This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Kevin Tambascio. Kevin is the director of cybersecurity data and application protection for the Cleveland Clinic. He has over two decades of experience in software development and cybersecurity. Kevin has done work in embedded systems and attack surface reduction and has a couple of patents related to this. He is the president-elect for the Northern Ohio HIMSS Chapter. In his spare time, he supports Velosano in fundraising for cancer research.
Chapter Titles:
00:00 Introduction
02:12 From Rockwell to Cybersecurity
04:53 Nation-state actors
07:32 FedEx and Merck Cyber insurance lawsuit
09:04 Cybersecurity awareness for healthcare. Is it discussed?
13:08 Getting the Executive’s attention
18:19 Healthcare Data
21:55 Purple Team/Red Team: What is their role?
27:40 Getting the word out about Cyber
33:03 Embedded Systems: How big of a threat are they and how do we manage it?
37:22 Compromised Chips
38:16 Open source components: What are the risks?
41:06 Updating the law? Can we secure everything?
45:24 Velosano: fundraising for cancer research.
47:42 More about Kevin
Audio:
Important Links:
Transcript
Manoj Tandon
Welcome to another episode of Dark Rhino Security Confidential. Today we have another fantastic guest, Kevin Tambascio. I hope I didn’t pronounce that incorrectly, Kevin. Kevin’s a fantastic guy, and he’s from my hometown back in Ohio, so he gets extra points for that.
Regardless, he’s currently the Director of Cybersecurity Data and Application Protection for Cleveland Clinic. He’s worked at great companies like Rockwell. He has over two decades of experience in software development and cybersecurity, and he has a couple of patents to his name to add to the credentials here. Also, Kevin, I believe you’re the president-elect of the HIMSS chapter in Northern Ohio. Congratulations on that.
When he has spare time—and I don’t know when he does, but when he does—he likes to get involved with charities, and he’s working with VeloSano in raising funds for cancer research.
Thank you, Kevin, for being here and joining the show.
Kevin Tambascio
Thanks, Manoj. Thanks for having me.
Manoj Tandon
I really appreciate it. That’s quite a resume you’ve got there. I gotta tell you, there are a lot of questions. I don’t know how many we’re going to be able to get through today, but I can tell you that everyone listening is going to have a keen interest because there’s not one of us that, unfortunately, is not going to get sick and at some point is going to need healthcare.
It’s just a fact of life; it’s part of being human. Unfortunately, healthcare has been in the news a lot. A lot of health systems have been in the news, so I’m sure you’ve got the audience’s attention. Let’s start with your work at Rockwell.
Rockwell deals with industrial systems, and now you’re in healthcare. Those two worlds on the surface seem very different when it comes to cyber, but how did that experience shape your view into healthcare cybersecurity?
Kevin Tambascio
Yeah, thank you for the question. I spent over 18 years at Rockwell, starting as a software developer, and then I started to get into cybersecurity well before we had any formal cybersecurity programs or activities happening there.
We started to create internal products and cybersecurity governance at some point, and started to build secure requirements, including pen testing of products—a number of different activities aligned to really improve the security of those products before they hit the market.
If you’re not familiar with Rockwell, they produce products that work in the industrial control system sector. This includes many industry verticals like pharmaceutical, water and wastewater treatment, food and beverage production, and energy production and distribution. There are many different verticals that are impacted by cybersecurity, and I worked with them to drive improvements into the product lines.
A lot of people, when I told them I was going to the Cleveland Clinic, were really surprised. I even have a family member who works at the Clinic and she was like, “Why would you come here? Why is this important?” It was really eye-opening.
There are a lot of similarities and a lot of differences. Similarities include looking at how healthcare is a critical infrastructure. It is a critical industry just like power or food and beverage production here in our country. There are lots of legacy systems in both hospitals and industrial control systems. You have an “if it’s not broke, don’t fix it” type mentality. You have large capital systems that are in place, which are very expensive to rip out and replace. The prevailing mentality in many cases is going to be, “Hey, it’s working, let’s keep it running. Let’s not touch it. Let’s not have that risk of change here in the organization.”
