2024年医疗保健行业网络安全调查_35页_4mb
报告摘要
2024 HIMSS Healthcare Cybersecurity Survey Summary
Core Content
The 2024 HIMSS Healthcare Cybersecurity Survey provides insights into the current and future state of cybersecurity in the healthcare sector, focusing on budget allocations, security awareness programs, incident response strategies, ransomware trends, and the adoption of artificial intelligence (AI).
Main Points
Cybersecurity Budgets
- Investments are increasing: Organizations are allocating more resources to cybersecurity, reflecting a strategic focus on critical vulnerabilities.
- Budget allocation trends:
- 52% of respondents expect an increase in overall IT budgets from 2024 to 2025.
- 10% expect a decrease, and 28% anticipate no change.
- 20% of respondents are unsure about budget changes.
- Cybersecurity budget percentages:
- 20% of organizations have no specific carve-out but spend on cybersecurity.
- 19% allocate 3–6% of IT budgets to cybersecurity.
- 14% allocate 7–10%, 7% allocate 11–14%, and 9% allocate more than 14%.
- 1% of organizations do not spend any money on cybersecurity.
- 23% of respondents are unaware of their organization’s cybersecurity budget allocation.
- Budget changes from 2023 to 2024:
- 3–6% allocation increased from 13% to 18%.
- 1–2% allocation decreased from 10% to 7%.
- 7–10% allocation slightly decreased, and over 10% allocations dropped significantly.
- Impact of budget increases:
- 57% of respondents reported significant improvements in tools.
- 47% reported improvements in policies.
- 31% reported improvements in staff.
Security Awareness
- Training methods:
- 73% use regular email alerts.
- 63% use simulated phishing.
- 49% use interactive discussions.
- 47% hold in-person or virtual workshops.
- 38% conduct tabletop exercises.
- 10% use interactive games.
- 4% reported no training, 2% were unaware, and 3% used alternate methods.
- Effectiveness of programs:
- 62% of respondents rated their programs as somewhat effective.
- 18% found them very effective.
- 18% found them only slightly effective.
- 2% stated they were not effective at all.
- Need for improvement:
- Training must address emerging threats like deepfakes, smishing, and quishing.
- Custom programs are needed to ensure relevance and comprehensiveness.
Security Incidents
- Initial points of compromise:
- General email phishing (63%) is the most common.
- SMS phishing and spear-phishing (each 34%).
- Business email compromise (31%), phishing websites (21%), malicious ads (20%), social media phishing (19%), vishing (17%), and whaling (16%) are also reported.
- 8% did not know, and 18% reported no incidents.
- Testing of incident response plans:
- 45% of organizations conduct tabletop exercises.
- 39% do not, and 16% are unsure.
- Stakeholder participation:
- IT and cybersecurity staff are most involved (89% and 77% respectively).
- Senior management (73%) and executives (58%) also participate.
- Other departments like compliance (48%), clinicians (44%), informatics (44%), HR (43%), and legal (42%) are involved.
- Vendors (22%) and contractors (15%) have lower participation rates.
- Board of directors participation is only 21%.
Ransomware
- Present state:
- Ransomware attacks remain a major threat, often state-sponsored and highly organized.
- 74% of respondents reported no ransomware attacks in the past 12 months.
- 13% reported being targeted, and 13% were unaware.
- Ransomware trends (2022–2024):
- The percentage of organizations experiencing ransomware attacks has remained relatively stable at 13%.
- 74% reported no attacks in 2024, similar to previous years.
- Ransomware payments:
- 62% of respondents reported not paying ransoms in 2024.
- 11% paid, and 27% were unsure.
- In 2023, 30% paid ransoms, while 52% did not.
- Proactive vs. reactive measures:
- 62% of respondents implemented new security tools.
- 57% established new security policies.
- 49% enhanced security awareness training.
- 43% upgraded legacy technology.
- 30% increased cybersecurity staff.
- 16% invested in cyber liability insurance.
- 14% enhanced existing coverage.
- 16% were unaware of what measures were taken.
- 3% focused solely on device lifecycle management.
Artificial Intelligence
- AI adoption:
- 81% of organizations allow AI use.
- 16% prohibit AI use.
- 3% are unsure.
- AI governance:
- 50% allow only approved AI technologies.
- 30% allow AI without formal restrictions.
- 16% prohibit AI use entirely.
- 1% have active AI policies or guardrails.
- AI use cases:
- 37% use AI for technical tasks (support, data analytics).
- 35% use it for clinical services (diagnostics).
- 34% use AI for cybersecurity and administrative tasks.
- 31% use it for healthcare operations.
- 24% for research, 21% for patient engagement, and 16% for clinical training.
- 4% use niche applications like virtual meeting transcription and content creation.
- 10% are unaware of AI use in their organizations.
- 14% stated it did not apply to them.
- Future concerns:
- Lack of formal AI governance and oversight increases risk.
- Active monitoring and clear policies are needed for responsible AI use.
Third-Party Risks
- Third-party risk management:
- 20% of organizations have formal programs.
- 28% experienced third-party security incidents.
- Impacts of third-party incidents:
- These incidents cause disruption and other impacts.
- The need for better oversight and communication is evident.
Insider Threats
- Formal programs:
- 23% of respondents reported no formal insider threat programs.
- These programs are critical for managing insider risks.
Conclusion
The survey highlights a growing recognition of cybersecurity as a strategic priority in healthcare. While budgets are modestly improving, awareness and transparency remain issues. Ransomware continues to be a significant threat, with a decline in ransom payments but ongoing risks. AI is increasingly adopted, though governance and oversight are lacking. Third-party and insider threats also require more attention. Overall, the healthcare sector is moving toward more proactive measures, but further investment and strategic planning are essential to address the evolving threat landscape.
试读结束,高清完整版pdf/doc/ppt,请点下载