Hospitals urged to reduce, replace, and recover this October

CISA is asking critical infrastructure operators, hospitals included, to shrink attack surfaces and rehearse recovery during October's awareness campaign.

MedRisk Staff
By
2 Min Read

October’s Cybersecurity Awareness Month arrives with a second theme aimed squarely at the sectors patients depend on. Alongside the familiar password, MFA, and phishing guidance, CISA and the National Cybersecurity Alliance are asking critical infrastructure operators – hospitals, labs, and health systems among them – to adopt three habits the campaign calls the 3Rs.

Reduce, replace, recover

Reducing means shrinking the attack surface: keep systems patched, apply updates promptly, and retire software and devices before they slide into end of life. Replacing means swapping out gear and platforms that can no longer be defended. Recovering means writing, practicing, and maintaining plans that let clinical operations keep running during an incident and come back fast afterward.

CISA says the threat picture is not shifting so much as scaling. Vulnerabilities are being published in record numbers, and AI is speeding up both the discovery of flaws and the mass exploitation that follows. Internet-exposed systems, software, and devices remain the recurring way in. For healthcare the pressure is familiar: ransomware crews keep landing on hospital networks through unpatched edge devices and legacy medical equipment that cannot run current security software, the exact end-of-life problem the 3Rs target.

Compliance officers can treat the month as an audit prompt: inventory exposed systems, map end-of-life clinical equipment, and test recovery plans against a scenario where the electronic health record is unavailable for a week.

Share This Article