HSCIC Cyber Security Presented by: Richard Ives - Stakeholder Engagement Manager IGA Conference - 16 Mar 2016.

Slides:



Advertisements
Similar presentations
Personalisation Implications for the workforce. On the internal workforce –What does the new agenda mean for social care staff? –What changes will we.
Advertisements

Informatics priorities and strategy Chris Carrigan Deputy to the PHE Chief Knowledge Officer, Information Services.
Well Connected: History A reminder - previous presentation in December 2013: Arose out of Acute Services Review Formal collaboration between WCC, all.
Changing Lives Induction Jenny Atkinson Innovation, Organisational and Community Development Manager.
A Covenant University Presentation By Favour Femi-Oyewole, BSc, MSc (Computer Science), MSc (Information Security) Certified COBIT 5 Assessor /Certified.
Integrated Digital Care Records and Interoperability Inderjit Singh Head of Enterprise Architecture 12 November 2014 Health Insights.
National Update: The information revolution and the 2012 Caldicott Review Simon Richardson – Information Rights Manager.
The Care Debate: an NHS provider perspective Dr Ros Tolcher Chief Executive, Harrogate and District NHS Foundation Trust National Care Association Symposium.
Data Protection in Higher Education: Recent Experiences in Privacy and Security Institute for Computer Law and Policy Cornell University June 29, 2005.
Patient Advice and Liaison Service NHS Devon, Plymouth and Torbay The work of PALS Patient transport Health and Wellbeing Boards.
Resiliency Rules: 7 Steps for Critical Infrastructure Protection.
NHS Greater Glasgow & Clyde Local Data Sharing Partnership Case Study “ Data Sharing Enabled by Clinical Portal Technologies” George Lynch Information.
NHS England & Customer Contact Centre FOI Introduction 2013.
Safeguarding Adults Board 6 th Annual Conference Adult Safeguarding and the NHS Alison Knowles Commissioning Director NHS England, West Yorkshire.
Satbinder Sanghera, Director of Partnerships and Governance
CCG Strategy Update Lewisham Children and Young People Strategic Partnership Board 26 th January 2015.
Open Data Platform Supplier Forum 13 January 2012.
1. How can we promote pharmacies and the full service available? Think about: How the NHS works with Local Authorities to enhance the role of community.
IAEA International Atomic Energy Agency IAEA Nuclear Security Programme Enhancing cybersecurity in nuclear infrastructure TWG-NPPIC – IAEA May 09 – A.
© British Telecommunications plc Workshop Outputs.
Having your say within the new NHS health structures.
Commissioner Feedback for SLAM CQC Inspection in September 2015 Engagement with Member Practices 1.
Trevor Single Chief Executive Officer Telecare Services Association United Kingdom.
Mapping the Future A Vision for health and social care provision in Harrogate and Rural District.
ProMISE Proactive Management and Integrated Services for the Elderly ProMISE The Bromley Programme Sam Merridale, Programme Lead June 2012.
The power of information Putting all of us in control of the health and care information we need Dr Susan Hamer National Director of Nursing, Midwifery.
Improving Outcomes through Integrated Care Dr Anne Hendry National Clinical Lead for Integrated Care Joint Improvement Team.
℠ Pryvos ℠ Computer Security and Forensic Services May 27, 2015 Copyright © 2015 Pryvos, Inc. 1.
The New NHS Opportunities for Optometrists Chris Town Acting Chief Executive Cambridgeshire PCT.
Operating effectively as a Chief Clinical Information Officer Dr Phil Koczan CCIO UCLP.
Heart of England NHS Foundation Trust CSS Division National Survey Outcomes & Staff Engagement, 2012 With comparison where applicable: Heart of England.
Presentation heading Presented by / Sub-heading Commissioning Explained Sarah Freeman Local Service Specialist – West Midlands Team.
Engaging with Clinical Commissioning Groups (CCGs)
Access to data for local authority public health AGW Public Health Network Training Event: Public Health Data, Information and Intelligence 11 th November.
Anne Foley Senior Advisor, Ministry of Health New Zealand Framework for Dementia Care.
Engineering and Management of Secure Computer Networks School of Engineering © Steve Woodhead 2009 Corporate Governance and Information Security (InfoSec)
ANSI/ISA Workshop Chapter 4: External Communications and Crisis Management Team.
Improving Purchasing of Clinical Services* 21 st October 2005 *connectedthinking 
Housing with Care and Support. Workforce challenges and solutions.
Regional Telecommunications Workshop on FMRANS 2015 Presentation.
Practice Based Commissioning. Who We Are Large PBC Consortium - 75 Practices, 351 GPs, 652,000 population Majority of Northamptonshire covered4 locality.
Friday 22nd April 2016 DS Chris Greatorex SEROCU
Information Sharing for Integrated Care A 5 Step Blueprint.
EUROPEAN SECURITY POLICY A SNAPSHOT ON SURVEILLANCE AND PRIVACY DESSI WORKSHOP, CPH 24 JUNE 2014 Birgitte Kofod Olsen, Chair Danish Council for Digital.
CLOSE THE SECURITY GAP WITH IT SOLUTIONS FROM COMPUTACENTER AND CISCO AUGUST 2014.
Middle Managers Workshop 2: Measuring Progress. An opportunity for middle managers… Two linked workshops exploring what it means to implement the Act.
Cyber Security – Client View Peter Gibbons | Head of Cyber Security, Group Business Services Suppliers’ Summer Conference 15/07/2015.
Integrated Urgent Care Eileen Sutton, Head of Service Design and Innovation (111 and Urgent Care), Healthy London Partnership Dawn Chamberlain, Chief Operating.
Data Security and NDG Review Supporting the Wider System and National Data Guardian Review Presented by Chris Flynn Senior Service Manager NHS Digital’s.
Cyber Security Phillip Davies Head of Content, Cyber and Investigations.
Data Security How can healthcare organisations defend themselves from cyber attacks? Presented by Dan Taylor Head of Security NHS Digital’s Data Security.
Knowledge for Healthcare: Driver Diagrams October 2016
Cybersecurity, competence and preparedness
Cybersecurity - What’s Next? June 2017
Information Sharing for Integrated care A 5 Step Blueprint
Cyber Security: State of the Nation
Introduction to the Federal Defense Acquisition Regulation
About the national data opt-out
Cyber Security coordination in Europe CERT-EU’s perspective
National Cyber Security Programme Local : Building Resilience Together
Reducing Cyber Security Risks in the UK Public Sector
Reporting personal data breaches to the ICO
CRITICAL INFRASTRUCTURE CYBERSECURITY
Let’s plan Health and Care in Hereford
Public engagement strategy
Commissioner Feedback for SLAM CQC Inspection in September 2015
Cyber Security in a Risk Management Framework
Care Managers Network June 2019 Jenny Turner
“Workplace Behaviour: Activating your greatest security asset”
Thames Valley Chamber / Claire Logic
Presentation transcript:

HSCIC Cyber Security Presented by: Richard Ives - Stakeholder Engagement Manager IGA Conference - 16 Mar 2016

What is Cyber Security? “Refers to the management and application of Information Security standards. Applies to computers, computer networks, and the data stored and transmitted. Also covers physical and personnel security” Actually, its what we’ve always done - must do more of and must do better - it’s a brand 2

Cyber Threat in Health is Growing 3 Data security Incidents by Sector Health sector data security incidents over time Source Information Commissioners Office (ICO) In Q2 2015/16 Data Security Incidents are highest in the health sector compared to other sectors The trend is rising in respect of data security incidents in health

The Actors of Cyber Threat The current analysis of threat to health from the security services: State sponsored - possible - but not a main threat vector Terrorists - conceivable - to be disruptive ‘Bedroom hackers’ - probable - though more interested in defence/security/finance systems Criminals - very likely - to capture financial transaction information and for ID theft Staff - likely - 2.1m in Health & Care: –insider threat - malicious or accidental 4

In the Last 3 Months… 5 Hospital X: Infiltration onto local network; infiltrating 60+ internal servers (some clinical), used as a mail relay and over 2m SPAM s sent from hospital servers. Bedroom Hacker Govt Body Y: Insider, an employee was socially engineered by a journalist to release pseudonymised information on hospital statistics that due to their format could have been re-ID’d. Insider Threat Hospital Z: Malware attack, affecting 100 XP machines and multiple servers. Due to issues caused by data integrity fears, path results disrupted and discharge affected (bed blocking). Criminality

Cyber Security Defence in Depth 6 People Technology Process Correct Security Clearances, Education, Training, Understanding Personal Responsibility and building a security culture Access Controls/Passes, Network Technology, System Access, Patching and Encryption Adherence to robust business processes, defined security policies, incident management process

Enabling not Dictating from the Centre The centre - DH/HSCIC/NHS-E - understands care is delivered locally, as such our role is to enable local organisations to deliver safe and secure processing and use of digital information without dictating. We enable through defence in defence: People: providing training, support and guidance; Process: best practice, trusted advice and remediation; Technology: CareCERT, helping you stay ahead of the threat. 7

People and Process People: Accredited Cyber Knowledge - eg, HCISPP and Creation of Cyber Champions National Cyber Security e-Learning Platform - plus support materials for our staff Process: Launch of the CareCERT Information Sharing Portal Publication of best practice guidance Support to remediate and advise on cyber attacks 8

Technology Implementation of the CareCERT Service: Focusing on providing cyber security intelligence and advice to the health and social care system including mitigation and remediation advice –Contacts are now in place of 93% of all in scope (GPs, CCGs, CSUs including Hubs, NHS Trusts, Local Authorities, Pharmacies via aggregators and Arm Length Bodies) System-wide cyber security incident management - if and when the worst happens Enables a coordinated approach to be taken across health and social care Real Time local threat information at organisation level to inform local organisations of what is happening and what to do 9

CareCERT - What it does 10 BT ATI H&C CERT-UK Gov-CERT N3 Data ALBs DATA, DATA, DATA, DATA, DATA, DATA, DATA, DATA, DATA, DATA, DATA, DATA, 2. Data Analysis by CCERT Team High Risk Medium Risk Low Risk 1. Data is received into CareCERT from Various Sources 3. If a threat could affect H&C, it is triaged for severity Impact Likelihood 4. Broadcast Issued (Type dependent on Severity)

Technology - CareCERT - Broadcast Health and Care Threat Advisories with Remediation sent via appropriate channels … keeping the system ahead of the game … 11 High Severity - Emergency Broadcast Medium Severity - Weekly Broadcast Low Severity - Info Sharing Portal (Feb)

CareCERT - Remediation The importance of the threat advisories are to ensure patient information remains safe and secure - closing vulnerabilities and being proactive before a threat becomes an incident 12 Information Remediation Patient Info Safe & Secure

Future Enablement Our job at the centre is not done and we need to do more: CareCERT+ - opt in service giving first line cyber incident support and steps to take - trusted suppliers and remediation CareCERTified - independent evaluation of organisational cyber preparedness and actions to implement to improve - giving greater situational awareness to individual health and care organisations. 13

One More Thing … or Three Some final advice: Invest in your people - personal responsibility in cyber security is key - and management must make this happen Be part of CareCERT now - CareCERT+ and CareCERTified later this year - it’s free and it’s to help (we’re not a regulator we’re a support function) Don’t fall into the trap that Cyber Security doesn’t affect patient care or patient wellbeing - it does 14

Further Information CareCERT information: currently limited content Queries and CDB contact changes to: CiSP will be expanded from pilot in due course Although - we need to determine the role of this vis a vis the CareCERT Information Sharing Portal 15