When Cyber Attacks Hit Hospitals: Why Every Hospital Needs an Incident Response Team
![]() |
| Illustration of a hospital incident response team dealing with a ransomware attack on computer systems, showing doctors and IT staff collaborating |
Ketika Serangan Siber Menghantam Rumah Sakit: Mengapa Setiap Rumah Sakit Butuh Tim Tanggap Insiden
Gw mau lo bayangin sebuah skenario.
Pagi hari. Seorang dokter datang ke ruang praktik. Buka laptop. Siap-siap melayani pasien.
Tiba-tiba, layarnya berubah. Nggak ada file yang bisa dibuka. Nggak ada aplikasi yang bisa dijalankan. Yang ada cuma satu pesan:
"YOUR FILES HAVE BEEN ENCRYPTED. PAY RANSOM TO GET THE KEY."
Dokter itu bingung. Dia coba restart. Sama aja. Dia coba buka file pasien. Nggak bisa. Dia coba buka sistem resep. Nggak bisa.
Kemudian, dia denger kabar: komputer lain juga kena. Satu per satu. Kayak api yang menjalar. Server. Database. Sistem farmasi. Semua mulai mati.
Pasien mulai berdatangan. Tapi sistem pendaftaran nggak bisa dipakai. Dokter nggak bisa akses riwayat medis. Resep nggak bisa dikeluarkan. Rumah sakit mulai lumpuh.
Ini bukan film horor. Ini adalah skenario yang sudah terjadi di rumah sakit di berbagai belahan dunia. Dan ini bisa terjadi di rumah sakit mana pun—termasuk di Indonesia.
Pertanyaannya: kalau ini terjadi di rumah sakit kita, apa yang akan terjadi? Siapa yang bertindak? Apa yang harus dilakukan?
Nah, di sinilah peran TTIS—Tim Tanggap Insiden Siber. Atau dalam istilah internasional: CSIRT—Computer Security Incident Response Team.
Gw mau ceritain tentang ini. Tentang apa yang harus dilakukan ketika perlindungan data yang sudah kita bangun ternyata berhasil ditembus.
Dari Kriptografi ke TTIS: Nyambung Banget
Di sesi sebelumnya, gw udah bahas soal kriptografi. Itu adalah tentang bagaimana melindungi data. Kunci. Enkripsi. Algoritma. Semua yang bikin data aman.
Tapi nggak ada sistem yang 100% aman. Selalu ada celah. Selalu ada risiko. Dan kadang, meskipun udah berusaha sekuat tenaga, serangan tetap terjadi.
Nah, kalau sesi sebelumnya menjawab pertanyaan:
"Bagaimana data kita lindungi?"
Maka sesi ini menjawab pertanyaan:
"Kalau perlindungan itu ditembus dan serangan terjadi, siapa yang bertindak dan apa yang harus dilakukan?"
Jawabannya: TTIS/CSIRT.
Bayangin kayak gini. Rumah sakit adalah sebuah rumah. Kriptografi itu kunci pintu dan brankas. Firewall itu pagar dan gerbang. Antivirus itu anjing penjaga. CCTV itu sistem pemantauan.
Nah, TTIS/CSIRT itu adalah tim pemadam kebakaran dan investigasi. Mereka bukan cuma datang setelah kebakaran terjadi. Mereka juga mencegah, mendeteksi, menganalisis, dan memastikan kebakaran yang sama nggak terulang.
Kenapa Rumah Sakit Butuh TTIS?
Gw sering dengar orang bilang: "Ah, rumah sakit kecil, nggak mungkin kena serangan siber."
Salah besar.
Rumah sakit—besar atau kecil—sekarang udah sangat bergantung pada teknologi. Ada Rekam Medis Elektronik. Ada SIMRS. Ada sistem laboratorium. Ada sistem farmasi. Ada sistem radiologi. Ada sistem pendaftaran dan billing. Ada integrasi dengan BPJS. Ada SATUSEHAT.
Semua saling terhubung.
Dan di balik semua itu, ada data. Data pasien. Data medis. Data pribadi. Data yang sangat sensitif.
Akibatnya: semakin digital rumah sakit, semakin besar dampaknya kalau sistemnya diserang.
Coba bayangin. Satu komputer kena malware. Kelihatannya kecil. Tapi kalau malware itu menyebar? Dari komputer dokter ke server. Dari server ke database. Dari database ke aplikasi. Dari aplikasi ke perangkat medis.
Boom. Seluruh rumah sakit bisa lumpuh.
Dan ingat: di rumah sakit, setiap detik keterlambatan bisa berarti nyawa.
Tiga Jenis Masalah yang Harus Dipahami
Sebelum gw bahas lebih jauh tentang TTIS, gw mau jelasin dulu tiga jenis masalah yang sering terjadi di dunia siber. Ini penting banget buat dipahami.
1. Data Leak (Kebocoran Data)
Ini adalah ketika data terbuka—baik sengaja maupun nggak sengaja.
Contoh sederhana: staf rumah sakit salah kirim file Excel berisi data pasien ke grup WhatsApp yang salah. Nggak ada hacker. Nggak ada serangan canggih. Cuma human error.
Tapi dampaknya? Sama-sama berbahaya.
2. Data Breach (Pelanggaran Data)
Ini sedikit berbeda. Data breach adalah ketika data rahasia dibuka atau dicuri akibat serangan siber.
Misalnya: hacker berhasil masuk ke database rumah sakit dan mencuri 500.000 data pasien. Ini bukan kesalahan manusia. Ini serangan yang disengaja.
3. Data Hostage (Data Disandera)
Ini yang paling serem. Data dienkripsi sehingga nggak bisa digunakan sampai tebusan dibayar.
Ini adalah ransomware. Layar komputer tiba-tiba muncul pesan: "Bayar sejumlah uang untuk mendapatkan kunci." Semua file terkunci. Sistem nggak bisa dipakai. Rumah sakit harus milih antara bayar atau kehilangan akses ke data pasien.
Dan yang bikin lebih parah: bayar tebusan nggak menjamin data balik. Banyak kasus di mana setelah bayar, data tetap hilang atau malah dijual lagi di darkweb.
Kasus Nyata yang Bikin Merinding
Materi ini ngasih beberapa contoh insiden keamanan siber di sektor kesehatan. Beberapa yang paling terkenal:
- SingHealth, Singapura: Data 1,5 juta pasien dicuri. Termasuk data perdana menteri.
- Springhill Medical Center, AS: Serangan ransomware yang menyebabkan gangguan layanan dan diduga berkontribusi pada kematian pasien.
- Dusseldorf University Hospital, Jerman: Serangan ransomware yang menyebabkan pasien darurat harus dirujuk ke rumah sakit lain. Seorang pasien meninggal dalam perjalanan.
- Synnovis/NHS London: Serangan ransomware yang menyebabkan ratusan operasi dan janji temu dibatalkan.
Ini bukan cuma soal data. Ini soal nyawa.
Yang menarik dari kasus SingHealth adalah pelajarannya nggak cuma teknis. Ada empat aspek yang dievaluasi:
- People (Manusia): Apakah pegawai sudah terlatih?
- Process (Prosedur): Apakah SOP sudah jelas?
- Technology (Teknologi): Apakah sistem sudah aman?
- Partnerships (Kemitraan): Apakah koordinasi dengan pihak lain sudah baik?
Ini pesan penting: keamanan siber bukan cuma masalah teknisi IT.
Apa Itu TTIS/CSIRT?
Oke, sekarang gw jelasin intinya.
TTIS/CSIRT adalah tim yang disiapkan organisasi untuk menghadapi insiden keamanan siber.
Bukan cuma untuk "memadamkan api" ketika sudah terjadi. Tapi juga untuk:
- Mencegah insiden terjadi
- Mendeteksi ancaman sedini mungkin
- Menganalisis apa yang terjadi
- Menangani insiden dengan cepat
- Memulihkan sistem kembali normal
- Belajar dari insiden supaya nggak terulang
Bayangin TTIS kayak tim pemadam kebakaran digital. Tapi bukan cuma yang datang setelah api membesar. Mereka juga ngecek alat pemadam, ngecek jalur evakuasi, dan ngelatih orang supaya siap kalau terjadi kebakaran.
Model TTIS: Nggak Harus Satu Ruangan Penuh Orang
Salah satu hal yang menarik dari materi ini adalah: TTIS nggak harus berupa satu ruangan penuh orang.
Strukturnya bisa disesuaikan dengan kebutuhan dan ukuran organisasi. Ada beberapa model yang bisa dipilih. Yang penting: fungsinya jalan.
Intinya: nggak ada satu bentuk organisasi TTIS yang mutlak sama untuk semua rumah sakit. Yang penting ada orang yang bertanggung jawab, SOP yang jelas, dan kewenangan untuk bertindak.
Layanan TTIS: Apa Saja yang Mereka Kerjakan?
Materi ini ngebahas layanan TTIS secara cukup detail. Gw rangkum dalam tiga kelompok besar.
1. Reactive Services (Layanan Reaktif)
Ini adalah layanan yang dilakukan setelah atau ketika insiden terjadi.
Contoh:
- Menerima laporan insiden
- Analisis insiden
- Respons insiden
- Koordinasi dengan pihak terkait
- Analisis artefak (bukti digital)
Intinya: begitu insiden terjadi, TTIS langsung bergerak.
2. Proactive Services (Layanan Proaktif)
Ini adalah layanan yang dilakukan sebelum serangan terjadi.
Contoh:
- Penilaian keamanan
- Penilaian kerentanan
- Pemantauan (monitoring)
- Threat intelligence
- Pelatihan kesadaran keamanan
- Audit keamanan
- Penetration testing
Prinsipnya: jangan tunggu diserang. Cari kelemahan sebelum hacker menemukannya.
