
Loading summary
A
You're listening to the Cyberwire Network, powered by N2K. Yes, there are horrible people out there that have it out for you and it's either they want to disrupt you or they want to wipe stuff that you're doing to make an impact because they're acting on a name or acting according to a certain regime, or they just want to make money and it's pure business to them. So you better be prepared and make sure you have adequate security and investments in place.
B
Hello and welcome to another episode of Data Security Decoded. I'm your host, Caleb Tolan, and if this is your first time joining us, welcome to the show. Make sure you hit that subscribe button so you're notified when we drop new episodes. And if you're a returning subscriber, thanks so much for spending some more time with us. Make sure you give us a review a rating below, let us know what you think about the episode. Your feedback really helps me understand what you want to learn more about and it helps us reach more listeners like you who are trying to improve the resilience of their business. Now, in this episode, I am joined by John Focker, the VP of Threat Intelligence Strategy at Trellix, and we talked about their Healthcare Cybersecurity Threat Intelligence Report, which analyzes the 2025 healthcare threat landscape. There's a lot of really interesting stuff in this report. We had a really fantastic conversation. So without further ado, let's get into it. Well, we're really excited to dive in and talk a little bit about this report that you and the team put out. And so the first thing that I wanted to chat a little bit about was a stat that really, really stood out to me in terms of lethality. And so typically when we're talking about cybercrime, we're talking about, you know, what is the total dollars and the cost of a breach. What is the total economic impact of cybercrime? But, but your report found a 29% increase in inpatient mortality rates at hospitals hit by attacks. That's a really, really impactful and really just touching stat to hear. So when you're sharing this data with a ciso, how are they using that mortality stat to convince their board that cyber security isn't just a cost center, it's not just something that, that is a checkbox on a form, but it's actually a fundamental requirement of clinical missions.
A
Well, you said that. Right. And if I sum it up, in healthcare, downtime isn't just expensive, it is life threatening and it's Dangerous. So for a CISO where they historically had like, okay, it was just the IT systems, you now see that there's more like digitization, if you might call for things. And there's more advancements when it comes to building the networks and having everything connected. Their seat at the table has become much larger in having these figures or arming them with these figures will have them address the right audience. Because as much as it's, it's been hard in the past because yeah, a hospital board, they have only X amount of dollars to spend and they want to spend it on the best care they can give to their patients. And patient safety is number one. And now you see that transition from going from, okay, it's just the IT department, like, no, no, this has real impact on human lives. You're going into that patient safety space. So our report and many other reports, we will hope that like in the healthcare industry, those CISOs will have ample ammunition to open up that conversation. It's like, hey, listen, if we want to continue as is, patient safety is number one, we need to invest more.
B
Absolutely. And it's even starting to make its way into pop culture. You know, I'm not watching the pit. It's something that's on my list to get to. But I've heard so many people talk about this recent season and how much of a focus there is on cybercrime taking down hospital systems and how that is really impacting patient care. Just like what you were talking about. I have on the other hand seen Grey's Anatomy and gosh, it was probably like five or six years ago that they had an episode where the hospital was taken out by a ransomware attack. And, and so it's becoming a more prevalent and well known topic that, that cybercrime does directly affect patient outcomes. And something else that I found really interesting is attacks targeting non clinical systems like H VAC units to really bring hospitals down to their knees. So simultaneously, while attacks are, you know, attacking business associates and third party providers, given that like 99% of hospitals have at least one device known with a exploited known vulnerability, um, are we focusing too much on the hospital's front door while the back door is really wide open with partners and facilities that, that aren't addressing some of these issues.
