Risk

12/7/2017
10:30 AM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
50%
50%

Ransomware Meets 'Grey's Anatomy'

Fictional Grey Sloan Memorial Hospital is locked out of its electronic medical records, but in the real world, healthcare organizations face even greater risks.

Like many couples, my wife and I enjoy watching TV dramas together. However, the recent winter finale of the long-running Grey's Anatomy really hit home. It was about how the debilitating effects of a ransomware attack could leave a hospital and its patients at the mercy of attackers.

Natalie, my wife, is a pediatric intensivist (a doctor who works at an intensive care unit for children) and the chief medical information officer at Stanford Children's Hospital. I am the chief risk officer and chief security officer at Neustar, a company that is responsible for Internet and telecommunication services, as well as solutions that prevent and mitigate the types of attacks depicted in Grey's Anatomy.

Spoiler Alert!
Can hospitals really be taken offline, leaving critical support systems vulnerable and completely exposed to malicious actors? Or is this typical television hyperbole?

The harsh reality is that the producers of Grey's Anatomy did their research and delivered a dramatized description of a threat that multiple different types of businesses, including healthcare organizations, have come to know all too well. We saw a real-life example of the potential danger with the WannaCry ransomware attack that crippled a hospital in the UK last May. No one is immune to ransomware attacks, but you can fend them off, defend your critical infrastructure, and prepare for emergencies like this through preventive measures and training.

As a CMIO and CRO/CSO couple, we both immediately thought about the extensive work our organizations undertake to prevent these types of attacks and to mitigate the effects if they happen. Proper patch management is key to preventing known attacks. A solid Web application firewall (WAF) can ensure that you have the latest patches, and it also prevents most types of attacks.

But what if this isn't a known attack — what then? Business continuity management and disaster recovery are needed in that instance. Hospitals (and any IT system) should have backups and test these backups regularly. It is absolutely critical that health information technology departments closely monitor all of their critical systems, have backup copies of key information and systems, and have mitigation plans in place should any of those systems fail for any reason, including a cyberattack. In fact, many hospitals have complete duplicate copies of their entire electronic media record system in a location separate from the primary data storage site.

As we saw on television, Grey Sloan Memorial Hospital was locked out from accessing its electronic medical records. It could easily have been hit with a distributed denial-of-service (DDoS) attack as well. We have seen larger and larger DDoS attacks with the compromise of Internet of Things bots through Mirai. The hospital should ensure it has proper DDoS mitigation and a secondary DNS provider (should its primary DNS provider be attacked), and make sure that critical systems do not rely on third-party Internet access.

How Should a Hospital Respond in Real Life?
While Grey's Anatomy was significantly overdramatized, this type of crisis can and does happen (as in the UK hospitals hit by the WannaCry attack). A cyberattack is an emergency that hospitals need to be prepared for as much as they are for any other type of emergency, such as natural disasters and mass casualties. Our healthcare information systems have become tightly integrated into patient care, so — just as on Grey's Anatomy — younger physicians and staff members may not remember a time when they had to deliver care without these systems.

How does a health system prepare and respond? Planning, training, and practice. A hospital's office of emergency management works closely with the IT department to ensure that it is prepared for exactly these types of emergencies. Alternative workflows must be identified ahead of time. Staff members must be routinely trained on how to use the downtime systems. Regular, planned system downtimes can be used for training, practice, and testing of the downtime systems. In severe emergencies, prioritization schemas should be used to ensure that critical resources are going to the most appropriate patients and that patients are diverted to other facilities when necessary.

We all love a good television drama to get our minds off of work and the stress of our everyday lives. However, Grey's Anatomy is a stark reminder of the critical roles we play in our organizations and how important it is for everyone to prepare for the worst, so that we can be at our best if and when it happens.

Related Content:

Tom serves as the CRO and CSO at Neustar, Inc. Prior to this role, he served as chief risk 0fficer and chief information security officer at DocuSign. While at JPMorgan Chase, Tom served as the deputy CISO, where he led cybersecurity, fraud prevention, and protective ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Meet 'Bro': The Best-Kept Secret of Network Security
Greg Bell, CEO, Corelight,  6/14/2018
Four Faces of Fraud: Identity, 'Fake' Identity, Ransomware & Digital
David Shefter, Chief Technology Officer at Ziften Technologies,  6/14/2018
Containerized Apps: An 8-Point Security Checklist
Jai Vijayan, Freelance writer,  6/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-5236
PUBLISHED: 2018-06-20
Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 may be susceptible to a race condition (or race hazard). This type of issue occurs in software where the output is dependent on the sequence or timing of other uncontrollable events.
CVE-2018-5237
PUBLISHED: 2018-06-20
Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 could be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.
CVE-2018-6211
PUBLISHED: 2018-06-20
On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, OS command injection is possible as a result of incorrect processing of the res_buf parameter to index.cgi.
CVE-2018-6212
PUBLISHED: 2018-06-20
On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, a reflected Cross-Site Scripting (XSS) attack is possible as a result of missed filtration for special characters in the "Search" field and incorrect proc...
CVE-2018-6213
PUBLISHED: 2018-06-20
In the web server on D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, there is a hardcoded password of anonymous for the admin account.