May 30, 2018 By Douglas Bonderud 2 min read

Healthcare organizations are worried about cyberattacks. In fact, 77 percent of healthcare information technology (IT) professionals are “very concerned” about cyberattacks, according to a May 2018 survey sponsored by cybersecurity firm Imperva. Of those surveyed, 32 percent listed ransomware as their biggest fear, and employee actions grabbed the number two spot with 25 percent.

However, insider threats are the more persistent IT infection. As the 2018 Verizon Data Breach Investigations Report pointed out, healthcare is the only industry where insiders are responsible for more incidents than outside attacks.

Insider Threats: A Healthy Concern

According to Information Age, the use of unapproved applications by healthcare staff is often linked to IT risk, as employees may accidentally post or share confidential information to social media sites or send it via plaintext email.

Locking down access to cloud-based apps and services is often the go-to IT response — but this typically drives staff to use other applications that information security (InfoSec) professionals don’t know about and haven’t blocked. The result is a vicious cycle: IT’s attempts to reduce insider threats only increase total risk.

Despite the risk of malicious insider actions, companies are more concerned about accidental exposure. Imperva’s survey found that 51 percent of healthcare companies are more worried about careless users than staff-turned-attackers.

Although 73 percent of organizations now employ a senior information security leader — and 33 percent of respondents said their cyberattack response was “above average” — 38 percent of healthcare institutions suffered at least one cyberattack in the last year. Additionally, at least half of these attacks started with corporate insiders.

The Insider Threat Treatment Plan

What’s preventing health companies from curing the insider threat infection?

The Imperva survey pointed to four key factors:

  • More access by more people: More employees, contractors and business partners now access health networks, increasing insider impact.
  • More assets on the cloud: Increasing use of cloud services means more critical data is potentially at risk.
  • Lack of staff to analyze employee actions: As the total number of users and network-connected devices increases, staff struggle to effectively analyze insider actions.
  • Lack of monitoring tools: Without tools capable of monitoring activities across distributed networks, InfoSec professionals are hard-pressed to manage insider threats.

While there’s no cure-all, Information Age recommends making insiders part of the conversation about application use and safety. Rather than banning services outright, allow staff to use the applications of their choice wherever possible and adopt security best practices, such as deep inspection of web traffic, URL filtering and per-app monitoring.

As noted by Imperva, new machine-learning solutions can help IT teams “pinpoint critical anomalies that indicate misuse of enterprise data, so they can quickly quarantine risky users to prevent any further issues.”

The bottom line: Insider threats remain a persistent IT infection for healthcare organizations, despite increased recognition of cybersecurity risk.

More from

FYSA — VMware Critical Vulnerabilities Patched

< 1 min read - SummaryBroadcom has released a security bulletin, VMSA-2025-0004, addressing and remediating three vulnerabilities that, if exploited, could lead to system compromise. Products affected include vCenter Server, vRealize Operations Manager, and vCloud Director.Threat TopographyThreat Type: Critical VulnerabilitiesIndustry: VirtualizationGeolocation: GlobalOverviewX-Force Incident Command is monitoring activity surrounding Broadcom’s Security Bulletin (VMSA-2025-0004) for three potentially critical vulnerabilities in VMware products. These vulnerabilities, identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, have reportedly been exploited in attacks. X-Force has not been able to validate those claims. The vulnerabilities…

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today