Cargando…
Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study
BACKGROUND: Cyber threats are increasing across all business sectors, with health care being a prominent domain. In response to the ever-increasing threats, health care organizations (HOs) are enhancing the technical measures with the use of cybersecurity controls and other advanced solutions for fu...
Autores principales: | , , , , , , , , , |
---|---|
Formato: | Online Artículo Texto |
Lenguaje: | English |
Publicado: |
JMIR Publications
2023
|
Materias: | |
Acceso en línea: | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10415935/ https://www.ncbi.nlm.nih.gov/pubmed/37498644 http://dx.doi.org/10.2196/41294 |
_version_ | 1785087658692706304 |
---|---|
author | Argyridou, Elina Nifakos, Sokratis Laoudias, Christos Panda, Sakshyam Panaousis, Emmanouil Chandramouli, Krishna Navarro-Llobet, Diana Mora Zamorano, Juan Papachristou, Panagiotis Bonacina, Stefano |
author_facet | Argyridou, Elina Nifakos, Sokratis Laoudias, Christos Panda, Sakshyam Panaousis, Emmanouil Chandramouli, Krishna Navarro-Llobet, Diana Mora Zamorano, Juan Papachristou, Panagiotis Bonacina, Stefano |
author_sort | Argyridou, Elina |
collection | PubMed |
description | BACKGROUND: Cyber threats are increasing across all business sectors, with health care being a prominent domain. In response to the ever-increasing threats, health care organizations (HOs) are enhancing the technical measures with the use of cybersecurity controls and other advanced solutions for further protection. Despite the need for technical controls, humans are evidently the weakest link in the cybersecurity posture of HOs. This suggests that addressing the human aspects of cybersecurity is a key step toward managing cyber-physical risks. In practice, HOs are required to apply general cybersecurity and data privacy guidelines that focus on human factors. However, there is limited literature on the methodologies and procedures that can assist in successfully mapping these guidelines to specific controls (interventions), including awareness activities and training programs, with a measurable impact on personnel. To this end, tools and structured methodologies for assisting higher management in selecting the minimum number of required controls that will be most effective on the health care workforce are highly desirable. OBJECTIVE: This study aimed to introduce a cyber hygiene (CH) methodology that uses a unique survey-based risk assessment approach for raising the cybersecurity and data privacy awareness of different employee groups in HOs. The main objective was to identify the most effective strategy for managing cybersecurity and data privacy risks and recommend targeted human-centric controls that are tailored to organization-specific needs. METHODS: The CH methodology relied on a cross-sectional, exploratory survey study followed by a proposed risk-based survey data analysis approach. First, survey data were collected from 4 different employee groups across 3 European HOs, covering 7 categories of cybersecurity and data privacy risks. Next, survey data were transcribed and fitted into a proposed risk-based approach matrix that translated risk levels to strategies for managing the risks. RESULTS: A list of human-centric controls and implementation levels was created. These controls were associated with risk categories, mapped to risk strategies for managing the risks related to all employee groups. Our mapping empowered the computation and subsequent recommendation of subsets of human-centric controls to implement the identified strategy for managing the overall risk of the HOs. An indicative example demonstrated the application of the CH methodology in a simple scenario. Finally, by applying the CH methodology in the health care sector, we obtained results in the form of risk markings; identified strategies to manage the risks; and recommended controls for each of the 3 HOs, each employee group, and each risk category. CONCLUSIONS: The proposed CH methodology improves the CH perception and behavior of personnel in the health care sector and provides risk strategies together with a list of recommended human-centric controls for managing a wide range of cybersecurity and data privacy risks related to health care employees. |
format | Online Article Text |
id | pubmed-10415935 |
institution | National Center for Biotechnology Information |
language | English |
publishDate | 2023 |
publisher | JMIR Publications |
record_format | MEDLINE/PubMed |
