The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Hybrid Identity Protection Podcast
Hybrid Identity Protection Podcast artwork

Practice Makes Progress in Cyber Resilience with Jim Bowie, VP and CISO at Tampa General Hospital

Hybrid Identity Protection Podcast · 2026-06-23 · 36 min

0:00--:--

Key moments - from our scoring

Substance score

60 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality12 / 20
Guest Caliber14 / 20
Specificity & Evidence12 / 20
Conversational Craft10 / 20

Healthcare cybersecurity faces three unique constraints that distinguish it from other critical infrastructure: chronic underfunding, zero tolerance for downtime in 24/7 operations, and dependency on clinical staff who may resist security training. Jim Bowie argues that the path forward isn't purchasing expensive technology but rather investing in rehearsal, training, and building organizational muscle memory through adversarial simulations and tabletop exercises. Tampa General Hospital runs monthly threat detection exercises, quarterly adversarial attacks on its environment, and regular domain controller recovery drills using their crisis management tools. Bowie emphasizes that clinicians respond better when they understand how cyber events directly impact patient outcomes - not just at their hospital but across entire regional health systems. He also highlights the lack of mutual aid agreements between hospitals for cyber incidents, a stark contrast to the hurricane preparedness protocols that already exist. Courtney Gus adds that organizations over-engineer their incident response playbooks when they should recognize that "an outage is an outage" - whether caused by weather, vendor failure, or cyberattack, operational response patterns remain the same. This conversation will resonate with hospital executives, CISOs in critical infrastructure, and security leaders struggling to allocate limited budgets for resilience.

Key takeaways

  • →Healthcare organizations can reduce mean time to recovery by blocking immutable calendar time for monthly training drills, quarterly adversarial simulations, and recurring disaster recovery tests - not by buying expensive technology.
  • →Framing cybersecurity as a community health issue (showing how one hospital's compromise cascades through neighboring hospitals already at capacity) converts clinician resistance into buy-in for security practices.
  • →The cybersecurity industry has over-invested in AI-driven detection and prevention while almost completely neglecting AI-assisted incident response and recovery, leaving teams unprepared for the human-centered aspects of crisis management.
  • →Mutual aid agreements between hospitals for cyber incidents, already proven effective for hurricane response, should be standardized but face unexplained legal and competitive barriers.
  • →Training scenarios should mirror operational reality - asking clinicians "what do we do if the surgery robot goes offline?" is more effective than explaining technical attack vectors like compromised domain controllers.

In this episode

  1. 1Healthcare's Unique Crisis Management Challenges: Budget, Time, and 24/7 Operations
  2. 2Building Resilience Through Practice and Training Rather Than Technology Spending
  3. 3Engaging Clinical Staff: From Resistance to Commitment Through Education
  4. 4Community Impact and Mutual Aid: Why Healthcare Organizations Should Collaborate
  5. 5Monthly Adversarial Training and Quarterly Attack Simulations: Building Muscle Memory
  6. 6Making Training Time Non-Negotiable: Creating Organizational Culture Around Preparedness
  7. 7Balancing Prevention, Detection, Response, and Recovery with Focus on Recovery

Mentioned

Tampa General HospitalSemperisJim BowieShawn DubyCourtney GusKrista ArndtIBM SecurityBloodhoundMicrosoft SIMSANS

Guests

Jim BowieCourtney Gus

Topics in this episode

Business email compromiseRansomwareTampa General HospitalCybersecurity incident responseAdversarial training simulationsDomain controller recoveryCrisis management frameworksHealthcare mutual aid agreementsSIM tools (Security Information Management)Bloodhound threat detection

Questions this episode answers

Why do healthcare organizations struggle more with cyber resilience than other critical infrastructure?

Healthcare faces three constraints: chronic underfunding, 24/7 operations that cannot tolerate downtime, and dependency on clinical staff. When throughput (measured in patient treatment capacity) drops due to outages, bad outcomes increase immediately. Unlike energy or transportation infrastructure, healthcare's critical assets are people, making the human element non-negotiable.

How does Tampa General Hospital conduct crisis management training without taking systems offline?

They run monthly threat detection exercises in isolated lab ranges where teams detonate malware and practice detection/recovery, quarterly adversarial simulations attacking their production environment, and regular domain controller recovery drills using their crisis management tools. All training time is blocked as immutable on the calendar, protected from operational requests.

Why should hospitals care about cyber events when they're already managing hurricane preparedness?

Cyber events are more damaging than hurricanes from an adverse events perspective. When one hospital is compromised, neighboring hospitals already operating at max capacity become overloaded, triggering adverse cardiac events and treatment failures across the entire region. It's a community health problem, not just an IT problem.

What's the biggest gap in AI-driven cybersecurity solutions today?

75-80% of AI research focuses on detection and prevention of malware, but less than 5% addresses AI-assisted response and recovery. Most AI proposals for recovery exclude humans from decision loops, which security analysts don't trust. The industry needs AI augmentation that keeps humans in command for the next several years until confidence builds.

How do you convince busy clinicians to participate in security training when they think it's a waste of time?

Connect security directly to patient outcomes: explain how one hospital's compromise cascades through the regional health system, reducing treatment capacity and increasing adverse events for other hospitals. Once clinicians understand the bits-and-bytes problem affects their peers' ability to treat patients, they typically buy in.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode contains several genuinely useful insights - the AI research gap (75-80% of papers on detection, almost none on recovery), the cascading adverse outcomes to surrounding hospitals, and the 'immutable training time' principle - but is diluted by a lengthy off-topic Mustang conversation and recurring restatements of the people-process-technology triad without adding depth.

75 to 80% of them are all about how can I get AI to detect malware. And that is phenomenal...There is literally two papers I found around AI...around AI and recovery
The first thing I did when I came in was like how long does it take us to recover a DC...we got it down to like 20 minutes which is phenomenal

Originality

12 / 20

The mutual aid agreement observation - that hospital CISOs informally collaborate while the industry lacks formal agreements akin to hurricane mutual aid - is a genuinely fresh structural critique; the 'outage is an outage regardless of origin' framing is a useful simplification, but much of the episode replays well-known people-process-technology arguments.

I don't understand why in healthcare we don't do that...if you ask a CISO, group of CISOs...I can call up any one of our competitors in cyber security, and we will help each other all day long
An outage is an outage. Downtime is downtime regardless of the origination point

Guest Caliber

14 / 20

Jim Bowie is a working CISO at a major academic medical center with prior EMT and mass-casualty response background, giving him genuine cross-domain credibility; he speaks from direct operational experience running adversarial exercises and measuring DC recovery times, not from theory. Courtney Gus is a vendor-side expert rather than an independent practitioner, which slightly limits the overall caliber.

I have four teams under me. Network, Security, Operations, IAM, um, and GRC. They are all part of that
I was in EMS originally at the beginning of my career. I was an EMT and did mass casualty response

Specificity & Evidence

12 / 20

Concrete data points exist - DC recovery reduced from weeks to 20 minutes, monthly range training plus quarterly adversarial exercises, 4,000 computers cited for National Guard reimaging, and the AI paper distribution statistic - but the cardiac outcomes study is unnamed, the blood bank incident is unattributed, and several claims remain at the level of general assertion.

we got it down to like 20 minutes which is phenomenal
75 to 80% of them are all about how can I get AI to detect malware...There is literally two papers I found around AI...around AI and recovery

Conversational Craft

10 / 20

Questions are topically reasonable and occasionally productive (the identity rehearsal question draws out the token/credential chain insight), but the host rarely challenges or follows up on specific claims, frequently restates what the guest just said, and the final third of the episode is consumed by an extended off-topic Mustang/Knight Rider discussion that adds zero operational value.

So you're saying, Jim, uh, you know, the, the, what we so often address in cyber security is people, process and technology triad. You are, you're putting a little more emphasis on the people.
Well, just sort of. Sort of wrap up. Um, if you can. Jim, uh, if without violating operational security, can you tell us anything about your Mustang mods?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A66%
  • Speaker B21%
  • Speaker C13%

Most-used words

help18point15crisis14organizations13response13cyber12healthcare12practice12management11infrastructure11identity11downtime10hospital9critical9cybersecurity9tools9

Episode notes

This episode features Jim Bowie, VP and CISO at Tampa General Hospital, joined by co-host Courtney Guss, Director of Crisis Management at Semperis. Jim began his career in EMS and law enforcement before moving into cybersecurity, giving him a grounded understanding of how operational continuity and human outcomes intersect during a crisis. At Tampa General, he leads teams spanning network security, operations, IAM, and GRC, and has built a training culture centered on adversarial simulation, monthly range of exercises, and regular DR drills. In this episode, Jim argues that rehearsal is the highest-leverage move for resource-constrained security teams and explains why an outage is an outage regardless of cause. He covers why identity is consistently the weak point in every simulation and why the relationships you build before an incident are the ones that matter most. If your organization is still treating recovery as an afterthought, this episode will change how you think about it. Guest Bios Jim Bowie Jim Bowie is the Vice President and Chief Information Security Officer (CISO) at Tampa General Hospital (TGH).

Full transcript

36 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Cyber event is actually even more riskier than a hurricane at this point. It's not more costly from a damaged property perspective, but from an, uh, adverse event perspective, it can be pretty ugly.

Speaker B: Hi, everyone, and welcome to the HIP podcast. I'm, um, your host, Shawn Duby, principal technologist Americas for Semperis. Crisis management in the healthcare sector takes on an extra level of seriousness compared to other sectors because if a hospital is crippled, people may die. These organizations used to be off limits, but no longer. The combination of generally easy compromise and the critical need for services to be available often results in a greater likelihood to pay ransom quickly, and that's proved irresistible to cyber criminals. As a result, operational resiliency isn't a cliche at these organizations, it's a mandate. What are some of the unique challenges in making a, uh, healthcare organization resilient? What can we learn from their hard work to apply to our own organizations? My guest today is Jim Bowie, the vice president and CISO at, uh, Tampa General Hospital. Jim is an accomplished cybersecurity leader with decades of experience and leadership in threat hunting, incident response, threat intelligence, and security operations. He's a strategist that's able to bridge between security, infrastructure and business needs, and has experience leading multiple areas in information technology, including cloud infrastructure and security. I also happen to know that, like my recent guest, Krista Arndt, he's a fellow Mustang owner. Also, like Krista, he's done way more with his Mustang than I have with mine. Welcome, Jim.

Speaker A: Thank you. It's good to be here.

Speaker B: Joining us is my colleague, Courtney Gus, director of crisis management here at, uh, Semperis. Courtney brings over 20 years of experience in cybersecurity, crisis response, and business resilience. Over the course of her career, she's led cyber crisis management initiatives for a wide range of organizations, including global enterprises, government agencies, and Fortune 500 companies. She previously served as a senior consultant in IBM Security, where she specialized in cyber risk quantification and advised clients on regulatory compliance, incident response, and stakeholder management. Courtney also has a need for speed, but in her case, it's a motorcycle. I'm starting to see a trend here with crisis management experts. Thanks for joining us, Courtney.

Speaker C: Thank you for having me, Sean.

Speaker B: So, Jim, uh, just to sort of start things off, what are some of the unique challenges that healthcare organizations face in crisis management?

Speaker A: We have three, really. Uh, the first being money. Most of them are not well funded enough to carry out all the things that they need to do. Uh, the second is time. And by that I mean usually they're 24, 7, 365 operations. So taking the downtime to switch out your hardware, to upgrade it or to bring down an application, usually super, super tough. And what that means is when you do have a downtime and when you do have an incident that causes an unplanned downtime, uh, things go into chaos pretty quickly. When your, your organization is used to running at peak efficiency and you can do a certain amount of throughput, as soon as you reduce that throughput, it actually has a, the throughput is people, right? And so people can't get treated in time, then you have an increase in bad outcomes.

Speaker B: Right? Healthcare is critical infrastructure. But unlike other aspects of critical infrastructure, the moving parts are more often people in healthcare than they are in other, say, energy sector or other uh, critical infrastructure sectors. It's the people and the challenges in working with the people and how they respond to crisis that's different than other critical infrastructure.

Speaker C: Jim, when you're managing something like limited budget and resources and a low tolerance for downtime, I mean, I would think it would then heavily fall on prioritization to manage a situation like that.

Speaker A: Yeah, it's uh, so there's one thing you can do, uh, outside of a budget honestly, and it's one of the easier levels to leverage to pull. But you obviously, you don't see it a lot and, and that is to take a chunk of your time capacity of your team and reduce the length of that downtime. And m. By doing the way you do that without spending money usually is to just train, just practice, rehearse, um, go through your doctor procedures, your crisis procedures. Make sure you have the right tools in place off band obviously, uh, because you don't want them to be down the right tools in place to manage those things. And you have thought through these scenarios and you plan and you orchestrate that way. You reduce that downtime, right? You uh, reduce the meantime to recover. Not the meantime to triage and respond, but the meantime to recover, which is what the organization's after. And uh, by doing that and not having to, you know, spend a chunk of money to buy some multimillion dollar piece of tech to do it, you can, you can still have a very positive outcome on the, on the organization.

Speaker B: So you're saying, Jim, uh, you know, the, the, what we so often address in cyber security is people, process and technology triad. You are, you're putting a little more emphasis on the people.

Speaker A: It's all, it's all on the people. Like there's, there's some great tech out there. Don't get me wrong. I'm not, I'm not harping on that. You absolutely need a technology component to your, to your program. But at the end of the day, that tech is surfaced to a person in the chair, and if that person is not up to speed, there's no amount of tech that's going to help them and help you get through the crisis.

Speaker B: How does that work? You know, you have your constituencies in health care. You have very clear constituencies. And a little bit like higher education, you have some very. You have important Personas, uh, that are technologically adverse. How do you rehearse? How do you practice with those? And I'm talking about, obviously about clinicians and doctors and nurses. How do you rehearse them, uh, for this situation when they're obviously very busy and probably averse to, uh, quote, wasting their time. I'm, I, I'm putting words in your mouth. I don't know.

Speaker A: Right.

Speaker B: How do you handle that? How do you work with that?

Speaker A: So there has been, I will say, a massive culture change in the last few years, and I'd like Courtney to tell me if she thinks I'm wrong. But if you'd asked me that question in 2020, I'd have been like, I have no idea. It is a challenge. They think it's a waste of time. They don't want to do it. But at this point, I don't think I've met a clinician that doesn't have a peer or a friend, or they themselves, at another organization, have worked at a place that has had a cyber reverse downtime of some sort or been impacted by one of our vendors going down. And now we can't do blood draws or, uh, one of the big crises we had here in the Southeast two years ago, three years ago, where the blood bank, one of the major blood distributors, was out like that, all hit everybody at home very quickly. So the ostrich approach that they, I would say they used to have, they've kind of woken up to it. And so what you do with that is you don't use. At least, I don't, I don't use fear as a mechanism. I just educate. Like, look, if you practice this, this and this, let's walk through this tabletop. Let's talk about how we can make your unit more, uh, resilient. And in doing that, how you can, uh, how it directly affects patient outcomes. And, um, one of the ones that surprised them the most, one of the stats is there was a study done. Not only is when A local hospital goes down from a cyber attack. The patients at that hospital have adverse conditions. It's the surrounding hospitals themselves. They actually see, uh, a massive increase, uh, in treatment and positive outcomes for cardiac arrests and cardiac events, because they're overloaded, too. Because that one hospital, or healthcare in general, runs so lean. Uh, most big cities, most urban areas or even rural ones are already at max capacity. And so you start overloading a couple hundred patients, um, off onto them, then they start overloading, and they can't make the quick decisions they need to make. They're out of resources. And so those adverse events spread. So it's not just one hospital goes down, a staff hospital's problem, it becomes the entire community's problem. So once you frame it that way to the doctors, uh, and look, if you can help me, help your peers understand this, Everybody at the end of the day is there to treat people and help people. So it's very rare that you get someone once they make that connection between the bits and bytes and the person that they're like, well, this is a waste of m. My time at that point. Cort, would you agree or disagree?

Speaker C: Yeah, no, I think it's really interesting. You're in a very unique position. I think globally, a lot of our industries are becoming more interconnected than they ever were in the past. So like you said, the dependency on technology or other suppliers, I think we've all just become a lot more dependent and connected with each other and. But then the adverse of that is there's also a greater ripple effect when one or all of us are impacted. And so we rely on each other, we also impact each other. Um, and it does cause you to have to think outside the box a little bit in terms of what happens if my partner goes down and I'm impacted, or what's the impact I cause if I go down to my partners or my surrounding community. Um, and I think that shifts the way we practice as well. And Gemma, I'd love to get your thoughts on this, but I think practicing those scenarios where we're either reliant on other partners or we're causing an impact to other organizations is important because those are the reactions or those are the situations I don't think we're always prepared to handle. And handling some of that on the fly can be challenging if you don't have contacts or relationships pre built. To your point, I love the ostrich analogy, but I think the same goes for how we work with our partners too, not just how we practice internally.

Speaker B: You know, it's interesting, Jim, you're in the Southeast, where one of the features that you have are hurricanes. And so there is a precedent for inter. Organization communication, right. In case of disaster.

Speaker A: So it's actually. It was really shocking to me. So I was in EMS originally at the beginning of my career. I was an EMT and did mass casualty response and things of that nature. Law enforcement did the same thing there. And all these organizations, and I know they're government organizations, so maybe a little different, but have mutual aid agreements. And I don't understand why in healthcare we don't do that. I. I don't. I don't get what's stopping us there. I'm sure there's some lawyer will hop in and say, you can't do it, because XYZ. But if you ask, uh, CISO, group of CISOs, we're very. It's one of the weird parts where, like, my CIO or he's a great person to work for, but, uh, you know, he'll say, hey, all these other CIOs get really competitive and they don't really want to help, or all these other organizations don't want to help each other. I'm like, dude, I can call up any one of our competitors in cyber security, and we will help each other all day long, give all the intelligence we can, because we know that if one of us goes down, we all go down. I don't know why in this industry we don't have those mutual aid agreements. I've never. I've never understood what the legal barrier is for that. You would think just like in a hurricane, because all the hospitals will come together in a hurricane, just like all the county organizations were. But a cyber event is actually even more riskier than a hurricane at this point. It's not more costly from a damaged property perspective, but from a adverse event perspective. Um, they can be. They can be pretty ugly. The other issue that's really. Or the other thing that does help, when you're asking how we train, uh, Courtney, is we do at least a couple times a year here in the state of Florida, get to practice doctor policies. It's not a cyber event, but it's the same thing we go through. All right, what happens when the Internet goes down? Are we good to go? Do we all have our backup records? Have we moved our backups? Are they immutable? Are they in three different places? Do we have geographic disparity? What happens if this vendor can't get reached? We have enough linen towels, like, all that stuff Applies in the cyber attack too, but it just gets worked through in a hurricane to drill. Um, because if your linen provider goes out, it's the same drill whether or not you can't get linens on the island because it's flooded, or you can't get linens on the island because the linen provider is under attack and they don't have a distribution chain anymore. So it's the same, it's the same income.

Speaker C: You know, I actually think that's a really interesting point, Jim. When we shift the way we think about practicing. I think historically we've tried to over engineer the way we practice. And I'm not talking about just healthcare, but just in cybersecurity in general. We want to build, run books and playbooks for all of these different scenarios. And then it becomes, um, a bit of an uphill battle. It feels overwhelming to try to prepare, try to practice, try to keep these materials up to date. But I love the point you just made. An outage is an outage. Downtime is downtime regardless of the origination point. Now, the origination point determines how that team fixes the problem. But all of the operations that have to keep moving to support patient care are the same regardless of that, that starting point. And I think if we could distill some of the myths or beliefs that we need to engineer this to the nth degree, it might make it a little bit easier for teams to practice, kind of overcome that hurdle.

Speaker A: Uh, you don't have to come up with the crazy scenario of space aliens coming down and taking out, you know, your core switch. Like it can just.

