Content area

Abstract

Recent cyber-attacks targeting healthcare organizations underscore the growing prevalence of the sector as a prime target for malicious activities. As healthcare systems manage and store sensitive personal health information, the imperative for robust cyber security and privacy protocols becomes increasingly evident. Consequently, healthcare institutions are compelled to actively address the intricate cyber security risks inherent in their digital ecosystems. In response, we present RAMA, a risk assessment solution designed to evaluate the security status of cyber systems within critical domain, such as the healthcare one. By leveraging RAMA, both local stakeholders, such as the hospital’s IT personnel, and global actors, including external parties, can assess their organization’s cyber risk profile. Notably, RAMA goes beyond risk quantification; it facilitates a comparative analysis by enabling organizations to measure their performance against average aggregated mean scores, fostering a culture of continuous improvement in cyber security practices. The practical efficacy of RAMA is demonstrated through its deployment across four real-world healthcare IT infrastructures. This study not only underscores the significance of addressing cyber security risks within healthcare but also highlights the value of innovative solutions like RAMA in safeguarding sensitive health information and enhancing the sector’s overall cyber resilience.

Details

10000008
Business indexing term
Title
RAMA: a risk assessment solution for healthcare organizations
Author
Smyrlis, Michail 1   VIAFID ORCID Logo  ; Floros, Evangelos 2 ; Basdekis, Ioannis 3 ; Prelipcean, Dumitru-Bogdan 4 ; Sotiropoulos, Aristeidis 5 ; Debar, Herve 6 ; Zarras, Apostolis 7   VIAFID ORCID Logo  ; Spanoudakis, George 3   VIAFID ORCID Logo 

 SPHYNX Technology Solutions AG, Zug, Switzerland (GRID:grid.519511.8); City University of London, Department of Computer Science, London, UK (GRID:grid.28577.3f) (ISNI:0000 0004 1936 8497) 
 University General Hospital of Heraklion, Crete, Hellas (GRID:grid.412481.a) (ISNI:0000 0004 0576 5678) 
 SPHYNX Technology Solutions AG, Zug, Switzerland (GRID:grid.519511.8) 
 Bitdefender, Bucharest, Romania (GRID:grid.519511.8); Alexandru Ioan Cuza University, Iaşi, Romania (GRID:grid.8168.7) (ISNI:0000 0004 1937 1784); Paris-Est Créteil University, Créteil, France (GRID:grid.410511.0) (ISNI:0000 0004 9512 4013) 
 AEGIS IT Research, Braunschweig, Germany (GRID:grid.410511.0) 
 Institut Polytechnique de Paris, SAMOVAR, Télécom SudParis, Palaiseau, France (GRID:grid.508893.f) 
 Foundation for Research and Technology, Crete, Hellas (GRID:grid.4834.b) (ISNI:0000 0004 0635 685X); University of Piraeus, Piraeus, Greece (GRID:grid.4463.5) (ISNI:0000 0001 0558 8585) 
Publication title
Volume
23
Issue
3
Pages
1821-1838
Publication year
2024
Publication date
Jun 2024
Publisher
Springer Nature B.V.
Place of publication
Heidelberg
Country of publication
Netherlands
Publication subject
ISSN
16155262
e-ISSN
16155270
Source type
Scholarly Journal
Language of publication
English
Document type
Journal Article
Publication history
 
 
Online publication date
2024-03-01
Milestone dates
2024-01-27 (Registration)
Publication history
 
 
   First posting date
01 Mar 2024
ProQuest document ID
3060206363
Document URL
https://www.proquest.com/scholarly-journals/rama-risk-assessment-solution-healthcare/docview/3060206363/se-2?accountid=208611
Copyright
© The Author(s) 2024. This work is published under http://creativecommons.org/licenses/by/4.0/ (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.
Last updated
2025-11-19
Database
ProQuest One Academic