Cybersecurity breaches are commonplace in healthcare settings. Ron Cherry, Director, Cloud Cybersecurity & GRC, Nordic, discusses the cybersecurity threat environment within the healthcare space and how hospitals can move towards a true Zero Trust model.
Just how bad is the cybersecurity threat environment within the healthcare space at the moment, and what are you seeing?
The threat landscape in healthcare is worse than it has ever been. Ransomware, AI-assisted phishing and supply chain attacks are escalating, yet breaches no longer shock anyone. They have almost become routine. What makes healthcare uniquely vulnerable is that it operates on ageing infrastructure, runs on thin margins and prioritises patient care over system maintenance. This creates the perfect storm for attackers who know hospitals cannot afford downtime.
It seems like cybersecurity breaches in healthcare have become ‘routine’. What is the single biggest factor contributing to this, and how does your ‘fail small, not fail big’ approach directly address it?
Many health systems still build their security programmes around the idea that breaches can be entirely prevented. That is no longer the reality. Attackers have unlimited time and creativity. IT teams do not. The assumption that you can keep the bad actors out at all costs leads to brittle defences that collapse when a single gap is exploited.
That is where ‘fail small, not big’ comes in. Instead of thinking in terms of perfect prevention, you design for containment. It recognises that some incidents are inevitable, but they do not need to be catastrophic. This means re-architecting systems and policies so that if ransomware strikes, it cannot spread across the entire network. If phishing succeeds, it compromises one account – not the whole Active Directory.
Think in terms of measuring the blast radius. Can we limit a breach to a specific department or unit rather than the enterprise? Can we restore critical EHR systems in hours instead of days? That sort of pragmatic resilience does not just minimise financial and reputational damage; it protects continuity of patient care. And in healthcare, where downtime directly impacts lives, that is the metric that matters most.
What’s the most critical policy or behavioural change a hospital can implement today to move toward a true Zero Trust model?
Build the understanding that Zero Trust is not a product you can buy off the shelf. It is a cultural and policy-driven mindset. Too often, I see hospitals chasing shiny tools and missing the bigger picture. Zero Trust is about defaulting to ‘deny until verified’, and that requires people to work differently every day.
The single most significant behavioural change is around access: do not assume anyone – inside or outside the network – is automatically trusted. That means requiring verification for every connection, whether it is someone logging in from home or a device accessing private data from within the organisation. Eliminating practices such as split tunnelling and mandating the use of approved, secure cloud storage are practical examples. They force users into workflows that are safer by design, making it much harder for attackers to move laterally if they gain access.
For a small to mid-sized hospital with limited resources, what is the most practical and immediate step they can take to begin fortifying their systems?
The reality is that small and mid-sized hospitals simply do not have the staff or budget of a major health system. That makes it even more essential to focus on a handful of practical, high-impact moves that close gaps quickly.
The first place to start is endpoint security. It is the front door for most attackers, and most modern solutions are affordable and scalable. Pairing that with multi-factor authentication immediately makes life harder for bad actors. From there, use a short list of ‘non-negotiables’ that any hospital, regardless of size, can put in place:
- Eliminate split tunnelling so traffic is not flowing outside protected channels
- Require cloud storage with guardrails – this ensures data is not left vulnerable on laptops or personal devices
- Layer endpoint security with MFA as the baseline
- Establish an isolated recovery environment so critical systems like the EHR can be restored quickly without reinfecting the network
- Enforce regular patching and updates – it sounds basic, but unpatched systems are still the root cause of many breaches
None of these require a massive capital outlay or a full IT team. They are about creating smart guardrails that buy you resilience.
How do you measure the success of a cybersecurity strategy? Are there specific containment metrics you focused on at Mercy Health that you would recommend to other CISOs?
Success is not ‘we have not been breached’ – that is an illusion. Success is how quickly and effectively you can contain and recover. At Mercy, we measured things such as the ease and speed of identifying a compromised endpoint, the time to restore function from a recovery environment and the number of systems impacted during an incident. If the blast radius is shrinking with each incident, your strategy is working.
What’s a real-world example of a hospital using AI with the right policies in place, versus a dangerous use case you’ve seen?
I have seen AI help with anomaly detection – flagging unusual login behaviour that would have taken a human team much longer to notice. However, I have also seen the other side: hospitals experimenting with AI-driven automation without guardrails, for example, allowing AI tools to automatically quarantine or delete files. Without policy oversight, that can cause self-inflicted damage equal to an attack.
Could you walk us through the process of setting up an ‘isolated recovery environment’ to protect electronic health records (EHRs)? What are the key challenges, and how do you overcome them?
Think of an isolated recovery environment as a lifeboat for your most critical systems, especially the EHR. If ransomware takes down the main ship, you need a clean, separate environment you can fall back on to keep operations moving.
The process starts with segmentation – building a recovery environment that is physically or logically separated from your day-to-day production network. That means dedicated storage, restricted connectivity and hardened access controls so attackers cannot reach it even if they have compromised the primary environment.
Second is replication and validation. Continuously backing up critical data and configurations into that environment is critical, but it is not enough to just copy them over. They need to be scanned, verified and tested so you are not replicating infected files into your ‘lifeboat’.
Third is orchestration and testing. Hospitals often overlook this, but recovery is not solely about data. It is about workflows. You have to rehearse failover, test restoring your EHR in a live-but-contained environment and practise how users will log in and access records during downtime. A lifeboat only works if your crew knows how to use it.
The biggest challenges I have seen are resource-related. Setting up an isolated recovery environment requires investment, and smaller hospitals often lack dedicated cyber teams. However, there are ways to overcome this, including partnering with managed service providers, utilising cloud-based recovery solutions or phasing in the approach system by system rather than all at once.
The payoff is substantial: when you know you can restore critical patient data safely and quickly, you transform a ransomware incident from a full-blown disaster into a disruption that can be contained and recovered from. In healthcare, that difference can literally save lives.
How do you keep your cybersecurity strategy proactive rather than reactive, especially when the day-to-day focus is on containment?
A proactive strategy requires two things: continuous learning and cultural reinforcement. Every incident is an opportunity to shrink the blast radius next time. Treat small failures as data, not disasters. On the cultural side, leadership has to reinforce that cybersecurity is integral to patient safety. When your staff understand that protecting systems is protecting care, you have shifted from a reactive IT posture to a proactive safety culture.

