Skip to main content
    Back to episode
    Episode 75 · June 25, 2026 · 41m listen · 5,342 words · ~27 min read

    Cybersecurity Isn't an IT Problem Anymore with Melissa Aarskaug - Full Transcript | The Med Device Cyber Podcast

    Read the complete, searchable transcript of Episode 75 of The Med Device Cyber Podcast - expert conversations on medical device cybersecurity, FDA premarket and postmarket guidance, SBOM management, threat modeling, and penetration testing.

    Prefer the listening experience? Open the episode page for the synopsis, key takeaways, topics, and Apple / YouTube listen links.

    Episode summary

    In this episode of the Med Device Cyber Podcast, hosts Trevor Slattery and Christian Espinosa are joined by Melissa Aarskaug, EVP of Strategy and Growth at DruvStar, to discuss the critical evolution of cybersecurity from a technical function to a core business strategy. Melissa brings a unique perspective shaped by her career in highly regulated industries, including banking, civil engineering, and most notably, the high-stakes world of casino gaming. The conversation opens with a striking anecdote about a casino's network being breached through a connected fish tank, immediately establishing the theme that any connected device can be a vulnerability. The discussion frames cybersecurity not as a siloed IT problem, but as a central component of business risk, finance, and operations. This is highlighted by the trend of Chief Information Security Officers (CISOs) now reporting to Chief Financial Officers (CFOs), underscoring that security is fundamentally about managing financial risk and ensuring business continuity. The main argument of the episode is the necessity of shifting from a mindset of pure prevention to one of business resilience—accepting that incidents are a matter of 'when,' not 'if,' and planning for how to maintain operations during and after an attack. Melissa draws parallels between the gaming industry, with its zero tolerance for downtime and immediate revenue loss during an incident, and the equally critical MedTech and healthcare sectors. She explains that attackers specifically target these regulated industries because the immense pressure to avoid operational disruption, regulatory fines, and loss of patient or customer trust provides them with significant leverage for extortion. The hosts and guest explore how attackers are not just trying to exploit a technical weakness, but are strategically looking for pressure points within a business to force a response, such as a ransom payment. Throughout the conversation, Melissa outlines a practical, proactive approach to cybersecurity. She emphasizes that organizations must first achieve complete visibility of their digital environment to “know what they have,” including all connected devices and third-party vendor systems. Once the full attack surface is understood, the next step is to prioritize the protection of critical systems that would cause the most harm to the business if compromised. Furthermore, she advocates for regularly practicing incident response through internal simulations and tabletop exercises to ensure teams are prepared to act under real pressure. The discussion also touches on the changing landscape of cyber insurance, cautioning that it is not a silver bullet. Insurers are becoming more stringent, often denying claims to companies that have neglected their security duties. Ultimately, the episode serves as a call to action for leadership across all industries to integrate cybersecurity into their operational DNA, fostering a culture of security that goes beyond mere compliance checklists.

    Key takeaways from this episode

    • Cybersecurity has shifted from a supplementary IT function to a core business and risk management concern, impacting finance, operations, and customer trust.
    • Businesses should adopt a resilience mindset, focusing on how to continue operations during a security incident rather than solely on preventing one.
    • Highly regulated industries like gaming and healthcare are prime targets for cyberattacks because the immense pressure to avoid downtime provides leverage for attackers.
    • Any connected device, even something as seemingly innocuous as a fish tank, can serve as the weakest link for a network breach.
    • A fundamental step to effective security is achieving full visibility of all assets and systems to understand the entire attack surface and prioritize critical risks.
    • Attackers strategically look for business pressure points to exploit; understanding this helps in building a more focused and effective defense.
    • Cyber insurance is not a substitute for proactive security. Insurers increasingly require proof of due diligence and may deny claims if security measures are inadequate.
    • Cybersecurity is becoming a business-wide responsibility, with CISOs increasingly reporting to CFOs, reflecting its direct impact on financial risk and liability.

    Full episode transcript

    Page 1 of 6· Paragraphs 1 - 13
    Guest: I don't know if you guys heard about this in the gaming industry. They got in through a fish tank. Somebody got in to the fish tank and it was connected to their network. Christian: Cybersecurity used to be like supplementary to quality for a medical device. And now they're integrated. Cybersecurity is part of quality. So the quality and the effectiveness and the safety of this device, cybersecurity is part of that. Guest: Cybersecurity used to be an IT function, right? It was an IT team. But now CISOs are reporting to CFOs, because they're handling risk, their insurance policy, the money side of things. So we're seeing this shift, and I think AI is helping that shift. Guest: Hey there, and welcome back to another episode of the Med Device Cyber podcast. Uh, as usual, we have our two co-hosts, myself, Trevor Slattery, and Christian Espinosa. And today we are joined by a very special guest, Melissa Aarskog. I'd love to hear a little bit about you and, uh, just first a quick check in, how's your morning going so far? Guest: My morning is going fabulous. Thank you for asking. Excited to be here today and talk to you two about cybersecurity. Christian: You're coming from Austin, right? I think. Is it Austin? Guest: Yes, yep. Christian: Yeah, a little bit earlier for us today. It's, uh, like 7:00 in the morning for us. Guest: Love to hear a little bit about what you're working on and know that you're involved in cybersecurity, so it'll be a fun conversation. We're also obviously involved in cybersecurity, more on the medical side, but you're a little bit more, uh, outside of the medical space. Is that correct? Guest: Yes. My background is in regulated industries. I started my career in banking and then pivoted into civil engineering and then found my way into gambling and gaming and then found my way into cybersecurity. And so I've spent a lot of time in the casino gaming industry where it's a 24-hour, 7 days a week, 365 days a year business with, you know, financial systems, customer data, and really zero tolerance for downtime. It's a similar kind of to the healthcare industry, it's always up, always taking care of patients. And so, you know, when something goes wrong in the gambling industry, it's immediate revenue stops, regulators get involved, customers feel it, and it really forces a different type of mindset. And so you stop thinking about, let's perfectly protect, to, let's start thinking about how this is going to keep the business running, no matter what happens. Christian: I know when we were, uh, talking a little bit beforehand, you mentioned gambling is probably more regulated than medtech. And I was curious if you could expand upon that a little bit. Guest: Attackers are really hitting regulated industries. So there's a lot of industries that are regulated. Um, in gambling, um, before you can launch a casino or sell a product, there's a long, rigorous licensing process. Depending on what state you're in, each state has different regulations. You know, in some cases, some states will go back 10, 20 years. You know, if you made a thousand cash deposit into your bank account, they want to know what the cash was and why you deposited it. And so they get really in the weeds. And I've had several CEOs who have been married 30, 40 years tell me, gosh, you know, these regulators know more than my wife does about everything I've ever done in my entire life. So they really turn over every single rock to make sure the people that are operating and running these casinos online and, um, land-based are operating at a high level of integrity. Um, they're going about doing it the right way. And so, you know, I guess the question, why do attackers keep hitting these industries? Because they create pressure, right? I think attackers don't just look at or find the weaknesses. They look for environments that they can disrupt, um, and force a response, not only from the casino, but from regulators. So oftentimes regulators, you know, get involved quickly, um, and in, and regulated industries, they have high value data. They're always operating. They have the oversight from regulators and so there's really no tolerance for downtime. So attackers and perpetrators know that if they go after, you know, a space like that, they're going to be, you know, the casino's going to be forced to respond quicker versus just generally going into, you know, targeting anybody. So in gaming, if a system goes down, revenue could stop and that could be something like a million dollars a day or multiple million dollars a day depending on where your casino is. And the real loss is tens of millions of dollars in loss of, you know, gambling and systems. I forget the exact number, but I think it's, you know, cybercrime is projected to be, um, a 15 trillion business by 2030. I think it's about 15 trillion is projected.
    1 / 6