Transcript
And so this idea that we can get people together in a small environment, 15 execs at a time, they can chat in house rules, have the conversations about the really important, complicated stuff they're working on, why it works, why it doesn't work, and build these relationships that are unlike any other relationships you build any place else. Welcome to Building Cyber Resilience in Healthcare. The attackers are learning from each other and we should be too before everything's on the line. Here, healthcare leaders share the stories, insights, and lessons that get hospitals operational again faster and patient care restored. I'm Josh, your host, and with that, let's get started. Welcome. Today, I'm joined by Drexta Ford. He's a CIO, strategist, and CIO consultant and coach today. He's the host of the podcast, Unhack and Two-Minute Drill. Today, he serves as the president of the 229 Project Cyber and Risk Programs, and he's been a CIO and led transformation projects at the U.S. Air Force, Seattle Children's, Scripps Health, and Steward Healthcare. And today, we're going to talk about what it means to do the slow thinking now so you can take fast action later and what sort of priority cyber resilience projects deserve. Drexta, good morning. Thank you so much for being willing to be with me. I've enjoyed joining your podcast over time and I'm excited to talk with you this morning. I think you've got so much to share. So maybe you could start off by just helping people understand your role, This Week Health, the 229 Project, and then we can jump into a little chat about cyber resilience. Absolutely. So I'm Drexta Ford. I'm the cybersecurity and risk guy at This Week Health, but I'm a longtime healthcare CIO. Scripps and Seattle Children's and Steward, I was an independent consultant for a number of years, wound up as executive healthcare strategist at CrowdStrike before I came to This Week Health. So I've never really been, I always like to say this, I've never been a chief information security officer. I've always been a CIO who had security responsibilities the CSO often reported to me, but I've never actually done that specific job. Obviously, it's always been really important to me. And as Bill Russell, the founder of This Week Health, and I continued to sort of work together and talk together before I joined This Week Health. We talked a lot about cybersecurity and the issues that were just in many ways kind of ravaging healthcare over the last several years. And so Bill and I worked something out for me to come to This Week Health. And then we've also have started this project called the 229 Project. So think of This Week Health as sort of like the media arm of our company. And the 229 Project being the in-person events. And we thought the in-person events turned out to be really important because leaders in isolation are sort of doomed to failure. And so this idea that we can get people together in a small environment, 15 execs at a time, they can chat in house rules, have the conversations about the really important complicated stuff they're working on, why it works, why it doesn't work, and build these relationships that are unlike any other relationships you build any place else. So you find these people that you can lean on and learn from. And literally we see people leave the events and they have new best friends, new best friends who are peers from other organizations like their health system, but also great relationships with partners who are a big part of this project, 229 Project process. And you guys at Rubrik are part of that too. And we do this in different ways. We have sort of two and a half day summits and we do these city tour dinners, which are sort of one night events. And then starting next year, we did our first one this year, but starting next year, we'll do something called city staff round tables where we start to now push down into the organization. CIOs bring their teams and we create those connections across healthcare organizations in specific regions or cities. So it's been, I mean, it's been great fun on the cybersecurity side of the house. There's so many things to learn. There's so many potholes. Folks are in such different places from a security maturity perspective that opportunity to sort of find people who are ahead of you and they help pull you up or find people who are behind you that you can help pull up. It's super rewarding. And I love the work we're doing right now. Yeah, that was my first exposure to you and Sarah and Bill was at one of your summit events. And it was fascinating for us, like being on the vendor side, we have theories about what's important. We have theories about what are priorities and then getting to kind of sit in the back row and listen to all of these executives and CIOs talk about what's real in their world and what they're struggling with. And it was fascinating getting to listen to a CIO talk about the attack that they had experienced and the lessons they wanted everybody else to learn. And that was kind of the origins of this YouTube series was, and they actually said it, they said, here's what I would like everybody to know, but you can't tell them it came from me because I am share freely. Yeah, so question that I have for you is you coach a ton of CIOs today and you've been one and we think cyber resilience is really important. Probably no coincidence. It's how we make our money, but I'm well aware that there is a difference when you are responsible for such a wide variety of things. You've got so many projects coming at you, that are not the least of which 175 billion cut from Medicare and Medicaid. And it makes me question, is this actually important at a strategic level? Like when you think about everything a CIO has on their plate, where would you put cyber resilience as a priority? Yeah, no, it's a very interesting issue. We just did at This Week Health for our partners, we just did a presentation actually yesterday and it's kind of the, what we call the state of the CIO report. And it's sort of the compilation of all the conversations that we've had across 2025, all the city tour dinners and summits and other events and one-on-one conversations, both interviews and just phone calls. As you alluded to, there's a ton of people who just call and want to talk. And sometimes it feels like a counseling session or a mental health counseling session. But sometimes folks just want to get stuff off their chest or ask if we know somebody who knows something about whatever it is they're struggling with. I've called you guys and been like, I don't know where to start with this problem. Like, who do I talk to? And you've been very kind. Right. So the state of the CIO report, we cover eight major topics that were all sort of like the core parts of the discussions that we had during all of the events. The top three, you can probably guess what number one was, artificial intelligence and all of the branches of artificial intelligence we could have done the whole session just on AI. The second one definitely tied to that was sort of re-skilling and up-skilling because the world is changing so fast. Consolidation, new products, new capabilities. AI certainly plays into this. So re-skilling staff. The third issue, the number three issue was resilience. And so I think there's been this evolution of CIO, CISO, CTO thinking about resilience. We used to really sort of talk about it as business continuity. And we were really, I think we thought about this as our job in information services is incident response and recovery. Get the systems back up if they go down for cybersecurity reasons or any other reason. Business continuity is out there. The business clinical and research operators have to figure out how they're going to continue to work when the system goes down. So it's really their job. Paper processes, all the tools they need. What do they need to continue to operate? We can't tell them that, that's their job. And so there was always sort of like holding this BC part at arm's length. But I think what's happened over the last few years is that it's become really clear. We've always known that health systems are kind of like the bedrock of their communities. When they go down, there's chaos usually across the community. Even when there's multiple hospitals, the impact that it has on the other hospitals in the market who aren't having a cybersecurity event, but the negative impact it has on them and their patients and families. The challenge that staff has just with their own issues when something goes down, cybersecurity or otherwise. I think just that push of figuring out how do we continue to operate has become, we just can't wait anymore. So the resilience conversation now has rolled into the CISO and the CTO and the CIO and even the board about, we have to figure out how we're going to operate when we're down. And that probably isn't just a few hours. That may very well be a few days or several weeks. And each one of those stages kind of demands a different kind of work that we need to do to make sure that we continue to operate. Including all of the discussions around, when do we just declare that we have degraded capabilities? When do we close the emergency department? When do we, how do we change staffing levels? We've become so reliant on the technology that it's just, I think everyone's thinking hard about resilience and how do we run when the systems are down. Yeah, it reminds me, I've probably brought this up before, but I had this really thought-provoking conversation with an obstetrics nurse who is still practicing at 72 because she loves what she does and the health system still needs her because there's not enough nurses. And so, she's now working part-time. But she said, I was talking with her about this problem and she said, I'm the poster child for knowing how to do it the old way. And the thing that she brought up that was so thought-provoking to me is you've heard that conversation. These younger doctors and nurses don't know how to do it on paper. And it kind of like everybody chuckles and the conclusion is, well, we really need to drill them harder on how to run on paper. But she laid out this case of like the health system itself has changed. It's not the same as it was when we ran on paper. And it's not a question of, do we know how to do it on paper? It's that we can't do it on paper anymore beyond a short period of time. And she laid out all of these interesting effects like the manual that she used to use to calculate drug dosages. She's like, I hadn't seen that at a nurse's workstation in five or more years. We had to Google it because she had forgotten the title. And when she saw it on Google Image Search, it was like that one. That used to be at every nurse's workstation. Now it's not there anymore and hasn't been for a long time. And it kind of got me on this path of thinking about how there used to be layers of redundancy or people in certain positions, like there was a vacuum tube system that used to have a person who grabbed the packages and put them in the right areas for the right departments. Now that's a robot, right? And I think over the course of, you know, a decade or two, we've slowly made cost optimization decisions, you know, process improvement, whatever, that was designed for the current context where everything was stable, everything was online, and not having those drug manuals at every workstation. Why? We're not using them, right? Why would we spend money on this? But then when the tech goes away, now there's no fat, there's no cushion, there's no, you know, resiliency. And we are so leaned out that everything being down is a huge problem, right? The standard of care has changed. The variety of interventions that we can offer has changed. Every laboring mother is now on, you know, monitoring. That's a standard of care. And she even, like, outlined for me how the facility had changed, that it used to be a lot of mothers labored together in a single ward. So as a nurse who had five, you know, mothers concurrently, it was really easy to have awareness of this is what's happening with this patient, that's what's happening with that patient. And she's like, now it could be 300 feet in largely soundproofed rooms. And without that monitoring, I might miss something. And it just brought me back to this question of, like, cost optimization. And at the same token, I recognize everybody is struggling for every dollar at the moment. But, like, how do you balance this desire for cost optimization with knowing that the whole system can be upended at any point, right? And there's no fat left in the system. There's no resources who can, you know, take that on. That nurse is already stretched so thin. So I don't know where the question is exactly in that, but I would love to hear your thoughts. I'm with you. I mean, one of the things I say all the time is moderation in all things, including moderation. And what sort of happened, even with, like, the rooms, now every patient has, you know, a private room. This is a thing that's happened with the consumerization of health care. And we want to get, you know, good scores on those patient surveys. And so we've done away with sort of multi-patient rooms. And I don't think anybody did any of this kind of like in the, you know, for a bad reason. Yeah, we have an electronic health record. We spent $400 million on that. Why do we need these little books at all the nurses' stations now? Makes no sense. Let's just get rid of them. The problem with this, and it turns out, you know, even things like, I'm a Toyota production system guy. And I remember being at a health system when we went through a whole process of figuring out how to lean down supply chain. And we pushed a lot of this to the suppliers, repackage what we need and the number and the quantity that we need and deliver it every day. And then we don't have, we don't run that risk, the joint commission finding expired supplies or expired drugs because they all show up. They're fresh all the time. In fact, we can take the giant warehouse and we can make it a tiny little warehouse now. We don't need nearly all that space. We can convert that space into other things that we need. And that was all great until the pandemic hit. And then we realized like, oh no, we only have two days worth of supplies and the truck drivers aren't coming to work and the port people aren't coming to work and everything else that was going on. And so these are unintended consequences, right? I think we build systems that we assume are going to work flawlessly or even if they break, they're not going to break really, really hard. And yeah, and so we create efficiencies because of that. And we should. I mean, that is kind of innovation at its nutshell. How do we do more with less? By taking out waste. But the taking out waste is the, it can turn out to be the problem because you kind of referred to it as fat. Sometimes the fat in the system is the fat that you need to be able to survive those lean times. And we've just become so aggressive at trimming fat and the environment has created such an aggressive situation that we have to trim the fat, all of it, all the way down to the bone. And I think this is where we wind up. We wind up now stuck around things like resilience and how can we be resilient when we really only have this way of doing it. Yeah. And I don't know that there's a great answer because I'm hypersensitive to, I'm aware of how thankless a task it must be to be a leader in healthcare when on one hand you're looking at $175 billion cut from Medicare, Medicaid, every dollar is being questioned and scrutinized. And yet we can also see at the same time there's this need to have more redundancy, a bit more resiliency, and all of that costs, right? So I don't know exactly how, if I was a CIO today, how you square that circle. It is a huge problem. I mean, the balance is the tough part. And I think it's, you know, you find the places from a risk perspective that are the most risky where you need to start and you start there. Part of the problem with this, I think for a lot of people, and it's because also the world that we live in, they feel like I can't have a good resilience plan unless I solve world hunger. Like it has to be everything, whether it's, you know, partners who support us, who have had their outages, cloud partners who've supported, who've had their outages. There's nothing I can do about that. I don't know that I really have a backup plan for that. I mean, how do I have three EMRs running or, you know, something like that so that I've got a backup plan for my EMR all the time? But it's the challenge, I think, of just sort of saying, let's just start small. Where's the place that we can put in the best part of the backup system, the resilience system? The thing that if this really fails, it's going to really affect everything. Let's start with that and kind of grow that resilience program out over time. You're not going to be able to spend all the money in the world to solve every problem. And there's going to be some pieces of this you're just going to have to accept as, this is risk. It could be that this bad thing happens and we just have accepted that we're not going to have a resilience plan for that. We can't afford it. Yeah, two things come to mind. I was at a conference recently and a bunch of senior leaders from different health systems and one of them asked the question, if I knew I had a week, if I knew that our health system was going to get hit with an encryption attack next week, what would you recommend I do in the interim? Like, what are the highest priority things? And it led to a really good exercise of, you know, helping pull together this timeline that's downloadable from this YouTube series of all of the things that happen, all of the insights and trying to give people a list. So I pulled out five or six things and I was like, if it were me and I knew I had one week, this is what I would do in this order. And we got on some subsequent calls and I thought there was a lot of value in that conversation of, you know, there's a tendency when you have all of these teams who all have their part of it and everybody needs to understand what the others are doing. Like, there's this mutually dependent uncertainty before we can move forward. And yet, if we said like, it just happened, go. Well, there's no choice. We've got to get started. And when you get started, you can, through experimentation, work out this is what isn't working. We don't have a place to recover to, right? We need an isolated recovery environment. Well, where would we put it? We don't have our backup data. That got destroyed. Well, let's really figure out the difference between immutability between vendors, right? We don't have enough automation. We can't deploy systems fast enough. We don't know which applications to pursue in what order. Well, let's start pulling together that answer. And so this idea of like, don't let perfect be the enemy of the good. When you start doing, you will start learning. And the beautiful thing about a cyber recovery is so often is in an isolated environment. So there's nothing that stops you from doing this in the middle of the business day, trying to recover your most critical systems into an isolated recovery environment because production will be unimpacted. You don't have to worry about duplicate addresses or names on the network or any of that. So I've kind of been poking people in the meetings I talked to of like, if you knew you had one week, where would you start? What would you do? I like that scenario. I mean, this is the kind of thing that causes people to think about what is really important? How would I start this process? That kind of conversation combined with stuff like tabletop exercises, how do we run the playbooks? Do we have playbooks? When's the last time we actually looked at the playbooks? They're not all in SharePoint, are they? We might not be able to get to them if the systems are down, right? So it's all those kinds of things that people think through. You sent me the PDF the other day and I started looking through it and I'm just like, it's a dense, calorie-rich document that has all kinds of cool things that people have shared with you. And I know you're going to continue to update it. And I think it really is a thought-provoking, and it's not war and peace either. It's actually just a few pages, but it's very thought-provoking around how should I prepare? What are the scenarios I should be thinking about? What are the things that people who have been through this after the fact said, man, I wish we would have done this because it would have saved us a lot of time or a lot of pain are in this PDF. So, I mean, great job putting this together and I'm looking forward to when you actually sort of publish it widely. I think a lot of people are going to love it. Oh, thank you. Yeah, actually, every conversation I have, something new occurs to us that we add. I was on a panel at Chime a couple of weeks ago, and one of the members on the panel shared something that was super insightful around their cyber insurance provider wouldn't compensate them for certain things unless they could show how long that specific application was offline. So they had needed to have somebody taking notes of exactly what happened in their recovery process and the timestamps so that they could complete that documentation. And it's fairly simple, but it would have never occurred to me when the fat was in the fire of, hey, somebody should be the scribe, right? Somebody's got to take notes on what's happening with this event, yeah. It's really interesting, too. I mean, those things that, especially tied to cyber liability insurance, the, you know, who do we want to come and help us with our incidents? You know, can I put them on a retainer? Who do I have to get to approve this retainer process from the cyber liability insurance company? Those are all things that you can work in advance. I have a retainer with this company. I have a pre-approval from cyber liability insurance to say that when the bad thing happens, I can just call the, I can call my partner and they can, you know, bring the fire truck in the water and, you know, start working with us immediately. I don't have to go through a bunch of, jump through a bunch of hoops because all the time lost in any of those conversations, all that stuff is, you know, the situation just gets worse at your facility. You're touching on something really important. Can you drill down more there? So if I'm understanding what you're saying, you're talking about in the wake of an incident, you need certain people, skill sets, companies, organizations to conduct your recovery. Having pre-approval to reach out to them, like whitelisted with legal, is that, am I capturing that? Yeah, I mean, all of that, right? So if you don't have an incident response retainer with a partner so that they are ready to go, as soon as you dial their number, they immediately, you know, jump in planes or jump online and start figuring out how to help you. I hope everyone has one. And if you don't, and you start calling your breach coach and your cyber liability insurance company, they're going to make a recommendation for someone who can help you. And that's going to create now a situation where you're going to have to create a contract with those companies. All of this delays time. Any of these conversations are just time delays, right? So this work you can do in advance with your cyber liability insurance company and your incident response retainer company, making sure that they're connected and you have documented pre-approval process to say that if I have an incident, we can just start fixing it right away. And the cyber liability insurance company says, yeah, that's a company that we work with. We really like them. They're auto approved. You just, when you're ready to go and a bad thing happens, you just go. That's the kind of situation, I mean, seconds count. And it's sort of like figuring out as in your document, there's a lot of things in there that can just help people go faster. And speed is the key to the operation when it comes to a cyber incident. So Drex, we've talked about a whole bunch of things. I think you've really given us some goodness to think about of doing the slow thinking now so you can take fast action later of all of the organizations that you're going to need to conduct a recovery, getting pre-approval to talk to them so that you can take delays out of the process and can just start executing instead of needing legal approval, negotiating contracts so that activation of the army you're gonna need to conduct a recovery. I think that's a really valuable insight that people can take away and it's congruent with what I've heard from real world cases. So thank you for that. Anything else you wanna share before we drop off? No, it's always great to talk to you. I feel like sometimes when we're together, we could just click the button and record for a couple of hours. There's a lot of stuff I know that you're working on and I'm working on and it's always good to have a conversation and sit down with you. Thanks for having me on. Well, thank you for being with us. Appreciate you and happy Friday. To help build cyber resilience in healthcare, we've been gathering all the lessons learned from past ransomware attacks we've come across and we're making them available to help listeners prepare effectively. To download this content, please visit the link in the comments. We also wanna hear from you. If you know somebody with insights and lessons learned who'd be willing to share, reach out to me on LinkedIn and we'll get them on the show. Thank you.