The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Our Cybersecurity Mission
Our Cybersecurity Mission artwork

Our Cybersecurity Mission: The Vulnerability Audit Episode

Our Cybersecurity Mission · 2026-06-29 · 19 min

0:00--:--

Key moments - from our scoring

Substance score

33 / 100

Five dimensions, 20 points each

Insight Density6 / 20
Originality4 / 20
Guest Caliber10 / 20
Specificity & Evidence7 / 20
Conversational Craft6 / 20

Vulnerability management is not a one-time task but a continuous process requiring ongoing monitoring and patching across all systems - endpoints, servers, switches, and hardware - according to Mike Petucci, a senior information security auditor at Kirkpatrick Price with over 25 years of healthcare IT and security experience. The episode explores why static, infrequent updates fail against adversaries constantly evolving their attack methods, and outlines Petucci's audit methodology: first establishing a complete asset inventory (where many organizations discover forgotten systems in closets), then validating that stated policies match actual practice through tools and evidence. Organizations should patch critical and high-severity vulnerabilities within 15-30 days, update operating systems monthly at minimum, and implement a testing process before broad rollout. Petucci emphasizes that auditors validate compliance with an organization's accepted risk level and documented procedures rather than imposing standards - though practices like annual-only patching trigger exceptions as non-industry-standard. The conversation also covers personal cybersecurity hygiene, with Petucci advising users to avoid clicking suspicious links and instead call companies directly using verified phone numbers. Kirkpatrick Price has issued over 20,000 reports to 2,000 clients worldwide.

Key takeaways

  • →Vulnerability management is continuous monitoring and updating across all hardware, software, and applications - not a one-time implementation of antivirus.
  • →Many organizations fail to inventory all their assets (servers in closets, network hardware) and only focus on visible endpoints, creating blind spots for attackers.
  • →Critical and high-severity vulnerabilities should be patched within 15-30 days of patch release, with mediums at 60-90 days, following industry frameworks like CIS benchmarks.
  • →Auditors validate that organizations follow their stated security policies and procedures rather than imposing one-size-fits-all rules, flagging only practices that deviate from industry standards.
  • →Individual users should verify suspicious communications through established phone numbers or channels rather than clicking links, and should think critically before responding to urgency-based phishing attempts.

In this episode

  1. 1Introduction to Vulnerability Management
  2. 2Mike Petucci's Background in Healthcare IT and Security
  3. 3Asset Inventory and the Vulnerability Audit Process
  4. 4Continuous Monitoring vs. One-Time Updates
  5. 5Vulnerability Prioritization and Remediation Timelines
  6. 6Industry Changes and Growing Security Awareness
  7. 7Practical Cybersecurity Advice for Consumers
  8. 8Configuration Management Best Practices

Mentioned

Kirkpatrick PriceAli KringsMike PetucciMcAfeeCIS benchmarksM. Wayne Clement

Guests

Mike PetucciM. Wayne Clement

Topics in this episode

risk assessmentvulnerability managementPhishing and social engineeringConfiguration ManagementKirkpatrick PriceAsset InventoryPatch ManagementCIS BenchmarksHealthcare IT SecurityCompliance Frameworks

Questions this episode answers

What is vulnerability management and why can't organizations just patch systems once a month or quarterly?

Vulnerability management is a continuous process of monitoring and updating hardware, software, and applications across all systems - not a one-time task. It cannot be done monthly or quarterly because hackers and bad actors change their tactics constantly and are always attempting to find ways around protections, so organizations must maintain continuous monitoring and patching.

What is the first step Mike Petucci takes when auditing a company's vulnerabilities?

Petucci starts by validating that the organization has a complete asset inventory and knows everything it needs to protect. He takes a sample set of systems to review, as many organizations don't realize they need to protect servers, hardware switches, and equipment in closets - not just endpoints like computers and phones.

What are the recommended timelines for patching critical, high, medium, and low severity vulnerabilities?

Critical and high-severity vulnerabilities should be patched within 15-30 days of patch release; mediums within 60-90 days; and lows within 90 days. Operating systems should be updated at least monthly as a bare minimum, and patches should be tested on a sample set before full organizational rollout.

What personal cybersecurity advice does Mike Petucci give to home users to avoid being hacked?

Petucci advises: don't click links in suspicious emails or texts, even if they appear to be from legitimate companies; instead, call those companies directly using phone numbers from official sources like the back of your credit card or a known website. Think critically before acting - for example, ask whether a utility company would email you about an overdue bill or whether you were actually in the area for a toll charge.

How does Kirkpatrick Price maintain objectivity during security audits?

Auditors validate that organizations follow their documented procedures and policies rather than imposing personal preferences. They flag only practices that violate industry standards or best practices - such as patching once yearly - while accepting less frequent patch schedules (e.g., monthly) if the organization has completed a risk assessment and documented that approach in policy.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

6 / 20

The episode is mostly introductory-level vulnerability management content - patching cadences and asset inventory - with a large portion devolving into consumer phishing advice ('don't click') that adds little value for B2B operators. The few actionable data points (patching timelines) are brief and widely known.

you can't protect what you don't know you have
criticals and highs um, will have to be updated within 30 days for most of the major frameworks

Originality

4 / 20

Nearly every point made - continuous monitoring, asset inventory, phishing vigilance, patch testing on a subset - is standard cybersecurity boilerplate. There are no contrarian arguments, first-principles reasoning, or novel frameworks; even the 'we're our own worst enemy' observation is a familiar trope.

I think the biggest change that I've seen, um, is that it's not as much in the industry that has changed, um, but in the people's awareness
we're our own worst enemy sometimes

Guest Caliber

10 / 20

Mike Petucci is a genuine practitioner - 25 years in healthcare IT, former Director of IT and CISO - who has done the work on both sides of the audit table, which gives him credibility. However, he is not a particularly high-profile operator and represents a mid-market auditor role rather than someone who has scaled security programs at a notable organisation.

I've got over 25 years in, uh, healthcare, information technology and security
for the last eight or nine years, uh, in that career, I was their Director of Information Technology over all of it, as well as the Information Security officer

Specificity & Evidence

7 / 20

The episode provides a handful of concrete patching timelines (15 - 30 days for criticals/highs, 60 days for mediums, 90 days for lows) and a passing reference to 20,000 reports to 2,000 clients, but there are no named client examples, breach case studies, cost data, or framework citations beyond vague references to 'major frameworks.'

highs and criticals. Normally between 15 and 30 days should be um, implemented and then you can do, your mediums can go out to 60 days or 90 days for your lows
We've issued over 20,000 reports to 2,000 clients worldwide

Conversational Craft

6 / 20

The host structures the conversation reasonably but asks predominantly soft, leading questions and offers effusive praise mid-interview rather than pushing for depth or evidence. There is no meaningful pushback, no challenge to vague claims, and the conversation is redirected toward consumer-level advice rather than operator-relevant detail.

You know it's not very often that we get the chance to sit down with Somebody who has such a wealth of experience
How do you maintain um, that impartial kind of non biased attitude when you are going into an audit like this?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B66%
  • Speaker C26%
  • Speaker A5%
  • Speaker D3%

Most-used words

click14systems12antivirus9information8security8everybody8aware8cybersecurity7management7auditor6change6vulnerability6protect6phone6today5mike5

Episode notes

In this episode, host Allie Krings sits down with Michael Petucci, Senior Information Security Auditor at KirkpatrickPrice, who brings over 25 years of experience in healthcare, IT, and security to the conversation. What does vulnerability management actually look like from an auditor's perspective? Michael walks through how he approaches an audit, why organizations are often surprised by what they find in their own asset inventory, and what best practices actually look like when it comes to patching, prioritizing, and staying ahead of threats. Plus - his number one piece of advice for everyday people trying to protect themselves online. Spoiler: don't click. At KirkpatrickPrice, we're on a mission to help 10,000 organizations raise the bar for cybersecurity and compliance.

Full transcript

19 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: We believe if you're going to do it, the audit should be worth it. The problem is audits are hard. Yet We've issued over 20,000 reports to 2,000 clients worldwide.

Speaker B: Unfortunately, um, the hackers and the bad actors out there aren't just doing changes once a month. They're changing things all the time.

Speaker A: Cybersecurity and compliance will no longer be a mystery.

Speaker C: Hey, everyone. Welcome into our cybersecurity mission. My name is Ali Krings.

Speaker A: I'm your host.

Speaker C: Today we're sitting down with Mike Petucci, a senior information security auditor here at Kirkpatrick Price. Mike, thank you for joining me.

Speaker B: Thank you for having me.

Speaker C: So, a senior information security auditor.

Speaker B: Yes.

Speaker C: How long have you been here at kp?

Speaker B: I've been at KP for about three and a half years now.

Speaker C: And tell me a little bit about your background.

Speaker B: Uh, I've got over 25 years in, uh, healthcare, information technology and security, and, uh, then started here.

Speaker C: Wow. So were you on the other side of the audits before?

Speaker B: Yeah, for, uh, quite a while. I was a manager of the, um, networking, um, side of the IT house.

Speaker C: Oh, very cool.

