Blog Listing
Blog
Technology in Practice
Practical guidance on ERP, CRM, HR, finance, and the technology powering modern organizations.
IT / Infrastructure
Identity Attacks Are the New Cyber Threat: Why Zero Trust Matters for SMBs
Read more
Blog
Thoughts on AI Security: What I’m Hearing in the Field
Read more
Blog
2026 Trend MSP to MIP – Managed Intelligence Provider Tools for Growth
Read more
IT / Infrastructure
Adapting to the New Age of AI-Powered Cyber Threats
When you log in to your computer on a Monday morning and see that ransomware screen demanding payment, you should realize that the attack didn’t start that weekend. As Net at Work CISO Michael Powell explains, “To stage an attack, it’s not uncommon for a threat actor to have been in the environment up to 90 days.”
For weeks or months, threat actors may have been cataloging your data and exfiltrating files. With U.S. ransomware attacks up 149% year-over-year as of early 2025, understanding how these attacks work has never been more critical.
Most attacks follow predictable patterns. Once you understand the playbook, you can build defenses that work.
In this article you will learn:
Why even well-funded cybersecurity efforts struggle to keep pace with evolving threats
How the “double extortion” ransomware model puts organizations at risk even with backups
Why AI has made business email compromise nearly impossible to detect
Simple defensive strategies that dramatically improve security posture
How to evaluate readiness and find the right security partners
Why This Keeps Happening
“Why is it hard? Why are we still trying to solve this problem?” Powell asks. His answer: “We’re effectively in an arms race.”
Organizations invest heavily and close vulnerabilities. Yet as one gap closes, attackers adapt. Cyber attacks per organization increased 47% in Q1 2025, reaching 1,925 weekly attacks on average.
The real challenge is asymmetry. Powell explains, “There could be more people trying to attack your organization than you have to play defense.”
The Ransomware Reality
During the 30-90 day reconnaissance phase, attackers aren’t randomly grabbing files. “They pull a file listing and then based on the file names and the file structures, they go for the information that they think is pertinent,” Powell explains. They systematically identify personally identifiable information, financial records, and commercially sensitive data, then slowly exfiltrate copies.
When attackers are ready to strike, timing matters. “We often see spikes around weekends, around evenings, around holidays.” Powell notes, “This is because reconnaissance and encryption take time.” They choose moments when you’re least likely to respond quickly.
The Double Threat
Even with robust backups, you face what Powell calls the “double extortion threat.”
“Your data is encrypted, and you need to decrypt it to continue to do business,” he explains. “But the threat actor knows these days people put reasonable technology controls in place. They’re betting you have backups, so they add a second pressure point: pay up, or we leak everything.”
The consequences go beyond embarrassment. Depending on your location and the data involved, you may face legal obligations to notify affected individuals. The average ransom demand in 2024 was $4.32 million, but legal costs and reputational damage can dwarf that figure.
Nearly one in five small businesses that suffered a cyberattack filed for bankruptcy or closed. This isn’t an IT problem; it’s a serious business survival issue.
How AI Changed Business Email Compromise
While ransomware grabs headlines, business email compromise (BEC) operates quietly and is equally devastating. BEC was the second-costliest cybercrime in 2023, with nearly $3 billion in losses.
AI has fundamentally transformed the threat. Attackers compromise an email account and download sent items. Previously, analyzing that information manually took time. Now? “You download that information, you throw it into AI, and then you can ask it questions,” Powell explains.
The AI builds a complete profile and generates emails that perfectly mimic executives’ communication. “Where we used to be able to spot those emails with relative ease,” Powell says, “AI helps the threat actor be a lot more convincing with very little additional work.”
With 73% of reported cyber incidents in 2024 being BEC attacks, and organizations with 1,000+ employees facing a 70% weekly probability of at least one BEC attack, this demands constant vigilance.
Your People: Vulnerability and Solution
“Most of the compromises we see occur because a person takes an action,” Powell says. “But they’re rarely doing it with malicious intent.”
Most breaches happen because employees respond to what appears urgent. “Pretty much every phishing test I have ever been a part of, at least one person has clicked the email, and you only need one.”
The solution lies in changing the culture around reporting threats rather than carrying out punishments. “People shouldn’t feel that if they raise a security threat, the IT team is going to pounce on them,” Powell emphasizes.
“Every person is a sensor,” Powell explains. Train people to recognize what normal looks like, then empower them to speak up. Modern training uses gamification: You click something, and then there’s just-in-time training that shows you why that was good, or why that was bad.”
Building Defenses That Work
Effective defense requires layered approaches that create multiple “tripwires.”
“The more visibility you have, the more chances you’ve got of spotting an anomaly,” Powell explains. Each layer, including endpoint detection, email security, patching, backups, network segmentation, increases the likelihood you’ll catch attacks before they succeed.
But technology alone isn’t enough. Organizations need clear procedures. Powell shares an example of a company with excellent technology but no response plan: “Person A looks at person B, they don’t know who’s responsible. Can we turn the system off? We don’t know who approves that.”
His advice: “If you don’t know who to inform in case of a breach, find out.” Conduct tabletop exercises revealing gaps. “Have people sit around a table and practice what they would do if a ransomware email came in.”
Where to Start
Powell offers a straightforward evaluation framework:
Evaluate what you have. “There are so many times I’ve gone into an organization where they’re paying for something, but they’re using less than 10% of it.” Understand current capabilities before buying new solutions.
Define risk tolerance. What’s acceptable downtime for different systems? Document thresholds in advance.
Conduct regular audits. Most insurance carriers require annual assessments and often help with scanning.
Leverage available expertise. Your insurance company often provides guidance. If working with technology providers, understand what expertise they have that they could bring to bear in the event of an incident.
Consider cybersecurity as a service. For many businesses, working with a managed security service provider offers specialized skills without building an in-house team. “What they’re effectively doing is delivering the speed, delivering the skills and reducing the cost,” Powell explains.
When evaluating providers, Powell emphasizes fit over features: “Look for the one that suits your business and your processes.” And be sure to verify responsiveness: “There’s nothing worse than receiving a ransomware attempt on a Friday night and then realizing that the partner says they’ll deal with it Monday morning.”
And be sure to check references. “Try to find an organization they’ve worked with and talk to that organization. When you’re buying into cybersecurity as a service, you’re buying into trust.”
Moving Forward with Confidence
Understanding that attacks follow patterns, defenses can be layered effectively, and preparation dramatically improves outcomes will put you in a stronger position. With 86% of cyber incidents involving business disruption, the question isn’t whether to invest in security, but how to invest wisely.
Take the Next Step
Net at Work helps organizations build resilient security strategies that balance protection with practical business needs.
For a limited time, we’re offering complimentary assessments:
IT Infrastructure Assessment: Comprehensive evaluation identifying vulnerabilities and opportunities
Email Security Assessment: In-depth analysis of your email security posture—the primary attack vector for both ransomware and BEC
Don’t wait for a breach to discover where your defenses fall short. Contact Net at Work today to schedule your assessment and start building security that protects your business without compromising operations.
Ready to strengthen your security? Contact Net at Work to claim your complimentary assessments and speak with experts who understand your challenges.
Key Takeaways
Understand the timeline: Ransomware attacks involve 30-90 days of reconnaissance before encryption. Early detection is everything.
Prepare for double extortion: Even with backups, data leaks trigger legal obligations and reputational damage.
Take AI seriously: BEC attacks now use AI to perfectly mimic writing styles, making traditional detection nearly impossible.
Build culture, not just controls: Encourage reporting without punishment. Every employee is a sensor who can spot anomalies.
Layer your defenses: Multiple security controls create “tripwires” that increase chances of catching attacks early.
Rehearse your response: Tabletop exercises reveal gaps and build muscle memory for critical decisions.
Leverage external expertise: Insurance carriers and managed security providers offer prohibitively expensive skills and resources.
Sources
TechTarget, “Ransomware trends, statistics and facts,” 2025.
Check Point Research, “Q1 2025 Global Cyber Attack Report,” May 2025.
Spacelift, “50+ Ransomware Statistics for 2025,” July 2025.
Fortinet, “Ransomware Statistics 2025,” 2025.
The SSL Store, “Business Email Compromise Statistics,” March 2024.
Hoxhunt, “Business Email Compromise Statistics 2025,” March 2025.
LastPass, “Protect against business email compromise in 2025,” May 2025.
Palo Alto Networks Unit 42, “Extortion and Ransomware Trends,” April 2025.
Read more
ERP
IT / Infrastructure
Cybersecurity in Healthcare ERP: Strategies for Protecting Patient Data
If a cyberattack shuts down your healthcare ERP system for days, can your patients still receive the care they need?
Healthcare organizations face a growing cybersecurity crisis, with the American Hospital Association reporting that the healthcare field experienced more cyberthreats in 2024 than any other critical infrastructure industry, and related research found that, as of early 2025, 92% of healthcare organizations experienced at least one cyberattack in the past 12 months. Additionally, McKinsey & Company reports that healthcare provider organizations incur the highest cost for data breaches of any industry, averaging $9.8 million per incident, which is more than 1.5 times the financial services industry’s average cost of $6.1 million.
