The Signal Room | AI in Healthcare: Strategy, Governance & Ethical Leadership
The Signal Room is a healthcare-AI podcast hosted by Chris Hutchins, founder of Hutchins Data Strategy Consultants, for healthcare leaders implementing AI with strategy, governance, and ethical leadership. The show goes deep on AI strategy for healthcare, AI governance in healthcare, healthcare governance, ethical governance, ethical AI leadership, and responsible AI development — with CMIOs, chief AI officers, and operators driving trustworthy AI systems, clinical AI implementation, and AI compliance in healthcare across real-world health systems.
Each conversation unpacks healthcare AI ethics, healthcare AI risks, AI bias in healthcare, algorithm bias healthcare, health tech governance, AI implementation for healthcare leaders, ethical leadership in AI, and the practical realities of responsible innovation in healthcare.
If you are an AI strategist, healthcare executive, CMIO, chief AI officer, or AI governance leader committed to ethical leadership in AI, The Signal Room equips you to lead AI transformation effectively and responsibly. Join us for AI risk management in healthcare, healthcare data governance, AI strategy for executives, executive decision making in AI, and the trustworthy AI systems shaping clinical decision support and the future of healthcare AI.
The Signal Room | AI in Healthcare: Strategy, Governance & Ethical Leadership
Cybersecurity, Healthcare Security, Human Risk, AI Governance, Phishing, vCISO
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Cybersecurity failures do not begin and end with technical controls. They often begin with normal human behavior under pressure: urgency, trust, distraction, and the desire to help.
Chris Hutchins talks with Craig Taylor, co-founder of CyberHoot and a cybersecurity leader with decades of experience, about why punishment-based awareness programs fail and how positive reinforcement can build stronger security habits. Craig walks through the anatomy of modern social-engineering attacks, the ways AI is making those attacks more believable and more damaging, and the difference between checking a compliance box and building a culture that can respond.
They also discuss AI governance, approved tools, faster patching, data reduction, password managers, virtual CISO support, and the practical fundamentals healthcare leaders can act on now.
In this episode:
- Why fear and punishment do not create durable security habits
- How social engineering exploits ordinary human behavior
- What AI changes about phishing and cyberattacks
- The relationship between cybersecurity and AI governance
- Why positive reinforcement and psychological safety matter
- Practical steps for leaders, teams, and individuals
Connect with Craig and CyberHoot:
- CyberHoot: https://cyberhoot.com/
- Free individual training: https://cyberhoot.com/individuals/
- CyberHoot blog: https://cyberhoot.com/blog/
- Newsletter: https://cyberhoot.com/newsletters/
- Email: sales@cyberhoot.com
Offer mentioned during the episode: listeners who mention The Signal Room may receive 20% off their first year after converting from a free trial.
Craig’s CyberHoot role and approach are confirmed on the company’s official site. About CyberHoot.
About The Signal Room: The Signal Room is a podcast and communications platform exploring leadership, ethics, and innovation in healthcare and artificial intelligence. Hosted by Christopher Hutchins, Founder and CEO of Hutchins Data Strategy Consultants. Leadership, ethics, and innovation, amplified.
Website: https://www.hutchinsdatastrategy.com
LinkedIn: https://www.linkedin.com/in/chutchins-healthcare/
YouTube: https://www.youtube.com/@ChrisHutchinsAi
Book Chris to speak: https://www.chrisjhutchins.com
Welcome back to the Signal Room. I'm Chris Hutchin. Quick thing before we start. I wrote a book. It's called Beneath the Signal, and it's about the human work behind trusted data, responsible AI, and healthcare. If that's your job, go search Beneath the Signal at Amazon Dow and pick up your copy. Okay, here's our episode. Most conversations around AI, risk, and healthcare go straight to the model. Is it accurate? Is it biased? Was it validated? My guest today works on the part of the risk that isn't in the model at all. It's in the people using it. Craig Taylor has been a certified information systems security professional since 2001, with more than 30 years in cybersecurity. He's led organizations like CSC, JP Morgan Chase, and VistaPrint. In 2014, he co-founded Cyberhoot to teach the world cyber literacy. And today, he runs a virtual CISO practice serving more than 15 companies. And his core claim is an uncomfortable one. Even excellent controls do not fix human behavior. I want to bring that lens into the hospital floor where AI governance and security have to live in that same room. Craig, welcome to the Signal Room.
SPEAKER_02Chris, thanks for having me. It's great to be here.
SPEAKER_01As I said, I've been really looking forward to this because there's a there are some areas that I think a lot of people are really familiar with when it comes to cyber in terms of risk, what kind of insurance coverage you have to have, all those things. But the piece that I'm so excited to hear you talk about is the human piece of it, because there's really not enough safeguards that we should be sleeping on what may or may not be going on. So do before we get into the the details, maybe talk a little bit about you know who you are, um, what really led to you getting into the the space that you're in and what what maybe a little bit about what you're doing at Cyberhood.
SPEAKER_02Sure. Thank you, Chris. So as you explained earlier, I have a 30-year career in cybersecurity, but it didn't start that way. I started out with a degree in psychology where I studied operant conditioning, how people learn and how people change their behaviors. And that actually was a foundation of an excellent foundation for building a learning management system for the simple reason cybersecurity has been off on a tangent that's heading in the wrong direction of bigger sticks for clicks, punishing employees for making mistakes. And what we've learned in psychology for the last hundred years is that punishing behaviors doesn't exterminate the behavior or stop the behavior. It actually just suppresses it a little bit for a short period of time and then it recurs. What does change behaviors and what we're focused on exclusively at my company, Cyberhoot, is positive reinforcement of good behaviors. The behaviors you want to see more of, you reward. No different than it's a crass analogy, but training dogs with shot collars doesn't work either. But training dogs with treats, and my goodness, they'll bring you the leash to go to the dog park, right? They want the treat, they want to, they come, they sit, and my dog does this every night when he goes out for his uh nightly pee. Comes back to the door, he sits down, he looks at me. Do I get a treat? Is it a treat time? Because we reward him for coming back after his his uh bathroom break. So that's really where the human behavior and the psychology comes into play in the not only the cyber literacy training that we do at Cyberhoop, but what we're gonna talk about today with the use of AI. We need to think about this. There's a very, I would say, tumultuous couple of years in front of us as AI becomes the norm in all the different healthcare organizations of the world and all the businesses listening to this, and how we navigate through that is going to be fundamental to our success or our failures in this space.
