Security

Medical Institutions Face Intensifying Cyberattacks, but Security Remains Weak:

TECHWORLD ·

박종석 포티넷 상무. [사진=김혜진 기자]

✦ AI Summary

Medical institutions are seeing greater exposure to external attacks as connections to medical devices and IoT devices expand, and they are cited as a weak area in South Korea's cyberattack defenses.

Since January this year, cyberattacks targeting university hospitals including Chonnam National University Hospital and Kangwon National University Hospital have paralyzed imaging examination systems and computer networks.

The industry has stressed the need to strengthen automated response, management systems, and manuals and recovery systems to prepare for insider threats and future threats.

As medical institutions expand connections to medical devices and IoT devices, the number of exposure points to external attacks is increasing. With recent cyberattacks targeting medical institutions occurring in succession, hospitals and clinics are being cited as one of the weak points in South Korea's cyberattack landscape, and security vulnerabilities are being acknowledged in actual medical settings as well.

Since January this year, cyberattacks targeting university hospitals have occurred. At Chonnam National University Hospital, an imaging examination system was paralyzed, and at Kangwon National University Hospital, the computer network was brought to a standstill.

At Kangwon National University Hospital, diagnosis was delayed and treatment was disrupted after access to MRI and CT systems was blocked. The industry says these cases show that medical institutions lack the security conditions needed to respond to attacks targeting them.

On the 17th, the industry stressed the need to overhaul security systems that take into account threats ranging from insider threats to future threats. It said the main issue in attacks targeting domestic medical institutions is insider threats related to personal information leaks, rather than financially motivated attacks.

The medical industry has entered the stage of developing humanoids for surgical assistance as technology advances. Accordingly, the possibility has been raised that connections between medical devices and external systems will expand in the future. However, the expansion of such connections is also increasing the likelihood of greater security risks. In particular, if humanoids are deployed, cyberattacks could pose risks directly tied to life and death.

However, the current security environment at medical institutions has limits in responding to such changes. Legacy systems that are difficult to take offline exist, and those systems have restrictions even when it comes to patching and rebooting. In addition, there is a shortage of security specialists who understand hospital-specific IT and OT environments, and many medical institutions have limited security budgets, making an adequate response difficult.

In this situation, it is necessary to consider the rapid changes in the attack environment. As attacks become automated through the use of AI, attackers are gaining greater ease and speed in searching for vulnerabilities and carrying out attacks. That is shortening the time defenders have to respond, and making responses more difficult.

On the 16th, Fortinet and the Hospital Information Security Association held the 'Hospital OT&AI Security Forum' and discussed cyberthreats targeting medical institutions and the technical and administrative security systems needed to respond to them as key agenda items. The forum covered what kind of security framework should be in place as cyberthreats targeting medical institutions grow.

Speakers commonly stressed that medical facilities should review their security problems and strengthen security systems not only through technical responses but also from the perspective of incident risk management. The emphasis was on the need to strengthen systems that go beyond simply introducing technology to include incident risk management as well.

Park Jong-seok, executive director at Fortinet, said in his session that conventional defense methods, which proceed from patch download to target verification and application, have limitations and make it difficult to respond to attacks. He said the key problem lies not in threat detection itself, but in delays in analysis and response, and that if analysis and response are delayed, actual incidents may fail to be blocked. He added that an automated response strategy that performs vulnerability detection, analysis, threat hunting, and supplemental data enrichment without human intervention is needed, and proposed data unification and an AI-based automated analysis and response structure as solutions.

Security threats in the medical field are difficult to explain by technical intrusion alone. The means of resolving security problems also have limits if they rely only on technical solutions, and management issues such as inadequate control of administrator accounts and neglect of assets unused for long periods are explained as factors that connect to security threats. It is pointed out that the biggest threat felt by the medical industry is also a management issue.

Attorney Kwon Hyuk-chan of Kim & Chang explained the risks of hospital cyber incidents and response measures, saying that security threats involve not only technical intrusion but also management issues. He said that in situations where cyberattacks targeting hospitals occur, management issues also lead to security threats.

He recommended establishing a preemptive response system to prevent confusion in post-incident procedures. He also said that fixed manuals and playbooks are necessary, and that following them can prevent initial confusion. He added that this can also help block additional financial losses.

He also explained that the key to responding to hacking incidents lies in establishing a recovery system. He emphasized once again the importance of a recovery system.

Source: TECHWORLD · Kim Hye-jin
Original: https://www.epnc.co.kr/news/articleView.html?idxno=407078

References

This article was produced with the help of an automated content generation algorithm.


Source: TECHWORLD

View original

This article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.