Defense Just Lost Its Head Start. Ask A Hospital What That Costs.

Estimated reading time: 9 minutes

An AI agent ran a ransomware attack in July with nobody at the keyboard. When its first login failed, it read the error and corrected itself in seconds. Shelterzoom’s CEO says that becomes standard practice in months, not years.

The AI did not need a human at the keyboard. Chao Cheng-Shorland, co-founder and CEO of Shelterzoom, joined the Cyber Insurance News and Information Podcast to discuss that attack and what it changes.

The conversation covers a lot of ground. Why email still originates 91% of attacks. How ransomware payment bans look from inside a hospital. Where quantum decryption sits on the timeline, and why she puts it closer than most estimates. What underwriters should be asking about continuity, and whether demonstrable resilience deserves a pricing credit the way multi-factor authentication already does.

It starts with JadePuffer, the incident she describes as the moment the theory stopped being theoretical.

Cyber Insurance News podcast thumbnail reading AI Ransomware Is Here, with guest Chao Cheng-Shorland, CEO of Shelterzoom, over a darkened hospital corridor and workstation. This article is about the issue of business continuity in healthcare and other industries as a result of cyber risk.

Get The Podcast Here

Watch On YouTube

Watch Or Listen On Spotify

Listen On Apple Podcasts

Listen On Amazon Music

JadePuffer

An AI agent, built on open-source tooling, found an unauthenticated flaw and went to work.

“It did all the human operators could do. It’s much, much faster,” she said. “It basically hunted all the credentials, pulled all the API keys, even the cloud provider keys, even the keys for AI services.”

Then the part that should concern anyone pricing this risk. The first login attempt failed. The agent read its own error message, diagnosed the problem and corrected itself, in seconds.

“Everything happens so fast, and literally you don’t even have time to alert the cybersecurity team,” she said.

Asked whether JadePuffer was an outlier or a preview, Cheng-Shorland did not hedge. “It’s definitely the beginning of the new reality.” On how long before it becomes standard practice among ransomware operators: “I would think it’s in months rather than years.”

When Defense Stops Being Enough

That speed advantage changes what a control is worth, and it applies to every insured on the book.

The assumption underneath most cyber underwriting is that a competent security team, given adequate tooling, detects an intrusion in time to interrupt it. An attacker who reads error messages and self-corrects in seconds removes the interval that assumption depends on. Cheng-Shorland’s position is that the response cannot be organizational.

“You can’t have human governing anything in the AI era,” she said. “The AI has to be self-governed and self-defending. The system has to have that self-defense capability as well.”

Two structural weaknesses make that harder across every sector. The first is email, which she puts at the origin of 91% of cyberattacks and close to all ransomware. Cheng-Shorland points at the attachment specifically. “That paperclip is already 40 years old. It predates Windows 95, and it’s still in use by 70% of corporate users.”

The second is the tech stack itself, and particularly what happens when a well-run company acquires a badly-run one. “A very strong pattern is a legacy system that a very reputable company acquired,” she said, describing it as the door through which attackers reach the larger organization behind it.

See also  Resilience, CrowdStrike, and AWS Join Forces to Reduce Cyber Risk

Manufacturing, financial services, government and legal all sit exposed to the same combination. What separates healthcare is not the attack surface. It is what happens after the systems go dark.

Why Healthcare Ransomware Resilience Is A Different Problem

Healthcare absorbs a disproportionate share of these attacks for a reason that has nothing to do with weak controls.

“Healthcare, you can’t really stop,” Cheng-Shorland said. “Patients still get sick. The emergency people still need to come into the ED. The ambulance still needs to arrive.”

That makes hospitals reliable payers, and attackers know it. She argues the calculation gets worse after the payment clears. “They’d rather pay and get back in. But unfortunately, once they pay, they don’t get back in.” Her account of the pattern is that operators return partial access, enough to justify the transfer, while the records are already listed on the dark web.

The industry response has focused on prevention. Her argument is that prevention alone stopped being sufficient once attackers gained a speed advantage no defender can match.

“Defense is no longer enough. You have to be resilient. Resilient meaning you cannot let the hospital go down, regardless of what happened.”

Take The Cyber Insurance News Survey

Continuity During Failure, Not Recovery After It

The distinction Cheng-Shorland draws is one underwriters should find useful, because it separates two things the market often prices as one.

“We’re really talking about continuity during failure, not recovery after failure,” she said. “Everyone knows once you recover, you go, you continue, you do reconciliation. But what about the time? There’s a big gap between the time the system is down and before the system is up. That is the most vulnerable time.”

Hospitals already understand this in every other domain. Power fails, and a generator starts automatically. Her analogy for the digital equivalent is a spare tire rather than a second car.

“It doesn’t have to be as big or as expensive,” she said. “But you should at least have a spare tire to get you to the next destination, which is when your system gets restored.”

What happens without one is well documented and rarely visualized. Paper procedures kick in. Hospitals deploy what they call paper runners, staff who physically carry medication orders to the pharmacy and back. Cheng-Shorland says a complex emergency case that would normally take minutes to order can take half an hour to write up by hand.

She cites a 38% increase in mortality rates during downtime.

The 45-Day Problem

The financial mechanism is where this lands for insurers, and it operates on a longer timeline than most claims files.

