Qualys Risk Operations Conference: Christy Sluder on AI, Compliance, and the Future of Vulnerability Management | ROCon 2025
The Qualys Risk Operations Conference focuses on the critical need for security training and upskilling in the industry. Christy Sluder from HCA shares her insights on vulnerability management in healthcare, addressing compliance challenges with HIPAA and GDPR. The discussion highlights the evolving landscape of vulnerability management, the careful use of AI in security, and the importance of a risk management approach. Networking is also emphasized as vital for professional growth.
Transcript
We're back here live. I hope so. Um, at the Qualys Rock On Risk Operations Conference and continuing our coverage from, well, it's day one of the conference, but there's actually been two days of security training prior to this.
And I, I heard from my friends at Qualys security training was standing room only sold out. You, you know, there's 400 people here, I think something like half or more signed up and took the security training as well. So kudos to all of those people who are upskilling themselves and keeping current with the greatest stuff.
Speaking of upskilling and keeping current with the greatest stuff, let me introduce you to Christie Schluter. Mm-hmm. Did I get it right?
Yes, She did. Christie is with HCA, but we're gonna let her tell her story beyond that. Kristi, welcome to Textron tv.
Thanks for coming on. Thanks for having me. Our pleasure.
Um, introduce yourself. My name is Kristi Schluter, and I have been in healthcare it for over 25 years. Uh, I started out as a hospital technician that did break fix for the nurses and the doctors, and now I am managing a vulnerability, uh, management team for HCA Tough job.
Yes. A very tough job. It's been a lot of fun.
Yeah, it is. I, uh, yeah, I told this story before I, I had started a security company outta Boulder, Colorado in 2001 co-founding in 2003. We came out with a vulnerability management solution.
It was so eye-opening for me going to all these customers. You know, we never said it publicly, but in the office we used to call it the bad news generator because all it did was generate bad news and people would get, you know, they were never thrilled. But, but back then, it was a different world.
We would scan once a year and we'd give you like a phone book. And I, you know, I said phone book the other day, Christie and I realized that half my audience probably has no idea what I'm talking about. But anyway, phone books were these big fat books that used to get delivered to your house every year, the Yellow Pages and so forth.
And they were this thick. That's about how thick Oh, yeah. I Yearly vulnerability don't remember From, Yeah.
You remember. So, but of course, it's changed a little since then. Back then we, you couldn't even talk about automated remediation.
Right, Right, Right. Everything. I, you know, I, I remember going to one of the top, like a top Fortune five, fortune 10 company, a big bank.
Mm-hmm. You know, Microsoft Patch Tuesdays. Oh, Yeah.
Right. It would take them 90 to 120 days to roll out a patch from Patch Tuesday because they said they'd rather live with the vulnerability than potentially break something else. I never got it then.
I don't get it now, but I think the world's changed a little bit. But, um, you know, we, I forgot. HCAI think most of our audience is familiar with HCA, but they're probably one of the biggest medical services, health services Yes.
Provider in the country now, aren't they? Yes. We're one of the largest healthcare companies, uh, in, in the world.
Uh, we have 190 hospitals and over 2,500 points of care facilities. So there, that's a lot. Plus we have Gayland College, Including WebMD down my way in South Florida.
Right. They always make a big thing. WebMD an HCA affiliated.
Um, but all getting aside, you know, being a healthcare company provider has its own set of challenges from a security point of view, because HIPAA becomes, you know, a real big consideration. PII, you know, the data. You've also got GDPR because we're in Europe, so we have to find my, those regulations too.
So you are what we call a highly regulated industry. We are. Right.
S you for justice, but, um, you know, talk, you've been in this a while now. Yes. Talk to us about the evolution of how you approach vulnerability management.
Vulnerability remediation. I assume you use the Qualis solution. Yes, we do use Qualis talk.
Talk to us about how it's kind of changed over the years. Well, Over the years, uh, you know, things have changed. The landscape has changed, and, you know, not only do we have to be careful with patching devices, but we've got medical devices that are connected to patients.
So it's very important that, you know, we test and we make sure that everything is validated before we roll it out to everything. So the zero days, I mean, there's a lot of work behind the scenes in order to get those vulnerabilities remediated, because you have to test because patient safety is number one. Yeah.
So give us an idea. You know, so when I was doing this a hundred years ago, right? We didn't have thread intel and we didn't have some of the research labs, like the Qualys security research team and stuff like that.
How do you, is it just purely testing a patch on a machine, or do you kind of take the holistic view of looking at the whole, Well, you need to look at the holistic view. 'cause you need to see where, where the threat attacks could happen. Seeing all of those doors and being able to work with different cybersecurity teams to, to help you prioritize.
It's not just how bad is the vulnerability, but if somebody were to utilize that, what are the steps in? So making sure that you look at all of those points, bring those in, and then also work with your executive management. Absolutely.
Um, what about remediation? Are you using the automated remediation yet, or no? Uh, Not really.
Uh, we have a a a whole team that is just dedicated to remediation. Yeah. I, I, I think being in a highly regulated industry, it's, it's a bit of a, it's maybe a hill too far or a hill too high, I guess is the word for you guys at, at this point, Christy, I wanna ask you about ai.
Okay. Right. All of a sudden, this past year, now everybody's using ai.
Yeah. Everybody A BU's word. Yeah, it is.
How, how is that affecting your team? Uh, it's, it's got good points. It's also got some scary points.
Uh, but our company is taking the approach of we're being very cautious and making sure that we do this right. Mm-hmm. So it's more of measure twice, cut once.
So that's the approach that we're taking with ai. Excellent. So is this your first Qualys conference?
It is not. You've been, yeah, I've been several times. But it was all before COVID.
That was when it was, uh, Qualys Security Conference. QSC. Yes.
Yes. So now of course, it's Qualys, racon, it's got risk operation. Right.
How has the emphasis on managing risk versus just blindly patching everything or, you know, scanning and making your list and checking it twice? How has that changed how you guys approach vulnerability management? Oh, yeah.
Yeah. How it, it's a industry standard. I think the whole industry is going towards that, what we call exposure management slash ctm, uh, continuous threat exposure management.
Yep. All of the industry is going that way. And I think, you know, just Qualys is getting in line with that industry standard, and I think that is the way we're all going.
You know, I, I was, I was talking to the Koala, CEO summed mm-hmm. Earlier today, and he said it, you know, you can't just keep scanning and finding more vulnerabilities and fixing more vulnerabilities without recognizing what's the financial impact. Right, Right, right.
And does it make dollars and cents Right Now, in the case of HCA, again, highly regulated. You do have other things to worry about. Exactly.
Right. And sometimes it does cost a little more money Yes. To protect people's PII and so forth.
Right. But is that financial kind of analysis being done here at HCA, you think In terms Yeah. Oh, yeah.
Yeah. It's definitely being done. Today's World.
Yeah. Yeah. No, no one has that kind of, you know, you can't just Yeah.
You try to fix it. You, you definitely have to put that in there. Yep.
Um, so one of the questions I've been asking people is, I think people in your position, CISOs, executives, managers, they understand that in order to, to get budget to convey success or failure to talk to business leaders, you need to talk the language of risk management. Correct. But many people on your team that you manage, there's security people, right.
They talk, this is a major CVE, it's a minor CVE. This is, you know, they talk bits and bytes. Yes.
Not risk. How are you, are you telling them, Hey, you gotta learn a new language? I, I'm not really telling them that, but they're also seeing things change.
So they are getting educated, so they are reaching out. Several of my team members get educated. They're taking classes.
They're constantly staying on that, uh, education and just making sure that they're keeping with the landscape. So, uh, yeah. So they're, they're training themselves to actually be able to talk the language.
You know, we talked about ai, it's not just us who are using ai. The bad guys are using AI too. Yes.
This year we've probably seen more vulnerabilities, more attack. We see more attacks every year, but we're seeing more attacks, but we've seen more attacks that are AI assisted, let's call it. Right.
How's that affecting you and the team? Uh, it's definitely causing us to be more aware and being able to kind of look at our thread and tell, and also work with our other cyber teams at HCA and making sure that we're all on the same page and we're seeing the same things because, uh, you know, the different teams have different access to tools and all coming together. Collaboration is key in any security program.
It Is. It is. It is.
Um, what about in terms of, so vulnerability, one of the things, let me back up. One of the problems we, we've always had in security for as long as I've been in it, is we have silos. These people with the vulnerability management team, that team is the, you know, identity and access management, and then this team's endpoint security, and, you know, there's all these different silos.
How has, like looking at it from, let's call it a holistic r risk management right point of view, allowed you to maybe work those more closely or maybe not. Yeah. It's time to tear the silos down.
And that's what we are working on. We're tearing those silos down and working together. So it's not just, you know, cybersecurity working together, but you also have to work with it.
They're the ones that knows those devices the most. Yep. So being sure that you're staying, you know, walk step with each other as you are going through these processes is very, you know, the very important part of it.
Great. One last question for you. Sure.
So plans are to do more of these Qualys racon events mm-hmm. In the US all over the world, right. Along with the training mm-hmm.
Which is free if you come to the conference, the training, the day or two before is free because you, for your peers in security and security people out there, what's your advice? Like, is this a must attend show or Oh, yeah. Yeah.
I think it is a must attend because if, if you're using these type of tools, it's important to know how they function and coming to these things and getting more skilled at using the tool so that you can go back and make sure that you are doing everything correctly. And, and just the most important thing is the networking. Understanding how other companies are using things That peer-to-peer stuff.
Yes. That is, and that, and that, that's insightful because it's not something you hear, you know, they talk about a session and they mm-hmm. But it is the networking, the water cooler session, so to speak.
Yes. Yes. So they don't really have water coolers anymore.
Uh, but the water cooler sessions are, are where it's at. Yes. Yes.
That networking is just a valuable piece. Fantastic. Hey, I wanna thank you for coming on.
I know it's not, you know, you got to do your thing and you're here busy. I appreciate it. Mm-hmm.
And keep up the great work at HCA. My PII is in there, so keep an eye on it. Okay.
Will do. All right. We're live here at Qualys Ard.
We'll be back with more coverage of, of our first day of coverage here. Stay tuned. You're watching text from tv.