spelling | pubmed-104159352023-08-12 Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study Argyridou, Elina Nifakos, Sokratis Laoudias, Christos Panda, Sakshyam Panaousis, Emmanouil Chandramouli, Krishna Navarro-Llobet, Diana Mora Zamorano, Juan Papachristou, Panagiotis Bonacina, Stefano J Med Internet Res Original Paper BACKGROUND: Cyber threats are increasing across all business sectors, with health care being a prominent domain. In response to the ever-increasing threats, health care organizations (HOs) are enhancing the technical measures with the use of cybersecurity controls and other advanced solutions for further protection. Despite the need for technical controls, humans are evidently the weakest link in the cybersecurity posture of HOs. This suggests that addressing the human aspects of cybersecurity is a key step toward managing cyber-physical risks. In practice, HOs are required to apply general cybersecurity and data privacy guidelines that focus on human factors. However, there is limited literature on the methodologies and procedures that can assist in successfully mapping these guidelines to specific controls (interventions), including awareness activities and training programs, with a measurable impact on personnel. To this end, tools and structured methodologies for assisting higher management in selecting the minimum number of required controls that will be most effective on the health care workforce are highly desirable. OBJECTIVE: This study aimed to introduce a cyber hygiene (CH) methodology that uses a unique survey-based risk assessment approach for raising the cybersecurity and data privacy awareness of different employee groups in HOs. The main objective was to identify the most effective strategy for managing cybersecurity and data privacy risks and recommend targeted human-centric controls that are tailored to organization-specific needs. METHODS: The CH methodology relied on a cross-sectional, exploratory survey study followed by a proposed risk-based survey data analysis approach. First, survey data were collected from 4 different employee groups across 3 European HOs, covering 7 categories of cybersecurity and data privacy risks. Next, survey data were transcribed and fitted into a proposed risk-based approach matrix that translated risk levels to strategies for managing the risks. RESULTS: A list of human-centric controls and implementation levels was created. These controls were associated with risk categories, mapped to risk strategies for managing the risks related to all employee groups. Our mapping empowered the computation and subsequent recommendation of subsets of human-centric controls to implement the identified strategy for managing the overall risk of the HOs. An indicative example demonstrated the application of the CH methodology in a simple scenario. Finally, by applying the CH methodology in the health care sector, we obtained results in the form of risk markings; identified strategies to manage the risks; and recommended controls for each of the 3 HOs, each employee group, and each risk category. CONCLUSIONS: The proposed CH methodology improves the CH perception and behavior of personnel in the health care sector and provides risk strategies together with a list of recommended human-centric controls for managing a wide range of cybersecurity and data privacy risks related to health care employees. JMIR Publications 2023-07-27 /pmc/articles/PMC10415935/ /pubmed/37498644 http://dx.doi.org/10.2196/41294 Text en ©Elina Argyridou, Sokratis Nifakos, Christos Laoudias, Sakshyam Panda, Emmanouil Panaousis, Krishna Chandramouli, Diana Navarro-Llobet, Juan Mora Zamorano, Panagiotis Papachristou, Stefano Bonacina. Originally published in the Journal of Medical Internet Research (https://www.jmir.org), 27.07.2023. https://creativecommons.org/licenses/by/4.0/This is an open-access article distributed under the terms of the Creative Commons Attribution License (https://creativecommons.org/licenses/by/4.0/), which permits unrestricted use, distribution, and reproduction in any medium, provided the original work, first published in the Journal of Medical Internet Research, is properly cited. The complete bibliographic information, a link to the original publication on https://www.jmir.org/, as well as this copyright and license information must be included. |
spellingShingle | Original Paper Argyridou, Elina Nifakos, Sokratis Laoudias, Christos Panda, Sakshyam Panaousis, Emmanouil Chandramouli, Krishna Navarro-Llobet, Diana Mora Zamorano, Juan Papachristou, Panagiotis Bonacina, Stefano Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study |
title | Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study |
title_full | Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study |
title_fullStr | Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study |
title_full_unstemmed | Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study |
title_short | Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study |
title_sort | cyber hygiene methodology for raising cybersecurity and data privacy awareness in health care organizations: concept study |
topic | Original Paper |
url | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10415935/ https://www.ncbi.nlm.nih.gov/pubmed/37498644 http://dx.doi.org/10.2196/41294 |
work_keys_str_mv | AT argyridouelina cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy AT nifakossokratis cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy AT laoudiaschristos cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy AT pandasakshyam cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy AT panaousisemmanouil cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy AT chandramoulikrishna cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy AT navarrollobetdiana cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy AT morazamoranojuan cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy AT papachristoupanagiotis cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy AT bonacinastefano cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy |