Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.

Sep 03 2026
Security

AI Is Changing Cyberattacks. Are Healthcare Incident Response Plans Ready?

Resource-constrained teams must rethink how they plan for security incidents in this new era of artificial intelligence.

For years, healthcare IT teams have built their cybersecurity plans based on a stable assumption: Both the good guys and the bad guys work at human speed, have human capabilities and follow logical paths in their thinking. 

Artificial intelligence is changing all of that. On the attacker side, hackers are accelerating their lateral movement and privilege escalation with AI-controlled agents that bring truly novel attacks to the table. But on the defender side, security operation centers can use AI tools to correlate alert data, bubble up the most important issues and even react in milliseconds to an ongoing attack. That means a highly compressed timeline for both sides — speed that traditional incident response plans don't account for. 

Organizations need to protect patient data, maintain clinical operations and keep information flowing between care teams. This means reviewing incident response plans with a new awareness for the complexities of AI. Here are three items that may need to be added.

Click on the banner below to learn more about how IT leaders are tackling newer cyber risks.

 

1. Automation 

Many IT administrators have avoided automated responses to attacks, especially in conservative environments such as healthcare that are averse to false positives. Unfortunately, AI's attack speed means that human-level response times are no longer good enough. Automate where possible to reduce response latency. 

A key success factor here is to set boundaries on AI agents reacting to attacks: Under what conditions can an account be disabled? An endpoint quarantined? A server taken off the network or blocked at the firewall

Incident response plans must allow for automated actions. Plans should list what types of attacks need an immediate and automated action. Fortunately, AI tools can be much smarter, more dynamic and nuanced about both attack and mitigation risk than older cybersecurity systems, something healthcare leaders should take advantage of for their incident response plans. 

2. Feedback and Training 

Letting AI agents respond to attacks doesn't mean accepting their advice as perfect and not to be questioned. Human analysts need to be in the loop for high-impact actions. Incident response plans should recognize this dual path: low-risk actions taken automatically, to be approved or rejected later, and high-risk actions requiring sign-off and validation by an analyst. 

Automating the easy stuff frees up analysts to dive deep on high-risk attacks. Isolating network segments, disconnecting federated trust, revoking administrative credentials — these high-impact actions should be part of the plan, but only after a human has given their OK. 

Just as important is the feedback to AI controllers and agents: Every now and then, you must tell your tools, “Your recommendation was erroneous or unsupported.” Training AI tools should be part of the incident response plan, so that lessons learned won't be quickly forgotten. 

3. Anomaly Detection 

Intrusion prevention systems identifying indicators of compromise used to be the gold standard for network protection. The unpredictable nature of AI-driven attacks has now changed that. Setting AI loose on the massive amounts of telemetry data available from networks, middleboxes and servers to identify anomalous behavior is the best way to catch an attack that has never been seen before. Now is the time to add AI-driven anomaly detection to incident response plans as a primary indicator of attack or compromise.

Morsa Images/Getty Images