Ransomware no longer biggest cyber security threat, report finds
Ransomware attacks are becoming less prevalent as cyber criminals look to news way of attacking a system, a new report has found.
Instead, hackers are turning towards hidden HTTPs tunnels that appear as normal encrypted web traffic to target healthcare organisations.
The Vectra 2019 Spotlight Report on Healthcare identified Internet of Things (IoT) devices; unpartitioned networks; and reliance on out-dated systems, as weakness most likely to be exploited by cybercriminals looking to steal personal information and disrupt organisations.
It called for greater use of artificial intelligence (AI) and machine learning to detect hidden threats in IT networks before they can be exploited by hackers.
According to the report, ransomware, which was used in the WannaCry attack on the NHS two years ago, has become much less prevalent in the second half of 2018.
Attacks in which hackers hide their command-and-control communications in HTTPS tunnels, which often looks like service provider traffic, were the most common type of attack, according to the US-based AI company.
“Behaviours that point to the use of external remote access tools are the second most-common detections in healthcare,” the report said.
“Although these behaviours are consistent with cyberattack command-and-control communications, these behaviours also occur when healthcare organisations communicate with independent labs, imaging centres and other service providers.”
These can include anything from IT services logging in to user machines to high volumes of outsourced services.
But the report cautioned that health organisations should still continue to monitor for ransomware, as it still remains a concern.
“The increase in medical IoT is beneficial for patients but makes securing healthcare systems a challenge due to limited security controls around these devices,” said Brett Walmsley, chief technology officer at Bolton NHS Foundation Trust.
“Having the visibility to quickly and accurately detect threat behaviours on and between all devices is the key to good security practice, regulatory compliance and managing risk.”
Software technologies company Check Point also identified IoT devices as the weakest link in IT networks in a recent cyber security report.
It found outdated software and operating systems leave the NHS “vulnerable” to attack and recommended separating patient data from IT networks to make it harder for hackers to find.
Two years ago this month (12 May) the WannaCry attack brought parts of the NHS to its knees and proved the services was woefully unprepared for a cyber attack.
Just after 1pm in the afternoon NHS Digital’s CareCERT unit sent an alert to the Department of Health and Social Care informing them that four NHS trusts had reported ransomware attacks affecting a number of hospitals.
By 4pm, the ransomware had spread to 16 trusts and it was at this point NHS England publicly declared a major cyber security incident.
It led to disruption of at least 80 out of 236 hospital trusts in England, as well as 603 primary care and affiliate NHS organisations.
Subsequently NHS England published a “lessons learned” report in order to prepare the health service for any potential attacks in the future, but its still not known how many of the 22 recommendations have been met.
source digitalhealth
Industry: Cyber Security News
Latest Jobs
-
- Public Sector Cyber Security Sales | UK
- England
- N/A
-
Public Sector Cyber Security Sales | UK UK | Remote / Hybrid A cyber security provider is seeking a Public Sector Sales professional to drive growth across UK government and public sector organisations. Must have current Cyber Security sales experience. Responsibilities Generate new business selling cyber security solutions into UK public sector Build relationships with CIO, CISO and senior technology stakeholders Manage the full sales cycle from opportunity to contract close Develop pipeline across central government, local government and public sector bodies Support bids, tenders and framework opportunities Experience Proven cyber security sales experience in the UK Track record selling into public sector organisations Familiarity with CCS, G Cloud or other government frameworks Strong stakeholder engagement and deal management skills Location UK based Security Requirements Eligible to obtain UK Security Clearance
-
- Security Architect | MoD - Security Cleared. OUTSIDE IR35 | Hampshire
- N/A
- Outside IR35
-
Security Architect | MOD | Security Cleared | Outside IR35 | Hampshire Commutable The successful candidate must be willing to undergo DV Clearance, ideally already holding active clearance. You will produce high and low level security architecture documentation, guiding and validating designs for systems deployed within sensitive environments. The role requires providing specialist security input into solution design, service transition and change initiatives, working closely with engineering, operations, client and third party stakeholders. You must have current hands on architectural experience, including VMware secure platform design and virtualisation architecture, alongside AWS expertise. This is an outside IR35 contract- 6 month rolling. Part of a longer term MoD project
-
- Active Directory | RBA engineer | UK Remote | SC Clearable
- United Kingdom
- N/A
-
Technical Active Directory (AD) and RBA specialist needed to play a key part in complex, enterprise scale Active Directory and access transformation programmes. You will work alongside senior team, helping reshape access models, modernise legacy directory structures and strengthen security posture across secure environments. This is hands on delivery within high impact projects where your work directly improves access control, compliance and operational resilience. Active UK Security Clearance required. This is a remote role with client travel. Implementation of Role Based Access Control across large AD estates Restructuring complex permission models, security groups and delegated access Supporting domain controller upgrades and core directory improvements Applying security hardening standards and remediating audit findings Enhancing authentication, policy and access governance frameworks Troubleshooting and resolving technical AD challenges within live environments Producing robust technical documentation and identifying project risks You must have the following technical experience Enterprise Active Directory administration Role Based Access and permission remediation OU design and governance Group Policy management Security group delegation models DNS and DHCP services Kerberos authentication / NTLM PowerShell scripting and automation Azure AD | Entra ID Hybrid identity environments Identity Governance PAM
-
- Identity and Access Management Consultant (Saviynt & Microsoft Entra) | UK
- United Kingdom
- N/A
-
Role summary Technical IAM consultant delivering identity governance and cloud identity solutions to enterprise clients. What you will do Implement / Configure / Deploy Saviynt IGA / Microsoft Entra solutions: Lead technical workshops, gather requirements and translate into solution designs. Troubleshoot complex issues, support testing and deployments. Produce technical artefacts and configuration guides. Key skills Hands-on Saviynt IGA experience (workflow, connectors, access governance). Strong practical knowledge of Microsoft Entra ID / Azure AD identity and access controls. Understanding of identity protocols (SAML, OAuth, OpenID Connect) and hybrid identity. Experience with APIs / REST for integrations and automation. What we are looking for Proven delivery experience in IAM / IGA projects, preferably in consulting. Confident communicator with client-facing delivery exposure.