Cyber Security of Critical Healthcare Infrastructure-ICUs
University of Canberra | Flinders University
The Challenge
The healthcare industry is the most vulnerable sector to cyber attacks, but most attacks try to compromise the confidentiality and availability of data such as patient data. Although still prevalent, these types of attacks are now well understood and appropriate defences are being implemented.
This project responds directly to Australia’s Security of Critical Infrastructure Act (SOCI), which designates Intensive Care Units (ICUs) as nationally critical infrastructure. With ICUs now designated as critical infrastructure, hospitals are also required to put in extra measures to protect the availability of not just data but also ICU systems. But practical cyber threat models tailored to ICU systems have been lacking, leaving hospitals without the evidence base needed to justify targeted investments.
The Partnership
The project is a joint initiative led by NIIN partners the University of Canberra and Flinders University, under the leadership of Cisco Research Chairs Professor Frank denHartog and Professor Trish Williams, who found a shared interest in this topic. University of Canberra built the initial threat model and partners with Flinders University to conduct a risk analysis survey among practitioners.
The Solution
The next phase of the project will involve engaging cyber and healthcare IT experts through an online survey to assess the likelihood and consequences of these threats. The outcome will be the first practically applicable cyberthreat model for ICUs in Australia. We will take this generic threat model to individual hospitals, tailor them to their unique circumstance (every hospital and ICU is different) and then discuss next steps given the outcomes.
Recognition & Impact
Project Highlights
By applying internationally benchmarked methodologies such as MITRE ATT&CK and OWASP, the research team has identified 13 immediate threats to ICU systems, ranging from ransomware attacks and malware infections to insider threats and distributed denial-of-service (DDoS)attacks.
- Early insights also reveal that ICUs are highly interconnected environments, reliant on a complex web of medical devices, information systems, networks, and cloud services, where vulnerabilities in one element can quickly cascade across the system, amplifying the impact of attacks.
- Traditionally, cyber defences have been focussed on preventing access to data and systems by malicious actors. When protecting the availability of systems becomes the main objective, more attention needs to be given to cyber resilience, i.e., minimizing the impact of successful attacks by means of fast incident response, redundancy, and fast switchover procedures.
Contact Person & Details
- Prof Frank den Hartog, NIIN Research Chair in Critical Infrastructure, University of Canberra frank.denhartog@canberra.edu.au


