
Authenticate This! The Cybersecurity Leadership Podcast · 2025-12-17 · 56 min
Key moments - from our scoring
Substance score
56 / 100
Five dimensions, 20 points each
Richard Henderson brings 25 years of cybersecurity experience to his role protecting Alberta Health Services - Canada's largest hospital network with 150,000 staff and 250,000 endpoints serving 5 million people. His approach combines enterprise security fundamentals with thoughtful team development. Henderson implements mandatory individual learning plans for all staff, allocating dedicated time during work hours for professional development rather than forcing late-night studying. He emphasizes governance fundamentals, understanding the OSI model for technical depth where needed, and certifications like OSCP for those pursuing advanced technical careers, while recognizing that GRC-focused professionals need different skill sets. On the personal side, Henderson practices intentional parenting - delaying screen access for his seven-year-old son until introducing a locked-down Linux system (Endless OS) focused on typing and eventually Scratch coding. He draws parallels between parenting and team management: protecting younger minds from dangerous internet corners mirrors protecting junior security staff through structured onboarding. His leadership emphasizes whole-person health, enforcing vacation usage and monitoring after-hours emails, recognizing that constant vigilance in cybersecurity creates burnout similar to combat situations. Henderson's reading habit - physical books on governance, leadership, and security - reflects his belief that security leaders must develop beyond technical skills to effectively lead people.
It depends on career trajectory: professionals pursuing OSCP certification or senior technical roles need deep packet-level and OSI knowledge, but tier-1 SOC analysts working primarily in tools and tier-2/3 escalation roles, or those moving into GRC careers, don't require that foundation. Individual learning plans should guide this based on stated goals.
Similar to parenting: introduce tools and concepts gradually with structure, ensure they understand fundamentals before independent work, and allocate protected learning time during work hours rather than expecting self-study after-hours, which leads to burnout.
Create environments resilient enough that emergencies are truly rare, enforce vacation usage, prohibit regular after-hours emails, and remind staff their legacy shouldn't be burnout - when everyone is replaceable and life continues without them, protecting family and health matters more than any job.
Focus on IT governance fundamentals, leadership theory, and people management - security leaders manage people first, not just programs or technology, so understanding how humans work and need to be led is as critical as security knowledge.
Transparency about the 'why': acknowledge the dangers (dark corners of the internet, career-ending mistakes), show how structured introduction with locked-down systems and education-focused tools (like Endless OS for kids or formal training for junior analysts) reduces harm while building skills.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains a handful of genuinely useful operational insights - the 'no one gets to say no' enablement culture, on-clock learning mandates, PAM session-elevation auto-removal, and a prevention-last security philosophy - but these are buried under extended parenting anecdotes, Primitive Technology YouTube tangents, Ray Kurzweil digressions, and survival-skills analogies that eat a significant share of runtime.
the rule I've given them is nobody in my organization gets to say no anymore
prevention to me is just one of the least important things in my stack now. Response, detection, resilience, far more important in our environment than prevention
There are a few contrarian positions worth noting - treating prevention as the least valuable layer, and explicitly rejecting the autonomous SOC narrative on talent-pipeline grounds - but much of the episode recycles standard CISO advice (MFA everywhere, get the fundamentals, don't micromanage, take vacation) and well-worn book recommendations like The Cuckoo's Egg.
prevention to me is just one of the least important things in my stack now
the AI will never be able to come up with that gut feeling that we sometimes have in cyber, especially operational cyber, that something just doesn't feel right
Richard Henderson is a legitimate operational CISO running security at genuine scale - 106 hospitals, 150,000 staff, 250,000 endpoints, 5 million patients - with a credible career arc through provincial government and large vendors; he is clearly a practitioner who has done the thing, not a circuit thought-leader, though his public profile is modest.
I'm responsible for cyber, all things cyber for 106 hospitals, about 900 other facilities, 150,000 staff, and a quarter of a million endpoints serving approximately 5 million people
we're the world's largest single instance in epic
The episode is notably specific in places - a billion-dollar Epic deployment, 12 years and roughly 12 product launches, the blood-fridge trauma-unit scenario, the Saturday-night SharePoint on-prem response - but lacks financial security-budget figures, improvement metrics, or vendor contract data that would push the score higher.
we spent close to a billion dollars on our advic install and a dozen years to get to where we are. We had like something like a dozen product launches inside of epic
of that 150,000 staff, maybe 5,000 of them are knowledge workers. The rest of them are frontline staff
The hosts allow Richard to wander into lengthy parenting narratives, survival-skills tangents, and pop-culture digressions without redirecting; there are no challenging follow-ups or pushed-back claims, and Speaker A frequently pivots to personal anecdotes rather than probing deeper; Speaker C lands one genuinely good structural challenge about whether healthcare is actually simpler, but it's the exception.
It is. It is 9 inches of copy paper that he's.
I often joke that I want to go mow lawns at a golf course
Computed from the transcript - who did the talking, and the words that came up most.
In this episode, we talk to Richard Henderson , Executive Director and Chief Information Security Officer of Alberta Health Services , about leading cybersecurity across one of the largest hospital networks in North America. Richard explains how clinical operations, digital safety and human-centered leadership converge in high-stakes environments where downtime can directly impact patient care. He also shares how his background across public and private sectors informs his approach to team development, why he prioritizes continuous learning and rest, and how his perspective as a parent shapes his views on safe technology exposure and foundational digital skills. Key Takeaways: 00:00 Introduction. 07:13 Limiting screen time improves children's reading abilities. 13:19 Mandatory learning plans prevent burnout and enable growth. 22:30 Setting boundaries and reducing false urgency helps prevent burnout in security teams. 27:53 Saying yes enables business success and collaboration. 32:21 MFA and single sign-on form baseline security. 37:19 Architectural safeguards protect legacy medical devices with minimal risk tolerance.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Welcome to Authenticate this, the cybersecurity leadership podcast for CISOs and identity leaders. Navigating the complex world of identity. From real life breaches to internal missteps and everything in between, we bring you authentic stories, hard earned lessons and actionable insights to help you lead with confidence when chaos strikes. Our goal is to humanize identity, uncover actionable solutions and explore the business of identity beyond the spreadsheet. This is Authenticate this, where identity meets leadership. Welcome to Authenticate this. We have a very special guest, Richard Henderson, with AHS Alberta Health Services as the ciso. And we've got a lot to talk about today. We have a full lineup of topics and ideas. But before we dig in, I want to highlight some of the personal and professional things from Richard that really stood out. So first and foremost I see that you're a proud public servant. We're going to dig in on that, talk about some of the public service that you do. I also see that you listed dad as one of the very first adjectives about who you are and what you do. And so I want to dig in, Richard, on how you parent as a CISO and if there's any differentiators there and maybe some of the thought processes there as a father. I would really, really love to hear that. And then finally we're going to dig into some of your personal and professional history because as you mentioned in some of these prep calls, our, uh, personal and our professional lives are highly, highly intertwined and sometimes they're, they're intermingled to the point where we need to address both from a business and a personal standpoint. So let's take it real quickly on your proud public service. What are you doing? What are you doing in the public space there?
Speaker B: Uh, Richard, first, thanks for having me. So I'm Richard. I'm the chief information security officer for Alberta Health Services and HS is one of the largest hospital networks in the world. I'm responsible for cyber, all things cyber for 106 hospitals, about 900 other facilities, 150,000 staff, and a quarter of a million endpoints serving approximately 5 million people. When I took the job about 16 months ago, I really didn't know what I was walking into from a scope and scale, I'm not sure I would have if I taken that M course and being facetious because I was bullying. This is a destination career piece for me and I'm so proud to be able to sit in this chair. But so I run cybersecurity for one of the largest hospital networks in North America, the largest in Canada, responsible for protecting the second largest public sector environment in Canada and the fifth largest network in the country. So we are not small by any stretch of the imagination. I come to AHS from the Government of British Columbia where I ran security and privacy operations for the Ministry of Citizen Services, which is the tech ministry. Previous to that I did some senior strategic consulting, number of agencies and ministries in the government of Canada. But previous to that I spent a good decade in cyber in the private sector, primarily for a number of large cybersecurity vendors. And then previous to that, like many cybersecurity pros of my vintage, I've got the gray hairs to show the vintage now. I started in the server room, in the network room, desktop support, network support, polling cables, racking servers and so moved into cyber like many people back then. And so I've been doing this for, for almost a quarter of a century and ah, boy do I feel it sometimes.
Speaker A: Yeah, I bet, I bet. Let's talk about you as a father, right? That was your personal career. We don't need to get in a lot of details about, you know, your children, but because it's listed so highly on, you know, on your public profile, clearly it's important to you as a ciso.
Speaker B: Do you think you parent your children
Speaker A: differently or do you coach and train your children differently than you would if
Speaker B: you weren't a security professional? Yes, 100%. So there's a lot to talk about there and I'll try and be brief because I know we've done lots to talk about, but I'm the proud dad of a seven year old son. He just turned seven and he is the absolute greatest thing to ever happen in my life. As much as I say that I love being a CISO and I'm so lucky to be an enterprise CISO protecting literally millions of people. Being a dad, nothing pales in comparison to anything else. To answer your question about how I parent as a ciso, as someone who's been connected to the Internet since the mid-90s, I've seen the evolution of the Internet over the last 30 plus years and how it's changed for both the good and for the bad. And I've seen how easy it is for kids and young men and women to, to find themselves in dark corners of the Internet and get themselves in trouble, whether they, whether personal trouble or seeing things they shouldn't, or behaving in ways they shouldn't, or breaking into things they couldn't. Because I will tell you, when I was A teenager. It was a whole different world when you broke into something, right? Like, you know, shoulder surf, a, um, teacher's password in high school and got kicked out of a class because I got caught logging into the admin system, right? Like you go to jail for that kind of stuff now, right? Like you don't just get kicked out of a class. And so it's really easy for kids today to find themselves in the types of trouble where it can have lifelong consequences. And so when it comes to my son, only recently at the age of seven, did I finally relent and get him his first computer. My son has not no access to screens, very little access to screens, no Internet access at all. I just don't allow it because it's too dangerous for a young mind who is just like developing to be tainted by the types of things that you and I take for granted as people have been on the Internet for early decades. And so buying a computer for my son has been a very interesting exercise. I put a dedicated Linux install that's made specifically for education and for kids called Endless os. It took a lot of research to figure out how we were going to do this. We built the computer together. Obviously he watched me build it, but he asked questions through, well, quality. It's not connected to the Internet, it's totally locked down. And the only thing he gets access to right now is like basic educational software, for example, like I'm a big stickler for teaching him how to type. And so like every morning I'm like, you want to use your computer, go do your 20 minutes of typing lessons first. Because once you learn how to type, then we're going to learn how to code, you're going to learn Scratch, and then maybe you'll learn Python and then maybe we'll move you into C and I don't know where we're going to go. But he's really excited to do it and because he hasn't been force fed a diet, nonstop screens for the first, you know, five or six years of his life. It's novel and it's new to him. So, so if you're thinking about having kids, first of all, I'll say to your listeners, don't wait because a lot of people, I, uh, mean, this was me too. It's not, not the right time. I don't have enough money. I just, it's never going to be the right time. It'll never be the right time. Have a kid. If it's something you're interested in, it's one of the most rewarding things you will ever do. Watching this young child grow mentally and physically and having, having a part in that. And as a csaw, maybe I'm a bit of a Luddite and maybe that's just because I know how bad it could get. Right? And there are a lot of parents out there, we've all seen them who park their kids in front of a screen 24:7. That's not healthy for them and it's not healthy for their brain development. And so I take that responsibility really, really seriously to ensure that I'm setting up my kid to be as successful as possible when he becomes an adult. And I say that to my son all the time. I'm like, look, you know, I'm here to teach you how to be an adult, not here to teach you anything else. And so you may think some of the things I choose and some of the things I do are, I don't say punitive, but certainly like difficult. And so there's a rationale behind it. And to be honest, my seven year old son who just finished first grade is reading at a sixth grade level in the first grade. And that's because we read to him every single day since he was born. Didn't park him in front of a screen. And so I've been very deliberate in some of my parenting choices, much to the chagrin of some of my peers.
Speaker A: Yeah, no, I absolutely love to hear this. And I'm feeling a little bit of dad guilt because I jokingly said I was the best parent ever until I had kids. And then you realize the, the, the screen thing, right? You're sitting in a restaurant, you're, you're a four year old starting to scream in a restaurant and you give them your phone so they can watch a little video. And, and I, I see that. Right. But I love what you said, that there's harm that can be done. You consider yourself a Luddite with technology as a ciso, right? You're, you're at the cutting edge of technology, but you're not allowing your, your, your children to, to, to receive until they grow up. We could flip that on the professional side too, right? We've got a lot of new employees right out of, right out of college. Or maybe they're not tech savvy coming in and it's like we've got to
Speaker B: protect them in the same way.
Speaker A: It's almost like it's like you don't even get access yet until, until you're learning and then finally m on the scratch Thing. My little boy is also into coding. He's, he's a few years older than yours, but that's one of those applications. If I'm going to put my kid on an iPad and he's learning how to code, like, I actually don't feel guilt when he's doing that because he's learning a skill and he's learning a, uh, strategy and he's learning and creating with the technology tool. But just like you said, there's a lot of danger and there's a lot of positivity.
Speaker B: Right.
Speaker A: Scratch happens to be one of the very positive things for children to learn and to grow and. But it's easily accessible to anything else on the Internet, so that's really good.
Speaker B: Just be present in your kids, your kid's life. And there are far too many people who are so preoccupied with their own digital lives that they forget that we've had decades to be ready for this. Right? And we, we fail at it just as much as anything. So how can we expect children to, to be successful when we have a hard enough time being successful managing our digital lives ourselves was really cool.
Speaker C: You, uh, just thought as you were going through like how you've got your kiddo to get, uh, to the point to start using screens that you said first thing was building it all out and then also showing them how to install an operating system them. So I think one of the dangers is with evolution of, of technology and the Internet, there's a really cool future where we don't have to do basic stuff, but without an appreciation of the basic stuff, what happens when we do need to learn it. So I think in some of our prep calls we talked about like the uh, history of like needing to know like Cobalt or uh, you talked about a bunch of different teaching the different types of languages out there for coding. And so that's something I'd be interested to see more about is do you do that in your own professional career with your teams? Do you want them to know some of the basics so they can better understand what it takes to do the big picture items too?
Speaker B: That's a wonderful question. Right, Because I spend a lot of time thinking about this. And I will tell you quite honestly, my opinion has shifted back and forth more than once over the past. I've been in security 15 years over the past 15 years. And you know, there are plenty, again, I'll use the word vintage security professionals of my vintage who believe that you can't truly be a security professional unless you spend a whole bunch of Time in the trenches, doing the basic stuff that we did, becoming security professionals. But I'm not sure that's true anymore. Right. Security has become far more tool driven than it used to be, far more commodified, far more easy for people to get started in. And do you really need to know all the layers of the OSI model anymore? Do you really need to know how to punch down a Cat 5 key? Because I still do it and I do it because I do it in the house. Right. I run, um, my own cable and stuff like that. But, but am I becoming anachronistic perhaps? So it's been great for me to challenge my own thoughts on this, right? Do I need my tier 1 SoC analyst to know all of that stuff anymore? No, probably not. They're spending a lot of time working in tools, churning through tickets, escalating things up the chain to the tier 2 and tier 3 people or to external people who are supporting us. Would I like them to have that base level of knowledge? Yes, absolutely. But I'm, um, no longer, when I look at candidates, I'm no longer just making that one of the key things I look for because the security industry has evolved quite a bit in the last 20 years. And so is it needed? I would say it depends on how deep you want to go. If you become the type of security professional who really wants to move down, then I use OSCP as an example of a certification that requires a substantial level of technical depth and understanding to be able to accomplish that certification. If you want to move down that path towards wherever you're in your more senior security roles become, you still need that depth of understanding. You need to understand the life of the packet. You need to understand how things work at its most basic level. But if you want to move towards a GRC type career and stuff, you don't need that level of knowledge. You need other types of knowledge. And so when it comes to my people, what I've done here at HS is I've made it absolutely clear to all of my teams that individual learning and taking time for individual learning is essential and mandatory in my group. And so what I happen to do when I first got here is I made every single employee give me an individual learning plan. What do you want to accomplish in the next 12 months? What do you want to learn? How are you going to learn it? What sort of support do you need from me from a time perspective and a financial perspective, backing to be able to accomplish those goals? And I let all of my people dictate to me, what they were interested in and what they wanted to learn more about. Not just to help them with their role today, but to help them move into different roles inside the organization. And it's been relatively successful. Certainly some of them have struggled with that. But it's also important to remind, um, your staff, as a ciso, yes, we're all overworked. We've all got too much work to do. We're working too many hours. And that's always going to be the case, right? It doesn't make a difference. There's always more work. There's always not enough time. And so you have to, as a leader, say to your staff, look, I'm going to allow you. Maybe that's the wrong word, but I'm going to ensure that, uh, you are given four hours a week, three hours a week, five hours a week, whatever it may be, to allow you to spend time on your personal learning. And so I want you to do that on the clock. I don't want you going home and studying four or five hours for a certification exam when you finish your job. That's a hell of a quick way to burn people out, right? Uh, you have to have the downtime. So most of my people have been very good at ensuring they're allocating time during their week to spend time learning. I mean, I have to do it myself, right? There's my reading for the week, right? And so there's probably four or five hours of reading. Those who are listening only.
Speaker C: It is. It is 9 inches of copy paper that he's.
Speaker B: He's holding it. I swear I'm keeping the pulp and paper industry in Alberta going just myself, right? But I use that. But listen, there's a method to that madness, right? And that's disconnecting from everything, turning off the screens and going to sit in that little armchair over there in the corner of my office and just reading, right? And it trains different parts of your brain, right? And so it's important to take that time to learn. It doesn't matter how junior or senior you are. In our business, things are evolving every single day. If you're not dedicating and allocating time to learning, go drive a truck instead. Right? Like, I mean, some days I do feel like, as an enterprise C. So that maybe I want to pack it all in and go drive a truck instead. But there's nothing said, my dad drove a truck his whole career. Like, I mean, I know how hard he worked, but if you're not willing to exercise your brain every single day in this field, you're going to fall behind almost instantly.
Speaker A: I often joke that I want to go mow lawns at a golf course. And the reason, the reason I joke about that is because you could put a full day of work in and turn around and you get to see your efforts immediately, right? And if you're driving a truck, you can look down and say, I put in these many miles, right? So as a security leader, as a leader of people getting those validating points of, you can see your efforts. What are those for you? Right? Because you're reading. I'm assuming most of this reading is security related, but I'm assuming some of it probably isn't. There's a purpose, personal development that may be completely different and not, you know, involved with security, but it's something that could help you in your role.
Speaker B: I just look at a stack of books that I have over in this corner. Some of them are, you know, not just security related. Because I'll tell you, if you're interested in security leadership or you're a, you know, budding security leader, there are lots of other things you do as a cso, as a security leader that are not security related. For example, you better get really strong on governance, right? You can't do anything in an enterprise without a strong sense of fundamentals of governance. So reading more about IT governance and how that works, that's really important how to be a better leader. We forget, as, uh, security and IT people, that we're leading people, right? We're not just leading programs and we're not just leading technology. We're leading peoples. And those people deserve to be led by people who understand their unique needs, they understand how they work as people. They understand, uh, everybody has challenges. And so one of the things I remind my people here is that I refuse to let people bank a substantial amount of accrued vacation. Take your vacation, right? You need to have time away. And it's funny, I was talking, I was at a conference in Ottawa actually just a few days ago, and I was speaking to another CISO there. I love listening to this guy talk. He runs a group of casinos in Canada. And so talk about like a different type of security job, right? He's dealing with money and people who were looking to rob them all the time. And one of the things he reminded me was that he was, he's a reservist in the army, and I was a reservist once upon a time too. And so he does cyber in the army as well. One of the things he reminded me of is the fact that cyber people, one of the reasons we're so burnt out is because unlike soldiers who go into combat, fight for a couple hours and then have time to like, like not fight, we're fighting all day long. We come in, we fight, we defend, we defend and then we go home and we do it all over the very next day. We're just defending, defending, defending all day long and we don't have these moments downtime to be able to mentally recover from the non stop fight that you're in. And yes, is it the same as, as putting on a uniform or shooting a rifle? No, of course not. Uh, uh, but, but, but uh, there are parallels there, right? Like your mind is in this heightened sense of awareness and, and just go, go, go, go, go and deflect and defend. And so that can have some serious long term burnout repercussions to staff. And that's one of the reasons we see so much burnout in our industry. And so it's important for me to rem. You gotta just take the time that you're given to take time off. And it's not just that I remind my people, you know, I get people, I don't practice what I preach there either, right? Because I go home and I'll read for hours or I'll work for a couple more hours and, and my kid goes to bed, I'll just do more security stuff. But I love it, right? It doesn't feel like a job. So that's one of the reasons to do it. But like I remind my people, like, look, you know, I'll get the odd person who'll send me an email at 8pm or 9pm and I remind them that I never want to see an email from them after hours because I have to remind them like, you know, we forget everybody's replaceable. One day you're not going to be here, you're going to be forgotten about pretty quick, right? Because everybody else, life goes on, their work goes on, the job needs to get done, the things need to be done and you're going to get forgotten. And so are you going to want to uh, leave a legacy where you burned yourself out and you neglected your family, you neglected your friends and you neglected your personal health. That's what you're going to have left when you leave. Right? And so if you don't take care of those parts of your role in cyber, taking care of your family and your friends and your personnel, you're going to be a pretty bad place when you get out of cyber, whether you go to a new job or you get out of cyber or you retire, right? And so it's important to think big picture, whole circle, whole health. When it comes to cyber, you have a responsibility not just to your job, but you have a responsibility to your family and responsibility to yourself. Contribute the best person you can be. And so I drive that home with my people a lot. Uh, I will call people out anytime I see an email after hours and I will tell you that like there's only been a few situations in the first 16 months I've been here where I've had to like call someone after hours, seek something really emergent or something bad has happened. And we've built an environment that allows us to be resilient enough where we can typically it can wait till the next day. It's only been a couple times where we called someone late at night and said, hey, I need you to get online and take a look at this.
Speaker C: But that's the difference is I feel like a lot of people probably feel seen in that moment in what you're saying, because if you build a work environment where they can trust that you want them to go away, they can also trust that you will call when you do need them.
Speaker B: Well, the one senior analyst I called, one of my tier three SOC people, it was Saturday night, 10pm And I know we might have, we were probably going to talk about this later, but the SharePoint on prem vulnerability that popped up a few weeks ago, being a massive on prem healthcare environment, we have a number of that. And I called him at 10 o' clock at night and he answered like within three ranks. And I said, hey listen, you know, I'm sorry to bother you on Saturday night, this is bad. And I need you to jump on and check and see if any of our on premise service has been compromised. He's like, look, I'm not home but I'll be home in 20 minutes and I will call you as soon as I sit down at my desk. And he called me right back 20 minutes later he's like, look, you've never had to do this. So clearly I knew it was important. And when you remind yourself of this when everything's urgent, nothing is urgent. When everything is an emergency, nothing is an emergency. And so they build a culture inside your organization where everything's emergencies when you really need them on an emergency, sometimes they're not going to be there.
Speaker C: Right.
Speaker B: And my team was there that time, right. That security analyst called two other security senior security people and they worked nonstop for two days to get us through this incident. And of course, I stayed up with them the whole time. They called me every two hours, give me an update on how things were going. But it just. To your point, they knew it was important and so they put in the hours. And, um, I'm, uh, eternally grateful. And I'll tell you, by Monday morning, when the CEO called and said, hey, I just saw this thing in the news about SharePoint. We okay? Like, well, we weren't okay, but we're okay now. We took care of it already. We worked all weekend to fix it. And it's a pretty great feeling when you've built an environment that is capable of dealing with these things quick when you need to. And by the time it hits the news, you're already gone to bed.
Speaker C: That's actually pretty cool, too, that a CEO reaches out to talk to you about it too. That sort of culture starts top to bottom.
Speaker B: The executive leadership group here, who has had some substantial changes over the years, but they trust me enough to manage the security of the environment. And I don't want to say it took a long time to build that trust, but it took a lot of relationship building to let them understand that they have somebody who cares about it as much as they do. And they leave me to my own devices 99 times out of the heart. I mean, I'm in the public service. It's a little bit different than the private sector. And I've certainly spent a lot of time in both, so I can speak to both. But, like, I am, um, responsible legislatively in Alberta for the security of this environment, the security of our patients data and security of our staff's data, the security integrity and the availability of all of the things that touch the healthcare system in this province. And so the law stops with me. If something were to happen, I'm legislatively accountable. And so that's a pretty big responsibility. And so I make it clear both up and down that I hold that responsibility really close. And I'm sure I'm going to burn out before I know I'm holding that so close. But Charles Barkley said it best for all the 90s people here. Like, somebody's got to be me, so it might as well be me.
Speaker C: I love it. I love it.
Speaker A: What's really interesting is you're held to a very high level of accountability and your first order of action is to take care of your people, right? Like, that is not a common thing. Because if others were held to such a high level of accountability. They would want the right tools and processes have put in place, which of course are your concerns. But it sounds like people are first and because of that you've taken care of all of the rest.
Speaker B: People have to be first though, right? Like, like leaders who don't get that aren't going to be particularly successful. And I certainly, you know, as someone who spent a number of years in Silicon Valley and saw how Silicon Valley does things and it's go, go, go chew people up to get things done. That is not going to be successful long term. At least if it's going to be successful. You have to build an attrition program that, that is able to bring people in, in a regular cadence to be able to replace those people that you've chewed up and spit out. And that works certainly for some, but it's not gonna work in healthcare and it's, it's not particularly successful in operational cybersecurity. I can't do this by myself. And we're certainly not in a world where while some vendors would love to convince you otherwise that the AI is going to be able to take over cybersecurity, I think the promises of the autonomous SOC are overstated and not anytime soon. And I have some other challenges with it too. Around the cannibalization of your talent pool and the long term funnels that you're throwing out the window when it comes to building and curating talent inside your organization, when it comes to taking care of your people. I am the strategic leader for cybersecurity. I'm no longer a tactical leader, right? Certainly I'm tactically involved when I need to be, but it is no longer my job to be tactically involved. The day to day operations of cybersecurity in this organization. And you have to remember that as a C cell, right, you have directors and you have managers and you have individual contributors whose job it is to execute your direction and execute your strategy. And so don't micromanage your people, get out of their way, trust them enough to do their job. And it's funny, you just, just planted a, something um, in my head. Like when I got here, when I got here I gave my people a couple standing orders. It's around allowing them to be somewhat autonomous in how they do their work. And that's basically there are a couple rules that I have. Number ah, one is I never want to be surprised by anything. So if there's something you think I need to know about, I don't care how junior you are, you make Sure, I know about it, right? Because if someone from up top comes and asks me about something and I'm not aware of it, there's nothing that bothers me more than being caught flat footed, right? And not having at least a high level answer on something so pretty, they've done a pretty good job on that. But more importantly is I've enabled them to be able to say yes. What I mean by that is the rule I've given them is nobody in my organization gets to say no anymore. And what I mean by that is that if somebody comes to them with a request or an action or a need or a desire or a want, they don't get to say no anymore. Unless it's something so egregiously stupid that of course you're going to say no. Right? That's different. And what I mean by that is if they know what they need to do to get to yes, then they don't need to involve me in that decision because I trust them enough to go do it right. They know my thought process, they know how I feel, they know what my philosophy is. And if they just go get it done, then they can go get it done. And it builds much deeper collaborative relationships across the enterprise with other technology groups, not just technology groups like with frontline clinical staff who are used to cyber being. No, you can't do that. No, you can't do that. No, we're not going to let you do that. No, you can't have this product. That's not a great way to build an enterprise cybersecurity program. You are here as a cybersecurity program to enable the business to do their business right, and so figure out ways to get it done. And so ultimately the rule was if you feel a no decision must be made for something that needs to percolate up to my level so that I can understand the reason for the no and that I can communicate to my executive partners the reason for the no. And it's never a no, it's a, uh, no. But if you were to do a, B and C, we can change that no to a yes. And so it's helped me be very successful inside my organization by being seen as a cybersecurity leader who wants to help them get things done. And without the business, there's no need for security. I feel like I should print that out and put it on my wall sometime just to remind myself, without business, there's no need for security. So stop getting in the way of business getting done.
Speaker A: I love that. And Your current business specifically is health care. I would love to talk and, uh, talk about some of the unique challenges that you have within the health care space around, obviously all cybersecurity, but specifically within our domain of identity.
Speaker B: Yeah, my job is easy and difficult at the same time. From an identity perspective, it's relatively easy to protect our users because the vast majority of our users, like I said, we have 150,000 staff. Of that 150,000 staff, maybe 5,000 of them are knowledge workers. The rest of them are frontline staff, nurses, doctors, custodians, orderlies, you know, reception, things like that. All the core functions you would see in healthcare facilities whose technological needs are much different than you and I, right? And so your typical doctor or nurse working in a clinic or in a hospital are spending 98% of their day in email or in their clinical information system. In our case, it's epic. And by the way, we're the world's largest single instance in epic. So that's a whole other challenge on top of itself. My friends at HCA like to say they're the biggest in the world, but they have multiple instances, so they're the biggest. But if you add it all up, we're the biggest single instance of epic. So they spend most of their time working in tools, right? And so they don't need excessive access to things, they need access to the systems they need to do their job. And so it becomes very easy for me to secure those users because I don't have to worry about a thousand developers all wanting their own unique device running their own unique set of, of tools that they've used for the last 15 years of their career. And so it becomes relatively simple to secure those users. Now, that being said, there are a hundred thousand of them, right? And so there are a hundred thousand little points of attack that I have to defend against, right? I've got millions of emails a day that come into our environment, any one of those to be malicious, right? And so we mitigate a lot of the risks in our environment through some of the exceptionally tight basic hygiene controls, right? And so I remind listeners and viewers that like, stop trying to chase the big shiny stuff. Make sure you got the fundamentals down pat before you worry about it, because it's going to get knock out 90% of the stuff you need to worry about. So, for example, mfa, everywhere in our environment is a baseline, no mfa, no go, right? Internal and external, single sign on is huge in our environment, certainly, you know, as an environment as large as we are, we Certainly have plenty of legacy and systems that can't integrate with our single sign on. But we have other authentication and identification protocols to support them. But anything new that's procured in the environment must support our single sign of environment. So it makes it not just makes it simpler for us to defend, makes it simpler for our users to use. So everybody wins that way. Other, other basic controls that we do in our environment that probably don't work in a more traditional digital enterprise. Nobody has local admin on their machines in our environment.
Speaker C: Nobody.
Speaker B: There's no need for it. We have separate privileged account systems. If you need to elevate your privileges to do certain things part of your job, you log into our PAM system and you check out a secur password that expires after settlement time. And then you have a separate account that belongs to the domain admin group that uses that password. And then you go in, you do what you need to do, you're out, and it removes the access. And we're actually upgrading that too. We're moving from secure passwords to secure password or secure sessions where you'll log into the pams environment and you'll get an approval and it will elevate your account into the domain admin group or whatever elevated privilege you need, whether it be domain admin or whatever, and it will then automatically remove you from that AG group or entry group when you're done doing what you need to do. And so we're trying to make it simpler for our users to have elevated access when they need it and make it foolproof so that you don't forget to remove yourself from those special privileged groups when you're done. Because that's been a problem forever, right? Like you'll put yourself in a domain admin group and I just harbor domain, but you've been playing with active directory for 30 years now. You'll drop yourself or you'll have someone drop you into a domain group and then heaven forbid they forget to remove you from it. And all of a sudden you've got this bigger attack surface of privileged accounts than our attacker can go after. And then it's the keys to the kingdom, right? So you get your privileged access down and that between that NSA allow listing applications in our environment and again, same thing, the majority of our users don't need Spotify on their desktop and they don't need Dropbox on their desktop and they don't need all these other things that you would see in a more traditional digital enterprise. We are very, very tight on uh, restricting Access to applications in our environment because we have to be right. The risk tolerance in our environment is so high. I say this to people a lot that it is not hyperbole for me to say if we get it wrong, someone's life is at risk. Right. Because in a modern healthcare environment, one hospital or 100 hospitals, everything is relying on a digital system. Now, yes, a doctor can still stitch someone up if the power goes out and the systems go down, or can still use a scalpel and set a cast and things like that. But, for example, one of the things I like to do here is go tour our hospitals. I try and do it a couple times a year. Just go see how nurses and doctors especially are interfacing with technology in our environment. What do they like about it? M. I'll just randomly stop some random person in the hallway and ask them just a question. They're happy to share their feedback. Right. And I had one person take me for a tour of one of our local regional trauma units. And so, thankfully, there were no trauma cases in the KA at the time I was in there. So it was empty, and everything's idle and ready to go. And in this trauma center, there are four beds. And those four beds have these two giant semicircles of cabinets and equipment surrounding the bed. Because when someone comes in on a helicopter missing his arms, the doctors and nurses need literally everything within their arm's reach to be able to keep this person alive long enough to keep them stable, to help them, you know, get through this. And so there are a substantial number of digital products or tools that are in arm's reach. So one of them, for example, is there's a little fridge. Looks like a little bar fridge, but it's full of blood. And to get into that fridge, you don't just turn a key or open the door and pull out two units of opositive and give it to the person. They're prox card control. Right. Because everything has to be accounted for. And so to get into that fridge, you swipe your card and it unlocks it, and then you take units of blood out. Well, we had a catastrophic ransomware outage in our environment, and it took down those systems, or heaven, um, forbid even one system went down, and that happened to be the blood fridge. And I have a SOC analyst who has a playbook that says, thou shalt remediate that system when you detect malware doesn't work in our environment that way. Right. Because what happens in the one time out of a thousand, that machine got infected with something. And the SOC analyst just sees it as a machine on their screen. They don't have the context to understand that's a fridge full of blood that's serving the trauma unit. And then that SOC analyst decides to take that machine down to reboot it and remediate it. And that's the moment someone comes in with no arms. What do you think's going to happen? Right? They ain't waiting for that fridge to reboot itself. They're going to the fire cabinet and getting an ax. They're going to chop through that door to get through it. Right. And so that's kind of like the level of risk tolerance we have in our environment. And because we have that little tolerance for risk, we have no choice but to have exceptionally tight controls in our environment to protect against those risks. It's not to say it doesn't happen. We certainly have, you know, a handful of malware incidents a month, um, in our environment is much smaller than you would see in a traditional digital enterprise just because things are locked down tight. Now I've just cursed myself by saying that, right? But I'm very lucky to have an environment with such low tolerance for risk, which makes it easy for me to explain to the non technical people why we have to do things the way we do it. And I often use other healthcare systems who have had catastrophic incidents in their environment to remind them just of, uh, you know, the stakes we're playing with. I don't sleep very much, to be honest with you, thinking about this stuff.
