The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Cybersecurity at ViVE Podcast
Cybersecurity at ViVE Podcast artwork

Why Healthcare Organizations Are Losing the Cyber War (and How to Fight Back)

Cybersecurity at ViVE Podcast · 2026-03-18 · 25 min

0:00--:--

Key moments - from our scoring

Substance score

46 / 100

Five dimensions, 20 points each

Insight Density10 / 20
Originality7 / 20
Guest Caliber13 / 20
Specificity & Evidence10 / 20
Conversational Craft6 / 20

Gary Salman draws on 30 years in health tech and experience as a law enforcement captain to explain the systemic vulnerabilities plaguing healthcare cybersecurity. Healthcare organizations lose the cyber war because they invest heavily in reactive tools like CrowdStrike and Sentinel One while remaining blind to their actual attack surface - missing patches, misconfigured firewalls, and unmanaged third-party risks. Salman advocates for Continuous Threat Exposure Management (CTEM), a framework pushing organizations toward constant visibility into external (internet-facing), internal (devices and people), and third-party vulnerabilities rather than reactive quarterly scans. He emphasizes that approximately 90% of healthcare organizations hit with ransomware end up paying because they have no recovery path, and smaller practices are equally targeted despite myths to the contrary. Salman's key insight: executive leadership must own cyber risk through data-driven cyber risk ratings rather than outsourcing oversight to IT departments. Most attacks are preventable through proper configuration, patch management, and awareness training - but prevention requires knowing where risk actually exists.

Key takeaways

  • →About 90% of healthcare organizations hit by ransomware pay the ransom because they have no alternative path to recovery without it.
  • →Smaller healthcare practices face the same ransomware threat as large systems because attackers view them as easier targets with insurance policies they can exploit for quick payouts.
  • →Known exploitable vulnerabilities (KEVs) are the primary vector threat actors use to gain access and move laterally through networks, yet most healthcare organizations scan for them only monthly or quarterly, leaving them dangerously behind.
  • →Continuous Threat Exposure Management (CTEM) replaces point-in-time quarterly assessments with near real-time scanning of external attack surface (firewalls), internal attack surface (patches, software updates), and risk reprioritization as threats emerge.
  • →Executive leadership must demand independent cyber risk ratings and ask hard questions about where risk exists rather than trusting IT departments' claims of security without third-party validation.

In this episode

  1. 1Gary Salman's Background: Bridging Healthcare Tech, Cybersecurity, and Law Enforcement
  2. 2The Ransomware Crisis in Healthcare: Why Organizations Pay the Ransom
  3. 3Common Blind Spots: Lack of Visibility and Known Exploitable Vulnerabilities
  4. 4CTEM Framework: Continuous Threat Exposure Management for Risk Prioritization
  5. 5Why Smaller Healthcare Organizations Are Not Safe from Cyber Attacks
  6. 6Executive Accountability and Data-Driven Cyber Risk Ratings
  7. 7Real-Time Continuous Monitoring vs. Point-in-Time Assessments

Mentioned

Black Talon SecurityGary SalmanSandy VanceCrowdStrikeSentinel 1CiscoCISAFBIHomeland Security

Guests

Gary Salman

Topics in this episode

CrowdStrikeSentinel Oneransomware incident responseContinuous Threat Exposure Management (CTEM)Known Exploitable Vulnerabilities (KEVs)Black Talon SecurityCyber Risk RatingHealthcare EHR/EMR systemsEmail phishing and spear phishingAI-driven malware generation

Questions this episode answers

Why do 90% of healthcare organizations that get hit by ransomware end up paying the ransom?

Because ransomware encrypts their EHR, EMR, and imaging systems with no technical path to recovery without paying. They have no choice - patient care stops without access to these systems.

Are small healthcare practices really targeted by ransomware attackers or just large hospital systems?

Small practices are frequently targeted. Attackers view them as easier to break into with less time investment, and they often have million-dollar insurance policies that cover ransom payments, making them profitable targets despite their size.

What is Continuous Threat Exposure Management (CTEM) and how does it differ from traditional security scanning?

CTEM continuously scans external attack surfaces (firewalls, internet-facing assets), internal surfaces (patches, vulnerabilities), and third-party risks in near real-time, automatically reprioritizing risks as new exploit information emerges. Traditional scanning happens monthly or quarterly, leaving organizations days or weeks behind emerging threats.

How can healthcare leaders without technical expertise evaluate their cybersecurity risk?

Ask your IT department or MSP to provide a quantified cyber risk rating showing specific risk by location or facility on a 1-100 scale. If they can't produce this data, you have no visibility into risk and should bring in an independent third party to validate actual security posture.

What are the most common vulnerabilities healthcare organizations fail to address that attackers exploit?

Known exploitable vulnerabilities (KEVs) - missing patches and outdated software - are the primary vector. Threat actors scan networks for these and exploit them to gain initial access or move laterally until they reach patient data, financial records, or HR systems.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

10 / 20

The episode surfaces a few genuinely useful practitioner concepts - CTEM, KEV prioritisation, and the 90% ransom-payment rate - but they are surrounded by substantial filler: career backstory, law enforcement analogies, and generic 'get involved, ask hard questions' advice. The ratio of novel signal to padding is moderate at best.

about 90% of the healthcare orgs that we work with have to pay the ransom. There is no choice.
there's kind of this new concept that we've been pushing for about a year now called ctem, which is a continuous threat exposure management

Originality

7 / 20

The core arguments - patch management matters, executives must own cyber risk, don't trust your IT vendor to grade their own homework - are widely circulated in the industry. CTEM is repackaged Gartner terminology. The framing is competent but not contrarian or first-principles.

you can't have the fox guarding a hen house
cyber is kind of like a robbery or a burglary, right? Someone's going into something you own, like your house or your medical space, and stealing your stuff

Guest Caliber

13 / 20

Gary Salman is a genuine practitioner - CEO of a real managed-security firm covering 65,000 devices, doing live incident response for insurers and law firms, with hands-on forensics experience. He is not a pure thought-leader, but he also never names a client, cites a published case, or references third-party data, which limits how much of that credibility translates into the episode.

we get hired by insurance carriers and law firms to unfortunately help medical groups and dental groups that have been victimized by these attacks
Black Talon monitors and secures approximately 65,000 devices worldwide

Specificity & Evidence

10 / 20

There are some concrete data points - 90% ransom payment rate, 65,000 devices, a 1-to-100 risk rating scale, $1M insurance policy example, named tools like CrowdStrike and Sentinel One - but the 90% figure is asserted without sourcing, no named clients or breach cases appear, and most examples stay hypothetical ('five locations,' 'a plastic surgeon').

if it takes them a couple hours to break into a small organ, they have a million dollar policy and the policy OPTS to pay $1 million in ransom payments
on a scale of 1 to 100, 10 is really low. It's good. A hundred is a disaster

Conversational Craft

6 / 20

The host asks broad, open-ended topic-transition questions and defaults to affirmation rather than challenge - never pressing on the unsourced 90% claim, never asking how CTEM differs from existing Gartner frameworks, and closing with 'I love this so much.' The one natural follow-up ('Do you think they usually end up paying?') is the exception, not the rule.

I love this so much. Thank you for sharing your time with me today and these thoughts.
And the data is driving everything now.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A86%
  • Speaker B14%

Most-used words

risk32healthcare22cyber21security16data15organizations15cybersecurity11back10network10real8technology8computers8environment8attack8attacks7started7

Episode notes

In this episode, host Sandy Vance sits down with Gary Salman , CEO and co-founder of Black Talon Security , for a passionate and informative conversation about the growing ransomware crisis in healthcare. With over 30 years in health tech and a background as a part-time law enforcement captain, Gary brings a unique perspective to cybersecurity. He draws parallels between street-level crime and digital attacks. Whether you lead a large hospital system or a small specialty practice, this episode is packed with practical insights on how to assess your cyber risk, respond to an active breach, and build a culture of leadership accountability before disaster strikes.

Full transcript

25 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Welcome to the Cybersecurity at Vive series on the Beat podcast where we break down the fast moving world of cybersecurity and what it means for your healthcare business, your data and your everyday life. In this series, we'll go beyond the headlines to explore real threats, real defenses, and the people on the front lines keeping our digital world secure. And now your host, Sandy Vance.

Speaker B: Hey everybody. Welcome back to the cybersecurity series on the Beat podcast. I'm your host, Sandy Vance and today I'm here with Gary Salman, who's the CEO and co founder of Black Talon Security. Welcome to the show, Gary.

Speaker A: Hey, uh, thank you so much. Pleasure to be here, Sandy.

Speaker B: So you are a leading innovator in cybersecurity solutions for healthcare. I'm excited to be here with you. Over 30 years in health tech experience. But a first for me on this podcast that's been going on for five years is you're an actual law enforcement deputy sheriff. Tell me more about that.

Speaker A: Uh, so it's part time, right? I've always been kind of wired to want to help people, hence the reason I do cybersecurity. So I support a sheriff's department here in Westchester county. So my role as captain of the sheriff's department. So we have about 100 deputies that support the towns and cities and villages, uh, throughout this part of the state. So it's a nice way to kind of give back to our community.

Speaker B: Under Gary's leadership, Black Talon monitors and secures approximately 65,000 devices worldwide. You all are providing cybersecurity services to a wide range of clients, from small practices to some of the largest healthcare organizations in the United States States, including many of the top 20 dental service organizations. So I'm just interested in hearing, like, this career path that spans healthcare technologies, cybersecurity and active law enforcement. How does your law enforcement experience sort of shape the way you think about cybercrime in healthcare, especially when, you know, responding to real world attacks?

Speaker A: People always ask me that, like, what's the connection there? So I'll kind of explain that. But you know, I really started my career writing EHR software literally from the dorm room of my college many years ago based on a need from my dad, uh, being a oral maxillofacial surgeon. And that kind of led, you know, into other areas of technology. So, you know, I was kind of always the person who looked at a piece of technology and said, well, how can we use this in healthcare? Looking back, and I'm going to date myself now, but looking back to the late 90s, tablet computers, like legit Windows tablet computers started coming out. I'm like, why is anyone using an encounter form, right? Why can't the doctor just put, uh, his or her notes in this and check off the procedures that were performed on that patient and route them to checkout? So I was like, okay, well, how do we do this with wireless? And we started developing all this wireless technology. And then one day I was like, all right, we're all using the Internet now. Can I put my software on the Internet? So we started experimenting and actually set up what back then was called server based computing, which is kind of like cloud computing now in the year 2000. And quickly all of these healthcare entities are like, well, I don't want, uh, my own server anymore. I want to have you guys manage my software and my data. So one thing quickly led to another and we were starting to support thousands of users across the US Running our server based software. And that was really my first real wake up call to cyber. Because we looked at our database, we're like, whoa, we literally have millions of patient records in these databases. And if these servers get taken down in a cyber event, we're going to shut off thousands of healthcare entities across the U.S. and that's when I started really digging into, okay, what do we need to do to secure this stuff? And we started, um, playing with some of the Cisco technology to prevent these types of intrusions. So that was really my first kind of obsession with that, because you don't want the bad guys taking over your network and doing bad things with, uh, the servers and the data. And if you kind of look at law enforcement, what are we doing? We're trying to prevent bad things from happening to good people. In its most simplistic form, if you think about it, cyber is kind of like a robbery or a burglary, right? Someone's going into something you own, like your house or your medical space, and stealing your stuff, right? And they're holding you hostage, they've kidnapped someone or something that's valuable to you and now demanding you return something. So I think there are parallelisms between law enforcement and cyber. And look, in the real world, law enforcement, federal agencies do work very closely with cybersecurity companies, sometimes. Cyber companies, right. We also specialize in incident response. So we get hired by insurance carriers and law firms to unfortunately help medical groups and dental groups that have been victimized by these attacks to help them recover. And sometimes we see attacks that government agencies haven't seen yet, or they don't have data yet on. So there is definitely a lot of information sharing that, um, goes back and forth for good purposes. What I see is most healthcare organizations that are victims of these ransomware attacks, they are brought to their knees. There is no path forward for recovery, getting their ehr EMR M systems back up and running, their imaging back up and running, unless they pay the ransom.

