Resources
- -
- Solutions
- RadiantOne
- Why Radiant Logic
- Company
- Support
- Resources
© 2026 Radiant Logic, Inc. All Rights Reserved. | Privacy Policy
Speakers:
Paul Dant, Sr. Solutions Consultant, Radiant Logic
Kristin Hoppe, Director, Identity Access Management, Baylor Scott & White
Knowing how attackers operate is half the battle. Kristin Hoppe joins Paul Dant for a practitioner’s view of identity management and defense inside a major health system: the real constraints, the tradeoffs, and the decisions that hold up under clinical pressure.
In part one, we shared some sobering realities facing health care organizations. We talked about health care being a prime target, as I’m sure everyone on this call already knows. Ninety three percent of health care organizations have had at least one breach in the last year, And the average ransom payment we’ve seen in health care is 1,150,000, which is the highest of any industry. So it’s certainly a big pressing concern, and so that’s why we wanted to bring this topic to the audience today.
In part one, Paul Dant shared some real life examples of his background in red teaming to share how the attackers are not just breaking down walls. They’re actually using identity to walk in the front door.
Really sobering reality, lots of interesting stories. If you missed part one, by all means, go back and listen to Paul’s stories. Today, I’m particularly excited. We’re pivoting, and we brought on Kristin Hoppe. She’s going to be sharing some real life practitioners perspective from her experience as the head of identity at Baylor Scott and White. Baylor Scott and White is the largest not for profit healthcare system in Texas and one of the largest in The United States.
Today, Baylor Scott and White includes 48 hospitals, more than 1,000 patient care sites, more than 9,600 active physicians, and over 48,000 employees in the Scott and White health plan. So certainly a large number of identities that she’s managing. And so we’re really excited to have her share her insights and expertise to all of us today. Paul, Kristin, thank you both so much for being here.
Paul Dant:
My pleasure. Thanks for having me.
Kristin Hoppe:
No, absolutely. Thank you for having me.
Brooke Vixamar:
I’m going to turn off our screen because this is really going to be a conversation today. We’re really excited to really just dig in and have an open conversation. As we kick things off, Paul, I thought maybe we could start with you and you could kind of revisit a little bit from part one on how was it that you got in? And then we’ll we’ll pivot back to Kristin and say, hey. This is your building. How would you think about closing it? So let’s start with you on just kind of giving us a little bit of a flavor of what we talked about in part one.
Paul Dant:
Sure, sure. Thanks, Brooke. So one of the key things that we talked about when it comes to identity is that good intentions often lead to bad outcomes. And what we really mean by that is traditionally as we’ve built identity programs, we’ve managed identity, it’s been built more for success and operational efficiency, not so much around security and understanding risks. We’re bringing that sort of mentality to identity in much more recent times.
And I think really what we talked about from a what’s missing perspective is the overall idea that identity data is strewn all throughout the enterprise. And when we talk about healthcare specifically, we have so many different types of attributes related to identity that grant us access to so many different systems and applications. It’s incredibly challenging to bring all of that together into a unified view. And that’s really where one of the things that we left off in our last webinar was part one was about how does the attacker ultimately get in?
Why is healthcare seemingly so vulnerable to these attacks as the media reports would tell us and what can we do about it? So, as you mentioned, I’ve spent quite a bit of time as a, we’ll say an offensive security researcher, forty years in fact, and hospitals and other healthcare facilities have been part of some of the targets that I’ve led coordinated attacks around from a research perspective. So one of the things that I’ll kind of just throw out there that I think is very unique and specific to healthcare is in particular within facilities, wow, excuse me, the susceptibility of someone gaining initial access onto a network and then finding their way through lateral movement to all of the really important things.
And of course, plays a critical role in controlling what an attacker can do once an identity is compromised.
And I think that’s really where we break into part two here is understanding from a practitioner and defender perspective, what does that look like? So I’ll hand it back over to you, Brooke.
Brooke Vixamar:
Absolutely, great. Thank you for setting the stage on that.
Kristin, we’ll put you in the hot seat for a minute. I want to start with a little bit of the elephant in the room. I feel like health care is such a highly regulated industry.
I thought, as someone leading identity for such a highly regulated industry, where do you start? How do you decide your priorities and programs and what you put in place? How do you kind of approach it from that highly regulated industry standpoint?
Kristin Hoppe:
Yeah, absolutely. So starting from a regulated identity perspective, when you’re in an industry that requires that, you really have to understand the regulations themselves. So you actually should be reading them, understanding them, forming relationships with your privacy and your compliance and your legal entities within your organization.
Baylor Scott and White’s unique. We have a couple of different umbrellas that are on the same infrastructure. We have a health plan. We have We have a digital health office. We have a developer area.
We have joint ventures. So we have a number of different arms within our organization, and each of those has competing priorities. And each have competing regulations.
Some must be SOC compliant, others do not at that point. So you really have to regulate, or sorry, you have to build your program to defend the regulations that you’re responsible for, and not at the sake of end user function and ease of use either. I mean, as Paul already talked about in his intro, that’s a key component. So you need to make sure that your experience is as frictionless for your end user across any different persona, across any different regulation or branch that they’re working in within your organization, but your security is always in the background, and it’s always layered.
Brooke Vixamar:
That, across all of these personas, across all of these different departments, I think that kind of opens up the conversation around I think you’ve called them the unicorns in the past, the multi persona challenge that is really big in health care. You have someone who is legitimately three or four or five different people, they’re a clinician, a surgeon, a professor, a researcher. How do you manage that complexity?
Kristin Hoppe:
That is, it’s a complexity that never goes away. So even if you’ve developed a program, and we we have actually developed a very successful program at Baylor Scott and White, it still never goes away. You’re always gonna have these people. You’re always gonna have a person that is a student, but also as an employee, but also as a volunteer.
And then they’re going to change one of those personas, keep the other two throughout the duration of their time. They’re going to shift from employee to a contractor or contractor, better way to say that, to a contractor and then back again.
One of the best ways to do that is truly having a unified identity, but also having a global unique identifier. If you’ve assigned an identity so that Brooke Vixamer is who she is across all platforms, across any persona that she enters, then you’ve succeeded because you’re eliminating duplicate accounts. You’re eliminating the need for merging. You understand the access layers that that persona has depending on the role that they’re in.
That’s a big lift. It’s taken over two years for me to get that program up and running, and it is now finally running and working really well.
Brooke Vixamar:
I assume that also would be helpful for things like the contractors, the traveling nurses, the Yes. All of those pieces. Yes. Just having something that’s unique to them regardless of how they’re coming in and out of the system.
Kristin Hoppe:
100%.
Brooke Vixamar:
One of the particular challenges we see facing health care also is there’s a lot of legacy technology, and there’s a lot of operational technology that you can’t just ignore it. It’s important, but it’s very hard to manage.
So these are devices that are a little outdated and you can’t really patch them.
So if you can’t fix the device, what do you do instead?
Kristin Hoppe:
Yeah, absolutely. I think that’s to me.
From a practitioner side, sometimes that’s not an identity issue so much as you’re going to work with your partners across infrastructure and you’re going to
Brooke Vixamar:
work with your partners across security itself.
And you’re going to isolate it.
You’re going to put it
Kristin Hoppe:
on its own network segment.
You’re going to put boundaries and foxes around that with different technological layers than just identity. Now, one of the key things with identity is just, I mean, even establishing your standard and creating buy in and having everybody speak the language that is new applications are coming in, or they’re looking at replacement, or you’re talking to the operational stakeholders about what it means to be on a modern technology, just having them understand base words like SSO and SAML or OIDC, having them be able to be your advocate as they’re going into these rooms that you’re not in is key, and that’s something that we do really well in my program as we teach all of our practitioners, all of our partners across our IT departments that as they’re onboarding new or they’re replacing old or they have old, that we have to defend that. And that’s and that’s the way we’ve done that by giving them a common language.
Brooke Vixamar:
Paul, I’m curious if you, that was a great explanation, interesting from practitioners. Do you have any other kind of insights on that legacy operational technology challenges?
Paul Dant:
Sure, sure. So, I think one interesting aspect of that is it presents a really unique physical security challenge for facilities where we have these devices and we, from an attacker perspective, really just think of them as network access points.
And when you look at any sort of given hospital, there’s certainly security and visitor check-in and all of those things. But in general, it’s largely a public place. And once you’re in, you’re not necessarily gonna be challenged for stay wandering into an empty room. Everyone’s way too busy for that. And that’s where some of my research really showed that unique physical security aspect where if I can gain access to one of these legacy systems. And of course, most of the time legacy means not great security, especially if we’re not able to patch it. So if I can get some sort of terminal shell access on one of these devices simply because I plugged my laptop into an open network port on the back of it.
