Skip to content
IT Security

Jan 26, 2026

The Security Control Failure that Change Everything

Operational resilience and security control are now executive-level mandates. Learn how leaders must govern and evidence both under new regulations.

Illustration of a hospital building surrounded by warning icons for a security breach, including an open padlock, alert sign, and virus symbols.

It didn’t take a sophisticated attack or a complex system failure to cause widespread disruption; just one missing control was enough to change everything.

 

Watch the full Live Video

A Single Control Failure That Changed Everything

Sometimes resilience fails in the smallest, most preventable ways.

Last year, attackers exploited the absence of multi-factor authentication on a critical access point, triggering a chain reaction no organization wants to experience. This was not a sophisticated zero-day or nation-state attack, but a straightforward intrusion that enabled ransomware and disrupted healthcare operations across the United States.

The consequences were immediate, measurable, and deeply human.

The Control That Was Missing

Two-factor authentication (2FA) is widely recognized as a foundational security measure. Its absence enabled:

  • Credential misuse
  • Lateral movement within systems
  • Rapid escalation of the attack

This is not about advanced tooling. It’s about baseline discipline.

The Impact at a Glance

Area Affected Outcome
Healthcare operations Disruptions across multiple facilities
Patient data ~33% of patient records exposed or at risk
Financial cost Over $3 billion in total impact
Operational continuity Delayed care, system outages, emergency procedures
Human impact Patients, clinicians, and staff affected immediately

Why This Matters

This incident underscores a critical reality:

  • Resilience does not fail only because of complex threats
  • It often fails because of basic controls left unimplemented
  • The smallest gaps can carry outsized consequences

One missing control did not just compromise systems—it disrupted care delivery and placed real people at risk.

The Root Cause

While the missing multi-factor authentication may appear to be the root cause, it was really a symptom of a larger problem.  The real issue was the absence of clearly defined security standards, along with unclear ownership and insufficient oversight. Without enforced baselines and accountability, a foundational control was allowed to remain inconsistent. This was a governance failure, not a technology failure.

Key Takeaways for Leaders

Missing controls are symptoms of weak standards, ownership, and oversight. Critical controls must be consistently applied and verified across essential services. In regulated, mission-critical sectors, basic control failures can scale into multi-billion-dollar losses and repetitional harm.

Final Thought

This is one example among many. The lesson is clear:
Small gaps create massive failures.

The full breakdown and context are available in the original video linked above.

Latest Articles

Is Shadow AI the New Shadow IT?
Operational Resilience

Is Shadow AI the New Shadow IT?

Explore the rise of Shadow AI and its governance challenges, mirroring past issues with Shadow IT. Learn how organizations can manage AI re...

June 15, 2026

How Does Process Ownership Affect Operational Resilience in Enterprise Environments?
ITSM Best Practices

How Does Process Ownership Affect Operational Resilience in Enterprise Environments?

Discover how clear process ownership enhances operational resilience in enterprises, fostering accountability, consistency, governance and ...

June 08, 2026

Assessing AI Compliance for Operational Resilience
Operational Resilience

Assessing AI Compliance for Operational Resilience

Discover how to assess AI compliance for operational resilience, focusing on governance, risk management, and accountability in your organi...

June 01, 2026