The Host Gets Hosted - Ward Balcerzak - Guardians of the Data - Episode # 53

GOTD - Flip the Script
===

Speaker 2: [00:00:00] Welcome to Guardians of the Data. I'm your host, ward Balcerzak. Each episode will explore the passions, expertise, and real world experiences of security leaders who are helping the future of data security and governance. Guardians of the data is made possible by support from Centro. To learn more about our AI powered data security platform, please visit sentra.io.

Let's dive in.

Kraig Faulkner: Welcome back to another episode of Guardians of the Data podcast. I'm Kraig Faulkner. I'm your host today. I am the field CTO at InfoLock. What does that mean? It means that I lead our pre-sales engagement, customer technology strategy, all the things around AI, which is the hottest button lately. And you're probably wondering, "Why is this guy talking to us?

This is not the normal host." Well, the reason why is because we have a special episode. This is our one-year anniversary for Guardians of the Data podcast, by Ward Balzerzak. And so today we're flipping the script. I'm gonna be the host, and Ward [00:01:00] is actually gonna be interviewed. So welcome, Ward, Field CISO at

Ward Balzerack : I'm, I'm glad to be in the hot seat, I suppose.

Kraig Faulkner: Yeah. So how's everything going with you?

Ward Balzerack : Going good. Going good. And for this very special episode, folks that are actually tuning in on video are noticing I don't have my lame background. I'm, I'm showcasing my not so messy office. I cleaned it a little bit this morning, but, uh,

Kraig Faulkner: Well,

now people can see truly...

or so, and I see a bunch back there

Ward Balzerack : they, they see how truly nerdy I am at this point, but it's okay.

I'll let the nerd flag fly on this one

Kraig Faulkner: Well, awesome. Again, 53rd episode, one-year anniversary for your award. Congratulations. Big, uh,

Ward Balzerack : Thank you

Kraig Faulkner: on that many episodes. That's a great feat.

Ward Balzerack : It's, it's been fun

Kraig Faulkner: yeah, and, you know, I think I want to start today asking the same question that you ask all your guests. How does that, how does

Ward Balzerack : All right. All right

Kraig Faulkner: So all year, you have said to guests, "In your professional opinion, [00:02:00] what is the biggest challenge that organizations are facing when it comes to data security?"

Ward Balzerack : Yeah.

Kraig Faulkner: question

Ward Balzerack : It, it is. It is. And, uh, thank you. Thank you for kicking that back to me, Kraig. Um, you know, it's a super broad question. It's made to be, and I could definitely cop out here, right? I could cop out and select any one of my great former guests, including yourself, right, answer to this question.

But I, I'm actually gonna take a slightly different approach, and I'm gonna give a broad response to the broad question. And my response is that organizations typically, not everybody, you know, I'm, I am seeing a lot more organizations, and we'll get into it, you know, starting to do this, but traditionally, organizations do not prioritize, strategize, or focus on data security, period.

Right? Hasn't been sexy. And, and there's a lot that goes into that, but that's, that's my blunt, broad answer back to you, sir

Kraig Faulkner: Let me, let me double-click [00:03:00] on something there.

Ward Balzerack : Yeah

Kraig Faulkner: do you think the focus-- I mean, I have my own answer and I think we all do, but where is the focus then, and how can we shift that?

Ward Balzerack : quite honestly, my, my answer could probably be copied and pasted across other security initiatives or really any initiative, right? Pull IT into it, whatever. And it, it's, it's a bummer. So there, there's a couple of things I think that happen. A lot of folks fall into these traps. So I think first and foremost, knee-jerk reactions, right?

This thing happens or is happening or is new, and I'm going to do a reaction to it. Um, you know, case in point, AI, right? A lot of organizations... I, I know, I know, I hate that I'm answering it back and I'm cringing at myself here, but, you know, that's just an example of a knee-jerk reaction, right? When it came out big a couple years ago, just about every organization said, "Block it.

[00:04:00] Block it all. Slam those doors shut." Knee-jerk reaction, right? Uh, another thing that I think folks fall into is, "Hey, great, you're gonna do data security." Big, big, big clapping, big gold star, but they don't hire a leader or appoint a leader to actually focus on it, right? It, it becomes somebody's hat, right?

All those hats folks are wearing. And, and you can be successful. I'm not saying you need to go out and hire me or anybody else out there that's been doing it for years, but y- you do need to focus, just, just like anything else, right? You need to focus to do good. And I think the last piece, and again, another, another broad answer here is, um, maybe they do number one and number two, right?

Maybe, maybe they don't... Sorry, they don't do number one. They don't knee-jerk. They do hire a leader, uh, but they don't dedicate resources to, to that person, that initiative. And, and resources can be money, time, people, any of those, right? And, um, that's where I [00:05:00] think many organizations struggle

Kraig Faulkner: Yeah, I think those are all really good points. They are broad, but I think they all have their place and are, you know, people are gonna know who you're talking to when they hear you say some of those things, right? So, uh, all good. Uh, let's take a step back for a second. Ward, obviously that was an opening kind of question just to set the stage, and we'll get, dive deeper into a lot of those aspects.

But little bit about yourself. I don't know if everybody knows enough about you. How long you been in the industry? Obviously I

know kind of about your background as a practitioner and things like that, but give us a little, uh, synopsis about you

Ward Balzerack : Yeah. It, it's funny, right? I've been, I've been speaking and hosting this thing for, for a year when this, this goes live, and, and folks, unless they're looking at my LinkedIn or know me personally, probably don't know much. So,

Kraig Faulkner: Yeah

Ward Balzerack : uh, like you said, and thank you, you know, I'm currently the field CISO at, at Sentra.

Um, you know, what is that? I, I get to be an advisor, right? I get to, to talk to a lot of great folks, meet a lot of great folks, do events, do this podcast, to evangelize data security and, and talk through it. [00:06:00] Um, I've been playing, learning, leading data security for going on 20 years at this point. Um, would I have guessed that that was gonna be my, my path?

Probably not, and I, I can get more into that later. But, uh, um, I've been in the large enterprise, so I worked for a defense contractor to start out my career, then I moved on into consulting. I did that, you know, large consulting and small boutique. And, uh, I've done the vendor space now twice, and, um, it's, it's been fun.

And, and I guess what, what I like to hang my hat on when, when I talk to a lot of folks is I built the data security programs at Allstate and at Fidelity National Financial, um, a- along with advising and doing the consultancy around it for others. But those are the two big ones, you know, both, uh, program build-out, technology build-out, and personnel.

Um, you know, prior to my current role, I was a people [00:07:00] leader, so

Kraig Faulkner: where do you feel the prioritization is? And I've talked about this several times, right? And I think I talked about it on your podcast and in other talks, but where do you think the prioritization is between people, process, and technology

Ward Balzerack : Oh, boy. Oh, boy. Well, I think there's where the focus... It, it is, it is, and it goes back to the whole broad piece, right? And actually I tease it out, right? You know, money, time, and people, you know, that, that can go right back to people, process, and technology. Um, you know, there's a lot of organizations I talk to, um, either in my current role or in the past or advising, and they've got a data security concern or a concern that involves data security, and that's always great.

Hey, gold star, glad you're thinking about it. If I happen to be, like, a personal customer, I'm obviously saying, "Yay, you're gonna protect my data. Awesome." Um, but what I notice in a lot of those conversations is it's a technology-first conversation. "Hey, [00:08:00] I'm doing this thing. I need to go buy a thing, or I think I need to buy a thing.

Let's talk about it." And, um, that can be the right answer, right? It can be the right answer. "Hey, I've got a gap I need to fill with technology." Um, but that's the right answer if you have the other pieces. Um, I would say first thing to prioritize on would be people or person, goes back to saying you need somebody to focus on, on data security, very quickly followed, if not in parallel, with process.

Um, I, I think my former team members have definitely heard me beat this drum quite a bit, but, but governance, audibility, you know, process documentation, it's all huge. Um, it's even more important than technology half the time

Kraig Faulkner: Agreed. One thing that's interesting to me, I was just thinking about this as you were talking, the, of these words, right? in [00:09:00] ABC order. Did we just start saying them because they're in alphabetical order, or are we not really leaning into kind of the, the reason why we put them in that order, right?

Ward Balzerack : Yeah.

Kraig Faulkner: it's really

Ward Balzerack : I've never thought about it

Kraig Faulkner: I hadn't either

Ward Balzerack : That's interesting. Yeah, I mean, it isn't... So, you know, when, when you talk to other, other leaders out there, and there's lots of good leaders out there i- in cyber and outside of cyber, and you always hear them say people, process, technology. And, you know, a lot of those same really good leaders do prioritize in, in that piece.

Um, I think where we're going, so where we are and where we're going, um, and I'm not gonna make this about AI just yet. Um, so

Kraig Faulkner: getting

Ward Balzerack : let's I know we're getting there, and that's, that's cool, right? It, it

Yeah

it is forefront in everyone's mind. But let's, let's go back five years, right? Definitely pre-commoditization of AI.

Um, a lot of [00:10:00] organizations... Actually, five years might be too much. That was COVID days where technology spend was big. Let's go following COVID, pre-AI.

Kraig Faulkner: years.

Ward Balzerack : now we're getting a little too specific here, but what, what I'm trying to get at is a lot of budgets are getting slashed out there, right? And they have been for years.

Um, there used to be really good numbers around, hey, if your IT spend is X, then your, um, you know, security spend needs to be Y. Um, I'll tell you, a lot of the organizations I've worked with and for, it's never been close to those guardrails. Never ever. And, and you, you sit there and, and you try to talk to your board, your C-suite, whatever, and say, "Hey, like, we're off by factors of whatever.

Like, we need more money. We need to do more things." And y- you never really got it, right? So you never really got the budget, um, which would go, you know, OpEx and CapEx, right? So you never really had the budget for maybe some of the tools you need. You never really had the budget for the team size [00:11:00] that you might have required for, for whatever you were trying to do.

Um, but you were still expected to move at the pace of business, um, and be able to keep up and, you know, keep everything secure and keep the bad guys out. Um-

Hasn't changed, right? That aspect has not changed. I think it goes back to the people process technology. I think, again, um, we've ignored the people piece, right? We've seen, you know, team sizes stay relatively stagnant or go down through attrition, right? Go- going down through attrition's been a real strategy for many organizations.

Um, it has, right? It has. I mean, I've, I've heard it in, in some cases, unfortunately, directly from HR in meetings like, "Hey, we're gonna reduce headcount through attrition." It's like, well, hold on.

Kraig Faulkner: Interesting

Ward Balzerack : talk about what that means. Yeah, let's talk about what that means. And, and, and obviously, I mean, just for, for the [00:12:00] listeners, like talking through that, like that can be an okay strategy if it's let's, let's get rid of the folks not pulling their weights, right?

But what I, what I've seen firsthand is you're losing the good folks through that because you're giving them more work, they're picking up the slack from others, and they're saying, "The heck with this. I'm gonna go over there, get a big bundle of cash as a sign-on or additional money, and I'm gonna have a better standard of living."

And, and unfortunately, the through attrition means you're, you're keeping some of that poorer talent at that point.

Kraig Faulkner: Grass isn't always greener on the other side though, unfortunately

Ward Balzerack : right. Right. I mean, you've seen it, I've seen it, right? That, that, that, that happens quite a bit. But, but anyways, going, going back to it, it, it's People have not dedicated the time and energy into the right things with regard to data security is, is really the bottom line

Kraig Faulkner: Yeah. So let's take those two words, data security. I want you to define them for me. What does that mean

Ward Balzerack : Oh, man

Kraig Faulkner: in the [00:13:00] day of AI now, like kinda talk about what is, you know, what do those workflows kinda look like that you advise on? What are some of the tools? Obviously, there are some new tools we've seen come out.

Yeah. Yeah

state of the industry? What does data security mean to you?

Ward Balzerack : Well, all right. I mean, you're gonna put me on a soapbox here, which I guess is great. I'm the guest. I can be on a soapbox now finally. Um, I mean, data security, I mean, bluntly is securing data, right? That's the cop-out answer. But what, what I... One of my unpopular opinions, to steal Joshua Copeland, hope you're listening, my friends.

Uh, he, he does the unpopular opinion quite a bit. Um, one of my unpopular opinions in cybersecurity is unless you're in, um, you know, could be defense like the military, or you're in, um, OT, or you're in energy, like your intellectual property is data, period. So what are you truly doing with all of your controls?

You're securing data, [00:14:00] and I, I think there's probably gonna be people that get out the pitchforks and torches and say, "Boo you, Ward," right? 'Cause they don't, they don't like data security. It's, it's been kind of, um, you know, ostracized for years up until recently. Um, sorry, sorry to tell you, your, your EDR technologies, your UEBA, your firewalls, all of that, right?

All of that has been to protect data. So, I mean, that, that's my little bit broader answer on what is data security. It is truly what everybody is doing in the organization is protecting that lifeblood. Now, when you talk about traditional data security, the controls that are actually purpose-built for, you know, hitting those documents, databases, whatever, there's a lot, right?

And there's a lot that people don't even think about. Um, when, when I go and talk to somebody about data security and I say, "Hey, I'm a data security leader," I, I usually get one of those [00:15:00] sour looks because they're thinking about DLP, right? They're thinking about data loss prevention. And, uh, um, it, it's a bummer.

I personally love DLP. I, I have for many years. It's where I started my, my data security career. Uh, but you know, the DLPs of the past, um, even some of the current, were, uh, were rotten false positives. They were hard to operationalize, and they caused business disruption, right? So, you know, DLP is, is definitely a facet of data security.

Um, you've got data discovery, data classification. You know, today that's typically wrapped into DSPM type technologies. Data identification falls into there as well. Um, and, and then you've got, you know, some of the pieces that people don't necessarily think about. You've got like, um, activity monitoring, so FAM and DAM, right?

File and database activity monitoring. Uh, sometimes you have, uh, FIM, right? Integrity monitoring or file integrity monitoring that [00:16:00] fits into that, which I don't even know if that, that's used anymore, FIM, but, uh, I remember hearing quite a bit about it years ago.

Kraig Faulkner: Yeah, I think it's kind of got wrapped into other technologies and it's kind of a component of some of the

Ward Balzerack : A- and we're seeing that, right? We're seeing that with a lot of these things that used to be individualized are, are now wrapping together. Um, but then you've got things like encryption, tokenization, um, and those technologies. That's, that's data security. Right but a lot of these... A- and there's more, right? I can go on and on around things that, that are made to, uh, protect data.

Again, it's everything. Um, but a lot of those technologies, wh- when you look at an organization, you'll see things like data discovery and DLP usually sitting in like a data protection organization. You would often see things like encryption, tokenization, and those either sitting with a wholly different group or sitting in IT or something else.[00:17:00]

Um, and then you would d- typically see like the activity monitoring solutions either sitting, you know, maybe in security engineering/SOC or, or maybe with the actual DBA organization itself, right? And they're using it for their own performance things, not really security use cases. So k- kind of going back to another issue, I'm gonna add a fourth, is, um, you know, and again, it goes back to focus, right?

You have all these disparate solutions that are great, um, they're probably being used for good, but they're not being used to their fullest because there isn't a holistic strategy around their usage in an organization

Kraig Faulkner: Those are all interesting points, Ward. Uh, I, you know, I find it very interesting that even through things you're saying, things I say on a daily basis, you know, we talk about keep the bad guys out, um, you know, DLP, these kinds of things. I would actually argue that all those tools you mentioned and that, uh, [00:18:00] defense in depth, the security stack we've all built, it's all DLP, right?

At the end

Yeah.

We're trying to prevent our data from going out. Now, some of that's keeping the bad guys away, some of that's knowing where your crown jewels are, some of that's the classification, all those things. Um, but I think at its core, you know, the now new focus, I would say refocus, I don't think anybody was ever truly focused on data before AI, but now this refocus, right, of data really matters, uh, is interesting. So

Ward Balzerack : know, I tell you, I would've argued with you on that point about 10 years ago. I would've argued with me about 10 years ago. We're both saying the same thing. I, I remember, uh, working for an organization. I was leading or I was building the data security program, and, uh, one of the leaders came to me and said, "Hey, uh, you need to own, um, basically rationalizing the firewall rules and making sure things are plugged."

I said, "Whoa, whoa, whoa. That's not... Like, my, my remit today is [00:19:00] DLP. It's a DLP project." She's like, "Well, well, that is DLP." And I remember just arguing, right? Defining here's what DLP is, but, but my arguments and my definition was based on the tooling, right? It wasn't based on the strategy, it wasn't based on the program.

Kraig Faulkner: Yeah

Ward Balzerack : Again, this was about a decade ago in my career. I wasn't as, hopefully, wise as I am today, or even as gray-haired as, as I am today. Uh, but I remember arguing against that, and it goes, again, directly against one of the points I made to you, which was you need to focus on building a program and a strategy, not just putting in a tool, which is what I was doing at the time

Kraig Faulkner: Agreed. I mean, I talk about that all the time. Obviously for everybody that knows Infolock, uh, that's what we do, right? Is that, it's that program. And so I am, I fully support you and I fully support everything you're saying, and I agree that I would've argued with myself 10 years ago as well, 'cause I'd have been like, "No, this isn't DLP.

This belongs, you know, with the firewall team," whatever.

So

Ward Balzerack : [00:20:00] know, something else I didn't mention in just going on and on about tools. It's not really a tool. There's tools in this. It's governance,

Kraig Faulkner: Ooh.

Ward Balzerack : And the idea of like a data catalog, which, you know, kind of cert- I mean, it could be your CMDB, it could be something else. So, you know, that, that is something else that I advise on quite a bit lately, where it's like, "Hey, great, you've, you've got this tool," data discovery, for example.

What the heck are you actually gonna do with it? So you're gonna get findings. Are, are you gonna pump that somewhere? Are you gonna just look at it and say, "Hey, there's a pretty report." What are you gonna do? And,

Kraig Faulkner: Yeah

Ward Balzerack : I try to tell people is like, "Hey, if you've got a CMDB that you're putting data elements in, you know, maybe risk scoring for your assets, fantastic.

Use that data discovery data either to trust but verify or populate it or both."

Yeah

or if you've just got a data catalog for like data flows and whatnot, like d- do the same. But that [00:21:00] is another piece of tooling and technology that people don't always associate with data security

Kraig Faulkner: I agree. I think we've gone a little bit, uh, I'll say tactical. I wanna switch to a little bit more strategic. Does that work?

Ward Balzerack : Absolutely

Kraig Faulkner: All right. So as an advisor, and I'm an- I'm one as well in my role, uh, boards and executive teams, how should they start measuring business risk relative to AI initiatives?

Ward Balzerack : Oh my goodness. Yeah, this is one of those big... Yeah, this is a tough one. This is a tough one. And, you know, this is, this is something I, I think no matter what conference you go to these days, big or small, there is likely a talk that is touching o- on this topic, right? Which is not, not only boards and measurement, but also just what the heck are we gonna do with AI?

And, and that's where I'm gonna start [00:22:00] my answer back to you. Um, there, there's a lot of organizations, it could be because they think it's a good idea, it could be 'cause they're getting pressure from their users, board, whatever, stakeholders or shareholders should say, that, um, we need to use AI, we need to adopt AI.

And that's great, that's noble. I think that's the right move for many organizations. But they don't bother, again, going back to knee-jerk, they don't bother sitting down and saying, "Okay, how the heck are we actually gonna use it?" All right. What are our use cases? Um, are we just getting it to be an admin assistant, right?

And take notes and assign out tasks and all that. It's a great use case, right? But that is pretty much already baked into a lot of things like Zoom and whatnot. Like, you just turn it on, you, there you go, right? You got it. Um, but, but people don't bother to really go into the trenches and say, "Hey, like, we're thinking about some AI initiatives outside of crafting emails, content, whatever.

What are you [00:23:00] gonna do? How can it make your life easier?" And I say that as the basis of my answer because I think when it goes back to measuring actual value, not getting to risks yet, but value, it needs to be what the heck are we gonna do about it? What are we trying to accomplish? And then building KPIs and other measurements around, like, did that actually come to fruition?

Did our idea of automating these things, uh, make it faster, make it cheaper, uh, make it better? And, you know, the aside to that is I think a lot of folks are finding the whole cheaper piece is, is not always the case, right? We're, we're seeing a lot of organizations that went completely both feet into the deep end on AI saying, "Holy cow, is this an expensive venture that we didn't think about."

So that's the measuring value. I think measuring value-- [00:24:00] Well, right. Right. And, and I, I equate it back to cloud adoption early on, too. When cloud first came out, the first organizations that went in just did a lift and shift for the most part, right? Let's take this thing in the data center, let's put it in the cloud, let's call it a day.

And they started getting those bills and they said, "Holy crap," right? Because they didn't do a transformation. They called it a cr- a transformation, but it was a lift and shift. So, a-and, and my, my, my forecast, it won't be as bad as cloud, but I'm g- I, I think AI's gonna happen the same thing. So with cloud, people went all in.

They said, "Oh, wait a minute." They brought things back on. Then they, like, transformed and started going back in. And that maybe happened once or twice for many organizations. I saw it firsthand, uh, twice. Um, I think some people will do with AI, right? They went all in. They're gonna say, "Oh, wait a minute. Wait a minute.

Let's pull that back. Let's have people do that stuff." And then they're gonna, like, either learn the first time and [00:25:00] tiptoe, or they're gonna make the same mistake, right? And have to do it again,

Kraig Faulkner: Insanity

Ward Balzerack : sanity, right?

Risk, that case.

well, well, well, yeah, I mean, that's the definition of insanity, right? Doing the same thing over and over, expecting different results.

Yeah. I mean, I guess if, if your AI's hallucinating, you might get different results, right?

Kraig Faulkner: gonna go down that path today, Ward. That's a, that's a different podcast, brother.

Ward Balzerack : Agreed. Agreed. Um, but, but risk A-again, I think it has to start with the use case, right? How, how and why are we gonna use this? That informs what data you're gonna give it access to, who you're gonna give it, what you're gonna do with it, which is gonna inform the risk, right? Are, are we going to be doing, um, modeling of this new thing, right?

This new thing we're producing. I'm, I'm trying to stay away from delicate subjects as I'm answering this. Um, w- again, what are we truly gonna do about it, right? Is it gonna be like low risk, you know, we're just using it [00:26:00] to, you know, check for bugs in software maybe and stuff like that? Okay, cool. Um, or, or is it gonna be higher risk where, you know, maybe we're gonna use AI to, um, you know, make, uh, first diagnoses for something, either, you know, medical or whatever.

Um, and, you know, with those, there's different data sets you have to give it access to, right? For the software, is it just gonna be your non-prod or is it gonna be your prod as well? And, um, are you gonna allow AI to take automated action based on what it finds? And are there gonna be thresholds, right? You keep on going into all these things just like we have for security initiatives for years.

