Guest article authored by Gabby Williams – Content Specialist at Hushmail
With the growing cybersecurity threats to businesses today, having a reliable and sturdy security solution is not a luxury but an absolute necessity. Not every organization is capable of enduring the legal, financial, and reputational consequences of a significant data breach. Ignoring the risks can lead to serious consequences.
According to a 2022 report sponsored by IBM, the actual cost of a data breach increased 10% over the past 12 months — the highest recorded increase in the last seven years. It is estimated that the average cost of a single data breach is $4.35 million globally and $9.44 million in the U.S.
In the healthcare industry, the average cost of a data breach is $10.10 million. From a business continuity perspective, the impact can be devastating.
In Jan 2021, an amendment to the HITECH Act was made into a law requiring the U.S. Department of Health and Human Services (HHS) to consider certain recognized security practices of covered entities and business associates when making certain determinations.
Section 13412 makes clear the incentives for covered entities having certain recognized security practices, which are defined as the “standards, best practices, guidelines, procedures, methodologies, and processes developed” under section 2(c)(15) of the National Institute of Standards and Technology (NIST) Act.
Cybersecurity among healthcare organizations is more important than ever. Here are 10 key steps you can take to improve your organization’s cybersecurity and prevent data breaches.
1. Locate your sensitive data
Hackers target confidential and sensitive information. In order to prevent data breaches, your organization needs to determine where your most sensitive datasets are located. Make a consolidated inventory of this sensitive data and update, review, and back it up regularly.
2. Keep strict tabs on privileged access
The leading cause of data breaches is human error. In fact, 82% of data breaches involve a vulnerability caused by a human. Organizations have a responsibility to ensure the integrity of data, and most have privileged access accounts that allow designated users to access certain information.
Even with the best intentions, granting privileged access to contractors and employees puts data at an unnecessary risk for breaches. It’s important to foster policies that keep strict tabs on who has elevated levels of access. There are numerous privileged access management tools that can facilitate this.
3. Properly patch your infrastructure
Your cybersecurity measures are only as strong as your organization’s underlying infrastructure. Your organization’s top priority should be patching your networks and systems. With the surging number of new discoveries of zero-day exploits every day, hackers can easily exploit unpatched software to access critical information. Regular patching can help strengthen your cybersecurity and prevent data breaches.
4. Fortify your network perimeter
While 39% of data breaches in the healthcare industry come from inside the organization, the majority come from external threats. Your network perimeter is your first line of defense against outsiders with malicious intent. This perimeter mainly consists of a firewall, intrusion detection system, intrusion prevention system, access controls lists, and a couple of other tools that facilitate seamless data flow while restricting intruders and unauthorized entries.
5. Get rid of redundant data
Safely disposing sensitive data is crucial. Many organizations, especially those in healthcare, finance, education, and the public sector, handle sensitive information as part of their daily routine. Ensuring safe and secure data purging mechanisms helps prevent stale data from being forgotten and stolen.
There are three main ways to properly dispose of data: overwriting, degaussing, and physical destruction. However, each method has its pros and cons. A sound system for disposing of redundant data will go a long way toward saving your organization from a potential data breach.
6. Ensure endpoint protection
Ensuring the systematic implementation of endpoint security controls is essential for your organization. It has never been more important than it is today, with so many remote devices connected to your network.
Remote workers often fall outside of legacy perimeter security tools. Endpoint protection can be a reliable shield against common internet threats like malware and ransomware. Laptops, mobile devices, and tablets should all be secured with endpoint protection, leaving behind no loopholes for hackers who would want to exploit them.
7. Encrypt data at rest and in transit
Unencrypted data is like a bank with an open vault. If data isn’t encrypted, anyone can access it or even steal it since there’s no protection. No matter where the sensitive data is at any time, its encryption is essential to prevent unauthorized access. Data encryption is not only important for data at rest, but equally vital for data in transit within a corporate network.
8. Establish a robust password policy
The importance of a sound password policy can’t be emphasized enough. It’s a necessity for all services and applications running on a network. Here are some general password policy requirements:
- Minimum of 8-10 characters
- 4 character types including uppercase, lowercase, number, and special character
- Must not have 3 consecutive or repeating characters
- 90-day password rotation policy
- Multi-factor authentication may also be enforced using email or soft token
9. Prepare business continuity and disaster recovery plans
Properly responding to a data breach is a challenge. Ensure your organization has a reliable business continuity and disaster recovery plan, and review and update it regularly. Unfortunately, many organizations miss the importance of these plans and neglect to set them in place due to cost.
New cloud-based high availability and disaster recovery plans are becoming popular because of their resilience, scalability, and flexibility. Conduct periodic audits of your system, and back up your systems regularly for data security strategy and future planning.
10. Instill cybersecurity training across your organization
Any cybersecurity strategy without thorough security workforce training is incomplete. Since most data breaches occur due to unintentional mistakes made by employees, partners, and contractors, holistic training that covers common threats, data usage guidelines, password policies, and awareness related to social engineering and scams should be mandatory and occur regularly.
Conclusion
With hackers becoming more sophisticated, it’s vital for organizations to upgrade their cybersecurity arsenal to prevent data breaches. These 10 key steps are proven to help organizations develop a successful cybersecurity strategy. Each organization must find the right mixture of cybersecurity practices and policies in order to maximize their cybersecurity and prevent data breaches.