
Double Trouble: Why Cyber Attacks Are Starting to Come in Pairs | 2 Minute Drill with Drex DeFord
Questions Answered in This Episode
- Why are healthcare security teams now battling multiple cyber incidents simultaneously?
- Is your organization prepared to respond to two major breaches at once?
- How does legacy infrastructure and tech debt multiply your attack surface?
- Can your CISO team actually practice and manage parallel security incidents?
- What happens when your healthcare vendors face the same cyber vulnerabilities you do?
About This Episode
Picture this. You're the CISO at one of the world's largest healthcare companies, and Monday morning brings a call about a cybersecurity incident in a legacy diagnostics environment. Before the briefing even wraps, someone walks in with news of a second incident. Different system, different root cause, same day.
Drex breaks down why that scenario isn't hypothetical, using a recent real-world healthcare giant's dual cyber battles as the wake-up call. Between sprawling app portfolios, aging infrastructure, and an expanding web of AI-powered partners, the attack surface has changed and so has the shape of a breach.
So here's the question for your team this week. If two incidents hit at once, could you actually handle both?
Remember, Stay a Little Paranoid
Transcript
Hey, everyone. I'm Drex and this is The Human In Drill. Thanks to Fortified Health Security for sponsoring today's podcast. It's great to see you today. Here's some stuff you might wanna know about. Imagine that you're the chief information security officer at one of the world's largest healthcare companies, and you wake up on Monday morning to a phone call One of your teams is responding to a cybersecurity incident that affects a really large legacy diagnostics environment. And it's Monday, so you bolt out of bed, and you skip the coffee, and you head straight to work, right into the war room. And before you finish the initial briefing, someone walks in and says, "We got another one," another cybersecurity incident at the same time. A different system, different infrastructure, likely a different root cause, but now you're spinning up another response team all on the same day. And this isn't a story about one breach. It's about today's reality that cybersecurity events have stopped being a single incident, and many times they have become parallel incidents. And all of that springs from the reality that our environment is now driven by a portfolio of problems. The public's image of a cyber attack usually tracks as one dramatic event, a single group of cyber thugs that are attacking a health system or a healthcare partner. There's a ransom note, and then there's a big recovery effort to get everything back online. That's kind of the way these things are usually reported, but our reality continues to change. Healthcare organizations are often large enterprises. They're operating thousands of applications. Even the smallest places run several hundred applications. There are multiple cloud providers and hundreds of vendors, and we're buying and selling hospitals or practices. And generally, there's tech debt. Ugh, the tech debt, right? Legacy apps, legacy infrastructure, older medical devices, a lot of it no longer supported by vendors, so there's no software updates, and there are certainly no security patches. And then we're laying on AI and the AI capabilities and the agents, not just in our health systems, but every one of our hundreds of partners, all those folks we're connected to, almost all of them have the same challenges, all those things I just described. So that's today's attack surface on steroids. So nobody should be surprised that the story I started the podcast with about two cyber events going on at the same time, that's actually a real story. Abbott Labs recently fought two cyber battles at the same time. One involved legacy cancer diagnostic infrastructure, and the other one involved LabCentral, which is a customer-facing hosted portal. Different technologies, different exposure, different investigations, both at the same time. But to everyone outside the company, it's just Abbott got hacked. But that's the part that's changed because since the Abbott story broke, I've had several conversations with security folks across the industry who tell me this happens more often than you think. Our risks continue to change. Our exposures continue to change. And it's now more likely than ever that your CISO and CTO and apps team and a sig- a significant number of other teammates w- are all gonna be working on multiple cyber incidents at the same time. So your question for the team this week, are we ready? Have we practiced this scenario? Can you show me? Because the reality is this, our future will likely be one where we have to manage multiple security incidents at the same time. That's it for today's Two Minute Drill. Thanks to Fortified Health Security for sponsoring today's podcast. Drop me a note. I'd love to hear what you're thinking or what you're working on. I'm drex@229project.com. Thanks for being here. Stay a little paranoid, and I will see you around campus