SPEAKER_01Yeah, it's a it is an interesting phenomenon that's out there. The conversations you hear most often, I'm sure that you know this very well, which is obviously why you you're having success with bringing this kind of an approach to cybersecurity. Uh, you've built your entire practice around the human risk versus the the technical controls that typically are getting the attention. What does human risk management actually mean? And why is it the piece that most security programs underinvested?
SPEAKER_02Well, you kind of said it in the introduction, right? You can put all the technical controls you want in place, but there are human tasks that all the technical controls allow through, such as email to your inbox. Your inbox lives on your computer. And if you click on the wrong thing or you're not aware of what you're doing, let me know if now's a good time to tell a quick analogy or a quick story to put this in real terms for your listeners. So we had a breach that was reported to us. Our virtual CISO practice also handles forensics. And this happened to be a CPA firm. But let's imagine it was a doctor's office. I'll translate into a doctor's office for you. The front desk gets an email saying, I missed my mammogram, my colonoscopy. I need to have see a GP, need to see my GP to get an appointment, but I need to do it virtually, like this telemedicine thing. So could you fit me in? It's kind of urgent. And you know, the receptionist will look at that email, say, sure, let me see if your GP has an opening for a telehealth, you know, a video conference meeting. It's more common now since COVID, right? So fast forward a week, there's a meeting scheduled, it's say a Zoom link, and the patient emails in, I can't get on your Zoom link, but I have a Teams account. Would you mind joining my Teams meeting instead? And there's trust, there's urgency, there's authority in that I have something you can use to solve my problem. And we are 10 minutes late into this telehealth meeting. So the physician says, sure, send me the link. And they click on the Teams meeting link. But it's not a Teams meeting. It says HTTPS, teams.microsoft.com, and then some dots, and the rest is hidden from the screen. And the in the urgency and the authority of that time frame, the physician doesn't hover over the link or the CPA firm didn't hover over the link. And it's truly a click fix like attack where clicking that link pushes an RMM solution to the desktop. And the user, if they have the correct permissions for the administrative rights, which most people should not operate. I don't use administrative rights, and I'm a cybersecurity professional on my desktop. It has the permissions to silently install a remote access solution, Teams Viewer, some RMM solutions, some Python scripts and tools. And the next thing you know, you have a secret door into that healthcare provider or CPA firm, all from the ruse of help me out. I I missed filing my taxes, or in this case, I missed my appointment and I can't get on your telehealth zoom, so do this other version. Now, I'm sure that won't wouldn't be a common thing in your healthcare providers because you have legal requirements to use certain telehealth software so that the data is stored safely and securely. But this really did happen to a CPA firm, and it is as simple as having that urgent replacement link that you can convince someone on the target to click on. And so this happened. It led to a breach, it led to a ransomware event, it led to extortion and a lot of headaches simply because a company was targeted and nursed for a few communication emails along the way, and then an end user was convinced to click. That's how easy it can be, and that's how it can happen. And so that's what we're all up against.
SPEAKER_01Yeah, that it it's it's interesting. You know, I I've been inside of health systems for for the majority of my career, and some of the things that I've seen happen over over time. I'm encouraged by it because there are people inside the organizations, at least at least the ones that I've worked for, uh, that really were solid and had a pretty aggressive approach to making sure that we are as current as we could be in terms of protections, but it still does not solve the the human problem. I mean, the example you gave is is you know enough enough uh evidence from from where I'm sitting that that there's a real need to look at the human behavior component of it. Besides the the obvious from the scenario you just painted, what are some of the other factors that and what what caused you to really start to think about the human side of it? And in particular, I believe you talked to me, talked to me a little bit about uh psychology, was part of your your education as well, that had you know kind of got you pretty deep into this kind of stuff.
SPEAKER_02So we we need to always concern ourselves when we build a cybersecurity program to protect the data that's entrusted to us, whether you're in healthcare or other companies or other areas of field. And you we you know, a technology stack is important, so putting in the appropriate firewalls and the guests the the the desktop EDR and probably the detection and response uh solutions, and the technical stack has to be solid. But because email and because users go surfing the internet, uh and there are so many threats out there that have basically been put on steroids by artificial intelligence that can create very believable, very desirable emails based on targeted attacks to individuals whose social media profiles are consumed by AI. We need to educate our end users in a way that they'll listen. Too many times we see companies today that use bigger sticks against the clicks that their employees make mistakes on, and that leads not to change behaviors. That's not what psychology would say will happen. It leads to apathy and an abdication of responsibility. I've talked to so many individuals, Chris, who have said I clicked on one or two of my comp my own company's phishing emails. I made mistakes, I got 45-minute videos. I give up on this stuff because no one's ever taught me how to spot and avoid these phishing emails, whether it's real or or or or legitimate from my own IT team or it's a hacker attacking us. So I make no mistakes now because I forward everything to IT. I don't understand this, and I'm not gonna learn this, and I give up. I'm just forwarding it all to IT until, truthfully, Chris, they say that, but then there's the golf book a free golf outing on us email to the avid golfer because he's socially social media to post his, you know, 70, he broke 80, and and so he's really into golf, right? And here's a free golf outing to his favorite course. Of course, he's not going to forward that because he wants it to be true. He clicks and the rest is history. So, what we have to do is we have to recognize the psychology behind creating a high engagement, a cyber aware culture, people that want to learn this stuff because it's not punitive, it's rewarding. And so at Cyberhoot, we basically built a gamification system that rewards making good decisions in phishing simulation. So we don't trick anyone, we're not deception in the inbox, phishing testing. We're in simulation in the browser based on an assignment you receive in your email. So your assignments from Cyberhoot are twice a month. You get a video that might teach you about something that's an emerging threat. We've sent videos on overpayment scams or financial scams. Like you got paid too much money on something you sold on Facebook Marketplace before you refund that money, you might want to wait for the money to clear your account because it's probably not. And so we we do all these different videos that train people on common theme scams, romance scams, whatever it might be. But we do this phishing simulation, and as you go through and you pick and choose, is the sender safe or is it suspicious? Is the greeting or the subject safe or is it suspicious? We're rewarding you with points towards an uh leveling up of your avatar, a certificate of completion for your continuing education credits. We make it fun and gamified where you can compete on an anonymous leaderboard within your company or a non-anonymous. In other words, you can invite friends in your finance division to compete to see who can get the highest scores over time and lead the leaderboard. And that creates a game where people compete with one another for a little bit of friendly, fun competition, but it removes the work aspect of it. So people don't mind doing it. And the outcome is that they learn how fishing works. There's this old saying that I love to use feed a person a fish, feed them for today. Teach them how to fish, feed them for a lifetime. Now that's F-I-S-H, but we have the same word in cybersecurity, fishing, P-H-I-S-H, which is this social engineering attack. So if we can teach people how hackers fish us and teach them with authority, like confidence, efficiency, they're going to participate if it's a game, if it's fun, if it's short, and if it's non-punitive, but rather positive reinforcement. And that will actually lead to behavior change that sticks for the long term. There's a technical way of explaining this. It's an internal locus of control when you do a reward system. People internalize this because they want to remember how to get the rewards going forward, just as your dog comes back to the door at night, as opposed to the shock collar, where it's like, how do I get out of this? How do I escape? I don't want to be shocked and make mistakes. There's no internal learning there. It's all an external locus of control as punishment. So that's the human behavior that we all live with. And my 30 years of cybersecurity experience has shown the psychology does work. When you reward the good behaviors and you gamify it, you remove the work aspect of things and you make it more of like a video game of sorts, right? Where people want to play, they want to level up, they want to show their levels and their accomplishments. That really does create engagement, positive outcomes that last.
SPEAKER_01Maybe we talk a little bit about that and how you've seen organizations start seeing some measurable improvements with this approach that you you bring to the table.
SPEAKER_02Sure, Chris. And I have two firsthand knowledge events, right? I have two breaches that I managed in this year. Uh there's just been a growth in breaches. There's more attacks. We know this from the AI and from what's happening out there. There was an advisory about AI recently from the Five Eyes organization talking about the threats we face from AI. That's another topic for another day. But here's two examples of what a positive culture can create in terms of reporting a breach quickly and containing it, versus what a fear-based culture creates and people not wanting to admit mistakes and kind of hoping nothing bad happens, and I'm just going to keep quiet. So, in the first breach, we had a company going through cyber who training, positive reinforcement. They called out the highest performers and they gave gift cards or free lunches to the division that had the highest compliance. Everyone was encouraged to participate. The gamification was recognized, and the public recognition was all positive. And someone yet still makes the mistake. They clicked on a link they shouldn't. They thought, this, I need to let my IT team know that I did something wrong. And so they did. IT team swooped in within 30 minutes. It was reported and looked at. And yes, there was the beginnings of a of an attempt to install something remotely. It didn't work quite as expected, but it was they were able to shut it down, shut the PC down, get it offline, cleanse it, put it back in service. And at the end of the day, there was no reportable breach. They caught it in the cusp. And it's because the culture was if you see something, say something, and you'll be rewarded for doing so, even if you made a mistake, because while we teach you, we don't punish you for uh failures or mistakes. Second company, traditional attack messages to the it box. If you clicked on one, you got three warnings and then you're fired, right? The first warning was a meeting with your manager, the second was with HR, the third was you're out the door. Everyone was fearful, everyone forwarded things to IT. The IT department spent 10, 15, 20 hours a week responding to individuals who didn't know if it was a fish or not. And, you know, the false positive rates of email sent to IT was very, very high. And people were afraid. Someone made a mistake. Let's use that golf outing as an example. They clicked on the free golf outing and nothing happened. Or their machine started to slow down. And there were indicators that were subtle, but things weren't quite hunky-dory. Guy just kept quiet, didn't say a word. And, you know, a couple weeks go by and suddenly we identify there's someone in the network, there's an incident, we track it back to this person's machine, and we ask, why didn't you say something? And well, truthfully, you know, I don't know. I just didn't think there was any problem. But the real truth is that there was a culture of punishment and negative, you know, fear and shame for making mistakes. So things went unreported. Those two sides of the coin can lead to success or to failure in these scenarios, right? A quick response to a breach can contain the blast damage. A slow response or no response means it's just going to compound exponentially.
SPEAKER_01Yeah, that's a the the the psychological safety component of this thing, these type of activities is so it's so under recognized, I think, at least in my in my my experience. I'm sure you you have a better and more comprehensive experience than that. But I I think the the approach has always been, you know, from a compliance standpoint, everybody just needs to do their part, be attentive. And you know, we we kind of go through the motions, but it without the operational components of it, that I think you've been you've been working on. There's not a I haven't seen a model that was truly effective in the way that you're describing. I've seen organizations improving, no, don't misunderstand me, but I think this is at a different level. And I think we are at a point in time where it really does have to go into this really operational mode so that it becomes just part of how people operate. They understand it from the beginning. And they, you know, whether or not there's a reward system, the ownership of that responsibility is something that everybody in an organization has to be the cave to.
