As the U.S. biomedical community rushes to combat COVID-19, the FBI announced last week that, in a bid to win the race for a vaccine or cure, state-sponsored Chinese hackers are targeting U.S. researchers in an attempt to “obtain valuable intellectual property and public health data related to vaccines, treatments, and testing.”
China is not alone in its nefarious intelligence-gathering efforts. On May 8th, Reuters reported that Iran-linked hackers had targeted Gilead Sciences, makers of the promising antiviral drug remdesivir.
In light of these attacks, the bioscience community must step up its cyber vigilance. It only takes a misconfigured piece of software, an open access port, or an insecure remote office network for a hacker to gain entry to systems that store scientific research, intellectual property, and the personal data of subjects involved in clinical trials.
Here are four key measures that security leaders can take to mitigate risk as their organizations race to develop vaccines.
1. Visualize risk across all digital assets
The global effort to beat COVID-19 is using technology at scale in ways never seen before. The number of digital touchpoints that scientists, researchers, government agencies, and others interact with day-to-day is growing exponentially — as is the attack surface. This puts tremendous pressure on security leaders who don’t have a handle on the risk hidden across digital assets in the cloud or across geographies, subsidiaries, and their remote workforces.
Yet organizations often lack visibility into the inventory of critical assets that comprise these complex ecosystems, such as connected medical devices, applications, and cloud infrastructure. They may also lack insight into the level of risk associated with each asset, not realizing when a piece of software needs an update or runs a high risk of being breached. Only with this understanding can organizations make strategic decisions about prioritizing their remediation efforts and moving their cybersecurity programs forward. Bitsight Attack Surface Analytics provides that understanding. It can help security teams overcome the challenges of detecting and managing unknown cyber risk hiding throughout their expanding digital ecosystem.
2. Discover risk in remote environments
The number of workers now working remotely has risen sharply since the pandemic began. Yet these environments pose significant cyber risk. A Bitsight study found that home and remote offices have alarming security issues that could put upstream company networks and data at risk of compromise.
Security teams can address the challenges created by this massive shift to remote work with Bitsight Work From Home - Remote Office. This solution empowers organizations to easily and effectively identify vulnerabilities and infections on IP addresses associated with remote operating environments, such as residential IPs. With these insights, unknown security issues across remote endpoints can be quickly discovered on a continuous basis for efficient remediation.