Healthcare Videos
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Healthcare Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
HealthcareVideosUnHack the Podcast Inside a Real LockBit Attack - Lessons From Fighting Ransomware with Zach Lewis
HealthTechHealthcareCybersecurity

UnHack the Podcast Inside a Real LockBit Attack - Lessons From Fighting Ransomware with Zach Lewis

•February 24, 2026
0
This Week Health
This Week Health•Feb 24, 2026

Why It Matters

The breach demonstrates that even mature security programs can be compromised by simple configuration errors, emphasizing the need for strict change‑management and robust incident‑response. It also illustrates the tangible financial benefit of skilled negotiation during ransomware crises.

Key Takeaways

  • •Configuration gap during firewall migration enabled LockBit entry
  • •Negotiation reduced ransom cost by $1.25 million
  • •Ransomware groups mimic corporate structures, quotas, benefits
  • •Strong security scores don’t guarantee immunity
  • •Post‑attack lessons improve institutional cyber resilience

Pulse Analysis

Higher‑education institutions have become prime targets for ransomware gangs like LockBit, drawn by the wealth of personal data and research assets they hold. In the case of the University of Health Sciences and Pharmacy, a routine firewall migration introduced a configuration gap that the attackers exploited, bypassing layers of security that otherwise earned the school an A‑minus rating. This incident underscores a broader industry lesson: sophisticated defenses can be undone by a single misstep in network architecture, making continuous validation of change‑management processes essential for any organization.

The financial dimension of ransomware incidents often hinges on negotiation tactics. Zach Lewis’s decision to engage with LockBit’s negotiators resulted in a $1.25 million reduction in the ransom demand, a savings that dramatically altered the university’s recovery budget. This outcome reflects a growing trend where ransomware operators run their enterprises with the same rigor as Fortune 500 firms—maintaining quotas, offering employee benefits, and employing professional negotiators. Understanding this business‑like behavior equips defenders with better leverage, turning a potentially catastrophic payout into a manageable expense.

Beyond the immediate response, the episode provides a roadmap for strengthening cyber resilience. Post‑attack analyses emphasize the need for real‑time monitoring, automated configuration audits, and cross‑functional incident‑response drills that include senior leadership. Embedding these practices into governance frameworks not only patches the technical gaps that enabled the breach but also cultivates a culture of preparedness. As ransomware tactics evolve, institutions that combine robust technical controls with disciplined operational oversight will be best positioned to mitigate risk and protect their critical missions.

Original Description

When Zach Lewis, CISO and CIO at the University of Health Sciences and Pharmacy in St. Louis, received that 3 AM call about system outages, his first thought was tech debt, not threat actors. What followed was a masterclass in ransomware response that he's now captured in his new book "Locked Up." Despite A-minus security scores, board briefings, FBI connections, and all the right frameworks in place, LockBit still found its way in through a configuration gap during a firewall migration. In this raw conversation, Zach reveals why the negotiation process saved them $1.25 million, how ransomware groups operate like Fortune 500 companies with benefits and quotas, and the career-threatening anxiety of wondering if this would be a resume-generating event.
Key Points:
00:44 Discussing 'Locked Up'
05:37 Initial Response and Realization of Ransomware Attack
16:05 Decision-Making and Negotiations with LockBit
18:45 Understanding the Ransomware Ecosystem
24:01 Lessons Learned and Strengthening Cybersecurity
Golf Tournament Registration: https://carahevents.carahsoft.com/Event/Details/686801-ThisWeekHealth
Linkedin: https://www.linkedin.com/company/ThisWeekHealth
Twitter: https://twitter.com/thisweekhealth
Donate: Alex’s Lemonade Stand: Foundation for Childhood Cancer - https://www.alexslemonade.org/mypage/3173454
0

Comments

Want to join the conversation?

Loading comments...