Speaker B: Do you think usually they do end up paying the ransom?

Speaker A: Oh yeah, I would say about 90% of the healthcare orgs that we work with have to pay the ransom. There is no choice.

Speaker B: That's just crazy to think about. And there's so much more awareness of this now too. I mean like the time and energy in organizations that goes into disaster recovery now is monumental. And most organizations, at least the larger scale ones, have a, uh, chief information security officer or an organization that they work with. I mean, from what you're seeing today, like with this increased awareness of cybersecurity attacks, like what are the most common blind spots in healthcare? Um, like why do we continue to see these challenges despite this growing awareness in the industry?

Speaker A: One of the biggest things that I see when we do these forensics investigations, they do often uncover the blind spots. Right. And what I always talk about is organizations often say, oh, I'm going to get burned down on the north side and the south side of my building. So let's fortify those doors and the threat actors, like, um, I'm just going to walk through your west side, we're going to come right in. Right. That's unprotected. And why is it unprotected? Well, there was no visibility and I think that's a challenge. I mean, if you think about the complexities of these environments, even smaller organizations, the number of computers and devices and firewalls and remote employees and third party companies that do revenue cycle, and now we're bringing in AI into everything, it just starts to get almost out of control. And I think a lot of organizations are putting most of their eggs into some type of reactive process, meaning something bad is happening on my network and we're going to respond to it. You know, there's a lot of really good technology out there like CrowdStrike and Sentinel 1 and tools like that that if it does detect something bad in the environment, it's going to hopefully react and either eliminate that or minimize the impact. But one of the things that I always argue about is why do you want those tools to ever go off? Right. If you can say, I know for sure, I've locked all my doors on My building conceptually, let's just say that's the parallelism for your network. I've shored up most of my people because people are a risk, right? Obviously everyone knows phishing and spear phishing and stuff like that. If I can have full visibility into my people, if I can have full visibility into everything Internet facing, if I can have full visibility into my computers and how they're potentially vulnerable and exploitable, there's kind of this new concept that we've been pushing for about a year now called ctem, which is a continuous threat exposure management, which basically talks about you need to know your attack surface, your external attack surface, which is anything Internet facing, your internal attack surface, which are, uh, computers and people. And one could even argue third party, fourth party, fifth party attack surface. And not only do you need to know about it, you need to know about it almost in near real time. So this continuous threat exposure management really talks about being able to constantly test and probe your environment, identify where you have risk, help you better understand the priorities of those risks. Right? So one of the big things that cisa, uh, Homeland Security, the FBI, private sector companies like us, are really pushing healthcare organizations hard about is understanding where you have what are known as kevs, which is an acronym for known exploitable vulnerabilities. And what I find is when you ask organizations, even very large ones, many times like, hey, how are you guys managing your known exploitable vulnerabilities? And then you typically get the giggle and the laugh like, oh, you know, we run some scans like every month or quarterly, and sometimes we do things with those, sometimes we don't. That's the problem. The threat actors, when they land on your network or if they want to get through firewalls and things like that, they will absolutely exploit known exploitable vulnerabilities to either gain initial access into a network, or once they land on a workstation or workstations, they will start scanning the network, sometimes the entire network. They'll find these KVs, they will take a tool out of their hacking toolkit, and guess what? They will just continue to exploit your network until they ultimately get what they want, which is usually the patient data, financials, hr, things like that. So, so this whole concept of CTEM is, hey, we need continuous evaluation of where we have threats in our environment. And it's not just limited to one part of our organization. It needs to be, you know, systemic through the entire environment. And I think that type of visibility along with risk priority prioritization is just so important. And then it kind of also leads into you don't have unlimited time, resources and money to address vulnerabilities. So CTEM really helps with a, uh, CISO or CIO or CTO or director of it, depending on the size of the organization, or maybe even external managed service providers that are managing that organization. It really helps them understand where they have risk. What are my priorities in terms of those risks so I can focus my energy correctly so that I can minimize my risk as much as possible. And that is an ongoing process.

Speaker B: You talk a lot about working with larger organizations and I think that a lot of the healthcare leaders we see at Vive believe that cyber attacks only. And uh, maybe it's not fair to say they believe it, but you think about cyber attacks most frequently happening in large systems. But black talent actually works extensively with some smaller and mid sized practices. What do you think that the biggest misconception smaller health care organizations have about their cyber risk is?

Speaker A: So I think the blind spots are similar, they're just at a different scale. Right. So if you have five locations or you know, urgent care facilities versus 100, you know, it is somewhat proportional. Right. Uh, you obviously have more risk with more locations, but the risk is the same and the damage is the same. Right? So five locations going down, that can crush an organization that only has five locations. You know, you have an org with that as 100 clinics across the US if 100 go down, right, that's the same impact, you know, financially, operationally to, you know, as well as to the general public. So I do see a ton of small organizations, small healthcare orgs getting hit with ransomware. Um, there are plenty of public sites out there now that literally publish every ransomware victim. And if you scour that information, oh, there's plastic surgeons, dermatology, smaller orthopedic groups, and then obviously you see the bigger systems. So the hackers don't care. Right. They know that quote, unquote, a hit's a hit. And they also know that many of these smaller health care organizations do have pretty decent insurance policies. So if it takes them a couple hours to break into a small organ, they have a million dollar policy and the policy OPTS to pay $1 million in ransom payments. That's a lot of money for a little bit amount of work. And I also believe that a lot of business leaders and in the smaller groups it could be a doctor, you know, that has, you know, built up a bunch of derm practices or plastic surgery practices or orthodontic practices, whatever. And now they have 10 locations. They're like, oh, uh, they're not going to come after me. They're going to hit the hospital down the street from me or that orthopedic group with 5,000 employees. Um, so I think there's a lot of misinformation floating around in terms of who gets targeted and how they get targeted and the why. And then the other big problem, and this is what I hear in almost every single event, is, well, we hired an IT company or we hired a managed service provider. They told me they do cybersecurity. Every time we asked, they just kept saying, oh, we're safe, we're good, stop worrying about this, we got you. And then they turn around and have a five, $10 million cyber event on their hands. And now the IT resources are, ah, left reeling trying to explain how they just made that statement a couple weeks ago about having them, quote, unquote. So I think healthcare workers really, really need to rethink how they're managing security. And this could be cliche, but what I always say is you can't have the fox guarding a hen house. You know, if you're, if you're a business owner, right. If you are a executive in one of these healthcare orgs, ask yourself a very simple question, which is, has your IT group, whether it's internal or external, ever sat down with you and said, hey, Mrs. CEO, uh, here are all the places that we have serious security problems. If you've never been provided with a report showing you everywhere you have a significant security risk, then by default you have no idea where you actually have risk, and you can't put anything in place to try and mitigate that risk. And when regulators come to you and say, hey, because of the cyber attack, 100,000 patients or more, whatever the numbers, was compromised. What did you know from a security perspective prior to this event? And you put up your arms like, yeah, I don't know, I trusted someone

Speaker B: else could have prevented it.

Speaker A: Yeah, maybe if I had known where my risk was, I would have said, you know what, go ahead, spend that money. I can't accept that risk. Let's get this resolved. And all too often, I'll say a very high percentage of the cases, no one on the executive team had any visibility into their cyber risk. It was simply outsourced to someone else.

