The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Wake Up by Veeam
Wake Up by Veeam artwork

The Data Residency Gap: Policy, Practice & True Understanding | Wake Up S02E08

Wake Up by Veeam · 2026-04-30 · 26 min

0:00--:--

Key moments - from our scoring

Substance score

39 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality7 / 20
Guest Caliber12 / 20
Specificity & Evidence6 / 20
Conversational Craft6 / 20

Jan Declercq, Chief Technology Officer for Cyber Services at HPE, joins Rick Vanover to examine the critical gaps between data governance policy and operational reality. The episode centers on three interconnected challenges: organizations lack visibility into their data inventory and classification, data sovereignty extends far beyond simple data locality to include regulatory compliance and third-party risk management, and leadership teams often make assumptions about their security posture without rigorous evidence. Declercq emphasizes that data resilience requires a holistic approach spanning technical controls, people, processes, and continuous governance-risk-compliance (GRC) management. The conversation addresses how cloud-native applications, distributed teams, and emerging AI systems complicate data residency decisions, using real examples like the Safe Harbor Act's government access provisions and follow-the-clock operational models. For B2B operators managing hybrid or multi-cloud environments, this episode provides actionable frameworks: implementing permanent GRC offices, conducting regular tabletop exercises and recovery drills, mastering third-party risk assessment, and maintaining both analog and digital backup procedures. The discussion clarifies why immutability, firewall hygiene, and patch management remain foundational, while acknowledging AI's potential to address the critical shortage of cybersecurity expertise.

Key takeaways

  • →Organizations typically lack complete visibility into where their data resides, how it's used, and how it's secured, creating fundamental vulnerabilities that must be addressed before implementing AI initiatives.
  • →Data sovereignty is far more complex than data locality and includes legal, operational, and third-party risk factors - organizations must understand who can access their data, when, and through which geographic and organizational boundaries.
  • →Mature cyber resilience requires continuous risk management through a permanent GRC office and regular tabletop exercises and recovery drills, not one-time implementations or assumptions made by C-level leadership.
  • →Third-party risk management represents a critical gap where organizations lack insight into components and services provided by external vendors, creating attack vectors that threat actors exploit.
  • →AI can help address the cybersecurity skills shortage and knowledge gaps, but organizations must verify technical claims in security solutions and maintain basic controls like updated firewall rules, patching, and analog backups.

In this episode

  1. 1Understanding Data Security and the Awareness Gap
  2. 2Data Sovereignty vs Data Locality: Complexity Beyond Storage Location
  3. 3Third Party Risk Management and Application Architecture Challenges
  4. 4The Human Cost of Cyber Expertise and AI as a Solution
  5. 5GRC Frameworks and Governance as Continuous Process
  6. 6Importance of Drills, Playbooks and Returning to Basics

Mentioned

VeeamHPESecurity AIRick VanoverJan DeclercaDigitalVeeam IntelligenceData Resilience Maturity ModelXDR

Guests

Jan Declerca

Topics in this episode

Third party risk managementXDR (Extended Detection and Response)GRC (Governance, Risk and Compliance)Data sovereigntyTabletop exercisesRansomwareData Resilience Maturity ModelAI and Agentic AIData Classification and LabelingImmutability

Questions this episode answers

What is the difference between data sovereignty and data locality?

Data sovereignty is much broader than data locality. While locality focuses on where data is physically stored, sovereignty encompasses legal issues (like US Safe Harbor government access), remote access patterns, billing data flows, and operational complexity from distributed cloud architectures and third-party components. Simply storing data in one country does not guarantee sovereignty if data can be accessed by foreign governments or uncontrolled instrumentation processes.

Why do organizations struggle with data security and resilience according to HPE's experience?

Most organizations lack visibility into their data inventory, don't know where data is stored or how it's used, and skip data classification and labeling. Additionally, C-suite and CISO-level leadership often make assumptions without real evidence and lack comprehensive oversight, resulting in gaps between assumed and actual security posture.

What does a mature approach to data resilience require?

Data resilience requires continuous governance-risk-compliance (GRC) management covering technical controls, people, processes, trained incident response teams, documented playbooks, regular tabletop exercises and recovery drills, and a risk-centric approach that evolves continuously rather than a one-time implementation.

What are common policy gaps HPE sees with data sovereignty implementations?

Organizations often underestimate the complexity of cloud-native architectures where application components are distributed across platforms and geographies, don't understand what third parties are actually processing their data, lack third-party risk management processes, and don't account for instrumentation or billing data flowing back to cloud providers.

How can AI help address the cybersecurity expertise gap?

While there is a significant shortage of specialized technical security profiles, agentic AI tools can help fill some gaps by providing context and accelerating threat detection and response, though human oversight and verification remain critical to avoid over-reliance on AI systems.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

The episode contains a few genuinely useful points - the sovereignty-vs-locality distinction, the XDR detection gap for bring-your-own-encryption-key attacks, and the Lego-model supply chain risk - but large stretches are filler, product promotion, and generic security truisms that any practitioner would already know.

data sovereignty is confused with uh, data locality or knowing where your data is stored. But data sovereignty is much broader, much more complex than that
But then how would you handle, for example, if the malware brings its own encryption key? So they cannot detect that.

Originality

7 / 20

The XDR signed-code detection gap is the episode's one genuinely fresh technical observation; everything else - basics matter, GRC is ongoing, AI fills skills gaps - is standard cybersecurity discourse recycled without a contrarian or first-principles angle.

the way that they do this is basically they check whether there's an, an external piece of code, unsigned, that is unsigned or is not using a trustworthy certificate that is trying to access one of the local uh, encryption engines or key generation engines
we don't have monolithic applications anymore like we used to to have. It's more the Lego model with different blocks possibly hosted on different platforms in different geos

Guest Caliber

12 / 20

Jan Declerq is a legitimate 30-year practitioner serving as CTO for Cyber Services at HPE with real customer incident involvement, not a career thought-leader; however, the conversation rarely draws out depth commensurate with that seniority.

I'm the CT for Cyber Services and I'm also leading one of our sub teams that is focusing on, on integrated cyber services
last week I was involved in the evaluation of an XDR solution

Specificity & Evidence

6 / 20

A handful of anecdotes add texture - the customer with only digital playbooks, the monthly-drills customer, the Safe Harbor Act - but there are no named companies, no dollar figures, no failure rates, and no dated metrics; most claims are asserted rather than evidenced.

they only had a digital copy of their, uh, playbooks and of their SPOCs. So that was a big problem
One of our customers is doing monthly um, recovery drills, uh, tabletop exercises, which is very good. We still have customers that, that maybe m do them once a year or even worse than that

Conversational Craft

6 / 20

The host asks for one specific example on data locality, which is the episode's best moment, but otherwise leads witnesses, agrees with every claim, and devotes substantial airtime to Veeam product plugs and self-referential anecdotes rather than probing or challenging the guest.

Can you give me an example? Because I really, really love that I've got m my own perspective, but maybe one specific example where locality isn't the complete story.
I totally agree with that. And I look at what veeam's doing in the market and especially the recent acquisition of security AI

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B51%
  • Speaker A49%

Most-used words

data52veeam17organizations17important16sovereignty15resilience14today12problem12security11risk11sure10different10tricky10cyber9organization9example9

Episode notes

Knowing where your data is stored is not the same as knowing where your data is safe. In this episode of Wake Up, the podcast by Veeam, host Rick Vanover speaks with Jan De Clercq, CTO for Cyber Services at HPE, about why data sovereignty is far more complex than most organizations realize - and why the basics of cyber resilience still trip up even the most sophisticated enterprises. Together they explore why GRC is a continuous discipline, not a checkbox, how third-party risk quietly becomes the biggest gap in most security programs, and why it's better to suffer during a drill than during a real incident. Veeam is the Data and AI Trust Company, combining data protection, security, and AI to help organizations keep their data available, trusted, and recoverable across every environment. With smart protection, dependable threat detection, and trusted cyber extortion readiness and response, Veeam ensures confidence before, during, and after cyber events. #Veeam #dataresilience #WakeUpPodcast #cybersecurity #DataSovereignty #dataprotection #CyberResilience Visit the Veeam Thought Leadership Hub to see how resilience leads the way:

Full transcript

26 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign.

Speaker B: Welcome to the Wake up podcast powered by Veeam. I'm your host Rick Vanover. The Ricatron today with fresh perspectives to wake up to. I joined by Jan Declerca. Thanks for joining us Jan.

