The CODEW is published and edited by Erwin Castro, an independent tech journalist focused on the intersection of business strategy and enterprise software.

Cybersecurity Watch: Healthcare & Financial Services Face Rising Cyber Risks in July 2026

The CODEW | Cybersecurity Watch
As Cyber Threats Evolve, Healthcare and Financial Services Face Diverging—but Equally Critical—Security Challenges. 
Following our mid-year cybersecurity threat landscape overview, this edition of Cybersecurity Watch examines the unique risks, regulatory developments, and defensive priorities shaping two of the world’s most targeted industries: Healthcare and Financial Services.
Although both sectors remain prime targets for ransomware operators, financially motivated cybercriminals, and state-sponsored threat actors, their security priorities differ significantly. Healthcare organizations must protect patient safety while modernizing aging infrastructure, whereas financial institutions are strengthening digital resilience against increasingly sophisticated identity-based attacks and AI-powered fraud.

Close-up of a computer screen showing dynamic financial market data and charts, indicating real-time trading updates.
Photo by Саша Алалыкин from Pexels



Healthcare: Security Is Now Patient Safety

Healthcare remains the costliest industry for cyber breaches. According to IBM’s latest Cost of a Data Breach research, the average healthcare breach now costs $10.93 million, marking the fourteenth consecutive year that the sector has led all industries in breach costs.
The consequences extend far beyond financial losses. Cyberattacks increasingly disrupt clinical operations, delay treatments, divert emergency services, and directly impact patient care.

Regulatory Momentum Builds

Cybersecurity regulation continues to accelerate across the healthcare sector.
The bipartisan Health Care Cybersecurity and Resiliency Act of 2026 (S. 3315) has gained significant momentum following its advancement by the Senate HELP Committee. If enacted, the legislation would push HIPAA-regulated organizations toward stronger baseline cybersecurity controls, including:
  • Mandatory multi-factor authentication (MFA)
  • Encryption of protected health information (PHI) both at rest and in transit
  • Routine penetration testing
  • Enhanced cybersecurity risk assessments
One of the bill’s most significant provisions is a proposed 12-month safe harbor, which could reduce enforcement penalties for organizations that demonstrate continuous alignment with recognized NIST cybersecurity standards before a security incident occurs.
The proposal reflects a broader regulatory shift from reactive compliance toward measurable cyber resilience.

IoMT Expands the Attack Surface

Hospitals continue to rapidly deploy Internet of Medical Things (IoMT) devices—including smart infusion pumps, patient monitoring systems, imaging equipment, and remote telemetry platforms.
While these technologies improve clinical efficiency, many legacy medical devices cannot support modern endpoint detection agents, advanced encryption, or frequent software updates.
To compensate, healthcare organizations increasingly rely on:
  • Network segmentation
  • Passive network monitoring
  • Behavioral analytics
  • Device-specific access controls
These layered defenses help identify anomalous device behavior without disrupting critical clinical operations.

Ransomware Continues to Disrupt Care

Modern ransomware operations have evolved well beyond simple encryption attacks.
Threat groups increasingly employ multi-extortion tactics, stealing electronic health records and sensitive patient information before encrypting hospital systems. The threat of publicly exposing medical histories places additional pressure on victims while amplifying operational disruption.
Recent attacks have resulted in:
  • Canceled surgeries
  • Delayed treatments
  • Ambulance diversions
  • Extended downtime of electronic health record (EHR) systems
For healthcare providers, cybersecurity has become inseparable from patient safety.


Financial Services: Identity Under Attack

Financial institutions face a fundamentally different threat landscape.
Highly digitized banking platforms, expanding open banking ecosystems, cloud-native architectures, and complex API integrations have made identity the new security perimeter.

DORA Raises the Compliance Bar

Organizations operating within—or conducting business with—the European Union must now comply with the Digital Operational Resilience Act (DORA).
DORA significantly strengthens operational resilience requirements by mandating:
  • Continuous ICT risk management
  • Strict incident reporting timelines
  • Threat-led penetration testing (TLPT)
  • Oversight of critical third-party ICT providers
  • Comprehensive operational resilience governance
The regulation extends accountability beyond internal infrastructure, requiring organizations to evaluate the security posture of vendors throughout their digital supply chains.

Identity Becomes the Primary Battleground

Credential theft has evolved dramatically over the past year.
Financial institutions report increasing campaigns involving:
  • Adversary-in-the-Middle (AiTM) phishing
  • Session hijacking
  • QR-code phishing (“quishing”)
  • Token theft
  • Credential replay attacks
These techniques frequently bypass traditional MFA by stealing authenticated session cookies rather than user passwords.
At the same time, attackers increasingly target internet-facing edge infrastructure—including VPN appliances, secure gateways, and remote access systems—before public vulnerability disclosures, enabling lateral movement into internal banking environments before defenders can deploy patches.

Agentic AI Creates a New Fraud Landscape

Artificial intelligence is transforming both financial operations and cybercrime.
Banks are deploying autonomous AI agents to automate:
  • Loan underwriting
  • Claims processing
  • Fraud detection
  • Customer service
  • Real-time transaction monitoring
Cybercriminals are responding with increasingly automated attacks powered by Agentic AI, including:
  • Synthetic identity fraud
  • Automated account takeover campaigns
  • High-velocity transaction fraud
  • AI-assisted social engineering
This emerging AI-versus-AI environment is reshaping fraud prevention strategies across the financial sector.

Comparative Sector Overview

Focus AreaHealthcareFinancial Services
Primary Driver
Patient safety and S. 3315 readinessDORA compliance and operational resilience
Top Attack Vector
Phishing, EHR data theft, vulnerable IoMT devicesAiTM phishing, API abuse, edge infrastructure exploitation
Primary Defense Priority
Network segmentation, immutable backups, medical device visibilityIdentity-first security, Zero Trust architecture, API protection


Key Takeaways for Security Leaders

Cyber resilience increasingly depends on proactive governance rather than reactive incident response.
Healthcare organizations should align cybersecurity programs with recognized NIST frameworks to strengthen resilience and prepare for potential S. 3315 safe harbor provisions. Financial institutions, meanwhile, should ensure third-party ICT providers meet DORA’s operational resilience requirements and continuously validate supply chain security.
Traditional multi-factor authentication alone is no longer sufficient. Organizations across both sectors should accelerate adoption of phishing-resistant authentication methods such as FIDO2 security keys, WebAuthn, and passkeys to mitigate session hijacking and credential theft.
Security teams should also prioritize visibility into internet-facing infrastructure. VPN appliances, firewalls, remote gateways, and edge devices have become preferred targets for attackers seeking early access before vulnerability disclosures or patch deployment.
As threat actors increasingly automate attacks using artificial intelligence, defensive strategies must evolve accordingly. Organizations that combine strong governance, continuous monitoring, identity-first security, and resilient architecture will be better positioned to withstand the next generation of cyber threats.


Cybersecurity Watch is The CODEW’s monthly cybersecurity intelligence series, delivering timely analysis of emerging threats, regulatory developments, and defensive strategies shaping today’s digital security landscape.

Erwin Castro

Founder & Editor • The CODEW

Erwin Castro is the founder and editor of The CODEW, covering technology mergers and acquisitions, startup exits, artificial intelligence, enterprise software, and Build vs Buy strategy. With more than a decade of journalism experience, he has contributed to Sportskeeda, IBTimes, University Herald, US Blasting News, and Seeking Alpha. His work focuses on explaining the business strategy behind technology deals and their impact on the global technology industry.

About Erwin | Build vs Buy | Weekly Roundups | Latest Deals

Cybersecurity Watch: Healthcare & Financial Services Face Rising Cyber Risks in July 2026 Cybersecurity Watch: Healthcare & Financial Services Face Rising Cyber Risks in July 2026 Reviewed by Erwin Castro on Tuesday, July 21, 2026 Rating: 5

No comments: