Situation Critical: Intensive Cybersecurity Care Needed
摘要
Healthcare organisations are increasingly targeted by cybercriminals. Such attacks are not just an attack on data but on this critical infrastructure – putting lives at risk. They face multiple challenges in maintaining their cybersecurity, including the technology infrastructure in use, the heterogeneity of healthcare and admin staff and the IT and cybersecurity skills within the organization. This paper focuses on healthcare and admin staff within a single hospital in Italy. The study sought to understand the differences in perceptions of culture between different staff groups and the overall relationship between these perceptions and behaviours. The methodology consisted of a cultural, behavioural and data use questionnaire, translated into Italian and distributed to doctors, nurses and administrators. Linear regression models suggest that security culture significantly predicts how important and achievable staff perceive cybersecurity behaviours to be. Further analyses found significant differences between the doctors and other staff groups. Doctors reported a significantly more negative perception of cybersecurity culture. They also perceived cybersecurity behaviours to be significantly less important and less achievable than the other two groups. Doctors were also most likely to copy and access patient data outside of the institution, albeit for benign or patient centered reasons. Overall, in terms of cybersecurity, doctors were the least compliant staff group – albeit with the best of intentions (i.e., focus upon patient care). These data, alongside other research, suggest that healthcare staff focus on delivering patient care and see cybersecurity as interfering with, rather than facilitating, their clinical practice. There is a need for change to ensure that cybersecurity measures are appropriate, work within the clinical workflow and staff accept cybersecurity as crucial to protecting patients.