Skip to the main content.

7 min read

45 Minutes Alone with the Hospital Network

45 Minutes Alone with the Hospital Network
45 Minutes Alone with the Hospital Network
13:52

*45 Minutes Alone with the Hospital Network

Why Cybersecurity in Healthcare Doesn’t Fail Due to a Lack of Technology, but Rather Due to Priorities

A real-world account from the hospital setting, where risks abound

A few days ago, I was sitting in a university hospital. Not as an employee of RIEDEL Networks. Not as an IT security speaker or in my role as “Professional Timo.” But as an expectant father.
My wife, in her 28th week of pregnancy, was at the hospital for prenatal care and registration. After a long wait, she was escorted into an examination room by a visibly overworked medical assistant and hooked up to a CTG monitor there. Unbenannt-2The staff member was friendly, professional, and above all, under enormous time pressure. Then she left the room—for the next 45 minutes. Left behind were my wife, two beeping sensors on her stomach, and me.

Right next to my chair was a mini-PC. Unlocked. With a file open. Several free USB ports. Several free RJ45 network jacks. In addition, there were other unused network jacks on the wall. And suddenly, I had 45 minutes to think about cybersecurity. Because while many people would have simply kept their eyes on the CTG, I saw something else: a potential vulnerability.

Cyberattacks rarely start the way we imagine they do

When people talk about cybercrime, many think of highly specialized hacker groups, complex malware, and spectacular attacks. The reality is often much less dramatic. Sometimes a security incident starts with an open door. An available network port. An unattended workstation.
Or simply with enough time. And that’s exactly the combination that was present that afternoon. Of course, I didn’t do any of those things. The really interesting question, however, is: What would someone have done who didn’t come with good intentions?

The USB Drive That Isn’t One

In my presentations, I often use the example of a so-called “Rubber Ducky.” The device looks like an ordinary USB flash drive. In reality, however, it’s a tool that registers with the operating system as a keyboard and can automatically execute commands. A particularly simple version could, for example, take a screenshot every ten seconds and send it via mail. Or I choose the Bashbunny, which saves it locally on the drive. No network connection required. No data transmission to the outside world. No firewall to raise the alarm. The drive is plugged in during the first appointment and collected again during the next visit.
IMG_0315 KopieWhat was recorded in the meantime? Possibly patient data. Internal applications. Login credentials. Duty rosters. Appointment lists. And that’s just one of many conceivable possibilities. Equally conceivable would be keyloggers, network analysis devices, or hardware for intercepting communication data. The question isn’t whether these attacks are technically possible. The question is why they should be possible at all.

The Open Network Jack as a Symbol

It was precisely these kinds of observations that gave rise to the idea of the so-called RJ45 Port Buddies at RIEDEL Networks a few years ago. Not because a small piece of plastic would suddenly solve all security problems, but because cybersecurity is rarely achieved through a single major measure. It is achieved through many small hurdles. After all, if you want to protect your home from burglars, you don’t rely solely on a particularly sturdy front door. Instead, you make sure that a potential intruder has to overcome as many obstacles as possible. Lockable windows, outdoor lighting, motion detectors, fences, or cameras gradually increase the effort required.

RJ45 Port Buddies_RIEDEL Networks KopieInterested parties can ordertheRJ45 Port Buddies from RIEDEL Networks on our website

Every additional hurdle costs time. Every additional hurdle increases the risk of detection. And every additional hurdle makes a target a little less attractive. The RJ45 Port Buddies are based precisely on this idea. Not as a high-tech security solution, but as a visible reminder that even seemingly small things can make a difference. In fact, we often use them more as a conversation starter than as a product. We deliberately place something physical in our customers’ hands and pair it with a simple message:

Take a piece of cybersecurity home with you today. Start somewhere.

After all, the biggest challenge in information security often isn’t finding the perfect solution. The biggest challenge is simply taking that first step. The open network jack is therefore less of a technical problem than a symbol. It serves as a reminder that security doesn’t begin with complex technologies, but with the willingness to even recognize obvious risks as such.

