The CODEW | Cybersecurity Watch As Cyber Threats Evolve, Healthcare and Financial Services Face Diverging—but Equally Critical—Security Challenges.
Following our mid-year cybersecurity threat landscape overview, this edition of Cybersecurity Watch examines the unique risks, regulatory developments, and defensive priorities shaping two of the world’s most targeted industries: Healthcare and Financial Services.
Although both sectors remain prime targets for ransomware operators, financially motivated cybercriminals, and state-sponsored threat actors, their security priorities differ significantly. Healthcare organizations must protect patient safety while modernizing aging infrastructure, whereas financial institutions are strengthening digital resilience against increasingly sophisticated identity-based attacks and
AI-powered fraud.
Healthcare: Security Is Now Patient Safety
Healthcare remains the costliest industry for cyber breaches. According to IBM’s latest Cost of a Data Breach research, the average healthcare breach now costs $10.93 million, marking the fourteenth consecutive year that the sector has led all industries in breach costs.
The consequences extend far beyond financial losses. Cyberattacks increasingly disrupt clinical operations, delay treatments, divert emergency services, and directly impact patient care.
Regulatory Momentum Builds
Cybersecurity regulation continues to accelerate across the healthcare sector.
The bipartisan Health Care Cybersecurity and Resiliency Act of 2026 (S. 3315) has gained significant momentum following its advancement by the Senate HELP Committee. If enacted, the legislation would push HIPAA-regulated organizations toward stronger baseline cybersecurity controls, including:
- Mandatory multi-factor authentication (MFA)
- Encryption of protected health information (PHI) both at rest and in transit
- Routine penetration testing
- Enhanced cybersecurity risk assessments
One of the bill’s most significant provisions is a proposed 12-month safe harbor, which could reduce enforcement penalties for organizations that demonstrate continuous alignment with recognized NIST cybersecurity standards before a security incident occurs.
The proposal reflects a broader regulatory shift from reactive compliance toward measurable cyber resilience.
IoMT Expands the Attack Surface
Hospitals continue to rapidly deploy Internet of Medical Things (IoMT) devices—including smart infusion pumps, patient monitoring systems, imaging equipment, and remote telemetry platforms.
While these technologies improve clinical efficiency, many legacy medical devices cannot support modern endpoint detection agents, advanced encryption, or frequent software updates.
To compensate, healthcare organizations increasingly rely on:
- Network segmentation
- Passive network monitoring
- Behavioral analytics
- Device-specific access controls
These layered defenses help identify anomalous device behavior without disrupting critical clinical operations.
Ransomware Continues to Disrupt Care
Modern ransomware operations have evolved well beyond simple encryption attacks.
Threat groups increasingly employ multi-extortion tactics, stealing electronic health records and sensitive patient information before encrypting hospital systems. The threat of publicly exposing medical histories places additional pressure on victims while amplifying operational disruption.
Recent attacks have resulted in:
- Canceled surgeries
- Delayed treatments
- Ambulance diversions
- Extended downtime of electronic health record (EHR) systems
For healthcare providers,
cybersecurity has become inseparable from patient safety.
Financial Services: Identity Under Attack
Financial institutions face a fundamentally different threat landscape.
Highly digitized banking platforms, expanding open banking ecosystems, cloud-native architectures, and complex API integrations have made identity the new security perimeter.
DORA Raises the Compliance Bar
Organizations operating within—or conducting business with—the European Union must now comply with the Digital Operational Resilience Act (DORA).
DORA significantly strengthens operational resilience requirements by mandating:
- Continuous ICT risk management
- Strict incident reporting timelines
- Threat-led penetration testing (TLPT)
- Oversight of critical third-party ICT providers
- Comprehensive operational resilience governance
The regulation extends accountability beyond internal infrastructure, requiring organizations to evaluate the security posture of vendors throughout their digital supply chains.
Identity Becomes the Primary Battleground
Credential theft has evolved dramatically over the past year.
Financial institutions report increasing campaigns involving:
- Adversary-in-the-Middle (AiTM) phishing
- Session hijacking
- QR-code phishing (“quishing”)
- Token theft
- Credential replay attacks
These techniques frequently bypass traditional MFA by stealing authenticated session cookies rather than user passwords.
At the same time, attackers increasingly target internet-facing edge infrastructure—including VPN appliances, secure gateways, and remote access systems—before public vulnerability disclosures, enabling lateral movement into internal banking environments before defenders can deploy patches.
Agentic AI Creates a New Fraud Landscape
Artificial intelligence is transforming both financial operations and cybercrime.
Banks are deploying autonomous AI agents to automate:
- Loan underwriting
- Claims processing
- Fraud detection
- Customer service
- Real-time transaction monitoring
Cybercriminals are responding with increasingly automated attacks powered by Agentic AI, including:
- Synthetic identity fraud
- Automated account takeover campaigns
- High-velocity transaction fraud
- AI-assisted social engineering
This emerging AI-versus-AI environment is reshaping fraud prevention strategies across the financial sector.
Comparative Sector Overview
| Focus Area | Healthcare | Financial Services |
Primary Driver | Patient safety and S. 3315 readiness | DORA compliance and operational resilience |
Top Attack Vector | Phishing, EHR data theft, vulnerable IoMT devices | AiTM phishing, API abuse, edge infrastructure exploitation |
Primary Defense Priority | Network segmentation, immutable backups, medical device visibility | Identity-first security, Zero Trust architecture, API protection |
Key Takeaways for Security Leaders
Cyber resilience increasingly depends on proactive governance rather than reactive incident response.
Healthcare organizations should align cybersecurity programs with recognized NIST frameworks to strengthen resilience and prepare for potential S. 3315 safe harbor provisions. Financial institutions, meanwhile, should ensure third-party ICT providers meet DORA’s operational resilience requirements and continuously validate supply chain security.
Traditional multi-factor authentication alone is no longer sufficient. Organizations across both sectors should accelerate adoption of phishing-resistant authentication methods such as FIDO2 security keys, WebAuthn, and passkeys to mitigate session hijacking and credential theft.
Security teams should also prioritize visibility into internet-facing infrastructure. VPN appliances, firewalls, remote gateways, and edge devices have become preferred targets for attackers seeking early access before vulnerability disclosures or patch deployment.
As threat actors increasingly automate attacks using artificial intelligence, defensive strategies must evolve accordingly. Organizations that combine strong governance, continuous monitoring, identity-first security, and resilient architecture will be better positioned to withstand the next generation of cyber threats.
Cybersecurity Watch is The CODEW’s monthly cybersecurity intelligence series, delivering timely analysis of emerging threats, regulatory developments, and defensive strategies shaping today’s digital security landscape.
Erwin Castro
Founder & Editor • The CODEW
Erwin Castro is the founder and editor of The CODEW, covering technology mergers and acquisitions, startup exits, artificial intelligence, enterprise software, and Build vs Buy strategy.
With more than a decade of journalism experience, he has contributed to Sportskeeda, IBTimes, University Herald, US Blasting News, and Seeking Alpha. His work focuses on explaining the business strategy behind technology deals and their impact on the global technology industry.
About Erwin |
Build vs Buy |
Weekly Roundups |
Latest Deals
No comments: