Industry executives and experts share their predictions for 2025. Read them in this 17th annual VMblog.com series exclusive.
By Joel Burleson-Davis, SVP Worldwide Engineering, Cyber at Imprivata
Cyberattacks
targeting organizations like American Water and Change Healthcare have posed significant challenges to our critical
infrastructure and healthcare sectors this year. In fact, attacks on U.S.
utilities surged by 70%, disrupting essential services and operations. While these
incidents have caused considerable damage, they also offer key lessons we must
learn from to better prepare for the future. As we look ahead to 2025, here are
some critical takeaways to strengthen our defenses and prevent similar attacks
in the year to come.
Identity security challenges in healthcare will make way
for a passwordless future. A new GAO report revealed that the Department of
Health and Human Services has faced challenges mitigating cybersecurity risks
in the healthcare sector. One of the biggest struggles has been identity
security, largely attributed to hospitals balancing large workforces, contractors,
billing systems, strict compliance and privacy regulations, and the need for
quick, always-on access to patient data across multiple shared devices. While
healthcare remains a top target for breaches, next year I anticipate an
acceleration in the shift toward passwordless, whether it is adopting
passwordless technology or preparing to adopt it, authentication across the
healthcare industry. Passwordless authentication is an important step along the
path to enhanced security and workflow efficiency, moving organizations from
password-based access to fully passwordless workflows over time. For example,
masking passwords from users significantly reduces cyber risks and improves
clinical workflows today, getting rid of the password entirely only improves
that benefit. By adopting passwordless authentication tailored to diverse
healthcare workflows, organizations can protect sensitive data, boost
operational efficiency, and enhance patient care.
Nation-state attacks are poised to become the greatest
threat to critical infrastructure, growing in frequency and sophistication. The sophisticated network of
malicious actors officially and unofficially, being sponsored by adversarial
nation-states like Russia, China, and Iran often conduct reconnaissance to
identify vulnerabilities and entry points within systems like healthcare,
water, energy, and telecommunications, often taking advantage of the
interconnected systems of devices, technologies, and affiliated organizations
in these industries rely on, leveraging them in an attack designed to inflict
broad-scope pain and disruption. Such attacks can lead to severe
consequences, from disruptions to providing care in both acute care facilities
like a major hospital as well as other ancillary avenues of care for those in
need, to supply water, food, energy and communication to a broad population.
These attacks underscore the risk of significant damage during geopolitical
conflicts, where these vulnerabilities could be exploited to cause widespread
chaos and harm at a critical time when we need them most.
Healthcare systems and critical infrastructure will treat
cybersecurity, particularly around supply chain and third-party
dependencies, as a non-negotiable
imperative. The vulnerability of healthcare systems to cyberattacks has been
highlighted by recent incidents where hospital operations were disrupted,
leading to delays in medical treatments which incur risks to patient safety and
jeopardize the financial stability of the organizations providing care.
Although these attacks, often originating from a third
party compromise, are aimed at systems and data, particularly critical systems
and sensitive data, they are ultimately a threat to public health in the
near-term, undermining our ability to provide care, as well as the long-term by
undermining our trust and confidence in these institutions.
Simultaneously, attacks on power grids,
water systems, and communication networks can also lead to near-term and
long-term disruption through economic damage, creating public safety hazards,
and destabilizing essential services, affecting millions of people. The threat
to critical infrastructure underscores the need for robust cybersecurity
measures across both first and third-parties paired with the means to enact
them, increased public awareness, and cooperation between government and
private sectors to enhance resilience against these
threats. This balanced approach is crucial in mitigating the risks posed by
cyberattacks and ensuring the safety and well-being of the public now and into
the future.
As the new year begins, it is crucial for
organizations supporting the critical workforce to prioritize cybersecurity.
Recent attacks have highlighted the severe disruptions they cause, often
threatening essential, life-saving operations. It is no longer a question of if
these attacks will occur, but when. Being prepared is not optional – it is essential for safeguarding
operations and the vital services that depend on them.
##
ABOUT THE AUTHOR
Joel Burleson-Davis is the SVP of Worldwide
Engineering, Cyber at Imprivata where he’s responsible for
building, delivering, and evolving the suite of Imprivata’s cybersecurity
products that include Privileged Access Management, Privacy Monitoring, and
Identity Governance solutions.
Prior to joining Imprivata, Joel was Chief
Technical Officer at SecureLink, the leader in critical access management for
organizations in need of advanced solutions to secure access to their most
valuable assets, including networks, systems, and data.
While at SecureLink, Joel was responsible for
the overall technology and operational strategy and execution including
direction and oversight for Product Development, Quality Assurance, IT and
Cybersecurity Operations, Compliance, and Customer Success.