A New Report Every Week

What’s particularly noteworthy is that such incidents aren’t occurring in just any company, but in the healthcare sector—an industry that has been a prime target for cybercriminals for years. It feels like hardly a week goes by without reports of attacks on hospitals, hospital networks, or other healthcare facilities. The reasons for this are obvious. Healthcare facilities process highly sensitive data. They rely on the availability of their systems. And they often have legacy IT infrastructures that have evolved over many years—and in some cases, decades. For attackers, this is an attractive environment. For the affected institutions, this means a constant battle against ever-changing risks. IMG_0317 Kopie

The Real Problem Is Prioritization

Anyone who thinks this article is meant to criticize those in charge at hospitals is mistaken. In fact, my impression on site was exactly the opposite. Everyone involved was clearly working at their limit. At that moment, the medical assistant likely had more important things on her mind than available USB ports or unused network connections. She was taking care of patients. And that is precisely the key point. From numerous conversations with partners in the healthcare and medical technology sectors, we know that cybersecurity is by no means an unfamiliar or unimportant topic there. On the contrary. The problem often lies in the fact that cybersecurity competes with a multitude of other demands for attention, budget, and personnel. At the same time, organizations and manufacturers must address issues such as:

  • Data protection and the GDPR

  • Medical device regulations

  • MDR and IVDR

  • Quality management

  • Risk management

  • Clinical Evaluations

  • Validation and Approval Processes

  • KRITIS Requirements

  • Certifications and Audits

  • Documentation Requirements

  • Workforce Planning

  • Economic Pressure and Shortage of Skilled Workers

  • Actual patient care

Added to this are cybersecurity requirements stemming from NIS-2, the Cyber Resilience Act, and other regulatory developments. All these issues compete for the same resources: the same time, the same budgets, and the same staff. And that is precisely why cybersecurity is often put on the back burner—not because no one has recognized the risk, but because other challenges seem even more urgent at that moment.

IMG_0316 KopieA charging cable that looks perfectly ordinary but actually has an internal antenna and transmits data to an external receiver. This, too, is unlikely to be noticed if you accidentally leave it lying around or even simply place it in its original packaging on the charging cable stand at the hospital kiosk.

 

The Uncomfortable Truth About Compliance

Under these circumstances, cybersecurity often becomes a compliance project. Guidelines are created. Processes are documented. Audits are prepared. Reporting requirements are met. All of this is important. But none of these measures automatically answers the crucial question:

How secure is the organization, really?

The uncomfortable truth is this: The more complex the regulatory landscape becomes, the greater the risk that organizations will confuse security with documentation. This often creates a significant gap between regulatory requirements and operational reality. If all requirements related to data protection, KRITIS, MDR, quality management, NIS-2, and cybersecurity were examined with equal rigor today and immediately sanctioned, many organizations would likely face challenges that are nearly impossible to solve.

Not because those in charge are inactive. Not because they don’t care about the risks. But because the number of requirements is constantly growing, while time, personnel, and budgets remain finite . The real challenge, therefore, is not identifying risks.

The real challenge lies in deciding which risks to address first.

Why Cybersecurity Is Not an IT Task

This is precisely why I now consider the term “IT security” to be problematic. It suggests that responsibility lies with the IT department. But that is only partly true. IT can identify risks. It can expose vulnerabilities. It can make recommendations. It can implement measures. However, the decision about which risks to accept, which investments to make, and which issues to prioritize is not made in the server room.

It is made in conference rooms. It is made during budget meetings . It is made by executives. Cybersecurity is therefore much more than just technology. Cybersecurity is governance. Cybersecurity is risk management. Cybersecurity is leadership. Because ultimately, it always comes down to the same question:

Which risks are we willing to take—and which are we not?

The 32 Cybersecurity Excuses

It was precisely this experience that led to the creation of the “Lazy Excuses Quartet” some time ago . A collection of 32 excuses that IT managers hear regularly:

  • “There’s nothing to steal from us.”Faule Ausreden Quartett

  • “We don’t have a budget for that right now.”

