
A recent breach at Stryker, in which hackers broke into the company’s systems via stolen administration credentials, highlights the importance of identity systems in modern enterprise. The identity layer encompasses everything from application access to remote connections, and when these systems are compromised, daily operations can come to a halt.
Employees can’t log in, applications can’t start, and administrative access becomes impossible. For this reason, identity has become the modern security perimeter, stretching from Active Directory into the cloud through platforms such as Entra ID, Okta, and Ping Identity.
According to the report, identity weaknesses were part of nearly 90% of investigations. A recent Semperis survey of 1,100 IT and security professionals found that 75% of healthcare organizations expect artificial intelligence to make identity attacks more common.
However, only 27% are very confident they could recover if an AI agent exposed admin credentials. The Stryker incident demonstrates the consequences of an identity-driven attack, which can be widespread and have significant operational disruptions and financial consequences.
The fallout from an identity-based attack doesn’t end with the initial target. Modern enterprises are increasingly interconnected, and with national supply chains dependent on continuous service delivery, one compromised identity can set off a chain reaction of disruption beyond the original breach.
In healthcare, those disruptions can jeopardize patient care. The effects spiral when bad actors move deeper into critical systems, but the dangers start much earlier when security teams blind themselves to unseen identity vulnerabilities.
Common attack vectors include stolen credentials and weaknesses in platforms such as Active Directory and cloud identity services. Without visibility into identity systems, security teams can’t easily spot suspicious activity or initiate crisis response processes to halt and contain threats.
Related: Nutanix Report Reveals Healthcare Cloud Trends
Companies that adopt an “assume breach” mindset will be better prepared to respond to threats when they occur. Resilience starts with assuming identity will be targeted, but it becomes real when organizations can spot weakness early, rehearse response, and remediate faster.
This is true cyber resilience. Operating with an “assume breach” approach also means staying vigilant. If a compromise is detected in one portion of a network, it’s wise to assume there may be others still hidden.
Quick containment, investigation, and response are key to limiting impact and maintaining trust in high-risk environments. Healthcare organizations should also monitor unauthorized changes occurring in their Active Directory infrastructure and have real-time visibility into changes to network accounts and groups.
Prioritizing true identity resilience will stop the chain reaction at its source and increase an organization’s overall security. In the middle of this complex issue, it’s clear that healthcare organizations need to be prepared for the potential consequences of an identity-based attack, and taking a proactive approach to identity resilience is essential.
The potential for the weaponization of AI agents inside healthcare systems only compounds the challenge facing defenders. Semperis‘s research also found that only two-thirds of healthcare organizations fully register, authenticate, and authorize AI identities — leaving a significant portion of the sector with limited visibility into the agents operating on their networks, which can drive up healthcare costs.
For healthcare organizations, one compromised identity can lead to disruptions in patient care, and disruptions across a vast network of companies that feed into an organization’s supply chain.
As the healthcare industry continues to evolve, it’s likely that identity resilience will become an even more critical component of overall cybersecurity strategy.