Manoj Tandon
One question I had, because you are familiar with ICS and DCS systems—and we’ve had this discussion on the show a couple of times—is that from a threat intelligence perspective, the FSB in Russia and the GRU are actively working on ways of physically causing discrepancies in ICS and DCS systems. They’re really focused on that for obvious reasons.
Have you seen something like that developing in the healthcare space? Do you see nation-state actors wanting to look at disrupting healthcare, or is it really just criminals right now that are playing that role?
Kevin Tambascio
It’s probably safe to say it’s both at different levels. Certainly, a lot of activity we see is from the financially motivated groups that are out there. As you know, the value of healthcare information—I’ve seen estimates anywhere from 10 to 40 times more expensive on the black market compared to credit cards and other types of personal information. So there’s an incredible amount of money being made by these groups who are targeting healthcare and the information due to the value of that information.
I think a lot of the threats we see are tied more toward those actors who are financially motivated. But we have seen evidence of other nation-states involved in these as well. We talk a lot as a team about geopolitical situations. When conflicts arise politically, that can influence all participants in critical infrastructure. So not just healthcare, but other verticals can also be affected by those types of activities believed to be driven from nation-state actors.
Attribution is always difficult. It’s very difficult. But it’s safe to say there is a lot of financial motivation. Certainly, as geopolitical things happen, we see effects in other industries that likely are coming from nation-state actors too.
Manoj Tandon
I haven’t followed this case closely, but it came to my attention: it was the federal lawsuit that Merck and FedEx had filed against their insurance carriers for refusing to pay out a claim on their cyber insurance policy. That was a result of an action resulting from the Russians in Ukraine. This was way back in 2017 when they annexed Crimea. They were collateral damage. Both FedEx and Merck had offices there, and that became the conduit by which bad things came into their network.
In the case of Merck, they couldn’t supply vaccines for quite some time as it really disrupted their operations physically. Their cyber insurance policy actually didn’t cover it. Now it’s a lawsuit. I don’t know what the final result is, but as far as the insurance company was concerned, that was the result of an act of war, and that’s not covered.
Kevin Tambascio
Again, that difficulty in finding attribution and definitively saying what happened or who was behind it leads to a lot of that ambiguity. You’ll continue to see those kinds of situations because how do you definitively prove it was Group A or this nation or whatever? It’s very, very difficult to do. It takes a lot of resources.
Certainly, I know our law enforcement agencies—unless the case is of a magnitude where they have to get engaged—it’s very difficult given the number of cyberattacks occurring on a daily basis.
Manoj Tandon
One thing that comes up with that is, in the business of healthcare at the executive level, how much of a priority is spending on cybersecurity relative to everything else that budgets have to go toward? Is there a growing awareness there, or are things changing? What are your thoughts, Kevin?
Kevin Tambascio
I think there certainly is growing awareness. Nobody wants to be in the news for the wrong reasons. I think that drives a lot of that awareness. Every time there’s a new situation where a healthcare system is impacted, I’m sure there are lots of conversations at other institutions saying, “What is it going to take to make this never happen to us? How do we avoid ever being on the front page of the paper as a result of something like this?”
I recently read a report from Cybersecurity Ventures predicting about a 15% year-over-year increase in cyber spending by healthcare institutions, totaling up to $125 billion from 2020 to 2025. When I talk to peers at hospitals, a lot of investment is happening.
Certainly, I think executives are seeing the impacts. They’re seeing operational downtime and recovery costs that can far exceed the spending they might have to do from a cybersecurity perspective. I recently read some other stats that 25% of ransomware-hit institutions experience maybe a month of impact, or it takes a month to fully recover from one of these attacks. Ninety-four percent said that ransomware affected their ability to deliver care to their patients.
It’s important that executives understand that cybersecurity is patient safety. Just like in the control system world, cybersecurity is a factor in safety in general. You look at the safety of those types of systems, and it’s important for them to really understand that connection—that these two are related. Just like in industrial control systems, healthcare is all about availability. We need to have availability of care. Our institutions don’t close; people are in need 24/7.
If this can impact availability of care or our ability to deliver care at scale, it matters. It’s really more of a patient safety issue than a cyber issue in that sense.
Manoj Tandon
I’m so glad to hear you say that. I hope the folks who are in the industry listening really take that to heart.
We’ve always seen this tension—on our side as a cybersecurity firm, our evidence is anecdotal, essentially our customer base—but we always see this tension in healthcare regarding priority of spending. A new MRI versus a new SIEM—I’m just making this up—or investment in a SOC.
Sometimes the impression we get—and of course, we’re biased because we’re in cybersecurity—is that these goals are somewhat orthogonal to each other: spending on specific healthcare instrumentation versus spending on patient safety. How can we reconcile that, or how can we help the executives in the industry reconcile that? You gave some great stats, but are there some approaches that have worked for you that people can use?
Kevin Tambascio
I think those two—helping patients or investing in care and investing in cyber—I personally don’t view as mutually exclusive. Again, I think if you connect it to patient safety… if you go to the executive team and talk about firewalls and endpoint protection and all these great technologies and stuff that we could bring if only you gave us the money for them, you’re probably not going to get their support.
But if you talk about how this could disrupt care, if you talk about the impact on patient safety, and if you talk about how patients are at their most vulnerable when they’re in our care, the last thing we want them to be thinking about is: “Is my data safe? Are these devices that are connected to me safe? Am I safe being in this facility?”
Those are the last things we want them to really be worrying about. So I think you have to have a talented cybersecurity leadership team that can really translate technical tools into language they care about. In probably every hospital, patient safety, availability of care, and protection of confidential information are paramount.
It’s paramount to our reputation and inherent to the trust that we want to have with our patients. That trust can be lost instantly if we don’t invest and protect those things. It’s not really a technical discussion at that point. You have to have someone who has the skills to really understand their concerns and bring that message to them in a way that is going to resonate. Hopefully, you’ll see successful funding and support from the top down once you’re able to achieve that.
Manoj Tandon
That is a little bit of a critique of our own colleagues in the cybersecurity industry. I do think they’re guilty of this: quite often, the discussions turn into technology conversations that business leaders are not going to find relatable. That becomes a failure point. As you’re describing, that bridge needs to be crossed. It’s really not about the technology; it’s about this.
Kevin Tambascio
I also think about maintaining it. How do you keep crossing that bridge? We invest a lot into metrics and tracking results. If you go back to the board in six months and say, “Hey, we deployed endpoint protection,” okay great, that’s fine.
But if you could say, “Hey, we’ve blocked three million emails that had malicious attachments, or we’ve stopped 500 people from clicking on an attachment through our awareness training,” they can actually start to see the impacts. Had one of those attachments gotten through or been clicked on, we could be in a situation where we’re in the news for the wrong reasons.
Connecting it to real outcomes is something that our leadership team takes really seriously. Once you’ve gotten your initial resources, that’s great, but then how do you maintain that support? You have to continue to find ways to measure your progress—not in tools or technology, but in real outcomes. To your point, that resonates with the business leaders and the executives. “I’m getting value from these dollars I’m spending.”
That’s probably true for every industry. Nothing really is healthcare-specific here. You have to find out what that executive team cares about and how cybersecurity impacts their work. In many organizations in manufacturing, availability of the plant is huge because downtime costs a lot of money. How does cybersecurity help you keep that plant running? That can be a motivator to help gain support.
It’s really about understanding what’s important to them and tailoring your message, and then trying to find ways to measure your progress in that same language so that you continue to get that support.
Manoj Tandon
Well, let’s talk about something specific to healthcare. We look at it as a highly regulated environment with a host of regulations that govern the environment, HIPAA being the most obvious. But to the layperson, it seems like, even in spite of that regulation, the safety of that data hasn’t really improved as a result. Is there a disconnect there in perception?
