The Cybersecurity Gaps Attackers Are Counting On

Oct 1, 2026

October is Cybersecurity Awareness Month. CISA’s 2026 theme,  Building a Cyber Strong America, is a reminder that cybersecurity stopped being just an IT department problem a long time ago. For healthcare practices, law firms, dental offices, and any organization handling sensitive data, it is a business continuity issue and a legal liability that does not negotiate.

We are not going to spend this post telling you to use a strong password. You know that. What we are going to do is tell you where businesses — including ones that think they have this handled — are leaving the doors open right now.

Healthcare organizations reported over 700 data breaches in 2023 through HHS’s breach portal alone. The attack vectors are predictable. The gaps below are not theoretical. They are the ones we see when we audit environments that believed they were covered.

 

Gap 1: Multi-Factor Authentication That Isn’t Covering Everything

Multi-factor authentication is one of the most effective, accessible security controls available — and one of the most inconsistently deployed. Organizations turn it on for the primary email platform and call it done. Meanwhile, remote access tools, cloud file storage, billing systems, EHR portals, and practice management software remain single-factor.

Credential-based attacks — stolen or phished passwords used to log in as a legitimate user — are among the most common entry points for ransomware in healthcare. Attackers don’t need to break through your firewall if they can just log in. A single unprotected system is enough to get a foothold, and from there, lateral movement across your network is often straightforward.

The fix is straightforward: audit every external-facing system your team accesses — not just the obvious ones. Remote desktop tools, cloud backup consoles, insurance portals, AI tools adopted this year. MFA should cover all of them. If you are not sure what is in your environment, a vulnerability scan will tell you.

 

 

Gap 2: Phishing Has Gotten Better Than Your Training

The phishing simulation your team completed two years ago was built around recognizable tells: generic greetings, off-brand logos, obvious grammar errors, suspicious links. Those still exist, but they are no longer where the meaningful risk lives.

AI-generated phishing emails in 2026 reference your organization by name, address staff by their correct job titles, match your internal communication tone, and arrive from look-alike domains that clear most spam filters. Voice cloning attacks allow bad actors to impersonate your CEO or a known vendor over the phone. QR codes embedded in printed mail bypass email filters entirely.

Awareness training that has not been updated in the last 12 months is training staff to recognize the threat landscape of 2023 — not what is hitting inboxes right now. The answer is not more training. It is current training, simulations built around today’s attack patterns, with clear protocols that tell staff what to do when something looks off.

 

Gap 3: Patch Management That Happens When Someone Remembers

When a software vulnerability is publicly disclosed alongside a patch, a clock starts. Attackers are actively scanning for organizations that have not applied the fix. In 2025 and 2026, the median time between public disclosure and active exploitation in the wild has dropped to days — sometimes hours for high-severity vulnerabilities in widely used software.

Most organizations know patching matters. The failure mode is not ignorance — it is that manual patching in a busy environment gets deprioritized, delayed, or inconsistently applied across devices. A workstation added during a busy stretch. A piece of networking equipment that runs fine and gets ignored. A software package on a single staff member’s laptop that was never enrolled in the patch management system.

Managed patching — applied systematically across every device in your environment, verified, and reported — closes that window. ICS manages patching as part of our core managed IT offering, so nothing falls through the gap when your team is stretched.

 

 

Gap 4: Third-Party Vendor Access With No Ongoing Oversight

EHR support vendors. Billing and revenue cycle partners. Cloud service providers. The AI scheduling tool someone on your team started using in April. The IT company that set up your system three years ago and whose VPN credentials were never revoked. Each one of these is a potential entry point into your environment if their access is not actively managed.

HIPAA’s Security Rule requires covered entities to manage third-party risk through vendor oversight and executed Business Associate Agreements. Most healthcare practices have the paperwork. Fewer have the actual access controls to match. A vendor granted broad remote access during an EHR implementation two years ago that was never scoped down after go-live is a gap no BAA on file will close.

For organizations running EHR platforms like Epic, NextGen, or Greenway, vendor access management is a specific configuration task — not just a policy question. Our team can walk through what that looks like in your environment.

 

 

What to Actually Do About It

None of these are multi-quarter projects. Each can be scheduled and completed within a few weeks — and each one closes a gap that attackers are actively scanning for. Start here:

  • Audit MFA deployment. Verify coverage on every external-facing system, not just email.
  • Review phishing training. When was it last updated? Is it built around current attack patterns?
  • Run a patch status report. Every device, every piece of network equipment, every software package.
  • Pull your vendor access list. Who has active credentials, what can they reach, and is each still appropriate?
  • Verify your BAAs. Especially for any AI tools adopted in the last 12 months. Does the agreement cover how the vendor is actually using your data?

 

 

The Bottom Line

The gaps above are not novel. They are consistent, predictable, and closeable. The organizations that come out ahead are not the ones with the largest security budgets — they are the ones that treat these gaps as a maintenance task rather than a future project.

ICS has been providing managed IT and cybersecurity services for healthcare practices, dental offices, law firms, and businesses across Mississippi for over 20 years. If you want to run through this checklist against your actual environment,  we are glad to help.

 

Book a Free Consultation >