YouSaid · the spoken record

Drew Schaefer

lines on the record
84
first
2022-10-27
most recent
2022-10-27
sittings or episodes
1
sources
podcast

Every line below is reproduced as it was said and linked to the record it came from. Nothing here is summarised or generated. Directory · Search · Corrections

  1. Been very interesting trend there as well because cyber insurance underwriters have had record payouts with all the breaches and ransomware attacks that we've seen. And as a result, the premiums are going up substantially. I mean, they've doubled, right? Over the last couple of years. And on top of that, they are really demanding. There's really no other word for it, but they require and maybe requiring. They're requiring that before they're going to sign this policy, you have to have certain security controls in place. And that's putting even more pressure on the insurers. And it's good because they're becoming more secure. But it's basically a cookie cutter approach. You have to have these things, whether they're the best things for the organization or not. And the retention is going up, right? So you're going to pay more out of pocket. If you have a claim and limitations.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  2. Yeah, I've actually, I don't think that's recently, but I actually heard somebody at one point saying, oh, yeah, we just, you know, we'll just have enough Bitcoin available to pay the ransom. I don't I don't think that's a good strategy. I don't think it's a common one. There is insurance, right? There's cyber security insurance.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  3. They're probably going to say yes to. So they're very clever like that. And I think as a market fluctuates, they'll probably just, you know, they'll probably just be thoughtful in that regard as well.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  4. Honest, it's not a trend I've looked at specifically. It's a great, great point. I don't think that the fluctuation in the crypto market is necessarily having a big impact on the attacks that we're seeing, especially in healthcare. Again, if you just kind of look at what we've seen over the last several months and even now, they're happening now. So it's very interesting because what they will do, the cyber attackers that are asking for the ransom is they spend time actually thinking about what the organization's willing to pay. And smaller organizations are going to ask for less money. Bigger organizations are going to ask for more money. They're pretty good at trying to find an amount where it's like, okay, let's pick an amount that

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  5. But that's real, right? I mean, it is one of the The things a cryptocurrency has enabled is ransomware attacks at scale. Crypto is crashed, right? It's not quite as valuable as it used to be. It might be coming back up. Do you see the pace of ransomware attacks fluctuate with the price of cryptocurrency?

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  6. So we've talked about paying the ransom several times. You can only pay the ransom because cryptocurrency exists, right? If the attackers were demanding US dollars, the attackers would get arrested more often.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  7. Very quickly, and if you're sitting around the table with a number of people and you haven't had these discussions before, that can be quite difficult, quite stressful. So that's the environment that you're going to be in. And then there's certainly plenty of cases where we've seen more on the hospital side of things. Some of the impacts that have had when organizations have not been prepared.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  8. Because a lot of times it's the insurance providers that have a SWAT team that comes in, if it's a smaller organization, if you're a larger organization, it's different. You're going to follow your plans and your procedures for this. But if you're a smaller organization, you're probably going to call your insurance provider. They're going to bring a forensics team in to support you and to assist you. But you have other questions to ask. Like what are we going to do in terms of our reporting to our patients? Do we have any third-party information that we have contractual obligations to report on? We might not know at this point if any data has been exfiltrated. And we also need, of course, to make that decision whether we pay the ransom or if we try to restore. How long will that take? And then, of course, there's business continuity. How are we going to manage and operate during this time? There's questions from the media. You're going to have questions from your employees. It goes on and on and on, right? So those decisions have to be made very

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  9. Yeah, so that's a great question. So, you know, first and foremost, you're trying to contain the attack, right? And you're trying to shut it down. There's actually a good white paper coming out where we talk about how TechLock actually went through that process of chasing an attacker out. Let's say you have the ransomware attack, right? And now the organization now is going through the process of having to deal with that. What we find, and this is a really important point, is that organizations that have done incident response exercises have playbooks that they're using to deal with those situations and have gone through those tabletop exercises are going to be much more well prepared for that attack. So what we recommend, right, is to go through that process. You're typically going to have your executives in the room and you're going to have to answer some questions, right? Like, who do we call?

