Why Even Your Smartest Employees Can Screw Up and Trigger a Healthcare Security Breach
Cybersecurity is often viewed as a technology problem, but according to Robert Siciliano, that's only part of the story. While healthcare organizations continue investing heavily in firewalls, encryption, compliance programs, and sophisticated security tools, most successful attacks still exploit something much more predictable: human behavior.
In this episode, Stewart Gandolf welcomes cybersecurity expert and ProtectNow LLC founder Robert Siciliano to discuss why even highly intelligent employees fall victim to phishing attacks, social engineering, and increasingly sophisticated AI-powered scams. Drawing on more than three decades studying fraud, scams, identity theft, and cybercrime, Siciliano explains that today's greatest security risk isn't a lack of technology—it's the natural human tendency to trust. To illustrate just how convincing modern attacks have become, he shares the story of an elaborate phone scam that nearly fooled him—a veteran cybersecurity expert. Only because he remained skeptical and verified every detail was he able to recognize the deception before it was too late.
The conversation explores why traditional security awareness programs often fail to change employee behavior, the growing threat posed by AI-generated voice cloning and deepfakes, and why healthcare leaders must move beyond compliance-driven training toward what Siciliano calls "security appreciation." Rather than treating employees as the weakest link, he argues organizations should help people understand how cybersecurity affects their own lives, making security personal before expecting them to protect the organization.
Stewart and Robert also discuss the psychological foundations of trust, real-world examples of sophisticated scams that nearly fooled an experienced cybersecurity professional, the lessons healthcare leaders should learn from recent ransomware attacks, and practical strategies for building a stronger culture of security throughout an organization.
As cybercriminals become increasingly organized and AI makes deception more convincing than ever, this episode offers healthcare executives an important reminder that protecting patient information requires more than better technology—it requires changing human behavior.
Why Listen?
- Walk away with practical ideas for helping employees become a stronger first line of defense against cyber threats.
- Learn why human behavior—not technology—is responsible for many healthcare security breaches.
- Understand how AI-powered scams, deepfakes, and voice cloning are changing the cybersecurity landscape.
- Discover why traditional security awareness training often fails to change employee behavior.
- Explore Robert Siciliano's concept of "security appreciation" and how it can strengthen organizational culture.
Key Insights and Takeaways
- Technology alone won't stop most breaches. Despite significant investments in cybersecurity tools, many successful attacks still begin with employees responding to phishing emails, text messages, phone calls, or other forms of social engineering.
- The greatest vulnerability is human psychology. People are naturally wired to trust one another. Cybercriminals exploit that instinct far more effectively than they exploit software vulnerabilities.
- Compliance doesn't necessarily change behavior. Traditional security awareness training often satisfies regulatory requirements without creating lasting habits that help employees recognize and respond to threats.
4. AI is dramatically increasing the sophistication of attacks. Voice cloning, deepfakes, and AI-generated phishing campaigns are making it increasingly difficult to distinguish legitimate communications from fraudulent ones.
5. Security must become personally relevant. Employees are more likely to develop lasting security habits when they understand how protecting themselves, their families, and their own identities also protects their organizations.
6. Building a culture of security starts with leadership. Executives play a critical role in moving organizations beyond check-the-box compliance toward an environment where security awareness becomes part of everyday decision-making.

Robert Siciliano
Founder, ProtectNow LLCSubscribe for More
Don’t miss future insights—subscribe to our blog and join us on LinkedIn: Stewart Gandolf and Healthcare Success.
Note: The following AI-generated transcript is provided as an additional resource for those who prefer not to listen to the podcast recording. It has been lightly edited and reviewed for readability and accuracy.
Read the Full Transcript
Stewart Gandolf (Healthcare Success): Hello everyone, Stewart Gandolf here, host of the Healthcare Success Podcast. I'm excited today to welcome Robert Siciliano, who is the CEO and founder of ProtectNow LLC. We have a fun topic today that's a little different than what we usually do here.
First of all, welcome, Robert.
Robert Siciliano (ProtectNow LLC): Thank you. Happy to be here.
Stewart Gandolf (Healthcare Success): I think we're going to enjoy this a lot today, and I think our listeners will too.
Robert, we're going to talk today about our headline for the podcast: Why Even Your Smartest Employees Can Screw Up and Trigger a Healthcare Security Breach. We're going to drill down into this today and find out—is it intellect? What is wrong? What happens? With all of our technology, where can things still go wrong? So I'm excited to get straight into this.
Robert, we talked offline pretty extensively, and you mentioned that you've spent your whole career studying scams, fraud, and security. What's the single biggest thing healthcare leaders get wrong when we think about security today?
Robert Siciliano (ProtectNow LLC): The majority of breaches, depending on the stats you're looking at, revolve around something like 75% of employees making mistakes. Those mistakes could be clicking a link in a phishing email. It could be reacting or responding to a text message or phone call. It could be going outside the system and making the system itself vulnerable.
Ultimately, the single biggest thing that healthcare leadership teams are getting wrong is mistaking compliance theater for real-world security. Plain and simple.
Executives pour millions into software patches, firewalls, encryption keys, completely overlooking the vulnerability of what I call their wetware—essentially the human brain, the biological brains of their staff. They treat cybersecurity as a technical IT check-the-box rather than an active behavioral discipline.
By relying on passive annual compliance video training through an LMS that employees are trying to beat, it creates a massive what I call a security appreciation gap.
What is that? It's where employees remain trapped in an accidental vulnerability mindset because they haven't been trained to build active verification habits. They're not really looking for threats—they're reacting to them.
Essentially, when an aggressive social engineering storm hits the front line of your employees, your expensive tech stack becomes entirely irrelevant if a distracted worker is manipulated—which is the whole point of it—into handing over the keys to the digital vault.
Stewart Gandolf (Healthcare Success): Yep, and that totally makes sense. When we talked about human nature, what is the part that...why do people get in trouble? What's the flaw in us humans where we just seem to make these mistakes over and over again?
Robert Siciliano (ProtectNow LLC): Every one of us suffers from what I call the human blind spot. No piece of software will ever fully solve the human psychological vulnerability. I trust you. You trust me. Man trusts woman. Woman trusts man. Ultimately, the genders trust each other so they can procreate. That is our baseline. We want to and need to trust each other as an interdependent species.
All day, every day, the people you come in contact with physically, driving down the road, people in other cars, phone calls, emails, text messages, pop-ups—you want to believe that the person on the other end has your best interest in mind. So this human blind spot is the innate biological and psychological need to trust each other.
Essentially, experts focus almost entirely on hardening network infrastructure while leaving the human perimeter totally exposed because of the human blind spot. Until organizations recognize and stop treating employees as an inherent liability and start engineering them into an aggressive, proactive human sensor network, tech-centric frameworks will continue to fail against high-precision social engineering.
Stewart Gandolf (Healthcare Success): So what is it about the trust part? I'm actually a student of a lot of things related to human nature. Right now I'm watching a series on YouTube that's actually quite well done on the history of humans—humans and fire, humans and this, humans and that.
What is it about trust that you think makes this happen? I'm asking you to speculate here because I know this probably isn't your specialization, but why are humans so trusting—or have such a desire to trust—and how does that get them into trouble when it comes to security?
Robert Siciliano (ProtectNow LLC): Look, I believe 97% of all the people we will ever come into contact with over the course of our lives are essentially to a degree worthy of our trust. They mean no harm. They don't intend to hurt us. Generally, they don't deceive. Occasionally they lie, but their intention isn't to hurt.
Whereas as much as 3% of women and as much as 6%t of men—and you can Google this—worldwide have what the medical community would diagnose as sociopaths or psychopaths.
Those sociopaths and psychopaths, not all of them, but in general, they don't experience empathy, sympathy, guilt, or remorse. Therefore, hurting people, taking from others—that isn't a big deal to them. They're essentially the narcissists amongst us who truly have no shame.
That 3% makes a lot of noise and can do a lot of damage. Ninety-seven percent of our lives are spent with good people, but occasionally that 3% makes its way in. It's much harder to constantly think, "Bad actors, bad actors, bad actors," unless we're properly trained to do so in a way where it becomes normal, kind of like riding a bike. Once you understand that not everybody is truly worthy of your trust—and while that sounds rudimentary—not everybody truly is worthy of your trust, and you understand how and why they choose their victims, then it becomes much easier to navigate.
