What They Won’t Tell You About AI in Healthcare

with Craig Taylor

Watch with video summary and resources

Episode 43August 30, 202658 min

What They Won’t Tell You About AI in Healthcare

with Craig Taylor · Co-Founder, CyberHoot

Cybersecurity failures do not begin and end with technical controls. They often begin with normal human behavior under pressure: urgency, trust, distraction, and the desire to help. Craig Taylor explains why punishment-based awareness programs fail and how leaders can build habits that hold up under attack.

Show Notes

Cybersecurity failures do not begin and end with technical controls. They often begin with normal human behavior under pressure: urgency, trust, distraction, and the desire to help. Craig Taylor explains why punishment-based awareness programs fail and how leaders can build habits that hold up under attack.

What We Cover

  • Why fear and punishment do not create durable security habits
  • How social engineering exploits ordinary human behavior
  • What AI changes about phishing and cyberattacks
  • The relationship between cybersecurity and AI governance
  • Why positive reinforcement and psychological safety matter
  • Practical steps for healthcare leaders, teams, and individuals

Key Takeaways

  • Human behavior is part of the control environment. Excellent technical safeguards cannot eliminate every decision an employee must make under pressure.
  • Positive reinforcement changes habits. Security cultures improve when people are rewarded for reporting and practicing the right behavior, not punished for every mistake.
  • AI raises the quality of deception. More believable messages and faster personalization make verification, approved tools, and response readiness increasingly important.

Chapters

  • Opening: why human behavior remains a security risk
  • Positive reinforcement versus punishment-based training
  • How social engineering exploits urgency and trust
  • What AI changes about phishing and impersonation
  • Psychological safety, reporting, and security culture
  • Practical AI governance and cybersecurity fundamentals

About Craig Taylor

Craig Taylor is Co-Founder, CyberHoot. Learn more at https://cyberhoot.com/ or connect on LinkedIn.

Related Resources

Full Episode Transcript

Chris Hutchins (00:01.977) Welcome back to the Signal Room. I'm your host, Chris Hutchins. Excited to have a really great guest with me today, talking about some things that are probably top of mind for a lot of you out there will be listening. We're definitely in it in a massive transformation that has all kinds of potential opportunities to really goof things up. And I don't mean this to suggest that it that that we're talking about an area that you should be terrified of.

But there's definitely an area where you want to be paying attention. Most conversations around AI, risk, and health there, healthcare go straight to the model. Is it accurate? Is it biased? Was it validated? My guest today works on the part of the risk that isn't in the model at all. It's in the people using it. Craig Taylor has been a certified information systems security professional since 2001, with more than 30 years in cybersecurity.

He's led organizations at like CSC, JP Morgan Chase, and Vistaprint. In 2014, he co-founded Cyberhoot to teach the world cyber literacy. And today, he runs a virtual CISO practice serving more than 15 companies. And his core claim is an uncomfortable one. Even excellent controls do not fix human behavior. I want to bring that lens into the hospital floor where AI governance and security have to live.

in that same room. Craig, welcome to the Sigma Room.

Craig Taylor (01:38.766) Chris, thanks for having me. It's great to be here.

Chris Hutchins (01:42.697) As I said, I've been I've been really looking forward to this because there's a there are some areas that I think a lot of people are really familiar with when it comes to cyber in terms of risk, what kind of insurance coverage you have to have, all those things. But the piece that I'm so excited to hear hear you talk about is is the human piece of it because there's really not enough safeguards that we should be sleeping on what may or may not be going on. So do before we get into the the details, maybe talk a little bit about you know who you are, what what

really led to you getting into the the the space that you're in and what what maybe a little bit about what you're doing at Cyberhoop.

Craig Taylor (02:20.461) Sure, thank you, Chris. So as you explained earlier, I have a 30 year career in cybersecurity, but it didn't start that way. I started out with a degree in psychology where I studied operant conditioning, how people learn and how people change their behaviors. And that actually was a foundation of an excellent foundation for building a learning management system.

For the simple reason cybersecurity has been off on a tangent that's heading in the wrong direction of bigger sticks for clicks, punishing employees for making mistakes. And what we've learned in psychology for the last hundred years is that punishing behaviors doesn't exterminate the behavior or stop the behavior, it actually just suppresses it a little bit for a short period of time and then it recurs. What does change behaviors and what we're focused on?

exclusively at my company, Cyberhoot, is positive reinforcement of good behaviors. The behaviors you want to see more of, you reward. No different than it's a crass analogy, but training dogs with shot collars doesn't work either. But training dogs with treats, and my goodness, they'll bring you the leash to go to the dog park, right? They want the treat. They want to they come, they sit, and my dog does this every night when he goes out for his nightly pee.

comes back to the door, he sits down, he looks at me. Do I get a treat? Is is it a treat time? because we reward him for coming back after his his bathroom break. So that's really where the human behavior and the psychology comes into play in the not only the cyber literacy training that we do at Cyberhoop, but what we're gonna talk about today with the use of AI. We need to think about this. There's a very

Chris Hutchins (03:48.182) Right.

Craig Taylor (04:13.131) I would say tumultuous couple of years in front of us as AI becomes the norm in all the different healthcare organizations of the world and all the businesses listening to this. And how we navigate through that is going to be fundamental to our success or our failures in this space.

Chris Hutchins (04:34.381) Yeah, it's a i it is an interesting phenomenon that's out there. the conversations you hear most often, I'm sure that you know this very well, which is obviously why you you're having success with you know bringing this kind of a an approach to cybersecurity. you've built your entire practice around the human risk r versus the the technical controls that typically are are getting the attention. What does human risk management actually mean and

Why is it the piece that most security programs underinvest in?

Craig Taylor (05:08.161) Well, you kind of said it in the introduction, right? You can put all the technical controls you want in place, but there are human tasks that all the technical controls allow through, such as email to your inbox. Your inbox lives on your computer. And if you click on the wrong thing or you're not aware of what you're doing, let me know if now's a good time to tell a quick analogy or a quick story to

Chris Hutchins (05:16.143) Yeah.

Craig Taylor (05:37.89) This is in real terms for your listeners. So we had a breach that was reported to us. Our virtual CISO practice also handles forensics. And this happened to be a CPA firm. But let's imagine it was a doctor's office. I'll translate into a doctor's office for you. The front desk gets an email saying, I missed my

Mammogram, my colonoscopy, appoint I need to ha see a GP. I need to see my GP to get an appointment, but I need to do it virtually, like this telemedicine thing. So could you fit me in? It's kind of urgent. And you know, the receptionist will look at that email and say, sure, let me see if your GP has an opening for a telehealth, you know, a a a video conference meeting. It's more common now since COVID, right? So fast forward a week.

there's a meeting scheduled, it's say a Zoom link, and the patient emails in, I can't get on your Zoom link, but I have a Teams account. Would you mind joining my Teams meeting instead? And there's trust, there's urgency, there's authority, and that I have something you can use to solve my problem. And we are 10 minutes late into this telehealth meeting. So the physician says, Sure, send me the link, and they click on the Teams meeting link.

But it's not a Teams meeting. It says HTTPS, teams.microsoft.com and then some dots, and the rest is hidden from the screen. And the in the urgency and the authority of that time frame, the physician doesn't hover over the link, or the CPA firm didn't hover over the link. And it's truly a click fix like attack where clicking that link pushes an RMM solution to the desktop, and the user, if they have the correct permissions or the

administrative rights, which most people should not operate. I don't use administrative rights, and I'm a cybersecurity professional on my desktop. It has the permissions to silently install a remote access solution, Teams viewer, some RMM solutions, some some Python scripts and tools. And the next thing you know you have a secret door into that healthcare provider or CPA firm.

Craig Taylor (08:05.619) All from the ruse of help me out. I I missed filing my taxes, or in this case, I missed my appointment and I can't get on your telehealth zoom, so do this other version. Now, I'm sure that won't wouldn't be a common thing in your healthcare providers because you have legal requirements to use certain telehealth software so that the data is stored safely and securely. But this really did happen to a CPA firm, and it is as simple as

having that urgent replacement link that you can convince someone on the target to click on. And so this happened. It led to a breach, it led to a ransomware event, it led to extortion and a lot of headaches simply because a company was targeted and nursed for a few communication emails along the way and then an end user was convinced to click.

Chris Hutchins (08:49.945) Well yeah.

Craig Taylor (09:03.425) That's how easy it can be and that's how it can happen. And so that's what we're all up against.

Chris Hutchins (09:07.779) Yeah.

Yeah, th it it's it's interesting, you know, I I've been inside of health systems for for the majority of my career and w some of the things that I've seen h happen over over time. I'm encouraged by it because there are people inside the organizations, at least at least the ones that I've worked for, that really were solid and had a pretty aggressive approach to making sure that we are as coured as we could be in terms of protections, but it still does not solve the the the human problem.

I mean the example you gave is is you know enough and enough evidence from from where I'm sitting that that there there's a real need to to look at the human behavior component of it. besides the the obvious from the scenario you just painted, what are some of the the the the other factors that and what what caused you to really start to think about the human side of it and in particular

Craig Taylor (09:53.805) Mm-hmm.

Chris Hutchins (10:07.819) I believe you talked to me talked to me a little bit about psychology w w was part of your your education as well that had you know, kinda got you pretty deep into this kind of stuff.

Craig Taylor (10:17.895) Mm-hmm. So we we need to always concern ourselves when we build a cybersecurity program to protect the data that's entrusted to us, whether you're in healthcare or other company, other areas of field. And you we you know, a technology stack is important, so putting in the appropriate firewalls and the desk the the the desktop EDR enterprise and detection and response solutions.

Chris Hutchins (10:29.08) Right.

Craig Taylor (10:47.661) And the technical stack has to be solid. But because email and because users go surfing the internet, and there are so many threats out there that have basically been put on steroids by artificial intelligence that can create very believable, very desirable emails based on targeted attacks to individuals whose social media profiles are consumed by AI.

We need to educate our end users in a way that they'll listen. Too many times we see companies today that use bigger sticks against the clicks that their employees make mistakes on. And that leads not to changed behaviors. That's not what psychology would say will happen. It leads to apathy and an abdication of responsibility.

I've talked to so many individuals, Chris, who have said I clicked on one or two of my comp my own company's phishing emails. I made mistakes. I got 45-minute videos. I give up on this stuff because no one's ever taught me how to spot and avoid these phishing emails, whether it's real or or or or legitimate from my own IT team or it's a hacker attacking us. So I make no mistakes now because I forward everything to IT.

I don't understand this and I'm not gonna learn this, and I give up. I'm just forwarding it all to IT. Until, truthfully, Chris, they say that, but then there's the golf book a free golf outing on us email to the avid golfer because he's socially social media to post his, you know, 70. He broke 80, and and so he's really into golf, right? And here's a free golf outing to his favorite course.

Chris Hutchins (12:38.297) Right.

Craig Taylor (12:42.125) Course he's not gonna forward that because he wants it to be true. He clicks and the rest is history. So what we have to do is we have to recognize the psychology behind creating a high engagement, a cyber aware culture, people that want to learn this stuff because it's not punitive, it's rewarding. And so at Cyberhoop we've basically built a gamification system.

That rewards making good decisions in phishing simulations. So we don't trick anyone. We're not deception in the inbox, phishing testing. We're an simulation in the browser based on an assignment you receive in your email. So your assignments from Cyberhood are twice a month. You get a video that might teach you about something that's an emerging threat. We've sent videos on overpayment scams or financial scams. Like you got.

paid too much money on something you sold on Facebook Marketplace, before you refund that money, you might want to wait for the money to clear your account, because it's probably not. And so we we do all these different videos that train people on common theme scams, romance scams, whatever it might be. But we do this phishing simulation and as you go through and you pick and choose, is the sender safe or is it suspicious?

Chris Hutchins (13:44.046) Right.

Chris Hutchins (13:51.151) Yeah.

Chris Hutchins (13:58.747) Right.

Craig Taylor (14:06.549) Is the greeting or the subject safe or is it suspicious? We're rewarding you with points towards an leveling up of your avatar, a certificate of completion for your continuing education credits. We make it fun and gamified where you can compete on an anonymous leaderboard within your company or a non-anonymous. In other words, you can invite friends in your finance division to compete to see who can get the highest scores.

Over time and lead the leaderboard. And that creates a game where people compete with one another for a little bit of friendly, fun competition, but it removes the work aspect of it. So people don't mind doing it. And the outcome is that they learn how fishing works. There's this old saying that I love to use feed a person a fish, feed them for today.

Chris Hutchins (14:37.914) Right.

Chris Hutchins (14:52.848) Yeah.

Craig Taylor (15:03.543) Teach them how to fish, feed them for a lifetime. Now that's F I S H, but we have the same word in cybersecurity, fishing, P-H-I-S-H, which is this social engineering attack. So if we can teach people how hackers fish us and teach them with authority, like confidence, efficiency, they're going to participate if it's a game, if it's fun, if it's short, and if it's non-punitive but rather positive reinforcement.

And that will actually lead to behavior change that sticks for the long term. There's a technical way of explaining this. It's an internal locus of control when you do a reward system. People internalize this because they want to remember how to get the rewards going forward, just as your dog comes back to the door at night, as opposed to the shock collar, where it's like, how do I get out of this? How do I escape? I don't want to be shocked and make mistakes. There's no internal

Chris Hutchins (15:49.732) Right.

Craig Taylor (16:00.801) learning there, it's all an external locus of control i in i as punishment. So that's the human behavior that we all live with. And and my thirty years of cybersecurity experience has shown the psychology does work. When you reward the good behaviors and you gamify it, you remove the work aspect of things and you make it more of like a video game of sorts, right? Where people want to play, they want to level up, they want to show their

Chris Hutchins (16:25.593) Right. Yeah.

Craig Taylor (16:29.793) their levels and their accomplishments, that really does create engagement, positive outcomes that last.

Chris Hutchins (16:40.109) Yeah, it strikes me that what you're describing actually moves the the whole thing out of this compliance training that you could do one or two times a year into really operationalizing it and baking it into the DNA of your company. maybe talk a little bit about that and and how you seen organizations start start seeing some measurable improvements w with this approach that you you bring to the table.

Craig Taylor (17:06.861) Sure, Chris. And I have two firsthand knowledge events, right? I have two breaches that I managed in this year. There's just been a growth in breaches. There's more attacks. We know this from the AI and from what's happening out there. There was a an advisory about AI recently from the Five Eyes organization talking about the threats we face from AI. That's another topic for another day. But here's two examples of what a positive culture can create.

in terms of reporting a breach quickly and containing it versus what a fear-based culture creates and people not wanting to admit mistakes and kind of hoping nothing bad happens and I'm just gonna keep quiet. So in the first breach, we had a company going through CyberHOOT training, positive reinforcement. They called out the highest performers and they gave gift cards or

free lunches to the division that had the highest compliance. Everyone was encouraged to participate. The gamification was recognized and the public recognition was all positive. And someone yet still makes the mistake. They clicked on a link they shouldn't, they thought, this I I need to let my IT team know that I did something wrong. And so they did. IT team swooped in within 30 minutes.

It was reported and looked at. And yes, there was the beginnings of a of an attempt to install something remotely. It didn't work quite as expected, but it was they were able to shut it down, shut the PC down, get it offline, cleanse it, put it back in service. And at the end of the day, there was no reportable breach. They caught it in the cusp. And it's because the culture was if you see something, say something, and you'll be rewarded for doing so.

Chris Hutchins (18:53.711) Amazing.

Craig Taylor (18:58.077) Even if you made a mistake, because w while we teach you, we don't punish you for failures or or mistakes. Second company. Traditional attack messages to the idbox. If you clicked on one, you got three warnings and then you're fired, right? The first warning was a meeting with your manager, the second was with HR, the third was you're out the door. Everyone was fearful, everyone forwarded things to IT. The IT department spent 10, 15, 20 hours a week.

responding to individuals who didn't know if it was a fish or not and you know the false positive rates of email sent to IT was very very high and people were afraid. Someone made a mistake. Let's use that golf outing as an example. They clicked on the free golf outing and nothing happened. Or their machine started to slow down and there were s indicators that were subtle but things weren't quite hunky dory. Guy just kept quiet. Didn't say a word.

And you know, a couple weeks go by and suddenly we identify there's someone in the network, there's an incident, we track it back to this person's machine, and we ask, why didn't you say something? And well, truthfully, you know, I don't know, I just didn't think there was any problem. But the real truth is that there was a culture of punishment and neg you know, fear and shame.

For making mistakes. So things went unreported. Those two sides of the coin can lead to success or to failure in these scenarios, right? A quick response to a breach can contain the blast damage. A slow response or no response means it's just gonna compound, you know, exponentially.

Chris Hutchins (20:49.677) Yeah, that's a th th the the psychological safety component of this thing, these type of activities is so it's so under recognized, I think, at least in my in my in my experience. I'm sure you you have a better a more comprehensive ex experience than that. But I I think the the the approach has always been, you know, from a compliance standpoint, like l e everybody just needs to do their part, be attentive.

And you we we kinda go through the motions, but it without the operational components of it that that I think you've been you've been working on there's not a I haven't seen a model that was truly effective in the way that you're describing. I've seen organizations improving, don't no don't misunderstand me, but I think this is at a different level and I think we are at a point in time where it really does have to go into this

really operational modes so that it becomes just part of how people operate. They understand it from the beginning. And they you know whether or not there's a reward system, the ownership of that responsibility is something that everybody in an organization has to be the c the the care

Craig Taylor (22:01.697) You're absolutely right, Chris. You want everyone to buy into this, right? twenty years ago and even ten years ago, people said, Well, security is not my job. It's the IT department lead. now we come to recognize that it that's sort of cybersecurity is everybody's responsibility, but I think we've missed the opportunity to take a multidisciplinary approach to the problem.

Chris Hutchins (22:14.873) Right.

Craig Taylor (22:28.139) That's the real key here, right? And that's I think if you look across all of science, all of the industries of the world, the companies that do the best are the ones that don't take just a single focused of you know blinders on view of their problem. They look at it from multiple dimensions, right? you wanna bring in human resources, you wanna bring in psychology.

Want to bring in a technology stack that helps prevent mistakes from compounding by having great detection, great notification and alerting, maybe even a honeypot inside your network, especially as we approach you know the the AI breaches that may be coming. But at the end of the day, when you look at a problem from multiple dimensions, multiple disciplines, you're gonna find a better solution, a better resolution.

Chris Hutchins (23:12.377) Right.

Craig Taylor (23:23.831) Think that's what we've stumbled upon here at Cyberhoot, simply because through trial and error, we've recognized that w in our beginning, in truth, and and going back right to the beginning, Chris, we tried to be another attack phishing company sending these messages to the inboxes. And we pivoted very quickly based on my background and some of the other co founders here's experience of what wasn't working. And look, look in the news media.

Do you need any more confirmation that cybersecurity seems to be lost, other than how many breaches we see every day, how many ransomware events? I mean, it's become the norm. It's bec it used to be when you got that one letter in the mail, you're like, my God, my data was exposed. What's gonna happen? Now I get them every other month. It happens so frequently that we have to ask ourselves are we doing things the right way?

Given the number of breaches and the number of mistakes people are making. And I think the answer is no, we're not. We have to rethink how we're approaching changing behaviors and making people more aware and more engaged and more responsible for their own cyber literacy. And the the huge benefit here is that this all applies personally as much as professionally, right? I've been at companies where I've had people say,

I can't come into work today because my identity's been stolen. And I have to go to the courts and prove I am who I say I am because someone else has stolen my identity. Right. You're going to help people personally, and and we shouldn't look at this as a work cost. It should be a work benefit for employees when it's constructed in a way that's positive, rewarding, gamified, where people enjoy participating and the

The merits and the benefits extend into our personal lives. So

Chris Hutchins (25:23.257) Yeah, and I I love that because you t you're talking about really it's something you're doing to benefit your team. The protection aspect of it I think is probably under emphasized you know far too often, but I think it's it's such an important factor because people oftentimes are not looking at it from from the big picture. They're just like, man, I hate doing these annual compliance trainings.

Craig Taylor (25:47.864) Well, it's a checkbox for the cyber insurance. Do you train your staff once a year for four hours? D does working out at the gym in January seventeenth work for four hours, you know. Does the is that person who goes for that first workout of the year are are they gonna come back? No. Are they gonna hurt themselves? Probably, right? You need to do this peri you need to do what we call H I T in cybersecurity, high interval

Chris Hutchins (25:54.371) Yeah.

Chris Hutchins (26:01.722) come on, don't don't meddle now.

Right.

Craig Taylor (26:17.677) Training, high intensity training, where you you do short little bursts, three to five minutes, once or twice a month, and over time you begin to change behaviors. If you try to do it all once a year on a checkbox exercise, you're just doomed to failure.

Chris Hutchins (26:34.349) Right. You know, there's it's it strikes me that you know we're in a period of time where it seems like every day or every couple of days we're hearing more about governance when it comes to data and AI within within the a healthcare organization. but we talk a little bit about the the the the differences between the two things because when you're thinking about governance, these organizations that I've been been part of over the years, there's this legacy.

Craig Taylor (26:50.829) Mm-hmm.

Chris Hutchins (27:04.771) perspective that exists because organizations have tried to formalize governance ahead of the point in time where they actually have something for people to govern. AI is dramatically shifting that from a timing perspective because it's no longer the traditional quarterly or biannual or or annual release schedule that you t tend to be on with your systems. So we talk a little bit about how you see this and

Craig Taylor (27:16.781) Mm-hmm.

Chris Hutchins (27:28.975) You know, the difference between the security and the AI governance. I don't think they're disconnected, but they are differently definitely distinctly different in some ways.

Craig Taylor (27:38.886) Yeah, so I've seen a couple of healthcare providers that lock down their AI usage policies and their employees' ability to work with AI in various aspects of their job. And the unintended consequences is something that's of interest to me. And I may this might not be answering your question, Chris, but let's tease this thread for a moment.

they purchased a an expensive license, which was a private LLM where the data wasn't consumed or used to improve the model or train the model, and and the data was all maintained in its own enclave. And that company was very successful with their employees using just that model because it was always on, it was a there, they could put

What they wanted into it to help with diagnoses, to write emails, to do what they needed to do. It was an empowering solution. And it it provided what the employees wanted and desired to improve their productivity. Now flip that coin upside down. There's another healthcare provider that I was consulting with and they locked everything down. They blocked access to the AI models. They didn't fund a private model. And you know.

Everyone was thought that they were okay because they'd locked it down. But when you went there and you observed what was going on, people were pulling out their phones and putting information into their AI chat model on their phone. And it was going around the system. Now can I prove that patient data was put in there or other things?

Probably you know, I I people are smart enough to know they can't put patients' names and diagnoses into an AI model, I hope. But there was definitely leakage going on, and it was definitely content going into a public LLM like OpenAI or or Andro Anthropic. And the employees were working around the system because it had been locked down so much. And so

Craig Taylor (30:00.45) there were threats and risk, but there was no way to measure and quantit quantify them, right? and ultimately I'm sure someone did put data in that they shouldn't. So if you look at those two coins, like what do you need to learn from this scenario is you you employees are resourceful. They'll work around the system to get what they want. I I know in the older days, like maybe COVID era, you couldn't print at home

when you worked from home because that was not allowed. You can't print company data on your home printer. So what did people do? Forward that to my personal email, download it to my work home computer, print it at home. I need to get the job done, right? So the unintended consequences and the psychology of all this is that people are resourceful, they'll get to what they need, want and and desire one way or another. So you have to empower them in ways that works for their workflow.

And that would allow you in the former case, it allowed you to limit and protect that interaction with AI in a way that was both empowering, productivity enhancing, the desired way employees, doctors and nurses and practitioners all wanted to use AI to help them get their job done better, more efficiently. The other way was to lock everybody out and then they just worked around the system.

Chris Hutchins (31:27.022) Yeah, I I I know. It was pr well before the pandemic, but I but I remember just the access to like your your private email became problematic because it was taking so much bandwidth in an organization. and people felt a little p you know put off by that. But the the the reality is there are

Craig Taylor (31:44.983) Mm-hmm.

