> Hospitals are why I don't "blame" underinvestment into cybersecurity. Their #1 goal is saving people's lives, not messing with IT issues. You want hospitals to be paying for important equipment, important people, important skills. The whole IT part is just supporting the administrative tasks.
And yet everything crumbles and collapses when there's an IT outage. How interesting.
These organizations might not be culturally accustomed to have IT at the core of their business/mission, but it very much is. They might not value engineering skills and people in IT, but they have evolved an absolute dependency on those over the years.
The issue here is cultural, not technical. These randsomware attacks, breaches and outages are completely self-imposed. They can end anytime as soon as the hospital wants it. All they have to do is value and acknowledge IT as a fundamental pillar of their organization. Else the cycle will endlessly repeat itself.
And yet everything crumbles and collapses when there's an IT outage. How interesting.
These organizations might not be culturally accustomed to have IT at the core of their business/mission, but it very much is. They might not value engineering skills and people in IT, but they have evolved an absolute dependency on those over the years.
The issue here is cultural, not technical. These randsomware attacks, breaches and outages are completely self-imposed. They can end anytime as soon as the hospital wants it. All they have to do is value and acknowledge IT as a fundamental pillar of their organization. Else the cycle will endlessly repeat itself.