I'm Mary and Colby Seckmiki, executive editor and information security media group, and I'm here at the HIMS Cyber Forum in Boston speaking with Erica Decker, who is Vice President and Sizzo of Intermountain Healthcare. Hi, Erica. Hi, Erin. Nice to see you.
You, too. So, Eric, you spoke here at the conference about the importance of developing and fostering a cyber security mindset in healthcare. Is that easier said than done and why? Yes, it is easier said than done.
You know, I think one of the hardest things in cyber security is to, is how folks understand the issues, the threats that we face, the reason why we have the controls that we have, and, you know, how that intersects with their daily life. You know, when you think about your, you go about your work and there's a friction point that's inside your work, if you understand the reason for the friction point, it's easy to have a mindset that says, this isn't an annoyance, this is a problem, et cetera. It actually might be an annoyance, and it might be a problem. Like, there are times that we implement things that might actually be too friction forward.
So, you know, really, you know, getting to a security-driven culture, a fostering a security-driven culture, which was the talk that we just gave, you know, my opinion, that's a culture that understands the reason why we do what we do. They feel part of the team, they feel comfortable and safe to be able to bring issues up with us, both things that, they think the mistakes that they might have made that might have induced risk in the organization, or, you know, just feeling safe to ask a question or a clarifying question about why a particular control is in place, or here's how this is, you know, causing an impact in our workflows and environments, and, you know, partnering with us on those, on trying to make those changes, or just understand that. I think that's, that's important, and when you have a good healthy dialogue and a good safe space for that, you can really, you can shine the light on a lot of areas of friction that exist, it might not need to be there, and then when you need to apply friction, when you need to apply the breaks, it makes it easier for the organization to understand why and to adapt to that, and partner with you on that, so. What are some of the areas you do see friction between perhaps what, you know, is the best for the organization when it comes to security initiatives, but perhaps push back from clinicians and others that think that, you know, this might be, you know, additional hurdles and what they need to do, to take care of patients?
I mean, the classic example is authentication, and needing to log in or multi-factor authentication, you know, type in a password that you, you hit approve on your phone, and, you know, need for that kind of control is important, very important, in this world that we live in, but I think one of the things that we can do better in cybersecurity is actually taking user-centric mindset when we apply these kinds of controls. There are ways to do it. We can, we can flip up votes, we can have authentication, we can have multi-factor authentication, we can have a highly secure environment that maybe the physician, clinician, or nurse only deals with, you know, once, twice or three times during the day, but that requires us to have a very systems thinking mindset and be able to understand where they're moving and how they're moving around and then actually integrating those systems in the back end. This is where the tech side of this comes into play to architect that way.
If you don't, you just approach it on an application-by-application basis, then it's going to feel very fragmented, and for the user that's coming in, they're going to just, they might groan a lot about how many times they have to type in their password, you know, and that's, that's a problem. So now it's also a budget planning time for many healthcare organizations. Any suggestions or tips for how healthcare CISOs and their teams can make their cases stronger to the top brass about why they need the funding and resources that are being sought? Yeah, the first thing I would say is it's really important in this day and age, right now in healthcare with how the adversaries are beating us is to have an adversarial mindset to risk, meaning know what the tactics and techniques are that they're using to get in.
We know that phishing is a common enough attack still, unfortunately. What's the most effective control against phishing? It's multi-factor authentication. Ideally, fish resistant multi-factor authentication, but any multi-factor authentication is going to be better than zero multi-factor authentication.
What does that really mean? It really means getting it in to every edge point where there is a lot of accessibility, such as the internet, and an exposure of that credential is going to be, you know, used against you. So I think there are March actually just recently put down five mandatory controls that you have to have if you want to be in short. That's kind of the first step into the industry applying pressure to, and that's based on their science, based on their claims data that said these were the controls that were bypassed that ultimately led to a shutdown of the organization.
And so you've got to do those five things. And they're kind of forcing it. I would say, you know, start there, start on like one of those minimum things, start to look at the March 5 and see how you how you're set up. So now, Eric, looking ahead to next year, what's on the list of your top cybersecurity projects and priorities and why?
So, you know, we at Intermountain, we are, you know, we grow in an inorganic method. And so we have a lot of M&A work. And so my focus continues to be supporting the M&A, supporting getting the security program into every new company that we are bringing on. It's continuing to mature our capabilities of our teams and our defenses.
And it's continuing to have hyper focus on this adversarial mindset. There are a lot of really good projects. There's a great design architecture that you can apply to Active Directory called isolation. You speak called Red Force.
Now, it's a isolation zone architecture. It's one of our projects. And it just significantly improves your defensive capabilities. So it's stuff like that.
When you apply that the way that you're getting the health systems are getting beat and then you look at yourself and do that gap analysis, you can find target rich opportunities there. And finally, Eric, we hear so much about generative AI and healthcare. What are you keeping your eyes on these days in terms of the potential use cases involving AI that could have a big impact, good or bad in healthcare? Yeah, I don't think I have a really good answer on this one.
I think it's still being highly explored. Our clinicians and nurses are looking at various use cases. There's various use cases in contact centers that people think are going to be applied. It has potential.
I think the thing that people need to understand with AI is it's not magic. So you have to have tailored correctly and modeled correctly for your environment and validated that it works correctly for your environment. That takes time. It takes resources.
It takes skills. Well, thank you, Eric. I've been speaking to Eric Decker. I'm Mary and Coba Seck-McGhee of Information Security Media Group.
Thanks for joining us.