Speaker B: When you go back to thinking about being prepared, right, so you train a lot of healthcare professionals and speak at conferences to folks about this, what shift in mindset or behavior do you believe that these healthcare leaders could adopt to sort of stay ahead of what's coming. Because, you know, there's this saying, I'm sure you've heard it. It's like, if you haven't experienced an attack, you will. It's not if, it's when, right? Like, this is a, uh, common thing now. What do you want or wish for these healthcare leaders?

Speaker A: So what I started really seeing in the industry, probably mid-2025, and is kind of in full force in 2026, is executive accountability, right? Leadership accountability. This is no longer an IT problem, right? Anyone who says, well, it addresses this, or it's their responsibility and there's no accountability, right? There's no, you know, let's just say monthly meetings to assess our security risk, right? That's going to be a really big problem. AI is moving things so quickly that is almost impossible to keep up everywhere in healthcare, not from imaging, Right. To development of new drugs, to treatment of patients, analysis of records, revenue cycle, billing. Like, AI is touching everything, right? And it's being used for a lot of really, really good purposes. But as a threat actor, as a hacker, a bad guy is also leveraging this technology to generate malicious code, right? So hackers don't need to be anywhere near as sophisticated as they used to be. They can leverage AI to build bad things, right? Bad toolkits, export kits, things like that. So one of the things that I always talk about is the fact that leaders need to understand that this stuff is moving way faster than ever before. They need to have full ownership of cyber risk. And one of the best ways that they can do this is through data. You know, And, Sandy, you probably know this, right? Uh, would you agree that most healthcare organizations make almost all of their decisions based on data nowadays? Yeah.

Speaker B: And the data is driving everything now.

Speaker A: Everything. Right. But when you ask them, hey, what data are you using to drive and enhance your security? Uh, cyber security posture. Often it's shrugs like, I. I don't know, I'm not very technical. Right? That's. That's not what I do.

Speaker B: Oh, okay. Yeah. That's not the question I thought you were asking, but, yeah, no, that's an excellent point. I mean, prioritizing things should be data driven, right?

Speaker A: For sure. So one of the things that we're doing right now, which is really changing the industry, is through providing what we call a cyber risk rating, right? So we can take all of this telemetry from the network. You know how many known exploitable vulnerabilities they have? Um, are their firewalls configured properly? Are there firewalls at risk for Exploitation, how well are their people doing from a, uh, cybersecurity awareness training perspective? You know, are tools constantly intercepting malicious code in the environment? If that's the case, that's not good. They shouldn't have a lot of malicious activity going on in the network. That means there's a weakness somewhere else that's allowing that to enter. So we're taking all of this telemetry and near real time, presenting the leadership team with a, uh, cyber risk rating for the organization globally. You can also get a cyber risk rating for facilities or locations or clinics. So, so that way, within seconds, a business leader who isn't even really technical can say, all right, a whole bunch of my facilities, they have a cyber risk rating of 10. Right? So on a scale of 1 to 100, 10 is really low. It's good. A hundred is a disaster. But they can look at all of this data and instantly say, whoa, why do these five facilities have very high cyber risk ratings? This one's got 76, this one's got an 80, this one's got a 90. What the heck is going on? And they can immediately start asking hard questions.

Speaker B: So when you guys do monitoring, is it more of a continuous monitoring process than, uh, doing that testing and providing a report?

Speaker A: Exactly. So one of the things that we do is this, the C10, this continuous threat exposure management. So our platform basically analyzes the external attack surface. So think about, like, your firewalls or anything facing the Internet. It does internal attack surface management, which identifies missing patches and software that needs to be updated, um, because there are security problems with that software or operating systems. So our platform is constantly scanning the external environment, the internal environment, and providing this risk prioritized data back to those individuals that are responsible for, um, managing those computers, managing firewalls, managing the security of their environment. And because it is real time and because new information is constantly coming out every day, that data may actually change from yesterday to today. So for argument's sake, we could scan some computers and find a vulnerability with Google Chrome. Pick something easy, and the software flags that as a medium risk. Tomorrow morning, it now becomes apparent that hackers are actually exploiting that Google Chrome vulnerability and gaining access to those machines. Well, all of a sudden, our platform will then say, oh, this is no longer a medium risk, this is now a high risk because it is a known exploitable vulnerability. And that risk will be reprioritized. And now the cyber team or the, the tech team will say, okay, I got to now patch a thousand computers and eliminate this Google Chrome vulnerability. But what if you were only doing these scans every month? You are literally, for argument's sake, 29 days behind ball, you know, on that information. So this is really where the cyber games at right now. These point of time tests, these point of time evaluations, or assessments as we like to call them, that's got to stop, right? That those are just not effective anymore.