SPEAKER_02You're absolutely right, uh, Chris. You want everyone to buy into this, right? Twenty years ago and even 10 years ago, people said, well, security is not my job. It's the IT department lead. Now we come to recognize that it that sort of cybersecurity is everybody's responsibility, but I think we've missed the opportunity to take a multidisciplinary approach to the problem. That's the real key here, right? And that's, I think if you look across all of science, all of the industries of the world, the companies that do the best are the ones that don't take just a single focused of blinders-on view of their problem. They look at it from multiple dimensions, right? Uh, you want to bring in human resources, you want to bring in psychology, you want to bring in a technology stack that helps prevent mistakes from compounding by having great detection, great notification and alerting, maybe even a honeypot inside your network, especially as we approach, you know, the the AI breaches that may be coming. But at the end of the day, when you look at a problem from multiple dimensions, multiple disciplines, you're gonna find a better solution, a better resolution. I think that's what we've stumbled upon here at Cyberhoot, simply because through trial and error, we've recognized that in our beginning, in truth, and and going back right to the beginning, Chris, we tried to be another attack phishing company sending these messages to the inboxes, and we pivoted very quickly based on my background and some of the other co-founders here's experience of what wasn't working. And look, look in the news media. Do you need any more confirmation that cybersecurity seems to be lost other than how many breaches we see every day, how many ransomware events? I mean, it's become the norm. It's bec it used to be when you got that one letter in the mail, you're like, oh my God, my data was exposed. What's gonna happen? Now I get them every other month. It happens so frequently that we have to ask ourselves, are we doing things the right way given the number of breaches and the number of mistakes people are making? And I think the answer is no, we're not. We have to rethink how we're approaching changing behaviors and making people more aware and more engaged and more responsible for their own cyberliteracy. And the the huge benefit here is that this all applies personally as much as professionally, right? I've been at companies where I've had people say, I can't come into work today because my identity's been stolen, and I have to go to the courts and prove I am who I say I am because someone else has stolen my identity. You're going to help people personally, and we shouldn't look at this as a work cost, it should be a work benefit for employees when. And it's constructed in a way that's positive, rewarding, gamified, where people enjoy participating, and the the merits and the benefits extend into our personal lives.
SPEAKER_01So Yeah, I I love that because you're talking about really it's something you're doing to benefit your team. The protection aspect of it, I think, is probably under-emphasized far too often, but I think it's it's such an important factor because people oftentimes are not looking at it from the big picture. They're just like, oh man, I hate doing these annual compliance trainings.
SPEAKER_02Well, it's a checkbox for the cyber insurance. Do you train your staff once a year for four hours? Does working out at the gym in January 17th work for four hours? You know, does that is that person who goes for that first one? Are they gonna come back? No. Are they gonna hurt themselves? Probably, right? You need to do this period, you need to do what we call HIT in cybersecurity, high interval training, high-intensity training, where you you do short little bursts, three to five minutes, once or twice a month, and over time you begin to change behaviors. If you try to do it all once a year on a checkbox exercise, you're just doomed to failure.
SPEAKER_01Right. You know, there's a it's it strikes me that you know we're in a period of time where it seems like every day or every couple of days we're hearing more about governance when it comes to data and AI within within the healthcare organization. But let me talk a little bit about the the the differences between the two things because when you're thinking about governance, these organizations that I've been part of over the years, there's this legacy perspective that exists because organizations have tried to formalize governance ahead of the point in time where they actually have something for people to govern. AI is dramatically shifting that from a timing perspective because it's no longer the traditional quarterly or biannual or annual release schedule that you tend to be on with your systems. So talk a little bit about how you see this and you know the difference between the security and the AI governance. I don't think they're disconnected, but they are differently, definitely distinctly different in some ways.
SPEAKER_02Yeah, so I've seen a couple of healthcare providers that lock down their AI usage policies and their employees' ability to work with AI in various aspects of their job. And the unintended consequences is something that's of interest to me. And I may this might not be answering your question, Chris, but let's tease this thread for a moment. They purchased an expensive license, which was a private LLM where the data wasn't consumed or used to improve the model or train the model, and the data was all maintained in its own enclave. And that company was very successful with their employees using just that model because it was always on, it was there, they could put what they wanted into it to help with diagnoses, to write emails, to do what they needed to do. It was an empowering solution. And it it provided what the employees wanted and desired to improve their productivity. Now, flip that coin upside down. There was another healthcare provider that I was consulting with, and they locked everything down. They blocked access to the AI models, they didn't fund a private model, and you know, everyone was thought that they were okay because they'd locked it down. But when you went there and you observed what was going on, people were pulling out their phones and putting information into their AI chat model on their phone. And it was going around the system. Now, can I prove that patient data was put in there or other things? Probably, you know, I I people are smart enough to know they can't put patients' names and diagnoses into an AI model. I hope. But there was definitely leakage going on, and it was definitely content going into a public LLM like OpenAI or Andro Anthropic. And the employees were working around the system because it had been locked down so much. And so there were threats and risks, but there was no way to measure and quantity quantify them, right? Ultimately, I'm sure someone did put data in that they shouldn't. So if you look at those two coins, like what do you need to learn from this scenario? Is you you employees are resourceful, they'll work around the system to get what they want. I I know in the older days, like maybe COVID era, you couldn't print at home when you worked from home because that was not allowed. You can't print company data on your home printer. So, what did people do? Forward that to my personal email, download it to my work home computer, print it at home. I need to get the job done, right? So the unintended consequences and the psychology of all this is that people are resourceful, they'll get to what they need, want, and desire one way or another. So you have to empower them in ways that works for their workflow. And that would allow you, in the former case, it allowed you to limit and protect that interaction with AI in a way that was both empowering, productivity enhancing, the desired way employees, doctors, and nurses and practitioners all wanted to use AI to help them get their job done better, more efficiently. The other way was to lock everybody out, and then they just worked around the system.
