Cyberattacks on Healthcare Organizations – Michael Tal, Votiro
Michael Tal, technical director for Votiro, explains why cyberattacks against healthcare organizations are increasing in volume and sophistication.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Michael tal who is technical director for a vorturo? And they do a lot of stuff in the realm of zero trust and content and we'll get into that in a minute. But right now we're going to talk about Healthcare and the tax against those types of organizations, Michael.
Welcome the show. Hey, Mike, stay Thank you for having me. It's great being here.
We've seen an increase in the rate at which attacks are being launched against Healthcare organizations in particular. They're not necessarily net new ideas in any shape manner or form but we're seeing more of them and I'm just curious at this Junction. Why are we seeing more of that now than we were early or even though we all know that these are high value targets.
Sure. So it's it's quite interesting because many think that Healthcare organizations should be lost on the list for cyber criminals attacks, but the reality shows that there are no exception for fret actors with when they are trying to gain profit. So of course infiltrating Health Care are no, you know, there are no there are no strange for for cyber criminals attack.
One of the things that I I personally think that what the increase in in cyber criminals attack against against Healthcare organization is the fact that or is a is a result of the covid-19 pandemic, of course, covid-19 introduced the risk risk factor for healthcare, including the remote Workforce the new system. They need to be supported in some of the Staffing challenges. So all of the above, I think that causes also the increase on on cyber, criminals around the healthcare organization are the records that they're going after more valuable than most other records because it seems like it's gonna also include people's medical information and as the competition in that space increases, they're probably just going hey, you know, all those other records are on as valuables.
They used to be so more more of them are focused on health careers. Right. I agree that most of the time the asset of the of the patients and the medical information that these organizations hold is the the most important thing and the fat Act was trying to to expose and try to get control over the DCA important information.
And of course that that value that has on the on the black market is highly valuable. So therefore they trying to put their hands on on that important information it goes without saying of course with the you know, they're the Fret actors try to also take over some of the A healthcare machines for instance the ventilator machines we heard about an attack that that one group eliminated the the ventilator machine and causes a life-threatening situation in in a hospital. So these are just more of the things that they're trying to to expose or to compromise when they are taking over those those threats that they are looking to expose.
The attacks themselves are also not limited to the physical premises of the healthcare organization anymore. It seems like there's more telemedicine. There's more remote.
I don't know doctor in a box type of places that we see here in the US all the time when they're little retail outlets. So has the attack surface for these organizations expanded beyond their ability right now to cope with Absolutely, I think that you know due to the situation where there was an increase in remote Workforce. So some of the some of the system were not just on the on-premises data centers.
They also needed or required to move into the cloud. So some of these processes were digitized and you know their new right now, they're or not new but more option for the Fret actor to try to invade and maybe to to get themselves inside those digitized digital processes and and also to find some way to to insert themselves and to to get control over that sensitive data. They are looking to to get control.
So we are here in a lot more about zero trust and it's not clear to me that people understand exactly what's involved in that because I mean conceptually they'll get the idea in a second but it's not like I roll out of bed in the morning and go let me go buy some zero trust. There's a lot of stuff I got to get and bring together. So where are we in terms of zero trust and what should people be thinking about?
So in my opinion zero trust is, you know, a framework that more and more organization are adopting nowadays. And most of what we're seeing at least in my company is the requirement and the need to to secure the content that the organization is deal with so health care as long with other organization adopting the zero trust when they're interacting with content, right? So we spoke a little bit about the the digital processes that are moving now not just from the on premises data centers, but also move to the cloud and they know they need to secure those areas as well.
So it's not just you're you're getting an email with with the malicious fine in it. It's also the requirement the need to secure the those collaboration tool that are publicly Expos. To anyone or for instance if we're talking about a portal that that a medical clinic has to to serve their end clients or patients in order to upload some medical documents.
So these are also a weak points for the hackers to try and maybe upload a malicious content to those portals where where their patients their end clients are interacting with so the the thinking around, you know securing content and not trust any file or content that may leave your organization or you may receive from an external Source. This is where we'll sing at least the the need to you know, to reconstruct or to sanitize everything that you're interacting with in terms of content. How do I go about securing content people understand data, and they understand networks, but what exactly is content and how do I secure it?
Perfect. So today when we're talking about content, it's not just the importance of making sure that it arrives securely within your network by leveraging, you know, the SSL TLS methods and not just the the method to encrypt it when the data is is addressed but it's also to ensure that the data that you receive from any source is completely secure and you're able to open that file you are able to to interact with that document securely without the need to think twice whether that you know that email or that file came with any kind of malicious content in it. So the again the zero trust strategy in in especially in the CDR space which stands for Content this arm and reconstruction is to basically reconstruct every file that Your interacting with and by leveraging that technology You're simply looking at only the known good content of the of the file of the content itself rather than you know, just being depending on traditional security mechanisms such as AVS or other scanning tools because today we're seeing the fact that ransomware's and you know groups the Fret actors groups are evolving.
