How Can Hospitals Prepare for Ryuk Ransomware?

166 views
•
December 10, 2020
by
RSAC Cybersecurity
YouTube video player
How Can Hospitals Prepare for Ryuk Ransomware?

TL;DR

Hospitals can improve ransomware resilience by knowing their assets, mapping workflows, building threat models, involving information security staff early, and using defense in depth. Because healthcare operates continuously across interconnected clinical, administrative, and digital systems, organizations should plan for attacks and prioritize rapid recovery rather than assume that every intrusion can be prevented.

Transcript

Hello, RSA Conference community. My name is Cecilia Marongue. I am the program director of innovation at the conference. I am lucky to be joined with Nina Ali, who is the biomedical advanced research and development. She has a fellowship at the Biomedical Advanced Research and Development Authority, but most importantly, some of you might have seen... Read More

Key Insights

  • Healthcare is a continuously operating ecosystem in which hardware, software, clinical systems, administrative processes, and connected devices must work together. Security teams therefore need ways to investigate and remediate problems without overlooking how a change to one component might interfere with another part of care delivery.
  • Every hospital is a distinct technology environment, so one standardized fix cannot automatically secure all facilities. Differences in locations, staffing, devices, clinical workflows, and connected systems require organizations to understand their own configurations before deciding how a particular vulnerability or remediation applies.
  • Medical devices are only one part of healthcare cybersecurity risk. Electronic medical records, radiology information systems, laboratory information systems, billing, insurance, personal phones, implanted devices, diabetes equipment, and digital medicine all contribute to the interconnected environment that defenders must assess.
  • Attackers may remain inside a system for an estimated 90–120 days while observing operations. During that period, they can identify information worth taking, find components they can disable without immediate detection, and learn how the organization functions before their activity becomes visible.
  • Large and small hospitals face different resource and exposure problems, but both require protection. Smaller organizations may have fewer technology personnel, while larger systems may contain more information and more unnoticed places where an attacker can operate after gaining access.
  • Ransomware resilience is increasingly measured by recovery speed after an attack, not solely by whether an attack can be prevented. Hospitals should prepare for compromise, understand operational dependencies, and establish the knowledge needed to restore essential functions while limiting further damage.
  • Asset inventories make security alerts actionable by showing whether an organization owns an affected device model or software version and where it is deployed. This knowledge allows staff to locate and remove a vulnerable component rather than losing time determining whether it exists.
  • Threat modeling, workflow analysis, early information security involvement, and defense in depth are practical foundations for hospital preparedness. The FDA is asking medical device manufacturers to provide threat models so healthcare facilities can build on existing analysis and secure devices for their particular environments.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can hospitals prepare for Ryuk ransomware attacks?

Hospitals can prepare by maintaining accurate asset inventories, documenting clinical and technical workflows, developing threat models, involving information security personnel early, and applying defense in depth. Preparation should also focus on recovery because attacks may already have occurred before staff recognize them. Knowing which systems support each service helps teams find affected technology, reduce exposure, and restore operations more quickly.

Q: Why are hospitals especially vulnerable to ransomware?

Hospitals operate continuously and depend on many connected components, including medical devices, electronic medical records, radiology systems, laboratory systems, billing, insurance, phones, and digital medicine. These components must work together while patient care continues. Healthcare organizations can also be resource poor, and an institution may have an IT team without a dedicated information security team to identify and address threats.

Q: Are medical devices the main cybersecurity risk in healthcare?

Medical devices are an important risk area, but they are not the only source of healthcare cybersecurity exposure. The environment also includes electronic medical records, radiology information systems, laboratory information systems, billing and insurance processes, digital medicine, personal phones, pacemakers, and diabetes equipment. Defenders must examine the broader system and the connections among its components rather than treating devices as the sole problem.

Q: Why does each hospital need its own cybersecurity plan?

Each hospital has a different ecosystem of technologies, locations, staffing, clinical departments, devices, and workflows. A solution that fits one organization may not address the configurations or dependencies of another. Hospitals therefore need to map their own assets and operations, test whether a proposed fix could cause interference, and adapt security controls to their specific clinical and technical environment.

Q: How does an asset inventory improve hospital security?

An asset inventory tells a hospital whether it owns a device model or software version named in a security alert and where that asset is being used. Staff can then locate the affected equipment, such as a unit allocated to a particular clinical floor, and remove it from exposure. Without a reliable list, teams may waste critical time determining whether the vulnerable component is present.

Q: What is threat modeling for medical devices?

Threat modeling is a structured way to understand assets, workflows, potential security problems, and the protections needed around a device or system. It gives healthcare organizations a starting point for evaluating how technology fits into their environment. The FDA is asking medical device manufacturers to prepare threat models that can be provided to hospitals and ambulatory centers, which can then apply additional security as necessary.

Q: How long can attackers remain inside a hospital system?

The interview gives an estimated period of 90–120 days during which people may already be inside a system and observing its operations. That time can allow attackers to determine what information is available, identify components that can be disabled without attracting attention, and remove data while remaining unnoticed. The estimate reinforces the need for visibility, preparation, and rapid recovery capabilities.

Q: What does ransomware resilience mean for healthcare organizations?

Ransomware resilience means preparing to recover quickly after an attack rather than relying only on prevention. Hospitals should assume compromise is possible, understand which assets and workflows support essential services, and know how to isolate affected components. Early information security involvement, defense in depth, threat models, and accurate inventories can reduce an attacker's available landscape and help teams restore operations faster.

Summary & Key Takeaways

  • Healthcare is a continuously operating system of systems that combines medical devices, electronic medical records, radiology and laboratory information systems, billing, insurance, and digital medicine. A disruption in one area can affect other operations, while the mixture of technologies and people makes identifying, testing, and correcting vulnerabilities especially difficult.

  • Every hospital has a distinct environment, so a single security fix cannot protect every organization in the same way. Small facilities may have limited teams, while larger organizations offer attackers more information and more places to hide. Both require coordinated industry support, clear asset visibility, and recovery-focused resilience planning.

  • Threat models, workflow documentation, accurate asset inventories, early information security involvement, and defense in depth can improve preparedness. When an alert identifies a vulnerable model or software version, a hospital should be able to locate affected equipment quickly and remove it from exposure. Manufacturers are also being asked by the FDA to provide threat models.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