RadiantLogic-Cisco-Dashboard-Reporting-Hero

Healthcare is Under Attack: Make Identity the Perimeter



Speaker: Paul Dant, Sr. Solutions Consultant, Radiant Logic

Paul Dant draws on real-world red-teaming experience to show why healthcare is so heavily targeted, and how attackers no longer need rare zero-day exploits to get in. Weak identity controls, excessive privilege, and lateral movement drive ransomware, and an overreliance on EDR and SIEM leaves a major gap in defense.

Read the transcript

Brooke Vixamar: Hello. Welcome, everyone. Welcome to the webinar, Healthcare is Under Attack, Make Identity the Perimeter. I am Brooke Vixamar. I’m the senior director of product marketing here at Radiant Logic, and I’ll be moderating this two part series. Today, I’m very excited to be joined by Paul Dant. He’s a senior solution consultant here at Radiant Logic with myself.

He also spent a great deal of his early career breaking into systems. And then the rest of his career has been helping people keep people like him out. So we’re really excited to hear from him today on this very timely topic on how we’re able to make identity at the perimeter. This is just part one of a two part series.

In two weeks, we’re gonna be joined by Kristen Hoppe. She is the Director of Identity and Access Management at Baylor Scott and White. She’s going to give us that practitioner’s view from inside a major health system. So we’re really excited about the full series.

When you register, you should have been able to register for both. If not, we’ll get you a link at the end of today’s presentation to make sure that you’re able to attend the second part of this series. A quick housekeeping note, we do want to be able to answer any questions that come up during our presentation.

So please use that questions section at the bottom of your screen and type out any questions that you have there. And then as we have time at the very end, we’ll answer as many of those questions as we can. And any questions that we don’t get to today, we will be able to take advantage of in our part two secondtion and answer any of those questions then. And that part two is gonna be held on September twenty third. So definitely mark your calendars if it’s not already on there.

As we kind of jump in here, two numbers are setting the stage. The point isn’t that health care is getting breached, it’s that these breaches are in health care in particular disrupting patient care. So I wanted to toss this over to Paul to kind of set the stage for us a little bit on the industry and what these numbers really mean.

Paul Dant: Hi, Brooke. Great to be here. Thank you for having me. So I think one of the things that we can really reflect from these numbers is that today, attacks are much more about using systems as they’re meant to be used. Hackers are doing a lot less hacking and a lot more just logging into our systems. And that’s really what’s driving both the prevalence and the rate in which we’re seeing attacks against healthcare.

Brooke Vixamar: Absolutely. Now let’s pivot from industry at large and dive into your story, Paul. Take us back to nineteen ninety six. You were the one watching the logs coming in. What did you see?

Paul Dant: Yes, nineteen ninety six. So I was actually still a student in high school. I was around sixteen.

And I was the sysop of a web server that actually represented the county, the Board of Education’s very first website. This server was hosting that website.

Important to mention that how I got into this role was actually getting caught earlier carrying out my own exploits against school systems.

And in this particular case, this was one of those decisions that the county made instead of pursuing me for these things, they decided to hire me to have me help prevent these types of things. And that’s exactly where I I got into this this position of having administrative security administrative responsibility over this server.

So in this case, you know, we’re talking about nineteen ninety six. It’s a Red Hat Linux server with no firewall or packet filtering of any kind in front of it. In fact, the network card actually had a publicly routable Internet address on it. So given my background, my first suspicion is somebody is going to want to attack this system. So I had put some very rudimentary log monitoring things in place. And as I suspected, there was actually an intrusion.

So in this particular case, I noticed that not only was there someone logged in that wasn’t me, which really shouldn’t have been the case, but this person was logged in as the principal of my high school. So that sounded really odd to me given that there was no reason the principal who did have an account would actually log into this system.

So I kind of responded as an investigator as best as I could. This was the first time I had ever actually caught someone like myself doing the things that I had been doing.