So again, if you don't have use cases defined around what you're gonna do, you really can't make informed decisioning on what you're gonna give it access to, who's gonna have access, what are the anticipated outcomes to be able to actually measure risk around it. Um, you could try. [00:27:00] You could try to still do it, but it's gonna be the same thing that we've been doing for years.

It, it's guess, it's guesswork at that point. You're licking your finger, you're putting it in the wind and saying, "Oh, I think this isn't very risky."

Kraig Faulkner: So let's take a look back then. Let's take out AI and say people that did or did not have governance. you think that you can have successful AI governance if you don't have data governance without the AI first and foremost? I think

they're

it's interesting.

Right?

Ward Balzerack : Yeah, I, I think they are as well. I think it's a Venn diagram, right? I think it's a Venn diagram where, um, there, there's circular overlap for sure. So wh- when I think about AI governance, uh, for me, being very self-centered, a big part of that circle is, is data governance. And it's not just data security, but it's data as well.

It's gonna include things like, um, data accuracy, data hygiene, all, all of those other things that are not data security, but very, very data focused, 'cause that's [00:28:00] typically what AI is. Deletion, right? Data rot, age,

Kraig Faulkner: forgot

Ward Balzerack : of that stuff. Oh, yes. You, you are correct. We did forget about data deletion. That's a big one.

Um, but then you've got things that are just like, "Hey, what's the AI model you're using? What vulnerabilities might it have? Where did it come from?" Like a- again, your typical governancy type of thing. I think I just created a word on that, governancy.

Kraig Faulkner: Governancy

Ward Balzerack : governancy, right. And then, and then there's obviously data governance and data security governance.

A- again, Venn diagrams. You probably have three circles now on this, and that's gonna include like everything else essentially, because not every organization's gonna be never, I don't think, 100% AI driven. You are gonna have other things that's likely processing data, using data, and creating data

Kraig Faulkner: Yeah. Well, and me and you have talked about this several times. I don't believe that AI will ever get to that point 'cause I think there always needs to be human in the loop. Uh, the second that we just [00:29:00] our controls away, we're already... Somebody's gonna come at me with a pitchfork now. We're already bad enough at our controls, right? You know, if we just let some other right, uh, take control, uh, then we're, you know, we're in for a, a bad time, right?

So, and that's, that's an interesting point too, entities, right? We're introducing identities in a realm that we've never experienced before that's also producing data in a non-human way, right? Which requires better context understanding. Mm-hmm.

Ward Balzerack : the kind of the two groups that have always been kind of ostracized in security, 'cause they weren't sexy, right? They weren't easy, they weren't sexy, they weren't always prioritized for funding people, any of that, was identity and access management and data security.

Guess what? In my [00:30:00] opinion, those are the two biggest things right now with regard to AI adoption in the enterprise. Like, if your identity is, your identity structure is bad and your data security is bad, you're probably gonna have a bad time with actual secure adoption of AI

Kraig Faulkner: So how do you see people balancing that, right? Like, I think there's a delicate balance between the needs of data security and all of the other things that come along with that, uh, as well as AI innovation. So how do you balance AI innovation with the needs of data security?

Ward Balzerack : Yeah. It's, it's, uh, so I, I would say it's not necessarily a new question or new problem because we've, we've always should be balancing, you know, good security, good things with the needs and the velocity of business, right? Because unless you're truly a security company, um, you're not getting your paycheck if the business can't do what it needs to do, right?

You're not getting paid. You're probably getting fired, right? You're sitting in the unemployment line if, if you're holding folks up, at least if you're holding them up [00:31:00] too much. There can be a healthy amount of breaks applied for, for certain things. But, Everything needs to be fit for purpose. Now, again, if you had talked to me 10 years ago, I would've said, "No, you need to go buy the most expensive, you know, McLaren of every product.

You need to put those in. The heck with if they talk to each other. Like, just buy all the, you know, top of the top solutions, put them in, and of course you're gonna be good to go. Of course your risk is gonna reduce and, and the challenges are gonna melt away, and there's never gonna be any issues for the business at that point."

Right

however, being more seasoned and wiser now and seeing the bad part of those decisions, uh, not just my own, but others, I now realize everything has to be fit for purpose, and it all goes back to use cases. So not only use cases of, in this case, AI and AI adoption, right? Again, what the heck are we gonna be using?

How do we need to control [00:32:00] it? Uh, but also use cases for the business, right? There may be certain things that make absolutely zero sense for the industry that you're trying to secure or, or maybe it makes sense, but not to the level of a highly regulated industry versus that of which really isn't regulated, right?

It might be a good, like, good idea here, but required here sort of thing. So goes back to actually, like, having folks, hopefully your CISO to start with, right? Hopefully the CISO having that strategic mindset, zooming out, but then also their lieutenants, right? To include a data security leader to actually zoom out more to the macro level, understand the business, understand the use cases, and identify the for-purpose items that are necessary

Kraig Faulkner: Yeah. One thing you said there is, uh, brought a phrase to my mind that I say a lot, [00:33:00] and it's best of breed or best of platform. And I think that that's actually the wrong thing to say now. I think it's an and/or statement because again, based on use case, based on how it's being used, uh, what, you know, people are doing with it internally, are platforms that are gonna solve that, and there are best of breed that are gonna solve that, and there are best of breed platforms that are gonna solve that, right?

So we've seen just like a, you know, huge consolidation across tool sets, uh, which is interesting. But yeah, I don't think best of breed or best of platform wins anymore. I think it's truly centered on consultative action of understanding what the customer needs, right? Which is where you and I sit all day, every day. Uh,

Absolutely

our listeners out there, uh, definitely could, you know, maybe do that more internally within their organizations, right? So

Ward Balzerack : And I think it's truly understanding. So, so going back to your point, best of breed, best of [00:34:00] platform. If you have a platform, and I think just about everybody does, not everybody, but just about every... Microsoft, Microsoft's a, a prime example of this.

Yep

There are many organizations that are gonna own, you know, E3, E5, I, I think there's an E7 out there now, whatever.

Yeah.

E something, right? But there's a lot of organizations that don't really understand what the heck that means, what's actually in there. And, and part of that's on purpose, so, you know, I'll give kudos where kudos is due. You know, good job, Microsoft. And, and others do the same thing, right?

They have the menu, and if you need two things, you could pay X, but if you need three things, you might as well buy them all because it's, it's cheaper that way. Um, there's a lot of organizations that don't understand what actually goes into that. So just picking on Microsoft for a second, a lot of my conversations is around Purview, and it's great.

And I tell a lot of organizations when they're like, "Oh yeah, we're gonna use Purview," I said, "Why wouldn't you? Why wouldn't you use Purview? Why wouldn't you [00:35:00] start there?"

Kraig Faulkner: Yep

Ward Balzerack : Because you own it, you have it, you might as well operationalize it, unless you're actually getting off the Microsoft stack. If you're getting off the Microsoft stack and you're getting rid of E whatever, different conversation.

Kraig Faulkner: Sure.

Ward Balzerack : Completely different conversation.

Kraig Faulkner: Agreed

Ward Balzerack : But if you're keeping E5, I wanna talk about that, right? And, and I wanna talk about what can you actually use in the platform, what is a gold star thing for your use case versus what's maybe a, I, I don't know a good color for it, but what's maybe a half a star. We'll use, we'll use, like, portions of stars.

What's maybe a half a star? It's not great, but it could be a stopgap for a time. Um, and here's what that means for you, you know, Mr. or Miss Customer at that point. So you're-- I, I completely agree with you, Kraig. Like, people have to look at what they have today. If it's platform, fine, understand what that means.

If it's point solutions, also fine. But also [00:36:00] realize these platform players, at least today, um, they have full stars, full gold stars on one or more of their components. Uh, but inevitably some of the components are gonna be half stars or less, um, because you can't be good at everything.

Kraig Faulkner: Oh yeah. Agreed. Agreed. Unless you're me and Ward, and we're good at

Ward Balzerack : Absolutely. Then it's, you know, it's actually five stars across the board for everything at that point

Kraig Faulkner: Um, so I know we're, we're come- kinda coming to the end of the show here. I've got one question for you, and then I've got one to end it that I think is gonna take a few minutes, so I wanna make sure we

All right

it. my next question is still around AI. I'm just curious 'cause I'm starting to scrape this conversation with people. Uh, we mentioned it a little bit earlier. What are you advising on? What kind of discussions are you having around agentic AI right now?

Ward Balzerack : Yeah. I mean, that's-- I would say a lot of my, a lot of my advisory is, is [00:37:00] actually still the same, you know, fr-from a foundational perspective.

Yep

again, it's what are your use cases? What are you trying to do? I think, and I'm not really answering your question with my response here. I'm gonna generalize it to all AI usage.

There is a real problem that organizations are trying to, uh, uh, fix, and I hate using the phrase, I'm gonna call it shadow AI, right? Now, granted, I know it probably is. There probably is out there, right? People probably have it, but I mean, shadow AI, yeah, it's no different than shadow IT or shadow da- shadow anything, right?

Typical industry is, is calling shadow everything. But, um, it's a real problem that organizations are grappling with. So more at the macro level, like just about everything is now including some form of AI. What that actually means, you have to dig into. Um, [00:38:00] there are f- you know, full questionnaires now that organizations are using specific to AI, which is great, right?

Understand like what are you truly doing, how are you doing it, how are you using our data, are we using our data, all that stuff. But to get more specific to your question around agentic, th-there's still a big governance piece, right? Like, are you controlling your identities and identities well? Do you have an understanding of all your non-human identities?

Do you have a way to detect, monitor, what have you, with any a-agentic agents or workflows that are coming into the, uh, organization? And do you have maybe a tollgate process to actually bring those in?

Kraig Faulkner: Right

Ward Balzerack : my personal opinion on that is bringing in a, uh, a-a-agentic AI agents, uh, agentic AI, agentic AI solution is no different than bringing in any other solution, [00:39:00] and it should go through a full architectural and security review or a subset, maybe not a full, right, if you're not actually deploying infrastructure or whatever.

But it needs to go through that to actually identify what the heck is it trying to do, how is it trying to do it, and what guardrails need to be put around it

Kraig Faulkner: Yeah, and I think going back to a question we were talking about earlier with executives, one thing that I see as a norm, maybe it's just 'cause we don't have as much purview on kind of the vendor and partner side, but I remember 10, 15 years ago everything was centered around a pilot, UAT, and then prod rollout. I just feel like those kinds of steps don't happen anymore,

Ward.

Ward Balzerack : we're showing our age with that, man. I mean, same, right? As I would build project plans and those are the exact phases, right? Hey, it's gonna be, you know, X weeks here, X weeks here, and you're probably also, to take it a step further, you're probably gonna build a UAT, maybe an acceptance environment.

Maybe you're also gonna have a dev environment on top of [00:40:00] it, and finally you're gonna have prod, right? You're gonna have three or four environments before it gets there. Um, I, I still see it out there from a more like enterprise system, um, environment, like an ERP system or whatever. But, uh, you make a really good point with that, sir.

Like I, I don't see a lot of customers or organizations necessarily doing the same with their security stack,

Yeah.

my last job

Kraig Faulkner: with AI agents specifically, right? Treat them as

Ward Balzerack : Absolutely.

Kraig Faulkner: them the

Absolutely.

All that, so

Ward Balzerack : Yeah. Yeah. I mean, I remember at, at my last job when, when I was building, uh, when I was owning data security building and I was talking to vendors, and some were SaaS vendors.

I said, "Hey, congratulations. You're gonna give me a UAT SaaS tenant." And I'd always get weird looks. I'm like, "No, I'm not gonna, I'm not gonna play in prod, period." Like, call me old school, call me old-fashioned, like, if you wanna charge me a nominal rate, 'cause I get it, there's resources being used, fine. But understand this is not prod.

