Semperis’s Marty Momdjian on Handling Ransomware in Healthcare

Transcription

hi I'm James Maguire and on today's webcast we're talking about ransomware attacks on hospitals we're taking a look at what's going on with this concerning Trend and how hospitals can best handle these attacks to discuss that I'm joined by someone who knows a lot about the topic with me is Marty Momin Executive Vice President and general manager of seus Marty absolutely thrilled to have you with us today thanks James I'm happy to be here so so let's do a sort of a nutshell portrait of seus obviously a lot of people know about the company already but for those who aren't as familiar how does seus serve its clients uh we're essentially a nutshell active directory in identity security and resilience company our main focus is protect active directory protect Cloud identities and make sure customers are resilient able to recover and that they have a good Premier security solution in place for it that there's certainly a market for no no doubt and I would even say an urgent Market um speaking of which we hear that hospitals are considered an easy target for ransomware actors that's really bad news if all the organizations you would wish would be left alone uh by malicious actors it would be it would be hospitals and health organizations so so why is this true yeah I mean I wouldn't say it's just everybody's kind of an easy target right what what's unique about Healthcare and hospitals is it's critical infrastructure right it's the severity of impact is very very high so when adversaries threat actors uh State uh nation sponsored Bad actors when they target Healthcare organizations uh they know the damage can be very severe and they know the impact can be very severe and they know that Healthcare organizations can get backed into the corner to pay their Ransom and I I think why they you know we coin it as an easy target it's it's not that they're easy their it systems are extremely complex right they're extremely complex there's a lot of Legacy systems vulnerabilities are harder to manage there's a lot of iot devices there's a lot of points of entry into Healthcare organizations and that's where really they become an easy target right it's just heavy Reliance on technology at the end of the day and their environment are super complex one Interruption sorry you talking about the Legacy I I would guess that maybe the the the healthcare it infrastructure might be a bit more Legacy some than some other organization other sectors and that it's it's so expensive to upgrade the it so it's maybe some of that the infrastructure is lagging a bit in healthcare it perhaps it is it is and it isn't right what if you look at Healthcare I've been in healthcare almost 20 years now okay and we we spent billions of dollars if not more on modernizing Healthcare it infrastructure on the EMR right let's engage the patients where they are the pandemic happened we spent even more money on technology for remote care remote access really what's become Legacy see is in healthcare the technology that's implemented has to work and operations wise the EMR the modern EMR does a very very good job at being a medical record system right at a clinical access system at a patient access system what they don't do really that well is the security aspect of it and now that's where it's become extremely complex of you know what's new now is Legacy in five years but if it's still working very well why spend more money on trying to modernize it again of course of course well I I guess the other part of this is you know so do hospitals tend to pay ransomware more frequently than other organization other sectors um in some sectors yes right if you look at our ransomware risk report we went out and did a survey of hundreds of organizations and what stood out was number one on that list was the finance industry and out of the you know survey that we did 78% of companies in average that got hit by ransomware paid some kind of Ransom whether it was the initial ransom for decryption uh secondary extortion right for data theft Data Destruction or denial of service attacks if you look at specific Industries um this was kind of a shocking result to us because of our customer base is so big in the healthc care side and we always see it on the news right it's 72% paid multiple ransoms of any industry with specific Industries the highest was 85% at travel and transportation companies uh and then Finance Finance was interesting at 80% Telecom 79% and Healthcare was actually at 66% which was on the lower side but when it came to double extortion it was actually at 79% right and I'm sorry 76% but higher yeah double extortion hits Healthcare significantly and the amount of Ransom paid by Healthcare is actually higher than other Industries at the end of the day because hospitals have to operate right after a certain amount of time somebody has to make the decision you know they shouldn't but is it do you have to pay the ransom to get back online or can you take another week or two to recover right and and the answer is they they can't in many cases and I think one of the is I would guess one one of the issues there is that um hospitals OB obviously have all that exceptionally sensitive information patient information so they can't they can't let that be compromise if there's anything they can do is that play a role in it yeah I mean your P your patient information follows you everywhere right your health ID is there it it's if you look at what's really unique in healthcare is it's Children's Health number one on the list right their patient record for a 5-year-old a oneye old 17y old that's their record for life it follows them now with the modern EMR from one healthare system to another and that's where adversaries and threat actors and Bad actors can sell that information and then they target the healthc care organization's consumer because their identity and their patient record is their patient record right that's where they commit fraud at the end of the day right and that's really becoming more and more problematic now and well known in the adversarial space well I guess then the big question is and you're you're so close to the market I mean that really I'm sure people want to hear what advice do you have for Hospital administrators that have been impacted by ransomware how should they handle it what what what are your thoughts it comes down to what everybody in the industry says right it's preparation I think what a lot of organization a lot of companies and people in cyber don't understand is unless you come from Healthcare you don't understand the complexity of how hard it is to do healthc care operations and then clinical operations and then it operations on top of that all of these have to work in harmony day-to-day just to get patient care done to get revenue cycle done right get patients in and out the door and literally deliver care to them I mean what I always tell them is like healthc Care organizations know their business better than anybody else right they know their patient care business they know their revenue cycle business they know how to access their patients they know how to get their clinicians to where they need to be and the best thing to do is keep doing simulations and tabletop exercises at the leadership and at a technical and tactical level muscle memory becomes very very important right a Really healthc Care Systems have to leverage what they have and they should also bring in external experts that are not health care experts but expert counsel from the cyber security side and the law side of the house and liability side leverage their cyber insurers right leverage their cyber security partners that have dealt with other um events happening in the ransomware space so we knowledge share with them and then what is really most important is everybody says people processing technology H having done incident response over and over a major Brees it's technology is as good as the people that manage it and the processes that are implemented right it becomes chaotic that's where muscle memory and practice really helps and they need to focus on the top three things we focus on during a actual incident it's get clinicians online get clinical systems online and patient management systems and then payroll revenue cycle and everything else so they should spend time to really understand what it takes to recover those systems in a sanitized state to continue business operations I guess I okay good that makes a lot of sense I want to make sure I'm showing the difference between it sounds like some of those ideas are what what happens if you are involved in the attack which is exactly what people want to know the other part of that seems to be how do you present how do you prevent it in this first place I guess so the question is what what what are best practices for improving operational resiliency I guess how do you how do you make it so it never happens in the first place it's inevitable it's going to happen any technology you implement is going to have some kind of vulnerability or flaw right that's what the adversaries are after you can spend all the money in the world on cyber security technology protecting your perimeter putting defense and depth into place something will fail right to to me where resiliency comes in is having a plan for when technology fails or has a vulnerability right people resiliency is number one on the list your technology can be resilient as you want but make sure again your people are resilient you have a backup plan for your people you have out of- band communication for them they have a process in place where people will get burned out when events happen and my number one rule is assume breach right is what I'm sorry assume the breach assume the bre in other words it's going to happen which seems sort of tragic in a sense but okay it makes sense yeah and that's what we as cpress tell all of our customers that's what we talk about in the industry it's at some point there's always an identity that is compromised there is a system that's compromised there's third party risk it's a lot for ciso to manage and best practice for me for operational resiliency is assume that you're always in a breach State and make resiliency part of your dat day-to-day operations so it's almost like um don't don't let your guard down you you always in the middle of a battle the battle never stops you've got to be battle ready at all all points it's there's something unfortunate about that but it seems very realistic yeah just because you bought technology is it implemented right is there care and feeding right are you retooling the technology when you need to do your people know how to use that technology are you upscaling them when you need to can you rely on your third parties when you need to I mean resiliency should be day-to-day operations not when you need it mhh well I if I look ahead to the future I I have this sort of optimistic maybe naive Vision that oh it's not going to be so bad in the future because we're going to realize that the Bad actors took advantage of this vulnerability and this vulnerability and this vulnerability now we've we've cured them we know that technology always has a flaw I think it's a really good point you make but that the flaws are so tiny and and they're harder to to breach now we're going to we're going to get to some place in the next few years where this is far less of a problem is that is that a realistic Vision or is that just way way too optimistic at this I think that's way too optimistic honestly the way I look at it think about how much technology we've embraced and implemented not just in healthcare everywhere the last 10 years yeah what technology are we going to implement now right the more technology we implement the more Reliance we have on that dayto day me as a patient and a consumer rely on it every single day right hospitals rely on it to improve operations and efficiency and we're just introducing more and more which means more complexity right I I would be optimistic if technology was becoming less complex and I'd be way more optimistic there right but now we just keep throwing more technology to solve the cyber security problem then we throw on more technology to solve the operational problem that cyber security causes for friction right it's it's a never ending now the Bad actors have access to the technology as well so well it's true and sometimes I I think you know since I cover the tech Market day in and day out I I am amazed at the complexity as you say it's like it is only getting more complicated I've talked to some of the most advanced professionals and they say to me oh no no it is it's it's far more complicated than it used to be sometimes I think we're going to collapse under the weight of our own complexity uh but but be that as it may I I guess um all right you you you made some really good points in closing anything you want to make sure you get said to to hospital administrators about Ransom where you you you really you said it but anything any closing comments my biggest thing is talk to each other right as Hospital administrators as the cyber security folks the technical leadership the Tactical practitioners in cyber security focus on continuous insident response and reach out to your peers in the industry talk to them right talk to organizations that have had events and just have open dialogue with them because what I've seen is we in cyber security and Healthcare share as much much as we can that we're allowed to and that's probably the most important tool in our tool belt that sounds like a really powerful tool that's a that's a great piece of advice uh Marty I think you said it uh thank you so much for sharing your expertise today and I hope you come back and and talk with us again sometime yeah definitely thank you James thank you for having me on

This transcript was generated automatically from the video's captions and may contain errors.

Written By
James Maguire
James Maguire
Published: Sep 19, 2024
Updated: Sep 27, 2024
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Hospitals are particularly vulnerable to ransomware attacks. Marty Momdjian, EVP and General Manager at Semperis, discussed how healthcare organizations can best handle the many difficult issues involved with ransomware.

 

James Maguire

James Maguire has been reporting on emerging technology for more than 15 years. He has won two ASBPE Awards of Excellence for in-depth feature articles about cloud computing and artificial intelligence. He has covered the gamut of enterprise and consumer technology, and regularly communicates with leading IT newsmakers, vendors and analysts.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.