Pressure Zone a podcast by Hack The Box
Pressure Zone is a game-driven cybersecurity podcast where CISOs and executives are placed inside escalating, realistic risk scenarios that mirror the complexity of today's cyber leadership. Each rung requires the guest to make a decision under pressure, explain the rationale, and translate the impact into business terms, just as they would with a board, CEO, or executive team. The episode unfolds as a structured game, creating an engaging format that reveals authentic leadership judgment, tradeoffs, and security insight without feeling like a traditional interview or sales pitch.
Each episode is built around escalating rounds: connected, sequential scenarios that move from early warning signs to high-stakes incidents, where every decision shapes the context and pressure of what comes next. Guests must assess the risk, make a clear call, and defend it in business terms. If they dodge a question or avoid a decision, they trigger a Confession Card penalty, prompting an honest, insight-revealing response such as a hard lesson learned or an unpopular opinion. This keeps the tension high while preserving the realism, pace, and authenticity of the game.
Pressure Zone a podcast by Hack The Box
The Phantom Fleet
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
What happens when a cyber incident reaches into the systems that keep patients safe?
In Episode 8 of the Pressure Zone podcast, Krista Arndt faces a series of decisions as a shadow vendor integration, connected medical devices, and unexpected security signals collide inside a healthcare environment. With incomplete visibility, operational pressure, and patient safety on the line, every choice carries consequences.
The episode explores why security leaders need to prepare for the unknown, build visibility across complex environments, and rely on cross-functional teams when the situation moves beyond the boundaries of cybersecurity. Because you can never know everything that is happening across a modern environment — but you can build the readiness to make difficult decisions when something inevitably falls through the cracks.
So you're saying we should start sending out free margarita kits to all these seasons?
SPEAKER_00Congratulations, ma'am. You didn't kill anybody and you survived and you didn't get fired. There's your margarita.
SPEAKER_01Welcome to the Pressure Zone podcast, uh, where we peel back the polished executive dashboards to expose the messy, connected reality of critical infrastructure. I'm Christine Bartlett, and today I'm hosted by Krista Arndt, Associate CISO at St. Luke's University Health Network. Krista, thanks for joining us. Hey, thanks for having me. Krista, you're a leader who openly champions an authentic, grounded approach to cyber risk. You've noted that healthcare connectivity has adopted technology at a velocity that outpaces standard corporate readiness, creating an incredibly intricate web of IT, cloud, and biomedical assets. You've built mature programs by bringing clinical leadership into the technical fold, focusing on real-world resilience rather than abstract compliance data. But today we are stepping into the Phantom Fleet, a scenario where the spreadsheets say everything is perfectly inventoried, but the actual ward floor says otherwise. A shadow vendor integration has left a backdoor wide open. The connected patient devices are throwing intermittent faults, and your internal technical teams are speaking a completely different language than your bedside clinical staff. Let's see how you steer the ship when the data says you're safe, but your operations are actively stumbling. All right, let's get into the actual storyline here. Your regional health network utilizes a centralized cloud-hosted telemetry dashboard to monitor real-time vital signs across multiple regional campuses. Your enterprise asset management tools and attack surface dashboards report 100% visibility and clean security postures. However, a third-party clinical vendor trying to speed up a software deployment for a regional clinic quietly spun up an unvetted shadow cloud testing gateway to sync data with a subset of wireless smart infusion pumps. A threat actor discovers this unmapped testing API gateway and begins flooding it with malinformed synchronization requests and credential stuffing attempts. The attack doesn't brick the devices. Instead, it backs up the telemetry processing queue, causing a baseline processing delay that forces pumps to intermittently drop their Wi-Fi RF check-ins. This triggers false communication failure alarms on the floor. Your central security dashboard show nothing because the traffic originates from a whitelisted vendor tenant using encrypted SAS endpoints, masking the abuse as legitimate business data while nursing staff grow fatigued by phantom alerts. Krista, are you ready to step into the zone?
SPEAKER_00Oh my god, can I phone a friend or like my entire team?
SPEAKER_01You got this, you got this. All right, round one. Um, the alert fatigue gap. It's 8 a.m. on a Tuesday. The nursing director of your largest regional campus contacts the IT help desk directly, bypassing the security portal. She reports that over the past 12 hours, dozens of wireless smart infusion pumps across the medical surgical floors have been erratically chirping with network connection alerts. Your SOC lead checks the centralized enterprise network monitoring system and reports zero active anomalies. The main segmentation controls are holding, and traffic volume looks completely standard. The nursing director warns that her staff is beginning to ignore the chirping devices due to alert fatigue, meaning a genuine clinical equipment failure could be missed. What is your initial directive? Don't worry, you get multiple choices. You get four options here. Okay, here we go. A the clinical safety lock. Order the local clinical engineering biomed teams to physically round on the floors and manually take the erratic pumps off the network entirely, forcing them to into localized offline manual operation while security hunts the technical root cause. B the vendor tenant audit, keep the devices active to preserve live clinical metrics, but launch an emergency out-of-band audit of all active third-party API tokens and B2B vendor federations in your cloud identity management system to find the source of the anomaly. C the periphery network capture, direct your network infrastructure team to immediately deploy an inline packet capture tool on the specific wireless VLAN handling the regional pumps to analyze the raw, low-level packet handshakes for signs of malformed commands. D, the joint triage huddle, refuse to pull hardware offline or start a blind technical hunt, convene an immediate 15-minute emergency command call between your app sec leads and biomedical engineering director and the clinical nursing lead to assign clear localized visibility roles before making a system-wide change.
SPEAKER_00Yeah, definitely. So I'll tell you that it would before you said the last option, it would have been the first, just because I've been through this. Um and I'll tell you why I would even consider the first. So the problem with the first option, even though you really want to do it, is it could affect patient care. So you would really want to still coordinate with Biomed and convene on, okay, like what are its capabilities still operating in offline mode? Because that's what you really do, right? Biomed is very commonly attacked because of how difficult it is to put our security stuff on. And so you always want to take caution. It's always segmented off on its own. And but the problem with blindly taking things offline is you have to very con be very conscious in healthcare with how you affect clinical operations. And although your biomed team is probably wonderful like ours and really knows the ins and outs of what is effective from a business perspective or an operational perspective, there could be something that you're missing, and especially infusion is a big concern because that that's a critical function of healthcare. So I would um and I understand that time to time to tackle and time to remediate is of the essence, but I would really like to huddle with the experts and not just assume everything is a security incident because we had something like this in the recent past, and it ended up just being a glitch with the um software that that talks to um the devices. And so it wasn't infusion, but the whole idea is, you know, it could just be something, and there were multiple things in simultaneous rooms next to each other where we are having issues. And so um I never want to assume, but I do always um appreciate our clinical workers taking caution and saying, hey, we're worried this is a security incident, which is what they said. And that's you know, we looked at it and it was escalated more quickly because God, it's just like it's the one time it's not or it is that they'll just be like, oh, we just have to try turning it off and back on again. Like good, and try to take troubleshooting into their own hands. So I think a following organized troubleshooting processes, which your hospital system should have these documented because this it does happen, right? Like you'll have multiple um biomed devices having issues is of the essence because doing it that way and coordinating the team quickly um can also help you understand the triage steps that have been taken to rule out anything that you may have missed.
SPEAKER_01Okay. No, that's good. Um, so you're going with D, the joint triage huddle for now, um, calling a huddle to ensure alignment, very collaborative and very grounded, while you're also getting the clinical lead, the biomed team, and the engineers into a shared bridge line. Another 15 minutes, of course, slips by without a definitive containment command and a complex health network structured consistency ensures buy-in, but also burns precious time when a vendor connection is actively misbehaving, potentially. All right, so round two. You know, it's gonna continue to potentially spiral here. The um the unmapped gateway discovery. It's now 11:30 a.m. on Tuesday. Your technical response path has yielded results. Your app sec team has pinpointed the source of the malformed traffic. It isn't coming from your core cloud environment, but from an inventoried uh public-facing testing API gateway hosted on an external AWS instance. The instance was spun up six months ago by a specialized clinical middleware vendor during a fast-tracked pilot program at your regional campus, then left active and forgotten. A script kitty found the unhardened endpoint via automated internet scanning and is running a brute force credential stuffing campaign against it, accidentally causing the back-end telemetry queue to lag. The vendor admits the mistake, but states their tier three cloud engineering team is based in a different time zone and cannot tear down the instance for another four hours. Your internal network team can block the attacker's IP range at your edge firewall, but doing so will temporarily sever the legitimate API sync pipeline for the regional campus's pharmacy tracking system as it shares the same cloud tenant gateway. How do you prioritize? We've got it doesn't get better, it always gets worse. A the absolute edge block. Uh issue an immediate command to block the vendors testing IP space at your core firewall, protect the integrity of the network now, accepting that pharmacy tracking for the regional campus will shift to manual paper verification for the afternoon. B the cloud credential freeze, refuse to disrupt the pharmacy pipeline, work with your identity and access management team to target the vendor's service access tokens within your environment, revoking their internal active directory rights to neutralize the traffic without dropping the connection. C the monitored coexistence, leave the firewall and accounts open to preserve seamless clinical operations, direct your SOC to establish a dedicated isolated monitoring channel to watch the brute force attempts in real time, waiting for the vendor team to come online to patch it cleanly, which would be roughly four hours. D, the localized network containment, order the regional campuses' internal IT leads to shift the local wireless access points, handling the pumps onto an isolated IoT VLAN sandbox, removing them from the shared enterprise backbone while preserving routing to the pharmacy data pipeline.
