YouSaid · the spoken record
Drew Schaefer
- lines on the record
- 84
- first
- 2022-10-27
- most recent
- 2022-10-27
- sittings or episodes
- 1
- sources
- podcast
Every line below is reproduced as it was said and linked to the record it came from. Nothing here is summarised or generated. Directory · Search · Corrections
“Realize the value and the synergy of those transactions like any other private equity firm at some point, we all know that they're going to do something to exit the business. And what that is right now, I don't know, and we're not even thinking there. We've got so much ahead of us right now in terms of growth opportunity. So our full focus is really on that right now”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“The investment thesis around TechLock. TechLock is also bringing some additional compliance capabilities that we don't have, which are important. So it's a really very strategic acquisition for us with Synergistek. A lot of the motivation there was about gaining scale, increasing our customer base, and having complementary solutions that we can provide to our customers, ideally packaged into managed services, which we think will provide more value to them, and making us a stronger partner, giving us a more robust management team, the resources we're getting in terms of the consulting team. It's really not easy to hire talent and cybersecurity today. I think we've done a good job of it and retaining folks, but we need people. And we're a people business. So we got great people as a result of that. We're pretty early. And since that's happened, we've got a lot of work to do to fully.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“No timeline. I think the real important point here is that our investors have a lot of conviction about the market growth and about Clearwater. And I think we're really excited by that and appreciate that very much. In terms of the acquisitions to us, they were very strategic, right? So one driver for us, important driver in terms of our strategy where we want to go with the company was to position ourselves in the MSSP space, in particular in security operations, right? The 24-7 eyes on glass that we didn't have at Clearwater. And we see that as a really important market. It fits our strategic principles. It's a growing market. It adds value for our customers. It's a place we think we can be competitive, but developing in our own would be really challenging to do. So that was the...”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Mentioned PE companies, they tend to move fast and try to flip the company, you have a PE backer. You've just bought two companies, right? That's a roll-up just like the PE companies are doing with doctors. Are you on a timeline to going public or exiting or selling yourself?”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“decisions in the organization, we communicate our strategic priorities to our entire organization. So our top first most important priority is always quality and customer success. That's the message that I daily am giving to the entire organization. But in addition to that, we have priorities around our business plan, our business growth. And the purpose of doing that is to ensure that everybody in the organization understands what's most important. And when they're thinking about decisions, because we do want to empower our colleagues to be able to make decisions, we want them to be thinking about our strategic priorities. Where does it fit in the priority scheme and how do we make choices? Because we're not a huge organization, as we just discussed. We have limited resources. We need to make sure that we're doing things in a way that align to our strategy and that are according to our priorities in the organization.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“To continue to grow. We think a lot about value for our customers. How does it create value? Is it going to solve a pain point? Is it going to make our customers better? And then again, how differentiated is that? Culture is a big part of our strategic principles, what we're doing benefits our colleagues at Clearwater. That's a really important part of how we make decisions. And then, of course, we've got financial goals and objectives like every other company. So we start with those strategic principles more from an organization perspective and how we try to make”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, so that's a good question. So, a couple of ways. First, we have a Clearwater, well-defined strategic principles. So we've aligned on a strategy. We've put some very strong statements around that strategy and what we're trying to achieve. And when we're going out to make decisions about where we play and how do we play there, we want to make sure, number one, that it fits our strategic principles. So, for example, we're focusing a lot on healthcare, right? So is it something that we're doing that's going to be value to healthcare? Is it going to help us to grow in a market that we've identified as a growing market, right? If we're going to a new market, is it growing? And then very importantly, can we be competitive? That's a really important strategic principle. We don't just want to be able to do something, but we want to be able to do something better in a market that's going to be...”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“And then last decoder question you also run a company that has PE investment. You've been growing. You're merging with other companies. You're buying other companies. You've got this market that's growing. How do you make decisions?”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“To do is grow the business like most private equity firms at some point they want to sell the business, right? And if I have a ransomware attack or a breach, that's really going to make it difficult for me to do that. So do I want to do that myself or do I want to go out and get somebody who's really, really good at that? And that's what private equity firms do in professional management teams do is they go out and they figure out how do I have the best operations I can, right? Operational efficiency and quality. That message has resonated really well. And for those types of organizations, we do, again, a lot of times go with our Clear Advantage program, which has all these components. There's different levels of the program depending on where they want to get to and how quickly they want to get there. And then there's a fixed fee that we established for them. And as they grow, if they get to be larger, then there's some increase in that fee. It's not a linear increase, but something that's very reasonable. So, yeah, but it's a predictable model. They know that there.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, no, it's a good question. So it's very similar. We do. It depends on the contract with the customers. Most of the physician practice management groups we're working with. It's not your single doctor practice. So what we've seen more from a trend perspective is private equity has really been investing a lot in rolling up these groups under MSO or managed service organization models. And they're bringing in professional management teams. They're going out. They're acquiring different practice locations. They usually have some sort of strategy, whether it's a technology platform or reimbursement model or a specific focus on how they're delivering the care. But it's a company that's really very business focused and they're growing really quickly. So what their concerns are is, hey, my business is growing really fast. How am I going to protect it? And while I continue to grow. Because what I really want to do is...”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“So let's say I run a small physician group and I'm like, man, I don't want to hire a head of security. I install all these computers and that was a mistake. I should have done this all on paper, but whatever. I hire you to do it. Am I just paying you a fee like I would pay for every month for janitorial services? Does a price go up and down? Is that predictable for you?”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Map to whatever it is that they need to achieve. Customer requirements HIPAA or other regulations, and of course their own risk tolerance. So that's a big part of our business. We also have a software program called IRM Pro, which is a risk management tool that's in compliance management tool that's really geared for healthcare organizations. And that's something that we sell for a subscription fee, your typical SAS model. And then thirdly, we do have consulting services, which are more project-based. They also tend to be fixed fee, I'd say, nine times out of 10 that's preferred.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Day to day, and there's been so much transition in security, especially within healthcare that it's hard to get that consistent program going. So we take that program, we outsource it, it's a fixed monthly fee, and then they can bolt on additional services that we can add and incorporate that. The other type of managed services program that we have is our Clear Advantage program, and that's targeted really more to the physician practice management and digital health companies and other mid-market organizations that need a more mature and robust cybersecurity and compliance program, but they just don't have the people to do that or really the knowledge of what they need to do, let alone the resources to do it. So we again outsource that, we'll take on the role of chief information security officer for the organization, which is a seasoned executive that has both technical and business experience. And then we'll actually implement and execute their program for them on an ongoing basis.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“All the above. Most of really where our customers are moving to or managed services. And it's maybe something more healthcare specific, but I think having that predictable cost for whatever it is that they're getting is very attractive. And so what we're offering today, really a couple of programs that are, again, aligned to market segment and the managed services bucket in the hospital and health system space, we offer a program called Clear Confidence. Clear confidence is really rooted in that risk management program, which I described before, and it's moving hospitals and health systems from point in time assessment of their risk in response to those assessments to an ongoing risk management program. So they're really outsourcing that to Clearwater, which is helping them address some of the challenges that they have around staffing, resources, expertise. They're just so busy dealing with.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Chime organization, which is the College of Health Information Management Executives, which are basically all the CIOs of hospitals. So they're part of Chime. We're a sponsor of Chime. We work very closely with that organization. So it's a little bit more of a targeted approach, but still trying to get in front of the right people that are making the decisions.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“We've worked with our customers who have had investigations or corrective action plans with the Office for Civil Rights, which is the Enforcement Arm of HHS Health and Human Services, which enforces compliance with HIPAA. We've helped our customers in four dozen cases. We've had a 100% success rate with having our risk analysis accepted by OCR. So we've got some very important benefits, I feel, that we can offer our customers and those people that are working in the industry appreciate that, right? We're speaking their language and we can offer something that's a little bit more differentiated and more unique. So we're still trying to get our name out there, not as broadly as being in the airports, but we do it through other places that executives are traveling, like, for example,”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Absolutely. I mean, there's a lot of, you know, there's a lot of competition in this space. It's a huge market. It's growing in healthcare, I think, 16% CAGR per year. So it's a very attractive market even within healthcare. Healthcare is very nuanced. And people that work within healthcare, they really feel strong. Most of them will feel very strongly about that. How we've differentiated ourselves in the marketplace for a long time has been with our understanding of the healthcare industry, people that have worked in environments that have healthcare technologies that understand the regulations like”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Thought leadership. So it's not the same type of strategy where you're going out there and you're just saying, hey, Clearwater, we're a leader in this space. We're trying to establish our leadership by providing valuable content and people will make that connection on their own from what they're seeing and what they're reading.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Our marketing budget yet has not yet allowed for Super Bowl ads, but we're working our way to that. Yeah, our marketing approach has very much been thought leadership-based. And if you kind of go back into the history of Clearwater and Synergistec for that matter as well, both of those organizations founders really established the company initially by learning a lot about the subject matters that are helping their customers with and then going out and talking about and teaching people. And there's a lot of education in our industry that's needed because things are happening so quickly. They're changing so quickly it's very difficult for our customers to keep up with all that. So what we do at the core of our marketing program is produce a lot of thought leadership, webinars, white papers, educational programs, and then we share that freely with the market. When we go out and we do advertising, so to speak, we're buying those digital ads, it's all about leading people back to that.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“You have a marketing function. Are you the one buying the ads in the airport and on Thursday night football? Because, right, that's like all those are always tailored at like CIOs. That you? Does that work”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“And our delivery organization is to have people that are really, really good at understanding the business of a digital health company versus an ambulatory organization versus a hospital. And we found that allows us to be more valuable to our customers and more competitive in the marketplace. So even within our services organization, which is the largest part of our team, we have different practice areas for those different verticals. And then we also have different types of practices, which are not really as vertical specific. So things like technical testing services, privacy around HIPAA, that tends to be something that you don't necessarily have as many nuances, still some nuances, but not as many nuances as you move from one industry to the other. So our services organization, sales organization, they're organized that way because it helps us to be better solution providers. And then we have a marketing division, which is, again, integrated, and then your typical.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“From a good market perspective, maybe a good place to start there, how are we really organized? So all the companies have been fairly similarly organized. We have a consulting services division that's providing solutions, Clearwater and TechLock both also have software development groups. So we have leaders. We have a leader for software development. We have a leader for consulting services. Sales, we've got a very specific go-to-market strategy in how we approach our sales and also our delivery for that matter. We focus a lot on different market segments, in particular within healthcare. So a hospital system is different than a digital health company, much more complex at a hospital in terms of the organization, the technologies, just how they're structured. And then their overall maturity. So that's just an example. So the way we've aligned our sales organization.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, so for now, we're spending a lot of time learning and getting to a really good understanding of what each of these organizations are doing. And we are certainly planning to bring everybody together as one organization, but do that in a way that doesn't destroy any value for our customers. So we know there's a lot of good solutions, good experience, great people in all these companies. And we're working through aligning the services portfolio, the technologies that we have. There's a lot there, again, which is really exciting. But ultimately, it will be one organization serving our customers. TechLock has been fairly well integrated into the organization already pretty quickly. And then we're working now very diligently on doing the same with Synergist Echo.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Was reading a press releases of those acquisitions. Both of them say, We're going to run these as independent divisions of the company. How are you structured? How are you thinking about the company structure over time?”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“We just did a couple of acquisitions this summer, which grew the company quite a bit. So we're over 200 workforce members today. And the two that we did, we acquired a managed service security provider called TechLock, which provides managed detection response services, security operations, and doing things like endpoint detection and log management. We also acquired or really merged with a company called Synergistek, which is another healthcare-focused cybersecurity and compliance provider that we've respected for a long time. We've competed against, and now we're joining forces to Really come together to be a stronger partner for our customers. So growing quickly, but certainly still not extremely large organization, but definitely feeling very excited about the new capabilities that we have as we're growing here.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, absolutely. And that's exactly where it's going to go. I think patients and employees for that matter too, right? We all need to be taking control or being responsible for how we're protecting data. And for Decoder listeners as well, I mean, thinking about your own security of your own personal data that you have at home. I mean, that's something we all need to be very aware of. Security awareness, again, is the number one thing that really leads to avoiding phishing attacks, which again is the most common way that bad actors are getting or successful with a ransomware attack.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“So that's not good, right? Things like that, if that happens, then you probably might want to question their security program. But I think you really want to make sure that you're going to organizations that are demonstrating that they're protecting information, that you can look around and see if screens are left up or it's going to be hard to probably identify whether the medical device has been patched. I'm sure if you ask your nurse, she's probably not going to know the answer to that question or just going to say, of course. But, you know, I think.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Oh, that's a good question. I mean, I've yet to hear of patients in hospitals asking about the security program in the hospital. I think you want to go work with providers that are demonstrating that they're protecting your data well. So if you're a consumer, things you can look for without even having to ask questions would be just the way that the professionals that you're working with are interacting with the data that they have. I remember one time I was getting my eyes checked and there must have been somebody that was subbing in to do the exam. And she didn't have the password to the machine. And she shouted down the hallway asking for the password and they shouted it back down. And that kind of concerned me.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“I mean, those are very, very serious concerns if a cyber attacker gains access to that and is able to control that. So I think that for the industry, that's a big challenge. And it's one that, you know, as an industry, we're going to have to find better ways to address it. There's been a lot of technology that's come out over the last several years, but the healthcare organizations are having a real hard time using that technology, making sense of the data and doing stuff with it because, again, they just don't have the people to do it.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“The organization. We didn't talk too much about medical device security, but that's a really concerning topic for security professionals and clinical professionals in the healthcare space. The FBI just released a bulletin last month identifying increased number of vulnerabilities posed by unpatched medical devices that are running outdated software. And they found that as of January of 22, over 50% of the connected medical devices were other internet of things and hospitals had critical vulnerabilities. I mean, that's just a staggering number. And that's a real safety risk. And, you know, we're very early days there from an industry perspective in ensuring that we're addressing those vulnerabilities and that we're monitoring those devices. And we're talking about things like insulin pumps or mobile cardiac to pacemakers, pain.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, well, I think next for Clearwater, we touched on that before. A lot of wood to chop here on integration and getting to a point where we're really seeing value for our customers. I think we're seeing that already, but we've got a really clear vision on being a leader in healthcare cybersecurity. I think we've got all the pieces now. And the next step is to put them into programs for our customers that create a lot of value for them and give them a lot for what they're paying. So we're really focused on that. I think the managed security, you know, managed detection threat detection and response is a really big part of where we're going with the company now. And then combining these technologies and these assessments and other things that we're doing for our customers into a single pane of glass. I mean, that's ultimately where we want to get to so that they have a single view of what's going on.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Have to think of all that, of course. I mean, we have to think about all the threats, all the vulnerabilities that we think are relevant, in particular for the healthcare market. Yeah, absolutely. I mean, again, that's another great point that you're bringing up is just threat intelligence and having that incorporated into how you're thinking about risk also from a monitoring perspective, right? You're looking at different techniques, different indicators of compromise that may occur that you need to have good understanding of those. And then from a technology perspective, more from a monitoring in the technology that we use, having good technology that helps to identify those things and orchestrate it and automate that so that it goes to an analyst to investigate. So yeah, absolutely.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Think all the way up to the sort of state actor level like oh boy the NSO group in Pegasus can target zero click attacks at doctors with their iPhones we have to factor that into the risk profile of the hospital”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“No, I mean, we have to think about other operating systems as well. I mean, Windows is going to be a common one, of course, but Mac, I mean, as well, mobile devices, we have to think about those operating systems as well. And of course, we're now dealing in cloud technology. So we've got to be good at understanding AWS, Azure, Google, and so on. So all those things are require, again, a lot of expertise. It's every day keeping up with what's happening and going on. And I think, again, speaks to why it's important to have a partner or an advisor that's doing that, right? Because you want to be able to make your decisions on what's best for the business, not on, well, if this is, you know, if I've got multiple technologies in here, I have to learn how to protect all of them individually. That is an important consideration. But ideally, you have the capability.