42edf0ba-79e8-4285-bbb7-19ee9dd78855/5-0
00:00:03.829 --> 00:00:06.992
We're here today with Matt Morton of the
University of Chicago,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/5-1
00:00:06.992 --> 00:00:10.995
where he is the Assistant Vice President
and Chief Information Security Officer.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/5-2
00:00:10.995 --> 00:00:13.269
Matt,
thank you so much for joining us today.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/6-0
00:00:14.229 --> 00:00:18.764
Thanks, Jordan. I'm glad to be here today.
And, you know, just to be clear, you know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/6-1
00:00:18.764 --> 00:00:22.455
we're going to talk about some cool stuff
today around cybersecurity,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/6-2
00:00:22.455 --> 00:00:26.779
but most of these are the views of myself
and don't necessarily reflect the views
42edf0ba-79e8-4285-bbb7-19ee9dd78855/6-3
00:00:26.779 --> 00:00:28.309
of the University of Chicago.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/7-0
00:00:29.029 --> 00:00:33.467
Perfect. Glad to have you on here, Matt.
Understood. For those who don't know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/7-1
00:00:33.467 --> 00:00:36.669
as background,
the University of Chicago is broader than
42edf0ba-79e8-4285-bbb7-19ee9dd78855/7-2
00:00:36.669 --> 00:00:39.759
the health system.
UChicago owns and operates UChicago
42edf0ba-79e8-4285-bbb7-19ee9dd78855/7-3
00:00:39.759 --> 00:00:42.400
Medicine,
an integrated academic health system
42edf0ba-79e8-4285-bbb7-19ee9dd78855/7-4
00:00:42.400 --> 00:00:45.152
headquartered in Chicago, Illinois,
which has 2,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/7-5
00:00:45.152 --> 00:00:49.029
000 beds across 10 hospitals serviced by
3,000 providers. But again,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/9-0
00:00:49.749 --> 00:00:55.785
Matt represents the University of Chicago,
which is much larger and all-encompassing
42edf0ba-79e8-4285-bbb7-19ee9dd78855/9-1
00:00:55.785 --> 00:01:01.396
than just the health system. So, Matt,
today we're going to talk about kind of
42edf0ba-79e8-4285-bbb7-19ee9dd78855/9-2
00:01:01.396 --> 00:01:05.799
the increasing risks posed by cyber
attacks to organizations,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/9-3
00:01:05.799 --> 00:01:09.989
cyber attacks that are driven by new Gen.
AI capabilities.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/10-0
00:01:10.709 --> 00:01:17.323
and kind of framing the conversation as
investments in funding for cybersecurity
42edf0ba-79e8-4285-bbb7-19ee9dd78855/10-1
00:01:17.323 --> 00:01:23.120
can be seen as insurance policies against
these attacks. So with that,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/10-2
00:01:23.120 --> 00:01:27.938
I'd like to ask you,
what is the state of cybersecurity at
42edf0ba-79e8-4285-bbb7-19ee9dd78855/10-3
00:01:27.938 --> 00:01:30.469
UChicago? What are you doing to
42edf0ba-79e8-4285-bbb7-19ee9dd78855/11-0
00:01:30.669 --> 00:01:38.709
protect the university from cyber attacks
and how has Gen. AI changed your approach?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/12-0
00:01:39.989 --> 00:01:43.769
Yeah, so it's a great question.
Very broad,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/12-1
00:01:43.769 --> 00:01:49.784
a lot of things changing in this space.
As you can imagine, you know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/12-2
00:01:49.784 --> 00:01:54.596
the recent attacks by OpenAI on Hugging
Face, you know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/12-3
00:01:54.596 --> 00:01:58.549
Agentic AI and AI as a whole is being
used to
42edf0ba-79e8-4285-bbb7-19ee9dd78855/14-0
00:01:59.349 --> 00:02:02.684
reduce, I guess,
the time it takes to identify
42edf0ba-79e8-4285-bbb7-19ee9dd78855/14-1
00:02:02.684 --> 00:02:07.580
vulnerabilities and exploit them from
what used to take maybe weeks,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/14-2
00:02:07.580 --> 00:02:12.405
perhaps even days, now into hours.
And when that happens like that,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/14-3
00:02:12.405 --> 00:02:17.869
that creates an environment that it's not
a matter of if you're going to get
42edf0ba-79e8-4285-bbb7-19ee9dd78855/15-0
00:02:17.989 --> 00:02:21.836
you know, hacked.
It's a matter of when and how you respond.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/15-1
00:02:21.836 --> 00:02:26.630
And so our focus has been on, you know,
of course, three legs of the stool,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/15-2
00:02:26.630 --> 00:02:31.298
making sure that we're focused on
remediating the vulnerabilities we know
42edf0ba-79e8-4285-bbb7-19ee9dd78855/15-3
00:02:31.298 --> 00:02:34.326
about,
making sure that we're planning for when
42edf0ba-79e8-4285-bbb7-19ee9dd78855/15-4
00:02:34.326 --> 00:02:37.669
downtime has to occur,
that we have good resiliency,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/16-0
00:02:38.069 --> 00:02:42.956
that we have the ability to recover from
not just an attack, but you know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/16-1
00:02:42.956 --> 00:02:47.257
we use a lot of vendors.
There's a lot of SaaS vendors out there,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/16-2
00:02:47.257 --> 00:02:49.929
right?
