When AI Agents Start “Moving Like Attackers”

A real-world wake-up call from a SOC lab experiment Executive Summary To safely evaluate autonomous SOC investigation agents, we built a controlled AWS-based lab environment that closely resembles a modern security operations ecosystem. We wanted to test how aggressive an AI agent would be when trying to complete a task. Would it fail at the […]
What It Means to Be Cyber Smart

Now in its 18th year, National Cybersecurity Awareness Month (NCSAM) continues to raise awareness about the importance of cybersecurity. Led by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cyber Security Alliance (NCSA), National Cybersecurity Awareness Month is a collaborative effort between government and industry to ensure everyone in the Nation has the […]
Understanding SIEM, MDR, and XDR in Healthcare

New cybersecurity innovations continue to fill the market each year as organizations attempt to stay ahead of threat actors. Sifting through all the options to find the solutions that best fit your healthcare organization’s needs can be a confusing and time-consuming challenge. Compounding the issue are the increasing pressures from cyber insurance providers and governing […]
Top Cybersecurity Threats Facing Hospitals and How to Reduce your Risk

Every single facility that treats patients and gathers patient data is a target for a cyberattack, and this risk is growing. In just the first six months of 2023, more than 300 data breaches were reported to the U.S. Department of Health and Human Services Office of Civil Rights (OCR), an increase of more than […]
Threat Hunting in Healthcare: What It Is & Why It Matters

Incident response is a vital part of a strong cybersecurity program. However, responding to cybersecurity threats and attacks is only part of the equation. Healthcare organizations need to be proactive in their security solutions, spotting threats before they lead to data loss. This is where threat hunting comes in. What is threat hunting? Threat hunting […]
Third-Party Risk Management in Healthcare: The “Must-Haves”

The rising costs associated with cybersecurity breaches, like the Change Healthcare incident and CrowdStrike breach, underscore the severe consequences and need for third-party risk management in healthcare. These incidents serve as urgent reminders of how much damage can result from unmitigated vulnerabilities. Healthcare organizations, which rely heavily on third-party vendors and external partners, must actively […]
Third-Party Risk Management: A Guide to More Secure Partnerships

The use of third-party vendors has become essential for delivering comprehensive patient care, streamlining operations, and enhancing service quality in healthcare. However, these relationships present complex data security challenges for healthcare organizations. This article will explore the complexities of managing third-party risk in healthcare, how threat actors exploit vendor vulnerabilities, and provide best practices for […]
The Risk and Rewards of Quantum Computing in Healthcare

Healthcare organizations depend on strong cryptographic technologies to secure data. As quantum technologies rapidly advance, concerns are growing about the threats quantum computing poses to widely used encryption methods. If you’re concerned about—or even unaware of— the issues surrounding quantum computing, this post will explore the potential threats to your healthcare organization and the strategies […]
The Evolution of TPRM in Healthcare: From Spreadsheets to Strategic Change

Third-party risk management (TPRM) is no longer a nice-to-have in healthcare; it’s a strategic necessity. Healthcare organizations are under growing pressure to manage third-party risk more effectively. High-profile incidents like the Change Healthcare breach have shown just how deep the ripple effects of a vendor issue can run; impacting operations, financial systems, and patient care […]
The Evolution and Impact of NIST CSF 2.0

NIST, or the U.S. National Institute of Standards and Technology, is at the forefront of the evolving realm of cybersecurity. Their goal is to provide recommendations that can be used as guideposts for industry best practices and more efficient ways of working However, cybersecurity is notoriously difficult to build standards around because the threat landscape […]