Modern Identity Defense for Healthcare Series–Defending Against Identity Attacks – When MFA Isn’t Enough Webinar [PODCAST]
Modern Identity Defense for Healthcare Series: Defending Against Identity Attacks – When MFA Isn’t Enough Webinar
In this episode, Eric Englebretson, Besler Holdings’ Vice President of Information Technology, provides us with a glimpse into Webinar, the first in its Modern Identity Defense for Healthcare Series: Defending Against Identity Attacks – When MFA Isn’t Enough live on Wednesday, August 12, at 1 PM ET.
Highlights of this episode include:
- What is this webinar about?
- MFA still effective?
- How the attacks are evolving
- What session tokens are and why you should care about them
- Why healthcare is a frequent target
- Warning signs that an account may be compromised
- Next evolution beyond traditional MFA
Subscribe Today!
Kelly Wisness: Hi, this is Kelly Wisness.We’re pleased to welcome back Eric Englebretson, Besler Holdings’ Vice President of Information Technology. In this episode, Eric will provide us with a glimpse into Besler Holdings’ next Webinar, the first in its Modern Identity Defense for Healthcare Series–Defending Against Identity Attacks – When MFA Isn’t Enough live on Wednesday, August 12, at 1 PM Eastern Time. Welcome back and thank you for joining us, Eric.
Eric Englebretson: Thank you so much. I’m happy to be here.
Kelly: Well, great. Well, let’s go ahead and jump in. So can you provide a quick overview of what you’re going to be reviewing during this webinar?
Eric: Absolutely. So, the thing that I think is very important for us to cover is that identity has become one of the most targeted areas in all of cybersecurity right now. It used to be that attackers focused on servers or the corporation’s network, and once they’d gotten in from there, they would pivot to get at the thing they’re really after, which is often a company’s data. In the age of cloud computing and remote work, defenses have generally gotten better because traditional defensive methods of defending the network give way to security practices like something called Zero Trust, whereby any interaction with an organization’s resources must be authenticated no matter where a location request might come from. And so, the next logical step is identity attacks. And why is that? Like I said, since attackers focus used to be on breaking into networks and servers, the payoff might be limited. A compromised web server hosting a hospital website might not have any access to any data at all, really, but in today’s integrated environments, one compromised user account. Now that can give an attacker access to email, collaboration tools, patient systems, financial applications, and cloud services, depending on your role. In most organizations, your identity becomes the new perimeter, and that’s why attackers increasingly target people and accounts instead of infrastructure. This is going to be a two-part series covering modern identity security, why attackers have moved to trying to capture identities as a first attack rather than compromised servers, what we can do about it. And in part two, one of the biggest new advancements you’re probably already using in a few places, passkeys.
Kelly: Awesome. Sounds like you’re going to cover a lot during this webinar. I’m really looking forward to it. So, we hear a lot about MFA and how attackers try to bypass it. So is MFA still effective?
Eric: Absolutely. So, MFA really remains one of the most important security controls that has come to us in the past 10 or so years, and it really does stop the vast majority of common attacks, including password reuse, credential stuffing, and other attacks similar to those. The key message here is that MFA is definitely not broken. The message is that attackers have evolved and they’re now looking for ways to get around it. It is just that effective. They’ve got to work around it now rather than just simply trying to use a username and password. And that means organizations need additional layers of protection alongside of MFA.
Kelly: Yeah, so we know that MFA is still effective. So how are attacks evolving to work around it?
Eric: Modern attackers often focus on stealing authenticated sessions rather than stealing passwords. In some phishing attacks, victims enter their credentials and complete MFA successfully, but the attacker captures the resulting session that’s created. Think about it this way. Is it easier for a thief to steal your hotel room key or to try to convince the front desk to issue a new one? In most cases, it’s easier for the thief to steal your room key. After that, they can just come and go as they please, usually without so much as a second glance. We’ve put so many guardrails around the authentication process that attackers are now moving on and looking at what’s behind that, something called sessions and tokens.
Kelly: So, what are session tokens and why should people care about them?
Eric: So, session tokens and they are kind of background… so this is kind of we enter that realm of nerdy a little bit, but stick with me. Session tokens are what keep you log in after you’ve authenticated. They’re the reason that you don’t have to enter your password and MFA code every single time you open an email or click a new page. They’re incredibly useful, but that makes them also incredibly valuable to attackers. If an attacker does steal a valid session token, they may be able to act as though they’re already authenticated without having to have your password again. And that is what makes them so important, and that is why people should care.
Kelly: Yeah, no, that makes a lot of sense. Why is healthcare such a frequent target for identity attacks? I mean, we’ve been hearing so much about this lately.
Eric: Absolutely. So, the main reason for that is that healthcare combines highly valuable data with extremely time-sensitive workflows. Clinicians and staff are constantly dealing with alerts, messages, urgent requests, and attackers understand that environment, and they design their hacking and phishing campaigns specifically to exploit human pressure and urgency. Healthcare isn’t targeted because it’s careless. That’s actually quite the opposite. It’s targeted because its mission creates very unique opportunities attackers can try to exploit.
Kelly: Yeah. I guess having that– always having that sense of urgency probably doesn’t help us in that way, right?
Eric: Absolutely.
Kelly: Yeah. So, what are some warning signs that an account may be compromised?
Eric: So, a few of the things that you should look out for some of those red flags include unexpected MFA prompts, alerts about sign-ins from unfamiliar locations. If you are looking at your inbox forwarding rules, which I recommend that everybody does every once in a while, if a forwarding rule you didn’t set up has appeared and it’s forwarding to some account you don’t know about, that is definitely a big red flag, or just anything that seems off to you that might signify unusual account activity. And one of the most important things you can do here is just to simply report those to your IT staff, help desk, or security staff, whatever your normal workflow is, immediately. Early reporting can often stop a small incident from becoming a major breach.
Kelly: Yeah, no, that makes a ton of sense. Just be more vigilant. So, what’s the next evolution beyond traditional MFA?
Eric: And that is an excellent question. This is something I’m going to cover in part two. The future is phishing resistant authentication. So, there are technologies, and I’m going to use another nerd word here like FIDO2 security keys, Windows Hello for Business, and Passkeys are designed to prevent attackers from stealing or reusing credentials and session information. In part two of the webinar series, we’re going to explore how passkeys work, why companies should adopt them, and how they can dramatically improve both security and user experience.
Kelly: Wow, sounds like things are always changing in this space for sure. Well, thank you so–
Eric: Absolutely.
Kelly: Yeah. Well, thank you so much for joining us, Eric, and for giving us this glimpse into our next free Webinar — Defending Against Identity Attacks – When MFA Isn’t Enough. Join us live on Wednesday, August 12th at 1 PM Eastern Time. And as a bonus, you can also earn CPE. Thanks again, Eric.
Eric: Absolutely.
Kelly: And thank you all for joining us for this episode of The Hospital Finance Podcast. Until next time…
[music] This concludes today’s episode of The Hospital Finance Podcast. For show notes and additional resources to help you protect and enhance revenue at your hospital, visit besler.holdings/podcasts. The Hospital Finance Podcast is a production of Besler Holdings.
If you have a topic that you’d like us to discuss on The Hospital Finance Podcast or if you’d like to be a guest, drop us a line at update@besler.com.






