Skip to content
MarketScale
‹ Back to IndustriesHealthcare

New Penalties is a Push to Mitigate Cybersecurity Threats in Telecommunications and Healthcare

Regulators are introducing new penalties targeting cybersecurity weaknesses in telecommunications and healthcare, two sectors considered critical infrastructure. Security experts debate whether financial penalties are sufficient to drive meaningful improvements given the complexity and scale of vulnerabilities. The discussion centers on whether enforcement mechanisms can keep pace with rapidly evolving cyber threats.

This story was produced through MarketScale. See how Healthcare teams put it to work with Executive Thought Leadership.

Promoted content from Experts Talk on MarketScale.

By Mike Isbitski · CybersecurityExperts TalksHealthcareMichael Isbitski
Share

Key takeaways

01

New regulatory penalties are being introduced to address cybersecurity gaps in telecom and healthcare sectors.

02

Security experts question whether penalties alone are an effective deterrent given the scale and sophistication of modern cyber threats.

03

Critical infrastructure sectors face unique challenges in closing security gaps due to legacy systems, regulatory complexity, and resource constraints.

Cybersecurity has emerged as a critical issue in telecommunications and healthcare—two industries intertwined as essential services. With both sectors recognized as critical infrastructure, the consequences of cyber attacks can be far-reaching, impacting everything from individual privacy to national security. While recent regulatory changes are aiming to tighten security protocols, it also raises questions about the adequacy and effectiveness of current security practices.

How do the challenges and strategies in cybersecurity compare between telecommunications and healthcare? What impact do new regulations have on these critical industries?

Discussing the subject for an "Experts Talk" roundtable on cybersecurity in healthcare, Michael Isbitski, Director of Cybersecurity Strategy at Sysdig, provided some valuable insight into these pressing issues. Having nearly two decades of experience in telecommunications, Isbitski connected the parallels and divergences in cybersecurity challenges facing the two sectors. He further gave a comprehensive understanding of recent regulations and offered a clear picture of how the cybersecurity landscape is evolving.

Several takeaways from Isbitski's discussion include:

  • The ways cyber attackers quickly evolve, posing continuous threats to critical infrastructure sectors such as telecommunications and healthcare.
  • Why the interconnected nature of modern industries means that compromising one can lead to cascading failures across others, highlighting the need for robust security in telecommunications as a backbone.
  • Recent cybersecurity regulations across various countries and sectors are aligning more closely with long-standing security practices, emphasizing better access control and intrusion monitoring.
  • The critical nature of cybersecurity and how it often competes with financial constraints within organizations, leading to potential vulnerabilities unless regulatory penalties enforce stricter compliance.
  • How so many organizations struggle with insufficient staffing and budget for cybersecurity, which can hinder their ability to effectively manage and mitigate risks.

Isbitski's perspective shed some light on the importance of adopting and adapting to these new regulations to enhance the security and resilience of both telecommunications and healthcare industries.

Video TranscriptExpand ↓

Yeah. And our attackers pivot very quickly too. You know, I'd say from my perspective and I worked for telco for close to twenty years, which is now critical infrastructure provider. Right? And then they become the interconnect to all other verticals like health care or utilities. Right? So if you can attack the communications, then you can now bring down anything. So then you start rabbit holing into that whole topic of resiliency. But, you know, my career at that telco, very difficult. Right? A lot of the things that Davey's hitting on. Right? You're you're always fighting for that budget. You're fighting for the headcount. You you know the things that you have to do for your security program, but, you just don't have the teeth. So one of the things that I like that has been a more recent trend is kind of the wave of cybersecurity regulations that are hitting, things like EU's, NIST two directive, the US national cybersecurity strategy, SEC cybersecurity disclosure rules. And there you know, there's a lot of regs. Right? And I could probably spend the next ten minutes just listing all of them. Right? Every nation state's gonna have their own and then verticals are gonna have their own, implementations of them. But they're saying a lot of the things that security practitioners have been saying for decades at this point. Right? Like, we have to be better at access control. We have to, monitor for intrusions. Like, what does our threat detection and response capability look like? Can we detect things timely, and then is that disclosed? How do we coordinate vulnerability response? So the regulations are finally starting to catch up with that. But then in tandem with that is also penalties. Right? And that that's the reality. Right? We are talking about businesses, and we're kind of in weird macroeconomic times. Although, hopefully, coming out of that, Right? But globally, things were very suppressed. So most organizations were scaling back all all of their spend. Right, whether it was IT or security. And and, usually, security is first to go. Right? Like, well, let's be honest. They're not revenue generating. The risk is just accepted by organizations. So now regulation kind of has more of that teeth. So if you're making sacrifices on your risk management approach, whichever aspect that might be, maybe it's access control, maybe it's threat detection, there's multiple pieces. Right? Patching, how are you managing supplier risk? All these are components of that. If you're making sacrifices there, it has to be disclosed, to the regulatory body or maybe the public. And then if you have a failure, like in the case of an incident or breach, there might be financial repercussions to that. Right? Your leadership might be at fault. Potentially, you can't practice. Right? Maybe there's criminal criminal penalties on the table. So that looks much different than it did twenty years ago. So as a practitioner and a a leader, right, I was managing or leading the application security efforts a component of it at, Verizon, and that was a large team. Right? Many organizations don't even have adequate staff. Right? Their security are are juggling all of the security roles. But I never had enough, people, and I never had enough money. And I was constantly fighting those battles, and it's exhausting. So, yeah, as a practitioner and leader and advisor, it's like, this is great. Right? This is music in my ears. We need to ride that wave because that's gonna improve all industries, certainly certainly health care. But, yeah, the tech hasn't really changed. We're talking about a lot of the same problems that just kind of got swept under the rug, unfortunately.

Experts Talk

Part of this channel

Experts Talk

Industry experts debate the ideas that drive B2B decisions.

Visit the channel →

About the author

MI
Mike Isbitski

Healthcare: are you visible to AI?

Before they reach out, Healthcare buyers ask AI engines which vendors to trust. See how AI describes your company today, and where competitors show up instead.

Free workspace

You just read one expert. Imagine publishing your whole team.

This article was produced through MarketScale. Create a free workspace and turn your own team's expertise into articles, video, and social posts. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale Studio workspace
One video edit a month, on us
AI writing, editing, and publishing tools
In-platform coaching to learn the system

More Healthcare Insights

Healthcare's digital skills gap: why existing competency tools aren't built for the full workforce

Healthcare's digital skills gap: why existing competency tools aren't built for the full workforce

Reviews have revealed that current competency tools in healthcare are inadequate for measuring and developing digital skills among both clinical and public health teams. These tools fail to address the comprehensive needs required for the evolving digital landscape in healthcare. Addressing this skills gap is crucial for the effective digital transformation of health systems.

  • 01Current digital competency tools in healthcare do not adequately cover the full workforce.
  • 02Improved measurement and development of digital skills are needed across clinical and public health teams.
  • 03Addressing the digital skills gap is essential for successful healthcare transformation.

Jul 19, 2026

St. Kitts and Nevis launches national digital health platform covering 51,000 citizens

St. Kitts and Nevis launches national digital health platform covering 51,000 citizens

St. Kitts and Nevis have introduced a national digital health platform to enhance healthcare delivery for its 51,000 citizens. The platform integrates electronic health records, AI decision support, and facilitates health information exchange throughout the region's healthcare ecosystem.

  • 01St. Kitts and Nevis's digital health platform serves 51,000 citizens.
  • 02The platform incorporates electronic health records and AI decision support.
  • 03Health information exchange is central to the region's healthcare integration.

Jul 19, 2026

Clinical AI at a crossroads: skill decay, robotic surgery, and the wearable data frontier

Clinical AI at a crossroads: skill decay, robotic surgery, and the wearable data frontier

The article discusses the impact of three converging developments on the use of AI in healthcare: skill decay, robotic surgery, and wearable data analytics. These advancements are prompting health system operators to reevaluate the deployment and management of AI in clinical environments. The focus is on how AI is integrated, governed, and assessed in healthcare settings.

  • 01Health systems are rethinking AI deployment due to the impact of skill decay, robotic surgery, and wearable data.
  • 02The integration of AI in healthcare requires reevaluation of governance and evaluation processes.
  • 03Robotic surgery and wearable data are key areas influencing AI usage in clinical settings.

Jul 18, 2026

Explore More Healthcare Insights

Read more expert perspectives from across Healthcare.

Browse Healthcare Hub

About the Expert

MI
Mike Isbitski

Director of Cybersecurity Strategy at Sysdig

Mike Isbitski is a cybersecurity strategist with extensive experience in application security, cloud-native security, and regulatory compliance. He has held advisory and strategy roles at several security-focused technology companies, including Sysdig and42Crunch. He regularly speaks and writes on topics including zero trust, API security, and security policy.

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Healthcare and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512