3. Security Quality Management Services
Ini lebih ke peningkatan kualitas keamanan secara berkelanjutan.
Contoh:
- Analisis risiko
- Perencanaan business continuity
- Perencanaan disaster recovery
- Konsultasi keamanan
- Pendidikan dan pelatihan
- Evaluasi produk
- Sertifikasi
Dasar Regulasi: BSSN Nomor 1 Tahun 2024
TTIS ini nggak cuma "ide bagus". Ada dasar hukumnya.
Lewat Peraturan BSSN Nomor 1 Tahun 2024 tentang Pengelolaan Insiden Siber, setiap instansi—termasuk rumah sakit—diwajibkan punya kemampuan untuk mengelola insiden siber.
Beberapa fungsi TTIS yang disebutkan:
- Memberikan peringatan keamanan
- Merumuskan teknis penanganan insiden
- Mencatat laporan dan aduan
- Memberikan rekomendasi
- Melakukan penilaian/triage insiden
- Melakukan koordinasi penanganan
Ini sinyal yang jelas: negara serius soal keamanan siber di sektor kesehatan.
Apa Itu "Triage" Insiden?
Istilah ini penting banget.
Triage adalah proses menentukan seberapa serius sebuah insiden dan apa yang harus dilakukan terlebih dahulu.
Bayangin rumah sakit menerima 10 laporan dalam satu hari:
- Komputer lambat
- Email spam
- Server database nggak bisa diakses
- Ransomware menyebar
- Website lambat
Mana yang harus didahulukan?
Jelas: ransomware yang mulai menyebar ke sistem kritis. Itu prioritas tertinggi. Email spam? Bisa ditangani nanti.
Jadi TTIS harus bisa memilah mana yang kritis, mana yang sedang, mana yang rendah.
Orang-Orang di TTIS Harus Punya Kompetensi
Ini sering dilupakan. TTIS nggak cukup cuma "orang IT yang bisa memperbaiki komputer."
Dibutuhkan pengetahuan tentang:
- Keamanan siber
- Manajemen aset
- Manajemen risiko
- Incident management
- SMKI
- Jaringan
- Log security
- Proses bisnis
- Threat intelligence
- Endpoint security
- Digital forensics
- Malware reverse engineering
Dan satu yang paling sering dilupakan: memahami proses bisnis rumah sakit.
Kenapa ini penting? Karena keputusan teknis harus mempertimbangkan dampak operasional.
Misalnya: TTIS menemukan server farmasi terinfeksi malware. Secara teknis, solusinya gampang: "Matikan server." Tapi dari sisi bisnis: apakah farmasi bisa tetap melayani pasien? Bagaimana kalau sistem resep nggak bisa digunakan? Bagaimana kalau obat pasien nggak bisa diverifikasi?
Jadi orang TTIS harus paham: dampak teknis → dampak operasional → dampak pelayanan pasien.
Sarana dan Prasarana TTIS
TTIS juga butuh alat. Beberapa di antaranya:
- IDS (Intrusion Detection System): Kayak alarm. Memberi tahu kalau ada aktivitas mencurigakan.
- SIEM (Security Information and Event Management): Kayak pusat CCTV digital. Mengumpulkan berbagai log dan event dari banyak sistem.
- Log Management: Tempat mengumpulkan dan mengelola catatan aktivitas sistem.
- Malware Analysis Tools: Buat membedah malware: "Ini sebenarnya melakukan apa?"
- Vulnerability Assessment Tools: Buat mencari kelemahan sistem: "Bagian mana yang bisa diserang?"
Ini semua adalah alat bantu. Tapi pada akhirnya, manusialah yang menentukan apakah alat tersebut digunakan dengan efektif.
Bagaimana Melaporkan Insiden?
Materi ini ngasih alur pelaporan yang jelas. Secara sederhana:
INSIDEN → LAPOR KE CSIRT ORGANISASI → CSIRT ORGANISASI → KOORDINASI DENGAN CSIRT SEKTORAL
Dalam konteks rumah sakit: pegawai/dokter menemukan kejadian → lapor ke TTIS rumah sakit → TTIS melakukan pemeriksaan → jika diperlukan, koordinasi dengan CSIRT sektoral.
Yang dilaporkan adalah insiden yang memiliki risiko tinggi. Bukan setiap email spam. Tapi insiden yang berpotensi mengganggu operasional atau membahayakan data pasien.
Contoh Kasus yang Diberikan PDF
Nah, ini bagian yang menurut gw paling relevan buat rumah sakit.
Materi ngasih simulasi: Seorang dokter sedang melayani pasien. Tiba-tiba komputer nggak bisa diakses. Muncul pesan tebusan. File berubah jadi ekstensi aneh kayak .locked, .encrypted, atau .rsync.
Kemudian ternyata: komputer lain juga mengalami hal yang sama.
Akibatnya:
- Sistem elektronik nggak bisa digunakan
- Aplikasi nggak bisa digunakan
- Perangkat medis tertentu nggak bisa digunakan
Ini adalah skenario ransomware yang sudah berkembang menjadi insiden serius.
Dan pertanyaannya: siapa yang bertindak?
Pembagian Tanggung Jawab Saat Insiden Terjadi
Materi ini membagi tanggung jawab menjadi tiga kelompok:
1. Dokter / Tenaga Medis
Fokus: pasien.
2. Tim IT Rumah Sakit
Fokus: sistem dan keamanan.
3. Manajemen Rumah Sakit
Fokus: kelangsungan pelayanan, keputusan, koordinasi, dan risiko organisasi.
Ini sangat penting. Karena ketika ransomware menyerang, bukan cuma masalah IT. Ini masalah seluruh rumah sakit.
Fase 0-2 Jam: Deteksi dan Respons Awal
Ini adalah fase paling kritis. Keputusan di 2 jam pertama bisa menentukan apakah insiden bisa dikendalikan atau justru membesar.
Yang Harus Dilakukan Dokter/Tenaga Medis:
- Jangan panik.
- Jangan mematikan/mengutak-atik komputer sembarangan. Ini bisa menghilangkan bukti digital.
- Laporkan segera ke TTIS atau IT.
- Jangan menghubungkan perangkat tambahan kayak flashdisk.
- Gunakan prosedur manual untuk melayani pasien.
- Jangan menyebarkan informasi insiden sembarangan.
Tujuannya: keselamatan pasien tetap prioritas.
Yang Harus Dilakukan Tim IT:
- Isolasi jaringan yang terkena
- Identifikasi ruang lingkup infeksi
- Hubungi pimpinan IT
- Amankan sistem yang belum terinfeksi
- Cegah penyebaran ke sistem lain
- Hubungi pihak terkait (TTIS, manajemen)
Tujuannya: mengendalikan penyebaran dan mengetahui seberapa luas dampaknya.
Yang Harus Dilakukan Manajemen:
- Aktifkan Business Continuity Plan
- Aktifkan tim krisis
- Libatkan dokter, IT, humas, hukum, dan pihak terkait
- Pastikan pelayanan pasien tetap berjalan
- Tentukan keputusan strategis (apakah bayar tebusan atau tidak, apakah rujuk pasien, dll.)
Manajemen nggak boleh berkata: "Itu urusan IT." Karena ketika sistem rumah sakit lumpuh, itu sudah menjadi masalah bisnis dan pelayanan rumah sakit.
Fase 2-24 Jam: Penilaian dan Stabilisasi
Pada tahap ini, TTIS mulai melakukan:
- Investigasi: Apa yang sebenarnya terjadi?
- Identifikasi titik masuk serangan
- Verifikasi sistem yang masih aman
- Pemeriksaan log dan bukti digital
- Koordinasi dengan CSIRT sektoral
- Menjaga sistem kritis tetap aman
Tujuannya: mengendalikan situasi dan memahami apa yang sebenarnya terjadi.
Fase 1-7 Hari: Pemulihan Bertahap
Sekarang rumah sakit mulai mengembalikan layanan. Tapi ada prinsip penting:
Jangan langsung menghidupkan semuanya.
Harus dipastikan dulu: "Sistem ini sudah bersih atau belum?"
Langkah-langkahnya:
- Restore dari backup yang sudah diverifikasi bersih
- Verifikasi data yang dipulihkan
- Reset password semua akun
- Monitoring ketat untuk memastikan nggak ada sisa ancaman
- Pemulihan sistem secara bertahap—prioritaskan yang paling kritis
- Pengujian sebelum sistem kembali digunakan
Fase 1-3 Bulan: Pemulihan Penuh dan Pelajaran
Ini adalah fase yang paling sering dilupakan.
Setelah sistem kembali normal, pekerjaan belum selesai. Rumah sakit harus melakukan:
- Evaluasi: Mengapa serangan bisa terjadi?
- Perbaikan: Bagian mana yang harus diperbaiki?
- Monitoring: Apakah masih ada ancaman yang tersisa?
- Kebijakan: Apakah SOP perlu diperbarui?
- Pelatihan: Apakah pegawai perlu dilatih lagi?
Dengan kata lain: insiden harus menghasilkan pembelajaran. Nggak boleh cuma "udah, selesai." Harus ada perbaikan berkelanjutan.
Siklus Incident Response: Bukan Sekali Selesai
Jadi siklusnya bukan:
Serang → Perbaiki → Selesai.
Tapi:
DETEKSI → RESPONS → INVESTIGASI → KENDALIKAN → PEMULIHAN → EVALUASI → PERBAIKI → CEGAH TERULANG → KEMBALI KE DETEKSI
Inilah yang disebut incident response lifecycle. Siklus yang terus berputar. Setiap insiden adalah kesempatan untuk menjadi lebih baik.
Bagaimana Mengukur Apakah TTIS Bagus?
Materi ini juga ngebahas KPI TTIS/CSIRT. Artinya, keberhasilan TTIS nggak cukup diukur dengan "timnya ada." Harus diukur berdasarkan kinerja.
Beberapa contoh KPI:
- Seberapa cepat merespons? Kalau insiden terjadi pukul 08.00, apakah TTIS baru merespons pukul 12.00? Atau 08.05 sudah ditangani?
- Seberapa cepat insiden dipulihkan? Berapa lama sampai layanan kembali normal?
- Seberapa efektif mendeteksi? Apakah serangan ditemukan oleh TTIS, atau justru diberitahu oleh hacker?
- Berapa banyak insiden yang berhasil ditangani?
- Apakah insiden yang sama terulang? Kalau ransomware terjadi tiga kali dengan penyebab yang sama, ada masalah dalam proses perbaikannya.
Faktor Keberhasilan TTIS
Materi ini nyebut enam faktor yang menentukan keberhasilan TTIS:
- Mandate & Governance: Harus ada dukungan dan kewenangan dari manajemen. Tanpa ini, TTIS susah bekerja.
- People & Capability: Harus ada orang yang kompeten dan terlatih.
- Process & Technology: Harus ada SOP dan teknologi yang tepat.
- Response Effectiveness: Respons harus cepat dan efektif.
- Measurement: Kinerja harus diukur.
- Continuous Improvement: TTIS harus terus berkembang dan memperbaiki diri.
Dan di bawah semua itu, ada konsep yang lebih besar:
Kolaborasi + Komunikasi + Kepercayaan + Budaya Keamanan
Ini adalah jiwa dari seluruh materi. Karena keamanan siber nggak bisa dikerjakan sendirian.
Yang Bisa Kita Simpulkan
Kalau semua ini harus gw simpulkan dalam satu paragraf:
Rumah sakit sekarang sangat bergantung pada sistem digital. Serangan siber bukan lagi masalah "kalau" tapi "kapan." Ketika serangan terjadi, rumah sakit harus punya TTIS/CSIRT yang punya kewenangan, personel kompeten, SOP jelas, teknologi memadai, dan jalur koordinasi yang terstruktur. Respons harus dilakukan secara sistematis: deteksi → lapor → isolasi → investigasi → stabilisasi → pemulihan → evaluasi. Dokter fokus pada pasien, IT fokus pada sistem, manajemen fokus pada keberlangsungan pelayanan. Dan setelah insiden selesai, rumah sakit harus belajar dan memperbaiki diri.
Dan satu hal yang paling penting: keamanan siber adalah pekerjaan bersama. Bukan pekerjaan satu orang. Bukan pekerjaan satu bagian. Tapi tanggung jawab semua orang yang terlibat dalam ekosistem kesehatan.
Pertanyaan yang harus kita tanyakan pada diri sendiri dan institusi kita:
"Ketika serangan siber terjadi, apakah rumah sakit kita siap menghadapinya?"
Bukan "apakah akan terjadi." Tapi "kapan terjadi, dan apakah kita siap?"
Entahlah. Mungkin gw yang terlalu paranoid. Tapi menurut gw, lebih baik siap sedia daripada menyesal di kemudian hari.
Gimana menurut lo?
When Cyber Attacks Hit Hospitals: Why Every Hospital Needs an Incident Response Team
I want you to imagine a scenario.
Early morning. A doctor comes to their practice room. Opens their laptop. Ready to serve patients.
Suddenly, the screen changes. No files can be opened. No applications can run. All that's left is one message:
"YOUR FILES HAVE BEEN ENCRYPTED. PAY RANSOM TO GET THE KEY."
The doctor is confused. They restart. Same thing. They try to open patient files. Can't. They try to open the prescription system. Can't.
Then they hear: other computers are also affected. One by one. Like a spreading fire. Servers. Databases. Pharmacy systems. Everything starts shutting down.
Patients start arriving. But the registration system is down. Doctors can't access medical histories. Prescriptions can't be issued. The hospital is grinding to a halt.
This isn't a horror movie. This is a scenario that has already happened in hospitals around the world. And it could happen to any hospital—including in Indonesia.
The question is: if this happens in our hospital, what would happen? Who acts? What should be done?
This is where TTIS comes in—Tim Tanggap Insiden Siber, or Cyber Incident Response Team. In international terms: CSIRT—Computer Security Incident Response Team.
I want to tell you about this. About what needs to be done when the data protection we've built turns out to have been breached.
From Cryptography to TTIS: They're Connected
In the previous session, I talked about cryptography. That was about how to protect data. Keys. Encryption. Algorithms. Everything that keeps data secure.
But no system is 100% secure. There's always a gap. Always a risk. And sometimes, no matter how hard we try, attacks still happen.
If the previous session answered the question:
"How do we protect our data?"
Then this session answers the question:
"If that protection is breached and an attack occurs, who acts and what should be done?"
The answer: TTIS/CSIRT.
Think of it like this. The hospital is a house. Cryptography is the door lock and safe. Firewall is the fence and gate. Antivirus is the guard dog. CCTV is the monitoring system.
TTIS/CSIRT is the fire and investigation team. They don't just come after the fire breaks out. They also prevent, detect, analyze, and make sure the same fire doesn't happen again.
Why Do Hospitals Need TTIS?
I often hear people say: "Ah, it's a small hospital, it wouldn't be targeted by a cyber attack."
That's completely wrong.
Hospitals—big or small—are now highly dependent on technology. There's Electronic Medical Records. Hospital Information Systems. Laboratory systems. Pharmacy systems. Radiology systems. Registration and billing systems. Integration with health insurance. SATUSEHAT.
Everything is connected.
And behind it all, there's data. Patient data. Medical data. Personal data. Highly sensitive data.
The consequence: the more digital the hospital, the greater the impact if its systems are attacked.
Imagine. One computer gets malware. Seems small. But if that malware spreads? From the doctor's computer to the server. From the server to the database. From the database to applications. From applications to medical devices.
Boom. The entire hospital could be paralyzed.
And remember: in a hospital, every second of delay can mean a life.
Three Types of Problems to Understand
Before I go further into TTIS, let me explain three types of problems that often occur in the cyber world. This is important to understand.
1. Data Leak
This is when data is exposed—either intentionally or unintentionally.
A simple example: a hospital staff member accidentally sends an Excel file containing patient data to the wrong WhatsApp group. No hackers. No sophisticated attack. Just human error.
But the impact? Just as dangerous.
2. Data Breach
This is slightly different. A data breach is when confidential data is opened or stolen as a result of a cyber attack.
For example: a hacker successfully breaches a hospital's database and steals 500,000 patient records. This isn't human error. This is a deliberate attack.
3. Data Hostage
This is the scariest. Data is encrypted so it can't be used until a ransom is paid.
This is ransomware. The computer screen suddenly shows a message: "Pay a sum of money to get the key." All files are locked. Systems can't be used. The hospital has to choose between paying or losing access to patient data.
What makes it worse: paying the ransom doesn't guarantee the data will be returned. In many cases, even after payment, the data remained lost or was sold again on the dark web.
Real Cases That Give Chills
This material provides several examples of cybersecurity incidents in the healthcare sector. Some of the most well-known:
- SingHealth, Singapore: Data of 1.5 million patients stolen. Including the prime minister's data.
- Springhill Medical Center, US: A ransomware attack that caused service disruptions and was believed to have contributed to a patient's death.
- Dusseldorf University Hospital, Germany: A ransomware attack that caused emergency patients to be referred to other hospitals. One patient died in transit.
- Synnovis/NHS London: A ransomware attack that caused hundreds of surgeries and appointments to be cancelled.
This isn't just about data. This is about lives.
What's interesting about the SingHealth case is that the lessons aren't just technical. Four aspects were evaluated:
- People: Were staff properly trained?
- Process: Were SOPs clear?
- Technology: Were systems secure?
- Partnerships: Was coordination with other parties good?
This is an important message: cybersecurity isn't just an IT technician's problem.
What Is TTIS/CSIRT?
OK, now let me explain the core.
TTIS/CSIRT is a team prepared by an organization to handle cybersecurity incidents.
Not just to "put out fires" when they happen. But also to:
- Prevent incidents from occurring
- Detect threats as early as possible
- Analyze what happened
- Handle incidents quickly
- Recover systems to normal operation
- Learn from incidents so they don't happen again
Think of TTIS like a digital fire department. But not just one that comes after the fire is already big. They also check extinguishers, check evacuation routes, and train people to be ready in case of fire.
TTIS Models: Doesn't Have to Be a Room Full of People
One interesting thing from this material is: TTIS doesn't have to be a room full of people.
The structure can be adapted to the needs and size of the organization. Several models are available. What matters: the function works.
The point: there is no one-size-fits-all TTIS structure for all hospitals. What matters is having responsible people, clear SOPs, and the authority to act.
TTIS Services: What Do They Actually Do?
This material discusses TTIS services in quite some detail. Let me summarize in three main groups.
1. Reactive Services
These are services performed after or when an incident occurs.
Examples:
- Receiving incident reports
- Incident analysis
- Incident response
- Coordination with relevant parties
- Artifact (digital evidence) analysis
In essence: once an incident occurs, TTIS springs into action.
2. Proactive Services
These are services performed before an attack occurs.
Examples:
- Security assessments
- Vulnerability assessments
- Monitoring
- Threat intelligence
- Security awareness training
- Security audits
- Penetration testing
The principle: don't wait to be attacked. Find weaknesses before hackers do.