Speaker C: This is interesting because one of the things you said earlier and all that was that you're not an enterprise. You've got a hundred thousand people who are frontline, so it's easier for you to manage. I would argue every healthcare client that I've dealt with, most of them all in um, the United States, feel that they are the hardest. And I would often agree with them because, you know, they grow through mergers, acquisitions. They've got six instances of Epic. They all operate in different ways and they have 600 different devices that have software installed on different XP machines and everything like that too, because you've got older technologies running some of these devices too. So what I'm trying to figure out is, is it in some ways in your mind easier because it's one giant instant epic. But that means you, um, have also, as an organization have had to, certainly you've had to simplify things or at least hyper focus on what matters in order to tolerate the right kind of risk. Is that what you're doing. Like how do you think that differs from what I'm seeing at like clients and hospital clients in the U.S. so
Speaker B: there's a whole bunch to talk about there. Right. And so uh, being a single payer system in Canada, like in the UK as opposed to the US there's not the same types of operational incentives that you would see inside a US health care system. Right. We certainly have more than our share of legacy systems and environments that for one reason or another we can't decommission. Some cases the vendor doesn't exist anymore. In some cases it's a frontline diagnostic device that's been used for 15 years, 20 years and until it dies it's not being replaced. And so architecturally we protect the rest of the environment from those legacy devices to ensure that if something were to happen, the possibility or likelihood of splash or actor being able to move from there to big juicy middle is limited. We certainly have also lots of detective controls watching for that. But again, basic hygiene stuff. So for example, the very small number of Windows XP things we have in our environment, we're no different than anybody else. We certainly have some, not a lot, way less than you would think. But uh, those devices, and we just did this in the past year and it took a lot of winning of hearts and minds. None, uh, of those devices now have any way to get to the Internet. None of them have any browsers installed on them anymore, none of them have any email installed anymore. So it's not to say that like, you know, they're not vulnerable to the eternal blue type exploits that are out there that are inherent in those devices that you're never going to go away because it's XP or Windows 7. Right. But we've minimized the possibility of something connecting to that device and taking advantage of its inherent vulnerable state. So it's not perfect, but it's the best we can do. And so to come back to your, your, your, your question about how like, you know, many US healthcare systems would do this. So there's a little bit of historical context there. So AHS was born about 15 years ago or so. The government of Alberta at the time had decided to amalgamate all the regional health authorities in Alberta into Warren. And so in Canada there are every city or regional area will have its own little healthcare system and they're managed their own way by their own group of people with their own technology stack, whatever they think makes the most sense for them. They decided to amalgamate all that into one statewide system in our borough. So we've had 15 years to figure it out. So for example, our EPIC installation, my understanding is we spent close to a billion dollars on our advic install and a dozen years to get to where we are. We had like something like a dozen product launches inside of epic, slowly and deliberately moving towards an end state that we had identified. And so from a cyber perspective, you have to mirror that model, right? You have to. One of the first things I did when I got here is unspent, um, a couple months doing a very deep, both qualitative and quantitative assessment of the security maturity of the organization in every discipline of cyber. And so I found a banner printer vendor and printed out this eight foot tall mind map of all the things that an enterprise CISO should be responsible. And so I sit here at my desk and I stare at once in a while I'll uh, just pick one redditor thing and I'll say how are we dealing with this? Or are we dealing with this? Or am I responsible for this? Or am I accountable for this? Or is this relevant in my organization? And so if you're interested in that, go Google CISO mind map. And there's a gentleman and I can't remember his name so I, uh, you'll have to forgive me, but he has a fence. Every year he publishes a new seesaw mind map of all the things seesaw should be thinking about. And so go download a PDF of it and take a good look uh, at it, go back and think about things that were relevant 10 years ago or 15 years ago. Think how much this discipline has grown over the past decade or so. And so to go back to my point, after I did that deep dive quantitative assessment of the maturities of the organization, it allowed me to identify some, I don't say fundamental, but some, some areas of improvement that needed to happen. And so I use that to build my five year strategic roadmap. Here's where I think we need to focus more things on. And I use Gartner for some of this too. And Gartner some fantastic tools if you're a garter shop for assessing quantitatively how you are from a security perspective, not just for healthcare, but for any like industry. And they rate you against your peers and so how are you doing against your peers? And boards love to hear that. When you talk to boards, they want to know how are we doing against our competition? How are we doing against our peers? Are we better than them? Are we worse than them? Are we better than them? M over here, are we Worse than them over here. And so that allowed me to get really tactical on where I wanted to focus some, um, of my budget requests. And it's allowed me to build a very, very tactically focused strategic plan to get to an end state that we need to get to in cyber. So now, of course, you know, all the things like AI and stuff, throw a giant wrench in all of it. And so I've had to go back and reevaluate my strategic direct four times in the past year. But again, you gotta be, you gotta be on your toes now. It's not like I go off topic again. I go on tangents all the time, so listeners will just have to ride it out with me. But like, I think about either. You guys ever read the Singularity is Near by Ray Kurzweil?
Speaker A: Okay.
Speaker B: Well, basically, uh, the tiniest of nutshells, it's that the pace of technological change is accelerated so quickly that soon we're going to reach this hockey stick moment where everything will change exponentially. And we're already starting to see it, right? Think about how fast AI has developed in the last five years, right? And it's getting faster and faster and faster. And I go back to when we were kids. When I was a kid, I had the same 24 inch console TV in the corner of our living room for like 20 years. You go to Costco now you can buy 100 inch LCD TV for a thousand bucks. People are buying new TVs every year. That's how fast the market is changing. And we're seeing that in technology as well. Not just like consumer goods or consumer electronics. We're seeing it in goods. And so you better be prepared for that to be able to be fast enough to respond to things as they pop up. Uh, because I will tell you, like, you know, you see lots of vendors talking about, well, attackers are using AI for everything. Now, I'm not quite sure we're there yet, but we're getting awfully close. And so you better start thinking about that kind of stuff. Now. How am I going to deal with, with a world where attackers can spin up AI based attack bots or whatever the hell you want to call them and launch attacks within minutes of a CVE becoming public? Because I think we're really close to that kind of stuff happening. So you better start thinking about how you're going to re architect your security stack to be able to be more resilient to those types of attacks as opposed to just preventing them, because you're not going to be Able to prevent them. Right. Prevention as a, as a core fundamental. In my opinion anyways. I know people will argue this to me to death. But like prevention to me is just one of the least important things in my stack now. Response, detection, resilience, far more important in our environment than prevention because I can't prevent it all. And you put all your eggs in a prevention basket. You're asking to get burned. That was a whole bunch of tangents right there. So sorry.
Speaker C: Well, but they all tie back to something I think you talked about at the very beginning. We talked about like a second ago. You talk about the, the hockey stick of technology and how do you, how do you prepare for that as things change? It starts with what you do with your kid. It starts with teaching them the basics so that they can understand and focus. HM. On the right things. And then the second question after that we talked about, is it important for you to do that with, with your staff and with your staff. I mean you said you, you go back and forth. And I think the key reason for that is, is what is the end goal? If I'm looking to do home improvement, I do not need to know. I need to know how to use a drill. I need to use a uh, level, all that kind of stuff. And I no longer need to know how to tie special knots for connecting sticks together. I don't know, I don't even make my own clay. But that is a part of the origins of home improvement. But I do need to know that still today if I want to be a survivalist, I want to be, I still need to know those basic things. Those basic things still exist. And so when we talk about when you train your people, as part of that, I need to make sure people prioritize and, and know how to learn for themselves. I love that you talked about giving them their own responsibility of time management and financial as part of their, their day lives. Because if we don't we start to miss other things in the future. Like this hockey stick of change that you're bringing up and we don't do the right things that are in that probably in your mind map I can imagine if not they'll be there is to make a CISO's job easier. I first need to understand how other things work. So epic. As an example in the U.S. i've got, I've got clients who've got six epic instances. If I as a CISO, I'm um, not a CSO, never have been. But like as a security leader, if I can help My business. Back to you talking about earlier about the business and business operations, if I can help my business scale down to one epic instance now, my security footprint's much smaller and it's something that operationally I can simplify. And so that allows me then to understand other areas and utilize new technologies to do that. The TV you mentioned, 100 inches. I mean, I. The compute power, the LCD screen that you've got to have for that. Like, there are so many different technologies wrapped up into that one TV that had to happen at one moment for it to connect. Like, we could have made. We can make a 200 inch LCD screen, but there's more to it than just that size to still make it at an affordable price. And so I like, I mean, you say tangents, but I think they're all connected, man. I think it's. It's really cool to think about that idea for us to hockey stick. We've got to connect the stuff and we've got to be ready to learn along the way.