But we don't look at the world that way because we don't want to. Humans gravitate toward pleasure and move away from pain. Trusting people feels good. We don't want to think bad actors would ever choose us. Therefore, we don't even want to think for a second that we'd ever be targeted.
When I get in front of a live audience, I ask questions like, "How many of you have a home security system?" Maybe 15% of the room raises their hand.
I ask, "Why don't you have one?"
The hands fly up.
"I don't want to have to worry."
"I don't want to live in fear."
"I don't want to be paranoid."
As if installing a home security system is going to make you paranoid. We have a very unhealthy relationship with security because security means recognizing risk. People want to say, "I just trust people." What they're really saying is, "I'd rather live in denial." We play tricks on ourselves because it's simply more natural to trust than it is not to trust.
Stewart Gandolf (Healthcare Success): Yeah, that's such a blind spot. I can see if people are habitually—if 97% of your interactions are with people who don't want to harm you—it's easy to overlook the other 3%. Then the second part of it is there's this sort of ostrich complex of burying my head in the sand. Well, if I bury my head in the sand, then therefore it can't happen to me.
I'll share a story, Robert, that's a little scary. My wife and I finally were in Cabo on a trip recently, and my neighbor called. My daughter—our oldest daughter—is always worried about security. Of course, she's at home while we're in Cabo, in another country. My neighbor calls me and says, "Did you just put out a new security camera in your bushes?" I said, "No." Apparently, some local California gang had stuck a camera there to case our neighbor's house—not our house—because the cameras were facing toward their house. Of course this happens when I'm on vacation. Of course. There was harm intended there for sure. That's just so scary that even happens. I don't know if you have any comment on that, Robert.
Robert Siciliano (ProtectNow LLC): Organized crime today has it down pat. They know what they're doing. They have all the technology at their fingertips. They understand that most people aren't locking their doors or even have a home security system. They know we don't want to engage in basic one-on-one risk management, and they know that all they need to do is pay attention to us and monitor us—via phone, email, in person, or through video cameras. Eventually they're going to learn what it takes to overpower us, whatever that might mean, and they've pretty much figured all that out.
At this point, things like home burglaries happen 1.5 to 2 million times every single year in the U.S., but only about 15% of consumers have a home security system. Why? Because of that unhealthy relationship with security.
I've been doing what I do now for more than 30 years. What has changed in 30 years is that criminals are now fully organized, and cybercrime has eclipsed the illicit drug trade in dollars. Think about that for a second. Cocaine. Fentanyl. Cybercrime is where the money is now.
What hasn't changed is that consumers—citizens, you and I—I ask this question every time: "How many of you can honestly say you're using a different passcode across your critical accounts?" If I get 10% of the room to raise their hand, that's a lot. That means 90% of healthcare executives' employees are using the same passcodes across multiple accounts, at least at home. What that means is they don't take their security seriously at home. What makes you think they're going to take it seriously at work?
Stewart Gandolf (Healthcare Success): Of course that's really scary in healthcare, particularly regarding HIPAA, because, as you and I talked about offline, if there's a big breach of credit card numbers, that's bad, but people can change their credit card numbers pretty quickly. Things are automated these days. But you can't change your healthcare information. HIPAA breaches—not to mention the liability that comes along with them—are so vital and so dangerous in healthcare in particular.
Robert, the headline of the podcast is that even smart people can get fooled. You told me about a scam that almost got you recently—a professional expert. I'd love you to share that because I think it's such a great story for people to understand.
Robert Siciliano (ProtectNow LLC): It wasn't too long ago that the phone rang, and it was from California. I answered because I do a lot of media, and when the media calls, you've got to answer the phone or else you don't get the gig—TV, radio, print. It was California, so I thought maybe it was another California television station or another opportunity.
The caller said, "Hi, this is Google Security. Is this Robert Siciliano?" I said yes. Right off the bat I'm thinking, "Is this really Google Security?" But I'm interested to see what's going on because I answered the phone.
"Hi, this is Google Security. Is this Robert Siciliano?" I said yes. They confirmed my email address. They confirmed my phone number. Of course they had my phone number because they called me. Then they said, "At Google Security we take our clients' security seriously. The reason we're calling today is because it looks like your Gmail account is in the process of an account takeover. Somebody is trying to add a Canadian phone number to your account for two-factor authentication. Are you in Canada right now changing your phone number?" I said, "No." They asked, "Do you have a family member in Canada who might be doing this?" I said, "No."
While they're talking, I'm logging into my Gmail account. I'm checking my two-factor authentication. I'm confirming my phone number. I'm checking my backup phone number. I'm seeing that nothing has changed. My password hasn't changed. I'm Googling the phone number that called me to see where it's coming from. I'm doing my due diligence while we're talking, making sure my account is secure and trying to determine whether this really is Google.
At the same time, I said, "I'm not sure you're actually Google. Can you provide me with a case number?" They said, "Yeah, no problem." Two seconds later, I received an email from a [email protected]address. An actual Google email. Instantly.
Just like that. Okay. So what they did was a redirect. They actually sent me a Google email, which really piqued my curiosity because I'm thinking, "Okay, this is an actual Google email." While I'm still on the phone with them, I went into the source code of the email and put it into Google Gemini and said, "Who's this coming from?" It actually told me this was a real Google email that had been sent to me through a spoofed address. Somehow they were able to manipulate the system and get an actual Google email sent to me, but they spoofed it.
All that being said, they had my curiosity. When it was all said and done, I was on the phone with them for 12 minutes. Then I received an actual text message to my phone to reset my passcode. Basically saying, "Are you in Boston, Massachusetts, trying to reset your passcode?" I was in Boston, Massachusetts. They were trying to reset my passcode. They used a VPN to redirect that password reset through the phone they were on to my Boston location, which was awesome.
It was awesome. It was awesome. I gotta tell you, I'm looking at it going, "No. No. There's no way." It was good. You know who would have fallen for that? My dad. You know who else would have fallen for that? My wife. You know who else would have fallen for that? Probably 99 % of the general public. Probably 99% of your employees.
Why? Because it was orchestrated. It was organized. It was good. It was good. It's awful what they do. It's awesome what they do. And the general public—when I get in front of a live audience—you know what kind of questions they ask me? This is your healthcare employees.
"How do we know what links are okay to click when we do a Google search?" Basic. 101. "How do we protect our credit cards?" Basic.
Which tells me they don't know what they're doing when it comes to effectively managing risk in the workplace, never mind at home, because they're doing nothing at home because they don't want to think it's going to happen to them to begin with.
So healthcare IT is up against that.
Stewart Gandolf (Healthcare Success): Okay. At the end of the day, then, you're not the only cybersecurity expert out there. Where do you differ in your viewpoint? What do you think other experts just have all wrong? How should CEOs be thinking about this differently?
Robert Siciliano (ProtectNow LLC): They need to think differently because technical leaders manage the plumbing, but executive leadership owns the ultimate financial sustainability. They also own the organizational risk and the brand reputation.
When a sophisticated fraudster today uses what I call neural puppetry—essentially using AI and deepfakes to clone a patient's voice or bypass authentication protocols through the contact center—the resulting downtime is part of the IT problem, but it's also a massive cash flow, operational, and liability crisis is what it boils down to.
When a staff member is socially engineered into permitting an intrusion, network logs might still look clean. Your CISO can secure the server room, but only the CEO can mandate a cultural shift from passive awareness—which is what current security awareness training is—to active appreciation of what security actually is and what effectively managing risk actually looks like, not just at work but in employees' personal lives so they do better at work.
Ultimately, we build what I call a strategic human firewall across the entire enterprise.
For me, every phone call, every text message, every email, every pop-up—I immediately look at it and ask myself, "What is really happening here?" Why? Because I want to know whether it's really Google or not. I'm guessing you probably do the same thing with most phone calls, emails, and text messages. I'm guessing most executives do the same thing.
Most employees do not. If you look at your own parents or your own siblings, you're constantly talking them off the ledge. "Mom, don't click that link." That’s most employees. They just don't know.
They need to be upgraded and updated and brought up to speed regarding what security is. It's not paranoia. It's not worry. It's not fear. It's a good thing. It's like putting on a seatbelt. It's about getting control. Once they understand that, this all starts making a lot more sense. "I want to engage in phishing simulation training." "I understand what I need to do when the phone rings." "I recognize there is risk. Therefore I need to pay a little more attention."
That's a good thing.
Stewart Gandolf (Healthcare Success): One thing you've said a couple of times reminds me of a misconception that only older people fall for this. I've had employees in our company, on multiple occasions, get fooled personally.
One time—and we've seen this over and over again—somebody sent a text pretending to be me asking an employee to go buy a bunch of Apple gift cards. Just the absurdity of that. Why would I call an employee and ask them to cash in Apple gift cards? But they've actually done it before.
Another person on the technical side actually fell for a scam. He couldn't believe it. He was humiliated. He was so mad at himself. What causes that?
First, I just want to make the point that it's not just your grandma. It could be your employees. Second, tying that into the idea of security awareness versus security appreciation, help me understand why this happens so much.
Robert Siciliano (ProtectNow LLC): Security awareness has been around for hundreds of years. In corporate America over the past 15 or 20 years, they've kind of ruined what the term security awareness actually means. Security awareness truly is personal security. It's violence prevention. It's theft prevention. In the physical world, that's what security awareness originally was. Now they've turned it into phishing simulation training.
Phishing simulation training is just that. It's phishing simulation training. It's not really security awareness. As a result, we're not really making the human being aware of security. We're just training them on one issue—phishing. Ultimately, we're not speaking to that person where they are in their own life regarding what security is, what security isn't, and so forth.
Ultimately, that causes what I call security fatigue, which is a compliance trap. It's bombarding employees with complex, impersonal rules that trigger security aversion. It creates a false sense of security by meeting regulatory requirements while actual human behavior remains unchanged. That's unfortunate.
The strategic human firewall is designed as the ultimate defense against deception. As a result, it brings people to what I call security appreciation. It's a dialogue. It's not the blunt-force hammer over the head. It's actually an interactive event where we're talking about all the various issues humans face on a regular basis—password management, two-factor authentication, home security, your child going off to college, basic things we all want to know about, credit card security, what links are okay to click on Google.
Now they go from, "I was required to be in this room because my employer made me," to, "This isn't about the company. This is about me. I have questions. I want to know."
Now you're engaged in a dialogue with people who've had questions their entire lives about issues they've always been concerned about but never really had anyone to ask because they didn't know who to talk to. The CISO never did that.
What's great about a dialogue is you'd be amazed how everyone has similar—or the same—questions. Once you get through all of that, they're saying, "This is great. Security's a good thing. I want more of this in my life, both personally and professionally."
I'll ask you a quick question. When you're on an airplane and the flight attendant is providing instructions and she talks about the oxygen mask, what does she say to do first?
Stewart Gandolf (Healthcare Success): Help yourself.
Robert Siciliano (ProtectNow LLC): Yes. Why? Because you're more effective in helping others once you help yourself first. All security awareness training should be that. Help yourself first so you can, in fact, help others. That's what security appreciation does. It provides an appreciation for the value security has in your life—protecting your identity, your passwords, your bank account, your child's digital footprint.
Going forward, people look at all aspects of business security in a very different light because they see how it affects them. We are selfish, self-interested creatures for a reason. That's not necessarily a bad thing. You've got to take care of your body. You've got to take care of your mind. Your mental health. Your physical well-being. Security is a good thing. Once you weave security appreciation into the paradigm, everything changes. Employees begin looking at security very differently.
Stewart Gandolf (Healthcare Success): I can see that because it goes from an intellectual exercise—"Okay, okay, okay"—kind of like HIPAA training, to, "Wait a minute. This is my own life. I need to understand this stuff better."
They're meaning to be good employees, but certainly getting them personally engaged is going to make it better.
Breaches are still happening while organizations are spending millions on technology, consultants, compliance, and cybersecurity.
Can you think of any breaches recently—or even in the past—where it really came down to one employee making a mistake? Is that a common thing? Can you think of any examples or stories that fit from a healthcare perspective?
