Skip to main content

Search site

Find podcasts, news, articles, webinars, and contributors in one search.

Executive Interview
Executive Interview artwork

Zero-Day to Weaponization Is Now Sub-Hour.

·18:47.016000000000076
0:000:00

Questions Answered in This Episode

  • If zero-day to weaponization is now sub-hour, what in your program still assumes a human patch cycle?
  • Do you know whether the box you would quarantine is running a CT scanner?
  • If 97 percent of breaches miss the EMR, where is the data actually sitting?
  • Can you talk to the board about resiliency and patient care without using fear?
  • Is your inventory clean enough to let an agent take an action?

About This Episode

September 9, 2026: Russell Teague (Chief Strategist and CISO, Fortified Health Security) sits down with Drex DeFord. Healthcare has been the number-one targeted industry for 13-plus years. Fortified only does healthcare, because no other industry has human life on a 24/7 stack. From there: 40-plus autonomous SOC vendors at Black Hat, a workstation that might be the CT scanner, 97 percent of breaches that never touch the EMR, and a board conversation that has to be about resiliency and patient care, not fear. Zero-day to weaponization is now sub-hour. You will not patch at machine speed.

Guest: Russell Teague (Fortified Health)

Key Points:

  • 01:35 Healthcare, Number One for 13 Years

  • 05:06 Human in the Loop

  • 09:08 97 Percent of Breaches Are Not the EMR

  • 13:13 Zero-Day to Weaponization Is Sub-Hour

  • 15:47 Talk to the Board About Patient Care

  • 17:19 Fear Will Not Win You Money

Bring color and joy to a child’s day: https://augustsartists.networkforgood.com/projects/166901-everyday-giving

Keep up to date on the latest in health IT:

https://thisweekhealth.com/news/

Thank You to Our Episode Partner

Fortified Health

Contributors

People featured in this episode — open a profile for more.

Transcript

This transcription is provided by artificial intelligence. We believe in technology but understand that even the smartest robots can sometimes get speech recognition wrong.

Zero-Day to Weaponization Is Now Sub-Hour.