Speaker B: So there's a couple of things there that, like, you made me think of, right? And so I've thought about this for a long time around just. You ever hear the term standing on the shoulders of giants, right? Like, it's. It's not just a crappy Oasis album, right? It's like it's a real thing, right? Like, to your point, if the power went out in the world, say we had that massive solar flare event that they've been talking about that aren't they all talked about 30 years ago, right? And like, say we had the type of thing, we lost electricity for a month. How many people could truly survive, right? How many people really know how to grow their own food, how to, like, make their own bread, how to do all these basic things, grind their own flour from wheat, right? Like, I live In Alberta, there's 10 million acres of wheat five minutes from here, right? So I could go harvest some wheat myself. But do I know how to grind? No, of course not, right? And so, like, I'm worried about us losing that fundamental set of knowledge. And, uh, the parallel to cyber is like, sometimes we need to have that fundamental knowledge on how some of this other stuff works. And I make a point of just understanding how everything works and at its lowest level. And so you mentioned, like, you know, turning clay into a pot type thing. And so There's a fantastic YouTube channel and I want everybody to go watch. The guy's called. It's called Primitive Technologies, okay? He's got like a million followers and this dude is, he's in Australia, he lives in the outback and he makes pots from dirt and he makes like bricks from dirt and he makes, he finds in a creek bed, he finds like iron loving bacteria and he can like smelt it down into like pills of iron. And so like, you want to see like just how far we've come as a society, go watch what this guy is able to do with just his hands and like, with vines and like rocks that he uses into the eyes. It's, it blows me away. And I, I'm, I'm always worried about us forgetting those fundamentals. And there's a parallel there to cyber, right?
Speaker C: I think so. And I think if we keep the fundamentals, if you still understand how to, how to learn and you've got access to the knowledge. So like I have a little survival book that we keep just in case, just for that reason, like it's just access to the knowledge. I've got the skills to do it. And I would argue that it's humanity holistically may have gotten smarter but, but the individual humans, we still have the same brain we've had for a long time. It's not that we just have more tools to use. And so, and that's the specialty of humans all, ah, to begin with, right, is the ability to use tools. And so if we leverage those tools as we grow and those tools expand and we can play safely with those tools, I think we'll be well prepared, at least many of us, if we're teaching people how to use tools, not just memorization, not just going to the thing that shortcuts everything, I think we can be successful. And then the same thing applies inside of our cyber world.
Speaker B: Well, funny you say that because I think about AI and the implications of the AI around that. Right Again. Another thing someone said to me the other day made me pause to think about this, is that the AI might be able to replace some of us some of the time, but the AI will never be able to come up with that gut feeling that we sometimes have in cyber, especially operational cyber, that something just doesn't feel right. This doesn't look right to me. I can't put a finger on it, I can't tell you why, but there's something wrong here and I got to figure out what it is. And the AI will never be able to do that. And so I want to build a culture inside my organization, security, operations perspective where I encourage my people to trust their gut to say, look, I'm going to pull on this thread for a little while and see where it goes. Maybe it's going to go nowhere, but it just, something's off. And so there have been plenty of cases in the world where humans gut reaction, reaction has led to them figuring something out. Incredible. Or you go back and you look at like, read stories about how like spies were caught up or how like, for example, go back and read the Cuckoo's Egg. Have you ever read the Cuckoo's Egg? What a fantastic book that is. And so for some of the younger listeners and viewers, go read the Cuckoo's Egg. It's such an amazing book to read. It's like at uh, the very start of like cyber security, computer security. And this guy at Clifford stole the billing system, was off by like a couple cents. And this was back when it was mainframes and timesharing computers and things like that. And it just bugged him. Something didn't seem right. He pulled on these threads and he found like, I think it was a Soviet hacker who. Anyways, go read the book. It's worth reading. But like, don't downplay the ability for us as people to see patterns that computers can't see or just get a, get a feeling that we're on to something like that.
Speaker C: It sounds like that book is based as what Office Space is based off of just stealing a little bit of
Speaker B: sense at a time that the Superman 2 movie.
Speaker C: Yeah, well, I learned, I learned a ton today, Richard. Mostly about, I mean, you talked about trusting your gut. I really like the uh, learning how to learn simplifying concepts along the way. But one of the things I was most excited from the get go of this was ownership. You clearly are very motivated by what you do and see value and then you've transferred that value to your people. I mean, you said five times on this call, not that my job is to do a cil and I stop these breaches. My job is to protect the 5 million people that I'm responsible for. And you said that, you said I'm responsible for these people. And I can see, I can imagine your team sees that and feels that today. And you're responsible for those team members. You want them to make sure they get the right rest. So if they get the right rest at somebody else's shift, they're not responsible for it. And so when they're, they're there, they're there for those 5 million people, well rested and ready to work. So I'm sure our, uh, listeners learned a ton too. But those are a couple things I learned. And Richard, thank you so much for coming to hang out with us. I hope to talk to you again soon.
Speaker B: Yeah, well, thanks for having me. It was an absolute pleasure. Nice to see you guys.
Speaker A: M thank you for joining us in this episode of Authenticate this, the cybersecurity leadership podcast. Check out the show notes for links and resources mentioned in today's shows. If you enjoyed the show, please leave us a five star review and be sure to subscribe so you don't miss on any future episodes.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.