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, I mean, look, I think it's always great to have competition in the market. There's a flip side to that as well when you have multiple technologies, then you have to learn how to protect those different technologies as well. But that is a great point, right? From an attack surface perspective, the attackers are only learning, having to learn one technology. I think you could probably argue that either way.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Feels like in the background of all this, I've mentioned it several times is Windows, right? Like all of these companies run on Windows. And I know Microsoft does a good job. Would it help if there were more operating systems in the mix or more EMR software providers? Or it just seems like you've got these huge attack surfaces at huge companies. So you've got like a shrinking number of giant companies running the same software. And if you are a Russian ransomware operator, you can just focus your effort as opposed to saying, all right, we got to go figure out iOS too or Linux or something else.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“And the budgets are much bigger. The IT budgets are much bigger to begin with. So it's a bigger percentage of a bigger number. And small hospitals, it doesn't amount to a lot of money. So coming together certainly creates some efficiency or some scale, let's say, in trying to address that challenge. Again, we're trying to advise our clients that when they're doing these integrations, that they need to be thinking a lot about governance and how they set up their policies and procedures in a way that ensures that the organization is operating within the framework that they've established and the risk tolerance they've established, but also giving them some flexibility at the individual hospital level to do the right things on the ground. And, you know, we call that our principled-based governance policy and procedure framework, and it's really helpful in those types of situations.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Right. Well, whether it's for me or from somebody else, they should be doing it. But yeah, the point there really, again, is that smaller organizations are going to have a harder and harder time dealing with this. And their data is still valuable. Whether you're a critical access hospital, which is a 25 bed or less hospital, where you're a large integrated delivery network with dozens of hospitals, clinical locations, ambulatory, you name it. You still have very valuable data and there's some amount of money that you're going to be willing to pay. Now the small hospitals, small providers, most of them don't have a security officer. They probably have an IT person who's got some security responsibilities. They don't have, you know, you think about how much are they spending healthcare spending between five and seven percent of their IT budget on security as opposed to the financial industries or spending 10% or more.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“In the long term, it's helping. I think in the short term, there's a little bit of disruption, right? I mean, you have organizations coming together on different systems and you're going through a process to integrate those technologies. And as you start integrating technologies, again, you're opening up the organization for even more vulnerabilities. Again, how do you address that? You should be doing risk analysis before we implement the technology, right? You should do risk analysis. You should buy my product.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Of the things that has come up in this conversation a lot is a theme is consolidation and the pressures in the healthcare industry. There is a lot of consolidation in the healthcare industry, right? The big hospital groups are rolling up. The physician groups are rolling up. Your company is rolling up. Is that helping or hurting, right? Is it, okay, now that there's only like three big hospital chains in America, they're going to have all of the resources and they're going to be able to repel attackers or there's three big hospital chains in America. They're a little bloated and slow. We're going to go after them and they're going to be rich hard.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Different healthcare providers and other organizations, other companies have experienced that. So they've seen it happen. They've seen the cost. They've seen the devastation. It's moved from that could happen. I get it. But I have all these other things that are happening right now that I need to deal with to, oh, wow, that is happening. And, you know, 89% of the organization surveyed from the Panaman Institute had a cyber attack targeted them last year, right? So almost every organization's being being attacked. So it is happening. And that is why we're seeing more investment in cybersecurity. But there's a long way to go. And it's just not going to happen overnight. It would take a lot of time, a lot of effort, a lot of resources. Again, that's where we're, you know, we think we're helping our customers quite a bit in providing them with those capabilities that they don't have and doing it in a way through a managed service that allows them to get a lot more for their money. That's really what we're trying to do.