Hi friend,

Thinking Like an Attacker: A Pen Tester’s Perspective on Why Penetration Testing Matters

I came across a number the other day that would keep most IT professionals up at night: 43,200. 

This is the number of ransomware attacks predicted to occur each day by 2031, based on rising industry trends. That’s an attack every 2 seconds (Cybersecurity Ventures, 2025). 

I’ll share another shocking number: 74. That’s the percentage of critical vulnerabilities that were not fully remediated by organizations in 2025 (2026 Verizon Data Breach Investigation Report). 

If that’s not enough to make you lose sleep, IBM Newsroom reported the average cost of a data breach was $4.99 million in 2025, and it’s only expected to rise.

Find Out Before They Do
The good news is that professional penetration testers can help identify your environment’s critical weaknesses by approaching it the way a real threat actor would. That perspective gives your organization a realistic view of your security posture. 

By identifying vulnerabilities, performing enumeration, and exploiting weaknesses through chained attacks designed to achieve privilege escalation and compromise, penetration testers show how an attacker could pivot through an environment, move laterally, and ultimately gain access to your critical systems and data.

Professional penetration testers also prioritize findings, explain business impact, and recommend remediation steps with validation testing to confirm the fixes worked. The result is a clearer understanding of your organization’s risks, gaps, and opportunities for improvement before a threat actor can discover them. That’s a much better way to get a good night’s sleep.

The Times They Are A-Changin’
Bob Dylan got it right when he sang, “The Times They Are A-Changin’.” That statement is more relevant than ever in today’s constantly evolving cybersecurity landscape. Two major developments are making a big impact across the industry: cyber insurance requirements and proposed HIPAA regulatory changes.

Over the past several years, cyber insurance underwriters have continued tightening their requirements. Controls such as multifactor authentication, EDR deployment, and documented incident response plans have become standard expectations for organizations seeking coverage. Alongside these, annual, sometimes more frequent, penetration testing requirements are showing up in policy renewals, which may force the conversation about whether your organization is ready or not.

An even bigger shift in the industry may be coming with the proposed changes to HIPAA regulations. Among these is a proposed requirement for covered entities to conduct penetration testing at least once every 12 months. If your organization doesn’t already have a regular penetration testing cadence, you may be required to establish one.

The Case for Penetration Testing
Whether the motivation comes from industry trends, insurance requirements, regulatory changes, or your organization’s own risk appetite, the direction is clear: penetration testing is shifting from a recommended practice to a business necessity. Organizations that establish a recurring penetration testing program today gain evidence-based insights that support future security decisions, strengthen their overall security posture, and reduce organizational risk. The question is no longer whether penetration testing provides value. The question is whether your organization can afford to go without it.

Katherine Ramage
Offensive Security Supervisor, BlueOrange Compliance

 

 

John DiMaggio to Join AI Governance Panel at MEDITECH LIVE 26

As Managing Director & Co-Founder of BlueOrange Compliance, John DiMaggio will join the Governance of AI panel on Wednesday, September 30, at MEDITECH LIVE where he will share strategies for balancing innovation with privacy, security, and patient trust, along with Darin Brannan, MD, MPH, FAAP, DTM&H, and Chief of Clinical Innovation from Bethany Children’s Health Center. Learn more about MEDITECH LIVE→


Consider Penetration Testing

You may be armed with firewalls, antivirus, and MFA, but are you confident that what you’ve done could prevent today’s sophisticated attackers from finding their way in? Are you able to document that your security controls are doing their job? CloudWave and BlueOrange’s Penetration Testing is a solid start. It can also provide actionable insight you can use to close security gaps, strengthen compliance, and protect patient care.

Learn more →


Bringing AI to our Security Risk Assessments

As artificial intelligence becomes more common across healthcare organizations, it’s introducing new security, governance, and operational risks.

To help clients address these emerging concerns, we are adding an AI-focused component to all Security Risk Assessments.

This enhancement will evaluate how AI is being used across the organization, identify potential gaps, and provide practical recommendations as part of the existing SRA process—at no additional cost.

It’s another way we are continuing to expand the value of its assessments as the healthcare technology landscape evolves.

Stay tuned for more information coming soon.

Meanwhile, don’t wait until compliance deadlines or cyber incidents put your healthcare enterprise at risk. Partner with BlueOrange Compliance for a HIPAA Security Risk Assessment that strengthens both compliance and patient safety. Learn more →


Become a Cybersecurity Insider

We’re excited to invite you to join our Cybersecurity Insider Program (CIP) — your exclusive gateway to the latest healthcare cybersecurity insights and resources.

Register today to get these exclusive benefits:

  • On-Demand Learning Library
  • Exclusive Member Offers
  • Early Access to Specialized Content
  • CIP Roundtables, Webinars, & Events

 


Events & Webinars

LeadingAge Annual Meeting  | October 25 – 28 | Philadelphia, PA | Convention Center, Learn more

📅 View All Events →


Product & Platform Updates

  • BlueOrange Compliance Elevates Cybersecurity with NIST CSF 2.0
    Healthcare organizations continue to face rising cyber threats, tighter regulatory scrutiny, and increasing operational pressure. In this environment, a strong, future-ready cybersecurity and compliance posture is essential. That’s why BlueOrange Compliance is proud to announce our transition to the NIST Cybersecurity Framework (CSF) 2.0, fully integrated with NIST SP 800-53 Rev. 5 and NIST SP 800-66 Rev. 2. This upgrade replaces our previous assessment approach rooted in 800-53 Rev. 4 and 800-66 Rev. 1, offering a more comprehensive, modernized, and aligned path to security and HIPAA compliance. Read More →
  • EDR Powered by SentinelOne: Simplify endpoint protection and visibility. Read More →

Resources & Insights

Thank you for being part of our BlueOrange Compliance customer community. We’re proud to support your mission to keep healthcare safe, connected, and resilient.

Stay tuned for next month’s issue!

– The BlueOrange Team