I now have potentially a starting point for lateral movement into much more important systems. And Kristin hit the nail on the head where this isn’t necessarily an identity problem per se. It’s a blast radius problem for sure. And so much of that comes down to other compensating controls like network segmentation, all of that kind of stuff that we know we need to do, but we also know it’s really difficult to put in place.
Brooke Vixamar:
Absolutely. We will dive deeper into that shortly. Before we do, Kristin, you said something when we were chatting earlier that you can secure the person and not the hospital, which I thought was a profound and true line. Where does identity’s responsibility end and the SOCs begin?
Kristin Hoppe:
Oh, that’s a really good question, and I don’t know that it’s, I think it’s kind of always a partnership. Your SOC is gonna be always responsible for seeing anomalous behavior, but sometimes that anomalous behavior doesn’t trigger in the SOC. It might not register that way.
You might see it from the network team. The network team might go, that’s really odd. We’ve we’ve never seen this before. And if you’ve worked across your lines of a silo of, okay, we’re identity, we’re only focused here, and you’ve talked to your network teams, and you’ve built relationships, they’re gonna go, that’s weird.
And they’re gonna come over, they’re gonna hit you up, and they’re gonna ping you and say, hey, I see this I see this activity. And you’re gonna then pull in the sock, and you’re gonna pull in your identity teams or whoever. You might see one day you might see that, you know, our account lockouts seem really high. Why is that happening?
This is really odd behavior. That doesn’t always register at the SOC. It should, but sometimes the way that comes in and the alert doesn’t fire correctly, or it’s just below the threshold because sometimes attackers are really smart and can keep it below standard thresholds, and you’re gonna see that. So it’s always a partnership.
Obviously, the SOC does a lot of the, you know, our significant monitoring. They’re always gonna be working on that and looking for the anomalous behavior and that threat activity.
But Gartner coined the phrase a couple of years ago of identity threat detection and response and ITDR programs. And if you, as an identity practitioner, do not have an identity threat program that you’re managing, that you’re running, you’re remiss. You’re you’re kind of behind the game. There are a couple of solutions out there. You can do this with alert and monitoring, but you should be running that as well because you’re going to see different information in the patterns than sometimes others will.
Brooke Vixamar:
Oh, well said. Let’s, pivot now to kind of, like, leaning into that defense standpoint.
Relatively simple attacks that can happen can, healthcare in particular, but in all industries, have a much larger blast radius.
We know that simple things to come in and then the explosion can be huge.
What are the things that can shrink it? And it’d be really interesting to hear from both of you on this. Kristin, you can kick us off, but thinking about what are the things that can potentially shrink that blast radius that Paul mentioned a few minutes ago?
Kristin Hoppe:
From an identity perspective, if you’ve got an identity that’s been picked up, really making sure your access controls are tight, you need to be positive that your specific identity, if they compromise a physician’s credentials, that that has no lateral movement, that you can’t elevate privilege on that. That’s, I mean, it really is a credential that they can go steal a paycheck and that’s it, and that has significant impact to the individual, but it’s impact to the individual versus the organization. So there are kind of two things there outside of that that’s locking down all of your privileged access, no standing privileged access if you can get there.
It’s a really mature state to be in. And then you’re gonna layer in a lot of other controls. You’re gonna have a robust SOC. You’re gonna have a vulnerability program.
You’re going to make sure that network segmentation is as robust as your organization can support.
There’s a lot of layers to protect and remediate that blast radius. I would be very remiss in not stating if you don’t have your whatever your active directory is, we you know, we’re still an active directory shop. Some are not, some are Entre, some are whatever, but if you don’t have an actual isolated backup that you could recover from, you really need to evaluate that. Resiliency is key. I think everybody understands that in the world we live in now, particularly with the advent of AI, It’s sometimes not a matter of when it’s or it’s not a matter of if, it’s a matter of when and what that actually looks like. And so being able to recover from an event is gonna be as as well is is very, very key in controlling the blast.
Brooke Vixamar:
Yeah. You you we talked about it earlier and you talked about zero trust also, like that zero trust. You’re assuming that there’s vulnerabilities. You’re assuming that it’s gonna go wrong.