A
Yeah, that's a good point. If you look at it, the attack might start in the back office. Right. But then the impact is definitely felt at clinical care. When we look at not only hospitals or medical systems, but OT in general. If I just generalize, OT like operational Technology. In our other report, the OT Fit report, we divided up in three elements. It's like the direct ot. So you can, if you, if you kind of take that same analogy for hospitals or healthcare, it would be like, hey, it's your MRI system. Is that connected to the Internet? Is that vulnerable? So in the ot that would be the plc, right? And then it's, you have all the systems adjacent that not only. And an H VAC system they can be like we can, we can count that under. Those systems are not directly impactful to the machine itself. But disrupting these will change the environment for hospital or logistics or other things that will have an impact. And then they have, from a safety perspective, they'll have no other choice than to shut things down. Very, very similar. Like everybody knows Colonial Pipeline, right? The actual pumps did not get infected. It was the system that maintained the accounting, making sure that the logistics were in order. Those were impacted by I believe darkside ransomware and that short that caused the shutdown. So you will see that there's in that whole chain in order to deliver either patient care or OT environment, there's different systems. And then lastly there's systems that like you have the adjacent systems and then there's systems for like logistics, like do the right supplies come in? So let's say a IT system because it's not connected to anything else, but it manages, it's connected to the pharmaceuticals. So the hospital can get enough medicine in for instance, or enough supplies that gets impacted and that gets shut down, disrupted in any way or form that could also impact the patient care.
B
Absolutely. Yeah. I was even going to ask you, like what are some of those non clinical systems that you've seen that are kind of those curveballs that people aren't necessarily affected by. But those are some really, really interesting examples. And so I want to shift gears a little bit and talk about dwell and downtime. So the global median dwell time for a ransomware attack used to be about five days. But your report found that in healthcare in particular, it was a 279 day detection and containment cycle that is wild, nearly like you know, the better part of a year of an adversary living in your network. So my question really is have adversaries mastered the art of blending into the background of a busy hospital? What kind of like anomalies can it and security teams listening in look out for so that they can stay on their toes and identify these anomalies before they become out of hand?
A
Yeah, and it's good to know that like that number is ultimately an outlier. Right. It's like staggering because when I saw that number the first time I was like, holy moly. And at the same time, on the other hand, you have ransomware attacks that come in and they have a pretty short dwell time. And if they deploy ransomware that locks up systems, they want to, yeah, they want to, it's all business, right. It's money. So they, they want to make sure that they're known. They lock up the systems, put the pressure on, on, on the hospital or on the, the medical provider, it might say. So because mind you, our data set is not only pure hospitals, it's the larger healthcare organizations. And then so the dwell time is relatively short just to meet their objectives and then they will make themselves known and then we'll start the extortion. But going back to like, hey, there's 99% of systems are vulnerable to certain exploits. That is in the military you would say a target rich environment. Right. There's a lot of entryways getting into the network and for certain, certain threat actors, it's interesting to stay under that radar, to stay within the network or exfiltrate data out or just having some kind of foothold. And that's from the attacker's point of view and then from the defender's point of view we see that. Yeah. And that's, it's all interconnected. So that goes back to the investments. It's like, okay, do you have the proper tooling and solutions in place to see those living off the land type of attacks that go low and slow under the radar because they want to blend in. They're not always using malware to get in. So they're using some, they have legitimate accounts and then you have to spot the anomaly. So like how do you spot malicious behavior exhibited by non malicious tools? And that is where usually like an EDR type of tooling comes in or an NDR type of tooling, proactive threat hunting that we're big on as well. So these are the things that you can help spot these, these anomalies. But mind you, I think the biggest factor that we saw against healthcare organizations at large, so not only hospitals, but anything from pharmaceuticals or whatever, the number one entry point or the biggest one that we saw was still email. So like email security is a big, big thing for these organizations. Make sure that you can stop it before it actually gets inside your network.
B
Yeah, you know, both really. I'm the, I'm the oddball in my family, everybody that I is in my immediate family, my Sister and both my parents all have worked in hospitals, and so now working in cyber security, I talk to them all the time about the stuff that I'm working on. And they're like, oh, you know, I had to take that phishing, you know, that phishing security thing. And I'm like, yes, it's very important. Please pay attention to it. Because we still continue to see that these entry points are from some of the most typical places that we've been talking about for really decades now. So I really kind of want to zoom in a little bit on what you were talking about about with like, indicators of compromise. So what are like some of the standout behaviors that you've seen that really distinguish between care and crime when you have a threat actor living within a system and they've, you know, credential crept their way into an administrative role? Like, what. What do those IOCs look like typically? And what are some of the interesting ones that you've seen?
