Лидеры мнений

Что происходит, когда злоумышленники действуют быстрее, чем система здравоохранения успевает устанавливать патчи?

mm
Добавьте Unite.AI в избранные источники в Google

Сектор здравоохранения уже давно сталкивается с реальной преградой при установке исправлений уязвимостей: Команда безопасности больницы может выявить уязвимость в клинической системе за полдня, но безопасное внедрение исправления обычно затруднено практической реальностью бешеного суетливого ритма работы больницы. Производителю устройства может потребоваться подтвердить обновление, больнице — протестировать его и запланировать простой, а некоторые изменения могут даже потребовать регуляторного обзора.

У злоумышленников нет ни одного из этих ограничений. Инструменты ИИ ускоряют разведку уязвимостей, их исследование и разработку эксплойтов, из‑за чего уже и без того напряжённые процессы исправления в здравоохранении находятся под ещё большим давлением.

Особенно болезненной эта проблема становится из‑за того, что задержки в патч‑менеджменте часто удлиняются из‑за зависимости от поставщиков. Например, исправление для МРТ‑системы может потребовать валидации от поставщика, но всё равно должно быть одобрено контролем изменений в больнице. И всё это должно быть выполнено без нарушения ухода за пациентами.

Health-ISAC’s Frontier AI in the Health Sector report names delayed patching as one of the sector’s defining exposures. Which leaves hospitals with one viable way forward: They may not be able to control every part of the patch timeline, but they can limit what an attacker can do while an update is being rolled out.

Временная шкала патчей имеет нижний порог не без причины

Many of the steps in a hospital’s patching timeline may annoy information security professionals, but they exist to ensure patient safety. No untested update to a ventilator or an infusion pump that aims to close a cybersecurity risk is worth the cost of hindering patient care. The answer therefore, is to speed up the parts of the process that can be accelerated without weakening existing protocols.

Auditors and boards tend to treat long remediation windows as a program maturity or budget problem, and sometimes they are right. Usually, long patching timelines are a symptom of weak execution, lack of resources, or bottlenecks outside the security team’s control. More analysts may improve vulnerability detection, triage and prioritization, but they can’t shorten a manufacturer’s timelines or move downtime windows.

With vulnerability exploitation emerging as the most common way attackers gain access to target networks, the Verizon 2026 Data Breach Investigations Report (DBIR) shows just how little room organizations have to roll out patches. The median time to fully remediate a known exploited vulnerability climbed to 43 days in 2026 from 32 days the prior year, while the share of vulnerabilities fully closed dropped to 26% from 38%.

The fact that these figures are not specific to healthcare shows how difficult remediation already is, before accounting for the clinical and vendor constraints hospitals must also manage.

Пора смотреть дальше оценок тяжести

While remediation windows have gotten longer, attackers have been getting faster. The DBIR found that vulnerability exploitation is now the leading way hackers get into systems, at 31% of breaches, passing stolen credentials for the first time in the 19 years the report has been published.

Verizon says AI has helped accelerate the discovery and exploitation of vulnerabilities, so much so that what once took months may now take hours or days. And that was before the current generation of frontier models was released, as the DBIR’s dataset ended in октябрь 2025.

But everyone expects such speed these days. Health-ISAC’s report flags something more consequential: newer AI models can chain low-severity findings into critical attack paths, identifying combinations of weaknesses that may look less important in isolation. That creates yet another problem for remediation programs that prioritize severity scores, as low-severity findings that are often ignored or pushed into the backlog may suddenly matter much more if they affect access or critical systems.

Swelling backlogs only worsen the picture. Writing in Nature, Max Planck Institute director Thorsten Holz described Mozilla using a frontier model to find and fix 271 vulnerabilities in a single Firefox release, well beyond what its existing tooling and reviewers had surfaced in a typical month over the previous year.

That triage pressure is extending to the supply side, too: Linus Torvalds, the maintainer of the Linux kernel, in May pointed out that bug reports generated by AI are overloading maintainers.

Если нельзя исправить быстрее, сократите доступную поверхность

Thankfully, a backlog that cannot be eliminated can still be managed. If a patch has to wait, the priority should be to lower the chances of any vulnerability being reached. That moves the work from remediation speed to reachability, which is something hospitals can control.

Segmentation can serve as a strong offset. An imaging device with broad access can reach a domain controller, a file share, and the open internet. But if it’s limited to an isolated segment that permits traffic to its PACS server and the manufacturer’s update endpoint, while denying access to the rest by default, any vulnerability affecting it can remain contained for however long a patch may take.

Where the device and vendor requirements allow it, hospitals can use segmentation, egress controls and deny-by-default rules to narrow and even close off access paths while a patch is pending.

Hospitals do not need a complete asset inventory before they start shrinking the exposed surface. Count the systems answering to the internet first, keep that number current as the broader inventory continues, and prioritize limiting what those systems can reach inside the network.

Health-ISAC’s survey data indicates the industry is already beginning to move in that direction. Roughly 80% of Health-ISAC members say they’re planning to increase their budgets for AI-powered security tools or exploitability assessment. One path that may prove useful is to analyze which attack paths work in your own environment: find combinations of low-severity vulnerabilities that may deserve attention before a priority score draws your attention.

Vendor conversations must get past the language in the service level agreement, too. Contracts contain what you and your vendors committed to years ago, but the threat model has changed dramatically. So first identify how long validated patches to vulnerabilities may take to be issued following public disclosure, and then find out what mitigation measures are available while you wait for the update. It’s also worth asking whether they test their product against current AI-assisted attack techniques.

Управляйте воздействием, которое нельзя устранить

Most organizations cannot say how long it takes to have a validated fix running in production once an exploit has been made public. Focus on arriving at that number so you can stop debating patch windows and start focusing on finding out which vendors and systems stay exposed the longest. That will let you decide what your remediation efforts must prioritize.

Sharing information can significantly shorten that decision cycle. Some of the fastest remediation decisions I’ve seen happen when a hospital hears from a peer about a vendor platform being exploited before the vulnerability is publicly disclosed.

The validation window itself is not going to widen. Hospitals will keep running clinical systems with open vulnerabilities on them, which means the segmentation strategy for those systems must be given more importance than the patch schedule. Every hospital should be able to specify, for each of its critical platforms, what would happen on the network if that platform were breached tomorrow.

Эррол Вайсс присоединился к Health-ISAC в 2019 году в качестве первого офицера по информационной безопасности и создал центр операций по угрозам, расположенный в Орландо, Флориде, чтобы предоставлять значимую и действенную информацию о угрозах для специалистов в области информационных технологий и информационной безопасности в сфере здравоохранения.

Эррол имеет более 25 лет опыта в области информационной безопасности, начав свою карьеру в Агентстве национальной безопасности (NSA) с проведения тестов на проникновение в классифицированные сети. Он создал и возглавлял Глобальный центр кибербезопасности Citigroup и был старшим вице-президентом по информационной безопасности в команде глобальной информационной безопасности Bank of America.