The Evolving Threat Landscape: A New Dawn in Cybersecurity with Chris Bowen | SecOps Vision 2024
Health care organizations face unique challenges due to the sensitive nature of patient data, the high value of such data to cybercriminals and the critical need for continuous availability and integrity of health information systems. In the increasingly digital world of today, cybersecurity threats have become a pressing concern for both individuals and organizations. The evolving landscape of these threats is characterized by a surge in sophistication and frequency, making them more challenging to detect and counter.
Chris Bowen, ClearDATA’s founder and CISO, shares his viewpoint on the present state of cyberthreats, highlights the notable transformation in digital dangers and offers tangible examples from the real world. Chris discusses emerging technologies in cybersecurity, outline the differences between cybercrime and cyberwarfare and will provide insights into the future trajectory of the industry. Viewers will also gain practical advice on best practices in DevSecOps and shift left to give you actionable strategies to bolster your organization’s cybersecurity efforts. By the end of the session, viewers will not only understand the evolving cyberthreat landscape but have the knowledge and tools to navigate the evolving landscape of cybersecurity and safeguard their organizations against these threats.
Transcript
Hi, everybody. My name is Chris Bowen. I am the founder and the Chief Information Security Officer at ClearDATA.
ClearDATA maintains continuous security and compliance for full visibility, protection, and enforcement of security and compliance measures in the public cloud. That is a mouthful, I understand. But we're gonna get into some of that.
We're gonna talk about what the threat landscape looks like, how we're looking in, in defending against attacks in healthcare. So let's get right to it. All right, let's talk about why people, why bad guys target healthcare.
What I'm seeing, what we're seeing at Clear data is that healthcare seems to be expanding its threat services. It's, it's a attack surface. The, the blast radius, if you will, if you think about data liquidity, if you think about, uh, one visit to a doctor and your data goes to over a hundred different places, you're starting to see just how, how your data is just all over the place, and it's just a ripe target for, uh, for, for bad guys, for threats.
We're also seeing an increasing quantity of assets. Now, when I talk about assets, we're talking about medical devices. We're talking about systems in hospitals.
Uh, it could even be a kiosk. I remember one, uh, breach occurred with a food vendor within a, a cafeteria at a hospital that caused a, a great big data breach. So lots of different things are going into the healthcare system to try to make the lives better of those who are being treated or those who are serving in healthcare, we're seeing difficulty with onboarding.
If you recall, during c Ovid 19, this was especially in a, a, an important issue where doctors would come in to try to help someone within a different hospital system, and they would have difficulty understanding what systems needed to be, uh, operated in a specific way. Training was a, a tough one. So as we start to see, uh, additional onboarding actions happen within healthcare, uh, the training needs just aren't, aren't keeping up.
Uh, you can also think about that from a, a security awareness perspective. Uh, this is one of those requirements by the HIPAA security rule, which is you shall train your workforce to make sure that they're aware of some of these threats or of the, any threat that could take down a hospital system. We could go on and on about that.
Let's move on to some employee errors and manual requirements. When a employee makes an error, sometimes that can show its ugly head down the road when someone comes in to have a, a treatment or, or some kind of a, uh, an operation or something like that. Um, healthcare's costly just to get an X-ray machine is, is lots and lots and lots of money.
Um, and then I think one of the most important challenges that we have is that by 2025 globally, we're projected to see a huge number of unfilled cybersecurity jobs just because there's not the cybersecurity talent throughout the world to accomplish what needs to happen. So the average healthcare data breach is around 10 million bucks. Um, practice your practice, your breach simulations, make sure that you're prepared if you ever have some attack that that could threaten your landscape if you'll, so we see this a lot.
We see data breaches happen a lot. There's just, I think everybody in America has been been breached, uh, from a numerical perspective multiple times. Our data's out there.
It's been, it's been attacked, it's been used nefariously. Um, there's just so many breaches that, that it's hard to keep up. What we wanna try to do is bring that down to the patient level, make it a human issue that's actually happening.
Uh, what we're seeing is that ransomware attacks now impact human life. We were just talking about this in some of our meetings last week in Austin, and one of the things that we know is that if a hospital goes down, not only does that hospital, uh, have to divert traffic, have to divert ambulances and patients, but there may be spillover hospitals in the region that also have to accommodate and, and, and pull in some of those redirected ambulances. What that does is puts a an incredible strain on the healthcare system, and we've actually seen multiple instances where patients will actually pass away because of the fact that a ransomware attack has occurred.
