Sophos has published a new sectoral survey report: “The State of Ransomware in Healthcare 2022.” The findings reveal a 94% increase in ransomware attacks on the organisations surveyed in this sector. In 2021, 66% of healthcare organisations were hit; 34% were hit the previous year.
The silver lining, however, is that healthcare organisations are getting better at dealing with the aftermath of ransomware attacks, according to the survey data. The report shows that 99% of those healthcare organisations hit by ransomware got at least some their data back after cybercriminals encrypted it during the attacks.
Additional ransomware findings for the healthcare sector include:
“Ransomware in the healthcare space is more nuanced than other industries in terms of both protection and recovery,” said John Shier, Senior Security Expert at Sophos. “The data that healthcare organisations harness is extremely sensitive and valuable, which makes it very attractive to attackers. In addition, the need for efficient and widespread access to this type of data – so that healthcare professionals can provide proper care – means that typical two-factor authentication and zero trust defence tactics aren’t always feasible.
“This leaves healthcare organisations particularly vulnerable and when hit, they may opt to pay a ransom to keep pertinent, often lifesaving, patient data accessible. Due to these unique factors, healthcare organisations need to expand their anti-ransomware defences by combining security technology with human-led threat hunting to defend against today’s advanced cyber-attackers.”
More healthcare organisations (78%) are now opting for cyber insurance, but 93% of healthcare organisations with insurance coverage report finding it more difficult to get policy coverage in the last year. With ransomware being the single largest driver of insurance claims, 51% reported the level of cybersecurity needed to qualify is higher, putting a strain on healthcare organisations with lower budgets and less technical resources available.
In the light of the survey findings, Sophos experts recommend the following best practices for all organisations across all sectors:
“The State of Ransomware in Healthcare 2022” report is available on Sophos.com. The State of Ransomware in Healthcare 2022 survey polled 5,600 IT professionals, including 381 healthcare respondents, in mid-sized organisations (100-5,000 employees) across 31 countries.