Jérémy Dréan is the Managing Director at Automatique & Industrie,

a Certified BMS and Critical Power EcoXpert™.

Across industries, the Internet of Things (IoT) is driving significant investment in projects that integrate smart devices, big data, analytics, and other digitization-related tools. Healthcare institutions are no exception. Hospitals benefit from this advanced connectivity through increased efficiencies, lower costs, and better patient care. As more building infrastructure gets connected; however, the risk and frequency of cyberattacks will increase. According to Cybersecurity Ventures, the estimated global cybercrime cost will climb to more than $10.5 trillion by 2025. That's why sound cybersecurity protection strategies are more critical now than ever.

Increasing cyberattacks are placing hospital health records, clinical research data, and patient records that include social security numbers, billing information, and insurance claims at risk.

For example, a hospital-related cyberattack could involve an assault on the hospital's power supply through an electrical engineering management system. An attacker could take partial control of the system and block important power fallback modes (like load shedding capabilities), thus putting the hospital at risk for a complete blackout without the ability to monitor the facility's core power systems.

Ransomware has also emerged as a major concern for many healthcare institutions. This cyberattack occurs when malicious software is used to restrict access to a computer system or data until the victim pays the ransom requested by the criminal. Such attacks are now happening globally every 11 seconds.

Under these circumstances, the challenge is to protect building infrastructure systems without blocking them. It is necessary to know how to maintain operational flexibility while working within security constraints. At Automatique & Industrie, a Schneider Electric certified EcoXpert partner with extensive experience in smart building management systems (BMS), cybersecurity, artificial intelligence, and smart data architecture, we are often asked to help clients attain a flexible balance between efficient operations and security.

Addressing OT cybersecurity protection gaps is critical

Most information technology (IT) services groups within hospital organizations have global cybersecurity strategies in place that address the entire Hospital Information System (HIS) including patient files and medical data. However, other systems like hospital operations technology (OT) systems and biomedical systems are often underserviced from a cybersecurity perspective. These systems are critical because they guarantee the overall service continuity of the hospital infrastructure including power supply, air renewal, and safety and security management.

Cybersecurity is a global process. The mere implementation of technical solutions, like firewalls, does not by itself render an installation cybersecure. The healthcare staff must also raise their level of awareness and be educated by the organization on how to modify procedures and human actions to enable cybersecurity improvements.

Regulations like ANSSI (the National Cybersecurity Agency of France) must also be adhered to and should help to shape the rules put in place to address issues such as system access levels and "need to know" visibility to key operational tasks.

Cybersecurity roadmap helps create a secure facility

At Automatique & Industrie, we focus on deploying and securing operations technology (OT) in hospitals. Our customers ask us to conduct assessments of their infrastructure that include diagnosis of cyber vulnerability. When we perform these engagements, we complete the following tasks:

  • Define the level of cybersecurity need for each system
  • Map the OT network to analyze information flow patterns
  • Implement password and cybersecurity software version management
  • Deploy cybersecurity solutions (like firewalls, probes, and VPN access) as appropriate
  • Conduct employee training and awareness

Cybersecurity today is no longer an afterthought or a bolt-on solution. The Schneider Electric solutions we recommend are cyber secure by design complying to the foremost in OT cybersecurity requirements from the international standard IEC 62443, providing robust cybersecurity features right from the factory. Once installed, these solutions are supported by services that allow healthcare organizations to maintain high levels of protection and low levels of risk as the cybersecurity outlook continues to evolve.

Get help to develop a cybersecurity protection strategy

To learn more about how sound cybersecurity practices and smart building systems can increase your healthcare facility's performance, visit us at the Automatique & Industrie web pages or consult the Schneider Electric web pages.

Contributor: Romain Deux, Expert Cyber OT at Automatique & Industrie

Romain has been working in automation and industrial computing for several years now. With his knowledge of the industry, he specialized in computer networks and cyber security applied to industrial environments.

Schneider Electric has been recognized as the world's most sustainable corporation in 2021 by Corporate Knights Global 100 Index.
EcoXperts are the Enablers of Buildings of the Future

The EcoXpert Partner Program is unique in its industry and made up of a best-in-class global ecosystem of expertise. Trained and certified by Schneider Electric, EcoXperts are the implementation arms of EcoStruxure and Wiser all over the world.

Buildings of the Future is about delivering solutions for the sustainable, resilient, hyper-efficient, and people-centric buildings that our customers need. For our EcoXpert partners, this unveils immense growth opportunities through the transition to end-to-end portfolio sales that will resolve our customers' most critical needs. For our shared customers, this means that together with our EcoXpert partners, we will drive the building industry transformation and help our customers survive and thrive today - and tomorrow. Download the EcoXpert Digital Transformation Benchmark Study.

Visit EcoXpert to learn more. Discover Buildings of the Future.

Learn More about Buildings of the Future

Want to see how Automatique & Industrie, a Schneider Electric EcoXpert partner, is helping to enable Buildings of the Future? Read more here.

Automatique & Industrie is also certified in the following EcoXpert competencies: BMS and Critical Power and registered to become certified in Access Control.

Interested in learning about the EcoXpert Partner Program? Visit the EcoXpert website for more details about the benefits for our business partners.

Learn more about Automatique & Industrie

Since 1995, Automatique & Industrie (AI) has been committed to bringing the know-how and experience of its talented employees to the design and integration of turnkey automated and energy systems for industry, building, and infrastructure. The company is in the Isère department of France and has offices in Toulouse so it can work more closely with its clients. AI also works for companies located abroad.

Automatique & Industrie has an adaptable and flexible organization that can quickly make decisions, ensuring it can meet deadlines. AI knows how to design simple yet efficient systems and has a network of partners who can supplement projects as needed. AI is also known for its specialists and experts with comprehensive skills and the knowledge and dedication needed to deliver solutions that meet and exceed customer goals.

Attachments

  • Original Link
  • Original Document
  • Permalink

Disclaimer

Schneider Electric SE published this content on 25 January 2022 and is solely responsible for the information contained therein. Distributed by Public, unedited and unaltered, on 26 January 2022 09:55:02 UTC.