Speaker B: I love this so much. Thank you for sharing your time with me today and these thoughts. Do you have any parting thoughts before we wrap up here?

Speaker A: The best advice I can give anyone in a leadership or ownership position is kind of what we talked about, right? Get involved. Ask the hard questions. Where do we have risk? Can you quantify risk for me? Are we decreasing our security risk? Are we increasing our security risk? Are we not budgeting enough money to properly do this? And then make sure you're working with an independent company, right? It's very easy for IT resources to say we're doing a good job, but where's the validation? Right? So I always say get the proper validation from a company like us to help you identify where you have risk and address it. Right? So you're not in a, uh, cyber event. Look, honestly, most of the events we've done from a ransomware perspective, data theft perspective, email intrusions, these are all preventable events, right? It's because mistakes were made, technology wasn't configured properly. Right? And in the end, we're just paying bad guys a lot of money and it's not right.

Speaker B: Well, Gary, how can folks learn more about black talent security on the web?

Speaker A: Visit us@blacktalentsecurity.com youm can hit me up on LinkedIn also, Gary. Salman S A L M A N I push out a ton of great content. I have thousands of healthcare leaders and doctors following me there. So we're constantly pushing out, like, best tips, security alerts, you know, things like that. I have a lot of people in IT that follow me as well to try and keep up with the moving threats and, um. But yeah, I think that's probably the best way.

Speaker B: All right, well, thank you so much for your time today.

Speaker A: You got it. Thanks, Sandy. Appreciate you very much. Hey, if you enjoy listening to this podcast, be sure to check out all the content around data innovation@vive2026 by visiting health.com that's hlth.com from there, go to the Events tab and you will find recordings of nearly 100 case study presentations, podcasts like this, and white papers presented by leading technology solution providers. Be sure to subscribe so that you don't miss the next Vive event presented by Health and Chime.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • A 2005 Malware Find That Rewrites Cyber Warfare HistoryWhat's Up with Tech? · on Sentinel One90 / 100
  • OpenAI launches Daybreak with Cisco, Cloudflare and CrowdStrike, Vapi wins Amazon Ring as it raises $50M Series B, JPMorgan picks Mistral as $430bn sovereign-AI rival, Isomorphic Labs banks $2.1bn led by Thrive CapitalThe Daily Marketing Brief · on CrowdStrike88 / 100
  • Cyber Ranges, Attack Simulations & AI: Proving Cyber Readiness | Interview with Lee RosseySecure & Simple · on CrowdStrike86 / 100
  • How to Sell Against a Competitor Already in the BuildingSales Leadership with Fexingo · on CrowdStrike85 / 100
  • Episode 125: Origins of MITRE ATT&CKThe Azure Security Podcast · on CrowdStrike84 / 100
  • Ep. 8 CISO Sebastian Goodwin on Advising DSPM and Automation StartupsGenealogy of Cybersecurity - Startup Podcast · on Sentinel One81 / 100

More from Cybersecurity at ViVE Podcast

All episodes →
  • Trust, Verify, Repeat: Securing Healthcare in the Age of AI Voices 62 / 100
  • Security vs. Convenience: Can Healthcare Have Both? 44 / 100
  • Rethinking Network Defense in Healthcare 59 / 100
  • Compliance Isn’t Security: The Biggest Cybersecurity Myth in Healthcare (HITRUST Explained)78 / 100
  • Why Healthcare Needs Cyber Resilience, Not Just Cybersecurity
All Cybersecurity at ViVE Podcast episodes →