<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>firewall Archives - InnoHEALTH magazine</title>
	<atom:link href="https://innohealthmagazine.com/tag/firewall/feed/" rel="self" type="application/rss+xml" />
	<link>https://ztt.nrm.mybluehostin.me/innohealthmagazinetag/firewall/</link>
	<description>India&#039;s first magazine on healthcare innovations</description>
	<lastBuildDate>Thu, 27 Jun 2019 07:27:18 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://innohealthmagazine.com/wp-content/uploads/2017/11/innohealthmagazine-favicon.png</url>
	<title>firewall Archives - InnoHEALTH magazine</title>
	<link>https://ztt.nrm.mybluehostin.me/innohealthmagazinetag/firewall/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">139068796</site>	<item>
		<title>Cybersecurity Business Evangelist</title>
		<link>https://innohealthmagazine.com/2019/in-focus/theme/cybersecurity-business-evangelist/</link>
					<comments>https://innohealthmagazine.com/2019/in-focus/theme/cybersecurity-business-evangelist/#respond</comments>
		
		<dc:creator><![CDATA[InnoHEALTH Magazine]]></dc:creator>
		<pubDate>Thu, 27 Jun 2019 07:27:18 +0000</pubDate>
				<category><![CDATA[Theme]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[business evangelist]]></category>
		<category><![CDATA[cloud threats]]></category>
		<category><![CDATA[cyber threat]]></category>
		<category><![CDATA[cyber threat protection]]></category>
		<category><![CDATA[cyber vulnerabilities]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[Data collection]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[healthcare data]]></category>
		<category><![CDATA[healthcare data breach]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[malware attack]]></category>
		<category><![CDATA[medial device]]></category>
		<category><![CDATA[network access]]></category>
		<category><![CDATA[operating system]]></category>
		<category><![CDATA[patient data]]></category>
		<category><![CDATA[Personal health information]]></category>
		<category><![CDATA[personal indentifiable information]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[phishing attack]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[social security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[WannaCry]]></category>
		<guid isPermaLink="false">https://ztt.nrm.mybluehostin.me/innohealthmagazine?p=6227</guid>

					<description><![CDATA[<p>Healthcare data breaches have risen nearly every year from 2010 through 2019 and the cybersecurity risks jeopardize hundreds of millions of patients records.</p>
<p>The post <a href="https://innohealthmagazine.com/2019/in-focus/theme/cybersecurity-business-evangelist/">Cybersecurity Business Evangelist</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[
		<div id="fws_69f37e3b5b90b"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row top-level"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><a href="https://innohealthmagazine.cominnovatiocuris/disha-act/">Healthcare data breaches</a> have risen nearly every year from 2010 through 2019 and the cybersecurity risks jeopardize hundreds of millions of patients records. Although physical theft used to be the data breach method of choice, now hacking has become the most prevalent method. This partly stems from more information being stored electronically and network servers becoming a more attractive hacking target.</p>
<p style="text-align: justify !important;">However, much like the rest of the world, healthcare organizations are shifting work to cloud services in order to improve accessibility and patient care. The migration of these workloads and moving valuable information such as PHI (personal health information) and PII (personally identifiable information) to the cloud has also led to cyber criminals taking a particular interest in the industry. Having shifted workloads to the cloud, healthcare organizations have highly connected systems that run the risk of being deeply affected even if the attack takes place on smaller,partial systems. In other words, a <a href="https://innohealthmagazine.comcybersecurity/the-vulnerability-of-medical-institutions-to-cyber-attacks/">cyber attack</a> in one place could bring down the entire system. In May2017, the <a href="https://innohealthmagazine.comissues/ransomware-epidemic/">WannaCry ransomware</a> attack forced multiple hospitals across the United Kingdom to turn away ambulances transporting patients and cancel surgeries that were within minutes of starting. Even basic processes like admitting patients and printing wrist bands were compromised.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3b6bbd5"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;">The number of <a href="https://www.akamai.com/us/en/resources/what-is-ransomware.jsp?gclid=EAIaIQobChMIjbe_nYuJ4wIVQ5SPCh0vogWXEAAYASAAEgIsu_D_BwE&amp;ef_id=EAIaIQobChMIjbe_nYuJ4wIVQ5SPCh0vogWXEAAYASAAEgIsu_D_BwE:G:s&amp;utm_source=google&amp;utm_medium=cpc">ransomware</a> and other malware attacks is rising incredibly fast in the healthcare industry, putting human lives as well as critical data at risk.One of the key aspects making healthcare organizations a top target is the value of their data. Commonly, a single stolen credit card number yields an average $2,000 profit and quickly becomes worthless. Healthcare data, however, such as PHI or PII, is extremely valuable on the black market.</p>
<p style="text-align: justify !important;">A single PHI file, for example, can yield a profit of up to $20,000. This is mainly because it can take weeks or months for a healthcare data breach to be discovered, enabling cyber criminals to extract much more valuable data. Moreover, because healthcare data can contain dates of birth and Social Security numbers, it is much more difficult or even impossible to change, so thieves can take advantage of it fora longer period of time.</p>
<p style="text-align: justify !important;"><img fetchpriority="high" decoding="async" class="size-full wp-image-6236 aligncenter" src="https://innohealthmagazine.comwp-content/uploads/2019/06/cyber-security-business-evangelist-2.png" alt="cyber security business evangelist 2" width="570" height="369" srcset="https://innohealthmagazine.com/wp-content/uploads/2019/06/cyber-security-business-evangelist-2.png 570w, https://innohealthmagazine.com/wp-content/uploads/2019/06/cyber-security-business-evangelist-2-300x194.png 300w" sizes="(max-width: 570px) 100vw, 570px" /></p>
<p style="text-align: justify !important;">Data breaches cost the healthcare industry approximately $5.6 billion every year, according to Becker’s Hospital Review. The Breach Barometer Report: Year in Review additionally found that there was an average of at least one health data breach per day in 2016, attacks that affected more than 27 million patient records.</p>
<p style="text-align: justify !important;">The continued under investment in cybersecurity has left many so exposed that they are unable to even detect cyber attacks when they occur. While attackers may compromise an organization within a matter of seconds or minutes, it often takes many more weeks – if not months – before the breach is detected, damage is contained and defensive resources are deployed to prevent the same attack from happening again.</p>
<p style="text-align: justify !important;">As organizations seek to protect their patient information from these growing threats, demand for health informatics professionals who are familiar with the current state of cybersecurity in healthcare is on the rise.</p>
</div>



<div class="img-with-aniamtion-wrap center" data-max-width="100%" data-max-width-mobile="100%" data-shadow="none" data-animation="fade-in" >
      <div class="inner">
        <div class="hover-wrap"> 
          <div class="hover-wrap-inner">
            <img decoding="async" class="img-with-animation skip-lazy" data-delay="0" height="312" width="572" data-animation="fade-in" src="https://innohealthmagazine.com/wp-content/uploads/2019/06/cyber-security-business-evangelist-1.png" alt="cyber security business evangelist 1" srcset="https://innohealthmagazine.com/wp-content/uploads/2019/06/cyber-security-business-evangelist-1.png 572w, https://innohealthmagazine.com/wp-content/uploads/2019/06/cyber-security-business-evangelist-1-300x164.png 300w" sizes="(max-width: 572px) 100vw, 572px" />
          </div>
        </div>
        
      </div>
    </div>
			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3b78592"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p>“So, What is Wrong With the Picture?”</p>
<p style="text-align: justify !important;">The base question to ask is “Who would be interested in hacking patient data?” It is precisely this attitude together with the rat eat which healthcare refreshes its technology that exposes healthcare organizations to a high risk of cyber-attack. The fact that makes the industry appealing to hackers: ransom for money;denial of service for malice and money; stealing confidential data;compromising data; identity theft and compromising devices. The scale of disruption and impact to busy healthcare settings already operating at capacity caused by a cyber-attack needs no explanation. The reality covers the four main domains:</p>
<ul>
<li>Leadership: Ownership of the issue</li>
<li>Culture/Staff responsibility/awareness: Training and awareness of cybersecurity and its related implications</li>
<li>Policies and procedures: Understanding of business continuity processes and incident response procedures</li>
<li>General cybersecurity knowledge: Use of fundamental security processes that are currently followed within the organization to mitigate security breaches, e.g., use of USB, on- and off-boarding processes, password policies,organizational asset register,and so on.</li>
</ul>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3b78abe"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>The Challenges</strong><br />
The newest cyber vulnerabilities are not necessarily an organization’s biggest cyber threat. Consequently, many common threats continue to be problematic in healthcare, including:</p>
<ul>
<li><strong><em>Malware and ransomware:</em></strong> Cyber criminals use malware and ransomware to shut down individual devices, servers or even entire networks. In some cases, a ransom is then demanded to rectify the encryption.</li>
<li><strong><em>Cloud threats:</em></strong> An increasing amount of protected health information is being stored on the cloud. Without proper encryption, this can be a weak spot for the security of healthcare organizations.</li>
<li><strong><em>Misleading websites:</em></strong> Clever cyber criminals have created websites with addresses that are similar to reputable sites. Some simply substitute .com for .gov, giving the unwary user the illusion that the websites are the same.</li>
<li><strong><em>Phishing attacks:</em></strong> This strategy sends out mass amounts of emails from seemingly reputable sources to obtain sensitive information from the users.</li>