So today's not just banking Trojans that are spread around. These are collaborating groups that working together to to evolve those platforms and the ransomware and those malicious malware's keep keep evolving everything. So we need to keep with with that same pace and we learned that you know being dependent on traditional security mechanism is not the way to to ensure that the security the this the organization is cured.
The way around would be to concentrate on the good content from the file and then deliver only the safe content to the end user while living behind everything which is unknown or potentially bad content. Do you think the bad guys are getting better and inserting themselves into processes and kind of they're not just doing a smash and grab these days. They're we breaches themselves.
They're hanging around longer to see how things work and kind of inserting themselves into the workflows. Absolutely, I think also, you know the threat actors the security company on the one on the one hand try to to keep up with the pace and always the developing new technology, but on the other hand the Fret actors are always keep evolving and they also looking at at some smart and and sneaky ways to get inside of an email fret for it. For instance.
We're seeing, you know, Fred actors that are stealing legitimate email addresses and then by inserting themselves to a legitimate correspondence between you know, two parties they can easily have that, you know, the trust that they they need to have between the those two parties in in compared to someone, you know, just trying to leverage a Gmail or a Hotmail mail address that would maybe look suspicious to to some someone that interacts with that email but when they hijacks illegitimate email and then by leveraging As legitimate email address they will try to insert a weaponized file. Most of the time that will embed some malicious code inside of this file. This is the way that they're trying to, you know, get over or you try to to insert themselves within the security solution that the organization leverage at the moment.
Think most health care organizations are up to the challenge because for everyone huge Hospital chain, it seems like there's thousands of little Health Care Providers out there that have all this data and the bad guys are just as easily go after them as they would big Healthcare organization that has lots of security. Right. So I I think that's that's a really good point because most most of the healthcare organization, especially when we're talking about the public sector these specifically stating the hospitals are sometimes they have budget constraints.
So they they're not leveraging they they're not especially leveraging the latest technology and these can be a week a weak point for the Fret actor but that that again doesn't say that the Fred hand the Fret actors will will not try to invade or to to compromise also a large health care which have which may may or may not have the latest technology. So I believe what what will continue Drive the Fret actors group is the fact they will would like to have their hands on these on the sensitive data. So that's first of all that will be the the main Chase and they will try to at some point to get inside one of these sectors one one of these organization and it's it won't be a matter of you know, having the latest technology or having the existing the existing security mechanism.
But just whether the Fret actor will go after the sensitive data. It seems like we are heavily concerned about ransomware as always but are these attacks changing in nature going Beyond ransomware and people need to think more aggressively about just what it is. These books are up to Sure.
So the this is today I could say and it's related related to something that we touched a little bit before but today those ransomware or those malware's they they keep evolving because they're not just a Trojans. They're not just you know, Trojans that try to get the data from you. Once you're clicking and malicious link.
This is a whole platform. So when whenever you're getting an email for instance that has and and attachment and that attachment can be let's say a word document and for instance the word document has a macro embedded in it. So that that macro can initiate a malicious coat on your on your machine.
But what we're seeing today is that most of these attacks the way they are evolved is that the malicious code will not Run as soon as you will open that word document or that PDF file that you're getting from someone that would be a multistage kind of attack when you're first open the the fourth the first document that first document will will run another process and that process will make in some cases will open another document and that the the second documents that opens it will try to interact with an external source and that external Source still can be at be nine Source, but from that point where the the benign the benign host can can serve a payload that will then download to your machine and this is where the things getting more more and more dangerous because the payload the downloads to your machine. This is when the the actual processes start to run on your system and this is where the interaction with the with the hard disk in some Cases is getting into into the fact that it will it will download the final payload on your machine. So those kind of multi stages attacks that we're seeing are keep always keep evolving and it's not just you know, the the easiest way to just open a document and get attack but, you know having a multi-stage kind of attack that will at some point will run the the end or the the final malware on your machine and and we'll have the and we'll let the group or the attacker get control over your files and maybe do some lateral movement inside in into your network and gain the assets that they would like to have.
Do you think we're in danger of some sort of backlash against digitization of healthcare because of these attacks or when we just kind of keep plowing ahead regardless. So I I definitely think there's there's a concern around those those kind of digital processes mainly because of the fact that today is at least as we're seeing the market the the security around those tools are specifically with you know, enabling multi-factor authentication is the user login to the platform and sometimes you know again to to make sure that we're securely uploading the the file into into those tools in in the data will be encrypted in flight. And also of course maintaining the data I press to be encrypted but it's not just that because again when we're talking about a possible malware that can be hidden inside a file that stay that stays in those collaboration tools whenever someone will try to download all we will interact with that file.
This is It gets more complicated. So also the the platform the digital processes should be also secured with with enhanced mechanism in order to ensure that they also protecting the data itself. Not just with the common methods that we're seeing in the in the market.
All right, folks. I heard it here first the healthcare guys are far from out of the woods yet, and they might be more trouble coming than they can handle, but we'll see what happens from here and hopefully everybody will do the right thing. Hey, Michael.
Thanks for being on the show. Thank you very much. Mike for having me great being here today again.
Thank you very much. All right guys back to you in the studio.