It's disgusting. It makes me angry. It makes me want to, uh, continue to, uh, go hunting for these threats to try to obliterate them if we can.
All right, so there's cyber crime. There's cyber warfare. I don't, I think the, the end result is similar.
I think what we're seeing now is that nation states are, uh, funding cyber criminals. They're actually creating tools to hack, uh, US healthcare and healthcare abroad and Europe and other areas. So in, in cyber crime, uh, calm if you will, you'll have, uh, motives for, for money.
And this is usually the, the case with, with any kind of cyber crime. But the motive is, is either a group of illegal, um, uh, cyber criminals or individuals. Uh, they'll try to do some phishing.
They'll try to attack you where it's easiest. Uh, they will try to use your information for identity theft, et cetera. In cyber warfare, what we're seeing is that, uh, nation states are funding operations.
Uh, China happens to be one of the, the larger, uh, culprits of, of cyber warfare. They're also going after us from an espionage perspective, propaganda campaigns as, as well. You can start to see some of the Middle East issues, and you can also see critical infrastructure attacks where they're actually trying to weaken, um, not only healthcare, but, but power grids and water supplies and things like that as well.
So knowing who to blame and cyber security and, and understanding who is the attacker is becoming increasingly difficult. And so what we're having to do is we're, we're trying to identify where they are, how we can block them. One of the things that ClearDATA does is it has a contributory network of healthcare customers, hundreds of them.
And so when we see something that is, uh, potentially going to harm one health system, we actually deploy safeguards and countermeasures, uh, across our entire fleet of customer systems so that, uh, everybody is covered. Everybody is protected. To do this effectively, we have to go hunting.
We have to go hunting on a, on a regular basis, on a daily basis for, uh, looking for, uh, indicators of compromise, looking for areas where, uh, a compromise can actually be exploited or, uh, the vulnerability could be exploited. And so we're trying to figure out and understand these types of, uh, blurred lines, if you will, on a, on a regular basis. It's a challenge.
And, you know, my heart goes out to all of you who are in that fight in the trenches trying to attribute what's going on and, and how to block it, how to defend yourselves. This is where DevSecOps comes in. I think DevSecOps is a, is a wonderful thing.
This looks a bit daunting if you think about it, but if you, if you really get into it before you deploy a cloud, a piece of cloud infrastructure, an asset, if you will, a service in the cloud, uh, one of the things you should really think about doing is, is planning your safeguards in advance of deploying the, the service or the, the asset, if you will. That includes, um, purpose building your infrastructure. Uh, if you're in healthcare, you need to actually think about the alignment to security safeguards with the security rule, the HIPAA security rule.
And in our case, we do it with high trusts. We'll identify what needs to be audited, how, how we log certain things, align those to policies. Um, and then of course, uh, we'll make sure that the code is scanned and everything is, there's no vulnerabilities deployed with, uh, with a, a cloud formation template or a Terraform template or something like that.
And then, we'll, we'll test as we go. So this is a, is a great representation of, of Dev DevSecOps and how you should incorporate your threat intelligence and your operations within this. ClearDATA, uh, has just released a, a new offering, which is managed, uh, detection and response.
And it's, uh, it's, it's one of those things that, uh, that we're hopeful that others, uh, take advantage of. So there's some emerging technologies in cybersecurity that we're, we're gonna kind of go into a little bit. Artificial intelligence is a big deal right now.
Uh, we're excited about it. We're helping our customers leverage it in a way that keeps them safe, keeps them from having, uh, infras data leave the infrastructure or the environment. There are areas like blockchain technology, maybe not as widely used in healthcare as in other areas, uh, simply because the, the blockchain is a little bit more public than patients sometimes, like, but we're also seeing advances in secure data sharing.
Uh, threat hunting has become, uh, a very important part of our toolbox, if you will. Threat hunting has also leveraged ai, artificial intelligence to help us identify where the threats are and how we can put the countermeasures in place before we are attacked. So an active defense strategy, I would call it a a a, an offense is a great defense, if you will.
Uh, I know others in the world. Australia, for example, has a very active, uh, threat hunting program where they've actually said they're scouring the, the globe for cyber criminals to take them down. And I applaud that, and I've continued to advocate for that in the US as well.
And I know that some of our law enforcement are, are doing that to some degree. So what happens if you do have a breach? It's a lot more expensive than having, if you had prevented a breach.
If you'll, in this slide one, one of the things that we did was take a look at what was, what was the, the big issue with a related breach. Uh, so you see here, a, a risk matrix. You see the likelihood of a, of a possible issue that might've been part of a breach.
