Christopher Frenz
The recent CrowdStrike outage might have made the issue top of mind for many hospitals IT and security leaders. But it's important to remember that controls don’t fail in just major events – they're always at risk.
Cyberattackers have been shifting to strategies where legitimate tools commonly installed on desktops and servers are abused for malicious purposes. To fight back, knowledge is power.
As an industry we've bought into the idea for too long that we can simply buy some cybersecurity tools and be safe.
While compliance-based frameworks are not without merit, it is important that they be viewed as minimum acceptable standards and not as end goals.
The widespread use of SolarWinds software means many organizations are now scrambling to determine whether they too may have suffered a breach. Here are some remediations and mitigations that can help get a handle on the issue.