Speaker A: Thank you Rikkert and thank you for inviting me.

Speaker B: Tell me a little bit about your role. You know, great partner of Veeam. Tell us and introduce everyone to your role.

Speaker A: Well, I work in the, in the services division of hpe, uh, and I've been in the services business for quite a while. I started with this uh, company called Digital, if you remember, a long time ago. So I've been in the industry uh, for about 30 years. I've been doing a lot of customer facing stuff. Um, currently, um, I'm the CT for Cyber Services and I'm also leading one of our sub teams that is focusing on, on integrated cyber services. So basically making sure that in all the engagements that we do that security is not an afterthought, that cyber is embedded in everything that we do.

Speaker B: I love that because, and we, we chose these guests like you and some of the other guests will have this season to really challenge what you think of a brand. And Veeam's going through that as well. And you think hpe, these are some very specialized services that you and your colleagues are representing. And I think that's a really good uh, setup for the topic we're going to have today. Really talking about data and stuff to wake up to. So I'm excited for it. Now, uh, we did a little bit of pre work. You're based in Belgium but you have a global role, I take it?

Speaker A: Yeah, correct. We have a multinational team uh, of specialists around the globe focusing on different facets of security. As you know, security is a very broad area.

Speaker B: Um, yeah, and I'm convinced also that it's one of those things that security never sleeps. Everyone's on the cybersecurity team and that is something to wake up to.

Speaker A: Always new challenges, always new threats.

Speaker B: Indeed, indeed. So let's jump into it. So I've got a, I don't want to say a bold claim, but a rather strong assertion and I want your opinion on it. Challenge me on it. That you know an organization and you know you and I have plenty of stories. The challenge is that an organization's data may be untrustworthy. And if you could think about everything from cyber resiliency to their AI journey and more. What's your initial reaction to that challenge? That an organization's data may be untrustworthy?

Speaker A: I think, um, Ah, organizations. Most organizations still have a problem with data security overall. And I think it all starts with, uh, knowing what your data is, where they are, where they are stored, how they are used. So a lot of organizations still, they don't know where their data is, how it is used. That's a key problem, I think. And then after that you have, of course, the need for data classification and data labeling, which is of course missing as well, if you don't know what you have. Um, and I think that will only, that problem will only become more bigger because of the, uh, rise of AI. Uh, so AI, it consumes a lot of data and generates new data. So I think it will become even more, uh, challenging to, uh, secure your data and to know what you have.

Speaker B: I totally agree with that. And I look at what veeam's doing in the market and especially the recent acquisition of security AI, and we're at this really amazing time where our product portfolio is converging and solving some of these problems. But I honestly feel that that problem is real that you just described. However, the only practical way I think that organizations can really get their minds and their hands around the problem is with the power of AI and there's going to need to be products, there's going to need to be expertise. And I'm absolutely convinced there's going to be a combination of reactions like, aha, uh-huh, oh, wow, I didn't know that about my data, or maybe, oh, no, we're into some compliance or sensitive data situations that we didn't know about. So I think there's going to be potentially some discomfort. And in your experience, when you talk to decision makers, leaders, a, uh, board level, CISO level, do they really understand, do they really have the comfort of some of those risks of their data, their footprint, the quality of it, the security of it?

Speaker A: Well, I think, uh, there's still a lot of, uh, ignorance there, I think, in organizations, or maybe that's a bit of an extreme word, maybe I should say that they don't have enough oversight of what they have, how it is secured. And I think, uh, another key problem, I think, is that a lot of what we see today in security and in resilience is, um, sea level people. They often do make a lot of assumptions, so they don't have real evidence, um, to know whether they are data security, that data resilience is in good shape. Um, and I think that's pretty important. And it's also a very complex discipline. So data resilience is a very, very Complex, tricky thing.

Speaker B: I think that's very much in line with research that Veeam has done for many years. I'm uh, in my 16th year here at Veeam. I remember the availability gap, the data resilience gap, and so many other shortcomings of the expectations versus the reality of what's been implemented. Now this is the Wake up podcast. We're not all doom and gloom. The reality is the products, the expertise, the way forward to tackle this is out there in the market. And that's why I want to highlight some of these different perspectives. But when you talk about this gap, I think it's the best way to explain it. I think one of the ways that it's come about, there's a certain understanding of the business and the business grows and the business changes. But do you see a problem where decision makers maybe don't verify completely what they've uh, implemented or maybe represent certain parts a lot better than other? I don't want to, you know, kind of lead the witness, but that's kind of what I see. I'm just curious if that matches what you see.

