Quantum readiness for health boards and executives: what to do now, what can wait
READ TIME 8 MIN
Cyber readiness is three disciplines your organisation already practises clinically: prevention (the Essential Eight), a response protocol (the Cyber Incident Response Plan), and rehearsal (a trained team, exercised at least annually). Miss any one of the three and the other two will fail when it matters. Australia's Notifiable Data Breaches scheme makes the stakes non-optional, so as a board member you should be able to evidence all three. The five questions at the end will tell you where you stand.
As a former CIO of a billion-dollar healthcare system, I have taken that 2am phone call. The one where clinical systems are down across multiple sites, nobody can yet say whether it's an equipment failure or an attack, and the next several hours will determine whether the organisation has a hard night or a hard year.
As a board member of any size healthcare organisation, it's important to remember that cyber incidents are not an "IT problem". At their core they are patient-safety events with a communications crisis attached, which means the board needs to own them the same way it owns clinical governance.
The good news, and the central argument of this article, is that your organisation already knows how to do readiness. Many of you have run emergency departments, drilled hospital codes and practised infection control protocols on a daily basis. Cyber readiness is the same three readiness disciplines (1. prevention, 2. response protocol, 3. rehearsal/drill) applied to a different kind of "pathogen". So breathe a sigh of relief: you don't need to learn about technology. This article breaks down healthcare cyber readiness into a language you already understand.
The Essential Eight is a set of eight preventative controls published by the Australian Signals Directorate (ASD), the Commonwealth's technical authority on cyber security. In healthcare jargon, the "eight" are basic hygiene: control which software can run, patch known weaknesses quickly, limit who holds powerful access, require more than a password to get in, and keep backups an attacker can't reach. Most successful attacks on Australian organisations would have been prevented by these eight controls, competently implemented.
Two things about the Essential Eight matter at board level. First, maturity is measured on a scale from Level Zero (control effectively absent) to Level Three (fully implemented and verified), for each of the eight items. Second, and this is the part most boards have never been told: your overall rating arises from your weakest control, not your average. The ASD scores it that way deliberately, because attackers don't average your defences; they find the one door left open. An organisation with seven excellent controls and one absent control is, for practical purposes, a Level Zero organisation.
As a board member of any size healthcare organisation, the questions are simple:
If those three questions can't be answered from existing board papers, it's probably safe to say your Essential Eight maturity level would be Zero, and there are some actionable items your executive team needs to be looking at. (If you want an indicative feel for the maturity assessment, the Essential Eight Pulse on this site takes three minutes.)
The Cyber Incident Response Plan (CIRP) is your organisation's pre-agreed protocol for the day that prevention tactics have failed. It should detail who does what, in what order, with what authority, when minutes matter and information is incomplete.
As a board member, you should easily be able to access a copy of the CIRP. For medium-sized healthcare organisations, this may be owned by a Corporate Services manager or IT manager; in large organisations it should be owned by the executive in charge of IT.
A CIRP worth having answers five things in plain language:
One sentence to keep in mind: a CIRP that has never been tested is a document, not a plan. When your insurance company or Australian regulators come knocking, you want evidence-based proof that your board was not negligent in preventing a breach of sensitive healthcare information.
So far we have looked at how to prevent cyber healthcare incidents by first assessing your organisation against the Essential Eight controls for cyber safety. As a board member, you should understand what cyber-security maturity level your organisation is at, and where it should be.
We then looked at what should be in your organisation's Cyber Incident Response Plan (CIRP), a critical document that details actionable steps when something goes wrong and your healthcare company is actively under attack. As a board member you should be familiar with this document and your role when the CIRP is activated.
If you have come this far, you are probably wondering what else there is for you to do as a board member of a healthcare organisation. Remember earlier when I said there are non-optional notifiable requirements when your company experiences a cyber attack? As a board member, you will want any Australian regulators, insurance personnel or other engaged third parties to have a smooth and controlled experience with your organisation when an incident occurs. That means:
The best way to achieve this is like anything else in healthcare: drills and practice runs.
The Cyber Incident Response Team (CIRT) is the group that executes the CIRP. The CIRT is substantially a leadership team, not a technical one. The technicians contain the incident. But the decisions that determine the outcome, such as whether to close the clinic or not, divert the ED or not, isolate the EMR or not, what to tell staff and media, and when to call the minister's office, belong to executives. If your CIRT roster is entirely people from IT, your actual crisis team has not been properly organised.
Just naming the team in the CIRP is not enough. The team will not be a ready team. Nobody learns resuscitation by reading the protocol during cardiac arrest; that's why clinicians drill it until the sequence survives the adrenaline rush of an emergency. The cyber equivalent is a tabletop exercise, run at least annually, with your CIRT. A good exercise will have:
The board's role is not to attend every exercise. It is to require that one has happened in the last twelve months. When I am hired to run these exercises for healthcare organisations in Australia, I ask the board to ensure the executive team will be present and participative, and required to read the debrief report I send, as opposed to being allowed to simply send a one-line email assuring the board that all went well. My aim with these exercises is to find the holes in the response plan; in my opinion, an exercise without findings for improvement was inadequate in testing the response in the first place.
If you're interested in how I can tailor an exercise for your Australian healthcare organisation, book a call with me directly in my calendar.
Book a callIf you have come this far, thank you for being proactive about making your healthcare organisation safer and ensuring your obligations as a healthcare board member are met. In summary, let me boil this article down into five YES or NO questions you can ask at your next meeting to get started, or to double-check how well your healthcare company is doing with cyber responsiveness and readiness:
None of this requires the board to become technical. It requires the board to apply the governance discipline it already applies to clinical risk: prevention is funded, protocols are current, and people are rehearsed. Your healthcare organisation would never accept a resuscitation protocol nobody had practised. Your cyber incident response deserves the same standard, because on the night it's needed, it protects the same patients.
Cyber readiness is three disciplines a health organisation already practises clinically: prevention (the Essential Eight), response (a Cyber Incident Response Plan), and rehearsal (a trained team, exercised at least annually). Miss any one of the three and the other two fail when it matters.
A CIRP is your organisation's pre-agreed protocol for when prevention has failed: who does what, in what order, and with what authority, when minutes matter and information is incomplete. It sets decision rights, escalation triggers, communication discipline, clinical recovery priorities, and notification obligations.
The board's. A healthcare cyber incident is a patient-safety event with a communications crisis attached, so the board owns it the way it owns clinical governance, rather than delegating it to IT.
At least once every twelve months, with the real executive decision-makers in the room and not only the IT team, followed by a frank debrief and the remediation of any gaps the exercise exposes.
An occasional brief, no more than once a month, for senior leaders in health, government and defence: field-tested frameworks, the thinking behind my client work, and first access to new tools and dispatches. No selling, no noise.