MétaCan
Menu
Back to cohort
Record W4416589253 · doi:10.1016/j.radonc.2025.111305

ESTRO framework for radiation oncology departments to mitigate against cyberattacks

2025· article· en· W4416589253 on OpenAlexaff
Samuel Peters, Anita O’Donovan, Amanda Caissie, Mary P. Coffey, Ali Dabach, Geoff P. Delaney, Gert Frenken, Brian Liszewski, Philippe Maignon, Eric Messens, Sophie Perryck, Baoshe Zhang, P.M.J. Reijnders-Thijssen

Bibliographic record

VenueRadiotherapy and Oncology · 2025
Typearticle
Languageen
FieldComputer Science
TopicInformation and Cyber Security
Canadian institutionsCancer Care OntarioDalhousie UniversityTrinity College
Fundersnot available
KeywordsPreparednessRadiation oncologyHealth careProtocol (science)Data breach

Abstract

fetched live from OpenAlex

INTRODUCTION: The healthcare sector, particularly radiation oncology departments, is facing an increasing threat of cyberattacks that compromise patient data, disrupt clinical workflows and endanger patient safety. These attacks highlight a critical lack of preparedness and the need for a structured approach to cybersecurity resilience. While other industries have comprehensive mitigation measures in place, specific guidance for radiotherapy is lacking. This paper aims to present practical and comprehensive recommendations for mitigating cyberattacks and minimising their direct impact on patient care in radiation therapy. METHODOLOGY: Preparing this report involved three phases. First, the authors adapted existing international frameworks, such as the NIST CSF, to the specific needs of radiation oncology, resulting in a six-step framework: Preparation, Prevention, Detection, Response, Recovery and Debriefing and Continuous Improvement. Secondly, a systematic literature review was conducted using keywords related to cyberattacks in healthcare and radiotherapy. Third, the information extracted from the literature was aggregated and summarised into specific action measures, with final consensus being reached by the entire group based on their collective expertise. RESULTS: The literature review resulted in 133 relevant articles, which were then aggregated and formulated into 190 specific action measures in total. These were assigned to the 6 steps (43 for preparation, 28 for prevention, 14 for detection, 50 for response, 22 for recovery, 24 for debriefing and continuous improvement, and nine additional steps), enabling departments to be guided through the entire lifecycle of a cyberattack. Step 1: Preparation: This proactive phase of planning for potential cyberattacks involves thorough risk assessment and identification of all systems, tools and processes. A key component is the development of a detailed business continuity plan (BCP), which must include procedures for the offline treatment or referral of patients, communication and patient prioritisation. The plan should also define the roles and responsibilities of an interdisciplinary incident response team. Step 2 - Prevention: This step focuses on implementing proactive security measures to prevent attacks. This includes user training to raise awareness, regular system updates, and general protective measures. Step 3 - Detection: This step involves identifying suspicious activities within systems and networks. It emphasises the use of security tools for real-time monitoring and the establishment of clear communication processes to enable the prompt reporting and response to potential threats. Step 4: Respond: This is the central phase of a cyberattack, focusing on executing the BCP to ensure continuity of patient treatment as quickly as possible. This includes isolating affected systems and implementing continuity of treatment procedures, which may involve using analogue workflows or transferring patients to other hospitals. Step 5: Recovery: This step begins in parallel with step 4 and involves restoring data and systems from backups or rebuilding them from scratch. It is particularly important to carefully check the restoration and merging of data to avoid incorrect documentation or erroneous treatment. Step 6: Debriefing and continuous improvement: This post-incident step ensures that lessons learned are fed back into the preparation process. It involves a thorough analysis of what went right and wrong, leading to the adaptation of the BCP. CONCLUSION: This framework aims to help departments create their own local protocols. Implementation of the framework will vary significantly between departments and preparing for an attack should be a high priority. Preparedness is not the sole responsibility of the RO staff or of the IT department; it requires comprehensive cooperation between IT specialists, clinical staff and system providers. Since the next cyberattack is not a question of 'if' but 'when,' healthcare providers must have a protocol in place that can be quickly implemented to prioritise patient well-being and safety.

Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.

How this classification was reachedexpand

Full frame machine prediction

Teacher imitation

Not calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.

metaresearch head score (Codex)0.003
metaresearch head score (Gemma)0.006
Version: metacan-v3-hybrid-931329e0061cValidation status: machine_predicted_unvalidated
Candidate categoriesnone
Consensus categoriesnone
DomainCandidate signal: none · Consensus signal: none
Study designCandidate signal: Not applicable · Consensus signal: Not applicable
GenreCandidate signal: Methods · Consensus signal: Methods
Teacher disagreement score0.025
Threshold uncertainty score0.085

Distilled classifier scores by category (both heads)

CategoryCodexGemma
Metaresearch0.0030.006
Meta-epidemiology (narrow)0.0010.001
Meta-epidemiology (broad)0.0000.001
Bibliometrics0.0010.000
Science and technology studies0.0010.001
Scholarly communication0.0030.003
Open science0.0030.005
Research integrity0.0010.002
Insufficient payload (model declined to judge)0.0250.010

Machine scores (provisional)

The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.

Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.

Opus teacher head0.012
GPT teacher head0.337
Teacher spread0.325 · how far apart the two teachers sit on this one work
Validation statusscore_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from it

Classification

machine, unvalidated

Machine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.

The models applied no category: nothing in the taxonomy fit this work.
Study designNot applicable
Domainnot available
GenreMethods

How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".

Quick stats

Citations0
Published2025
Admission routes1
Has abstractno

Explore more

Same venueRadiotherapy and OncologySame topicInformation and Cyber SecurityFrench-language works237,207