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Of course. Yeah. And that's changing, right? It's changing. But if you think about, again, healthcare, the healthcare industry has a lot of challenges, right? They've had very rapid adoption of technology where they've underinvested in cybersecurity. Not great, but that's what happened. And reimbursements are getting more and more challenging for a lot of hospitals, health systems. They have major challenges in staffing. Costs are going up with inflation. There's a lot of pressure to spend money in a lot of different places. So when they're thinking about risk holistically across the organization, cybersecurity, the risk of a breach, the risk of a ransomware attack is one of many, many risks that they're dealing with. What is happening, what has happened is that risk has become greater and it's become more impactful to the organization.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“I mean, I think in this day and age, I think every CEO certainly understands the importance of cybersecurity. I just can't imagine to be in that position and not be aware of that. And I think every CEO.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Feel like if we go to the CEO of a bank and say, Hey, we need to invest in security, they will at least understand that there's money in the bank and investing in security keeps the bad guys away from the money. Do you go to the sea of a hospital and say, hey, you need to invest in security for whatever cloud-based system that is expressed on Lenovo laptops throughout the hospital? They're like, why? Right? Like, is that the issue there that they just don't see the connection between oh, we're going to end up paying a lot of money or is that changing now over time?”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Viable to continue to attack your company or your organization, right? Go attack somebody else or eventually be great if they all go out of business. I don't think that's going to happen. But we're trying to get our clients to a point of maturity that makes it, again, very, very difficult for them to have those events occur.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“So there's a reason for that everybody's making money in doing it. So, yeah, certainly if our clients, not just our clients, but if the industry was better at protecting their organizations, kind of like what you've seen in the financial industry, right? It's a very mature industry when it comes to cybersecurity. You don't hear about a lot of ransomware attacks in financial institutions. It's uncommon because there's been investment in controls because there's ongoing risk management. And does it mean that the banks are not being attacked? Of course not. I mean, they're still trying to go after that industry, I'm sure, where they see weaknesses, but were they really focusing a lot of their time and effort on it? It's health care, it's education. It's, you know, those industries that have underinvested. So, you know, the end game here is to get to a point where it's not economic.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, I mean, I think our incentive is to help our customers be secure. And, you know, in terms of making it more difficult, I think for an attacker to be successful, to me, that's really what our endgame is, right? We want to make it more and more challenging for a third party to be able to successfully attack. Because at the end of the day, this is about economics, to your point. that's been established, ransomware as a service, there's affiliates, it's almost like franchise locations for ransomware.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Well, unless the FBI has changed its position on that, I believe they will tell you not to pay. The FBI is involved or should be involved. So one of the things that we recommend to our clients is that they establish a relationship with their local FBI office. And the FBI does get involved, especially again in cases of hospitals, health care providers, right? It's a critical infrastructure industry. One of those first calls should be to the FBI. And they will assist and they will certainly investigate. And they are trying to do things to stop this, right? I mean, there is law enforcement out there. It's just very difficult because a lot of these attacks are coming from Russia and from other parts of the world where our law enforcement is not really able to operate.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“FBI has said this, I've heard them say it over and over again. If you pay the ransom, they know you're going to pay. So, you know, you're... Going to come back at some point and try again. So it's a very tough decision and sometimes there is no other option, right? You've got to negotiate something because you just don't have a good alternative, but you want to make it as difficult as possible for those situations to occur. You want to have a good business impact analysis in place that you understand what the impact is going to be to different business processes if it were to occur and then you want to design your disaster recovery and your business continuity plan and then test that plan and then test your incident response. If you do all those things you're going to reduce the impact of a breach or of a ransomware attack.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT
“Are going down, and then again, costs are going up, right? So the average cost of a breach being in healthcare over the last two years has gone from $7 million to $10 million, according to the Potomac Institute. So if you think about it's costing more, your insurance is harder to get, it's more expensive, and it's covering less. That's a real challenge. And the answer to that is it goes back to risk analysis and risk management. I mean, you really have to do a very rigorous, thoughtful assessment and analysis of the risks in your organization. And then you have to make a business decision on where you want to spend money. Because just, you know, saying it's going to happen and I'll have some Bitcoin over here, it's almost 100% if you pay the ransom, they're going to come back again.”
2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT