2024年医疗保健行业网络安全调查(英)_35页_6mb
报告摘要
2024 HIMSS Healthcare Cybersecurity Survey Summary
Key Findings Overview
- Cybersecurity Budgets: Organizations are allocating more resources to cybersecurity, with modest improvements expected in IT budgets for 2025. Budget allocations are shifting toward moderate levels, but awareness of spending details is lacking in many organizations.
- Security Awareness: Training programs focus on phishing and attack simulation, but effectiveness is limited in addressing emerging threats. Awareness initiatives are increasing due to phishing's dominance.
- Security Incidents: Phishing remains the top initial point of compromise for attacks. AI-driven threats like deepfakes are emerging, highlighting vulnerabilities in defenses.
- Ransomware: Fewer ransom payments are reported, but attacks persist. Organizations are prioritizing ransomware defense, with trends showing a shift from reactive to proactive measures.
- AI Adoption: AI is widely used in healthcare for tasks like diagnostics, data analytics, and automation, but governance is insufficient. Key concerns include data privacy, bias, security risks, and lack of transparency.
- Third-Party and Insider Threats: Third-party security incidents are significant, causing disruptions and financial losses. Insider threat programs are underdeveloped, and AI and external access introduce new risks.
Recommendations
- Strengthen cybersecurity budget planning and transparency.
- Enhance security awareness training to cover evolving threats.
- Improve incident response and preparedness through regular tabletop exercises.
- Implement robust AI governance and monitoring to mitigate risks.
- Expand third-party risk management and insider threat programs to enhance resilience.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载