  • “We’ve never had an incident.”

  • “We’ll do that next year.”

  • “We don’t have time for that.”

This quartet is meant to be humorous. At the same time , it highlights a serious problem. Many security vulnerabilities don’t arise because no one recognized the danger. They arise because other issues seem more important in the short term.

Diagnosis Comes Before Treatment

It was precisely this idea that later served as the starting point for the development of the IT assessment. In medicine, a simple principle applies: No treatment without a diagnosis. No one would begin treatment without first assessing the patient’s condition. Why should it be any different in cybersecurity?

Before deciding on measures, the following should first be clarified:

  • Where are the vulnerabilities?

  • What risks actually exist?

  • Which measures provide the greatest benefit?

  • What problems have been overlooked so far?

Only a realistic assessment of the situation enables sound decisions.

Conclusion: The biggest vulnerability is rarely found in the server room

Ultimately, the most important insight from my visit to the university hospital had little to do with technology. No one on site acted negligently. No one deliberately ignored risks. Everyone involved was trying their best to fulfill their duties under intense pressure . That is precisely why cybersecurity isa management responsibility today—not because employees fail, but because organizations must decide which risks they can afford to take and which they cannot. Our Spotlight IT Security white paper offers a good introduction to this topic.

Cybercriminals aren’t interested in whether compliance documentation has been fully filed away. They’re interested in whether a network port is open. Whether a USB port is accessible. Whether an identity can be compromised. Or whether someone gives them 45 minutes alone with a system. Compliance remains important. But true security starts earlier. It starts with awareness. And with the willingness to honestly question one’s own status quo.

*This article was created with the help of Copilot, taking current market events into account. The author, whose views are represented herein, was responsible for crafting the prompts and supervising the article. 

 

About the Author:

Timo Imbrogno Mitarbeiter von RIEDEL Networks kniet in einer weißen Box mit einem Arm an der Wand abgestützt. Trägt kariertes Hemd in Blau-Weiß, graue Hose und weiße Sneaker mit roten Details.Timo Imbrogno is Director of Marketing at RIEDEL Networks—certainly not an IT expert, but a nerd at heart who enjoys taking a peek behind the scenes every now and then. He found his first bug right at the start of his career, back when Facebook was still all the rage. Back then, it was in the publishing feature of Fan Pages and custom apps, which were still really (!) all the rage at the time.

From time to time, he gets the itch to explore things not just from a marketing perspective, but through his own unique lens. In doing so, he likes to use unconventional approaches to illustrate his point of view or spark reflection. One example worth mentioning here is the IT-SA 2024 advertising material exchange station. 

His contributions deliberately straddle the line between expertise and humor—and invite readers to view even complex topics from an unfamiliar perspective.

 

About RIEDEL Networks

RIEDEL Networks is a privately held, global network provider focused on customized networks. We are listed in the Gartner Magic Quadrant for Global WAN Services as a niche provider specializing in mid-sized international companies and the media and events sectors. With our own global backbone, we help companies stay connected worldwide. Our services include Internet connectivity, MPLS, SD-WAN, SASE, Cloud Connect, security, and much more. Our customers come from a variety of industries and value quality, security, and reliability. RIEDEL Networks is a wholly owned subsidiary of the RIEDEL Communications Group in Wuppertal, Germany, and is privately owned by Thomas Riedel.

 
The chance discovery that probably wasn't a coincidence

5 min read

The chance discovery that probably wasn't a coincidence

*Open doors in the digital front garden What a LinkedIn experiment reveals about the state of IT security in Germany A field report paints an...

Read More
The IT Wizards, or Why DIY Isn't the Answer

3 min read

The IT Wizards, or Why DIY Isn't the Answer

*The IT wizards or why DIY is not the solution The managing director of a medium-sized company was a man of exceptional calm. This calm was based...

Read More
Europe's Digital Fortress

3 min read

Europe's Digital Fortress

*A 2024 Health Check with a Wink "good news / could-do-better" The EU’s networks had quite the year: 188 reportable telecom incidents—a record...

Read More