When US Airways Flight 1549 took off from New York’s LaGuardia airport on January 15, 2009, neither the flight crew nor the 155 passengers were prepared for a flock of birds to strike the aircraft, causing lost thrust in both engines. Captain Chesley “Sully” Sullenberger and First Officer Jeffrey Skiles had only minutes to respond to the sudden and dramatic change in circumstances. With no time to return safely to an airport, they landed the Airbus A320 on the Hudson River, saving all staff and the 155 passengers. Today, people refer to this event as the Miracle on the Hudson.
While a world of difference exists between landing an aircraft on the Hudson River and responding to a cyber attack in a healthcare organization, they share a fundamental principle. The initial event may be difficult to prevent, but they can manage the aftermath with training, experience, situational awareness, communication, leadership, and the ability to recognize that the circumstances had fundamentally changed.
When expected options no longer help, healthcare cybersecurity leaders need to be prepared to adapt, especially when the environment changes faster than the playbook.
A Plan on Paper Isn’t PreparednessA Plan on Paper Isn’t Preparedness
Compliance requires that every healthcare organization create and implement an incident response (IR) plan based on the risks and threats defined in the risk analysis. This IR plan is the basis for the organization’s playbooks that define how to detect, investigate, respond, and recover from incidents.
Realistically, having a plan and being prepared to execute it under pressure are very different. Returning to Flight 1549, the crew first seriously considered emergency procedures before the engines lost thrust. Training throughout their careers helped them stay calm and take action in the moment.
Healthcare organizations need to think about cyber resilience the same way. Incident response cannot be a document updated annually for compliance. Disaster recovery cannot be a collection of recovery objectives and procedures that have never been meaningfully tested. Business continuity cannot begin during the crisis.
These capabilities need to become organizational muscle memory.
- Tabletop exercises.
- Technical recovery testing.
- Executive simulations.
- Clinical downtime exercises.
- Communication drills.
- Backup restoration.
- Third-party outage scenarios.
- Testing critical dependencies.
- Testing what happens when identity services are unavailable or normal communication channels cannot be trusted.
- Deliberately testing scenarios where the expected answer isn’t available.
Occasionally, exercises should be uncomfortable because their purpose is to discover where a plan fails to work while consequences remain hypothetical. Through these activities, the document becomes a capability, and the capability becomes a culture.
Preparation teaches security teams to understand choices so that they can respond faster when something unexpected happens.
Design for the Moment a Control Fails
When the environment moves faster than the playbook, adaptability becomes the critical component of the security plan. For example, a recent discussion with Shawn Anderson, Cybersecurity Director at Intermountain Health, during a Fortified Health Security webinar, covered several key challenges that healthcare organizations face:
- Attackers entering systems through successful social engineering.
- Malicious actors leveraging third-party vendors as the attack vector.
- Threat actors exploiting a technical vulnerability before the organization can apply a security patch.
While these are three different doors into the environment, the objectives after gaining a foothold are remarkably similar:
- Move throughout the systems and networks to identify critical assets and sensitive data.
- Escalate privileges to gain more access within the environment to engage in further reconnaissance or exfiltrate data.
- Gain remote control over devices, databases, and other assets to establish permanence.
An organization’s architecture can fundamentally change the outcome. For examples, an Active Director isolation model breaks the privilege-escalation pathways by:
- Separating administrative tiers.
- Reducing excessive privileges.
- Protecting privileged credentials.
- Preventing lower-trust environments from controlling higher trust environments.
- Protecting sensitive administrative functions.
When organizations assume that attackers will eventually open one door, they design the building so that the door fails to provide access to every room.
This blast-radius reduction is the cyber resilience through adaptability that protects healthcare environments. Sometimes stronger resilience introduces friction or administrators need to work differently. Sometimes segmentation and isolation makes environments less convenient.
The right cybersecurity decision might require users and organizations to step outside the architecture they know, but at least, the plane can land safely.
Leadership Makes a Culture of Cyber Resilience Possible
Leadership drives these cyber resilience initiatives. Cybersecurity is everyone’s responsibility, but leadership must model the culture. A healthy culture of cybersecurity includes:
- Boards and executives establishing expectations and provide resources.
- Security leaders translating cyber risk into organizational risk.
- Managers reinforcing behaviors.
- The workforce putting the behaviors into practice.
Leadership also determines whether an organization is willing to accept short-term inconvenience in exchange for meaningful risk reduction by answering questions like:
- Will executives participate seriously in tabletop exercises?
- Will the organization support difficult architectural changes?
- Will leaders address known risks even when remediation is uncomfortable?
- Will employees feel empowered to stop and say, “Something doesn’t seem right”?
- Will an administrator feel supported saying, “I don’t actually need this much access”?
- Will an incident-response team be rewarded for finding weaknesses during an exercise rather than encouraged to hide them?
A culture is more than a policy. It is a set of business norms with someone who owns the responsibility for continuously moving the cybersecurity program forward by evaluating it and asking:
- Where are we today?
- Where do we need to be?
- What are our greatest risks?
- Which gaps have we closed?
- Are our people prepared?
- Do we understand our partners?
- Can we contain an incident?
- Can we recover?
- Can we demonstrate that our program is more mature today than it was a year ago?
Cybersecurity maturity doesn’t happen accidentally. It requires leadership, expertise, measurement, accountability, and continuous involvement.
Final Thought
Not every healthcare organization has every capability internally. Models such as virtual CISO leadership and Expertise on Demand can help provide experienced healthcare cybersecurity leadership and specialized expertise where needed.
But regardless of how that expertise is sourced, someone has to keep asking, “Are we actually getting better?”