Robert Siciliano (ProtectNow LLC): Change Healthcare is a prime example where, frankly, a failure in operational leadership was the definitive root cause of a catastrophic breakdown. Ultimately, the entry point for the ransomware was an authoritative corporate access account that completely lacked multi-factor authentication. That's a human problem.
Leaving a primary digital gate unbolted on a vital healthcare clearinghouse isn't a software engineering glitch. It's an organizational governance failure. Leadership permitted operational shortcuts that allowed a critical access point to remain vulnerable. What was that—almost two hundred million records? Medical billing operations nationwide were paralyzed, demonstrating how compliance theater crumbles under real-world pressure and human error.
My job is to make employees care about security. When I walk into a room, I'm looking at a hundred people with their arms crossed, a scowl on their face, looking at me, looking at their watches, thinking, "Okay, security guy. Tell me something I don't already know. I've got work to do."
That's what I'm looking at when they introduce me. I start asking challenging questions about home security. "Did you know that almost two million homes are burglarized every single year?" They're like, "Whoa. I didn't know that. Maybe I should start locking my doors. Maybe I should consider a home security system."
Then I ask them about password managers. "Did you know there are twenty billion passwords floating around on the dark web?" They're like, "Whoa. I didn't know that." I show them tools where they can type in their email address and see the websites where their credentials have already been compromised.
Again, "Whoa. I didn't know that." As I'm showing them all this, it's actually kind of fun to watch. Physically, they lean into the conversation. The scowl disappears. Their eyes open a little wider. Their arms come down. Then their hands start going up because now they have questions.
We have this dialogue, and at the end people come up to me and say, "I didn't really want to be here. My boss made me come. I didn't think I needed this. But I'm so glad I came. I wish my spouse had been here because they would have loved it."
That's what security training should be. That's almost never what it is today.
Stewart Gandolf (Healthcare Success): You brought up something earlier, and it reminds me of a scene in the original Terminator where the Terminator starts talking to Sarah Connor. It's her mother—but it's not her mother. It's Arnold Schwarzenegger with what amounts to an AI voice mimicking her mother, and it fools her into this. That was 1984. That's real now.
It really is scary. You think about AI spoofing voices and sounding like people. If people weren't paying attention before, now it's even worse. Is there any hope? What's happening there? Will people be able to tell what's real and what's fake when it's already so terrible and so confusing?
Robert Siciliano (ProtectNow LLC): First of all, I'm a hope guy. I'm a glass-half-full all day long. But no—they will never be able to tell the difference. What we can do is condition them not to automatically accept the reality of what's in front of them.
Healthcare leaders are heavily underestimating the speed and weaponization of AI in executing localized social engineering. They assume hackers are still relying on obvious, poorly written phishing emails or easily detectable scams. In reality, mass-market AI tools have completely eliminated those classic warning signs. Blunt-force phishing with typo-laden emails is gone. Criminal syndicates now scrape public audio and video to execute hyper-personalized cloned attacks using the voices of CEOs, COOs, coworkers, family members.
Leaders mistakenly view AI primarily as a clinical or administrative tool, completely missing how easily criminals use automated deception to target vulnerable patients navigating high-stress life transitions or to trick frontline executives and medical staff working under intense operational pressure. We're heading to a point where we truly cannot trust what we see and what we hear truly ever again. I don't say that to be an alarmist. I say that because I know. When I take quizzes and tests asking, "Is this AI or is this real?" I get it wrong 60% of the time. I'm just guessing because I'm human like everybody else. There really isn't a telltale sign anymore.
Anybody can go on Facebook Reels right now. You don't know if that dog is really doing what it's doing or if it's AI. They've taken some of the fun out of it because you just don't know anymore. You don't know if it's a person, a dog, a cat—you don't know what's real.
We're never going to be able to tell what's real and what's fake. What we can do is condition people to accept that they're never going to know for certain, and help them understand what's happening to them biologically and psychologically. We can teach them how inbound information affects their senses, influences their emotions, and translates into actions that could ultimately result in harm to themselves, other people, patients, clients, or the organization. That's something we can teach.
Stewart Gandolf (Healthcare Success): You mentioned earlier—and maybe you've already answered this—but what should healthcare leaders be worried about most? Is it AI? Is it all of it? The vulnerability, the humans, the technology?
One thing that scares me even more than the accuracy of AI is the scale. Before, somebody actually had to call somebody. Now the bots are calling. The scale is almost infinite.
Robert Siciliano (ProtectNow LLC): When a sophisticated fraudster is using neural puppetry to clone a company CEO, an administrator, a patient—or bypass authentication protocols through a contact center—that's going to result in large-scale reputational loss because leadership didn't see it coming.
We already have all the technology we need to secure the network. These technology stacks are designed to be relatively bulletproof. What they aren't designed to do is account for the physical, emotional, and biological fallibility of human beings. If we think existing phishing simulation training is going to solve that problem, it simply isn't.
We need an upgrade. We've put the cart before the horse for too long. We've made phishing simulation training the primary metric for solving the human-factor problem, and with AI and deepfakes it's no longer capable of doing that by itself.
Instead, we need to engage in actual human risk management. We need to meet people where they are in their own lives—their own digital footprint, their own identity, their own passwords, their own bank accounts. We need to go back to the fundamentals of what security awareness really is. People protect what they love first. People protect what's important to them first.
I'm not talking about throwing out all security awareness training. I'm talking about adding to it. This doesn't have to happen every month or every quarter. It could happen once a year. We're simply trying to change basic habits. Locking your front door is a habit. Arming your home security system every night is a habit.
Having a conversation with your daughter before she leaves for college about sexual assault is a something everyone should do. It's an uncomfortable conversation, but it's one every parent should have—not because they want to live in fear, but because it's the smart thing to do.
Those are the conversations I have with my daughters. Those are the conversations I have with audiences. I want people thinking about security as something positive because it's important—not because they should worry, but because it's simply the smart thing to do. We've convinced ourselves security is a negative thing, and I think that conversation needs to be completely flipped.
Stewart Gandolf (Healthcare Success): Two last questions as we wrap up. What are some practical habits that work for healthcare employees, both personally and professionally? Without giving away everything you teach, what are two or three things people could walk away and start doing tomorrow that would immediately make them better protected?
Robert Siciliano (ProtectNow LLC): Really simple things. If I were addressing a room full of healthcare CEOs, my directive for the next 90 days would be to ditch the compliance theater and activate what I call the kitchen table effect. That's when employees take what they learn at work home and talk about it with their families.
Stop forcing staff to endure stale, technical, check-the-box training that they immediately forget—or spend their time trying to beat. Instead, teach them how to secure their own families. Freeze your personal credit. Have you frozen your credit?
Stewart Gandolf (Healthcare Success): Nope.
Robert Siciliano (ProtectNow LLC): Freezing your credit is one of the most basic things you can do, and it's been available since 2008. Every employee—including every executive—should have their credit frozen. It prevents someone from opening new credit in your name or damaging the good credit you've spent your life building.
That's basic, foundational security. When you teach employees how to protect their own personal legacy at home, you automatically build the secure muscle memory needed to protect the organization.
Stewart Gandolf (Healthcare Success): Finally, at the organizational level, what should CEOs be doing over the next 90 days to reduce their risk? Anything we haven't already discussed?
Robert Siciliano (ProtectNow LLC): Again, ditch the compliance theater. Start having these uncomfortable conversations with the people in your own life. Find out where they really are. You'll be amazed how vulnerable most people actually are because we've trained ourselves not to think about security in an effective healthy way. We tell ourselves, "It won't happen to me," and then we do nothing.
All security is personal. The most effective corporate security strategy begins by teaching your workforce how to protect their own families and their own digital lives. Understand that the technical perimeter has faded. Fraudsters have stopped wasting time trying to breach your firewall. They're focused on exploiting the biological human blind spot of your employees.
Stewart Gandolf (Healthcare Success): That's a scary—but good—way to end. How should people contact you if they'd like to learn more?
Robert Siciliano (ProtectNow LLC): I'm on the Google. I'm on LinkedIn. I'm giving this information away every couple of weeks. Otherwise, my website is ProtectNowLLC.com.
Stewart Gandolf (Healthcare Success): Right. Thank you, Robert. I enjoyed this.
Robert Siciliano (ProtectNow LLC): Thank you.
















