Healthcare Data Security – Terry Ray, Imperva
Healthcare providers rely on web applications and APIs to deliver secure and reliable access to patient data. But, automated threats and insecure APIs pose serious cybersecurity risks. Terry Ray, Imperva SVP, data security GTM and field CTO, discusses the latest threat research from Imperva and steps healthcare providers must take to protect their data against supply chain threats, malicious bots and attacks on applications and APIs. For more information, visit Imperva.com or Imperva’s healthcare event on June 28, 2023.
Transcript
This is techstrong tv. Well have the great privilege of being joined by Terry Ray. Terry is SVP Data Security, g t m, and field CT O with Imperva.
Welcome Terry. Thanks. Thanks for having me, Mitch.
Always good to talk with you. Great. Well, before we get into our topic, we're gonna talk about healthcare and security, which I'm excited to hear some of your thoughts about that.
Tell us a little bit about yourself and tell folks a little bit about Imperva. Sure. Yeah.
Uh, well, I mean, me, maybe it's not that interesting couple of kids, you know, dog, all that kind of fun stuff. But I am in Texas and I talk fast for a Texan, so I always do my, I do my best. Yeah.
Nortex, I guess Slow down, right? Slow down my role. So I'll, I'll do my best to do that.
Um, but I get excited about these topics. Uh, you know, Imperva has been doing data security, application security, and if we had to sum it up, we do all, we, we protect all paths to data. So it doesn't matter how you get to your data, our mission is to make certain that you have eyes on the people and the things and the stuff that they are doing and the stuff that maybe they shouldn't be doing in that data.
And that's, uh, that's the, if you had to sum it all up, that's what we do. Some people call that web application firewalls. Some people call it database activity monitoring.
They all have their acronyms, but it comes down to that one use. Let's protect data and all paths to it. Mm-hmm.
And there's multiple paths to, to doing that. Of course. Like you say.
Um, and, and Imperva two focuses with, um, large enterprise, large organizations at, at, at big scale as well. I'm sure you can do smaller things too, but I think this, one of the distinct things about Imperva is yeah, we're dealing with some very large organizations across verticals. Absolutely.
If you're, you're in good company, I would say if you're, uh, leveraging Imperva technology, you're with the, you're, you're with the, the big folks that are out there. And, and exactly to your point, my first customers were not a, you know, a bank you would've ever heard of. They were a small regional bank, cuz they have the same regulations, not picking on, on private data here, but they have the same data that a big bank does.
Healthcare, small healthcare has the exact same data that big healthcare has. However, they have smaller budgets, maybe fewer people, maybe less security. A a as well, right?
So, you know, if I'm a bad actor, do I want to bang my head against a, a massive financial services organization to steal some data? Or can I get the same quality and volume of data if I go against a, uh, maybe a, a smaller, less hard target? I like the old adage, why do they keep robbing banks?
Well, that's where the money is. Well, let's talk about healthcare. Cause I know, you know, in, in Perva and, and all the work that you do with customers, I'm sure you do some analysis on the trends and the data and the things that are happening across the various products and industry verticals, healthcare particular one because of regulation and privacy and, and, and, and.
Mm-hmm. Um, and we could go down that list. I'm curious.
Um, you know, we're, we're, we all see malware, we all see fishing, we all see bad bots. There's a long, there's a, a long list of things, but there's a few that we see a large quantity of. And I'm curious kind of what your perspective is on that.
Yeah, absolutely. And, and, and I, I'll admit, right, I I deal with a lot of different industries. So I pulled together some stats specifically for this discussion to make sure that we, you know, we had our ducks in the row.
And I thought one of the interesting things, uh, was it's, it's a little bit less of a stat and really more of a trend that, that I'm seeing in, in healthcare. Uh, and it goes hand in hand with a lot of other industries, but I think it goes without saying in healthcare ransomware is, is is always the, the top of mind, right? It's, it's always what they think about, uh, my wife is, you might be able to see in the background, right?
There's some surgical books back there somewhere, whatever. So my wife is a surgeon, pretty Sophisticated up there. That's not my half my half's, the other here, Stephen King.
Okay, I'm with you. But, but the point is, is is they're always worried about this stuff because if, if, if it, if, if you get ransomware and there's multiple ways to get it, then it can, it can shut down your business. That's not necessarily the top vulnerability that exists in healthcare, but it's the one that is most impactful.
And frankly, most healthcare have done a pretty good job. Now after seeing this problem af you know, the last five to eight years or so, most of them, I hope most of them have a solution around ransomware. But what we see in addition to that now going forward, is a lot of supply chain type stuff.
It's the, it's the vulnerabilities and exposure that exists through the manufacturers. Cuz let's face it, when you're a provider, you don't manufacture anything. Everything is supply chain.
Everything is third party. So all of your apps, all of the bedside pieces, everything. Someone else developed it, someone else is on the hook for developing it securely and providing what third party components exist in that.
And if it stores the data and their site, or whether it stores it on your site or even in your electronic medical records system, that also you didn't create yourself at the provider somebody else made. What's the security around it? So the trend that I'm seeing is organizations saying, okay, we've got ransomware pretty well taken care of.
What can I do about this third party piece? And third party can be supply chain, it can be other apps, but it's, it's essentially all of this stuff that the provider didn't create. The last piece here, and it, this is one that is not unique to healthcare, but, but affects healthcare significantly because of, of the budgets that tend to exist in healthcare, which tend to be a little smaller than elsewhere, is a talent shortage, right?
So it's hard enough to find network folks out there that can do network security and even traditional, uh, uh, endpoint security and other types of security, but trying to find detailed expertise around protecting my data and the paths to my data application security. And otherwise, if they find one, it's really easy for organizations with much larger budgets to steal those people straight away. And so it's hard for healthcare to keep that, that, that brain drain from constantly happening in their environment.
Very interesting. Um, I'm curious, going back to your second trend, oftentimes we don't know what the chain of the supply chain looks like, right? It's what are all the pieces and what are those parts made up?
You know, it's kind of the, the multi-layers of that. And how far do you go? Do you go with that?
In, in, in, my father was a doctor, so I had been exposed to a few medical books and a little bit of medicine. Um, but but it, there's, there's a logistics and a supply of those materials, right? Um, that's all part of healthcare and running a hospital or a doctor's office or whatever.
And I wonder if they, if, if they have the good handle on our data, where's it at? Who's managing it? How is it being managed?
Or is that where people now turning a lens to and they're really putting a lot more focus on it? Yeah, so I, I wanna say it's the providers, you know, whether they're big or small, it's the providers, the physicians and otherwise that are saying, we need to pay attention to us. That's what I wanna say.
I think the reality is, is it's the regulators. Regulators are saying, okay, we know you have the data. We know you've had the data for decades, upon decades, upon decades, but now you're being mandated by some regulations, high high tech and high trusts and others.
You have to share this data. The data has to be shared between your provider and other providers. Your data has to be shared between your different components and applications and ambulatory and in different places where you're gonna use that data.
We're all gonna always have to fill out the same forms every time we go in. That's not gonna change, but I have to be able to sign that form. And then my data gets shared between different, different places that sharing exists across APIs and in modern application security today, or modern application development today, the way that you share that data is no longer mailing something.
Or, yes, you might break your finger and get a, get a c a a d a CD or a DVD v D to give to somebody, but I assure you that information is electronic and shared electronically through an a p i through multiple systems within a provider. And so when, when I hear, and I think about supply chain, yes, there's all the logistics and all the other pieces and things that have to happen, but the inner, the, the connective tissue, if you will, between all of those individual pieces are the communication channels that exist from a p i to a P I and a p i to p i, which is supply chain to provider and provider to supply chain and et cetera. And I think that's where there's a lot of ambiguity in the, in the providers themselves to understand what they really need to do to secure that, those APIs and the data behind them, but also whether or not they even have gaps there.
I I was speaking with one provider a while back, and I was asking them if they understood what fire was F H I R, the fast healthcare interoperability resource, which mandates the security around APIs. And this part particular ciso, he is like, look, he's like, uh, he's like, not only do I not know what fire is, uh, I, yeah, I know my team develops APIs, some of my team does create their own APIs, but I don't have a mechanism for identifying which APIs need to adhere to fire, which ones don't, which ones in fact do because they need to and which ones don't. And so he is like, it is a gap for me, but it was a gap I didn't even know about.
And so I think this is one of these other, I dunno if it's a trend, but it was certainly an example of a case where there's, there's without a doubt, a gap that that particular provider had no idea that they needed the security to the level they did around APIs, and they didn't understand the gap that they had was as large as it really is. Yeah. I, this is just a guess on my part, but it, it seems like there's a tipping point whether you're a network security engineer or you're a CISO where you're thinking about moving from the protection model, right?
I'm gonna build things around things to keep people out or keep them from going anywhere if they do get in to, no, it's what happens between components. It's whether it's microservices, stocking over APIs or it's SaaS service in your application and moving data to some third, you know, at a data lake, at a, at a, at a hyperscaler, whatever those scenarios are. It's those connective tissues, if I can use that analogy.
Um, that's, that's where sort of the danger is. And that isn't all just network traffic, right? It's what's happening inside of all that network traffic.
That seems to be the next layer of where folks are going down to really try to get a handle on what don't I know about, what do I need to have a better handle on? Do you agree with that? I, I, I do.
And, and I think, you know, when you look at, when you look at, and I'm, I'm today on this call, I'm, I'm mostly picking on, you know, bots and, and, and uh, APIs, right? But I think when, when you start to really dig into the challenges that a lot of these providers have, it's okay. I, I know I have APIs that connect to my electronic medical record system.
I know I have APIs that connect over here, but what a lot of organizations do is they don't recognize that about 4% of their overall a p i infrastructure are what's considered shadow APIs. They don't know that they exist. Mm-hmm.
They're completely, I, I won't say that they're hidden, but they were part of a component that might be legacy or part of a component that came with another component that you didn't know how they were interacting. And so all of a sudden you've got something and 4% seems like it might be small, but the reality is, is, you know, it, it's pretty uncommon that you have a, a security gap that's 70% of somebody's infrastructure. Usually your security gap is gonna be a small little sliver that you may not, you as a provider or you as a security person may not either see or consider that critical or may not have the tool to, to go and find it necessarily.
But when someone, I really, really dedicated or dedicates their time to go and look for where you might have vulnerabilities, where you might not have patched or where your third party might not have patched, the places they're gonna find are those places that you didn't know existed because they haven't been patched. Cuz you don't know they exist, they don't have security on them because you don't know they exist. They don't have the same level of scrutiny that the rest of your infrastructure does.
So they're going to stand out like a bright flashing light to say, yeah, I've got all these existing vulnerabilities, I've got all this stuff, and that's where you're gonna have your problem. And so I think a lot of organizations I'm seeing now are coming to us and saying, help, how can I identify these types of issues? Cuz what they've recognized either doing a, a, a, a proof of concept with technology or hearing about their peers, if they've recognized that it's no longer the, the te and it hasn't been for a long time to be fair, it's no longer Terry the hacker on a Saturday afternoon typing on his keyboard looking for something.
Mm-hmm. Now it's bots, right? And it has been bots for a very long time, and I'll give you one more statistic.
You know, 31% of all healthcare traffic in fact is bad bot traffic. Wow. That it sounds like a lot.
But to be fair, that's a pretty consistent statistic. Regardless of the industry on the internet, about 31% of your traffic or 30% of traffic is bad bot traffic. It doesn't matter what industry you're in, doesn't matter.
So if 30% of your traffic is bad bot traffic, and I'm not talking Baidu being in Google and everybody else, if it's all this bad bot traffic and it's always looking for those little gaps, it's those little gaps that are gonna get you. And it's those little gaps that they're going to find because they're not being selective. They're only, they're not just looking at the APIs that you know about.
They're not just looking at the applications that you know about. They're being opportunistic and they're scanning the whole system. They're looking at the whole system and they will find the little, the little hotspot in your environment that, uh, that you didn't know about.
Mm-hmm. Yeah. And it's, it, it's very much a moving target too.
It's not like, okay, we deployed some stuff, it's got APIs and once we find them, we're good. Oh, they're contemporary software architectures like cloud native and things like that. Or API first design, right?
Mm-hmm. Where the APIs is with the glue of what keep builds the application, keeps it work, working together. I mean, we're creating APIs maybe on a daily basis, right?
In our software development process. And so it isn't, you know, because we did it, we worked on this last week, we're good for a couple months. No, we may good for an hour if we're lucky in some cases cases and, and that that's, that's, that's a, that, that's a different world than the deploy it and we kind of leave it alone.
So it'll be stable for a few months or whatever time period. It, it's, it's, it's a different environment that you're having to chase after or try to get in front of. And I'm curious, are there, are there ways that people can both find what, you know, it's the unknown unknowns or they can, they can start to get kind of in front of this at all?
Yeah, so I think, you know, if you, if you look at, you know, what the components are in an application, right? You know, of course we, as we've been talking about, applications are no longer monolithic like they were years ago, right? They're APIs, microservices, as you mentioned, functional, and you know, all of these sorts of things, right?
So purpose-built code to do very specific things broken out across a, uh, a multi-layered application. Um, what that means to an organization, especially an organization that has the, the talent shortage that I talked about, not just on the security side, but even on the development side, is organizations are leaning heavily into automation and simplification in, in fact, I'm seeing a lot of organizations say and recognize, I need somebody to do this for me. I, I need, I need, I know I need application and data security, but I need it in a way and in a form that I can consume that is as easy for me to use being a network engineer as it is.
If I were a a, an application expert or an application software expert, it's gotta be framed in a way that my, my standard engineers can understand it. And more importantly, it's gotta be able to recognize that application security is not a p i security. Now it, a few years ago it was, but today, now with application security, even the OWAS brought the open web application security you program.
