Cybersecurity Roundup: Healthcare Resilience, Regulation and Managed Security – July 24, 2026

Today’s cybersecurity developments point towards a more structured approach to digital resilience.

European authorities are turning healthcare-security objectives into procurement requirements and support services, Jersey is introducing statutory obligations for essential operators, the World Health Organization is framing cyber defence as a patient-safety issue, and ENISA is developing a certification framework for managed security providers. Meanwhile, Silent Push is betting that partnerships will be central to bringing threat intelligence into more organisations.

ENISA begins implementing the EU Health Action Plan

The European Union Agency for Cybersecurity has taken its first implementation steps under the EU Action Plan for the cybersecurity of hospitals and healthcare providers.

According to ENISA, the agency has signed a €6 million contribution agreement with the European Commission. The three-year agreement will support the development of a proposed European Cybersecurity Support Centre for healthcare organisations.

The planned mechanism will provide guidance, tools and services covering preparedness, threat detection, incident response and governance. ENISA will create a service catalogue by building on existing tools and consulting member states, healthcare organisations and other stakeholders.

One of its first deliverables is an updated set of cybersecurity procurement guidelines for hospitals and healthcare providers.

The guidance covers the complete procurement lifecycle and is intended to help organisations include cybersecurity objectives when purchasing products and services. It addresses security expectations for suppliers and includes a practical checklist connecting procurement requirements with specific threats.

This matters because hospitals frequently inherit cyber risk through medical devices, cloud platforms, third-party software and suppliers with remote access to clinical environments. Once these systems are purchased and integrated, replacing or securing them can be expensive and operationally difficult.

HIPTHER has previously examined how medical-device vulnerabilities turn procurement decisions into patient-safety risks. Requirements such as software bills of materials, vulnerability-disclosure processes, patching commitments and security service-level agreements are therefore becoming essential components of healthcare contracts.

The new ENISA guidance effectively moves cybersecurity closer to the beginning of the investment process. Hospitals should assess whether a product can be securely operated throughout its useful life—not simply whether it meets an immediate clinical or administrative need.

Silent Push appoints CRO to accelerate partner-led growth

Threat-intelligence provider Silent Push has appointed Kirk Appelman as chief revenue officer as the company shifts towards a partner-first commercial strategy.

Channel Dive reports that Appelman joins from Synack and brings approximately 25 years of technology sales and leadership experience.

Silent Push operates a scanning and aggregation engine that tracks changes across millions of IP addresses. Its objective is to identify infrastructure and behavioural patterns associated with threat actors before attacks reach their final stages.

Appelman’s priorities include strengthening the company’s new partner programme, identifying several strategic partners in each sales region and using existing relationships to navigate complex enterprise procurement and onboarding processes.

The company eventually intends to pursue a fully channel-focused model supported by resellers, systems integrators and managed service providers. It is also considering an original-equipment-manufacturer programme through which its intelligence could be incorporated into other cybersecurity products.

The strategy reflects an important reality within enterprise security: even technically strong products can struggle to reach organisations without trusted implementation and advisory partners. Customers need assistance integrating threat intelligence with their existing security operations, workflows and risk models.

Commercial leadership in cybersecurity must therefore connect product capabilities with measurable organisational problems. Programmes such as cybersecurity education designed specifically for senior leaders also demonstrate why security decisions increasingly require coordination between technical, operational and executive teams.

Jersey’s Cyber Security Law takes effect in two phases

Jersey’s new Cyber Security Law will begin taking effect on 1 September 2026 following the signing of its Commencement Order.

According to Channel Eye, the legislation is intended to protect critical infrastructure and essential services across sectors including energy, transport, healthcare, water and public administration.

The law creates statutory responsibilities for Operators of Essential Services. These organisations will be required to register, implement proportionate security measures and report significant cyber incidents to the Jersey Cyber Security Centre.

It also formally establishes the centre’s legal status and responsibilities. The JCSC will maintain the register of essential operators, issue guidance and facilitate information sharing during significant incidents.

Implementation will take place in two phases. The provisions governing the JCSC will become effective in September, while the sections identifying and regulating Operators of Essential Services will follow in December. The phased approach gives affected organisations additional time to determine whether they fall within the law and prepare for their obligations.

The framework resembles the wider European movement towards mandatory resilience standards for essential and important entities. As previous analysis of NIS2 and its impact on the technology channel has shown, this creates opportunities for security providers while also increasing their compliance and reporting responsibilities.