<li><strong><em>Encryption blind spots:</em></strong> While encryption is critical for protecting the health data, it can also create blind spots where hackers can hide from the tools meant to detect breaches.</li>
<li><strong><em>Employee error:</em></strong> Employees can leave healthcare organizations susceptible to attack through weak passwords, unencrypted devices and other failures of compliance.</li>
</ul>
<p>Another growing threat in healthcare security is found in medical devices. As pacemakers and other equipment become connected to the internet, they face the same vulnerabilities as other computer systems.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3b78f5d"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>How are Hackers Achieving this, You Would Ask?</strong></p>
<p style="text-align: justify !important;">Hackers usually access information in one of two ways. They can try‘social hacking’, which means tricking a human being into giving oversensitive information or security credentials which in turn allows access to sensitive information. This could happen by tricking either someone who works directly for the provider, or an outside contractor. An unsophisticated example could be, ‘Hi, I am an IT provider for your company, and I need to carry out some maintenance, could you please provide these sensitive details for me?’. The second way is brute force:directly attacking a security system.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3b89622"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>Once Hackers Get Access to The Data, What Do They Do with It?</strong></p>
<p style="text-align: justify !important;">In some cases, hackers access sensitive data, extract it, and lock it off. They can then sell it back to the company. If the company does not have backups, buying it back is probably the only viable option. The alternative is for them to lose all records of their patients which they will never be able to replace.Another possibility, is hackers stealing data and selling it to the public. The information may be sold to criminal groups on the dark web who wish to use sensitive information for blackmail or fraud purposes.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3b8becc"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>What Can the Healthcare Industry Do to Mitigate Cyber Threats?</strong></p>
<p style="text-align: justify !important;">The industry must realize that cybersecurity is human-centric. Gaining insight into the users&#8217; behavior, for example, or the flow of data in and out of the organization improves risk response.</p>
<p style="text-align: justify !important;">Additionally, the industry should be aware that cybersecurity isn&#8217;t just the responsibility of the IT department: everyone should be aware of the risks, from management down to brand-new contract staff.</p>
<p style="text-align: justify !important;">Healthcare security professionals need to understand the threats they face and the regulations they must comply with, and they must be provided with best practices for strengthening cybersecurity defenses. This means implementing comprehensive security awareness training that educates all people on current threats, red flags to look for in an email message or web link, how to avoid infection, and what to do in case of an active exploit. And since the threat landscape is constantly changing, training should be repeated and updated regularly.</p>
<p style="text-align: justify !important;">Furthermore, implementing the right cybersecurity measures, such data loss prevention, user behavior analytics, and endpoint security technologies, will further protect an organization&#8217;s infrastructure and patient data from ransomware attacks. By creating a system that guards the human point — where people interact with critical business data and intellectual property — and takes into account the intersection of users, data, and networks, the healthcare industry can improve its cyber threat protection.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3b8c378"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>In Simple Terms: How Do We Improve Cybersecurity?</strong></p>
<p style="text-align: justify !important;">Due to the significant financial impact of data breaches in healthcare, health informatics and other professionals need to play an important role in ensuring that medical organizations remain secure. Individual healthcare organizations can improve their cybersecurity by implementing the following practices:</p>
<ul>
<li><strong>Establish a security culture:</strong> Ongoing cybersecurity training and education emphasize that every member of the organization is responsible for protecting patient data, creating a culture of security.</li>
<li><strong>Protect mobile devices:</strong> An increasing number of health care providers are using mobile devices at work. Encryption and other protective measures are critical to ensure that any information on these devices is secure.</li>
<li><strong>Maintain good computer habits:</strong> New employee on boarding should include training on best practices for computer use, including software and operating system maintenance.</li>
<li><strong>Use a firewall:</strong> Anything connected to the internet should have a firewall.</li>
<li><strong>Install and maintain anti-virus software:</strong> Simply installing anti-virus software is not enough. Continuous updates are essential for ensuring health care systems receive the best possible protection at any given time.</li>
<li><strong>Plan for the unexpected:</strong> Files should be backed up regularly for quick and easy data restoration. Organizations must consider storing this backed-up information away from the main system if possible.</li>
<li><strong>Control access to protected health information:</strong> Access to protected information should be granted to only those who need to view or use the data.</li>
<li><strong>Use strong passwords and change them regularly:</strong> The Verizon report found that 63 percent of confirmed data breaches involved taking advantage of passwords that were the default, weak or stolen. Healthcare employees should not only use strong passwords, but ensure they are changed regularly.</li>
<li><strong>Limit network access:</strong> Any software, applications and other additions to existing systems should not be installed by staff without prior consent from the proper organizational authorities.</li>
<li><strong>Control physical access:</strong> Data can also be breached when physical devices are stolen. Computers and other electronics that contain protected information should be kept in locked rooms in secure areas.</li>
</ul>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3b8c816"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>How to Defend Against the Growing Threat?</strong><br />
Deterrence, prevention, detection and response all have their place.</p>
<p style="text-align: justify !important;">Prevention is preferable to detection and reaction. But without data collection, an organization cannot successfully detect or react to anything.</p>
<p style="text-align: justify !important;">Alerts or alarms should be designed to detect event sequences with potentially negative consequences. Statistical and anomaly detection methods are particularly good for these purposes, as are rule-based detection mechanisms.</p>
<p style="text-align: justify !important;">Security information and event management or log management tools can augment data collection efforts.</p>
<p style="text-align: justify !important;">In addition to deploying technology tools to help defend against and detect intrusions, it&#8217;s important to formally define roles and responsibilities for incident response. Organizations need to document procedures that specify what the response team should do if there&#8217;s an incident and test those procedures periodically.</p>
<p style="text-align: justify !important;">It&#8217;s not just one technology, it is multiple technologies in order to repel these highly sophisticated and organized attacks. That includes deploying SIEM, as well as multi factor authentication to enter critical systems.</p>
<p style="text-align: justify !important;">The Internet is increasingly a swamp. It&#8217;s no longer sufficient to just look at standard security logs. You need integrated security information event management that brings together network logs, users log, application logs and server logs, and looks for non obvious associations.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3b96913"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>In Conclusion</strong></p>
<p style="text-align: justify !important;">To improve cybersecurity in health care, organizations need to hire informatics professionals who not only collect, manage and leverage data, but protect it as well. In addition, health data professionals need to on a continuous basis develop new strategies and best practices to ensure the safety of sensitive health data, protecting both the patient and organization from financial loss and other forms of harm.We know that reaching 100% security against cyber attacks is not realistic but, with a few steps, healthcare organizations can make sure that it&#8217;s too complex or unprofitable for threat actors to attack them, which will result in them moving on to another target.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3b96d78"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<h2>About the author</h2>
<p style="text-align: justify !important;"><em><strong>Kris Seeburn</strong> is an enterprise trainer and a member of Advisory Board of The New Security Foundation, Member of The American College of Forensic Examiners &amp; Institute of Forensics Science</em></p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
<p>The post <a href="https://innohealthmagazine.com/2019/in-focus/theme/cybersecurity-business-evangelist/">Cybersecurity Business Evangelist</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://innohealthmagazine.com/2019/in-focus/theme/cybersecurity-business-evangelist/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">6227</post-id>	</item>
		<item>
		<title>Cybercrime and Threats in 2019</title>
		<link>https://innohealthmagazine.com/2019/persona/exclusive-interview/cybercrime-and-threats-in-2019/</link>
					<comments>https://innohealthmagazine.com/2019/persona/exclusive-interview/cybercrime-and-threats-in-2019/#respond</comments>
		
		<dc:creator><![CDATA[InnoHEALTH Magazine]]></dc:creator>
		<pubDate>Thu, 23 May 2019 09:45:17 +0000</pubDate>
				<category><![CDATA[Exclusive Interview]]></category>
		<category><![CDATA[Persona]]></category>
		<category><![CDATA[access point]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[Artificial Intelligence]]></category>
		<category><![CDATA[biometric hacking]]></category>
		<category><![CDATA[Bitcoin]]></category>
		<category><![CDATA[black hat hacker]]></category>
		<category><![CDATA[blockchain]]></category>
		<category><![CDATA[Bot]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Chatbot]]></category>
		<category><![CDATA[clinical data]]></category>
