Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug - Full Transcript | The Med Device Cyber Podcast
Read the complete, searchable transcript of Episode 75 of The Med Device Cyber Podcast - expert conversations on medical device cybersecurity, FDA premarket and postmarket guidance, SBOM management, threat modeling, and penetration testing.
Prefer the listening experience? Open the episode page for the synopsis, key takeaways, topics, and Apple / YouTube listen links.
Episode summary
In this episode of the Med Device Cyber Podcast, hosts Trevor Slattery and Christian Espinosa are joined by Melissa Aarskaug, EVP of Strategy and Growth at DruvStar, to discuss the critical evolution of cybersecurity from a technical function to a core business strategy. Melissa brings a unique perspective shaped by her career in highly regulated industries, including banking, civil engineering, and most notably, the high-stakes world of casino gaming. The conversation opens with a striking anecdote about a casino's network being breached through a connected fish tank, immediately establishing the theme that any connected device can be a vulnerability. The discussion frames cybersecurity not as a siloed IT problem, but as a central component of business risk, finance, and operations. This is highlighted by the trend of Chief Information Security Officers (CISOs) now reporting to Chief Financial Officers (CFOs), underscoring that security is fundamentally about managing financial risk and ensuring business continuity. The main argument of the episode is the necessity of shifting from a mindset of pure prevention to one of business resilience—accepting that incidents are a matter of 'when,' not 'if,' and planning for how to maintain operations during and after an attack. Melissa draws parallels between the gaming industry, with its zero tolerance for downtime and immediate revenue loss during an incident, and the equally critical MedTech and healthcare sectors. She explains that attackers specifically target these regulated industries because the immense pressure to avoid operational disruption, regulatory fines, and loss of patient or customer trust provides them with significant leverage for extortion. The hosts and guest explore how attackers are not just trying to exploit a technical weakness, but are strategically looking for pressure points within a business to force a response, such as a ransom payment. Throughout the conversation, Melissa outlines a practical, proactive approach to cybersecurity. She emphasizes that organizations must first achieve complete visibility of their digital environment to “know what they have,” including all connected devices and third-party vendor systems. Once the full attack surface is understood, the next step is to prioritize the protection of critical systems that would cause the most harm to the business if compromised. Furthermore, she advocates for regularly practicing incident response through internal simulations and tabletop exercises to ensure teams are prepared to act under real pressure. The discussion also touches on the changing landscape of cyber insurance, cautioning that it is not a silver bullet. Insurers are becoming more stringent, often denying claims to companies that have neglected their security duties. Ultimately, the episode serves as a call to action for leadership across all industries to integrate cybersecurity into their operational DNA, fostering a culture of security that goes beyond mere compliance checklists.
Key takeaways from this episode
- Cybersecurity has shifted from a supplementary IT function to a core business and risk management concern, impacting finance, operations, and customer trust.
- Businesses should adopt a resilience mindset, focusing on how to continue operations during a security incident rather than solely on preventing one.
- Highly regulated industries like gaming and healthcare are prime targets for cyberattacks because the immense pressure to avoid downtime provides leverage for attackers.
- Any connected device, even something as seemingly innocuous as a fish tank, can serve as the weakest link for a network breach.
- A fundamental step to effective security is achieving full visibility of all assets and systems to understand the entire attack surface and prioritize critical risks.
- Attackers strategically look for business pressure points to exploit; understanding this helps in building a more focused and effective defense.
- Cyber insurance is not a substitute for proactive security. Insurers increasingly require proof of due diligence and may deny claims if security measures are inadequate.
- Cybersecurity is becoming a business-wide responsibility, with CISOs increasingly reporting to CFOs, reflecting its direct impact on financial risk and liability.