For Jersey’s essential operators, preparation should include asset inventories, risk assessments, incident-reporting procedures, supplier reviews and evidence that security controls are being maintained—not merely documented.

WHO frames healthcare cybersecurity as patient safety

Cyber incidents affecting healthcare organisations can interrupt far more than ordinary business operations. They can delay diagnosis, disrupt treatment, expose sensitive health information and prevent clinicians from accessing essential systems.

In opening remarks at a webinar on cybersecurity in healthcare, WHO Regional Director for the Eastern Mediterranean Dr Hanan Balkhy highlighted the need to strengthen the resilience of health systems against digital threats, according to the World Health Organization.

Healthcare’s digital transformation has expanded access to services and improved the movement of clinical information, but it has also created a larger attack surface. Electronic health records, connected medical devices, telemedicine platforms, laboratory systems and hospital networks now form a highly interdependent ecosystem.

Attackers understand that healthcare organisations face intense pressure to restore services quickly. This makes hospitals attractive ransomware targets and means that even relatively short outages can produce serious operational and clinical consequences.

The sector’s response must therefore bring together cybersecurity teams, healthcare leadership, clinical engineers, suppliers and frontline personnel. Incident plans should include safe manual alternatives for critical services, clear clinical escalation procedures and communication protocols for staff and patients.

The consequences of weak coordination were illustrated by the notification and accountability questions following the Change Healthcare breach. When interconnected providers share systems and data, responsibilities for containment, notification and recovery must be defined before an incident occurs.

Cybersecurity in healthcare is consequently not only an IT responsibility. It is part of clinical governance, service continuity and public-health preparedness.

ENISA seeks feedback on certification for managed security services

ENISA has published a draft European Cybersecurity Certification Scheme for Managed Security Services and opened it for public review.

The EUMSS scheme is being developed under the European Cybersecurity Act and is intended to establish common security requirements for managed-service providers, according to Industrial Cyber and the ENISA certification portal.

Managed security providers perform increasingly sensitive functions, including threat monitoring, vulnerability management, incident response and access to customer systems. A weakness or compromise at one provider can therefore affect multiple organisations simultaneously.

A European certification scheme could give buyers a more consistent way to assess whether providers meet defined standards. It could also reduce the need for customers to design completely separate due-diligence processes for every procurement.

However, certification will only be valuable if it demonstrates meaningful operational resilience rather than becoming another documentation exercise. Requirements must consider supply-chain security, personnel controls, access management, incident disclosure, service continuity and the provider’s ability to respond under real-world pressure.

This aligns with the wider move towards continuous monitoring of security controls and regulatory compliance, rather than treating an annual audit as evidence that risk remains controlled throughout the year.

ENISA’s public consultation runs until 13 September 2026. Respondents are encouraged to submit specific amendments and proposed wording alongside broader feedback.

The bigger picture

Today’s developments show cybersecurity moving from voluntary guidance towards a combination of enforceable duties, procurement controls and standardised assurance.

For healthcare organisations, security is being embedded into purchasing decisions and patient-safety planning. For essential-service operators, incident reporting and resilience are becoming legal obligations. For managed security providers, customers and regulators increasingly expect comparable evidence that services can be trusted.

The connecting principle is accountability. Organisations must know which assets and suppliers they depend on, who is responsible when systems fail and what evidence demonstrates that risks are being actively managed.

Cyber resilience cannot be purchased as a single product or achieved through a policy document. It must be built into leadership, procurement, supplier relationships and the daily operation of essential services.

Zoltán is a self-taught publisher and events organizer who has developed several brands and services that have increased the notoriety of his company within multi-billion dollar industries. In 2018, he has become a TEDx speaker and talked about reputation management in the digital era. As Co-Founder of HIPTHER Agency, Zoltan has helped develop highly respected online news portals, virtual and in-person conferences that cater to multiple industries on 5 continents. Among the developed brands and services you can find online news portals that cover several tech industries, gaming, blockchain, fintech, artificial intelligence, and more. In parallel, the company has built a portfolio of annually organized boutique-style conferences in Europe and North America. All the events organized by his company focus on bringing a wealth of information about the latest innovation in several industries such as Entertainment, Technology, Gaming and Gambling, Blockchain, Artificial Intelligence, Fintech, Quantum Technology, Legal Cannabis, Health and Lifestyle, VR/AR, eSports and many more. Zoltan enjoys writing articles on all portals owned by the HIPTHER Agency, talking at conferences, hosting the weekly HIPTHER Talks Podcast, and loves spending time with his family. Zoltan is a duathlete who enjoys training for different international competitions which include running and cycling.