
1. WHY DID YOU JOIN T4H26?
We are participating in T4H26 to be closer to healthcare stakeholders and address their priority challenges: service continuity, security, infrastructure modernization, and cost control. It is also a key moment to meet our partners and present a pragmatic vision, focused on concrete use cases.
2. HOW DOES THE CENTRAL THEME "CONNECT AND SECURE FOR BETTER CARE" CONCRETELY RESONATE WITH THE CURRENT PRIORITIES OF HEALTHCARE CIOS AND CISOS?
It resonates very directly with their current priorities: ensuring continuity of care while raising the security level of the HIS (Healthcare Information System) in a context of increased cyber threats, heterogeneous information systems, and budgetary constraints.
Concretely, "connecting" means making exchanges and interoperability reliable (sites, GHTs, applications, cloud, remote access) with networks and infrastructures capable of absorbing usage without degrading service. And "securing" translates into pragmatic actions: segmentation, strong authentication, immutable backups/DRP, supervision, and hardening, to limit the impact of an incident and ensure that the hospital continues to operate — ultimately leading to better care.
3. WHY DID HELIAQ CHOOSE TO PARTICIPATE IN CYBERCAMP SANTE, AND HOW DOES THIS EVENT ADDRESS THE VERY SPECIFIC CHALLENGES OF HOSPITAL CIOS AND CISOS?
Heliaq chose to participate in CyberCamp Santé because it is an event focused on the essential: protecting the continuity of care in the face of cyber pressure that has become daily in the hospital sector.
It very concretely addresses the specific challenges of CIOs and CISOs (heterogeneous IS, regulatory constraints, lack of resources, 24/7 availability imperative) by focusing on pragmatic and operational approaches.
It is also an ideal setting to share feedback, such as our Cleanroom solution, and co-build cybersecurity roadmaps adapted to on-the-ground realities.
4. FACED WITH THE MULTIPLICATION OF CYBER INCIDENTS, WHAT DO YOU CONSIDER TO BE THE ESSENTIAL PILLARS FOR ENSURING CONTINUITY OF CARE FROM AN IT AND SECURITY PERSPECTIVE?
-Resist (BCP), which means preventing downtime by securing existing systems: segmentation, hardening, access control, and supervision.
-Recover (DRP), which means being able to resume quickly with reliable, tested backups and realistic recovery scenarios. Finally,
-React (cyber-resilience), which means surviving an attack and restarting on a sound basis through controlled restoration in an isolated environment, restoring clinical activity while limiting operational impact.
5. HOW CAN MANAGED SERVICES HELP CIOS AND CISOS STRENGTHEN THEIR CYBERSECURITY POSTURE WHILE DEALING WITH OFTEN LIMITED INTERNAL RESOURCES?
Managed services allow CIOs and CISOs to strengthen their security level without relying solely on already heavily solicited internal resources. They provide dedicated expertise, continuous monitoring (24/7 as needed), and industrialized processes to accelerate detection, reaction, and remediation.
Concretely, this translates into better visibility of the IS, more rigorous management of vulnerabilities and patches, truly operational backups/DRP, and long-term steering via clear indicators.
The challenge is twofold: reducing risk and securing continuity of care, while allowing internal teams to focus on business and project priorities.
6. WHAT ERRORS OR BLIND SPOTS DO YOU MOST FREQUENTLY OBSERVE IN HEALTHCARE FACILITIES REGARDING SUPERVISION, DETECTION, OR INCIDENT RESPONSE?
The most frequent blind spots do not stem from a lack of tools, but from a lack of mastery of internal processes and resources.
We often observe overly partial supervision (incomplete scope, unqualified alerts), late detection due to lack of triage and escalation, and incident response that is still too dependent on a few key individuals. Finally, the differentiating factor remains human: without regular training, crisis exercises, and capitalization of feedback, teams lack the necessary reflexes on the day "everything stops" — and that's when recovery time explodes.
7. OVER THE NEXT 3 TO 5 YEARS, HOW DO YOU SEE THE ROLE OF HEALTHCARE CIOS AND CISOS EVOLVING IN THE FACE OF REGULATORY REQUIREMENTS, CYBER PRESSURE, AND IS RESILIENCE CHALLENGES?
Over the next 3 to 5 years, the role of healthcare CIOs and CISOs will clearly evolve towards a strategic resilience management function, on par with medical continuity and patient safety issues. They will have to reconcile increasing regulatory requirements, constant cyber pressure, and increasingly interconnected IS, while maintaining a high level of availability.Concretely, we will move from a "protect" logic to a "hold and restart" logic.
Their role will evolve from an "IT & security" posture to one of guarantors of business continuity, directly serving care teams. The challenge will no longer be just to secure an IS, but to protect clinical activity: access to EHR, imaging, emergencies, operating room, admissions... with a 24/7 level of demand.
In this context, they will have to orchestrate resilience designed "by use": prioritization of critical applications, controlled degradation scenarios, DRP/BCP tested with business units, and upskilling of teams.




