The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/Let’s Talk Data: Business Technology Podcast
Let’s Talk Data: Business Technology Podcast artwork

Securing the Gold: AI Threats, Data Visibility, and Cybersecurity Best Practices

Let’s Talk Data: Business Technology Podcast · 2026-06-08 · 40 min

0:00--:--

Key moments - from our scoring

Substance score

40 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality7 / 20
Guest Caliber9 / 20
Specificity & Evidence8 / 20
Conversational Craft7 / 20

Lisa Horwich brings her background in SAP R3 implementations and tech consulting to qualitative research, where she now interviews CISOs, data architects, and security experts about their biggest challenges. The conversation centers on how AI is simultaneously a threat and a solution in data security. Bad actors are using generative AI to craft sophisticated phishing attacks, while agentic AI compounds risks by removing human oversight. Organizations face critical data visibility problems - shadow data living on employees' laptops, data sprawl across numerous SaaS applications, and an inability to classify and protect data they can't locate. Horwich explains that most enterprises cobble together 6-10 point solutions (data loss prevention, identity and access management, privilege access management) but struggle monitoring them all simultaneously. She describes a shift toward consolidated data security posture management tools that can discover, inventory, classify, assess risk, and provide remediation guidance - ideally with AI agents wrapped around these platforms to augment stretched security teams. The research reveals customers want a single pane of glass and integrated suites rather than best-of-breed fragmentation, even as they use AI defensively to combat AI-powered attacks.

Key takeaways

  • →Data visibility is the foundational challenge preventing organizations from protecting their most valuable assets, since unclassified and unmapped shadow data cannot be secured.
  • →Agentic AI removes human oversight from decision-making, creating a new category of security risk beyond traditional prompt injection and jailbreaking vulnerabilities.
  • →Organizations are shifting from best-of-breed point solutions toward consolidated data security posture management platforms that provide unified visibility and AI-assisted remediation.
  • →Data poisoning in AI models - bad training data that produces hallucinations or inaccurate outputs - is largely undetectable in frontier models because they function as black boxes.
  • →Security teams can augment their capacity by deploying AI agents defensively to discover, classify, and monitor data across their ecosystem, effectively multiplying the coverage of small security engineering teams.

Guests

Lisa Horwich

Topics in this episode

prompt injectionAgentic AIData loss prevention (DLP)JailbreakingSAP R3AI security threatsData poisoningShadow dataData sprawlData visibility

Questions this episode answers

What is shadow data and why is it a security problem?

Shadow data is information generated and stored outside official IT infrastructure - like a spreadsheet downloaded to a personal laptop. Security teams cannot protect data they cannot see or classify, making shadow data a major vulnerability even in organizations with strong security policies.

How are threat actors using AI to improve their attacks?

Bad actors use generative AI to craft convincing phishing emails without typos or grammatical errors, and can now infiltrate company networks using sophisticated, creative attack methods that were previously impossible with manual approaches.

What is prompt injection and jailbreaking in the context of AI security?

These are techniques where attackers use specific prompts to trick AI systems into revealing passwords, confidential information, or performing unauthorized actions - demonstrated by tools like Lakera's Gandalf, which gamifies the process of exposing AI vulnerabilities.

What is data poisoning and how do security teams address it?

Data poisoning occurs when bad or unvetted data is used to train AI models, leading to inaccurate outputs and hallucinations. Organizations building homegrown AI can curate training data, but cannot verify whether frontier models were trained on clean data, since they function as black boxes.

What tools do security teams use to manage data across multiple solutions?

Organizations use point solutions like data loss prevention, data access governance, identity and access management, and privilege access management, plus consolidated data security posture management tools that discover, classify, assess risk, and provide remediation guidance across their entire ecosystem.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode surfaces several legitimate security concepts - shadow data, data poisoning, DSPM, impossible travel detection, access creep - but large portions are spent on biographical setup, defining basic terms for beginners (e.g., what qualitative research is, what MFA is), and host restatements that add no new content. The insight-per-minute ratio is materially diluted.

data visibility is one of the biggest challenges that the people I talk to run into, they don't know where the data is. And if you don't know where the data is in your organization, they can't classify it. If I can't classify it, I can't protect it
they want to secure against AI, but they're also saying I want to use AI to help my posture be better

Originality

7 / 20

The episode reprises widely circulated security doctrine - zero trust, least privilege, MFA, encrypt at rest and in transit - without a contrarian or first-principles angle. The one genuinely fresh framing is the terms-of-service red flag around silent policy changes, which is practical and underemphasised elsewhere.

My favorite red flag in terms of service is we reserve the right to change these terms of services, and you have to keep checking back. We will not notify you
identity and access is. They call it the new perimeter

Guest Caliber

9 / 20

Lisa Horwich is a credentialed B2B tech qualitative researcher who conducts primary interviews with CISOs and security architects, giving her genuine synthesis value; however, she is a researcher-about-the-field rather than a practitioner who has built or run security programs at scale, and the insights she shares are largely paraphrased from unnamed sources rather than first-hand operational experience.

I talked to a VP who said, gen AI pose a lot of risk to security in the sense that attackers are going to use them in lots of new and creative ways and are already using them
I talked to a head of cybersecurity who talked about, hey, my top security risks are exposure of private data

Specificity & Evidence

8 / 20

The episode names a handful of concrete references - SolarWinds, Anthropic's model finding vulnerabilities, Lakera AI's Gandalf tool, SOC 2, ISO 27001 - and provides a rough range of 6 - 10 tools that enterprises deploy. However, there are no hard breach statistics, no client case studies with outcomes, and all research quotes are attributed only to anonymous job titles.

There's a fun website from a company called Lakera L A K E R AI. They have tools called Gandalf that demonstrates how to jailbreak passwords. They totally gamified it
large organizations can be using upwards of 10 different tools to secure data

Conversational Craft

7 / 20

The host keeps the conversation on track and occasionally adds useful framing (the COVID/perimeter analogy), but predominantly summarises the guest's points back at length and poses leading questions rather than probing claims or introducing productive tension. There is no pushback or follow-up that forces the guest beyond prepared talking points.

Is that a fair statement?
So thinking about good posture, bad posture, there's gotta be some best practices that you can share

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C66%
  • Speaker B32%
  • Speaker A3%

Most-used words

data112security57tools20access20idea18research14posture13sure12call12tech11different11information11professionals10solutions10protect10best10

Episode notes

In this episode of Let’s Talk Data, host Daniel Dukes of SAP America is joined by Lisa Horwich, founder of Pallas Research and a leading B2B tech qualitative researcher who interviews CISOs, data architects, and security professionals to surface actionable insights for technology companies. Lisa and Daniel explore how AI is fundamentally reshaping the cybersecurity landscape- from AI-powered phishing and expanded attack surfaces to risks like prompt injection, jailbreaking, and data poisoning. They also tackle the persistent challenge of shadow data and data sprawl, where sensitive information lives outside sanctioned IT infrastructure, making it nearly impossible to classify and protect. The conversation covers the spectrum of security tools available to organizations, from point solutions to holistic Data Security Posture Management (DSPM) platforms, and closes with key best practices: zero trust, least privileged access, multi-factor authentication, and using AI defensively to combat the very threats it enables.

Full transcript

40 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: This is season 10 and this season we're focusing on the people who make data work. The data professionals shaping how businesses run. From data engineers and scientists to stewards, analysts and architects. These roles don't work in silos. They collaborate, balancing trust, governance, scale and speed to turn raw data into real impact. Because data professionals aren't just supporting the business, they're driving it forward. This season we'll explore how ideas become impact, the decisions, the day to day realities and the challenges of building data driven organizations. This is let's Talk Data. Let's talk about the work that makes data matter.

Speaker B: Hi everyone. Welcome to this next episode of the let's Talk Data podcast. This episode will especially appeal to anyone interested in data security and how that affects AI security. My name is Daniel Dukes, uh, and today I have the pleasure of talking with Lisa Horwich, founder of Palace Research, a qualitative researcher who is her time interviewing CISOs, data architects and security experts about cybersecurity, data protection and AI, and then having the pleasure of turning those conversations into actionable insights. Welcome, Lisa, to the podcast. Please tell our listeners about yourself.

