217 episodes
- When a hospital's systems go down, care does not stop. It goes back to pen and paper, and the first sign is quiet, because the alerts stop. Physician and CISSP Mark Yoffe explains clinical compensating controls: the steps clinicians take to keep patients safe during downtime. He covers who owns the clinical workflow, how to make controls workable and tested, how to recover information lost in the "memory hole," and what leaders should demand as proof. Paper is not the same as proof. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates.
LinkedIn: https://www.linkedin.com/in/mark-yoffe-md-cissp-a9927956/
"Fire Doesn't Innovate" by Kip Boyle: https://a.co/d/0bYatohy
LinkedIn post:
Questions:
Here are audience engagement questions for this episode, organized by segment:
Segment 1 – When the Hospital Goes Analog
Have you ever worked through a system outage — at a hospital or anywhere else? What was the first thing that broke down?
Does your organization have any setting where "no news is bad news" during downtime — where information stops coming to you and you don't immediately notice?
Segment 2 – Ownership
Who owns your clinical downtime workflow right now — not IT, but the clinical side? Can you name them?
If your systems went down tonight, is there a single person accountable for whether patient care workflows hold up — or would people be figuring it out as they go?
Segment 3 – Workability
Does your downtime policy actually get used, or does it live in a binder somewhere? When did anyone last open it?
What's one task your team assumes staff can improvise during downtime — that they probably can't?
Segment 4 – The Memory Hole
After your last outage, how confident are you that everything documented on paper actually made it into the record? Did anyone check?
Has a gap in documentation during downtime ever affected a patient's care — or nearly did?
Segment 5 – Leadership Oversight
If your CEO asked today, "Can you show me that our clinical downtime controls actually work?" — what would you hand them?
When did your organization last run a tabletop exercise specifically for clinical downtime — not just IT recovery?
Closing poll question:
Does your organization have a named, clinically credible owner for downtime workflows — yes, no, or "I genuinely don't know"? - After a breach, you either pay the fine, or fight the regulator and lose. There's a third path. It comes down to one word: reasonable. A method called DoCRA turns that question into something a court can use. DoCRA is short for Duty of Care Risk Analysis. Our guest Chris Cronin of HALOCK Security Labs helped build it. Now it's in standards and law. And it shaped a real case where a breached company spent its money on cybersecurity, not fines. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates.
LinkedIn: https://www.linkedin.com/in/chris-cronin-351416/
"Fire Doesn't Innovate" by Kip Boyle:
https://a.co/d/0bYatohy
Learn more about DoCRA: https://docra.org - There's a popular new playbook for running an "AI-native" company. Record everything, put all your data in one place, and let an AI agent reach all of it. The productivity story is real. New hires ramp up in days, and the whole company can ask questions it never could before. But the same moves that create the speed also switch off safeguards that some businesses are not allowed to switch off. So, which controls are we turning off to get this speed, and are we allowed to? Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates.
Y Combinator's AI native playbook video -- https://youtu.be/B246K_G7mHU
AIR-MAP website -- https://air-map.io/ - Your cybersecurity tools were built for people: a login, a single sign-on, an email address. But the AI agents now showing up inside your company don't work that way, and most of them slip right past your controls. So how do you find the "Shadow AI" already running in your business, and get a handle on it? Let's find out with our guest Nancy Wang, Chief Technology Officer at 1Password, who works at the front edge of how machines get access to systems. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates.
LinkedIn profile profile: https://www.linkedin.com/in/wangnancy/
1Password: https://1password.com/ - Would you know if the AI tools your team is buying are actually trustworthy to use? Who gets to decide what trustworthy AI even means? Let's find out with our guest Jim Reavis, CEO of the Cloud Security Alliance, the group that helped the world learn to trust the cloud and is now building the standards for trusting AI. Jim explains how AI is changing what attackers, defenders, and governments can do, and walks through the tools his team built so you can adopt AI without guessing. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates.
Cloud Security Alliance: https://cloudsecurityalliance.org/
More Business podcasts
Trending Business podcasts
About Cyber Risk Management Podcast
Cyber risk made clear for busy leaders. Cyber threats move fast. Your business must move faster. In every episode, Kip Boyle—author of "Fire Doesn’t Innovate" and CISO at Cyber Risk Opportunities—joins cybersecurity attorney and CISSP Jake Bernstein to break down the latest cyber risk. You’ll hear plain-English explanations of what's going on and what you need to do about it. No jargon. No doom. Just clear steps you can use today to save money, win buy-in, and stay out of the headlines.
Podcast websiteListen to Cyber Risk Management Podcast, Honest Money and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Cyber Risk Management Podcast
Scan code,
download the app,
start listening.
download the app,
start listening.
Cyber Risk Management Podcast: Podcasts in Family

















