The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Cyber Work
Cyber Work artwork

From security audits to privacy consulting: Building a GRC practice | Will Sweeney

Cyber Work · 2025-07-21 · 42 min

0:00--:--

Will Sweeney built Xaviant into a leading GRC consulting firm by recognizing the massive opportunity in GDPR compliance and data privacy regulations. Starting his career in audit roles at KPMG doing Sarbanes-Oxley and FISMA testing, Sweeney transitioned into implementation and consulting at IBM before founding Xaviant in 2016. The episode explores a critical career insight: auditors excel at understanding regulatory requirements but often lack the technical depth to implement solutions, while implementation consultants combine both skills. Sweeney emphasizes that successful compliance work requires stakeholder buy-in across organizational levels, addressing knowledge gaps and resource constraints. He discusses how Xaviant helps Fortune 100 companies navigate overlapping frameworks - GDPR, US state privacy laws, CMMC, ISO 27001, and SOC 2 - by identifying programmatic synergies. The conversation highlights emerging challenges including data discovery and classification, third-party risk management, and the tension between AI adoption and data privacy law compliance. Sweeney argues that GRC expertise is too specialized for internal upskilling and recommends outsourcing to firms with deep subject matter expertise, though improving GRC software tools are making practitioners more efficient.

Key takeaways

  • →The skills required for security auditing versus implementation consulting differ significantly - auditors understand requirements but may lack technical depth, while implementers need both regulatory knowledge and hands-on technical ability to solve compliance gaps.
  • →Most organizations struggle with knowledge gaps and resource constraints rather than budget, and cannot simply assign network engineers or IT operations staff to handle data privacy and GRC work due to fundamentally different skill sets required.
  • →A programmatic approach to compliance can create efficiencies where solutions for GDPR compliance simultaneously advance US state privacy law and other framework requirements, reducing redundant work.
  • →Data discovery, classification, and governance remain critical challenges because organizations historically lack visibility into where their data resides, making it impossible to apply appropriate security controls or demonstrate compliance.
  • →The rise of AI and large language models creates a fundamental tension with data privacy regulations - AI needs data for effectiveness, but GDPR and similar laws grant individuals rights to consent, deletion, and data portability that may be technically incompatible with how AI systems operate.

Guests

Will Sweeney

Topics in this episode

GDPRThird party risk managementSarbanes-OxleyISO 27001CMMC (Cybersecurity Maturity Model Certification)SOC 2US State privacy lawsFISMAData discovery and classificationAI Act regulation

Questions this episode answers

What is the main difference between security audit work and implementation consulting?

Audit work identifies gaps and issues through assessment, producing a report of problems for remediation. Implementation consulting does the same assessment but then actively solves those identified problems alongside the client, making it hands-on and solution-focused rather than just gap-reporting.

Why can't companies just upskill existing IT staff to handle GDPR and data privacy compliance?

Data privacy and GRC work requires fundamentally different skills than network engineering or IT operations - building data maps, privacy notices, and compliance documentation cannot be effectively performed by staff whose core expertise lies in infrastructure, and outsourcing to subject matter experts is more cost and time-effective.

What are the biggest compliance challenges organizations face beyond just regulations?

The largest challenges are lack of data governance and visibility into where data resides in their environment, inadequate stakeholder buy-in across organizational levels, and increasing enforcement and fines from regulators investigating false compliance claims.

How does the EU AI Act and emerging AI regulations conflict with existing data privacy laws?

AI systems require large amounts of data to be effective, but data privacy regulations like GDPR grant individuals rights to consent, access, and deletion - creating technical and legal tensions around whether AI can lawfully collect and retain data in ways required for the technology to function.

Has GRC software improved the efficiency of compliance work?

Yes, GRC tools have improved significantly over the past five years with better automation, allowing practitioners to focus on problems software cannot solve and making the delivery of compliance services more efficient overall.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B65%
  • Speaker A35%

Most-used words

data39privacy37security31requirements20compliance18sure17understand15cybersecurity14help14problems12level12started11industry11roles11back11continue10

Episode notes

Get your FREE Cybersecurity Salary Guide: Will Sweeney, founding and managing partner of Zaviant, joins the Cyber Work Podcast to discuss the evolving landscape of data privacy and GRC (governance, risk and compliance). With experience overseeing complex information security audits for Fortune 100 companies, Will shares insights on everything from the key differences between security auditing and implementation to whether privacy regulatory frameworks will continue multiplying or begin consolidating. He offers practical advice for GRC aspirants, emphasizing the importance of understanding core security processes rather than getting lost in framework structures. Will also discusses the challenges of starting a consultancy practice and provides valuable career guidance for those looking to transition into the data privacy and compliance space. 0:00 - Intro 1:15 - Cybersecurity Salary Guide promo 2:30 - Will Sweeney and his early tech background 6:45 - Building his first high school website 9:20 - Career pivot from IT to data privacy and GRC 12:15 - Audit vs.

Full transcript

42 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Today on UM, Cyber Work, Will Sweeney of Xaviant joins me to discuss Data Privacy GRC and the future of privacy regulations. Zaviant has overseen complex information security audits for much of the Fortune 100 companies. We talk about everything from the split between the skills needed for security auditing versus security implementation, whether privacy regulatory frameworks will continue multiplying or begin a process of consolidation, as well as a key way to understand many different compliance frameworks at once. The tip is to focus on the security processes themselves, not the structure of the framework. GRC Aspirants There's a lot of tips to get you started here. So that's all today on cyberwork. The IT and cybersecurity job market is thriving. Bureau of labor statistics predicts 377,500 new IT jobs annually. You need skill and hustle to obtain, uh, these jobs, of course. But the good news is that cybersecurity professionals can look forward to extremely competitive salaries. That's why InfoSec has leveraged 20 years of industry experience drawing from multiple sources to give you cyberwork listeners an analysis of the most popular and top paying industry certifications. You can use IT to navigate your way to a good paying cybersecurity career. So to get your free copy of our Cybersecurity Salary Guide ebook, just click the link in the description below. It's right there near the top, just below me. You can't miss it. Click the link in the description and download our free Cybersecurity Salary Guide ebook. Your Cybersecurity journey starts here. Now let's get the show started. Welcome to this week's episode of the Cyber Work Podcast. I'm your host Chris Sanko. My guests are a cross section of cybersecurity industry thought leaders. Our goal is to help you learn about cybersecurity trends and how those trends affect the work of infosec professionals, as well as leaving you with some tips and and advice for breaking in or moving up in the cybersecurity industry. My guest today, Will Sweeney, is the founding and managing partner of Xaviant. Before starting the firm in 2016, he held leadership roles at companies including KPMG, Comcast and IBM, gaining valuable experience overseeing complex information security audits and data privacy compliance for much of the Fortune 100. Today, Will leads Xaviant's ever growing team of data privacy and security experts who serve as trusted advisors to some of the nation's most prominent enterprises. Will has been featured in the Philadelphia Business Journal, 40 under 40 and Titan 100 lists and is an active member of the Forbes Technology Council. Additionally, he is frequently published and quoted in the media for his industry expertise. When not working at xaviant, Will is involved in a number of community and philanthropic initiatives, including the Giorgio Foundation, Irish American Business Chamber Network, the Centennial Education foundation, the Uncommon Individual foundation, and the Union League of Philadelphia's Legacy Foundation. So today we're going to be talking data privacy and GRC and whatever else comes up today. So Will, thanks for joining me and welcome to Cyber Work.

Speaker B: Hey Chris, thank you so much for having me. Look forward to the conversation today.

Speaker A: Absolutely. Same here. So, uh, so Will, let's start, uh, about your early years. Do you remember what the initial spark was that got you excited about tech cyber security?

Speaker B: Yeah, so I, um, was really lucky at an early age for, uh, my dad, who knew, uh, nothing about computers. He was a, uh, H VAC and plumbing technician. Um, he knew that computers were going to be important, so he went out and bought me a computer at a very early age. I, um, remember it being a Packard Bell computer and just kind of, you know, doing some initial experimentation with it and trying to learn. I think at that point we were on Windows 95, maybe. I'm not even 100% sure. But, um, had a chance to learn a lot about it and just getting used to the Windows environment, um, and then just taking various courses at both my middle school and high school. Um, I can still remember I had a professor in middle school who, um, he made us memorize the keyboard. And I can still to this day I know all the keys on the keyboard and what order they go in. M And I also was really fortunate to have a teacher, uh, in high school, uh, Carolyn Fisher was her name, who, uh, let me actually build the uh, website for our high school. Um, and uh, it was kind of the first, uh, website that the high school had. And um, you know, just really started to kind of pick things up from there. And um, going to college, I built my own computer and uh, assembled the parts and things. And now that's kind of a trendy thing to do. I think a lot of people do that nowadays. But, uh, back then it was um, not. Not as common.

Speaker A: It was a leap of faith back then for sure because, yeah, you were, you were just sort of putting all these pieces together. And yeah, even now there's still, you know, doing little mismatches can really cause big problems down the line. So, yeah, that's a, that's a hard challenge. Now, Um, I want to back up a couple of things there, uh, when you were, uh, asked to do the school's website, was it, Were you already sort of learning HTML or was this like a real big leap of faith in terms of like, oh, I have to, I have to learn how to do this now. But they just sort of were like, you're, you know, you're a computer guy. Why don't you do it?

Speaker B: Yeah, a little bit of both. Um, I did, I did spend some time learning about HTML and, you know, just some basic, uh, tags and things like that and how to structure a website. And um, I took to that pretty quickly. Um, but back then we were using a product called, um, Dreamweaver. Um.

Speaker A: Oh, yeah, that's why I learned on too. Nice.

Speaker B: Yeah, so I started building with Dreamweaver and then learned a little bit about, um, Flash Script and I think it was called ActionScript back then. Um, so started learning about the ActionScript language and then, um, built the website from there. And looking back at it, I mean, you can go back on the Wayback Machine and see the website, what I created back then. And yeah, um, very rudimentary. But, um, you know, it was exciting. You know, it was something that I'd never done before and I was given a really nice opportunity to do it.

Speaker A: Yeah, that is really cool. And uh, yeah, I'm in full agreement that, uh, I think, uh, of all the things I learned in high school, learning, uh, touch typing and knowing where all the keys on the keyboard are, nothing else has served me in life quite like that has absolutely cornerstone at this point. So, uh, I want to go a little forward into some of your key career roles. You started strongly in roles around it, but your interest in financing focus over the past many years has been, uh, specifically around data security, data privacy, regulation. Uh, was this, uh, an interest pivot or an opportunity pivot? Did someone sort of get you, uh, into these type of roles or was this like, more interesting to you than the sort of ITIS stuff?

Speaker B: Yeah, you know, I kind of stumbled my way into data, um, security compliance, starting at, um, kpmg doing a lot of Sarbanes Oxley and IT General Control testing, um, and then spent some time doing fisma, um, and fiscam reviews for the federal government. Um, so that was mostly kind of audit experience. And then later when I worked for IBM, um, I was in their data security and privacy, uh, practice and helping companies actually sit on the other side. So not doing the audits, but actually doing, uh, implementations and consulting engagements to help companies to comply with a variety of, uh, you know, primarily information security frameworks, so SOC 2, ISO, NIST, that kind of thing. Um, and um, kind of out of the blue, one of the partners and I were talking a little bit about uh, GDPR which um, the time was an emerging data privacy regulation that nobody really knew very much about. Um, and she said to me, she said hey listen, we think that this is going to be a big thing. We're not really sure but we'd like for you to go kind of learn about it. Um, and I started really going out there and just initially just reading and understanding the text around the GDPR and what the article said in gdpr and I pretty quickly realized that you know, this was going to be a huge problem for companies that they were going to have to comply with this regulation. It was kind of its first of its kind which carried very significant fines for non compliance. So yeah, um, you know, I knew that they were going to have to do something and it also baked in a lot of, in addition to the data privacy requirements, it baked in a lot of information security requirements as well, which I had a strong background in. Um, so honestly I think I spent probably about a year really gaining a really strong understanding of the gdpr and then shortly after started um, Xavian and went out to market thinking maybe this is an area where we can help some companies. And um, I always tell people I think I drastically underestimated the amount of work that was out there and the opportunity around helping companies comply with um, these requirements. It really was just opportunistic.

Speaker A: Nice. Uh, okay, so um, because a lot of uh, the listenership of this show is sort of trying to figure out what types of work they want to do later on. Can you draw a distinction in terms of like the actual day to day tasks between someone who's doing uh, the sort of audit versus doing the implementation. Obviously I realize they're sort of related, uh, and obviously one's a lot more hands on than the other, but what's the difference between the two?

Speaker B: Yeah, so when you're doing an audit and one of the things that I did not really like about audit was um, you would go in and conduct these assessments of these organizations and you would issue a report. Here are where all of your problems are, right? And really that's what the audit's meant to do. It's to um, yeah, we obviously want to give credit for the good things that you're doing, but we want to point out more so the gaps, right, so that you can go out and start actually remediating those gaps in Preparation for getting a clean audit opinion in the future. Um, you know, in a consulting engagement you're still doing that assessment to understand where the gaps are. But you know what I really liked about it was then taking those gaps and actually solving those problems for customers. Right where the audit was. What I didn't really like about it was um, in my experience a lot of times it wasn't that these companies didn't understand that they had problems, it's that they didn't really understand how to fix the problems. So going into that consulting setting was not only were we calling out the issues, we were actually helping to solve them. And I think that's the big difference between the two is in a consulting engagement you're really hands on sitting with the company uh, and helping to fix the issues that you've identified. Mhm.

Speaker A: And I imagine that requires a lot different background in terms of your skills or can you start from the same and diverge into the, the two different roles?

Speaker B: You know I think what's interesting is I think I probably started more so on the technical side of things and some of my, my colleagues who are auditors and I think that the, the auditors um, are typically very good at understanding the requirements and how to apply them but they may not have the technical acumen to actually go out and fix those gaps.

Speaker A: Right.

Speaker B: So I kind of started more on the technical side and then did the audit and then moved into the consulting. So I would say you're right, there's very similar skill set there. But I think it can be difficult for an auditor to bridge that gap.

Speaker A: Good to know. So you mentioned that these particular types of job uh, roles basically moved you into where you are now with Xavian Consulting. Can you talk about your current role as managing partner? Because uh, obviously this is a pretty big uh, role and a pretty big jump up and you've help a lot of big time companies with their compliance and security posture. So what is, what is the work like now in, in the sort of managing partner space as opposed to the implementation that you did before?

Speaker B: Yeah, so yeah, now I'm, I'm really um, my focus is really on you know, making sure that the team understands um, the services that we're going to market and that we're providing. Making sure that we're bringing the best possible delivery to our clients. Um m going out and finding new opportunities, um, with new clients. Um, and my role has really shifted. I'm not as hands on with the delivery of the service as I once was. Although I love doing the delivery of the service. Now I'm really focused more on scaling and growing a business and my capacity as a managing partner here. Um, but in order for me to be successful in that role, I still need to be able to talk to the clients, understand the problems that they're having, understand the regulations that they're having to comply with. Uh, I'm still working very closely to make sure we have stakeholder buy in across the various levels of the business, including in the C level, um, communicating across different jurisdictions in different operating entities. Um, so that kind of shifted is, I would say more, uh, communication heavy and stakeholder heavy. Um, you know, that's kind of the big difference now is I'm not as hands on with the delivery as I once was. And I'm very fortunate because my team is really, you know, there's some really good experts on our team who are really probably at this point better than I am at doing the delivery, um,

Speaker A: without, uh, you know, obviously, uh, you know, listing out specific problems that certain clients have. But can you give me an example of some of the types of challenges that you're being asked to solve in these particular situations? Can you sort of give me some of the, like, the top level, most common, uh, you know, security regulation problems or whatever that Xaviant is working on?

Speaker B: A lot of what we're doing is helping companies to comply with things like the GDPR and the US State privacy laws, um, helping to build out third party risk management programs, um, helping companies to comply with things like the CMMC or ISO 27001. Um, and I think kind of the common theme there amongst those requirements is again, just going back, I think you really need stakeholder buy in and support across the various levels of the organization. Um, and you know, one of the things I'm doing quite regularly is helping just kind of navigate the complexity of all of those requirements and how they relate to each other and how they differ. Um, and coming at it from kind of a programmatic point of view to say maybe if we do these five things for GDPR compliance, it also helps us for US State privacy law compliance. But I would say those big themes are the uh, data privacy laws and the uh, third party risk programs and the information security requirements.

Speaker A: What are the most common hindrances to buy in? Because you would think maybe it's money, but it's not money because they're hiring you to get this thing done. So is it just the complexity of it? Is it people don't want to change? Is it uh, general exhaustion with having to sort of like figure out all these new sort of compliance regulations, where's the friction happening?

Speaker B: Usually I think a lot of it is, you know, a knowledge gap and I think a lot of it is a resource gap. So, you know, A, I think a lot of people really don't understand, you know, exactly how to go about solving these issues. And then B, even if they do understand it, a lot of times they don't think they have either the right resources or the number of resources that they need to deal with these problems. Because the reality is that complying with these requirements, it can be very resource, um, intensive and time intensive. It's not something that you just do one time, you have to do it and then you have to maintain it on an ongoing basis. So it is very resource and time intensive.

Speaker A: Yeah. Does that, I mean, do those resources involve just adding more sort of work to the workflow, more people to the pipeline, or sort of throwing money at the problem or just sort of a combination of all those things?

Speaker B: Yeah, I would say it's a combination of all of those things. Um, but you know, one of the other issues I would say is you can't take someone who's really good at uh, network engineering and have them help with, you know, complying with the GDPR or building out a data map or building out a privacy notice. They're two very different skill sets. Just as much as we can't go do network engineering and administration or IT operations, they cannot go do the same things that we can do around um, the compliance requirements. So I would say there's a big kind of, um, to my earlier point, I think there's both a resource issue from a number of resources, but really an expertise standpoint and interesting. That's an industry wide problem where I think across the industry we just don't have enough folks who really understand, um, how to deal with these problems.

Speaker A: Yeah. Now, uh, I'm assuming that most of the uh, the companies you work with, their solution is not, well, let's hire someone who is an expert in that area, but is sort of like let's upskill the people we have now is, I mean, do you have any thoughts on that? Like, like I know that we're trying to solve the, the primary problem around cybersecurity. Um, I mean we're also seeing Contractions of SOCs and security teams due to budgets, due to uh, economic circumstances or whatever. So a lot less people are asking to be done, asking to do a lot more. So where do you see this going? Um, A lot of the expertise that you need for privacy regulation or GDPR or what have you, I assume is almost a completely different person rather than like you said, the network engineers and things like that. So, um, what do you think? Is this a contractor, uh, thing? Is this like a temporary services thing? Uh, what do you think?

Speaker B: Yeah, so I think, well, first of all I would say that the software that practitioners and experts use for GRC have improved drastically in the past, for sure, five years, you know, so it's gotten a lot more efficient for people like me to be able to do my job. And there's much better tools that we can deploy which have a lot more automation. Right. So like that, that's definitely happening. Which is, which is great. And it, I think it makes, you know, the practitioners much more efficient. They can focus on the problems that maybe software isn't able to solve. Um, so I think that's a big part of what we're seeing happen. Um, and then to be honest, and maybe this sounds kind of self fulfilling here, but I really believe that um, if this is not a core competency for you or your team, I think you should outsource it. Um, it's not something where I think you can upskill someone to the extent that they can help maybe project, manage it or act as a liaison between the business and um, the subject matter expert. But I think it's very unlikely that um, someone who is not, you know, making this their core focus on a daily basis is going to be very effective. Um, so I happen to believe that, you know, again, maybe this is self fulfilling, but I do believe that outsourcing it to a firm who has a lot of subject matter expertise in this space, I just think is more cost and time effective.

Speaker A: Yeah, I think, yeah, I think, I think that's probably going uh, to be the case, uh, for the foreseeable future. Obviously uh, the skills gap is not being solved anytime soon here. So uh, what in your opinion, Will, are the most challenging data security and data privacy issues happening in the moment? I mean obviously you know what the regulations say the big ones are. But from a big picture, big stroke, uh, perspective, what are some looming threats that organizations are turning to Will Sweeney and others to address?

Speaker B: Yeah, so I think what we're seeing is there's a lot more compliance requirements that are coming along. I think you pointed that out earlier. So now we have, you know, cmmc, we've got the SEC Cyber rules, we've got um, you know, the FTC now investigating, you know, contracts law to make sure. That if companies are representing that they're compliant with something that they actually are, um, you've got, you know, breaches where companies, you know, previously, you know, represented that they were protecting data that were not. And now they're being, you know, they're on the receiving end of significant fines for the, for that. Uh, and I think that this additional complexity around the compliance requirements is going to continue to grow. Uh, and I think we're going to continue to see more enforcement, not less. Um, I think that that's something that companies are going to have to navigate. And um, one of the challenges that I think comes along with that is, uh, having to implement software that can actually go out and find and classify data in the environment, um, and determine whether or not it is in scope for some sort of, um, compliance requirement or data privacy law. I think that that's a challenge that companies have, I think they historically have not had really good governance around their data and had a good understanding of, um, where that data was. And that's extremely important for complying with any, uh, data privacy law. And if you don't know where your data is, there's no way that you can implement the appropriate security controls to protect that data. So I think that those things are going to continue to be important. Um, I think another area where I think everybody is talking about it is, um, the advent of AI and what that's going to mean for business. And I think a lot of companies now are trying to find new ways to implement AI technology and do it in a way where they're maintaining security and compliance, uh, and avoiding data loss. Um, I think there's going to be a continued emphasis around, around that. And I think, I think there was a moratorium, uh, put in place either this week or last around states introducing their own AI, uh, laws at the state level so that the Fed can kind of preempt those, those laws. And we've got the EU AI Act. And um, you know, I think that that's going to be something where, um, you know, I'm, I think there's going to be a lot more, um, emphasis placed on those types of things. So, um, you know, I think with AI specifically, um, some of the technology you could argue potentially runs counter to the data privacy laws where, uh, individuals are given the right to consent to the processing of their data. Well, have those AI technologies, um, gather that data in a way that's lawful and in compliance with law? I'm not sure, um, if someone has, you know, wants to exercise their right for an organization to go through and actually delete the data. How do we actually pull that out? Um, I'm not sure if that, if that's, if we're able to do that. Um, and so, you know, I think this kind of, there's going to, there's a little bit of, kind of a juxtaposition happening with um, you know, these emerging AI tools and the consumption of data that they need to be effective, um, and what the data privacy laws say that you have to do as an organization when you're processing data. So I think those are the big themes that I see happening now and I think will continue to be really important, um, in the next 12 to 24 months.

Speaker A: Yeah. Now, uh, you mentioned you need to know where your data is to know how to secure it and stuff. Do you have, are there any commonalities of things that you see a lot of companies need improving that kind of surprise you, like, really, you know, what you would think of as like blind spots in terms of their security posture? Are there things that a lot of companies just aren't doing or aren't thinking to do?

Speaker B: Yeah, and I think, you know, some of the basics. Right. So doing phishing training, having multi factor authentication in place.

Speaker A: Yeah.

Speaker B: Um, making sure that, you know, standard users don't have excessive privileges, like they're not local administrators or have other special privileges within the environment. Um, having a lot of service accounts with a shared password, stuff like that. I think a lot of those things seem very basic but they very often get overlooked. And um, I think fixing those particular issues that goes a very long way into maturing your security posture.

Speaker A: Oh yeah, absolutely. It seems wild to me that, that multi factor is not sort of like standard practice at this point. But it's still not for a lot of people.

Speaker B: It's not. And I think I, uh, think the statistic is something like 60 to 70% of security incidents are as, as a result of, you know, a phishing attack. I think everyone has this misconception that it's, you know, really sophisticated attackers sitting in a room somewhere launching zero day exploits. It's, it's, it's kind of brute force phishing attacks that lead to the majority of security incidents that lead to like a ransomware event or like that. So yeah, it's shocking, but you're right, it's a lot of the basics.

Speaker A: So for listeners who want to get into the work of data privacy and the sort of work that you do, what should they be working on now to make themselves more appealing to potential Employers, because like you said, I know there's a lot of new factors entering AI tools and things are pretty disrupted at the moment. Where should they be focusing their talents and interests at the moment to sort of hit this field running?

Speaker B: You know, I, I, I think spending time actually researching and learning the background of the data privacy regs, um, what's happening in that space. I think also spending time um, learning around, around something like SOC2 or ISO 27001 and understanding those concepts. I think that's a good basic understanding. Um, you know, I, I would say spend some time learning the very, the basic things that comprise those requirements. So understand what a data mapping is, understand what's important about privacy notices and consent management. Um, you know, there's a lot of really good information out there on the web and although it's very dense, I would say, you know, actually sit down and read what's in those requirements and just kind of familiarize yourself with it conceptually. Um, I think that's a good place to start and um, and do some, you know, and learn a good bit about this.

Speaker A: Yeah, I, you know, not to sort of flatten all of these big privacy, uh, platforms down, you know, too excessively. I imagine there's really kind of 10 or 20 sort of core things you need to understand and that a lot of those kind of repeat almost verbatim from uh, regulatory framework to another. Is that the case?

Speaker B: It is. And you know, I would say frankly a lot of, of what we see from other data privacy laws start from the gdpr. Right. So there's a lot of very similar concepts across the board. And then a lot of what we see from information security requirements. If you go read NIST OR ISO or CIS or SOC2, the concepts are very similar. Have an information security policy, have an access management policy, implement controls, make sure those controls are in place and that they're operating effectively over a certain period of time. So a lot of those core concepts, um, regardless of what the regulation or compliance framework is to your point, they're very, very similar across the board.

Speaker A: Yeah, that's interesting because I think it would be easy enough to want to become a master of one. Especially if you think you're going to work for a European company or you're going to work for someone in California and you just targeted on that. But if you spend more time maybe just understanding the core concepts that unite them all, then it gets you sort of like diversify your skill set by being able to kind of zigzag between these and say okay, well, this one requires this six things. This one requires these 12 things, but six of them are same from here to there. And I suppose that really makes you a lot more flexible as a potential candidate, right?

Speaker B: Yeah, exactly. And when you're talking to organizations that have to deal with those problems, you can talk about them even at a very high level, a conceptual level, like, I understand what those things are. And yeah, I think that in itself is a really good starting point for a conversation.

Speaker A: Yeah, yeah. You know, I've met some pretty amazing guitarists over the years, and the ones that say they just learned every single chord in the chord book, you know, I think get a lot further than those that, uh, just keep playing the same song over and over until they. They master it or whatever. So that's, uh. Yeah, I think that's awesome advice in terms of understanding, uh, sort of the building blocks of these. So, um, pulling back a little bit, um, you know, not to add a whole bunch of new people to your, uh, to the slipstream here. Do you have any advice for people going into data privacy regulation or GRC consultancy? So for listeners who might have an entrepreneurial itch, are there hidden challenges to getting a consultancy practice like this off the ground and taking it to a new level?

Speaker B: Yeah, you know what? I think I really, um. Everyone talks about going out and starting their own business and starting your own consulting firm and all those kinds of things. I think what people often underestimate is to really be successful, you need to be able to demonstrate to a client or potential client your expertise in that particular space. So that's obvious. You need to be really good at what you're doing. And then the other thing is you really need to be able to build a team. So once you get beyond one client or two client, maybe you get to five or ten clients, you need to be able to build a team to be able to go out and execute on those engagements. So you need to also be able to attract people to your business to come help those clients. Right. So, um, that's probably a hidden challenge, I always say. Um, I think hiring your first person or your second person is probably one of the hardest things you'll ever do when you start a business. At least for me, it was, um, and doing it at the same time as actually going out and executing on the delivery of the service. It's very, very challenging. Um, but I think if you're willing to spend the time, really gain that expertise, um, provide that thought leadership and kind of differentiate yourself to clients about what it is that you're able to bring to the table and why it's important. I think that resonates with people and I think that, um, from there it's really just kind of following through and executing at a very high level and making sure your customers are happy on a continuous basis with the work that you're providing them.

Speaker A: Okay, you said the magic word there. Uh, the hardest job you'll have to do. Can you talk about what the challenges are or any advice you have around hiring your first employee if you're starting a consultancy like that? Because that sounds like something people really are going to need to watch out for, because that's where you start. So, uh, what are some of the pitfalls involved in that?

Speaker B: Um, don't hire friends. I would say that that's an obvious one. Um, try not to hire, hire friends if you can avoid it. Obviously you don't want to, um, you know, mess up a personal relationship. That's not good. Um, and obviously you need to be also able to provide difficult feedback to people if they're not performing at the level that you need them to. Um, and it's not really nice to do that with a friend. Uh, so that's a, that's a common issue. Um, I would say, you know, you also need to be in a position where you can compensate someone, you know, equal to or above, uh, where the market says that they should be being compensated. If you can't do that, then you're going to have to probably offer them some sort of equity in the business. And, you know, people probably, you know, people view that differently. Some people are okay with that idea and some people are not. Um, you know, my particular case, my feeling was I want to be able to go out and justify a hire based off of, um, the revenue that existed in the business and not have to, um, start introducing equity into the conversation. Because I thought that that was going to be even more confusing. Um, and I think just being very specific about what your expectations are on both sides of the table. What does this person want to get out of the job? And what do you need to get, um, out of the person who's coming into your business and hopefully helping you grow the business.

Speaker A: Nice. Okay, that's, uh, yeah, excellent advice. Um, so looking to the years coming, do you. What, where do you see the state of GRC going? I mean, we mentioned AIs, LLMs. Uh, do you see more privacy frameworks mushrooming up or maybe more consolidating of the existing ones? What do you think the landscape is going to look like in say, five or 10 years.

Speaker B: I think in the US we're probably, I think it's unlikely at this point that we'll see a federal privacy law. Maybe it will happen, I'm not sure, but I think it's unlikely. I think last week I think Massachusetts introduced a new privacy law. So I think we're up to somewhere around 20 plus US states with their own individual privacy laws. I think that that trend is going to continue. Um, I know Australia right now is working on updates to its privacy protection law. Um, and we've got a myriad of other privacy regs across Europe, um, Canada and Latin America and even India and Asia and China and so on. Uh, so I think that um, this kind of dispersion of different requirements is going to continue to kind of be the same going forward. I think as it pertains to um, AI protection laws, I think that we'll probably see a more unified front on that side of things, at least in the us. I think the US probably recognizes that uh, the approach for US privacy law was maybe not the best one. And I think they're trying to get ahead of putting more sensible requirements in place around AI. And I think that's also representative of how we're viewing the risk around AI, uh, which I think is a good thing. Um, mhm. Specific to uh, the GRC role in general, I would say that the role is going to continue to evolve. I think uh, what's helpful is the software tools have really, really drastically improved over the past several years and got a lot more effective tools that we can use to help deliver solutions to customers and even manage those requirements internally. Um, I think that's very helpful and I would say probably even in these GRC tools you'll start to see the adoption of some sort of AI technology or AI agent that will help facilitate the uh, ongoing maintenance of controls and uh, requirements. I think that will help reduce the burden and introduce some additional efficiency, uh, to grc. Um, and I would say, um, you know, there's going to continue to be this issue around just a resource deficit. I think that AI is going to eliminate certain jobs. Um, but I think it's also going to, I think we're going to wind up in a very similar situation we are in now where you're going to need uh, practitioners and subject matter experts who really understand those tools to even be able to implement them and manage them. Right. So, mhm, I don't see that shifting and going away. I think this GRC function as a Whole uh, continues to be more important in the coming years. Um, and I think with new tools there's always going to need to be folks who are really well read up on how to leverage those uh, software products to help us um, be successful in this area.

Speaker A: Yeah. Now uh, as we wrap up here, we're getting close to the end of our time here. Uh, one of the sort of archetypes that you know, or people who write to us with comments and so forth is the, you know, the person who feels they're stuck in uh, help desk role or a very low level SOC role and they don't quite know what they need to do to move into more specialized areas. And yeah, like you said, I think the next 10 years it's going to be all specialization, it's going to be all um, knowledge based and a lot less sort of brute uh, rote work and so forth that goes with those type of roles. Uh, do you have any sort of um, strategies for helping someone to uh, sort of get out of these sort of lower level uh, grunt roles into something more substantive?

Speaker B: Yeah. Ah, first of all I would say a soc job or a help desk job is a great entry into this space. Um, and if you're working in one of those roles, I would say if there's a GRC function within the organization, if it's, if it's a um, if it's an industry that you're working in, I would say reach out to those folks and understand, you know, what they're doing and try to get involved as much as you can. If you're working for an MSSP or some sort of MSP and you want to kind of pivot into more of this GRC and compliance space, go out and find those free resources that are out there on Google and LinkedIn and read about them. Um, we have someone on our team who um, spent about 30 years working in uh, the fitness industry, decided that he no longer wanted to work in the fitness industry, um, started spending a lot of time learning and reading resources on Google and LinkedIn and then he went out and got a master's in cybersecurity from an online university. And he's phenomenal. I mean he's one of the best uh, folks on our team and we're very fortunate to have him. Um, so you know, but you've got to be willing to roll your sleeves up and do that work and go out and learn and talk to people and um, go out and reskill and there's a lot of great free resources out there that I would say Again, Google and LinkedIn have a lot of those. Um, and if you need to go back and pursue, uh, another degree, I would say, um, it can certainly be worth it if you can, uh, find yourself in even an entry level role in grc.

Speaker A: Yeah, yeah, yeah. That's another big part of our demographic is people pivoting later in life. And yeah, I suppose that's probably the kind of the best advice you can give is, you know, sort of just learn your way into it. You know, it's, you're not, you're not necessarily going to have experience, but you will have, I suppose, some advantage over, you know, an entry level, you know, or a student trying to apply for a job like that. Because people know you can do work. You know, uh, those 30 years in the fitness industry means, you know, I know how to come to work every day. I know how to, you know, finish a task and so forth. And I think that's, I think that's, that's as as valuable as anything. So. So one. Yeah. As we wrap up, what's, uh, what's the best piece of career advice or advice in general you ever received?

Speaker B: Um, my dad had all these like very basic maxims that um, you m. Know, I told you earlier he was a H Vac and plumbing. Plumbing guy. And I just remember working with him when I was in high school on jobs and he would always tell me like, just do the job. Right. Um, he would tell me, Murphy's Law, whatever can go wrong is going to go wrong. Um, he would say, never get too excited about the highs or too upset about the lows. Uh, so, you know, those are some very basic maxims that he gave me that have always stuck with me through the years. Mhm. And um, you know, having an opportunity to watch my dad, who ran his own plumbing, uh, business up close, he always treated the customers right. Even if they were difficult. He was always going out of his way to make sure that they were happy. And in certain cases he wouldn't charge them for work that he did just because he felt like this was someone who was going to continue to be a good customer for him in the long term. Right. So. Mhm. I think that that's really important is, um, you know, some of those very basic maxims that he shared with me and um, you know, just making sure that you're treating customers extremely well and doing the best possible job you can.

Speaker A: Yeah, great advice all around. They're called maxims for a reason. They stick around for a reason. They are always useful. As we wrap up, tell our listeners more about xaviant and the work you do.

Speaker B: Xaviant is a data security and privacy consulting firm. Uh, we help our clients navigate complex security compliance requirements and data privacy laws. Uh, we do that by building programs, processes and procedures and by implementing GRC software to support their business requirements. Uh, we specialize in things like third party risk management, uh, SOC 2 and uh, GDPR compliance.

Speaker A: Nice. All right, and one last request. Uh, here, tell our listeners where to find more Will Sweeney and Xavient online.

Speaker B: Uh, you can find us@xaviant.com and uh, I'm on LinkedIn. I spend a lot of time on LinkedIn and we also, our company's on LinkedIn as well, so follow us on there.

Speaker A: Fantastic. Well Will, thank you for your insights. And now this great privacy talk. It was a lot of fun.

Speaker B: Thank you so much, Chris. It was nice talking to you today.

Speaker A: And uh, thank you to everyone who watches, listens and writes into the podcast with feedback. If you have any topics you'd like us to cover or guests you'd like to see on the show, drop them in the comments. Uh, or make use of our YouTube community tab. We're trying to get that a lot more active. Or hey, uh, stop by our TikTok channel, InfoSec Edu. Uh, before we go, don't forget InfoSecInstitute.com free is a place where you can get a whole bunch of free and exclusive stuff for cyber work listeners, including our free cybersecurity Talent development playbook which contains, uh, in depth training plans and strategies for the 12 most common security roles, including SOC Analyst, pen tester, cloud security Engineer, information risk analyst, Privacy manager, secure coder, ICS Professional, and more. If you want to know how much a career in cybersecurity pays, get our free cybersecurity salary guide for the latest data on popular certifications and their related roles. There's also security awareness posters, ebooks, and you can sign up for 100 plus free courses, uh, for a month in our infosec skills platform. You can learn incident response, forensic security architecture and more. Uh, all of that is@infosecinstitute.com free and the link is in the description below. One last time, thank you to Will Sweeney and xaviant and thank you all for watching and listening. This, uh, is Chris Sanko signing off. Until next time, make sure to learn something new every day day. Keep one step ahead of the story and don't forget to have a little fun along the way. All right. Bye for now.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • CMMC Level 2: Documentation, Costs, and Audit Readiness | Interview with Bruno LecoqSecure & Simple · on ISO 2700189 / 100
  • The Evolution of Modern GRC ft. James Huang, Head of GRC @ GongSecurity & GRC Decoded · on ISO 2700186 / 100
  • The CUI Scoping Mistake Blows Up CMMC BudgetsTrust Issues · on CMMC (Cybersecurity Maturity Model Certification)80 / 100
  • AI and Cybersecurity in SMBs: Insights from Bruno LecoqSecuring the Realm · on ISO 2700179 / 100
  • Navigating AI Risks with Trevor Horwitz from TrustNetB2B Automation Spotlight · on ISO 2700179 / 100
  • CMMC Readiness Can’t Pause Just Because Phase 2 of the Program DidThe Government Technology Insider Podcast · on CMMC (Cybersecurity Maturity Model Certification)78 / 100

More from Cyber Work

All episodes →
  • From stealing servers to saving lives: Working in red teaming | Jim Broome69 / 100
  • Why Hackers Are Stealing Encrypted Data Now To Decrypt Later | David Close
  • Working in ransomware response, investigation and recovery | John Price
  • From "dead-end job" to CEO: Building an IT consulting business | John Hansman
  • From FBI Cyber Agent to Police Tech Innovator | Andre McGregor
Explore the best B2B Engineering & DevTools podcasts →
All Cyber Work episodes →