Medical Devices Used for 20 Years... Fortinet: Protect the Network and Endpoints Together
IT DAILY ·
✦ AI Summary
Fortinet Korea Managing Director Moon Gwi spoke at the 'Hospital OT and AI Security Forum' held on the 16th at the Korea Chamber of Commerce and Industry in Seoul's Jung-gu, presenting on OT security architecture for protecting hospital infrastructure environments.
He explained that Windows PCs installed with medical devices such as MRI systems are used for 10 to 20 years and age over time, and that security problems grow as patching stops and antivirus functions weaken.
He also said that because hospitals have both IT systems and medical devices and external connections are unavoidable, they must apply network segmentation, perimeter firewalls, EDR, and other security measures together.
Fortinet emphasized the need to protect networks and endpoints at the same time in relation to medical device security. Moon Gwi, executive director at Fortinet Korea, gave a presentation on OT security architecture for protecting hospital infrastructure environments at the 'Hospital OT and AI Security Forum' held on the 16th at the Korea Chamber of Commerce and Industry in Seoul's Jung-gu.
Moon identified the aging of long-running medical devices and the PCs connected to them as a key challenge in hospital security. He explained that expensive medical equipment such as MRI systems is used for 10 to 20 years after installation, and that the Windows PCs installed alongside medical devices also age. He added that patching stops and antivirus functions deteriorate on these aging PCs, and said the biggest security problem in the medical field lies in protecting such systems.
Moon stressed that hospitals must consider not only the long life cycle of medical devices but also the unavoidable need for external connections. Accordingly, he said that protecting hospital infrastructure requires a security architecture and an OT security framework suited to that environment.
Hospitals are targets for cyberthreats. If a medical institution is attacked, it may suffer information leaks, clinical system disruptions, and even threats to patient lives. In 2024, Synnovis, a testing organization under the NHS, was hit by a Qilin ransomware attack, which caused some systems to go down. King's College Hospital said delayed blood test results were one of the factors that affected the death of one patient.
In South Korea, attacks on medical institutions are also increasing. According to the Korea Social Security Information Service, incidents involving domestic medical institutions rose from 18 in 2020 to 71 in 2024, an increase of about 3.9 times from 2020 to 2024. Earlier this year, ransomware infections occurred at Chonnam National University Hospital and Kangwon National University Hospital, disrupting the operation of the picture archiving and communication system (PACS) at both hospitals.
Hospitals have a structure in which OT environments composed of IT systems and medical devices coexist. Medical Internet of Things (MIoT) devices are also deployed inside hospitals. Examples of Medical Internet of Things (MIoT) include patient monitoring equipment, incubators, and X-Ray systems, and patient monitoring equipment, incubators, and X-Ray systems are IT-connected devices.
Moon identified the long usage cycle of medical devices as a major risk factor. He said medical devices are expensive and can be used for as long as nearly 20 years after being introduced to a hospital. In that process, the Windows PCs installed with the medical devices also age, increasing exposure to attacks as the equipment deteriorates. He also explained that there are cases in which operating system technical support ends, and situations arise in which patches cannot be applied even after vulnerabilities are discovered.
Moon, however, explained that it is difficult to disconnect medical devices from external systems. He cited the need for medical staff to check test results through linkage with the hospital information system, the need to check test results through linkage with the picture archiving and communication system, and the need for remote access by outside vendors for maintenance purposes. Accordingly, he said the key lies in controlling and protecting the unavoidable connection points.
Moon particularly emphasized the OT-IT boundary and legacy endpoints. As countermeasures, he proposed separating OT and IT networks and installing firewalls at boundary areas, saying the purpose of firewalls is threat control. He added that only the minimum necessary connections should be maintained through firewalls. He also highlighted the ability of Fortinet solutions to identify and control medical information protocols such as DICOM and HL7.
The importance of managing legacy endpoints on which patching has stopped was raised. These devices are difficult to update and also impose a heavy burden if antivirus software is installed, so EDR was mentioned as an effective alternative. EDR was described as having characteristics optimized for detecting abnormal behavior.
Moon said that the role of medical devices is limited and that the functions used by medical staff are also standardized. Accordingly, he explained that detecting abnormal behavior alone can allow threats to be identified and addressed early.
Moon said that the medical OT environment is difficult to protect with a single security product. He added that security is not complete simply by installing one firewall or securing visibility. He said that network security, access privileges, remote access, and endpoint security all need to be covered, and that multiple security tools should be introduced after priorities are set for each environment.
The event was co-hosted by Fortinet and the Hospital Information Security Association. The Korea Social Security Information Service, Yulchon LLC, and Kim & Chang were among the speakers, representing the medical, public, and legal sectors. Yulchon LLC and Kim & Chang presented on response measures for the AI Framework Act and on legal risks and response strategies related to hospital cybersecurity incidents.
Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241669
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.