Chris Hutchins (31:52.784) threats that people are really are just not aware of. And honestly, it's because people like you and the teams that you've built over the years, they you you are constantly staying vigilant and on top of those things. So it it kind of gives people this sense of security in one hand. But at the same time we don't we we don't really want them to stay comfortable about it. But without this kind of approach you're talking about where it's kind of being baked into operations.

You're you're still gonna be having those kind of challenges, and people will find the work runs, to your point. I I got cell signal, I don't need the Wi-Fi, so I can just go do it on my phone. I'm sure. Yeah. So policy oftentimes once it hits, the the team that develops it, they they feel like they've done a good job with it, it's gonna be effective, it gets sanctioned, announced, communicated, whatever, and they believe.

Craig Taylor (32:29.879) That's right. A hundred percent.

Chris Hutchins (32:49.518) maybe too easily that the the behavior is going to change automatically. d like what as is we are we just talked about the s systems are changing. AI is a whole different ballgame. The evolution and the training and development of these models, it's it's a it's a constant thing. So maybe talk about you know how from a psychological standpoint, when you're writing policies, understanding that they don't you typically change what people actually do.

What what's your advice to organizations as they're trying to navigate through this from a transformation standpoint? Because there's a lot of legacy approaches. Informed consent's a great example where the way that we managed it historically has to change because of the nature of new technology that we're using, the way it's evolving.

Craig Taylor (33:35.094) Mm-hmm. Mm-hmm. Well, so it look, a lot of this boils down to common sense, Chris. I've seen we have a virtual CISO practice in Cybercooth where we come in and we evaluate the cybersecurity programs of the company and we help them build, you know, a bunch of pillars in their cybersecurity program. So training and governance is one of them, or training and and fishing simulations is one aspect.

Governance is another. And when I ask for how do you govern your employees, like what instructions do you provide new employees about how they're expected to behave and how they're expected to use technology? So we got that covered. We have a a handbook, a company handbook. Show me the handbook. And they pull off this, you know, document that's four hundred pages thick and it has everything from

dress code and vacation schedules to acceptable use of computers and privacy and and data governance and labeling, it's all in this buried in this huge document that no one, not even the people that wrote it, who are no longer there usually, have read it. And so I say, well h how does that get consumed? Are are you familiar? You probably I know you've heard this before, but there's a TLD R too long, didn't read.

That's one of the favorite things I tell AI to give me on anything I have to read. Like, give me the TLDR of this. And it says bullet by bullet. Here's the four things you need to learn from this document. So I say if you want people to actually understand and reference your governance policies, you need to keep them TLDR'd, short. In other words, your password policy, it needs to be

Only the password policy, and it needs to be one or two pages of instruction. You can have a table of contents, or you can have, you know, the re revision and approval controls in there. That's all good stuff. But people can ignore and skip all that. They just need to read the 30 bullet points on password hygiene that they have to follow. or 15 to 20, whatever you can boil it down to. But it needs to be short. And then you need to reward people.

Craig Taylor (35:53.87) For engagement with that and compliance to it. So, for example, a password policy might say you must adopt the company password manager. And that's by all by all means every if you learn one thing from this conversation today, if you're not using a password manager, you need to. Stop what you're doing. Go look at, I can recommend three if you want to pick one of the three. There's six or seven great ones out there.

Chris Hutchins (36:12.271) Right.

Craig Taylor (36:20.365) but you need a password manager today, if only to identify where you're reusing passwords, help you change them to be all long and unique, and lastly to manage your pass keys as we transition from passwords username, password, and MFA into pass keys, which are superior to anything password, username and password and MFA related, multi-factor authentication, those little six-digit codes.

Pass keys replace all that with a single step and it's equivalent and it can't be stolen. So there's a lot of huge benefits for that. But if you're not on a password manager, then I know you're reusing your passwords and your employees are reusing your passwords. So if you can keep the password manager in that password policy and push and subfund it, then you're going to reduce the stress of your employees in using and managing passwords, right?

Think there was a study of the average employee spends four to six hours a year resetting and waiting for passwords and troubleshooting passwords. Which password did I use? Logging in with three of their favorite passwords until one works. A password manager eliminates all of that. So keeping it short, keeping it digestible, TLDRing the governance policy. I've seen some companies where they even take the

The policy and they put a TLDR summary of what it states in a box at the top of the policy. It says this policy covers password managers, password hygiene, multi-factor, duh, and it spells it out for them. All of that's going to create a much more successful governance program where your employees will actually be at least have a chance of reading and digesting this stuff rather than a 30-page, 40, 50, 100-page employee handbook.

Chris Hutchins (38:14.148) I you know you you touched on this a little bit already, but when we're talking about the the social engineering aspects of what what's happening right now, we we've been hearing things about and we've been exposed to education around fishing quite a bit over the last you know several years. I'm not quite sure exactly when I first started seeing it, maybe probably about 10 years ago, I think. but things are changing at a

Craig Taylor (38:22.669) Mm-hmm.

Chris Hutchins (38:41.648) at this point in time because people are accustomed to it. And you know, s maybe some things that used to be obvious. They're not so much anymore for someone who's not really delving into this stuff and paying attention on a regular basis. Maybe describe some things that that that you see that are indicative of an AI assisted attack in a in a hospital kind of a setting. And what are some of the things that make clinical staff, for example, a a particular target, because they're like super busy, they you know they

struggling with burnout, that we keep introducing new technologies to them that actually disrupt their workflow instead of improving it. so they're they're oftentimes really already frustrated. And then these things, these additional things are are something they have to contend with. You would talk about what from your perspective, what makes them a a target and and how are how are you thinking about helping organizations to start to resolve

Craig Taylor (39:23.201) Mm-hmm.

Chris Hutchins (39:38.938) put things in place to relieve some of that from

Craig Taylor (39:42.158) Sure. whenever you want to understand why your your company may or may not be a target, you have to look at what data you have. What data does a hospital or a healthcare provider have that is a target of organized crime, nation states, you know, hackers of any kind of ilk or what have you. And in those settings, it's the health records, right? The patient records. And

What is the most common form of attack is whatever I as a individual in the internet space can get into a person at the at the healthcare provider, and that's usually through email and that sort of thing. Many hospitals have moved from open email systems where you could email your doctor to patient portals where things are contained and constrained and protected. That's a good thing, and that's to be applauded and should continue.

