Health-ISAC Survey Reveals Recovery is Weakest Link in Cyber Maturity

Recovery is the weakest function in health sector cybersecurity programs.
Only 22 percent of surveyed CISOs rate themselves at the top two maturity levels for restoring operations after an incident. That finding comes from the 2026 CISO Benchmarking report from Health-ISAC, which surveyed 76 security executives. Respondents spanned providers, pharma, medical devices, payers, and health IT. In fact, more than a quarter placed themselves at Level 1 or 2 on the NIST Cybersecurity Framework Recover function.
Every other CSF function scores higher, with Detect leading at 60 percent reporting Level 4 or 5 maturity, followed by Protect at 55 percent, Identify at 48 percent, and Respond at 44 percent. Health-ISAC also noted that even large organizations average Level 3 for Recover. Similarly, only 6 to 10 percent of programs reach Level 5 in any function.
Because the pool spans multiple segments, the figures describe the sector broadly. Size segmentations use employee count and revenue bands, not bed count.
Detection maturity without recovery maturity leaves organizations able to see an attack clearly while uncertain how fast they can restore clinical systems. Health-ISAC described that distance as a clinical risk. Accordingly, it recommended elevating business continuity and disaster recovery investment to a board-level priority.
Read the article in HealthSystemCIO. Read More
- Related Resources & News
- Threat Actor Playbook: Conversational Social Engineering in Care Settings
- The Human Risk Layer of AI
- Cybersecurity in the Lab
- Operation Vital Signs: First-of-its-kind exercise stress tests health sector cyber resilience
- What’s in America’s Code?
- Introducing AI Agents to Your Identity Fabric
- Cyberattacks on Healthcare Sector Jumped 14% in First Half of 2026
- What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience
- Continuous attack surface monitoring and sophisticated social engineering assessment
- Hospital Networks are Becoming Targets in Cyberwarfare, and They’re Unequipped to Deal With It