		<category><![CDATA[crypto]]></category>
		<category><![CDATA[cryptocurrency]]></category>
		<category><![CDATA[cyber criminal]]></category>
		<category><![CDATA[cyber threat]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Evil twin]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[Hacker]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[injection attack]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[Internet of Things]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[IP address]]></category>
		<category><![CDATA[IP camera]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT Act 2000]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[refrigerator]]></category>
		<category><![CDATA[smart gadgets]]></category>
		<category><![CDATA[Smartphone]]></category>
		<category><![CDATA[Social media]]></category>
		<category><![CDATA[tabletheater]]></category>
		<category><![CDATA[white hat hacker]]></category>
		<guid isPermaLink="false">https://ztt.nrm.mybluehostin.me/innohealthmagazine?p=5917</guid>

					<description><![CDATA[<p>Exclusive Interview: Karnal Singh, the Former Director of Enforcement Directorate opens up his opinion on trends of cybercrime and threats in 2019.</p>
<p>The post <a href="https://innohealthmagazine.com/2019/persona/exclusive-interview/cybercrime-and-threats-in-2019/">Cybercrime and Threats in 2019</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[
		<div id="fws_69f37e3bc03e2"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>Karnal Singh</strong>, <em>the Former Director of Enforcement Directorate</em> opens up with the <strong>Sachin Gaur</strong>, <em>Executive Editor, InnoHEALTH Magazine</em> about his opinion on trends of cybercrime and threats in 2019.</p>
<p style="text-align: justify !important;"><em>He is a 1984 batch IPS officer and Engineer from Delhi College of Engineering (DCE) and Indian Institute of Technology (IIT), has over 34 years of experience in the investigation of corruption, terrorism, money laundering, and cyber-crime cases. He is a recipient of President’s medal for distinguished service and Police medal for meritorious service.</em></p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3bc0858"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>Q. Given your important assignments for the Government of India in the past, share with us the big picture. What are the trends you see in terms of cybercrime and threats for 2019?</strong></p>
<p style="text-align: justify !important;">The world is getting more connected and technology has seeped into every aspect of our lives. On one hand, these advancements make our lives easier and on the other bring a lot of vulnerabilities with them if security isn’t strong enough to tackle cyber criminals. Hackers today are well-educated and have the capabilities to develop new methods and tools to exploit the vulnerabilities on the computer systems and networks. Few do it for their academic interest and thrill and inform the person concerned about the vulnerabilities so that the same can be plugged. They are known as white hat hackers. While the others do it with malice and self-gain and are known as Black hat hackers.</p>
<p style="text-align: justify !important;">To gain access to the computer systems, the cybercriminals and hackers will continue to deploy already existing tools (called as exploits) with enhanced capabilities. More advanced tools will be also be developed in the coming years. Some of the important ones are enumerated below:</p>
</div>



<div class="img-with-aniamtion-wrap center" data-max-width="100%" data-max-width-mobile="100%" data-shadow="none" data-animation="fade-in" >
      <div class="inner">
        <div class="hover-wrap"> 
          <div class="hover-wrap-inner">
            <a href="http://bit.ly/2IY3u54" target="_blank" class="center">
              <img decoding="async" class="img-with-animation skip-lazy" data-delay="0" height="60" width="728" data-animation="fade-in" src="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png" alt="cyber4healthcare-online-course-bottom-ad (2)" srcset="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png 728w, https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2-300x25.png 300w" sizes="(max-width: 728px) 100vw, 728px" />
            </a>
          </div>
        </div>
        
      </div>
      </div>
			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3bd4472"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>1. Chatbots:</strong> There will be extensive use of machine learning techniques (Artificial intelligence) in the near future. A Chatbot can be injected into the important website (for example, a banking site). Chatbot in the form of a man or woman would pop up on the screen and will start interacting with the user (like what we see the google assistant doing). Then it may misdirect the customer to a nefarious link similar to an actual banking site, thereby fetching important information from the customer and compromising his banking information.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3bd4892"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>2. Bot and botnet:</strong> The hackers have been successful in remotely taking control of the hacked computer systems. Such a system is known as a bot. The hacker can remotely misuse a machine (using computing time or other resources) without the actual user being aware of it. If there is more than one compromised device, then it is called a botnet. Botnets can be put to perform some distributed function viz, crypto jacking (mining bitcoins) or distributed denial of service attack.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3bd4c24"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>3. Discover and target organizations outside the firewall:</strong> Most of the commercial organizations deploy firewalls, intrusion detection systems, and intrusion protection systems; thereby making hacking difficult. But they use the third-party software, which may be having vulnerabilities. Hackers can attack the third-party systems used by commercial websites.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3be2f95"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>4. Injection Attack:</strong> Protective systems installed on computers look for malicious files to detect cyber-attack. The injection attack is filed less; the hacker directly inserts the malicious code in the memory, thereby compromising the machine, without ever dropping a file onto the infected system. One such example is British Airways site hack in 2018, resulting in identity theft of around 3,80,000 users.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3be7658"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>5. Biometric Hacking:</strong> Cybercriminals use brute force attack, dictionary attack or social engineering, etc., to crack the passwords. Many people have shifted to biometrics. The academic research suggests that a number of officers print authentication systems could be spoofed, even highly sophisticated facial recognition system has been proven vulnerable to more advanced hacking efforts.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3bee3b6"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>6. Application of artificial intelligence:</strong> Artificial intelligence techniques will be used more and more to avoid detection by intrusion detection tools. For example, Waterminer, a cryptocurrency mining tool injected as malware, stops mining when task manager or antimalware scan is run.</p>
</div>




<div class="wpb_text_column wpb_content_element " >
	<p>Also Read:<br />
<a href="https://innohealthmagazine.comissues/social-isolation-in-a-digitally-connected-world/">Social Isolation in a Digitally Connected World</a><br />
<a href="https://innohealthmagazine.compersona/sweden-india-collaboration-health-sector/">Sweden-India Collaboration in Health Sector</a></p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3bf35de"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>7. Rouge AP(access point) and Evil Twin:</strong> Rouge AP is an access point installed on the network without the knowledge of the administrator, while the evil twin is identical network.</p>
<p style="text-align: justify !important;">The above-mentioned techniques will be sharpened to attack numerous utility services (some of which are listed below) by the black hat hackers for malicious purposes:</p>
<p style="text-align: justify !important;"><strong>A. Internet of things(IoT):</strong> the Considerable number of smart gadgets (such as TV, plugs, IP cameras, smartphones, tablets, network video recorders, heaters, refrigerators) are used at homes and industries. When these gadgets are connected to the Internet, they are termed as the Internet of Things. The hackers will increase their attacks on IoT using a vulnerability in cloud infrastructure and hardware to threaten the users physically or mentally.</p>
<p style="text-align: justify !important;"><strong>B. Attack on identity platforms:</strong> Identity platforms offer centralized secure authentication of users, devices, and services across the IT environment. It could be a database of banks, hospitals, social media sites, etc. Identities of a large number of persons would be attempted to be stolen for extortion, impersonation or proving the inadequacy of the commercial organization in securing the important data (so as to blackmail).</p>
<p style="text-align: justify !important;"><strong>C. Real world damages:</strong> There will be more and more attacks on services providing community services viz, municipality, health sector, electricity supply, water supply, and sewer systems. Besides the cybercriminals, who would use such hacking for ransom, terrorists and even nations can use it against public or adversaries.</p>
<p style="text-align: justify !important;"><strong>D. Social media content compromise:</strong> There will be increased use of Botnets to compromise social media to influence public opinion.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3bf3a5b"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>Q. Being a healthcare publication, our readers would be interested in healthcare-specific cyber threats. What is your opinion on the health sector threats? </strong><br />
The health sector offers life critical services. It maintains the identity and clinical records of a large number of patients. The following factors make the health sector more vulnerable as compared to the other sectors.</p>
<ul>
<li>IoT (Internet of Things) devices are used extensively for the treatment of the patients viz. smart continuous glucose monitoring, connected inhalers for asthma, apple watch Identity platforms offer centralized secure authentication of users, devices and services across IT environment. It could be a database of banks, hospitals, social media sites, etc. PERSONA THEME TRENDS WELL-BEING ISSUES RESEARCH NEWSCOPE app that monitors depression, etc.</li>
<li>The doctors and patients can connect external storage devices and even mobile phones to the hospital database system.</li>