Speaker C: That's a fun one.

Speaker A: Yeah, that's on my bingo card for this year. Just on the way the year's going, so we'll see if it actually comes true. But no, but like you said, like, just sit down with your operational folks. They don't need to know the tech wizardry that, hey, the core router's down and your firewall's been flummoxed and all that. They say, hey, you don't have a surgery robot, what are you gonna do? Right? Like your mid surgery surgery robot goes out or you are running an ED and now you can't type blood. What, what are we gonna do? What's our procedure? And it doesn't matter. And it's our job as IT to train the actual scenarios of, like, how would that happen? From an IT downtown perspective, but from an operational perspective, they don't care whether it's an IT outage or blood just disappeared. It's still the same response, like you said. And that makes it much simpler. You're right.

Speaker B: I know. In our conversation we talked about, um, the need for rehearsal, and we're sort of talking about rehearsal. Can you talk a little bit about that aspect of it? How do you, how do you start and how do you, how do you continue to adapt or continue to improve your staff once you started?

Speaker A: So I, like I said, a big believer in training. And part of training is not just the book learning, it's the doing. That's where you build your muscle memory. Uh, so I fight to the death. And like I said, my boss is wonderful about this. To take a training budget and keep it. And it's, it's a sizable training budget compared to the rest of it. And, uh, what we do with that, not only do I send them to whatever conferences I can, whatever actual, you know, certifications, whatever they want to do, whatever interests them and point them at it. It's like, go. Uh. We also do adversarial training and risk simulation. So we hire third parties to come in and attack us. And it's not a pen test. It's not like, where are your weaknesses? It is, where are your gaps in your team? And I don't. And they don't mean like, in a harsh way. It's just like, could you detect bloodhound going off and how long did it take you to see that? And what was your response time like? And what you do while you do that is you actually use your crisis management tool and you're testing your, your incident response plan and you're making sure your notifications are going out the way you normally would send them out or supposed to for compliance and regulatory reasons. And you have your scribe there making sure they're writing everything down. Unless you've got, uh, a scribe, automated scribe of some kind. Or you pull in all the people on, um, don't just have your ops team. Like I'm under, I have four teams under me. Network, Security, Operations, iam, um, and grc. They are all part of that. They all come in, they all experience. Because when the crap's hitting the fan, they're all going to be involved anyway. So they're all running through, um, the INR or the incident response with us and every one of those simulations. And we do those monthly and the. So there's. There's two parts of things we do. We do adversarial training, the actual attack on our environment with our tools quarterly. And the team loves it. It's a huge game to them and they, they absolutely enjoy the hell out of it. Turns it into almost like a mmo. I guess they compare against other people, um, other industries. The other thing we do is we have monthly training in a range that they can actually detonate things at and see live attacks. And I don't mean simulated attacks that are tooth de tooth. I mean like, hey, they're detonating malware. Here's your environment, here's a sims, here's a Microsoft SIM deployed with the exact kind of same tools that you're used to seeing. Go find the attack. Let's see how long it takes you to recover. It was the ultimate, takes you to respond. How do you actually mitigate, you know, a business email compromise versus, um, a ransomware detonation on network attached storage or someone has compromised your domain controller. How are you going to recover those? Uh, the other thing you do is if you have Dr. Tools. We train monthly too. We restore DC all the way from scratch using our tools. Um, yeah, like, you just, you got to keep doing that. It's like muscle memory.

Speaker C: I'm just so impressed. I think that's a cultural difference within your organization, Jim. I think emphasis on practice and preparedness on the technical side, as much as doing your day to day job, that's a tough balance, right? Like pulling people off the keyboard and having them spend time in a range or having them spend time in an exercise. Um, is the mindset that no matter how much we work on our day to day work and we're as good as we are, things are going to happen. We have to be prepared for that. I see organizations really struggle with making time for things like that because they're afraid to take their eyes off the ball or they just don't have enough resources. So I, I applaud you guys first, but also, was that a shift you brought in or was that your, your cio? Was that a joint effort? Like, how did you guys decide that that was going to be your, your balance there?

Speaker A: Uh, I made a unilateral decision and then I told my leaders and it's going to sound harsh, but they were on board anyway. I was like, look, we are, this is not a, oh, let's block off time to train and then never get to it. This is, you're going to block this time off. Y' all decide together when we're going to do this. That is sanctuary. Uh, like you cannot eat into that time absent a true, real critical ir. Obviously we're not going to go off and play in the range, if you know, China's in the network but you know, absent that, that time is. There's a word for this like sanctimonious or whatever that you cannot. Immutable. That time is immutable. It goes. Yeah, cyc. Thank you. If you, if you block that time off and that's the time we've decided we're going to do a cloud range or an adversarial attack or uh, restore D.C. you're going to do it. Nothing else happens. And if an operational person or you get an elbow pull during that time, you escalate to me and I'll be like, they're busy, we'll get to it. So I think of the three years, it was a big change because having a lot of times, a lot of cyber teams, especially ones I've even been on before, even when I was ones of leaders before, I didn't realize how strict you have to be, be withholding that calendar time and making it not changeable, not negotiable. We booked it, we're going to do it. Uh, because it's very easy to say, oh man, I got four hours. Well, let me just. We'll just push it off. And then you keep pushing it off and it never happens. It's uh, it's almost like your personal health, right? You can say, I'll go to the gym later. Oh, I'll go to the gym later. I'll go to the gym later. And the next thing you know, you're in the hospital. Coronary, heart failure. You're like, man, I should have gotten to the gym like four years ago. So, so it's just, you gotta do it and it becomes routine at that point where everybody becomes a habit, right? It becomes a habit for me. So that it becomes less hard to do once you do it a few times.

Speaker B: I love that you had mentioned Jim and some of your training, uh, about uh, the recovery aspects of it. And I know this is another three part framework really uh, around crisis management, prevention, prevention and the detection and response and recovery. What are your thoughts about how do you, how do you balance these different aspects?

Speaker A: So as far as prevention goes, look, uh, the industry has spent, and I mean the cybersecurity industry, I mean the healthcare industry, the cybersecurity industry and the vendors and the partners out there have spent an inordinate amount of money into the detection and prevention problem. And they're really, we've gotten really good at it as an industry. If you put the time and effort into it, you can have A really good prevention of text improvement that may all be going out of the water soon with some AI stuff. But for now prevention and detection is phenomenal.

Speaker B: I think this week and it's a Friday.

Speaker A: Yeah, exactly correct. Not uh, to say things don't get through because there's humans involved. So it's always a mistake. But like the, the industry, if you look at all the, the actually look at the academic research around AI, if you collate every paper written since 2020 to now, 75 to 80% of them are all about how can I get AI to detect malware. And that is phenomenal. They've gotten really good at uh, detecting malware with AI and SOC teams and different SIM tools and whatever you want to do. There is literally two papers I found around AI, uh, and it was more just hypothetical. Oh, we should do this around AI and recovery and AI and actual response past that detection. Uh, and all of it's focusing on just automating it all, which is not a human in the loophole command scenario. You're not going to get that kind of buy in. What's crazy about it is if you ask, uh, I think Sans or Silence does a survey every year and in their survey they will tell you that AI can be like every analyst wants an effective AI augmentation. They can, they want to believe in it, but they don't have any confidence in any of it. The only way you're going to do that is to for the first few years or first a while is have the human and human command scenarios until we start to build that confidence. So I really went on a tangent there. But it goes back to what I'm saying. Prevention's handled for the most part. There's plenty of tools for it. Response and recovery. The industry has a lot to go with now. There are um, crisis management tools out there. Um, you know, for instance, like ready one to plug something that's here already. Uh, but very, very few vendors are worried about that side of it. And that's really where your most time to gain. If you're going to do a racing analogy if you need to, if you're trying to find where you're losing time in your laps, it's on the recovery side. It's on the response and recovery. It's not on the detection. The meantime to uh, detect and respond. Numbers have just taken a nosedive. Like we've done really good as an industry but we have not done a great job at mean time to recovery. Um, and because we've been focusing on the prevention part and building really good notes. But now they're getting in. What do you do? So

Speaker B: it's human nature to um, it's human nature to hope that you've done enough, uh, and not want to have to think about. Oh, gosh, many years ago, um, many years ago, uh, I wrote one of the first blog posts on Semperous and it was called Thinking the Unthinkable, um, about recovery. People don't want to really have to think about it. I mean we move quite a ways down the road since that time that was 2015 or someplace like that. But um, yeah, very much so. This is an identity podcast. We haven't really talked much about identity. I know you're a big proponent of identity protection and paying attention to the risks around your identity infrastructure. How does this fit, uh, how does identity fit in this rehearsal recovery framework? When you rehearse your team, what do you have them do around identity?

Speaker A: Uh, there's a lot in that question. So if you're talking about the identity infrastructure, we talked about recovering domain controllers and what to do once they've assumed breach kind of a situation like how do you recover receive point, how quickly can you recover? So that that drill is most important. Like the first thing I did when I came in was like how long does it take us to recover a DC and get. If the DCs go down and we need to redeploy from scratch, how long that was? You know, a week or two. Just because you had to pull in the backups and download the backups and we got it down to like 20 minutes which is phenomenal as far as the identity of the human or your non machine, your machine identities or like the individual user, if you want to call it that, whether it's human or not. Um, it's. In those scenarios one of the things that you often see that gets through the quickest is a compromised account somehow. It's just super hard in the way that at least in healthcare, the way in healthcare networks and servers and Windows and Microsoft is set up, it is super hard to prevent someone from actually getting uh, uh, a token or to pass the hash or to. You just have so many legacy pieces of equipment out there, things still running, NTML versions that are way out of date just because it's a 30 year old piece of equipment. Like you just. You have to assume the worst on that front. And so what you have to do to fix that is you do have to have monitoring on it. And then once you have monitoring on it, it's great that you can flip that one identity, but then you have a whole chain that you don't understand. And one of the first adversarial events we did, they got one of the accounts and so they kept resetting the account that the good guy, the blue team did, my team did. But the attacker kept being able to propagate and eventually it took them a little while to realize there's more than just the password. There's the tokens, there's the, um, store credentials, there's certificates. They got to wipe it all. And so more and more, the more you attack those things and the more you work through it, you'll eventually have a playbook that says, all right, every time I need to reset a user, you've got to do A, B, C, D, E, F, G, um, and it just comes from experience and getting attacked that way. So I, I tell my vendors when they do the third party simulations on us to absolutely trash the identity space and attack it as much as you can, because that's where the weakness is. Because at the end of the day, there's a human on one side of it and humans are the weakest part of this whole thing.

Speaker B: You made me think of something else, though, um, in regards to crisis management, and that is, um, dealing with outside parties, outside agencies such as the FBI or other perhaps resources that can help critical infrastructure organizations in this situation. Do you have any recommendations around that?

Speaker A: I do. Um, the FBI and the incidents I've been involved in, in real life, the FBI has been extremely helpful. Everybody thinks the FBI is going to come in or assist is going to come in and they're going to start writing notes about everything you did. That's wr not what happens. They come in and they can usually give you some intelligence, some nudge, nudge. You know, they can't tell you everything, obviously, because they have their own little secret squirrel labelings, but they will help you, point you in the right direction. You're dealing with this. You should look at this. They've been super helpful. As soon as you come, they're more than happy to help. Um, so if you don't have a relationship with your local FBI cyclocrime task force people, you should absolutely get that number set up. Time just, you can't, you can take them to lunch, but they won't let you pay for it, even if they're just not allowed to. So don't get offended. But, like, go to lunch with them, sit down, get to know each other, get cell phones, have the contact because when you need it, it is an amazing thing. Uh, it's amazing resource, the other resource. And I need to give a shout out to Nate. Um, uh, he's up in New England, he's a ciso. He uh, he was giving a lesson to us, uh, when we were talking about using the National Guard in almost every state or some regional area has a National Guard unit attached to cybersecurity and some sort of IT incident. So when you have an incident and if you can get your governors and who are whatever, depending on the state, whatever workflow you need to do, to do to talk through it, if you're critical infrastructure, this won't be hard at all. Do pre plan have the National Guard commit. They're not going to take over your network. They're not, you're not, it's not like Armageddon, uh, where David Keith is going to come in and all these people are going to sit down at consoles and kick your engineers out. It's just they're going to come in, they're going to say how can we help? And it could be even something as simple as hey, I need your help reimaging 4,000 computers. Let's go. And they will see fine. They will put up assembly line up and they'll take your image and they will help you reimage 4000 computers. Like that's just non intrusive but super helpful. It's there as you got a resource for it. Now if you're not critical infrastructure, maybe a little harder. But uh, yeah, National Guard since the ah, FBI, um, other other peers, like just call up your buddy, get to know your other, your other cybersecurity teams in the area. Hey, I'm dealing with this. Help me out. What have you seen? Oh, here's how we fix this problem like you can without getting the lawyers mad. You can absolutely. There's a lot of help out there. That's what I'm saying. Right, right.

Speaker C: I think one of the things I've heard Jim, from speaking with some of your peers and traveling around is the extra set of hands. Just, you just need more hands than you realize, more brain power than you you have prepared. Whether it's on the technical cybersecurity side of it or the clinical side. Uh, one of our other hospital organizations that we work with said they didn't realize during downtime how many different tasks require two people. Because you just need somebody to double check prescriptions. You need somebody to double check an image cybersecurity, you need people to image machines and there Are all these things that you plan for in an exercise but you don't plan for the extra head count. Where am I going to get that? How quickly can I get that person in here? Um, you end up paying or pulling in a bunch of very expensive resources or not having it at all. And I think it's just such an interesting piece that we often overlook when we practice is the number of people we need.

Speaker B: Well, and who would have thought about National Guard and hands on keyboards? That's. Those two are. You don't. Those are not usually thought of in the same sentence. Well, just sort of. Sort of wrap up. Um, if you can. Jim, uh, if without violating operational security, can you tell us anything about your Mustang mods?

Speaker A: Oh, uh, yeah. So I needed to teach myself AI because I got to defend it. You can't defend what you don't understand. So I have built or am building into my Mustang, uh, kit from Knight Rider. Uh, the hardest part was the 40 hours it took finding samples of his voice to clone it. But right now, uh, it's hooked into the OBD2 port, but it'll eventually be tied into the can bus. And the whole point of it is to uh, when I go out on the track, it'll monitor all the vitals of the car and like, so I don't have to practice on that. Eventually it'll um, help make me recommendations. Hey, you're 2 seconds or 0.2 seconds slower. Try breaking a little later kind of a thing. Um, um. But it's a lot of fun and you can also talk to it as an API call out that I can have it talk to it say hey, what's the wire like? Or tell me when the movie times are now that I'll do that while I'm racing. But um, no, it's, it's a fun. It was a really fun project to do. Still, uh, doing. Obviously I don't have a lot of time, but uh, when I finally got it booted up and running, it has visual recognition. So if I sit in front of it, it'll say hey Jim, if someone sits in front of it, doesn't know, it'll be like who. Who the heck are you? And then it'll, you know, memorize their face locally, not sending it off somewhere. But uh, it's been a lot. It's been a lot of fun. It kind of ties in all the products of 8i AI and taught me a bunch of different stuff.

Speaker B: Wow. So. So I have two. Two things. One, does it do you gonna put the little LEDs in the front.

Speaker A: Uh, so I'm gonna put it on. No, uh, because that would get me pulled over. But I am gonna put, um, I have a. You. A GUI I built that has kits. Know the four lines, the four red lines on there that it'll talk when m talking. Yeah.

Speaker B: The other is. This is. Of course I hadn't expected your answer and it's driving me crazy. I know the actor that does the voice. Uh, I think he passed away fairly recently. He's a pretty well known actor. Really. I like that guy.

Speaker A: So, yeah, he was super cool. There's a good documentary coming out about it soon. Um, an out night writer.

Speaker C: Really?

Speaker B: Yeah, yeah, he played John Adams in the. He played John Adams in the movie 1776, which I saw way back in the day. Um, uh, ever since then. Yeah, he's, he had done some cool things. So Val, that's, that's like to say people need projects, you know, you need. Especially, especially in your job. Everybody seems to need a project that woodworking is really popular. It seems something that you can focus on that doesn't have anything to do with, you know, your day to day job and you can just kind of shed it behind you. So, um, I, I look Forward to the YouTube video, uh, someday, uh, of how that works. You can um, maybe you can show something at the end of your, of your session at Hip in, in Nashville. Who knows?

Speaker A: I don't know if I'll be ready. We' we'll see.

Speaker B: Okay.

Speaker A: If I drive it up there, we can look at it.

Speaker C: Oh, I'll take a ride over the YouTube video. Okay.

Speaker B: That's a bit of a drive, but, uh, yeah, I'll just, I'll be happy to just see a. See a demo video of it, so.

Speaker A: Oh, no, if I'm going to Nashville, I'm stopping my tail the dragon. We'll do a whole road trip in Appalachians and then come to Nashville.

Speaker C: Oh, okay.

Speaker A: Yeah. So. All right.

Speaker B: Very fun. Well, thanks, ladies and gentlemen. Uh, I appreciate this. I thought it was a really interesting conversation and of course your perspective on um, the challenges, the unique challenge that healthcare has in crisis management and incident response is always appreciated. And uh, we will all be seeing each other in Nashville. Uh, Courtney, do you want to show the shirt?

Speaker C: Yep, I'll be there.

Speaker B: There's the hip Nash culture. What's the date again? September. I should know this.

Speaker C: Uh, eighth and ninth, I believe.

Speaker B: Whatever it says in your shirt, I can't read it from here.

Speaker C: Just says September. I don't think we had it decided September 8, Tuesday through Thursday after Labor Day.

Speaker B: Okay, well, there you go. Uh, and of course you can see this. You'll see this podcast and a whole bunch of other podcasts and information about the conference itself. There's my plug@hipconf.com so once again, thanks everybody. Thanks for joining me today and, uh, enjoy the rest of your week.

Speaker C: Thank you, Sean. Thanks, Jim.

Speaker B: Thanks so much for listening to the HIP podcast brought to you by Semperis, the leader in identity resilience. If you found this conversation valuable, subscribe to the show on YouTube, Apple Podcasts, Spotify or wherever you get your podcasts so you never miss an episode. And if you have a minute, please give us a rating or leave us a review as that really helps other listeners find the show. You can find past episodes and more information@hipcomp.com podcasts I'm Shawn Duby. Stay secure and I'll see you in the next one.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • How Zalando Deployed GenAI Without Handing Attackers the Keys with Florence MottayCyber Leaders · on Ransomware87 / 100
  • Why “Cyber Is Broken”, And Building Trust in an AI World - Karl Van den Bergh CMO IllumioCyber Go-To-Market Talk · on Ransomware87 / 100
  • Building a Cybersecurity Culture in Your Company (Encore)The Backup Wrap-Up · on Ransomware86 / 100
  • Secure AI Starts with EducationBuilding Unbreakable Brands · on Business email compromise86 / 100
  • ACH Rule Changes for 2026: What Treasury Needs to KnowThe Treasury Update Podcast · on Business email compromise85 / 100
  • Reframing Cyber Risk with Jane Frankland MBEBCG on Compliance · on Ransomware84 / 100

More from Hybrid Identity Protection Podcast

All episodes →
  • Agentic AI and the Authorization Gap No One Closed with Geoffrey Mattson, CEO of SecureAuth
  • Where Gartner Sees Identity Security Heading with Mark Diodati, Managing VP of IAM at Gartner
  • Why Identity Security Needs Its Own Program with Angie Klein, IAM Business Technology Manager at Federated Insurance
  • Securing Non-Human Identities in the Age of Agentic AI with Sarah Cecchetti, Director of Product Management at Semperis
  • 1 Thing to Do to Avoid a Breach: 5 Identity Experts Answer
Explore the best B2B Engineering & DevTools podcasts →
All Hybrid Identity Protection Podcast episodes →