The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/IoT Security Podcast
IoT Security Podcast artwork

From Boardroom to Backend: Cybersecurity Tactics for Emerging Tech in Finance

IoT Security Podcast · 2025-07-01 · 34 min

0:00--:--

Amy Cheney brings nearly two decades of experience in financial services cybersecurity, risk management, and automation to discuss the intersection of emerging technologies and enterprise security. At Citi, an "AI-first bank," she describes how to structure security and policy frameworks that evolve alongside new technology implementation - sometimes requiring off-cycle approvals and agile security pathways rather than traditional pre-vetted cycles. The conversation covers how automation and visibility tools help organizations move from point-in-time assessments to continuous contextual intelligence, and how cloud computing prepared the industry for the AI wave by establishing patterns of elastic resource allocation and shared responsibility models. Cheney emphasizes translating technical risks into business impact language (reputation, financial loss, competitive advantage) when speaking with boards and executives. She recommends studying industry news, understanding each business unit's specific interests, tailoring conversations accordingly, and never attending board meetings alone. The episode is valuable for security leaders, CISOs, and emerging technology practitioners seeking to build credibility with executive stakeholders and implement security governance at scale in large financial institutions.

Key takeaways

  • →Define your business case for each technology adoption with measurable expected results and rollback thresholds, not just tool selection based on capability.
  • →Translate security risks to boards using business impact language (revenue, reputation, shareholder value) and industry precedents rather than technical terminology like 'remote code execution.'
  • →Create off-cycle approval pathways and agile security controls to move alongside rapid technology implementation, balancing risk appetite with business velocity.
  • →Position security as a competitive advantage enabler - proper data flow control and contextual intelligence can accelerate sprint velocity and decision-making for business units.
  • →Never brief executives alone; bring technical expertise to the back pocket and ensure continuity by having resources attend executive town halls and major meetings.

In this episode

  1. 1Defining AI Use Cases and Business Outcomes in Finance
  2. 2Amy Cheney's Background in Cybersecurity and Automation
  3. 3Cloud Migration as Foundation for AI Implementation
  4. 4Building an AI-First Workforce and Culture
  5. 5Evolving Security Policies Alongside Emerging Technologies
  6. 6Managing Change Control and Risk in Large Banks
  7. 7Communicating Security to the Board and Business Units

Mentioned

PhosphorusCitiBank of AmericaChaseAmy CheneyDaneRSA

Guests

Amy Cheney

Topics in this episode

Citidata loss preventionAI-first workforce strategyIdentity and access management transformationCMDB health and contextualized data taggingHolographic banking agentsChatbots vs IVR systemsOff-cycle change managementDetective and corrective security controlsCloud resource elasticity

Questions this episode answers

How should you communicate cybersecurity risks to the board and business executives?

Translate risks into business terms using the company's mission, objectives, and shareholder impact - not technical jargon - and overlay scenarios against financial loss, reputation risk, and competitive advantage. Always bring a technical resource and study recent industry news to be ready for follow-up questions.

What's the right balance between innovation speed and security controls in financial institutions?

Use risk appetite and tolerance calculations to determine which changes go through normal cycles, which need fast-track approval, and which require exceptions. A 100% locked-down change environment is unrealistic; banks need pathways to manage different risk profiles simultaneously.

How did cloud computing prepare security teams for AI adoption?

Cloud established the model of elastic, contextual resource allocation and shared responsibility for security. The same principle applies to AI: instead of one-size-fits-all security tools, organizations can now shape and blend tools dynamically based on threat evolution and business scenarios.

What's the difference between detective controls and corrective controls?

Detective controls identify issues before they cause damage; corrective controls address problems after they occur and restore systems. Both are part of a layered security strategy.

How should security policy and governance evolve when implementing new technologies like AI?

Policy describes macro-level standards and requirements, while implementation details and partnerships with vendors deliver the actual controls. In fast-moving environments, policies must sometimes go live alongside tools rather than being pre-vetted, requiring agile governance pathways.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A81%
  • Speaker B19%

Most-used words

trying18security17different15bank12information12tools11technologies11sure11environment11start10sometimes10risk9board9understand9best8scenarios8

Episode notes

Amy Chaney, SVP Technology, COO for Citi, shares a seasoned perspective on driving technological transformation and robust security in large financial institutions. The episode explores practical guidance for aligning business cases with emerging technologies like AI, highlights the importance of agile security policies, and emphasizes the critical skills needed to effectively communicate security priorities to boards and business units. Chaney underscores how fostering a balance between innovation and risk management empowers organizations to build resilience amid evolving threats and rapid tech advances. Let’s connect about IoT Security! Follow Phillip Wylie at The IoT Security Podcast is powered by Phosphorus Cybersecurity. Join the conversation for the IoT Security Podcast - where xIoT meets Security. Learn more at

Full transcript

34 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: I had 18 people in the room. We had 13 value statements on their top use case for, um, why they use AI in their company. You have to define what you're trying to do because really, you can improve anything. What is it you're trying to do and then what's the best tool to do it? Your different teams are going to use different tools. So defining that business case, just like you would define in a classic way, what's the expected result, how is it measurable? You know, how much effort can we put in until we have to roll back like a Rubicon thinking? You know, you can't just go forever on an adventure.

Speaker B: On this episode of the IoT Security Podcast by Phosphorus, I'm joined by Amy Cheney, a member of the executive cybersecurity community in the Dallas Fort Worth area. She's a cybersecurity leader and risk expert working for a large global bank. She shares her insights on how to implement, uh, technology and security in large financial institutions and shares tips and tricks on how to speak with the board and the executives and business units if you need to help improve those skills, as well as learn more about emerging technologies and how to properly implement AI and other emerging technologies. I think you're going to enjoy this episode. Hello, Amy. Thanks for taking time out of your schedule to join me today on the phosphorus IoT security podcast.

Speaker A: Yeah, glad to be here. Thanks so much for having me.

Speaker B: Yeah, I appreciate you taking time out of your busy schedule. We were trying to get you worked in during rsa was one of Dane's amazing recommendations. Uh, it's kind of funny, all the people he recommended, people that I know from the Dallas CISO community, uh, here. So it's good to finally get you on. I look forward to hearing your insights.

Speaker A: Yeah, excellent. And Dane's a good friend to the community for sure. So glad to be here today.

Speaker B: Yeah, it's good to have you. You've got a really interesting background. So, uh, for the folks that don't know you, Amy's, uh, worked in the financial industry for quite a while. She's worked, uh, in risk and cybersecurity and automation. I'm really interested to hear what you're doing on the automation, uh, and optimization stuff there, where you're at.

Speaker A: Yeah, absolutely. So right now there's so much focus on, um, how do we get the right set of curated security tools, um, at the ready and then continue to evolve that as the threat team evolves, the automation gets the complete, we'll say, visibility, uh, that not everybody always had to Manage to in the past a lot of folks are uh, managing to unfortunately assessments, spot check, point in time, information, latent information, not really contextual sensory information. So automation goes hand in hand with optimizing intel reflex, uh, and reaction and response to intel before threats develop. Um, even um, just reactive to marketplace changes or different strategies, uh very quickly is part of that total strategy. And um, it's a lot of fun to be able to work in environments that can make those moves, uh, and maneuvers and really invest in that uh, focus.

Speaker B: I'm sure because you've been in the industry for a while, I'm sure it's kind of exciting and refreshing to work in an area with the newer technologies and stuff because after a while this stuff can get boring at times.

Speaker A: Um, yeah, I tend to be on the front edge as often as I can. Kind of like uh, if you think about surfing the wave, I'm right up there on the board at the front many uh, times looking at what's uh, being developed, uh, what's coming out on the marketplace, how quickly we can understand the environments. Right now we can see environments very quickly but can we um, understand that in a contextual way to recommend what actions should or shouldn't be taken, at what time span or with what thresholds and triggers against how a company might want to operate? Is it a few additional steps? Um, we're trying to get those types of decisions, uh, as seamless, as quick and as uh, we'll say updated as quickly as we can. So that reflex to be able to be more fluid and maneuver in your environment and shape to what's happening is not dissimilar to when we think about cloud. The biggest selling strategy of cloud is it will size and shape to your workload. Right? Um, it will spin up and perform high compute when you need it, it will compress down. You don't have to have a uh, magnificently large colo data center and then three twins of it somewhere uh, in different locales anymore because now you can just borrow that power. It's not a dissimilar strategy when you start to blend a lot of these tools um, into agility and uh, changing marketplace. And it's especially important in global banks and there is none more global than my current bank which is in all, all countries basically around the globe. So we rely on these strategies.

