HomeMalware & ThreatsHow Subtractive Security Eliminates Attack Paths

How Subtractive Security Eliminates Attack Paths

Published on

spot_img

Title: Chris Frenz Advocates for Proactive Cybersecurity Measures in Healthcare

In an era where cyber threats are increasingly sophisticated, Chris Frenz, the Chief Information Security Officer (CISO) at Rectangle Health, emphasizes a paradigm shift in healthcare cybersecurity strategies. Instead of mainly focusing on detection and response, Frenz advocates for a proactive approach—removing potential options for attackers before incidents occur. This innovative framework, known as "subtractive-hardening," aims to limit attacker pathways and create a more secure healthcare environment.

Frenz’s approach is informed by his expertise and contributions to the Open Worldwide Application Security Project (OWASP), where he developed standards that prioritize architectural changes in system design. The main components of his strategy include architectural deletion, followed by architectural constraint, and lastly, detection and response. “This hierarchy is crucial,” Frenz explains, “as it allows organizations to reduce potential attack vectors without disrupting essential business or clinical operations.”

To illustrate the effectiveness of this framework, Frenz discusses the importance of analyzing technology usage within healthcare organizations. By understanding which functions and technologies are utilized, security teams can remove unnecessary capabilities. For example, he points out the common usage of Secure Shell (SSH) among IT staff to access various resources within the network. However, he asserts that healthcare professionals, such as nurses and doctors, typically do not require access to SSH. By conducting behavioral analytics studies, organizations can determine that only the IT team needs this capability. As a result, they can safely revoke access to SSH for non-IT personnel, which significantly diminishes the organization’s attack surface while having no adverse effect on business operations.

Frenz highlights a common pitfall among Chief Information Security Officers (CISOs)—a reluctance to remove access to tools or capabilities, even when they’re unnecessary for certain staff members. He remarks, “Many CISOs are hesitant to take away something that someone might need. However, the focus should be on security, which sometimes requires difficult decisions.”

Generally, he observes that many security teams place significant emphasis on detection and response mechanisms but often neglect architectural controls that prevent intrusions. By adopting a subtractive-hardening approach, organizations can apply principles from reliability engineering to security architecture. “If an alert triggers an architectural change, it means you’re treating security like an engineering discipline—not just as an afterthought,” Frenz explains.

Frenz’s OWASP initiative also introduces a unique metric called the “path erasure rate,” which quantifies how many attack pathways have been eliminated over time. This metric serves as a crucial indicator of an organization’s commitment to reducing opportunities for attacks. “The key question that organizations must ask is—how can I effectively eliminate these attack paths?” Frenz states. By reorienting the focus of cybersecurity measures toward eliminating pathways for attackers, organizations can significantly enhance their security posture.

Moreover, during a recent video interview with Information Security Media Group (ISMG), Frenz discussed practical tips for implementing a reductive security framework within healthcare settings. He addressed how persistent security alerts could inform architectural investigations, leading to the identification of vulnerable attack paths that should be eliminated. Frenz also underscored the need for scrutiny of unused protocols, administrative utilities, and outdated functionalities which are perfect candidates for deletion from organizational architectures.

He highlights how employing techniques such as segmentation and stringent application constraints can effectively limit lateral movement in ransomware attacks, which become increasingly common once a device is compromised. Such strategic segmentation is particularly vital in ensuring that a breach in one part of the infrastructure does not facilitate widespread damage in others.

As a seasoned healthcare cybersecurity professional, Frenz is driven by a commitment to fostering a robust security culture within the healthcare landscape. At Rectangle Health, he is dedicated to not only executing this subtractive-hardening framework but also expanding his expertise in areas such as zero trust, micro-segmentation, and medical device security. Frenz’s actionable insights serve as a significant contribution to the ongoing conversation about the evolving challenges of healthcare cybersecurity and highlight the necessity for innovative and proactive security measures.

In conclusion, Chris Frenz’s vision of healthcare security is not merely about reinforcing existing defenses but about eliminating potential vulnerabilities before they can be exploited. As cyber threats continue to escalate, the industry must heed his call to change the narrative—from reactive responses to proactive measures that fundamentally reshape the architecture of healthcare security.

Source link

Latest articles

EvilTokens Exploits Microsoft Device Codes to Hijack Accounts Without Password Theft

EvilTokens, a new criminal operation, is advancing phishing-as-a-service (PhaaS) by leveraging Microsoft’s device authorization...

Hackers Exploit Critical Vulnerability in Oracle HTTP Server to Access and Modify Sensitive Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added a critical vulnerability...

WordlistLoader Delivers Amatera Through ClickFix, SynkLoader Phishes Windows Passwords

Emerging Malware Families: WordlistLoader and SynkLoader Exposed Recent research from cybersecurity experts has spotlighted two...

Windows 11 Update Causes Game Crashes on Systems with RGB Lighting Drivers

Microsoft Investigates Windows 11 Game-Crashing Issue Linked to RGB Hardware Microsoft is currently addressing a...

More like this

EvilTokens Exploits Microsoft Device Codes to Hijack Accounts Without Password Theft

EvilTokens, a new criminal operation, is advancing phishing-as-a-service (PhaaS) by leveraging Microsoft’s device authorization...

Hackers Exploit Critical Vulnerability in Oracle HTTP Server to Access and Modify Sensitive Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added a critical vulnerability...

WordlistLoader Delivers Amatera Through ClickFix, SynkLoader Phishes Windows Passwords

Emerging Malware Families: WordlistLoader and SynkLoader Exposed Recent research from cybersecurity experts has spotlighted two...