
AI is compressing the timeline of cyberattacks from days to minutes and healthcare organisations are especially exposed.
In this Q&A, Jim McGann, CMO at Index Engines, explains why traditional defences like backups and immutable snapshots aren’t enough on their own, and why “recovery confidence” is becoming the new benchmark for cyber resilience in healthcare IT.
1. With AI accelerating the pace of cyberattacks, how should healthcare IT leaders rethink cyber resilience?
The more useful question is not whether every attack can be prevented, but can we recover from every attack.
In healthcare, where downtime can disrupt delivery of patient records and critical information, the better question is how quickly and confidently you can recover.
Prevention will always be essential, but it has never been enough on its own. Healthcare organisations that prepare for recovery before an incident occurs will be in a much stronger position than those relying solely on stopping every attack.
2. Many health systems already have backups, replicas, and immutable snapshots. Why isn’t that enough?
It’s because having a copy of the patient’s data is rarely the problem. The harder question is whether the recovery point is actually clean.
If compromised or corrupted data is restored, the attack can be reintroduced into the environment, extending outages and increasing operation disruption. Recovery isn’t simply about restoring data, it’s about restoring trusted data.
3. How has the shift toward connected care and digital health changed the way ransomware affects healthcare?
There are now more pathways into healthcare environments than ever before.
Connected care, cloud platforms, third-party vendors and digital health technologies have made care more efficient, but they’ve also expanded the number of trusted relationships that attackers can exploit.
Jim McGann
AI is simply accelerating how quickly those pathways can be identified and used. That‘s why cyber resilience is no longer about preventing every attack. It’s about recovery confidence – knowing you can restore clean, trusted data and safely return clinical operations to normal when an incident occurs.
4. You’ve spoken about “recovery confidence” as the next security metric. What does that mean?
Security teams have traditionally measured success by how quickly they detect an incident and how quickly they respond. Recovery confidence adds another dimension: knowing, at any given moment, that your most recent recovery point is clean and can be restored safely.
As AI models with Mythos-like capabilities continue to accelerate how quickly attackers can identify and exploit vulnerabilities, that confidence becomes just as important as prevention, especially in healthcare, where access to trusted data directly supports patient care.
5. There’s been a lot of discussion around Mythos recently. From your perspective, what’s real, and what’s simply noise?
Mythos isn’t a skeleton key that suddenly breaks every security control.
What it does demonstrate is how AI can rapidly identify pathways that already exist, including vendor connections, remote access, managed service providers, and partner integrations.
Those relationships have always been part of modern IT. What’s changed is the tempo. AI can now map and exploit those pathways in minutes instead of days, making resilience every bit as important as prevention.
6. As AI capabilities continue to advance, what should healthcare leaders take away from both JadePuffer and the recent discussion around Mythos?
Models like Mythos are accelerating how ransomware can easily circumvent traditional security tools, and emerging AI variants such as JadePuffer are automating attacks outright.
It’s scary, but they don’t change the fundamentals of cyber resilience.
Prevention remains essential, as does resilience, recovery, minimising the impact of an attack. The organisations best positioned for what’s next will be those that know they can recover quickly, and, more importantly, recover with confidence by restoring clean, trusted data when it matters most.
Jim McGann, CMO at Index Engines
Jim is a globally-experienced marketing and business development executive instrumental in developing key relationships and brand development at Index Engines.
Jim is experienced with both large established software firms and emerging startups and is a frequent writer and speaker in the areas of ransomware recovery, cyber resilience and unstructured data management.