Kevin Tambascio
I think it’s a great question. It comes down to that mindset of security versus compliance. Compliance may be more focused on what the minimum set of requirements is to earn that certification. Some of these compliance frameworks also are very risk-based. When they’re risk-based, it allows you to potentially document a shortcoming or accept risk for something that’s not there.
One of the things I do is a lot of road biking. There’s one house that always makes me think about this question. It’s a house on a corner that has two driveways. They have a gate across each of the driveways. Compliance says, “Hey, we need to have a gate across your property.” Okay, so we’ve got a gate. You check a box for compliance—you have a gate.
The problem is there’s no fence that connects the gates in any way. So you have a gate, but you don’t have a fence. Maybe you have guard dogs or other things, but from the outside looking in, it looks like you’re not secure. I’m reminded of that example as I think about this question.
Compliance frameworks and regulations are great, but the threat landscape just changes so fast. New attacks are happening. Tactics and techniques are changing so frequently. It’s hard to keep up. Some of these compliance frameworks assess you every couple of years. How does that environment change in the course of two years? Two years is a lifetime when it comes to cybersecurity, as we all know.
In terms of why people are still getting impacted, a lot of cybersecurity controls have a hard time stopping the human aspect. It’s hard to stop insider risk and social engineering, where they’re able to get around the protections you have in place.
I think a lot of things lead up to that. A lot of healthcare institutions are doing a great job at bolstering cybersecurity, and there’s no doubt that there is a big role for these regulations. There’s also a lot of work to validate the environment and make sure that controls are working and producing value, defending against the threats that you expect to see.
Manoj Tandon
Is this where a role of a purple or red team can come into play? Regulations are kind of based on a rearview mirror looking at what the threats were, but red and purple teams… that’s where ingenuity can come into play. What are your thoughts on their role in this ever-changing landscape?
Kevin Tambascio
Just before I took this job, I was leading our purple team and red team efforts at the Cleveland Clinic. We built a program with the mindset of: “How do we validate the environment? How do we validate that controls are working?”
This is an incredibly complex institution, and we have a variety of different controls that all have to work together to give a picture of the health of the organization and our defenses. We set out to take a group of people to look at some of the most realistic threats we expect to see. We came up with a way to stratify the different threat actors based on whether we feel they’re a direct threat to us or just a direct threat to the healthcare industry.
We would take some time to study what tactics and techniques they’re using. Are they using malware delivered through email? Are they trying to directly attack the infrastructure of the victim? We started to come up with a backlog of different scenarios we wanted to try. In some cases, we were using off-the-shelf tools; in some cases, we were developing stuff to try to get around our endpoint controls in the same way that a threat actor would do.
We were actually able to test out these scenarios in a safe way. We really used it to try and drive continuous improvement here. How can we get better? How can our defenses be improved? What gaps do we have? We were able to make a lot of defensive improvements through that work.
It involved a lot of tuning of controls. Maybe we didn’t have a feature turned on, or maybe we needed a better option for something. It led to a lot of really good insights to help operationalize and practice the people, processes, and technology that make up your defensive capabilities.
It also helped us answer questions from our leadership. It wasn’t uncommon for them to see some news article over the weekend saying, “Hey, APT29 is doing this,” and they come in Monday morning asking, “Should we be worried about this?” What we were able to do over time is put our results into the MITRE ATT&CK framework and start to characterize it.
“Well, APT29 is using these tactics and techniques; we’ve already tested these techniques against our environment, and here is how we fare.” Then we could show that we have confidence that we can stop this, or maybe we have some gaps we need to go fill quickly. Having that real-world validation and real-world data was so helpful, and it continues to be helpful.
Having real data about how our tools, people, and processes work is invaluable. I feel like it’s very important—and I’ve done presentations on this—to truly validate the environment. It’s great to get a cybersecurity control in place, but bringing it into the organization is really just the first step.
How do you operationalize it? How do you build processes around it? How do you make sure information is going to the defensive team? How do we practice the attacks and make sure those tools are detecting the things they should be, or preventing the situations they should prevent? How do we know the defense team is going to react in the way we want? It definitely provided a framework of how we bring in controls and make sure that they’re ready for prime time.
Manoj Tandon
That alone was worth the price of admission to this podcast. You pretty much laid out the ABCs, the fundamentals, and the value of what you were doing with the red and purple teams. You’re absolutely correct.
It’s refreshing to hear that the scenarios are undergoing real-world testing. So it’s not just a check in the box on the control; it’s actually a validation that the control has an effectiveness to it and, perhaps more importantly, the policies that are built around it.
I would imagine at some point you would have to bring all the end users into the equation, because a policy without their support really isn’t very effective. Was there an approach you used to get the knowledge out to the broader community or try to get that culture of cybersecurity—that we want you to do A, B, and C, and this is for everyone’s benefit?
Kevin Tambascio
We have a training platform. We do annual cybersecurity training, just like many different companies. Certainly, we do regular testing of our employees with phishing tests and look for ways to improve and raise awareness of the threats.
A couple of weeks ago, I was at a birthday party my son was at. Some of the other people at the table were nurses at Cleveland Clinic. I mentioned I worked there too, in cybersecurity. They asked me about why they can’t access personal email like Gmail. I started talking about the threats—how attachments could get in and bypass our controls. They just had no idea what I was talking about. The concepts were just so foreign to them.
It highlights the fact that people in cyber are not “normal” people. We see and breathe this stuff every day. We see the bad news and the threat actors, but “normal” people do not see all of this. You have to work hard to help them understand that this stuff is happening and we’re not making this up. There are real attacks occurring.
It’s really important to connect with them. People are still the most vulnerable part of an organization. You have to share stories and have awareness activities. Have a cybersecurity week or events to raise awareness on top of your training.
Much like the executive audience: what’s important to a clinician? Let’s not talk to our nurses about firewalls and antivirus stuff. Let’s talk about ransomware and how it could affect operations or patient care—something they can relate to and clearly care a lot about.
Make sure that training is approachable and that they can understand it. We have to share these stories, but not in a “world’s burning” mode. We’ve all seen those types of presentations. There is a reasonable approach you can take to share that in a way that makes an impact. Certainly, the nurses I was talking to at the birthday party walked away thinking, “Okay, it is important to have complex passwords and not click on stuff.”
Manoj Tandon
Can you share anecdotally a story or two that really resonated with them?
Kevin Tambascio
Just talking in general about how these attacks originate. You could be sort of innocently browsing your email and you download something, and you don’t think twice about it. You might open it up on a work asset.
There’s a thought that the way people get in is through some advanced attack from the outside. The idea that someone could almost innocently click on something and it starts a major incident was the eye-opening part—realizing how easy it is. This isn’t necessarily hard to carry out.
You’re sending malware through automated mechanisms and stolen botnets. As we’ve seen, there are ransomware groups for hire and open-source toolkits. The bar has continued to get lower and lower for managing these campaigns. The average person doesn’t realize how prevalent this is or how relatively easy it is for them to unknowingly be a part of an incident like that.
Manoj Tandon
Absolutely. Let’s talk about some things that are not so easy to do. Regarding embedded systems, which you’re an expert on: there are a lot of them, and many were not built with security as a prime factor in their design. How big of a threat are they, and how does one go about managing this?
Kevin Tambascio
How big of a threat are they? Certainly, we are seeing impacts from attacks affecting these types of devices. However, in talking to peers in the industry, many of these systems—operational technology systems like medical devices and control systems—are talking back to standard IT infrastructure or servers that are just like any other server in your environment.
It’s important to look at the whole picture of where you have the most risk, but also recognize that threats to operational technology can be more IT-centric. The servers supporting medical devices next to servers supporting email could both be susceptible to ransomware via human interfaces.
In terms of what we do about it, vendors are doing a lot of good things. There are many industry standards that have come about. IEC 62443 in the industrial control space was put together to drive improvements to devices, system integrators, and operators in how they maintain the cybersecurity quality and safety of a system.
You have Biden’s executive order from last year to start incorporating cybersecurity measures into IoT and medical devices. The language was for anything the federal government buys. It turns out the VA is a really big buyer of medical devices. So a lot of those activities are also going to start to flow into the medical device space.
It really is a partnership between vendors and end users like us. Vendors have to engineer products with cybersecurity in mind. Their teams and processes must account for cybersecurity by doing secure design reviews and threat modeling to look at the threats a system is exposed to.
I view them as enabling us to then take ownership of the cybersecurity. In order to do that, we have to understand the attack surface of these systems. We have to understand patching requirements, how to set up accounts securely, and how to connect it securely to our infrastructure. Can we segment the network?
For us to take ownership and maintain security, the vendor has to enable us to be able to do that. At the same time, we could buy the most secure product in the world, but if we turn on risky features or don’t deploy it in a secure manner, we’ve undone all their work.
It’s a partnership between product vendors, system integrators, and operators. Each of us has to enable the next group to take responsibility for security.
Manoj Tandon
Is there a threat from foreign chip manufacturers whose subsystems are getting embedded in these products?
Kevin Tambascio
Yes, absolutely. There have been instances of compromised chips. It’s a big problem to look at the authenticity of these components. These devices are incredibly complex. The hardware bill of materials, or HBOM, can be hundreds or thousands of individual components.
Being able to account for the security of each of those components, knowing each probably has its own HBOM and software bill of materials, or SBOM, becomes an incredibly complex problem to vet every component.
Manoj Tandon
What about using open-source libraries in these systems? I’ve never programmed an infusion pump, but I would imagine it’s got open-source components. No one’s building everything from scratch. Are there inherent risks coming from that arena?
Kevin Tambascio
Absolutely. I think any product out there today—think about devices running embedded Linux. Think of the thousands of open-source developers who’ve had a hand in some component of Linux. In a general sense, there are so many components and things in there. It’s incredibly complex.
In my experience, 20% to 30% could be code the vendor has written on top of a Linux device or some other type of embedded operating system. You’re taking the word of the vendor, or you have to find a way to trust the open source.
The customer is going to look at that device as having your name on it. Whether you wrote the code or brought in an open-source library… think about Heartbleed several years ago. The OpenSSL library was a component many devices had inside their product.
Whether you wrote the code or not, you’re putting your brand and reputation on that device. You have that responsibility. It’s very important that when you’re engineering these products, you have processes in place to account for the risk of everything: the code you’re writing, the code your employees are writing, or if you’re contracting it out.
Are they building the product in a way that represents your standards? Anything you bring in, whether commercial or open source—how do you vet it? How do you make sure it’s at the level of quality you’re looking for?
Ultimately, you’re responsible for what happens with that product from a security perspective. The customer doesn’t care; they’re not going to say, “Oh, that’s just the open-source piece.” They bought a widget from you, and you are responsible for it.
Manoj Tandon
So do our laws need an update, or are there some government policy things that need to come into play? It’s impossible to secure everything; it’s just not realistic.
Kevin Tambascio
There is certainly some movement starting to happen there. The executive order and other legislative activities seem to be brewing to address concerns, especially in the medical device realm, to ensure at least some basic cybersecurity hygiene can be put into these devices.
No device should have a hard-coded password that you can’t change—effectively a backdoor. You should be able to have services off by default and keep that attack surface as small as possible. Regarding signed firmware: how do we guarantee the software running in these devices is authentic?
I think if you look across all these different regulations and things happening, there are certainly common principles we can all agree are good things to have in these devices.
Manoj Tandon
When you look at the aviation industry, engine control system software even a couple of years ago could not be updated online. It was still delivered on disks to ensure the authenticity of that code. If it were updated by some cloud server, the OEMs couldn’t guarantee it was genuine.
You’re absolutely right. Your attack surface is so big it’s mind-boggling—the number of devices and integrations you folks have. It’s just impossible to seal every single thing. There has to be a level of risk. There’s no such thing as 100% cybersecurity.
I’m advocating personally that there has to be some leeway because it’s just not realistic to have zero risk.
Kevin Tambascio
It comes down to really understanding the threats. It sounds cliché because everyone says this, but it’s understanding your threats and your assets. Both are very difficult to wrap your arms around.
There are great resources out there, like the Health ISAC. Each ISAC organization can provide healthcare organizations with information about threats we face. That’s when you can start to orient your approach to security.
Without understanding that, everything feels like a priority and everything feels like a good thing to do. You start to get to another level of maturity when you realize these are the top three things. Maybe email is our most important focus because everyone in the industry is getting attacked through email.
You can give direction to your teams and spend in that way. You have to provide priorities, or else we all have 15 “number one” priorities. You have to have something guiding you—whether it’s the threats or a general risk approach.
Manoj Tandon
Speaking of guiding you, we’re coming to the end here. VeloSano seems very important to you, and you are engaged with them in fundraising. Tell us about them and other things you’re involved with that you’d like our listeners to know about.
Kevin Tambascio
VeloSano is a fundraiser that the Cleveland Clinic puts on. We raise money for cancer research. To date, over $30 million has been raised for what they call “seed grants.” These help us do initial research, and they can then take those results to apply for state and federal grants that amplify the initial investment.
We just had our annual bike ride back in September. To date, over $3 million was raised for this year, and 100% of that goes to cancer research at our institute. It’s a great event from a cycling perspective. If you’re in the Cleveland area, I recommend checking it out.
There are also ways to do virtual fundraising to support members who are doing it. Cancer, unfortunately, affects all of us. Everyone has a story. I lost my grandfather in 1995 and have had other friends and family members affected. It’s a very personal cause to me. It’s great to give back to my institution and all the great work that our caregivers do in that space.
Manoj Tandon
Fantastic. Do you have any talks or appearances coming up?
Kevin Tambascio
At this time, I don’t have anything planned. But I have been a past participant of the National HIMSS event coming up in April 2023. That will be in Chicago.
Last year, I went with one of my team members and we talked about purple teaming in healthcare—a longer version of what we just discussed—and had a great dialogue with the audience.
Manoj Tandon
Fantastic. Well, Kevin, we’re at the end of the show. Thank you so much; it’s been a very enlightening conversation. I appreciate you taking the time out of your busy day to share your knowledge with us.
Kevin Tambascio
Thanks, Manoj, for having me. It’s great to be a part of this podcast. Thank you.
Learn more about the Cleveland Clinic
Learn more about Kevin on his Linkedin
Check out the other episodes in Season 8:
Ep. 0 Dark Rhiino Team – Data Loss Prevention
Ep. 1 Boyd Clewis – Cofounder, Author, and Cybersecurity Speaker
Ep. 2 Ken Underhill – CEO, Author, and Cyber Life
Ep. 3 Dr. Gerald Auger- Simply Cyber, Black Hat 2022, and Security Awareness
Ep. 4 Eddie Thomason – Humility, Negativity, and Twitter News
Ep. 5 Zinet Kemal – Author, Diversity, Cloud Security, and CISA
Ep. 6 Derek Scheller – Cyber Warrior, Veteran, and Podcaster
Ep. 7 Ted Harrington – Hackable: How to do Application Security Right
Ep. 8 Kevin Tambascio – Cyber Professional, Cleveland Clinic, and HIMSS
Ep. 9 Greg Tomchick – Pro Athlete turned Cybersecurity CEO
Ep. 10 Brian Stoner – Remote work: Can You Trust Your Employees?
About Kevin Tambascio

Kevin is the director of cybersecurity data and application protection for Cleveland Clinic.
He has over two decades of experience in software development and cybersecurity.
He has done work in embedded systems and attack surface reduction, has a couple patents related to this.
He is president elect for the Northern Ohio HIMSS Chapter.
In his spare time he is involved with supporting Velosano in fundraising for cancer research.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