Right, you should only be able to communicate with your healthcare providers through your patient portals because that can be protected from a lot of the different types of attacks that are ongoing. But in healthcare providers where you could get an email into a provider, we're seeing the focus be on these phishing attacks, where, first of all, there's no more grammatical mistakes. AI can target an individual.

No lon so in go back ten years, it was pray spray and pray that someone will click on a link to a similar email sent to everybody that we could identify at the hospital. Today there's what we call spear phishing attacks where any individual is the target of an attack based on who they are, their likes, their dislikes, their social media, their online presence, right? And so every email that's sent as a phishing attack to that individual.

Is targeting the individual based on their personality. And it is perfectly aligned to who they are and what their interests are. So if you're a golfer, you're gonna get golf fishing attacks. If you're a lawyer, you're gonna get law-based ones. If you're whatever your personality is, you're gonna have these specific attacks directed at you. And they may even know through internet research that.

Chris Hutchins (41:52.142) Ready?

Craig Taylor (42:05.569) you're using this particular email client and you're using this particular technology and so it might tie to that. We we we've seen it even within our company. We have a a a

Content management system, I won't name it, but it has been sending emails out on our behalf. And so someone did their research, got one of those, and then they turned it into, hey, your campaign is stuck and you need to click here to investigate and release your emails to your target audience. And it was a phishing attack. And you could you couldn't tell unless you were really diligent about hovering over to the end of the link because it had our CRM was sitting there in the

In the bold face URL with some dots after it, no different than the Teams attack we talked about earlier on. So the attacks are becoming s much more focused, much more frequent against individuals, and they can get multiple attacks over the course of days and weeks, all from the same, you know, hackers seeking to breach into that healthcare provider. So we have to be, as healthcare providers, we have to be

Perfect every day on every single email attack that we receive. And w one other note I'll make is that any errant clicks, any errant mistakes are even more dangerous and devastating when they occur. AI has not only made the attacks more voluminous, more common, more frequent, and more believable, and more tailored to the individuals.

but they're also more damaging on the back end and what they can accomplish. It used to be a hacker would get into that account and start doing things on the keyboard, right? Like let me deploy this software and get remote access. Now let me land and expand over here. AI systems are designed to just do all that at machine speed. Once you get the click and you get the first payload in, the payload then it lands, it does these network scanning, it fans out, it puts itself into other places.

Craig Taylor (44:13.407) And then it beacons back to the hacker saying, Hey, I got into this account and I have these permanent locations that I'm in the network. we had an incident yesterday I was talking about on a call with some l a legal team, and there was a school district in the United States. I won't say anything, but we know that they were breached a year ago because it was very big public breach, and big ransom event, public disclosure, student records were put at risk, they paid the ransom.

They cleaned it all up and they went away. Well, the hackers actually weren't cleaned out of their network because we had a client who was attacked from their network. And the RMM tool that was used to install on this company over here came from that school district. So the the hackers were still in that school district, right? They didn't clean it up all the way. so th it these kinds of things are happening all the time. So to go back to your first point.

The fishing simulations are still the number one way people are getting in. You have to get on top of that awareness and teach people how fishing works. And to there's a simple little analogy that we use. It's the word par, it's not golf par, P A R. Whenever you are about to click on anything anywhere, home or at work, par it. P-A-R. Pause, assess, and report.

Chris Hutchins (45:27.556) Yeah.

Craig Taylor (45:41.577) If it's suspicious, pause, assess, report, par. Simple three letter acronym, you cannot forget that. Do not click without following PAR.

Chris Hutchins (45:53.829) Yeah, I I I I think though the the the way you're kinda j just simplifying it, I think that's the that's definitely something that that that can actually stick, but it's not an after the fact bolt on because organizations are in various places in their journey right now with implementing AI, but there's a lot of pressure to actually do it effectively. talk a little bit about you know what what are some of the things that you would tell organizational leaders you know

whether they're IT, you the C suite or maybe even the boards, what are some of the things that you would advise them to be to start doing regardless of their journey, but just so that they can have some confidence that they are doing something that's moving the needle from a cultural standpoint and it's not as you mentioned earlier, just checking a box.

Craig Taylor (46:43.595) Right. Yeah, if if you're checking boxes, you're going to be breached. I promise you. I cannot emphasize that enough. This is no longer a checkbox exercise. It's only a matter of time. And with the advent and growth of AI, more and more people are able to become your opponent, your adversary to try and break into your business and extort you for money. And all over the world.

People are seeing other hackers be successful in these spaces with AI empowering them to breach companies and they're getting these big ransomware payments. And it's ballooning the industry. It's growing faster than any other industry in the world, I believe. And so you cannot be taking a checkbox exercise. You have to, like, let's assume that you're not going to do checkbox. You're going to have a positive reinforcement culture, you're going to adopt a tool.

Like Cyberhoot that rewards good behaviors, teaches people how phishing works, all of that. Well, your AI journey of protection is not done, right? Your users are gonna get that constrained, contained, purchased AI tooling for your employees to use AI the way they want to. Like we spoke about earlier, you're not gonna block access to everything, you're gonna have a prescribed, approved AI tool. Some of the new you know healthcare systems are actually allowing AI dictation.

So when you're in the room, remember you you this happens to you, right, Chris? You go to your annual physical and you're looking at the person, here's your healthcare provider, and they say, Okay, tell me how you've been, and they ask you a bunch of questions, and they're doing this the whole time. They're like

Chris Hutchins (48:11.237) No, yeah.

Craig Taylor (48:24.321) Because they're trying to get all the data and or while you're telling them. Well AI can get rid of all that so they can look you in the eye and they can say, my gosh, that must be so painful. Let me let me talk about what, you know, carbuncles or whatever the ailment is is with you and and empathize and be a good bedside patient, you know, interaction. AI will summarize it all for me and then we'll we'll put you on whatever prescribed medication or or c mitigating

Things to do. That's the beauty of AI when you build that into your systems and tooling. But you're still not done. Why? Because you have a hospital, you have a website, you have a footprint on the internet. I think the five eyes advisory that came out three weeks ago, if you haven't read that, you should go and do that if you're a leader or an IT professional in a healthcare situation in a healthcare provider. Because

What is Five Eyes? It's the US, Canada, UK, Australia, New Zealand. These five cybersecurity divisions of the government got together and said, folks, you have weeks and months, not years, to mitigate the threats we're about to face from AI. There's a new technology called Mythos from Anthropic, which can basically identify vulnerabilities in your website or your

firewall or your router or any of these things. Now the good news is Anthropic looked at what they had built, this it mythos vulnerability identification frontier AI model, and they said, it's too dangerous. We can't release this to the world. So we're gonna put a moratorium on anyone using this. We've they formed a glasswing coalition. You can research that or go to Cyberhoot's blog, cyberhoot.com slash blog, and you can read about this. And they've

Got the top 50 software vendors of the world together. They said, scan your solutions with our tool, find the vulnerabilities, patch them before other AI vendors catch up to us. Because ultimately, DeepSeek from China is going to catch up to Anthropic here in the United States or OpenAI or Grok or whomever. And that's what's been done. And the evidence of what the power and capability of these frontier models is in the patches that have been released.

Craig Taylor (50:50.061) Google Chrome had 10 patches a month forever, backwards in time, 15 patches. They had 600 patches fixed in the last release. 600. Microsoft set all records in June for their patch Tuesday for themselves. They had 10 times as many patches, so normally they're about 20 patches a month. They released 300 patches, fixes in June. And then in July, they released

If it's not 3,000, it was an enormous amount. You can go and look it up. but they did that because they had been scanning with mythos. So as a healthcare provider, what's the message for you? Go to my blog, read it, because there's more to it than we have time to talk about. But there are five things. Reduce your attack surface. Imagine your hospital is a house, and your house currently has four doors.

Front door, back door, left door, right door, and 10 windows. Get rid of all the windows and doors. Have one front door into your building and that's it. Get rid of everything else. So that you can have arm guards monitoring that door and anybody that tries to come in or out, you know who they are. Just attack surface reduction. Go study that and get rid of every port protocol that you can into your networks that you can. Patch faster.

When Microsoft releases a zero day patch to fix a a a vulnerability that could allow a hacker in, AI can now scan it and reverse engineer it and create an exploit within hours. It we used to have two hundred days ten years ago, then we had like twenty days three or five years ago. Now it's the same day. So you can't afford to wait on your patching. You have to turn on automated patching for all your, you know, wireless access controllers, your firewalls, that sort of thing. But even Microsoft or or

Max, just automatically apply those patches as soon as possible, same day if possible. So patch faster. Continue to educate your humans because humans are still going to be one of the weakest links. well, you know, you gotta keep doing that. reduce your data. I had a breach here. I I'm sorry to be keep talking about breaches, but this it just happens that we have a lot of breaches in the last six months.

Craig Taylor (53:10.625) We had a customer who had twenty-five years of legal records on their internal network that were all ransomed, all exfiltrated or stolen out of the the law firm and threatened with, you know, public disclosure of twenty-five years of records. So what what's the consequence of that? They had to go and contact twenty-five years of clients. They didn't know where half of them were, because they were out of business, they'd moved, their numbers had changed, their emails had changed, their

Chris Hutchins (53:37.915) Well, yeah.

Craig Taylor (53:39.458) You know, they were acquired and they had to go and do that work. It took six to nine months for them to do that work, wherein they had no reason or business having twenty-five years on their internal network. They could have seven years. There's legal requirements for seven years of data. Same for HIPAA and healthcare. There's requirements for a certain amount of data. But archive the rest. Get it off your internal network. Assume you'll be breached and remove as much data as possible so you're not exposing it. you know, and

Chris Hutchins (53:51.825) Yeah.

Craig Taylor (54:09.191) In health records and health systems, you're in a little bit of a enviable position in this case because most of that's living in Epic in a cloud provider, right? It's no longer on-prem on a custom homegrown application. It's in these great secure applications. Hopefully they're part of the Glasswing Coalition, so they're not gonna be breached. but reduce your data there. Put a honeypot out there. Put something that a honeypot is basically this

Hardware device or a software file that is very attractive to hackers. It might be passwords, it might be salaries, it might be configuration of the firewall files or whatever it is. The moment they're touched, it's like that red line in one of those Tom Cruise movies, right? You break the line, alarms go off, and the gig is up. So you you know, hackers honey pots are not as common today as

We would hope, but the average hacker is gonna trigger a honeypot and you're gonna know the moment they're in your network instead of weeks and months later. Like dwell time, we've known that can be 180 days in many companies. You want a dwell time of zero or one day before they trigger this, and then you can react and and contain the damage. So those are all things that are common sense but are much more important, and they're part of the five eyes advisory.

Chris Hutchins (55:16.88) Right.

Craig Taylor (55:36.394) And it it it just makes sense that we have this future year or two where these frontier models are going to be able to break into things despite our best efforts, and we gotta monitor better, reduce the ability to get in, reduce the data inside, patch faster, all these things can help sort of limit the damage of what might or might not happen in the near future.

Chris Hutchins (56:01.094) Right. Yeah, it it it's a it was a profound moment for me when I actually w I was d reading up on a couple of different technologies at one point, probably about a year ago, and the moment that it hit me that there are people that are using a completely different

model, but with the same tech stack that we're using to try to get ahead of what they're doing. So we're trying to improve our ability to detect and stop their trying to detect our detection so that they can actually go go blow right past it. you know and as your as organizations are moving into this, you know, you you mentioned the next two to three years. the things that you've talked about are probably new to a lot of folks, but what are some of the other things that you see

that could become a threat o over the next couple of years and and what should be peop what what should people be doing right now in terms of trying to get themselves buttoned down. Obviously if they don't have access to the s security experts like you s like yourself, that's probably the first call they should make. But love to see love to hear a little bit about what what you see coming.

