Klaus Mochalski and Silvia Seeger (Cyber Risk Manager at Relyens) shed light on the specific challenges of cybersecurity in the healthcare sector. Learn why medical technology plays a unique role between IT and OT, and why rigid manufacturer approvals make it difficult to patch legacy devices.
Sound Bites
Silvia Seeger: “I basically see it as three groups [...] first, traditional IT, [...] then I tend to classify building automation as part of industrial engineering [...] and then, as a third group, medical technology.”
Silvia Seeger: “I have a specific configuration; the medical device manufacturer uses this to obtain its approval and bring the product to market, and I’m not allowed to just change anything. That means I’m also not allowed to simply install an antivirus program on a medical device.”
Silvia Seeger: “[...] then the device is integrated, but usually the IT department no longer feels truly responsible[...] and in the end, there’s a major risk that a gap in responsibility will arise—that no one feels responsible—and that things like vulnerability management or patch management [...] don’t take place.”
Silvia Seeger: “Ideally—or to add to that—there’s the so-called industry-specific Hospital B3S security standard, [...] because it incorporates these specific requirements [...] as well as two additional protection goals: patient safety and treatment effectiveness.”
Silvia Seeger: “A standard set of personal data would be worth around $20. But if it’s personal health data, then around $60. So the ratio is roughly one to three [...]”
Silvia Seeger: “Once I’ve done my homework, [...] I’ll certainly still have some residual risk left. [...] And now, for the sake of resilience, I’m transferring that residual risk, because I know it’s no longer a question of whether an attack will hit me, but only a matter of when.”
Chapters
00:00 Introduction to Silvia Seeger and her role in cybersecurity in the healthcare sector
02:21 The complexity of OT, IT, and medical technology in hospitals
05:24 Connectivity and risks associated with medical imaging and devices
06:43 Challenges in the approval and maintenance of medical technology
09:53 Responsibilities and security measures in hospitals
11:07 Standards and best practices for cybersecurity in hospitals
12:32 Regulatory requirements and the role of the Medical Devices Regulation
15:51 Current threat landscape and types of attacks in the healthcare industry
19:25 Measures to improve security in hospitals
24:49 The role of insurers in prevention and emergency management
Keywords
Cybersecurity, Hospitals, Medical Technology, Risk Management, OT Security, Cyber Threats, Medical Devices, Insurance, Digital Health