It's possible that there could be
42edf0ba-79e8-4285-bbb7-19ee9dd78855/16-3
00:02:49.929 --> 00:02:53.122
situations where we have a very critical
vendor,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/16-4
00:02:53.122 --> 00:02:57.749
say like what happened in May with
Instructure, that's a public event.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/17-0
00:02:59.349 --> 00:03:05.243
And we have to be able to respond and be
resilient in the face of those kinds of
42edf0ba-79e8-4285-bbb7-19ee9dd78855/17-1
00:03:05.243 --> 00:03:10.702
downtimes and things that are going to
occur. And then the third thing is,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/17-2
00:03:10.702 --> 00:03:14.413
of course,
is using AI and using agentic AI on the
42edf0ba-79e8-4285-bbb7-19ee9dd78855/17-3
00:03:14.413 --> 00:03:20.380
team and making sure that we're trying to
be as proactive and knowledgeable as we
42edf0ba-79e8-4285-bbb7-19ee9dd78855/17-4
00:03:20.380 --> 00:03:21.909
can be so that we can
42edf0ba-79e8-4285-bbb7-19ee9dd78855/19-0
00:03:23.189 --> 00:03:26.071
you know,
defend against these adversaries that are
42edf0ba-79e8-4285-bbb7-19ee9dd78855/19-1
00:03:26.071 --> 00:03:28.953
going out there. I mean,
a lot of these things are,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/19-2
00:03:28.953 --> 00:03:31.447
there's some that are financially
motivated.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/19-3
00:03:31.447 --> 00:03:34.606
There's some that are politically
motivated. Ultimately,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/19-4
00:03:34.606 --> 00:03:38.596
despite what the motivations are,
they're still very impactful and they
42edf0ba-79e8-4285-bbb7-19ee9dd78855/18-0
00:03:38.149 --> 00:03:38.549
Her.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/19-5
00:03:38.596 --> 00:03:41.589
really impact the mission of what we're
trying to do.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/20-0
00:03:42.709 --> 00:03:48.100
So for those who are listening to this
episode right now, they may say, I know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/20-1
00:03:48.100 --> 00:03:53.155
you know, yes, there are attacks,
but there are a lot of priorities and we
42edf0ba-79e8-4285-bbb7-19ee9dd78855/20-2
00:03:53.155 --> 00:03:58.412
have to focus on putting our funding for
frontline clinicians. And of course,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/20-3
00:03:58.412 --> 00:04:03.129
our EHR is a huge line item.
And so how do you make the case to those
42edf0ba-79e8-4285-bbb7-19ee9dd78855/20-4
00:04:03.129 --> 00:04:04.949
listening to this show that
42edf0ba-79e8-4285-bbb7-19ee9dd78855/21-0
00:04:05.349 --> 00:04:09.224
Funding needs to be diverted to support
disaster recovery,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/21-1
00:04:09.224 --> 00:04:14.018
to support independent recovery
environments, support high availability,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/21-2
00:04:14.018 --> 00:04:19.272
and to support CISOs and their teams as
they try to prevent and rapidly respond
42edf0ba-79e8-4285-bbb7-19ee9dd78855/21-3
00:04:19.272 --> 00:04:20.389
to cyber attacks.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/22-0
00:04:21.269 --> 00:04:25.047
Yeah, no, that's a great question.
And it's a hard one.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/22-1
00:04:25.047 --> 00:04:30.107
It's a hard one to answer because there's
no direct value creation, right?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/22-2
00:04:30.107 --> 00:04:34.897
You're not creating revenue.
You're protecting revenue in the security
42edf0ba-79e8-4285-bbb7-19ee9dd78855/22-3
00:04:34.897 --> 00:04:38.203
space.
And that's how I kind of like to have the
42edf0ba-79e8-4285-bbb7-19ee9dd78855/22-4
00:04:38.203 --> 00:04:42.386
conversation is that it's even more than
an insurance policy.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/22-5
00:04:42.386 --> 00:04:46.029
Because in an insurance policy,
you never really want
42edf0ba-79e8-4285-bbb7-19ee9dd78855/23-0
00:04:46.109 --> 00:04:49.269
to have to pay out, right?
Because if you pay out,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/23-1
00:04:49.269 --> 00:04:53.545
you're paying premiums into it.
I would say that those premiums that
42edf0ba-79e8-4285-bbb7-19ee9dd78855/23-2
00:04:53.545 --> 00:04:56.395
we're investing into cybersecurity,
you know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/23-3
00:04:56.395 --> 00:05:01.476
should be at a balanced level based on
the risk that you're dealing with. And so,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/23-4
00:05:01.476 --> 00:05:06.495
unfortunately, in things like, you know,
the technology that supports the health
42edf0ba-79e8-4285-bbb7-19ee9dd78855/23-5
00:05:06.495 --> 00:05:09.903
processes that we have,
whether that be revenue cycle,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/23-6
00:05:09.903 --> 00:05:10.709
whether it be
42edf0ba-79e8-4285-bbb7-19ee9dd78855/26-0
00:05:10.749 --> 00:05:16.088
delivery of patient care and clinical
care, and clinical research,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/26-1
00:05:16.088 --> 00:05:22.144
all of those things are extremely
important and part of what the mission of
42edf0ba-79e8-4285-bbb7-19ee9dd78855/26-2
00:05:22.144 --> 00:05:27.882
a healthcare organization is.
And so we have to be able to support that
42edf0ba-79e8-4285-bbb7-19ee9dd78855/26-3
00:05:27.882 --> 00:05:31.149
mission with the right amount of funding.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/24-0
00:05:29.109 --> 00:05:29.589
Mhm.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/28-0
00:05:31.869 --> 00:05:35.912
Now, that funding doesn't have to be,
you know, at a level that's, you know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/25-0
00:05:32.149 --> 00:05:32.629
So...
42edf0ba-79e8-4285-bbb7-19ee9dd78855/28-1
00:05:35.912 --> 00:05:38.432
I guess,
out of line with what you're trying to
42edf0ba-79e8-4285-bbb7-19ee9dd78855/28-2
00:05:38.432 --> 00:05:41.372
work with there,
but you have to look at it from a risk
42edf0ba-79e8-4285-bbb7-19ee9dd78855/28-3
00:05:41.372 --> 00:05:44.890
perspective. What's the impact?
What's the likelihood of something
42edf0ba-79e8-4285-bbb7-19ee9dd78855/28-4
00:05:44.890 --> 00:05:48.461
happening and what that event is?
