Since the first Geneva Convention was signed, medical workers have been granted special status and hospitals have been recognized as neutral territory. In the future, we will probably need some kind of online counterpart; healthcare companies suffer from cyberattacks no less than other targets do. The big difference is that in the case of public health companies, what’s at stake is not only business, but also human health. However, even if such a convention comes into force, it will not rid medical companies of the necessity of providing full-fledged protection against cyberthreats. Quite often, malefactors launch “mass destruction” attacks, and as much as they would like to affect the way the victims are chosen, altering the selection isn’t possible. For example, take a couple of recent epidemics , WannaCry and ExPetr. At first glance, both seemed to be encrypting attacks, and both affected a vast number of healthcare enterprises. The first, the notorious WannaCry, launched on May ...