Blog

CISO Brief September 2026: Cybersecurity Threat Recap & Key Insights

Imagine a whiteboard covered with thousands of colored sticky notes, each one a risk to delivering services. Each one a task that needs to be completed to help keep patients safe.

Now, like the sticky note, most healthcare cyber programs aren’t designed to handle the explosion of to-dos from vulnerabilities discovered in 2026.

With CVEs released through August up 84% YoY, putting it ahead already of the total number released in 2025, teams are prioritizing ruthlessly and holding more risk open for longer as they fight to keep up. The 2026 Mid-Year Horizon Report reported that the overall risk remediation rate dropped to 6.4%, down from 23.3% year over year in Q1, while the average healthcare organization saw a 60% increase in critical and high-risk findings.

Healthcare Impact

Recent conversations within the Fortified ecosystem confirmed these realities. Budget and staffing constraints were cited most often, with threat and vulnerability volume close behind. Members also voiced challenges with regulatory and compliance expectations, operational resilience and downtime risk, and board or executive pressure.

Those pressures connect to tangible constraints: technical sprawl, vendor spread, competing priorities, and the challenge of translating risk into decisions executives can act upon.

Resilience now depends more on building a program that turns the right risks into accountable, prioritized, measurable actions.

Leadership Recommendations

How to Attack the Big Board of Sticky Notes

Separate strategic decisions from operational work

Governance committees should not become work queues. Their value comes from deciding what the organization will fund, defer, consolidate, escalate, mitigate, or formally accept.

Keep those decision-making responsibilities clearly defined and separate from day-to-day operational work. Focus the committee on results and decisions, not execution.

Make ownership explicit before findings pile up

Unclear ownership is one of the biggest barriers to operationalizing risk management. That problem becomes more costly when findings cross clinical, IT, security, privacy, compliance, finance, vendor, and biomedical domains.

Ensure every high-priority risk has an owner, a decision path, a target outcome, and a defined escalation route.

Use AI to strengthen governance, not create another silo

Artificial intelligence can help teams analyze risk, surface trends, and support faster decisions across security, privacy, compliance, and third-party risk. Organizations should build AI into existing governance processes and vendor oversight now, rather than waiting for a new budget cycle, annual plan, or incident to force the issue.

Prove risk reduction with trends, not activity volume

More alerts, reports, dashboards, and findings do not automatically create cybersecurity resilience. It’s what teams do with those cyber signals that tells the story and garners board support.

Leaders should track whether priority risks are being reduced, whether critical remediation is closing faster, whether accepted risks are reviewed, and whether downtime exposure is shrinking. Focusing on the right areas will help protect patients, data, and healthcare service delivery.

Essential Healthcare Leadership Cybersecurity Questions:

  • Which risks require executive choice, and which simply require accountable execution?
  • Who owns the risk, who owns the work, and who has authority to remove blockers?
  • Do we know where AI is being used, what data it touches, who governs it, and when a human must remain in the loop?
  • Are we measuring risk reduction, or are we only measuring security activity?

Executive Takeaways:

  • Separate strategic decisions from operational work
  • Make ownership explicit before findings pile up
  • Treat AI as a governance accelerator, not a separate silo
  • Prove risk reduction with trends, not activity volume

Threats to Monitor

Peer Pulse: Strategic Planning, Governance, and AI Risk with vCISOs Mike Gregory and Troy Cruzen

Russell Teague: There’s a lot competing for attention right now. When healthcare leaders sit down to plan for the year ahead, what should they be thinking about from a cyber risk perspective?

Mike Gregory: Strategic planning must focus the organization on mitigation. Healthcare teams deal with risk reduction, compliance, board pressure, budget limits, operational resilience, and vulnerability volume all at the same time. A strategic plan must be built around a clear understanding of how the organization structures mitigation, prioritizes what matters most, and decides what to fund, defer, consolidate, or escalate.

Russell Teague: What role should governance committees play in that process?

Mike Gregory: The most effective models I have seen separate the workgroup from the governance body. The workgroup handles detailed analysis, remediation plans, KRIs, KPIs, and reporting.

The governance body uses that information to make strategic decisions, assign accountability, and determine when a risk needs to move higher because of financial, patient-care, operational, cyber, or strategic impact.

Russell Teague: What’s the distinction between strategic work and tactical work? Why does that matter?

Troy Cruzen: A firewall rule review is tactical work. It addresses a specific task or control. Strategic planning is different. It sets priorities, determines where resources should go, and defines which risks the organization is willing to address, defer, or accept.

AI is a good example of why that distinction matters. The strategic question is not whether a team should use a specific AI tool. It is how AI changes the organization’s risk, governance, investment, and oversight priorities.

Russell Teague: What AI-related risk should healthcare leaders pay closest attention to right now?

Mike Gregory: Many AI committees begin with a vision for what they want to accomplish, such as improving patient health, supporting research, or creating useful internal models. That is important, but it can leave blind spots.

Leaders also need to understand how AI may already be entering the environment through vendors, user behavior, unsanctioned tools, and work-related data being fed into personal AI systems. The governance question is not only what AI can do for the organization. It is also what exposure AI may already be creating.

Russell Teague: How should leaders think about AI outputs and clinical or operational decision-making?

Mike Gregory: The danger is for humans to disengage. Using AI should not mean accepting outputs without review. If anything, leaders need to be more engaged in understanding what the model is producing, how it is producing it, what data is involved, and where human oversight is still required. That becomes especially important as healthcare organizations evaluate predictive tools, vendor models, clinical support systems, and internally developed workflows.

Closing Perspective

Every risk deserves attention. Not every risk deserves action today.

The challenge for healthcare leaders is determining which decisions will have the greatest impact on resilience, patient safety, and operational continuity.

In a year defined by cyber volume, prioritization may be the most important security control of all.

Share

Related Articles

Healthcare Security Tool Sprawl: Why More Means Less Protection

Beyond the Policy: 3 Key Components of AI Governance in Healthcare

CISO Brief August 2026: Cybersecurity Threat Recap & Key Insights