And what are the costs that would
42edf0ba-79e8-4285-bbb7-19ee9dd78855/28-5
00:05:48.461 --> 00:05:51.349
actually be incurred if that event
actually did occur?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/29-0
00:05:51.749 --> 00:05:54.389
So those are the kind of the factors that
we look at.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/30-0
00:05:55.109 --> 00:05:57.922
Right. So I love that.
I want to go deeper there.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/30-1
00:05:57.922 --> 00:06:02.311
So you said you have to balance your
funding for cybersecurity with the level
42edf0ba-79e8-4285-bbb7-19ee9dd78855/30-2
00:06:02.311 --> 00:06:05.461
of risk you're facing.
I'd like to dive into how you're
42edf0ba-79e8-4285-bbb7-19ee9dd78855/30-3
00:06:05.461 --> 00:06:09.906
evaluating the level of risk and the
amount that an organization should invest
42edf0ba-79e8-4285-bbb7-19ee9dd78855/30-4
00:06:09.906 --> 00:06:13.676
in protection from this risk.
So you said you evaluate the impact,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/30-5
00:06:13.676 --> 00:06:15.589
the likelihood, the cost incurred.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/33-0
00:06:15.869 --> 00:06:21.627
Could you go as specifically as possible
into how UChicago is evaluating the risk
42edf0ba-79e8-4285-bbb7-19ee9dd78855/33-1
00:06:21.627 --> 00:06:25.630
and from there,
deriving a formula to determine how much
42edf0ba-79e8-4285-bbb7-19ee9dd78855/33-2
00:06:25.630 --> 00:06:28.931
to invest in this?
Should we give you 50 FTEs?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/33-3
00:06:28.931 --> 00:06:33.636
Should we give you 20 FTEs?
Should we invest in this IRE with this
42edf0ba-79e8-4285-bbb7-19ee9dd78855/32-0
00:06:32.549 --> 00:06:33.029
Right.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/33-4
00:06:33.636 --> 00:06:34.549
organization?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/34-0
00:06:34.709 --> 00:06:37.429
How do you determine the appropriate
level of funding?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/36-0
00:06:38.309 --> 00:06:41.725
Right, right, right.
So what I use personally is the FAIR
42edf0ba-79e8-4285-bbb7-19ee9dd78855/36-1
00:06:41.725 --> 00:06:44.905
framework.
I don't know if you're familiar with that.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/35-0
00:06:42.189 --> 00:06:42.669
Mhm.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/36-2
00:06:44.905 --> 00:06:49.087
It's a risk management framework
typically used in financial services.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/36-3
00:06:49.087 --> 00:06:53.917
But that simplification of that framework
is essentially what I just told to you,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/36-4
00:06:53.917 --> 00:06:56.744
right,
which is likelihood impact and what that
42edf0ba-79e8-4285-bbb7-19ee9dd78855/36-5
00:06:56.744 --> 00:06:58.629
annual loss expectancy might be.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/39-0
00:06:59.029 --> 00:07:02.521
So we take an look at an incident that
would occur.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/39-1
00:07:02.521 --> 00:07:08.230
What's the likelihood that a threat actor
would gain control and deliver ransomware,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/39-2
00:07:08.230 --> 00:07:11.454
right?
We evaluate that based upon what's going
42edf0ba-79e8-4285-bbb7-19ee9dd78855/37-0
00:07:08.629 --> 00:07:09.109
Mhm.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/39-3
00:07:11.454 --> 00:07:14.476
on in the industry with our peers,
you know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/39-4
00:07:14.476 --> 00:07:18.909
kind of benchmarking against that.
We kind of develop also a risk
42edf0ba-79e8-4285-bbb7-19ee9dd78855/38-0
00:07:14.749 --> 00:07:15.349
Mhm.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/41-0
00:07:19.109 --> 00:07:21.848
appetite,
like we gauge the risk appetite of our
42edf0ba-79e8-4285-bbb7-19ee9dd78855/41-1
00:07:21.848 --> 00:07:24.924
senior leadership and the leaders in the
organization.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/41-2
00:07:24.924 --> 00:07:28.558
And then we balance that with what we
think the impact would be,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/40-0
00:07:25.909 --> 00:07:26.389
Mhm.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/41-3
00:07:28.558 --> 00:07:32.919
what that loss expectancy would be,
and then the likelihood of how that would
42edf0ba-79e8-4285-bbb7-19ee9dd78855/41-4
00:07:32.919 --> 00:07:37.224
occur, say in a five-year period,
how many times do we expect that to occur,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/41-5
00:07:37.224 --> 00:07:39.349
right? Or maybe it's a 10-year period.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/42-0
00:07:40.309 --> 00:07:44.250
We have cybersecurity insurance,
and that's kind of very similar how they
42edf0ba-79e8-4285-bbb7-19ee9dd78855/42-1
00:07:44.250 --> 00:07:47.125
price that.
And so then we have some data that we can
42edf0ba-79e8-4285-bbb7-19ee9dd78855/42-2
00:07:47.125 --> 00:07:50.055
look at to kind of help identify that.
The problem is,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/42-3
00:07:50.055 --> 00:07:53.090
is that there's so many of these events,
like, you know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/42-4
00:07:53.090 --> 00:07:57.244
especially ones that are being driven by
AI now, that we haven't seen before.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/42-5
00:07:57.244 --> 00:07:58.629
And so there's no history.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/45-0
00:07:58.909 --> 00:08:03.518
So when you look at things like car
insurance or you look at things like even
42edf0ba-79e8-4285-bbb7-19ee9dd78855/45-1
00:08:03.518 --> 00:08:06.827
life insurance,
there's literally either 50, 100 years,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/43-0
00:08:03.749 --> 00:08:03.909
Mm.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/45-2
00:08:06.827 --> 00:08:11.378
maybe 200 years of data that insurance
companies are using to generate their
42edf0ba-79e8-4285-bbb7-19ee9dd78855/45-3
00:08:11.378 --> 00:08:16.046
predictability about what they think
those expenses are going to be. In cyber,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/45-4
00:08:16.046 --> 00:08:18.469
we've only been doing this for 20, right?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/44-0
00:08:18.629 --> 00:08:19.029
No.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/47-0
00:08:19.029 --> 00:08:24.640
And so that's that kind of helps kind of
indicate it is a bit of a guess too.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/47-1
00:08:24.640 --> 00:08:27.589
So it's an informed guess, we'll call it.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/46-0
00:08:26.309 --> 00:08:26.629
No.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/48-0
00:08:27.989 --> 00:08:32.956
I think a lot of our listeners would be
interested in hearing about what new
42edf0ba-79e8-4285-bbb7-19ee9dd78855/48-1
00:08:32.956 --> 00:08:38.053
kinds of attacks there have been and how
organizations are responding to these
42edf0ba-79e8-4285-bbb7-19ee9dd78855/48-2
00:08:38.053 --> 00:08:43.279
attacks in new ways with your new agentic
tools. And also in responding to that,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/48-3
00:08:43.279 --> 00:08:47.408
I'd love if you could ground it at all in
actual real examples.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/48-4
00:08:47.408 --> 00:08:49.989
You mentioned a case from this past May.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/49-0
00:08:50.309 --> 00:08:53.234
or even something that may not have
affected you, Chicago,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/49-1
00:08:53.234 --> 00:08:56.309
like the Change Healthcare attack from a
year and a half ago.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/50-0
00:08:57.349 --> 00:09:01.309
Yeah, yeah, so I mean, yeah,
the change healthcare attack is a...
42edf0ba-79e8-4285-bbb7-19ee9dd78855/51-0
00:09:01.989 --> 00:09:06.094
textbook example of a, you know,
a third party risk, right?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/51-1
00:09:06.094 --> 00:09:10.747
Change healthcare was embedded in
everybody's, you know, processes.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/51-2
00:09:10.747 --> 00:09:15.879
And when they got attacked, that impact,
that breach impede, or excuse me,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/51-3
00:09:15.879 --> 00:09:21.490
impacted delivery and collection of funds
and all sorts of revenue cycle problems
42edf0ba-79e8-4285-bbb7-19ee9dd78855/51-4
00:09:21.490 --> 00:09:23.269
that were generated there.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/52-0
00:09:23.749 --> 00:09:27.856
huge numbers that when it was actually
all said and done,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/52-1
00:09:27.856 --> 00:09:33.521
both from the settlements and from the
impacts that health organizations had to
42edf0ba-79e8-4285-bbb7-19ee9dd78855/52-2
00:09:33.521 --> 00:09:37.204
deal with.
There was one in May as well that was on
42edf0ba-79e8-4285-bbb7-19ee9dd78855/52-3
00:09:37.204 --> 00:09:41.665
Instructure, you know,
by a threat actor that has been labeled
42edf0ba-79e8-4285-bbb7-19ee9dd78855/52-4
00:09:41.665 --> 00:09:42.869
as shiny hunters.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/54-0
00:09:43.669 --> 00:09:49.723
They had delivered ransomware,
and that brought down learning management
42edf0ba-79e8-4285-bbb7-19ee9dd78855/54-1
00:09:49.723 --> 00:09:56.108
systems across the world, essentially,
right before or during finals of many
42edf0ba-79e8-4285-bbb7-19ee9dd78855/54-2
00:09:56.108 --> 00:10:02.411
institutions. And as you can imagine,
delaying finals is not a very popular
42edf0ba-79e8-4285-bbb7-19ee9dd78855/53-0
00:10:00.629 --> 00:10:00.869
Mm.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/54-3
00:10:02.411 --> 00:10:06.309
thing to do when you're working with
students.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/55-0
00:10:06.789 --> 00:10:10.802
And so that's, you know,
yet another piece of extortion that,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/55-1
00:10:10.802 --> 00:10:13.910
you know,
that they were looking at to get done
42edf0ba-79e8-4285-bbb7-19ee9dd78855/55-2
00:10:13.910 --> 00:10:16.823
there.
Those are the kind of sophistication,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/55-3
00:10:16.823 --> 00:10:20.124
I guess,
around ransomware gangs that is going on.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/55-4
00:10:20.124 --> 00:10:25.109
But the other thing I would point out is
that with the use of AI is that now
42edf0ba-79e8-4285-bbb7-19ee9dd78855/56-0
00:10:26.229 --> 00:10:31.640
to get into that market of being an
extortion operator or a ransomware gang
42edf0ba-79e8-4285-bbb7-19ee9dd78855/56-1
00:10:31.640 --> 00:10:34.773
is a lot, the bar is much lower now,
right?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/56-2
00:10:34.773 --> 00:10:40.399
Because if you get the right model and
you're able to use it in the right way,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/56-3
00:10:40.399 --> 00:10:46.024
you can identify vulnerabilities and
things way faster than anybody else could
42edf0ba-79e8-4285-bbb7-19ee9dd78855/56-4
00:10:46.024 --> 00:10:46.309
use.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/57-0
00:10:46.829 --> 00:10:52.999
faster than the organizations can respond.
And that is a significant, I think,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/57-1
00:10:52.999 --> 00:10:57.061
event that we probably haven't seen the
end of yet.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/57-2
00:10:57.061 --> 00:11:01.669
And it'll continue to get worse before it
gets any better.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/58-0
00:11:02.389 --> 00:11:08.238
So would it be fair to characterize the
market of black hat cyber criminals as
42edf0ba-79e8-4285-bbb7-19ee9dd78855/58-1
00:11:08.238 --> 00:11:11.866
viewing AI as a democratizing tool,
meaning Gen.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/58-2
00:11:11.866 --> 00:11:18.086
AI is now expanding and making it a lower
barrier to entry for wannabe criminals to
42edf0ba-79e8-4285-bbb7-19ee9dd78855/58-3
00:11:18.086 --> 00:11:22.158
become successful criminals and to do so
more quickly?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/58-4
00:11:22.158 --> 00:11:26.749
Is that the greatest difference between
now and a decade ago?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/59-0
00:11:27.509 --> 00:11:31.575
Oh, absolutely. Yeah, yeah.
The tool sets that are available are much
42edf0ba-79e8-4285-bbb7-19ee9dd78855/59-1
00:11:31.575 --> 00:11:34.480
easier to get a hold of, easier to use.
You know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/59-2
00:11:34.480 --> 00:11:39.186
used to be you had a lot of skills you
had to know. Now you can just ask, right?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/59-3
00:11:39.186 --> 00:11:42.846
How do I do X? I have this,
I want to do this. How do I do it?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/59-4
00:11:42.846 --> 00:11:45.809
You know,
assuming you've got an open weight model
42edf0ba-79e8-4285-bbb7-19ee9dd78855/59-5
00:11:45.809 --> 00:11:47.029
that you've broken or
42edf0ba-79e8-4285-bbb7-19ee9dd78855/60-0
00:11:47.309 --> 00:11:50.192
that some of the larger groups have
trained themselves, right?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/60-1
00:11:50.192 --> 00:11:52.389
That they've built these models
themselves, so.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/61-0
00:11:52.949 --> 00:11:57.013
So are you, so just,
and just to put a bow on this,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/61-1
00:11:57.013 --> 00:12:00.998
are there any brand new types of attacks
from Gen.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/61-2
00:12:00.998 --> 00:12:06.469
AI or just new people doing old attacks
more quickly and effectively?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/63-0
00:12:07.109 --> 00:12:11.289
Well, I mean, ultimately, you know,
in the world of, you know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/63-1
00:12:11.289 --> 00:12:14.540
criminal activity and so forth,
there is always,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/63-2
00:12:14.540 --> 00:12:17.460
it's a repeat of old crimes, right?
I mean,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/63-3
00:12:17.460 --> 00:12:22.569
there's nothing new in that world in
terms of like the what, but in the how,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/63-4
00:12:22.569 --> 00:12:26.949
that's what the new is, right?
And so impersonation is a big one.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/62-0
00:12:22.869 --> 00:12:23.109
Mm.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/65-0
00:12:27.109 --> 00:12:30.340
right?
AI allows for the type of impersonation
42edf0ba-79e8-4285-bbb7-19ee9dd78855/65-1
00:12:30.340 --> 00:12:35.702
and fraud that can be done now over video,
over audio, things of that nature,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/65-2
00:12:35.702 --> 00:12:40.858
you know. And we have seen that.
And we've seen where they not only use it
42edf0ba-79e8-4285-bbb7-19ee9dd78855/65-3
00:12:40.858 --> 00:12:44.983
at a small scale, say,
trying to get someone's credentials,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/64-0
00:12:44.469 --> 00:12:44.949
Mhm.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/65-4
00:12:44.983 --> 00:12:47.389
but I've heard of other attempts at
42edf0ba-79e8-4285-bbb7-19ee9dd78855/67-0
00:12:47.509 --> 00:12:53.749
larger scale things where financial
transactions of large amounts were talked
42edf0ba-79e8-4285-bbb7-19ee9dd78855/66-0
00:12:52.269 --> 00:12:52.949
Mm-hmm.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/67-1
00:12:53.749 --> 00:12:57.189
about.
And that fraud was attempting to be
42edf0ba-79e8-4285-bbb7-19ee9dd78855/67-2
00:12:57.189 --> 00:13:03.269
committed by these groups using simulated
or AI generated tools, excuse me,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/67-3
00:13:03.269 --> 00:13:07.909
people that were, you know,
meant to fool people, really.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/68-0
00:13:07.989 --> 00:13:11.161
It's that's the impersonation aspect of
it. So, so,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/68-1
00:13:11.161 --> 00:13:14.944
but there's always been a level of
attempts at impersonation.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/68-2
00:13:14.944 --> 00:13:19.886
It's just now it allows more people to
try it and it makes it easier for them to
42edf0ba-79e8-4285-bbb7-19ee9dd78855/68-3
00:13:19.886 --> 00:13:20.069
do.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/69-0
00:13:20.469 --> 00:13:23.365
I suppose a listener to this episode says,
wow,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/69-1
00:13:23.365 --> 00:13:26.503
I'm really concerned about impersonation.
You know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/69-2
00:13:26.503 --> 00:13:29.520
I think we're going to do a deal with XYZ
vendor,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/69-3
00:13:29.520 --> 00:13:34.589
and we're going to give them $2 million a
year with an initial payment of 3 million
42edf0ba-79e8-4285-bbb7-19ee9dd78855/69-4
00:13:34.589 --> 00:13:39.115
because it's implementation as well.
How do I know if I'm actually dealing
42edf0ba-79e8-4285-bbb7-19ee9dd78855/69-5
00:13:39.115 --> 00:13:41.589
with the vendor I think I'm dealing with?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/70-0
00:13:42.389 --> 00:13:45.313
Yeah,
so there are tools out there that allow
42edf0ba-79e8-4285-bbb7-19ee9dd78855/70-1
00:13:45.313 --> 00:13:48.746
you to kind of have an intermediary in
place. I mean,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/70-2
00:13:48.746 --> 00:13:52.624
a lot of this has to do with your
business processes, right?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/70-3
00:13:52.624 --> 00:13:57.010
Those tools kind of do a verification.
It always comes down to that.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/70-4
00:13:57.010 --> 00:13:59.871
How do you verify it? You know,
for example,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/70-5
00:13:59.871 --> 00:14:03.749
with people who are impersonating in
order to, you know, the
42edf0ba-79e8-4285-bbb7-19ee9dd78855/71-0
00:14:03.989 --> 00:14:08.793
North Korean job scams that go on, right,
where there's people doing that stuff.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/71-1
00:14:08.793 --> 00:14:13.360
You can do simple things like, well,
require an in-person meeting. You know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/71-2
00:14:13.360 --> 00:14:17.690
perhaps the transactions don't occur
until you've actually shaken hands.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/71-3
00:14:17.690 --> 00:14:20.300
I mean,
I know that's inconvenient and it's
42edf0ba-79e8-4285-bbb7-19ee9dd78855/71-4
00:14:20.300 --> 00:14:23.029
difficult in today's digital world,
but we've
42edf0ba-79e8-4285-bbb7-19ee9dd78855/73-0
00:14:23.069 --> 00:14:26.408
We've got to come up with ways to work
around that. Now,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/73-1
00:14:26.408 --> 00:14:29.805
these companies that provide that
verification, you know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/72-0
00:14:29.349 --> 00:14:29.749
Who?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/73-2
00:14:29.805 --> 00:14:33.144
they are subject also to the same
impersonation attacks,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/73-3
00:14:33.144 --> 00:14:37.596
many times at a higher scale than what
others, because if you get in there,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/73-4
00:14:37.596 --> 00:14:42.048
you've got access to a lot of stuff,
right? So yeah, it's a great question,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/73-5
00:14:42.048 --> 00:14:45.328
but it comes down to your processes more
than anything.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/73-6
00:14:45.328 --> 00:14:47.789
So cyber is moving out of this space of...
42edf0ba-79e8-4285-bbb7-19ee9dd78855/74-0
00:14:47.869 --> 00:14:53.748
of what I'll call baseline security into
this concept of digital trust, right?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/74-1
00:14:53.748 --> 00:14:59.255
And that digital trust is where we're
going to have to build not just the
42edf0ba-79e8-4285-bbb7-19ee9dd78855/74-2
00:14:59.255 --> 00:15:05.134
cybersecurity aspects, but also privacy,
resiliency, and trust into, you know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/74-3
00:15:05.134 --> 00:15:10.269
all parts of the organization so that
people understand what exactly
42edf0ba-79e8-4285-bbb7-19ee9dd78855/75-0
00:15:10.549 --> 00:15:15.280
and who they're dealing with,
because that's where the attackers are
42edf0ba-79e8-4285-bbb7-19ee9dd78855/75-1
00:15:15.280 --> 00:15:16.309
moving towards.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/76-0
00:15:16.949 --> 00:15:21.598
So how have you been working to direct
your team to enhance privacy, trust,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/76-1
00:15:21.598 --> 00:15:25.269
and resiliency at UChicago?
What are some discrete methods,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/76-2
00:15:25.269 --> 00:15:28.083
potentially with infrastructure,
for example?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/76-3
00:15:28.083 --> 00:15:32.488
Is there something that are you moving?
Is it private cloud or on-prem?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/76-4
00:15:32.488 --> 00:15:35.363
Are you doing kind of,
as I mentioned earlier,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/76-5
00:15:35.363 --> 00:15:39.829
an independent recovery environment?
Are you thinking disaster recovery?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/79-0
00:15:40.029 --> 00:15:44.115
What are you doing specifically,
especially from, you know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/79-1
00:15:44.115 --> 00:15:47.111
under beneath the scenes,
beneath the hood,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/77-0
00:15:46.469 --> 00:15:47.589
Yeah, yeah.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/79-2
00:15:47.111 --> 00:15:50.789
that people won't see to enhance these
digital trust?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/83-0
00:15:51.269 --> 00:15:54.169
Yeah, yeah.
So if you think about from the standpoint
42edf0ba-79e8-4285-bbb7-19ee9dd78855/83-1
00:15:54.169 --> 00:15:57.982
of if you're providing a service,
even if you've contracted with a SAS
42edf0ba-79e8-4285-bbb7-19ee9dd78855/83-2
00:15:57.982 --> 00:16:02.064
provider to provide that service,
to build the trust with our constituents,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/81-0
00:15:59.309 --> 00:15:59.829
Mhm.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/83-3
00:16:02.064 --> 00:16:04.642
right,
we've got to make sure that that service
42edf0ba-79e8-4285-bbb7-19ee9dd78855/83-4
00:16:04.642 --> 00:16:08.080
stays up. Or if it does go down,
we're able to recover quickly.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/83-5
00:16:08.080 --> 00:16:11.195
That's the disaster recovery or BCP
portion of it, right?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/82-0
00:16:08.389 --> 00:16:08.869
Mhm.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/83-6
00:16:11.195 --> 00:16:14.149
But we have to work closely with our
partners on that.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/85-0
00:16:14.509 --> 00:16:18.482
doing things like, you know,
not just backing up the data and not just
42edf0ba-79e8-4285-bbb7-19ee9dd78855/85-1
00:16:18.482 --> 00:16:21.839
having a recovery of the data,
but also the configurations.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/85-2
00:16:21.839 --> 00:16:24.861
When you set up a SAS tool,
if anybody has, you know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/85-3
00:16:24.861 --> 00:16:29.058
done any large scale SAS deployment,
there's still a significant amount of
42edf0ba-79e8-4285-bbb7-19ee9dd78855/85-4
00:16:29.058 --> 00:16:33.534
configuration that goes into those and
you have to be able to back that back up
42edf0ba-79e8-4285-bbb7-19ee9dd78855/84-0
00:16:32.389 --> 00:16:32.949
Mhm.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/85-5
00:16:33.534 --> 00:16:35.829
if you're going to rebuild it if you get.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/86-0
00:16:35.909 --> 00:16:40.009
hit with a ransom or they get hit with a
ransomware attack and those kinds of
42edf0ba-79e8-4285-bbb7-19ee9dd78855/86-1
00:16:40.009 --> 00:16:41.429
things. In terms of like...
42edf0ba-79e8-4285-bbb7-19ee9dd78855/87-0
00:16:43.589 --> 00:16:50.043
what we're doing across the board,
identity verification is a critical piece
42edf0ba-79e8-4285-bbb7-19ee9dd78855/87-1
00:16:50.043 --> 00:16:56.331
of that infrastructure. So, you know,
administrators, software developers,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/87-2
00:16:56.331 --> 00:17:01.109
anybody that maybe holds keys to a
kingdom of some sort,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/88-0
00:17:02.629 --> 00:17:06.263
has to be verified. If they say, oh,
I can't remember my password,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/88-1
00:17:06.263 --> 00:17:10.602
I've got to go get it reset. Well, great.
