Skip to main content

Cytactic CEO on a hospital ransomware case where staff couldn't trust patient records, and why most CISOs never rehearse their worst day [Podcast, 33 min]

0
Medium
Published: 09/30/2026 (09/30/2026, 20:43:34 UTC)
Source: Reddit Cybersecurity

Description

This content is a podcast episode discussing a hospital ransomware incident where staff could not trust patient records, highlighting challenges in incident response and the importance of rehearsal for CISOs. It includes insights on rapid exploitation enabled by AI and the complexity of layered defenses. The episode also emphasizes the need for incident response exercises to consider scenarios where data and logs may be unreliable.

Reddit Discussion

r/cybersecurity·posted by u/PracticalAssist2600
00

Disclosure: my studio produced this episode of Responsible Disclosure, Zafran's podcast. Sharing it because a lot of it is about incident response in practice, and I've summarized it below so you can skip to what's relevant.

Nimrod Kozlovski has spent about twenty years across cyber law, VC, and crisis management, including running incidents at Fortune 500 companies. A few parts I think this sub would care about:

At 03:12 he walks through three incidents: stolen source code at a homeland security company, a crypto wallet takeover, and a hospital extortion where staff didn't know whether patient records had been altered.

At 13:03 and 16:21 he argues AI has cut the time from vulnerability to exploitation to minutes, and that attackers are chaining identity, permissions, and applications to get past layered defenses.

At 24:03 and 26:01 he gets into why most CISOs face their worst day with little rehearsal, and why tabletops matter when you're deciding on partial information.

Also a fun story at 09:21 about the DEF CON crowd deciding he was a fed.

For the IR people here: do your tabletops include injects where the data turns out to be wrong? The hospital case made me think most exercises assume you can trust your logs and records.

https://youtu.be/B8YB42zON8U

Links cited in this discussion

Also discussed in: r/Information_Security

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/30/2026, 20:47:59 UTC

Technical Analysis

The podcast features Nimrod Kozlovski discussing multiple cybersecurity incidents, including a hospital ransomware case that caused uncertainty about the integrity of patient records. He notes that AI has accelerated the timeline from vulnerability discovery to exploitation, with attackers chaining multiple attack vectors. The discussion stresses that many CISOs do not adequately rehearse their worst-case scenarios, and that incident response tabletops often assume trustworthy data, which may not be the case in real incidents.

Potential Impact

The hospital ransomware incident led to staff being unable to trust patient records, potentially impacting patient care and operational decisions. The accelerated exploitation timeline due to AI increases risk exposure. The lack of rehearsal for worst-case scenarios among CISOs may reduce organizational preparedness and response effectiveness during critical incidents.

Defensive Guidance

No specific patch or remediation is applicable as this is a discussion of incident response challenges rather than a software vulnerability. Organizations should incorporate scenarios involving unreliable data into incident response exercises and conduct regular rehearsals of worst-case incidents to improve readiness.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":30,"reasons":["external_link","newsworthy_keywords:ransomware","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["ransomware"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6abd757b2a4e24523d92cfb4

Added to database: 09/30/2026, 20:47:55 UTC

Last enriched: 09/30/2026, 20:47:59 UTC

Last updated: 09/30/2026, 22:47:50 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses