Mongolia’s Health Cybersecurity at a Crossroads as Digital Care Expands Faster Than Defences | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Mongolia’s rapid shift toward digital healthcare is creating new opportunities for better services, faster information exchange and more efficient management, but it is also exposing hospitals and health agencies to growing cyber risks. The World Bank’s Cybersecurity Maturity Review of the Health Sector in Mongolia rates the sector 2 out of 5, placing it in the “formative” stage of cybersecurity maturity. While Mongolia has established important laws and national cybersecurity institutions, the assessment shows that implementation inside the health system remains uneven, making cybersecurity increasingly important for patient safety, data protection and the reliability of healthcare services.

Digital Health Is Growing Faster Than Cyber Protection

Mongolia has considerably strengthened its overall cybersecurity framework. Its position in the International Telecommunication Union’s Global Cybersecurity Index improved by 17 places between 2020 and 2024, reaching 103rd among 194 countries. The Cybersecurity Law adopted in 2021 established responsibilities for organizations operating critical information infrastructure, supported by national cybersecurity authorities and Cybersecurity Incident Response Teams.

The challenge is translating these national rules into everyday protection inside healthcare institutions. Mongolia has 216 designated critical information infrastructure organizations, and health organizations constitute the largest group. Yet hospitals face shortages of ICT personnel, limited cybersecurity expertise, inadequate budgets and difficulties replacing outdated hardware and software.

Cybersecurity compliance can also be expensive. The assessment says risk assessments can cost critical organizations around MNT30 million-MNT40 million ($8,350-$11,150), while audits can cost approximately MNT20 million ($5,600). As of December 2024, six critical hospitals had undergone risk assessments and nine had commissioned approved audits.

For policymakers, the message is clear: cybersecurity regulations must be supported by realistic financing. Requiring hospitals to undertake assessments, purchase licensed software and strengthen networks without providing adequate resources risks creating compliance requirements that weaker facilities cannot effectively implement.

A Cyberattack Can Become a Healthcare Crisis

Cybersecurity is no longer simply an IT issue. As hospitals increasingly depend on electronic records, connected systems and digital communications, an attack can interrupt healthcare delivery, expose confidential information and generate substantial recovery costs.

Mongolia has already experienced these risks. A November 2024 cyberattack against Intermed Hospital in Ulaanbaatar resulted in information relating to around 60,000 patients being released. The case illustrates how a digital breach can quickly become a patient-privacy and public-confidence problem.

The report also identifies weaknesses in incident preparedness. Health organizations depend heavily on national and public Cybersecurity Incident Response Teams, but sector-specific response arrangements have not been sufficiently developed and tested with health institutions. Only one critical infrastructure entity interviewed for the assessment had developed its own organizational Incident Response Action Plan.

For development partners supporting digital health, this creates an important policy lesson: investments in electronic health records, hospital information systems and other digital platforms should include financing for cybersecurity, workforce skills, risk assessments and incident-response capacity.

People, Software and Procurement Are Critical Weak Points

Technology alone will not solve the problem. The assessment identifies low cybersecurity awareness and poor cyber hygiene among healthcare workers. Training exists but is inconsistent, while participation and understanding are generally not systematically measured. Senior managers also receive little dedicated cybersecurity training.

Procurement presents another vulnerability. Health institutions do not consistently follow standardized cybersecurity criteria when purchasing software and ICT systems. Some facilities have used unlicensed software or operated with expired security products because of financial constraints.

This creates both opportunities and responsibilities for private-sector companies. Cybersecurity firms, software providers, cloud companies, training organizations and ICT vendors could find growing demand for secure platforms, licensed software, risk assessments, network protection and incident-response services.

However, stronger procurement standards could also mean greater scrutiny of suppliers. Vendors may increasingly need to demonstrate secure software development, regular security updates, vulnerability management and reliable incident-response arrangements.

Nine Recommendations Can Turn Compliance Into Resilience

The World Bank proposes nine recommendations grouped under four action paths. The first calls for stronger cybersecurity governance, including a larger supervisory role for the Ministry of Health, better information sharing with national cybersecurity authorities and stronger cybersecurity skills within health agencies.

The second focuses on understanding risks. Mongolia should map digital assets, stakeholders, technology suppliers and cross-sector dependencies and use this information to develop a sector-wide Cybersecurity Risk Management Strategy. Critical health organizations should then develop their own strategies based on regular risk assessments.

The third calls for practical protection. Mongolia needs a health-sector Incident Response Plan covering responsibilities, reporting procedures, outages and crisis communications. Individual institutions should develop aligned response plans and regularly test them through simulations. Authorities could monitor performance through indicators such as detection and response times.

The fourth concentrates on people. Senior managers need training on cybersecurity risks, budgets and business continuity; ICT professionals require greater technical skills; and frontline healthcare workers need practical knowledge about passwords, suspicious communications, patient-data protection and incident reporting.

For policymakers, international development institutions and private investors, the central lesson is straightforward. Mongolia has already created much of the legal foundation for cybersecurity. Its next challenge is financing implementation. Building skilled teams, purchasing secure and licensed technology, strengthening procurement, sharing threat information and repeatedly testing response systems will require sustained investment. If these measures accompany digital-health expansion, cybersecurity can become an enabler of Mongolia’s healthcare modernization rather than a growing vulnerability.

——————————————————-


Click Here For The Original Source.