Reduce the Risk of Remote Worker Error Based Cyberattacks
Introduction
The pharmaceutical industry has been at the forefront in the project to overcome the COVID-19 pandemic. From research to find drugs that are an effective treatment for anyone with a severe infection, through to research, design, manufacture, and trials of multiple vaccine candidates. Several of which have been approved and are rolling out globally.
The success of the vaccine program and the Pharma industry's work is heavily reliant on big data and extensive biological and medical trials. Advances often take years due to collaboration between scientific, technological, and medical specialities within and between companies, and public sector research bodies such as Universities. Indeed, the underlying technologies for the mRNA viruses that went from conception to mass production in about a year resulted from decades of work and data sharing between many organisations.
The importance of large data sets and data science to Pharma and medical companies will only grow in the future. It will become easier to quickly sequence the genomes of pathogens to discover how they cause disease. And as the age of personalised medicine progresses with the cheap and quick sequencing of individual human genomes to create targeted drug regimens designed for each individual patient.
What is Big Data in the Pharmaceutical Industry?
The number of data sources and the amount of data they generate increases year on year in the life sciences industry. According to a study conducted by Unisys, 70% of Big Pharma executives, IT professionals, and operations managers in the sector said that the number and diversity of data sources in their organisations had increased over the previous two years. And 64% of respondents said that the task of managing and using the data effectively had become harder in that period.
The data tsunami that is engulfing the sector comes from all departments of the businesses, including research and development, clinical trials, electronic health records, manufacturing, operations, packaging, distribution, logistics, sales, quality assurance, and finance. Additional data comes from partners, vendors, suppliers, customers, regulators, and others. Managing, securing, and making sense of these diverse data streams is critical to the ongoing success of Big Pharma organisations.
Drug development and drug discovery within pharmaceutical companies will be increasingly reliant on big data analytics, artificial intelligence (AI) and machine learning (ML). Data scientists and data mining will be as crucial as biochemists in the search for new drugs. New treatments will be reliant on new technologies that companies will invent to integrate the real-world data across multiple data sources.
Securing Data Across Big Pharma
The systems in Pharma companies and the suppliers they interface with are not monolithic in nature. They all have many different systems that are providing various services to many groups. These systems are also deployed across multiple locations in private data centres, the cloud, and increasingly on edge networks with IoT and 5G connectivity at manufacturing facilities.
Not everyone within an organisation needs to access all systems or all the data they hold. Most only need access to the IT systems and data that are relevant to their job. This means that networks are already logically split up from a user perspective into lots of small groups of users and clients that access particular systems. When data sharing is required for research and operations, it needs to be shared securely.
Traditionally, Big Pharma has managed security from the data centre level with firewalls, Internet Protocol Security (IPsec) systems, and other point solutions. Traditional security infrastructure like this does not work well with large lateral data movements between systems. As a result, access to the data sets is often broad. This means that insiders often have access to data they don't need for their job function. Even worse than that, it means that any cybercriminals who breach external defences have unfettered access to many systems and their data sets. And the ability to steal intellectual property or do malicious damage is unchecked.
To counter this threat but at the same time not introduce frictions that reduce cross-discipline collaboration and research is what Unisys's microsegmentation solutions provide.
Unisys Microsegmentation Solutions
To counter cybercriminal threats but still deliver the data sharing and innovation vital for business growth and development, Big Pharma can use the advantages of microsegmentation when deployed as a primary security measure.
Microsegmentation involves partitioning networks to shrink the potential attack surface and prevent attacks from spreading across a network. Each system or datastore is logically isolated within its own micro-network, with communication occurring only through authorised channels that are limited to authorised and authenticated users. These micro-networks are invisible to anyone who doesn't need to access them. Unless given explicit access, then they logically don't exist on the network.
The same applies to any cybercriminals who breach the perimeter security protections on a network. The breach is sandboxed within the particular micro-segmented portion of the overall network that was compromised. This is especially useful when dealing with ransomware type attacks that have become numerous and sophisticated over the last few years. Suppose a user is tricked into following a phishing link and gets their device infected with ransomware. In that case, the malware can only spread within the micro-segment that the user is on. The rest of the network that the user never uses is invisible to them, and any malware they introduce can't infect it.
At the same time as securely isolating multiple parts of the network, microsegmentation also enables critical assets such as servers, workstations, clinical trial systems, drug manufacturing machines, and Internet of Things (IoT) devices to communicate through isolated, secure, encrypted channels. This helps to dramatically lower the risk of exposure in the event of an attack.
The Business Benefits of Microsegmentation
When decision making on cybersecurity systems to protect the data required for a modern Pharma company, consider these four benefits that implementing microsegmentation delivers:
Intellectual Property - Big Pharma companies frequently have R&D facilities and manufacturing operations located in multiple countries. There is an understandable concern for protecting intellectual property, both with regard to the medicines themselves and the manufacturing processes. Microsegmentation protects companies against data theft by external hackers and also from insider threats.
Research and Development - R&D is a complicated process, with cross-collaboration constantly happening within and between organisations to create new medicines and innovate drug therapies. The potential for the introduction of malware and theft of IP by insiders is huge. Microsegmentation creates communities of interest, ensuring that stakeholders only have access to data they have a right to see.
Supply Chain - Big Pharma engages with various partners, providers, suppliers, and vendors via complicated supply chains. These external stakeholders often need access to company data. Through microsegmentation, organisations can establish security policies to ensure they are only allowed access to the data and systems they need.
Mergers and Acquisitions - Big Pharma organisations engage in mergers and acquisitions regularly. It is necessary to interact with and often integrate systems during the merger process. Microsegmentation can protect the native Big Pharma systems from unknown threats hidden within the acquired companies systems by only opening up the bare minimum needed for the successful merger and on-boarding of staff.
In addition to providing end-to-end security without compromising data sharing and connectivity, microsegmentation also contributes to cost containment and cost reduction. Microsegmentation dramatically minimises the impact and costs of an attack – in terms of money, downtime, and reputation – regardless of internal or external origin. Deploying VLANs, firewalls, and IPsec tunnels are all expensive options to put in place and maintain. Microsegmentation is simple to implement and requires less staff to operate, allowing critical IT resources to work on other activities.
Conclusion
Data sources will continue to multiply for Big Pharma, as will the need for data sharing and connectivity. Through microsegmentation, Big Pharma can ensure data security across people, organisations, supply chains, and countries, creating an environment where innovation can flourish. Contact Renaissance to find out how the Unisys microsegmentation solutions can secure your business.