SPEAKER_01Yeah, I I I know there was a point in time, it was well before the pandemic, but I but I remember just the access to like uh your your private email became problematic because it was taking so much bandwidth in an organization. And people felt a little bit you know put off by that. But the the reality is there are threats that people are really are just not aware of, and honestly, it's because people like you and the teams that you've built over the years, they you are constantly staying vigilant and on top of those things. So it it kind of gives people this sense of security in one hand, but at the same time, we don't need we we don't really want them to stay comfortable about it. But without this kind of approach you're talking about where it's kind of being baked into operations, you're you're still gonna be having those kind of challenges, and people will find the work press, to your point. I I got cell signal, I don't need the Wi-Fi, so I can just go do it on my phone.
SPEAKER_02That's right.
SPEAKER_01I'm sure 100%. So policy oftentimes, once it hits, the team that develops it, they feel like they've done a good job with it. It's gonna be effective, it gets sanctioned, announced, communicated, whatever, and they believe maybe too easily that the behavior is going to change automatically. We just talked about the systems are changing. AI is a whole different ballgame. The evolution and the training and development of these models, it's it's a it's a constant thing. So maybe talk about how, from a psychological standpoint, when you're writing policies, understanding that they don't typically change what people actually do. What's your advice to organizations as they're trying to navigate through this from a transformation standpoint? Because there's a lot of legacy approaches. Informed consent's a great example where the way that you manage it historically has to change because of the nature of new technology that we're using, the way it's evolving.
SPEAKER_02Well, uh, so it look, a lot of this boils down to common sense, Chris. I've seen we have a virtual CISO practice in Cybercook, where we come in and we evaluate the cybersecurity programs of the company and we help them build, you know, a bunch of pillars in their cybersecurity program. So training and governance is one of them, or training and and fishing simulations is one aspect. Governance is another. And when I ask for how do you govern your employees, like what instructions do you provide new employees about how they're expected to behave and how they're expected to use technology? So, oh, we got that covered. We have a uh handbook, a company handbook. Show me the handbook. And they pull off this, you know, document that's 400 pages thick and it has everything from dress code and vacation schedules to acceptable use of computers and privacy and data governance and labeling. It's all in this, buried in this huge document that no one, not even the people that wrote it, who are no longer there usually have read it. And so I say, Well, how does that get consumed? Are you familiar? You probably I know you've heard this before, but there's a TLDR. Too long, didn't read. That's one of the favorite things I tell AI to give me on anything I have to read. Like, give me the TLDR of this, and it says bullet by bullet. Here's the four things you need to learn from this document. So I say if you want people to actually understand and reference your governance policies, you need to keep them TLDR'd, short. In other words, your password policy, it needs to be only the password policy, and it needs to be one or two pages of instruction. You can have a table of contents, or you can have, you know, the revision and approval controls in there. That's all good stuff, but people can ignore and skip all that. They just need to read the 30 bullet points on password hygiene that they have to follow, or 15 to 20, whatever you can boil it down to. But it needs to be short. And then you need to reward people for engagement with that and compliance to it. So, for example, password policy might say you must adopt the company password manager. And that's by all by all means every if you learn one thing from this conversation today, if you're not using a password manager, you need to stop what you're doing, go look at, I can recommend three if you want to pick one of the three. There's six or seven great ones out there, but you need a password manager today, if only to identify where you're reusing passwords, help you change them to be all long and unique. And lastly, to manage your pass keys as we transition from passwords, username, password, and MFA into pass keys, which are superior to anything password, username and password and MFA related, multi-factor authentication, those little six-digit codes. Pass keys replace all that with a single step and it's equivalent and it can't be stolen. So there's a lot of huge benefits for that. But if you're not on a password manager, then I know you're reusing your passwords and your employees are reusing your passwords. So if you can keep the password manager in that password policy and push and subfund it, then you're going to reduce the stress of your employees in using and managing passwords, right? I think there was a study of the average employee spends four to six hours a year resetting and waiting for passwords and troubleshooting passwords, which password did I use, logging in with three of their favorite passwords until one works. A password manager eliminates all of that. So keeping it short, keeping it digestible, TLDRing the governance policy. I've seen some companies where they even take the policy and they put a TLDR summary of what it states in a box at the top of the policy. It says this policy covers password managers, password hygiene, multi-factor, duh, and it spells it out for them. All of that's going to create a much more successful governance program where your employees will actually be at least have a chance of reading and digesting this stuff rather than a 30-page, 40, 50, 100-page employee handbook.
SPEAKER_01But when we're talking about the social engineering aspects of what's happening right now, we we've been hearing things about and being exposed to education around fishing quite a bit over the last several years. I'm not quite sure exactly when I first started seeing it, maybe probably about 10 years ago, I think. But things are changing at a at this point in time because people are accustomed to it. And you know, maybe some things that used to be obvious, they're not so much anymore for someone who's not really delving into this stuff and paying attention on a regular basis. Maybe describe some things that you see that are indicative of an AI assisted attack in a in a hospital kind of a setting. And what are some of the things that make clinical staff, for example, a particular target? Because they're like super busy, they they're struggling with burnout. Uh, that we keep introducing new technologies to them that actually disrupt their workflow instead of improving it. Uh so they're they're oftentimes really already frustrated. Then these things, these additional things are something they have to contend with. Talk about what from your perspective, what makes them uh a target? And and how are how are you thinking about uh helping organizations to start to resolve and put things in place to relieve some of that?
