Skip to content
MedusindMedusind

Follow us

© 2026 Medusind. All rights reserved

Search
  • Cybersecurity

The Next Cyber Threat May Not Look Like a Cyber Threat

Read time: 4 minutes

By Jigar Shah, Chief Information Security Officer at Medusind

Every October, Cybersecurity Awareness Month gives us an opportunity to talk about passwords, phishing, suspicious links, and protecting information.

Those things still matter. But this year, I want to talk about something bigger.

Cybersecurity is changing – which means the way we think of it must change as well.

The next cyberattack may not arrive as an obviously suspicious email from someone you have never heard of.

  • It could look like a casual email from a colleague.
  • It could sound like the voice of someone you know.
  • It could be a text message asking you to urgently resolve a business issue by EOD.
  • It could be an AI-generated document that looks completely legitimate.

A separate risk arises when someone uploads sensitive company or patient information into an AI tool without authorization for that specific use and without regard for required privacy, security, and contractual safeguards.

Welcome to cybersecurity in the age of AI.

Today, we’ll discuss some of the ways that AI is changing cybersecurity, and how medical and dental leaders can adjust their mindset to stay ahead of this rapid evolution.

AI is changing both sides of cybersecurity🔗

Artificial Intelligence is creating tremendous opportunities for us and for healthcare. It can support in automating administrative work, analyzing information and allowing us to serve our customers more effectively alongside human review appropriate to the task.

However, it’s important to remember there are two sides to every coin, and the same technology that is so useful to us is also available to our attackers.

AI can help cybercriminals:

  • Create more convincing phishing messages
  • Impersonate trusted individuals
  • Automate and systematize reconnaissance
  • Find vulnerabilities faster
  • Scale attacks that previously required significant time and expertise.

The 2026 Verizon Data Breach Investigations Report illustrates how quickly this landscape is changing. Across its broader dataset, they found that vulnerability exploitation became the leading initial breach vector, surpassing credential abuse.

For healthcare, that finding is particularly relevant. Verizon's 2026 healthcare analysis found the human element present in 54% of healthcare breaches, while third parties were involved in 32%. Exploited vulnerabilities, phishing, and credential abuse all remain important (and frequently utilized) paths into healthcare organizations.

There is another shift worth noting. Attackers are increasingly meeting us where we live the most: on our phones. Verizon reports that simulated mobile social-engineering attacks using channels such as text and voice achieved click rates 40% higher than email-based attacks.

That means the old advice of simply “don't click suspicious emails" is no longer enough.

Our cybersecurity priorities are changing🔗

Historically, cybersecurity programs were built primarily around protecting networks, devices, applications, and data.

Those remain fundamental. But as we move towards 2027, our security model must increasingly protect identity, data, AI, third parties, and business decisions. That means our priorities must continually evolve.

  • We must strengthen identity and access controls so the right people have the right access.
  • We must regularly identify and remediate vulnerabilities based on risk before attackers can exploit them.
  • We must understand the security posture of the vendors and partners connected to our ecosystem.
  • We must govern how AI is used and what information it can access.
  • We must continue protecting endpoints, applications, cloud environments, and sensitive healthcare information data.
  • And increasingly, we must build cyber resilience - not only to prevent an attack, but to improve detection, response, and recovery and support continuity of critical services.

Technology will play an enormous role in all of this, but technology alone will never be enough. Most organizations have also hired cybersecurity professionals whose job is to protect the company. However, the true measure of success in fighting against AI-enabled cybercrime isn’t whether you can hire great people and use innovative technology – it’s whether your organization can truly build a culture of cybersecurity.

Preparing for 2027 starts today🔗

I am often asked what the biggest cybersecurity threat will be next year. AI-powered attacks, ransomware, third-party compromise, identity attacks, software vulnerabilities, and deepfakes are all enough on their own to keep any security professional up at night. However, the true answer is that we need to prepare for all of them - and we should expect them increasingly to interact.

The 2026 DBIR, for example, reports ransomware in 48% of breaches across its dataset and vulnerability exploitation as the initial vector in 31%, with generative AI augmenting numerous attacker techniques.

Those figures are frightening, but fortunately, the fundamentals we’ve relied on for years still work.

  • Strong identity protections
  • Secure systems
  • Timely patching
  • Responsible data handling
  • Good judgment
  • Verification
  • Rapid reporting
  • Resilient operations

AI does not make those principles obsolete. It makes them more important.

At the end of the day, cybersecurity is ultimately about trust. Patients and clients trust healthcare organizations and their service providers to handle sensitive information responsibly.

Our job is to protect that trust. Cybersecurity Awareness Month is a reminder that security isn't something the cybersecurity team does to the organization. It is something we build together.