S1E6 AI Cyberattacks (ft. Matt Morton, University of Chicago)
Healthy Uptime Podcast Matt Morton (University of Chicago) _ Jordan Cooper (Rackspace)-20260923_112654-Meeting Recording
September 23, 2026, 3:26PM
22m 12s
Jordan Cooper 0:03
We're here today with Matt Morton of the University of Chicago, where he is the Assistant Vice President and Chief Information Security Officer. Matt, thank you so much for joining us today.
Matthew Morton 0:14
Thanks, Jordan. I'm glad to be here today. And, you know, just to be clear, you know, we're going to talk about some cool stuff today around cybersecurity, but most of these are the views of myself and don't necessarily reflect the views of the University of Chicago.
Jordan Cooper 0:29
Perfect. Glad to have you on here, Matt. Understood. For those who don't know, as background, the University of Chicago is broader than the health system. UChicago owns and operates UChicago Medicine, an integrated academic health system headquartered in Chicago, Illinois, which has 2,000 beds across 10 hospitals serviced by 3,000 providers. But again,
Matt represents the University of Chicago, which is much larger and all-encompassing than just the health system. So, Matt, today we're going to talk about kind of the increasing risks posed by cyber attacks to organizations, cyber attacks that are driven by new Gen. AI capabilities.
and kind of framing the conversation as investments in funding for cybersecurity can be seen as insurance policies against these attacks. So with that, I'd like to ask you, what is the state of cybersecurity at UChicago? What are you doing to
protect the university from cyber attacks and how has Gen. AI changed your approach?
Matthew Morton 1:39
Yeah, so it's a great question. Very broad, a lot of things changing in this space. As you can imagine, you know, the recent attacks by OpenAI on Hugging Face, you know, Agentic AI and AI as a whole is being used to
reduce, I guess, the time it takes to identify vulnerabilities and exploit them from what used to take maybe weeks, perhaps even days, now into hours. And when that happens like that, that creates an environment that it's not a matter of if you're going to get
you know, hacked. It's a matter of when and how you respond. And so our focus has been on, you know, of course, three legs of the stool, making sure that we're focused on remediating the vulnerabilities we know about, making sure that we're planning for when downtime has to occur, that we have good resiliency,
that we have the ability to recover from not just an attack, but you know, we use a lot of vendors. There's a lot of SaaS vendors out there, right? It's possible that there could be situations where we have a very critical vendor, say like what happened in May with Instructure, that's a public event.
And we have to be able to respond and be resilient in the face of those kinds of downtimes and things that are going to occur. And then the third thing is, of course, is using AI and using agentic AI on the team and making sure that we're trying to be as proactive and knowledgeable as we can be so that we can
you know, defend against these adversaries that are going out there. I mean, a lot of these things are, there's some that are financially motivated. There's some that are politically motivated. Ultimately, despite what the motivations are, they're still very impactful and they really impact the mission of what we're trying to do.
Jordan Cooper 3:38
Her.
So for those who are listening to this episode right now, they may say, I know, you know, yes, there are attacks, but there are a lot of priorities and we have to focus on putting our funding for frontline clinicians. And of course, our EHR is a huge line item. And so how do you make the case to those listening to this show that
Funding needs to be diverted to support disaster recovery, to support independent recovery environments, support high availability, and to support CISOs and their teams as they try to prevent and rapidly respond to cyber attacks.
Matthew Morton 4:21
Yeah, no, that's a great question. And it's a hard one. It's a hard one to answer because there's no direct value creation, right? You're not creating revenue. You're protecting revenue in the security space. And that's how I kind of like to have the conversation is that it's even more than an insurance policy. Because in an insurance policy, you never really want
to have to pay out, right? Because if you pay out, you're paying premiums into it. I would say that those premiums that we're investing into cybersecurity, you know, should be at a balanced level based on the risk that you're dealing with. And so, unfortunately, in things like, you know, the technology that supports the health processes that we have, whether that be revenue cycle, whether it be
delivery of patient care and clinical care, and clinical research, all of those things are extremely important and part of what the mission of a healthcare organization is. And so we have to be able to support that mission with the right amount of funding.
Jordan Cooper 5:29
Mhm.
Matthew Morton 5:31
Now, that funding doesn't have to be, you know, at a level that's, you know, I guess, out of line with what you're trying to work with there, but you have to look at it from a risk perspective. What's the impact? What's the likelihood of something happening and what that event is? And what are the costs that would actually be incurred if that event actually did occur?