Speaker C: Oh, thank you so much, Daniel, for having me on this podcast. I'm so used to being the one interviewing people that turning the tables on me is really kind of fun. So, yeah, so I am a qualitative researcher. I started out actually in the tech industry. Post when I got my MBA, I started out in doing tech and it was Y2K was the big issue. It was the late 90s, so I'm totally dating myself. There was a big push for ERP systems and I ended up going into system integration consulting for Ernst and Young. At the time, I think they were part of the big eight accounting firms who also did consulting. And a, uh, fun fact, my first big project was implementing SAP R3. So like I said, I am really dating myself from there. I ended up going into product marketing for a small software developer, worked really closely with my engineering manager, my QA manager, learned all kinds of fun terms like compiler and regression testing and really became kind of just uh, rounding out my education in tech. But how I got into market research was pretty much like most everybody of my what I say sort of generation is I fell into it. We, you know, most of us really just kind of ended up doing market research. Although nowadays it's pretty cool. There's a, there's a couple schools out there that really just focus on market research programs. It's like the University of Georgia, Michigan State University are kind of the ones who now offer programs in it. And I actually started out as a quantitative researcher. I wrote surveys and uh, mainly for large tech companies. So once again there's this sort of thematic thing is I've taken what I always said is my domain expertise and sort of learned another way to use it. So I knew a lot about tech, I didn't know a lot about market research. I didn't do a whole lot of marketing classes in college and then started doing market research studies for them. But qualitative kind of ah was another sort of avenue I took. I found numbers were interesting and I'd done a lot of statistics work. But I really found I liked talking to people. It was a lot more fun. So that's kind of how I got started. That's sort of my background of how I ended up doing what I do today.

Speaker B: Wow. So that is extremely interesting. So you went from implementing R3 and you took a journey from that point to doing qualitative research in the tech field. Let me ask you this, do you have a specialty area that maybe from your background or from your experience that you really like to focus in on?

Speaker C: Yeah, My specialty is B2B tech. It's kind of funny, I am a specialist. A lot of people in my industry are a lot more generalist. They can do cpg, consumer packaged goods, they can do finance, they can do medical. We have a lot of people who do pharma in my association. But I am one of the very few who really, really specializes deeply into B2B tech. And a lot of it is I sort of feel like I bring this credibility and most clients don't know this, but when I start out my interviews with my participants, my interviewees, I actually tell them that I have this deep background in tech, that I used to be a system integrator, I used to be in software development because it brings a lot of credibility to my conversations. Also I know a lot of the jargon nowadays and it's really useful in these studies that I do.

Speaker B: I think it's really interesting especially hearing about how you're. You specialize in qualitative research. For those that are listening that may not be familiar with that as a discipline, walk through what your day to day looks like as that type of researcher.

Speaker A: Right.

Speaker C: So a qualitative researcher, for those out there who've never heard of it, is you've probably heard of people who do focus groups and especially if you, uh, anybody used to watch Mad Men, the people behind the, behind the screen or behind the window. So we talk to people for a Living. We study people and a uh, day to day is a client will come and they have a business problem. They're trying to understand something. They're trying to understand the why. Why are people purchasing my product? What are the pain points that people are experiencing that maybe I can create a product will help them. We create a discussion guide and then we conduct either focus groups. We can do one on one interviews which I tend to do mostly and then we also can do online discussion boards. We can do all kinds of different areas and different ways to uncover that why behind the what Got it.

Speaker B: And so I know you mentioned you really specialize in the tech industry. Are there certain size companies that you target and then also are there specific roles within those companies that, that you find yourself commonly interacting with?

Speaker C: Yes, I uh, not only as a B2B tech researcher, my company, the company sizes I tend to talk to are mid market to enterprise. If they've got basically an in house IT group I tend to talk to. I did I also talk to people who outsource it and I'll talk to those, they're called managed service providers. So they provide IT services to companies. Industries. I talk to all kinds of different industries, everything from healthcare to hospitalities, a lot in financial services. And the people I talk to most, I tend to say they are decision makers. Very often it's the C suite. It is chief information officers, chief technology officers. As you mentioned earlier in my introduction, I talk to chief information security officers, the CISOs. Occasionally I do projects where I will talk to people that I will term influencers. They influence a purchasing decision. They might not be the final decision maker but they have a very influential place in that they tend to be the people I would refer to as information workers, managers, people like that.

Speaker B: Interesting. So here's a big question for you from all across these industries, all these different levels of people that you talk to within recent. Huh. How would you describe the major themes you were hearing? Are there any trends, is there anything that seems to be more important than the other?

Speaker C: Well I would sort of say security tends to be really really big these days. You know every day you hear about a data breach. Many years, a couple years ago, this ide, solar winds, these things happen, they could come very public. So my clients who often create products and solutions to help people with their security, they want to know even more like what are the exact security things that people are experiencing. Also I'll talk to companies where like their security teams are just so overworked because of this just proliferation of data breaches. And breaches and security breaches. So those companies are trying to consolidate. These people are overworked. How can they help them? Um, how can my clients create products that can help them and make their jobs easier? I kind of think that, you know, is it. Is it sort of the. The chicken and the egg? Is it that I see a lot more security things because it's out there, or is it that I do a lot of security projects so I seem to see more security? I'm not exactly sure which one is that.

