NNews-Spring-2022

24 M any healthcare companies wonder how can they de-risk or mitigate cyber threats. It is an important question and certainly one that needs to be addressed given the high-risk nature of healthcare as a profession. Healthcare provid- ers are keepers of valuable and very lucrative information which, in the wrong hands, could be destructive for clinics and/or for their cli- ents. Therefore, the risk vs. reward calcula- tion a cybercriminal would perform would often lead to the conclusion that a minimally protected clinic is a perfect target. The data also supports it. According to Check Point Research (CPR), from mid-2020 throughout 2021, there has been an upwards trend in the number of cyber-attacks. This trend reached an all-time high at the end of the year, peak- ing to 925 cyber- attacks a week per organiza- tion, globally. In 2021, the healthcare sector experienced a high volume of attacks, with an average of 830 attacks per organization every week. This was a 71% increase from 2020. In other articles, we cover cyber threat man- agement, but this seems like the right place to reframe the discussion. The risk is not a “cyber risk”. It is rather a business risk that exists because of cyber threats. The under- standing that this is a business risk allows us to leverage and apply various risk-manage- ment frameworks to manage cyber threats specific to a given firm. So, which business risks could emerge post-breach? Reputational Damage – Cyber attacks come in various shapes and co- lours, but all share a similar goal of stealing valuable information and/or hindering your ability to operate. While the attack type may vary, the consequences in this respect will not. Existing clients and prospects could lose trust in your organization and its ability to be a confidant and keeper of sensitive informa- tion. Moreover, the breach ramifications could spill over and impact your credibility and reputation as a healthcare professional. Privileged Client Information Leakage – A healthcare provider’s work also involves managing confidential client informa- tion. Clinics and practitioners are privy to the most sensitive of information such as health issues, mental state, financials, intellectual properties, commercial details, material risks, and so forth. A practice that experiences a cyber-attack that results in privileged client information leakage might experience multiple consequences such as clients’ departure, litigation actions, regula- tors’ examinations, fines, punitive measures, and more. Financial Damage to the Firm/Firm’s Clients There are multiple types of cyber-attacks that are financially oriented. The attacker will take over part of the payment process and will fraudulently route clients’ or the firms’ funds to ravage bank accounts. The level of sophistication is so high today that most of the time, those funds are virtually not recoverable. This is especially noticeable in small- to medium-sized organizations, mainly because firms usually invest less in protecting themselves against cybercrime or lack the knowledge to properly analyze and address the risks. Compromised Communication Channels – Secured communication channels are a key enabler to allow normal business conduct for any health practitioner today. Unfor- tunately, we often see poor cyber hygiene and awareness, which result in communi- cation channels (voice, data, applications on desktop and mobile devices) used by Cyber-Attacks Pose Business Risks and By: Amit Kaminer, Vice President, Marketing, Armour Cybersecurity

RkJQdWJsaXNoZXIy OTU2NTU4