You see the impact as well. And understanding of course, that on the top right is the most impact that you could have, uh, at least on this grid. So again, levels of risk vary per breach.
One of the things that we've seen in our analysis is that misconfiguration, it's not a surprise. Misconfiguration and human error are the top threat to, to a cloud system. It's a top threat to any system really.
If you have humans that are interacting with, uh, a service or configuration, usually that's, uh, an issue We're seeing we and stolen passwords. It's amazing how many people will use a password that is very weak in some cases. Um, you'll see passwords written on walls in hospitals.
Literally, I've seen this before. Um, most of the time you'll see, uh, a well-meaning person at the front desk storing a password under a mouse pad. Please, if you, if you ever go into a hospital, make sure that you, you say, Hey, please change your password if you, if you have it under your pass, under your mouse pad.
But we're seeing some amazing, uh, amazing strategies to hide passwords so that people can easily get them. There's some great tools out there to use. We're seeing patch failures.
Uh, we're seeing end of life, uh, windows 2012 on October 10th just went end of life. And so if you're not working on a, a path to migrate all of your older servers off of, off of that into a newer version, then you need to get working on that. Social engineering healthcare's, especially weak when it comes to social engineering.
One of the primary reasons is because people in healthcare like to help people. And so bad people, bad guys will take advantage of that and try to socially engineer those in healthcare. There's others, excessive permissions, all of that.
What I wanna show you in this next slide though, is I'm, I'm gonna give you the, the dollar amounts of certain breaches that have occurred because of these specific things. So if you look at, if you look at the money, you'll see on the top right that, again, I'll come back just for one second. IAM failures, that's identity and access management.
3 million because of a data breach caused by IM failures. 1 million. So you can, you can ascribe a dollar amount to most of these major issues.
We've never seen the OCR fine for any of these down here. Um, but that doesn't mean that they're not looking for it as well moving forward. Uh, these, if, if anybody's a regulatory junkie on the code of federal regulations, here's where the, the heat map is from a regulatory perspective, again, major areas of focus include no risk analysis.
You'll get a, you'll get a big fine if you have a breach and you don't have a risk analysis, make sure that you do that. Um, failure to safe safeguard. PHI is a big one.
Email is a, is one that infuriates me. When people send PHI through email systems only to then have those email systems compromised or accidentally emailed a spreadsheet full of PHI to somebody outside your system or outside of your authorization. All kinds of issues there.
So how do we mitigate some of these risks or these threats? Well, we have, uh, a couple of ways that we do that. Number one, we have to implement comprehensive cybersecurity measures.
For us, what that means is we leverage the HITRUST framework, the, the common Security Framework. Now, that doesn't mean that's all we do, but HITRUST has a very prescriptive set of controls. We have about 575 at this point in time, and those are very specific.
And they cover everything from, uh, cryptography to human resources, to, um, resiliency, all of the things that you can imagine. It's a, it's a comprehensive program. Uh, the other thing we have to do is we have to invest in the right cybersecurity technology and the teams.
Uh, we have to understand what kind of heuristics are happening in the environments. That means, uh, using some older tools may give you a little bit of peace of mind, but they not, may not be, uh, appropriate for the use. Uh, for example, if we're monitoring thousands of, of cloud services, we have to have, uh, a sim of of incident and event management system that allows for us to see comprehensively across the fleet.
Regular training, regular employee education programs. Those kinds of things are very, very important as well. So looking ahead, what we wanna try to do is we wanna try to understand in healthcare what the nature of these attacks are, if we can learn from these things.
And again, one of the things that NIST does is a great job of is, um, going through and walking through a incident process. One of the important parts of that is the lessons learned. Understanding what caused the issue, what caused the incident, and allowing you to learn and make sure that you address the things that, that were weak that may have caused the incident itself.
Again, comprehensive employee training. Implement, uh, effective strategies for prevention of incidents. It's always better to prevent than to respond and try to fix afterwards.
And then think about, uh, strengthening your, your relationships with cybersecurity firms. That includes penetration testing firms, that includes, um, software companies that will help you see and understand what's happening in your environments, those kinds of things. So with that, I appreciate the time.
I hope that this was a bit valuable to you and that you, um, certainly can look this up and, and refer to it often. Uh, I appreciate it and I hope all of you stay safe out there. And remember, it's always best to prevent rather than to, uh, fix afterwards.
Thank you very much.