So that’s the whole point. You’re setting up this whole system as you’re talking about as like something can, something will. There’s vulnerabilities. Assume it, and then set up your program accordingly.
Right?
Kristin Hoppe:
Yeah. 100%. I mean, if your pen testers aren’t finding things, get new pen testers.
Like you want, I mean, you kind of almost want like your friendlies to find something because you were like, hey, that’s one attack factor that’s now closed down. They’ve done a really good job. They highlighted something we didn’t know about.
And that’s key. I mean, particularly when you look around lateral movement on legacy systems and directories that have been stood up for fifteen years. I mean, if you’re looking at a directory that’s 20 15 years old, you don’t know all the things that are there. There’s no possible way. So you need that external validation that it’s secure and locked down.
Brooke Vixamar:
Totally. Okay, Paul, I don’t think there’s a better setup than that.
Like, as someone Kristin, that puts some
Paul Dant:
you make it sound so easy.
Kristin Hoppe:
It’s so not easy.
Paul Dant:
No, that was a perfect response. I mean, there are so many layers. And I mean, at the end of the day, understanding blast radius, you know, that alone is easier said than done.
So unified identity is really where all of that comes into play to make sure that we not only have a unified layer of identity data, but also that we understand from, we’ll call it a unified access chain perspective. Any given identity, a particular account, what can that account do in what systems and what can it do in those systems that from a privileged perspective?
As Kristin was saying, if we don’t have a true understanding of that, when the SOC does detect something in so many cases, it’s well after the initial compromise. It’s well after the hours, days, maybe even weeks of lateral movement throughout the network to find the most critical points, the pressure points for a hopeful ransom payment, whether it’s extorting the organization through stolen data or DDoSing legitimate systems that allow them to stop say patient intake. Those things are catastrophic, not just for the business itself, but for us as human beings. That’s the really terrifying part around a lot of these attacks. So understanding blast radius from that perspective is arguably the most critical part.
Brooke Vixamar:
Okay. I have, I think, what might be a slightly impossible question to answer then.
What would you fix first?
Is it data hygiene? Is it like, what is there for someone that’s listening to all of this and is like, I’m overwhelmed, where do you start?
Paul Dant:
Who’s starting with that one? I I’ll I’ll give that one to Crystal first.
Brooke Vixamar:
I’m looking for either of you….
Kristin Hoppe:
Thank you. That’s so gracious. Gracious.
No, I, I mean, every prong of security and organization has a responsibility. So you have to have as much as you have to have identity identity hygiene, hygiene, you you have have to to have have a data loss prevention program. In the world we live in now, vulnerability management is more important than ever it’s ever been. We know it’s always been important, but now it’s it’s the most critical thing that we’re talking about.
It’s kind of shifting the layer from identity a little bit away is now we’re talking about, you know, making sure your vulnerabilities are patched within the same day because AI is highly exploitive and we’re everybody’s rapidly adopting that technology.
So it’s not a singular place to start.
There’s a couple of layers that need to be well in hand and understood. And even if you don’t have the fixes in place, if you understand the baseline of where you’re starting, you’re doing well. Like you need to understand your program and don’t have, you know, ego about your program. Understand that, Hey, I’ve got areas that I’m blind to.
Bring in a partner and have an assessment done. Do an assessment yourself. Poke holes in what you’ve looked at and where your maturities are, and then complete something and reevaluate. We reevaluate probably every few months, every six months, we’re constantly absorbing what’s changing, what’s going on, and shifting our short term and long term strategy to accommodate that, particularly within the organization.
We got obliterated by, AgenTik AI this year.
So let’s
Brooke Vixamar:
Thank you for admitting to that, and you’re certainly not the only one.
Yeah.
Kind of everyone a little bit, yeah. I want to lean into that assume vulnerability aspect.
In health care, literally this life and death. Like this is not, oh, the system broke down. It’s okay, manufacturing, we’re gonna lose some money. Like we’re talking life and death situation.
So the stakes are much higher. So when we’re thinking zero trust, we’re thinking assume vulnerability. Kristin, what does that look like when a clinician calls you at two in the morning and their credential isn’t working, access isn’t working? How do you assume vulnerability when the stakes are so high?
How do you kind of balance the needs and the, yeah, risk?
Kristin Hoppe:
Yeah, I mean, so you, there is
Brooke Vixamar:
a little bit of that where
Kristin Hoppe:
you have some naturally absorbed risk in the organization.
