Health IT Security December 20, 2023
CISA urged the healthcare sector to use phishing-resistant MFA, implement network segmentation, and verify the implementation of appropriate hardening measures to mitigate cyber risk.
The Cybersecurity and Infrastructure Security Agency (CISA) published a cybersecurity advisory based on key findings that the agency uncovered during a risk and vulnerability assessment (RVA) conducted at a healthcare organization in early 2023. The results of the RVA revealed improvement areas that CISA says can be applied to the entire sector, from asset management to identity and vulnerability management.
CISA conducted the RVA at the request of a large healthcare organization that was in the process of deploying on-premises software. The RVA consisted of a two-week penetration test of the entire organization, including one week...