Transcript
to disrupt you or they want to wipe stuff that you're doing to make an impact because they're acting on a name or acting according to a certain regime or they just want to make money and it's pure business to them. So you'd better be prepared and make sure you have adequate security and investments in place. Hello and welcome to another episode of Data Security Decoded. I'm your host Caleb Tolan and if this is your first time joining us, welcome to the show. Make sure you hit that subscribe button so you're notified when we drop new episodes. And if you're a returning subscriber, thanks so much for spending some more time with us. Make sure you give us a review, a rating below, let us know what you think about the episode. Your feedback really helps me understand what you want to learn more about and it helps us reach more listeners like you who are trying to improve the resilience of their business. Now in this episode, I am joined by John Falker, the VP of Threat Intelligence Strategy at Trellix. And we talked about their Healthcare Cybersecurity Threat Intelligence Report, which analyzes the 2025 healthcare threat landscape. There's a lot of really interesting stuff in this report. We had a really fantastic conversation. So without further ado, let's get into it. Well, we're really excited to dive in and talk a little bit about this report that you and the team put out. And so the first thing that I wanted to chat a little bit about was a stat that really really stood out to me in terms of lethality. And so typically, when we're talking about cybercrime, we're talking about, you know, what is the total dollars and the cost of a breach? What is the total economic impact of cybercrime? But your report found a 29% increase in inpatient mortality rates at hospitals hit by attacks. A really, really impactful and really just touching stat to hear. So when you're sharing this data with a CISO, how are they using that mortality stat to convince their board that cybersecurity isn't just a cost center? It's not just something that that is a checkbox on a form, but it's actually a fundamental requirement of clinical missions? Well, you said that right. And if I sum it up, in healthcare, downtime isn't just expensive. It is life-threatening and it's dangerous. So for a CISO, where they historically had like, okay, it was just the IT systems. You now see that there's more like digitization, if you might call for things, and there's more advancements when it comes to building the networks and having everything connected. Their seat at the table has become much larger. And having these figures or arming them with these figures will have them address the right audience. Because as much as it's been hard in the past, because yeah, a hospital board, they have only X amount of dollars to spend and they want to spend it on the best care they can give to their patients and patient safety is number one. And now you see that transition from going from, okay, it's just the IT department. Like, no, no, this has real impact on human lives. You're going into that patient safety space. So our report and many other reports, we will hope that like in the healthcare industry, those CISOs will have ample ammunition to open up that conversation. It's like, hey, listen, if we want to continue as is, patient safety is number one. We need to invest more. Absolutely. And it's even starting to make its way into pop culture. You know, I'm not watching The Pit. It's something that's on my list to get to, but I've heard so many people talk about this recent season and how much of a focus there is on cybercrime taking down hospital systems and how that is really impacting patient care, just like what you're talking about. I have, on the other hand, seen Grey's Anatomy and gosh, it was probably like five or six years ago that they had an episode where the hospital was taken out by a ransomware attack. And so it's becoming a more prevalent and well-known topic that cybercrime does directly affect patient outcomes. And something else that I found really interesting is attacks targeting non-political systems like HVAC units to really bring hospitals down to their knees. So simultaneously, while attacks are, you know, attacking business associates and third party providers, given that like 99% of hospitals have at least one device known with an exploited known vulnerability, are we focusing too much on the hospital's front door while the back door is really wide open with partners and facilities that aren't addressing some of these issues? Yeah, that's a good point. If you look at it, the attack might start in the back office, right? But then the impact is definitely felt at clinical care. When we look at not only hospitals or medical systems, but OT in general, if I just generalize OT, like operational technology, in our other report, the OT report, we divide it up in three elements. It's like the direct OT, so you can, if you kind of take that same analogy for hospitals or healthcare, it'd be like, hey, it's your MRI system. Is that connected to the internet? Is that vulnerable? So in the OT, that would be the PLC, right? And then it's, you have all the systems adjacent that not only in an HVAC system, we can be like, we can count that under those systems, are not directly impactful to the machine itself, but disrupting these will change the environment for hospital or logistics or other things that will have an impact. And then they have, from