SPEAKER_00I will tell you, because I have confidence in our BCDR, that I would honestly sever the connection. And the problem with leaving that stuff online, like, yes, you could isolate it, but you're still putting the patients at risk and you're putting the devices at risk. So you're not solving the whole problem. You're just solving the problem of not putting the rest of your network at risk. And so you would typically think with something like that, with where we are, we would have that micro-segmented anyway. And so, like, segmenting it more really isn't going to do anything for us. So I'd absolutely at that point take it offline because you're talking about potential vulnerabilities there that could exist and are not patched, and you're just waiting for one attempt in that brute force attack to be successful, and then you're compromising the device. Any information that lies on the device, the patient who could be potentially connected to that infusion device. Like, just it's not a good look. So I'm gonna go with A. Take it offline.
SPEAKER_01Okay, all right.
SPEAKER_00We're lying on processes.
SPEAKER_01Hey, it's an option, right? So I think the the key too is you gotta make a decision and see what happens next, and then keep moving forward with your team. All right, so we'll move to round three: the internal escalation and narrative control. So now it's 2 p.m. on Tuesday. The telemetry lag is under engineering containment, but news of the glitching infusion pumps has leaked internally across the regional hospital campus. A local healthcare reporter has just emailed your public relations team stating they have a tip from an anonymous floor nurse claiming that critical patient monitoring systems are experiencing a cyber attack. No data breach has occurred, patient care hasn't been compromised, and the risk is entirely operational. However, the regional hospital president is now in a panic about community trust and hospital ratings. He calls your secure line and says, Krista, I need you to sign off on an internal statement to staff stating that this is simply a routine, scheduled cloud maintenance update that caused an unexpected system glitch. We cannot afford an unvetted security narrative leaking to the press right now. You are being asked to compromise on technical transparency to preserve immediate operational trust. How do you handle it? A. The strict transparency veto flatly refuse to sign off on the statement, insists that mislabeling a security exposure as scheduled maintenance destroys credibility with your internal engineering and clinical staff, and offer a candid risk-calibrated statement instead. B. The technical compromise narrative, agree to use the word glitch in the general staff memo, but require that a separate technically accurate advisory be sent privately to the biomedical and clinical leadership team so that they understand the actual third-party asset vulnerability. C. The strategic deferral, refuse to draft or sign the memo yourself, defer the corporate communication strategy entirely to the chief legal officer and corporate and corporate PR person, stating that your mandate is strictly limited to technical containment and risk validation, not narrative spin. D, the clinical town hall uh pivot, reject the corporate statement entirely, request an immediate closed door huddle with the hospital's chief medical officer, nursing director, and nursing directors to explain the risk directly, letting clinical leadership handle the internal floor narrative while you manage the technical reality.
SPEAKER_00So I'm gonna cross lines there because if you're handling this correctly and you are at a point where you have to incite your BC, your business continuity plans for something like that, your IT leadership has already had that communication because of our instant response program with your um immediate clinical and senior leadership. And so we have a great liaison system there. Um but I'll tell you what I would pick is absolutely C when it comes to me signing off on something like that. This is really important to control the narrative, not reputation is the utmost importance to make sure patients get care and they understand what is really going on because this can get blown out of proportion. And so while C legal would be handling the narrative more widely, we are also working with legal, and big I I've been this physician to deal with the initial um clinical worker narrative too, because that's what happens. You have people working in other hospital systems. Oh my god, I heard this vendor guide breach. Like, has it affected your operations, right? And we have to be prepared to respond to that. And while we should already have basic communication plans in place and communication escalations, um the CISO should never be signing off on a narrative of anything without legal PR communications review and guidance, because truthfully, the way that you phrase something can can lead to class action lawsuits, misrepresentation, things that are gonna hurt the organization far worse than just preserving basic reputation in the heat of the moment.
