Transcript
with Skip Sorrels. He's one of our field CTOs. Skip, I'd love to know what you've seen around the show this week and how you're seeing the CPS market for healthcare right now. Sure, thanks for having me. Man, I'm super excited to be here. The weather's been great. RSA's hopping. AI is top of mind for everybody that I talk to, but the other question comes in, man, what about this thing with Stryker? What about healthcare? What about HIPAA? And there's so much going on that is projecting an image, or to me, kind of where things will go. We're gonna move in healthcare from a recommendations from, you know, OCR from HIPAA to a regulation that will result in fines or reduction in reimbursement. That's the signals we're seeing from legislation. And I'm not a big fan of the carrot and stick, but sometimes you gotta have a skin in the game. I just hope that what we see is some money come towards healthcare to help build their infrastructure up and get rid of some of the legacy debt that is out there. There was money pushed to the states for rural healthcare in January. That's huge. Lots of money going to that. So paying a closer attention to how we help out the rural communities that are serving the underserved. I think the key thing for me that I'm asked a lot this week already is, well, what would you do? And I said, you know, governance is the underpinning of everything that you do in cybersecurity, but more importantly, we've got to remember the fundamentals are the most important things we have to cover. And we tend to look that over, because we're always looking for a silver bullet, and there really isn't one. So that's kind of my take and feel of RSA so far. Yeah. I mean, we're right in the middle of it, so we'll see how the rest of the day goes. It makes sense. And we see the industry advancing, and there's so much innovation visible in products across cybersecurity as a whole. And yet, attacks happen that are taking advantage of the same underlying problems that we've seen for 20, 30 years. I imagine that's even more challenging to address in a connected healthcare environment that has largely legacy devices that were never intended to be anywhere near internet facing. How are organizations dealing with that kind of disparity of all of the connectivity and none of the technical capabilities for it? I think one, there's an awareness that's happening. It's bringing attention to operational technologies and healthcare as an example, which is largely considered to be facilities, right? They don't think about the infrastructure of a city, like a hospital basically, being compromised. And the things that we've learned just in the last couple of weeks is that adversaries are looking for the path of least resistance. They're not using malware to create compromise. They're finding legacy systems with default passwords or no passwords sitting open on the internet, and they're just walking through the front door with it. And it's sad. So the addressable issue there is one, we've got to know what we have to protect it. So it's all about visibility and understanding what is on the wire, where it talks to the internet, what it's talking to, and just start locking those doors and closing the windows, so to speak. Knowing what is in what cabinet and how to lock the cabinet. Absolutely. Really excited to have you with us. Thank you so much. I am personally really looking forward to your Lunch & Learn today. What else are you looking forward to about the rest of the week? What I can learn. I love talking to people and hearing how they're addressing their own environments and their own issues. And that takeaway with that is extremely powerful. Help me in the field, help other people. So thank you. Yeah, amazing. Well, thanks so much. And we hope to see you at the Lunch & Learn later. Yes, please come join me.