Unfortunately, there are no easy solutions to the healthcare IT security crisis, no magic black box you can simply hook up to the network, no five-step checklist to solve all your problems. One would wish that IT criminals could simply be put behind bars, but many—or most—operate from rogue jurisdictions such as Iran or Russia, where they are untouchable.
This will be a long journey and all stakeholders need to pull together. Not only must device manufacturers learn how to improve device security and law enforcement agencies how to collaborate internationally in an efficient manner—healthcare organizations must also learn how to continuously improve their security in an incremental fashion. However, while there are no easy solutions, there are at least some basic guidelines for improving your security.
Chief of these is the realization that you are never done. You are up against motivated and intelligent adversaries who will come up with a steady stream of new ways to attack you. The saying “security is a process, not a product” is not just a cliché. It is also true.
Also remember that security needs to be improved in a balanced manner. If you spend all your budget on improving medical device security, you are not really much better off because the bad guys will simply attack your office network instead. You can safely assume that the attackers will always go for your weakest point. And, finally, don’t forget those SCADA systems!
By Leif Nixon, Security Expert at Sectra Communications