Speaker A: I think it's when you want to do proper data security, data resilience, it's very important that you, that you look at the whole spectrum in a very complete holistic way. Right? I mean um, when you do data resilience you must make sure that you have uh, controls in place that uh, cover both the technical aspects, technical controls, but also the people, the process aspects. Um, in case you have an incident, it's very important that you have uh, trained exercise, people that know how to run the playbooks that you have prepared before in the best case. Some organizations don't have those playbooks, uh, unfortunately. Um, so you need to make sure that you have beforehand, uh, a very well preparation, that you are very well prepared, that you cover uh, the different controls that you need, people process technology, um, and that you think uh, that you always take uh, a risk centric approach. Uh, and risk centric is um, it's not a one time thing, it's a continuous thing that you uh, it's basically part of grc, right? Governance, risk and compliance management. So uh, governance and compliance management is not a one time thing. It's something that you must continuously evolve and maintain, uh, to make sure that exactly, for example in the AI, uh space or in the AI time that you are living, that you keep pace with the changing threats, uh, and the new challenges that come up there.

Speaker B: I think you walked right into something that's super Important to Veeam. You mentioned people, processes and technology. Now I'm going to fast forward rewind myself back to Veeam. Uh, on last year we announced the Data Resilience Maturity Model which is really uh, an important way that organizations can assess their resilience from a standards based approach.

Speaker A: And we are very closely collaborating there. Right?

Speaker B: Yeah, exactly.

Speaker A: We will have a cyber resilience workshop soon together.

Speaker B: Yeah, I like to say at Veeam, partnerships are in our DNA. And whether, you know, hpe true, uh, story one of the most longest running integrated primary storage partners actually is the single longest running organization, um, integrated primary storage partner and it's expanded to so many other things. Now we're talking hypervisors, industry standard serve servers, as well as some of the expertise around the cybersecurity practice. So yeah, definitely the maturity model will align very well there. Uh, now bringing this topic kind of home, will decision leaders kind of proceed without verifying some of their risk and take that gamble? Do you see that happen?

Speaker A: Yeah, unfortunately we see that happening. Uh, we had a huge, uh, we were involved in a huge recovery a couple of years ago where uh, we saw a lot of very basic things that were not, uh, okay, not in place. Um, very basic things like firewall, uh, rules that were out of date, systems that were unpatched. Um, also they didn't have a routine to do regular um, uh, incident testing, um, tabletop exercises. So yeah, it's definitely still a problem.

Speaker B: The basics will always get you. I talk a lot to organizations about immutability, uh, you know, securing remote access, phish awareness training, doing updates. Always.

Speaker A: Yeah, it's much more than just having a backup. Um, it's much more tricky than that.

Speaker B: So one of the other things that come up, and you know, especially now we're both on global roles, but I've realized, and you and maybe some of your nearest line colleagues deal with that a little bit more often is data sovereignty. And I'm convinced that this is one that some organizations might not give it enough priority. Uh, what's your kind of short take on sovereignty?

Speaker A: Yeah, I'm from Europe, so in Europe sovereignty is an incredibly hot topic for the moment. But it's not only Europe. I think uh, data sovereignty is hot, uh, around the globe in the current geopolitical, political climate we're living in, um, on the data sovereignty level, I think it's uh, what we often see is that data sovereignty is confused with uh, data locality or knowing where your data is stored. But data sovereignty is much broader, much more complex than that. And uh, in fact sovereignty itself is also much more complex than data sovereignty. Um, you need to look at uh, platform technological sovereignty, operational sovereignty, uh, and data sovereignty is a key part of that.

Speaker B: Can you give me an example? Because I really, really love that I've got m my own perspective, but maybe one specific example where locality isn't the complete story.

Speaker A: Well, I think uh, there are kind of different tricky aspects related to data locality. Right. There can be legal issues. So I'm sure you have heard about the um, U.S. safe Harbor act that allows access to data by the US Government, uh, data that are hosted by a cloud provider, even if it is in a secure country, in a sovereign country. Um, another problem is um, remote access. Um, yeah, we have a follow the clock model in most operational, um, uh, companies, um, where your data may be accessed depending on the time of day by uh, different geos from different geos. Uh, and related to that, there's also an issue with instrumentation data and billing data that often flow back to the mothership, call back to the mothership. So also in that area, I think locality is a pretty tricky thing to uh, enforce, which makes this whole data sovereign thing in many cases much more complex than just data locality.

Speaker B: Uh, I agree 100%. And you walked into that example perfectly, Jan, because organizations have to think end to end in the sense of, I talk to a lot of folks that in the veeam conversation, maybe they're putting backup data here. And so we're really intentional, not just about the locality, but the encryption and then who has access to it. And I love those other examples of uh, billing, follow the clock, global team of admins. Those types of things all matter and are all touch points. Is there any example of like a big policy gap that maybe, you know, you've had where when it comes to data sovereignty, like the biggest maybe surprise that people have had that they thought they were on a path. But then one very important detail came up and really changed the game.

Speaker A: Yeah, well I think another thing um, that makes this data sovereignty a bit more complex is the current application model and cloud model that is used by a lot of applications and services today. So we don't have monolithic applications anymore like we used to to have. It's more the Lego model with different blocks possibly hosted on different platforms in different geos. Um, in some cases even the uh, owners of um, the service, the application, they don't know very well that a certain component is provided by a small company in, I don't know, part of the world. And they don't have insight in all the details there. Um, and that brings me to the importance of a third party risk management. Right. So it's very important. And that's where most of the gaps are today. So a lot of organizations, they don't have enough insights in the third parties that they are using or their partners are using. Uh, and that's often how risks are introduced and gaps are introduced. And that's often used as a stepping stone then to attack um, or to compromise some of the corporate data or services.

Speaker B: So that leads me to a really important example that I want to share. I speak a lot to customers and partners, likely as you do as well. And there's a word I've made up a word, sometimes I do that. And those who know me know that explainability. And I think whether an organization is on an AI journey or on a data sovereignty initiative, having that explainability of what's been implemented I think is a massive positive way to maybe dispel any gaps between the policy and then what's, what's uh, expected, uh, from the organization.

Speaker A: And the devil is in the detail there, right? It's very important to understand every detail of your application, of the solutions that you're using. Uh, for example, last week I was involved in the evaluation of an XDR solution and uh, the vendor, they claimed that they can uh, detect uh, encryption of data. Um, and the way that they do this is basically they check whether there's an, an external piece of code, unsigned, that is unsigned or is not using a trustworthy certificate that is trying to access one of the local uh, encryption engines or key generation engines. So based on that, they detect when a ransomware, uh, encryption attack would take place. But then how would you handle, for example, if the malware brings its own encryption key? So they cannot detect that. So when you're evaluating solutions, it's very important, important that you look at all the details that you make sure that you. And that also requires I think, uh, a deep understanding of um, the attack kill chain, how they are carried out. I think in many cases you need to adopt a mindset of a hacker, uh, to make sure that you can fully understand what's happening and how you need to protect yourself.

Speaker B: And that is a wake up moment for sure. And I totally agree with you there Jan, because this aligns to what the resiliency aspect of veeam is bringing to market today. But I think there's a cost, there's a human cost. And the details, the sheer volume of information that managers um, CISOs, even you know, admins and day to day end users have to deal with there's a massive human cost for this. Uh, do you see bigger risks, uh, up the chain of uh, organizational structure or do you see everyone really absorbing this risk? What's your take on that human cost?

Speaker A: Well, I think on the human side one of the key problems still today is the shortage of expertise and experts. Um, it's hard to find certain technical profiles, uh, certainly when you are looking for very focused and specialized roles. Um, but the good thing is that hopefully uh, uh, it's already the case. I think AI will come to the rescue there. So I think AI will, uh, and certainly now in the days of agentic AI may fill some of those gaps. Um, but again we shouldn't, uh, yeah, yeah, we shouldn't over trust AI. Right. So we still need to be very confident. We need to double check and check again. Um, but I'm hopeful that that AI will fill some of the gaps there that we have today.

