| Literature DB >> 35206941 |
Fotios Gioulekas1, Evangelos Stamatiadis1, Athanasios Tzikas1, Konstantinos Gounaris1, Anna Georgiadou2, Ariadni Michalitsi-Psarrou2, Georgios Doukas2, Michael Kontoulis2, Yannis Nikoloudakis3, Sergiu Marin4, Ricardo Cabecinha5, Christos Ntanos2.
Abstract
Recent studies report that cybersecurity breaches noticed in hospitals are associated with low levels of personnel's cybersecurity awareness. This work aims to assess the cybersecurity culture in healthcare institutions from middle- to low-income EU countries. The evaluation process was designed and performed via anonymous online surveys targeting individually ICT (internet and communication technology) departments and healthcare professionals. The study was conducted in 2019 for a health region in Greece, with a significant number of hospitals and health centers, a large hospital in Portugal, and a medical clinic in Romania, with 53.6% and 6.71% response rates for the ICT and healthcare professionals, respectively. Its findings indicate the necessity of establishing individual cybersecurity departments to monitor assets and attitudes while underlying the importance of continuous security awareness training programs. The analysis of our results assists in comprehending the countermeasures, which have been implemented in the healthcare institutions, and consequently enhancing cybersecurity defense, while reducing the risk surface.Entities:
Keywords: awareness; cybersecurity culture; healthcare domain; security assessment
Year: 2022 PMID: 35206941 PMCID: PMC8871847 DOI: 10.3390/healthcare10020327
Source DB: PubMed Journal: Healthcare (Basel) ISSN: 2227-9032
Figure 1Cybersecurity Culture Framework.
Figure 2Campaign general participation information: (a) per profession, (b) healthcare professional per institution, and (c) ICT hospital employees per institution.
Figure 3ICT personnel responses on common cybersecurity vulnerabilities.
Figure 4Cybersecurity Incident: Downtime and Time to Resolve.
Figure 5Awareness of Non-ICT personnel on legal aspects, privacy and cybersecurity structure.
Figure 6Digital behavior and security comprehension level of non-ICT Healthcare Employees.
Percentage (%) of answers related to cybersecurity awareness along with the corresponding standard deviations for non-ICT personnel.
| Question | Institution A | Institution B | Institution C |
|---|---|---|---|
| Do you have cyber-security policies at your hospital? | |||
| Yes | 11% ± 0.5 | 55% ± 4.9 | 60% ± 5.3 |
| No | 14% ± 0.7 | 2% ± 0.2 | 7% ± 0.6 |
| Do not know | 75% ± 3.5 | 43% ± 3.8 | 33% ± 2.9 |
| Have you been informed or trained regarding General Data Protection Regulation (GDPR) in order to minimize private personal data breaches or cybersecurity incidents? | |||
| Yes | 31% ± 2.5 | 31% ± 0.2 | 31% ± 0.1 |
| No | 69% ± 0.08 | 69% ± 0.2 | 69% ± 0.1 |
| How careful are you when you open an attachment in email? | |||
| I always make sure it is from a person I know, and I am expecting the email | 32% ± 6.7 | 48% ± 15.9 | 50% ± 18.4 |
| As long as I know the person or company that sent me the attachment, I open it | 59% ± 7.7 | 42% ± 15.4 | 45% ± 18.4 |
| There is nothing wrong with opening attachments | 9% ± 6.3 | 10% ± 12.3 | 5% ± 7.4 |
| Have you given your password to your colleagues or your manager, when you were asked for it? | |||
| Yes | 33% ± 9.1 | 26% ± 14.2 | 30% ± 24.1 |
| No | 67% ± 9.1 | 74% ± 14.2 | 70% ± 24.1 |
| Is anti-virus currently installed on your computer? | |||
| Yes | 60% ± 2.8 | 16% ± 1.4 | 79% ± 6.9 |
| No | 11% ± 0.5 | 65% ± 5.8 | 5% ± 0.4 |
| Do not know | 29% ± 1.3 | 19% ± 2.7 | 17% ± 1.5 |
| I am confident that I could recognize a security issue or incident if I saw one. | |||
| Strongly agree | 4% ± 2.4 | 4% ± 4.6 | 14% ± 12.3 |
| Agree | 24% ± 8.1 | 39% ± 18.3 | 59% ± 15.3 |
| Neither agree nor disagree | 42% ± 10 | 34% ± 18 | 8% ± 7.8 |
| Disagree | 23% ± 8.3 | 20% ± 9.1 | 17% ± 10.3 |
| Strongly disagree | 7% ± 4.5 | 3% ± 3 | 2% ± 1.9 |