scieee Open visual document viewer

Systematic Review of Current Risk Management Methods in Cybersecurity for Healthcare

Soukupová, Marie; Doskočil, Radek

Abstract

Presented systematic review is analyzing cyber risk management, more specifically economic aspect of the measures resulting from the risk analysis, through search of Web of Science and Scopus databases. The article questions the current scientific knowledge in the field of applicability of quantitative methods on measuring of the negative impact of successful cyberattacks. The purpose of the article is to define how these shall be improved for real application in the environment of healthcare, being specific not only by operating with sensitive patient data, but also by the urgency with which system malfunctions must be dealt with in order to prevent threatening the health and lives of patients (the fact that is providing the attacker with a unique position of privilege). While it is apparently necessary to invest more resources into the cybersecurity in healthcare, it is at the same time essential to ensure that these measures are profitable and the resources for them are spent economically. While cost of human life cannot easily be quantified, it is now time to search for methods on how to define an appropriate cybersecurity investment as opposed to the costs of a potential cyberattack.

Full text

Sys ema ic Re iew o Cu en Risk Managemen Me hods in Cybe secu i y o Heal hca e Ma ie SOUKUPOVÁ* and Radek DOSKOČIL B no Uni e si y o Technology, B no, Czech Republic; Ma ie.Soukupo a1@ u .cz; Radek.Doskocil@ u .cz * Co esponding au ho : Ma ie.Soukupo a1@ u .cz Abs ac : P esen ed sys ema ic e iew is analyzingcybe isk managemen , mo e speci ically economic aspec o he measu es esul ing om he isk analysis, h ough sea ch o Web o Science and Scopus da abases. The a icle ques ions he cu en scien i ic knowledge in he ield o applicabili y o quan i a i e me hods on measu ing o he nega i e impac o success ul cybe a acks. The pu pose o he a icle is o de ine how hese shall be imp o ed o eal applica ion in he en i onmen o heal hca e, being speci ic no only by ope a ing wi h sensi i e pa ien da a, bu also by he u gency wi h which sys em mal unc ions mus be deal wi h in o de o p e en h ea ening he heal h and li es o pa ien s ( he ac ha is p o iding he a acke wi h a unique posi ion o p i ilege). While i is appa en ly necessa y o in es mo e esou ces in o he cybe secu i y in heal hca e, i is a he same ime essen ial o ensu e ha hese measu es a e p o i able and he esou ces o hem a e spen economically. While cos o human li e canno easily be quan i ied, i is now ime o sea ch o me hods on how o de ine an app op ia e cybe secu i y in es men as opposed o he cos s o a po en ial cybe a ack. Keywo ds: isk managemen ; cybe secu i y; heal hca e; measu e; cos JEL Classi ica ion: G32; I15; K24 1. In oduc ion Cybe a acks on hospi als a e some hing ha one can come ac oss e y o en hese days. Wi h inc easing numbe o a acks, ollowed by inc ease o cos s o ansom and/o epai s and dec ease o a ailabili y o heal h se ices, he ques ion o how hese si ua ions can be p e en ed na u ally comes o mind. The causes o hese si ua ions (meaning speci ic examples o he lack o cybe secu i y measu es in he cu en heal hca e) oge he wi h he possible me hods o p e en ion (meaning he isk managemen app oaches) will be discussed in his a icle. The aim o his pape is o assess whe he he le el o scien i ic knowledge in he ield o economic op imiza ion o measu es in he cybe isk managemen p ocess in heal hca e is su icien and whe he he cu en me hods de eloped o measu ing cybe isks a e use ul. The basic condi ion o he cybe isk managemen p ocess indica es ha he cos s o secu i y measu es adop ed in o de o p e en cybe a acks shall be p opo ional o he amoun o damage done in case o a success ul cybe a ack (ENISA, 2012). Thus, analyzing he economical aspec o secu i y measu es and especially he me hods used o quan i y i is he aim o his a icle. doi: 10.36689/uhk/hed/2024-01-033 376 The opic o he a icle conce ns mul iple scien i ic ields consis ing o isk managemen on one side, and cybe secu i y in heal hca e on he o he . While cybe secu i y is an u gen and cu en opic amongo ganiza ions a ound he wo ld, one canno onlyunde s andi om he pe spec i e o echnical and echnological imp o emen s, bu mus also always conside he cos so he measu es. Tha is whe e isk managemen and i s me hods s ep in. Vice e sa, cybe secu i y plays an indispensable ole in isk managemen , cybe a acks being o en de ined as he mos se ious and a he same ime p obable isks known o o ganiza ions. The mos common cos o cybe b eaches in heal hca e does no conce n he pu chase o new ha dwa e, bu he dis up ion o ope a ions which means cu ing he hospi al o i s unding om he heal h insu ance companies which a e inancing he ea men s (Lee, 2021). 1.1. Cybe secu i y in Heal hca e Qui e a ew speci ics o he ield o cybe secu i y can be ound, among all else seeing ha i is no some hing ha o ganiza ions would p oudly p oclaim.Fo ob ious easons, i he le el o secu i y is low and p o en by ecen cybe b each, he o ganiza ion will ha e no desi e o publicly alk abou i , bu e en i he le el o secu i y is conside ed high in an o ganiza ion, i is ad ised no o be e y speci ic especially abou i s ulne abili ies. This ac makes esea ch on he opic complica ed. As well as digi aliza ion, he cybe c ime has also been ising exponen ially in he cou se o he pas ew yea s. Wi h he widening o he cybe space in he ecen yea s, equen in oduc ion o new echnologies, he quan i y o de ices in a ne wo k, wi h wi eless ones playing a majo ole, i has become easie o h ea en o ganiza ions. The s a e o cybe secu i y in heal hca e is inadequa e o he s a e o secu i y in o he o ganiza ions, al hough in e es in his opic om he side o senio managemen o heal hca e acili ies has changed conside ably in he pas ew yea s as se e e (especially ansomwa e) a acks on hospi als ha e been success ul and g a ely damaging (Pea s & Kons an inidis, 2021). Ne e heless, cybe secu i y, no being he p ima y se ice ha he medical sec o ocuses on, s ill ge s less a en ion and unding han necessa y (Vuko ich, 2023). Mo eo e , wha some senio manage s do no ealize is ha cybe secu i y does no only a ec heIT depa men , bu he en i e pa ien ca e. As a ma e o ac , close a en ion o he managemen should be paid o e e y aspec o he sys em ha i is o e looking, om he pe spec i e o i s ulne abili ies o i s de ense mechanisms. The p oblem wi h ising in es men s in cybe secu i y is he lackingda a-d i en s a egy (Ro h ock e al., 2017).Indeed ea , a he han a clea ision, should ce ainly no be he p ima y eason o cybe secu i y in es men s. Addi ionally, i is necessa y o he managemen o own esponsibili y o cybe secu i y policies ha i should a i y and comply wi h (Ab aham e al., 2019). I is no wonde ha wi hou cons uc i e guidance om he au ho i ies and wi h he sho age o cybe secu i y specialis s on he labo ma ke , he acili ies a e unce ain abou he secu i y decisions and pu chases ha hey should con ey. As a consequence, mos acili ies lack cybe secu i y s a egies and since public spendings a e being cu due o go e nmen ’s e o s o sa ings in almos all sec o s ([Czech] Go e nmen app o ed he s a e budge o 2024, decided o pu chase F-35 supe sonic ai c a and ook ano he s ep o s eng hen ene gy secu i y, 2023), cybe secu i y budge s o hospi als canalsobe expec ed o dec easein hecu en calenda yea . 377 Fu he mo e, he speci ic ulne abili y o he heal hca e sec o is caused by he sensi i e pa ien da a ha i ope a es wi h. Conside ing ha sensi i e da a is e en mo e alued by hacke s han he da a in banking o e ail sec o s (Syman ec, 2017) pu s ex a s ess on secu i y in his indus y. Hence o h, he human ac o con inues o p o e as he weakes poin o a secu i y sys em in any o ganiza ion (Lo d, 2018), which, in case o heal hca e, is e en ampli ied by he no o ious o e wo k o s a (B anley-Bell e al., 2021). 1.2. De ices and Ne wo ks in Heal hca e Al hough heal hca e acili ies usually do no ope a e wi h In e ne o Things (IoT) de ices since hei echnologies a e mo e ou da ed and he e o e, hey do no ace he se e e h ea s o dis ibu ed denial-o -se ice (DDoS) a acks h ough IoT, hey s ill ace many p oblems conce ning hei ne wo ks. The p oblems a e, o cou se, caused by he ou da ed echnologies hemsel es oge he wi h a lack o su eillance (SCADA) sys ems, esul ing in he ac ha he adminis a o s o en do no ope a e wi h an up- o-da e o e iew o he ne wo ks ha i is hei esponsibili y o moni o . In some sense, one can unde s and medical acili ies as unde de eloped and/o amily businesses in e ms o hei le el o cybe secu i y, main di e ence be ween he wo ca ego ies being he size o he ac ual o ganiza ion whe e hospi als ensu e a wide ange o p ocesses a ying om heal hca e h ough ca e ing o adminis a ion. Howe e , he cu en secu i y conce ns consis no only o s a and es ablished echnological measu es (such as i ewalls, an i i us o enc yp ion) since hese a e no su icien anymo e (B anley-Bell e al., 2021), bu also o inc easingly common wea able de ices, especially hose connec ed o he cloud. These a e a e sion o IoT ha is beginning o be used in heal hca e. As wi h echnological inno a ions in gene al, p essing ocus o de elope son deli e ing he solu ions i s o ma ke pushes p oduc secu i y o hesidelines (Mills e al., 2016). Wea able de ices a e unique in many ways. Fi s o all, hey can no only be comp omised in he sense o a da a b each, bu hey also ha e he po en ial o physically hu he pa ien wea ing hem (Mills e al., 2016), being in di ec con ac wi h hei bodies (Mills e al., 2016). Al hough wea ables a e no he eali y o he majo i y o hospi als oday, hey a ede ini ely helong- e mgoalo heal hca e(since heyp o ide he pa ien s wi haddi ional possibili y o mobili y du ing he eco e y o moni o ing phase o ea men ) which is why i is necessa y o ake hei ulne abili ies in o conside a ion, especially since hey can se e as means o comp omising he en i e ne wo k (Ab aham e al., 2019). 1.3. Da a and Regula ions Recen ine i able igh ening o egula ions conce ning da a p o ec ion (GDPR, 2018) has made i e en mo e di icul o medical (as well as o he ) acili ies o na iga e hemsel es in he cybe secu i y issues (Lee, 2021) which also inc eased equi emen s o al eady unde s a ed cybe secu i y specialis s. A he same ime, mo e ecommenda ions om he go e nmen in o de o educe he di e si y o sys ems in each medical acili y is ad isable. A egula ion named HIPAA (Heal h Insu ance Po abili y and Accoun abili y Ac o 1996, 1996) which is in o ce in he USA can be used as a bes p ac ice, appa en ly aking 378 in o conside a ion he di e ences ha he heal hca e sys ems in he USA and in Eu opean coun ies ha e. Nowadays, da a is he mos aluable asse o o ganiza ions and he e o e needs o be p o ec ed wi h special ca e. A he same ime, in each o ganiza ion, he e a e de ini ely a ious ca ego ies o da a wi h di e en alue. A b each o ca e e ia menus will su ely cos he heal hca e acili y less han he b each o esul s o sc eenings o pa ien s including hei social secu i y numbe s. Tha is why da a wi hin an o ganiza ion shall be classi ied and p o ec ed based on i s impo ance. Heal hca e sec o , o a ce ain ex en compa able o unde de eloped companies, can in some pe spec i e bene i om i s ou da ed echnologies in use. Since he e a e inc easing isks wi h new echnologies (such as cloud se ices), he ac ha hose a e no commonly used in his sec o migh be ecognized as a isk educ ion. Howe e , his a gumen is alse since o en, he issue ha he cloud se ices do no co e mus s ill be eplaced by ano he , o en unsys ema ic and he e o e e en less secu e solu ion. Fo ins ance, o en imes, he pa ien ’s da a (such as sc eenings o scans) is no s o ed on a sha ed cloud s o age, howe e mul iple depa men s o he medical acili y need o access i in o de o p o ide he pa ien wi h u he ea men . Wha hey do is o en ei he send he da a physically (by p in ing each pape ou o w i ing he condi ions down by hand), o send i h ough pe sonal, unsupe ised online communica ion ools (such as Wha sApp o email) while nei he o hese solu ions complies wi h any basic secu i y ules. This is one o he p ocesses ha shall wi hou a doub be eplaced by a obus con olled sys em so ha he en i e heal hca e can sha e necessa y sensi i e in o ma ion in a conside ably sa e way (D ape & Raymond, 2020). The heal hca e sec o is now he e o e acing a c ucial ques ion: how o ully digi alize i s p ocesses and da a. The main isks o he digi al ans o ma ion a e appa en , mos se ious o hem being unau ho ized access o sensi i e da a. Howe e , hose isks (in limi ed sense) al eady occu in he cu en (insu icien ) s a e o digi aliza ion. Wha digi aliza ion comes wi h is he solu ion o backups coun ing wi h high olumes o da a being s o ed a sa e, accessible cybe space so ha hey a e a ailable e en in case o c isis. Concluding ha digi aliza ion is ce ainly he way o go. 1.4. Risk Managemen While all he aspec s o cybe secu i y men ioned abo e can be economically pe cei ed as a cos , he ques ion how omeasu e whe he he cos is adequa e o he isk and cos o po en ial damage done is s ill p esen . Tha is wha he ollowing chap e s o he a icle a e discussing. 2. Me hodology The sys ema ic e iew includes syn hesis o publica ions ha had o ul ill p ede e mined eligibili y c i e ia such as belong o he ca ego y “Economics and Business” wi hin he Web o Science da abase, o be published in 2018 o mo e ecen ly. The a icles we e sea ched wi hin he Web o Science and Scopus da abases using he keywo ds “cybe secu i y” AND “hospi als” and “cybe isk managemen ” AND “heal hca e”. 379 Figu e 1: Flowcha o selec ion p ocess o ele an a icles The indings we e summa ized and he subsequen ou pu s we e analyzed. Implica ions we e d awn based on hem. Rele an s udies we e selec ed while excluding duplici ies, i ele an s udies based on he con en o hei abs ac , and una ailable s udies we e excluded as well as s udies published in p eda o y jou nals. Use ul e e ences om sui able a icles we e used o u he ex ension o he e iew. Apa om he Web o Science and Scopus da abases, a numbe o espec able websi es o egula o y ins i u ions was inspec ed (such as he o icial ENISA websi es) o he pu pose o his e iew. 3. Resul s The e iew has concluded ha he e a e qui e a ew app oaches o cybe isk managemen . Some o hem highligh he echnological measu es (Lockheed, 2009), some o he s poin ou he secu i y o he en i e supply chain (NIST, 2018)and o he ones conside 380 Table 1: Bibliome ic analysis o a icles Au ho Ti le o A icle Ti le o Jou nal Yea o publica ion Lee, In Cybe secu i y: Risk managemen amewo k and in es men cos analysis Business Ho izons 2021 Ab aham, Chon, Cha e jee, Da e, Sims, Ronald R. Muddling h ough cybe secu i y: Insigh s om he U.S. heal hca e indus y Business Ho izons 2019 Ea on, Tim V., G enie , Jona han H., Layman, Da id Accoun ing and Cybe secu i y Risk Managemen Cu en Issues in Audi ing 2019 D ape , Ch is, Raymond, Anjane e H. Building a isk model o da a inciden s: A guide o assis businesses in making e hical da a decisions Business Ho izons 2019 B anley-Bell, Dawn, Co en y, Lynne, Sillence, Elizabe h P omo ing Cybe secu i y Cul u e Change in Heal hca e The 14 h Pe asi e Technologies Rela ed o Assis i e En i onmen s Con e ence 2021 Vuko ich, Geo ge Heal hca e and Cybe secu i y: Taking a Ze o T us App oach Heal h Se ices Insigh s 2023 he human ac o and consequen o ganiza ional measu es as well. While all o ha makes pe ec sense, he p oblem in ques ion is no only he de ini ion o he measu es hemsel es, as much as measu ing o hei cos s and he cos s o a po en ial cybe b each, ollowed by a cos -bene i analysis. Cybe secu i y depa men s should h i e o quan i y he impac s o isks as well as measu es in o de o jus i y in es men s in o hem (Lee, 2021) which is whe e he e iew ound a blind spo . No ha ing access o accu a e quan i ied da a makes he wo k o cybe secu i y manage s in all so s o o ganiza ions conside ably mo e di icul especially in he aspec o nego ia ions on unding o cybe measu es wi h he op managemen . A ew o he pape s ha we e analyzed o he pu pose o his e iew o e somewha o a solu ion. The p oposed cybe isk managemen amewo k designs ou laye s consis ing o cybe ecosys em (ou side o he o ganiza ion i sel ), cybe in as uc u e (o ganiza ion, employees, echnologies), cybe isk assessmen (designing he isk managemen oge he wi h in es men s needed) and cybe pe o mance (consis ing o he implemen a ion, moni o ing and con inuous imp o emen o he cybe isk managemen ) (Lee, 2021) ha a e o be go e ned by he cybe isk managemen . Beyond doub , he ecosys em laye (Lee, 2021) is a a he impo an one in case o heal hca e, aking in o accoun he di e en s akeholde s in- and ou side o i s own ield. Di e en heal hca e acili ies shall be able (unde he condi ion o accessing only he da a ele an o hei own wo k – meaning he da a o he pa ien s ha a e in hei ca e – no he da a o all pa ien s as is o en he case) o exchange and discuss in o ma ion ela ed o he pa ien . 381 The e a e also ongoing deba es abou whe he heal hca e da a should be used o o he public se ice pu poses (such as gi ing ax bene i s o paye s ha p o e ha hey a end check-ups). These deba es a e o cou se highly hypo he ical a he momen since he e a e conside able p oblems accompanying he ans e o da a wi hin he heal hca e sec o i sel , le alone i s ans e beyond i . Howe e , his only p o es he impo ance o aking he su oundings o a single hospi al in o accoun when designing a cybe isk managemen amewo k in i . In case o heal hca e, he ecosys em consis s mainly o i s global supply chain managemen , pa ien s, au ho i ies, and he heal h insu ance companies which a e usually he main p o ide s o income o he hospi als. Rega ding cybe secu i y a ea speci ically, one shall also ake in o accoun he consul ing specialis s and he hacke s. Nex on he lis , he cybe in as uc u e laye , consis ing o IT and non-IT s a as well as echnologies wi hin he o ganiza ion (Lee, 2021), shall in opinion o he au ho so his e iew be mo e speci ied by he public au ho i ies, especially om he echnological poin o iew. Fi s o all, IT s a in hospi als could use guidelines o ollow whe eas minimaliza ion o he di e si y o ne wo ks in heal hca e would help inc ease secu i y o e all. Cybe de ense s a egies ollowed by ecu ing ainings o all s a and possibly mos impo an ly, a cul u e o posi i e cybe secu i y beha io , a e a pa o his laye (Lee, 2021). O cou se, keeping he echnologies upda ed oge he wi h an o e iew o hei ulne abili ies is essen ial he e as well. Da a also alls unde his laye , nowadays being he p ima y a ge o he cybe a acks in heal hca e and ou side o i (Lee, 2021). Cybe isk assessmen laye is whe e his e iew can ge inspi ed by s anda d isk managemen app oaches, h ough isk iden i ica ion, i s quan i ica ion and cybe in es men analysis (Lee, 2021). Iden i ica ion o cybe isks can be done by lea ning om success ul cybe a acks ca ied ou on simila o ganiza ions (o cou se, he de ails o which he ic ims usually wan o keep p i a e because o he damage done o hei co po a e epu a ion). This is whe e expe ienced cybe secu i y consul ing specialis s can p o e e y use ul since hey usually o e look a numbe o somewha simila o ganiza ions. Once again, isk quan i ica ion is necessa y o e iciency o in es men s in o secu i y (Chen e al., 2011). While he me hod o cybe laye s analyzed abo e, being one o he sca ce numbe o me hods published in scien i ic ci cles in ecen yea s, desc ibes he cybe isk managemen om all he di e en pe spec i es ha need o be aken in o conside a ion, i lacks a speci ic quan i ica ion me hod ha could be used in he heal hca e sec o . The eason o quan i ica ion is as ollows: secu i y can ne e be es ablished up o he poin o elimina ion o all isks, bo h om echnological poin o iew, whe e all isks can ne e be o eseen, and om he cos -bene i poin o iew, whe e cos o some measu es exceeds he cos o damage done by ce ain isks. The e o e, he ealis ic secu i y app oach mus be o educe he isk as long as implemen a ion o measu es agains his isk has he same alue as addi ional sa ings om possible inciden s caused by i . Indeed, he p ocess o es ima ing his alue is whe e quan i a i e me hods a e needed, he issue wi h hem being he lack o a s anda d ha would 382 help de e mine he cos s o secu i y measu es as well as cos s o asse s ha a e being p o ec ed by hem (Bojanc & Je man-Blažič, 2008). Some o he a iables ha he pape s analyzed o he pu poses o his e iew men ioned as app op ia e o quan i ica ion we e namely equencies o cybe a acks as well as inancial losses esul ing om each o hem (Lee, 2021). Na u ally, s a is ical me hods (such as he p obabili y densi y unc ion) can also be used, al hough da a om a SCADA moni o ing sys em may be conside ably mo e accu a e. Abo e all, he cos o acybe b eachshall include ines, cos s o lawye s and consul an s hi ed o se le he p oblem and he alue o da a eleased (Lee, 2021),in case o heal hca e ex ended by he ansom, eloca ion o pa ien s o o he si es, he cos o go e nmen penal ies, eco e ing da a and eplacing equipmen oge he wi h damage o epu a ion (Ab aham e al., 2019). While scien i ically discussing di e en possible a iables ha could be included in a quan i a i e model, we canno o ge o ake he eali y in p ac ice in o accoun . I is possible ha a gi en cybe secu i y manage migh no ha e access o all inance- ela ed in o ma ion in he o ganiza ion. Be o e designing a easible quan i a i e cybe isk model, i is he e o e necessa y o in e iew he p o essionals ho oughly. The mo e p ecisely he isk is quan i ied, he easie i should be o ad oca e o he in es men in he secu i y measu es h ough an elabo a e cos -bene i analysis. Ano he app oach men ioned in he analyzed pape s desc ibes compa ing inancial loss in case o a cybe b each o he cybe in es men cos , meaning he expenses o cybe secu i y (Lee, 2021), sugges ing a a he b oad and unspeci ied a iable. 4. Discussion The e iew p o ed ha he e is a scien i ic gap in he sense o a quan i a i e cybe isk model ha is cu en ly missing. A numbe o scien i ic pape s published in espec able jou nals was analyzed in o de o con i m he need o a quan i a i e app oach in he de ined opic. A ew o hem indica ed sui able a iables o be included in such a quan i a i e model, hough o en wi hou a p ope conside a ion o whe he he alues o hese a iables a e accessible o he cybe secu i y expe s wi hin he o ganiza ion which is applying he model in p ac ice. The appa en ecommenda ion o he au ho s o his e iew conce ns consul ing an ex e nal cybe secu i y specialis a he han assigning he cybe secu i y ole o a andomly selec ed membe o he IT depa men . While lea ning om p e ious cybe a acks in simila acili ies migh be di icul due o hei will o keep he de ails o he inciden s p i a e, cybe secu i y expe s a e he ones able o sha e he lessons lea ned since hey we e o en he ones wi nessing i happen. Clea ly, he e is space o u u e esea ch in his a ea. One o he appa en di ec ions includes coope a ion among di e en depa men s o a heal hca e acili y. As desc ibed in mo e de ail abo e, cybe a acks a e no jus he issue o one depa men since hey e ec he en i e