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  10. Industries as well because there is so much information now that we're trusting to third parties. Unfortunately, you're relying on that vendor, right? So you're relying on that vendor to deal with the situation, but it's still the covered entity or the provider or the payer who has to deal with the reporting to OCR and has a responsibility of dealing with all the notifications out to their patients.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  11. Yeah, so Clearwater is not dealing with the attack itself, although we do have partners that we work with that can help and we can help our customers through that process. But yeah, I mean, most healthcare organizations, what they should have in place, of course, is they should have policies, procedures, and plans to deal with these types of situations. So first on the vendor side, there's a lot of shared responsibility in cybersecurity today because many organizations now are in the cloud or using third-party software and they're relying on that vendor to have security controls in place. So the hospital, the payer, even the vendor itself that has its own vendors should be conducting an assessment of their vendor's security program, right? They should understand how they're going to protect data. In the case that there is a third party breach, and that's been a huge problem in healthcare and other

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  12. What's your relationship to the vendors, right? So an attacker hits a hospital system, they lock down the system, they encrypt the data, they say, if you want this back, you want to run your hospital again, pay us the money. The hospitals are mostly running on Windows, right? Then they're running EMR software on top of Windows, right? And maybe that's from Epic or somebody else. When there's an attack, is it clear water that goes out to the vendors? Does Microsoft ever even get involved? How does that work?

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  13. And data breaches that way, but certainly once you're inside the organization and you have those credentials, there's a lot of opportunity to exploit vulnerabilities and continue to move laterally and then exfiltrate data or just tie up the organization at a ransomware attack.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  14. Well, it's not always encrypted. No. Part of the challenge. I mean, it's not, right? So the other challenge is that there, even if it is, a lot of what you're seeing with ransomware tax, a lot of those attacks start with gaining credentials of an employee. So once you get access, and that's really one of the most common ways or the most common way that these attacks start, it's through some sort of social engineering or fishing where somebody is duped into providing their credentials. And if the organization doesn't have the appropriate security controls in place, like the multi-factor authentication or other controls, then they can get into the organization. And then from there, of course, they can begin to move laterally. So, you know, one, not everything is encrypted. I mean, these days, most laptops are encrypted. It'd be less likely to see what we saw maybe five, ten years ago with stolen laptop.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  15. Impact. You can't get medical records. You can't get tests back. You have to delay procedures. You have to divert ambulances from emergency rooms. I mean, that is a severe impact to the quality of care. And they're going to continue to do that because they know they're more likely to get their money to get it very quickly. And then you add on double extortion, right? So you've got not only the ransomware attack, but now they've exfiltrated the data. So even if you refuse to pay and you say, I'm just going to restore everything from backup or do whatever I need to do to get my systems back online, you still have the threat that they're going to expose your data or sell your data. And sometimes they do it anyway, right? So, you know, it's a really very, very difficult problem, especially in healthcare when you factor in the sensitivity of the data. And of course, the delivery of care.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  16. It's still a huge problem, absolutely. I mean, there were 168 ransomware attacks against healthcare organizations in 2020, 2021. This year, we're continuing to see ransomware attacks. They're going on right now. I mean, and we don't know if this hasn't been announced as anything more than a cybersecurity or cyber incident right now, but common spirit, the second largest nonprofit hospital chain in the US is undergoing something's going on right now. You know, they shut down their IT systems. There is another ransomware attack going on in Texas, an organization called Oak Ben Medical Center. So right now, there are healthcare providers that are dealing with ransomware attacks. So it's a huge problem. Healthcare providers are the most likely organizations to actually pay the ransom, right? So the ransomware attackers know very well this is a huge...

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  17. Talk about ransomware since you brought it up. It has been a long year of ransomware attacks, of crypto-based ransomware attacks in particular. Is this still a problem? Is it as bad as it used to be? Has the industry started to figure it out?

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  18. Vulnerabilities. It's also led to more data, right? So we're protecting more information than ever before. So you have this dual effect of more vulnerabilities, more data, and now bring in the threat actors, ransomware attacks have increased 123% in 2021. You've had a doubling of cyber attacks in the past year. So imagine you're in an environment where It's becoming more and more complex to manage. There's more at stake and now you have more people coming at you faster, more well coordinated. It's just an evolving landscape and it's something that needs to be continually managed over time.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  19. Yeah, I think that's right. And if you look at some of the trends through the pandemic, we had a massive acceleration of digital adoption over the last couple of years. And that happened very, very quickly in response to a crisis. And in that case, we didn't necessarily as an industry go through all the steps that typically one would go through, even under the best of circumstances, we're probably not doing as much as should be done in healthcare. But in this case in particular, there was a very rapid adoption of these new technologies. In addition to that, the data is available now in people working from home. We have not just HIPAA, but the promoting interoperability requirements now as well where we need to share that information more openly and securely with other technology providers. The massive change in the technology landscape in healthcare has led to increased

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  20. Yeah, I just think HIPAA is one of those things, right? It accomplished a goal, which is we're going to computerize all these health records. We're going to give people access to them on their phone. We're going to make it easier to take those electronic records to your other doctor or to switch providers entirely. That's all good. We made a database and we're going to make that database secure in some way. And we're going to give you the customer access to that database. On decoder, we always talk about once you add computers to stuff, you inherit all of the problems of computers. So in my medical records were in a paper file in the basement of the hospital. Were harder for me to get to, but they were very hard for anyone else to get to. We've added computers to the chain to make it easier for me to get to them.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  21. Regulations that have also come into play over the last decade or so, state regulations around privacy, state regulations around security. We also have contractual obligations that have become, in some cases, much more stringent than even the regulations themselves. So I just want to make that distinction that while HIPAA is still very, very important and it's a big driver, it's one of the many, many things that healthcare organizations have to deal with in terms of compliance and managing their security program.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  22. Yeah, sure. So Clearwater, and just to make this note, we start in compliance. HIPAA was a big driver back in 2009 when a lot of the regulation came out with the high-tech act. We don't have to go into the weeds on that. But really at that point, what that has required, and that really hasn't changed much two big components of HIPAA, one is we wanted to make sure that that information was portable, that it could be shared, there was a big push to get hospitals and health systems to EHR or electronic health records to make our data more digital. And we also wanted to make sure that patients could access that data. That was a very big part of HIPAA and that we protected that information as well. We made sure that it was kept private and that it was kept secure. So in a nutshell, that's what HIPAA is about. In terms of clear water, while HIPAA has been a big driver of what we do, at this point, it's really cybersecurity has become the biggest driver. And there's other types of regulatory.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  23. On the dark web could be up to $1,000 a record as opposed to a social security number or a credit card record being a few dollars. You can change your credit card information. You obviously can't do that with your Social Security number. But medical information has a lot of different components to it. So you put that information together. It becomes very, very valuable.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  24. Credit card information obviously is part of that as well. So it's very, very rich and robust information that can be used to generate economic benefit from a criminal, right? So that's really the motivation. The other motivation of cyber criminals is that they want to extort money, right? Ransomware. And if they're attacking a healthcare organization and disrupting operations, that then becomes a patient safety issue for the healthcare organization. If they're attacking a digital health or health IT company that's providing technology to a provider, then they're still interrupting services. And those types of organizations might have dozens or hundreds of customers. So you're just multiplying the amount of data that they have and makes them a very interesting target. So this is very valuable data just to give you a frame of reference, electronic protected health record.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  25. Yeah, really it's any type of sensitive data, but in particular in healthcare, we think about what's called EPHI, which is electronic protected health information. That's going back to a HIPAA term. That is one of those terms. And that is really all the different type of information that you just described. It's very well defined in HIPAA has certain criteria of what defines EPHI. But that data is very valuable. It's very valuable because it's extremely rich in terms of the types of information that is included in it. So you have obviously your personal information, very often social security number. You also have medical records. You have insurance information. And criminals are buying this information on the dark web in order to obtain prescription medications that could be part of drug trade. There's insurance fraud.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  26. When you say data being valuable, is it patient data? Is it billing data? Is it here's how many people got their vaccinations last month data? What is the specific data that you're trying to protect in the healthcare system?

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  27. With a risk management plan. So yeah, pen testing part of that risk analysis, which I just described, is a part of that. And then there's other types of security activities that we'll want to do on an ongoing basis like vulnerability management and so on.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  28. Different levels of pen testing you can do. But then there's other types of things that you would do as part of your risk management program by looking at the controls themselves that are in place, looking at very specific vulnerabilities. And it's not just a attacker coming from the outside, right? It could be somebody from the inside. And that's a real big problem that we see today in healthcare is insider threats, people recognizing how valuable this information is, stealing the information, selling it. So you're thinking about risk management, you're thinking about, one, defining how you're going to do it from a governance structure where your risk threshold actually is. And then you're really putting a process in place to do this on an ongoing basis, identifying assets, assessing, controls, assessing threats and vulnerabilities and the effectiveness of those controls. And then ultimately having a determination of your risk and then managing it on an ongoing basis.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  29. from lawsuits or from environmental risks and so on and so forth. So when you're thinking about cybersecurity risk, you have to start by thinking about the assets that we have, information assets, right? These are not necessarily physical assets. It's data that's very sensitive, that's very valuable, and people want to get to it. You're also thinking about risk to your operations, your ability to continue to operate if you don't have those information systems available to you. So first thing we need to think about are what are those systems, what are those crown jewels that are really important to our business, and then we need to think about how do we assess the risks to them. So pen testing, like you mentioned, that's one of the things that you might do to test how strong your controls are, how effective your controls are, how good is the organization at closing vulnerabilities. And there's

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  30. Yeah. We're going to have a whole moment where you just explain to me what HIPAA is. It's going to be great. I'm very excited for this question to come. When you just talk about that sweep of things, every time I hear a security person say we assess the risks, I just think of that scene at the beginning of the movie Sneakers where Robert Redford's company figures out how to break into the bank and then they go and they tell the bank how to secure that. Is that where you doing pen testing? Are you out there figuring out, okay, these are the vulnerabilities in your systems. We've exploited them. We can fix them. Or is it a little more sedate? Yeah, that is definitely a part of it. You know, when we think about risk, and this is a really important point, risk management is an ongoing program, right? Any type of organization that has something at stake that it needs to protect, it's going to think about risks, right? We think about that in many domains, not just in cybersecurity. We think about it in how we protect our organization.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  31. And then we look at the specific vulnerabilities that those systems have, the threats that are applicable to those systems, and we help them understand how likely it would be for an attack to occur or a breach to occur, and how that would impact their organization. From there, we help organizations make better decisions about what they should do in order to solve those challenges or to address those specific risks. And then we help them in execution mode. So building programs to run that on an ongoing basis to manage that on an ongoing basis and doing some of the other more tactical activities that are involved in that. The other thing I'll add in healthcare in particular, compliance is a big part of the equation. So helping organizations not only to address the cybersecurity risks, but also to do the things that they need to do to comply with the various regulations that are applicable.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  32. Sure. Well, what we do to help our customers tackle the challenge of protecting their critical data, their protected data in their organizations is first and foremost help them better understand their risk. And it's a very complicated process, especially in hospitals and health systems and large provider organizations. Even in digital health companies that are implementing new technologies. So the challenge of actually protecting the organization's sensitive information and protecting the organization's operations, it's very difficult. And the first thing you really need to do to be good at that is to understand where your risks are. And to understand what type of controls they might have in place currently.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  33. Sure. Well, Clearwater is a provider of cybersecurity, privacy, and compliance solutions to healthcare and other regulated industries. We specialize in focus on healthcare in particular. We think of healthcare as an ecosystem with different practices at Clearwater specializing in hospital systems, physician practice management groups, digital health, health IT. And really what we do is we help our clients to achieve their missions by moving them to a more secure, compliant, and resilient state.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT

  34. That ransomware attackers know that hospitals are more likely to just pay up. In fact, one of the things a cryptocurrency explosion has really accomplished is making ransomware attacks easier and more lucrative for bad guys. Steve and Clearwater Compliance try to make it harder. And then there's the data in these systems. Steve told me there's so much personal information in a hospital system that a single patient record can sell for a huge premium over entire data sets from other kinds of companies. We're talking about $1,000 and up for a single patient record on the black market. There's a lot of decoder themes in this episode. First of all, where does Steve's revenue come from? How do hospitals allocate the money to pay a company that Clearwater compliance to lock it down? What kind of regulation is needed to make hospitals safer? There are insurance providers that require hospitals to have a minimum level of security or they won't be covered. That's a big deal for Clearwater compliance. And then as the threats grow.

    2022-10-27 · Decoder with Nilay Patel · Never pay the ransom — a cybersecurity CEO explains why · IDENTIFIED FROM THE TRANSCRIPT