The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Inclusive Cyber: Unlocking Innovation in Cybersecurity
Inclusive Cyber: Unlocking Innovation in Cybersecurity artwork

Smriti's Journey Proves Cyber's Talent Problem Isn't a Pipeline Issue. It's a Perspective Problem.

Inclusive Cyber: Unlocking Innovation in Cybersecurity · 2026-01-19 · 37 min

0:00--:--

Key moments - from our scoring

Substance score

54 / 100

Five dimensions, 20 points each

Insight Density11 / 20
Originality10 / 20
Guest Caliber12 / 20
Specificity & Evidence12 / 20
Conversational Craft9 / 20

Smriti's career trajectory challenges the conventional pipeline narrative that cybersecurity needs more computer science graduates. Starting as a biomedical engineer working on medical devices, she pivoted to cybersecurity after learning about insulin pump vulnerabilities - incidents that made her realize security and safety are intertwined disciplines. Her program management background proved directly applicable, allowing her to bridge technical security work with business objectives and cross-functional collaboration. She credits mentorship, systems thinking from engineering, and intentional skill-stacking (bringing existing expertise while learning cybersecurity) as her foundation. Danny and Smriti explore how organizations like Women in Cybersecurity, corporate mentorship programs, and cold outreach through LinkedIn can connect career-changers with advocates. They discuss certifications pragmatically: useful frameworks (like CISSP for program managers) but not gatekeepers. The conversation highlights that cybersecurity's real bottleneck isn't pipeline - it's perspective. The industry advertises only the stereotypical security engineer or penetration tester, overlooking how program managers, clinical staff, hardware engineers, and domain experts from healthcare, utilities, and finance all drive security outcomes. Smriti's story proves that non-traditional backgrounds bring systems thinking and cross-functional problem-solving that pure technical pipelines cannot.

Key takeaways

  • →Systems thinking from biomedical engineering - understanding how different functional areas interconnect - translates directly to effective cybersecurity program management and prioritization aligned with business goals.
  • →Medical device cybersecurity breaches like insulin pump hacking incidents can be powerful catalysts for career transitions, reframing security as a patient safety issue rather than just data protection.
  • →Mentorship and supportive management matter more than formal credentials for career transitions; cold outreach on LinkedIn, professional organizations like Women in Cybersecurity, and corporate mentorship programs are practical pathways to finding advocates.
  • →Cybersecurity's talent problem isn't a pipeline shortage but a perception problem - the industry promotes hackers and pen testers while overlooking how program managers, clinicians, hardware engineers, and domain experts drive security outcomes.
  • →Certifications should be chosen strategically to reinforce how you frame problems (e.g., CISSP for understanding business-security alignment) rather than pursued as generic credentials.

In this episode

  1. 1Smriti's Background: From Biomedical Engineering to Cybersecurity
  2. 2Systems Thinking and Program Management in Medical Device Security
  3. 3The Role of Mentorship in Career Transition to Cybersecurity
  4. 4Building Skills Without Traditional Cybersecurity Training
  5. 5Certifications: Strategic Goals vs. Requirement Debate
  6. 6Interconnectedness: Understanding Cybersecurity's Cross-Functional Impact
  7. 7Generative AI: Opportunities and Risks in Cybersecurity

Mentioned

SmritiDannyInclusive CyberSociety of Women EngineersWomen in CybersecurityVICESHack the BoxPMIPMP

Guests

Smriti

Topics in this episode

Systems thinkingbiomedical engineeringCISSP certificationHack the BoxMedical device cybersecurityProgram management (PMP certification)Women in CybersecurityGenerative AI in cybersecurityInsulin pump vulnerabilitiesCross-functional collaboration in security

Questions this episode answers

How do you transition into cybersecurity from a non-computer science background?

Bring an existing skill (like program management, domain expertise, or systems knowledge), find mentors through professional organizations like Women in Cybersecurity or by cold outreach on LinkedIn, be supported by an open manager, and self-educate through free courses, gamified learning platforms like Hack the Box, and targeted certifications aligned to your role.

What caused insulin pump recalls and why does it matter for cybersecurity careers?

Insulin pumps and medical infusion pumps had cybersecurity vulnerabilities that allowed attackers to alter drug delivery settings, putting patients at risk; these incidents made Smriti realize security and patient safety are two sides of the same coin and shifted her career focus to medical device cybersecurity.

Should you get cybersecurity certifications if you're coming from another field?

Certifications are valuable for framing how you think about problems (CISSP helps connect business goals to security) and give you an anchor goal to work toward, but they're not absolute requirements; choose them strategically based on your role rather than getting them indiscriminately.

Is mentorship in cybersecurity accessible if you don't have an existing network?

Yes - join professional organizations like Women in Cybersecurity, Women in Cybersecurity (part of ISSA), or look for structured corporate mentorship programs; you can also respectfully cold-reach out to people on LinkedIn whose work you admire and ask for a conversation.

Why does cybersecurity have a talent problem if there are many job openings?

The industry advertises cybersecurity as only pen testing and hacking, overlooking that program managers, clinicians, hardware engineers, and domain experts from non-tech fields all drive security outcomes; it's a perspective and marketing problem, not a pipeline shortage.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

11 / 20

The episode delivers moderate substance on career transition and non-traditional pathways into cybersecurity, but relies heavily on broad platitudes about mentorship, learning, and systems thinking without concrete frameworks or data. The discussion of medical device classification (Class 1-3) and FDA regulations provides specific value, but much of the conversation circles general advice ("reach out to mentors," "be curious," "have a goal") that experienced operators have heard repeatedly. Limited novel claims per minute justify mid-range scoring.

mentors can be anybody. They can be people that you really respect, or they've done a project that you're really inspired by
cybersecurity is not just security engineers doing risk management work. It's a lot of different areas

Originality

10 / 20

The core insight - that cybersecurity has a perspective/diversity problem rather than a pipeline problem - is stated in the title but underexplored in the transcript itself. The guest reinforces conventional wisdom about cross-functional thinking and regulatory constraints in medical devices without offering contrarian takes or first-principles reasoning. The discussion of AI in cybersecurity presents balanced but standard talking points (defenders vs. attackers, efficiency gains, risk mitigation) that circulate widely in the industry.

cybersecurity is the other side of the coin of safety. Right. So it's safety and security are the two sides of the coin
it's a completely different compared to your regular Silicon Valley tech company

Guest Caliber

12 / 20

The guest is a genuine practitioner with 5-6 years in cybersecurity program management at what appears to be a medical device company, providing relevant operational experience. However, she is not a senior executive, widely recognized expert, or proven thought leader in cybersecurity at scale. Her credentials are solid but mid-level; she brings real domain knowledge (medical devices, FDA compliance) but limited evidence of having driven major organizational outcomes or industry impact.

I am a program manager in cybersecurity
I've been a program manager for a while now. I think for about five, six years now

Specificity & Evidence

12 / 20

The episode includes some concrete specifics (insulin pumps, pacemakers, defibrillators, Class 1-3 device classifications, PMI PMP certification, NIST standards, EU MDR) that add credibility. However, much of the conversation lacks supporting data: no metrics on diversity gaps in cybersecurity, no numbers on hiring outcomes, no financial impact examples, and no specific company case studies beyond the guest's own experience. The regulatory discussion is more educational than evidential.

They were mostly pumps, insulin pumps, and um, medical pumps that had cybersecurity issues where you could actually alter the amount of drug that was delivered to the patient
Class 3 devices have extremely stringent regulatory requirements... Class 2 devices are like your ophthalmic devices

Conversational Craft

9 / 20

The host asks reasonable setup questions and follows some threads (mentorship, certifications, AI), but rarely pushes back, challenges claims, or probes for specificity. Follow-ups are largely softball confirmations ("That makes sense") rather than productive friction. The host pivots to books at the end without diving deeper into the guest's actual operational challenges, trade-offs, or failures. Missing are hard questions about how non-traditional hires actually perform or whether the diversity argument translates to measurable outcomes.

No, thank you for that explanation. I was completely ignorant about medical devices and different classes
Yeah, No, I love that response there, Smirthi, because I think the interconnectedness

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A69%
  • Speaker B31%

Most-used words

cybersecurity60different35devices35medical24program21cyber18management18security15learn15role15device14side14career13areas13thank12class12

Episode notes

hink you need a computer science degree to break into cybersecurity? Think again. In this eye-opening conversation, Smriti shares her unconventional journey from biomedical engineering to medical device cybersecurity, revealing how patient safety and security are two sides of the same coin. This isn't your typical "hacker in a hoodie" story. Instead, discover how systems thinking, strategic mentorship, and leveraging transferable skills can open doors you never knew existed in cyber. Whether you're considering a career transition or questioning if cybersecurity is only for the technically elite, this conversation will challenge everything you thought you knew about entering the field. Key Themes: 1. Your "Non-Technical" Background Is Actually Your Superpower Why cybersecurity desperately needs diverse perspectives from biomedical engineering, healthcare, and beyond. Smriti breaks down how her engineering mindset became her competitive advantage, not a liability. 2. Medical Devices Can Kill: Where Cybersecurity Meets Life and Death The chilling reality of hackable insulin pumps and pacemakers.

Full transcript

37 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign.

Speaker B: Thank you for joining me here on Inclusive Cyber. How's it going?

Speaker A: Everything is going great, Danny. Thank you so much for having me. I'm so excited to have this conversation with you.

Speaker B: Yeah, I know we've been going back and forth because, you know, life gets in the way, which is fine, but can you provide a quick background for the audience on who, you know, where you've been so far in your career?

Speaker A: Yes. So, hi, everyone. Hi, all Inclusive Cyber listeners. My name is Smriti and I am, um, a biomedical engineer by background, and I've kind of taken a scenic route to cybersecurity. So I've done a few different things. I started off in, um, medical device testing and development and then kind of worked my way through different teams and different roles into the cybersecurity field. So it has not been a very linear path to cybersecurity, but I think they're very interconnected in many ways. So biomedical engineering, device development and cybersecurity all share a common theme, which is patient safety and people safety and security, which kind of is the common theme that I see in all of these three areas that I've worked in.

Speaker B: I appreciate your quick overview of your background, Smirthy. Um, I definitely agree. I think one thing that we're missing here in cyber is people are looking for the traditional background into cyber. And what I mean by that is going through school, computer science degree, kind of electrical engineering degree, and kind of going up the ranks. But I think with your background, um, you know, biomedic, um, engineer, and just the medical field as a whole that's adding and enriching cyber security as a whole, because we need different ideas. And something that I've kind of, uh, pontificated on social media is that we need new ideas. And the only way we're going to get that is bringing in more people from other backgrounds and professions. So definitely resonates with me. So let's, um, let's start off. Why? What got you interested in your, um, biomedical engineering?

Speaker A: Um, absolutely. So I've always wanted to add value to people's lives as part of my career. So I wanted to do something that has a tangible impact on people. Um, and biomedical engineering and biomedical sciences was something that has always interested me. It's kind of that sweet spot where between medical sciences and engineering, two areas that I'm very interested in, and I went to college for it, and I really liked the electronics and instrumentation side of things, and I also really liked kind of the patient side of things and the clinical side. Of things. So I felt like it gave me so many different areas to work with. It gave me kind of that understanding of systems kind of doing systems thinking, understanding how different systems connect and interact, but at the same time the use, the security and the reliability of devices being at the forefront of that product as well. So I am a person that likes kind of that diversity in the m work that I do. I don't think I do very well just being stuck to like one doing the same thing every day. And biomedical science has kind of opened this world up to me where I could experiment with different areas. So even in my master's program I noticed that there were my peers who were working on um, very math heavy areas of biomedical sciences where they were doing imaging and you know, all of those uh, types of very math heavy areas. And there was this completely different group of like cell and tissue engineering and there was that world going on all under the umbrella of biomedical sciences. So that's what got me into uh, this, this field of biomedical engineering and just kept me interested, has kept me interested so far.

Speaker B: So, uh, you mentioned a lot of great things, but I want to kind of pull uh, the thread on one because I'm reading a lot on this and kind of listening to podcasts. System thinking. So can, can you break down? Because I'm still trying to learn myself on kind of system thinking and then even the science as a whole, it's about um, experimentation, right?

Speaker A: Absolutely.

Speaker B: Something that we don't do in cybersecurity. So if you can, I guess, you know, talk about system theory, um, and systems thinking just to provide some, some additional context.

Speaker A: My experience with cybersecurity has been that that system thinking has kind of tied in one on one with my kind of, my experience and my role in cybersecurity. Uh, because cybersecurity is not just security engineers doing risk management work. It's a lot of different areas. The patient safety and security is at the forefront. The clinical side is at the forefront. You have to think about the regulatory side of things, you have to think about the business goals and how all of these efforts kind of tie into the business goals. So I think that interconnectedness of different areas and understanding the interconnectedness of those areas, not working in silos and having that kind of overall high level picture of what is it that I'm trying to do and how does this impact the various tentacles that is branching out and it's connected to, is very important. Um, that is something that you learn as part of engineering and you utilize as part of your biomedical degree or sciences or work that you do. But that has also for me, my personal experience translated into my program management role in cybersecurity. Currently I'm a program manager in cybersecurity and my role is very focused on how these different initiatives that I work on are, ah, tied to business objectives. They have to have business value. You cannot be just thinking about it in its own kind of vacuum. You need to understand how it affects your patients, what kind of risk does it have? But at the same time, what is the work that you're doing? How do you prioritize that in accordance to, uh, the business goals and objectives that you have? And some things just fall off because they may not make sense. Right. So that understanding is very essential.

Speaker B: Thank you for that background. Uh, Smirthy, especially the other thing you just mentioned, business value. Again, in my experience within cybersecurity and all the different roles that I've had, we miss that, uh, right, we're, we're in that silo, our own bubble, talking technical with each other. But then we miss kind of that holistic picture and what is influencing cyber as a whole within the company and maybe even outside of the company. There's this book, and I'll mention it probably later in the show, that looks at it from a kind of the system theory and looking at outside of cyber. So thank you for that perspective. Um, so walk me through the steps. So you're in biomedical sciences. How did you navigate towards cybersecurity? Was it a class? Was it a colleague, a professor?

Speaker A: So, um, when I was working in medical devices, I heard a few different stories and instances of medical devices being recalled because of cybersecurity potential cybersecurity issues or vulnerabilities in those devices. Um, they were mostly pumps, insulin pumps, and um, medical pumps that had cybersecurity issues where you could actually alter the amount of drug that was delivered to the patient through a cybersecurity kind of hacking the system and uh, changing the settings of the device. That changed my entire perspective of cybersecurity because until that point, for me, cybersecurity was data, uh, data security, that kind of, that perspective on cybersecurity. But when I understood the patient safety aspect of cybersecurity in medical devices, it completely changed my perspective into, uh, you know, cybersecurity being the other side of the coin of safety. Right. So it's safety and security are the two sides of the coin. They have to go hand in hand. I started reading more about it. I started Reading articles online and educating myself about medical device cybersecurity and kind of understood how important it is to have cybersecurity as part of medical device development, uh, in the development phases itself. Then I started looking for job opportunities and mentors have really kind of helped me, coach me and you know, understand the benefits of being in this field. So I did not have formal training in cybersecurity. I did not have any certifications earlier, uh, on uh, but I reached out to a few people who had experience in the field who were able to provide very valuable insights and information about what would it be like working in a medical device cybersecurity role. And that is what really gave me the uh, kind of the interest and the courage to apply and go forward with taking a role in cybersecurity, uh, despite not having formal training, training in that, in the area.

Speaker B: So I think you, you segue perfectly into my next question about mentors. So did you have people in your network, was it employees that you reached out to? I guess just trying to understand because the reason I'm trying to kind of uh, pull the thread a little bit, I get a lot of responses on LinkedIn or emails to say he, how do I find a mentor in cybersecurity? And then I kind of, you know, proceed with that. So if you can shed some, some light on exactly how that uh, transpired.

Speaker A: Absolutely. So I think for everyone, um, that's in a, in a career trying to advance in their careers or is really invested in their careers, I think it's very important to be um, very thoughtful about how you approach your career and how you reach out to mentors. Mentors can be anybody. They can be people that you really respect, uh, or they've done a project that you're really inspired by. They conduct themselves in a way that you really uh, look up to. It could be anyone or it could be through a professional organization. So earlier on in my career when I was in college, I would be part of society of women engineers. There were a lot of different organizations like STEM organizations that were very useful to kind of be in a group of like minded people and be mentored by individuals like professors who were kind of further ahead in their, and were able to provide valuable guidance. And in corporate environments there are also structured mentoring programs a lot of times. So I would say uh, being a part of those are also really great opportunities. I personally was a part of those. And the benefit of being in a corporate mentorship program is that you can, apart from uh, developing your career and Advancing your career. You also learn how to navigate that specific corporate environment, which is very useful for a lot of people, especially for me, because you really need to understand how that organization works and what is really required in that organization. But apart from those few examples that I provided, there are also many standalone organizations that offer mentorships. There's, uh, vices is one that I've seen. Women in Cybersecurity is one. There are multiple organizations in cybersecurity, uh, that offer mentorship programs that have online presence and on LinkedIn as well. So, uh, I would look up, look them up, um, and sign up for those, to have those opportunities to connect with mentors. I personally am not connected to any specific cybersecurity mentorship, uh, organizations. What I did was I reached out to people that I found on LinkedIn. I just cold reached out to them, uh, connected with them, set up time with them. Um, there are also career coaches who kind of help you with the transition into a different, uh, area like cybersecurity that can, that can guide you. But for me, it was, um, more reaching out to people that I respected or I thought were doing something cool and asking to set up some time and, you know, just have a conversation with them.

Speaker B: No, Smirthi, thank you for, for that great advice there. Definitely makes sense. Just at the end of the day, you know, um, go local to these, uh, organizations and just ask, right? Just have that courage. Because a lot of people, they might be introverts, they might not reach out to folks, but at the end of the day, if you don't say anything, then, you know, nobody's gonna hear, uh, what, uh, what you need or want there. So great advice. Um, so then you get all of this help from, from your mentors, kind of looking at devices, medical devices that can be hacked and stuff. So you said you started applying to which one was your first one and what were you doing?

Speaker A: So this is my first job, so in program management, in cybersecurity. So I have been a program manager for a while now. I think for about five, six years now. I've been in program management. So, um, that was actually helpful because I had the basics of program management kind of sorted so I could take that expertise and bring it to a different field or a different area. So I think that might work for someone who's trying to get into cybersecurity is if you have a base skill that you can kind of bring into cybersecurity, you have that kind of footing, uh, in the ground of, okay, I know program Management, I can deal with this. And then you have just one variable that you have to kind of pick up on and learn. So I think that is what I did. I, uh, knew that I can bring my program management skills and then I can learn the cybersecurity side of things. Um, so this is my first role. Although what I absolutely did from the get go was starting to learn for cybersecurity. I think there's so much content out there, there's so much information, there's so many trainings, free trainings, uh, courses, boot camps, you name it. You have, like, cybersecurity is a hot field right now. Like, there's a bunch of stuff out there. So the content is really good. Um, and a lot of times the content is really good. And it's very intuitive. Like, it's interesting, it's intuitive. And there's also like very gamified systems like hack the box that you can kind of play around with and get really up to speed with how to do, you know, red teaming, kind of learn the concepts, learn the jargon, learn the language. So I did all of that because I was interested in the field and kind of that program management, uh, expertise gave me that kind of that solid foundation of I can do the program management side and now I can learn the cybersecurity side. But I also want to say this is where the mentors really come in, right? Because, um, in my role, uh, current role, also my manager, my mentor, they've all been extremely supportive and understanding of the fact that I did not come from a traditional cybersecurity area. Um, so my manager really gave me the space to grow into the role from a technical standpoint, gave me the opportunities and the space to do that. Um, and my mentor, who I kind of sought out and work with, she kind of gave me the kind of the, uh, background on the organization and kind of the support I needed from that standpoint. So I think that's a recipe that I think is very helpful for anyone to kind of be successful in a new role or area that they step in is to reach out and find the right team to work with, the right manager to work with, and also go and find that mentor who will kind of make your journey a lot more easier for you.

Speaker B: Yeah, I love that, Smirti. Uh, especially just, uh, connectivity with people and then having that radical curiosity, right? Trying to learn. And again, you know, a lot of people might not have good, um, mentors or may. They might not have mentors or good bosses and they might not have that opportunity. So that's great that uh, at least the people that you're working for are open for, for you to learn and grow into, into your role. Um, so as you were learning, did any of your mentors guide you towards certifications? Hey, you need to get all these certifications.

Speaker A: Yes.

Speaker B: Um, and if they did, which ones, um, did uh, did you ultimately go for?

Speaker A: So my mentor actually guided me. So I was doing a lot of different certificate like certification prep all together at once. And I have a toddler, so I was like all over the place. I was like doing my full time job and doing like being very confused. And then my mentor said, you know what, you know, you should probably do like the program management pmi, PMP cert, because you have the background for it. You've been working in program management, so why don't you just get it done? And she's like, I did it in like, uh, I studied in like a week and I got the cert. Like she really gave me, made it sound very simple and gave me the confidence for it. Uh, and she's a really like cool, fun person. Uh, she's uh, she's really technical but also really fun as a person. So she kind of gave me like the spiel of oh, it's going to be just one week and you, you'll be done. And I was like, okay, I guess. So I went and I got that cert. And I have to tell you that even though I'd been in the industry doing program management for a while, going through that certification for program management has been extremely helpful. And similarly for uh, cyber security, I'm currently working towards my system certification because I'm in program management. That is the one that I feel fits the bill the best with what I'm trying to do. Because it really talks about your objectives in cybersecurity and the business objectives and tying them together and having that connection. And I think these certifications are designed to kind of help your mind think and frame things in that way. I don't think you absolutely need certifications to be successful in your job, but they do have their place and they do help you frame things in a way that makes sense in your organization. So I would say be mindful and thoughtful of the certifications that you pick. Uh, but have a goal, you know, it kind of helps you learn, continuously learn. I like that. That's what I like. I like having a goal and then I like to get there and be like, okay, give myself a pat on the back and then do the next thing, right. It's like something to work towards for sure.

Speaker B: Yeah. No, thank you for, for your perspective on that smear, uh too, because a lot of people, that's the million dollar question, right? That either transitioning professionals or uh, students coming out of school, which certification should I get? Or on the flip side, should I go to school? And for me, I think we probably share the same kind of philosophies when it comes to certifications. Um, I never want to question the knowledge gained from any of the certifications, but whether or not you need, you know, here's my prop, a piece of paper to tell you that you are good on X, Y and Z. That's, you know, that that's I guess subjective. Right. But um, a lot of people in our industry, they look for those certifications and if you don't have them, you unfortunately don't have um, that opportunity to even try to find uh, you know, a job there. So it's kind of a balance that people, uh, must weigh. Um, but the other thing too, you have to have that goal because another thing that people do is I want to get into cyber and I'm like, um, okay, what part it is? It's just like I uh, want to be a doctor. Okay, well what time for doctor.

Speaker A: Right.

Speaker B: So there's this depth and breadth primarily, breadth of different roles within cyber that I would argue that there's some technical aspects obviously, but then there's some non technical aspects in cyber as well. And I like your, your advice about going through that program management route. Um, I went through the bootcamp, um, this was several years ago, but I never, I got lazy and never went for, for the certification there. So I have the knowledge somewhere in my mind.

Speaker A: It's a four hour exam. So you really, it's like these exams are like four, three hour, four four hour exams. I'm like waiting for it to end. So it is, it is a task for sure, but it's, it's kind of a nice anchor for you, you know, and it gives you something to work towards which I think is it's good, um, good for everyone to kind of have that goal in mind.

Speaker B: Yeah, definitely agree. So now being in the industry for roughly five or six years, what has surprised you about the industry, about the cybersecurity industry?

Speaker A: It's the interconnectedness of the different groups that work in cybersecurity. Because prior to being in the cybersecurity role, I always thought cybersecurity was pen testers, security engineers, you know, just a few People kind of working on figuring things out in their little group. Right. But now that I'm in the cybersecurity world, I see how it affects everyone that's working on a device and then the patients as well. That interconnectedness and that cross functional, um, structure is what has really been a standout, um, you know, a standout thing for me for cybersecurity for sure. So it's uh, from the development side of things, where you're trying to do secure development, hardware from a hardware side, from a software side, the clinical aspect, kind of all of those things tying in together for cybersecurity has been a big gotcha for me, for sure.

Speaker B: Yeah, No, I love that response there, Smirthi, because I think the interconnectedness, I think a lot of people in society don't really understand how much cyber plays into all our lives. Like for right now we have utilities that are providing electricity. So we can have this conversation here. But if that goes down. Yeah, then, you know, it affects a lot of people. So, you know, I think overall we don't really understand, I think, to your point. And it could be something that we in the industry kind of push out, that, oh, it's all about the pen testers, it's about the hackers. Right. Wearing the hoodie. But there's way more to that and it's attached to our financial industry, it's attached to utilities in your field, in the medical field. So it is way more integrated with society than I guess people realize or we don't advertise enough.

Speaker A: And I think that's the best. I think that's one of my favorite parts of cyber security is the diversity in how different teams kind of connect and interact for cyber security. And that opens up cybersecurity to so many different people in different areas. Right. Like your podcast is called Inclusive Cyber. It's kind of talking to the same thing, in my opinion is getting people from all these different areas and walks of lives who work in cybersecurity and it's kind of saying the same thing. So, yeah, I think that aspect of how all of these different teams are affected by cybersecurity and work towards it has been, uh, a great kind of revelation for me for sure.

Speaker B: Definitely. So let's transition to the word of the millennia. The word, the phrase that we keep on hearing constantly. Generative artificial intelligence. So what are your initial thoughts on that and how, how have you played around with it and how is it helping you in your, um, in your work?

Speaker A: So I think like, everything It's, I have a balanced outlook towards generative AI. There are pros and cons to it. So when I think about it from a cybersecurity perspective, it definitely helps you uh, strengthen your defenses against attacks, does uh, data collection much quicker, looks at and does analysis much quicker. So it kind of increases your efficiencies in how you are uh, reviewing your data and how you are able to respond to threats and vulnerabilities that are out there for sure. Uh, and there are many companies that are training their models on local data, right? So they're just training their models on local data. They're not sharing their data across platforms or across companies. So it's kind of uh, in its own, uh, controlled environment. But at the same time on the flip side it makes it so much easier for, you know, threat actors who don't have very advanced skill levels can gain the ability to do more advanced attacks. Uh, we need to be prepared as companies and organizations on how to perceive those potential threats and then plan for mitigating those activities. So I think that's my view. I do think there are efficiencies that are gained with generative AI in cybersecurity and it's inevitable. We are kind of as a world, we are moving in that direction, slow down that wagon right now. But what we need to do is also understand with these efficiencies gained there's like the bad actors who have access to the same technologies and what are they going to do about it, what are they going to do with it and then how can you be prepared for those potential issues that arise, um, with those kind of, with those areas. For me personally I use AI mostly in my program management role, um, for efficiencies in the work that I do. So for simplifying my tasks I also use AI quite a bit with um, my knowledge related activities. So if I have to learn something or if I have some cybersecurity terms and any topic that I want to deep dive into, I can really dive deep using AI tools. So that's kind of the extent to which I use AI in my role right now. But I think with cybersecurity there is going to be a lot of AI usage, both from protection security standpoint, but also we need to be prepared and put the guardrails for it from a standards, um, point of view, which I don't think we've set in place as much as now, but it's something that should be set in place.

Speaker B: Yeah, no, it's definitely going to be A race between the attackers and then the defenders and who's going to get there first. Right. I think the way you're using it is kind of the way I use it, kind of more in the writing aspect as well, and which is great, but I think people are looking for more like that killer app. What is the killer app that AI is going to do, but to kind of juxtapose two different concepts here. So Silicon Valley is, uh, their ethos is move quick, break things and repeat. And now when you look at the medical devices, like you mentioned, so how do you balance that where it's a business proposition, we need to get this outside the door so we can make the money. But then how do we slow it down to introduce that security?

Speaker A: So medical devices is a highly regulated industry because of, in the US because of FDA regulations, and in Europe because of regulations like the EU mdr. For example. So even if you wanted to move fast and break things, there's a lot of regulations in place that will prevent you from moving fast. So it's a. I feel like it's a completely different compared to your regular Silicon Valley tech company. So in that perspective, I think for medical device and cybersecurity, there's already a lot of regulations in place that prevent you from, um, implementing features that are not thoroughly tested, uh, for safety, security and usability of the device. Um, which is a good place to be in because it kind of stops you from doing that. Um, but generally from an industry standards perspective, something to fall back on for all industries. Right. Not just medical devices, or not just specific industries. I think there should be, um, a base set of regulations that are identified for these tools and then you can customize them for your specific industries. So for medical devices, it might be certain NIST standards or other standards that you customize that meet the needs of the medical device industry. For class devices. So class one devices, class two devices, class three devices, you have specific regulations tied to AI for those classes of devices. I think that's how I conceptualize regulations kind of coming in for AI and uh, in cybersecurity within the medical device industry.

Speaker B: Can you talk a little bit about the classes I'm not too familiar with?

Speaker A: Yeah, so Class 3 devices are like your pacemakers and your defibrillators. They are the implantable devices. Right. That are, ah, very, that are invasive, that have a huge impact, um, on the patient. And then Class 2 devices are more like your ophthalmic devices. Um, so it's based risk classification, your devices, uh, the classification of Your, the classes of your devices are based on the risk classification of the devices. So class three is your highest risk. Like your, uh, implantables, your defibrillators, your pacemakers. Class 2 devices are like your ophthalmic devices. Like if you go to an eye doctor's office, the devices that you work with. And then class one devices are like your dental, the tools that the dentist's office uses. So very simple tools, very simple devices. Right. So those are the three different classes of, of medical devices, and the regulatory requirements for each of these devices are different. So Class 3 devices have extremely stringent regulatory requirements. So for those pumps that I mentioned at the start of our podcast, where you could potentially program and change the amount of drug that's delivered to a patient, those devices, uh, like infusion pumps, for example, or diabetes pumps, for example, have a very stringent regulatory requirement compared to something That's a Class 2 device. Right, so your regulatory requirements are different. So the FDA looks at these devices differently and applies, uh, a different set of regulations for each of these classes of devices.

Speaker B: No. Thank you for that, Smirthi. And then I'm assuming they do audits or they get a third party to kind of break the system to see what type of.

Speaker A: Absolutely, yes. So the audits. Both. So usually there are FDA audits as well. Um, but there are a lot of third party audits that companies just proactively do to make sure that their design history file is all good and set up the right way, and all the risk management activities are up to date and all of the documents are reviewed and documented in the right place. Um, so there are these stringent reviews that happen in medical device companies to make sure that, uh, you are meeting your requirements. And the safety, security, uh, and reliability of your device is always, um, good to go and you're compliant.

Speaker B: No, thank you for that explanation. I was completely ignorant about medical devices and different classes. So thank you for that clarification. And it makes sense. Right? Um, we always want to, to your point, cyber is about protecting people. Same thing with the, with the medical field. So it's a combination of, uh, two different, um, kind of domains coming together with the same mission. Right? Protecting, Protecting, uh, people at the end of the day. So where do you see yourself, I guess, navigating in your career? What would be the next logical step, um, that you'd be looking for?

Speaker A: So I have tied myself very strongly to, like a specific five year plan for myself. What I really want for myself is to keep learning and keep seeing myself incrementally grow in my career and improve in my career. So I want to, uh, I want to be a little flexible with how I move and change in my career because I've noticed that when I've done that, it has always led me to interesting career paths like this one that I'm m in right now, which is cybersecurity. I did not think I would be in cybersecurity, uh, five, six years ago, and here I am now. So I want to keep myself flexible. I am interested in the leadership path. I really enjoy working with people. Being in program management, I get that opportunity to work with people. And with cybersecurity training and development and work experience that I'm building, I'm hoping to move into a leadership role, uh, in cybersecurity sometime in the future.

Speaker B: Now that's, uh, great to hear, Smriti. Uh, so I know we're coming up here, uh, on time for, for the podcast. So the way I like to end the podcast is books. So as you can see here, my, in my left corner, uh, here's a, uh, bookcase full of books that I just buy books and I'm like, in the middle of ten different books here. So, um, but, um, I got this from another podcast called Consulting Success Podcast. And all the, um, the guests, the hosts would ask them, what book are you currently reading that just resonates with you? So in this case, it doesn't have to be about cyber. Some people, obviously, they're going to read their cyber books and, you know, recommend that, which is nothing wrong with that. Somebody had recommended a fantasy book. It's like, I don't want to say it. I'm like, no, say it.

Speaker A: It.

Speaker B: I think the way we're going to help our industry is when we get ideas from other different, um, areas of expertise, whether it's fantasy, whether it's medical, whether it's sports, et cetera. So with that being said, Smriti, what books, um, would you like to share with the audience that you've read or are currently reading?

Speaker A: Very books recently that my, my friend lent it. So she read the book and she gave me. So you have to read this book. This is really good. And everything was against them. Backgrounds. Uh, most of them did not get along well with each other. When they came together as a team and just focused on that task that they were doing, they were able to experience flow and they were able to work in unison. It's a true story and it's a very inspiring story. So I have been, um, very inspired by that book because it talks about resilience and how you need to bring that into every aspect of your life. Um, even if things are kind of going and you're trying. You feel like you're swimming upstream. Yeah.

Speaker B: No. Thank you for sharing that. I'll make sure to put that in the show notes. Smirti M. Thank you for taking the time to chat with me. This has been an awesome conversation.

Speaker A: Thank you, Danny, for your time as well. This has been great. I really enjoyed chatting with you.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Allie K. Miller: Find your "weirdos" - and let them leadWorkLab · on Systems thinking85 / 100
  • From Trust to Action: The Skills That Make Teams Actually WorkTeamwork - A Better Way · on Systems thinking85 / 100
  • Medical Device Cybersecurity Is Tricky [The Industrial Security Podcast]The Industrial Security Podcast · on Medical device cybersecurity85 / 100
  • Sense-Making Through Uncertainty: Stories, Signals, and Swarms with Dave SnowdenHumanity At Scale: Redefining Leadership · on Systems thinking76 / 100
  • Dashboards Are Dead with Ankita PoddarHRchat Podcast · on Systems thinking74 / 100
  • The CRO Environment and Autonomous AI Agents with Jonathan M K.The CRO Spotlight Podcast · on Systems thinking74 / 100

More from Inclusive Cyber: Unlocking Innovation in Cybersecurity

All episodes →
  • AI, Adversaries, and the Human Problem in Cyber | Fireside Chat with Max Margolis59 / 100
  • Lavanya's Take on AI, Cyber Jobs, Social Media, and the Future of Tech35 / 100
  • Sofia Rodriguez on Breaking Into Cyber: The Entry-Level Trap, Help Desk Reality, and Networking57 / 100
  • Never Assume Anything: Stacy O'Mara on Policy, Breaking Into Cyber, and Why Basics Still Fail63 / 100
  • Why Cyber Intelligence Professionals Are Stuck in the Shadows with Melissa
Explore the best B2B Engineering & DevTools podcasts →
All Inclusive Cyber: Unlocking Innovation in Cybersecurity episodes →