How DMARC helps boost healthcare’s herd immunity to ransomware

With its sudden onset, devastating effects, and long recovery time, ransomware can be best likened to a disease. And no industry knows this better than healthcare. In 2021, there were 1203 attacks on US healthcare institutions alone, and for 11 consecutive years, healthcare has been hit with the heftiest costs for data breaches, largely resulting from attacks like these.

But what makes ransomware such a serious affliction for healthcare providers is that the data breaches and disruptions resulting from attacks have a very human cost. In research carried out by Ponemon Institute, 22% of respondents agreed that ransomware has an impact on increased mortality rates, while PBS uncovered a shocking parallel between ransomware and an uptick in fatal heart attacks.

It’ll only become a more pressing priority for healthcare providers to strengthen their defenses against this affliction as we move into 2022, and DMARC plays a key role in this. 

How does ransomware work?

Ransomware is a type of malware – most often disguised in a phishing email – that once deployed, blocks you from accessing your data through encryption. Cybercriminals then demand a ransom for access to this, otherwise, your data might be lost or leaked. 

What makes companies susceptible to ransomware?

Sensitive data, legacy systems, a widespread attack surface, and digitization all contribute to a company’s vulnerability to ransomware attacks. But not having the essential security protocols in place to secure vital information and infrastructure makes any business vulnerable, and these are often overlooked.

As our CEO Rahul Powar explains, “Primarily what makes companies susceptible to ransomware attacks is a lack of the basic infrastructure and protocols which are designed specifically to mitigate these risks. Businesses should be asking themselves if they have protocols like DMARC in place to stop exact impersonation attacks, if their inbound protection like SEGs or Advanced Threat Protection products are in order, and whether sufficient awareness training has been provided. Ransomware attackers will take any opportunity to hit an organization with a lot of sensitive data, and the more robust, standardized solutions businesses can put in place to plug the gaps, the better protected they are.” 

Why is healthcare such a lucrative target for cybercriminals?

There are a number of reasons why ransomware is so rife in healthcare:

  • Healthcare organizations store mass amounts of very sensitive data, and cybercriminals know this. 
  • It’s a sector which is rapidly digitizing, meaning there are vulnerabilities if the right measures aren’t in place.
  • There’s a widespread attack surface with many staff who’ve often not received adequate security awareness training in many areas.
  • Large supply chains and alot of third-party outsourcing, meaning there are more endpoints and opportunities for attack.
  • Legacy systems and outdated processes contribute too.

“Healthcare organizations are lagging behind other verticals in cybersecurity defenses because they do not invest enough on cybersecurity protection and are known to be vulnerable to attacks. Some of the basic protections against cyberattacks are not deployed and hence they are easy targets for hackers. Attacks on healthcare have a higher impact from the perspective of lives lost or physical harm as data or critical systems are compromised, as well as the sensitivity of the data being exposed.”

Issam Bandak, Red Sift Director of Sales Engineering

How can protocols like DMARC help create herd immunity in the healthcare sector?

DMARC stands for Domain-based Message Authentication, Reporting, and Conformance. It’s a globally standardized email authentication protocol that protects domains from exact domain impersonation or ‘email spoofing’. Essentially, when implemented properly at a policy of p=reject, it ringfences your domain (www.example.com) and blocks hackers from being able to use it to impersonate your business and send phishing emails to your patients, employees, and supply chain.

Given that 90% of cyber attacks start with an email, and 90% of malware is delivered via spam email, DMARC is an essential – and surprisingly cost-effective – way for providers to secure this particularly vulnerable vector. Better still, the more organizations that adopt it, the fewer domains are on offer for hackers to impersonate for phishing attacks, BEC, ransomware, and vendor fraud. That’s where the concept of herd immunity comes in; if every organization implements DMARC, then ransomware will be driven down, and healthcare organizations, their data, suppliers, and most importantly patients, will be better protected.

Get your free DMARC health check today

At Red Sift, we’re passionate about democratizing the technology essential to cybersecurity – in short making it easy and accessible for everyone. So take the first step to DMARC protection today and get your free DMARC, SPF, and DKIM health check using our investigate tool.

Check email DMARC setup

PUBLISHED BY

Sabrina Evans

11 Feb. 2022

SHARE ARTICLE:

Categories

Recent Posts

VIEW ALL
News

Introducing DNS Guardian: Stop impersonation and spam caused by domain takeovers 

Rahul Powar

tl;dr: We’re thrilled to announce DNS Guardian — a new feature in Red Sift OnDMARC that can swiftly identify and stop domain takeovers that lead to malicious mail. Back in February, we shared updates with the community about SubdoMailing – an attack discovered by Guardio Labs. The attack was a form of subdomain takeover,…

Read more
Email

“What’s Next for DMARC”: Red Sift & Inbox Monster Webinar Recap

Red Sift

The recent webinar hosted by Inbox Monster, “What’s Next for DMARC: Data & Predictions for a New Era in Email Authentication,” featured insights from Red Sift and examined the significant changes brought by Yahoo and Google’s bulk sender requirements earlier this year.  It also offered a forward-looking perspective on the future of email authentication.…

Read more
Security

Navigating the Information Security Landscape: ISO 27001 vs. SOC 2

Red Sift

As cyber threats evolve, so do the standards and frameworks designed to combat them. Two of the most recognized standards in information security are ISO 27001 and SOC 2. What sets them apart, and which one is right for your organization? Let’s delve into the key differences. Purpose and Scope: Global Framework vs. Client-Centric…

Read more
News

G2 Summer 2024 Report: Red Sift OnDMARC’s Winning Streak Continues

Francesca Rünger-Field

We’re delighted to announce that Red Sift OnDMARC has again been named a Leader in G2’s DMARC category for Summer 2024. This recognition is based on our high Customer Satisfaction scores and strong market presence. Red Sift appeared in 11 reports – 5 new ones since Spring 2024! – earning 5 badges: A few…

Read more
News

Google will no longer trust Entrust certificates from October 2024

Red Sift

Tl;dr: Google has announced that as of October 31, 2024, Chrome will no longer trust certificates signed by Entrust root certificates. While there is no immediate impact on existing certificates or those issued before 31st October 2024, organizations should start reviewing their estate now. On Thursday 27th June 2024, Google announced that it had…

Read more