A
Wow, there's been so many. A lot of times, like when we talk about IOCs within Trellix, we kind of label that as atomic indicators. So that's more like the tactical layer when it comes to technical threat intelligence. Very often we don't see a lot of indicators. So it's, it's very much more tool usage. So we see that more in an operational intelligence layer. So we see legitimate tools like PowerShell being used, the command line, and PS exact to execute some stuff. And it really depends on what phase the attacker is in. So if they have an initial foothold, let's say they send out an email, right? They have some kind of implant or a different lure, and you would see like, okay, they have one system and now they need to, okay, where am I? So, yeah, it sounds silly, but sometimes you still see who am I? Which is actually a dead giveaway if they use that command. But it's system discovery. So they need to figure out, where am I in the system, Did I hit the jackpot, or am I at like a lonely computer somewhere in the HR department and I need to work my way up to become domain admin or so. So system discovery, like ad find tools like that, just to figure out where they are. And then you would see that try to escalate privileges move laterally. So the tool usage for that is also very obvious, obviously, like process injection, those type of techniques we see, and there's a thousand ways of doing so. And then when they move through the network, it really depends on what they do, what they want to do. Right. They want to find if they, if their goal is, let's say a ransomware group that does data extortion, they would look at finding the interesting data and something that really like there's things that pop up like they would use like 7 zip and if you're not using 7, 7 zip is a legitimate tool. But if you're not using that in your network or some user is obviously never used it and starts using might be it's your, your family member that heard from UK hey, 7 sip is really great and then I want to use it. But it could also be that somebody's actually got that account and then is, is, is using it as well. And another thing that we, we often see is like when threat actors have a legitimate foothold and we see this, this across the board. So it's not only on, in, in the medical sector using legitimate remote management tools. That is such a prevalent thing. Like we just published a whole report on the capability from the Iranian threat actors and they leverage a whole set of legitimate remote management tools. And that's what we often advise our customers and everybody else is like, listen, like as soon as they can install this, say they do anydesk or Altair or TeamViewer, it doesn't matter. That is disguised as legitimate traffic and it will not stand out because. And then they have the ultimate backdoor. They can just communicate back and forth in. And they don't need any elaborate cobalt strike or anything else because they already have that foothold. And especially when you're dealing with HIPAA compliant data or it's like you get into a system where there's patient files, you want to, you want to put a hold on this, you want to, you want to lock this down and make sure like, hey, this is within our organization, this is the only tool we use and we block everything else. So that's something that we, we, we really often see across the board. It's like, okay, we got in, it's like, oh, we made a little noise to do the thing that we need to do. And if we're in and we want to stay in, as soon as we can switch to remote management tools, legitimate ones, and just, they can sit there, they can do anything until they meet their objective.
B
All right, you're even getting ahead of me because I was just about to say my next question for you is what are the three actions that defenders can take today to start improving their clinical cyber resilience? You already mentioned one, so let's get two more on the books too.
A
Oh my gosh. So email, it's like the front door. You need to lock the front door. And that goes like, if we talk about front door emails, one like have really good email security. If you do not have an organization like a basic email blocking system, invest in like a team that can also augment your security team on top of that. So email and anything you can do to harden, that is a great one. So we say like having an ability and that goes beyond remote management tools, an ability to monitor any suspicious behavior in your network. So having more grip on the low bins because that's kind of a common threat. If we talk about what we've been discussing, segmentation still holds up. So any like the OT requirements that we have. So your most vulnerable systems. And I realized this, right, so having segmentation in a network, not everything has to be connected is actually a healthy thing. And then lastly, I would say limit your attack service. So if you look at how a lot of these threat actors will operate is they'll scan your IP space and they look for vulnerable systems that are accessible through the Internet. And if you do this as a security team on a continuous basis and you can address these vulnerabilities and then it's not only, and this is very funny, it's not only the vulnerability that you have to plug, but you have to use threat intelligence. Threat intelligence about like, okay, which threat actors are leveraging this vulnerability? And how can I rule out that? Yes, I put my finger in as a Dutch analogy, right? My finger in the dam. But you want to know like all the water that already came through, is that not like where, where are the piles on the puddles of water? So like where's. If the threat actor already got in, where could he hide? So proactive hunting in your environment is another thing.
B
Yeah, yeah, that's great. And we did a recent episode with, with Kyle Feeler on the Rubrik zero Labs team and we talked about how backups can be and rather unexpected resource for your threat intelligence as a, as a telemetry mechanism. So if you're looking at your backups and you see threat actors living within there, it's really a good record keep of basically your entire security stack failing to identify these threats before they made it up to your backup. So that's a, that's another, another great resource to look at. And if anyone listening in and hasn't given that episode a listen, then I highly encourage it. All right, next one for you is Two Inconvenient Truths. What are Two inconvenient truths that every security leader is ignoring right now in healthcare when it comes to data security, maybe not every security leader, but maybe maybe the ones that have their rose colored glasses on.
A
I would say AI for data security is as much a savior as it is a curse. When I look at our data security solutions, it's a lot of times our customers are like, hey Trellix, can we have AI to help identify sensitive data in our organization? So can you have your Trellix wise AI assistant help us identify data sets, codify them, label them, all that stuff. So we need to have on this side and then the other end is like, hey Trellox, we have no clue who is using AI and if our intellectual property is going out the door. So it's like we have to embrace AI by making things easier for customers. But at the same time it's like how do we put guardrails on? And especially in, in the healthcare industry where, or pharmaceuticals where you're dealing with IP, the last thing you want is that somebody puts IP in the public ChatGPT function and it like goes out the door and then it's out on the open. So the for AI, that's definitely one inconvenient truth. It's as much a blessing as a curse. I think the inconvenient truth is that kind of touches on data too is for the longest time we've been thinking about healthcare or healthcare providers, hospitals, and I've seen like the start of ransomware targeting hospitals because first that was like, oh, we don't do that, that's unethical. And for the longest time health, healthcare providers and hospitals had something that I, I'd like to call the cyber Red Cross syndrome. So you know, like, hey, we're the Red Cross or the half moon, like you don't attack us, we're, we're neutral or whatever. And I was like, no, that's, that's passe, that's no longer it. But that's still, that attitude still is prevalent within certain healthcare organizations. And by adopting that attitude you limit yourself from a security standpoint because it's like that moment has passed. And if any, like, even with the recent like attack against Stryker, which has a medical tie in, and how the threat actors were leveraging itunes to delete everything, yeah, you're a target. So like you need to drop that and that's inconvenient because that like yes, there are horrible people out there that have it out for you and it's either they want to disrupt you or they want to wipe stuff that you're doing to make an impact because they're acting on the name or acting according to a certain regime, or they just want to make money and it's pure business to them. So you better be prepared and make sure you have adequate security and investments in place.
B
I couldn't agree more. I mean, look, I put you on the spot and you gave two really, really good inconvenient truths. So, so kudos to you for that. And you've shared so many really, really actionable insights that our listeners can, can take away with them. But what is the single most important message that you want to leave the listeners with today?
A
Well, if there's one message, and it's also on the report, is that healthcare cybersecurity cannot be treated as a, like a back office compliance exercise. I really think it has to be approached as an operational resilience and patient safety priority. And that's kind of the two things we already touched upon. And organizations that do that well will be best positioned to absorb any attempts against disruption. And they will protect the trust of their patients and they keep care moving along because that's what it is. Right? So you want to be able to provide the best level of care to all your patients no matter what. So it's all about resilience, right?
B
Absolutely. It's that concept of minimum viable hospitals, like know what your dependencies are and ensure that you can have that operational continuity, even despite everything feeling like it's on fire, which is something we want to avoid. But, you know, it's always good to have that plan in place. So, John, thank you so much for joining us today. This was a fantastic conversation. I really appreciate your time and all the insights you shared with our audience today.
A
Thank you so much, Caleb, and it's a pleasure.
B
That's a wrap on today's episode of Data Security Decoded. If you like what you heard today, please subscribe wherever you listen and leave us a review on Apple Podcasts or Spotify. Your feedback really helps me understand what you want to hear more about. And if you want to reach out to me about the show, email me directly at data-security-decoded2k.com thank you to Rubrik for sponsoring this podcast. The team at N2K includes producer Liz Stokes and executive producer Jennifer Ibin. Content strategy by Mayan Flout Sound design by Elliot Peltzman Audio mixing by Elliot Feltman and Trey Hester Video production support by Bridger Kirke Wilde and Sorrel Joppi. Until next time, stay resilient.
A
It.
Host: Caleb Tolan
Guest: John Focker, VP of Threat Intelligence Strategy, Trellix
Date: April 7, 2026
In this powerful episode, host Caleb Tolan sits down with John Focker from Trellix to analyze the alarming 2025 Healthcare Cybersecurity Threat Intelligence Report. Their in-depth discussion highlights why cyber resilience is essential for healthcare and life sciences, not only to protect economic interests but to safeguard lives. The episode covers the direct link between cyberattacks and patient mortality, overlooked vulnerabilities, adversary tactics, and the actionable steps and hard truths that healthcare leaders must confront.
"Downtime isn't just expensive, it is life threatening and it's dangerous."
— John Focker [02:20]
"The attack might start in the back office, right. But then the impact is definitely felt at clinical care... If your logistics system is disrupted, that could also impact patient care." — John Focker [04:52]
"I saw that number the first time I was like, holy moly... there’s just so many entryways."
— John Focker [07:56]
"They would use like 7zip and if you're not using 7, 7zip is a legitimate tool. But...it could also be that somebody's actually got that account and then is, is, is using it as well." — John Focker [14:00]
Top 3 Immediate Actions for Defenders: ([15:15])
"Having segmentation in a network— not everything has to be connected— is actually a healthy thing." — John Focker [16:45]
AI Is a Double-edged Sword: ([18:18])
"AI for data security is as much a savior as it is a curse...You want to embrace AI, but at the same time, how do we put guardrails on?" — John Focker [18:18]
The ‘Cyber Red Cross’ Fallacy Is Over:
"That moment has passed...you better be prepared and make sure you have adequate security and investments in place." — John Focker [20:40]
Resilience Is Patient Care: ([21:30-22:18])
"Healthcare cybersecurity cannot be treated as a back-office compliance exercise...It has to be approached as an operational resilience and patient safety priority." — John Focker [21:30]
Caleb reinforces the concept of a “minimum viable hospital” and the crucial need to map dependencies and have strong continuity plans.
Mortality Stats as a Board-Level Conversation Starter:
"Their seat at the table has become much larger...patient safety is number one, we need to invest more."
— John Focker [02:20]
Attackers Use Business Logic Against Us:
"It's all business, right. It's money. So, they want to make sure they're known, they lock up the systems, put the pressure on."
— John Focker [07:56]
Spotting Friendly Tools in Enemy Hands:
"As soon as they can switch to remote management tools, legitimate ones...they can sit there, they can do anything until they meet their objective." — John Focker [14:00]
End of Innocence for Healthcare:
"For the longest time, healthcare providers had something I’d like to call the cyber Red Cross syndrome...that's passe, that's no longer it." — John Focker [19:20]
This episode makes a compelling case for prioritizing cybersecurity as core to clinical missions—not just for compliance or cost control, but as a matter of life and death. Focker’s insights offer both urgent warnings and practical guidance, pushing listeners to recognize that every device, system, and third-party link in healthcare is a potential entry point for adversaries. The future of care, trust, and operational continuity hinges on embracing a resilience mindset—immediately.