[00:00:05] Drex: Hey, everyone, welcome to the show. I'm with Russell from Fortified Health Security. Hey, it's good to see you today.
[00:00:12] Russell: Drex, thanks for having me. I look forward to the conversation today.
[00:00:14] Drex: Yeah, I'm glad you're here. Chief Strategist and CISO at Fortified Health Security, even doing this for a long time.
[00:00:22] Drex: Healthcare, pharma, life sciences, finance, retail, manufacturing, oil and gas, amazing background.
[00:00:31] Drex: US Army intel, our shared military background is kind of forms some to some degree the way we think about adversaries and trade craft and not just controls.
[00:00:43] Drex: You have an amazing background. What's what's what's next for you?
[00:00:49] Russell: Yeah, it's interesting throughout almost 30 years, right?
[00:00:54] Russell: As you indicate, I started in the military really around electronic and electronic engineering.
[00:00:58] Russell: So I have a strong technical background is where I tend to focus on mostly.
[00:01:03] Russell: As my journey continued through my career, I really began to adopt the cyber security focused in the early days with IBM, really in the beginning.
[00:01:12] Russell: I've been consulting services. And then through those through my career, I've kind of followed the threat actors, whether they were focusing on, you know, oil and gas, retail, banking and finance, utilities, and now in healthcare.
[00:01:27] Russell: And they've been here in healthcare. Healthcare has remained the number one targeted industry for 13 plus years now.
[00:01:34] Russell: And so, which is uniquely different than all of the other industries, right? In terms of, and I tend to focus on what did they do differently that actually move the threat actor to another place?
[00:01:47] Russell: And what can we do here in healthcare to get that same outcome to try to drive threat on the Earth?
[00:01:53] Drex: I mean, one of the really interesting things about, sorry, go ahead.
[00:01:58] Russell: No, I was just going to say to ultimately raise the bar in cyber security.
[00:02:02] Drex: Yeah, one of the really interesting things about what you're doing now, what you've been doing for a while at Fortified Health Security is that you guys focus only on healthcare, which really is a unique approach to this.
[00:02:16] Drex: Most are across multiple industries. You guys have honed in specifically on healthcare. Talk a little bit about that.
[00:02:23] Russell: Yeah, no, I'm absolutely Fortified Health Security is a managed security service provider exclusively focused on health care. As you said, that makes us uniquely different in terms of how we think about the problem, how we think about the impact associated with security exposures and security risk within healthcare.
[00:02:41] Russell: No other industry across across the globe has human life connected to technology like healthcare does. No other industry operates on a 24 by 7 basis with human life connected to it.
[00:02:54] Russell: And so when you think about the most basic things, oh, I'm just going to schedule a downtime or patch or you know, schedule reboot cycles. Those are very difficult in healthcare.
[00:03:05] Russell: And so that requires a different mindset when you think about how do I remediate or how do I begin to think about managing risk within a healthcare setting.
[00:03:14] Russell: That's significantly different than any other industry. Yeah, for sure.
[00:03:18] Drex: You were a Black Hat this year. What did you see? What did you hear about? What was interesting there?
[00:03:26] Russell: Black Hat always blows me away. You know, I go to most of the national conferences across the board, whether it be RSA or Black Hat. Black Hat is obviously uniquely focused on the cyber aspects of things.
[00:03:38] Russell: And so still very much a business to business or partnership type of of conference rather than a client. You will find, you know, CIOs and CISOs and and CTOs walk in the floor.
[00:03:50] Russell: But the majority of them are really, you know, partner to partner kind of conversations.
[00:03:57] Russell: As you can imagine, AI everything. Yeah. You know, the two, the two kind of areas that stood out to me the most was the emerging focus on AI.
[00:04:09] Russell: Soc automation or AI sock. I'm in the thinking about that.
[00:04:16] Russell: 40 plus vendors focusing on that area across done the Black Hat floor.
[00:04:23] Russell: Yeah, it went around and did a poll. Well, I went through and looked at the inventory.
[00:04:27] Russell: And then I probably hit 10 or 12 of them. Some of the others that I'd already met with in prior years because this has been an emerging trend over the last several years.
[00:04:39] Russell: I still think we have a ways to go in terms of broad adoption. Right. Many of these platforms are assuming you're going to turn everything over to a set of agents that are going to, you know, use the inbound technology, analyze the data being pumped into it triage it investigated.
[00:04:58] Russell: And then using reasoning and decisioning actually take a decision take take an action.
[00:05:05] Russell: My belief is that a human still has to be in the loop, especially in healthcare, right.
[00:05:10] Russell: You don't know if that workstation is running oncology imagery, you know, running the CT scanner. Right.
[00:05:20] Russell: You don't know if if that is a, you know, that device that you're going to quarantine or shut down is tied to, you know, medication, administration, you know, tons of other things.
[00:05:31] Russell: It's just we don't have the context right out effective, acid inventory and all the other stuff added into that. And, you know, being being, being, you know, having visibility as large as I do across the healthcare ecosystem.
[00:05:46] Russell: I can tell you these things are just not standard across health environments. And so all of the visibility needed to get to an autonomous state is just not really available and is not clean data. So bad data in is bad decisions out.
[00:06:02] Drex: Yeah. I look at this too. We talk about data quality a lot as we talk about AI a lot in 229 project events. We talk about data quality.
[00:06:14] Drex: And the way that we talked about data quality for a long time, we have to improve our data. We have to understand what are the real sources of the data, which one is the one that we're going to use for metrics or dashboards of those kinds of things.
[00:06:27] Drex: AI has really helped us drive more discipline into data or it's doing that, I think, because now we really have this like exciting use case. I feel like a little bit of, you know, what you were just saying, like AI and sock operations or AI in any kind of cybersecurity operations.
[00:06:47] Drex: Maybe drives us to more and better discipline around knowing what we have on the network, knowing what it connects to and how it connects and all those kinds of things that we've always wanted to do, but we've never had the reason to, you know, compel us to do it.
[00:07:04] Drex: The bad guys are using AI and they're going super fast and I feel like we're going to have to get on that same train, but we got to have all the material, all the data to get there.
[00:07:15] Russell: Yeah. The technology that I see being developed across the floors right at these national conferences does excite me, right, does give me hope that we're heading in the right direction.
[00:07:25] Russell: And most of these platforms to do to reach the outcomes that they're proposing requires complex integrations into every asset of the organization into the asset inventory, into the, you know, into the customer inventory, into the workflows, you know, all the logs, all the network data, you know, integration in the EDR, the SIM, the network detection and response, bringing all of that capability together, right, you and I've been around long enough to know back in the G or C.
[00:07:55] Russell: And I think it's really a big, really big thing to be able to do is to get the data and to get the data to be compliant stays where, you know, you, you bought a platform and it took you three to five years to implement a customized, actually get an outcome.
[00:08:04] Russell: My fear is some of these, some of these platforms and their aspirations are are going to be too far to achieve because healthcare has a challenge with clean data, right.
[00:08:15] Russell: So, and then ultimately when you're talking about board decisions and you look at what the data tells us, right, 97 plus percent of breaches don't happen from them stealing data from the EMR, they steal it from local data stores where data is propagating.
[00:08:33] Russell: So back to your comment before around really focusing on the data, where it is, what, what business processes are putting data in unsecure or insecure locations.
[00:08:46] Russell: It will really help reduce your attack surface, right, and minimize the exposure network segmentation is going to become a, I think a more important element for organizations beyond just VLAN separation, right, which is really doesn't bring any true security to it.
[00:09:02] Russell: It just, it just makes it easier to control your network. But true, you know, VLAN separation or zero trust architecture style environments where you do true micro segmentation with restrictive access controls on those VLANs.
[00:09:17] Russell: I think are going to be the, we're going to see more and more in the future with data architecture security architects are getting back to the fundamentals.
[00:09:25] Russell: And then, and then once we have those, I think we can then speed up a lot of things and take advantage of the aggregated automation capability that AI brings us.
[00:09:34] Drex: Yeah. We've got, we've got quite the road to travel to get there.
[00:09:38] Drex: Yeah, it's, you know, I talk about sometimes we add automation to things that really aren't ready for automation.
[00:09:46] Drex: We take a train wreck of a process and we make it a really fast and efficient train wreck. And that's when we realize we have to go back and build the fundamentals in place so that we can actually do the automation that we kind of aspire to.
[00:10:00] Drex: I want to ask you about another thing too.
[00:10:03] Drex: You guys do a really cool report twice a year called the Horizon Report and the mid year report just came out recently.
[00:10:10] Russell: That's correct.
[00:10:11] Drex: What's the headline from the report? What, what do people need to know and where, where do they go? Download it?
[00:10:18] Russell: Yeah, no, I appreciate it. You can definitely download it on our, on our website at fortifiedhealthsecurity.com.
[00:10:23] Russell: There's an entire section on, you know, our documentation and the Horizon Report. So I encourage you to go get that.
[00:10:30] Russell: You'll find it on post it on LinkedIn and many other places as well.
[00:10:34] Russell: You can also just request it at connect at fortifiedhealthsecurity.com and we'll get it to you as well.
[00:10:41] Russell: But I think the major takeaway of that is as we try to do this twice a year mid year is one that we just released.
[00:10:47] Russell: It really tries to take a look at what we've seen over the first six months of the given year.
[00:10:54] Russell: And then the end of year will wrap up kind of bad and then also set our predictions for for 2027.
[00:11:00] Russell: Currently we're seeing, you know, obviously we're seeing some of the same in terms of threat actors still targeting.
[00:11:07] Russell: We're not winning that battle and driving them away by raising, you know, this cybersecurity bar to push them away.
[00:11:13] Russell: It's still too easy.
[00:11:14] Russell: So that trend continues. But we are seeing a significant shift in what they're targeting and how they're targeting.
[00:11:22] Russell: They are still playing into hack the human that is a still a very viable and traditional approach.
[00:11:29] Russell: But this year is the first year we've seen vulnerabilities themselves rise to the top.
[00:11:35] Russell: And you'll see this in many of the many of the threat reports out there today, whether it be from Verizon or many of others out there.
[00:11:42] Russell: Vulnerability and technology exposures is quickly rising.
[00:11:46] Russell: And I think that's the advent of the threat actors using AI.
[00:11:50] Russell: Frontier models.
[00:11:51] Russell: Yeah.
[00:11:52] Russell: Yeah. They're moving faster, having access to optimized foundational models as well as the frontier models.
[00:12:01] Russell: I don't know how much of the frontier models the threat actors are totally using today because obviously there's some hoops to go through to get access to them.
[00:12:10] Russell: But you know, that's only the major four or five that have restricted access.