Beyond financial losses, cyberattacks directly threaten patient care and organizational survival. For small-to-medium-sized healthcare practices and senior living centers, this reality demands immediate attention to how enterprise resource planning (ERP) systems handle patient data protection.
The Current Threat Landscape
Rising Attack Frequency and Sophistication
Cyberattacks targeting the healthcare sector have continued to intensify, with hundreds of healthcare cyberattacks reported thus far in 2024. These aren’t simple data theft attempts; they’re sophisticated operations designed to maximize disruption to patient care.
The most significant cyberattack in U.S. healthcare history occurred when ransomware hit Change Healthcare, impacting every hospital in the country and exposing the health data of 190 million people. This incident highlighted how interconnected healthcare systems create cascading vulnerabilities that can paralyze entire care networks.
ERP Systems as Prime Targets
Healthcare ERP systems are particularly attractive to cybercriminals because they:
Centralize vast amounts of protected health information (PHI)
Control critical business functions including billing, scheduling, and supply chain management
Often integrate with multiple third-party vendors and systems
More than four out of five physicians have been victims of some type of cyberattack, with “phishing” being the most common (55%). These attacks frequently target ERP login credentials to gain system-wide access.
The Critical Role of ERP Selection in Cybersecurity
Cloud-Native vs. Legacy Systems
The choice between modern cloud-based ERP systems and legacy on-premise solutions directly impacts cybersecurity posture. According to a 2021 survey, 73% of the healthcare industry uses legacy technology, leading to manual reporting processes that are time-consuming and prone to human error.
Modern cloud ERP systems can offer several security advantages:
>Built-in Security Architecture: Cloud-native systems are designed with security as a foundational element, not an afterthought. They include encryption, multi-factor authentication, and automated security updates as standard features.
Compliance by Design: Healthcare ERP software like Sage Intacct helps healthcare organizations maintain HIPAA compliance through advanced security controls and audit trails.
Vendor Security Expertise: Cloud ERP providers invest significantly more in cybersecurity expertise than individual healthcare organizations can afford internally.
“Beyond financial losses, cyberattacks directly threaten patient care and organizational survival.”
Integration and Third-Party Risk Management
Third-party breaches remain top concerns for 2025, with supply chain attacks becoming increasingly common. ERP systems must be evaluated not only for their internal security but also for how they manage integrations with:
Electronic Health Records (EHR) systems
>Medical devices and IoT endpoints
Payment processing platforms
Business intelligence tools
Vendor management systems
Essential Cybersecurity Strategies for Healthcare ERP
1. Comprehensive Risk Assessment
Before selecting or upgrading an ERP system, healthcare organizations must conduct thorough risk assessments that include:
Asset Inventory: Maintaining comprehensive and continuously up-to-date visibility across the whole organization is the first step in healthcare cybersecurity.
Data Flow Mapping: Understanding how PHI moves through the ERP system and its integrations
Vendor Security Evaluation: Assessing third-party providers’ cybersecurity practices and compliance certifications
2. Zero Trust Architecture Implementation
Organizations must adopt a zero-trust approach that treats all access requests as potentially malicious, regardless of source. For healthcare ERP systems, this means:
Network segmentation to isolate ERP systems from other network traffic
Multi-factor authentication for all system access
Role-based access controls with principle of least privilege
Continuous monitoring and verification of user activities
3. Advanced Threat Detection and Response
AI-driven threats are becoming increasingly sophisticated, requiring equally advanced defense mechanisms. Healthcare organizations need ERP systems that incorporate:
Real-time threat detection powered by artificial intelligence
Automated incident response capabilities
Behavioral analytics to identify unusual user patterns
Integration with security information and event management (SIEM) systems
4. Regular Security Assessments and Updates
The HITECH safe harbor requires healthcare organizations to adopt “recognized cybersecurity practices” to qualify for reduced penalties in case of breaches. This includes:
Regular vulnerability assessments and penetration testing
Automated security patching and updates
Compliance monitoring and reporting
Business continuity and disaster recovery planning
The Value of Expert Technology Advisory
Why Healthcare Organizations Need Specialized Guidance
Gartner predicted that by the end of 2025, lack of talent or human failure will be responsible for over half of significant cyber incidents. Small-to-medium-sized healthcare organizations face particular challenges:
Limited internal IT security expertise
Budget constraints for cybersecurity investments
Complexity of healthcare compliance requirements
Rapidly evolving threat landscape
The Technology Advisor Advantage
Working with experienced technology advisors provides several critical benefits:
Industry Expertise: Advisors specializing in healthcare understand the unique regulatory requirements and operational challenges facing medical practices and senior living centers.
