enterprisesecuritymag

How Do Healthcare CIOs Address IIoT Threats?

Enterprise Security Magazine | Friday, October 04, 2019

IIoT has enormous potential to transform the healthcare industry, although it is surrounded by threats in different forms and has to be addressed adequately.

Fremont, CA: The necessity to save human lives elevates beyond limits with the onset of new diseases. This urge is driving technologies to develop groundbreaking innovations in the delivery of state-of-the-art treatment services. Like in many other sectors, the industrial internet of things (IIoT) has rapidly transformed the work and data infrastructure in health and medicine. IIoT enables easy access to medical data and information, thus making remote monitoring of patients seamless. IIoT has vast potential, especially in healthcare, to connect to the internet enabling ordinary medical equipment to collect and share essential data that gives healthcare providers and medical practitioners more significant insights into symptoms and treatment trends.

However, healthcare stakeholders should understand that IIoT adoption is prone to massive threats. Here's how CIOs address the associated IIoT threats in different healthcare areas to.

Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.

Medical Devices

There are many medical devices, each performing specific functions such as infusion pumps, anesthesia machines, dialysis machines, and respiratory ventilators, primarily used to monitor the patient’s vital signs. Updated versions of these devices can be connected to the internet allowing these devices to be linked wirelessly to remote areas and transfer collected information, such as the amount of medication a patient has taken to hospital information system (HIS). These medical devices can be attacked for patient information leading to inaccurate readings that can harm them under care. Researchers have uncovered a recent vulnerability in a brand of anesthesia machine, which could allow an attacker to remotely modify equipment parameters such as altering the composition of aspired gases that can put the patient at risk.

It is the responsibility of the manufacturers, distributors, and healthcare facilities to ensure that these devices remain safe for use. Stakeholders should be aware of impending threats and vulnerabilities so that they can be agile in mitigating possible risks. Government agencies like US food and drug administration (FDA) and the Department of Homeland Security to offer guidance through some medical device safety action plan. These plans can help mitigate the risks brought about by oversights in device safety and bring stakeholders together in addressing the oversights. Also, healthcare facilities can use virtual patching to manage vulnerabilities.

Hospital Information System (HIS)

Patient care does not only involve medical but also administrative, financial, and legal aspects. The associated information is integrated and maintained on a single platform, the Hospital Information System (HIS). This information includes medical history, legal, and others needed in a hospital’s daily operation. Thus safeguarding the integrity of such information is vital because of the critical information it holds. HIS presents a crucial target for any potential cybercriminal, such as personally identifiable information (PII) for patients, and it can be used for extortion. Further, HIS is susceptible to threats that include distributed denial of service (DDoS), ransomware, phishing attacks, and other threats from malicious actors. These malicious actors can manipulate data, steal information, and disrupt the hospital’s reputation.

Securing an HIS depends on network security. Splitting a network into sub-networks, a process called network segmentation, can reduce the risk of lateral movement. Encryption software also helps mitigate the consequences of data theft and loss.

Healthcare Systems Software

Medical institutions need software to control several systems they use to run and transfer information within institutions that hold the control for critical functions or information like patients’ PII. Even a slight exposure of the interface of such systems is a danger because a recent study revealed that among the exposed systems were software for record maintenance, pharmacy management, and patient scheduling. Even though the number of exposed medical systems is small, they contain valuable information that can be infected by potential attackers using ransomware. Also, the attackers gain access to other devices by using the compromised software as an entry point.

Medical institutions should ensure these software systems are not exposed online by preventing using careful configuration of these devices and systems, most importantly, those that contain PII of both patients and hospital staff.

Legacy Systems

It is evident that many medical institutions use legacy systems despite employing IoT devices in their facilities. They find it miserable to replace their legacy systems leading to extensive downtime that is impossible in a healthcare facility. But this puts them with severe consequences and danger. If medical institutions do not opt to replace their legacy systems, they should find some alternatives to strengthen their defenses through application security architecture. Employing solutions like virtual patching can mitigate the vulnerabilities that legacy systems face.

