Dangerous Misconceptions That Put Critical Infrastructures at Risk

Aug 14, 2021

On May 12, 2021, the White House issued an executive order to improve the nation’s cybersecurity and protect federal government networks—a move that it claims to be “the first of many ambitious steps the Administration is taking to modernize national cyber defenses.”


While this news sounds like something that concerns only the government, it actually emphasizes that cybersecurity requires more than government action.


Cybersecurity requires a partnership between the Federal Government and private sector.


The executive order encourages private sector companies like your practice to follow the Federal Government’s lead and take ambitious measures to augment and align cybersecurity investments with the goal of minimizing future incidents.


Why is this relevant?

All this is relevant simply because cyberattacks against critical infrastructures are on the rise. And these attacks affect you, your practice, and your patients.


The Cybersecurity and Infrastructure Security Agency (
CISA) defines critical infrastructure as the physical and cyber systems and assets that are so vital to the United States that their incapacity or destruction would have a debilitating impact on our physical or economic security or public health or safety.


Here are a few recent attacks on critical infrastructures here in the US:


Critical infrastructures aren’t just power plants, transport systems, and military systems...they’re also food manufacturers, gas pipelines, and yes, the electronic healthcare systems you have in your practice.


You have critical infrastructure within your organization and you play a vital role in protecting it. 


But where and how do you start?


Start by addressing misconceptions

The tech world is full of myths, misinformation, and misconceptions that can keep you from taking the first steps toward securing your critical infrastructure.


In a recent
webinar hosted by Cato Networks, CISA Cybersecurity Advisor Ron Ford explained how the US Federal Government, through CISA, is zeroing in on protecting critical infrastructure and how some misconceptions about cybersecurity can interfere with the process.


Here are some of the most common misconceptions that organizations like yours need to overcome:


I need a big budget!

Many organizations think being cyber secure means needing to have every single tool and technology. That’s not true.


It’s important to pace yourself. Ford calls this the crawl-walk-run approach. 


Cybersecurity has a lot to do with the layered defenses of different solutions.


Identify the cybersecurity solutions that you already have (whether these are tools or training), fine-tune these solutions, and start drilling down on the type of cybersecurity that’s important to your organization.


I need a silver bullet solution!

Unfortunately, there isn’t one. Just like getting every single tool isn’t the solution, getting just one miracle tool isn’t the answer, either.


You need to get the basics in order—particularly, visibility and
training.


  • Visibility. You need insight into what should and should not be on your network. Turn on applications that should be enabled and turn off those that shouldn’t.


  • Training. Provide your organization with staff regular cybersecurity awareness training so you can be equipped with the knowledge you need to spot, respond to, and avoid cyber threats in the future.

But I’m not a target!

We wish that were true. However, every organization can be a target…especially when they deal with critical infrastructure.


Think you’re too big to get infiltrated? Cybercriminals have been able to hack government systems, multinational corporations, and tech giants. No target is too big. 


Think you’re too small to be a target? Cybercriminals are known to launch attacks on smaller organizations as testing grounds or stepping stones for much larger attacks. No target is too small.


Healthcare practices like yours are
especially attractive targets because the data you handle can be worth a lot of money on the dark web, and cybercriminals will go to great lengths just to steal them.


There’s too much to do, I’ll never get anything done!

There is quite a lot to do when it comes to keeping critical infrastructures secure, but you don’t have to do all of them at the same time. You need to wrap your head around what’s important for your organization in particular.


In Ford’s words, one has to “separate the noise from the signal.” Find a way to know what your “crown jewels” are. Ask yourself this:


What critical services, endpoints, or technologies within your network architecture that, if they go down, will cause a cascading impact on your practice, patients, and partners? 


These are the things you can start focusing on.


But we don’t own the risk!

Actually, you do. You may pay a person or a company to manage and monitor certain services, but at the end of the day, you ultimately still own the risk.


The US government will save us!

Unfortunately, the US government cannot save everybody when it comes to cybersecurity attacks on critical infrastructure.


This is why the partnership between the federal government and the private sector is key in minimizing cyber incidents in the future.


Partner up with healthcare IT experts!

Sorting through misconceptions is one thing, but implementing visibility, training, assessments, and cybersecurity strategies is quite another.


For the latter, you’re going to need to partner up with
tech experts who specialize in healthcare IT.


Know what’s going on with your network infrastructure, what cybersecurity solutions are available to you, and what you can do to fortify your defenses.


Protect the critical infrastructures you have in your organization by working with experts in healthcare IT, cloud, and compliance.


CLAIM YOUR FREE IT ASSESSMENT TODAY

Search Articles

By DrCatalyst Marketing 11 May, 2022
There are severe retributions when breaching HIPAA regulations, from hefty civil fines to criminal penalties. Get to know the legal implications of HIPAA violations.
How to Improve Your Patient LTV with Cloud-Based Phone Systems
By DrCatalyst Marketing 06 May, 2022
Achieving a high lifetime value is an important goal for any business. Read this article to learn how to increase your patients' LTV with ease.
The Fastest Way to Find Out if Your Email or Social Media Account Is Hacked
By DrCatalyst Marketing 29 Apr, 2022
Have you noticed a sudden change in your email or social media account? Check now to find out if it's been hacked.
7 Proven Advantages of Having a Managed Cloud Service Provider For Your Medical Practice
By DrCatalyst Marketing 21 Apr, 2022
Getting your clinic staff to focus on patients rather than your IT is just one of the benefits of managed cloud services. Read on to discover more benefits.
Uncommon Email Attacks to Watch Out For and How To Prevent Them
By DrCatalyst Marketing 14 Apr, 2022
Email is the most used form of communication in healthcare, but it’s also the main point of attack for hackers. Here are some surprising ways in which your emails can be attacked.
Stress Awareness Month: Reduce Clinic Staff’s Stress with IT Outsourcing
By DrCatalyst Marketing 07 Apr, 2022
IT is a crucial part of any healthcare organization, but it can also be one of the most stressful. Learn how a managed service provider (MSP) can help reduce that stress.
How to Protect Your Medical Practice Against URL Phishing  or Fake Website Scam
By DrCatalyst Marketing 01 Apr, 2022
URL phishing is among the most common phishing scams, yet it can be easily prevented if you take precautions. Find out how you can protect your clinic against this threat.
Is Your Medical Practice’s IT Support Responsive?
By DrCatalyst Marketing 29 Mar, 2022
Are you able to get the IT support you need when you need it? If you’re not sure how to answer that question, your practice may be at risk.
Women in Tech: Contributions, Opportunities and Breakthroughs
By DrCatalyst Marketing 29 Mar, 2022
This March, we celebrate the women – careers, opportunities and breakthroughs in the tech industry
Tech as the Answer to Healthcare Labor Shortages
By DrCatalyst Marketing 25 Mar, 2022
Technology can help address the unprecedented labor shortages in the industry. Here’s how.
Show More

News & Resources

By DrCatalyst Marketing 11 May, 2022
There are severe retributions when breaching HIPAA regulations, from hefty civil fines to criminal penalties. Get to know the legal implications of HIPAA violations.
How to Improve Your Patient LTV with Cloud-Based Phone Systems
By DrCatalyst Marketing 06 May, 2022
Achieving a high lifetime value is an important goal for any business. Read this article to learn how to increase your patients' LTV with ease.
The Fastest Way to Find Out if Your Email or Social Media Account Is Hacked
By DrCatalyst Marketing 29 Apr, 2022
Have you noticed a sudden change in your email or social media account? Check now to find out if it's been hacked.
More Posts
Share by: