Skip to main content
The Markets by Proactive
Go to Proactive UK
Proactive UK has moved. Proactive’s coverage of London’s small caps continues on proactiveinvestors.com Go there →
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Coverage of London’s small caps continues on proactiveinvestors.com
Go to Proactive UK
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK

Pharma & Biotech

Healthcare cybersecurity risks grow as sector faces critical gaps

Cybersecurity threats are a growing concern for the healthcare industry, as more digital systems expose sensitive patient data to cybercriminals. Despite efforts to strengthen defences, a new report by Fortified Health Security reveals that while progress has been made in key areas, critical vulnerabilities remain.

These persistent gaps could have serious financial and reputational consequences for healthcare organisations — and, by extension, their investors. The Fortified report outlines both the advancements and risks that investors in biotech and healthcare companies need to be aware of in a rapidly evolving cybersecurity landscape.

Progress on cybersecurity maturity

Fortified Health Security's 2025 Mid-Year Horizon Report provides a snapshot of healthcare cybersecurity at the midpoint of 2025. While there are positive developments in several key areas, critical gaps remain.

One of the most significant improvements is in governance, with healthcare organisations now treating cybersecurity as a core part of their governance structures. Many have introduced dedicated committees for information security and privacy.

“Leaders no longer treat cybersecurity as an afterthought; it’s becoming a formal part of governance structures,” the report noted.

In incident response, organizations are now treating cyber incidents as enterprise-wide challenges rather than isolated IT issues. Many have integrated their incident response plans with disaster recovery and business continuity strategies. “Leaders are increasingly aligning their incident response plans with broader disaster recovery and business continuity strategies,” the report said.

It highlighted improvements in risk assessments, with many healthcare organisations adopting NIST-based maturity assessments. These frameworks provide a more comprehensive view of cybersecurity posture, allowing organisations to assess their strengths and weaknesses. “Risk is now recognised as an enterprise-wide responsibility, extending beyond the IT department and into the core organisational strategy and governance models,” the report’s authors wrote.

Persistent vulnerabilities remain

Despite the progress, several critical vulnerabilities remain within the healthcare sector that could expose organisations to significant risks.

One major concern is the lack of a unified risk management strategy. Many healthcare organisations still struggle to define their risk tolerances and assign clear responsibilities. This fragmentation leads to inconsistent practices and delays in decision-making, which can leave organisations exposed to attacks.

Another issue is supply chain risk management. While some healthcare organisations are integrating third-party risk management into procurement decisions, many treat it as a secondary issue, leaving them vulnerable to cyberattacks targeting weaknesses in the supply chain.

“While some healthcare organizations make Third-Party Risk Management (TPRM) part of procurement decisions, many still treat it as a checkbox activity,” according to the report.

In asset management, many healthcare organisations lack comprehensive, up-to-date inventories of their assets, especially medical devices that process sensitive patient data, the report warned. “Without a complete and up-to-date inventory, organisations lack a clear understanding of what they protect, making effective risk management nearly impossible.”

Emerging technologies: AI and attack surface monitoring

The report also highlights emerging technologies that could help mitigate cybersecurity risks. Attack Surface Monitoring (ASM), which provides visibility into an organization’s external digital footprint, is gaining traction in healthcare.

“ASM evaluates what your organization looks like from the outside, or your perimeter exposure in near-real-time,” T.J. Ramsey, senior director, threat operations at Fortified Health Security, explained in the report.

Artificial Intelligence (AI), another trend gaining ground, is being used to streamline threat detection and data analysis, allowing organisations to identify and respond to risks more quickly. However, Preston Duren, VP of Threat Services at Fortified, stressed that “AI handles specific tasks quickly, but it still falls short in the adaptability and context awareness that human analysts rely on to make the right call during alerts, something that’s critical in healthcare environments.”

Integrating cybersecurity into business strategy

The Fortified Health Security report highlights the need for healthcare organisations to adopt a more proactive approach to cybersecurity. The progress made so far is promising, but organisations must treat cybersecurity as a core business responsibility, embedded into every aspect of their operations.

For investors, this means evaluating companies not only on their clinical performance but also on the robustness of their cybersecurity strategies.

“Real progress happens when organisations teach people to see through a different lens, where every story, simulation or phishing test becomes a chance to build smarter, more secure habits,” the report said. “The organisations that will lead in the years ahead are those embedding cybersecurity into decision-making, culture and care delivery.”

Advertisement
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK