Department of Software and Information Systems Engineering, Faculty of Engineering Sciences, Ben Gurion University of the Negev, Beer Sheva, Israel.
Department of Health Systems Management, School of Public Health, Faculty of Health Sciences, Ben-Gurion University of the Negev, Beer-Sheva, Israel.
Euro Surveill. 2020 Feb;25(6). doi: 10.2807/1560-7917.ES.2020.25.6.1900574.
Next generation sequencing (NGS) is becoming the new gold standard in public health microbiology. Like any disruptive technology, its growing popularity inevitably attracts cyber security actors, for whom the health sector is attractive because it combines mission-critical infrastructure and high-value data with cybersecurity vulnerabilities. In this Perspective, we explore cyber security aspects of microbial NGS. We discuss the motivations and objectives for such attack, its feasibility and implications, and highlight policy considerations aimed at threat mitigation. Particular focus is placed on the attack vectors, where the entire process of NGS, from sample to result, could be vulnerable, and a risk assessment based on probability and impact for representative attack vectors is presented. Cyber attacks on microbial NGS could result in loss of confidentiality (leakage of personal or institutional data), integrity (misdetection of pathogens) and availability (denial of sequencing services). NGS platforms are also at risk of being used as propagation vectors, compromising an entire system or network. Owing to the rapid evolution of microbial NGS and its applications, and in light of the dynamics of the cyber security domain, frequent risk assessments should be carried out in order to identify new threats and underpin constantly updated public health policies.
下一代测序(NGS)正成为公共卫生微生物学的新标准。与任何颠覆性技术一样,其日益普及不可避免地吸引了网络安全参与者,因为卫生部门具有吸引力,因为它将关键任务基础设施和高价值数据与网络安全漏洞结合在一起。在本观点中,我们探讨了微生物 NGS 的网络安全方面。我们讨论了此类攻击的动机和目标、其可行性和影响,并强调了旨在减轻威胁的政策考虑因素。特别关注攻击媒介,在整个 NGS 过程中,从样本到结果,都可能存在漏洞,并根据代表性攻击媒介的概率和影响进行风险评估。对微生物 NGS 的网络攻击可能导致机密性丧失(个人或机构数据泄露)、完整性丧失(病原体检测错误)和可用性丧失(测序服务被拒绝)。NGS 平台也有被用作传播媒介的风险,从而危及整个系统或网络。由于微生物 NGS 及其应用的快速发展,以及网络安全领域的动态性,应经常进行风险评估,以识别新的威胁,并为不断更新的公共卫生政策提供支持。