Speaker B: So did uh, the whole move to cloud seem to help prepare you for uh, this next wave of technology with AI?

Speaker A: Yeah, it's interesting because um, I remember around 2012 um, cloud was um, the term CMT was being used a lot and um, there was a lot of concern uh, for co, ah maintained or co mingled tenancy basically. Ah, and so um, the thought was if you use the cloud that somebody else uses your information and their information can both be visible um, to the uh, cloud which is not true at all. But um, the initial concerns and risks that were being um, guardrailed against almost seem you know a little bit simple today because it's um, natural how we think about the environment. So in the same way you know there's things that we learn right at the front and we say well these questions we, we just really need to know to understand the borders or what we're talking about. Um, and then we get more fine grained with our knowledge, our understandings, um, different ways we can apply or turn on certain technologies to deal with different uh, scenes, scenarios, activities or even um, start to synchronize information. Because we understand ah, with some of these tools, especially our cloud providers, that they work across many sectors, they aggregate a lot of information and they might know more than we do about um, you know the way markets are um, shaping, responding or preparing for certain things. So that information exchange is equally important as well.

Speaker B: So with, with AI being just the, the hot topic of the day, everyone is hearing about AI, it's becoming used more and more. Uh, is there a lot of pressure within organizations to get uh, using migrating processes over and implementing AI?

Speaker A: It's a great question. There can be and there can be very successfully. Um, uh my bank Citi uh is an AI first bank. Uh, we are an AI first workforce. We say that tools uh, are available, forums are available, resources are available, you can bring cases, you can understand, understand applications, you can use AI, uh to filter even where to go in the AI help scenarios uh, that are offered. And that's becoming more common. It's not unique only to my company but um, it's becoming more common. Uh companies and teams are embracing and um, creating pathways to let employees explore, explore those business scenarios that they have but not um, to the degree where people are getting distracted from you know actually executing their role. So there's a, there's a fine, you know, there's a fine balance there between you know, having the workshops offering the tools and then also making sure people are using them and then making sure people aren't overusing them um, in lieu of the actual work. And so you know that's what it looks like today in an AI workforce, um, strategy where uh, maybe other companies might still be putting policy out about what you can, what you can't, where you should or you shouldn't put certain, you know, um, pieces of information or scenarios that might relate to something that sounds like a corporate confidential or a client asset type scenario. You of course couldn't put in a public space. And so some companies are still defining those boundaries for their employees. Some companies are fully embracing and blending AI ah technologies into we'll say even uh, contest like environments to uh, rev up and ramp up what used to be yesterday's operation and um, the streamlined, efficient operation of the future to usher that in.

Speaker B: I can imagine that chatbots could really help uh, kind of change and improve upon uh, the old IVR systems where people would call up to get bank balances or to get help and just kind of, I'm sure it's kind of such an improvement over those old systems with AI chatbots.

Speaker A: Yeah, that makes me think of the um, classic Seinfeld episode where Kramer was answering the movie phone and just giving the voice with the numbers. I mean the feeling soon will be the IVR will feel like, you know, press for, just will feel antiquated. Today it's okay to still cue in, we do that, um, that behavior won't, won't be um, a normal behavior in the future. Most likely because of the conversational nature that's coming along so quickly.

Speaker B: Yeah, that's going to be a big improvement because I don't like IVR systems myself. I like any business I'm doing business with. I like the chat bots instead because it's so much easier. It seems like with the IVR systems you have to overcome the different language dialects and accents from different folks and getting that to work and be able to hear people clearly and return response.

Speaker A: Yeah, and that's hard too. Just um, you know, individuals do have difficulty understanding each other. Uh, sometimes when they're having a direct conversation. Sometimes people say I want, I want to talk to a person. When they do talk to a person, they have trouble talking to that person. Then they want to talk to a different person. Um, and sometimes an agent or a bot, um, is much faster, much more efficient and feels more like the exchange you expected to come from a person. Um, maybe something else that's very interesting is uh, several years ago in some of the banks, um, and this is true for many of the banks, bank of America Chase, uh, lots uh, of banks have put out um, thoughts about where they're developing their technologies for consumers. Uh, specifically, um, there's holographic, uh, agent uh, type experiences where you may go to a brick and mortar and work with somebody that's not physically there with somebody that might not be a somebody. And you know there's all these different ideations that are being tested and tried and some populations and if enough, you know, enjoy this type of experience versus that they'll start to be offered in markets where um, that's a desire m. As long as it can be, you know, secure, um, represent all of the things it needs to. And um, you know it's just an evolution of how people want to do business. Um, there was a day that people didn't push their own shopping carts. You know, uh, now there's a day that we just expect it to maybe deliver at our door or our workplace or within a four hour window or something to that effect. So um, it's just adjustments and it feels very natural once we do adjust.

Speaker B: So I know you're in an environment that's very mature and you know you have worked, you guys have worked on your security for years and everything. So how important is it to have that security structure, policies and all that stuff in place when implementing new technologies?

Speaker A: Yeah, it's important um, all the way through. So the policy is meant to uh, describe at the macro level the standards are the what um, really the requirements. Um and then you get into the, how you actually do these things. And that's where the partnerships and the vendor tools often come in. And um, the delivery of certain security aspects um, is then delivered upon by you know, very large network and market that's much larger than the bank itself. And this is true for any company that works with um, third, fourth and you know, external parties to process. So the security decisions have to be um, you know, mirrored, reflected all the way through these processes. And many times that means we're not only beholden to them, we have to insure them. For companies that we don't directly manage because they're managing assets that we're responsible for which might be um, corporate, they might be um, a country, they might be um, you know, personal but they're not ours and they're not the third or fourth parties. And so we have to guarantee that security posture all the way through. So therefore um, banks have many, many layers of um, risk and compliance and legal and review and different types of partnerships and procurement. And you know we, we probably have the maximum quantity of steps you could take. Um but on the other hand um, we rarely are on tier one media outlets um comparatively to the amount of times that we're being attacked, which is all day, every day, on every possible front. You know, usually the largest threats are insiders because it's the people doing a great job or the people missing things, um, or people that are intentional, um, that create those open doors. And after all we did create all the tech as it is.

Speaker B: So how is it to uh, adding these new technologies, how hard is it to kind of uh, have your security and policies evolve with it as you're implementing uh, these new technologies?

Speaker A: Traditionally you would wait for a certain cycle, you would have things prepared, pre vetted. We, we don't always have the luxury. Um, sometimes we implement a new tool. The policies, the you know, the controls, the measures, everything has to be um, live right there with it. So we're preparing for that type of a start. Um, so there are more agile paths, um, there are off cycle paths. One um, bank I got to, and it's a major bank and a bank doing very very well. Um, when I got there 88% of their changes were happening off cycle. Uh, that's a lot. And so um, that was not the way the bank was left, um, but that's where it was starting. And that's a difficult environment because that's kind of anybody and everybody shoving things through as soon as they believe they're ready versus a more managed environment. If you have 100% managed change environment, you're really saying we respond to nothing, we've planned everything. And so that's not really likely either. So having the pathways to maneuver and know what to fast track, what to create, an exception for what to create, um, you know, a ah, longer path for uh, is always a calculation. There's a risk appetite, a risk tolerance and there's that, you know, the reality of what you do. And um, all of that doesn't matter if you're breached, you know, and so sometimes you can take a very, very strong position, uh, and sometimes there's no position strong enough. You have to include risk to do that business you have to have ports to transmit digitally. Right. Um, therefore there's a level of breachability. So it's those types of decisions going all the way down to the macro cases, the micro trends, uh, and then the megatrends. The Megatrend might be um, a two year project that puts uh, identity and access management transformation at the forefront. Therefore those controls were modernized or transformation uh for a year where uh, data is getting um, contextualized tagged environments are getting um, reviewed and flowed out and the CMDB is getting healthier. So you're going to have waves of this Health, um, hygiene type, uh, control environment that moves and then things can get thrown off. If uh, there's an acquisition, if there's a divestiture, if there's a change in business, um, you don't want to bring business into your environment unless it's we'll say sanitized, cleaned and ready. But you know, the reality is we're always um, working with a prioritization. We haven't secured everything we want to in the way we want to.

Speaker B: Yeah, I used to work in the financial industry. It was like my third IT job was working for a mortgage company. I was there like around 14 years. But it was interesting to see all the mergers and acquisitions that went on in those companies like that.