So I did a reverse lookup on the IP address that I had pulled from the logs, and that led me to an ISP. Now back in ninety six, virtually everything was dial up. And in Aurora area, like where I grew up, there weren’t a lot of Internet service providers. So I recognized the ISP that this IP led back to and made a telephone call to them.

May have overplayed my hand a bit as a security administrator for the county and didn’t mention that I was still a student a high school, but nevertheless, it worked and I was given the identity of this person tied to the IP address.

For those listening, wanna call to your attention if you haven’t already made the connection.

Even in nineteen ninety six, this was a huge violation of privacy of this ISP customer, the person who was actually attacking the system.

You know, without any court order, anything like that, I was given full name, phone number, address of this attacker, which I loved, but looking back, it’s pretty horrifying. Nevertheless, now I know who this person is, and it didn’t take very long to actually make the connection that this person that had just attacked this system was another student in the high school, which was disappointing to me to say the least. But in taking this in true incident response fashion to the administration of the school, I was kind of able to negotiate with them to let them handle it my own way. And that involved, we’ll call it an interview with this student.

It was really more of an interrogation, but really the goal was trying to understand exactly what was your motivation for logging into this system? Why did you choose the principal’s account? And how did you learn to do these things? Which eventually I was able to uncover all of those things.

But, yeah, that’s that was nineteen ninety six, the first time I had been involved in an incident responding to it and finding out that another student had actually hacked into our server.

Brooke Vixamar: And as the student hacker turned administrator, that must have felt like a personal affront that he got into your system.

Paul Dant: Certainly did.

Brooke Vixamar: So you caught him. That sounds like a win.

Why do you tell this as a story of failure that you learned from?

Paul Dant: Yes. So great that I I caught an intruder, but the failure really comes down to the fact that I was the problem and not the hacker. Having security responsibility over system means that I created the principal’s account. I assigned the password for that account to be the same as the username, a huge security violation.

But probably most importantly of all of this is that there was really no reason for that principal to actually have an account on that system. He didn’t know that system was there, was never going to log in, but it was good intentions that led me to create that account and leave it in place even though I knew that it didn’t necessarily need to be there. So good intentions, very bad outcome, and an initial lesson about identity hygiene and how critical it is.

Brooke Vixamar: Absolutely.

This story, I mean, from ‘ninety six, it was one account, one school many years ago.

As we’re thinking to our audience today of health system administrator, identity access professionals, security professionals, How many accounts like this does a health system have right now?

Paul Dant: Great question. And I would venture to guess, depending on the size, hundreds to maybe thousands. We’re talking about such a diverse population within a healthcare system.

Shared credentials are often a thing at, say, nursing stations, vendor accounts that were created for technology integrations that may have ended years before.

Locums log in, nobody’s deprovisioned as those temporary placeholder employees and workers move from one position to the next. So just like nineteen ninety six, all of these accounts, all of these entitlements are granted with good intentions.

And that’s really what the rest of this session is about. How do we identify these things that were created with good intentions, but may lead to bad outcomes?

Brooke Vixamar: Absolutely.

So let’s think, pivot a little bit more and think about what makes healthcare structurally different.

They’re not worst offenders necessarily going after healthcare, but there are certainly different conditions. When you walk into a health system today, what would you say you hit first?

Paul Dant: So I think there are two core pressures that we see, not necessarily uniquely, but very prevalently within healthcare, and then three characteristics that really accelerate those pressures. So the first pressure that I see that I’m typically looking at, third party non employee identity. As I mentioned, healthcare systems typically employ a very diverse workforce.

So that workforce has multiple personas that may actually fit one person multiple personas at a time. Very challenging, very difficult to manage, especially when we bring in access requirements, you know, things that those workers need to be able to do their jobs.

In a lot of these cases, we see that these accounts are not necessarily part of a solid joiner mover lever workflow lifecycle management program, but are sometimes created on the fly depending upon what that persona is.

The other core pressure that I see is just legacy directory sprawl that usually comes about through M and A. Healthcare organizations tend to grow inorganically through acquisitions.

And as we bring one identity ecosystem from a healthcare system and try to merge it into an existing ecosystem from another healthcare system, we run into a lot of challenges with aligning those directories.

So those are the two core pressures that I think healthcare faces. The acceleration that I really wanna focus that’s here on the slide is workflow versus access.

This is the one that I would highlight as probably being the large accelerant for these pressures, meaning that if a particular identity within a healthcare system, let’s say a practitioner, a doctor, a nurse practitioner, if those identities don’t have the proper access entitlements, they’re not able to do their jobs, which now means potentially lives are at stake, health is at risk, if we’re not enabling those practitioners to be able to access the things that they need to be able to access.

That becomes really challenging when we sort of bring that all into the to the idea of identity access management.

Brooke Vixamar: Well, there we go. Let’s think about, from your perspective, when you’re on a Red Team engagement against an organization like this, what’s the pattern that gets you in?

Paul Dant: So I think first and foremost, we’ll start with the statement that every successful ransomware attack starts with a compromised identity. That’s an essential truth that we not only need to accept but we can sort of empirically see by looking at attacks.

When we see an initial compromise into a healthcare system, it’s typically an identity that was kind of hanging out there as low fruit. And then we have factors that I think are really tied to the overall success of a ransomware attack post initial access. We controls. We know that traditionally controls around identities have been challenging, and one of the main reasons for that is a lack of overall coherent visibility across the entire landscape of identities.

As I mentioned earlier, healthcare having multiple personas, meaning a lot of different types of workers that need a lot of different types of access to systems, building programs around that and keeping them in place, keeping them running smoothly can be really challenging and that’s where we tend to see weak controls come into play, a lack of visibility and not really seeing the ever evolving state of identities within a health care system and the way risk tends to come about through really simple things like a termination date has passed, but that particular identity’s accounts are all still active.

Very plausible scenario, even though it is an extremely critical high risk scenario.

Excessive privilege kind of goes along with that. If don’t have full visibility into our identities, we have a difficult time understanding what identities tied to accounts are actually able to do within particular systems.

So we tend to have kind of standing access that allows a particular user way more access than he or she might actually need to carry out their their job from day to day.

The excessive privilege and weak controls then leads to what we refer to as lateral movement. That’s an attacker’s ability to basically log into one system and then using credentials, maybe stolen after the initial access, maybe the same credentials, logging into yet another system and another system. Sometimes escalating privilege, sometimes not, but the key is with each lateral movement that attacker is likely furthering just one step closer to their overall attack objectives.

And then lastly, phishing. So phishing is really something that comes into play with that initial attack where credentials are harvested, sold on the deep dark web to attackers that are then able to sell them to ransomware groups. An entire business, an entire market exists around all of that, but our inability to prevent those style of attacks using the phishing technology that’s available available to us presents a lot of risk. As I said earlier, most attackers don’t need to break into your systems. They just need to do what people normally do and log in with credentials.

Brooke Vixamar: Absolutely. There’s all this new technology and new ways of hacking and doing these things, but these are the same they’re just expedited now, right? The same phishing exercise you did in nineteen ninety six to get the ISP information.

Those phishing techniques are still what is being used. It’s just AI is its own kind of accelerant. The the technology that we have available now just makes these things even more dangerous. Absolutely. Yeah.

Paul Dant: Yes. Social engineering is a critical part of phishing, and AI does really make social engineering a lot easier to carry out, and it provides a number of novel approaches to it as well.

Brooke Vixamar: Absolutely.

Let’s think specifically for a minute about the CISO.

They’re telling their identity team, hey, we already have EDR, same. Why isn’t that enough? How would you respond to that CISO and to that identity team?

Paul Dant: Sure. So let’s start first with those two technologies. They have a role. There’s no doubt in in any modern cybersecurity program, EDR of some sort is what’s helping us to detect and respond to endpoint incidents.

SIEM is ultimately bringing all of our logs together and hopefully correlating them to be able to surface security incidents that any single data source might not be aware of. You know, a a malware alert along with an outbound fire firewall alert that confirms a malware callback is an extremely valuable notification that we’re able to see through a log correlation with SIM. That said, neither one of those can really tell us the subject that’s involved in that. So if it’s an endpoint detection, if it’s some kind of similar, we’ll typically see an account name associated with that alert.

So when it goes to an incident analyst or responder in the security operations center, they’re starting with an account name. That’s a real challenge because that account name is not really giving us any idea of the identity that’s tied to that account and most importantly, what can that account do in what systems? So in in another phrasing, helping us to understand what is the blast radius of this particular user should this attack activity continue.

So both EDR and SIEM are necessary without a doubt, but we need the ability to bring additional identity context into that ecosystem so that we can better understand blast radius of a particular attack.

Brooke Vixamar: So as we explored previously, if this gap really isn’t a tooling gap, what is the mental model that people are missing?

Paul Dant: So I think a lot of that comes down to how we tend to look at identity. In my mind, you know, identity is state. It’s a stateful model, and that state needs to be earned. What we mean by that is when we see a change in an identity, if we have the proper context around what that identity is able to do, the entitlements within a system or multiple systems, now we can understand risk associated with that particular identity.

Even better, what if this identity is compromised? What can happen from there? And I think that’s the part where we need to adjust a bit. It’s a matter of identity typically being driven by an ideal outcome of success as opposed to assuming compromise and thinking, as I’m granting rights to this particular identity, what would happen if this identity was compromised?

What would the the potential outcome look like? So identity is stateful. Identity is also layered.

It’s a lot more than just active directory accounts.

Entitlements, group membership, all of these things come together into a stack. The analogy I tend to like to use is if you think back to the OSI reference model for networking protocols, it explains exactly what role each layer in that stack has in processing data over a network. Very similar concept here with identity. At the bottom, we have what we can think of as systems of record where the data lives.

As we move up that stack, we see systems of action like IGA, joiner mover lever, user access reviews, all those critical exercises that make up modern identity practices, but it’s all supported by the data that is underlying.

And I think that’s really if if we look at identity as a stateful layered model, it really helps us to understand the need for observation, being able to see every change made to a particular identity, validate that that particular transition, whether it’s an access to a system, a new active directory group membership, we need to be able to validate that that transition was supposed to happen.

And if not, we need to act on it, but act with precision. A lot of times we’ll see incident response playbooks that if an account is suggestive of malicious activity, we’ll immediately shut that account down.

We’ll try to map that account to a particular identity and then shut the rest of the identity’s accounts down. The challenge there, of course, is that is not a precise response to what we may be seeing. We may actually cause more business outages that cost the company more money than an actual security incident in this scenario would have cost them. So being able to act with precision and truly understanding the context of, say, an account that’s been flagged as tied to malicious activity, being able to understand the identity context is critical here.

Brooke Vixamar: Well said. We talked about a lot of things today, and I want to open it up to have some questions too, but I thought now is a good time to kind of take a deep breath and look back to the things that we’ve already talked about and kind of just what are the key takeaways, Paul, that you kind of put together thinking through here that the people on the call here can take back to their teams?

Paul Dant: Absolutely. So first, if we name the risk, as we talked about, ransomware in healthcare starts with identity. We may see a lot of exotic old days being reported on in the media and published. We see all kinds of things with with AI breaking out of their their localized networks, gaining access to other systems, and hacking into them.

The real risk is in identity. All of those things that we hear about in the media, if you really dig into those attacks, it’s all centered around identity. And so weak controls, access privileges, lateral movement that we talked about earlier, those are the things that actually do the work for attackers in a successful ransomware attack. That’s the risk that we need to be focused on.