Jordan Cooper 5:32
So...
Matthew Morton 5:51
So those are the kind of the factors that we look at.
Jordan Cooper 5:55
Right. So I love that. I want to go deeper there. So you said you have to balance your funding for cybersecurity with the level of risk you're facing. I'd like to dive into how you're evaluating the level of risk and the amount that an organization should invest in protection from this risk. So you said you evaluate the impact, the likelihood, the cost incurred.
Could you go as specifically as possible into how UChicago is evaluating the risk and from there, deriving a formula to determine how much to invest in this? Should we give you 50 FTEs? Should we give you 20 FTEs? Should we invest in this IRE with this organization?
Matthew Morton 6:32
Right.
Jordan Cooper 6:34
How do you determine the appropriate level of funding?
Matthew Morton 6:38
Right, right, right. So what I use personally is the FAIR framework. I don't know if you're familiar with that. It's a risk management framework typically used in financial services. But that simplification of that framework is essentially what I just told to you, right, which is likelihood impact and what that annual loss expectancy might be.
Jordan Cooper 6:42
Mhm.
Matthew Morton 6:59
So we take an look at an incident that would occur. What's the likelihood that a threat actor would gain control and deliver ransomware, right? We evaluate that based upon what's going on in the industry with our peers, you know, kind of benchmarking against that. We kind of develop also a risk
Jordan Cooper 7:08
Mhm.
Mhm.
Matthew Morton 7:19
appetite, like we gauge the risk appetite of our senior leadership and the leaders in the organization. And then we balance that with what we think the impact would be, what that loss expectancy would be, and then the likelihood of how that would occur, say in a five-year period, how many times do we expect that to occur, right? Or maybe it's a 10-year period.
Jordan Cooper 7:25
Mhm.
Matthew Morton 7:40
We have cybersecurity insurance, and that's kind of very similar how they price that. And so then we have some data that we can look at to kind of help identify that. The problem is, is that there's so many of these events, like, you know, especially ones that are being driven by AI now, that we haven't seen before. And so there's no history.
So when you look at things like car insurance or you look at things like even life insurance, there's literally either 50, 100 years, maybe 200 years of data that insurance companies are using to generate their predictability about what they think those expenses are going to be. In cyber, we've only been doing this for 20, right?
Jordan Cooper 8:03
Mm.
No.
Matthew Morton 8:19
And so that's that kind of helps kind of indicate it is a bit of a guess too. So it's an informed guess, we'll call it.
Jordan Cooper 8:26
No.
I think a lot of our listeners would be interested in hearing about what new kinds of attacks there have been and how organizations are responding to these attacks in new ways with your new agentic tools. And also in responding to that, I'd love if you could ground it at all in actual real examples. You mentioned a case from this past May.
or even something that may not have affected you, Chicago, like the Change Healthcare attack from a year and a half ago.
Matthew Morton 8:57
Yeah, yeah, so I mean, yeah, the change healthcare attack is a...
textbook example of a, you know, a third party risk, right? Change healthcare was embedded in everybody's, you know, processes. And when they got attacked, that impact, that breach impede, or excuse me, impacted delivery and collection of funds and all sorts of revenue cycle problems that were generated there.
huge numbers that when it was actually all said and done, both from the settlements and from the impacts that health organizations had to deal with. There was one in May as well that was on Instructure, you know, by a threat actor that has been labeled as shiny hunters.
They had delivered ransomware, and that brought down learning management systems across the world, essentially, right before or during finals of many institutions. And as you can imagine, delaying finals is not a very popular thing to do when you're working with students.
Jordan Cooper 10:00
Mm.
Matthew Morton 10:06
And so that's, you know, yet another piece of extortion that, you know, that they were looking at to get done there. Those are the kind of sophistication, I guess, around ransomware gangs that is going on. But the other thing I would point out is that with the use of AI is that now
to get into that market of being an extortion operator or a ransomware gang is a lot, the bar is much lower now, right? Because if you get the right model and you're able to use it in the right way, you can identify vulnerabilities and things way faster than anybody else could use.
faster than the organizations can respond. And that is a significant, I think, event that we probably haven't seen the end of yet. And it'll continue to get worse before it gets any better.
Jordan Cooper 11:02
So would it be fair to characterize the market of black hat cyber criminals as viewing AI as a democratizing tool, meaning Gen. AI is now expanding and making it a lower barrier to entry for wannabe criminals to become successful criminals and to do so more quickly? Is that the greatest difference between now and a decade ago?
Matthew Morton 11:27
Oh, absolutely. Yeah, yeah. The tool sets that are available are much easier to get a hold of, easier to use. You know, used to be you had a lot of skills you had to know. Now you can just ask, right? How do I do X? I have this, I want to do this. How do I do it? You know, assuming you've got an open weight model that you've broken or
that some of the larger groups have trained themselves, right? That they've built these models themselves, so.
Jordan Cooper 11:52
So are you, so just, and just to put a bow on this, are there any brand new types of attacks from Gen. AI or just new people doing old attacks more quickly and effectively?
Matthew Morton 12:07
Well, I mean, ultimately, you know, in the world of, you know, criminal activity and so forth, there is always, it's a repeat of old crimes, right? I mean, there's nothing new in that world in terms of like the what, but in the how, that's what the new is, right? And so impersonation is a big one.
Jordan Cooper 12:22
Mm.
Matthew Morton 12:27
right? AI allows for the type of impersonation and fraud that can be done now over video, over audio, things of that nature, you know. And we have seen that. And we've seen where they not only use it at a small scale, say, trying to get someone's credentials, but I've heard of other attempts at
Jordan Cooper 12:44
Mhm.
Matthew Morton 12:47
larger scale things where financial transactions of large amounts were talked about. And that fraud was attempting to be committed by these groups using simulated or AI generated tools, excuse me, people that were, you know, meant to fool people, really.
Jordan Cooper 12:52
Mm-hmm.
Matthew Morton 13:07
It's that's the impersonation aspect of it. So, so, but there's always been a level of attempts at impersonation. It's just now it allows more people to try it and it makes it easier for them to do.
Jordan Cooper 13:20
I suppose a listener to this episode says, wow, I'm really concerned about impersonation. You know, I think we're going to do a deal with XYZ vendor, and we're going to give them $2 million a year with an initial payment of 3 million because it's implementation as well. How do I know if I'm actually dealing with the vendor I think I'm dealing with?
Matthew Morton 13:42
Yeah, so there are tools out there that allow you to kind of have an intermediary in place. I mean, a lot of this has to do with your business processes, right? Those tools kind of do a verification. It always comes down to that. How do you verify it? You know, for example, with people who are impersonating in order to, you know, the
North Korean job scams that go on, right, where there's people doing that stuff. You can do simple things like, well, require an in-person meeting. You know, perhaps the transactions don't occur until you've actually shaken hands. I mean, I know that's inconvenient and it's difficult in today's digital world, but we've
We've got to come up with ways to work around that. Now, these companies that provide that verification, you know, they are subject also to the same impersonation attacks, many times at a higher scale than what others, because if you get in there, you've got access to a lot of stuff, right? So yeah, it's a great question, but it comes down to your processes more than anything. So cyber is moving out of this space of...
Jordan Cooper 14:29
Who?
Matthew Morton 14:47
of what I'll call baseline security into this concept of digital trust, right? And that digital trust is where we're going to have to build not just the cybersecurity aspects, but also privacy, resiliency, and trust into, you know, all parts of the organization so that people understand what exactly
and who they're dealing with, because that's where the attackers are moving towards.
Jordan Cooper 15:16
So how have you been working to direct your team to enhance privacy, trust, and resiliency at UChicago? What are some discrete methods, potentially with infrastructure, for example? Is there something that are you moving? Is it private cloud or on-prem? Are you doing kind of, as I mentioned earlier, an independent recovery environment? Are you thinking disaster recovery?
What are you doing specifically, especially from, you know, under beneath the scenes, beneath the hood, that people won't see to enhance these digital trust?
Matthew Morton 15:46
Yeah, yeah.
Yeah, yeah. So if you think about from the standpoint of if you're providing a service, even if you've contracted with a SAS provider to provide that service, to build the trust with our constituents, right, we've got to make sure that that service stays up. Or if it does go down, we're able to recover quickly. That's the disaster recovery or BCP portion of it, right? But we have to work closely with our partners on that.
Jordan Cooper 15:59
Mhm.
Mhm.
Matthew Morton 16:14
doing things like, you know, not just backing up the data and not just having a recovery of the data, but also the configurations. When you set up a SAS tool, if anybody has, you know, done any large scale SAS deployment, there's still a significant amount of configuration that goes into those and you have to be able to back that back up if you're going to rebuild it if you get.
Jordan Cooper 16:32
Mhm.
Matthew Morton 16:35
hit with a ransom or they get hit with a ransomware attack and those kinds of things. In terms of like...
what we're doing across the board, identity verification is a critical piece of that infrastructure. So, you know, administrators, software developers, anybody that maybe holds keys to a kingdom of some sort,
has to be verified. If they say, oh, I can't remember my password, I've got to go get it reset. Well, great. You're going to be getting on a video call with this and you're going to have to provide your, you know, either passport or government ID so that we know who you are and that we can verify that that is indeed the case. That identity verification is a key aspect to the assurance that we need to provide.
when we're working with these folks. That's definitely at a very discreet level. That's how we're talking about it. The same is true with vendors as well.
Jordan Cooper 17:34
I think it's really interesting that there are increasingly, according to what I'm hearing from you, analog responses to end with manual workflows with physical airplane flights to have meetings and physically shake hands in response to technological advancement with AI. It's just
an interesting kind of, I guess, pendulum swing in response to pushing forward with technology.
Matthew Morton 18:03
Yeah, yeah. And it's balanced with the risk, right? I mean, a risk of a $50 transaction is a lot different than a risk with a $5 million transaction, right? And so we balance that with the risk. But yeah, that is the quickest and easiest way to do that verification, because every time we come up with a digital solution,
Jordan Cooper 18:11
Mhm.
Mhm.
Matthew Morton 18:22
the attackers come up with a way to circumvent that, right? So.
Jordan Cooper 18:27
I would like to, we're running up on the end of this podcast episode, so a few more questions. Just to circle back real quickly, when we were talking about the attacks of Change Healthcare or Instructure, has there been any post-mortem evaluation of the
Matthew Morton 18:43
Uh-huh.
Jordan Cooper 18:47
costs of those attacks and any comparison between those costs and the expected fair framework projected cost of what those attacks would have been like, you know, a few years ago prior to the attacks.
Matthew Morton 19:02
Yeah, no, that's a great question. I'm not aware of any research in that space that would do that. I mean, there have been what I'll call estimates of the change health care attack, and you can look those up. I don't have them off the top of my head. My memory is it was over a billion dollars. But that could be wrong.
Jordan Cooper 19:14
Mhm.
Mm hmm. But.
In general, I guess not specific, but more generally, do you feel like the actual frequency and costs associated with attacks are aligned with the projected frequency and cost of attacks?
Matthew Morton 19:37
Well, we can never predict the future. And so they're always going to be, you have, there's an element of guessing that goes on, I guess, maybe intuition that you have to apply to those kinds of things, right? The past is not always a predictor of the future. Because, you know, I mean, who would have predicted, right, we would be dealing with generative AI attacks.
Jordan Cooper 19:48
Who?
Mhm.
Matthew Morton 20:00
in today's world five years ago. You know, I don't think that was on my radar. And especially with regards to those costs.
Jordan Cooper 20:02
Got.
So...
So just kind of a final question, I'd like to open up for you, Matt. Talk about kind of AI governance or conceptualizing investing in cybersecurity as insurance policies, evaluating your investment in terms of the risk posed by new attacks. What are some final parting thoughts?
either advice to listeners on what they should do at their organizations, or maybe even advice to yourself a year ago about what you wish you would have known that you know now.
Matthew Morton 20:35
Yeah, that's a great, great question. Yeah, I would say that first of all, you're never going to be, you're never going to have enough knowledge. So just accept the fact that we don't know what we don't know right now. Many times we have to begin with something and start somewhere. AI governance is a very,
interpreted term now, right? Depending on your place in the organization and depending what vertical you're in. But essentially, you have to have some understanding of how the AI, how AI tools and how AI systems are being set up in your organization so that you don't actually create a bunch more risk
that you're going to have to be dealing with, you know, a year from now. At the same time, you have to enable it because there's a lot of FOMO. A lot of organizations are concerned that they're not going to be relevant if they don't get these things implemented, you know, and so they want to be first to market. And so that's fair. I think that's a very fair assessment.
But you have to balance it. So you have to include people. You got to make sure that you're collaborating with your security professionals, but also with the business unit responsible, you know, executives, et cetera, to make sure that they are involved in that decision making that's going to happen.
Jordan Cooper 21:55
All right, thank you, Matt, for joining us. For our listeners, this has been Matt Morton, the AVP and CISO at the University of Chicago. And again, Matt, thanks so much for joining us on Healthy Uptime Podcast.
Matthew Morton 22:09
Sounds great. Thanks, Jordan. Appreciate it.
Jordan Cooper stopped transcription