HITRUST CSF – The Adaptive Framework That Is 99.64% Breach-Free
Key Takeaways
- Adopt an Adaptive Framework: HITRUST CSF helps organizations continuously respond to evolving cybersecurity threats and changing risk environments to deliver an adaptive system of protection.
- Address Third-Party Risk: 35% of breaches originate from third parties, and growing supply chain and vendor risks make visibility across systems and data increasingly important for identifying and managing vulnerabilities.
- Measure Security Performance: HITRUST’s reported 99.64% breach-free statistic for 2025 demonstrates a strong track record of measurable, validated security performance.
- Prepare for AI Threats: HITRUST CSF maps controls to MITRE ATT&CK and MITRE ATLAS, helping organizations address emerging threats associated with AI and evolving attack techniques.
Gaps in visibility across systems and user activity contribute to a growing confidence gap among leaders (CISOs and other decision-makers), as they work to manage risk, safeguard data, and respond to increasingly sophisticated threats. This challenge is further intensified by the expansion of the attack surface to include supply chain dependencies – especially vendor risk – as well as emerging risks associated with generative AI.
An Increase in Risk
The Verizon DBIR reports that third‑party breaches doubled from 15% to 30%, increasing the risk for supply chain risk management and contributing to the potential lack of visibility that could create the blind spots – or even just one blind spot – needed for attackers to exploit. SecurityScorecard’s 2025 Global Third‑Party Breach Report also found that 35.5% of breaches originate from third‑party compromises.
AI agents can impersonate user identities to execute attacks, enabling them to scale rapidly and operate with high efficiency. These threats are particularly difficult to detect, as they closely mimic legitimate user behavior and can obscure their identity within system logs.
A survey of 600 leaders conducted by Sygnia found that 73% of decision-makers have implemented risk management programs but are not confident in their organization’s preparedness. Many expressed concern that their organization would not respond effectively in the event of a cyber incident, and the survey specified the following:
- Organizations have implemented risk management practices but still lack confidence in their effectiveness.
- 75% of the organizations surveyed reported having experienced a breach.
HITRUST CSF – The Adaptive Framework
HITRUST CSF is a threat-adaptive framework with an impressive breach-free statistic of 99.64% for 2025, and 99%+ for four years leading up to and including 2025, positioning itself as “measurable, validated security performance.” It is considered the gold standard of cybersecurity assurance and information risk management, especially in regulated industries like healthcare. It provides the rigor and proven track record of helping organizations map their controls to evolving real-world attacks and attack behavior.
HITRUST CSF explicitly maps to NIST CSF and NIST 800-53 in a formal framework that consists of standardized, prescriptive control requirements that help organizations reliably compare vendors across industries in a consistent format. HITRSUT CSF also provides strong audit strength through an independent validation process and quality assurance.
HITRUST for AI Threats
As a cyber threat-adaptive framework, HITRUST aligns its control requirements with MITRE ATT&CK and MITRE ATLAS (for AI) through control-to-threat mapping, leveraging these repositories of real-world adversary behaviors to ensure controls mitigate relevant tactics, techniques, and procedures (TTPs), including those associated with AI-enabled threats.
HITRUST offers a HITRUST AI Certification that is independently assessed and validated for AI systems, validating that an organization’s AI systems are secure, controlled, and defended against AI-specific attacks. MITRE ATT&CK and MITRE ATLAS describe the attacks, and HITRUST CSF maps the control requirements to MITRE ATT&CK and ATLAS to provide quarterly analysis and reporting.
Final Thoughts
The information security landscape has become increasingly complex due to expanding supply chain risks and the growing need to manage third-party risk, particularly associated with SaaS-based services. Visibility across systems and data is becoming more challenging as environments become more decentralized and less standardized. As a result, gaps in threat identification and vulnerability detection increase the risk that attackers can successfully exploit weaknesses within the environment.
McKonly & Asbury’s HITRUST team is available to assist your organization in evaluating what assessment report best fits your needs. For more information, be sure to visit our HITRUST page and don’t hesitate to contact Dave Hammarberg, CPA, CFE, CISSP, GSEC, MCSE, CISA with further questions regarding HITRUST and our services.
About the Author
Chris Fieger, CPA, CISA, CISM, CCSFP, CCP is a Senior Manager with the firm. He is a member of the firm’s System and Organization Controls (SOC) & Technology Practice, performing SOC 1, SOC 2, and SOC 3 engagements, as well as HITRUST an… Read more