Skip to main content

Search site

Find podcasts, news, articles, webinars, and contributors in one search.

Executive Interview
Executive Interview artwork

This CISO Says AI Doesn't Forget, That Should Scare You | Executive Interview with Robert Forbes

Questions Answered in This Episode

  • Why should healthcare leaders fear that AI doesn't forget patient data?
  • How are attackers using AI to outpace healthcare's defensive capabilities?
  • What is minimum viable care and why does it matter for cybersecurity?
  • Can you patch a nine-year-old medical device that's critical to operations?
  • Should healthcare run AI locally or risk data exposure in the cloud?

About This Episode

August 05, 2026: Robert Forbes has spent 40 years in cybersecurity, from working on MILNET before the public internet existed to running the Air Force's high-performance compute center, to leadership roles at CA, Okta, and now Field CISO at SHI. Drex DeFord sits down with Rob to unpack why healthcare's AI moment is different from every other industry's. Rob introduces the concept of "minimum viable care," explains why agentic AI breaks the traditional non-human identity model, and shares the real story of an AI agent that deleted a production database while trying to log in. A candid look at governance, cost, and risk for healthcare leaders navigating AI right now.

Key Points:

  • 03:21 AI Pressures and Threats

  • 05:59 Minimum Viable Care Model

  • 09:07 AI Governance Wake-Up Call

  • 11:21 Wrap-Up and Community

Bring color and joy to a child’s day: https://augustsartists.networkforgood.com/projects/166901-everyday-giving

Keep up to date on the latest in health IT:

https://thisweekhealth.com/news/

Thank You to Our Episode Partner

SHI

Contributors

People featured in this episode — open a profile for more.

Transcript

This transcription is provided by artificial intelligence. We believe in technology but understand that even the smartest robots can sometimes get speech recognition wrong. This episode is brought to you by SHI. As a trusted partner to healthcare IT leaders, SHI understands the unique challenges of managing complex healthcare technology environments. Their IT asset management team has helped health systems save millions in licensing costs, eliminate security vulnerabilities, and optimize IT investments. Whether you're modernizing your infrastructure, implementing AI solutions, Or strengthening your cybersecurity posture. SHI expertise helps CIOs and their teams focus on what matters most. Enabling quality patient care through technology. See how other health systems have transformed their IT operations at ThisWeekHealth. com slash SHI. I'm Drex DeFord from The 229 Project and This Week Health. Our mission is healthcare transformation together. Welcome to this executive interview, real conversations about managing risk at the highest levels. Let's dive in.  Hey, everyone, I'm Drex, and I've got Rob Forbes, who's the, the field CISO for SHI here with me today. Uh, hey, Rob, welcome. I'm glad you're here. Tell me a little bit about yourself. Tell me a little bit about SHI and, and what you all do.   Sure. Thanks, Drex. Really, really appreciate it. Ha- happy to be here. Field CISO for, for SHI. I'm, I'm the old guy we trot out sometimes. I've been doing this for 40 years. I started out working on MILNET at Headquarters Air Force really before there was a public internet, so a long time. Then, then a lot of time with organizations as they were rolling out their cert teams and rolling out their firewalls and, you know, places like Nationwide Insurance and Bank One and AutoZone, so a lot a, lot of time in the seat, everything from a keyboard jockey all the way up. Uh, actually ran the Air Force's high performance compute center at Wright-Patt, uh, at, at AFIT, so a, a lot of lived experience. And then a chunk of times at organizations like CA and Okta, Opaque, which you'd call 40 SASE these days. So a lot of times on the vendor side, and then now, uh, a chunk of time on the consulting side, helping customers solve their challenges and problems. And that's, that's where SHI brings, brings myself and the other field CISOs to the table is to help our customers think about their challenges across their IT stack, across their cybersecurity stack, across their infrastructure. I've got peers that are CTOs that do the same type of thing, and it- it's come in, it's our investment into the, into the customers to help them at these high levels without saying, "Hey, write me a check for this." No, we're gonna come in and solve some of these challenges for you across the entire infrastructure.  Yeah, I love that. I, I'm a retired lieutenant colonel. I worked on MEDNET early. We probably chewed some of the same electronic dust at one time.   I'm betting we did. We were probably- Yeah ... on some of the same bits and bytes channels.   Prior enlisted comm computer guy and then became a hospital administrator, medical service corps officer. So it's so funny sometimes when you find these overlaps. And in the market today, like, there's a lot happening right now and kind of change is constant, tons of financial pressure- So you talk to a lot of execs. What do you hear when you're out there talking to folks?   Yeah, so, so right now we, we are hearing that, you know, the, the, the change and the rate of change that they're facing is one of the biggest challenge. Obviously, AI is, is exacerbating that from, from two sides. You know, for a lot of organizations, especially in healthcare, they're seeing that the AI is enabling the attackers. They're becoming faster. They're becoming more adaptive. The static approaches aren't working. Um, third party, you know, the, the attacks of third party, even third party's AI are something they're, they're really concerned about. But at the same time, they're concerned about getting AI into the patient rooms, into the outcomes, into the imaging, into the different things. So they're being pushed from both sides of the AI side, and it's, it's interesting because the attacker's gonna come at it unmitigated. They get to roll out AI without any thoughts of hallucinations, governance, privacy, spin, security. So they're, they're escalating at a rate that's hard for healthcare to, to focus on. And, and healthcare traditionally, the, the number one thing isn't the technology. It's not even the, the finance. Their, their biggest concern is the patient outcome. Hmm. Do I have patients who, who are, who are coming out of this? Am I able to provide care to them? So they're trying to bring AI in, but they've got new requirements from HIPAA that say, "Hey, you gotta have inventories of all your AI. You gotta have controls of your AI." Yeah. So they're getting squeezed from both sides. It is the business and the doctors and, and everybody saying, "Hey, we need AI over here," and at the same time they've gotta understand the threat from AI. So they're, they're getting double dipped on it.   Uh, the frontier model, um, you know, impact on patching is one of the big things that I hear about, um, all the time too. A lot of, a lot more conversations, not just about preventing things, but the whole resilience conversation. How do we stay up and running and treating patients when the bad thing happens, no matter whether that's a security thing or not? The identity problem, which, I mean, I know that's a huge conversation that you're   It is a big challenge for 'em, and, and you, you, you've nailed on something very specifically, that resilience side of it, the frontier side of things. It's, it's interesting because healthcare's unique from some of the other organizations. Healthcare buys for seven, 10, 15-year life cycles of hardware. Hmm. But our vendors and our partners aren't providing patching and security and maintenance for these things. So now healthcare, you know, and traditionally we've had this, "Hey, everything's flat. I've, I've got a network. I've got- Yeah ... cows. I've got wows. I've got, you know, technology. I've got monitoring systems. They're all on the same floor. They're on the same subnets 'cause that's how we built these things." But now I have the threat vectors that are coming in from third parties and from things that bring these, these threats into my internal network. You know, the identity side. We're not hacking in, we're logging in. So now how do I actually go secure those things that, that... I, I've coined a phrase that I u- been using that I call minimum viable care. We've got minimum viable company, you know, what does the company have to have? Well, for healthcare, they need to stop and think about minimum viable care. What are the systems and the, the procedures and stuff that need to be online for me to be able to go, "Hey, I'm not sending you to another hospital. I can get the ph- Hey, maybe I don't need to do outpatient pharmacy, but I need to do inpatient pharmacy. I gotta be able to, to, to get the, the, the drugs and the, the IVs and stuff for surgery and stuff like that. I need to have my imaging system, so I need to think about this concept of minimum viable care to ensure patient outcomes." And it's a, it's a shift for them because it lets them then say, "Hey, where do I spend my money strategically so this outcome, that minimum viable care, occurs?" So now maybe it's not, hey, I go buy micro-segmentation for everything, but I buy it for these systems that I need to target. So now it gives them a mindset to actually go say, "Hey, when I'm thinking about this, I've got limited spend, limited dollars, limited resources, and my primary focus is that." Putting that lens and approaching on things is something we've been talking to healthcare organizations about for, you know, about the past two, three months when we actually said, "Hey, here's a way that you, we can actually steer you and guide you for this."  Yeah. You can't duplicate everything, I guess. So where's SHI g- given, I mean, all the things we talked about and probably a whole lot more, where is SHI focusing right now? What are you building or changing or rethinking working with health systems?   Yeah. So it, it is really putting ourselves into that different world that they live in from everybody else. You know, healthcare and universities are probably two of the most complex environments that you've got from an identity standpoint, from a technology standpoint, from a operational standpoint. They're, they're, they're not similar to how other organizations function inside these areas. So, so looking at the tools and technologies that they actually help solve their problems. So looking at those players in the space, the Orders, the Cephables, the Dragons, the, um, the, the ZScalers and other folks, what technologies can we bring into play to solve the challenges that are specific to healthcare and work within their constraints that they have? Hey, we, we know that we can't patch everything. We know that we can't, you know... Hey, that, that system over there, that X-ray system we've got, it's nine years old. There are no patches for it, but it's gotta be up in that minimum viable care model. Mm. So how do I secure that? Whether that's using, you know, segmentation on the LAN, whether it's using local OS protocols. What are the tools that I can bring to bear in there? What is the thinking I can bring to bear in there that solves the challenge for the organization?  What do you want other healthcare leaders to hear? there's a lot of noise right now. If you could turn off all the noise, and you had, like, you know, a, a minute to say something like, "Okay, now that I have your attention, this is really important." Fill in the blank. What's the thing you would say to, to healthcare leaders right now?  So, so now that I have a minute, the, the really important thing I would say to healthcare leaders is you have to stop and think about the governance of your AI. AI is changing the way we do everything, but it's not the traditional mindset of a non-human identity. We... A lot of organizations think of humans and non-humans, and they're lumping AI into those non-humans. But that's fundamentally flawed because non-humans are typically devices, they're scripts, they're batch jobs that when they break, when they don't work, it, stops.  AI and agentic AI are actually changing that mindset and that approach for the organizations because it is a new class. It doesn't just stop. It doesn't say, "Hey, I can't log in," and go, "I'm breaking." It goes and looks for that API key, such as PocketOS saw where their Claude agent said, "Hey, I can't log in. Let me go get an API key. Let me log in. By the way, oops, that's the production environment, not the test environment. And oops, I deleted all our production databases." So we need to stop and think about the implications of AI. We're being asked to roll it out, but a lot of times we're, we're treating it just as a, as another non-human identity, but it's not. It brings different privacy concerns. AI doesn't forget. If I put the data in a database or I stick the data in the email, I can go delete it. I can delete that record. I can delete that row. If AI consumes it, I can't delete it. I can't change it. So this becomes challenges we haven't thought about. You know, this is more things we have to deal with privacy. And then obviously the spend impact. You know, we, we... The one other big one we hear is tokenomics, token tolls. We had this with cloud, we had this with cloud exit fees. We suddenly hit there, and we got it, and we're like, "Oh." So that-   Way more expensive than we thought.   Way more expensive than we thought, and privacy and security and everything, 'cause when I push it out in the cloud, if it accidentally consumes that data, I can't tell Gemini, I can't tell Anthropic Claude to go delete my data that accidentally got in there. So do I need to think about running this locally and, and securing it locally? What are my opportunities there? How do I do that? So those are, those are probably the two things of it. You know, the how do I, how do I govern this new entity, human, non-human, now agentic or AI entity, and then how do I actually manage that? Do I stick it in the cloud? Do I run it local? What are those implications? And for healthcare, those are very critical things you need to think about.   Yeah. Hey, thanks for being on today, Rob. Uh, I really appreciate your time, and I hope I, uh, get to see you on the road sometime soon.   Awesome. Thanks, Drex. I look forward to it.   thanks for joining this executive interview with me, Drex DeFord. Here at This Week Health, we believe every healthcare leader needs a community to lean on and learn from. Build your network at thisweekhealth.com/subscribe, and share all of this with a colleague. Thanks for being here. I'll see you around campus

Found this useful? Share it with your network