Speaker A: Yeah, for sure.

Speaker B: And it's kind of interesting too. So how's your experience been with companies? Uh, to start adopting security and really wanting to get on board because you know, I know back in the earlier days it was a lot of challenge. You had to keep things going. Of course, understandable, you had to make money. But to get buy in, to be able to implement security controls and technologies to help with that security could be a challenge at times.

Speaker A: Yeah. So I'm usually in environments that are able to um, I'll say buy their way out of a lot of problems by having the ability to um, lab, create proof of concept, ah, champion Challenger scenarios and kind of be at the front edge of the technology. People also learn in environments like that are outside of that and are attacking at that level. We'll say um, so the leading edge of the good, there's always also a leading edge of the bad. And they're usually fairly um, similarly um, capable or able. It's just depending where everybody's focused, what they're trying to do. Right. I say that to say that we're dealing with the most difficult criminals and we have probably some of the best technologists and technology minds in the world. If they're not sitting directly in our company, they're a company that we work with all the time and we're talking to them trying to solve these problems. So even in that type of environment, which allows you to maybe do as much as you can, um, we find scenarios that are brand new, um, you know, zero days of course, or just things that were unknown. Um, we find scenarios that are um, difficult to unravel because of whatever the scenario is. Maybe brittle architecture in the middle or a monolith somewhere that's just holding a lot of data we didn't recognize we had a home for and it throws a few weeks into a plan or um, months, um, prioritization issues, things like that. So it's really fun to be able to be, uh, modernizing things. It's exciting in a way. But um, when you're in security, it's almost like the excitement isn't the point. The all the possibilities of what could go wrong are the point. So you're always training your mind back to maybe you got new budget. It's not a fun, exciting time to spend. It's a time to explore those scenarios, those difficult ones that you couldn't touch before and now figure out the best way to cover them. Um, and so there's kind of a leveling off that always has to happen and normalizing and resetting of, yeah, this is how far we got. And um, always trying to rebalance um, that message. Because people will read things, they'll read a Forbes article, they'll read a, um, you know, they'll, they'll read one response, uh, to an issue plan, something like that, and they'll get an idea. We really don't know the next attack coming. So we're constantly trying to keep a lot of balls in the air. Right. So, um, it's a good environment to do it, but um, we're still going to be always looking for new technologies, new ways to transform, uh, two or three tools into one, to be frank.

Speaker B: Yeah. So I'd imagine with your, with your experience, you've probably dealt with the board a lot and dealt with the business units. What's your recommendation for building relationships with the business and the board? To be able to form that alliance to get things done, security, uh, wise and technology, you know, how to build that trust and to be able to communicate with them where they can understand. I think communication a lot of times is the issue because when the techies are speaking in geek speak and you tell them something about a remote code execution and they're going to look at you like you're speaking a foreign language. So kind of how do you deal with that?

Speaker A: Yeah, um, you know, I'll first say what not to do, what not to do is assume that something has to be dumbed down. It doesn't have to be dumbed down. It might just have to be translated. Your board understands your company, your business, their mission, their vision and objectives. If you tell them what objective is hampered by which scenario and start from there, it helps a lot. If you start with now let me make this simple for you type of feeling, it's going to come off just like how it sounded when I said it like offensive. Um, they're very intelligent, they're very uh, esteemed and uh, have experiences way beyond um, you know, what, what you might know as somebody who's going to be a presenter to them. So, so you don't assume you know any knowledge gaps. You just assume um, that you have to put it in real terms and overlay it on the company, the shareholders, if it's a publicly traded company or the customer's clients reputation, um, impact financial loss, whatever it is, um, or competitive advantage loss and sometimes the other way around. Getting a good security play can advance. You can really um, add velocity if you understand all of your data flows um, and can turn them up and down when needed. All of a sudden you're very agile and how quickly your sprints can produce responses. So um, when you're talking to the board they have a diverse background but high knowledge. So you want to give them the uh, effects and impacts and kind of like the you know, green arrow up, red arrow down, you know, and this um, business unit or customers at large, things like that. They will always know if something major has happened in and around a company or size, uh, in the industry at large, uh, if it's made news outlets. Be ready for any questions on those types of things. It's a simple um, you know, AI click if you don't have a source, um, you know, latest headlines, condensed uh, types of things, uh as well. I recommend that now when you're working with executives, um, it's going to be their interest, their business unit. If they're an information executive and they sit over a particular business unit, um like consumer ah banking, you're going to be talking to them through that lens, um, their initiatives, their portfolio, their clients, their you know, cities, uh, jurisdictions where they're working, whatever it is, um, if it's the ciso, you're talking domains, you know, uh, this is a data loss prevention item that we can apply AI to. We can pick up all these, you know, under whatever size, filter things, run them through a smart model and tell you um, patterns we see and start to look for insider loss, um, or data replication or something. You start to put it in terms they know. But as you know once you step outside of that you're always um. It's best for us to have three questions ready to answer with a technical expert or a back pocket, but always speak in business terms. Have somebody that's reading, sitting, attending their town halls, their um, their major meetings, somebody that's uh, in that discussion as well, with you don't go alone, um, and have a resource to, if it, if it needs to be something that needs to be takeaway, take it and bring it back. So that's my, um, recommendations is very bespoke and tailored for your business. Um, very, uh, applied to your company and shareholders, for your board.

Speaker B: Yeah, it's interesting to see and especially your background having the risk background because a lot of people in security don't really speak risk. And it seems to be one of those languages that the boards and uh, executives understand over more technology specific language.

Speaker A: Yeah, yeah. Um, it's a lot of translation and timing, to be frank. Um, so if I were to say a detective control finds something before it happens. A corrective control finds, uh, whatever was damaged and solves it, fixes it, makes it whole. That makes sense with the timing preventive, keeps it from getting in your environment completely. So that timing aspect makes sense. Then, you know, if I were to say the nature of the control, it's an operational health control or it's a, um, risk prevention control. You know, that starts to make sense too. It makes sense to everybody. But that one step translation, um, you know, when you're talking to cyber, makes the least amount of sense because cyber's always trying to stop everything from the outside, always finding whatever hits on the inside. So it, to them, it's their natural life cycles. Um, so the translations aren't hard, but, um, they mean everything sometimes because if you have, uh, the experience of one or two trusted people that always seem to be able to speak to the board and get whatever they want, it's because they've cracked that code. Right. And you want to be the people that crack that code. The best way to crack it is listening to how they speak, what they talk about, what concerns them, and then just talking back in their language.

Speaker B: So do you have any good resources for someone to learn that?

Speaker A: Yeah, I mean the town halls are always helpful. Um, investor reports. If you're in a bank, if you're in a healthcare company, if you're, you know, you're publishing periodical resources, most people don't read them. If you have enough stock in your company and you get proxy votes, go actually read. Um, listen to those. It's like, Jules, you'll find it's being said at the top of the house. It's being said by all of their leaders. Everybody under that is making strategies to try to fill these things. And so, um, it's hidden in plain sight. Um, too often we try to find the next three amazing things we can do out of our uh, empowerment area, our zone of expertise, what's been granted to us within a company versus just connecting to um, efforts that are already in motion. If you connect to the efforts that are already in motion, well you'll find open arms. Uh, so that's, you know, that's, that's my tip is you'll, you'll have superpowers and skills that attach to what your company's trying to do, jump in there and be valuable there. Before um, trying to present individual ideas. It's just um, it's like a pay or dues things.

Speaker B: So one thing I was kind of curious about too. Do you have any recommendations for anyone that are, you know, since you've worked with a lot automation and uh, all this. Do you have any recommendations on AI, how to uh, securely implement AI in enterprises?

Speaker A: Yeah, you have to determine um, what you're trying to do and why you're trying to do it, then find the right um, generative, artificial, synthetic, whatever it is, types of tools. If it's a research engine like a wiki, we used to always have to go find these different things, go dig through a policy, standards, uh, and requirements and baseline pile to try to find a position on something or what we do. That's a perfect case for a language model. That's a small language model, an SLM that just has all that information constantly updated, bouncing it against every um, regulatory change, frameworks and just maintains all that for you. You know, here's what the company says. We have regulation that's gone advanced that. So these jurisdictions should be aware. And there you go. Within, you know, an hour of programming, you've solved thousands uh, of hours of time that month, um, for you know, your company. Hundreds uh, or thousands maybe depending on how big your company is. So getting into AI is finding um, a way to improve something, an innovation, a way to make something a little easier, a little simpler or more. Sure, there, there needs to be a goal. The goal doesn't have to be the same thing. I um, did a boardroom at Boston which is a big um, like education, Harvard and you know, and Cambridge, uh, and, and then a bunch of healthcare and biopharma. Right. I had 18 people in the room. We had 13 value statements on their top use case for um, why they use AI in their company. So strategies, um, to find new, you know, medicines to. So you have to define what you're trying to do because you really, you can improve anything. So what is it you're trying to do and then what's the best tool to do it. The best tool might be a machine learning, um, you know, exercise where, uh, it's looking at a lot of different exercises, looking at your company, looking at the market and determining what your best tabletops and education, you know, opportunities are in your cyber, um, threat zone. Um, it might be emerging risks, it might be, you know, what AI are you going to look for that? That's all research. Um, are you trying to do something agentic? Are you trying to up your marketing, um, and create things that people haven't seen, um, and make people turn their heads and have a response. Um, so, um, your different teams are going to use different tools. So defining that business case just like you would define in a classic way, what's the expected result, how is it measurable, you know, how much effort can we put in until we have to roll back like a Rubicon thinking? You know, you can't just go forever on an adventure. You have to have a, a product and a result, uh, you know, and test it. And sometimes it may start out, model one is not so good. Model four or five, you're going to switch over at some point. So it's worth it. You just have to determine your appetite, how much time you can put in that and the effect on the people. Um, there's a sweet spot where people can go and explore and play a little bit and motivation. The whole job gets done faster. Um, and then there's a, you know, I'm lost, I've just been playing for three weeks land you don't want to send people to. So those are my tips. Just kind of, you know, make tools available but make sure people are smart about it. They've thought about a case. They're not just going and seeing what's out there and then trying to figure out how they can use it. That's backwards.

Speaker B: I appreciate you joining Dan. Thanks for sharing all your advice and wisdom. It was very informative. I'm sure I could listen to you for 30 minutes longer or more and uh, we'll have to catch uh, up sometime locally so I can uh, pick your brain a little bit more, learn a little bit more from you is very helpful for me because being more on the practitioner side, understanding someone that knows how to communicate with the leadership and has worked those leadership roles is very valuable. So I'm sure our listeners are going to get a lot of good information from the episode. So thanks again.

Speaker A: It's been wonderful being on. I was looking forward to this for just, uh, weeks, so I'm glad we made it happen. And, um, you know, it's a tough world out there. When you have time to learn and do good and lift up your team. Definitely do it. Because sometimes, uh, you know, you wake up and it will be that tough day, and you'll need that team.

Speaker B: Great words of wisdom there. Thank you.

Speaker A: All right. Thank you so much.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • What Businesses Get Wrong About AI (and How to Fix It)Room at the Table: Building Culture by Breaking Barriers · on data loss prevention71 / 100
  • Mission-Driven Finance Leadership with Dai Shi, SVP & CFO at Mission Square RetirementThe Next CFO · on Citi55 / 100
  • Running on Empty - Why high-achievers struggle to slow down and what it takes to truly rest.Practical Product Management · on Citi55 / 100
  • Payments Brief: Jun 24, 2026Payments Brief · on Citi50 / 100
  • Lunar Launches Youth Banking App, Valley National Bank and Achieva Credit Union Make Senior Level Appointments, Wall Street Suffers Downturn as Consumer Debt Concerns Grow, & Major Banks Make Strategic Moves Into the BNPL MarketBanking on Disruption Daily · on Citi46 / 100
  • MasterCard: 28.8% Surge Potential? 04/14/26Rapid Money Radio · on Citi26 / 100

More from IoT Security Podcast

All episodes →
  • Hacking Culture, Community, and Curiosity: Evolving Security Research in a Modern World67 / 100
  • Bridging Worlds: The Evolving Landscape of IoT Security and Regulation
  • Breaking Down Barriers: Making IoT and Hardware Hacking Accessible to All with Andrew Bellini
  • Building IoT Trust: Budgeting, Community, and the Hacker Mindset with Ted Harrington
  • Breaking In to Break Things: Practical Paths to Hardware Hacking and IoT Security
Explore the best B2B Engineering & DevTools podcasts →
All IoT Security Podcast episodes →