acili y. The e o e, i is only logical o suppo coope a ion o mul iple pa s o he acili y o p e en hem. Wha he au ho s o he e iew ind especially po en ially ui ul is he coope a ion o cybe secu i y manage s and accoun an s who may be mo e compe en o 383 quan i y ce ain isks and cos s associa ed wi h cybe a acks. Accoun an s, being expe s in his ield, shall o e hei ad iso y and/o assu ance capaci ies (Ea on e al., 2019). Only wi h speci ic and measu able impac o cybe a acks se ing as p oo can cybe secu i y manage s ob ain be e inancial suppo o he p o ec ion o he ne wo ks om he side o he senio managemen . And ha is why a quan i a i e cybe isk model is needed. Fu he mo e, ano he esea ch di ec ion is a hand: du ing he design o he new model, au ho s mus no o ge o consul he cybe secu i y expe s in p ac ice in o de o include a iables ha hey ha e access o and ensu e he model’s easibili y and use ulness. Thus, ase o in e iews o ques ionnai es shall be conduc ed and analyzed o u u e s eps o he esea ch. The au ho s o he e iew would, among all else, like o s a is ically e i y hei assump ion ha cybe secu i y s a in heal hca e may bene i om ad anced le el o go e nmen suppo in he o m o o icial ecommenda ions ega ding ne wo k esilience e c. A ool whose applicabili y in he ield o cybe secu i y in heal hca e shall beexamined om he poin o iew o scien i ic esea ch is also he a i icial in elligence. Many a e discussing i s secu i y isks, bu o ge ing ha i migh be used as a pa o secu i y i sel , especially in he con ex o sho age o s a and expe s in cybe secu i y, namely isible in heal hca e. The e iew de ined a need o a easible quan i a i e cybe isk model usable in heal hca e which he p ac ice is now lacking, esul ing in low secu i y o e all. While de ining he new model, no only shall he expe s in p ac ice be in e iewed, bu emphasis on con inuous imp o emen shall be emembe ed since e e y model becomes less accu a e wi h ime passed, especially when i conce ns he apidly de eloping ield o IT. One does no need o be a cybe secu i y expe o no ice he ac ha cybe a acks on hospi als ha e been ising in he pas yea s. By being able o measu e he cos s and bene i s o secu i y as well as he cos s o damage done, hospi als (as well as o he o ganiza ions) will be able o make in o med and s a egic decisions conce ning hei secu i y and hei pa ien s will be able o eco e in a sa e space. By building esilien ne wo ks suppo ed by e i ied p o ide s, he cybe a acks shall become less and less success ul, e en ually making heal hca e sec o unappealing o hacke s o whom i will be ha d o a ec i and hospi als shall once again become he places whe e ci izens in hei g ea es need will come wi h ull us in he ins i u ions o heal hca e as well as he s a e i sel . Con lic o in e es : none. Re e ences [Czech] Go e nmen app o ed he s a e budge o 2024, decided o pu chase F-35 supe sonic ai c a and ook ano he s ep o s eng hen ene gy secu i y. (2023). Vláda České epubliky. Re ie ed Janua y 10, 2024, om h ps:// lada.go .cz/cz/media-cen um/ak ualne/ lada-sch alila-s a ni- ozpoce -na- ok-2024-- ozhodla-o- nakupu-nadz uko ych-le ounu- -35-a-ucinila-dalsi-k ok-k-posileni-ene ge icke-bezpecnos i-208775/ Ab aham, C., Cha e jee, D., & Sims, R. R. (2019). Muddling h ough cybe secu i y: Insigh s om he U.S. heal hca e indus y. Business Ho izons,62(4), 539-548. h ps://doi.o g/10.1016/j.busho .2019.03.010 Bojanc, R., & Je man-Blažič, B. (2008). An economic modelling app oach o in o ma ion secu i y isk managemen . In e na ional Jou nal o In o ma ion Managemen ,28(5), 413-422. h ps://doi.o g/10.1016/j.ijin omg .2008.02.002 B anley-Bell, D., Co en y, L., & Sillence, E. (2021). P omo ing Cybe secu i y Cul u e Change in Heal hca e. In P oceedings o he 14 h PE asi e Technologies Rela ed o Assis i e En i onmen s Con e ence (pp. 544-549). h ps://doi.o g/10.1145/3453892.3461622 384