SPEAKER_02Sure. Whenever you want to understand why your company may or may not be a target, you have to look at what data you have. What data does a hospital or a healthcare provider have that is a target of organized crime, nation states, you know, hackers of any kind of ilk or what have you. And in those settings, it's the health records, right? The patient records. And what is the most common form of attack is whatever I, as an individual in the internet space, can get into a person at the at the healthcare provider. And that's usually through email and that sort of thing. Many hospitals have moved from open email systems where you could email your doctor to patient portals where things are contained and constrained and protected. That's a good thing. And that's to be applauded and should continue, right? You should only be able to communicate with your healthcare providers through your patient portals because that can be protected from a lot of the different types of attacks that are ongoing. But in healthcare providers where you could get an email into a provider, we're seeing the focus be on these phishing attacks where, first of all, there's no more grammatical mistakes. AI can target an individual no longer. So in go back 10 years, it was prey, spray and pray that someone will click on a link to a similar email sent to everybody that we could identify at the hospital. Today, there's what we call spear phishing attacks, where any individual is the target of an attack based on who they are, their likes, their dislikes, their social media, their online presence, right? And so every email that's sent as a phishing attack to that individual is targeting the individual based on their personality. And it is perfectly aligned to who they are and what their interests are. So if you're a golfer, you're gonna get golf phishing attacks. If you're a lawyer, you're gonna get law-based ones. If you're whatever your personality is, you're gonna have these specific attacks directed at you. And they may even know through internet research that you're using this particular email client and you're using this particular technology, and so it might tie to that. We we we've seen it even within our company. We have a uh a content management system, I won't name it, but it has been sending emails out on our behalf, and someone did their research, got one of those, and then they turned it into, hey, your campaign is stuck, and you need to click here to investigate and release your emails to your target audience. And it was a phishing attack. And you could you couldn't tell unless you were really diligent about hovering over to the end of the link because it had our CRM was sitting there in the in the boldface URL with some dots after it, no different than the Teams attack we talked about earlier on. So the attacks are becoming much more focused, much more frequent against individuals, and they can get multiple attacks over the course of days and weeks, all from the same, you know, hackers seeking to breach into that healthcare provider. So we have to be as healthcare providers, we have to be perfect every day on every single email attack that we receive. And uh what one other note I'll make is that any errant clicks, any errant mistakes are even more dangerous and devastating when they occur. AI has not only made the attacks more voluminous, more common, more frequent, and more believable and more tailored to the individuals, but they're also more damaging on the back end and what they can accomplish. Uh, it used to be a hacker would get into that account and start doing things on the keyboard, right? Like, let me deploy this software and get remote access. Now let me land and expand over here. AI systems are designed to just do all that at machine speed. Once you get the click and you get the first payload in, the payload then lands, it does these network scanning, it fans out, it puts itself into other places, and then it beacons back to the hacker saying, Hey, I got into this account and I have these permanent locations that I'm in the network. We had an incident yesterday I was talking about uh on a call with some uh a legal team, and there was a school district in the United States. I won't say anything, but we know that they were breached a year ago because it was very big public breach and big ransom event, public disclosure, student records were put at risk. They paid the ransom, they cleaned it all up and they went away. Well, the hackers actually weren't cleaned out of their network because we had a client who was attacked from their network, and the RMM tool that was used to install on this company over here came from that school district. So the the hackers were still in that school district, right? They didn't clean it up all the way. So these kinds of things are happening all the time. So to go back to your first point, the phishing simulations are still the number one way people are getting in. You have to get on top of that awareness and teach people how phishing works. And to there's a simple little analogy that we use. It's the word par. It's not golf par. P-A-R. Whenever you are about to click on anything, anywhere, home or at work, par it. P-A-R. Pause, assess, and report if it's suspicious. Pause, assess, report, par. Simple three-letter acronym. You cannot forget that. Do not click without following par.
SPEAKER_01Yeah. I I I think the the the way you're kind of j just simplifying it, I think that's the that's definitely something that can actually stick, but it's not an after-the-fact bolt on. The organizations are in various places in their journey right now with implementing AI, but there's a lot of pressure to actually do it effectively. Talk a little bit about you know what what are some of the things that you would tell organizational leaders, um, you know, whether they're IT, you know, the C-suite or maybe even the boards, what are some of the things that you would advise them to be to start doing, regardless of their journey, but just so that they can have some confidence that they are doing something that's moving the needle from a cultural standpoint, and it's not, as you mentioned earlier, just checking a box.
SPEAKER_02Right. Yeah, if if you're checking boxes, you're going to be breached. I promise you. I cannot emphasize that enough. This is no longer a checkbox exercise. It's only a matter of time. And with the advent and growth of AI, more and more people are able to become your opponent, your adversary to try and break into your business and extort you for money. And all over the world, people are seeing other hackers be successful in these spaces with AI empowering them to breach companies and they're getting these big ransomware payments, and it's ballooning the industry. It's growing faster than any other industry in the world, I believe. And so you cannot be taking a checkbox exercise. You have to, like, let's assume that you're not going to do checkbox. You're going to have a positive reinforcement culture. You're going to adopt a tool like Cyberhoot that rewards good behaviors, teaches people how phishing works, all of that. Well, your AI journey of protection is not done, right? Your users are going to get that constrained, contained, purchased uh AI tooling for your employees to use AI the way they want to. Like we spoke about earlier, you're not going to block access to everything. You're going to have a prescribed, approved AI tool. Some of the new healthcare systems are actually allowing AI dictation. So when you're in the room, remember you this happens to you, right, Chris? You go to your annual physical and you're looking at the person. Here's your healthcare provider. And they say, okay, tell me how you've been. And they ask you a bunch of questions. And they're doing this the whole time. They're like, because they're trying to get all the data and while you're telling them. Well, AI can get rid of all that. So they can look you in the eye and they can say, Oh my gosh, that must be so painful. Let me let me talk about what you know, carbuncles or whatever the ailment is with you and empathize and be a good bedside patient, you know, interaction. AI will summarize it all for me and then we'll we'll put you on whatever prescribed medication or or uh mitigating things to do. That's the beauty of AI when you build that into your systems and tooling, but you're still not done. Why? Because you have a hospital, you have a website, you have a footprint on the internet. I think the five eyes advisory that came out three weeks ago. If you haven't read that, you should go and do that if you're a leader or an IT professional in a healthcare situation, in a healthcare provider. Because what is Five Eyes? It's the US, Canada, UK, Australia, New Zealand. These five cybersecurity divisions of the government got together and said, folks, you have weeks and months, not years, to mitigate the threats we're about to face from AI. There's a new technology called Mythos from Anthropic, which can basically identify vulnerabilities in your website or your firewall or your router or anything. Of these things. Now, the good news is Anthropic looked at what they had built, this it mythos vulnerability identification frontier AI model, and they said, it's too dangerous. We can't release this to the world. So we're going to put a moratorium on anyone using this. We've they formed a glass wing coalition. You can research that or go to Cyberhoot's blog, cyberhoot.com slash blog, and you can read about this. And they've got the top 50 software vendors of the world together. They said, scan your solutions with our tool, find the vulnerabilities, patch them before other AI vendors catch up to us. Because ultimately, DeepSeek from China is going to catch up to Anthropic here in the United States or OpenAI or Grok or whomever. And that's what's been done. And the evidence of what the power and capability of these frontier models is in the patches that have been released. Google Chrome had 10 patches a month forever, backwards in time, 15 patches. They had 600 patches fixed in the last release. 600. Microsoft set all records in June for their patch Tuesday for themselves. They had 10 times as many patches. So normally they're about 20 patches a month. They released 300 patches, fixes in June. And then in July, they re-if it's not 3,000, it was an enormous amount. You can go and look it up. But they did that because they had been scanning with mythos. So as a healthcare provider, what's the message for you? Go to my blog, read it because there's more to it than we have time to talk about. But there are five things. Reduce your attack surface. Imagine your hospital is a house, and your house currently has four doors front door, back door, left door, right door, and ten windows. Get rid of all the windows and doors. Have one front door into your building, and that's it. Get rid of everything else so that you can have armed guards monitoring that door and anybody that tries to come in or out, you know who they are. Just attack surface reduction. Go study that and get rid of every port protocol that you can into your networks that you can't. Patch faster. When Microsoft releases a zero-day patch to fix a vulnerability that could allow a hacker in, AI can now scan it and reverse engineer it and create an exploit within hours. We used to have 200 days 10 years ago, then we had like 20 days three or five years ago. Now it's the same day. So you can't afford to wait on your patching. You have to turn on automated patching for all your, you know, wireless access controllers, your firewalls, that sort of thing. But even Microsoft or Mac just automatically apply those patches as soon as possible. Same day if possible. So patch faster. Continue to educate your humans because humans are still going to be one of the weakest links. Well, you know, you got to keep doing that. Reduce your data. I had a breach here. I'm sorry to be keep talking about breaches, but this it just happens that we have a lot of breaches in the last six months. We had a customer who had 25 years of legal records on their internal network that were all ransomed, all exfiltrated or stolen out of the law firm and threatened with, you know, public disclosure of 25 years of records. So what's the consequence of that? They had to go and contact 25 years of clients. They didn't know where half of them were because they were out of business, they'd moved, their numbers had changed, their emails had changed, that you know, they were acquired, and they had to go and do that work. It took six to nine months for them to do that work, wherein they had no reason or business having 25 years on their internal network. They could have seven years. There's legal requirements for seven years of data. Same for HIPAA and healthcare. There's requirements for a certain amount of data, but archive the rest. Get it off your internal network, assume you'll be breached, and remove as much data as possible so you're not exposing it. You know, and in health records and health systems, you're in a little bit of an enviable position in this case because most of that's living in Epic in a cloud provider, right? It's no longer on-prem on a custom homegrown application. It's in these great secure applications. Hopefully, they're part of the Glasswing Coalition, so they're not going to be breached. But reduce your data there. Put a honeypot out there. Put something that a honeypot is basically this hardware device or a software file that is very attractive to hackers. It might be passwords, it might be salaries, it might be configuration of the firewall files or whatever it is. The moment they're touched, it's like that red line in one of those uh Tom Cruise movies, right? You break the line, alarms go off, and the gig is up. So you, you know, hackers, honey pots are not as common today as we would hope, but the average hacker is going to trigger a honeypot and you're gonna know the moment they're in your network instead of weeks and months later. Like dwell time, right? We've known that can be 180 days in many companies. You want a dwell time of zero or one day before they trigger this, and then you can react and contain the damage. So those are all things that are common sense, but are pretty much more important, and they're part of the five eyes advisory. And it it just makes sense that we have this future year or two where these frontier models are going to be able to break into things despite our best efforts, and we got to monitor better, reduce the ability to get in, reduce the data inside, patch faster, all these things can help sort of limit the damage of what might or might not happen in the near future.
SPEAKER_01Right. Yeah, it it's a it was a profound moment for me when I actually I was reading up on a couple of different technologies at one point, probably about a year ago, and the moment that it hit me that there are people that are using a completely different model, but with the same tech stack that we're using to try to get ahead of what they're doing. So we're trying to improve our ability to detect and stop their trying to detect our detection so they can actually go blow right past it. You know, and as your as organizations are moving into this, you know, you mentioned the next two to three years. Uh the things that you've talked about are probably new to a lot of folks, but what are some of the other things that you see that could become a threat over the next couple of years and and what should be pe what what should people be doing right now in terms of trying to get themselves buttoned down? Obviously, if they don't have access to the security experts like you like yourself, that's probably the first call they should make. But to hear a little bit about what you see coming.
