Thursday, May 23, 2019

Forescout report finds healthcare IT cybersecurity lacking

PARCA eNews – May 15, 2019 – In a survey of more than 430,000 devices on 1500 medical virtual local area networks (VLANs), Forescout Technologies found that healthcare IT continues to increase in diversity while too many networks continue to rely on legacy Windows operating systems and lack sufficient segmentation strategies.

Forescout Technologies, a provider of device visibility and control services for large enterprises and government agencies, issued its report of healthcare cybersecurity May 15, 2019.


A total of 75 global healthcare deployments were analyzed for the study, which included more than 1.5 million devices operating on 10,000 virtual local area networks (VLANs).

Entitled, "Putting Healthcare Security Under the Microscope," the report aims to focus a spotlight on healthcare information vulnerabilities. The key findings were:

  • Today’s healthcare environments are increasingly diverse: Rapid growth and diversity of connected medical devices and operating systems make it increasingly difficult to secure networks.
  • Legacy Windows operating systems are a major vulnerability: Many networks still use unsupported Microsoft Windows operating systems. A major Windows milestone is soon approaching that will leave many more devices unsupported.
  • Segmentation strategies are lacking: Network segmentation, a best practice for limiting malicious lateral movement by focusing on data sensitivity, location and criticality, is inconsistently applied on today’s diverse networks.
  • Device vendor sprawl needs to be tamed: The proliferation of device vendors causes major interoperability, security and asset management challenges.
  • Common services left on leave the network vulnerable: Common protocols left open provide uncontrolled access to attackers.
The report concludes that it is critical for healthcare organizations take a holistic strategy to security and risk management and prioritize securing all devices across the extended enterprise, not just medical devices. Such an approach requires continuous visibility and control over the entire connected-device eco-system.

The full report is available for download on the Forescout Technologies website.

Source: Forescout press release

No comments:

Post a Comment

Followers