Vendor Agnostic Approach: The best advisors maintain an agnostic approach, recommending solutions based on organizational needs rather than vendor relationships.
Holistic Security Strategy: Rather than focusing solely on ERP selection, experienced advisors help organizations develop comprehensive cybersecurity strategies that address people, processes, and technology.
Ongoing Support: Dedicated support teams ensure that organizations maximize their software investment, benefiting from continuous updates and expert guidance tailored to their needs.
Regulatory Compliance and Future-Proofing
Evolving Compliance Requirements
Several bipartisan bills have been introduced to strengthen cybersecurity requirements in the healthcare sector, including the Health Infrastructure Security and Accountability Act of 2024. Healthcare organizations must ensure their ERP systems can adapt to evolving regulatory requirements.
Key compliance considerations include:
HIPAA Security Rule requirements for PHI protection
State data protection laws and breach notification requirements
Medicare and Medicaid compliance for billing and claims processing
Emerging cybersecurity frameworks and performance goals developed by HHS in cooperation with the Healthcare and Public Health sector
Building Cyber Resilience
Technology failures and cyber outages can disrupt operations for extended periods, with one in three physicians reporting their practice experienced a cyberattack-related business shutdown. Resilient ERP systems must include:
Redundant data centers and backup systems
Real-time data replication and recovery capabilities
Business continuity planning and testing
Staff training and incident response procedures
Key Takeaways for Healthcare Leaders
Cybersecurity is a Patient Safety Issue: In 2023, >71% of healthcare organizations surveyed who had suffered cyberattacks reported poor patient outcomes because of delays in procedures and tests following the attacks.
ERP Selection Directly Impacts Security Posture: Modern cloud-based ERP systems offer significantly better security capabilities than legacy on-premise solutions, with built-in compliance features and professional security management.
Integration Security is Critical: Third-party breaches remain a top concern for 2025. ERP systems must be evaluated for their ability to securely manage integrations with other healthcare technologies.
Expert Guidance is Essential: The complexity of healthcare cybersecurity requires specialized expertise that most SMB organizations cannot maintain internally. Working with experienced technology advisors ensures proper ERP selection and implementation.
Proactive Approach Reduces Risk: A survey of physicians by the American Medical Associationfound that 85% believe it is crucial to share electronic data outside of their health system for quality care but want to do it safely. Proactive cybersecurity measures enable secure data sharing while protecting patient privacy.
Compliance Benefits Healthcare Practices: Organizations that adopt recognized cybersecurity practices may qualify for reduced penalties under HITECH safe harbor provisions.
Securing Your Healthcare Organization’s Future
The cybersecurity landscape for healthcare organizations will only become more challenging. Selecting the right ERP system and working with experienced technology advisors can mean the difference between becoming another breach statistic and maintaining secure, efficient operations that protect both patient data and care quality.
The time for reactive cybersecurity approaches has passed. Healthcare organizations must take proactive steps now to implement comprehensive cybersecurity strategies centered around secure, modern ERP systems and expert guidance.
Ready to strengthen your healthcare practice’s cybersecurity posture?
Contact Net at Work today to discuss how our healthcare ERP expertise and comprehensive technology advisory services can help you protect patient data, ensure compliance, and build resilient operations for the future.
Read more
IT / Infrastructure
A MasterClass in Digital Transformation Strategy: Overcoming Digital Roadblocks
In today’s rapidly evolving digital landscape, organizations face numerous challenges and opportunities. How do you navigate these complexities to ensure you not only survive but thrive? Join us for an enlightening live web event titled “Transform and Thrive: Overcoming Digital Roadblocks in Your Business.”
Navigating Common Digital Transformation Challenges & Implementing Effective Strategies
We are excited to feature Eric Sluss, a seasoned Chief Information Officer from Net at Work’s Fractional CIO & Advisory group. Eric will share his expertise on how to tackle the human capital, process, and technology challenges that often hinder digital transformation. His insights are designed to help you drive meaningful change and foster innovation within your organization.
Whether you’re at the beginning of your digital journey or looking to fine-tune existing processes, this on-demand webinar promises to equip you with the essential knowledge and tools for a successful transformation.
During this recorded webinar, you’ll discover:
The key components of digital transformation: Understand the foundational elements that drive successful digital initiatives.
Common challenges encountered along the way: Learn about typical obstacles and how to overcome them.
Best practices for ensuring success: Gain actionable strategies to ensure your digital transformation efforts are effective and sustainable.
Watch on-demand webinar for this opportunity to turn challenges into opportunities and propel your business towards unparalleled success. Join us and transform your digital future!
Read more