SPEAKER_02Yeah, so we've talked about a lot of stuff, Chris. Let's keep it simple and let's keep it fundamentals. I think we need to return to fundamentals, to be quite honest. You might hear all this fancy AI this and you need to do that. But the fundamentals is what will help protect us moving forward over the course of the next two to three years. As individuals, we need to get on password managers and adopt and learn how to use them. That's your single strongest protection that you could put in place today. Because when something is breached or someone gets hold of one of your passwords, if they're all different, all unique, you're not going to have to go change passwords in a million places. And if you click on a link that takes you to a Microsoft login page and you don't know your Microsoft account because it's your password manager spits it in there every time, you're not going to fall victim to that fake Microsoft login page because your password manager won't fill it out. So that's number one. Get a password manager for people in positions of authority and responsibility, the C-suite, get a virtual CISO in your organization, in your healthcare provider. You might not be able to afford a $300,000 full-time CISO position, but you can afford a $100,000 or an $80,000 part-time vCISO who has not only your responsible company, but has 10 other companies so that they can bring best practices from all these different places. And the team of vCISOs can bounce ideas off of each other. So instead of having this one CISO who is dedicated to you and doesn't have visibility into all these other things that are going on, you hire a virtual who has access to dozens of other virtual CISOs, has visibility into dozens of other companies and can bring the best of the best to you. And so when they say, hey, this has worked over here and here and here and here, you have a high degree of likelihood it's going to work for you, right? That's the second thing I would suggest. Third is get on a positive culture and a positive reinforcement awareness training and cyber literacy program that is focuses on rewarding good behaviors. Stop punishing bad behaviors, build a culture of see something, say something, reward people for talking about problems and bringing up issues to leadership that engages the employees instead of ostracizing or disengaging them, fight that apathy. Those are three things that I think would be great take-home messages from our conversation today.
SPEAKER_01Yeah, I totally appreciate that. I would just encourage people who are who are listening to this. If you're in an organization where you've not been able to figure out how to how to pay for an expert of your own, um the the important thing I want to caution people about is you've got some fantastic talent in your organization, there's no question about that, and they want to do the best that they can possibly do for you for you. But we're talking about a level of skill now that really requires career-level commitment and constant education and learning. I I just would encourage you if this is an area where you're struggling, you're not quite sure where to go, you definitely want to reach out to an expert like Craig. And you know, he and his company actually have the right talent that they've this is what they live, sleep, eat, and breathe. You you definitely want this, whether you have to do it on a fractional basis or however, but you got to make sure that you've got some people who are vigilant and making sure these things are being monitored and you're you're getting at least what the current the best information you can at any point in time. But having a trusted partner, I think, is gonna be really critical. So Craig, if you could just tell people how to how to get a hold of you, if they want to they want to you know read your content, they want to have a call, bring your bring in your experts.
SPEAKER_02Yeah. So I'll start with this. We give our entire solution away free to individuals. So if you go to cyberhoot.com forward slash individuals with an S at the end, you can register and get our videos and our phishing, what we call boot fish. It's a non-deception-based phishing simulation. So you get an email that says you have a phishing simulation to take. And you go to the browser, and the browser walks you through teaching you a rubric of how to spot and avoid and understand phishing, feeding you for a lifetime of confident, efficient, and secure email processing. So that's a wonderful thing. But if you want to reach out to us, email sales at cyberhoot.com, visit cyberhoot.com for a free demo. Anyone listening to this that actually ends up getting a free trial, if you convert to a paid subscription, we'll give you 20% off if you mention the signal room for your first year. We're happy to do that for you. Our blog is out there and it's more, you know, I met with an AEO person, somebody at search engine optimization, but also for AI. He says, You're not doing a bunch of these really important things around what is it, the schema of your blog articles. I'm like, well, I'm trying to teach people what they need to know. I'm less concerned with, you know, being the AI search engine output of every search that people do in AI these days. I think that's important and we want to do that, but I've really focused on the content and communicating these steps that you need to take to protect yourself. And so I need to do a better job, do both so that AI can point people to us. But our blog is just a is just full of all kinds of great articles about emerging threats, uh, the five eyes advisory, mythos, and everything else in between. We have a cybersecurity library of terms, thousand plus terms. So if you're wondering what is a Bitcoin or what is two-factor authentication or multi-factor, we've got it defined with video linkages and all of that good stuff too. So go to cyberhoot.com slash blog. We have a newsletter. You can go to cyberhoot slash.com slash newsletters and sign up for our summary once a month. That's a great way to learn about what we're doing and what the threats are out there. But all of those are ways to reach us.
SPEAKER_01Phenomenal. For the audience, I'll make sure that all this information will appear in the show notes. And I encourage you to seek out Craig and his team if you're realizing that you've got to firm some things up, make sure that your organization is protected. Craig, this has been amazing. I've learned a lot over the course of our conversation. I really want to thank you for the work that you do because I've been on the data side, the chief data officer for a long time. And I have a receding hairline, but I would be completely bald if it weren't for people like you that have the drive and motivation to stay ahead of this kind of stuff. I don't know that people realize how many times a day the the information security team is actually being alerted and having to address things. I appreciate you coming on the show, and I'm really excited for the audience to be able to hear the conversation and even more excited to see where you go from here. Uh obviously, you're doing some really important work and a lot of the passion that tells me that you're you're not done.
SPEAKER_02I I very much appreciate being here, and we'll make sure we get all those links for your show notes sent over to you.
SPEAKER_01Fantastic. Thanks again for our listeners. I'm Chris Hutchins, and I look forward to seeing you next time on the Sega Room. Healthcare has spent five years getting AI in the door. Pilots, ambient documentation, predictive models, triage tools. The technology is here. The oversight is not. I'm Chris Hutchins. I've spent thirty years inside health systems. The hard part is almost never the model. It's the meeting after the bottle. It's who owns the alert. It's whether anyone will say out loud that the data isn't ready. I wrote a book about that work. It's called Beneath the Signal. The human work behind trusted data, responsible AI and healthcare. It's for the people who have to make this actually function. It's the CMIOs, the data leaders, the ones who get called at three in the morning. Search beneath the signal on Amazon and get your copy today. And you'll be back here on the segment room.
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
Practical AI in Healthcare
Steven Labkoff, MD and Leon Rozenblit, JD, PhD
AI and Healthcare
Tensor Black
The Business of AI in Healthcare
Robert Kaiser
The Future of Healthcare AI
Bain Capital
The AI Healthcare Podcast
Dylan Reid
AI Governance with Dr Darryl
Dr Darryl
The AI Rules Podcast
Council on AI Governance