is that the producers of Grey's Anatomy did their research and delivered a dramatized description of a threat that multiple different types of businesses, including healthcare organizations, have come to know all too well. We saw a real-life example of the potential danger with the WannaCry ransomware attack that crippled a hospital in the UK last May. No one is immune to ransomware attacks, but you can fend them off, defend your critical infrastructure, and prepare for emergencies like this through preventive measures and training.

As a CMIO and CRO/CSO couple, we both immediately thought about the extensive work our organizations undertake to prevent these types of attacks and to mitigate the effects if they happen. Proper patch management is key to preventing known attacks. A solid Web application firewall (WAF) can ensure that you have the latest patches, and it also prevents most types of attacks.

But what if this isn't a known attack — what then? Business continuity management and disaster recovery are needed in that instance. Hospitals (and any IT system) should have backups and test these backups regularly. It is absolutely critical that health information technology departments closely monitor all of their critical systems, have backup copies of key information and systems, and have mitigation plans in place should any of those systems fail for any reason, including a cyberattack. In fact, many hospitals have complete duplicate copies of their entire electronic media record system in a location separate from the primary data storage site.

As we saw on television, Grey Sloan Memorial Hospital was locked out from accessing its electronic medical records. It could easily have been hit with a distributed denial-of-service (DDoS) attack as well. We have seen larger and larger DDoS attacks with the compromise of Internet of Things bots through Mirai. The hospital should ensure it has proper DDoS mitigation and a secondary DNS provider (should its primary DNS provider be attacked), and make sure that critical systems do not rely on third-party Internet access.

How Should a Hospital Respond in Real Life?
While Grey's Anatomy was significantly overdramatized, this type of crisis can and does happen (as in the UK hospitals hit by the WannaCry attack). A cyberattack is an emergency that hospitals need to be prepared for as much as they are for any other type of emergency, such as natural disasters and mass casualties. Our healthcare information systems have become tightly integrated into patient care, so — just as on Grey's Anatomy — younger physicians and staff members may not remember a time when they had to deliver care without these systems.

How does a health system prepare and respond? Planning, training, and practice. A hospital's office of emergency management works closely with the IT department to ensure that it is prepared for exactly these types of emergencies. Alternative workflows must be identified ahead of time. Staff members must be routinely trained on how to use the downtime systems. Regular, planned system downtimes can be used for training, practice, and testing of the downtime systems. In severe emergencies, prioritization schemas should be used to ensure that critical resources are going to the most appropriate patients and that patients are diverted to other facilities when necessary.

We all love a good television drama to get our minds off of work and the stress of our everyday lives. However, Grey's Anatomy is a stark reminder of the critical roles we play in our organizations and how important it is for everyone to prepare for the worst, so that we can be at our best if and when it happens.

Related Content:

Tom serves as the CRO and CSO at Neustar, Inc. Prior to this role, he served as chief risk 0fficer and chief information security officer at DocuSign. While at JPMorgan Chase, Tom served as the deputy CISO, where he led cybersecurity, fraud prevention, and protective ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
WebAuthn, FIDO2 Infuse Browsers, Platforms with Strong Authentication
John Fontana, Standards & Identity Analyst, Yubico,  9/19/2018
NSS Labs Files Antitrust Suit Against Symantec, CrowdStrike, ESET, AMTSO
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/19/2018
Turn the NIST Cybersecurity Framework into Reality: 5 Steps
Mukul Kumar & Anupam Sahai, CISO & VP of Cyber Practice and VP Product Management, Cavirin Systems,  9/20/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Are you sure this is how we get our data into the cloud?
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-8298
PUBLISHED: 2018-09-24
Multiple SQL injection vulnerabilities in the login page in RXTEC RXAdmin UPDATE 06 / 2012 allow remote attackers to execute arbitrary SQL commands via the (1) loginpassword, (2) loginusername, (3) zusatzlicher, or (4) groupid parameter to index.htm, or the (5) rxtec cookie to index.htm.
CVE-2018-14825
PUBLISHED: 2018-09-24
A skilled attacker with advanced knowledge of the target system could exploit this vulnerability by creating an application that would successfully bind to the service and gain elevated system privileges. This could enable the attacker to obtain access to keystrokes, passwords, personal identifiable...
CVE-2018-17437
PUBLISHED: 2018-09-24
Memory leak in the H5O_dtype_decode_helper() function in H5Odtype.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.
CVE-2018-17438
PUBLISHED: 2018-09-24
A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.
CVE-2018-17439
PUBLISHED: 2018-09-24
An issue was discovered in the HDF HDF5 1.10.3 library. There is a stack-based buffer overflow in the function H5S_extent_get_dims() in H5S.c. Specifically, this issue occurs while converting an HDF5 file to a GIF file.