Why health systems should stop chasing cybersecurity ‘unicorns’

Advertisement

Healthcare’s cybersecurity workforce problem may have less to do with finding more candidates and more to do with changing who health systems are willing to hire, how they develop them and what they do to keep them.

Cybersecurity leaders at four health systems told Becker’s that continually competing for the same pool of experienced professionals is not a sustainable strategy as cyber risks expand and the skills needed to manage them become more complex.

“The cybersecurity workforce challenge has shifted from a talent shortage to a talent entry problem,” Trevor Martin, vice president, chief information security officer and interim chief technology officer at Madison, Wis.-based UW Health, said.

Mr. Martin said there are many high-potential people trying to enter cybersecurity, but organizations frequently prioritize candidates who already have experience instead of creating pathways for people to gain it.

Healthcare could benefit from hiring more heavily for aptitude, adaptability and an understanding of business and clinical operations, then developing those employees internally, he said. UW Health has found success moving talent from adjacent IT disciplines into cybersecurity roles and providing opportunities for employees to grow within the field.

Jeff Aguilar, chief information security officer at Newport Beach, Calif.-based Hoag, sees a similar need to rethink the traditional hiring model.

“Over the next five to 10 years, healthcare must move beyond competing for a limited pool of experienced cybersecurity professionals and instead focus on building a sustainable talent pipeline,” he said.

Hoag’s approach has included early career opportunities, targeted hiring, mentorship, professional certifications, ongoing skills development and pathways for career progression. The health system has seen early career professionals develop into meaningful contributors to its cybersecurity program, he said.

Mr. Aguilar also pointed to partnerships with universities, healthcare organizations and community programs as ways to expand the pool of future cybersecurity workers.

Jason Taule, chief information security officer at Annapolis, Md.-based Luminis Health, said health systems should similarly focus more on developing experienced cybersecurity talent themselves and widen where they look for prospective employees.

“Stop trying to find the mythical unicorns,” he said.

Hospitals can narrow an already small talent pool when they require candidates to have performed the same job at another healthcare organization, Mr. Taule said. Instead, he said employers should look outside healthcare and consider people in adjacent fields who have skills that can translate to cybersecurity.

That can include clinicians.

Several people on Mr. Taule’s team have clinical backgrounds, including an employee who previously worked as a respiratory therapist before earning a cybersecurity degree. He said experience can be particularly valuable because cybersecurity professionals must understand the environment in which security requirements are being applied and communicate with clinicians, whose primary focus is delivering patient care.

Recruiting more people into the field, however, does little good if organizations cannot keep them.

“You have to fix the retention issue before you expand your pipeline,” Mr. Taule said.

Health systems risk investing significant time in developing employees only to lose them once they are able to work independently, he said. If cultural and workplace issues driving turnover remain unresolved, expanding the pipeline could result in organizations developing cybersecurity professionals who ultimately take those skills elsewhere.

Competition for cybersecurity employees also extends beyond healthcare. Mr. Taule said Luminis operates in a Mid-Atlantic market where healthcare employers compete with federal agencies, government contractors and organizations in larger markets for talent. Remote work has further expanded the number of employers workers can consider without relocating.

Mr. Taule said health systems also need to consider which cybersecurity capabilities truly need to remain in house. He pointed to around-the-clock security operations as one area organizations could evaluate rather than assuming every cyber function must be staffed internally.

At the same time, the definition of healthcare cybersecurity talent is getting broader.

Eric Sean Clay, vice president and chief security officer at Baton Rouge, La.-based FMOL Health, said healthcare should move away from viewing cybersecurity as a standalone discipline and instead build a wider enterprise resilience workforce.

Digital and physical security risks increasingly overlap, he said, particularly as technologies such as access controls, video surveillance, wearable duress alarms, weapons detection systems and connected medical equipment cross traditional organizational boundaries.

FMOL Health has worked to break down silos between its cyber and physical security teams through shared risk assessments, joint incident response planning and greater communication between the groups.

“The most valuable professionals will be those who can bridge cybersecurity, physical security, AI governance, cloud technologies and business operations,” Mr. Clay said.

He said healthcare organizations should recruit for aptitude and alignment with their mission while creating stronger pipelines through universities, community colleges and military transition programs. Continuous learning and internal career mobility will also become increasingly important as the expertise health systems need continues to evolve.

Mr. Taule similarly said connected medical devices, third-party vendors, cloud infrastructure, changing care delivery models and AI are reshaping the skills cybersecurity teams need. AI should be treated as another layer of expertise cybersecurity professionals must develop rather than an entirely separate workforce pursuit, he said.

For health systems, that means the cybersecurity workforce challenge may require something broader than filling vacancies.

“By treating workforce development as a strategic investment rather than a staffing challenge, healthcare organizations can build the diverse, resilient and highly skilled cybersecurity teams needed to protect patient care and support innovation in an increasingly digital healthcare environment,” Mr. Aguilar said.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement