The Cyber Event Playbook: What to Do Before, During, and After an Attack
Most healthcare executives believe their IT team has cybersecurity covered. Gary Salman responds to active cyber events every day and says that assumption is costing healthcare organizations millions.
About Gary Salman: Gary Salman is the CEO and Co-Founder of Black Talon Security, a firm that secures approximately 2,000 healthcare entities globally and is regularly retained by law firms and insurance carriers to handle active cyber events. With 33 years in healthcare technology, from early practice management and EMR systems to one of the first cloud infrastructures built in the late 1990s, Gary has spent his career on both sides of this problem: building the systems healthcare runs on and protecting them from the people trying to take them down.
In this episode:
1. [04:12] Why email account takeover has surpassed ransomware as the #1 threat. When a C-suite account is compromised, hackers access M&A data, wire transfer instructions, and vendor relationships. The damage spreads fast and goes far beyond the organization itself.
2. [07:17] Why almost every healthcare victim pays the ransom, even with backups. When patient data is exfiltrated, the alternative to paying is that data getting auctioned to the next threat group on the dark web.
3. [08:51] Why class action lawsuits now arrive before the ransom is resolved. A mid-size DSO was served within 48 hours of the breach. A three-location dental practice maxed out its cyber insurance and went out of business.
4. [19:27] Why self-auditing is the #1 systemic failure in healthcare security. 90% of small to mid-size healthcare organizations have never had a formal security vulnerability review. Asking the team that built the system to validate it doesn't work.
5. [22:17] Why IT support and cybersecurity are not the same function. Gary's analogy: a cardiologist and a cardiothoracic surgeon both work on the heart. They are not interchangeable. Most executive teams are making that substitution right now.
6. [24:00] The four-layer security framework executives need to understand. Outer perimeter, internal network, managed detection and response, and staff training. Gary breaks down what each layer does, what questions to ask, and what good looks like.
7. [27:47] The exact sequence to follow in the first 60 minutes of a cyber event. Hard stop, network shutdown, insurance claim, incident response counsel. Why the instinct to restore operations fast is the most expensive mistake executives make.
Full conversation on Healthcare100.
🎧 Spotify: https://t2m.io/yq0eaWz [https://t2m.io/yq0eaWz]
🍎 Apple: https://t2m.io/1bQPiib [https://t2m.io/1bQPiib]
📺 YouTube: https://t2m.io/U3Q6xPB [https://t2m.io/U3Q6xPB]
🌐 All episodes: https://t2m.io/kSc7KYQ [https://t2m.io/kSc7KYQ]
⚡ Amol Nirgudkar (Patient Prism CEO, 8 years healthcare AI expertise) and A.J. Peak (multi-site healthcare operations expert and founder of Health Wealth Capital) dig into the tactical frameworks that separate scaling winners from everyone else on Healthcare100. We break down the growth engines behind America's fastest-scaling healthcare organizations with the operators who built them.
Follow us for more insights: https://t2m.io/HGeS9xG [https://t2m.io/HGeS9xG]