So O OSP used to have an OS top 10, they still do, but now they've got an OWAS top 10 for bot, it's an OS top 10 for a p I and OWA top 10 for applications. They've even broken it out recognizing that the same level of attacks that can work on an A P I and also work on applications, while they do tend to work on APIs, in some cases APIs have their own nice little list of 10, you know, top attacks and they're not the usual suspects you see in application security. So what we're seeing from organizations today is they're looking for a single stack, if you will, that says, I'm gonna protect your applications, I'm gonna protect your APIs, I'm going to detect your bad bot activity and good bot activity and distinguish between the two.
I'm gonna be able to recognize account takeover attempts that are all bad bot. And when I look at, for example, A A T O account takeover attempts, it's just, it's just trying to manipulate the business logic of your, of your system. And in some cases just credential stuff.
Just take from a prior install, a prior data theft and just try a bunch of logins. We're seeing that, uh, I'm looking at a statistic here, but 20% of all login attempts in healthcare, that's one fifth, one fifth of all login attempts in healthcare are brute force or credential stuffing attacks from a t o and they're bad bots. So what we're seeing at an in short, I know this is a long, long, long discussion here, but what we're seeing in short from organizations is them saying, I need you to be able to not just detect my bots and not just do a p i security and application.
I need you to do this all in one thing because it's a, it's a chain of information that I need to have. I need to know first and foremost, is it good or bad bot? Because I'm gonna have both.
Is it a good or bad bot or maybe in hu a human, if it's a bad bot, I don't care what it's trying to do, you're done out now is it application security? Is IT app, you know, API security, break it down the path. And when you have a single stack of technology that can look at that string of data across all of those various data points and be able to say, this doesn't belong here because it's a bad bot, it's not a human, it is an a p i attack, it's a business, a broken object level, you know, uh, uh, resource.
It's, it's some kind of a, a API I attack over here, block it out. You only get that if you can bring all that together in one place and be able to answer that question that way. And so that's, that's a, that's a big, big key piece that customers are coming to us for that reason.
Cuz prior to now they had a WAF and they had maybe some API security or maybe a bot solution, but they don't work together and they need that to all work together to answer that question of what is good and bad. Well, it's, it's the era of point solutions versus I have to be able to look at data and I need to add context and connect the dots, right? To see what's happening.
To really understand, okay, it takes three of those data points to know whether I've got an issue, not just one or, and you can't do it manually, right? I mean, the time it takes, you know, have the resource, the people, et cetera. We're, we live in an automation world of security operations too, not just, uh, business process, uh, other parts of the business.
So, well, fascinating talking with you, Terry. Um, we're, you know, this is a, it's a hot topic. Healthcare is a big, a big area where there's a lot of, uh, a lot of conversations happening and a lot of work being done.
Where, where can folks learn more about what's happening with security and healthcare? So we, we have a webinar coming up. com.
You can certainly go there all the time. Uh, I think you'll have a link, uh, attached to, uh, to uh, this, uh, this webinar here, this, this discussion here. Um, but we have a webinar coming up with a lady named Lisa Gallagher and myself, we'll be chatting about the data security side of this, not specifically the API security side of this, um, with regard to, uh, healthcare and epic systems and some of these sorts of things, um, on June 28th, uh, and this is part of the Health IAC initiative, and we'll have about three of these webinars throughout the year.
This will be the first one of those. Before you jump though, I did wanna say one last thing. We talked about shadow APIs and I just wanted to clarify, you know, when people do recognize that they likely have shadow APIs, certainly in that, that, that, uh, that chain of technologies, one of the things that customers do come to us as well with is find my APIs, give me a real list and really dig into those APIs.
So the discovery is certainly there. I I didn't mention it, but I just wanted to be clear. That's kind of how people frankly begin, right?
Go find all my stuff so I can put my controls on it. That's, that's the security mindset is I need to know what I have to know, what I need to secure, right? So it fits right into that model too, whether it's APIs or devices, you know, or whatever it might be on the network.
That's right. Well, the event on the 26th sounds great and, and having someone, you know, with, uh, that kind of expertise working on projects and, and, uh, healthcare initiatives, I'm, I'm sure that she'll have a lot of insights. So good luck with the webinar and the 28th.
And I will, I'll get ahold of the link and add that to the description of this video so folks can go check that out too. com. Lots of good.
There's a lot of great information there as well. And, uh, download some good stuff and check out some great products. Terry, it's been a pleasure talking with you and, uh, let's have you back.
We'd love to chat some more. Excellent. Thanks for your time, Mitch.
Thank you. You bet.