Black Hat
,
CISO Trainings
,
Events
CRISP Shared Services’ Bezawit Sumner on Mission-Driven Hiring, Retention and Trust
Healthcare organizations have become more attractive targets for attackers even as their security budgets remain constrained, said Bezawit Sumner, CISO and senior director of security and compliance at CRISP Shared Services. That leaves teams competing for the same talent pool as major technology firms with larger budgets.
See Also: How Postman Embeds Wiz Risk Data Into Dev Workflows
Retention starts with the people already on the team. Organizations should prioritize psychological safety, so employees feel comfortable flagging mistakes rather than hiding them. “The best thing we can do is create comfort for the individuals that are implementing the tools,” Sumner said.
Security programs also need to evolve with the threat environment. Sumner urges teams to study major breaches and apply those lessons before similar weaknesses surface internally. “You don’t have to make the same mistakes. Mistakes are made. We can learn from it,” she said.
In this video interview with ISMG at Black Hat USA 2026, Sumner also discussed:
- How giving team members latitude to pursue personal projects and outside training builds more diverse, resilient teams;
- How lessons from the aviation industry’s safety culture apply directly to cybersecurity incident reporting;
- Why security audits should evolve with emerging threats instead of relying solely on lookback assessments.
Sumner’s work focuses on protecting sensitive health data and supporting secure, interoperable data exchange. She supports health information exchange and health data utility services across multiple states while helping strengthen organizational resilience and cybersecurity maturity across complex healthcare environments.
