Defense Against the Dark Arts, training your organization against ransomware.

Paige Ishii (Cybersecurity Analyst Senior · Paige Ishii)

SAINTCON 2025 · Day 1 · Main Track 1

Overview

Paige Ishii, a Cybersecurity Analyst Senior at Intermountain Healthcare, delivered a compelling talk at SAINTCON titled "Defense Against the Dark Arts, training your organization against ransomware." This presentation delves into the evolving and increasingly severe threat of ransomware, particularly within the critical healthcare sector, and outlines practical, human-centric strategies for organizational defense. Ishii emphasizes a cultural shift within organizations, moving away from traditional, often ineffective, training methods towards fostering a partnership with employees as the primary line of defense.

Watch on YouTube

Visual summary for Defense Against the Dark Arts, training your organization against ransomware. by Paige Ishii
Visual summary for Defense Against the Dark Arts, training your organization against ransomware. by Paige Ishii

Key moments

  1. 0:00 Introduction and speaker's cybersecurity journey
  2. 2:00 Ransomware's evolution: cost, healthcare impact, 'threat to life'
  3. 3:10 Case study: Julius Kessamakus (Zkill) and Vastamo
  4. 4:30 Vastamo: double extortion targeting mental health patients
  5. 6:05 Vastamo lessons: lack of encryption and GDPR fines
  6. 6:45 How to fight back: empowering staff through recognition
  7. 7:40 Ineffective security awareness training: LMS, passive, punitive

Defense Against the Dark Arts, training your organization against ransomware.

Speakers: Paige Ishii (Cybersecurity Analyst Senior, Intermountain Healthcare)

Conference: SAINTCON

YouTube: https://www.youtube.com/watch?v=efG9rhRBYYY

Overview

Paige Ishii, a Cybersecurity Analyst Senior at Intermountain Healthcare, delivered a compelling talk at SAINTCON titled "Defense Against the Dark Arts, training your organization against ransomware." This presentation delves into the evolving and increasingly severe threat of ransomware, particularly within the critical healthcare sector, and outlines practical, human-centric strategies for organizational defense. Ishii emphasizes a cultural shift within organizations, moving away from traditional, often ineffective, training methods towards fostering a partnership with employees as the primary line of defense.

The talk is a critical resource for cybersecurity professionals, IT leaders, and anyone involved in organizational security awareness and training. It highlights the urgent need to adapt defense strategies to counter the sophisticated and financially devastating nature of modern ransomware attacks. By sharing Intermountain Healthcare's journey and successful initiatives, Ishii provides a blueprint for cultivating a cybersecurity-aware culture that empowers employees to actively participate in protecting their organizations from one of the most pervasive cyber threats today.

Ishii's insights are particularly pertinent given her extensive experience, having witnessed the transformation of cybersecurity over eight years, from the nascent days of multi-factor authentication (MFA) to the current ransomware crisis. Her work as a training and education coordinator has provided a unique perspective on the challenges and successes of building robust human defenses against cyber adversaries.

Background

▶ Watch: Introduction and speaker's cybersecurity journey (0:00)

Eight years ago, when Paige Ishii first entered the cybersecurity field, ransomware was largely an unknown term, considered merely a "disruptive nuisance" with isolated instances. Today, it has escalated into a "chaotic disruptor," capable of crippling entire companies and industries. The financial impact alone underscores this dramatic shift: what once might have cost an organization around $1 million, now carries an average ransom demand of $2.9 million.

The healthcare sector, in particular, has become a prime target, experiencing a staggering 264% increase in ransomware attacks over the last five years. This surge has prompted serious warnings from bodies like the U.S. Department of Health and Human Services (HHS) and the Health Sector Coordinating Council (HSCC), which now classify ransomware against healthcare as a "threat to life crime." This grim designation was tragically underscored by the first recorded death directly attributable to a ransomware attack.

To illustrate the human cost and evolving tactics of ransomware, Ishii delved into a significant case study involving Julius Kessamakus, better known by his online alias Zkill, a member of the notorious Lizard Squad hacker group. This attack, which began in 2018 and saw the perpetrator caught in 2024, targeted Vastamo, a mental health online company in Finland. Zkill's malicious actions involved not only holding patient records for a ransom of €469,000 but, upon Vastamo's refusal to pay, executing a double extortion scheme. He began releasing sensitive mental health records of 33,000 patients onto the dark web and directly emailing victims, demanding personal payments to prevent the release of their confidential information.

The Vastamo breach exposed critical vulnerabilities in cybersecurity practices. The primary failure was a complete lack of encryption for patient data, a fundamental cybersecurity 101 oversight. Consequently, Vastamo faced not only the extortion attempt but also a substantial fine of €650,000 under the European GDPR (General Data Protection Regulation) for failing to protect personal data and violating the "right to be forgotten." This case vividly demonstrated the devastating consequences of ransomware, particularly when it intersects with highly sensitive personal information.

Traditional approaches to cybersecurity training have proven largely ineffective against such sophisticated and impactful threats. Ishii highlighted several common pitfalls:

  • Learning Management System (LMS) training: Often perceived as "boring check-the-box" exercises, these annual, lengthy modules fail to engage employees or instill lasting behavioral change.
  • Passive training: Simply sending a simulated phishing email and hoping employees click or report it without proper context or follow-up yields poor results.
  • Punitive approaches: Threatening or punishing employees for security lapses creates a culture of fear and resentment towards cybersecurity, rather than fostering partnership and proactive reporting. These methods alienate employees, making them less likely to report suspicious activities for fear of reprisal.

Recognizing these failures, the talk underscored the necessity for a radical shift in how organizations approach security awareness and training, moving towards strategies that genuinely engage and empower employees.

Key Findings

▶ Watch: Case study: Julius Kessamakus (Zkill) and Vastamo (3:10)

The core finding of this talk is that effective ransomware defense hinges on transforming organizational culture and empowering employees as active partners in security. Intermountain Healthcare's experience reveals that a successful strategy moves beyond passive compliance training to embrace personalized, empathetic, and data-driven approaches.

Ishii outlined what does work:

  • Pinpointing the "why": Employees need to understand the personal and organizational impact of ransomware to be motivated.
  • Making it personal: Connecting cybersecurity threats to employees' daily lives, their families, and the critical services their organization provides.
  • Getting people to care: Shifting from a mindset of obligation to one of shared responsibility and purpose.

Intermountain Healthcare implemented several key initiatives to foster this cultural transformation:

  1. A unifying slogan: Following the significant Change Healthcare breach in April 2024, which affected two-thirds of U.S. healthcare systems, Intermountain's CISO and communications director coined the slogan: "Our best defense against ransomware is all of you." This message explicitly positioned every employee as an integral part of the solution, not a potential weak link.
  2. Cultural mindset shift: The organization actively moved to instill a belief that everyone is "part of the solution, not a part of the problem," fostering a sense of collective ownership over cybersecurity.
  3. Targeted training: Moving away from generic, one-size-fits-all training to specific, in-person engagements tailored to different employee groups.
  4. Revamped phishing program ("fishing 2.0"): A sophisticated, data-driven approach that segments employees based on their reporting behavior and delivers customized phishing simulations and follow-up.
  5. Consolidated and simplified reporting mechanism: Introducing an "easy button" for reporting suspicious emails, ensuring it is consistent and readily accessible across all platforms.
  6. Quarterly, bite-sized LMS training: Breaking down mandatory annual training into shorter, more frequent modules to keep cybersecurity top of mind.
  7. Micro-training: Utilizing very short (under three minutes) educational videos or content snippets to cater to modern attention spans and deliver focused learning.

These findings collectively demonstrate that a holistic, employee-centric strategy, underpinned by clear communication, easy-to-use tools, and adaptive training, is crucial for building robust human defenses against ransomware.

Technical Deep Dive

▶ Watch: Vastamo: double extortion targeting mental health patients (4:30)

While the talk does not delve into traditional software or network security protocols, its "technical deep dive" is into the methodology of human-centric cybersecurity defense, which is equally critical. Ishii presented the BJ FOG BMAP method (Behavior, Motivation, Ability, Prompt) as a foundational framework for driving cultural change and desired security behaviors within an organization.

  1. Behavior: This component defines the specific action an organization wants its employees to take. In the context of ransomware defense, the primary desired behavior is reporting suspicious emails or activities. This is a proactive measure that empowers employees to be the eyes and ears of the security team.
  1. Motivation: To encourage the desired behavior, employees must be motivated. Ishii emphasized "pinpointing the why" and "making it personal." This involves:
  • Connecting to impact: Explaining how ransomware can lead to a public health crisis (in healthcare), impact patient care, or affect the personal data of employees and their families. The power outage scenario at Intermountain's flagship facility served as a tangible example of operational disruption, making the potential impact of ransomware more real.
  • Fostering partnership: Shifting the narrative from employees being a risk to being the "best defense." Intermountain Healthcare's slogan, "Our best defense against ransomware is all of you," directly addresses this, creating a sense of shared responsibility and teamwork.
  • Positive reinforcement: Acknowledging and thanking employees who consistently exhibit desired behaviors, such as reporting phishing attempts.
  1. Ability: Employees must have the ability to perform the desired behavior easily. A significant barrier to reporting suspicious activities is often a cumbersome or inconsistent reporting process. Ishii highlighted the critical importance of an "easy button" for reporting fish.
  • Consolidation and Consistency: At Intermountain, initial challenges included a hidden and inconsistent "report suspicious" button across different platforms (mobile devices, Outlook, and other web interfaces). By working with their vendor, they consolidated the button's appearance and placement, making it uniform and highly visible across all three environments. This single change resulted in a 10% overnight increase in reporting rates in one department that previously had only 2-3% reporting. This demonstrates that simplifying the user experience for security tools is paramount.
  • Accessibility: The goal is to make reporting as frictionless as possible, eliminating the need for complex steps like attaching emails or navigating multiple menus.
  1. Prompt: For behaviors to become habitual, employees need regular prompts or reminders. This is where Intermountain Healthcare's innovative training and phishing programs come into play:
  • Targeted Training: Instead of broad, generic sessions, security teams conduct in-person "targeted training" sessions. These focus on the basics – social engineering, phishing, and ransomware – keeping the message simple and emphasizing the partnership between employees and the cybersecurity team. The goal is to reach about 10% of their 68,000 employees with this direct interaction.
  • Phishing 2.0 Program: This is a sophisticated, data-driven approach that segments employees based on their reporting rates (not just click rates) into three groups:
  • Group 1 (Low Reporting): These employees are "fished" monthly with simpler simulations because they are still learning to recognize threats. The intent is to provide repeated exposure and learning opportunities.
  • Group 2 (Sometimes Reporting): These employees receive phishing simulations every other month (six times a year), providing regular reinforcement without over-saturating them.
  • Group 3 (High Reporting / "Top Fishers"): These exemplary reporters are "fished" only once a quarter with more difficult simulations. Critically, they also receive positive reinforcement through "thank you" emails, acknowledging their vital contribution. This positive feedback loop is a powerful motivator. The program has shown an incremental rise in reporting rates, with almost 10% increases for each group.
  • LMS Training Revamp: Instead of a single, lengthy annual training, Intermountain broke down its mandatory LMS content (covering regulatory requirements like PHI and HIPAA) into quarterly 15-minute modules. This ensures cybersecurity remains "top of mind" throughout the year, rather than being a forgotten annual chore.
  • Micro-training: Recognizing the dwindling attention spans (estimated at 45 seconds for the current workforce), Intermountain introduced "micro-training" – content under three minutes, ideally focusing on "one idea" per bite-sized piece. This format is more likely to be consumed and retained than longer videos.

By systematically addressing Behavior, Motivation, Ability, and Prompt, Intermountain Healthcare has engineered a comprehensive, adaptive, and effective human defense strategy against ransomware, shifting the burden from technical controls alone to a fortified human firewall.

Demo / Proof of Concept

▶ Watch: How to fight back: empowering staff through recognition (6:45)

While this talk did not feature a live technical demonstration or a software proof-of-concept in the traditional sense, Paige Ishii presented compelling evidence of the effectiveness of Intermountain Healthcare's human-centric security programs. The "proof of concept" lies in the measurable improvements and cultural shifts observed within their vast organization of 68,000 employees.

Key results demonstrating the success of their initiatives include:

  1. Reporting Button Impact: The consolidation and simplification of the "report suspicious" button, ensuring a consistent and easily accessible interface across all platforms, led to a dramatic improvement. In one specific area of their organization that previously had only 2-3% reporting rates, this single change resulted in an overnight increase to 13% reporting, representing a 10% jump. This clearly demonstrates that reducing friction in security processes directly correlates with increased user engagement and compliance.
  1. Phishing 2.0 Program Success: The data-driven, segmented "fishing 2.0" program, which tailors simulation frequency and difficulty based on reporting behavior, has yielded significant positive outcomes. Ishii reported that they have seen "incrementally every single group going up" in their reporting rates. Specifically, there have been "almost 10% increases for each group," indicating that personalized and positively reinforced phishing simulations are highly effective in cultivating better reporting habits across the entire employee base. This continuous upward trend in reporting rates serves as a strong validation of their adaptive strategy.

These metrics provide concrete evidence that Intermountain Healthcare's approach—focused on motivation, ability, and consistent prompting—is not merely theoretical but delivers tangible improvements in organizational cybersecurity posture.