When we talk about gaps in the stack, EDR, SIM absolutely have their role, but they tell you that something happened. They don’t necessarily tell you which identity, which account needs to be focused on, which entitlement, or which access record needs to be focused on. And that gap is where attackers are able to be successful in the fact that EDR and SIEM are just typically not providing us with the context we need to truly address the incident and then resolve the vulnerability, the risk, whatever may have led to the incident.

And then lastly, strengthening what you own. If we are able to unify all of the different identity data sources that are sort of strewn across the enterprise today, We can actually align all of those identities with human owners that have responsibility, have management requirement over these accounts, and we can actually act on risks as they’re identified. A unified identity layer also is able to feed all of your critical identity systems, IGA, PAM.

Rather than replacing those systems, a unified identity layer is actually what we can do to what we can utilize to shrink the attack surface overall and reduce the risk that we’ve talked about today that’s involved in identity management.

Brooke Vixamar: Well said. Paul, I feel like I should give you a second to take a glass of water. I keep putting you on the spot.

Before we get to those questions, I wanted to just kind of give you the floor to kind of like close out closing comments on what we’ve covered so far, and then we’ll open it up to some questions. So just kind of closing out kind of the overarching story of what this webinar is and how were the vulnerabilities of health care attacks and the important role that identity plays in all of that.

Paul Dant: Absolutely. So I think this statement here, critical lesson that I learned at sixteen and sharing with the entire audience here, good intentions don’t secure systems. Good practices do.

In nineteen ninety six, my good intention was creating accounts for people just because of their prominence in that particular world. In a high school, the principal should have access to everything and that I guess included web servers in nineteen ninety six. But bottom line is that mistake, that good intention led to a very bad outcome, which was an attacker being able to utilize very simple attack techniques to actually log into that system. No real harm was done, but I think we can all agree that we don’t want people being able to freely log into systems that they should not have access to.

So good intentions don’t secure systems. Good practices do. That’s a core takeaway, I think, from from this session. But what I’ll also say, you know, just in terms of what we see in twenty twenty six, the example I gave from nineteen ninety six is very simple, very straightforward.

It’s a lot different today in healthcare. Things are not simple and straightforward. And the really scary part is that health and patient health, patient lives are potentially at risk when we have ransomware attackers running rampant within healthcare system networks, taking systems down that may be needed to provide the proper care for a patient. So I think we hear about zero trust a lot being a mentality, a philosophy, and an overall program that organizations need to adopt.

It’s true, but we need to keep in mind that zero trust is not a product. It’s a mindset. And critical to that mindset is that we assume compromise and expect that if attackers are not already within our networks, within our systems, they will be.

If we build our and design our security practices, our cybersecurity programs around that assumption, things start to seem a little bit clearer in what it is that we’re actually trying to do. So your policy tools are are really only as good as the identity data that they have access to, and that’s the other critical piece that we’re highlighting here. A modernized, unified identity data platform is critical to be able to really start to address and counter the risks that we see today, particularly in health care.

Brooke Vixamar: Yeah, well said. Great conclusion.

We do have a few minutes for questions, and there have been a number of questions that have come in. So I’m sorry, but we won’t be able to get to all of them. We’re just going to try and knock out a couple of them here. And like I said, we’ll make sure to incorporate them in part two that’s coming up in a couple weeks of this webinar series.

But the questions let me start here, Paul. Where do most organizations discover they have a problem?

Is it audit? Is it an incident or and A due diligence?

Where do you see most organizations having that kind of we have a problem discovery first come up?

Paul Dant: That’s a great question.

So I think if we kind of tackle those three individually, M and A due diligence certainly uncovers risks in a similar fashion, I think, to audit compliance. So we’ll often know that there are problems.

Compliance audits typically have findings. They’re rated.

We can do our best to address those findings.

