In the healthcare sector, cyberattacks are not limited to hospitals; pharmaceutical companies, insurers, medical analysis laboratories, and all other institutions that may hold sensitive information are targets for cybercriminals. In light of this, many initiatives have been put in place.

Table of Contents
What protections are available?
Collaborative approach
TEAM: Together Everyone Achieves More
As we have seen, in our first article dedicated to healthcare, every hospital manages its organizational security in a disparate way. Now more than ever, it seems necessary to increase resilience, and this must be achieved through collaboration. There is strength in numbers.[1] and many initiatives are emerging, such as in France:
- The France Relance program offers cooperation between the public and private sectors. This program encourages cyber-expert organizations to assist public entities in developing security audits, penetration testing, vulnerability reviews, and governance. The program plans to dedicate €6 billion to the healthcare sector as part of the Ségur de la santé.
- The ACSS unit (Cybersecurity Support for Healthcare Structures), renamed CERT-Santé (since April 2021), aims to structure the cyber ecosystem, strengthen technical resources, and promote sovereign solutions. It is tasked with mobilizing various cyber stakeholders on topics such as prevention, awareness, monitoring, and incident response.
- The cybersecurity pathway offered by ANSSI supports healthcare institutions in better resisting cyberattacks.
- The Cyber Campus which brings together around sixty players from the cyber community ready to help hospitals and healthcare facilities.
In Spain, the COVID-19 pandemic had a significant impact on the cybersecurity of healthcare institutions. In 2021, to strengthen Spanish defense and cybersecurity capabilities, the government announced a 450-million-euro plan over three years. The "Academia Hacker" program is also part of an initiative to better prepare future talent for cybersecurity.
Awareness
27% of these breaches are due to human error, one of the highest percentages of any sector[2]
Regarding healthcare staff, it is observed that they are not sufficiently trained against cyberattacks, and cybercriminals take advantage of this gap. Training and awareness remain the first building block of any security program. All end users must realize that cybersecurity is everyone's responsibility; this requires recurring IT security awareness campaigns. Every staff member, and especially those with a higher threat profile than others, must have the ability to detect a phishing email, a suspicious file, an inconsistent call, etc. For this, in addition to theory, it is important to implement "contextual" training, meaning putting the user in a real-life attack situation based on current events. These tests should not be a one-off exercise; on the contrary, they must be regular to ensure everyone fully understands their role and the risks involved. In Spain, according to our partners at Proofpoint, 90% of attacks against healthcare were Business Email Compromise (BEC) attacks. This highlights the importance of raising awareness among security operations teams and users.
Robust defense strategy
Once the staff is involved, the second building block is to arm them. To do this, these structures must be equipped with an effective cybersecurity strategy.
Segmentation
The second step is network segmentation. The network is increasingly dense, complex (IoT, IT, OT), and constantly changing. This sector must manage both connected physical elements, such as cameras and secure physical access points, as well as IoT devices like medical equipment, as well as medical and financial records, etc. All these elements, both physical and virtual, must be segmented. All environments, whether routers, firewalls, or the cloud, are affected. Managing this environment is difficult, and cybercriminals will exploit this complexity. Segmentation is a solution to mitigate cyber risk. Indeed, by compartmentalizing, identifying sensitive assets, dividing systems, and isolating certain environments from one another, the spread of an attack can be prevented. Each asset can be protected by a TEHTRIS.Healthcare organizations can ensure data security through TEHTRIS solutions, which protect every endpoint as well as network traffic using its Deceptive Response and NTA technologies.
Zero-Trust
Finally, the healthcare sector is prioritizing the zero trust concept in its security strategy: 79%, compared to an average of 75% across all sectors.[3]. Healthcare data can become vulnerable and exposed to theft if employees leave files accessible, fail to store information in the correct location, and so on. It is therefore essential that certain staff members have no access to sensitive data. All access to applications and environments is thus secured both from inside and outside.
- The value of the information and the high turnover rate in this sector require the implementation of specific "zero trust" monitoring to detect suspicious staff activity and thereby protect against any insider threat. This involves implementing effective email and authentication controls.
- Every vendor that connects represents a risk; here again, security measures and audits must be strictly implemented and enforced to eliminate any risk of a supply chain attack.
Overall, when facing any cyber threat, regardless of the sector, anticipation is the watchword. Every organization must plan for attack scenarios, be prepared for a crisis, understand the nature of cyber threats, and have a firm grasp of sector-specific threats—knowing the enemy, their motivations, who the target is, and who is most at risk. By mastering this context, we can build a solid defense.
TEHTRIS Offerings
The healthcare sector faces technical specificities and a constant race against time, which require a turnkey security strategy. This is why TEHTRIS has chosen to play an active role in the France Relance project by providing its cutting-edge technology to strategic national entities. According to Gartner, "from a security and risk practitioner perspective, SRM (security and risk management) leaders must treat smart buildings, remotely piloted aircraft, or connected medical devices, for example, in a completely different way." Gartner adds that "the security of critical information systems must focus on safety, reliability, resilience, adaptability, and privacy."[4]. The research firm Gartner has named TEHTRIS as a representative vendor offering XDR solutions in the 2021 Market Guide for Extended Detection and Response.
Trusted by
In early 2021, several French hospitals were targeted by the Ryuk ransomware. However, even while an attack is underway, TEHTRIS can deploy Digital Forensics Incident Response (DFIR) technology in just a few hours to contain and remediate the threat. As part of the France Relance program, TEHTRIS has extensive experience in monitoring and protecting hospital IT systems. TEHTRIS constantly improves its detection capabilities by leveraging artificial intelligence, binary behavioral analysis, and its own cyber threat database. Thanks to Cyber Threat Intelligence (CTI), which is natively and systematically integrated into all TEHTRIS tools (EDR, EPP, SIEM, etc.), suspicious programs are sent directly to a sandbox to verify their behavior. The CTI Sandbox tool is capable of recognizing a large number of known threats and ransomware, such as Ryuk, but can also alert on the suspicious behavior of unknown threats. TEHTRIS goes further than other solutions, as active defense systems can be configured to respond autonomously, 24/7, to an attack—even an unknown one—by following predetermined criteria and policies, from raising the alert to immediate and automatic neutralization, without wasting time or energy, to best support healthcare staff.

Why choose TEHTRIS?
Choosing TEHTRIS guarantees:
- A sovereign solution that can easily protect employee and patient data.
- Full coverage of all endpoints to detect and neutralize ransomware in real time. This ensures 360° endpoint protection against the most advanced threats through hyper-automation and artificial intelligence.
- Compatibility with the ecosystem and the client environment (Windows 7).
- Rapid deployment () and support in tracking the cybersecurity roadmap.
[1] Esope[2] The Cost of a Data Breach report 2020 released by IBM and the Ponemon Institute.[3] EfficientIP and International Data Corporation (IDC) report. July 2021.[4] Source Gartner. 3 Initial Steps to Address Unsecure Cyber-Physical Systems. Katell Thielemann. 4 November 2021