Defensive Implications

▶ Watch: Ineffective security awareness training: LMS, passive, punitive (7:40)

The strategies outlined by Paige Ishii offer critical defensive implications for any organization grappling with the pervasive threat of ransomware. The core message is a call to action for a fundamental shift in cybersecurity strategy, moving from an exclusive focus on technical controls to a robust, human-centric defense.

  1. Embrace a Partnership Mindset: Defenders must abandon punitive approaches and instead foster a culture where employees are seen as integral partners in cybersecurity. Framing security as a shared responsibility, as exemplified by Intermountain's "Our best defense against ransomware is all of you" slogan, builds trust and encourages proactive engagement.
  2. Prioritize User Experience for Security Tools: The "easy button" for reporting suspicious emails is a powerful lesson. Security tools and processes must be intuitive, consistent, and frictionless. If reporting a potential threat is difficult or confusing, employees will avoid it. Investing in a streamlined, accessible reporting mechanism (e.g., a single, consistently placed "report suspicious" button across all email clients and devices) can significantly increase threat intelligence from the front lines.
  3. Implement Data-Driven Security Awareness Training: Move beyond generic, check-the-box training. Organizations should segment their employee base based on observed security behaviors (e.g., phishing reporting rates) and tailor training content and frequency accordingly. This allows for targeted interventions for high-risk groups and positive reinforcement for high performers, maximizing the impact of training resources.
  4. Focus on "The Why" and Personal Impact: Employees are more likely to care and engage when they understand the personal and organizational consequences of cyberattacks. Regularly communicate the real-world impact of ransomware, including financial costs, operational disruptions, and potential threats to lives or livelihoods, to build intrinsic motivation for security best practices.
  5. Adopt Bite-Sized, Frequent Training: Replace lengthy, annual LMS modules with shorter, more frequent training sessions (e.g., quarterly 15-minute modules or micro-training videos under three minutes). This approach caters to modern attention spans, keeps cybersecurity top of mind, and ensures continuous learning and reinforcement.
  6. Measure and Track Reporting Rates, Not Just Click Rates: The efficacy of security awareness programs should be measured by employees' ability and willingness to report suspicious activity, not just by how many click on a simulated phishing link. Tracking reporting rates provides a more accurate indicator of an organization's human firewall strength and its ability to detect and respond to real threats.
  7. Keep Messaging Simple and Focused: Overloading employees with too much technical jargon or too many different security topics can lead to disengagement. Focus on the basics: recognizing social engineering tactics, identifying phishing attempts, and understanding the immediate threat of ransomware. This clarity helps employees internalize core defensive behaviors.

By integrating these implications, organizations can build a resilient defense-in-depth strategy that leverages their most valuable asset: their employees.

Key Takeaways

  • Ransomware is an escalating, life-threatening crisis: It has evolved from a nuisance to a "chaotic disruptor," with average ransom demands nearing $3 million, and has been linked to patient deaths, particularly in the healthcare sector.
  • Effective defense demands a cultural shift: Organizations must move beyond punitive approaches and foster a partnership with employees, making them feel like part of the solution rather than the problem, to build a strong human firewall.
  • Simplicity and accessibility are paramount for security tools: An "easy button" for reporting suspicious activity, consistent across all platforms (mobile, desktop), dramatically increases employee engagement and threat reporting rates.
  • Training and phishing simulations must be data-driven and tailored: Segmenting employees based on their reporting behavior and customizing the frequency, difficulty, and reinforcement of phishing campaigns significantly improves overall security posture.
  • Frequent, bite-sized training is more effective than lengthy annual sessions: Breaking down mandatory training into shorter, quarterly modules and utilizing micro-training (under three minutes) keeps cybersecurity top-of-mind and caters to modern attention spans.
  • Measure reporting rates, not just click rates: True success in security awareness is reflected in employees' willingness and ability to report suspicious activities, providing critical intelligence to security teams.

About the Speaker(s)

Paige Ishii is a Cybersecurity Analyst Senior at Intermountain Healthcare. With approximately eight years of experience in the cybersecurity field, she began her journey as a training and education coordinator. This background has given her a unique perspective on the evolution of cyber threats, from the early days of multi-factor authentication (MFA) to the current complex landscape dominated by ransomware. Ishii is passionate about empowering organizational staff to recognize and report cyber threats, advocating for a cultural shift that positions employees as key partners in defense against cybercriminals.

All talks from SAINTCON 2025