“Most hospitals only carry cash for 45 days. Some carry for 60 days,” Cheng-Shorland said. “A lot of them only carry thirty days.”

Once a hospital reaches that threshold during an extended outage, the sequence described compounds. Claims cannot be submitted. Reimbursements freeze. Payroll comes due anyway.

“You can’t get an insurance claim back, everything’s frozen, you can’t get cash coming back in, you can’t pay your doctors anymore, and you can’t do anything. That’s when hospitals go bankrupt.”

See also  Cyber Insurance Cost Savings: NIST Framework Adoption Reduces Premiums by 33% for Healthcare Organizations

Cheng-Shorland says several hospitals she has worked with went under roughly two years after their ransomware incident, looking for an acquirer rather than a recovery. One closed in January, 45 days after the event.

Her conclusion is a reframing of the budget line. “That is why it is revenue protection, not a cost center.”

Should Resilience Earn A Pricing Credit?

Multi-factor authentication and tested backups already move cyber premiums. Asked directly whether demonstrable continuity capability should do the same, Cheng-Shorland reached for another vehicle.

“When you insure a car, if you don’t have a spare tire put in your trunk, it probably will reduce the rating,” she said. “I need to increase your premium because you don’t even have a spare tire to get you out of trouble.”

She goes further than a credit. In her view, carriers should be interrogating continuity capability at bind and should be prepared to decline without it.

“Insurers should say, I’m not going to insure you unless you have all this planning in place or the technology in place,” she said. “Every ransom, every cyber incident, or even just every downtime incident that doesn’t have to be a major cyber attack. Some hospitals go down for days because of an engineering mistake. All of that comes back to the insurer.”

What Resilience Does To A Ransom Negotiation

There is a second-order effect worth noting, and it is one that shows up in claims severity rather than frequency.

Cheng-Shorland describes hospitals that refused to pay and restored from backups over roughly three weeks. The insurer paid out regardless, because three weeks of disruption is expensive whether or not a ransom changes hands.

Genuine continuity changes the conversation while it is still live.

“You genuinely have leverage to negotiate,” she said. “We [don’t] need you. We have everything backed up. We already have another system going. Either you give it back, or you just wait for the FBI to come and get you.”

The Quantum Timeline

On post-quantum exposure, she is less optimistic than most published estimates and more direct about the reason.

“The readiness is still very low,” she said. “Initially, we were saying 2030. Then AI moved everything forward. I would say within the next twelve to twenty-four months it will arrive.”

The exposure that concerns her is not future encryption. It is data already stolen and held. Attackers harvest encrypted material now on the expectation of decrypting it later, which turns today’s breach into a liability that matures on someone else’s schedule.

She credits hyperscalers with moving faster than most, having already built post-quantum readiness into their service offerings.

The Chicken Coop

The metaphor Cheng-Shorland returns to explains Shelterzoom’s whole thesis, and it is a useful frame regardless of what technology a carrier ends up crediting.

“Everyone on this planet is building a coop,” she said. “All these technology companies are so busy building a coop because they want to keep their chickens safe. Unfortunately, the hackers are clever, like foxes. They always figure out a way to break in and eat the chicken, because your chicken is not protected.”

See also  Ransomware Negotiation, Cyber Insurance, and Cyber Hygiene: Takeaways from Kurtis Minder - NEW PODCAST

Shelterzoom’s position is that the file, in the “coop”, should carry its own protection rather than relying on the perimeter around it, using blockchain-based tokenization so that a document remains owned and revocable after it leaves the sender.

Whether that specific approach becomes standard is a question for the market. The underlying observation stands on its own. Every control an underwriter currently asks about is a coop.

FAQ – Healthcare Ransomware Resilience

What was the JadePuffer attack?

An incident in early July 2026 that Chao Cheng-Shorland describes as the first ransomware attack executed by an AI agent with no human at the keyboard. Built on open source tooling, it exploited an unauthenticated flaw, harvested credentials and API keys, and corrected its own failed login attempt within seconds.

Why is healthcare the most targeted sector for ransomware?

Because hospitals cannot pause operations. Patients keep arriving, so attackers know the pressure to restore systems is immediate. Cheng-Shorland argues that urgency makes hospitals reliable payers, and that paying often fails to return full access.

What is continuity during failure?

The ability to keep treating patients while systems are down, as distinct from recovering after they come back up. Cheng-Shorland compares it to a hospital generator or a spare tire, and argues the gap between outage and restoration is the most dangerous period.

Why do hospitals go bankrupt after ransomware?

Cash reserves. Most hospitals hold 30 to 60 days of cash. During an extended outage they cannot submit claims or receive reimbursements while payroll continues. Cheng-Shorland says several hospitals she worked with failed roughly two years after their incident.

Should cyber insurers price for resilience?

Cheng-Shorland argues yes, in the same way multi-factor authentication and tested backups already earn credits. She goes further, suggesting carriers should require demonstrable continuity capability as a condition of cover for critical infrastructure.

Full Cyber Insurance News Podcast Transcript

Download the full transcript of this episode. Transcripts are machine-generated and lightly edited. Accuracy is not guaranteed. Please refer to the audio for the record.

6 thoughts on “Defense Just Lost Its Head Start. Ask A Hospital What That Costs.”

Leave a Comment

×