Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Cybersecurity NewsBanking/Finance/InsuranceHospitality & Casinos

Ransomware and Data Breaches Force Doctors, Lawyers and Employees to Address Cybersecurity

Will the Panama Papers and Ransomware Deliver a Cyber Wake-Up Call for Employees?

By Dan Lohrmann
Ransomware attacks have forced doctors, lawyers and more to reconsider cybersecurity efforts and awareness.
April 29, 2016

“Doctors just don’t care much about cybersecurity. They have other, more important, things to worry about. They expect the technology and security people to deal with those problems. Besides we can’t control them anyway. Most of them don’t work for us.”

As I travel around the U.S. leading information security awareness seminars, I hear comments like this all the time from security professionals.

Or, “Lawyers are just too busy. Every second is precious and must be billed to a client. We can’t include them in security awareness training. Everyone else at the firm is fine – but we leave them alone.”

But is change in the air for doctors and lawyers regarding cybersecurity practices? Could these respected professionals take part in next-generation security awareness training? 

Perhaps.

As a result of a ransomware pandemic hitting hospitals and the infamous Panama Papers being released, hospitals and law firms all over America are reassessing how they protect sensitive data. “Eyes only” materials can include health records and/or confidential client data. Might lawyers and doctors suddenly find more time to pay attention to email scams and spot phishing links?  

The likelihood of new attention focused on security topics for doctors and lawyers is higher than ever before. Here’s why.

 

Background on Recent Security Incidents

Over the past two months, new ransomware cases have dramatically changed the online security landscape for hospitals.  As described in this Ransomware Emergency article:

The Henderson, Ky.-based Methodist Hospital was “operating in an ‘internal state of emergency’ after a ransomware attack rattled around inside its networks, encrypting files on computer systems and holding the data on them hostage unless and until the hospital pays up.”

In addition, Hollywood Presbyterian Hospital was held hostage by hackers who initially wanted 9,000 bitcoin, but ended up settling for much less to unencrypt their critical data.

The FBI issued a press release warning in March about the growing threat of ransomware. Here is an excerpt:

The FBI strongly encourages you to protect your computer from ransomware by:

  • To prevent the loss of essential files due to a ransomware infection, it is recommended that individuals and businesses always conduct regular system back-ups and store the backed-up data offline. Ransomware will encrypt any drive that is visible to the computer, including back-ups.
  • Filter out e-mails with .exe attachments and set your computer to show hidden file extensions. Ransomware is often delivered as a file with more than one file extension such as example.pdf.exe.
  • Make sure you have updated antivirus software on your computer.
  • Enable automated patches for your operating system and web browser.
  • Have strong passwords and don’t use the same passwords for everything.
  • Use a pop-up blocker.
  • Only download software — especially free software — from sites you know and trust (malware can also come in downloadable games, file-sharing programs, and customized toolbars).

Meanwhile, the massive release of documents called the Panama Papers continues to wreak havoc to international clients of Mossack Fonseca. Every law firm in the world is on high-alert and reexamining their process following this high-profile situation that has led to senior political leaders resigning their positions.

The daily headlines which focus on the Panama Papers have already revealed that thousands of companies had offshore accounts to avoid paying tax. Here’s an excerpt:

When the International Consortium of Investigative Journalists released the trove of data on secret financial dealings now known as the Panama Papers, it claimed it linked 140 politicians from more than 50 companies to secret offshore accounts. In the eight days since, the revelations have ended one political career — that of the prime minister of Iceland — and have revealed new scandals in dozens of other countries.

Beyond the embarrassing details revealed, many questions are being asked about the information security practices utilized at Mossack Fonseca and the security flaws involved. Could this situation have been avoided?

 

Fallout for Hospitals And Law Firms?

Which begs the question, will these new developments lead to new priorities for doctors and lawyers. Can financial losses or the damage to the reputation of a health system or law firm lead to a new sense of urgency to update accepted security practices and even codes of conduct with hospital data? Will regulatory bodies mandate more training for these two distinguished professions that have largely opted out of serious cybersecurity training up until now?

Only time will tell, but experts in the field see the importance of cybersecurity growing in the coming years.

Mark Ford, U.S. National Cyber Risk leader for Deloitte Life Sciences and Health Care, agrees: "This new rash of ransomware attacks is catching a lot of attention by many of my Provider clients. There will be a near-term response and willingness for practitioners to take part in cybersecurity training.”

However, Ford also warns: “After the attention dies down, they will revert to the same risky behaviors, if… the executives don't make cybersecurity education and awareness training a strategic priority.  You must have a corporate culture that manages cybersecurity as a top-tier business risk from the top down.  Many of my client CEOs and management teams are willing to participate in phishing testing.  They lead by example." 

 

Are There Positive Hospital Examples To Model?

Beaumont Health System in Michigan did not wait for new mandates or targeted ransomware attacks to train their staff on better security practices and good cyber hygiene at home and work. Beaumont is already leading the way by providing comprehensive security awareness training for their 35,000 staff, including the doctors and nurses, across statewide facilities.

According to Scott Larsen, the Security Operations Manager at Beaumont: “Employee awareness is the single most important factor in protecting against cybersecurity threats today.  By investing our security awareness education program we have seen an increased awareness along with a positive response from our clinical and administrative personnel, even applying what they have learned in their home environments.”

 

Where to Next?

Most global security firms predicted a dramatic increase in ransomware at the beginning of the year, and events so far in 2016 have basically followed that script. I expect to see more attention on the resiliency of business processes for small medium and large businesses moving forward.

There is no doubt that hospitals and law firms are now paying more attention to security practices. The question that remains is whether more lawyers and doctors will get, and follow, the memo.  

KEYWORDS: cyber security awareness data breach costs Panama Papers ransomware security education security training

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Dan Lohrmann is an internationally recognized cybersecurity leader, technologist and author. Lohrmann currently serves as the Chief Security Officer (CSO) and Chief Strategist for security awareness training company Security Mentor, Inc. He is leading the development and implementation of Security Mentor’s industry-leading cyber training, consulting and workshops for end users, managers and executives in the public and private sectors. 

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

The Lourve

The Lourve Heist: What Was the State of the Museum’s Security?

The 2025 Security Benchmark Report

The 2025 Security Benchmark Report

American Airlines

Security Leaders Discuss Cyberattack on American Airlines Subsidiary

Office supplies

Security Leaders Share Why 77% Organizations Lose Data Due to Insider Risks

University lecture

1.2M Individuals’ Data Stolen In University Hacking

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

November 17, 2025

SECURITY 500 Conference

This event is designed to provide security executives, government officials and leaders of industry with vital information on how to elevate their programs while allowing attendees to share their strategies and solutions with other security industry executives.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Data Breaches Force Healthcare to Invest in More Cyber Defenses

    See More
  • Ransomware, Data Breaches Leading to Increase in Fatal Heart Attacks at Hospitals?

    See More
  • ransomware cyber

    New ransomware task force seeks to disrupt ransom payments

    See More

Related Products

See More Products
  • facility manager.jpg

    The Facility Manager's Guide to Safety and Security

  • A Leaders Guide Book Cover_Nicholson_29Sept2023.jpg

    A Leader’s Guide to Evaluating an Executive Protection Program

  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Events

View AllSubmit An Event
  • October 8, 2025

    How to Support the Security Guard Force in Challenging Environments

    ON DEMAND: In this webinar, Brian Howell, Vice President, Global Head of Security at ADM, shares how his organization fosters trust among their security guard force to improve security posture and the safety of sites, processes and the officers themselves.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing