CISO Brief: A Look Back at Healthcare Cybersecurity in 2025, A Year Defined by Disruption

As 2025 comes to a close, it’s impossible not to view the year through a wide-angle lens. Healthcare cybersecurity in 2025 did not follow a clean, predictable arc. Instead, it delivered a series of sharp turns, unexpected pivots, and both hard-earned wins and hard-learned lessons. If 2024 felt volatile, 2025 reaffirmed that volatility is now the default operating […]
Inside a Healthcare Ransomware Battle: How Preparation Saved Patients

With 25 years in cybersecurity, including experience at the Department of Defense and National Security Agency, Phil Alexander has seen the full spectrum of cyber threats. Since founding his consultancy and working extensively with healthcare organizations, he’s gained unique insights into the industry’s specific vulnerabilities and the most effective strategies to address them. His experience […]
When Cyber Threats Hit Rural Hospitals: Lessons from the Front Lines

A savvy CEO leads a rural hospital through a cybersecurity crisis Cybersecurity attacks on rural hospitals are no longer a question of “if,” but “when.” For Mount Desert Island Hospital in Bar Harbor, Maine, that moment came during Chrissi Maguire’s tenure as CEO. A longtime financial and operational leader turned hospital chief, Maguire had to […]
CISO Brief: October 2025 Cybersecurity Threat Recap & Insight

October delivered two wake-up calls for healthcare cybersecurity leaders: a critical WSUS remote-code execution flaw that exposed update-chain integrity and a major AWS US-EAST-1 outage that disrupted global services for hours. Together, they underscored a single truth—even trusted infrastructure and cloud providers can become a single point of failure. This month’s CISO Brief for October […]
How to Make Third-Party Risk Manageable

A new Fortified webinar, “Make Third-Party Risk Manageable,” will help you take steps to protect your organization from the security threats posed by vendors. This informative webinar is hosted by Melissa Adams, Fortified’s Director of Third-Party Risk Management, and Jared Michaels, Principal Solutions Architect. Some of the largest healthcare breaches in recent years have involved […]
Lessons from the Front Lines: The Perspective of a Cyberattack from the Nursing Floor

A longtime nurse has seen the impact of cyberattacks up close and personal. Don Neal is a Certified Registered Nurse Anesthetist (CRNA) with nearly 50 years of healthcare experience. As a self-described “old-timer,” he experienced the shift to healthcare technology firsthand, from using electronic charting to switching to automated blood pressure machines. While he says […]
Lessons From the Front Lines: How One Hospital Survived 30 Days Offline

For healthcare leaders, there’s no good time for a cyberattack, but they’re especially aggravating when they hit while you’re on vacation. That’s what happened to Katrina Brown, chief nursing officer of Providence Hospital in Mobile, Alabama, when the EMR system and other software went down while she was in Hawaii. The Response Strategy: Taking Quick […]
Lessons from the Front Lines: Learning from the SolarWinds Attack

Two security engineers take us into the trenches—and talk about what happened afterward. James Edgell and Dan Colon work in IT security for Lawrence General Hospital in Lawrence, MA. Normally they spend their days scanning systems, working on cybersecurity awareness newsletters, coordinating with Fortified on business impact analyses, and other routine tasks. However, it wasn’t […]
5 Ways to Strengthen the Cyber Conversation with CFOs

Cybersecurity isn’t just a technical conversation anymore; it’s a financial one. In healthcare, the cost of cyber risk is measured not only in terms of breached records or downtime, but also in canceled procedures, delayed reimbursements, and long-term reputational damage. When patient safety and solvency are both at stake, CISOs and CFOs must operate as […]
Lessons from the Frontlines: Navigating a Cybersecurity Crisis During Healthcare Integration

A healthcare CISO faced an unusual situation in an already challenging time. Louis Wright, CISO and Director of IT Security for USA Health in Mobile, Alabama, oversees cybersecurity for a healthcare network that includes major hospitals and more than 70 clinics spread across Mississippi and Alabama, including some that were part of the recently acquired […]