Healthcare 2022: Almost 60 percent affected by ransomware

Healthcare 2022: Almost 60 percent affected by ransomware

Share post

As an interesting global study by Trend Micro shows, almost 60 percent of the healthcare companies surveyed were affected by ransomware in 2022. A quarter of all affected healthcare facilities have to stop operations. The supply chains were the main source of risk.

According to the study by the Japanese security provider, well over half (57 percent) of the healthcare companies surveyed admitted to having been compromised by ransomware in the last three years. 25 percent of the victims also stated that their operations had come to a complete standstill. Another 60 percent experienced an impairment in their business processes. On average, it took most organizations days (56 percent) or weeks (24 percent) to fully restore operations. Ransomware is not only causing significant operational problems in the healthcare sector, but is considered one of the top cyber risks in other industries as well.

weeks until operations were up and running again

For around 60 percent of those surveyed, sensitive data fell into the wrong hands as a result of the attack. This poses an increased compliance risk and can damage the company's reputation. It also increases the cost of investigating, containing, and cleaning up the incident.

The participants in the study named vulnerabilities in the supply chain as one of the biggest challenges. The following areas are particularly relevant:

  • 43 percent believe their partners have made them a more attractive target.
  • 43 percent also say a lack of visibility into the entire ransomware attack chain has made them more vulnerable.
  • 36 percent cite a lack of visibility into their attack surface as another reason that has made them more of a target for attacks.

The good news is that a majority of healthcare organizations (95 percent) regularly update patches, especially for systems that are visible to the outside world, while an almost as large proportion (91 percent) restrict email attachments, thereby reducing the risk of malware. Many of the companies surveyed also use tools for Network (NDR), Endpoint (EDR) or Extended Detection and Response (XDR).

Healthcare study: Other potential vulnerabilities

  • A fifth (17 percent) have no remote desktop protocol (RDP) controls at all.
  • Many organizations don't share threat intelligence with partners (30 percent), suppliers (46 percent), or their broader ecosystem (46 percent).
  • A third (33 percent) do not share information with law enforcement.
  • Only half or fewer of the companies surveyed currently use NDR (51 percent), EDR (50 percent), or XDR (43 percent).
  • Worryingly few healthcare companies are able to detect lateral movement (32 percent), first access (42 percent) or the use of tools like Mimikatz and PsExec (46 percent).

🔎 Supply chains were the main source of risk (Image: Trend Micro).

“Cyber ​​criminals specifically target healthcare facilities that appear to have a weak link in their defense chain. The great pressure that is currently weighing on companies and institutions in the industry, as well as often low IT security budgets that are disproportionate to the importance of the systems, make them easy victims of attacks," says Richard Werner, Business Consultant at Trend Micro. "This makes the healthcare industry one of the top 3 most attacked industries worldwide."

It should also be pointed out at this point that the Federal Government has also been supporting investments in IT security since January 2021 as part of the Hospital Future Act (KHZG).

About the Study

Trend Micro commissioned Sapio Research to survey 2022 IT decision makers in 2.958 countries, including the UK, France, Germany and the US, in May and June 26. The study "Everything is connected: Uncovering the ransomware threat from global supply chains" is available to read online.

More at TrendMicro.com

 


About Trend Micro

As one of the world's leading providers of IT security, Trend Micro helps create a secure world for digital data exchange. With over 30 years of security expertise, global threat research, and constant innovation, Trend Micro offers protection for businesses, government agencies, and consumers. Thanks to our XGen™ security strategy, our solutions benefit from a cross-generational combination of defense techniques optimized for leading-edge environments. Networked threat information enables better and faster protection. Optimized for cloud workloads, endpoints, email, the IIoT and networks, our connected solutions provide centralized visibility across the entire enterprise for faster threat detection and response.


 

Matching articles on the topic

IT security: NIS-2 makes it a top priority

Only in a quarter of German companies do management take responsibility for IT security. Especially in smaller companies ➡ Read more

Cyber ​​attacks increase by 104 percent in 2023

A cybersecurity company has taken a look at last year's threat landscape. The results provide crucial insights into ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Mobile spyware poses a threat to businesses

More and more people are using mobile devices both in everyday life and in companies. This also reduces the risk of “mobile ➡ Read more

Crowdsourced security pinpoints many vulnerabilities

Crowdsourced security has increased significantly in the last year. In the public sector, 151 percent more vulnerabilities were reported than in the previous year. ➡ Read more

AI on Enterprise Storage fights ransomware in real time

NetApp is one of the first to integrate artificial intelligence (AI) and machine learning (ML) directly into primary storage to combat ransomware ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more