New guidance from the Cybersecurity and Infrastructure Security Agency encourages healthcare organizations to consider internal network and internet facing cyber decoys as a practical way to strengthen cyber defenses and improve early threat detection. Realistic fake assets, such as files, accounts and credentials, can help security teams identify malicious activity quickly while generating fewer false alarms than traditional monitoring tools.

For hospitals facing increasing ransomware risks and persistent workforce constraints, cyber decoys offer a potentially cost-effective layer of protection. Any activity from the decoys will signal possible compromise. According to CISA, these techniques can reduce the time needed to detect intrusions, improve the use of limited cybersecurity resources, and provide valuable insight into attacker behavior.

The guidance also notes that cyber decoys align well with modern Zero Trust security strategies, which assume that attackers may eventually gain some level of network access. The cyber decoys are not a replacement for existing security controls, but they may provide an affordable and scalable way to improve cyber resilience. Community hospitals and regional health systems, in particular, could benefit from deploying high-confidence tripwires around electronic health records, financial systems, administrative accounts and other high-value assets, CISA notes.

For more information on this and other cyber and risk issues, contact John Riggi, AHA national advisor for cybersecurity and risk, at jriggi@aha.org, or Scott Gee, AHA deputy national advisor for cybersecurity and risk, at sgee@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity.

Headline
The National Security Agency Oct. 8 released guidance for critical infrastructure organizations that recommends adopting high-impact zero trust strategies to…
Headline
The FBI and Secret Service released an advisory Oct. 6 warning of ongoing activities by FortiBleed, a global credential-compromise campaign used by threat…
Headline
In a new blog, John Riggi, AHA national advisor for cybersecurity and risk, and Scott Gee, AHA deputy national advisor for cybersecurity and risk, highlight…
Headline
The Senate passed the Health Care Cybersecurity and Resilience Act on Sept. 30 by unanimous consent. The bipartisan bill seeks to improve coordination between…
Headline
The AHA provided comments Sept. 30 to the Senate Homeland Security and Governmental Affairs Subcommittee on Disaster Management, District of Columbia and…
AHA Cyber Intel
While we may feel inundated with alarming news about escalating cyber threats against healthcare organizations, there is also some good news. Let’s explore how…