Health care continues to be a top target for cybersecurity attackers, yet most organizations continue to rely on legacy software and access management policies stitched together in an ad hoc manner. By attempting to use yesterday’s tools to meet today’s challenges, organizations are unnecessarily putting themselves at risk and making it all too easy for attackers to access what they want when they want it.
Adopting a zero-trust approach lets organizations set firm policies about what a user, device, or application can access, and it requires authentication for each session. Zero-trust network access (ZTNA) goes a step further and applies this approach across the enterprise network. This strengthens data and application protections while minimizing risk, and it supports a broader strategy of converging network and security capabilities.
Yesterday’s products don’t meet today’s challengesEvery health care executive understands the grave cybersecurity risks facing the industry. From Change Healthcare and Ascension this year, to HCA Healthcare and Anthem of years past, countless organizations have been hit with cybersecurity attacks that compromised patient records, brought operations to a standstill, and hit the bottom line.
Unfortunately, far too many health care organizations continue to use outdated software tools and security strategies to address ever-changing risks. Consider the following:
● Ad hoc network connectivity practices persist among disparate business units. This lack of consistency makes networks difficult to manage effectively and all too often resource-strapped teams opt for whatever option creates the least friction.
● Similarly, organizations maintain a range of threat monitoring tools implemented on an ad hoc basis. For these legacy products, even functionality as basic as filtering requires manual updates, but skipping updates because they take too long only leaves organizations more vulnerable.
● Firewalls create a walled garden around enterprise assets that stops external traffic, but they don’t restrict lateral movement across a network once access has been granted. Once an attacker gets in, little is off-limits.
● As an ever-increasing volume of health care data is generated beyond hospital walls, organizations must maintain network access for contractors, vendors, and even patients in addition to employed staff. This requires managing many roles, and it can quickly get out of hand.
As if these challenges weren’t enough, ongoing financial pressures have left many organizations with limited financial resources. IT teams are being asked to do more with less, often keeping legacy solutions in place even if they don’t meet today’s security challenges or put the enterprise at risk. In this environment, organizations must approach access management with increased vigilance.
Zero trust: A paradigm shift for accessing critical resourcesForward-thinking organizations are providing this vigilance by leveraging ZTNA across the health care enterprise, from the large hospital to the community clinic to the visiting nurse. As the name implies, this strategy relies on zero trust security: the “never trust, always verify” approach to access management.
The zero-trust approach emerged as an antidote to the pitfalls of assuming that any user or device granted access to a firewall is legitimate and trustworthy. Under that assumption, anyone behind the firewall could easily move laterally through an organization and gain nearly unfettered access to mission-critical applications and information. Attackers could get what they wanted in little time with little difficulty.
As outlined below, zero trust has four general principles. In a nutshell, zero trust authenticates the identification of a user, application, or device; enforces the appropriate policies for that ID; and allows or denies access only to resources that specific ID is authorized to access.
The four principles of zero-trust security Identity-centric Issue one ID for every entity in the IT environment. This single ID is used throughout all IT infrastructure and cannot be duplicated or shared. Strong authentication Verify the ID of users as well as applications and devices. This is a critical step in a hospital where each room may have more than 10 connected devices and clinical apps often request records from each other. Least privilege access Grant permissions for users, apps, and devices that are limited to what’s required for their role. This limits the blast radius if an account is compromised. Continuous verification Assess access requests based on permissions and privileges and approve access for only the duration of a single session. This makes it more difficult for an attacker to hijack an abandoned session. Extend zero trust across the enterprise networkZTNA takes the core principles of zero trust and extends them from individual resources or assets to an enterprise’s network. ZTNA is especially effective for health care organizations because it recognizes three important ways the perimeter of the physical network no longer exists:
● Users, applications, and devices are far from the hospital campus. They’re increasingly based in external partner clinics, research facilities, digital health apps, and even patients’ homes. Because authorized access means better patient care, organizations need a robust strategy to broadly manage identity and access.
● Applications are moving to the cloud due to its flexibility, scalability, and potential to reduce IT costs. As organizations make the most of the cloud and locate resources with multiple service providers, it’s imperative to think beyond the traditional firewall when it comes to granting access.
● Technology vendors and contractors increasingly play a critical role in managing IT services or delivering care. Additionally, permissions and privileges for non-staff frequently change depending on factors such as the terms of a contract or the business unit being supported. Here, maintaining manual access management policies quickly becomes a headache.
ZTNA offers several benefits to network security when compared to the outdated approach of assuming implicit trust:
● microsegmentation. Instead of installing a physical perimeter around an entire network, organizations may establish a software-defined perimeter around smaller, more critical parts of a network. A hospital may do this for remote monitoring devices in the intensive care unit, which share vital information with clinical applications in real time.
● Replace the legacy VPN. The VPN authorizes access based on a single username and password, which is inadequate in today’s security environment. A VPN also routes traffic to its own server before routing it to the cloud, which is likewise inadequate for modern infrastructure. ZTNA provides scalability, low-latency connectivity, and strong access controls.
● Minimize risk. Restricting access based on privilege and permission limits the damage a compromised account can cause. An attacker won’t be able to move laterally throughout a network, nor will they be able to request additional privileges without authorization.
● Protect internal applications. Requiring approval for access requests with each log-in attempt means applications are unavailable over the public internet. This keeps critical clinical and financial information off the internet, which protects organizations from the data leaks that make headlines and result in fines.
● Provide secure cloud access. Since each user, application, or device entity has a clearly defined role with specific permissions, access to cloud environments can be restricted. Entities also lack the authority to change cloud configurations, which is an all-too-common attack vector for cloud services.
● Support compliance. Zero-trust principles align with regulatory requirements and industry standards for health care organizations to verify that only authorized users can access applications containing patient data. With ZTNA in place, organizations can be confident that their access management approach will comply with the provisions of Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry Data Security Standard (Payment Card Industry (payment card industry (PCI))), and General Data Protection Regulation (GDPR).
SASE and zero trust: A winning combination for health careAs valuable as ZTNA can be on its own, it’s even more powerful when it’s managed as part of a larger secure access service edge (SASE). SASE converges both network and security capabilities as cloud-native services, as it recognizes that most organizations now choose to locate users, applications, and devices outside their physical walls.
There are two important reasons that ZTNA is more powerful when it’s under the SASE umbrella. The first is the ability to couple zero trust with other leading threat prevention services. These typically include the following:
● A cloud access security broker (CASB) to monitor activity and enforce security policies.
● Next-generation anti-malware (NGAM) tools to protect data in transit.
● data loss prevention (DLP) software to prevent data from breach as well as destruction.
● Software-defined, cloud-based firewall-as-a-service (FWaaS) products to filter traffic.
The second benefit is the potential to layer on network and performance monitoring tools to ensure high availability. This is a vital need for health care organizations that can ill-afford network downtime. Real-time monitoring helps organizations identify traffic bottlenecks or other issues before they escalate to the point that clinical operations may be compromised.
Comments