And, [00:41:00] and, you know, the, the vendors, uh, would eventually give that to me. "Oh, yeah, here's, you know, five licenses for this thing. Here's your tenant."

Right

but 100% agree with you. You know, i- if we do it for our ERP systems, if we do it for our security stack, you know, building fire range and stuff like that, we should absolutely do it for AI technologies, agentic or not, because it's just an extension of all of those other things that we just mentioned

Kraig Faulkner: Yeah, and I think we, um, we were ahead of the game. You mentioned UEBA earlier. It, it was called UBA at one point,

Ward Balzerack : Yes.

Kraig Faulkner: wasn't in there, and I

think we were kind of foreshadowing on ourselves and didn't even realize we were doing it. Um, but I think IAM, identity and access management, is gonna evolve, right?

Whether it be IEAM or EAM, right? Just entity access management. Because non-human identities and human identities are doing some of the same stuff now, right? So, um, yeah, I agree with you

Ward Balzerack : There will definitely be an evolution there. And I guess [00:42:00] what I would say on that front, and that, that's another area that I'm seeing explode. You know, I've got a lot of friends in the industry that either were, you know, longtime IAM folks or have made the transition, you know, recently. And, um, they're busier than busy, right?

They're deploying new solutions or they're doing finally some of those hygiene pieces that they're like, again, "Oh crap, you know, now we've got AI that's exposing these bad habits."

Kraig Faulkner: Put it back in the bottle.

Ward Balzerack : yeah. Close that box. Oh,

Kraig Faulkner: it.

Ward Balzerack : where, where's the lid? Lid's gone, right? Lid, lid is completely blown away

Kraig Faulkner: All right, Ward. We're coming to the end here. listeners hopefully have gotten a lot of good information today, I want to ask you a visionary question to round this out.

Ward Balzerack : Oh God. All right, here we go

Kraig Faulkner: So we're in 2026, halfway through it, so next three to five years.

So let's say we can even go up to, like, 2035 if you want to. Um, next three to five years, how do you expect, personally, do you expect [00:43:00] AI to drive data security strategy, evolution, uh, new tooling, new ways to do things, all of that? Like, what is your vision of data security within the AI era, if you will, uh, in the next three to five years?

Ward Balzerack : Oh, man. Um,

Kraig Faulkner: Do you remember my prediction from my show? I'm curious if you do

Ward Balzerack : I, you know, I should have done my homework went back. I do not remember your prediction.

My

that on me first

Kraig Faulkner: prediction was that everything is gonna go back on-prem

Ward Balzerack : Oh, okay. I, I actually do remember that now that you mentioned that. Yes.

Kraig Faulkner: We'll see.

Ward Balzerack : we're, we're gonna turtle up, we're gonna go back. Um, all right, so three to five years. So actually I kind of said the same, right, when I was answering before to a different question. I, I do think we'll see a wave with AI where, uh, right now there's a lot of people being all gung-ho.

We're already seeing the articles of folks like, "Holy crap," and the memes, right? "Oh my, oh my God, here's my bill. I could have spent, you know, 70K on an analyst. I got a 300K bill here." [00:44:00] Um, I think some of that's actually gonna be real, right? So I think we're gonna see some organizations stutter step and either, uh, rehire FTEs, uh, or they'll look towards partners to fill the gap, right?

Either MSS folks like Infolock, right? Or, uh, or other, yeah, or other organizations out there to help fill the gap, right? Uh, you know, staff augmentation, all that, which I think would be good, right, for some of the junior folks that, um, thought, "Hey, I'm gonna get a, uh, college degree," or, "Hey, I'm gonna go get a cert, I'm gonna get a job," right?

It's a tough, tough industry right now. So if we do have that wave, I think that would be good for some of the folks today that weren't necessarily banking on, on AI just exploding. Uh, it would give them a chance to get in, get some experience and, and skill up, right? Um, I think that'll be nearer term, right?

I don't think that's gonna happen three years from now. I think if it is gonna happen, it's gonna be probably in the next 12 months

Yeah

see that. We're gonna see some people turtle up a bit, [00:45:00] close the doors a bit, and then, and then get back into it. I... The, the box is open. It's never gonna be completely closed and put on the shelf, which I think is fine.

Um, I think also we're already seeing changes, or at least I am. Uh, uh, I, I don't really need to wait three, five, 10 years to see changes in data security. Um, a lot of folks neglected, uh, again, the basics of data security, and, and one of my soapbox arguments is, um, AI didn't introduce new risk. It exposed risk that we swept under the rug or we neglected for years,

Kraig Faulkner: Yep.

Ward Balzerack : Data at rest security. Um, I remember doing that 15 years ago for three letter agencies and, um, they were obviously a mess. They still are, right? A lot, lot of those agen- it's the government. Uh, but they understood then, um, that data sitting around, data not stored by sensitivity or classification, you know, they, they truly use [00:46:00] classifications there, uh, is a problem, right?

Other organizations, when I got out of that consulting gig, went back into the enterprise, they didn't see the same problem. "Oh, what do you mean that I should not have highly restricted data, you know, cobbled together with, you know, maybe just internal, like, regular data? I don't see a problem, really." And, and the thing is people are now seeing that, right?

People are seeing that as they bring in a co-pilot into their organization and people can search whatever the heck they want and boom, you know, now it's a jumble of results from "Hey, like, here's my executive salary," which my personal opinion is like, whatever, who cares? Uh, to, "Hey, I'm on a RIF list." That's a bummer, right?

If they find that out or anywhere in between, right? Anywhere in between people shouldn't have had data. So I think there's that, right? People finally focusing on data at rest.

