I Know What You Did Last...

Preview:

Citation preview

Threat Landscape

• Hackers• Cyber Crime Syndicates

• Malware Mercenaries

• Insiders• Clinical Staff

• Physicians

• Administrative/Support Staff

Attack Vectors

• External• Social Engineering

• Phishing

• Impersonation

• Vulnerable Systems

• Internal• Web Browsing

• Downloads

• External Media

Mitigation: Threat Intel

• Infragard

• US-CERT

• National Health • Information Sharing Analysis Center (NH-ISAC)

• Anti-Malware/ Security Vendors

Mitigation: Vulnerability Management

• Vulnerability Management Program• Routine Scans• Risk Assessment• Segregation

• Patch Management Program• Applicability• Understand Risk• Metrics

• Time to remediate• Remediation Percentage

Recommended