Diagnosis Cyber: The Cyber Threats to Healthcare

Diagnosis Cyber: The Cyber Threats to Healthcare By Olly Jones – PGI Cyber The Cyber Threats to Healthcare took another twist as news…
Icon blue background - Security Buyer

Share this article:

Diagnosis Cyber: The Cyber Threats to Healthcare

By Olly Jones – PGI Cyber

The Cyber Threats to Healthcare took another twist as news emerged this week that a virus had infected the network of the Northern Lincolnshire and Goole NHS Foundations Trust (NLAG), forcing it to shut down computers in two hospitals and cancel operations across Lincolnshire. While the antenatal clinics, chemotherapy treatments and emergency departments remained open, a major incident was declared. Operations and outpatient appointments were cancelled for a 48-hour period to enable IT staff to investigate and remove the malware. While the majority of systems have now been reportedly restored, details of the malware or whether this was a specifically-targeted attack against NLAG are limited.

This is just one of many examples of the cyber threat facing the healthcare sector. It emerged as a significant cyber security risk in 2016 and research from IBM has revealed that the healthcare industry became the most-attacked sector in 2015. The Information Commissioners Office (ICO) has also recently reported that half of all UK data breaches reported to the ICO in the final quarter of 2015 came from private or public health organisations.

So Why is Healthcare Such an Attractive Target?

  • The healthcare sector is increasingly targeted due to perceived poor cyber defences and the large amount of sensitive data it holds. Health data, much of which remains valid (and therefore potentially exploitable) for years, contains valuable personal information which some suggest can be 10 times the value of a stolen credit-card information.
  • Continued budgetary constraints often results in many healthcare providers having computer networks based on outdated, legacy systems. Recent research identified that at least 42 NHS trusts in the UK still run Microsoft’s now-outdated Windows XP operating system and NHS Digital admitted that 15 per cent of Windows installations in the sector are on XP. The healthcare sector also includes many small companies who generally lack the financial resources and technical expertise to update legacy systems or implement robust cyber security strategies.
  • The nature of the sector means that lives are literally at stake. If a critical system is compromised with ransomware, with a time-restricted deadline before critical data is potentially lost, it is unlikely that victims will wait for a technical solution to be found rather than just paying the ransom. Cybercriminals are acutely aware of this which is why the sector is being so aggressively targeted.

What Are the Threats?

Ransomware

Reports of UK entities being targeted thankfully remain rare, but the highest profile healthcare victim to date was the Hollywood Presbyterian Medical Centre in Los Angeles. After a ransomware infection forced the hospital to shut down all of its computers and revert to using fax machines and paper records for a week, the centre reluctantly paid $17,000 (£12,000) in Bitcoin ransom to hackers to end the crisis and protect their patient records. Regrettably, paying this ransom set a precedent that this form of cyber-extortion works and, following publication of this case, many copycat-style attacks occurred in California, Indiana, Kentucky and Maryland.

Hacking Health Equipment

Any headline-grabbing media stories relating to healthcare almost always includes a feature about medical equipment being hacked and the associated risk to life. Security researchers have demonstrated it is possible to gain access to critical medical devices, and although part of the threat exists from actors wishing to steal the technology behind the equipment, the main perpetrators are most likely to be cybercriminals whose main incentive is money. They are unlikely to have the motivation or intent to conduct attacks that would directly lead to the loss of life.

What Does This Mean for the UK?

The UK healthcare sector faces significant cyber security challenges, complicated by the 100,000 or so different authorities, public and private bodies that make up the sector. This is compounded by government plans to digitise the NHS and become paperless by 2020. A perceived lack of understanding of the threat and a shortage of both funding and experienced information security staff to help protect outdated systems is also a significant challenge.

The decision whether to spend already tight budgets on new security technology is clearly difficult, but cyber security solutions do not have to be expensive. By separating critical medical devices for patient care from general networks, implementing a regular patching regime and educating network users to prevent the potential infection of malware, the cyber risk can be significantly reduced.

For more information about their capabilities just click the button below:

[su_button url=”https://www.pgicyber.com/” target=”blank” style=”flat” background=”#df2027″ color=”#ffffff” size=”10″ radius=”0″ icon=”icon: arrow-circle-right”]Find out more about PGI Cyber[/su_button]

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Ai Solution of the year - securitybuyer.com

Have your say: vote for AI Solution of the Year

Voting is open for AI Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited to select their winner
Access control of the year - securitybuyer.com

Have you voted for Access Control Solution of the Year?

Voting is open for Access Control Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited
PaxLock Pro2 - securitybuyer.com

Paxton officially launches PaxLock Pro2

Paxton the security technology manufacturer has launched a brand-new re-engineered PaxLock which is built to protect straight
KentixONE data centre - securitybuyer.com

Data centre security with KentixONE

Prior1 develops container data centers to meet the highest security and energy efficiency standards. Their containers require
Chubbsafes - securitybuyer.com

Chubbsafes explores certified storage for jewellery and precious metals

Chubbsafes, part of Gunnebo Safe Storage, has launched a new technical discussion guide examining when certified
Mercury trends report - securitybuyer.com

New Mercury Research Finds Growing Cybersecurity Gap

2026 Trends in Access Controllers Report finds interoperability, cloud connectivity and AI are reshaping long-term controller strategies.
Chris Carroll - securitybuyer.com

Comelit-PAC Promotes Chris Carroll as Sales Director

Comelit-PAC has appointed Chris Carroll as Sales Director, following an 18 year career with the company, seeing him progress
Jason Bezuidenhout - securitybuyer.com

Zygal Appoints Jason Bezuidenhout

Zygal has appointed Jason Bezuidenhout as Chief Revenue Officer (CRO), strengthening its leadership team as the company continues
Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
Scroll to Top