Cargando…

Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study

BACKGROUND: Cyber threats are increasing across all business sectors, with health care being a prominent domain. In response to the ever-increasing threats, health care organizations (HOs) are enhancing the technical measures with the use of cybersecurity controls and other advanced solutions for fu...

Descripción completa

Detalles Bibliográficos
Autores principales: Argyridou, Elina, Nifakos, Sokratis, Laoudias, Christos, Panda, Sakshyam, Panaousis, Emmanouil, Chandramouli, Krishna, Navarro-Llobet, Diana, Mora Zamorano, Juan, Papachristou, Panagiotis, Bonacina, Stefano
Formato: Online Artículo Texto
Lenguaje:English
Publicado: JMIR Publications 2023
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10415935/
https://www.ncbi.nlm.nih.gov/pubmed/37498644
http://dx.doi.org/10.2196/41294
_version_ 1785087658692706304
author Argyridou, Elina
Nifakos, Sokratis
Laoudias, Christos
Panda, Sakshyam
Panaousis, Emmanouil
Chandramouli, Krishna
Navarro-Llobet, Diana
Mora Zamorano, Juan
Papachristou, Panagiotis
Bonacina, Stefano
author_facet Argyridou, Elina
Nifakos, Sokratis
Laoudias, Christos
Panda, Sakshyam
Panaousis, Emmanouil
Chandramouli, Krishna
Navarro-Llobet, Diana
Mora Zamorano, Juan
Papachristou, Panagiotis
Bonacina, Stefano
author_sort Argyridou, Elina
collection PubMed
description BACKGROUND: Cyber threats are increasing across all business sectors, with health care being a prominent domain. In response to the ever-increasing threats, health care organizations (HOs) are enhancing the technical measures with the use of cybersecurity controls and other advanced solutions for further protection. Despite the need for technical controls, humans are evidently the weakest link in the cybersecurity posture of HOs. This suggests that addressing the human aspects of cybersecurity is a key step toward managing cyber-physical risks. In practice, HOs are required to apply general cybersecurity and data privacy guidelines that focus on human factors. However, there is limited literature on the methodologies and procedures that can assist in successfully mapping these guidelines to specific controls (interventions), including awareness activities and training programs, with a measurable impact on personnel. To this end, tools and structured methodologies for assisting higher management in selecting the minimum number of required controls that will be most effective on the health care workforce are highly desirable. OBJECTIVE: This study aimed to introduce a cyber hygiene (CH) methodology that uses a unique survey-based risk assessment approach for raising the cybersecurity and data privacy awareness of different employee groups in HOs. The main objective was to identify the most effective strategy for managing cybersecurity and data privacy risks and recommend targeted human-centric controls that are tailored to organization-specific needs. METHODS: The CH methodology relied on a cross-sectional, exploratory survey study followed by a proposed risk-based survey data analysis approach. First, survey data were collected from 4 different employee groups across 3 European HOs, covering 7 categories of cybersecurity and data privacy risks. Next, survey data were transcribed and fitted into a proposed risk-based approach matrix that translated risk levels to strategies for managing the risks. RESULTS: A list of human-centric controls and implementation levels was created. These controls were associated with risk categories, mapped to risk strategies for managing the risks related to all employee groups. Our mapping empowered the computation and subsequent recommendation of subsets of human-centric controls to implement the identified strategy for managing the overall risk of the HOs. An indicative example demonstrated the application of the CH methodology in a simple scenario. Finally, by applying the CH methodology in the health care sector, we obtained results in the form of risk markings; identified strategies to manage the risks; and recommended controls for each of the 3 HOs, each employee group, and each risk category. CONCLUSIONS: The proposed CH methodology improves the CH perception and behavior of personnel in the health care sector and provides risk strategies together with a list of recommended human-centric controls for managing a wide range of cybersecurity and data privacy risks related to health care employees.
format Online
Article
Text
id pubmed-10415935
institution National Center for Biotechnology Information
language English
publishDate 2023
publisher JMIR Publications
record_format MEDLINE/PubMed
