Skip to content
MarketScale
‹ Back to IndustriesHealthcare

New Penalties is a Push to Mitigate Cybersecurity Threats in Telecommunications and Healthcare

Regulators are introducing new penalties targeting cybersecurity weaknesses in telecommunications and healthcare, two sectors considered critical infrastructure. Security experts debate whether financial penalties are sufficient to drive meaningful improvements given the complexity and scale of vulnerabilities. The discussion centers on whether enforcement mechanisms can keep pace with rapidly evolving cyber threats.

This story was produced through MarketScale. See how Healthcare teams put it to work with Executive Thought Leadership.

Promoted content from Experts Talk on MarketScale.

By Mike Isbitski · CybersecurityExperts TalksHealthcareMichael Isbitski
Share

Key takeaways

01

New regulatory penalties are being introduced to address cybersecurity gaps in telecom and healthcare sectors.

02

Security experts question whether penalties alone are an effective deterrent given the scale and sophistication of modern cyber threats.

03

Critical infrastructure sectors face unique challenges in closing security gaps due to legacy systems, regulatory complexity, and resource constraints.

Get featured

Want to get featured in MarketScale Healthcare?

Create a free MarketScale workspace and get your company's expertise featured across our Healthcare coverage. No credit card, no demo required.

Start free

Cybersecurity has emerged as a critical issue in telecommunications and healthcare—two industries intertwined as essential services. With both sectors recognized as critical infrastructure, the consequences of cyber attacks can be far-reaching, impacting everything from individual privacy to national security. While recent regulatory changes are aiming to tighten security protocols, it also raises questions about the adequacy and effectiveness of current security practices.

How do the challenges and strategies in cybersecurity compare between telecommunications and healthcare? What impact do new regulations have on these critical industries?

Discussing the subject for an "Experts Talk" roundtable on cybersecurity in healthcare, Michael Isbitski, Director of Cybersecurity Strategy at Sysdig, provided some valuable insight into these pressing issues. Having nearly two decades of experience in telecommunications, Isbitski connected the parallels and divergences in cybersecurity challenges facing the two sectors. He further gave a comprehensive understanding of recent regulations and offered a clear picture of how the cybersecurity landscape is evolving.

Several takeaways from Isbitski's discussion include:

  • The ways cyber attackers quickly evolve, posing continuous threats to critical infrastructure sectors such as telecommunications and healthcare.
  • Why the interconnected nature of modern industries means that compromising one can lead to cascading failures across others, highlighting the need for robust security in telecommunications as a backbone.
  • Recent cybersecurity regulations across various countries and sectors are aligning more closely with long-standing security practices, emphasizing better access control and intrusion monitoring.
  • The critical nature of cybersecurity and how it often competes with financial constraints within organizations, leading to potential vulnerabilities unless regulatory penalties enforce stricter compliance.
  • How so many organizations struggle with insufficient staffing and budget for cybersecurity, which can hinder their ability to effectively manage and mitigate risks.

Isbitski's perspective shed some light on the importance of adopting and adapting to these new regulations to enhance the security and resilience of both telecommunications and healthcare industries.

Video TranscriptExpand ↓

Yeah. And our attackers pivot very quickly too. You know, I'd say from my perspective and I worked for telco for close to twenty years, which is now critical infrastructure provider. Right? And then they become the interconnect to all other verticals like health care or utilities. Right? So if you can attack the communications, then you can now bring down anything. So then you start rabbit holing into that whole topic of resiliency. But, you know, my career at that telco, very difficult. Right? A lot of the things that Davey's hitting on. Right? You're you're always fighting for that budget. You're fighting for the headcount. You you know the things that you have to do for your security program, but, you just don't have the teeth. So one of the things that I like that has been a more recent trend is kind of the wave of cybersecurity regulations that are hitting, things like EU's, NIST two directive, the US national cybersecurity strategy, SEC cybersecurity disclosure rules. And there you know, there's a lot of regs. Right? And I could probably spend the next ten minutes just listing all of them. Right? Every nation state's gonna have their own and then verticals are gonna have their own, implementations of them. But they're saying a lot of the things that security practitioners have been saying for decades at this point. Right? Like, we have to be better at access control. We have to, monitor for intrusions. Like, what does our threat detection and response capability look like? Can we detect things timely, and then is that disclosed? How do we coordinate vulnerability response? So the regulations are finally starting to catch up with that. But then in tandem with that is also penalties. Right? And that that's the reality. Right? We are talking about businesses, and we're kind of in weird macroeconomic times. Although, hopefully, coming out of that, Right? But globally, things were very suppressed. So most organizations were scaling back all all of their spend. Right, whether it was IT or security. And and, usually, security is first to go. Right? Like, well, let's be honest. They're not revenue generating. The risk is just accepted by organizations. So now regulation kind of has more of that teeth. So if you're making sacrifices on your risk management approach, whichever aspect that might be, maybe it's access control, maybe it's threat detection, there's multiple pieces. Right? Patching, how are you managing supplier risk? All these are components of that. If you're making sacrifices there, it has to be disclosed, to the regulatory body or maybe the public. And then if you have a failure, like in the case of an incident or breach, there might be financial repercussions to that. Right? Your leadership might be at fault. Potentially, you can't practice. Right? Maybe there's criminal criminal penalties on the table. So that looks much different than it did twenty years ago. So as a practitioner and a a leader, right, I was managing or leading the application security efforts a component of it at, Verizon, and that was a large team. Right? Many organizations don't even have adequate staff. Right? Their security are are juggling all of the security roles. But I never had enough, people, and I never had enough money. And I was constantly fighting those battles, and it's exhausting. So, yeah, as a practitioner and leader and advisor, it's like, this is great. Right? This is music in my ears. We need to ride that wave because that's gonna improve all industries, certainly certainly health care. But, yeah, the tech hasn't really changed. We're talking about a lot of the same problems that just kind of got swept under the rug, unfortunately.

Experts Talk

Part of this channel

Experts Talk

Industry experts debate the ideas that drive B2B decisions.

Visit the channel

Your experts belong here

Every story in MarketScale Healthcare starts with a company putting its clinicians, service-line leaders, and field engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Service-line buyers vet vendors quietly, and your clinicians become the proof they find while doing it.

Get your team featuredSee how it works15 minutes, straight to a calendar.

About the author

MI
Mike Isbitski

Follow Healthcare Insights

Get new expert content in your inbox.

Healthcare: are you visible to AI?

Before they reach out, Healthcare buyers ask AI engines which vendors to trust. Explore how your experts, customers, and partners can become useful content for buyers and AI search.

Free plan

You just read one Healthcare expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your clinicians, service-line leaders, and field engineers into the articles, video, and social content Healthcare buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale workspace, up to 10 people
One professional video edit a month for qualifying companies
Media requests to your crowd, remote recording, AI writing tools
$0, no credit card, nothing that expires

More Healthcare Insights

Most reprocessing audit gaps trace back to training, turnover and leadership

Most reprocessing audit gaps trace back to training, turnover and leadership

Joint Commission findings on its reprocessing standard point mostly to training, turnover, leadership and missing ownership, not sterilizers. CDC epidemiologists and a 2019 review add cleaning verification and manufacturer instructions as the steps to watch. Audit people and process steps as closely as the autoclave.

  • 01Of the Joint Commission's list of reasons hospitals miss reprocessing standard IC.02.02.01, at least eight concern people, priorities and management, so competency records and a named process owner belong in the audit as much as sterilizer logs.
  • 02A structured audit tool that scores compliance step by step, as a 2020 BMC Health Services Research study did across 189 reprocessing cycles, shows where training hours should go; the Nepal hospitals scored best on cleaning and storage and worse on the steps between.

Sep 14, 2026

From Data to Decisions: Leadership, Trust, and AI in Healthcare with Dr. Julia Rehman

Healthcare leaders often struggle to convert abundant data and AI investments into actionable decisions that improve care. Dr. Julia Rehman emphasizes that effective AI integration requires human judgment in the loop, strong governance frameworks, and frontline staff engagement, especially in resource-constrained settings.

  • 01AI should target specific operational challenges like staffing, readmissions, and bed capacity, with humans retaining decision-making authority.
  • 02Few healthcare organizations have governance structures to ensure accountability, audit trails, bias monitoring, and oversight as AI adoption accelerates.
  • 03Data richness without strategic insight and human judgment informed by experience limits the value of technology investments in healthcare.

Sep 14, 2026

Two Radiology Deals Signal Focus on Coverage, Not Scanners

Two Radiology Deals Signal Focus on Coverage, Not Scanners

Colorado Imaging Associates and TRA Medical Imaging announced Sept. 8, 2026 that they are forming Affiliated Radiology to expand physician coverage for a shared health system client, Radiology Business reported. Separately, Align Capital Partners said in late May 2026 it agreed to acquire Boise-based Heritage Imaging, a mobile diagnostic imaging provider operating in 14 states, according to Radiology Business.

  • 01Affiliated Radiology was formed by combining Colorado Imaging Associates and TRA Medical Imaging to expand physician coverage for a shared health system client.
  • 02Heritage Imaging operates mobile diagnostic units across 14 states, providing PET-CT, MRI, nuclear medicine, ultrasound and echocardiography to critical access hospitals and community clinics.
  • 03Health system sourcing teams should request service-level commitments, credentialing procedures, cross-location read routing, and PACS/RIS/EHR integration details before contracting with coverage-focused or mobile imaging arrangements.

Sep 12, 2026

Explore More Healthcare Insights

Read more expert perspectives from across Healthcare.

Browse Healthcare Hub

About the Expert

MI
Mike Isbitski

Director of Cybersecurity Strategy at Sysdig

Mike Isbitski is a cybersecurity strategist with extensive experience in application security, cloud-native security, and regulatory compliance. He has held advisory and strategy roles at several security-focused technology companies, including Sysdig and42Crunch. He regularly speaks and writes on topics including zero trust, API security, and security policy.

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Healthcare and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512