Need Someone to create a (Narrated Presentation) for me from my given PowerPoint. Also, technical and lab Reports are provided for better understanding. (I need this to be done in 6 hours).
MedStar
Group 3
March 3, 2021
MANAGING CYBER THREATS FOR MedStar system
1
Agenda
About MedStar
Our Story
Our Product and Services
Cyber Challenges
Mission
Technical Paper Summary
Lab Report Results Review
Vulnerabilities
Unauthorize Access
Ransomware
Denial of Services
Key project updates
2021 Plan
Recommendation
Executive Team
Kenneth A. Samet
Susan K. Nelson
Scott MacLean
Closing
Summary
Questions and Answers
Our Story
Highlights
MedStar Health is a not-for-profits health system dedicated to caring for people in Maryland and the Washington DC
MedStar’s 30,000 associates, 6,000 affiliated physicians, 10 hospitals ambulatory, and urgent care center
MedStar Health research institute are recognized regionally and nationally for excellence in medical care
MedStar trains more than 1,100 medical residents annually
Highlights
MedStar treated more than 6,000 patients, handled 2,400 ER patients, and performed 782 surgeries.
MedStar judged top among 70 nominees in the category recognizing “best use of storage technology to drive performance gains
3
Our Products and Services
ephi
phi
Hipaa/hitech
Cyber Threats Challenges
The health system was forced to shut down its computers and email during the March 28 attack
The healthy system lost access to more than 370 computer programs
New employee didn’t know how to operate without computer system
Cyber attacks represent the greatest threats to protecting healthcare data
The attack forced the organization to power down critical process and infrastructure
The attackers used ransomware
The attack slowed down operations with majority of services taken offline
5
Mission Best Practices
Email Projection
Endpoint Protection
Asset Management
Network Management
Medical Device Security
Policies and Procedures
6
Technical Paper Summary
7
Organization Overview
Technology Used
Vulnerabilities and Mitigation
Conclusion
LAP REPORT REVIEW
| APOLLO (ophcrack) (BRUTE FORCE) | Batman (ophcrack) (BRUTE FORCE)) | CHEKOV (ophcrack) (BRUTE FORCE | CSADMIN (ophcrack) (BRUTE FORCE) |
| Ophcrack recovered the password the quickest. | Ophcrack recovered the password the quickest. | Ophcrack recovered the password the quickest. | Ophcrack recovered the password the quickest. |
| Using Brute Force, the predefined field and the password length has to be adjusted properly to recover a password in the reasonable time. | Using Brute Force, the predefined field and the password length has to be adjusted properly to recover a password in the reasonable time. | Using Brute Force, the predefined field and the password length has to be adjusted properly to recover a password in the reasonable time. | Using Brute Force, the predefined field and the password length has to be adjusted properly to recover a password in the reasonable time. |
| Apollo password could take 2 years to recover | Apollo password could take 2 years to recover | Apollo password could take 2 years to recover | Apollo password could take 2 years to recover |
8
BRUTE FORCE
an attacker submitting many passwords or passphrases with the hope of eventually guessing a combination correctly. The attacker systematically checks all possible passwords and passphrases until the correct one is found
Dictionary Attack is a form of brute force attack technique for defeating a cipher or authentication mechanism by trying to determine its decryption key
Ophcrack is a free open-source program that cracks Windows log-in passwords by using LM hashes through rainbow tables. The program includes the ability to import the hashes from a variety of formats, including dumping directly from the SAM files of
Vulnerabilities
12
Unauthorize Access
Ransomware
Denial of Services
Key Project Updates
Implementing preventive measures by working to educate employees and staff on how to mitigate and prevent further attacks on the systems infrastructure.
Ethical decisions regarding protected patient information should be made in timely manner
Maintaining communication with stakeholders, acting in a timely manner, protecting confidentiality, ensuring professional competence, and collaborating with appropriate agencies to solve the issue.
Most cyber security breach are due to compromised passwords, MedStar should taken a strong view that all external/internal access requires two factor authentication to prevent comprising our systems
Lesson Learned
13
Recommendation What are our keys plans for the coming years of 2021?
MedStar need to implement both key technologies and process to protect against Cyber Threats as well as defining organizational process to manage risk
Network Segmentation diving the network into manageable parts and monitoring communications between each of the part provides early detection of potential cyber threats while limiting organization risk
Most cyber security breach are due to compromised passwords, MedStar should taken a strong view that all external/internal access requires two factor authentication to prevent comprising our systems
14
Our People Executive Team
Scott T. MacLean
CEO
Susan K. Nelson
CFO
Scott T. MacLean
CIO
15
Thank you
Questions?
.MsftOfcThm_Accent2_lumOff_2_Fill { fill:#28C4CC; }
.MsftOfcThm_Accent2_Fill { fill:#2683C6; }
.MsftOfcThm_Accent2_lumOff_0_Fill { fill:#2693C8; }
.MsftOfcThm_Accent2_lumOff_1_Fill { fill:#27A3C9; }
.MsftOfcThm_Accent2_lumOff_1_Fill { fill:#27B3CB; }