Cyber Survivor

Episode 25–Tabletop Drills, Real‑World Outages. With Greg Surla

Jan 22, 2026
Greg Surla, CISO at FinThrive and former U.S. Army signal intelligence leader, discusses third‑party risk, vendor tabletop drills, and how revenue cycle platforms tie to patient care. He covers ransomware readiness, preapproved workarounds like VDI and hardened devices, automation for vulnerability triage, and making security a business enabler through culture and board alignment.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Interconnected Risk Across Healthcare

  • Healthcare is deeply interconnected: vendor, regional, and cross-organization impacts ripple widely.
  • A vendor breach can indirectly harm many providers, so system boundaries are porous and shared risk matters.
ADVICE

Run Joint Tabletops With Critical Vendors

  • Join vendor incident-response tabletops and ask vendors to join yours to coordinate plans before an event.
  • Pre-approve workarounds like VDI access or spare laptops so customers can keep working during outages.
ANECDOTE

Forgotten Cloud Server Led To Breach

  • After acquiring a small company, a forgotten AWS server with customer data was breached because it lacked security and inventory tracking.
  • That experience taught Greg Surla that asset management and exhaustive checks are critical during M&A.
Get the Snipd Podcast app to discover more snips from this episode
Get the app