Speaker B: I think you're onto something. Um, I'm cautiously optimistic, um, very optimistic, but also yet cautious at the same time. Two things come to my mind. One is simply the workforce. If you look today, Generation ZED is entering the workforce is really the first AI native generation. Yes, it's an incredible set of capabilities that they have at their disposal, but they don't have decades worth of institutional knowledge. So there's a digital dependency maybe to watch out for or a blind spot or a wake up moment to be aware of. But the skills gap, the knowledge gap, that is a real thing and that's a shimmer of hope where AI can help with that. I look at what Veeam's done, everything from Veeam intelligence, putting it in several of our products to really save some time as well as give contextual information. So that's a good way to really tackle that. I really hadn't thought about AI as one of the solves for the knowledge gap, but it, it comes up a lot. But then with great power comes great

Speaker A: responsibility and that also brings other problems like, like uh, shallow AI. Yeah, these, uh, the Gen Z, they are inclined to use AI very much but in some cases beyond control of the organization. So that's, that can be tricky as well.

Speaker B: Indeed. And I think if we look at the bigger message here with Veeam, what the message we're bringing to market now is really around this third generation of risk. Right. Um, you and I both have been in the market for a long time. I grew up preparing for Fire, flood and blood. Then ransomware was the second generation cyber resiliency type initiative. And right now we're on this edge of the agentic era that has risks. We don't maybe know fully all how they may be.

Speaker A: Uh, and again I think the key thing there is data security. Right. And I think primarily data integrity and data confidentiality become more important in the age of AI.

Speaker B: Absolutely. So Jan, I want to really press in a little bit to something about how do you drive change in an organization? So if you're walking in to a decision maker today, what are some of the questions that you're going to ask that will identify the biggest opportunity to improve in this case cyber resiliency and more.

Speaker A: I think the uh, key thing that I also always fall back to is again grc, right? Does the organization have a uh, permanent GRC office in place or process to manage grc? Because if you don't have that then you have a big problem. And again I already mentioned it. It's very important that you have ongoing risk management risk assessment. Know your risk appetite that may change over the time m evaluate the new risks that are introduced with AI. Um, it's also very key that you understand your compliance requirements which is not easy today either. Um, it's the regulatory landscape is incredibly complex. Uh, certainly if you look at my region, uh, it's crazy like hell to know what applies to your business. Um, and then yeah, again this is not a one time thing. You need to govern it. You need to have a permanent process, uh, that assures that you have permanent uh, risk management, permanent compliance management, uh, in place for your entire uh, IT stack.

Speaker B: I think this is a super important maturation of the process. And I look at my own Veeam journey and it's an interesting one. I love it. Every day is like my first day. I come in with incredible enthusiasm. But I do have good remembrance of, of the history. And what really sticks out to me on is that GRC conversation. Because I'd like to say that some of the buzzwords of the past have actually come true. Take digital transformation maybe 10, 12 years ago, that's what we were talking about. Uh, uh, and we're there. And the logic is that when we have these digital entities that are driving our business, maybe even making decisions on their own, uh, and then further our business is absolutely depending on it. We can never be too far from these GRC types of requirements. And one of the things I personally like to say, uh, you've probably already figured out I make up my own Little, uh, they call them rich isms, these little phrases. But one of the things I like to say, and I'm giving this advice to folks who are on the AI journey, real simple business case, first compliance. Always never forget the business case, never. And always be aware of the compliance requirements. Real simple rule, and it protects you from so many other things. You can have compliance risks. You could have the cost model not aligned to the expectations, which is a real problem if you've already implemented it because it's too late. But I think those are, those are like some really serious questions and just a mature aspect of the technology for sure that will make the difference. And you don't need to be so hard on Europe about that. You know, the US has its own, uh, sets of standards as well. I've just found out there's a Colorado AI Act. Okay. So, you know, we have our own, uh, across the world. But I also think you might be walking into something of, let's just say the public sector is catching up with the times in a way.

Speaker A: Uh, and besides grc, I think another important thing to mention is don't forget the basics, right? I mean in data resilience, cyber resilience, um, a stupid example, a couple of years ago we had a customer, uh, that was over digitalized and when the rubber hit the road and they had this big incident, uh, they only had a digital copy of their, uh, playbooks and of their SPOCs. So that was a big problem. Right. They basically didn't have nothing, uh, to get started with the recovery. So make sure that you still have some analog in your environment.

Speaker B: I love the basics. In fact, I could write a whole book on the basics because that truly is one of those things that will be the biggest blocker. And I like to say the only way to learn how to swim is by so swimming you can't read it in a book. Uh, and the thought here is only by being comfortable with the uncomfortable going through those drills, those will be the moments that organizations can really prove that they are able to handle some of the risks in front of them. And I'll be one, one step further, Jan. A lot of times it's going to happen when the subject matter expert is hiking in the mountains and completely, uh, unavailable because the threat actors, those types of things.

Speaker A: But these drills and um, tabletop exercises are critically important. And I think it's better to suffer during an exercise than to suffer when you have a real incident. Right. Um, we have customers, ah, that have very good habits there. We have other customers have very bad habits. Uh, one of our customers is doing monthly um, recovery drills, uh, tabletop exercises, which is very good. We still have customers that, that maybe m do them once a year or even worse than that.

Speaker B: I can even confirm that that is effort worth doing. Uh, in the 2025 data resilience maturity Model we talked a lot about organizations who are mature in these things are actually, believe it or not, even more profitable and more efficient across the board. This is one of those things that truly the juice is worth the squeeze. So, so highly um, recommend organizations pressing on, uh, in that manner.

Speaker A: I fully agree.

Speaker B: Um, one more kind of broad question for you Yann. What about accountability? Anything you can add about how organizations are managing all of these scenarios, all of these details? What about accountability?

Speaker A: Well, I think uh, organizations have come a long way on the level of accountability. Um, the only issue with accountability is uh, what happens if you have something that uh, has never been experienced before, unprecedented. Um, then it becomes kind of tricky to finger point and to know who is exactly accountable. Um, I think sometimes in the resilience, data resilience space it's also very tricky because um, you have uh, different actors that need to work together. Um, ah, you have the cyber people, you have uh, the data protection officer, um, the governance people, the legal people. So it's sometimes tricky to, very tricky to come to an exact alignment of this accountability. But the good thing is that ah, uh, over the last decades I think we've come a long way. Um, most organizations, they have uh, Raci Matrix is up to date. Um, but again it may be tricky when something unprecedented happens unforeseen, um, the

Speaker B: unprecedented becomes a lot more common I think uh, is the real take, unfortunately. Uh, Jan, thank you so much for joining us here today.

Speaker A: Welcome.

Speaker B: That wraps this episode of the Wake up podcast powered by veeam. Find more episodes at a podcast platform near you and and more information@veeam.com.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Ship It Conversations: Jake Warner on Cycle.io, Bare Metal’s Comeback, and Why Private Cloud Is Getting Interesting AgainShip It Weekly · on Data sovereignty91 / 100
  • How Zalando Deployed GenAI Without Handing Attackers the Keys with Florence MottayCyber Leaders · on Ransomware87 / 100
  • Why “Cyber Is Broken”, And Building Trust in an AI World - Karl Van den Bergh CMO IllumioCyber Go-To-Market Talk · on Ransomware87 / 100
  • Security Is a Human Problem, Not a Tool Problem ft Steven Asifo, Director of Security & GRC @ YahooSecurity & GRC Decoded · on GRC (Governance, Risk and Compliance)85 / 100
  • Practice Makes Progress in Cyber Resilience with Jim Bowie, VP and CISO at Tampa General HospitalHybrid Identity Protection Podcast · on Ransomware80 / 100
  • VC10X - The AI Bottleneck Keeps Moving - Ashmeet Sidana, Founder & Managing Partner, Engineering CapitalVC10X · on Data sovereignty77 / 100

More from Wake Up by Veeam

All episodes →
  • Is Your CISO Holding You Back - Or Setting You Free? Wake Up | S02E07
  • Eroding Control: How Agentic AI Magnifies Data Trust Issues | Wake Up S02E06
  • AI Doesn't Fail. Leaders Do. | Wake Up S02E05
  • Who's Who: Securing Identity in a Synthetic World | Wake Up S02E04
  • Leading in the Dark: Resilient Decisions Amid Automation | Wake Up S02E03
Explore the best B2B Ops podcasts →
All Wake Up by Veeam episodes →