Artificial Intelligence & Machine Learning
,
Black Hat
,
Business Continuity Management / Disaster Recovery
University of Denver’s Staynings on Board Communication, Medical Device Security
Healthcare cybersecurity has become an enterprise-risk and patient-safety issue as hospitals adopt artificial intelligence, connected medical devices and digital services. Security leaders must translate technical exposure into business consequences that boards can evaluate, said Richard Staynings, professor of healthcare cybersecurity at University of Denver.
See Also: AI Phishing Now Frighteningly Normal, Hard to Detect
“It’s vitally important for the business units … and the governance members of the organization to understand the complexity of these technologies, the associated risks as well as just the business benefits. That’s where security leaders have a role to play in that communication,” Staynings said.
Effective governance must address security, compliance and technology resiliency, he said. “We also need a component in there to understand the complexity and the risks around the AI technologies that we’re adopting.”
In this video interview with ISMG at Black Hat USA 2026, Staynings also discussed:
- How security leaders can position cyber as a core component of enterprise strategy;
- Why hospitals struggle to maintain visibility into connected medical devices and their associated risks;
- How segmentation, zero trust and compensating controls can reduce risks from legacy IoT and connected medical devices.
Staynings has more than 25 years of experience in cybersecurity leadership and consulting focused on the healthcare and life sciences industry. He is also chief security strategist at Cylera, where he focuses on medical devices and HIoT security.