a safety perspective, they will have no other choice than to shut things down. Very similar, like everybody knows colonial pipeline, right? The actual pumps did not get infected. It was the system that maintained the accounting, making sure that the logistics were in order. Those were impacted by, I believe, dark side ransomware, and that caused the shutdown. So you will see that there's, in that whole chain, in order to deliver out-of-patient care or OT environment, there's different systems. And then lastly, there's systems that, like you have the adjacent systems and then there's systems for logistics, like do the right supplies come in? So let's say a IT system, because it's not connected to anything else, but it manages, it's connected to the pharmaceuticals. So the hospital can get enough medicine in, for instance, or enough supplies. That gets impacted and that gets shut down, disrupted in any way or form that could also impact the patient care. Absolutely. I was even going to ask you, what are some of those non-clinical systems that you've seen that are kind of those curveballs that people aren't necessarily affected by? But those are some really, really interesting examples. And so I want to shift gears a little bit and talk about dwell and downtime. So the global median dwell time for a ransomware attack used to be about five days, but your report found that in healthcare in particular, it was a 279-day detection and containment cycle. That is wild. The better part of a year of an adversary living in your network. So my question really is, have adversaries mastered the art of blending into the background of a busy hospital? What kind of anomalies can IT and security teams listening in look out for so that they can stay on their toes and identify these anomalies before they become out of hand? Yeah. And it's good to know that that number is ultimately an outlier, right? It's like staggering. Because when I saw that number the first time, I was like, holy moly. And at the same time, on the other end, you have ransomware attacks that come in and they have a pretty short dwell time. And if they deploy ransomware that locks up systems, it's all business, right? It's money. So they want to make sure that they're known, they lock up the systems, put the pressure on the hospital or on the medical provider, it might say. Mind you, our data set is not only pure hospitals, it's the larger healthcare organizations. And then, so the dwell time is relatively short, just to meet their objectives. And then they will make themselves known, and then we'll start the extortion. But going back to like, hey, there's 99% of systems are vulnerable to certain exploits. That is, in the military, you would say a target rich environment, right? There's a lot of entryways getting into the network. And for certain threat actors, it's interesting to stay under that radar, to stay within the network or exfiltrate data out or just having some kind of foothold. And that's from the attacker's point of view. And then from the defender's point of view, we see that, yeah, and that's, it's all interconnected. So that goes back to the investments. It's like, okay, do you have the proper tooling and solutions in place to see those living off the land type of attacks that go low and slow under the radar? Because they want to blend in. They're not always using malware to get in. So they're using some, they have legitimate accounts, and then you have to spot the anomaly. So like, how do you spot malicious behavior exhibited by non-malicious tools? And that is where usually like an EDR type of tooling comes in or an NDR type of tooling, proactive threat hunting that we're big on as well. So these are the things that you can help spot these anomalies, but mind you, I think the biggest factor that we saw against healthcare organizations at large, so not only hospitals, but anything from pharmaceuticals or whatever, the number one entry point or the biggest one that we saw was still email. So like email security is a big, big thing for these organizations. Make sure that you can stop it before it actually gets inside your network. Yeah, you know, both really, I'm the oddball in my family. Everybody that is in my immediate family, my sister and both my parents, all have worked in hospitals. And so now working in cybersecurity, I talk to them all the time about the stuff that I'm working on. And they're like, Oh, you know, I had to take that phishing, you know, that phishing security thing. And I'm like, yes, it's very important. Please pay attention to it. Because we still continue to see that these entry points are from some of the most typical places that we've been talking about for really decades now. So I really kind of want to zoom in a little bit on what you were talking about with like indicators of compromise. So what are like some of the standout behaviors that you've seen that really distinguish between care and crime when you have a threat actor living within a system? And they've, you know, credential crept their way into an administrative role? Like what what do those IOCs look like, typically? And what are some of the interesting ones that you've seen? Wow, there's been so many. A lot of times, like when we talk about IOCs, within Trellix, we kind of label that as atomic indicators. It's more like the technical layer when it comes to technical threat intelligence. Very often, we don't see a lot of indicators. So it's, it's very much more tool usage. So we see that more in an operational intelligence layer. So we see legitimate tools like PowerShell being used, a command line, and PS exec to execute some stuff. And it really depends on what phase the attacker is in. So if they have an initial foothold, let's say they send out an email, right? They have some kind of implant, or a different lure, you would see like, okay, they have one system. And now they need to, okay, where am I? So yeah, it sounds silly, but sometimes you still see who am I, which is actually a dead giveaway, if they use that command, but it's system discovery. So they need to figure out where am I in the system? Did I hit the jackpot? Or am I like a lonely computer somewhere in the HR department, and I need to work my way up to become domain admin? Or so, so system discovery, like AD find tools like that, just to figure out where they are. And then you would see that try to escalate privileges move laterally. So the tool usage for that is also very obvious, obviously, like process injection, those type of techniques we see, and there's 1000 ways of doing so. And then when they move through the network, it really depends on what they do, what they want to do, right? If their goal is, let's say a ransomware group that does data extortion, they would look at finding the interesting data and something that really like, there's things that pop up like, they would use like 7-zip. And if you're not using 7-zip, 7-zip is a legitimate tool, but if you're not using that in your network, or some user is obviously never used it and starts using it, it might be it's your family member that heard from you, Caleb, hey, 7-zip is really great. And then I want to use it. But it could also be that somebody who's actually got that account and then is using it as well. And another thing that we often see is like when selectors have a legitimate foothold, and we see that this across the board, so it's not only in the medical sector, using legitimate remote management tools. That is such a prevalent thing. Like we just published a whole report on the capability from the Iranian selectors. And they leverage a whole set of legitimate remote management tools. And that's what we often advise our customers and everybody else is like, listen, like as soon as they can install this, let's say they do any disk or Altair or TeamViewer, it doesn't matter. That is disguised as legitimate traffic, and it will not stand out because they have the ultimate backdoor. They can just communicate back and forth and they don't need any elaborate Cobalt strike or anything else because they already have that foothold. And especially when you're dealing with HIPAA compliant data, or it's like you get into a system where there's patient files, you want to put a hold on this, you want to lock this down and make sure like, hey, this is within our organization, this is the only tool we use, and we block everything else. So that's something that we really often see across the board. It's like, okay, we got in, it's like, oh, we made a little noise to do the thing that we need to do. And if we're in and we want to stay in, as soon as we can switch to remote management tools, legitimate ones, and just they can sit there, they can do anything until they meet their objective. All right, you're even getting ahead of me because I was just about to say, my next question for you is, what are the three actions that defenders can take today to start improving their clinical cyber resilience? You already mentioned one. So let's get two more on the books too. Oh my gosh. So email, it's like the front door, you need to lock the front door. And that goes like, if we talk about front door, email is one, like have really good email security. If you do not have an organization, like a basic email blocking system, invest in like, a team that can also augment your security team on top of that. So email and anything you can do to harden that is a great one. So we say like, having an ability, and that goes beyond remote management tools, an ability to monitor any suspicious behavior in your network. So having more grip on the low bins, because that's kind of a common threat, if we talk about what we've been discussing, segmentation still holds up. So any like the OT requirements that we have, so your most vulnerable systems, and I realized this, right? So having segmentation in a network, not everything has to be connected, is actually a healthy thing. And then lastly, I would say, limit your attack surface. So if you look at how a lot of these threat actors will operate, is they'll scan your IP space, and they look for vulnerable systems that are accessible through the internet. And if you do this as a security team on a continuous basis, and you can address these vulnerabilities, and then it's not only, and this is very funny, it's not only the vulnerability that you have to plug, but you have to use threat intelligence, threat intelligence about like, okay, which threat actors are leveraging this vulnerability? And how can I rule out that, like, yes, I put my finger in as a Dutch analogy, right? I put my finger in the dam. But you want to know like, all the water that already came through, is that not like, where are the piles and the puddles of water? So like, if the threat actor already got in, where could he hide? So proactive hunting in your environment is another thing. Yeah, yeah, that's great. And we did a recent episode with Kyle