Kraig Faulkner: Do you remember,

I do think

15 servers across multiple data centers and like a year of scan compute to

Ward Balzerack : Grid scanning. Yeah. I, I actually [00:47:00] used to love that. I mean, I had, uh, I, I was-- I got to tell a story right quick 'cause you brought it up. Uh, I was using RSA DLP back in the day. Go Tablas, right? Um, not even a product anymore, but they had grid scanning technology, and I would go and steal, steal, re-repossess, uh, engineering workstations

Mm-hmm.

Be my grid scanners.

Um, and I had a whole back room, it was literally a closet where I plugged these darn things in,

Kraig Faulkner: awesome

Ward Balzerack : and, and they would go hit the file servers, right? Like they, they weren't servers, but they had enough meat to be my... They're, they're my botnet, essentially, right? They're my zombies that were going out and scanning and crawling.

Um, so y-yeah, that's, that's data at rest. Um, I think, a-again, riding the wave of, of AI specifically to security, I think a lot of frontline positions aren't gonna be frontline positions anymore, right? Your typical SOC positions. Uh, [00:48:00] for me, in, in my data security org, I always had L1, L2, L3 analysts for actual like DLP findings, data at rest findings, whatever.

I think L1s are gonna go away. Um, I think they should go away, truth be told, right? Because your typical L1 is doing information gathering, um, you know, enriching a case. Um, you know, when SOAR technologies came out, that was kind of the start of the answer to upskill or replace some of that menial work.

Never really fully got there. Um, I do think AI, um, in, in some cases has already replaced some of that work. There are some, you know, really great vendors out there that are innovating in that space, specifically around DLP. I'm really excited to be seeing that. Um, but I think we're gonna see more of that.

And I-I'm not saying that to be a doomsayer for any of my listeners that are currently in an L1, uh, capability. Um, I think it's a great opportunity for you to skill up, right? Um, you know, [00:49:00] skill up, start skilling up now and become that L2, become that L3, 'cause I think there's always like, like you do, Kraig, there's always gonna be a human in, in the loop, uh, or need to be a human in the loop for those things.

Kraig Faulkner: Yeah. I was gonna challenge our listeners with you saying that, that that

Ward Balzerack : Yeah

Kraig Faulkner: let people go. That means level them up, right? Like, make them better, get them to do tasks that we need human brains to apply knowledge to. Um, it doesn't mean a TRIT or RIF. It means level up, right? So I challenge our listeners to level your people up.

Ward Balzerack : Or put them on those initiatives that you ignored. You didn't have time for, okay, have AI do the things that you had them and then have them go do those side projects.

Kraig Faulkner: Yeah. Yeah, I

Ward Balzerack : Yeah. Yeah. I think I, I had a few, I have a few other thoughts, but I think the, the last thought I will, I will leave it on kind of goes back to, uh, the UBA, UEBA use case, right?

That, that, that solution, that space that, uh, sorry, I've got friends in the space. I do love some of the technologies out [00:50:00] there, but it never really lived up, right? Um, and, and it's probably gotten better. It's been a bit since I've looked at it, but I think the behavioral analysis, just taking the rest of it out of there, behavioral analysis, creating a baseline, understanding the business, understanding, uh, or starting to understand intent, um, you know, paired back to identity, paired back to, you know, baseline across peer group.

I think AI is going to disrupt that. Um, it probably already starting to, it is starting to do it. I think it's great. I think it needs to happen because the UEBAs of the old, you would buy it and they'd literally tell you, "Hey, it's gonna take, you know, 12 to 18 months to get value,

Yeah

baseline, to get value."

Who the heck has time for that?

Kraig Faulkner: Yeah. Agreed

Ward Balzerack : And those were expensive solutions, right? Hundreds of thousands of dollars

Kraig Faulkner: Yeah. I think that's another solution that's kinda gotten, um, enveloped into other [00:51:00] places, right? You see a lot of that in the SOC and the SOC technologies, right? We're seeing a huge splash with agentic in the SOC now too. So, um, yeah. I think we, uh, we opened a lot of can of worms today. I don't know that we, uh, kept any of the worms in, but

Ward Balzerack : Well, I mean, that's, that's kind of what advising is about, right? You, you're supposed to showcase some of the concerns and, and problems, and that's where the conversation starts, right?

For

where we start to have the real conversations around, "Hey, does any of this resonate with you?" "Oh, it does."

"Okay, cool. Let's, let's whiteboard it. Let's figure out how to solve for it." So agreed. We opened cans of worms. I hope for the listeners some of those things, right, resonated. And, um, I mean, that, that's where you need to actually, going back to my answer, right? Prioritize, strategize, and focus. Write those things down and do something with that.

Don't just write it down. I mean, have a notebook, right? Write it down and then close the notebook, put [00:52:00] it on a shelf. Don't do that. That's a problem

Kraig Faulkner: Agreed. Powerful words to end us out there, Ward. well, I just want to say thank you, Ward, for joining me today on your podcast. Uh, it was a pleasure to host. Uh, huge thank you to the audience. We absolutely enjoyed recording this episode again. , Hopefully you learned something from either myself or Ward, or at least made you think a little bit, about what you're doing in data security. Also encourage you to subscribe to Ward's podcast. Uh, tell the people in your network to follow, to listen. I know I sent it out to my family and a bunch of colleagues when I was on my first time, so I'll be doing that again this time. Um, and this has been another exciting episode of Guardians of Data podcast featuring Ward Balcerzak. See you next time

Ward Balzerack : Thanks everyone

Speaker: That's a wrap on another episode of Guardians of the Data. Thanks for tuning in for show notes and more Visit Guardians. The data do show Guardians of the data is made possible by support from Centro to see how we help organizations discover and classify all of their data accurately and [00:53:00] automatically while quickly achieving scale data protection without the fuss, please visit sentra.io.

Catch you next time.

The Host Gets Hosted - Ward Balcerzak - Guardians of the Data - Episode # 53
Broadcast by