Privacy-Preserving Cyber Threat Intelligence Sharing in Healthcare: Automated Anonymisation Under EU Regulations

Authors

  • Ilkka Tikanmäki Laurea University of Applied Scienses https://orcid.org/0000-0001-8950-5221
  • Lillebi Seistola Laurea University of Applied Sciences
  • Harri Silvola Laurea University of Applied Sciences
  • Pihla Parviainen

DOI:

https://doi.org/10.34190/eccws.25.1.4724

Keywords:

Cyber Threat Intelligence, Healthcare Cybersecurity, Data Anonymisation, EU Cyber Resilience Act, Privacy and Data Utility, NIS2

Abstract

Healthcare organisations face increasing cyber threats, making cyber threat intelligence (CTI) sharing an essential component of resilience. CTI sharing from hospitals often contains highly sensitive information such as patient identifiers, internal domains or IP addresses that can lead to re-identification if shared without proper protection. When this information is shared without protection, it can allow for re-identification or system mapping, exposing healthcare organisations to additional cyber and privacy risks. Under the emerging EU Cyber Resilience Act, ensuring secure and privacy-preserving cyber threat intelligence exchange becomes critical, requiring tools and processes that safeguard personal and organisational data while maintaining the analytical utility needed for threat detection. This study provides a theoretical framework for evaluating automated anonymisation in the sharing of healthcare cyber threat intelligence (CTI). It explains how to utilise tools such as ARX and DAT to execute privacy-preserving CTI exchange that is compliant with the EU Resilience Act (CRA) and the NIS2 Directive. The framework establishes evaluation criteria that balance anonymisation risk and analytical utility using synthetic CTI data (such as MISP feeds). The evaluation is intended to evaluate the efficiency of anonymisation by using re-identification risk metrics and retained CTI utility (such as Indicator of Compromise, IOC correlation). The model proposed follows European privacy and resilience rules and establishes the foundation for practical and compliant sharing of CTI in healthcare ecosystems.

Author Biographies

Ilkka Tikanmäki, Laurea University of Applied Scienses

MBA (Information Systems) Ilkka Tikanmäki is a Project Specialist in Business, Data Processing and Service Sector Unit at Laurea University of Applied Sciences and a doctoral student of Operational Art and Tactics at the Finnish Defence University. https://orcid.org/0000- 0001-8950-5221

Lillebi Seistola, Harri Silvola and Pihla Parviainen are students in the bachelor’s degree Programme at Laurea University of Applied Sciences in the Degree Programme in Business Information Technology, Cybersecurity.

Lillebi Seistola, Laurea University of Applied Sciences

MBA (Information Systems) Ilkka Tikanmäki is a Project Specialist in Business, Data Processing and Service Sector Unit at Laurea University of Applied Sciences and a doctoral student of Operational Art and Tactics at the Finnish Defence University. https://orcid.org/0000- 0001-8950-5221

Lillebi Seistola, Harri Silvola and Pihla Parviainen are students in the bachelor’s degree Programme at Laurea University of Applied Sciences in the Degree Programme in Business Information Technology, Cybersecurity.

Downloads

Published

2026-06-15