Feeler on the Rubrik Zero Labs team, and we talked about how backups can be a rather unexpected resource for your threat intelligence as a telemetry mechanism. So if you're looking at your backups, and you see threat actors living within there, it's really a good record keep of basically your entire security stack failing to identify these threats before they made it up to your backup. So that's another great resource to look at. And if anyone listening in hasn't given that episode a listen, then I highly encourage it. All right, next one for you is two inconvenient truths. What are two inconvenient truths that every security leader is ignoring right now in healthcare when it comes to data security? Maybe not every security leader, but maybe the ones that are, you know, have their rose colored glasses on. I would say AI for data security is as much a savior as it is a curse. When I look at our data security solutions, it's a lot of times our customers are like, hey, Trellix, can we have AI to help identify sensitive data in our organization? So can you have your Trellix-wise AI assistant help us identify data sets, codify them, label them, all that stuff? So we need to have on this side. And then the other end is like, hey, Trellix, we have no clue who is using AI and if our intellectual property is going out the door. So it's like, we have to embrace AI by making things easier for customers. But at the same time, it's like, how do we put guardrails on, and especially in the healthcare industry or pharmaceuticals where you're dealing with IP, the last thing you want is that somebody puts IP in the public chat TPT function and then it's like goes out the door and then it's out in the open. So for AI, that's definitely one inconvenient truth. It's as much a blessing as a curse. I think the inconvenient truth is, and that kind of touches on data too, is for the longest time we've been thinking about healthcare or healthcare providers or hospitals, and I've seen like the start of ransomware targeting hospitals, because first that was like, oh, we don't do that. That's unethical. And for the longest time, healthcare providers and hospitals have something that I'd like to call the cyber Red Cross syndrome. So you know, like, hey, we're the Red Cross or the half moon, like, you don't attack us. We're neutral or whatever. And I was like, no, that's passé. That's no longer it. But that's still that attitude still is prevalent within certain healthcare organizations. And by adopting that attitude, you limit yourself from a security standpoint, because that moment has passed. And even with the recent attack against Striker, which has a medical tie in, and how the Threat Actors were leveraging iTunes to delete everything, yeah, you're a target. So you need to drop that. And that's inconvenient, because yes, there are horrible people out there that have it out for you. And it's either they want to disrupt you, or they want to wipe stuff that you're doing to make an impact, because they're acting on the name or acting according to a certain regime, or they just want to make money, and it's pure business to them. So you'd better be prepared and make sure you have adequate security and investments in place. I couldn't agree more. I mean, look, I put you on the spot and you gave two really, really good and convenient So kudos to you for that. And you've shared so many really, really actionable insights that our listeners can take away with them. But what is the single most important message that you want to leave the listeners with today? Well, if there's one message, and it's also on the report, is that healthcare cybersecurity cannot be treated as a like a back office compliance exercise. I really think it has to be approached as an operational resilience and patient safety priority. And that's kind of the two things we already touched upon. And organizations that do that well, will be best positioned to absorb any attempts against disruption, or, and they will protect the trust of their patients. And they keep care moving along, because that's what it is, right? So you want to be able to provide the best level of care to all your patients, no matter what. And that's what resilience. Right. Absolutely. It's that concept of minimum viable hospitals, like, know what your dependencies are, and ensure that you can have that operational continuity, even despite everything feeling like it's on fire, which is something we want to avoid. But you know, it's always good to have that plan in place. So, John, thank you so much for joining us today. This was a fantastic conversation. I really appreciate your time and all the insights you shared with our audience today. Thank you so much, Caleb, and it's a pleasure. That's a wrap on today's episode of Data Security Decoded. If you like what you heard today, please subscribe wherever you listen and leave us a review on Apple Podcasts or Spotify. Your feedback really helps me understand what you want to hear more about. And if you want to reach out to me about the show, email me directly at data-security-decoded at n2k.com. Thank you to Rubrik for sponsoring this podcast. The team at N2K includes producer Liz Stokes and executive producer Jennifer Eiben, content strategy by Mayan Plaut, sound design by Elliot Peltzman, audio mixing by Elliot Peltzman and Trey Hester, video production support by Bridger Krookywild and Sorel Joppe. Until next time, stay resilient. Transcribed by https://otter.ai