SPEAKER_01Okay, so you're going with option C, right? So you're bringing in legal.
SPEAKER_00Yeah, absolutely. They would have known already. If it got to that point where we know that there was some sort of compromise, like, hello, legal, I have your number like our communications department is amazing and responsive, and we have such close collaboration. Like, dude, they would have been involved a long time ago.
SPEAKER_01Okay, so by by potentially completely outsourcing the narrative to legal and PR, you could allow them to publish a misleading statement that your own engineering team knows is false, causing additional internal morale to tank while you silently sit behind your firewall logs. Um, all right, round four. The unvetted remediation. It is now 4:30 p.m. on Tuesday. The specialized clinical middleware vendors tier three engineering team finally comes online. They realize they cannot easily tear down the legacy testing AWS instance without breaking an outdated hard-coded database link used by three other regional hospitals outside your network. Instead, their lead architect sends your team a proprietary unvetted hot patch script. He claims that if your team executes the script via your centralized cloud configuration manager, it will immediately force an encrypted tunnel on your end, filtering out the brute force noise and stabilizing the telemetry lag within 10 minutes. However, your AppSec team has not reviewed the code. It lacks an official software bill of materials, and your stagging environment and your staging environment is down for scheduled database re-indexing, meaning you have to deploy it directly to production. How do you direct your team? A. The strict governance veto, reject the vendor script, state that executing unvetted third-party code directly into a live healthcare production environment violates your foundational security gates, and choose to maintain the telemetry lag until a formal code review is completed. B. The isolated canary deployment. Authorize a highly restricted rollout. Command your engineering team to push the script to a single isolated server block, handling just one non-critical clinic ward, observing the live performance for 30 minutes before deciding on a wider network release. C the compensating technical control. Reject the vendor's code entirely. Instead of running their script, instruct your internal infrastructure team to build a temporary reverse proxy rule at your own cloud perimeter to drop the malformed traffic, taking full ownership of the mitigation, and D the clinical risk acceptance, bring the script to the chief medical officer, explain that the patch is unverified, but will instantly stop the alert fatigue and deploy it immediately if clinical leadership agrees that the operational relief outweighs the technical software risk.
SPEAKER_00So that's tough. So there, I I would do E, let me consult my architect because he's the brain, because the two options is rolling it out in some sort of isolated, non-critical environment. It could be a potential, but my concern there from a GRC perspective is we know nothing about that vendor. So how do we even know that's secure and that it doesn't contain malicious code in itself and hasn't been compromised? So truthfully, because I know the environment and I'm not about to take that risk when I also didn't want to take the risk to um not isolate the infusion pumps. I would prefer to handle it internally. And and every organization is going to depend on how mighty is your team and how much do they know? But for us, I would definitely take the last option. I I would absolutely not take that risk of unvetted code.
SPEAKER_01Okay, so sorry I missed that. You said option.
SPEAKER_00So it would be the last one where we we do it ourselves. Yeah, reverse proxy, yeah.
SPEAKER_01Okay, got it, got it, got it. You'd work with the chief medical officer to work that.
SPEAKER_00No, so what's the one with the reverse proxy? We would just fix it ourselves.
SPEAKER_01Uh, you're okay. The technical the technical control, rejecting the vendor's code entirely instead of running their script. Okay, got it. Instructions.
SPEAKER_00If we knew the vendor and like that's a whole problem, right? The vendor wasn't vetted. If we knew anything about the vendor and we had confidence from a risk perspective, then I would consider running their code. But also, hey, we were a Glen for punishment and that happened already. Let's just put the nail in the coffin and really own team, right?
SPEAKER_01You just have to to live with that. Yeah, no, that makes sense. Um, okay, round five. We're at the the at the end here. The secret the synchronization uh climax. It is now 6 p.m. on Tuesday. The clock is running out on your evening shift, and the telemetry lag hits a critical inflection point. The brute force automated scanning traffic hitting uh That unmapped shadow gateway has unexpectedly spiked by 400%, flooding the cloud-hosted processing queue. The system hasn't crashed, but your central dashboard now shows a rolling 45-second latency delay in vital sign trans transmissions across your flagship trauma center. Your app sec lead presents an emergency configuration script that can force a hard disconnect of the vendor's entire multi-tentant tenant cloud container block from your active active directory sink. It is 80 is an 80% chance of clearing the processing queue instantly and restoring the real-time vitals monitoring.
SPEAKER_0060% of the time it works every time.
SPEAKER_01I know you only get 80%. The other 20% chance is invalidating the session keys between your central telemetry service server and every wireless infusion pump on the floor, requiring a physical device-by-device manual, manual repair or factory reset by biomedical engineers over the next 48 hours. What is your command? A do it live, execute the hard disconnect configuration script immediately. We accept the 20% risk of cryptographic device corruption to eliminate the 45-second latency delay before the night shift begins. B the analog ward watch, reject the script gamble, maintain the current network state, and order an immediate physical ward watch, deploying the nursing students, float staff, and clinical engineers to stand physically at patients' bedsides to monitor vitals manually until the traffic subsides naturally. C the aggressive perimeter throttle. Instruct your network infrastructure team to implement an aggressive broad spectrum rate limiting rule at your external data border, dropping up to 50% of all inbound cloud traffic from the vendors region, accepting that some legitimate, some legitimate clinical check-ins would will be dropped as collateral damage. And then D, the emergency on-prem pivot, command your infrastructure team to instantly sever the external cloud telemetry sink entirely and attempt a forced unvetted fallback to your hybrid edge on-prem fallback cluster, risking a total data synchronization blackout during the transition.
SPEAKER_00Right, like I'm not the the medical expert, so we would be convening CIO, uh, ACMIO, CMIO, like architects, and we would decide on this together. I mean, the the first one seems, without being a medical expert and and an expert in medical systems, it seems to be reasonable. The 80-20 rule, because frankly, in security, unfortunately, we typically function at the 80% um confidence rule anyway.
SPEAKER_01Um that's why we have that one in there.
SPEAKER_00Yeah, legitimate. See what you did there. I feel like I would probably like lend more towards that one, just as long as I get guidance. I mean, I'm never gonna be making these decisions on myself. I know I have to make recommendations, but um, as long as the guidance from my medical staff isn't that that 20% is going to cause like some sort of significant quality issue to patients. Like, I'm my biggest concern is the patients in the trauma center. Trauma is like life or death, and 45 seconds matters. And so I think I would absolutely take that chance if it were just me and I I didn't know anything about medicine, which I don't. Um, seems pretty plausible, eh? Okay, well, I like that. Is that one a trap?
SPEAKER_01They're all traps, no.
SPEAKER_00Someone's working in security, Christine.
SPEAKER_01I know. You never get out, right? I always say, like, you can't unsee what you can't unsee what you've seen in this industry.
SPEAKER_00So nothing ever good comes of it, and you'll never win the battle. You just have to keep waking up and into groundhog day every day.
SPEAKER_01So true. Um, yeah, I think you outlined it, right? You eliminate you'll eliminate the data latency. Um, but that 20 for 20% failure hit rate just hit. Your server completely invalidated the session trust keys with the hardware. Dozens of smart pumps are now chirping and permanent lockup errors, and your biomedical engineering team has to spend their entire week physically touching every single device on the floor to repair them manually. You cleared the network cube but created a multi-day hardware crisis. But the good news is you still were not at this alone, right? Uh nobody died. And nobody died. Yeah, we would never do that. That would be terrible.
SPEAKER_00I was just waiting for that. Like, that would be the kicker. Well, that 20% hit, and you know, something happened in trauma, and like half your patients talk that be like, I'm just retiring now. I quit.
SPEAKER_01Yeah, I quit. Horrible. Uh okay. So here's the the quick recap and uh instant replay for what uh you've just been through, Krista. The processing cues are settling, uh, the shift change is complete, and your regional health network is either operating under a structured manual protocol, or your engineering team is resetting encryption keys by hand. You've just watched a vast network of life safety devices hang by a single unmapped vendor API gateway. You faced an alert uh fatigue crisis, an uninventoried shadow asset discovery, boardroom pressure over narrative control, an unverified vendor hot patch, and a final choice between software latency or manual operational chaos. Before we reveal your final score, I have to ask: when you are managing a modern, dynamic cloud healthcare infrastructure, can we ever truly achieve the absolute visibility we promise on paper? Or is it the job of the CISO simply learning to lead through the shadow spaces?
