CyberSecurity SEE

Critical Medical Devices Cannot Facilitate PQC Transition

Critical Medical Devices Cannot Facilitate PQC Transition

An investigation carried out by Forescout has brought to light critical vulnerabilities in the medical sector, revealing that the majority of medical devices are not equipped to transition to post-quantum cryptography (PQC). This inadequacy raises serious concerns regarding the potential risks posed to sensitive healthcare data as advancements in quantum computing threaten existing encryption methods.

In its analysis, Forescout examined over 2.5 million devices within more than 50 healthcare delivery organizations (HDOs). The findings were alarming, indicating that a mere 6% of Internet of Medical Things (IoMT) devices and only 16% of medical operational technology (OT) devices employed Secure Shell (SSH) implementations capable of facilitating a move towards PQC. To put this into perspective, traditional IT devices appear significantly more prepared, with around 50% capable of supporting PQC implementation.

PQC encompasses a new array of cryptographic algorithms specifically designed to safeguard data against attacks from quantum computers. Experts predict that quantum breakthroughs could lead to the capability of breaking current encryption methods within the next five years. The urgency highlighted by Forescout reflects the need for healthcare organizations to prioritize their cybersecurity strategies in light of these impending threats.

The report, which was published on October 6, underscores the heavy reliance of healthcare environments on IoMT, OT, and IoT devices. Many of these technological assets are integral to patient care, involved in crucial functions like administering medication through infusion pumps, monitoring patients’ vital signs, imaging, and laboratory diagnostics. Unfortunately, these devices typically have lengthy lifecycles, face limited opportunities for upgrades, and generally show slower adoption rates for modern cryptographic standards.

Daniel dos Santos, Vice President of Research at Forescout, voiced the concerns raised by their findings. He pointed out that the devices that are least prepared for the shift to PQC are often the same ones that healthcare organizations depend on most for effective patient care. He emphasized the importance of having visibility into these assets and understanding the sensitive data they handle to construct a viable migration strategy.

Healthcare Data Vulnerable to Harvest Now Attacks

The depth of vulnerability within these systems is striking. The study identified over 5,500 internet-exposed systems across the analyzed devices, many containing sensitive healthcare information such as electronic medical records (EMRs) and picture archiving and communication systems (PACs). Alarmingly, only 31% of these exposed systems currently support TLS 1.3, the only version of Transport Layer Security that accommodates standardized PQC.

This inadequacy positions these systems at particular risk for “harvest now, decrypt later” attacks, a threat landscape in which cybercriminals steal encrypted data with the intent to decrypt it later when quantum computing capabilities are sufficiently advanced. The nature of healthcare data—such as medical histories, diagnostic images, laboratory results, and prescription records—renders it highly sensitive and valuable, retaining its importance for many years, if not decades.

Preparing Healthcare Organizations for Quantum Threats

Given the level of vulnerability uncovered, Forescout has urged healthcare organizations to take proactive measures against potential quantum-enabled attacks to protect sensitive patient information. To aid in this endeavor, the organization has proposed a series of actionable steps, which include:

  1. Inventory and Classification: Organizations should undertake a thorough inventory and classification of all connected IT, OT, IoT, and IoMT assets, along with their interactions with other systems.

  2. Assessment of PQC Readiness: A careful assessment of which assets support PQC should be conducted. Systems requiring upgrades, replacements, or alternative controls ought to be identified.

  3. Segmentation and Isolation: Legacy systems that lack upgrade potential should be segmented and isolated from other networks to minimize risks.

  4. Incorporation of PQC into Governance: Integrating PQC readiness into governance, procurement, and risk management protocols is essential. This includes enforcing the use of TLS 1.3 wherever feasible.

  5. Vendor Engagement: Healthcare organizations are encouraged to engage with vendors to better comprehend their PQC roadmaps and timelines for migration.

As the healthcare sector stands at a critical juncture in the face of emerging quantum threats, the guidance from Forescout serves as a clarion call for hospitals and organizations to prioritize the cybersecurity measures vital for protecting patient data. The time for action is now, as the technological landscape rapidly evolves and vulnerabilities linger, necessitating robust strategies to shield sensitive information from potential future breaches.

Source link

Exit mobile version