spelling pubmed-104159352023-08-12 Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study Argyridou, Elina Nifakos, Sokratis Laoudias, Christos Panda, Sakshyam Panaousis, Emmanouil Chandramouli, Krishna Navarro-Llobet, Diana Mora Zamorano, Juan Papachristou, Panagiotis Bonacina, Stefano J Med Internet Res Original Paper BACKGROUND: Cyber threats are increasing across all business sectors, with health care being a prominent domain. In response to the ever-increasing threats, health care organizations (HOs) are enhancing the technical measures with the use of cybersecurity controls and other advanced solutions for further protection. Despite the need for technical controls, humans are evidently the weakest link in the cybersecurity posture of HOs. This suggests that addressing the human aspects of cybersecurity is a key step toward managing cyber-physical risks. In practice, HOs are required to apply general cybersecurity and data privacy guidelines that focus on human factors. However, there is limited literature on the methodologies and procedures that can assist in successfully mapping these guidelines to specific controls (interventions), including awareness activities and training programs, with a measurable impact on personnel. To this end, tools and structured methodologies for assisting higher management in selecting the minimum number of required controls that will be most effective on the health care workforce are highly desirable. OBJECTIVE: This study aimed to introduce a cyber hygiene (CH) methodology that uses a unique survey-based risk assessment approach for raising the cybersecurity and data privacy awareness of different employee groups in HOs. The main objective was to identify the most effective strategy for managing cybersecurity and data privacy risks and recommend targeted human-centric controls that are tailored to organization-specific needs. METHODS: The CH methodology relied on a cross-sectional, exploratory survey study followed by a proposed risk-based survey data analysis approach. First, survey data were collected from 4 different employee groups across 3 European HOs, covering 7 categories of cybersecurity and data privacy risks. Next, survey data were transcribed and fitted into a proposed risk-based approach matrix that translated risk levels to strategies for managing the risks. RESULTS: A list of human-centric controls and implementation levels was created. These controls were associated with risk categories, mapped to risk strategies for managing the risks related to all employee groups. Our mapping empowered the computation and subsequent recommendation of subsets of human-centric controls to implement the identified strategy for managing the overall risk of the HOs. An indicative example demonstrated the application of the CH methodology in a simple scenario. Finally, by applying the CH methodology in the health care sector, we obtained results in the form of risk markings; identified strategies to manage the risks; and recommended controls for each of the 3 HOs, each employee group, and each risk category. CONCLUSIONS: The proposed CH methodology improves the CH perception and behavior of personnel in the health care sector and provides risk strategies together with a list of recommended human-centric controls for managing a wide range of cybersecurity and data privacy risks related to health care employees. JMIR Publications 2023-07-27 /pmc/articles/PMC10415935/ /pubmed/37498644 http://dx.doi.org/10.2196/41294 Text en ©Elina Argyridou, Sokratis Nifakos, Christos Laoudias, Sakshyam Panda, Emmanouil Panaousis, Krishna Chandramouli, Diana Navarro-Llobet, Juan Mora Zamorano, Panagiotis Papachristou, Stefano Bonacina. Originally published in the Journal of Medical Internet Research (https://www.jmir.org), 27.07.2023. https://creativecommons.org/licenses/by/4.0/This is an open-access article distributed under the terms of the Creative Commons Attribution License (https://creativecommons.org/licenses/by/4.0/), which permits unrestricted use, distribution, and reproduction in any medium, provided the original work, first published in the Journal of Medical Internet Research, is properly cited. The complete bibliographic information, a link to the original publication on https://www.jmir.org/, as well as this copyright and license information must be included.
spellingShingle Original Paper
Argyridou, Elina
Nifakos, Sokratis
Laoudias, Christos
Panda, Sakshyam
Panaousis, Emmanouil
Chandramouli, Krishna
Navarro-Llobet, Diana
Mora Zamorano, Juan
Papachristou, Panagiotis
Bonacina, Stefano
Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study
title Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study
title_full Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study
title_fullStr Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study
title_full_unstemmed Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study
title_short Cyber Hygiene Methodology for Raising Cybersecurity and Data Privacy Awareness in Health Care Organizations: Concept Study
title_sort cyber hygiene methodology for raising cybersecurity and data privacy awareness in health care organizations: concept study
topic Original Paper
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10415935/
https://www.ncbi.nlm.nih.gov/pubmed/37498644
http://dx.doi.org/10.2196/41294
work_keys_str_mv AT argyridouelina cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy
AT nifakossokratis cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy
AT laoudiaschristos cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy
AT pandasakshyam cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy
AT panaousisemmanouil cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy
AT chandramoulikrishna cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy
AT navarrollobetdiana cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy
AT morazamoranojuan cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy
AT papachristoupanagiotis cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy
AT bonacinastefano cyberhygienemethodologyforraisingcybersecurityanddataprivacyawarenessinhealthcareorganizationsconceptstudy