Zero Trust Roadmap: Planning for Success
- As cyberattacks against healthcare organizations intensify, security leaders are turning to a new approach: zero trust.
- During a recent healthsystemCIO webinar, erik Decker, VP/CISO of Intermountain Healthcare, Greg Garneau, System VP and CISO at Hospital Sisters Health System, and Tamer Baker, Healthcare CTO at...
- Decker stressed the importance of adopting an "adversarial mindset," designing systems to withstand attacks by assuming a breach has already occured.
Healthcare organizations face intensifying cyberattacks, making zero trust security crucial. This model, a fundamental shift in cybersecurity, assumes no user or device is inherently trustworthy, demanding a new approach to data protection and resilience. Experts like Erik Decker and Greg Garneau highlight critical steps: adopt an adversarial mindset, prioritize cyber hygiene, and focus on rapid recovery times, thereby creating a secure environment. News Directory 3 emphasizes the importance of a phased, strategic implementation, notably for legacy systems, and the need for internal stakeholder buy-in. It demands that healthcare leadership engage teams early to gain support for zero trust initiatives, improve request security, and help keep patient data safe. Discover what’s next for fortifying your digital defenses.
Healthcare leaders Champion Zero Trust Model for Cybersecurity
Updated June 12, 2025
As cyberattacks against healthcare organizations intensify, security leaders are turning to a new approach: zero trust. This model abandons traditional perimeter defenses, assuming that no user or device, inside or outside the network, can be automatically trusted. The shift requires a complete overhaul of security architecture,according to experts.
During a recent healthsystemCIO webinar, erik Decker, VP/CISO of Intermountain Healthcare, Greg Garneau, System VP and CISO at Hospital Sisters Health System, and Tamer Baker, Healthcare CTO at Zscaler, discussed the keys to a successful zero trust journey. They emphasized that zero trust is not a simple add-on but a basic change in how organizations view and manage security risks,especially concerning healthcare data security and network segmentation.
Decker stressed the importance of adopting an “adversarial mindset,” designing systems to withstand attacks by assuming a breach has already occured. Garneau echoed this, noting that the traditional “castle” network is obsolete due to remote work, interconnected devices, and third-party access. Baker added that zero trust should focus on connecting users directly to applications, bypassing traditional network pathways for enhanced application security.
Implementing zero trust in complex healthcare environments presents challenges, particularly with legacy systems. Decker advised addressing basic cyber hygiene issues before implementing advanced architectures. He identified key threat vectors, including compromised credentials and exposed internet services. Baker emphasized eliminating the attack surface by making assets invisible to threat actors.
Garneau acknowledged the difficulty of applying zero trust to outdated medical devices that cannot be easily patched or upgraded. He and Decker emphasized a phased, strategic implementation that minimizes disruption to clinical operations. decker likened the transition to building a new utility pole with clean lines, gradually moving services over without interrupting patient care.
“Zero trust is not a bolt-on.It’s not something you can layer onto an existing environment and expect transformational outcomes,” Decker said. “It’s a mindset and an architectural approach that recognizes that no environment is inherently safe.”
“The old notion of the network being yoru castle no longer applies,” said Garneau. “Your castle is now the entire world… you have to view everything as a potential threat and re-architect accordingly.”
Building internal support is crucial. Decker advised building a coalition by engaging peers and helping them understand the risks. Baker noted that buy-in from the CIO is critical to overcome inertia. Garneau recommended framing zero trust in terms of risk and consequence, highlighting the potential impact of outages on clinical and financial operations.
The panel advocated measuring success by recovery time and continuity of care, rather than solely focusing on prevention. Garneau stated that resilience is the ultimate goal, aiming to reduce restoration time while maintaining operations.
What’s next
Healthcare organizations should prioritize a security-first mindset, securing identity processes, eliminating exposed assets, and segmenting privileged access. Early engagement with infrastructure partners, alignment with enterprise risk management frameworks, and investment in cultural change are also essential for a successful zero trust implementation.
