Blog

The Numbers Are In, and We Have Work to Do

According to the 2026 Data Breach Investigations Report, the Healthcare industry experiences the sixth highest number of security incidents in 2025. Additionally, the Federal Bureau of Investigation (FBI) Annual Internet Crime Report noted that Healthcare and Public Health organizations reported 460 ransomware events and 182 data breaches in 2025, making them the industry experiencing the most incidents overall.

For cybersecurity professionals who have dedicated significant portions of our careers to protecting healthcare, these numbers are difficult to hear. While this sounds pessimistic, I believe we can still change the trajectory. Modern healthcare organizations have access to better technology, threat intelligence, collaboration tools, and visibility into their environments. All of these upgrades enable healthcare security teams an increasingly sophisticated understanding of how their adversaries operate.

Unfortunately, these new tools fail to provide the one thing defenders need the most. Time.

Our Window Is Getting Smaller

Attackers have reduced the time from vulnerability disclosure to exploitation. According to a recent research published by the Institute of Electrical and Electronics Engineers (IEEE), the Time-To-Exploit (TTE) has contract toed only 3-5 days. Meanwhile, the Trellix CyberThreat Report, the TTE dropped from 23.2 days in 20205 to 1.3 days in the first quarter of 2026. [1] 

As the window between disclosure and exploitation continues to compress, automation and artificial intelligence are accelerating capabilities that historically required considerably more human effort. Healthcare environments often combine state-of-the-art platforms with legacy technologies approaching end of service (EOS) or devices beyond end-of-life (EOL). A single organization may be balancing hundreds of applications with interconnected dependencies, clinical workflows, medical devices, maintenance windows, vendor requirements, authentication services, and infrastructure constraints.

Many healthcare organizations need to review their familiar, traditional vulnerability management processes that consist of the following cycle:

  • Identifying a vulnerability as soon as possible, becoming more challenging as healthcare organizations manage more Internet of Medical Things (IoMT) devices.
  • Testing patches, complicated by manufacturers not always supplying updates quickly or in compliance with manufacturer revalidation requirements.
  • Following change control processes, which can become time-consuming if the organization lacks a clear approval process.
  • Deploying the update, which may pose a challenge as device availability is critical for patient care.

In healthcare, an unplanned outage isn’t always measured simply in lost productivity or revenue.

It may affect the delivery of patient care. Healthcare needs speed, but it also needs precision. The challenge becomes balancing the speed that the modern threat landscape requires against the cautious deployment required to protect healthcare operations and avoid unplanned downtime.

I felt that compared to the original, we needed to just create a bridge and if we were doing that, then having data to support wouldn’t hurt

Reduce the Blast Radius

While prevention always matters, resilience requires analyzing the amount of damage a failed control can actually cause. Healthcare organizations need more than speed. They need to ask and analyze the answers to questions like:

  • If an employee is successfully socially engineered, how much can that identity access? 
  • If a privileged credential is compromised, how far can the attacker move? 
  • If a vulnerability is exploited before we can patch it, can the attacker reach critical infrastructure? 
  • If a trusted third party is compromised, how far does that trust relationship extend? 
  • If multiple defenses fail, can we detect, contain, respond, recover, and continue delivering critical services?

These questions are not about accepting compromise or abandoning prevention. Their goal is to prevent one failure from becoming a failure across the entire environment.

Healthcare security professionals need to ensure that when attackers manage to enter through one door, they don’t gain unauthorized access to all systems, networks, applications, and services. Increasingly, resilience is an essential part of building a true culture of cybersecurity.

Making This November Count

While the healthcare industry may be losing many battles, we can change the trajectory by making this cybersecurity awareness month count through:

  • Educating our people.
  • Limiting unnecessary privilege.
  • Designing environments to contain compromise.
  • Continuously verifying our partners.
  • Practicing incident response, disaster recovery, and business continuity rather than simply documenting them.
  • Challenging assumptions that no longer fit the threat environment.
  • Insisting upon leadership that continuously moves our cybersecurity programs forward.

No one can predict every vulnerability attackers plan to exploit or every sensitive piece of data that will ultimately travel. However, security teams can prepare for what happens next:

  • Where one compromised credential doesn’t mean unrestricted access.
  • Where one exploited vulnerability doesn’t mean the entire network.
  • Where one compromised vendor doesn’t mean uncontrolled exposure.
  • Where one employee making one mistake doesn’t automatically become an organizational catastrophe.

Reducing the blast radius is about ensuring that a single failure at one layer never becomes a failure everywhere. Security teams don’t need perfect people, partners, and technology. They need to design cybersecurity programs that include:

  • Preparing people for incidents.
  • Building resilient architecture.
  • Working with trusted and continuously verified partners.
  • Practiced response and recovery.
  • Leadership willing to challenge yesterday’s assumptions when tomorrow’s threats demand something different.

Privacy may increasingly be an illusion, but preparedness, resilience, and progress are real.

Share

Related Articles

Legacy Medical Devices: Healthcare’s Persistent Security Challenge

Your Biggest Cybersecurity Risk Might Be Your Most Helpful Employee

BIAs: An Overlooked Keystone to your Cybersecurity Program