Speaker B: So as we begin to unpack these security conversations that you're having, is there anything very specific that you want to dive into? For instance, AI?

Speaker C: Yeah, I mean, AI and security is a really big thing. I mean, uh, I'm not exactly sure when we're going to air this podcast, but really, like a week or two ago, you know, Anthropic released their M Mythos model, and it was able to hack and find security vulnerabilities. And these are the kinds of things that are really keeping the CISOs up at night. And really, aside from AI being hyped up in the last few years, it's also the fact that these, what we'll call these bad actors are now using AI to attack companies. So remember way back when, you could easily tell that an email was a phishing attempt because it had typos, it had bad grammar. These are really coming from countries where English was not their first language. Nowadays with AI, not only can they craft these convincing emails, they can use it to infiltrate a company's network. And I did a study about a year or two ago where I was talking to information security people about AI and security, what their concerns were. And I had a VP who said, gen AI pose a lot of risk to security in the sense that attackers are going to use them in lots of new and creative ways and are already using them. So this really brings back this idea of, uh, AI being this big threat to security professionals.

Speaker B: Let me ask you this. When you talk about AI and you're talking about the greater threat, I hear this concept of attack surface. Can you explain to me what that means or to our listeners as well?

Speaker C: Yeah. So an attack surface is just how and where somebody can infiltrate a company. So it used to be you could infiltrate just like one little area, but with everything networked and AI looking at, uh, entire companies, it's now sort of the entire information security landscape is now, uh, the ability you can attack within it. Does that answer right?

Speaker B: It does. So it sounds like, for instance, the example you just gave around Genai introducing new and additional threats. Would you say the same also holds true even for instance, as we're getting into agentic AI? So the advances in AI, are they increasing the attack surface that security professionals need to be aware of?

Speaker C: Oh, absolutely. And agentic AI introduces a different whole other host of problems, because as soon as you take the human out of the loop and you let an agent act upon your behalf, suddenly there's less oversight. Suddenly there's, uh, an inability to know what it's going to do and action upon your behal. So it definitely brings a second, you know, an additional concern.

Speaker B: So, and I think about those types of concerns and just even prepping for this podcast, I, uh, read about things like leakage and privacy concerns and hallucinations or the accuracy of responses. How are the folks that you talk to thinking about those types of concepts?

Speaker C: Oh, well, gosh, we have all, all of those risks within AI and the data, and we've talked about that, uh, attack surface and smarter attacks and defenses. But data leakage is a whole nother area where companies are worried about losing data, having their data stolen. Yeah, back to that study I did earlier, I talked to a head of cybersecurity who talked about, hey, my top security risks are exposure of private data, and that's confidential data. Data. I think that's what everybody's concerned is how are these models using my private information if I put it in there? So really, they're really worried about data leakage and having it stolen.

Speaker B: You know, I had a customer once tell me my data is almost more important than the cash in the bank. Would you, would you agree or disagree with that?

Speaker C: Oh, I totally agree with that. Um, oh, good. I can put a plug for a desert island book, as I always call it, is if you've ever read Cryptonomicon by Neal Stephenson, he introduces the concept of data being more important, being as good as gold. So if you haven't read it, I highly recommend it.

Speaker B: Yes, we'll make sure to put that in the, um, episode notes as well. So kind of thinking kind of about if we call data gold, if we recognize the value of data and how we need to secure it, and then we kind of compare that to the threats that AI is presenting. What are you seeing as some of the very specific risks that AI is now posing? Prompt injection, jailbreaking, things like that.

Speaker C: Yeah, so there's a lot of those things. So for those who don't know what prompt injection and jailbreaking, this is when somebody uses, uh, A prompt to expose the data or perform what I'll call non sanctioned actions where you can kind of hack into, you can basically get, trick the AI into revealing passwords. If, uh, you want something, uh, listeners have time. There's a fun website from a company called Lakera L A K E R AI. They have tools called Gandalf that demonstrates how to jailbreak passwords. They totally gamified it. And you can do it with agentic AI too. The other issue is this idea of data poisoning. So, and this is when bad data is used to train an AI application and it's not always malicious, it's just sometimes when you just have bad data and it's used to train and it could be just from an unvetted source. And that goes back to that hallucination and that lack of accuracy. You know, we've seen AI make stuff up. We joke in our industry there's a lot of AI tools for qualitative researchers and we've had ones that have literally made up a participant in a focus group who didn't exist and attribute quotes to them.

Speaker B: So for me, the idea of data poisoning is. The term feels new, but the concept feels common. Right? Bad data in, bad data out. What is the research? The people that you're talking to, how are they curing this poison, if you will?

Speaker C: You know, they're not. And that's part of the problem because these AI tools are black boxes. So they don't always know that it's been trained on bad data. So the ones who create their homegrown AI applications, they can curate and make sure that the data going in is good. But, um, they can't always check that a frontier model or someone has always been trained on good vetted data.

Speaker B: That is a very interesting point because we talk about hallucinations and there are times when you know, hey, that's the wrong answer, but there may be times that you, you don't know the AI is giving you the wrong answer. And that could be the result of what we're talking about right now, data poisoning.

Speaker C: Right. And that once again, the need for the human in the loop.

Speaker B: And so with that human in the loop, maybe kind of switching a little bit to talking about data now is with that human in the loop, it not only makes sure the AI is right, but also the data that's feeding the AI is right. And that kind of gets into, I think some people call it this idea of data visibility. Can you talk about that a little bit?

Speaker C: Yes. Data visibility is one of the biggest challenges that the people I talk to run into, they don't know where the data is. And if you don't know where the data is in your organization, they can't classify it. If I can't classify it, I can't protect it. So this very often happens with this idea of shadow data. And that is data that is like it's generated and it's stored kind of outside the what I'll call official IT infrastructure. This idea also data sprawl. Data's living in all kinds of different places. And if you think about all of these SaaS, applications that are out there, there's just data is living in so many places. And so for an IT security person, if I don't know where it is, I can't protect it.

Speaker B: So when you talk about shadow data, just so I understand, I would imagine a lot of IT organizations within companies, they want to have control for very valid purposes. They want to bring that data in and they want to make sure the most valuable data, their gold is locked away, is managed, is secure. But what you're saying is that despite the best due diligence that a company can do, that these most valuable pieces of data still sit on somebody's desk or is still somewhere that nobody knows about until it turns up and then something happens because of it. Is that kind of what you mean by shadow data?

Speaker C: Exactly. Um, the term shadow data, the term shadow it, it's the same thing. It's somebody in the organization saying, I'm going to go use this program because it's going to make my job easier, even if it hasn't been vetted by my IT department. And then I'm going to, or I'm going to take this spreadsheet and put it on my laptop because I want to work on it offline. Well, now that data is living on somebody's laptop versus being live, living in the SharePoint drive or wherever the IT has sanctioned it is where they can protect it. Especially if it has, you know, personally identifiable information in it, other things that might be sensitive company secrets, whatever. If an IT department doesn't have can't see it, they can't protect it.

Speaker B: Interesting. So just like you mentioned R3 earlier, I used to be an SAP user as well. And one of my things I would love to do is to download data to a spreadsheet and use it offline. But now thinking about it, that was actually extremely insecure or a shadow use. So here's my question is if that is just one example of many problems out there that Data security professionals are struggling with, with their data. What type of tools are available for them? Um, can you go into like what would somebody use to be able to put a fence around this problem and to be able to get control over all of these both centralized and uncentralized uses of data?

Speaker C: Yeah, so there's a lot, I mean there are companies out there, large organizations can be using upwards of 10 different tools to secure data. And it's kind of funny because data professionals always want like a single source of truth for their data. Security professionals want a single pane of glass to monitor to security. So if you think about if somebody's using six to 10 solutions to secure, and I'll talk about what those solutions are in just a second. Think about the fact that they're going into all of those programs and having to monitor those programs simultaneously. So we sort of say they're called consoles, which is sort of where they can view how things are going and how security is happening within the organization. But imagine you have six to eight programs open simultaneously, have to monitor all of them. So for data folks, they don't want to have to keep monitoring a bunch of different places for their data. So the types of tools, uh, I classify them in kind of two different things. One of them are called point solutions. And think about a point solution as it does one thing. I joke in my kitchen I have the one hit wonder drawer of kitchen appliances that do one thing and they do them really well. Like a juice squeezer does one thing, does it great. And for data there are things like data loss prevention tools, there's data access governance tools, there's identity and access management tools, there are privilege access management tools. These are all different tools that somehow control data or they control access to the data. So uh, that's what a point solution is, does one thing, does it really well. Then there's also this idea of a uh, consolidated data security posture management. So think, thinking about posture management is thinking about sort of how your organization is holistically taking care of their data. So they look at, they call that their security posture. It's very common in cloud. There's a cloud security posture management idea where you can look at all of the solutions using cloud. It's the same thing with data. So um, these are solutions that can discover and inventory your data, they can classify your data, they can assess the risk, they can see what kind of compliance and policy you're doing. It can look at like if something's misconfigured, especially if you've got Data in a cloud storage, could it be potentially misconfigured? And then it can also give you guidance on how to fix things, what we call remediation. So that's the idea. So like I said, we have point solutions, we have this posture management. It's kind of this intersection of uh, data loss prevention, data access governance and cloud security. Posture management, it's probably a lot of acronyms I just threw out at you.

Speaker B: It is, and the first thing that came to mind is, uh, I guess you could look at a customer and say you have really bad posture.

Speaker C: Exactly.

Speaker B: So in correcting that posture and really trying to help a customer use the proper tools to stay secure. It sounds like if I understand what you're talking about, you definitely have these points solutions which can, can lock down different aspects of security. You have this posture management which says holistically, overall, kind of uh, coordinating and orchestrating how they all work together. At the end of the day, I guess my question is, is from what, from your research and from your expertise, what does good posture actually look like? If you can kind of give a customer example, that would be great too. Or you don't have to name the customer. I'm just kind of curious is for those listening is when you bring all this together, just kind of like what should they be shooting for?

Speaker C: I can say what they should be shooting for. I can tell you what customers really want. Customers really want to minimize the number of tools. It's back to that single pane of glass. They want something that can really work across their entire ecosystem because having a whole bunch of tools that you cobble together, they don't necessarily talk to each other. So we're seeing a kind of a swing, pendulum swing from people who went best of breed. I wanted just a bunch of point solutions to fix things to now saying I want a suite of tools and within that suite of tools I want AI wrapping around to use AI for security. So it's interesting that they want to secure against AI, but they're also saying I want to use AI to help my posture be better, help me be able to discover, help me be able to organize everything into one tool or one visible pane of glass where I can see everything

Speaker B: that is really interesting about especially wrapping the AI around it. So I would imagine you hear on the news and this type of thing where you have these data breaches and they were victims of attacks that were led by agentic AI and that type of thing. And so that's AI, I guess on the offensive. But what you're saying is companies can also create in their security concept and their security strategy this idea of using AI agents for defense as well against those attackers. Is that a fair statement?

Speaker C: It is. And if you see the major security companies out there are creating tools that have AI in them, embedded in them, and AI agents to work within them,

Speaker B: that is really cool. So you may have two or three security engineers who then can deploy and even augment their workload and their expertise with thousands of agents, all to combat this increased attack surface, if you will, and to be able to cover all the areas maybe that humans by themselves couldn't. But now with agents, AI agents, they can actually supplement and actually help reinforce the security that companies are trying to do to protect this valuable thing we call data. So thinking about good posture, bad posture, there's gotta be some best practices that you can share from your research. Is there anything that stands out when it comes to securing AI, securing data that you might want to share?

Speaker C: Yeah, so there is. And a lot of it really centers around this idea of access controls. So there's a big saying out there in the security industry that I hear a lot from the people I interview and that is identity and access is. They call it the new perimeter. So way back when, uh, the network used to be the perimeter. If you weren't on the network, you didn't get access to the data, to the files. Nowadays companies use an identity or a user ID as the gatekeepers. So that's how they can control access. Then what they'll do in best practice is this idea of zero trust, where it says I don't trust you, whoever you are. So I'm only going to give you the least privileged access. I'm going to give you the minimal amount of access that you need to perform your job. You're an accountant, you get access only to financial data. You are a marketing person, you don't get access to the financial data, you only get access to the marketing data. So by segregating and giving this whole idea of the least privilege access, it really helps companies kind of protect. And the biggest problem they find out though sometimes is that people will switch departments and then companies will forget and they won't revoke access. So a lot of companies I talk to still have access creep they call it, where they carry over these permissions and then suddenly somebody has way too many permissions. So what they really want to do, you really want to limit the permissions and really keep on top of that. Also things, silly things like multi factor authentication, like don't forget to do that. There's been huge data breaches where a company literally just forgo got to do something basic like using multi factor authentication. And for those who don't know what that is, anytime you log into something and somebody sends you a security code, that's a multi factor authentication. It's giving a second way to authenticate that you are who you are. So that's kind of access controls. Any questions on that one before I kind of launch into some other ways, some other best practices.