So in healthcare, you may not be able to patch as readily as you want. It may not be quite as aggressive as it needs to because you know that the particular items you’re patching are connected to patient monitoring. Okay, so that’s higher risk than our, you know, a server cluster that’s running our telecom. Still very important, but not quite as high necessarily as patient monitoring. So you have to look at what you’re actually doing when it regards to specific identity.
Identity verification is going to be the name of the game going forward. You really have to know that if you’re servicing a call from an individual that you’re really talking to that person and that they’re in possession of the device they’re talking about, because that’s probably on the individual level, your biggest risk, and that’s going to be eradicating bad multifactor methods. You’re going to have to have an identity verification. At some point, you’re probably going to have to have a deep fake one.
Those are things that are being adopted at scale. Service desks are really, really hard hit when you talk about social engineering on healthcare scale. They’re constantly being attacked and you have to provide them as identity verification, as identity, you have to provide them the right tools that allow them to do that, particularly if you look at a lot of service desks that tends to be an outsourced or offshore facility, and that presents its own challenge. You need to bring a tool in that’s easy to understand, that’s got a high efficacy rate, that’s not abhorrent to the caller because nobody wants to interact with something that makes them uncomfortable. It’s really hard to balance, but it’s necessary.
Brooke Vixamar:
Well said. Along those lines, I think it’s come up a little bit organically in the conversation, but what can you see today that you couldn’t see two years ago? What’s new that you are facing today that you didn’t?
Kristin Hoppe:
I mean, I think everybody at the top that the only answer here is AI and a Genentech AI. I mean, if you were involved in that world, I think you as an engineer probably understood that it existed.
If you were a practitioner in security, you probably tangentially knew it existed. I don’t think any of us just boots on the ground day to day realized it was going do what it did and how quickly it was going to shift the landscape.
Between that and the way that COVID changed the way we do business. I don’t think any of that was predictable, at least from my lens, it was not predictable.
Yeah. And that’s yeah.
Brooke Vixamar:
Well, yeah. And and even as you’re I mean, and then all of the derivatives of that as you’re talking about the classic or deep fakes and, like, the voice recognition tools. What do you do with that when a deepfake can mimic Yeah. Words.
I mean, there’s just so many different versions of
Kristin Hoppe:
the same old attacks that are now bigger easier an attacker to use, so.
Amplified. It’s even as simple as terminating an individual when you go through off boarding processes. You know, service accounts would continue to run and those were easily reassigned.
What do you do with agents?
You hope individual agents are just terminated part of the identity, which they should be typically.
But what about sub agents? Depending on that, if they were using multi tenant AI, it’s really challenging. It’s a really challenging process. And then how do you turn that new, how do you turn over the department’s agent to the right individual, to the right department? How do you make sure that that continues to run uninterrupted?
Those are big questions that we’re really starting to tackle and make sure occur well as we move into kind of the new age, I think. So life cycle management of agents is really gonna be interesting. And I don’t think ascribing it to we we’re struggling and we’ve kind of been working through this, but describing it to the kind of standard life cycle that we do to a human identity, it doesn’t work.
So we’re working on what that framework looks like. We’ve had a lot of, I think over the last six to eight months, we’ve spent a lot of time with other practitioners understanding what that new world’s gonna look like.
Brooke Vixamar:
Absolutely. We’ve talked about that internally a lot. We call it the uncontrolled inheritance chain where.
Kristin Hoppe:
Absolutely.
Brooke Vixamar:
An owner with an agent to an agent to a service account to data and when that owner leaves, what happens to the agent What’d do with it? To the service account. So having visibility in a way of flagging that and remediating that in real time, that’s a a big priority of what RadiantLogic is focusing on right now also.
Kristin Hoppe:
Yeah. We we’ve talked to Seb about it multiple times.
Brooke Vixamar:
Yes.
Paul Dant:
Yes.
Brooke Vixamar:
One other kind of part of the Augentica AI piece, so I guess you kind of already talked about it, but I just love this line that you said earlier, so I’m gonna say it. If you don’t know it’s there, you don’t know it’s there. And I think that’s the challenge, right, of these agents that are just you have to get ahead of it and get the visibility and know what they’re accessing and where they’re accessing it. Because it’s just out there and agents talking to agents.
That is terrifying. Question is gonna be to you. How do you get ahead of that? But, Kristin, how do you get ahead of that?