Robert Siciliano
Why Even Your Smartest Employees Can Screw Up and Trigger a Healthcare Security Breach
Robert Siciliano
Founder, ProtectNow LLC

Why Even Your Smartest Employees Can Screw Up and Trigger a Healthcare Security Breach

With Robert Siciliano
Listen to the podcast:
Apple Podcasts logoListen to podcasts on SoundCloudListen to podcasts on SpotifyWatch podcast on YouTubeiHeart Podcast Interview logoPodbean podcast platform logo
TuneIn podcast platform logo

Cybersecurity is often viewed as a technology problem, but according to Robert Siciliano, that's only part of the story. While healthcare organizations continue investing heavily in firewalls, encryption, compliance programs, and sophisticated security tools, most successful attacks still exploit something much more predictable: human behavior.

In this episode, Stewart Gandolf welcomes cybersecurity expert and ProtectNow LLC founder Robert Siciliano to discuss why even highly intelligent employees fall victim to phishing attacks, social engineering, and increasingly sophisticated AI-powered scams. Drawing on more than three decades studying fraud, scams, identity theft, and cybercrime, Siciliano explains that today's greatest security risk isn't a lack of technology—it's the natural human tendency to trust. To illustrate just how convincing modern attacks have become, he shares the story of an elaborate phone scam that nearly fooled him—a veteran cybersecurity expert. Only because he remained skeptical and verified every detail was he able to recognize the deception before it was too late.

The conversation explores why traditional security awareness programs often fail to change employee behavior, the growing threat posed by AI-generated voice cloning and deepfakes, and why healthcare leaders must move beyond compliance-driven training toward what Siciliano calls "security appreciation." Rather than treating employees as the weakest link, he argues organizations should help people understand how cybersecurity affects their own lives, making security personal before expecting them to protect the organization.

Stewart and Robert also discuss the psychological foundations of trust, real-world examples of sophisticated scams that nearly fooled an experienced cybersecurity professional, the lessons healthcare leaders should learn from recent ransomware attacks, and practical strategies for building a stronger culture of security throughout an organization.

As cybercriminals become increasingly organized and AI makes deception more convincing than ever, this episode offers healthcare executives an important reminder that protecting patient information requires more than better technology—it requires changing human behavior.

Why Listen?

  • Walk away with practical ideas for helping employees become a stronger first line of defense against cyber threats.
  • Learn why human behavior—not technology—is responsible for many healthcare security breaches.
  • Understand how AI-powered scams, deepfakes, and voice cloning are changing the cybersecurity landscape.
  • Discover why traditional security awareness training often fails to change employee behavior.
  • Explore Robert Siciliano's concept of "security appreciation" and how it can strengthen organizational culture.

Key Insights and Takeaways

  1. Technology alone won't stop most breaches. Despite significant investments in cybersecurity tools, many successful attacks still begin with employees responding to phishing emails, text messages, phone calls, or other forms of social engineering.
  2. The greatest vulnerability is human psychology. People are naturally wired to trust one another. Cybercriminals exploit that instinct far more effectively than they exploit software vulnerabilities.
  3. Compliance doesn't necessarily change behavior. Traditional security awareness training often satisfies regulatory requirements without creating lasting habits that help employees recognize and respond to threats.

4. AI is dramatically increasing the sophistication of attacks. Voice cloning, deepfakes, and AI-generated phishing campaigns are making it increasingly difficult to distinguish legitimate communications from fraudulent ones.

5. Security must become personally relevant. Employees are more likely to develop lasting security habits when they understand how protecting themselves, their families, and their own identities also protects their organizations.

6. Building a culture of security starts with leadership. Executives play a critical role in moving organizations beyond check-the-box compliance toward an environment where security awareness becomes part of everyday decision-making.

“People protect what they love first. Teach employees how to protect their own families, and they'll become better at protecting your organization.”
Robert Siciliano

Robert Siciliano

Founder, ProtectNow LLC

Subscribe for More

Don’t miss future insights—subscribe to our blog and join us on LinkedIn: Stewart Gandolf and Healthcare Success.

Note: The following AI-generated transcript is provided as an additional resource for those who prefer not to listen to the podcast recording. It has been lightly edited and reviewed for readability and accuracy.

Like Our Content?
Sign Up for Our Blog, Podcasts, Webinars, and eBooks Here.

Ready to explore a partnership?
© 2026 Healthcare Success, LLC. All rights RESERVED.