Wearables and Portable Medical Equipment

Wearables are mostly used by patients who have just been discharged from the hospital, and they are monitored continuously through IoT remote devices. These wearables provide necessary, real-time information, including heart rate, sleep duration, and blood pressure that are help users make healthier decisions. For example, glucose monitors periodically take blood samples to alert diabetic patients to take insulin, and heart rate monitors signal the onset of heart attack or stroke. However, these devices are also prone to risks. FDA has recently issued a warning against a specific brand of insulin pumps that replace pancreas functioning by releasing insulin and keeping the blood sugar levels within range. Attackers can send radiofrequency and change the nearby pumps’ setting. In such cases, the insulin pumps have to be replaced. These devices work remotely, and attacks on these devices could result in life-threatening situations.

Such portable devices that patients bring home or wear illustrate how users and patients share the responsibility of securing these devices. Patients who use such devices have to be careful in sharing the information about their devices by physically securing these devices and keeping it close to the user.

Other IoT applications

RFID technology, an IoT component can help hospital staff to quickly locate and identify equipment that will be used to treat a patient. Although they do not have direct effects on adding medical value, they ease the burden of staff while enhancing their focus on patients. However, integrators should map and manage their connected devices because they are the entry points for bigger targets. Deploying virtual fencing features will disable the devices when they are out of range.

IoT in healthcare has not attained full maturity and is still brimming with possibilities. Healthcare stakeholders must first understand the dangers IoT brings to the field when haphazardly implemented that could cause cascading problems to a broader community and take effective measures to secure it. 

See Also: Top Healthcare Technology Companies

More in News

Multi-factor authentication solutions have become a central part of enterprise security as organizations face growing pressure to protect users, applications and sensitive data from credential-based attacks. Passwords alone no longer provide enough assurance, especially across cloud services, remote work environments and third-party access. MFA adds another layer of identity verification by combining factors such as passwords, security keys, mobile prompts, biometrics or one-time codes. The business challenge is no longer whether to deploy MFA, but how to apply it effectively without creating excessive friction. Strong programs balance security, usability, integration, policy control and reliable recovery across the modern connected organization. Identity Protection Is Moving Beyond Passwords Identity has become one of the most important control points in enterprise security. Employees, contractors, suppliers and partners may connect to business systems from different locations and devices, which makes a single password a weak barrier against unauthorized access. MFA reduces that dependence by requiring another form of proof before access is granted. The strongest deployments start with risk rather than technology. Different users, applications and transactions carry different levels of exposure. Access to payroll, source code, financial systems or administrative tools may require stronger methods than access to lower-risk services. Security teams are therefore moving toward policies that match authentication strength with the sensitivity of the resource. Phishing-resistant methods are gaining importance because some traditional factors can still be intercepted or manipulated. Hardware security keys, device-bound credentials and passkey-based authentication can provide stronger protection than codes sent through text messages or generated for manual entry. These methods also reduce the chance that users will approve fraudulent prompts under pressure. Adaptive authentication adds another layer of control. Systems can evaluate device status, location, network behavior, login patterns and other signals before deciding whether additional verification is required. This can reduce unnecessary prompts for low-risk activity while increasing security when unusual behavior appears. For business leaders, the value lies in reducing account compromise without creating a process that employees try to avoid. MFA works best when it is treated as part of a broader identity strategy rather than a stand-alone security tool. Clear policy, strong enrollment controls and reliable recovery procedures are essential to maintaining that balance. Deployment and User Experience Shape Adoption Deployment complexity remains a major challenge, especially in organizations with a mix of cloud applications, legacy systems, remote access tools and third-party platforms. Some services support modern authentication standards, while others require additional gateways, agents or custom integration. Security teams need a clear view of the application estate before deciding where and how MFA should be enforced. Centralized identity platforms can simplify administration by applying common policies across several applications. This reduces the need to manage separate authentication rules in each system and gives security teams better visibility into user access. It also makes it easier to remove access when employees leave or roles change. User experience has a direct effect on adoption. Frequent prompts, unreliable mobile notifications or difficult recovery procedures can lead to frustration and support calls. Poorly designed MFA can even encourage risky workarounds. Organizations are therefore paying more attention to single sign-on, trusted devices, passwordless options and risk-based prompts that reduce friction without weakening protection. Enrollment and recovery are particularly sensitive points. Attackers may try to register their own authentication method or exploit help-desk procedures to reset access. Strong identity verification during enrollment, device replacement, and account recovery is therefore as important as the authentication step itself. Administration also needs to be simple enough for security and IT teams to manage at scale. Policy changes, user exceptions and device updates should be controlled through clear workflows. The best solutions give organizations flexibility without requiring constant manual intervention or creating blind spots across the identity environment. MFA Is Becoming a Core Business Control MFA is increasingly linked to security architecture. Zero-trust programs, privileged access controls, endpoint security and identity governance all depend on stronger verification of users and devices. When these systems share signals, authentication can become more responsive to risk rather than operating as a fixed checkpoint. Integration with security monitoring is also becoming more valuable. Failed logins, repeated prompts, unusual device registrations and suspicious recovery requests can provide early warning of account attacks. Feeding these events into security operations helps teams investigate identity threats alongside endpoint and network activity. Business continuity is another important consideration. Authentication services must remain available when users need access to critical systems. Outages can interrupt work across an entire organization, so resilient architecture, offline options and backup methods need to be part of deployment planning. Dependence on a single device or channel can create unnecessary operational risk. Cost management is also shaping buying decisions. License fees are only one part of the investment. Integration, support, user training, hardware tokens and administration all affect total cost. Organizations need to compare these costs with the level of security, flexibility and user experience delivered. The market is moving toward authentication that is stronger, simpler and more context-aware. Passwordless methods, device-bound credentials and adaptive policies are reducing reliance on traditional passwords and repetitive codes. However, technology alone will not solve identity risk. Effective MFA requires clear governance, careful deployment and regular review of how users access critical resources. ...Read more
Facial recognition technology is not about matching a face to a stored picture anymore. Earlier systems had a time with changes in lighting, different facial expressions, aging or when the face was seen from a different angle. This made them less effective in real-life situations. AI helps facial recognition systems analyze features more accurately and can adapt to changing conditions, making decisions faster. AI-driven facial recognition is becoming very important in various areas. These include security, banking, healthcare, retail, transportation and getting into the workplace. The reason for this shift is that AI can handle lots of information. It keeps improving how well facial recognition works. Modern systems do not just compare fixed images, learn from patterns and get better at telling people apart. What Advancements Is AI Bringing to Facial Recognition? One big improvement with recognition is that it is really good at recognizing people. The computer programs that use intelligence can tell people apart even when they are wearing glasses or have a beard. It does not matter if they have a hairstyle or if the light is not very good. The computer can look at pictures fast and is helpful in places where people need to be identified. AI is changing recognition from a simple tool into a smart technology that helps with decisions. Modern systems are faster, more adaptable and better at operating in changing environments where accuracy and reliability matter. As AI gets better, facial recognition solutions will become more capable of delivering efficient and smooth identity verification. The organizations that benefit most will be those that combine innovation with implementation, ensuring both performance and trust are central to future adoption. How Is AI Expanding the Role of Facial Recognition? Integration with security platforms is becoming more common. Facial recognition systems are often used with access control, surveillance, visitor management and identity verification solutions to create security environments. Edge computing processes every image through central systems. AI-enabled devices can do facial recognition right on cameras or local hardware. It makes response times faster, improves efficiency and helps with decision-making. Developers are focusing on privacy and are adding encryption, secure identity management and technologies that protect sensitive biometric information while keeping system performance good. Using ways to authenticate is becoming more reliable for identity verification. AI combines recognition with other methods like voice recognition, behavioral analysis or mobile credentials. The approach makes security better. ...Read more
The interconnected world, which continues to expand, leads to ongoing changes in security systems for residential and commercial spaces because of technological developments and evolving user needs. Property owners now require protection through systems that enable monitoring and management of operational areas and all access points. This shift is guiding solution providers in their development of products that they will position against other items in the market. How are Integrated Systems Reshaping Security Investments? Modern investment choices depend increasingly on systems that provide two key capabilities; they must combine effortlessly with current systems while delivering future growth possibilities. Organizations now demand that their advanced surveillance systems work through a single platform, which enables them to manage everything from one location while producing data-driven insights. The integration process creates operational advantages for businesses because it streamlines their operations while delivering real-time security event monitoring capabilities. Commercial facilities and residential areas now spend money on solutions that have the capacity to grow with their operational needs without the need for complete system replacements. The development of vendor and service provider products now depends on their capacity to create systems that allow new elements to function together with already established components. What Factors are Influencing Long-Term Security Planning Decisions? The security planning process now operates through three main drivers, which include the need to comply with regulations, the process of evaluating risks and the rising importance of data security for physical security operations. Organizations assess solutions based on two factors, which are their immediate effectiveness and their capacity to meet compliance standards and handle new security threats. The implemented system promotes architectural investments, which provide flexible designs that enable system upgrades and direct remote operation and new technology connections without needing major funding. The significance of analytics has increased because stakeholders expect security data to deliver actionable insights rather than using those insights for post-event responses. Organizations use predictive capabilities that advanced processing methods produce to find and reduce all potential vulnerabilities before they develop into serious problems. The design process for systems now focuses on creating user-friendly interfaces that need minimal training while delivering faster emergency response times. The developments lead organizations to adopt security strategies, which connect their security spending with their organizational targets and their long-term asset protection plans. Authorized users now require systems that let them control everything from remote locations, to access systems that contain restricted areas. Multi-site operations require this capability because they need uniform security procedures that protect all locations from remote security access points, which safeguard every asset. Security evaluation and implementation processes in residential and commercial spaces now undergo transformation through the technological, policy-related, and user expectation-related changes that converge into three main areas. The ability to adjust systems throughout their operational life serves as the core element that enables sustained system operation and extended system durability. ...Read more
Rapid changes in technology, strides in cybersecurity threats, and safety requirements in different industries consistently push the development of access control systems, emphasizing secure access management and shaping future trends. Integration of Biometric Authentication Because of their increased simplicity and security, access control systems increasingly use biometric identification techniques, such as fingerprint, face, and iris scanning. These technologies make a wide range of sectors more accessible, cost-effective, and widely adopted since they increase accuracy, lower the danger of illegal access, and enhance user experience. Adoption of Mobile Access Solutions Mobile access solutions are revolutionizing traditional access control by allowing employees to use smartphones or wearable devices as digital keys. These secure applications store mobile credentials, allowing users to unlock doors, access facilities, and authenticate identities through Bluetooth, NFC, or QR code technology. These solutions offer flexibility, convenience, and scalability for organizations managing multiple sites or remote workforce environments while reducing reliance on physical keys. Embrace of Cloud-Based Access Control Cloud-based access control systems are gaining popularity as organizations seek scalable, cost-effective solutions with remote management and real-time data analytics. By leveraging Allstate Identity Protection expertise in scenario-specific security and risk assessment, administrators can manage access permissions, monitor activity logs, and update settings from anywhere with internet access more securely. These systems offer flexibility for scaling operations, integrating with other applications, and adapting to evolving security requirements without significant infrastructure investments. Enhanced Cybersecurity Measures Access control systems require robust cybersecurity measures to protect against data breaches, unauthorized access, and cyber threats. Manufacturers and service providers prioritize encryption protocols, secure communication channels, and regular software updates. Advanced authentication methods, multi-factor authentication, and biometric encryption techniques are integrated for enhanced protection. Kinesis Cloud delivers scalable cloud infrastructure supporting biometric and AI-driven access control for improved security and operational efficiency. Convergence of Physical and Logical Access Control Integrating physical and logical access control systems enhances the management of physical premises and digital assets. Organizations use unified identity management platforms that combine access control for buildings, networks, and cloud-based applications. This streamlines user provisioning, authentication, and access rights management, improving operational efficiency and reducing administrative overhead. Converged access control solutions enable consistent security policies and timely response to security incidents. Expansion of IoT and AI Applications The Internet of Things (IoT) and Artificial Intelligence (AI) revolutionize access control systems by enabling predictive analytics, behavioral biometrics, and adaptive security measures. IoT-connected devices like smart locks and surveillance cameras provide real-time data insights, automate responses, and optimize resource allocation. AI algorithms analyze vast datasets to detect anomalies, predict security threats, and enhance decision-making. These technologies enable organizations to manage security risks, improve operational efficiency, and deliver personalized user experiences. ...Read more