[00:12:16] Russell: There are many others out there that are that are continuing to advance that are maybe non-US base that still have a lot of things to be building.
[00:12:24] Russell: So I think that's enabling them to move faster to do broader vulnerability identification and then allow them to literally pivot and build an exploit for that identified vulnerability, even if it may not be a known vulnerability.
[00:12:39] Russell: Right. So zero day to exploitation or zero day to weaponization is now sub-hour.
[00:12:46] Russell: Right.
[00:12:47] Russell: Yeah.
[00:12:47] Russell: Right.
[00:12:48] Russell: And so our ability to one get notified that that is a net new risk that potentially maybe in our environment and then us to go through a patch cycle.
[00:12:58] Russell: It's just not realistic.
[00:13:00] Russell: We're not going to be able to patch at machine speed as quickly as the threat actors are going to be able to identify vulnerabilities at machine speed.
[00:13:07] Russell: So we have to begin to think about how to think about our program differently, how to segment reduce the blast radius.
[00:13:14] Russell: Really secure your external enterprise.
[00:13:17] Russell: If you're going to focus on anything, right, understand your your external attack surface and begin to secure that first and foremost, at least keep them at bay.
[00:13:26] Russell: That's your first line of defense.
[00:13:27] Russell: And then and then internally, right, because they're hacking the human they're using a vulnerability to get a foothold in an environment.
[00:13:34] Russell: The data still shows that they're operating undetected in environments for months on end six, between six and eight months.
[00:13:42] Russell: And so which means we don't have good detection around lateral movement, right, things happening once they become a user on the environment.
[00:13:51] Russell: And so one of the focus areas that I've been really looking at is how do we bring network detection and response capabilities back into the mix for years we moved away from that and really thought the end point detection was the
[00:14:04] Russell: end point with SIM would get us enough visibility and provide us enough detection capability with the shift in this methodology.
[00:14:12] Russell: We're starting to see where threat actors can operate in that environment much longer without detection because we're not really doing anomaly based detection models use your behavior system behavior.
[00:14:23] Russell: Looking at when this system talks to this system and it's never done that stop, ask why, right begin to do a triage investigation.
[00:14:31] Russell: And what we'll do is we'll we'll cause them to hit the trip wire faster and help us identify what they're doing in the environment and allow us to to respond and contain much quicker before it becomes a major data loss.
[00:14:44] Drex: Let me ask you one more question.
[00:14:47] Drex: And this really has to do with the conversation that we're having as CISOs and CIOs with our fellow execs and our boards talking about security.
[00:15:00] Drex: Do we need to think seriously about changing the way given everything that we've talked about today and a bunch of other things that we probably aren't going to have time to talk about.
[00:15:09] Drex: Do we need to change way we talk about security to other execs in the board?
[00:15:14] Russell: You bring up a very good point because if you think about the financial pressures that health care sits under today, right, we're seeing large amounts of merger, merger acquisition consolidation of the industry, right, smaller entities that are failing or struggling financially.
[00:15:30] Russell: The Medicare Medicaid reimbursements that did not get renewed has really changed the landscape in terms of the financial models of health care today.
[00:15:41] Russell: And so boards need to understand not from a technical perspective around what risks they lie, but they need to understand the impact to resiliency, sustainability and operations of patient care.
[00:15:54] Russell: If you want to get support, start having a meaningful conversation around the impact of our ability to actually generate revenue, our ability to serve patients, which allows that revenue to flow in.
[00:16:07] Russell: And changing our conversation at that level, I think will still allow the cyber focus to remain in the forefront and allow what limit investments they have to continue to still flow in that direction to protect the resiliency, the uptime and the continuity of patient care.
[00:16:25] Russell: This is no longer a technical conversation fear and certainty in doubt will not win you more money, right, it'll get you shut down and probably not asked to come back to the board, right, so you've got to really begin to think about the pressure that the CFO is as under and the executive team is under to try to deliver a viable profitable business, even though it's super razor thin margins.
[00:16:49] Russell: But we got to figure out how to do that differently. And so rethinking your program, rethinking how you you position cyber is more is definitely a major takeaway and what I'm seeing 26 and beyond because the financial pressures aren't aren't going away.
[00:17:06] Drex: Hey, thanks for being on the show today, I really do appreciate it before I leave I'll ask you one more thing. Is there anything else I didn't ask you that I should probably ask you about?
[00:17:17] Drex: No, I mean, I think the only thing that I would share that that's kind of new for us is we just released a new module within fortified central command, called command AI.
[00:17:29] Russell: That's our implementation of where AI is assisting the human in the loop, where we were, you know, we in order for us to move faster, move through triage faster, right, reduce our our meantime to identify meantime to triage meantime to recover.
[00:17:46] Russell: We need automation. And so get a chance to look at it, love for you all to go out and look at command AI and look what we're doing.
[00:17:54] Russell: Again, fortified central command is an enablement platform. It's not something we sell. It's how we deliver our capabilities and our services to our clients. So yeah.
[00:18:03] Drex: Well, thanks for being on hopefully our pass will cross sometime soon on the road.
[00:18:08] Russell: I'm sure it will.

Found this useful? Share it with your network