I'm Mary and Colbus Ekmigee, executive editor at Information Security Media Group. Today I'm speaking with Mark Johnson, who is CISO, a Pack and Sack Meridian Health, which is the largest healthcare provider in New Jersey. We're going to be discussing cyber incident response and healthcare, and lessons that can be learned from those incidents. Hi, Mark.
Hi, Mary, and how are you? Good. So, Mark, you've had a long career in healthcare. Just to set the stage a little, what kinds of cyber incidents have you had to respond to over the years, including the most recent incidents involving your current role in Hack and Sack Meridian Health?
So, I've been fortunate in that my current role. We haven't had a cyber security incident since I've been on board, but I'm touching every piece of what I could touch right now. But over the years, we're responding to cyber security incidents like ransomware or virus attacks or just traditional hacking attempts. The challenge in all of that is identifying what happened, how do you retain it, how do you eradicate it, and then how do you restore to operational things.
What people don't often underestimate is the communication aspect of this. Because you've got to communicate to internal stakeholders, you've got to communicate to your business partners, you've got to communicate to potential patients at the end of it. You've got to talk to your leadership, you've got to talk to the regulatory aspects, you've got to talk to the outside counsel, cyber insurance. It's a lot of demands on communication that people underestimate every day of the week.
So now when you joined Hack and Sack Meridian Health, they had just had an incident a couple years prior, and that led to a quite significant transformation of your cyber security program, of the team. Tell us a little bit about that. Yeah, so you're right. I joined a couple years back, and this was about two years after the major event that they had, and what the transformation really came from the top.
So executive leadership and executive board level support said, we don't want this to happen again. And so they said, what do we need to do in order to make this change? And so they undertook really an organizational change management approach. Is that cyber security is an absolute bedrock requirement across the board.
We're not doing anything that we can't, we don't feel is the right cyber security risk. And it is a risk-based decision. It's not an ultimatum, it's not plus and one's and zeros. It is a balanced risk approach.
And that was probably the most transformational thing, and we could not have out there if it wasn't for that leadership. And the leadership of the people who were there and lived through the event and said, I don't want to do that again. So that's how it was. The CEO Bob Garrett did the opening keynote here at the conference at HIMS, and he was talking about AI.
But he kept coming back to you, you got to have security about that. We always talk about cyber security and innovation and how it sometimes goes against each other. And that's not the right approach. The right approach.
And this is where the transformation really took hold. The right approach is cyber security is about facilitating that change. It's facilitating it so that the organization can, in my case, change healthcare. Now the incident that did happen was a ransomware attack.
Systems were down for several weeks, and no one wants to go through that again. What are some of the key lessons that came out of that that you think other entities should be keeping in mind because you never know who the next victim is going to be? So, again, communication. Practice your incident response.
We do a tabletop exercise twice a year, once with the technical teams and once with the senior leadership, the executive leadership. We let them, we had craft a scenario. We bring in a third party to run them for us, and they drive that opportunity to make decisions. And it's a pressure cooker.
We do it for four hours. It's a real, no-kating pressure cooker. You got to make this call. You got to make this call right now.
And that practice is something that I would recommend everybody does. Because you got to be able to react and react without the panic. And doing this practice helps you do that. So, one of the things we hear so much about is patch your systems.
And I understand that as part of your transformation, you tackled what, like 90 or 80% of the vulnerabilities within a short amount of period. What was that like? And what did you have to do? Because there's so many systems in healthcare that, you know, clinicians say, oh, you can't take that down.
How do you tackle something like that? Yeah, it was, it was hard. It was very, very hard. And it's, again, to the leadership, the support of executive leadership, the support of the tactical leadership in our IT department, we call IT DTS.
So, I got to throw a dollar in the DTS jar after that. But the DTS leadership said, we got to fix this. And so, we couldn't have done it. You can't do it alone.
Cybersecurity, as someone said, is a team sport. And I hate that phrase because it's, you know, they're right. But it belittles what it really means. Okay?
So, we needed that commitment from everybody. We, we at the time had about 90 critical or high vulnerabilities per IP. We're down to less than a half of one. So, we couldn't have made that transformation without that change.
So, what could I buy into draft the gift from the clinical staff during this period? Because again, when you're fixing or patching systems have to be turned off, disruptive, what was I like? So, again, it's about shoe leather. It's about communication.
It's about making sure they understand what happens if we don't do these things. And working with them on when is the appropriate time? When is the best time to do this? Now we have standard change windows.
We have standard downtime windows and so forth for all the systems. We have major systems like our EMR and others have structured downtime and all that. So, we just extended that. And we, that's a really tough nut to crack.
That's a lot of commitment, a lot of support from leadership, etc. But it's also, it's, it's not, not losing focus, not giving up on that fight. And when it comes to support from leadership, I understand that before the event, your IT budget was like a half a percent. Now it's like six percent.
And you had maybe seven people before security. Now it's 35. How hard was that in order to get that buy into? Now let's focus and put more money, more resources, more people to these efforts.
So, you know, when they were going through the event, they said, Hey, I've got to fix this. I don't have a tool. I don't have something. So, they put things in right away.
They slam things in. And then, again, to leadership's credit and to the people who are on the grounds credit. Okay. And again, I wasn't there.
But to the credit of those people, they said, Listen, it doesn't snow good if we just throw it in and walk away from it. We've got to have the care and feeding for it. And leadership's listened to them and said, Yep, you're right. It doesn't snow good if we don't care and feed for these things.
And that's how it happened. And so, we got the support. We had benchmark studies from things and so forth. But we got the support to grow the team, leave the team, and be able to really give them a foundation to drive their career.
It's okay if they leave to go do another job. Because while they're here, we want to be valuable and contributing. And, you know, my career has been long enough. I know that I'm going to work with people again over the course of my career.
So, it's okay. But that's the key. It's getting the people to do this. Getting the organizational commitment to get the people and getting the people to do this.
That's the key to making this transformation successful in long-term. And what are the common threads that you see in terms of entities and what they should plan for? Regardless of what kind of incident they're dealing with. Are there certain chapters of playbooks depending on what the incident is?
What are the common threads that you think are key that entities might overlook? Well, I don't know if they're overlooking it because we talk about incident response all the time. And every cyber conference there is. I don't know if people are going to do it.
So, it's going to sound like I'm just telling you the same things, right? And that's the relationships. You've got to build relationships both internal to your organization. And as you heard in the presentation, I meet with compliance and legal all the time.
So, that's an important relationship. That they have an important aspect of the role of the job, just as we do in cybersecurity. And you've got to work together as a team. There's relationships do executives.
There's relationships outside the organization. Don't have the first time you're talking to law enforcement the day of the event. Don't have the first time you're talking to your cyber insurance team the day of the event. Have those relationships in place.
They know you know them. So, then when you're under crisis and you're in a crisis, you can react. So, finally, Mark, what are you keeping your eye on most closely when it comes to the cyber threat landscape right now in healthcare? What's most troubling keeps you up at night?
Well, I mean, everything is about AI now. Everything is about artificial intelligence. And artificial intelligence has great promise. But it also could be used for great evil.
And so, what's probably the scariest for me is that. Is what is artificial intelligence going to do to the threat landscape? How are we going to have to react faster than we currently are? And even today, we're using all of our cyber tools, leverage artificial intelligence so that they can be better.
It's an arms race. And that's the thing that I'm most worried about right now. It's artificial intelligence. Not because I don't want it to happen.
Because the power and the promise of this is so incredibly high. It's just what happens if. And that's kind of the attitude that I have as a cybersecurity guys. That's great.
That's how it works. What happens when it breaks? And any advice for dealing with the uncertainty or for other systems that are dealing with the same sort of we wonder what's coming? I mean, it's a standard advice that I give everybody who gets into cyber security.
And so this don't be the no-please. Don't be the no-please. The uncertainty that's coming. And every organization, every leader is a risk manager.
They make business risk decisions every single day. That's what they do. And your job in the cyber side is to explain that risk so that they can make an informed risk decision. If they go against a decision or how you feel as a CISO, the way it is, that's their progress.
And you've got to be really comfortable with that. And I think that's the number one challenge in cyber security here, especially like we talked about with AI. We're not walking away from AI. We're embracing AI.
All right. So have a seat at the table. Have the discussions. Have the relationships.
Well, thank you so much, Mark. I've been speaking to Mark Johnson. I'm Mary Ann Kolbasuk, the G of Information Security Media Group. Thanks for joining us.