Speaker B: And then, um, uh, for the last eight or nine years, uh, in that career, I was their Director of Information Technology over all of it, as well as the Information Security officer.

Speaker C: So why did you want to change direction? Rather than being the one that gets audited, why did you want to be the auditor?

Speaker B: I didn't see it as really a change in direction as much as it was allowing me to help a, um, a lot more organizations other than just staying in one organization.

Speaker C: Awesome. So having that experience and background in healthcare, has that proved to just be an asset as an auditor?

Speaker B: I think so. Um, uh, healthcare always seemed to be on the bleeding edge of technology as far as release of information, privacy, um, the it, the cyber world, um, as far as protecting everyone's data, you know,

Speaker C: and that's kind of the name of the game, right? Protecting everybody's data. Uh, this episode we're going to focus a little bit more on vulnerability management. I'm just going to start from the very top. What is vulnerability management?

Speaker B: It's a process that is not a one and done. Um, it requires you to do continuous improvement and monitoring over all of your systems. Um, you know, like, for anybody who even has like, um, their iPhone or a laptop that has antivirus on it, everybody think that it just stops there. Okay, I have antivirus, so I must be protected. But is it current? Is it updating? Um, um, is it scanning everything that IT should be scanning. Um, are the systems that you're using patched properly? Um, are they outdated operating systems? The hardware is the hardware that it's running on outdated? So it's more than just antivirus on a system. It's managing, um, the hardware and the software and the applications across the whole gamut.

Speaker C: Why is making sure everything is updated regularly and checking out is continuously a big deal? Why can't I just do it once a month or once a quarter?

Speaker B: Unfortunately, the hackers and the bad actors are out there, aren't just doing changes once a month. They're changing things all the time. And they're always trying to get into systems. So every time you're putting up a protection, they're trying to figure out a way around it. So it's a continuous process that you have to maintain.

Speaker C: So what's part of your process when you're trying to, um, see the vulnerabilities within a company and when you're doing an audit,

Speaker B: I would first take a sample of their systems to validate, um, that they know everything that they're trying to protect. Similar to like a risk management process. You can't protect what you don't know you have. So it starts with a good asset inventory of what they have. And then I'll take a sample set of those.

Speaker C: Are they ever surprised at that point where you say, okay, these are all of your assets? Are they ever like, whoa, I didn't know we were dealing with X, Y or Z?

Speaker B: Yes, exactly. A lot of times they are just thinking that they have to protect the endpoints. Um, they don't think about the stuff that's sitting in the closets, the servers, the hardware switches. Ah. And the hardware piece of that.

Speaker C: Why do you think that is? Is it just out of sight and out of mind?

Speaker B: Yeah, I think it's similar to out of sight, out of mind. But it's the people who are, who are making some of those decisions aren't even aware that that exists. Okay. They just think it works, it's magic. So they're just looking at the endpoints m that they're doing, their phones, um, their computers, their laptops. So they think, I got to protect this and there's nothing else I need to protect against.

Speaker C: Do you think sometimes it's because the people who are making sure the endpoints are protected are not always the developers and they're um, maybe not as involved in the day to day of the actual it?

Speaker B: Yeah, that could be, uh, um, part of it to not having people who are managing it aren't aware of all the vulnerabilities that they should be protecting against. But that's why they have us coming in and doing an audit. So once we get past that first shock of oh, you need to know all this information, then we'll drill in to validate that they are doing things. Like they'll say that they have all their systems have um, antivirus on it or are patched regularly. Okay, what does that mean? Does that mean that they're patched every six months or are they patched every month? Um, and we'll run our tools and our validation processes to ensure that they are doing it. So if they, if their policy says that they're updating their antivirus every week or daily and doing scans weekly, then we'll be able to validate that they're actually following their processes.

Speaker C: How do you maintain um, that impartial kind of non biased attitude when you are going into an audit like this?

Speaker B: I'm really asking our clients. So, um, um, how their program is run and then I go in to validate how it's run compared to the evidence that I can see. So it doesn't really matter. I don't really have a preference either way. I'd like to see that they're following their policy.

Speaker C: So you're just uh, able to be really objective.

Speaker B: I'm just able to see what they're doing and is what they're doing match their procedure? Because everybody follows the same procedure. It's not like, you know, I'm going to tell them, you know, you know, that they're only updating once a month and that they need to do it every week.

Speaker C: Sure.

Speaker B: You know what I mean. If they've done a risk assessment and um, have decided as an organization to only update certain things once a month and that's what they've accepted, then that's okay with me. I'm just validating that they're doing what they say they're doing. Now if they're doing something completely, you know, off the wall, like they're only updating every year, then I'm going to find that to be an exception. Even if it is their policy to do it once a year, it's not a best practice, it's not an industry standard, it's going to be something that would flag.

Speaker C: How often do you find something like that?

Speaker B: Um, it's usually the things that slip through the cracks. Um, the clients that I've had are usually pretty good with it. Um, their programs are more mature normally because uh, it's, it's everywhere. Everybody's worried about being hacked. Everybody's worried about ransomware even, even you know I get calls from my mother in law and you know, you know, you know who, you know, you know. Should I click this? Should I click this? No. So everybody is aware of it for just their own personal reasons. So I think it's more something that is something that is followed um, in the organization. Where I find things is that something slips through the cracks like somebody was on vacation, their system was off, it didn't get patched this cycle. Oh, I forgot about that old system here. So it's those things that people forget about.

Speaker C: You mentioned a moment ago, um, updating once a year. That's not really best practices. What would you say are some of the best practices that organizations uh, can follow when it comes to vulnerability management?

Speaker B: It's going to be what the organization um, um, how much they want to accept for risk. So for example, um, I would say that there are patches that come out every week. There's different patches for either applications, operating systems, antivirus patches. And there's certain times that you are going to want to do a testing of that and ensure that it's not going to um, affect a system that's live. So you'll do a test on a sample set and say only push that patch out to a small subset of systems still make sure everything's working, then roll it out to everybody else. So as long as you have a plan in place, um, uh, then that is usually okay. Um, I would say um, at a bare minimum um, to update your operating systems at least once a month. Um, um, any criticals and highs um, will have to be updated within 30 days for most of the major frameworks.

Speaker C: Yeah. So when you do identify these vulnerabilities, how do you start to prioritize them?

Speaker B: So um, again hitting the criticals highs first. Those usually will have a timeline of, of between 15 and 30 days to have those implemented um, after they're identified. Um, obviously you can't fix something before um, there's been a patch for it. But as soon as the patch comes out or um, the update comes out then highs and criticals. Normally between 15 and 30 days should be um, implemented and then you can do, your mediums can go out to 60 days or 90 days for your lows. Um, but um, it's very important to do at least all of your highs and criticals in 30 days.

Speaker C: You know it's not very often that we get the chance to sit down with Somebody who has such a wealth of experience and you know, it's, it's something that just can never be replaced. So I wanted to ask you a little bit about what you're seeing in the industry today and maybe how you've seen it change over the course of your career.

Speaker B: I think the biggest change that I've seen, um, is that it's not as much in the industry that has changed, um, but in the people's awareness, um, a lot of frameworks are requiring annual security awareness training for all employees. Um, even home users are starting to be more aware of it because it's affecting them. There's different solutions out there who are watching your credit report and they're watching your mortgage so your house doesn't get stolen. So they're just more aware that people are out there trying to get your data. So I think that's the biggest change is that people are more aware to protect their data and they're more cautious because of it.

Speaker C: You know, I think so often in a lot of our conversations we think about companies and we think about these big corporations. Let's talk about the people that they really affect. You know, I know you mentioned your mother in law, you know, calling about ransomware. What advice would you give to just regular people at home?

Speaker B: Don't click, Don't click, don't click.

Speaker C: Okay.

Speaker B: Don't click anything and think first. It's like I get tons of emails saying that like a bill is overdue for my McAfee antivirus. I don't use McAfee antivirus, so I just ignore it. But there are people who want to click on that. They want to know what? Why do you think I use McAfee antivirus? Or why do you think you use this or that? You know, so, so just think if you get an um, email that says, okay, your bill is overdue and they're going to shut off your power if you don't pay it. You know, has, have they ever communicated to you in that way before? Okay, um, M. Does your power company even know your email address?

Speaker D: Right?

Speaker B: They probably don't. It's probably not something you've given them tolls on the roads. People are getting those constantly. Okay, okay. Like a text to their phone saying that they owe a toll.

Speaker C: Mhm.

Speaker B: So were you even in the area? And even if they did turn you in, is it worth clicking? And the odds are probably know.

Speaker C: You know, those are really good examples of your cell phone, your email. What about just social sites like Facebook I see so regularly when I Scroll through my feed. Um, it feels like sometimes my friends are posting things that just don't quite add up, and they'll have a link. Are those other examples of things that are just don't, don't click.

Speaker B: I think we're our own worst enemy sometimes. So, um, when Covid happened, okay, everybody stopped going to conferences, they stopped doing things, they stopped meeting people locally and things like that. And what smaller companies and larger companies starting to do is they started try to get people to watch their, um, either podcasts or their webinars and stuff like that. And they would give them gifts and they'd say, if you attend this, we'll send you a $25 thing to Starbucks or to Dunkin Donuts or to something like that. And people click because they want that.

Speaker C: I mean, you gotta have your Dunkin, right?

Speaker B: And it was legit. But at the same time, we're telling people to watch out for scams. We went through a phase where we were doing legitimate things by offering them those trinkets that people would click on. So sometimes we're our own worst enemy. But stop and think before you do anything. Um, um, as far as. Is it really that important that you answer it? So I'll give you an example. I've gotten a text from our credit card company who says that your card was just used type of thing. Because I travel a lot for audits, so I'm always somewhere else. All the time. All the time. Um, and it'll say, okay, to clear this security request, click on this link now. There's a good chance that that link is legit. There's a good chance, but I don't click on it. I call my credit card company company with the phone number on the back of the card. Why click the link now? It might be them, it might not be them. But I don't know where that link is going to go from my phone all the time. If I was at my computer, saw an email, I might be able to tell, yes, this is real. But if you're not sure, um, um, so try to connect to your phone company, your, Your, um, um, um, um, insurance companies, your doctor's office. Try to communicate to them through a secure means that you're already aware of. Call them on the phone on a number you're aware of instead of. Instead of clicking.

Speaker C: You know, I so appreciate you breaking that down because I think again, a lot of the times we talk about big businesses, we talk about the corporations, and you and I might be savvy enough not to click but how many of us are getting calls from our mother in law or a family member or somebody who just doesn't have that same level of education? So I think it's highly, highly critical. Is there anything else that you want to add onto that?

Speaker B: I just think in general, if people just think before they act and I think that could go a long ways on a lot of different topics, but just specifically for vulnerability management.

Speaker C: Awesome. Well, Mike, I want to say thank you so much for taking the time to sit down with us today. I so appreciate it. And for those of you who have been tuning in, I want to invite you to go to our website KirkPatrickPrice.com podcast down below in the comments, somebody you can leave a comment and say, uh, you love this podcast. You can ask a question to Mike or if there's another topic that you'd love for us to cover on our cybersecurity mission, please go ahead and suggest that there as well join our community on LinkedIn. But Mike, thank you so much. I hope we get the chance to sit down again soon. And for my friends, thank you for joining us.

Speaker A: When you work with a Kirkpatrick Price cybersecurity auditor, you work with someone who's been in your shoes. Let's see what the next expert is ready to share to support you in your cybersecurity mission.

Speaker D: I'm M. Wayne Clement. I am a information security auditor and I enjoy talking about configuration management because it provides a means of quantifying how the settings that you have on your systems contribute towards your overall security and compliance goals. A ah resource I would recommend are the CIS benchmarks. They provide a really comprehensive set of settings and configurations, um, that you can use to harden your systems. They're very accessible, uh, and readable by, uh, systems administrators and change advisory boards.

Speaker A: Today's episode highlights the need for vulnerability management to achieve our challenging compliance goals. How you keep up with new and emerging vulnerability is critical for success. Are you ready to join a community of 10,000 people who are working together to elevate the standards for cybersecurity and compliance? It's free to Sign up@kirkpatrickprice.com podcast or check the show notes and achieve greater levels of assurance today? Thanks for joining us on our cybersecurity mission.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • If Your MSP Says ‘All Good’, Can They Prove It?The Small Business Cyber Security Guy · on Patch Management89 / 100
  • It's not you, it's your printer: State-sponsored and phishing threats in 2025Talos Takes · on Phishing and social engineering86 / 100
  • GRC Is an Engineering Discipline. Not a Checklist. ft Akhila Chitiprolu, Head of Security & GRC @ SierraSecurity & GRC Decoded · on vulnerability management86 / 100
  • ISO 27001 Certification: What Will the Auditor Look For? | Interview with Aron LangeSecure & Simple · on risk assessment83 / 100
  • Stop 90% of Ransomware Attacks with Basic Cyber HygieneThe Backup Wrap-Up · on Patch Management82 / 100
  • FoPLM: Introducing Product Memory! w/Special Guests!AI Across The Product Lifecycle Podcast · on Configuration Management80 / 100

More from Our Cybersecurity Mission

All episodes →
  • Our Cybersecurity Mission: The Scope Episode
  • Our Cybersecurity Mission: The Vulnerability Management in Development Episode
  • Our Cybersecurity Mission: The From Dama to Cybersecurity Episode
  • Our Cybersecurity Mission: The CI:CD Episode
  • Our Cybersecurity Mission: The IOT Episode
Explore the best B2B Engineering & DevTools podcasts →
All Our Cybersecurity Mission episodes →