Sophos, a global provider of next-generation cybersecurity, has released “The State of Ransomware in Healthcare 2022,” a new sectoral survey report. The findings show that ransomware attacks on organizations in this sector have increased by 94%. In 2021, 66% of healthcare organizations were affected, up from 34% the previous year.
According to the survey data, the silver lining is that healthcare organizations are becoming better at dealing with the aftermath of ransomware attacks. The report shows that 99% of healthcare organizations affected by ransomware recovered at least some of their data after cybercriminals encrypted it during the attacks.
Additional ransomware findings for the healthcare sector include:
“Ransomware in the healthcare space is more nuanced than other industries in terms of both protection and recovery,” said John Shier, senior security expert at Sophos. “The data that healthcare organizations harness is extremely sensitive and valuable, which makes it very attractive to attackers. In addition, the need for efficient and widespread access to this type of data – so that healthcare professionals can provide proper care – means that typical two-factor authentication and zero trust defense tactics aren’t always feasible. This leaves healthcare organizations particularly vulnerable, and when hit, they may opt to pay a ransom to keep pertinent, often lifesaving, patient data accessible. Due to these unique factors, healthcare organizations need to expand their anti-ransomware defenses by combining security technology with human-led threat hunting to defend against today’s advanced cyberattackers.”
More healthcare organizations (78%) are now opting for cyber insurance, but 93% of healthcare organizations with insurance coverage report that getting policy coverage has become more difficult in the last year. With ransomware being the single most common cause of insurance claims, 51% of respondents reported that the level of cybersecurity required to qualify is higher, putting a strain on healthcare organizations with limited budgets and technical resources.
In the light of the survey findings, Sophos experts recommend the following best practices for all organizations across all sectors:
The State of Ransomware in Healthcare 2022 survey polled 5,600 IT professionals in mid-sized organizations (100-5,000 employees) across 31 countries, including 381 healthcare respondents, and is available on Sophos.com.