You're going to be getting on a video
42edf0ba-79e8-4285-bbb7-19ee9dd78855/88-2
00:17:10.602 --> 00:17:14.236
call with this and you're going to have
to provide your, you know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/88-3
00:17:14.236 --> 00:17:18.412
either passport or government ID so that
we know who you are and that we can
42edf0ba-79e8-4285-bbb7-19ee9dd78855/88-4
00:17:18.412 --> 00:17:22.371
verify that that is indeed the case.
That identity verification is a key
42edf0ba-79e8-4285-bbb7-19ee9dd78855/88-5
00:17:22.371 --> 00:17:25.029
aspect to the assurance that we need to
provide.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/89-0
00:17:25.429 --> 00:17:29.477
when we're working with these folks.
That's definitely at a very discreet
42edf0ba-79e8-4285-bbb7-19ee9dd78855/89-1
00:17:29.477 --> 00:17:33.909
level. That's how we're talking about it.
The same is true with vendors as well.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/90-0
00:17:34.629 --> 00:17:39.016
I think it's really interesting that
there are increasingly,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/90-1
00:17:39.016 --> 00:17:44.481
according to what I'm hearing from you,
analog responses to end with manual
42edf0ba-79e8-4285-bbb7-19ee9dd78855/90-2
00:17:44.481 --> 00:17:50.162
workflows with physical airplane flights
to have meetings and physically shake
42edf0ba-79e8-4285-bbb7-19ee9dd78855/90-3
00:17:50.162 --> 00:17:54.909
hands in response to technological
advancement with AI. It's just
42edf0ba-79e8-4285-bbb7-19ee9dd78855/91-0
00:17:54.989 --> 00:18:00.699
an interesting kind of, I guess,
pendulum swing in response to pushing
42edf0ba-79e8-4285-bbb7-19ee9dd78855/91-1
00:18:00.699 --> 00:18:02.629
forward with technology.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/94-0
00:18:03.109 --> 00:18:06.164
Yeah, yeah.
And it's balanced with the risk, right?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/94-1
00:18:06.164 --> 00:18:08.808
I mean,
a risk of a $50 transaction is a lot
42edf0ba-79e8-4285-bbb7-19ee9dd78855/94-2
00:18:08.808 --> 00:18:12.334
different than a risk with a $5 million
transaction, right?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/92-0
00:18:11.029 --> 00:18:11.509
Mhm.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/94-3
00:18:12.334 --> 00:18:15.154
And so we balance that with the risk.
But yeah,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/94-4
00:18:15.154 --> 00:18:18.797
that is the quickest and easiest way to
do that verification,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/94-5
00:18:18.797 --> 00:18:22.029
because every time we come up with a
digital solution,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/93-0
00:18:22.469 --> 00:18:22.949
Mhm.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/95-0
00:18:22.469 --> 00:18:26.149
the attackers come up with a way to
circumvent that, right? So.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/97-0
00:18:27.429 --> 00:18:31.635
I would like to,
we're running up on the end of this
42edf0ba-79e8-4285-bbb7-19ee9dd78855/97-1
00:18:31.635 --> 00:18:37.667
podcast episode, so a few more questions.
Just to circle back real quickly,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/97-2
00:18:37.667 --> 00:18:43.700
when we were talking about the attacks of
Change Healthcare or Instructure,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/96-0
00:18:43.189 --> 00:18:43.589
Uh-huh.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/97-3
00:18:43.700 --> 00:18:47.589
has there been any post-mortem evaluation
of the
42edf0ba-79e8-4285-bbb7-19ee9dd78855/98-0
00:18:47.629 --> 00:18:53.828
costs of those attacks and any comparison
between those costs and the expected fair
42edf0ba-79e8-4285-bbb7-19ee9dd78855/98-1
00:18:53.828 --> 00:18:59.658
framework projected cost of what those
attacks would have been like, you know,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/98-2
00:18:59.658 --> 00:19:02.389
a few years ago prior to the attacks.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/101-0
00:19:02.789 --> 00:19:07.091
Yeah, no, that's a great question.
I'm not aware of any research in that
42edf0ba-79e8-4285-bbb7-19ee9dd78855/101-1
00:19:07.091 --> 00:19:11.511
space that would do that. I mean,
there have been what I'll call estimates
42edf0ba-79e8-4285-bbb7-19ee9dd78855/101-2
00:19:11.511 --> 00:19:15.106
of the change health care attack,
and you can look those up.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/99-0
00:19:14.909 --> 00:19:15.429
Mhm.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/101-3
00:19:15.106 --> 00:19:19.644
I don't have them off the top of my head.
My memory is it was over a billion
42edf0ba-79e8-4285-bbb7-19ee9dd78855/100-0
00:19:19.029 --> 00:19:20.629
Mm hmm. But.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/101-4
00:19:19.644 --> 00:19:21.589
dollars. But that could be wrong.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/102-0
00:19:21.989 --> 00:19:25.895
In general, I guess not specific,
but more generally,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/102-1
00:19:25.895 --> 00:19:31.972
do you feel like the actual frequency and
costs associated with attacks are aligned
42edf0ba-79e8-4285-bbb7-19ee9dd78855/102-2
00:19:31.972 --> 00:19:35.589
with the projected frequency and cost of
attacks?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/105-0
00:19:37.189 --> 00:19:41.677
Well, we can never predict the future.
And so they're always going to be,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/105-1
00:19:41.677 --> 00:19:44.770
you have,
there's an element of guessing that goes
42edf0ba-79e8-4285-bbb7-19ee9dd78855/105-2
00:19:44.770 --> 00:19:48.106
on, I guess,
maybe intuition that you have to apply to
42edf0ba-79e8-4285-bbb7-19ee9dd78855/105-3
00:19:48.106 --> 00:19:52.473
those kinds of things, right?
The past is not always a predictor of the
42edf0ba-79e8-4285-bbb7-19ee9dd78855/103-0
00:19:48.869 --> 00:19:49.189
Who?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/104-0
00:19:50.949 --> 00:19:51.429
Mhm.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/105-4
00:19:52.473 --> 00:19:56.597
future. Because, you know, I mean,
who would have predicted, right,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/105-5
00:19:56.597 --> 00:19:59.509
we would be dealing with generative AI
attacks.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/108-0
00:20:00.069 --> 00:20:04.693
in today's world five years ago. You know,
I don't think that was on my radar.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/106-0
00:20:02.469 --> 00:20:02.789
Got.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/108-1
00:20:04.693 --> 00:20:07.269
And especially with regards to those
costs.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/107-0
00:20:04.789 --> 00:20:05.269
So...
42edf0ba-79e8-4285-bbb7-19ee9dd78855/109-0
00:20:08.069 --> 00:20:12.520
So just kind of a final question,
I'd like to open up for you, Matt.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/109-1
00:20:12.520 --> 00:20:16.714
Talk about kind of AI governance or
conceptualizing investing in
42edf0ba-79e8-4285-bbb7-19ee9dd78855/109-2
00:20:16.714 --> 00:20:21.617
cybersecurity as insurance policies,
evaluating your investment in terms of
42edf0ba-79e8-4285-bbb7-19ee9dd78855/109-3
00:20:21.617 --> 00:20:26.069
the risk posed by new attacks.
What are some final parting thoughts?
42edf0ba-79e8-4285-bbb7-19ee9dd78855/110-0
00:20:26.349 --> 00:20:29.744
either advice to listeners on what they
should do at their organizations,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/110-1
00:20:29.744 --> 00:20:33.368
or maybe even advice to yourself a year
ago about what you wish you would have
42edf0ba-79e8-4285-bbb7-19ee9dd78855/110-2
00:20:33.368 --> 00:20:34.469
known that you know now.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/111-0
00:20:35.349 --> 00:20:40.063
Yeah, that's a great, great question.
Yeah, I would say that first of all,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/111-1
00:20:40.063 --> 00:20:43.834
you're never going to be,
you're never going to have enough
42edf0ba-79e8-4285-bbb7-19ee9dd78855/111-2
00:20:43.834 --> 00:20:46.914
knowledge.
So just accept the fact that we don't
42edf0ba-79e8-4285-bbb7-19ee9dd78855/111-3
00:20:46.914 --> 00:20:51.189
know what we don't know right now.
Many times we have to begin with
42edf0ba-79e8-4285-bbb7-19ee9dd78855/111-4
00:20:51.189 --> 00:20:54.709
something and start somewhere.
AI governance is a very,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/112-0
00:20:56.469 --> 00:21:00.607
interpreted term now, right?
Depending on your place in the
42edf0ba-79e8-4285-bbb7-19ee9dd78855/112-1
00:21:00.607 --> 00:21:05.366
organization and depending what vertical
you're in. But essentially,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/112-2
00:21:05.366 --> 00:21:08.883
you have to have some understanding of
how the AI,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/112-3
00:21:08.883 --> 00:21:14.539
how AI tools and how AI systems are being
set up in your organization so that you
42edf0ba-79e8-4285-bbb7-19ee9dd78855/112-4
00:21:14.539 --> 00:21:17.229
don't actually create a bunch more risk
42edf0ba-79e8-4285-bbb7-19ee9dd78855/113-0
00:21:17.309 --> 00:21:21.163
that you're going to have to be dealing
with, you know, a year from now.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/113-1
00:21:21.163 --> 00:21:24.225
At the same time,
you have to enable it because there's a
42edf0ba-79e8-4285-bbb7-19ee9dd78855/113-2
00:21:24.225 --> 00:21:27.129
lot of FOMO.
A lot of organizations are concerned that
42edf0ba-79e8-4285-bbb7-19ee9dd78855/113-3
00:21:27.129 --> 00:21:31.194
they're not going to be relevant if they
don't get these things implemented,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/113-4
00:21:31.194 --> 00:21:33.834
you know,
and so they want to be first to market.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/113-5
00:21:33.834 --> 00:21:36.949
And so that's fair.
I think that's a very fair assessment.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/114-0
00:21:37.989 --> 00:21:41.219
But you have to balance it.
So you have to include people.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/114-1
00:21:41.219 --> 00:21:44.833
You got to make sure that you're
collaborating with your security
42edf0ba-79e8-4285-bbb7-19ee9dd78855/114-2
00:21:44.833 --> 00:21:47.406
professionals,
but also with the business unit
42edf0ba-79e8-4285-bbb7-19ee9dd78855/114-3
00:21:47.406 --> 00:21:49.924
responsible, you know, executives,
et cetera,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/114-4
00:21:49.924 --> 00:21:54.085
to make sure that they are involved in
that decision making that's going to
42edf0ba-79e8-4285-bbb7-19ee9dd78855/114-5
00:21:54.085 --> 00:21:54.469
happen.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/115-0
00:21:55.189 --> 00:21:59.161
All right, thank you, Matt,
for joining us. For our listeners,
42edf0ba-79e8-4285-bbb7-19ee9dd78855/115-1
00:21:59.161 --> 00:22:03.259
this has been Matt Morton,
the AVP and CISO at the University of
42edf0ba-79e8-4285-bbb7-19ee9dd78855/115-2
00:22:03.259 --> 00:22:07.483
Chicago. And again, Matt,
thanks so much for joining us on Healthy
42edf0ba-79e8-4285-bbb7-19ee9dd78855/115-3
00:22:07.483 --> 00:22:08.429
Uptime Podcast.
42edf0ba-79e8-4285-bbb7-19ee9dd78855/116-0
00:22:09.189 --> 00:22:11.109
Sounds great. Thanks, Jordan.
Appreciate it.
We recommend upgrading to the latest Chrome, Firefox, Safari, or Edge.
Please check your internet connection and refresh the page. You might also try disabling any ad blockers.
You can visit our support center if you're having problems.