Defending Against Identity Attacks Webinar Summary

Defending Against Identity Attacks – When MFA Isn’t Enough Webinar Summary
The Hospital Finance Academy welcomed Eric Englebretson, VP of Information Technology at Besler Holdings and Sypher Security (A Besler Holdings Company), for an in-depth live session (on August 12, 2026). This webinar, Defending Against Identity Attacks – When MFA Isn’t Enough, is the first in the two-part series, Modern Identity Defense for Healthcare.
This webinar series discusses modern identity security challenges and solutions, emphasizing MFA, passkeys, and proactive defense strategies in healthcare.
The Growing Importance of Identity Security in Healthcare
- Healthcare relies on cloud platforms, remote access, and connected apps, increasing the attack surface.
- High-value patient data and operational urgency make healthcare a prime target for cyberattacks.
- Multiple user accounts and rapid workflows create vulnerabilities and opportunities for attackers.
How Modern Authentication Enhances Security
- Authentication involves passwords, MFA, access tokens, and sessions to verify user identity.
- MFA blocks credential reuse, credential stuffing, and many phishing attacks, strengthening security.
- Attackers evolve techniques from password theft to session hijacking and token theft.
Common Attack Techniques and Their Impact
- Credential phishing tricks users into revealing login details via fake pages.
- Push fatigue bombings flood users with approval requests, leading to accidental approvals.
- Session hijacking involves stealing and replaying valid session tokens to gain unauthorized access.
Healthcare-Specific Attack Scenarios and Consequences
- Phishing, patient data breaches, and financial fraud threaten patient safety and operational continuity.
- Early detection signs can include (but are not limited to) unexpected MFA prompts and unusual sign-in activity.
- Attacks can cause delays in care, system outages, and loss of trust.
Strategies for Defense and Response
- Prevent attacks with phishing-resistant MFA (e.g. passkeys) and conditional access.
- Detect threats through risk-based monitoring (e.g. impossible travel) and session anomalies.
- Respond by revoking sessions, invalidating tokens, focusing on removing ways attackers may have made future access easier (e.g. reviewing mailbox rules to detect rules forwarding passwords resets or MFA externally), and resetting credentials.
- Work with IT/security teams to preserve forensic evidence, as necessary.
Shared Responsibility and Security Maturity
- All users should verify links, report anomalies, and support security investments.
- A maturity model guides organizations from basic MFA to advanced zero-trust, phishing-resistant solutions.
- Passkeys represent the future of passwordless, phishing-resistant authentication.
Key Takeaways
- Identity is now the primary attack surface.
- MFA remains essential.
- Attackers increasingly target tokens and sessions.
- Phishing-resistant MFA is the future.
- Passkeys are the next step in identity security.
Connect with the expert team at Besler Holdings and Sypher Security for more information or to help strengthen your organization’s security posture.
Access the Modern Identity Defense for Healthcare Webinar Series
Part 1: Defending Against Identity Attacks | On-Demand Now
Part 2: Passkeys in Practice | Sept. 16 at 1 PM ET | Register Now



