Claroty, the cyber-physical systems protection company, announced the release of the Global Healthcare Cybersecurity Study 2023, a survey of 1,100 cybersecurity, engineering, IT, and networking professionals from healthcare organisations.

The study explores their experience with cybersecurity incidents over the past year, the state of their security programmes, and future priorities.

Myriad cybersecurity challenges

The survey’s findings show that healthcare organisations are facing myriad cybersecurity challenges that require them to increasingly prioritise cybersecurity and compliance. According to the study:

  • 78% of respondents experienced a minimum of one cybersecurity incident over the last year.
  • 47% cited at least one incident that affected cyber-physical systems such as medical devices and building management systems.
  • 30% cited that sensitive data like protected health information (PHI) was affected.
  • More than 60% reported that incidents caused a moderate or substantial impact on care delivery, and another 15% reported a severe impact that compromised patient health and/or safety.

Noteworthy financial implication

Another noteworthy financial implication, more than a third of experiencing incidents in the past year

Surprisingly, of the respondents who were victims of ransomware attacks, more than a quarter made ransom payments. Another noteworthy financial implication, more than a third of experiencing incidents in the past year incurred costs from the attack of more than $1 million.

The healthcare industry has a lot working against it on the cybersecurity front—a rapidly expanding attack surface, outdated legacy technology, budget constraints and a global cyber talent shortage,” said Yaniv Vardi, CEO of Claroty. “Our research shows that healthcare organisations need the full support of the cyber industry and regulatory bodies in order to defend medical devices from mounting threats and protect patient safety.”

Standards and regulations of cybersecurity

Additional findings show that increased standards and regulations fuel stronger cybersecurity, but there’s more work to be done:

  • Nearly 30% say current government policies and regulations require improvement or do nothing to prevent threats.
  • NIST (38%) and HITRUST Cybersecurity Frameworks (38%) were selected by most respondents as important to their organisations.
  • 44% cite regulatory developments such as mandated incident reporting as the most influential external factor to an organisation’s overall security strategy.

Cyber skills shortage

The study also found that the cyber skills shortage is still a top challenge: 

  • More than 70% of healthcare organisations are looking to hire in cybersecurity roles.
  • 80% of those hiring say it’s difficult to find qualified candidates who have the skills and experience required to properly manage a healthcare network’s cybersecurity.

Methodology

Claroty contracted with Pollfish to conduct a survey of healthcare providers, healthcare delivery organisations (HDOs), hospitals, and clinics in North America (500), South America (100), APAC (250), and Europe (250). Only individuals who work full-time in cybersecurity, clinical engineering, biomedical engineering, information systems, risk, or networking completed the survey, for a total of 1,100 respondents.

Respondents work for organisations with a minimum of 25 beds to over 500 beds, with the largest group (45%) working for organisations with 100 to 500 beds. The survey focuses on the period of June 2022–June 2023 and was completed in July 2023.

Stay ahead in the era of intelligent security systems powered by Artificial Intelligence with our special e-magazine on AI in security.

In case you missed it

How can physical security systems make schools safer?
How can physical security systems make schools safer?

Students deserve a safe and positive environment where they can learn and thrive. Teachers and administrators should be able to focus on their primary role of educating students be...

DNAKE smart intercom elevates Dickensa 27 security
DNAKE smart intercom elevates Dickensa 27 security

Dickensa 27, a modern residential complex in Warsaw, Poland, sought to enhance its security, communication, and convenience for residents through advanced intercom solutions. ...

Anviz transforms traditional property management into a smart reality, making digitisation more than just talk
Anviz transforms traditional property management into a smart reality, making digitisation more than just talk

The Middle East has recently expanded its real estate market as the region's economy grows and urbanisation accelerates. This trend has led to an increasing demand for smart securi...

Quick poll
How likely is it that companies will invest in cloud-based physical security solutions in the next 5 years?