This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Frank Riccardi. Frank is a cybersecurity and privacy expert and former C-level executive with 25 years of experience developing compliance and privacy programs for large healthcare systems. Riccardi has held positions as Chief Compliance and Privacy Officer overseeing high-profile data breaches and cybersecurity investigations. His book, “Mobilizing the C-suite: Waging War Against Cyberattacks,” urges C-suite leaders to take action against cyberattacks by deploying basic cybersecurity controls and supporting frontline cybersecurity professionals with companywide cyber hygiene training. It also introduces real-world cybersecurity principles to college students, our future generation of cyber-savvy leaders.
Chapter Titles:
00:00 Introduction
00:19 Our Guest
01:20 Frank’s Background
02:05 2021 Events, Motivation, and the Colonial Pipeline
07:28 Regulations in Healthcare
10:14 Does the C-suite understand that Cyber is a business problem or an I.T. problem?
17:53 The trickery behind the technology
21:17 The Human Factor is the weakest link in Cybersecurity
23:27 Why do Healthcare organizations ask for Social Security?
28:15 Why can’t the healthcare industry solve the problem?
31:55 Bills from Hospitals. What percentage do they get?
35:38 Mobilizing the C-suite: Waging War Against Cyberattacks
36:55 Connect with Frank!
Audio:
Important Links:
Transcript
Manoj Tandon (0:09)
Hello everyone, this is your host, Manoj Tandon. Welcome to another episode of Dark Rhino Security Confidential. Today we have another awesome guest. He is Frank Riccardi. Frank has over 25 years of experience in cybersecurity. He’s a former C-level executive in the healthcare industry. He has a lot of experience developing compliance and privacy programs for very large health systems. And he’s the author of the book, Mobilizing the C-Suite: Waging War Against Cyberattacks. And that’s just scratching the surface of who he is. He’s about practical advice and taking practical actions. Welcome to the show, Frank. Thank you so much for being here.
Frank Riccardi (0:59)
It’s a pleasure to be here, Manoj. I appreciate it. Thank you.
Manoj Tandon (1:04)
So, you can’t pick up a newspaper or a website, oftentimes, unfortunately, where you don’t see a data breach in the healthcare industry. So your timing is very appropriate to be seeing our forum here.
But were you always a cyber person? Is that how it started?
Frank Riccardi (1:23)
By accident. So, I’ve been in the healthcare field for 25 years. As you know, hospitals and physician practices—which is where I worked, I worked for big healthcare systems—had daily breaches and cyberattacks. I worked my way over the years to Chief Privacy and Compliance Officer roles. In those roles, I had a lot of experience, unfortunately, with managing data breaches, ransomware, and private cyberattacks. So over the years, I developed deep expertise in cybersecurity as well as data privacy.
Manoj Tandon (2:02)
Wow. And you sound fairly motivated. What’s the secret to that, given all the bad things that have happened in the healthcare sector in this regard?
Frank Riccardi (2:15)
In 2021, there were a spate of cyberattacks. You recall in 2021, it was just a terrible year. You had the rise of the Delta virus, so COVID-19 was raging. You had a lot of political issues: the January 6th riot in the Capitol, the chaotic withdrawal from Afghanistan. Everybody’s mood was bad.
On top of that, we had three horrible cyberattacks. There was a cyberattack on Schreiber Foods. They were a big dairy conglomerate in Wisconsin. There was a cyberattack on JBS Foods, which is a big meatpacking plant, and their meatpacking plants in the United States were shut down. So what you had with these two cyberattacks with Schreiber Foods, that was one of the causes of the great cream cheese shortage of 2021. You couldn’t get a smear on your bagel, and that makes people grouchy. With the JBS shutdown, you couldn’t get a ham and turkey sandwich. Not only does that make people grouchy, but now they’re worried about their food security. But the worst one was Colonial Pipeline in May of 2021. What happened there is there was a ransomware cyberattack, and basically, the executives shut down the pipeline. Colonial Pipeline had a pipeline that stretched from Texas to New Jersey, so it was 5,500 miles of pipeline, and it was shut down for a week along the East Coast.
If you think things make people grouchy—I can’t get a smear on my bagel, I can’t get meat—now on top of that, I can’t fill up my SUV. People are now, for the first time, making the connection that cyberattacks and ransomware are not just something ethereal that happens in cyberspace and it’s not just about data breaches; it can happen in the physical world. It can affect me in the physical world.
Then, with all the Congressional hearings over Colonial Pipeline, the public learns why the cyberattack was successful. With Colonial Pipeline, like a lot of other companies in the pandemic, they let their employees work remote, and they set up VPN accounts. They had an employee that would log in with the VPN. That employee quit and went to work somewhere else.
It’s believed that the password used for the VPN account was a reused password that the employee used somewhere else. Well, it got stolen. We don’t know how it got stolen, but there was a cybercriminal gang called DarkSide, and they were a Russian cybercriminal gang. Somehow, they got the stolen, reused password, and they put it in the VPN. Essentially, a credential stuffing attack, and it worked.
Now, what the public learns is they say, “Well, wait a minute, when that employee left the company, why didn’t Colonial Pipeline shut down that VPN?” That’s a common internal control. Had Colonial Pipeline done that, the cyberattack wouldn’t have happened. The other thing is the VPN was not protected by multi-factor authentication. Had MFA been enabled, DarkSide wouldn’t have been able to get in, even with the password, because they wouldn’t have the one-time numeric code.
This changes the paradigm. The public is really mad at cybercriminals for these cyberattacks, but now what happens is if the cyberattack happened because the company failed to implement basic cyber hygiene, like a basic control like MFA or not letting your employees access systems when they leave the company, or even teaching employees about the dangers of reused passwords—if it’s simple controls that were not implemented, what happens is the public is now just as angry at the C-suite as they are at the cybercriminals.
One of the reasons I wrote the book is I wanted executives to understand there is a greater degree of accountability now than there has been in the past for them to make sure they support a cybersecurity program and to understand basic cyber hygiene so that they can shepherd the organization to thwarting these cyber tactics.
Manoj Tandon (6:06)
Have you gotten any feedback from them?
Frank Riccardi (6:09)
Yes and no. Most of the feedback that I’ve gotten is very positive; the book’s doing very well. When I give presentations, executives get a little bit worried about it because they do enterprise risk assessments, and usually the internal audit division or whoever’s doing it puts cybersecurity straight at the top.
They’re scared about it. I think they do realize that they have a greater degree of accountability than they did in the past. I don’t think they understand why, but when they read my book and I give them the presentation, they make the connection.
If there’s one cyberattack a non-technical executive needs to know, it’s the Colonial Pipeline cyberattack. Once you understand that, all of the new regulations that are coming out—the Securities and Exchange Commission, there was a congressional law that came out, the Federal Trade Commission is doing a lot of work, there’s a lot of enforcement—all of that is flowing from the damage done by Colonial Pipeline. If you have to understand only one cyberattack, that’s the one to understand, and then you will understand your level of accountability.
Manoj Tandon (7:21)
Are there unique regulations in healthcare that have come to light that are further mandating healthcare systems to report on and take care of cyber in a different way than in the past?
Frank Riccardi (7:38)
I say HIPAA. HIPAA has always really required healthcare organizations to step up with cybersecurity. The Office for Civil Rights and other organizations have always been mandating regular requirements and so forth.
For example, encryption. Encrypting laptops—something as simple as that. Healthcare organizations, if they’re giving their employees laptops, these have to be encrypted, and there has to be workforce education on the encryption. Encryption is thwarted if an employee can’t remember the password, so they put it on a sticky note and stick it on the laptop, and it gets stolen in a smash and grab. So you have to educate the employees: don’t put a sticky note with the password on the laptop. Then, if you’re traveling, put the laptop in the trunk; don’t leave it on your car seat because the fines and penalties for a lost laptop that’s not encrypted, or if the encryption is bypassed, are going to be astronomical.
So I don’t think there are necessarily regulations that have making enhanced requirements. I think they’ve always been there. I just think that you have federal agencies that are promulgating rules, making requirements, and doing enforcement actions, like the Office for Civil Rights. They’ve been saying for a long time, “If you lose a laptop and there’s data on it and it’s not encrypted, get ready to write a check.”
Manoj Tandon (9:13)
Wow. And is that only in healthcare, or is that anybody?
