Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Monday, 15 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Report Reveals Healthcare Industry is Disillusioned in its Preparedness for Cyberattacks

by The Gurus
April 18, 2024
in News
health
Share on FacebookShare on Twitter

Kroll, the leading independent provider of global risk and financial advisory solutions, has released the State of Cyber Defense: Diagnosing Cyber Threats in Healthcare report, exposing the healthcare industry’s disillusionment in terms of its cyber maturity. The research reveals that over a quarter (26%) of healthcare businesses have immature cybersecurity processes yet nearly 50% believe their processes are ‘very mature’. Despite this high sense of self-confidence, only 3% of healthcare organizations surveyed actually have mature cyber processes in place.

Twenty-eight percent of healthcare organizations surveyed only employ the most basic security capabilities, such as cybersecurity monitoring, and none of the healthcare respondents had all recommended threat and detection capabilities in place. It is therefore no surprise that Kroll’s threat intelligence consistently finds the industry to be one of the most targeted sectors by threat actors. The industry is also particularly susceptible to data breaches, with healthcare being the most breached industry in 2022 and the second most breached in 2023, according to Kroll’s Data Breach Outlook.

The story becomes more interesting when looking at where healthcare organizations are sourcing their cybersecurity. Healthcare organizations are 65% less likely to fully outsource their cybersecurity services than the average organization. However, of the healthcare respondents who currently manage all their cybersecurity services in-house, 62% confirmed that they have plans to outsource in the next 12 months. Outsourced managed security could help the healthcare industry close the self-diagnosis gap and better protect themselves in the future.

Devon Ackerman, Global Head of Incident Response, Cyber Risk at Kroll, commented: “The self-diagnosis gap between healthcare’s confidence in its security and its real-world security capabilities is particularly worrying considering that a cyber incident could disrupt hospital operations and have devastating outcomes for patient care and treatment, even putting human lives at risk. Unfortunately, healthcare is a wide-reaching environment with varying levels of investment and IT complexity, not to mention extremely time-poor staff that need both maximum convenience and security from IT operations. This is often why relying on a trusted external third-party provider, with visibility into the changing threat landscape, can be a game-changer for improving security resilience to protect against today’s threats.”

Key findings from Kroll’s State of Cyber Defense: Diagnosing Cyber Threats in Healthcare report include:

  • Above-average confidence: Healthcare is the most likely industry to self-report as having very mature security. Only a tiny fraction of healthcare respondents (3%) said that they do not trust their organization’s ability to defend against most cyberattacks.
  • Below-average capabilities: Unfortunately, the real-world security capabilities of healthcare organizations are below average. Of healthcare businesses, 26% rank as having low cyber maturity, and healthcare performs badly in comparison to other sectors that scored highly for self-reported security.
  • In-house security services: Healthcare organizations are 65% less likely to outsource their cybersecurity services than other sectors due to the dynamic nature of these work environments. However, nearly two-thirds (62%) of healthcare companies that currently handle everything in-house plan to outsource some services in the next 12 months.
  • Credential access fears: Healthcare respondents selected credential access as their number one fear—more than ransomware, BEC and phishing. Interestingly, credential access was the least significant threat according to all other industries.
  • Email compromise and ransomware: Kroll Threat Intelligence finds that a third of cases (33%) infiltrated healthcare networks through the use of phishing links, and email compromise (37%) and ransomware (34%) are the two most common incident types. 
  • Top target for breaches: The healthcare industry is one of the most breached industries, ranking first in 2022 and second in 2023 in Kroll data. Further, the industry has had YoY increases in the number of inquiries and identified monitoring activations.

The State of Cyber Defense: Diagnosing Cyber Threats in Healthcare report is a combination of survey data from 1,000 global senior IT security decision-makers and Kroll data from its front-line threat intelligence and experience of handling over 3,000 yearly incidents. The third-party survey was carried out by an independent specialist in market research, Vanson Bourne, and all respondents had some responsibility or knowledge of cybersecurity within their organization.

To download the State of Cyber Defense: Diagnosing Cyber Threats in Healthcare report, please click here.

ShareTweet
Previous Post

Goldilock Partners with organisation behind NATO’s largest cyber defence exercise

Next Post

UK’s Cydea introduces new way to quantify risk management

Recent News

Check Point Expands MSP Platform with AI Security Capabilities and Unified Bundles

From Playbooks to Adaptive Workflows: How MSSPs Are Evolving Security Operations with Agentic AI

June 15, 2026
Nagomi Control Brings CTEM Into Action

2 in 5 Organisations Experienced Cyber Incidents Tied to Suppliers in Past Year

June 12, 2026
Certes Research Warns Legacy Systems Are Biggest Barrier to Quantum Security Readiness

KnowBe4 Expands Gamified Training Library With Launch of “Spot the Vish” Game

June 12, 2026
Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

June 12, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol