Health-ISAC held several Preparedness & Resiliency exercises in 2022 throughout the United States using an evolving ransomware scenario.
Participants shared best practices, resources, real-life experiences, and recommendations for continuous improvement.
The full version of the After-Action Report was made available to Health-ISAC members.
This Executive Summary captures the observations and learnings from the exercises consolidated into the following eight category summaries. Health-ISAC encourages health IT and cyber security professionals to consider these lessons learned for continuous improvement in their own organizations:
Malware Detection, Communications, Employee Cybersecurity Training, Crisis Management Team, IT / OT Facilities and Emergency Management Integration, Ransom Payment Decisions, Future Cyber Incident Preventative Measures, and other suggestions in the Miscellaneous category, expounded upon in the briefing.