Frank Riccardi (9:15)
I would think it’s anybody. I can only imagine. I can’t believe that would just be limited to healthcare. I would say this in my book to executives when we’re talking about encryption: don’t get hung up on the laws, don’t get hung up on the regulations. All you need to know is this:
If you have data on a mobile device and it gets lost and it’s not encrypted, get ready to write a check because whoever is going to enforce it, whether it’s the FBI, the Department of Justice, the Office for Civil Rights—whatever it is—they’re going to throw the book at you. If it’s a breach of unencrypted data, they are going to throw the book at you. So you don’t need to know what the regulations are; you just need to know it’s a big risk they have to be careful with.
Manoj Tandon (10:01)
As you were talking, one thing that occurred to me is: do you think the C-suite understands that cybersecurity is a business problem and not an I.T. problem?
Frank Riccardi (10:10)
I don’t know that they do. My experience in healthcare is the vast majority of C-suite executives that I’ve worked for come from a variety of disciplines. They might be former doctors, they might be former people in marketing, they might be legal, they might be Human Resources, or they could be in operations and they worked their way up.
But they don’t really come from an I.T. background, and I don’t know that they see cybersecurity as something that is a business enhancer, especially for this age of digital transformation. Digital transformation can do wonders for an organization, but sometimes I think cybersecurity is just not considered. It may be looked at as an add-on or more as a risk, unless there’s a business opportunity.
And it really is a business opportunity because the public is becoming more and more savvy about cybersecurity, and people very often may choose a more expensive option or a different option because they feel more comfortable with the security. I think there’s still a ways to go in the C-suite, and I think there’s a lot of education and discussions to be had.
Manoj Tandon (11:27)
Oh yeah. My reason for asking is like you look at, as you very eloquently stated, Colonial Pipeline, right? So yes, they could have shut it down with MFA; that was absolutely one way to deal with that vulnerability. The other way was you didn’t need any technology whatsoever. It was a question of process, and this is the part that bothers me personally.
When we talk to companies, a lot of times they’re just concerned about tech, more tech. “I’m going to throw more tech at it.” Well, a lot of things are cyber hygiene that you don’t need any tech for, other than a pencil and a paper and someone diligently tracking it. Had they de-provisioned that gentleman that had left, that doesn’t require any tech. All that does is somebody in I.T. to go in and turn his access off.
Frank Riccardi (12:21)
You just need a policy and procedure that says the Human Resources department, when an employee leaves the workforce, there’s a process to notify the I.T. department, and then the I.T. department terminates their access within 24 hours. That’s all you need, and it doesn’t need to be fancy.
Manoj Tandon (12:44)
That’s right. And I can tell you, as a professional in this industry, we have seen it time and time again that the de-provisioning part of the cycle is often broken. No one is really going in there and auditing it. There needs to be an identity life cycle. When you use the term “identity life cycle,” now that becomes a techie thing. It should be a personnel life cycle. When Manoj joins, this is what’s going to happen. When he leaves, this is what’s going to happen.
Frank Riccardi (13:15)
It’s just someone going through the checklist like pilots do a takeoff. Flaps set? Gas in the tank? Yes, it’s definitely something that should be audited periodically because it’s not just about the cyberattack. What if Frank Riccardi leaves the organization and he’s an aggrieved employee, and he’s mad at somebody and he’s still going in the systems? It’s not just a cyberattack because someone’s going to do a ransomware cyberattack; it’s just bad practice to let your employees still have access to your systems.
Manoj Tandon (13:53)
I guarantee you, if we randomly just threw a dart at a healthcare system in this country—you could pick anyone, I don’t care if it was Mayo Clinic, Cleveland Clinic, or Joe’s rural doc shop—I would absolutely bet good money that we would find process issues. The technology might be there, but as an example, even if you have MFA, Frank, what kind of policies have you put on top of MFA? What does MFA look like? Have you geofenced your MFA?
Frank Riccardi (14:24)
Right. And have you explained to your workforce? Because people don’t realize MFA is bypassed; it’s not perfect. There’s no perfect countermeasure.
You look at there was a cyberattack in 2021 against Twitter, and it was a spear phishing attack. What you had is three basically teenage cybercriminals. One was a guy who’s 19 years old from Boca Raton, Florida.
They went on the Twitter website, they got the HR policy and procedures, and they found out, “Oh, we found these four people that are super users, and when there’s a problem, they can go in and reset the password.” But they can also retract a tweet or add a tweet or do all these things. So they found out that the VPN network was slow, and these cybercriminals called these four employees, pretending to be from the help desk. They said, “Hi, I’m from the help desk. I understand your VPN is slow. I can help you. Let’s reset the password.”
They directed the employees to a fake website that looked like the Twitter website, and the employees put their username and password there. In real time, the cybercriminal saw it and then put the password in the real Twitter website. What happened is it generated an MFA request, and they just said to the person, “Oh, an MFA request is going to come; go ahead and approve it.” And they did.
So the cybercriminals got access to the Twitter account. They got access to Elon Musk, President Obama, and all these celebrities. Then they launched all these tweets saying, “Hi, I’m President Obama” or “I’m Elon Musk. If you send me a thousand dollars in Bitcoin, I’ll give you 2,000 just to pay it forward.” They actually gave the link to the cryptocurrency. It’s laughable, but they netted a hundred thousand dollars in Bitcoin. It worked.
Manoj Tandon (16:30)
It’s genius. I mean, that’s crazy. One thing—and that’s the other side of this—when people think about cybercriminals, Frank, as soon as you use the term “criminal,” people have this image of a guy with a knife or a gun on the street, some kind of a thug-type stereotype.
Frank Riccardi (16:49)
Whatever the hoodie looks like.
Manoj Tandon (16:51)
Cyber bad actors are—they might wear a hoodie, but they’re extremely intelligent people.
Frank Riccardi (17:04)
They are, and they’re exploiting process. What you described there was a stunningly beautiful example of exploiting a process. None of that exploitation really involved technology, other than that they didn’t really hack anything; they were given access.
Let me give you another example because you’ve hit on something. At the end of the day, it really isn’t so much the technology; it’s the trickery behind the technology. The technology doesn’t actually work without the trickery.
I’ll give you a good example. You probably have a lot of pen testers and ethical hackers that tune into the show. They’re all familiar with a device called the WiFi Pineapple. It’s called a Pineapple; it’s got these spiky antennae, even though it doesn’t look like a pineapple. It’s sold by a company called Hak5, and it’s just a glorified WiFi access point.
So, if I’m going to get a cup of coffee at a coffee shop, I’m looking on the ceiling and there’s a device. It’s the good wireless access point, and that’s what I want my smartphone to connect to. But a cybercriminal will use a device like a Pineapple and they’ll call it an “evil twin” because they’re trying to get you to connect to that instead of the good one. Once they do that, they can try to trick you to go on a fake website. A fake website is called an “evil portal.” It’s really a phishing scam—a high-tech phishing scam—to get you to put credit card information or a username and password so that they can steal it.
But here’s the thing: the WiFi Pineapple is a useless piece of junk if you just know that when I go to a coffee shop, it’s an insecure network and maybe I shouldn’t be checking my Charles Schwab account, making trades, or buying stuff on Amazon. If I am, I’m looking in the address bar. Where’s that padlock? Oh, maybe the site’s not encrypted. Or why does it not say HTTPS? Where’s the “S”? It’s just HTTP. What’s going on? Maybe it’s not encrypted. Maybe I’d better get the heck off. Or better yet, maybe a coffee shop is just meant for coffee and a newspaper.
Once you understand the trickery, the technology is almost an afterthought. When you’re trying to explain these things to executives, or your grandfather, your grandmother, or your dad, I like to talk about the technology, but then I like to talk about how it’s really the trickery. Once you know it’s the trickery, the technology won’t bother you.
Manoj Tandon (19:23)
That is employee awareness training. That’s the crux of cyber right there. That’s why this is a business problem and not an I.T. problem. It’s a human behavioral issue.
We had a gentleman from the CIA on whose professional, paid life was, for many years, to get people to do illegal things in other countries. I asked him, “How hard is it to compromise a human being?” I’m just paraphrasing because I don’t remember his exact answer, but it was, “It’s really easy to compromise people.” They’re so believing. A lot of times they’ll just give up the information. They don’t even know that they gave it up.
That Pineapple is exactly that: you’re giving up your username and password. I guarantee you that username and password has probably been reused a thousand times in other places. So now once I have it, I’ll try and get into your Netflix account.
Frank Riccardi (20:33)
The human factor—they say the human factor is the weakest link in cybersecurity. You brought up a reused password. There are studies that show that when companies force their employees to reset their password every 90 days, employees don’t reset the whole password; they just put an exclamation point at the end of it. They’ll just change one character of the password, and cybercriminals know this when they’re doing their password-cracking methodologies or when they’re trying to figure things out. It’s just human nature.
There are other studies that show that human beings cannot remember 100 different passwords, and so it just makes it very easy for people to want to reuse their passwords. But it’s an incredible risk that needs to be explained. Then that gets to, again, a process and policy thing. Should we go to passwordless systems as much as possible? And in cases where we need a password, why aren’t we using password managers with incredibly complicated passwords, so that people are forced to use a password manager because they’re not going to type in a 22-digit-long thing that is some encrypted gobbledygook?
Manoj Tandon (21:45)
But that’s again a policy directive; that’s not a technology directive. And that’s what I hope that people listening get across—that there’s so much to be done from a policy standpoint.
Do people audit their internal processes from a cybersecurity view, Frank? Does that happen in healthcare?
Frank Riccardi (22:07)
I don’t know if it’s happening enough. When you have a cybersecurity program, one of the things you should be doing is an annual risk assessment, and that should be part of the annual risk assessment: what processes do we need to look at?
The example of not terminating systems when someone leaves the organization is one. But yeah, you have to do a risk assessment and just try to figure out, because you can’t audit everything and it just gets to be an overwhelming task. But it would be part of a risk assessment to figure that out.
Manoj Tandon (22:48)
Absolutely. Let me ask you a simple question: why are healthcare organizations almost universally asking for an individual’s name, address, and then the final trifecta, the Social Security number? Why do they…? I always refuse to provide my Social Security number to a medical establishment, and they get really upset about it. They don’t like that.
Frank Riccardi (23:09)
My guess is that it’s the same reason that many others do, but when I was working in healthcare, you’d be surprised how many people have the same last name. You can have people with the same last name in a community, so one part of it is they’re trying to find a unique identifier to make sure that they’ve got the right patient.
Another part of it—and this is perhaps a darker side—is there’s a discussion to be had around healthcare organizations going after patients when they can’t pay. I think they want to have as much financial information as possible for some of those processes as well. So I think there are probably a lot of reasons for it, some good, some not so good, but I don’t think the reasons for that are any different than any other business. But I agree with you; I don’t like giving that out.
Manoj Tandon (24:10)
Well, if you think about it, now the risk is on both sides. Once you have my name, address, and Social Security number, you don’t need me. You now have a person. On that form, all medical forms have date of birth, name, address, and Social Security number.
I am irrelevant as a human being at that point. If you have that data, you can go to Chase Bank, fill out a form, or fill it out online—be anonymous—and you could create an account with my name, and I won’t know a heck about it. Then you can commit all kinds of financial fraud and the problem is I’ll get stuck with the bill.
There was a court case recently, and this was with a gentleman who lost $20 million because his phone got SIM swapped. That’s how they bypassed his MFA. They paid off an internal support agent at AT&T $200 and said, “Hey man, I need you to transfer this SIM to my phone.” Now guess what? All your MFA requests, everything.
There again is a good example. Cybercriminals bypassed not with technology; they just bribed somebody. But here’s what happened: they said AT&T was not liable, or T-Mobile, whoever the carrier was. The courts ruled that they’re not liable for the 20 million dollars in damages.
In the case of a healthcare situation, I would imagine a savvy attorney is going to probably cite that case. If a company commits fraud with your name, Frank, and you go after that healthcare system and sue them, you have no recourse.
Frank Riccardi (25:54)
I don’t know what the law is around it, but it just seems to me that an organization, whether it’s AT&T, Verizon, or a healthcare system, ought to be accountable and responsible for crimes like that that are committed with their information by their employees. There should be some level of accountability, but I certainly understand the frustration.
Manoj Tandon (26:23)
Well, I also see it even on the side of the healthcare system. If you’re storing people’s core identities and then that data is stolen from your environment, there has to be a real liability on you, even today, if not from me then at least federal agencies. Someone’s going to come after you if you give up everybody’s data.
Frank Riccardi (26:44)
Absolutely. I think the liability is just off the charts for data breaches and cyberattacks. Not just for healthcare, but I think the liability is off the charts. Some C-suite leaders have lost their jobs over it because of cyberattacks—some famous cases. Accountability is indeed high.
Manoj Tandon (27:07)
Going to healthcare breaches, Frank, we were briefly talking pre-show, and one of the things, if we study them, you’ll find recurring patterns that happen over and over again as to how these systems are compromised. Why is the healthcare industry not able to plug the holes? What’s the problem?
Frank Riccardi (27:35)
I think it’s a couple of things, not any one more important than the other.
One reason is they are being targeted by cybercriminals a lot more than other organizations because they’re sitting on a mountain of very valuable data. But more important than that, they service a very vulnerable population. If you’re a cybercriminal and you can shut down a nursing home or shut down a hospital, it’s not a white-collar crime; it’s a threat-to-life crime. Nothing gets a hospital administrator’s attention more than having to turn away patients because these patients could die, or nursing home residents could die if they’re not getting their medication. It’s a real patient safety issue.
So it’s not so much trying to get operations up and running to get the business going; lives are in jeopardy. They tend to be hit a lot more, I think, than other organizations. I think it’s just that cybercriminals have a lot of attention on hospitals and physician practices.
I think the other piece of it, too, is that there is a misperception that hospitals and physician practices and other healthcare providers make a lot of money and have a lot of profit. They don’t. Many organizations—rural health systems, healthcare organizations—are barely making it. So they don’t have all the money and the wherewithal to spend on cybersecurity, even if they think that they need to.
So I think there are budget problems. I think the third problem is that another issue is that in healthcare, a lot of people that make it to the top in the C-suite come from areas that are not directly in I.T. You might be a physician, you could be a healthcare provider, you could be in marketing, HR, legal, or operations, so you’re concerned about a lot of risks, a lot of things, and a lot of issues, and not necessarily just cybersecurity.
I think that the healthcare industry has struggled more than other industries. A good example is critical infrastructure like utility companies. They’re putting tons and tons and tons of money into cybersecurity. Big bank companies and financial companies like JP Morgan—I think JP Morgan puts a billion dollars a year into cybersecurity. They have huge programs. The hospital industry does not have the financial bandwidth to be able to do that.
Cybercriminals know that they don’t have the bandwidth; they don’t have all the cybersecurity controls in place necessarily. They know that they’re sitting on a mountain of data that the cybercriminals can monetize, and they know if they can shut down a hospital, a physician practice, or a nursing home with ransomware, the motivation to pay the ransom is going to be pretty high because people could die. I think healthcare is really in the crosshairs for cyberattacks.
There definitely needs to be—and actually, I think there is now—attention at the federal level to try to help healthcare organizations fend off these cyberattacks and deal with what they need to do to get their programs and their systems cyber-ready and cyber-resilient.
Manoj Tandon (30:51)
One question that comes to mind: you mentioned that there’s a perception that hospitals make a lot of money. I guess there is that, and I’d love for you to daylight when you look at the charges from a hospital, especially if you don’t have insurance and you get billed off a Charge Master in the hospital. You get these ridiculous bills that no one can afford to pay. How is it that someone taking in that kind of cash can’t… Where did the money go?
Frank Riccardi (31:20)
I could have a conversation with you about reimbursement, and the Charge Master, and the billing—it’s Byzantine, it’s complex—but what gets charged and billed is not what they actually get. What organizations get from Medicare or Blue Cross or other payers, particularly private payers, is based on contract.
There’s a lot of competition. You may have two or three big hospitals in an area—in a town that can really only support one hospital—and they’re competing with each other. So the hospital field is really struggling financially; they always have been for a long time. It’s not a big money-making process.
I’ll tell you: executives that go into healthcare don’t go in to make money; they go into it because they truly care about the patients. They’re on a mission, especially some of these faith-based healthcare systems. Beautiful, faith-based missions. So it’s a different kind of—I don’t even want to call it a business—profession where money is only part of it, but it’s patient safety, it’s spiritual and physical well-being of the community, it’s community benefit.
I will tell you, the vast majority of hospitals are really struggling financially.
Manoj Tandon (32:46)
Well, that’s something I did not… My impression was totally different. So thanks, Frank.
Frank Riccardi (32:54)
Well, somebody might have a different opinion, but that’s mine.
Manoj Tandon (32:56)
No, I’d rather hear from someone that’s been in the business as to what the heck is going on here. Because it just doesn’t come across that way when you look at healthcare premiums and what all of us who are on the payer side of it get.
Frank Riccardi (33:17)
Listen, I’m a user of healthcare too, and when I see my co-pay and deductible and how much it costs… But you think about healthcare services: they’re heavily labor-intensive, they’re heavily technology-intensive, and I just don’t see the hospital industry as being… It’s beleaguered, honestly. It’s beleaguered.
Manoj Tandon (33:39)
And that gets back to our conversation on cyber. Maybe take a brief pause on the tech and audit your processes. You might be able to get a huge bang for your buck there.
Frank Riccardi (33:51)
Yeah, focus on the human factor. Focus on human beings and the processes and how departments are working together. Try not to have silos. Technology is only a piece of the puzzle; the human side is probably 90% of it.
Manoj Tandon (34:04)
Let’s talk about your book a little bit more in detail. Who should be reading it, other than the obvious C-suite person?
Frank Riccardi (34:15)
Anybody in any organization that wants to understand basic cyber hygiene. If you’re an employee in an organization or an executive and you don’t know a lot about cybersecurity, this book is a quick read and it’ll bring you up to snuff. You’ll understand basic cyber hygiene and understand the countermeasures.
For every countermeasure you have—strong passwords, MFA, encryption, and so forth—for every measure, a cybercriminal can defeat it, and you’ll learn how they can defeat it. You’ll learn some of the technology, but you’ll understand that it’s the trickery and the scam that’s actually more important than the technology. Very often, the technology doesn’t work without the trickery.
Then I also talk about different risks: Shadow I.T. is a big risk, offshoring is a big risk, and not having good data backups is a big risk. So anybody that wants to learn about cybersecurity in an organization, how to protect yourself—it’s a great book to teach cyber hygiene to your company.
Manoj Tandon (35:24)
Okay. Fantastic. Well, Frank, we’re at the hour here, and I wanted to… Is there anything you’d like to plug? I want to give you the floor for a couple minutes.
Frank Riccardi (35:37)
Thank you. I guess if your listeners are interested in my work and what I do, I’d appreciate if they go to my LinkedIn profile. They can connect or follow me, and there’s a bell to the right of my picture. If you click on the bell, you’ll always get my posts.
I post frequently on cybersecurity issues and privacy issues, but I also post about dogs, I post about classic rock vinyl albums, and I even posted about my 105-year-old watch that is in my family from my grandfather—his railroad watch. A lot of fun things if you want to connect or follow me.
This was fantastic. I really enjoyed being on your show, and I enjoyed the conversation; it was wonderful.
Manoj Tandon (36:22)
Well, I learned a few new things, and I really appreciate you taking the time out of your busy day to do this. This has been really good, Frank. We’ve only scratched the surface; there’s a lot to talk about here.
Thank you so much.
Frank Riccardi on Linkedin
Franks’ Book
Check out the other episodes in Season 12:
Ep. 0 Dark Rhino Security – The IT Security Money Pit
Ep. 1 Marius Poskus – Tech talk overwhelms the nontechnical
Ep. 2 Robert Black – Who is responsible for Cybersecurity?
Ep. 3 Eric Allard – Your Guide to SBOMs
Ep. 4 Ryan Leirvik – Understand, Measure, and Manage Cyber Risk
Ep. 5 Dan Wachtler – Building Awareness About Your Startup
Ep. 6 Peter Warmka – A Seniors Survival Guide
Ep. 7 Susan Bennett – More than the Voice of SIRI
Ep. 8 Frank Riccardi – The Human Factor is the Weakest Link
Ep. 9 Dmytro Bielievtsov – What is Vishing?
Ep. 10 Chris and Rory – Bourbon Breakdown
About Frank Riccardi

Frank is a cybersecurity and privacy expert and former C-level executive with 25 years of experience developing compliance and privacy programs for large healthcare systems.
Riccardi has held positions as Chief Compliance and Privacy Officer overseeing high-profile data breaches and cybersecurity investigations.
His book, “Mobilizing the C-suite: Waging War Against Cyberattacks,” urges C-suite leaders to take action against cyberattacks by deploying basic cybersecurity controls and supporting frontline cybersecurity professionals with companywide cyber hygiene training.
It also introduces real-world cybersecurity principles to college students, our future generation of cyber-savvy leaders.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
