Photo pf Eric Belliere in a graphic with the words Secured Mindset

Belgian hospitals have recently faced cyberattacks that didn’t just hit systems, they disrupted care: causing operations to be postponed, slowing emergency services and locking access to critical medical data.

So what can healthcare organisations realistically do to protect themselves? In this Secured Mindset article, our cybersecurity expert Eric Belliere shares his perspective, grounded in real-world experience and a passion for data-driven insights. Eric unpacks why hospitals have become prime targets, how attackers exploit real‑world weaknesses (from the human factor to legacy systems) and what healthcare organisations can do to reduce risk and respond faster.

Why cybersecurity has become a matter of life and death

In recent months, Belgian hospitals have suffered several major cyberattacks, forcing the cancellation of surgeries, slowing down emergency rooms and jeopardising access to critical medical data. These incidents are part of a wider European escalation: the World Health Organization (WHO) now considers healthcare one of the most targeted sectors and the European Union Agency for Cybersecurity (ENISA) reported a 37% rise in ransomware attacks in one year, with service interruptions lasting up to 21 days.

Cyber risk in healthcare has become operational risk and ultimately, human risk.

To understand why hospitals have become such high-value targets, how attackers operate and what healthcare organisations can realistically do to protect themselves, we asked our cybersecurity expert Eric Belliere to share his perspective, grounded in real-world experience and supported by data.

A perfect target: Why healthcare attracts attackers

Hospitals combine several vulnerabilities that make them exceptionally appealing to cybercriminals.

  • High‑value data: Medical records and identity information are extremely lucrative, often fetching far more than financial data on the black market.
  • Human error: Staff across administration, HR, medical units and management all face daily threats.
  • Outdated systems: Many hospitals still rely on legacy software, unpatched devices and flat, poorly segmented networks. Around 75% lack adequate cybersecurity protection, and only 15% meet basic standards, especially around access control.
  • VPN weaknesses: Nearly 48% of ransomware cases start with compromised VPN access: a major issue in environments where remote connections are common.
  • Pressure and extortion potential: Hospitals cannot afford downtime. During the January 2026 attack on AZ Monica, more than 70 surgeries were cancelled, emergency services were disrupted and critically ill patients had to be transferred. When human lives are at stake, ransom pressure becomes even more effective.
  • Complex environments. Hospitals combine IT systems, OT/ICS (industrial control systems) equipment, medical devices and multiple external partners. This creates a landscape where even small misconfigurations can have cascading effects.

The human factor remains the biggest vulnerability and cybersecurity awareness is essential for every team, not only IT.

The 'human factor' was further analysed by one of our experts in a dedicated article within this series.

The real danger: When digital weakness becomes human impact

In a cyber incident, the most important factor is how fast you react and whether your processes are ready.

In hospitals, delays in diagnostics, treatment or medication workflows can directly impact patient safety. This means cybersecurity is no longer seen as a purely technical topic. It is part of the organisation’s duty of care.

Prevention matters, but detection, response speed and crisis preparedness are now just as critical.

Building resilience: How Nexova supports critical environments

Because threats escalate quickly, Nexova focuses on strengthening the capabilities that make the biggest difference during real incidents:

  • 24/7 SOC/MDR monitoring to detect attacks early and respond rapidly
  • Cyber awareness training for non‑technical teams, reducing the human‑error attack surface
  • Technical and leadership training covering incident response, crisis management and cyber governance, including realistic crisis simulations to test readiness.

The goal isn’t to overload hospitals with tools, but to give them what they need most: situational awareness, rapid reaction and solid processes.

Cybersecurity is now part of patient safety

Cyberattacks on hospitals are increasing in frequency and impact and Belgium is no exception. With outdated systems, high‑value data and limited resources, the sector faces a perfect storm. But with better awareness, strong monitoring and practiced crisis response, healthcare organisations can significantly reduce both disruption and harm.

Cybersecurity is no longer an IT concern. It has become a critical component of modern healthcare: as essential as sterile equipment and functioning medical devices.


Nexova provides specialist training, delivered by our highly experienced consultants and underpinned by our proprietary Cyber Integration Test and Evaluation Field (CITEF®) digital emulation platform. Find out about our Cyber Academy cybersecurity training.