Healthcare Security Challenges with Rubrik’s Rick Bryant
Rick Bryant, healthcare chief technology officer for Rubrik, explains how cyberattacks against healthcare organizations are starting to impact the confidence patients have in providers.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Rick Bryant, who's the healthcare CTO for Rubrik.
And we're talking about the cyber attacks on all these hospitals and medical institutions. It's just getting so much noise these days that even the patients know about it and they're getting a little uncomfortable 'cause they're not sure that if they show up that they can get in or be, if they're in, well when are they gonna get out? Because, well, it might turn out that the machines are broken or something.
But, um, Rick, welcome to show and walk us through how big a problem is this? 'cause I think we've all seen at least a few headlines in our local towns and areas, but is this a, an epidemic as they say? It's, uh, it's quite a problem, Mike, and thank you very much for having me on the show.
Um, when it comes to healthcare, I've been in healthcare for over 30 years and I've never seen an environment like this where it seems like the bad actors are specifically targeting our critical infrastructure. Um, not just for the purposes of of monetary gain, but to cause disruption in our society as well. And as you mentioned, that's severe concern.
I'm a patient, my children are patients. Everybody needs to know that they're gonna be taking care of effectively and safely and that their data's gonna be protected as well. So what's to be done about this?
Because we've been talking about, uh, resiliency and defending against ransomware attacks using backup and recovery forever. Is it just too big a task? Too big a job?
I mean, a lot of these organizations, they're not rich in the first place. They're borderline nonprofit. Um, some are of course very wealthy, but uh, the bulk are not.
So how do we solve this issue? Well, you know, you mentioned the margins within healthcare, it's not unusual for them to be around 2% and we have to maximize that value with that margin that they have. Their focus in healthcare has always been around patient care and I think unfortunately that's caused them lacking in a lot of security aspects, both the people process and technology to properly protect that data.
But I'm constantly faced with the reality that, you know, um, as my mom would always say, uh, uh, uh, ounce worth of prevention is worth a pound of cure, right? Would you like to spend the money now or do you wanna spend the money remediating after you've lost the trust? And I think that's really the situation that we're getting into, especially coming out of a pandemic where the world recognizes the criticality of access to healthcare.
And now seeing that a third of all Americans have had their patient care information compromised just in 2020 alone. And that they're starting to, uh, have concerns around trust, being able to have access. We show in our data that it impacts the ability to take patients in by a minimum of 20% when under ransomware.
And the part that scares us the most is we are now starting to correlate with data. Both the study at Vanderbilt University and the University of Minnesota that incorporated their study into our zero labs report, that if you go into a hospital that's under a ransomware attack, they're gonna be, have more medical errors and more sentinel events that are unfortunate. So that really brings up the trust concern.
We have to be able to protect these patients, not just to be able to take care of them real time, but we have to protect the information as well. Do you think that this is impacting a lot of the willingness of patients to go to the hospital? 'cause it's a big enough problem already.
A lot of people have concerns about going 'cause well, you know, they wanna postpone it as long as they can. And often why is it being too late? So, uh, is this just one more thing that's resulting in people not being proactive enough about their care?
Yeah, it's, it can be a concern. You know, preventative care is a major concern. It's one of the things that's supposed to help keep us healthy and help keep us out of the hospital.
But how likely are you, or how willing would you be to go into a hospital that's under an attack where there could be, um, problems with them accessing your, your history or your drug allergies or for that matter, even in critical care, your blood type, that's life threatening events. I know I wouldn't willingly go into that environment, but the most important thing I think is to work as an industry with the hospital, the covered entities, the providers themselves, and their technological partners to be able to make sure that that critical infrastructure is all available. To what degree, given the available expertise that a lot of hospitals have, especially around it and cybersecurity, should they be relying more on somebody to manage this as a service for themselves versus them doing it?
Or is it because of the nature of the data they gotta do it themselves anyway? Well, everybody has to be responsible for security, but it's not outside the realm of possibility to outsource it to expertise. You know, a lot of hospitals I work with, they tell me, you know, we're in the business of patient care.
We're not necessarily gonna be able to hire the top of the line security experts. By all means use a partner exo expert system to be able to leverage those kind of resources. But ultimately everybody in the ecosystem, including the business associates, have to be responsible for security.
Is this gonna get any easier anytime soon? You can't walk down the street without somebody leaping out to tell you about their new great AI thing. Um, can we get to the point where, uh, it's basically idiot proof?
Uh, I wish we could, but every threat, it's always like a cat and mouse game, right? As every threat develops, our preventative measures and remediation develop as well, and then they come up with a new method. I think the thing that scares me the most about the current environment is that there are literally platforms, ransomware as a service platforms out.
There we're a 12-year-old kid could launch an attack against an organization. They set up a Bitcoin wallet, they give them a target, they do the ransomware letter and they move on. So I don't think this is gonna go away, but I think our diligence around being able to identify and properly protect our critical data and having resiliency in our systems to where it becomes more of a nuisance than an existential threat, that's gonna be important.
A lot of the time I think folks are like, well, I backed up all my files and they're, I got my three points where I did that and I should be able to recover jointly only to discover that. Um, well it turns out that the bad guys are smarter and they basically target the backup first and then go after everything else second so that the backup itself is corrupted or is, is is a source of the malware. Um, so what's your best advice to folks about how to get smarter about the way they think about all this?
Well, it's interesting how you, you just mentioned a perfect example of how the attack profiles evolve, right? They know if they can get to your backups, they own you, you have no choice except for lose the data or to pay the ransom and hope that they give you the keys to be able to get the data back. Hope is not a strategy.
So having a good backup system in place, but more important, a backup system that has the intelligence to tell you this is a good copy or this is suspicious and you need to look at this. And more importantly, if something comes out tomorrow, being able to go back and look and say, alright, are these backups, do they have fidelity? Do they have a malware workload in there?
We have a technology that is absolutely incredible to where it stores an immutable copy from day one, but it also in real time will tell you if there's any anomalous type of activity in that backup stream, plus give you the ability to have threat hunting as well. But that's only one component of a resilient system. I always advocate that you have to look at not just the technology, but the people and the processes, and you have to have good perimeter security as well as, uh, user education.
All of these together in a highly mature organization where people, uh, feel like they have the, the confidence to be able to report something suspicious, but also the good security practices of not writing their passwords on the back of the keyboard, which I have done in olden days. Um, you know, those things will all come together to make us more responsible and accountable to our patients and hopefully build that trust back up. So who's in charge of this particular process within the healthcare sector?
I mean, is it that your average IT person, are there security people involved? Is this becoming something of a team sport? How does it work?
Yeah, it's a great question. I remember back in the day when you talked about security, it was about confidentiality, integrity and availability. But in reality, over the past two, uh, 20 years or so, we've had a separate silo for infrastructure and being able to keep up with that demand and security as a separate entity.
Well, we're seeing with modern day attacks, those groups have to be merged together. Like you said, it's a team sport now and understanding. And a good example of that is the infrastructure team will look immediately at recovering the data, whereas the security team might need to do some forensics on it to find the bad guys and need to make sure that the data is actually correct.
The infrastructure teams could easily reinfect the organization at that kind of odds if they're not working closely together. So it is a team sport. I highly recommend that you build this into your incident response plan and you actually test this in advance of a scenario.
Personally, I've been through three, uh, malware, uh, infiltrations in my career. One of 'em is zero day. And let me tell you, uh, coming up with the plan at that time, that's not the right time.
Pressures are running really high, they're stressed. People are considering, you know, is is this working or does this data set match the data set? You gotta plan this stuff in advance and then you'll feel much more confident about being able to recover and win.
Of course, one of the reasons that they're targeting hospitals is that those medical records are worth a lot more on the dark web than your average credit card number. Um, but what is law enforcement doing about this or what can they do and, and are we seeing any progress on that front? Um, personally I have been very impressed with both the federal government's ability to create a cybersecurity work group.
I actually had the privilege of, uh, working with them to show them what the threats are in the industry. Um, also the FBI has been very instrumental in being able to share threat information. I've seen some organizations that took that threat so seriously, they cut off all access until they knew that they were secure.
So there is some law enforcement aspect to this. Um, but ultimately it's gonna have to be the institution itself to be able to prevent and protect themselves against these measures. A lot of times they can do some threat, um, intelligence.
In fact, um, in the healthcare arena, we have what we call, uh, an isac, which is an information security sharing organization or nsac. There's many different acronyms for it. We need to get better at sharing that threat information both from the federal government and amongst ourselves.
And then properly, uh, patching and protecting our organizations as well as having good immutable and safe copies of the data for that worst case scenario. Why is that such a challenge? You would think that faced with a common enemy that we would all kind of naturally wanna, uh, circle the wagons, but what, what prevents us from doing?
Is it a cultural issue or a technical issue? Yeah, that's a very good question and I would have to say it's a bit of a cultural issue. You know, it's, it's kind of interesting in healthcare I do see more collaboration.
They're not as competitive even though they are competing. Um, but I think sharing a threat information might make you feel a little bit more vulnerable and sharing that information to the wrong people could, could actually make you a victim of a, an attack. So we have to find a way to be able to share this data safely, um, with confidence and then to be able to, to have the time to protect our organizations.
But I think that's a really interesting question. I'd like to see how that evolves. What is your best advice to folks?
What's the one thing you see folks doing today that still makes you shake your head and go, folks, we need to be better than that. Oh boy. Um, uh, as an industry expert, it always, uh, very much worries me how many of these attacks are not hacking in.
They're logging in and you'll see that in a number of fronts, not just in healthcare, but they're logging in because there's not good, um, what's the word I'm looking for? There's not a lot of cleanliness. There's not a lot of good process around being able to get rid of old accounts, get rid of old passwords, um, making sure that the developers that help put the system in those accounts are expired out when the system's actually in production.
So that's probably the biggest head shaker. Um, and that you have to be able to have a consistent security model and you have to have the discipline and hygiene to be able to affect it. I think that's the word you're looking for.
That's The word I was looking for. Hey folks, you heard it here. I don't know.
Maybe someday there'll be a rating for hospitals based on their IT security. They get rated for everything else and, uh, people will wanna know what the level of confidence is. So who knows, that might be the next big thing in the healthcare security space.
But in the meantime, be smart and be safe. Hey Rick, thanks for being on the show. Thank you so much.
I really appreciate it. All right, and back to you guys in the studio.