August 2025 CISO Brief: Policy, Funding, and the Path Forward 

How federal staffing cuts, government restructuring, and Medicaid policy shifts threaten the cybersecurity posture of our healthcare system.  In a recent set of Questions for the Record (QFRs), Senator Edward Markey highlighted growing vulnerabilities in the cybersecurity infrastructure supporting the U.S. healthcare system. These questions, submitted to the Senate HELP Committee, signal urgent concern over […]

April 2025 CISO Brief: Behind the Cyber Threat Headlines

Fortified’s Threat Services Team tracks the most pressing cyber threats targeting the healthcare sector each month. April’s activity surrounding PipeMagic ransomware, Oracle’s dual breach allegations, and the news regarding the DaVita ransomware attack illuminate a stark reality: the healthcare sector is under sustained siege from sophisticated threat actors intensifying their focus on healthcare’s legacy systems, […]

CISO Brief: AI Zero-Days & Holiday Threats; What Healthcare Must Prepare for Now 

CISO Brief with Russell Teague June 2025 recap

Over the past month, AI vulnerabilities, delayed breach disclosures, and geopolitical tensions have created new challenges for cybersecurity leaders in healthcare. In this CISO Brief for June 2025, we take a closer look at the month’s top threats and headline-making events – from the first known AI zero-day exposure in Microsoft 365 Copilot (“EchoLeak”) to […]

CISO Brief May 2026: Cybersecurity Threat Recap & Key Insights

Recent activity associated with ShinyHunters-branded extortion campaigns reinforces a critical shift in healthcare cybersecurity: attackers are increasingly targeting identity, SaaS platforms, and trusted third-party access paths rather than relying only on malware or traditional ransomware deployment. The FBI has previously warned that recent campaigns target Salesforce environments to steal data and extort victims, including activity […]

CISO Brief June 2026: Cybersecurity Threat Recap & Key Insights

Threat groups and nation-state actors attacking healthcare organizations continue to target the same pressure points: cloud access, exposed infrastructure, remote access, vulnerable perimeter systems, and trusted identities. That pattern matters. It tells healthcare cybersecurity teams where to focus their defenses, and gain a deeper understanding of the tactics threat groups use can help mitigate the […]

CISO Brief July 2026: Cybersecurity Threat Recap & Key Insights

Healthcare has always been prepared for cyber disruptions, but the playing field has changed drastically. Attackers can move faster, acquire capabilities more easily, and exploit numerous entry points into organizations. The emergence of ransomware-as-a-service has changed the game for cybercriminals. They no longer need to be tech geniuses; they can buy the tools they need […]

CISO Brief August 2026: Cybersecurity Threat Recap & Key Insights

Challenges surrounding Identity Access Management (IAM), Authentication, and Access Control are being uncovered at four times the rate of the previous year. Nearly two-thirds of these issues fall into the Critical or High category. Despite Multi-Factor Authentication (MFA) becoming standard practice for healthcare IT teams, healthcare’s complex network of Electronic Health Records (EHRs), third-party applications, […]