You are listening to a Podhoc podcast — a platform where anything can be turned into a Podcast to Learn in Motion.
The cybersecurity maturity of Belgian hospitals is a critical concern, with a recent report revealing that three out of four lack the required level of protection. This alarming statistic underscores the complex challenges healthcare institutions face in safeguarding sensitive patient data and ensuring operational continuity against escalating cyber threats. In this second part of our interview, Wim Bijnens, CEO of SHIELD, delves deeper into the resources, regional disparities, and strategic approaches shaping this vital sector's cybersecurity landscape.
Bijnens explains that for many hospitals, adapting to new regulations simultaneously is a significant hurdle. They must invest in governance, documentation, technical security, training, incident detection, response, and external audits all at once. The primary limitations aren't always technological; often, there's a shortage of specialized personnel, managerial time, consistent budgets, and adequate auditing capacity. Therefore, progress is achievable, but it requires a realistic approach that considers staff, existing technologies, financial resources, and the unique audit capabilities of each institution.
The complexity of the hospital environment presents unique obstacles to cybersecurity advancement. Older applications and medical devices have extended lifespans and are difficult to patch quickly, often relying on specialized, sometimes inaccessible, vendors. Furthermore, healthcare services must operate without interruption, making traditional technology replacement strategies impractical. Despite these challenges, recent audit data shows rapid improvement is possible, with Walloon and Flemish hospitals demonstrating significant gains, indicating that high maturity levels are attainable across regions.
Regional differences in cybersecurity maturity can be attributed to varied starting points, implementation timelines, chosen strategies, the effectiveness of support, and how thoroughly assessment feedback is utilized and shared. Smaller institutions and psychiatric hospitals often lack the critical mass of expertise needed internally, necessitating a progressive, shared approach to cybersecurity. This typically involves a validated set of priority controls, followed by enhancements through improvement plans, compensatory measures, exception management, and alignment with standards like ISO 27001 and CyFun.
Bijnens observes a growing awareness regarding technological sovereignty within Belgian hospitals, with increasing scrutiny on data storage locations, applicable legislation, access controls, involved subcontractors, and the risks of single-vendor dependency. He emphasizes that sovereignty extends beyond a vendor's nationality to encompass control, legal dependence, data portability, continuity, and the ability to operate autonomously. Realistically, widely adopted technologies like Microsoft's lack direct, large-scale equivalents for many functions, meaning sovereignty can't simply mean replacing all non-European technology.
The landscape for electronic health records shows more nuance, with many hospitals using in-house or European-developed solutions, often hosted locally, which can reduce dependence on public cloud platforms. While this historical approach offers some advantages, local hosting isn't inherently more secure or sustainable, as hospitals remain responsible for patching, redundancy, and oversight. Conversely, cloud adoption isn't automatically detrimental to sovereignty, provided key factors like encryption, key management, contractual rights, data location, transparency, portability, and the ability to maintain critical care during provider outages are addressed.
Belgian and European technological solutions deserve greater consideration, but they must compete on maturity, interoperability, support, and total cost of ownership. Addressing geopolitical dependencies is not solely a hospital responsibility; it's an industrial and European political challenge that could be bolstered by common public procurement and investments to help European alternatives achieve critical mass and gain necessary references. While technical solutions vary, shared security principles, maturity objectives, and evidence expectations should remain consistent across the sector.
There isn't a single, uniform technical strategy for all Belgian hospitals, as university, regional, psychiatric, and specialized facilities differ greatly in size, care profiles, research activities, architecture, budgets, and vendor landscapes. However, a common framework is emerging, highlighting the universal need for robust risk management, strong identity and access controls, network segmentation, monitoring, secure backups, incident response, vendor management, and business continuity planning. SHIELD translates these needs into shared policy models, registries, processes, and maturity metrics, offering reference architectures that hospitals can adapt.
This approach allows for the reuse of proven architectures without mandating specific products or vendors, fostering a focus on choices that meet comparable security criteria, are demonstrably managed, and prevent hospitals from constantly reinventing the wheel. While individual hospitals may not require identical technologies, the underlying security principles and demonstrable management of those choices should be consistent, promoting efficiency and a higher baseline of security across the board.
While SHIELD refrains from publishing individual rankings or labeling any hospital as "the safest," there are indeed leading institutions in cybersecurity. The top five performers achieve an average maturity of 3.20, with strong documentation scores, indicating that significant progress is possible. These leading hospitals often share characteristics like strong leadership support, formal governance, updated risk assessments, multi-year investment plans, robust detection and response capabilities, secure backups, regular drills, and structured vendor management.
A successful case study is not necessarily the one with the most expensive technology, but rather an institution that coherently integrates governance, people, processes, technology, and evidence. These leading organizations demonstrate that a holistic approach, connecting all these elements, is key to achieving a high level of cybersecurity maturity and resilience, serving as valuable examples for others in the sector.
Hospitals with lower maturity scores often face more challenging starting conditions: aging infrastructure, numerous medical devices and vendors, limited financial resources, a scarcity of specialized profiles, or a backlog of operational priorities. This doesn't imply a lack of importance placed on cybersecurity; rather, the solution typically involves clarifying responsibilities, critical care processes, dependencies, risks, and priorities. A multi-year plan can then address the most impactful risk-reducing controls first, while simultaneously integrating evidence production.
Shared services, such as SHIELD's library, validated designs, framework agreements, training programs, peer learning, common detection capabilities, and audit support, can accelerate progress for smaller or less mature institutions. These shared resources allow them to advance more rapidly without needing to develop all the necessary expertise internally, making cybersecurity more accessible and efficient.
Local IT and security teams should begin by establishing a realistic understanding of their critical processes, systems, data flows, and dependencies. Subsequently, they can assign a responsible party, deadline, controls, and necessary evidence for each prioritized risk. Key technical priorities include robust identity and multi-factor authentication, network segmentation, vulnerability and patch management, restorable backups, monitoring, logging, and access control limitations.
Measures only gain true value when executed and tested reliably, making exercises crucial. Hospitals must simulate scenarios where critical systems like patient records, networks, telephony, labs, medical equipment, or key vendors become unavailable, demonstrating that an incident plan is not just theoretical but actively practiced and effective in maintaining patient care.
For public authorities, the need is for clear, stable regulations. The Center for Cybersecurity Belgium (CCB) must harmonize interpretations, clarify evidence expectations, properly accept operational evidence, and define the relationship between CyFun, ISO 27001, and NIS2. Regional cybersecurity agencies (CABs) should apply frameworks uniformly and provide well-reasoned feedback. The public health service and other authorities are also expected to support multi-year funding and favorable sector-wide conditions.
Not every hospital needs its own Security Operations Center (SOC), incident response team, or specialized audit expertise; shared capabilities, joint procurement, threat intelligence, training, and targeted support for smaller institutions are more efficient and strengthen the entire sector. This collaborative approach ensures that resources are optimized and that the entire healthcare ecosystem benefits from collective improvements in cybersecurity.
Looking ahead to 2027 and beyond, a primary cybersecurity challenge for hospitals will be transitioning from mere compliance to genuine resilience. While documentation and audit evidence are necessary, the ultimate measure is the hospital's ability to continue providing safe care during a severe incident. The next crucial step involves moving from policy documentation to measurable implementation and true operational resilience, ensuring that security measures are not just on paper but actively functioning.
A significant challenge lies in the growing reliance on cloud platforms, software vendors, medical technologies, and complex digital supply chains, where an incident with a single vendor can affect multiple hospitals simultaneously. This elevates the importance of vendor risk management and coordinated incident response strategies. The persistent shortage of specialized IT professionals also necessitates collaboration, shared services, and automation to bridge the expertise gap effectively.
Managing legacy medical equipment and long-lifecycle applications remains difficult due to their slow update cycles compared to standard IT hardware. Furthermore, risks associated with artificial intelligence, geopolitical tensions, and supply chain attacks are escalating, coinciding with the increasing professionalization of cybercrime. Hospitals must therefore simultaneously enhance their maturity, master new technologies, and safeguard the continuity of patient care.
The increasing sophistication of cyberattacks, often amplified by AI, presents a significant threat to hospitals. AI lowers the barrier to entry for attackers, making phishing and social engineering more convincing, enabling faster adaptation of attacks, and facilitating broader vulnerability scanning. Realistic AI-generated voices, images, and messages also complicate identity fraud detection, posing a dual threat of data theft and operational disruption.
Patient data is highly sensitive and can be exploited for extortion, fraud, or blackmail, but the disruption of critical systems can have an even more immediate impact on patient safety and care continuity. Therefore, availability in a hospital setting transcends a mere technical criterion, demanding a multi-layered defense strategy that includes strong identity controls, phishing-resistant authentication where possible, network segmentation, endpoint detection, monitoring, secure and tested backups, rapid incident response, and rigorous vendor oversight.
Payment procedures, access restoration, and sensitive modification processes must be designed to withstand deceptive attempts via voice or image, underscoring the need for robust security protocols. Sector-wide collaboration is paramount, as identical attack patterns can affect numerous institutions, making shared SOC capabilities, swift threat intelligence exchange, common detection rules, and joint exercises vital for reducing the time between initial detection and an effective defense.
The impact of the AI Act on hospitals is clear and varies based on the specific application and the hospital's role, as they already utilize AI in areas like medical imaging, diagnostic assistance, planning, administration, research, and patient communication. Hospitals can act as acquirers, users, or even developers of AI systems, necessitating a comprehensive inventory of AI usage, including systems, purposes, data, departments, and human oversight.
Informal use of generative AI by staff must be identified to prevent sensitive information from leaving approved environments. For higher-risk AI applications, robust risk management, data quality assurance, logging, transparency, human oversight, and cybersecurity become essential. The classification of AI risk depends on its purpose, context, and influence on health, safety, or fundamental rights.
With European implementation timelines for AI obligations already in effect or imminent, hospitals must proactively integrate governance, training, inventory management, procurement conditions, and incident management into their existing information security, data protection, and quality policies. This ensures that AI is managed responsibly within established frameworks, safeguarding both patient care and data integrity.
Thank you for listening to this Podhoc podcast.
