Skip to main content

Search site

Find podcasts, news, articles, webinars, and contributors in one search.

UnHack the Podcast
UnHack the Podcast artwork

Improv in Cybersecurity and Stopping People Pleaser AI | Unhack the Podcast with David Finn

Questions Answered in This Episode

  • How can improvisation principles strengthen your healthcare cybersecurity governance?
  • Why does AI governance matter more than AI containment in healthcare breaches?
  • What governance structures prevent healthcare leaders from making costly tech mistakes?
  • How do you stop people-pleaser culture from sabotaging your security priorities?
  • Why should operations leaders, not CIOs, chair your technology committees?

About This Episode

June 31, 2026: David Finn has watched health IT security evolve from a compliance checkbox to an enterprise risk conversation, and now into an AI agentic era that's rewriting the rules again. Now teaching courses and advising across the industry, he unpacks what the recent OpenAI and Hugging Face breaches really exposed, and it wasn't a technology failure. It was a governance failure. David draws on decades of building security programs, including a stint as an "accidental CIO," to explain why healthcare keeps solving the wrong problem, why third-party risk is still underestimated, and why AI agents need constant behavioral monitoring instead of one-time guardrails.

Key Points:

  • 04:42 Governance Over Controls

  • 10:43 Pace Change: Get It Right

  • 16:12 Third Party Risk Reality

  • 20:34 Start With Executives

  • 22:39 AI Jobs Policies Monitoring

  • 37:56 Guardrails to Behavior Monitoring

Keep up to date on the latest in health IT:

https://thisweekhealth.com/news/

X: This Week Health

LinkedIn: This Week Health

Donate: Alex’s Lemonade Stand: Foundation for Childhood Cancer

Thank You to Our Episode Partner

Cyderes

Contributors

People featured in this episode — open a profile for more.

