Ying He
Healthcare Security Incident Response Strategy - A Proactive Incident Response (IR) Procedure
He, Ying; Maglaras, Leandros; Aliyu, Aliyu; Luo, Cunjin
Authors
Leandros Maglaras
Aliyu Aliyu
Cunjin Luo
Abstract
The healthcare information system (HIS) has become a victim of cyberattacks. Traditional ways to handle cyber incidents in healthcare organizations follow a predefined incident response (IR) procedure. However, this procedure is usually reactive, missing the opportunities to foresee danger on the horizon. Cyber threat intelligence (CTI) contains information on emerging attacks and should be ideally utilized to inform the IR procedure. However, current research shows that the IR has not been effectively informed by CTI, especially in healthcare organizations. This paper fills in this gap by proposing a proactive IR response procedure based on the National Institute of Standards and Technology (NIST) IR methodology. This paper then presents the NHS WannaCry case study to demonstrate the use of the proposed IR methodology. We collate cyber security advisories from different CTI sources such as US/UK CERT to protect interconnected systems and devices from Ransomware attacks. This research provides novel insights into the IR in healthcare through embedding CTI advisories into IR processes and concludes that our proposed IR procedure can be used to counteract WannaCry Ransomware using CTI advisories. It has the significance of transforming the way of IR from reactive to proactive using the CTI in healthcare.
Citation
He, Y., Maglaras, L., Aliyu, A., & Luo, C. (2022). Healthcare Security Incident Response Strategy - A Proactive Incident Response (IR) Procedure. Security and Communication Networks, 2022, Article 2775249. https://doi.org/10.1155/2022/2775249
Journal Article Type | Article |
---|---|
Acceptance Date | Jan 18, 2022 |
Online Publication Date | Feb 23, 2022 |
Publication Date | Feb 23, 2022 |
Deposit Date | Dec 5, 2022 |
Publicly Available Date | Dec 5, 2022 |
Journal | Security and Communication Networks |
Print ISSN | 1939-0114 |
Electronic ISSN | 1939-0122 |
Publisher | Wiley |
Peer Reviewed | Peer Reviewed |
Volume | 2022 |
Article Number | 2775249 |
DOI | https://doi.org/10.1155/2022/2775249 |
Public URL | http://researchrepository.napier.ac.uk/Output/2969497 |
Files
Healthcare Security Incident Response Strategy - A Proactive Incident Response (IR) Procedure
(1.4 Mb)
PDF
Publisher Licence URL
http://creativecommons.org/licenses/by/4.0/
Downloadable Citations
About Edinburgh Napier Research Repository
Administrator e-mail: repository@napier.ac.uk
This application uses the following open-source libraries:
SheetJS Community Edition
Apache License Version 2.0 (http://www.apache.org/licenses/)
PDF.js
Apache License Version 2.0 (http://www.apache.org/licenses/)
Font Awesome
SIL OFL 1.1 (http://scripts.sil.org/OFL)
MIT License (http://opensource.org/licenses/mit-license.html)
CC BY 3.0 ( http://creativecommons.org/licenses/by/3.0/)
Powered by Worktribe © 2025
Advanced Search