The managed SOC as a tool for cyber resilience
VIDEO. Santexpo 2023 Agora: How to Protect Yourself Against Cyberattacks?
On April 25th, prior to SantExpo, an agora was held on the theme: “Being Cyber Resilient: The Main Challenge for Healthcare Facilities. How to Achieve It?” Many solutions were proposed, but one element emerged as a central topic of discussion: the concept of a managed SOC (Security Operations Center).
Increasingly Direct and Rapid Attacks
In 2022, the overall threat level remained stable. Healthcare facilities now represent 10% of ransomware attack victims, compared to 7% in 2021 (ANSSI cyber threat report). Over the years, the risk has only increased. Attack vectors are multiplying. Gone are the days when we only had to deal with simple viruses spread via USB drives. The development of the IoT, in particular, has created vulnerabilities in systems and thus increased the risks. “The standard has always been to protect workstations,” explains Jérôme Lanniaux, Sales Director at BECYCURE, a cybersecurity specialist. “But IoT devices (such as probes, biomedical equipment, etc.) haven’t received the same level of attention, even though an intrusion on these devices can have serious consequences: • a surgical robot could be diverted from its trajectory, • a medical device might not deliver the correct dosage for treatment, • video surveillance could be disabled.”
Added to this is another difficulty: the fact that methods of operation are also evolving. Previously focused on finding valuable data, intrusions could last several days (or even several months) to collect and extract as much data as possible and encrypt backups. “Now we’re dealing with cybercriminals whose sole aim is to cause harm,” continues Jérôme Lanniaux. “These attacks are much faster, and we often only have a few hours to react.” With such a situation, appropriate tools are essential. Regulations are pushing in this direction. “NIS II (Network and Information Security) Directive, requirements of the Ségur du Numérique (a French government initiative to improve digital infrastructure), a new framework for health data hosting providers, the proposed Cyber Resilience Act… Regulations of all kinds are pouring in, and the level of maturity is progressing very rapidly,” explains Marguerite Brac de la Pierrière, a lawyer specializing in cybersecurity, IT, and health data.
Prevention is key
In this context, what exactly is cyber resilience? Cyber resilience is the ability of an information system to withstand cyberattacks and accidental failures, and then return to a satisfactory state of operation and security. “In the healthcare sector, this translates into the ability to care for patients in the event of cyberattacks,” explains Paul Milon, Deputy Director in charge of converged IT at the Var Hospital Group and CIO of the Toulon and Hyères Hospital Centers. “Increasing our cyber resilience means increasing the continuity of our service.” Xavier Stoppini, CISO of the Alpes-Maritimes Territorial Hospital Group (GHT 06), adds: “It also means the ability to limit data loss and maintain the operational readiness of our services.” To achieve this, prevention is the foundation of protection. Several steps must be validated: releasing budgets, assessing the maturity level of systems, establishing remediation plans, implementing a security assurance plan within institutions, applicable to service providers and software publishers, establishing a maintenance contract and making it an essential component, just like the GDPR contract… “The remediation plan and the attention given to its implementation are what can prevent the attacker from taking action and will make them look the other way,” explains Xavier Stoppini. Prevention also involves setting up a SOC (Security Operations System). Firewalls filter most intrusion attempts but let some weak signals through. It’s about analyzing the “background noise” to continuously detect anything out of the ordinary. “With attacks becoming increasingly rapid, it’s essential to have 24/7 monitoring,” observes Paul Milon. “But we don’t have the staff for that.” Hence the need for a managed SOC (an outsourced SOC provided by a specialized cybersecurity partner), which, according to Xavier Stoppini, offers “more nuanced knowledge.” And that’s where BECYCURE comes in. “Our role is, initially, to offer institutions tools adapted to threat detection: EDR, SIEM, NDR (network probe), vulnerability scanner,” explains Jérôme Lanniaux. “The SOC tools implemented then aim to monitor and analyze the information system, connected devices, and biomedical equipment to alert them in case of abnormal behavior. Then, on a routine basis, experts are available to institutions to process, analyze, and investigate cybersecurity alerts.” “At this level,” adds Xavier Stoppini, “the challenge is to contextualize the alerts within the targeted scope. These experts, thanks to their skills and intuition, are able to determine whether the anomaly is real or not, based on the habits and practices in place within each organization.” “This managed service respects the client’s existing tools. We don’t sell services in a black box,” the sales representative emphasizes. “Our client retains ownership of their products and data, and we complement their needs.” “Before implementing a SOC, preliminary work to identify the attack surface and harden existing systems is essential. The SOC and SOAR (Security Orchestration, Automation, and Response) represent the permanent prevention and remediation mechanisms that operate continuously. This is the promise we make within the teams led by Fabien SWIERGIEL, our SCC Hyperscale Director,” underlines Agnès SAUTEL, Director of the SCC France Healthcare Division.
Protection across multiple areas
This protection, based on human capabilities, is also, of course, fueled by machine learning, just like cybercriminals. “Attackers will constantly seek to be more creative in their attacks,” laments the BECYCURE specialist. It is therefore up to us to understand which paths he might take so that we, in turn, can be creative and thwart his plans.” The training aspect must not be neglected. From management levels to industrial positions, all staff must be trained. “On the technological side, I am not worried,” affirms Frédéric Avalet, Purchasing Director of GRADeS PACA, “there is a lot of expertise to properly protect systems. On the other hand, it is the training of end-user operators that can create vulnerabilities. That is why continuous training is absolutely essential to stay abreast of new threats.” In summary, according to Xavier Stoppini, here are the main recommendations regarding cyber resilience. “The first step is to set up a clearly identified information security team that will be integrated with the systems and backup teams. Then, vulnerabilities must be managed through continuous security audits of all servers, workstations, and any device connected to the network.” Establishing a dedicated backup sanctuary and hardening the Active Directory are also essential. Finally, teams must plan for a backup site available in case of an attack beyond the scope of the Disaster Recovery Plan (DRP) and raise staff awareness of cybersecurity vigilance. This is the key to improving cyber resilience in healthcare and enabling the continued shift to paperless processes, while guaranteeing optimal security.
[pdf-embedder url=“https://www.sih-solutions.fr/wp-content/uploads/2023/06/magazine-6667-2-copy.pdf” title=“SIH solutions Magazine”]