
003. Don't Call it a Breach: Healthcare Cybersecurity with Barry Mathis and Dan Schlacter
Allu Sirish
Description
Is it possible for a hospital to turn a small cybersecurity incident into a full-blown crisis based only on the words used and the approach to communicating about the event? What about the opposite – is it possible for a major incident to be mitigated and minimized with little reputational damage…just through effective communication? The answer to these rhetorical questions is, obviously, yes. That’s according to cybersecurity with Barry Mathis. Mathis is a principal at PYA where he draws on three decades of experience as a chief information officer, chief technology officer, and other roles to help healthcare clients plan, develop and implement complex IT solutions. As part of that work, Mathis spends a lot of time advising healthcare organizations on how to reduce risk and avoid – or worst-case scenario, minimize – the fallout from cybersecurity incidents. For this conversation Mathis joined Dan Schlacter, a vice president in the Jarrard Inc. Health Services Practice and lead on much of the firm’s cybersecurity work, to talk about the best practices and the role of communications both before and after an incident. Key Insights Be strategic about the words that you use to describe a cybersecurity attack: Avoid the word “breach,” and instead opt for a word like “incident,” to reduce exposure and dial down the temperature in communications about the event. Prioritize cybersecurity training and have a crisis response plan in place before an attack happens to ensure that your organization can respond to an attack quickly and efficiently. Loop in communications experts and legal counsel during the early stages of a cybersecurity incident. (And don’t take anything in this conversation as legal advice. We are not attorneys.) Learn more about your ad choices. Visit megaphone.fm/adchoices
Uploader
Episodes
003. Don't Call it a Breach: Healthcare Cybersecurity with Barry Mathis and Dan Schlacter
Allu Sirish