Cybersecurity leaders in health are confronting faster, more sophisticated threats while managing persistent gaps in recovery, staffing and governance. A recent report draws on survey data from 76 health sector CISOs and security executives across providers, pharmaceutical companies, medical device organisations and health IT organisations, collected in 2025–2026. The findings show phishing and social engineering remain the most frequently cited established risks, while AI-enabled attacks have become the leading emerging concern. Security priorities increasingly centre on identity, business continuity, cloud environments and third-party exposure as organisations seek to strengthen resilience without proportionate growth in teams and budgets.
AI Reshapes the Threat Landscape
Phishing and social engineering lead the established risk ranking, selected among the top three risks by 81% of respondents. Supply chain and third-party risk follows at 64%, with ransomware and malware at 60%. The survey links supply chain exposure to the health sector’s dense vendor ecosystem, where a breach affecting one supplier can reach multiple patient-facing platforms. Ransomware pressure is also changing, with newer extortion tactics combining encryption with direct threats to patients and attacks timed around critical care periods.
Must Read: Clinical Resilience Requires More Than Cybersecurity Tools
The emerging-threat picture places artificial intelligence at the forefront. AI-enabled attacks were selected among the top two emerging concerns by 80% of respondents, ahead of newer ransomware tactics and cloud or software-as-a-service compromise. Generative AI is being used to automate phishing, create deepfakes and accelerate exploitation, reducing the time available for human-led response. Security leaders also estimate that AI has roughly doubled the speed at which new attack variants emerge.
Defensive use of AI is developing alongside these threats. Current applications include alert triage and event correlation in security operations centres, automated analysis of threat intelligence, behavioural detection in endpoint platforms and phishing detection. Most security leaders are enabling AI features within existing tools rather than building bespoke systems. Identity and access management ranks as the leading priority for the next 12 to 24 months, followed by business continuity and disaster recovery and security for cloud and hybrid environments.
Governance and Workforce Capacity Remain Uneven
The security leadership role spans a wide operational portfolio, but organisational access remains limited. Security operations and incident response, threat intelligence, vulnerability management and cloud security sit within the responsibilities of most respondents. Medical device and Internet of Things security is owned by 62% of security leaders, yet only a small share of security staff is allocated to this function, creating a mismatch between accountability and operational capacity.
Reporting structures also keep cybersecurity closely tied to IT. Almost two-thirds of respondents report to a chief information officer or chief technology officer, while only 11% report directly to a chief executive or board. Board engagement remains uneven, with 44% briefing the board quarterly or more. Most organisations have a documented security strategy aligned with business objectives and a documented incident response plan, but budget and staffing remain continuing execution constraints.
Workforce data reinforces those limits. Forty percent of security programmes operate with 10 or fewer full-time equivalents, and most organisations expect headcount to remain flat or grow only modestly. Budget constraints are the most frequently cited workforce challenge, ahead of difficulties hiring skilled staff. External services therefore play a substantial role: managed detection and response or security operations centre services are used by 82% of organisations, while penetration testing is used by 79%. Spending remains concentrated on workforce, cloud software and outsourced services, with comparatively little allocated to training and awareness.
Recovery Capability Lags Behind Detection
Recovery stands out as the weakest area of cybersecurity maturity. While organisations have invested heavily in monitoring and detection, confidence in restoring operations after a significant incident is markedly lower. Only 22% of respondents rate their recovery capability at the two highest maturity levels, while 26% place it at the two lowest. Even among larger organisations, recovery averages only the middle level of the maturity scale.
This gap is particularly important because business continuity and disaster recovery ranks second among planned security initiatives for the next 12 to 24 months. System downtime is directly linked with patient harm, placing recovery beyond a purely technical function. A documented incident response plan is already present in 91% of organisations, but the frequency of table-top exercises varies widely. The findings therefore distinguish between having formal plans and possessing mature recovery capability.
Other resource gaps reinforce the resilience challenge. Medical device and Internet of Things security receives only 4% of security staff despite being a formal responsibility for many CISOs. Training and awareness also account for only a small share of spending even though phishing is the leading identified risk. Organisations are using multiple security frameworks, including NIST CSF, CIS Controls, ISO 27001 and HITRUST, but the maturity results show that broad framework adoption does not produce equal strength across operational areas. Recovery, staffing and practical capacity remain central weaknesses.
Health sector cybersecurity programmes are strengthening monitoring, adopting AI-enabled capabilities and maintaining investment, but significant gaps remain in recovery, workforce capacity and organisational access for security leaders. Phishing, supply chain exposure and ransomware continue to shape immediate risk, while AI is accelerating both offensive and defensive activity. Identity management, business continuity, cloud security and third-party oversight remain central priorities. The clearest operational weakness is recovery: formal plans and security frameworks are widespread, yet confidence in restoring services after major incidents remains comparatively low, alongside persistent resource gaps in training and medical device security.
Source: Health-ISAC
Image Credit: iStock
References:
Health-ISAC CISO Benchmarking Report (2026) Where Health Sector Security Leaders Stand and Where They’re Headed. S.l.: Health-ISAC.