CISO of the GHU Paris Psychiatry and Neurosciences: Enthusiasm in the face of challenges

By Charles Cardine
Published on 08/02/2023
CISO of the GHU Paris Psychiatry and Neurosciences: Enthusiasm in the face of challenges

In February 2021, following a wave of cyberattacks on healthcare facilities, the government announced a national cybersecurity plan. 135 hospital groups were then classified as “Operators of Essential Services” (OSE). Among them was the GHU Paris (a merger of three healthcare facilities since January 1, 2019). Pierre-Antoine Errard, Chief Information Security Officer (CISO), tells us how he turned this new status into an opportunity.

The OSE Status: Constraints, But Not Only

It’s an understatement to say that the 2020-2021 period was a busy one for Pierre-Antoine Errard. A cybersecurity engineer, he had previously worked at the Council of State, the University of Orléans, and the Ministry of the Economy. A long career in the civil service, then, until the day he was recruited by GHU Paris in November 2021 as CISO. “Around me, I heard that the healthcare sector was completely immature in terms of cybersecurity, poorly managed, and that it was going to be a real ordeal for me.” Undeterred, Pierre-Antoine Errard took up his duties as CISO (“the third full-time CISO for the institution”). In mid-2021, by decree of the Prime Minister, the GHU Paris was classified as an Operator of Essential Services (OSE) effective September 1, 2021. As a reminder, an OSE is an operator dependent on networks or information systems, providing an essential service whose interruption would have a significant impact on the functioning of the economy or society. This new status comes with strict rules and constraints regarding organizations, procedures, and crisis management.

At the heart of this framework is the NIS (Network and Information Security) regulation, which details 23 security points (see box). Among these requirements is the obligation to declare all of the institution’s Essential Information Systems (EIS) to the ANSSI (National Cybersecurity Agency of France) within two months. “We have about fifteen of them,” explains the CISO. “And we had to create a risk map and analyze the risks for each one.” But rather than seeing it as a constraint, the manager approaches the new status with enthusiasm. “It’s a great opportunity because it acts as a wake-up call for organizations, whatever their size. It’s a springboard that forces us to be better. The healthcare sector is a high-risk sector. We have a lot to gain by strictly adhering to the regulations.” And in this respect, Pierre-Antoine Errard has sensed a positive dynamic at GHU Paris. “I enjoy real autonomy,” he explains. Since the CISO reports to the General Management rather than the IT Department, I can avoid requesting hierarchical authorizations. I have relatively free rein.

Staying operational at all costs

Especially since the GHU Paris Psychiatry and Neurosciences is “relatively mature,” according to the expert. Two audits are conducted there each year on the applications (internal and external). Furthermore, the France Relance recovery plan, with its strong emphasis on digital transformation, allocated funds to Ste-Anne Hospital for Active Directory audits. “The scores obtained are very satisfactory. We achieved over 8,000 points out of a maximum of 9,000, which I have rarely seen in my previous experience!”

On this solid foundation, Pierre-Antoine Errard is placing great emphasis on the protection of industrial systems. “We absolutely must not neglect this aspect.” Often overlooked, they are crucial in healthcare facilities, particularly due to the development of connected devices. They must be protected and secured by isolating them from the main IT system. Compartmentalization is indeed the solution to avoid a blackout in the event of an attack. But to achieve this, the specialist remains mindful of priorities. “The hospital’s primary objective is to provide care. My departments must be analytical and compromise-oriented to remain operational at all costs.” Raising awareness, training teams, and communicating with software vendors and healthcare staff are all essential. A significant part of the work therefore also involves human interaction. Furthermore, vigilance is required in the tendering process to ensure security requirements are integrated into the specifications. “If a device meets 90% of the medical needs but only 10% of the security requirements, adjustments must be made, and workarounds must be found. We then move to perimeter security.” “

So, little by little, progress is being made. The complete isolation of the industrial system is scheduled for 2023. This is a major undertaking that the CISO intends to condense as much as possible to minimize the negative impact. And faced with this challenge, he remains positive. He has a message to share: “Don’t be afraid to work in healthcare. I’ve never felt so useful anywhere else. One of the first concepts I learned here is that of ‘patient loss of opportunity.’ Never forget that. What we do or don’t do, our decisions, all of it will have an impact on the patient’s life. And that’s the greatest motivation.”

Marion BOIS

[pdf-embedder url=“https://www.sih-solutions.fr/wp-content/uploads/2023/02/ste-ANNE.pdf” title=“ste ANNE”]