3. Security Quality Management Services
These are about continuous security quality improvement.
Examples:
- Risk analysis
- Business continuity planning
- Disaster recovery planning
- Security consulting
- Education and training
- Product evaluation
- Certification
The Regulatory Foundation: BSSN Regulation No. 1 of 2024
TTIS isn't just a "good idea." There's a legal basis.
Through BSSN Regulation No. 1 of 2024 on Cyber Incident Management, every institution—including hospitals—is required to have the capability to manage cyber incidents.
Some of TTIS functions mentioned:
- Providing security alerts
- Formulating incident handling techniques
- Recording reports and complaints
- Providing recommendations
- Conducting incident triage/assessment
- Coordinating incident handling
This is a clear signal: the state is serious about cybersecurity in the healthcare sector.
What Is Incident "Triage"?
This is an important term.
Triage is the process of determining how serious an incident is and what should be done first.
Imagine a hospital receives 10 reports in one day:
- Slow computer
- Spam email
- Database server inaccessible
- Ransomware spreading
- Slow website
Which should be prioritized?
Obviously: ransomware spreading to critical systems. That's top priority. Spam email? That can wait.
So TTIS must be able to prioritize what's critical, what's moderate, and what's low.
TTIS Team Members Must Have Competencies
This is often overlooked. TTIS isn't just "IT people who can fix computers."
Knowledge is needed in:
- Cybersecurity
- Asset management
- Risk management
- Incident management
- ISMS
- Networking
- Security logging
- Business processes
- Threat intelligence
- Endpoint security
- Digital forensics
- Malware reverse engineering
And one that's most often forgotten: understanding hospital business processes.
Why is this important? Because technical decisions must consider operational impact.
For example: TTIS finds the pharmacy server infected with malware. Technically, the solution is simple: "Shut down the server." But from a business perspective: can the pharmacy still serve patients? What if the prescription system can't be used? What if patient medication can't be verified?
So TTIS members must understand: technical impact → operational impact → patient service impact.
TTIS Tools and Infrastructure
TTIS also needs tools. Some of them:
- IDS (Intrusion Detection System): Like an alarm. Alerts when suspicious activity occurs.
- SIEM (Security Information and Event Management): Like a digital CCTV center. Collects various logs and events from many systems.
- Log Management: A place to collect and manage system activity records.
- Malware Analysis Tools: To dissect malware: "What is this actually doing?"
- Vulnerability Assessment Tools: To find system weaknesses: "Which parts could be attacked?"
All of these are tools. But ultimately, it's the people who determine whether the tools are used effectively.
How to Report an Incident?
This material provides a clear reporting flow. In simple terms:
INCIDENT → REPORT TO ORGANIZATION CSIRT → ORGANIZATION CSIRT → COORDINATE WITH SECTORAL CSIRT
In the hospital context: staff/doctor discovers an event → reports to hospital TTIS → TTIS conducts examination → if needed, coordinates with sectoral CSIRT.
What should be reported are incidents with high risk. Not every spam email. But incidents that have the potential to disrupt operations or endanger patient data.
A Case Example from the Material
Now, this is what I think is most relevant for hospitals.
The material provides a simulation: A doctor is treating a patient. Suddenly, the computer can't be accessed. A ransom message appears. Files change to strange extensions like .locked, .encrypted, or .rsync.
Then it turns out: other computers are also affected.
The consequences:
- Electronic systems can't be used
- Applications can't be used
- Certain medical devices can't be used
This is a ransomware scenario that has escalated into a serious incident.
And the question is: who acts?
Division of Responsibility During an Incident
The material divides responsibilities into three groups:
1. Doctors / Medical Staff
Focus: patients.
2. Hospital IT Team
Focus: systems and security.
3. Hospital Management
Focus: service continuity, decision-making, coordination, and organizational risk.
This is very important. Because when ransomware strikes, it's not just an IT problem. It's a whole hospital problem.
Phase 0-2 Hours: Detection and Initial Response
This is the most critical phase. Decisions in the first 2 hours can determine whether the incident can be contained or escalates.
What Doctors/Medical Staff Should Do:
- Don't panic.
- Don't turn off or tamper with the computer arbitrarily. This could destroy digital evidence.
- Report immediately to TTIS or IT.
- Don't connect additional devices like flash drives.
- Use manual procedures to serve patients.
- Don't spread incident information carelessly.
Goal: patient safety remains the priority.
What the IT Team Should Do:
- Isolate affected networks
- Identify the scope of the infection
- Contact IT leadership
- Secure unaffected systems
- Prevent spread to other systems
- Contact relevant parties (TTIS, management)
Goal: control the spread and understand the extent of the impact.
What Management Should Do:
- Activate the Business Continuity Plan
- Activate the crisis team
- Involve doctors, IT, public relations, legal, and other relevant parties
- Ensure patient services continue
- Make strategic decisions (whether to pay the ransom or not, whether to refer patients, etc.)
Management cannot say: "That's IT's problem." Because when the hospital system is paralyzed, it has become a business and service problem for the hospital.
Phase 2-24 Hours: Assessment and Stabilization
In this phase, TTIS begins to:
- Investigate: What actually happened?
- Identify entry points of the attack
- Verify unaffected systems
- Examine logs and digital evidence
- Coordinate with sectoral CSIRT
- Keep critical systems secure
Goal: control the situation and understand what actually happened.
Phase 1-7 Days: Gradual Recovery
Now the hospital starts restoring services. But there's an important principle:
Don't turn everything back on at once.
It must first be confirmed: "Is this system clean or not?"
Steps:
- Restore from verified clean backup
- Verify restored data
- Reset all account passwords
- Intensive monitoring to ensure no lingering threats
- Gradual system recovery—prioritize the most critical systems
- Testing before systems are returned to use
Phase 1-3 Months: Full Recovery and Lessons Learned
This is the phase most often overlooked.
After systems are back to normal, the work isn't finished. The hospital must:
- Evaluate: Why did the attack happen?
- Improve: What needs to be fixed?
- Monitor: Are there remaining threats?
- Policy: Do SOPs need updating?
- Training: Do staff need more training?
In other words: incidents must result in learning. Not just "it's over, done." There must be continuous improvement.
The Incident Response Cycle: Not a One-Time Event
So the cycle isn't:
Attack → Fix → Done.
But:
DETECTION → RESPONSE → INVESTIGATION → CONTAINMENT → RECOVERY → EVALUATION → IMPROVEMENT → PREVENT RE-OCCURRENCE → BACK TO DETECTION
This is the incident response lifecycle. A continuous cycle. Every incident is an opportunity to become better.
How to Measure If TTIS Is Good?
This material also discusses TTIS/CSIRT KPIs. The success of TTIS shouldn't just be measured by "the team exists." It should be measured by performance.
Some KPI examples:
- How fast is the response? If an incident occurs at 8:00 AM, does TTIS only respond at 12:00 PM? Or is it handled by 8:05?
- How quickly is the incident resolved? How long until services return to normal?
- How effective is detection? Was the attack discovered by TTIS, or were they informed by the hacker?
- How many incidents were successfully handled?
- Does the same incident recur? If ransomware happens three times for the same reason, there's a problem in the improvement process.
Success Factors for TTIS
This material mentions six factors that determine TTIS success:
- Mandate & Governance: There must be support and authority from management. Without this, TTIS struggles to function.
- People & Capability: There must be competent and trained people.
- Process & Technology: There must be SOPs and the right technology.
- Response Effectiveness: Response must be fast and effective.
- Measurement: Performance must be measured.
- Continuous Improvement: TTIS must continuously develop and improve itself.
And underneath all this, there's a bigger concept:
Collaboration + Communication + Trust + Security Culture
This is the soul of the entire material. Because cybersecurity cannot be done alone.
What We Can Conclude
If I had to summarize all of this in one paragraph:
Hospitals are now highly dependent on digital systems. Cyber attacks are no longer a matter of "if" but "when." When an attack occurs, the hospital must have a TTIS/CSIRT with authority, competent personnel, clear SOPs, adequate technology, and structured coordination channels. Response must be systematic: detection → report → isolate → investigate → stabilize → recover → evaluate. Doctors focus on patients, IT focuses on systems, management focuses on service continuity. And after the incident is over, the hospital must learn and improve.
And one most important thing: cybersecurity is a shared responsibility. Not one person's job. Not one department's job. But everyone's responsibility involved in the healthcare ecosystem.
The question we must ask ourselves and our institutions:
"When a cyber attack occurs, is our hospital ready to face it?"
Not "if it will happen." But "when it happens, and are we ready?"
I don't know. Maybe I'm being too paranoid. But I believe it's better to be prepared than to regret later.
What do you think?
Terima kasih sudah mampir! Jika kamu menikmati konten ini dan ingin menunjukkan dukunganmu, bagaimana kalau mentraktirku secangkir kopi? 😊 Ini adalah gestur kecil yang sangat membantu untuk menjaga semangatku agar terus membuat konten-konten keren. Tidak ada paksaan, tapi secangkir kopi darimu pasti akan membuat hariku jadi sedikit lebih cerah. ☕️
Thank you for stopping by! If you enjoy the content and would like to show your support, how about treating me to a cup of coffee? �� It’s a small gesture that helps keep me motivated to continue creating awesome content. No pressure, but your coffee would definitely make my day a little brighter. ☕️ Buy Me Coffee

Post a Comment for "When Cyber Attacks Hit Hospitals: Why Every Hospital Needs an Incident Response Team"
Post a Comment
You are welcome to share your ideas with us in comments!