The European Cyber Security Organisation (ECSO), in collaboration with its members and the ECSO Chief Information Security Officers (CISO) Community from the healthcare sector, has been gathering insights into the sector's current challenges across the EU and exploring potential solutions. These findings were recently discussed at ECSO’s "Cybersecurity in Healthcare: Insights from Security Professionals" webinar.
The EU is developing an action plan to emphasise the need for up-to-date cybersecurity in hospitals and healthcare providers, with a strategy that will be introduced during the first 100 days of Ursula von der Leyen mandate. In response, ECSO decided to collect inputs from its members regarding the main challenges in this sector and their solutions, along with a complexity level and their criticality.
The main constraint present in this sector is budget, making securing digital infrastructure and ensuring privacy increasingly difficult. Collaboration between public administration, healthcare professionals and business are essential to improve security.
Despite the current policy initiatives, such as the NIS2 directive, the Cyber Resilience Act and the GDPR, the healthcare sector remains a frequent target of cyberattacks and its cybersecurity maturity is still insufficient to protect critical infrastructure.
Insights from security professionals reveal that in the healthcare sector, especially in hospitals and healthcare providers, IT and security are still an afterthought, despite them being foundational for modern healthcare delivery. The lack of integrated cybersecurity in medical product development, reliance on legacy systems and difficulty in managing supply chain risks further increases the sector's vulnerabilities. Additionally, difficulties in attracting and retaining skilled cybersecurity talent, along budget constraints, further hinder the progress in addressing these issues.
To address those challenges, several solutions are proposed:
In conclusion, healthcare's cybersecurity is a complex issue that requires a coordinated approach. More attention should be given to alleviate budget constraints, secure the supply chain and develop secure technology.
For more information, visit:
https://ecs-org.eu/?publications=cybersecurity-in-healthcare-insights-from-security-professionals
Author Linkedin Profile: Marcello Carboni, Cyber Security Specialist, 8 West Consulting https://www.linkedin.com/in/marcello-carboni-b01228186/