<li>Third-party software and hardware are deployed which makes it vulnerable to supply chain poisoning.</li>
<li>Most of the services provided by the hospital are connected through the Internet or the cloud services.</li>
</ul>
<p>Clinical data is of immense use for cybercriminals and cyber terrorists. They can use vulnerabilities in cybersecurity in the following ways:</p>
<ol>
<li>Identity theft: Medical identity record is very useful for the cybercriminals as it can be used to impersonate people in the digital world and gain access to financial systems as well as to commit fraud by claiming treatment or insurance at the cost of insurance agencies and the patients. Therefore, this data is sold at a higher rate in the darknet as compared to identity records of other sectors.</li>
<li>The clinical records of the patients may sometimes contain their psychological disorders or conditions, or a person may be suffering from concealed diseases (sexually transmitted disease, etc). The hacker may make use of such information by blackmailing or harassing the patients. It would cause hardship to the patients and would put the reputation of the healthcare service provider/hospital at stake which failed to protect the patients’ identity and clinical records.</li>
<li>Ransomware attacks on hospitals will be on rising. The information of the patients is mostly time critical. If the cybercriminal denies the access of data to the hospital even for a short span of time, it may lead to lack of timely treatment to critical patients and therefore, hospital administration is not in a position to delay the ransom payment.</li>
<li>Prescription change: In India, the majority of renowned hospitals in metro cities are computerized. Doctors give online prescriptions which immediately become available to the concerned medical staff, such as a nurse who administers the drug to the patient. Cybercriminal scan tampers the prescription which may harm or even cause the death of the patient. They can cause an obstruction in the oxygen supply line or failure of electricity. They would be able to change the medical records of the patients, which will lead to wrong diagnosis and treatment. Not only cybercriminals but the terrorists can adopt the above techniques and threaten the nations or can even cause large scale fatalities.</li>
</ol>
<p>Therefore, it becomes extremely important to adequately secure the health sector databases.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3c0deb0"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>Q. The health sector has seen major attacks of ransomware; part of the equation is &#8216;money aka cryptocurrency&#8217; in organized crime. How do we handle this? </strong></p>
<p style="text-align: justify !important;">Being proactive about cybersecurity is perhaps the best approach to tackle cyber-attacks. The health sector should form cybersecurity forum for cybersecurity policy formulations and mutually evaluate hospitals’ preparedness against the cyberattacks ensuring adherence to the cybersecurity policies. Additionally, each hospital network should have a dedicated team of IT security professionals to guide the management and proactively check for any cyber invasion. The IT team should ensure that the latest patches for all the devices and software are installed and there is protection from supply chain poisoning. The system should be equipped with features firewalls, Intrusion Detection System, Intrusion Protection system and processes analytical tools among others.</p>
<p style="text-align: justify !important;">The blockchain techniques can also be explored for data management and the patient databases should be encrypted so that they are of no use to the hacker. Further, the hospitals must take data backup with a fast recovery plan. Regular penetration testing of the system should be done to eliminate potential vulnerabilities.</p>
<p style="text-align: justify !important;">Hospitals should invest in training IT staff in cybersecurity policies and cybersecurity technologies. Regular analysis should be done of employees’ computer usage pattern so that any compromised user is effectively detected and timely removed from using the system. There should also be a secure access control preferably using biometric features.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3c0e7cf"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>Q. Today security has become a hot topic and world over we see that regulation is leading change and innovation! What is your vision for India in regard? What regulations will make the health sector more secure? Or we don&#8217;t need regulation? </strong></p>
<p style="text-align: justify !important;">The cybercriminals attempt to hack the computer resources of the hospitals by exploiting the vulnerabilities in the computer systems. They manipulate the stored information, steal the same or hold it for ransom. The hospital databases work on the trust reposed by patients in the hospital administration that their data will be guarded with privacy.</p>
<p style="text-align: justify !important;">Cybercriminals can be prosecuted under various provisions of the Indian Information Technology Act, 2000(ITA). The IT Act creates civil liabilities for the offenses under the Act vide Sections 43 to 45, wherein an amount of compensation can be given to victims; it also creates criminal liabilities vide Sections 65 to 74 of the Act. Cybercriminals are liable to both civil and criminal liabilities.</p>