Craig Taylor (57:14.113) Yeah, so we've talked about a lot of stuff, Chris. Let's keep it simple and let's keep it fundamentals. I think we need to return to fundamentals, to be quite honest. You might hear all this fancy AI this and you need to do that. But the fundamentals is what will help protect us moving forward over the course of the next two to three years. as individuals, we need to get on password managers and adopt and learn how to use them. That's your single strongest.

Protection that you can put in place today. Because when something is breached or someone gets hold of one of your passwords, if they're all different, all unique, you're not going to have to go change passwords in a million places. And if you click on a link that takes you to a Microsoft login page and you don't know your Microsoft account because it's your password manager spits it in there every time, you're not going to fall victim to that fake Microsoft login page because you're

Password manager won't fill it out. So that's number one. Get a password manager. For people in positions of authority and responsibility, the C suite, get a virtual CISO in your organization, in your healthcare provider. You might not be able to afford a $300,000 full time CISO position, but you can afford a $100,000 or an $80,000 part time v CISO who has not only your responsible company.

But has 10 other companies so that they can bring best practices from all these different places, and the team of vCISOs can bounce ideas off of each other. So instead of having this one CISO who is dedicated to you and doesn't have visibility into all these other things that are going on, you hire a virtual who has access to dozens of other virtual CISOs, has visibility into dozens of other companies, and can bring the best of the best to you.

Chris Hutchins (58:46.193) Yeah.

Craig Taylor (59:08.907) And so when they say, hey, this has worked over here and here and here and here, you have a high degree of likelihood it's gonna work for you, right? That's the second thing I would suggest. Third is get on a positive culture and a positive reinforcement awareness training and and and cyber literacy program that is focuses on rewarding good behaviors. Stop punishing bad behaviors, build a culture of see something, say something, reward people for talking about problems and

and bringing up issues to leadership that engages the employees instead of ostracizing or disengaging them, fight that apathy. Those are three things that I think would be great take-home messages from our conversation today.

Chris Hutchins (59:53.81) Yeah, I totally appreciate that. And I I th I would just encourage people who are who are listening to this. If you're in an organization where you've not been able to figure out how to how to pay for an expert of your own, the the the important thing I wanna c you know caution people about is you've got some fantastic talent in your organization, there's no question about that, and they want to do the best that they can possibly do for you for you. But we're talking about a a a level of skill now.

that really requires career level commitment and in in your constant education and learning. I I just would encourage you if if this is an area where you're struggling, you're not quite sure where to go, you definitely want to reach out to that to an expert like Craig and you know he and his company actually have the right talent. That they've this is what they live, sleep, eat and breathe. you you real you definitely want this, whether you'd have to do it on a fractional basis or however, but

You gotta make sure that you've got some people who are vigilant and making sure these things are being monitored and you're you're getting at least is what the current the best information you can at any point in time. But y having a trusted partner, I think, is gonna be really critical. So Craig, if you could j just tell people how to how to get a hold of you. If they wanna they wanna, you know, read your content, they wanna have have a call, bring your bring in your experts.

Craig Taylor (01:01:17.003) Yeah. So I'll start with this. We give our entire solution away free to individuals. So if you go to cyberhoot.com forward slash individuals with an S at the end, you can register and get our videos and our phishing, what we call HootFish. It's a non-deception based fishing simulation. So you get an email that says you have a phishing simulation to take. And you go to the browser and the browser walks you through teaching you a rubric of how to spot and avoid and understand fishing.

feeding you for a lifetime of confident, efficient, and secure email processing. So that's a wonderful thing. But if you want to reach out to us, email sales at cyberhoot.com, visit cyberhoot.com for a free demo. Anybody listening to this that actually ends up getting a free trial, if you convert to a paid subscription, we'll give you 20% off if you mention the signal room for your first year. We're happy to do that for you.

our blog is out there and it's more, you know, I I met with an AEO person, somebody with search engine optimization, but also for AI. He says, You're not doing a bunch of these really important things around what is it, the schema of your blog articles. I'm like, Well, I'm trying to teach people what they need to know. I'm less concerned with, you know, being the AI search engine output of

Chris Hutchins (01:02:18.555) Yeah. Yeah.

Craig Taylor (01:02:37.299) every search that people do in AI these days. I I think that's important and we want to do that, but I've really focused on the content and communicating these steps that you need to take to protect yourself. And so I need to do a better job, do both so that AI can point people to us. But our blog is just a is just full of all kinds of great articles about emerging threats, the Five Eyes Advisory, Mythos, and everything else in between. We have a cybersecurity library of terms.

thousand plus terms so if you're wondering what is a bitcoin or what is two-factor authentication or multi-factor we've got it defined with video linkages and all of that good stuff too so go to cyberhoot.com slash blog you we have a newsletter you can go to cyberhoot slash dot com slash newsletters and sign up for our summary once a month that's a great way to learn about what we're doing and what the threats are out there but all of those are ways to reach us.

Chris Hutchins (01:03:37.051) Phenomenal. For for for the audience, I'll make sure that all all this information will appear in the in the show notes. And as I said, I encourage you to to to seek out at you know Craig and his team if you're realizing that you've you've got to really f you know firm some things up, make sure that your organization's protected. Craig, this has been amazing. I've learned a lot in this in the over the course of our conversation. in f on a personal level.

I really want to say thank you to you for the work that you do because I I've been on the data side, d you know, as a chief data officer for a long time. And there I I definitely have a receding hairline, but I would be completely bald if it weren't for people like you that have the have the d the drive and motivation to stay ahead of this kind of stuff. Cause I I don't know that people really realize how many times a day that you you know the information security team is actually being alerted and having to address things.

Craig Taylor (01:04:33.239) Business.

Chris Hutchins (01:04:33.531) But s again, thank you for what you do and I really s sincerely appreciate you coming on the show and I'm really excited for for the audience to be able to hear the conversation and even more excited to see where you go from here. obviously you're doing some really important work and I love the passion that tells me that you're you're not done. You're you're gonna continue to involve

Craig Taylor (01:04:53.185) Yeah, well thank you, Chris. I I very much appreciate being here and we'll make sure we get all those links for your show notes sent over to you.

Chris Hutchins (01:05:00.517) Fantastic. Thanks again. And and for our listeners, I'm Chris Hutchins and I look forward to seeing you next time on the Signal Room.