What is one of the biggest mistakes healthcare organizations make when trying to operationalize a GRC program?
The program is typically built during an initial large initiative with many vested stakeholders. Risks get identified, scored, assigned an owner, and mapped to controls, then it sits untouched until the next audit or assessment forces someone to blow the dust off it. By then, half the “owners” have changed roles and half the risks are stale or already remediated because nobody updated the register. Organizations end up spending the week before an audit doing frantic archaeology instead of actual risk management. The register isn’t a true reflection of the organization’s risk posture; it’s a compliance artifact performed for auditors rather than a tool used by the business. That’s the disconnect: the GRC program exists to satisfy an audit cycle instead of to inform decisions in real time.
Where do you most often see GRC programs get stuck between strategy and execution?
The stuck point is usually the translation layer between “we identified the risk” and “we did something about it.” Strategy says “manage third-party risk” or “mature our access controls,” which is fine at 30,000 feet. But execution requires someone to make decisions, such as which vendors go first, how deep the assessment should go, and what’s good enough versus best in class. That’s exactly where paralysis by over-analysis creeps in.
What emerging risk do you think will have the biggest impact on healthcare cybersecurity over the next 12–18 months?
Internal AI agents have already proven they can be a major risk to organizations. Giving an AI an identity and permissions, often elevated, to act autonomously on behalf of the organization is a significant shift. Without proper oversight, monitoring, and management, these agents have the potential to cause a wide spectrum of issues, up to and including major incidents.
What is one area where healthcare organizations have made the most progress in cybersecurity over the last few years?
Benchmark your cybersecurity program against your peers.
Overall, a lot of the organizations I work with have embraced building a culture around cybersecurity awareness and best practices. This is a critical step in empowering users at all levels of the organization to participate in securing the environment. Activities like reporting phishing attempts and participating in Cybersecurity Awareness Month help make employees feel truly involved in the effort.
If you could give healthcare security leaders one piece of advice going into 2027, what would it be?
Continue to focus on the fundamentals while anticipating major changes in how we manage vulnerabilities and patching, both near-term and long-term. Modern threat intelligence teams will increasingly embrace LLMs to probe their own environments and proactively find and patch vulnerabilities ahead of bad actors.
What is one thing people might be surprised to learn about you outside of work?
I don’t get to do it as much as I’d like, but I love fishing. My happy place has always been on the water with a fishing pole in my hand!