• Episode 109 - Building a Secure Development AI Program in 2026
    Jan 1 2026

    It is time for the annual holiday fundraiser episode! This year I deviate a little from the usual process but more on that later. Over the past year I have talked from time to time on the work that the AI and Dev Center of Excellences (CoE) have been doing. From implementing an enterprise wide code repository to opening up different Large Language Models (LLM) to the utilization of Agents for coding and Model Context Protocol servers a lot has changed.

    What better to help explain the journey that getting some of the key players on the podcast. I am very glad to have Kyle Jero , Lead Data Scientist of GenAI for Corewell Health and Aaron Tellis Senior Data Engineer for Corewell Health on the podcast.

    Here are just a couple of the great and insightful topics that we covered:

    • How AI and Dev CoEs and the policies and standards are evolving
    • The need for the creation of an Development AI Subcommittee
    • The concept of a 'Digital Twin for Developers'
    • The challenges on evaluating and onboarding AI Dev tools quickly where possible
    • Potential downfalls for Dev Teams when it coming to training Junior Devs in the future
    • AI tools being used for 'harm' and how to help be more secure
    • What does 2026 hold for Dev AI Teams?

    Fundraising Update:

    We did the fundraising for this event a little different this year, rather than have one or two vendors sponsor the episode, I was able to use some of the leftover funds from Cloud Con. I am happy to report that we donated $750 dollars to seven different charities. They were Toys for Tots of West Michigan, North Kent Connect, Black Girls Code, St. Joseph's Indian School, the Electronic Frontier Foundation, Guiding Light Ministries and Raices Cyber. The total donated for 2025 was over $1,500. I wouldn't be able to do this community work without the support of my awesome security leadership team at Corewell Health and Matt Nelson and the rest of the Really Bad Security crew. Here's hoping that 2026 is another great year!

    Show More Show Less
    58 mins
  • Episode 108 - Rethinking 3rd Party Risk in 2026
    Dec 30 2025

    In this episode I had a chance to do live remote podcast from the best hacker conference in the world, GrrCon. My guest for this episode is Shelly Migliore. Shelly is a Cybersecurity Risk Solutions Architect for Safe Security.

    The topic for this episode is Rethinking 3rd Party Risk in 2026. Shelly and I talk about some of the unique challenges that companies are facing as more and more industries are using 3rd party tool that utilize AI.

    YouTube Video Link:

    https://youtu.be/yxLIrlIUT68

    Show More Show Less
    25 mins
  • Episode 107 - Rethinking Threat Intelligence in 2025
    Jan 15 2025

    In this first episode of 2025, I picked a topic that is one of the few areas of security that is both 'hype' and 'real'. Threat Intelligence. It is an area that you can get great information for free but also overpay for what you get.

    I wanted to take a different approach to discussing this one, so I contacted a well-respected colleague of mine, Justin Lentz. Who happens to work in the SMB Threat Intel space to come on the podcast and share his experiences and thoughts.

    Talking Points:

    • How do you approach a smaller client when it comes to TI?
    • What is different when it comes to a client that has some experience with TI?
    • What are some pitfalls when you look at the different TI providers out there?
    • What happens when you run into data that is not relevant to your company's process?
      • Asking clients what is the problem that you are trying to solve?
    • What do you do when you have a low or limited budget?
    • What is his experiences running into this type of project (open source tools, using Azure, etc.)
    • What does it look like a year later?
      • SaaS platform
      • Partnering with different groups, agencies, etc.
      • The 'addiction' on wanting to get more data
      • Creating a Circle of Trust to share valuable information

    Episode Charity:

    Corewell Health's Blue Envelope Student Suicide Prevention Program

    Episode Sponsor:

    Solis Security is a cyber security managed service provider specializing in Threat Intelligence and Incident Response.

    Show More Show Less
    38 mins
  • Episode 106 - CISO Insights - Lessons Learned in My Healthcare Security Journey
    Dec 18 2024

    In this special episode, I finally get a chance to do a virtual fireside chat with my talented and funny CISO Scott Dresen. I actually started working with Scott while he was the Chief Technology Officer for Spectrum Health. It was in this role that Scott down the path to becoming the Chief Information Security Officer for Corewell Health. So you can say he has been here for the entire Information Security program revamp that started back in 2016.

    Talking Points:

    • Back in 2016 you were the CTO when the Information Security program was 'rebooted'. What were some of your biggest challenges and frustrations back then?
    • In 2018 you assumed the dual role of CTO and CISO, what was the hardest thing you had to change/overcome with having that dual role?
    • Let's talk to WannaCry incident, what did the high level leadership view look like and what decisions needed to happen?
    • In 2019 you had to re-evaluate the state of the security program at the halfway part of the timeline. During that you had to make some hard choice about the direction we needed to go in order to compete things. How did you come up with those decisions?
    • You have had the distinct 'pleasure' of being a part of both a small healthcare and large scale acquisitions, what are some valuable lessons learned from each?
    • In 2020 you had to pivot from an almost entirely in-person workforce to almost 100% remote, how did you manage to accomplish this in a timely and successful manner?
    • In 2023 you had a chance to speak in front of congress around healthcare security, walk me through how that came about, how you felt in the moment and what things would you do differently (in hindsight)
    • What has been the hardest part of planning and implementing Artificial Intelligence security?
    • Heading into 2025, what advice do you have for other healthcare security leaders as they face the challenges of tighter budgets, smarter threat actors and changing business strategies?

    Episode Charities:

    • Toys for Tots of Grand Rapids - Presents for less fortunate children
    • North Kent Connect - A great foundation that helps families with items that may not be covered by other programs
    • YMCA of Greater Grand Rapids - Great organization promoting healthy lifestyles

    Episode Sponsor:

    Cloud Con - Michigan's premier security and infrastructure conference!

    Show More Show Less
    51 mins
  • Episode 105 - Monsters Under Your Bed: Mapping The Dark Web with Python
    Nov 6 2024

    *Disclaimer* While this episode deals with an incredibly important topic, there are potential dangers in doing this type of work. PLEASE do your homework and be well prepared should you go down this path, as your life can be impacted with a wrong turn.

    In this episode, which is the first of a listener requested one around technical topics.

    With cybercrime and threat actor activity on the rise, it is more important than ever to understand the dark web and monitor it for potential risks or signs of a breach. There are several tools and intel providers that can do this, but they’re not cheap. So why don’t we just do it ourselves?

    Python can handle simple tasks surrounding dark web scanning and offers more customization for complex tasks. Using strictly free open-source libraries and any system you have available, you can set up an automated scanner and detect threats as they arise.

    Scan for IP addresses, potentially compromised emails, crypto addresses, and any regex patterns that you desire. Map your findings to the most relevant onion sites and get an understanding of where your adversaries tend to operate. This is just a start. From here, you can go almost anywhere.

    Episode Charity:

    Proceeds from this episode's sponsorship will be going towards the Baker-Bonsai Friendship Fund. Bruce Baker was a great bonsai tree artist and along with Deal Bull, helped make the art of bonsai be something wonderful that can be shared for future generations at the Frederik Meijer Gardens.

    Episode Sponsor:

    Cloud Security Alliance of West Michigan

    Talking Points:

    • Why is it important that you at least have a basic understanding of the Dark Web is you are in the Small and Medium sized Business (SMB) space.
    • Pros and Cons of Build vs Buy
    • What safeguards do you want when out in the fringes?
    • What are the mental health aspects of doing this type of work? How manage those pressures?
    • What are Seed URLs?
    • How to use Dark Web templates for scanning.

    Description credit to GrrCon

    Show More Show Less
    51 mins
  • Debunking The Zero Trust is Expensive and Painful Myth
    Oct 16 2024

    In this episode I talk with Tamer Baker around the not always clear topic of Zero Trust. While the term has been around while, it definitely gets overused by security vendors. However, because of Tamer's role as the Chief Technology Officer in the Healthcare space, he is also to bring several different points of view to the conversation.

    Several of these are key to solving questions such as:

    • Is Zero Trust truly expensive and painful? (Radiologist user experience example)
    • As more and more healthcare systems are having to worry about budgets, he challenges the concepts on doing the same with 'less'.
    • A lot of security vendors are talking AI in their products, what things is your company doing that is actually using AI?

    These are just a few of the tough questions that we tackle. So, set aside some time in your day to listen in to a great conversation!

    Episode Charity

    Since 2011, Black Girls Code has supported girls of color in tech through coding education and more. We partner with schools and organizations to offer a range of programs, both in-person and virtual, for ages 7-25.

    Episode Sponsor

    Zscaler is a Cloud Security company based out of San Jose California.

    Show More Show Less
    52 mins
  • Episode 103 - Let's have a RealTalk about Your Identity Journey
    Sep 4 2024

    In this episode I talk with Matt Berzinski about the important of understanding that identity is a journey not a destination. Matt is the Senior Director of Product Management for Ping Identity and has extensive knowledge about identity.

    Talking Points:

    • Realtime Fraud/Risk
    • Orchestration
    • Organizations (The importance of offload work that you don't need to do it)
    • Single Sign On
    • Multi Factor
    • Identity Verification (Francis talked about a local automotive company referencing mobile apps for a car)
    • Robot or Vehicle Identity is a relationship not a dependency (Matt has a great Rosie the Robot from The Jetsons reference)
    • Why is Obfuscation still important?

    Episode Charity:

    Proceeds from this episode's sponsorship will be going towards the Baker-Bonsai Friendship Fund. Bruce Baker was a great bonsai tree artist and along with Deal Bull, helped make the art of bonsai be something wonderful that can be shared for future generations at the Frederik Meijer Gardens.

    Episode Sponsor:

    This episode is sponsored by Ping Identity. Ping is an identity solutions provider based out of the great state of Colorado in the awesome town that is Denver.

    Show More Show Less
    49 mins
  • Tales from the Trenches: The Crowdstrike Incident and Other Crazy Stories from Summer 2024
    Aug 29 2024

    In this special end of summer episode, I sat down with Tyler Adams to talk about being in the trenches during the recent Crowdstrike incident and other interesting stories from the crazy summer. Tyler is an Information Security Analyst for Corewell Health. He works on the Security Business Engagement Team.

    Talking Points:

    • What was it like being in the trenches during the Crowdstrike incident
      • How having a Business Continuity Plan comes in play
      • What was the most surprising about the incident?
    • What challenges are stemming from what the business is working on?
      • Getting the business to understand the value of Multi-Factor Authentication
      • Data 'Cleanliness' is becoming more important
    Show More Show Less
    32 mins