CISA’s new ransomware vulnerability notification program

The Cybersecurity and Infrastructure Security Agency leverages multiple open-source and internal tools to proactively research and detect vulnerabilities within U.S. critical infrastructure as part of its new Ransomware Vulnerability Warning Pilot, which started on January 30.

WHY IT MATTERS

On Monday, CISA announced the creation of its RVWP program required by the Cyber Incident Reporting for Critical Infrastructure Act of 2022.

CISA says it can accomplish ransomware-vulnerability warning by leveraging its existing services, data sources, technologies and authorities, including the agency’s Cyber Hygiene Vulnerability Scanning service and its Administrative Subpoena Authority granted under Section 2209 of the Homeland Security Act of 2002, according to theFAQon its website.

“Organizations across all sectors and of all sizes are too frequently impacted by damaging ransomware incidents,” CISA said in the new FAQ.

Most organizations may be unaware that a vulnerability used by ransomware threat actors is present on their network. But damaging intrusions could be avoided by warning critical infrastructure entities, like hospitals and healthcare systems, of detected security vulnerabilities.

Once CISA identifies affected systems, regional cybersecurity personnel notify system owners.

CISA also offers no-cost cybersecurity resources and tools. It recommends that organizations sign up for its no-cost Cyber Hygiene Vulnerability Scanning service and take a self-assessment to determine progress in implementing cybersecurity performance goals.

By building a relationship with a regional CISA cybersecurity advisor, healthcare organizations can participate in additional services, the agency added.

THE LARGER TREND

Toimprove the cybersecurity posture of healthcarethe Department of Health and Human Services has recommended enterprise-wide risk analyses and a series of best practices, including vulnerability scans of all systems and devices to reduce the risks of common cyberattacks.

Vulnerability management has been the most important part of cybersecurity for the past 20 years, according to Darren Lacey, vice president and CISO for Johns Hopkins University and Johns Hopkins Medicine.

“We chase down vulnerabilities and, in fact, if you had to say what was the biggest change in cybersecurity over the last 10 years along with the ransomware spike would be the number of publicized vulnerabilities,” he toldHealthcare IT Newsin September.

Ransomware attacks doubledbetween 2020 and 2022, and with cyberattacks getting more innovative in their approaches over time, it behooves all healthcare organizations to make use of all the cybersecurity services CISA, HHS and industry resources offer.

ON THE RECORD

“Many of these incidents are perpetrated by ransomware threat actors using known vulnerabilities,” CISA says in its new RVWP program FAQ. “By urgently fixing these vulnerabilities, organizations can significantly reduce their likelihood of experiencing a ransomware event.”

Andrea Fox is senior editor of Healthcare IT News.
Email:afox@himss.org

Healthcare IT News is a HIMSS Media publication.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Danish campaign targets knowledge about cooling of hot food thumbnail

Danish campaign targets knowledge about cooling of hot food

Most businesses correctly cool down hot food but some violations were found during inspections in Denmark. The Danish Veterinary and Food Administration (Fødevarestyrelsen) investigated whether shops, restaurants and caterers were in control of the refrigeration and cooling process and its management. Overall, 91 percent of the sites subject to unannounced visits knew how to cool…
Read More
Drug withdrawal morphs brain communication networks in mice thumbnail

Drug withdrawal morphs brain communication networks in mice

Artistic visualization of the decreased modularity and increased synchronization between brain regions during psychostimulant withdrawal (left hemisphere) compared to control mice (right hemisphere). Credit: Lauren Smith, UC San Diego Health Sciences Addictive psychostimulants, from nicotine in cigarettes to illicit drugs like methamphetamine and cocaine, affect different regions of the brain. The same is believed true…
Read More
Amazon taps former head of Prime to lead health efforts thumbnail

Amazon taps former head of Prime to lead health efforts

Amazon has appointed Neil Lindsay, who formerly oversaw the tech giant's Prime and Marketing vertical, to lead the company's health efforts. As CNBC reported this week, Lindsay's LinkedIn profile now lists him as senior vice president of health and brand as part of the company's worldwide consumer business.   Sources familiar with the situation said…
Read More
Antidepressants versus running for depression: Is there a winner? thumbnail

Antidepressants versus running for depression: Is there a winner?

Credit: Pixabay/CC0 Public Domain The first study to compare effects of antidepressants with running exercises for anxiety, depression and overall health shows that they have about the same benefits for mental health—but a 16-week course of running over the same period scores higher in terms of physical health improvement, whereas antidepressants lead to a slightly
Read More
Former Amazon medical officer examines Surgeon General's clinician burnout warning thumbnail

Former Amazon medical officer examines Surgeon General’s clinician burnout warning

The U.S. surgeon general's recent advisory about clinician burnout cited numerous societal, cultural, structural and organizational causes – including excessive workloads, administrative burden and lack of organizational support. The potential fallout of this trajectory is alarming: The advisory cites the Association of American Medical Colleges' estimate on clinician demand outpacing supply, with an anticipated shortage of between
Read More
Index Of News
Total
0
Share