Hacked Healthcare: New KnowBe4 Report Shines a Spotlight on Cybersecurity Crisis in Sector

-

KnowBe4 (www.KnowBe4.com), the provider of the world’s largest security awareness training and simulated phishing platform, released its International Healthcare Report. The report takes a closer look at the cybersecurity crisis currently experienced by the healthcare sector, in particular hospital groups, across the world. 

Africa was the global region with the highest average number of weekly cyberattacks per organisation in 2023. One in every 19 organisations on the continent experienced an attempted attack every week. Although South Africa’s healthcare sector has managed to avoid a major attack since 2020, the alarming escalation of attacks in other sectors within the country suggests that it’s only a matter of time before the next attack strikes, making it a question of “when” rather than “if”.

Hospitals have become increasingly attractive targets for ransomware attacks due to their comprehensive patient databases, sensitive information, and their interconnectedness between systems and equipment. Moreover, poor security measures have made hospitals vulnerable to cyber threats. When attacked, cybercriminals can potentially take control of entire hospital systems, and gain access not only to patients’ health information but also their financial and insurance data.

Hospitals are severely impacted by cyberattacks (https://apo-opa.co/4csCXH4), which can lead to a reduction in patient care, loss of access to electronic systems, and a reliance on incomplete paper records. This can also result in the cancellation of surgeries, tests, appointments, and, in some cases, even loss of life. 

Some shocking facts discussed in the report include:

In the first three quarters of 2023, the global healthcare sector experienced a staggering 1,613 cyberattacks per week, nearly four times the global average, and a significant increase from the same period the previous year.
The healthcare sector has seen a dramatic surge in cyberattack costs over the past three years, with the average cost of a breach reaching nearly $11 million, more than three times the global average. This makes healthcare the costliest sector for cyberattacks.
Ransomware attacks have been the most prevalent type of cyberattack on healthcare organisations, accounting for over 70% of successful attacks in the past two years.
The majority of cyberattacks (between 79% and 91%), across sectors, begin with phishing or social engineering tactics, which allow cybercriminals to gain access to accounts or servers.
According to KnowBe4’s 2024 Phishing by Industry Benchmarking Report (https://apo-opa.co/4csuiEB), healthcare and pharmaceutical organisations are among the most vulnerable to phishing attacks, with employees in large organisations in the sector having a 51.4% likelihood of falling victim to a phishing email. This means that cybercriminals have a better than 50/50 chance of successfully phishing an employee in the sector.

“The healthcare sector remains a prime target for cybercriminals looking to capitalise on the life-or-death situations hospitals face,” says Stu Sjouwerman, CEO of KnowBe4. “With patient data and critical systems held hostage, many hospitals feel like they are left with no choice but to pay exorbitant ransoms. This vicious cycle can be broken by prioritising comprehensive security awareness training to empower employees and cultivate a positive security culture as a strong defence against phishing and social engineering attacks.”

The report examines the state of cybersecurity in the healthcare sector in North America, Europe, the United Kingdom, Asia-Pacific, Africa, and Latin America. In addition it also highlights some of the most prolific global ransomware attacks that occurred between December 2023 and May 2024, the aftermath thereof and what healthcare organisations can do to protect themselves from cyberattacks. 

To download a copy of KnowBe4’s International Healthcare Report, click here (https://apo-opa.co/3xIjjaY).

Distributed by APO Group on behalf of KnowBe4.

About KnowBe4:
KnowBe4, the provider of the world’s largest security awareness training and simulated phishing platform, is used by more than 65,000 organizations around the globe. Founded by IT and data security specialist Stu Sjouwerman, KnowBe4 helps organizations address the human element of security by raising awareness about ransomware, CEO fraud and other social engineering tactics through a new-school approach to awareness training on security. The late Kevin Mitnick, who was an internationally recognized cybersecurity specialist and KnowBe4’s Chief Hacking Officer, helped design the KnowBe4 training based on his well-documented social engineering tactics. Organizations rely on KnowBe4 to mobilize their end users as their last line of defense and trust the KnowBe4 platform to strengthen their security culture and reduce human risk.