Blog

Lessons From 25 Years in Healthcare IT

Justin Armstrong

I’ve been drawn to espionage, cryptography, and security since I was a kid. In fourth grade I found a copy of David Kahn’s “The Codebreakers,” way over my head at the time, but I understood enough to start inventing my own codes and ciphers for fun.

I started programming at 10, on Apple IIs. We had early access thanks to the Five College system near our small town in Western Massachusetts, unusual exposure for kids our age at the time.

I majored in Physics and Math in college, but computers never left the picture. I had three science internships in College, and each one required very technical computer programming. After graduating, I chose industry over academic research and joined MEDITECH as a developer. About 15 years in, hospital security became a priority, and that’s when I moved into a security role.

Test Your Own Product

I once asked our development team three times whether a particular product cached any data on the local device. Three times, I was assured that it did not. Then a customer discovered that it actually did. It turned out to be a one-character mistake in the code.

I took full responsibility for that, because I should have had it tested. Multiple application security testing companies missed it too. For anything critical, I will always insist that we personally test it. It’s vital to test your own product from a security and privacy perspective, and that lesson has shaped how I lead ever since.

The CISO Role Isn’t a Technical One

The biggest misconception people have about the CISO role is that it’s technical. People and business skills are absolutely essential for being successful as a CISO, perhaps even more than technical skills.

Identity and Access Management, Still

Ask most organizations what they think they’re doing well, and identity and access management often comes up. And yet, when people leave the company or change roles, some will continue to have the same access. It’s a common problem, and it’s genuinely challenging to do well.

The Blind Spot Waiting Behind the Facilities Door

Operational technology is the blind spot I see most often when I step into a new environment. This is the stuff controlling HVAC systems, badge readers, doors, and more. It’s a real disconnect. These systems are often managed by a facilities team with limited IT and cybersecurity experience, and even the OT vendors themselves tend to do a poor job on security.

Programs Move When Executives Talk About It

What separates security programs that actually move forward from the ones that stall is executive support. If the CEO does not publicly speak about the importance of cybersecurity, and security in general, people are not going to prioritize it.

I have a love/hate relationship with third-party risk management. Getting to know your vendors, learning about their security, and doing your due diligence is genuinely important. But a lot of organizations send out lengthy questionnaires, review them, and promptly file them away. They need to do more than ask questions. They need to make changes based on what they learn. Don’t feel comfortable with the security of a vendor who has remote access to your systems? Implement a solution that grants access on request rather than giving them unfettered access at all hours of the day. The vendor’s solution doesn’t have strong authentication? Write it into the contract that they must deliver one, or find another vendor.

A practical change organizations can make today: isolate vulnerable systems that have out-of-date operating systems or legacy applications, and don’t allow access to those systems from the internet.

Staying Sharp

It’s important to exercise even when you’re busy. Go for a walk, ride a bike, hike, or even just do some quick calisthenics at home.

Advice for Anyone Aspiring to Be a CISO

Don’t focus on the title. Simply continue to look for new ways to show your value to the organization. Learn everything you can. Do some hands-on hacking, get a Wi-Fi Pineapple, learn to pick locks.

And if your current employer doesn’t prioritize cybersecurity, it’s fine to try and raise the bar for them. But at some point, if you recognize it isn’t enough of a priority for them, you need to move on.

Justin Armstrong | Principal Consultant, SideChannel

Justin Armstrong has over 25 years of healthcare IT and software development experience. He led major changes in product and cloud security at MEDITECH, a top tier EHR vendor, including the architecture of MEDITECH’s first cloud hosted EHR and its ISO 27001, 27017, and 27018 certification project. Justin has advised on nearly 100 ransomware incidents at hospitals and is a working member of the IEEE SA-P2933 working group developing standards for Clinical IoT data and device interoperability. As a fractional CISO, Justin has led organizations through successful SOC 2 audits and continues to advise hospitals and healthcare companies on security and compliance.

About the Author Justin Armstrong
Back to Resource Center