Cyberattacks on healthcare organizations often look sudden. One morning the systems are locked, or a notice arrives that data has been stolen. But the attacker rarely arrived that morning. In many incidents, the intruder had been inside the network for days or weeks, exploring quietly, collecting information and preparing the moment of greatest impact.
The period between the first unauthorized access and its discovery is called dwell time. The shorter it is, the less damage an attacker can do. This post explains what attackers do during that time and the practical measures that help a small or mid-size organization find them sooner.
Dwell time is the gap between when an attacker first gets in and when you detect them. Ideally, that is minutes. In practice, it varies widely, and security reports regularly show that intrusions can go unnoticed for a long stretch. Because the number depends on the incident and the organization, avoid relying on any single figure. The key point is that a longer stay generally gives an attacker more opportunity.
An attacker who gets in through a stolen password or a phishing email rarely strikes immediately. Typical activities include:
Learning the environment. Mapping systems, servers, shared drives and user accounts.
Gaining more access. Looking for administrator credentials, so they can move beyond the first account.
Moving sideways. Reaching other computers and servers across the network.
Finding valuable data. Locating records, financial files and backups.
Disabling protections. Turning off security tools or tampering with backups to make recovery harder.
Stealing data. Copying files out of the network quietly, sometimes before any ransomware is deployed.
Setting up persistence. Creating hidden accounts or tools that let them return even if one entry point is closed.
Choosing the moment. Many ransomware attacks are launched at nights, weekends or holidays when fewer people are watching.
Healthcare organizations are attractive targets because data is sensitive and downtime affects care. Small organizations with limited IT staff may be especially exposed because no one is watching the logs.
Nobody reviews the logs, or the logs are not kept long enough.
Alerts are noisy, so important ones are missed.
Old accounts and shared logins blend in with normal activity.
Antivirus alone does not catch attackers using legitimate tools and valid passwords.
Unmanaged devices and forgotten servers sit outside normal monitoring.
Make sure your email platform, identity system, firewall and key servers record activity, and that the records are retained long enough to investigate. You cannot detect or investigate what was never recorded.
Watch for unusual sign-ins: unfamiliar locations, impossible travel, sign-ins at odd hours, repeated failures followed by a success and new devices. Many identity platforms can alert on these patterns.
Modern endpoint tools watch behavior on computers and servers, not just known malware. When combined with someone who actually responds to the alerts, they can catch an intruder's movements early.
Small organizations rarely have staff watching alerts around the clock. A managed service can supply that coverage. Ask exactly what is monitored, how fast they respond and what they are authorized to do.
Unexpected forwarding rules, new mail permissions and strange messages sent from staff accounts are common signs of compromise. Check for them regularly.
When accounts have only the access they need, and critical systems are separated, an intruder has fewer places to go. Use separate administrator accounts, protect them with strong multi-factor authentication and keep them from being used for everyday work.
You cannot protect what you do not know you have. Maintain a list of devices, servers, accounts and cloud services, and retire what you no longer use.
Keep systems updated, especially anything reachable from the internet. Close ports and remote access paths that are not needed. CISA publishes guidance and a list of known exploited vulnerabilities that can help you prioritize.
Keep backups separate from the main network and test restoring them. Attackers often look for backups first.
An incident response plan, with contacts and decision-makers identified in advance, shortens the time between detection and action.
Investigate promptly if you see accounts locked unexpectedly, security tools turned off, unfamiliar administrator accounts, unusual data transfers, slow systems for no clear reason or staff reporting strange prompts or messages.
No organization can prevent every intrusion, but you can make hiding harder. UnityCare IT helps healthcare organizations set up logging, sign-in monitoring and response processes, so unusual activity is noticed in hours instead of weeks.
Wi-Fi, switching, firewalls and internet that hold up across a whole facility.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172