Transcript

This transcription is provided by artificial intelligence. We believe in technology but understand that even the smartest robots can sometimes get speech recognition wrong. Speaker: . [00:00:00] AI agents are quickly becoming one of the fastest-growing identity types in healthcare. They're reviewing images and coordinating care, supporting scheduling, and accessing patient data across multiple systems. The challenge isn't the AI, it's governing what these digital identities can access and do and share. If an AI agent improperly discloses patient information, the OCR won't care whether it was a person or a machine. You'll still be accountable. CYDERES helps health systems give every AI agent the right access, the right context, and the right governance before it's allowed to act. Find out more at thisweekhealth.co m/cyderes Speaker 3: I'm Drex DeFord from The 229 Project and This Week Health. Our mission is healthcare transformation. Together. Welcome to UnHack the podcast, where we navigate healthcare security and leadership [00:01:00] challenges together, because cyber safety is patient safety. Let's get started. Drex DeFord: Hey, everyone, I'm Drex. Welcome to the podcast. , I have David Finn with me today. David is going to be a really great guest for a bunch of reasons, and one, one of those is that we've known each other forever. The other really hard part in all of this is that we have so many things to talk about, 'cause we only catch up from time to time. He has been through... I'm gonna brag on you for a minute, David. He has been through building security programs when compliance was mostly the driver of security programs. He's been through the phase of this where ransomware kind of transformed cybersecurity from an IT problem into an enterprise risk conversation, and that kind of grew and expanded. And now he's been involved in the AI agentic era where all these rules that we thought we knew are changing again. And so [00:02:00] I'm really glad you're on the show, David. , , G- give- can you give people the resume, , in some kind of short form? I'd really love for them to hear it. David Finn: I have a very weird background, but it's kind of that weird background that got me where I am. And I, I started, ... I have two degrees in theater, which certainly qualifies you to be a cybersecurity expert. , , but I started in college doing theater. And, and one of the first things I did was improvisational theater. Hmm. And cybersecurity is closer to improvisational theater than any other job I've ever had. But you learn to do improv. Mo- most people think it's just you go out there and start talking, but there's structures and rules around doing improvisational theater And this is where I, I was talking a little bit earlier. It's like we've completely missed that part in cybersecurity. , I, I [00:03:00] went from when I realized that, , theater was not a great way to make a living, I got into IT and started as an entry-level programmer. I was, I have to admit, the world's oldest entry-level programmer. , And, and, and the first, one of the first assignments I got, aside from writing a, , a, , payroll system in Lotus, , which- Oh tells you how long ago that was. Yeah. , when I went as a programmer to a major university, my first assignment was to write the, , coding requirements and, and rules and guidelines for writing code, which, which brought me back to rules and how we go forward. It, it shouldn't impinge on your creativity around writing the code, but you do have to follow some rules. Then I went into healthcare audit, and again, a- audit and [00:04:00] control, which is what this is all based on. Oh. And again, y- you should be doing it within some boundaries and frameworks. Then I had this 40-year gap of working in health IT. And, and so here I am, kind of looking at, , where we are, and, and we're looking at this, and we have to do this, and we have to- Yeah have these regulations and this compliance. And it's like when the companies who are developing those programs are paying no attention to what's going on in the sector, and the people who are working in the sector have no clue what it's like to actually build platforms and develop integrations and, and that kind of stuff. Drex DeFord: Yeah. David Finn: And, and so, , when the OpenAI breach happened, it's like my brain exploded, and all this stuff cart- starts coming back together. And, and I was re- re- reminded recently, it was a LinkedIn post today, I think, of Jensen Huang, the, the CEO of NVIDIA, [00:05:00] who was asked who the smartest person he knew was, and his answer was, "People who can see around corners." Drex DeFord: Yeah. David Finn: But we- Yeah ... don't look around corners anymore, and that's the one problem I think cybersecurity has. If you hire for judgment, for context, for discernment, and the ability to read what no one will say out loud, that reminds me of, of being a CISO in front of a hospital board- ... , you are building a team, and you're building structures that AI can't replicate, and that's what we're not doing. We're focused, I think, on the wrong problem. And the way that Open Eye and, and, and Hugging Face, that- Yeah ... , breach, , kind of got to me was everyone's talking about containment and controls, and we had a cybersecurity breach. But what caused it was not [00:06:00] the cybersecurity, which was where, which is what we're running out to try to fix right now. It comes down to all those things I talked about with improvisational theater- Hmm ... and writing coding guidelines. It's governance. Drex DeFord: Hmm. David Finn: And, and it all comes back to governance, and that's the part we're missing. Drex DeFord: That's a good transition into this question. You've been doing this for, you know, such a long time. What did we get wrong 15 years ago that if we would've got right, this would all be a little bit easier? David Finn: I was an accidental CIO. -h. I never intended to be a CIO. I was a privacy and security officer. We had an incident, which most people don't know about, and here it's where it's a few years down the road. But the first thing I did when I got moved over to the CIO role was create a governance structure. Drex DeFord: Hmm. David Finn: And it was massive and elaborate, certainly in those days, but even today it would be considered [00:07:00] an unwieldy, , governance structure. And it was- What, what was in there? Drex DeFord: What did it look like? David Finn: We had six separate committees, and, and we, so we had a research committee. We were a big children's hospital- -h ... academic medical center. , So we had research 'cause it was a key component. It wasn't involved in care necessarily. We had an IT group, a committee, which included our chief medical information officer. We had, , a business group that looked at things, and, and those were chaired by operational leaders from those areas- Yeah six of them. Yeah. , And, and then we had an information management executive committee, and it was two representatives from each of the six sub-committees- Hmm ... that made up that information management committee. And, and the COO and the CFO came to me and said, "You're gonna chair the information management executive committee." And I said, "No, I'm not, because I, , there's a conflict of interest [00:08:00] here." Being an auditor, I, I recognized that immediately. , I said, I said, "It has to be either the CFO," which I didn't like, "or the COO," 'cause the CFO has a, , vested interest, too. Kind of a conflict, yeah. The C- the CIO's job is to spend all the money in the world, and the CFO's job is to spend no money. Not too many money. But we agreed that the COO, whose job is to keep the operations running, whether it takes money or not, chaired our committee out of the gate. Hmm. And, and that is appropriate. I sat on the IT, , committee, and so I was the representative from IT. Because if you're not doing it for, if you're not doing the technology for operations, for the doctors, for the clinicians, for the patients, you shouldn't be doing it at all. So, , that was kind of where we wound up, and, , that's, that's, , it w- worked very successfully. In fact, [00:09:00] sometimes I was given more money than I asked for. Right. -h. , my favorite story is, this, this will date me again, virtualization was new, and we were going to virtualization. We had, you know, 1,100 servers or whatever, and we started, looked at virtualization. And, , and I came up, within IT we looked at doing 700, , servers year one, and then another 700. Well, the CFO must have had been flush with cash that year or something. He said, "Let's do all 1,400 in one year." "So I'm gonna give you the, the million dollars or whatever, over a million dollars." And I said, "I, I can't do it that fast." Yeah. "I don't have the people. We don't have the time. We don't have the resources internally. We don't even have a, a, a good handle on what we want to virtualize at this point." And, and they ran through the information management executive committee. I voted against [00:10:00] it, , and they- They gave you the money anyway approved the full funding. And, and then the economy took over, and, so about six weeks in I get a call from the CFO saying, "Would you mind if we cut that in half?" And, and I cleverly said, "Oh, what a brilliant idea. I wish I had thought of that." - That's Drex DeFord: where I started. David Finn: Yeah, exactly. , so, so we cut that in half. It, it went very successfully, and then the next year, , according to someone's, , original plan, we did the other, , set of servers and, and it worked. Drex DeFord: I- is the governance where then we kind of We, we didn't have good discipline around that 10 years ago or 15 years ago, and maybe that's still some of the problem today David Finn: - I think that is a lot of it, Drex. And part of it is the sp- the, the pace of change has so increased Drex DeFord: Hmm David Finn: And, and sometimes you, you can do things fast, and sometimes you have to do things slow. Sometimes [00:11:00] it's more important to get it right. , my, I, I have an Ivo Nelson story, , may he rest in peace. , But he, he used to always complain, I was a COO, , the last y- two years I was at IMG, and he says, "You, you got to go faster, David. You got to go faster." I said, "No, we've, we've got to get it right, and, and we'll get there." When, when we started... And, and he finally bought into that. I, I, I wrote, I actually wrote him a long letter explaining that, , there are, , and because I'm an Air Force brat you'll appreciate this Yeah ... , there are B-52s and then there are fighters, and you need both of them in the Force Hmm , but we had a lot of fighters in consulting at IMG Mm-hmm And, and I was the COO, and my job was to make sure, as the B-52, when I was done flying over, there was nothing left. It was all taken care of. Drex DeFord: [00:12:00] Yeah David Finn: Fighters had to go in and attack specific problems Drex DeFord: Yeah David Finn: But I was the last guy who came in- Yeah, becuase Drex DeFord: sweeper ... David Finn: , bombed the mess out of anything that was left, and, and then we could get going again. But, , so he, he got that. He liked war analogies. And so I was a B-52, all my consultants were fighters, and, and we had long-term plans at, at every place, and we carried out and initiated those plans. They took time. When I started Epic, when I started implementing Epic at Texas Children's, the, , my own team was coming to me saying, "We can go faster, we can go faster." I, I said, "No." Yeah I, I said... A- and, and it was always the physicians, the physicians were driving everything. And, and I said, "No, if, if we miss a go live date-" But we get it in later and it all works the way we told them it would, the doctors will forgive us. But if we get it [00:13:00] in, even if we get it in early but it doesn't work- Drex DeFord: Yeah ... the David Finn: doctors will never forgive us, and we'll never get a second chance. Drex DeFord: Yeah. So David Finn: I would rather be late and have it work than be on time and go through the chaos. So that- And, and that just served me pretty well. You c- you can't be too late, don't get me wrong. Yeah. You have to hit your project dates. But, , you have to be able to explain why you're delaying, and that's w- we don't take the time to explain what we're doing, in my opinion. Yeah. The pressure is so great. Drex DeFord: It's the, I think it's the, um There are, there are today, there are so many, um, w- you know, we, we do a market survey, , regularly with the folks who come to the 229 project events. Um, capacity is the issue, right? There's just too many requests. There's not enough resources to do everything, and if you're not super transparent about how and why you're prioritizing the things that you're prioritizing, everybody feels like there's some smoky backroom conversation that's going on that they're not part of. They [00:14:00] wind up starting their own little sideline piece of work, and, , ugh, I mean, ultimately it winds up being, you know, a bit of a, a bit of a mess. David Finn: That was key. We had this big, , , it wasn't kludgy. It sounds kludgy, and when I look at the diagrams of those sub-committees rolling up to the information management executive committee, but what it did was it engaged all the executives. In fact, I, I got sent to Texas Children's as the privacy and security officer, and that was because their HIPAA project had gone south. Drex DeFord: Hmm. David Finn: They had a great, , committee. They, they were pretty good at getting executives engaged, but by the time I got there, that committee had not met in almost a year. Hmm. So I called all the senior mem- all the members of that committee, which was the executive cabinet, and, and this was the deal I made with them. I said, "I will take care of HIPAA, and you don't have to do anything. You have to show up to the [00:15:00] meeting once a month. Now, between the two monthly meetings, if I call you, you have to answer the phone- Hmm and you have to do what I tell you to do." And, and they all said, because HIPAA was starting to breathe down our necks, they all agreed to that. A- and, and it worked because, you know, I couldn't tell nurses what to do, but when I called the CNO and said, "I need your help here. You've gotta talk to so-and-so and make sure they're getting this done"- Mm-hmm it happened. Sure. But that was the deal. Drex DeFord: It's interesting that that really turns out to be that you're ha- you, you're actually just having one big, long, continuous meeting. Instead of everybody saving up their, their complaints or their issues for the every-month meeting, um, you're just working through it and keeping everything moving. The, the meeting becomes more of, like, an update on what we did and what we're gonna do in the next 30 days, as opposed to this batch [00:16:00] process that happens. So David Finn: E- exactly. So the meeting was, was used to tee up those leaders for what was probably gonna happen in the next 30 days. Yeah, Drex DeFord: yeah. David Finn: I was- What I was gonna ask them to do. Drex DeFord: Yeah. I- if you compared healthcare today to five years ago, , more secure now or more secure then? David Finn: I just think because of the complexity and the connectivity that has happened, I, I think we're at greater risk today- Mm in healthcare than we've ever been. Drex DeFord: Have health systems, Finally accepted that maybe most of their risk is from stuff that's not inside the hospital. I'm talking about third party risk. Like, I think that's a big part of this evolution, right? David Finn: A- absolutely. And I, I was hopeful that Change Healthcare would, would wake people up. Drex DeFord: Yeah. David Finn: It was stunning talking to people during the, the Change outage who didn't even know they had Change in their [00:17:00] hospital. Drex DeFord: Yeah. David Finn: And, and then the poor physician practices, many of which wound up closing, who had no idea that that's where orders and that's where approvals and, and authorizations were coming from. And, and so I was hopeful that that would wake us up. We're certainly doing a lot more in third party risk, but it, it isn't where it needs to be. And it's, it's really tricky. I mean, hospitals have a lot of third party vendors in house. Drex DeFord: And David Finn: a lot of them- And Drex DeFord: third parties and fourth parties that are, I mean- Oh, it, it, yeah th- this, David Finn: this Drex DeFord: web that we've built. David Finn: Yeah. Drex DeFord: Um, it turns out, like, if one company out there stubs their toe, , everybody in the whole system feels it. David Finn: Absolutely. We're, we're to the Nth party now, whatever N is. Yeah. And, and it goes on and on. And, and that certainly complicates things, but it brings us back to the, the governance issue. And if, if we had, you know, purchasing on those committees and doing that due [00:18:00] diligence instead of, , no rules about who you buy from- Hmm ... , we, we could, , w- it will never be completely controlled, I'm not that crazy. But, but we could do a lot better. And, and then we have to look at the standards that are acceptable. , I, I to- I told you I've started working with a lot of non-profits outside of healthcare. Right, right. And that was kind of the wake up call for me, 'cause even, even a tiny hospital has someone who has information in their title somewhere. I'm working with non-profits, sometimes two or three employees, and, and y- you have to meet them where you are, and, and they don't really know anything. -h. And, and that is a different beginning. But it, but in hospitals there's some ... We, we've had the HIPAA regulations for couple decades now. We have, we have state laws, and we have HHS regulations, and Joint Commission regulations, [00:19:00] and people should be able to, to understand and start addressing these things. , I, I teach a course on operationalizing cybersecurity, - and privacy at UT Austin Mm-hmm And one of the exercises I give is the 10 myths, it's on the, um, HHS site to, to this day. It was written about 11 years ago. And the 11 myths, the staggering thing I ask the students to tell me which ones are still in place at their organization, there's 10 of them, and most of them list about eight that are still, people still think they, that having an EHR, the EHR vendor's responsible for your risk management. Drex DeFord: H. That's amazing David Finn: we're, we're, we are, we are 23 years down the road from privacy- Yeah ... 21 years down the road from security rule, and people still think if they've bought an, an [00:20:00] EHR that the EHR will take, is, they, they will take care of the privacy and security requirements for HIPAA. Drex DeFord: It is, it is really interesting how uneven that it's sort of knowledge about cybersecurity is, um, across the organization. It's part of the reason that, like, you know, I, as I'm doing two-minute drills and, and we're doing episodes like this, a lot of it is, , it's a cybersecurity podcast, but it's not a cybersecurity pos- podcast that's necessarily meant for cybersecurity people. It's for everybody else, because everybody else is part of the security team, whether they know it or not. So the more they know, the better off we are and, and all of that. If you were starting over again today, wh- , like, where would you start, , today? Like, firewalls or identity or MFA? Like, what- Here, David Finn: here's where I'd start. Yeah. And I came to this realization about five years ago, and that is I would start with the CEO, the CFO, and the COO. Mm. The IT and the security people know what the problems are. Where we've missed the boat is we're t- i- [00:21:00] in fact, we really should be at the board of directors and, and because they have fiduciary responsibility. And while it's a non-profit and there are certain protections and, and limitations around that, they are ultimately responsible for cybersecurity. It's a strategic imperative of the business now. And it should be, it should be right under the financials at every healthcare system board meeting. In fact, every healthcare vendor should, should have privacy and security on that list. And it, it took me a long time to figure that out, but I think we've targeted the wrong audience. Drex DeFord: Even for vendor partners, um, for their investors, for the folks who are getting these things off the ground, it has to be one of the top... I mean, I think to get in the door now in a health system, , you know, you gotta be this tall to ride the ride. Um, cybersecurity is- Right ... a huge part of that. And I would think that it, you know, if I'm making an investments in a company, um, I wanna make sure they're secure [00:22:00] 'cause that's my money that's building the product. Not the cybersecurity product, the name the product, but it needs to be secure. David Finn: Yeah. I completely agree, Drex. , security is a strategic function of every business now, whether it's a big hospital system or OpenAI or the, the little non-profits with two or three employees that I'm- Yeah working with today. And some of them are starting to figure it out. But when- Yeah ... the system shuts down, the business shuts down. That's right. That, that's not an IT problem at that point. Drex DeFord: That is the, that is the business. IT is the business. W- , thinking about, , you know, going back to sc- cybersecurity, one of the questions I get all the time, or not all the time, fairly regularly, people are trying to figure out what's the first cybersecurity job that AI completely replaces? Like, what, what do you see? What's your prediction in that [00:23:00] market David Finn: we're seeing it effectively used in some of the monitoring, 'cause it's very good at patterns. Hmm. And so when something breaks the anomaly, I mean, breaks the standard and is anomalous behavior, , AI can flag that very quickly. The problem is that, , there's discernment involved. There's judgment and context, and, and AI is not very good at that. , If you let AI go off and do things, y- there's no telling what you'll get. Right. But if you get the AI alert and someone who has the judgment and discernment to look at that and make an assessment, you can speed things up pretty significantly. So I think some of the monitoring will, will fall by AI, but you're always gonna have to human, , have to have a human in the loop. You know, , AI is kinda like, you're a dog person. I read the post, , and, , last week where, where someone told you that they wish their boss was- ... [00:24:00] talk to them the way you talk to your dog. Yeah. , um, and, and actually I wish I was your dog, but, - Drex DeFord: That's a whole nother- It is a pretty good life. David Finn: But yeah, it is, it is great. But, , you know, AI is like a golden retriever puppy- Hmm with a PhD. It's, it's, , very enthusiastic. It's anxious to make you happy. Drex DeFord: Yeah. David Finn: But it can't think, and sometimes it goes crazy, and you don't know what it's doing. So there always has to be a good master, a good trainer watching the puppy, , with its PhD, but, , you know, that, that's kinda where we are. It w- it will reduce the need for as many people, but it will never eliminate every job in cybersecurity. Drex DeFord: Yeah. , what's the last job that AI will never replace in the cybersecurity space? David Finn: this is gonna sound very odd 'cause it's something it should [00:25:00] be good at, but I would say writing your policies and controls. Hmm. Because you have to understand what you're actually trying to control. , , It, it's, it's very good at containment, which most of our detection systems are good at. But as we saw, once the AI, with the OpenAI Hugging Face breach, once, once the AI decided it was gonna leave where it was, the, the box it was contained in- -h ... all hell broke loose. So someone's got to make sure that they're looking at it constantly, not a one-time guardrail that when it, it, you've looked at it and it's still in the sandbox, and then right after you're done looking at it, it goes and attacks Hugging Face and, and now you're not gonna look at it again for another six weeks or whatever that cycle is. Drex DeFord: Yeah. I, you know, this whole, , OpenAI hugging face brings up so [00:26:00] many different, um, issues. I, I sit here, , I've really dug into this story now. I'm gonna... Tomorrow's two-minute drill, well, this will be, this will air after the two-minute drill, but, , the next two-minute drill show is gonna be about this. And, um, th- the, the challenge that is tied to you give instructions to the AI to do something, it tries really, really hard. It does the golden retriever thing and tries to do that, which means sometimes it decides to leave the yard even if you've told it not to leave the yard, right? It's almost like you... I, I don't know how to, I don't know how to solve this, right? We, we've sort of gone down this road with AI that if we give it instructions, it'll follow our instructions, and obviously it's not necessarily doing that. It's, , you know, literally thinking outside the box. Um, do we need to have an AI, , cybersecurity agent watching all of our agents to report back on their behavior? I, I mean, it just makes me wonder- Yeah ... how, how we're gonna [00:27:00] solve this. David Finn: That, that sounds high risk to me. , w- and a- and again, , my opportunity to say it's gonna come back to, to governance and, and all, some of those standards. , , a- and, and how we do that. And, and the governance, you know, it can't just include the IT and the security people. With, with AI particularly, you're looking at clinical workflows, you're looking at clinical decisions- Hmm ... you're looking at drug interactions. And, and a few of people in IT who are qualified for that, they're probably way underpaid, , and, and are kind of weird 'cause they could go make more money doing easier work, I think. But, but, , th- that, the governance has to include all of that, and, and you know, , I- I'll, I'll take a little, , side road here. , about, , I guess it's five years ago, I got involved [00:28:00] with a group called Trustworthy Technology and Innovation Consortium. Hmm. And you probably recognize 'cause we, we brought, , their, , founder, one of their founders into, , the AHIS meeting in Florida, Sherry Deauville And, and so what they've built is a group that's trying to build, , kind of w- rules, 'cause this is the problem with a framework. We all want a framework, but the framework isn't gonna fit everywhere. Mm-hmm. And so you have to be able to do improvisational theater- -h ... , to make, to make things, , fit there. But they're about, , having, , kinda standards or frameworks to build your AI governance, 'cause it's, it's very unique. It isn't just data management, which you have to have data governance in place. It isn't just security, which you have to have. Because of the nature of AI, you've got to have clinicians, you've got to [00:29:00] have bioethicists, you've got to have a whole different array of people. And so they are about that, , and getting that done. And they d- they've developed a couple standards. One is the IEEE 2999, which is medical devices. It was the first time the trusted, got built into an IEEE, , explanation, and healthcare runs on trust. Yeah. So w- we, we have to have that. They've developed some new standards around AI governance, and they, they can't tell you exactly how it needs to work in your organization, but this is the thing I'm afraid we're, we're missing, Drex. We've gotten so used to being told, "Here's how you do it," and, and make it work that way without making those organizations specific, and frankly person specific adjustments because of the people you have in your organization. , So it, it's a framework that allows you [00:30:00] to a- adapt it to your specific needs and organizations, Drex DeFord: Does that get to the issue of- A compliance driven versus, like, real security. Th- this idea that like, w- you know, we only, we only do things once we're told to do them or once they become a law or a regulation or something, and we have to do them, so we do them. Um, there- Now- There's something strange right now, I feel like, in that David Finn: That's a great question because w- , actually we don't do what we're told to do- ... which is one of the problems. If we had actually done... HIPAA was not well written and it's all addressable, but if we had simply done what was in HIPAA, we would've been further down the road. Most people didn't understand it. And so I think the lesson that TTIC learned is it y- it isn't a standard, it isn't a framework, it isn't a rule, it has to be operationalized. And so this working [00:31:00] group that's doing all this is CISOs, it's CIOs- Mm-hmm ... it's CEOs from companies. So you have people like Ed Gaudette, you have people like Ed March, you have people like, , , Chuck Podesta. , and then you have CEOs of c- of med tech companies who are looking at this stuff. Hmm. And, and it has to work for your organization. Hmm. But what we have to do is build with that trust in mind, not meeting a regulation. , And this is one of the problems in a, i- in this course at, at UT. Privacy and security are contextual. What works in one place- Drex DeFord: Right ... David Finn: is not gonna work in the, , the same way in another place. You may have different state regulations, you may have county regulations. Mm-hmm. And so it gets, it gets very bizarre. I remember one of my early consulting jobs, , we were recommending that they move their, , medical [00:32:00] record storage facility, and we were told they couldn't because the county had a law that the medical records- Hmm of county residents had to remain in the county. Give me a break. That isn't gonna work. I think it has since been changed, but once you go to the cloud, that's out the window. What is it gonna be? So when, when you have to be able to address these kinds of issues, and that's where having the operational people, not just IT and security- Yeah but the finance people, the HR people, the... All those people involved have to be at the table. They have to have some input, and they may reject it or accept it, but, but you've got to listen to their voices. Drex DeFord: Back to everything's connected to everything else. David Finn: Everything is connected to everything else. Drex DeFord: Yeah. David Finn: And y- no one's ever gonna be perfect. That's the other thing. No. If we're looking for perfection, and, and HHS has proven that [00:33:00] you just have to be well-intended, and you can't be too stupid. But if you're trying to do the right thing, that, you get credit for it. You get Drex DeFord: credit for that, yeah. Right. Hey, here's some, , lightning round questions. These are meant just for fun, , so we'll see how you do here. , Fill in the blank. Are you ready? David Finn: Sure. Drex DeFord: Fill in, fill in the blank. The biggest waste of money in cybersecurity is blank. David Finn: Too, too many tools. Drex DeFord: Too many tools? We buy David Finn: tools that we don't use. Drex DeFord: Yeah. Every CISO should stop blank. David Finn: Drinking. Drex DeFord: Using so many tools. Because David Finn: they're healthy. No. E- every CISO should stop pounding their head against the wall and try to get to the right target. , And it doesn't matter who they report to, they've got to find their way to the [00:34:00] CEO and the CFO and the board. Drex DeFord: I think the other thing, too, is that the cybersecurity program is a work in progress, that it's never gonna be f-... I mean, I think they know that- Right ... but I think there's a lot of people around them that think, like, there's a finish line, and it's just not true. Funny. Um, healthcare needs more blank. David Finn: the first thing that comes to mind is money, but that's a whole different, bigger political issue. I w- I won't go there. But, , you know, we, we've always been good in healthcare at identifying risks. Drex DeFord: Mm. David Finn: But we are horrible at prioritizing- Oh ... the risks, and ranking them and saying, "We're gonna do this first," because w- we have that let's do it all at once, , syndrome. So you have to identify the risks, and what I don't see happening very often is, is ranking them and moving them out. I, I remember when MFA was the fever, and it still [00:35:00] kind of is, but I, but I love to go to a place and they put MFA on every clinical system, but it's not on their email. Drex DeFord: Yeah. David Finn: Which is how most of the break-ins occur. Well, well, d. , why don't we start with MFA on the email and keep those guys out, and then we can start working? , I s- have yet to hear of an EMR being hacked into. I've never heard of it. That, that isn't where they get the information from. Drex DeFord: A lot of it is, , you know, the data that's been extracted from the EHR and put somewhere else in a shared drive. Yep. The, the crown jewels are usually not where you expect that they're going to be. Yep. And that's the stuff that gets stolen. , here's one for you. , these are actually pair- AI is over-hyped because blank David Finn: it doesn't have discernment, it doesn't exercise judgment, and it requires people [00:36:00] to manage it Drex DeFord: And it's under-hyped because blank. Why is it under-hyped? David Finn: Because we expect it to solve, , problems, and it's just another tool. It's not a problem solver, it's another tool. Drex DeFord: Interesting. Um, I'm gonna ask you one more question, I think, and then, , and then I'm gonna ask you what I... to tell me what I didn't ask you. What's one thing you had complete confidence in 10 years ago about cybersecurity that you have completely changed your mind about? David Finn: I was naive enough to believe that, , cloud platforms, cloud computing would actually increase, , security Drex DeFord: Hmm David Finn: And it has not worked out that way because of, again, the third-party risks and the hyperconnectivity. No one even knows what they're connected to anymore, [00:37:00] and, and that's really scary. Drex DeFord: I think there's this whole series of, like, unintended consequences, right? Yeah , especially when we got into the pandemic and people couldn't come in, and we were like, "How are we gonna run the data center?" So we went to a bunch of software as a service. So defen- depending on how you, you know, you talk to people, so define the cloud. Well, some people talk about it as, like, AWS and that kind of cloud, but a lot of people talk about it as a software as a service. Like, it's not my data center, so it's in the cloud. And, , all of the go- that got really complicated really fast. And- Yeah ... and it turned out that sometimes the stuff in the cloud was actually just something was running in somebody's garage- and wasn't more secure, and wasn't, , wasn't well looked after, so. David Finn: Yeah. Drex DeFord: Um, hey, I really appreciate you, , I really appreciate you being on. Before you go, is there something you wanted to, to talk about that I didn't ask you? David Finn: The world we live in, as, as connected as it [00:38:00] is, guardrails, which we've always considered the safety, the control, the guardrails in this world won't work anymore. You have to do constant real-time monitoring. , and, AI really blows that up because as we've noticed, , the, golden retriever puppy will run out of the yard even though you've fenced it in at, some point. And this is gonna shift. , I think it will, we'll begin to see that shift in security from guardrails and, fencing things in, and locking things down, to monitoring behaviors. We saw some of that around, , you know, , around, , DLP and where people were coming in from, but, but the AI hugging face has made it clear that, , rules don't cut it anymore in this world. You've got to watch what's happening all the time. . Drex DeFord: , Great closing point. David, thanks for being on the show today. I [00:39:00] really appreciate it. David Finn: Well, I, I thank you 'cause you're one of the few people I've known for a long time who doesn't call and just ask if I'm still alive, so. Drex DeFord: I'm glad you are, man. I'll see you- David Finn: Me too. Drex DeFord: I'll see you soon. David Finn: Take care. Speaker 3: Thanks for joining us for UnHack the podcast. Remember, you're not alone in this. Every healthcare leader needs a community to lean on and learn from. Be a part of that community. Go to thisweekhealth.com/subscribe and sign up. Then share the link, not only with your security crew, but with your entire leadership team and your entire staff. Thanks for being here. Stay safe, and I will see you around campus.

Found this useful? Share it with your network