<p style="text-align: justify !important;">Hospital administration is responsible for protecting the data and failure to protect can result in civil liability under Section 43A of the IT Act. However, this section can be invoked if the breached data results into wrongful loss to the victim or wrongful gain to a cybercriminal. The victim has to prove that there was a wrongful loss to him/her. The offenses by the intermediaries are criminalized under Section 67C of the IT Act. However, the same gets diluted by the provisions contained in Section 79 of the IT Act. Hence, the IT act doesn’t provide absolute data security laws.</p>
<p style="text-align: justify !important;">The Government of India appointed Justice BN Srikrishna Committee for effective data protection laws in India. The committee submitted the Draft Data Protection Bill, 2018 to the government in July 2018. It will be introduced in parliament after the forthcoming elections in India. The Government of India is also planning to introduce “The Digital Information Security in Healthcare Bill” in the parliament to secure the healthcare data of patients in India.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69f37e3c13bfb"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><strong>Q. As the cyber incidents keep rising and legal regime catches up, what is your opinion on our abilities in investigating cybercrime? As you know attribution and audit trail are not the easiest in the cyber world, any advice for stakeholders so that they are not wrongly prosecuted or get justice on time? </strong></p>
<p style="text-align: justify !important;">According to Section 78 of the IT Act, 2000, a police officer of the rank of Inspector and above is authorized to investigate the offenses under the IT Act. This is to ensure the quality of the investigation. However, all Inspectors in police are not trained in cybercrime investigation. Further, complexities of computer technology, tools, and methodology used by cybercriminals make it difficult even for a trained person to keep pace with the development in this field. Police organizations don’t employ external cyber experts to aid in the investigation. Each police officer investigating the case seeks help from other expert police officers or cyber experts of his/her choice. Therefore, institutional help is lagging.</p>
<p style="text-align: justify !important;">There is also the dearth of cyber experts in forensic science laboratories, resulting in delays of months and years in getting reports from them which can compromise the further evidence leading from forensic analysis of seized electronic material. During my tenure in the Enforcement Directorate, I found this delay to be of 1 to 3 years, therefore, I initiated six in-house cyber forensic labs. This led to the cyber forensic analysis done at a quicker pace also improving the quality of investigation.</p>
<p style="text-align: justify !important;">The next hurdle is the global spread of evidence into other jurisdictions. A letter rogatory (letter of request) is sent to each foreign jurisdiction for getting the evidence located in that jurisdiction. The process is slow and it may take 3 to 4 years in getting a reply. If that reply further requires evidence from another foreign jurisdiction then another 3-4 years are gone. Therefore, the entire investigation is time-consuming.</p>
<p style="text-align: justify !important;">The investigation becomes further complicated if Tor or onion routing is employed by cybercriminals. Finding the cybercriminal in this scenario becomes more difficult.</p>
<p style="text-align: justify !important;">The IP address (internet protocol) and the time of its use, identify uniquely the source of the attack. However, the cybercriminal may commit cyberattack through Bot or botnet. In that case, the IP address will lead the investigation officer to the slave machine, even though the user of this machine would have no knowledge of the misuse of his computer resources. If the investigating officer doesn’t go into the depth of log analysis of such a system, then the innocent people might have to face false prosecution. The stakeholders should ensure all logs are maintained and stored by his computer system so that the audit trail can lead to actual perpetrator of cyber-attack.</p>
</div>



<div class="img-with-aniamtion-wrap center" data-max-width="100%" data-max-width-mobile="100%" data-shadow="none" data-animation="fade-in" >
      <div class="inner">
        <div class="hover-wrap"> 
          <div class="hover-wrap-inner">
            <a href="http://bit.ly/2IY3u54" target="_blank" class="center">
              <img decoding="async" class="img-with-animation skip-lazy" data-delay="0" height="60" width="728" data-animation="fade-in" src="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png" alt="cyber4healthcare-online-course-bottom-ad (2)" srcset="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png 728w, https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2-300x25.png 300w" sizes="(max-width: 728px) 100vw, 728px" />
            </a>
          </div>
        </div>
        
      </div>
      </div>
			</div> 
		</div>
	</div> 
</div></div>
<p>The post <a href="https://innohealthmagazine.com/2019/persona/exclusive-interview/cybercrime-and-threats-in-2019/">Cybercrime and Threats in 2019</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://innohealthmagazine.com/2019/persona/exclusive-interview/cybercrime-and-threats-in-2019/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">5917</post-id>	</item>
	</channel>
</rss>