Speaker B: Yeah, so, so I really like what you said is this idea of least privileged access. And immediately when you said it, I thought about life within Covid. Whereas we went from everybody shows up into an office, we work in a professional setting to everybody was remote. And now post Covid, it's kind of a mix. But one thing Covid did was it busted up the perimeter. And I feel like a lot of what you're talking now is how do I deal with comparison workers who may never come into an office, workers who may come part of the time. And so it sounds like this, these best practices that you're talking about really, that the thought behind them had to change when we were no longer eight to fivers in an office. But some of us are working from home, some of us are working from coffee shops. And that type of thing, that type of security concept had to evolve to be able to still keep data secure, but at the same time allow for employee, uh, mobility.

Speaker C: That did that. And another thing that they added on top of that is it could be the user id and it could also. Then they tied it to location. So it said Daniel is in, logging in from his home, that's a trusted place. But if Daniel tries to log in from home and then 10 minutes later tries to log in from someplace, let's say in Europe, well, that's what they refer to as impossible travel. So that will boot you out. So that's what companies are now tying even further, is not only the person, but where is that person and can that person really be there?

Speaker B: Gotcha. Uh, so these are great recommendations. I love this idea of identity security. But we've really got to us to think about the idea of how does not only does security apply to data, how does it apply to AI, how does it apply to both? And as we begin to kind of wind down this episode, I'm kind of wondering from your research, what are you finding that companies are doing with their data? What are you finding that they're securing in addition to these best practices?

Speaker C: Yeah, well, A couple other best practices I wanted to throw in. There was this idea of segregating your data, making sure you classify your data, making sure your data is secure and encrypted. And you want to make sure it's encrypted, like when it's in transit, when you're uploading and downloading, and also where it's at rest. But to talk about kind of what they should be doing around AI and data security and the things that they should be thinking about is really, yeah, what's happening with my data and how's it securing, being secured? How are companies, especially AI companies, what are they doing with my data? Are they training their models on my data? These are all these things that you want to think about with respect to data and AI.

Speaker B: Are, uh, they working that into like terms of services, policies, anything like that?

Speaker C: Sometimes. So I speak about this a lot in my industry, in the qualitative industry, because we have a lot of AI applications coming out. And I always tell everybody two things. What are you doing with my data? Looking at the terms of service. Terms of service is really hard to find often, but that's where they have to explicitly outline if they're using your data to train your models. You also want to look at privacy policies. How are they protecting the privacy? So I joke. Qualitative researchers, we literally violate people's privacy all the time. We go into their homes, we follow them around to see how they're shopping, all of these things. So what we get from people is so private and so important to protect. Then how is it being secured? There should be security portals where they identify and lay out security practices. I also tell people, look for certifications, are they SOC 2 compliant, which tells you that they're securely storing and processing client data. It's audited. You gotta make sure that it's being audited by a reputable Firm. Are they ISO 2701? These are information security management systems. These are all the things that I say that I remind people to look for and ask questions. What security framework is this vendor using to create? Are they using, Are they building it with app, you know, security from the start, or are they trying to wrap around security at the end? And, um, this is what organizations, you know, these are the ways we can protect ourselves.

Speaker B: Let me ask you this. If I were or kind of new to the topic, and I was looking through these terms of services, these policies, trying to figure out, hey, is this going to be a good provider for my company? Are there any red flags? Just common red flags. That I should be on the lookout for that says, hmm, m. Maybe I need to check into this more.

Speaker C: My favorite red flag in terms of service is we reserve the right to change these terms of services, and you have to keep checking back. We will not notify you.

Speaker B: You.

Speaker C: That is like the first red flag because that says, uh, if I don't know that they're going to change because. And we've had it in my industry where suddenly a big survey platform decided to change their terms of service and nobody knew and suddenly they were using data to train their models. So that's the biggest red flag that I see in the terms of service is that given that you've given them too much agency, once again using that agent term.

Speaker B: So we are getting close to the end, uh, of the episode. This has been great information on data security, AI security, those types of topics. Just want to open it up. Are there any final thoughts that you want to share? Anything that you think would be great for our listeners to hear?

Speaker C: Yeah, I talk to these enterprise IT folks all the time. And this theme that there's no shortage of tools to protect their data tends to be this idea that's like kind of a shortage of clarity. Where, where's the data living? Who's got access to it? What's my real risk? So, you know, I hear this risk and this concern all the time. And, and organizations, you know, uh, they're uh, not necessarily the ones who are doing it right, might not have the biggest budgets or the most sophisticated tools. They're really knowing they've got business leaders and it. They're speaking to each other. They're talking about risk and mitigating risk. And you know, and I love this part as a researcher is I keep uncovering like I learn what kind of tools you're using, but really the pain points underneath so that my clients can kind of create the right solutions for these people. They can craft the right messages to reach people kind of understanding their needs. It's just going to get harder and harder out there with security and with data because people realize the value of the data and companies really are working really hard to protect it.

Speaker B: You know, I think you said something really, really important that I really want to reiterate that for our listeners is that this is not something that you accomplish security. It's not something that you accomplish in a vacuum. You mentioned talk to other professionals, share stories, that type of thing. And I think there's a community aspect to security that only benefits everybody involved. So I feel like that was a Great. You know, additional thing that you pointed out is, is the more we isolate ourselves, the actual less effective I feel like we be. We can, we become.

Speaker C: Yeah, absolutely. And they all talk to each other, so. But yes, the more we can and the more we share best practices helps everybody in the industry.

Speaker B: So with that said, you know, last thing I have is, is I'm sure there's going to be some of our listeners who'd love to get in touch with you, find out about more of your research, those types of things. How can they get in touch with you? How can they, uh, get more information?

Speaker C: They can reach out to me on LinkedIn. It's Lisa Horwich. H O R W I C H you can always email me. It's Lisa palaceresearch.com P A L L A S research.com Fun fact, Palace is Athena's first name, so it's Tie. I would love to tie back that wisdom to my company name and I'd love. I'm always happy to answer. I have some articles out there that I've written about how to buy and how to think about security and data and I'm happy to share that with anyone who would to like, like it.

Speaker B: Awesome. Thank you so much, Lisa, for joining this episode. I think this is a great place for us to end and I just want to say thanks to also to everybody who's tuned in downloaded this episode. Just encourage our listeners to make sure they check out the additional resources that are in the description. And I especially want to call out our new data professionals community where data pros just like yourself can go to learn, collaborate and connect on the topic of data and even data security. Like you've heard today, more information is in the notes. And so Lisa, our listeners, thank you all again for joining and I wish you all the best. Take care.

Speaker A: Thanks for listening to let's Talk Data. If this episode sparked something for you, we want to hear about it. The questions you're asking, the challenges you're navigating, and the work you want to go deeper on. You'll find additional context and resources in the show notes. If you want to go deeper, subscribe so you don't miss future episodes episodes. And stay tuned as we continue exploring how data professionals turn ideas into impact. Uh, thank you for being part of the conversation.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Decision Logic: The Difference Between an Answer and a DecisionThe AI Forecast · on Agentic AI87 / 100
  • KYA Won't Always Protect You. The Real Risk Is the Swarm!Fintech Conversations & Insights with Efi Pylarinou · on Agentic AI86 / 100
  • Agentic AI in Sales: What Business Leaders Need to KnowScaling with AI · on Agentic AI86 / 100
  • EP284 Closest Alligator to the Canoe: How Transforming SOC Became P0 for Lloyds BankCloud Security Podcast by Google · on Agentic AI85 / 100
  • AI Is Ready for Government. Is Government Ready?The So What from BCG · on Agentic AI84 / 100
  • Beyond the Simplistic Narrative that AI will Replace Software with Mahesh RajasekharanSaaS Scaled · on Agentic AI83 / 100

More from Let’s Talk Data: Business Technology Podcast

All episodes →
  • IBM’s Cloud ERP Transformation: Driving Business Value Through HCM, AI, and Enterprise Modernization
  • SAP Analytics Cloud and IBCS: Best Practices for Executive Dashboards and Business Reporting
  • How SAP Business Data Cloud is Transforming Data Science w/ Databricks and AI
  • A Day in the Life of a Data Steward - Behind the Scenes of Trusted Data
  • Driving Business Value Through ERP Modernization: A Real Manufacturing Transformation Story
Explore the best B2B AI & Data podcasts →
All Let’s Talk Data: Business Technology Podcast episodes →