Related Experiment Video
Updated: Jan 10, 2026

Author Spotlight: Improving Radiation Therapy Access with Radiation Planning Assistant
Published on: October 6, 2023
ESTRO framework for radiation oncology departments to mitigate against cyberattacks
Samuel Peters1, Anita O'Donovan2, Marcello Bellini3
1Department of Radiation Oncology, Kantonsspital St. Gallen, HOCH Health Ostschweiz, St. Gallen, Switzerland.
Introduction:
The healthcare sector, particularly radiation oncology departments, is facing an increasing threat of cyberattacks that compromise patient data, disrupt clinical workflows and endanger patient safety. These attacks highlight a critical lack of preparedness and the need for a structured approach to cybersecurity resilience. While other industries have comprehensive mitigation measures in place, specific guidance for radiotherapy is lacking. This paper aims to present practical and comprehensive recommendations for mitigating cyberattacks and minimising their direct impact on patient care in radiation therapy.
Methodology:
Preparing this report involved three phases. First, the authors adapted existing international frameworks, such as the NIST CSF, to the specific needs of radiation oncology, resulting in a six-step framework: Preparation, Prevention, Detection, Response, Recovery and Debriefing and Continuous Improvement. Secondly, a systematic literature review was conducted using keywords related to cyberattacks in healthcare and radiotherapy. Third, the information extracted from the literature was aggregated and summarised into specific action measures, with final consensus being reached by the entire group based on their collective expertise.
Results:
The literature review resulted in 133 relevant articles, which were then aggregated and formulated into 190 specific action measures in total. These were assigned to the 6 steps (43 for preparation, 28 for prevention, 14 for detection, 50 for response, 22 for recovery, 24 for debriefing and continuous improvement, and nine additional steps), enabling departments to be guided through the entire lifecycle of a cyberattack. Step 1: Preparation: This proactive phase of planning for potential cyberattacks involves thorough risk assessment and identification of all systems, tools and processes. A key component is the development of a detailed business continuity plan (BCP), which must include procedures for the offline treatment or referral of patients, communication and patient prioritisation. The plan should also define the roles and responsibilities of an interdisciplinary incident response team. Step 2 - Prevention: This step focuses on implementing proactive security measures to prevent attacks. This includes user training to raise awareness, regular system updates, and general protective measures. Step 3 - Detection: This step involves identifying suspicious activities within systems and networks. It emphasises the use of security tools for real-time monitoring and the establishment of clear communication processes to enable the prompt reporting and response to potential threats. Step 4: Respond: This is the central phase of a cyberattack, focusing on executing the BCP to ensure continuity of patient treatment as quickly as possible. This includes isolating affected systems and implementing continuity of treatment procedures, which may involve using analogue workflows or transferring patients to other hospitals. Step 5: Recovery: This step begins in parallel with step 4 and involves restoring data and systems from backups or rebuilding them from scratch. It is particularly important to carefully check the restoration and merging of data to avoid incorrect documentation or erroneous treatment. Step 6: Debriefing and continuous improvement: This post-incident step ensures that lessons learned are fed back into the preparation process. It involves a thorough analysis of what went right and wrong, leading to the adaptation of the BCP.
Conclusion:
This framework aims to help departments create their own local protocols. Implementation of the framework will vary significantly between departments and preparing for an attack should be a high priority. Preparedness is not the sole responsibility of the RO staff or of the IT department; it requires comprehensive cooperation between IT specialists, clinical staff and system providers. Since the next cyberattack is not a question of 'if' but 'when,' healthcare providers must have a protocol in place that can be quickly implemented to prioritise patient well-being and safety.
More Related Videos
08:25Radiation Planning Assistant - A Streamlined, Fully Automated Radiotherapy Treatment Planning System
Published on: April 11, 2018
06:20Irradiator Commissioning and Dosimetry for Assessment of LQ α and β Parameters, Radiation Dosing Schema, and in vivo Dose Deposition
Published on: March 11, 2021
Related Concept Videos
Radiation: Applications
The average...
Absorption of Radiation
Health Information Technology and Healthcare Information System
Health Information Technology, commonly called HIT, integrates advanced information systems and technology in healthcare settings. Its primary functions include:
Integrated Healthcare System
Biological Effects of Radiation
Ethical Standards I
The Code of Ethics provisions outline the nurse's duty to the patient, the healthcare team, the profession, and society. The Code's fundamental principles include advocacy,...