I think the point here is that we know we have a problem, but it’s the incidents that really show us the breadth and depth of our problems.

An audit finding might tell us that we have poor password policy over our Windows Active Directory accounts, but what it’s not telling us is you have five active directory accounts that are assigned with administrative privileges that don’t belong to any humans that that work for this organization any longer.

That’s a very, very serious challenge when we can’t see we don’t have the proper visibility into those accounts, aligning to when a particular user that owns account an account leaves. So getting back to the question, Brooke, I think organizations tend to truly understand the breadth of their issues once an incident takes place, when they actually see that initial intrusion led to an attacker finding their way across multiple networks into a Microsoft SQL Server database and then being able to take it down such that it’s basically a denial of service attack. Now that hospital, that medical facility no longer has a critical service that’s powered by that SQL Server, and the attackers have complete control over it. That’s a really critical position that a lot of organizations find themselves in during an incident and not necessarily before it, which is what we wanna change.

Brooke Vixamar: Yeah.

Which is why not to make a product pitch out of it, but why what we’re doing with observability and giving that near real time something funny is happening with an identity, flagging it to your Slack system so your your team can be on it as quickly as possible.

Because if you’re waiting until an incident, let alone an audit or due diligence process, something down the road, a quarterly check-in audit as opposed to I mean, they can be in and out in an hour or two, let alone twenty four hours, let alone a quarter. So you have as as much near time, real time observability that you can to to identify those things before they become an incident, all the better. For sure.

Another interesting question, not to open this can of worms, but does any of this change for nonhuman identities in service accounts?

Paul Dant: Another great question.

No, it doesn’t change, but I think this all becomes even more critical when we’re talking about nonhuman identities. Service accounts, of course, are something that we’ve had to deal with for decades now, But we also have new nonhuman identity constructs brought about by cloud platforms. So we have service principles in Entra. We have JSON web tokens. We have all kinds of things that allow us to delegate access through an identity. So this doesn’t necessarily change. It just further emphasizes the need to unify all of that identity data so that we have full visibility over it.

And then some of those factors that we talked about, weak controls, overprivileged accounts certainly tie to nonhuman as well and arguably present an even larger risk because a lot of those nonhuman accounts tend to have more access to systems than human accounts do. They’re doing something behind the scenes with the technology, extracting data, transforming it, loading it.

The bottom line is those nonhuman accounts may have the ability and access to really critical systems within the organization and if we’re not aware of them, we’re not aware of what they are doing, what they’re able to do within systems, when those those accounts are compromised, that’s when these attacks tend to go sideways and present real challenges operationally for the targets.

Brooke Vixamar: Great answer. Great insights. We do have more questions that have come in. We are running out of time at this point.

So I’m gonna compile all those and we’ll make sure that we address them in two weeks when we are joined by Kristin Hoppe. Like I said at the beginning of the call, she runs identity and access management at Baylor Scott and White. She is a just seasoned, experienced, very knowledgeable leader, and we’re really excited to have her join this conversation. So today we talked about the attacker and in our next session, we’ll be able to kind of talk to her about the practitioner’s point.

How does she view all of this? How does she set up her systems and protect her organization? And underlying all of this, when we’re talking about a major health system, how do we consider those real constraints, the trade offs, the decisions that you have to hold up under the pressures of being in a clinical environment. We know this is a special environment with which we have to engage in these conversations and in this payoff.

So we’re really excited to have Kristen join the conversation so we can dig into some of those things. Like I said, when you registered, you should have been able to register for both events. But just in case you didn’t, we’ll send you that registration link so you can make sure to join our session two weeks out. Paul, thank you so much for your time, your insights today.

It was a great conversation. I always love listening to your stories. You have a wealth of experience and knowledge, and I always learn so much when I get to hear from you. Thank you for joining us.

You everyone else for joining our call. I hope you have a great rest of your day.

Paul Dant: Bye, everyone.