SPEAKER_00Yeah, I I oh good. There's no there's no A, B, C, or D for that. Yeah, we're you're always gonna lead through shadow spaces. A, yes, B, no, C, don't even answer it because you're screwed either way. Um AI tells us there, it's like a drinking game that we're always leading through shadow spaces. And so um there's no right answer for how to secure around AI and um and allow agility as well. And so I will tell you that one of the biggest things that you can do to shift your program towards the resilience narrative, because it's not if it's when I don't care how strong your program is, there's always one thing that's gonna happen, um, is just to get as much visibility as possible. So yeah, I mean, you're you're never going to know everything out there, even and like I'm lucky to be across a lot of verticals and have a lot of contacts and get feedback. Even pharma, um, they have great CMDBs and they still are like, oh my god, we have so much work to do. So whenever you think you're in bad shape and and you have a pretty mature program, the majority is is far worse. And so there are things that even people with the biggest budgets don't know about. And so invest in your visibility and invest in your team's readiness and preparedness to be able to make hard decisions and talk to the right people, knowing that there's always going to be something you're missing.
SPEAKER_01Yeah, I love that. Well, that that leads into your your final score. Um, the grounded humanist, you have high relationship and practical mitigation. So relying on your own team, and then you also obviously mentioned multiple times, you know, you would leverage your your network of leadership, other leaders within within the healthcare network. Um, you chose clinical safety, absolute transparency, and cross-functional team alignment over quick, unvetted corporate uh software patches. You refused to lie um about the about the the ongoing um escalation and stood by your architectural gates and prioritized protecting the workforce from unverified third-party code. All right. Before we unlock you out of this hot seat, we get fun one final more question from a leader who values real-world transparency. If you could send a one-sentence uh cryptographically signed message back through your time to a younger self entering your very first infrastructure or cybersecurity role about dangerous illusion of a perfect asset inventory dashboard, what would it say?
SPEAKER_00Uh, it wouldn't even be a sentence, it would just be L-O-L. Doesn't exist. Ma'am, stop trying to chase perfection. It doesn't exist.
unknownYeah.
SPEAKER_00I just like to quote like I know that's like anaclimatic, but I love to quote Anchorman. Like 60% of the time it works every time tells me that nothing is ever perfect, and you gotta just use what you what you do have and hope that it's right.
SPEAKER_01I love that. Yeah, Will Farrell's one of my favorites. He's got some awesome lines. That is so true. Um, okay, anything else you'd like to add, Krista, on your experience here on the pressure zone?
SPEAKER_00Yeah, I mean, if if when we um do these big incidents or, you know, communications issues, all the stuff that we deal with in healthcare, if it would come with a free make-your-own-at-home margarita kit at the end, um, when when CISOs have to go through situations like this, I I think that retention would be a lot higher.
SPEAKER_01So you're saying we should start sending out free margarita kits to all of the CISOs.
SPEAKER_00Congratulations, ma'am. You didn't kill anybody and you survived and you didn't get fired. Here's your margarita.
SPEAKER_01And it we'll make sure that it's on a subscription package so it doesn't run out.
SPEAKER_00And it ups and flows based on like your your vertical and the stuff that is attacking your vertical at the time. Considering healthcare has a few major incidents like every quarter, then maybe our subscription, like Amazon, would be more frequent because they're like, we detect an incident just occurred. Please ship new margarita kit.
SPEAKER_01Deploy immediately.
SPEAKER_00I'm just saying, like, it it's a business prospect. Someone should look into this.
SPEAKER_01Yeah, no, you're giving me uh you're giving me some good marketing ideas. All right, well, thank you for your time. That's a wrap on uh the hack the box pressure zone. To our listeners and the clinical wards, the security operations centers, and the healthcare executive suites, remember that your environment is only as secure as the unmapped shadow vendors your partners spun up six months ago. Track your assets and protect your teams and watch the perimeters. Uh, join us next time when we bring another um awesome leader to the hot seat. I'm your host, Christine Bartlett, and thank you for joining us. Bye bye.