Risk Isn't Static - Guardians of the Data - Veena Nagarajan - Episode #55

GOTD- Veena Nagarajan
===

Speaker 2: [00:00:00] Welcome to Guardians of the Data. I'm your host, ward Balza. Each episode will explore the passions, expertise, and real world experiences of security leaders who are helping the future of data security and governance. Guardians of the data is made possible by support from Centro. To learn more about our AI powered data security platform, please visit sentra.io.

Let's dive in.

ward_1_07-14-2026_083941: Welcome to another episode of Guardian to the Data. My guest today has 15 years of experience in cybersecurity. Over that time, she's delivered numerous cyber program initiatives, managed large organizations of teams, and enhanced capabilities across multiple facets of her security program. She's currently the interim CISO of a healthcare organization. Nina Gatonagarajan, welcome to the show

squadcaster-b457_1_07-14-2026_083941: Thank you, Ward. It's great, uh, to meet with you and pleasure to share what we have experienced so far all these years

ward_1_07-14-2026_083941: Glad to have you here. So Veena, in your professional [00:01:00] opinion, what's the biggest challenge that organizations are facing with data security?

squadcaster-b457_1_07-14-2026_083941: I believe, um, obviously I have immense experience in healthcare. So looking from that perspective, it's always the data, uh, which I consider the crown jewel of every organization, what's important to them. And to healthcare, it's always the patient data. And the first and foremost, uh, kind of the responsibility that we have is to ensure that data is safe.

And we, uh, you know, ke- uh, you know, keep up with the, uh, you know, confidence and also the trust that, uh, the patients have on us that that data is safe. With that in mind, uh, that's going to be the first thing as a healthcare organization, making sure the patient privacy and their data is safe. Because it's not just to keep up with the reputation, but it's also regulation centric, [00:02:00] right?

So we have, uh, a lot of regulations that also kind of focus on patient privacy and making sure that data is secure, that data is not lost in any breach. So, uh, that's going to be kind of the biggest challenge. Uh, especially being in healthcare, uh, patient privacy is number one, uh, for any CISOs or any, uh, you know, uh, organization leader.

ward_1_07-14-2026_083941: I, I like it. I like it. And I, I believe you're one of my first guests that's solely focused on, on healthcare. I've had a few others that are healthcare and education. So, you know, with that, being in the healthcare industry, patient data obviously, right? Super important. Um, what kinds of things are, are, are you doing to ensure that that data is secured appropriately?

squadcaster-b457_1_07-14-2026_083941: A great question. Um, so, uh, as I pointed out, we do [00:03:00] have processes in place to make sure we, uh, assess the risk to the organization. For example, if any new solution is introduced in our environment, we make sure end-to-end process of that solution from ideation, from, you know, the initial phase of design, we look into end-to-end architecture of that solution and what data goes in, what data comes out.

So it starts off with the analysis of the whole workflow. So we ensure, uh, you know, uh, whatever we do, be it a qualitative assessment, it's data centric, and it kind of gives us the initial inherent risk to the organization. From there, we start, uh, you know, kind of, uh, assessing the risk. Then that's more of, you know, a qualitative control.

Looking into technical controls, we have, uh, kind of built a lot of guardrails to ensure the [00:04:00] data is safe. Um, and from a technical standpoint, uh, obviously we need to ensure we have a good data loss prevention software, right? Uh, you need to make sure there's a DLP solution to prevent and protect your organization from any kind of data exfiltration.

So that's number one. And especially Being in healthcare, uh, that's first and foremost. And, uh, with the advent of new technology and machine learning, uh, growing in, you know, light speed. So we want to make sure that DLP controls is concentrated even from an AI perspective. So, uh, that's, that's a goal to make sure we have the technical control in place.

We call it defense in depth. Probably you've heard it many times. So making sure you have all the layers of controls in place, uh, to reduce the attack surface, and that's going to be first and foremost. [00:05:00] Uh, as I pointed out, you have the process controls. You have... You assess the risk to your organization based on the data.

But also you'll... You've got to make sure you have the technical controls in place. You have the layers of controls, your DLP, and to make sure there is no exfiltration of data. Then you have to make sure you have a good EDR solution, which is a endpoint detection solution. And what is an endpoint? Endpoint is anything from a server to a workstation to a laptop to your BYOD.

So you've got to make sure you have a good EDR solution in place that serves as another layer, right? For example, if anybody tries to download a malware, you know, anybody tries to,

you know, click a link, your EDR is going to act and your EDR is going to have high fidelity in detection of these kind of malware. So you do need to have EDR in place. And there are other layers that we make sure [00:06:00] is in place to prevent any kind of data exfiltration

ward_1_07-14-2026_083941: I like it. I like it. I want to go back to kind of the first step that you mentioned, 'cause I feel like that step a, a lot of organizations kind of hurry through or maybe even gloss over, and that was, uh, you, you, you said analysis of workflow, right? Essentially how, a- and I think me reading into it, um, you know, how data is probably flowing, going in, created and all that.

So for, for those listeners that not have those processes yet or maybe need to, um, you know, evolve what they're doing, any tips or tricks you have for the audience on that?

squadcaster-b457_1_07-14-2026_083941: Sure. I, I would say, uh, before, uh, uh, before you bring in any solution into the environment, make sure you have a screening questionnaire, like a inherent questionnaire, right? But you don't have to have like fifteen or twenty questions, just have the ten basic questions, right? Is it internally hosted? Is it [00:07:00] externally facing, right?

What, uh, data is collected, uh, through the solution, right? What, what are the data elements? So being a healthcare, uh, I would say we concentrate on does it have PHI? Does it have... You know, with PHI is protected health information, which includes all the eighteen identifiers of HIPAA. And then we check if it has payment card information, which is PCI.

And then last, we also check if it has PII, which, which is personally identifiable information. Um, and each of that obviously it concentrates on the user data, the user identity. So everything revolves around a user's identity, which is kind of the key, right? Like we... Anybody who trusts the data, be it an employee who trusts an organization with the data, you know, making sure their, uh, employee data from...

Because obviously just like patient [00:08:00] information, and we get historical information of the patient, when an employee comes to an organization, we get that historical record. We do background checks. This is for any organization, right? So those are key elements and to keep up with the trust, trust of an employee, trust of a patient.

So that's going to be the key. So have your ten questions of what application interface it has and whether it is externally facing and, um, and then what data is collected. So based on the data elements, you can assess how deep dive you have to do the risk assessment, right? If you have to do, uh, if, if, if at all somebody says...

Let's take an example That they have... They collect the entire patient history. So we do... We ask additional questions. You can make... build a logic where you can ask us 10 questions, and if the 10 questions kind of tells you a story that this has much [00:09:00] more critical data and also it's externally facing, if it elevates the risk, then you a- get asked 10 more additional questions which would help you to see if the, if the security controls are in place.

Uh, what is necessary to make sure that the data is secure if it's externally facing, right? Do, do you have appropriate password controls? Do you have appropriate role-based access? Do you have appropriate endpoint controls in place to ensure the data is safe? Uh, again, it all... Like you said, like it's all re- it all revolves around the data, right?

Uh, that's kind of, uh, the, I would say, the nucleus of any organization

ward_1_07-14-2026_083941: I, I heard two really good things I'd love to highlight in, in what you just said there. So first, you really kind of started off in, in your process it back to the regulatory items that, that you need to [00:10:00] control. So you being in healthcare, obviously, right? PHI is a big one. You mentioned PII as well. Uh, PCI though, you know, obviously, you know, ano- another important one, especially if you're getting payment information. So, you know, would, would you say one of the first steps an organization should do is identify which regulatory frameworks they need to abide by?

squadcaster-b457_1_07-14-2026_083941: Excellent question and good point, right? Uh, yes. For example, I believe, you know, financial industry, you know, the SOC, S-O-X, that would be primary... And PCI, uh, would be the primary regulations, right? And, uh, obviously, uh, if it's a energy sector, they're going to follow regulations, uh, depending on, you know, country laws, depending on, you know, where, uh, you know, the energy is going to be obtained.

Um, and, uh, then healthcare obvious- obviously has c- I would say a good range of regulation that has to be followed because [00:11:00] it's not just HIPAA. If it's a state regulated, then you have to follow the state regulations. If it's a federal regulated, you have to follow the federal regulations, right?

Everything plays, uh, as part of healthcare. And again, like you said, different industries, uh, would, uh, kind of hone in their regulation that they have to comply to. And with that they identify what the crown jewels are. For financial industry, definitely financial data of the user, right? And for a energy industry, definitely that trade secret.

So that's, that's also there. So, uh, identify your crown jewels, identify the regulation that you have to follow and, uh, go, uh, have that as a baseline and, uh, kind of assess the risk to the organization.

ward_1_07-14-2026_083941: Outstanding. Outstanding. And then, you know, the next piece that you said before that I liked was, um, goes back to not boiling the oceans. You mentioned, you know, find 10 questions, [00:12:00] right? And, uh, I've, I've personally seen some of these questionnaires out there, and they are very in-depth sometimes, like, you know, 50 to 100 questions.

And, uh, always kind of laugh a little bit when I see those because, you know, where my mind goes is who the heck is actually filling this out, right? Are you handing it to the user and saying, "Fill this out?" Because that's not gonna happen with 50 or 100 questions. Is it gonna be the IT department? And is 50 or more actually required?

So I, I feel like when you were describing your process, really a-- It's funny, we're talking about data security. It's really a data-driven questionnaire, right? Like, if, if somebody answers yes to a certain question, you mentioned publicly exposed, um, there's probably other questions that then open up that they have to go into as well.

Is, is that kind of the, uh, the process you're advocating?

squadcaster-b457_1_07-14-2026_083941: [00:13:00] Yes. That, that, that's the process that I would kind of encourage. And you're, uh... it's, uh, funny you say that, right? So throughout my journey, all these 17 years, I've seen those challenges. If you hand over a question to a person or application owner, not every time that person has all the answers because it is a ven- it could be a vendor-hosted solution instead of internally developed solution.

Then who's going to answer the questionnaire, right? Will you get answers to all the quest- even it could be 10 questions, right? Um, and it might be very early stage of the project. And, uh, so I do not expect them to have all the answers in the early stage of the project because they probably don't know how many users are going to use it, right?

They probably don't know, uh, is it gonna be one use case or many use case? Uh, they probably don't know if, if it is, uh, [00:14:00] you know, it should be externally hosted or, uh, it is gonna be internally used. So of course, everything requires, you know, a requirement gathering phase. That's definitely there. But, uh, early stages of project, it's hard to get information, number one.

So I would encourage everyone to make sure to do an assessment when you have at least, uh, the basic information with you, right? You have the project details, you have the vendor information of how or it is going to be hosted. Otherwise, I would say you would not be able to give, uh, all the information.

Because take it this way, if they don't have accurate information, and if they just fill out that information with a vague, you know, response, then, uh, obviously they're not just, uh, putting themself at risk, they're putting the organization at risk by deploying that solution. So get the [00:15:00] necessary information.

Might not be deep, right? And then answer the questionnaire. And also you, you made a absolutely great point. Who, who should answer the questionnaire? Identify the person to answer the questionnaire. Now, you don't have to know all the details. Have the vendor on the call, you know. Have... You know, work through the workflow, work through the use case, and answer the questionnaire according to the needs and requirements of the end user.

So that should help you answer the 10 questionnaire. Absolutely. Identify the right person to answer the questionnaire, and that should be the first thing in everybody's, you know, kind of, uh, starting of a project or an initiative

ward_1_07-14-2026_083941: Something that I've seen missed i-i-in that process that, that you're... Uh, 'cause I, I too have been in those processes before, but something that I always saw missed was almost, um, you know, for lack of better terms, re-verification, right? So I've, I've seen organizations do this whole process for a POV, [00:16:00] right?

Proof of value. And they say, "Great, we're gonna buy it." And some organizations go directly from, we did this POV with this questionnaire," which may have been scoped for that POV, directly into production, right? Without going back and saying, "It, it-- all of our answers, are they still accurate?" Right? "Are they still true?"

Like the POV, maybe that was hosted externally and now it's internal or vice versa. So do you have any, um, any recommendations around more of like a re-verification process for those questionnaires?

squadcaster-b457_1_07-14-2026_083941: Yes. So, uh, as I was walking through the process, right? The first question is going to be g-give you an inherent risk. Now, as and when, uh, the project kind of progresses, you get more details, right? Whether it's externally facing, which ports to open, and then, uh, the IP addresses, the website, you know, from development to staging to [00:17:00] production, and whether it needs a vulnerability scans, what are the servers in place, all the details that comes for the entire deployment.

So as it progresses, you gather all the information. Things are getting stood up and things are getting staged. Uh, do add another layer to the, you know, uh, data, data gathering phase. With that said, uh, we... With the inherent questionnaire, right? You assess the risk. You get some gaps. So use those gaps and make sure you address and remedy it as you, uh, develop the project.

Now, keep in mind, the inherent questionnaire It's not just to assess the risk. The vendor who comes into your organization doesn't know your security controls, doesn't know your, you know, eight-character or twelve or sixteen-character passwords, doesn't know your policies that you have in your Azure. So the vendor doesn't know how it's all configured.

Now, when they [00:18:00] answer the questionnaire or when they help you answer the questionnaire, that's when they learn what is your organization policies. And when it generates the gaps, I would say take those gaps, work with the vendor and, you know, towards remediation. In that way, what came as a medium risk could be reduced to a low risk.

So as and when you progress, you do one risk assessment at the beginning, and as you remediate these gaps that come out of the initial questionnaire, you do another risk assessment towards two weeks before the deployment. So that gives you like a reassessment, like you s-said, right? Verify if the gaps are addressed.

In that way, the risk could be reduced. In that way, you can also ensure there's, you know, uh, it's not just, uh, you know, the inherent risk. Once you remediate, the risk is going to be reduced. What you have is a residual risk, so that risk is going to be lower. And not just that one. I mean, you just... It's not just doing the risk [00:19:00] assessment at the beginning and at the end, it has to be ongoing.

And how do you do it ongoing? Based on which tier is that application. It is a critical tier, like, you know, top tier. And what data does it have? Does it have the entire PHI or if it's a bank information, you know, whatever is critical to them. So does it have any of the critical information? Then do the risk assessment, you know, every six months or annually based on the criticality that you find out of the risk assessment, you know, be it at the inherent or the later stage, you make sure you have ongoing monitoring in place.

For example, uh, in our risk assessment, we collect critical, you know, uh, reports like, uh, SOC reports, right? I'm sure every organization generate that service organization controls that report. And, uh, that report kind of details you [00:20:00] How the vendor is securing our environment, how the vendor

ward_1_07-14-2026_083941: Mm-hmm.

squadcaster-b457_1_07-14-2026_083941: Is, you know, following those controls, be it role-based access, be it, uh, you know, kind of password controls or be it regular monitoring or be it vulnerability scans.

All that comes along to secure the environment. They make sure that is all audited and that's in that SOC report. So we ensure that SOC report is gathered every year, right? As, as and when we do periodic assessment, we gather those report to make sure ongoing monitoring is in place and the third party is keeping up with that security because that's what we want, right?

We want them to be secure as much as we are secure. We are kind of, uh, transferring the risk to them. When we go for a third party, we transfer the risk to them, right? And accept the risk that we have handed over to the third party, and they manage our controls [00:21:00] securely, our data securely. So that's kind of the process and, uh, I agree with you.

Re-as- re-verification, reassessment is important, but also ongoing monitoring of the controls is very important

ward_1_07-14-2026_083941: It, it occurs to me as, as we've been talking here, you know, we, we talked a lot about, you know, um, filling out questionnaires, right? Gathering evidence. Um, you, you mentioned like gathering SOC reports and such. Um, we didn't necessarily talk about what the heck to do with all of that, right? Um, you know, where, where to put it, how to store it.

Any thoughts or, or any tips and tricks on that front?

squadcaster-b457_1_07-14-2026_083941: Uh, sure. So we, uh, again, this is where, uh, the organization's, uh, you know, uh, scope comes into play. Do they, uh, uh, I mean, can they manage it in Excel spreadsheet? I know we are not at the age of Excel spreadsheet, but some organization, uh, they don't have, you know, uh, the bandwidth, they [00:22:00] don't have the budget to go for an automated solution.

So if you have, uh, you know, a risk assessment in an Excel spreadsheet, make sure you have it in one storage location, like a shared drive or a SharePoint where you have secure access to it just on need to know, because that, uh, has the entire database of your solutions and the risk to the organization.

So if it's, you know, a small, uh, industry, you know, that goes with spreadsheets, I would recommend that. Now, if in case we are able to kind of automate it and we are in kind of the, you know, uh, the generation of everything is automated, we are in a generation of AI, so there are solutions out there that could help you automate the process.

So in that way, uh, if it's, uh, you know, a SaaS solution, if it's a-- that's something that is hosted in the cloud, they help you, you know, have a good repository and good storage, a [00:23:00] good kind of a dashboard and a reporting structure where, uh, you know, it does everything, you know, in a periodic basis. And also a good, uh, location to have everything stored, uh, in their, you know, cloud repository.

So it does help. It, it is based on the organization scale and how much they can automate and how much they can, uh, you know, uh, look for, you know, as far as whether it needs to be a manual solution or an automated solution. If it's a manual solution, make sure you store it in your one-- like a OneDrive or a secure shared location.

Or, you know, if it's a SaaS solution, then they should be able to help you with a good repository of all the risk assessment and also keep the automation in place.

ward_1_07-14-2026_083941: You know, I, I got some shivers when you said Excel spreadsheet. Now I've been there, I've seen it, right? I think plenty of organizations do do that. And, [00:24:00] you know, wh- while we all laugh and joke, and I think we all secretly both love and hate Excel,

squadcaster-b457_1_07-14-2026_083941: Cheers

ward_1_07-14-2026_083941: I, I give plenty of organizations a gold star for that.

Like, at least they're doing something, right? That's, that's my big thing. Like, if you're, if you're gonna do anything, do something when, when

it comes to what we're

squadcaster-b457_1_07-14-2026_083941: and I agree, right? and I, I come from the age of Excel, so I still love it. I'll, I'll let you know that, right? Uh, but, uh, I do respect the organization that still follow that. The crux of it is as long as you follow the process, you, you have to follow the process. You have to keep it periodic.

It comes down to a streamlined process, and you can automate solution as much as you want. What if the automation doesn't work, right? What if the automation doesn't do its job? So, even if you have automation, you still need to have a human in the loop. You still need to make sure those are done regularly.

You still need to pull the reports. You still need to show the audit that those are done regularly, [00:25:00] right? Everything has to be in place. So it doesn't matter if it's manual or automatic. What matters is do you have it streamlined? Do you follow it regularly? Do you have continuous monitoring in place?

That is the key because that is what they look for. And if it's automated and if it fails to do the periodic assessment on time, then that becomes a finding, right? If it's manual and they still do it on time, then there's no finding. So it does not matter on the process. It matters on keeping it regular and consistent.

That's what it matters

ward_1_07-14-2026_083941: I totally agree. And I think the, the, the last piece, and, and, and you mentioned it in your initial answer, so we're, we're tying this all back together. It, it goes from doing all of this analysis, right? Doing all these questionnaires and follow-up and, um, you know, architecting a solution. And then there's finally actually doing something with that information, I think that's another [00:26:00] key too. I, I worked for an organization when, when they were kind of building out this process we're referring to, they built a really good process. It was a really good questionnaire. It came out with a risk score. It came out with a good thing that each application had a risk score and whatnot. And I remember asking, a- and it felt like I was asking a taboo question, but I remember asking, "Okay, what are we doing with this? What is anybody doing with this?" 'Cause we created this awesome s- uh, solution, um, but there was nothing at the end, right? There was no, there was no actual output. So, know, to, to tie it all together, you know, Veena, you mentioned, uh, doing the analysis, then finally having defense in depth, right?

Having controls. So do you have any thoughts on taking all that goodness we just talked about, the questionnaire, the information, all of that collaboration, to finally, you know, having rubber meet road with, um, you know, technical [00:27:00] control implementation?

squadcaster-b457_1_07-14-2026_083941: Sure. Um, and as, as I shared with you, uh, reducing the-- from, you know, from organization perspective, one should always think about reducing the attack surface. It's, uh, no longer a question of, hey, whether it's going to, you know, happen to you. The thought process should be: what if it happens to me? How do you be breach-ready, right?

How do you ensure you have the controls in place? Because when it happens, if it happens, what do you do, right? So I would recommend for any organization to make sure, be consistent on your tabletop exercises. Be consistent in doing your pen test. Be consistent in doing all your scans. So, uh, make sure you're more proactive, right?

Uh, we are talking about... These days, we are talking about shifting left, right? We are, we are talking about being more [00:28:00] proactive and doing continuous pen testing, you know, where possible to make sure every organization is secure. So in the age of AI, i- where we are talking about, uh, you know, uh, things getting, uh, kind of assessed, things getting deployed in machine speed, uh, we gotta get ahead of the game.

We gotta make sure the layers of security that's built is also going to the next level and keeping up with the pace of the technology. And with that, I know it's not easy. It's easy said and done because, uh, some... At one point, there were more security solution than at the time things were getting developed, right?

But now that's not the case. The speed at which technology solutions are developed are much more faster than the speed [00:29:00] of trying to secure it. So it's, it's no longer like the volume, it's about what's the most risk, what's the riskiest to the organization, what are the factors to look in to assess that risk, right?

And, uh, which one to address first. Uh, that's come... It comes down to that. So with that in mind, as you build your layers of security, as you work towards your defense in depth, make sure all your... You know, what's your first entry point? What's a day in, day out? It's a email. Make sure your email flow is secure.

Uh, you know, because, uh... And I know it's been talked about in many, you know, many... I'm sure you've heard it a lot. It's always that one click, right? It might be the same old story, but it... At the end of the day, it comes to the human factor. At the end of the day, it's always a human. It always [00:30:00] takes that one click for that human to expose the organization.

So make sure you have a good email security solutions that is able to detect any kind of malware, any kind of phishing link, or any kind of campaign that, uh, bad actors trying to launch at your organization. Because Those so- those solution use intelligence, use automation to have these kind of indicators in their solution that is already baked in in real time.

They update in real time, and they are able to detect it even before that particular email lands in the end user's inbox. So have a secure email solution as one layer. That's, that's your friend too, right? For anybody in the organization. And I would say as you use your endpoint, which I kind of shared with you, which could be your mobile app...

Your mobi-mobile, which could be a laptop, which [00:31:00] could be your desktop, your workstation. So make sure that particular system is secure with appropriate controls in place. Make sure you have a EDR solution, which is your endpoint detection response. You have lot of solutions, next generation EDR that helps you not only with the solution, but they also provide managed care, you know, uh, managed services that helps you with resources.

Make sure you have a good EDR that if in case if it sees something, it sends alerts and actions are taken immediately, right? Good, good EDR in place. Good DLP solution in place. And, you know, we're in age of zero trust, right? So you have a lot of zero trust solutions out in the mar-market, which is faster, which has highest fidelity in detecting any kind of threat.

So make sure you identify the right solution, do the right POCs, you know, do the right, you know, [00:32:00] bake-off to make sure which solution is best for your organization that is able to detect with highest fidelity and able to give you the results, uh, that could protect your organization because you need to kind of build those layers from a perimeter standpoint where it en- where the data goes in and out in your organization.

You need to have the DLP, you need to have the EDR, you need to have the network detection too. You have... It's not just EDR. You do have a NDR, right? A network detection response that listens to your network. Like, data is going back and forth in your network. It is... You know, each packet of data is going back and forth, and that needs to be inspected too.

So make sure you have those layers of control. I know I used quite a lot of buzzwords, uh, but nothing to be scared about. These are, are controls that are out in the market. You just have to, uh, look through those layers of controls, make sure those layers of [00:33:00] controls are in place, then that is going to take care of, you know, uh, your technical controls and give you the defense in depth that is required

ward_1_07-14-2026_083941: Completely agree. And, and Vina, we covered a lot of ground here. So I'm curious, you know, you've been in the industry for a while. You're currently an interim CISO. What was your journey? How did you get to where you are today?

squadcaster-b457_1_07-14-2026_083941: Uh, thanks for asking that. So it's, it's, it's, uh, it's a quite a journey, um, I would say. And, um, I, I'm from India, so I'm very proud, uh, of my country. So it's been 21 years since I came from India, and I would say, uh, like everyone says, uh, United States is a land of opportunities. And, uh, I came with a dream here, and, uh, I would say, uh, you know, my dream, uh, I'm, I'm still dreaming, but it has been a well, uh, you know, fulfilled dream.

Um, and I started, uh, my master's [00:34:00] and, uh, you know, uh, here in Houston. I completed my master's in information security and management. That was my focus. And, uh, I landed in healthcare even before I graduated. So, uh, it was a great opportunity in a great institution, which they opened the doors for me, and I do appreciate that, right?

Um, obviously, uh, when coming into an environment from a different country, uh, you're not accustomed to the culture, you're not accustomed to working in a different environment. It did give me a good platform, uh, the confidence that I need and the work environment that I need. So, uh, started off with, uh, that organization and, uh, learnt through my journey, and I had great mentors in my journey.

And, uh, I would say look for mentors through your journey They are the one who's going to shape your career, who's going to provide their experiences [00:35:00] that could-- that you could learn a lot from them, right? As they coach you, as they train you, that, that experiences will go a long way. Um, and also make sure you learn from them.

I mean, what... Like, there was one, uh, leader that told me in early in my career, "You know, as you grow, make sure you fill your toolset," right? Uh, you learn a lot and, uh, you might learn, uh, you know, different organization, different places, different scope. Make sure you fill your toolset and your knowledge, 'cause that's k- something that's going to stay.

Titles don't matter. You know, roles don't matter. But what you gain and the knowledge, that's something that's going to stay forever, and that's something that you can instill on others. So I started my journey with great mentors who shaped my career and, um, again, then I moved on to a different organization.

Um, you know, and that [00:36:00] also opened doors with a lot of great mentors and, uh, here I am. I started off as an senior analyst and moved as a architect and, uh, now, uh, I serve as a interim CISO to a great organization and, uh, thankful to my mentors who have coached me and, uh, and also shaped my career. And I would say, you know, that my American dream is getting fulfilled and, uh, I'm still learning, right?

There's no, uh, stop to learning So, uh, have-- I would say, you know, anybody who wants to choose a career in cybersecurity, be open to learning. Do not get stuck to titles or anything because, uh, if you get stuck to that, you will never learn, right? Growth is never going to be there, uh, if you just, you know, stick to a role or like think about a title.

It's more of being a leader, you know, trying to grow [00:37:00] as a leader where you have to make sure, uh, doesn't matter if it's cybersecurity, if you're placed anywhere, you should be able to lead a group of people. Because at the end of the day, it's all about the people, and it's all about the trust you develop with them.

It's all about the transparency that you share with them, and it's all about the teamwork. It's how best your team is, how best you build the trust with them and help them work as a team and create a safe environment where they c- where they can grow with creativity and grow, um, as a person. And I always say that, right?

Like, uh, a good leader, someone... When someone goes on a vacation, the team should be able to be self-sufficient and manage on their own. You have to make sure you create leaders and if in case one day you're not there, there should be someone in the team who could just stand up and take the team and run with it.

That's a sign of a good leader, [00:38:00] right? Uh, so, uh, make sure you learn, have a mindset to learn, and also make sure you have a mindset to be flexible and work with people. So that would take long ways. Doesn't mean-- matter which scope you are, if it's cybersecurity or data analytics or different area, right? Uh, that's what I would recommend.

ward_1_07-14-2026_083941: Great, great insight. So I'm, I'm curious, if you could go back in time, we'll say 15 years, if you go back 15 years, knowing what you know today, there any advice that you'd give a younger self?

squadcaster-b457_1_07-14-2026_083941: I would say, um Be more open, be more confident, right? Um, and, uh, there are a lot of, lot of people who want to kind of mentor you, who want to coach you through your career, right? Early in my career, obviously, uh, I was little, little [00:39:00] intimidated with the environment, and it took some time for me to gain confidence to work in environment that is different from what I have been, right?

Uh, so I would say be more confident. Be, uh, uh... Don't be afraid to ask questions. I would say that, right? If anybody stops you, never be afraid to ask question. No question is simple. No question is, uh, you know, uh, kind of silly. Be confident, ask question, ask the right question, be open to learning. I, I would say that.

And, uh, you know, initially, I would question myself, "Should I ask the question? Is it the right thing to ask?" That was way... I'm talking 20 years ago. It's no longer the case. I'm, I'm pretty, uh, you know, extrovert, but even with- within me, there were times where I would question, "Should I ask this question?" You know, this is, you know, uh, this is a leader, like, you know, uh, two grades above me.

Sh- you know, is it appropriate to ask questions? [00:40:00] So don't be afraid. Be confident and reach out to people. Never hesitate to reach out to people. There are people out there who wants to-- who want to help you, right? They have been in the same, same journey as you. So, uh, they will definitely help you to grow, uh, and, uh, that's, that's kind of what I would say.

Um, and but, uh, I would say I, you know, I've learned a lot through my career and, uh, you know, as I've been, I have grown, you know, in every step of my way. There has been failures. Uh, I would say, uh, never be afraid of any failures because, uh, there is no leader, you know, uh, the-- who had a perfect career, who had a perfect, you know, uh, uh, you know, kind of successes in their career.

You have to fail to learn. Never be afraid to fail. And, uh, again, even if you [00:41:00] fail, don't think the sky is falling, right? Uh, you know, make sure you stand up. Make sure you try. You know, make sure you go ahead. So that's kind of, uh, what you have to have in you. It's all about you, and that's what, that's what I've learned too.

Uh, you know, it's-- there might be outside influences, there might be politics, there might be everything, all the noise. Learn to filter the noise. Uh, so you have to learn to filter the noise. Learn to ask the right question. Be bold, be brave. Always understand there are people out there who also look out for you, who's there to help, who's there to mentor you, so reach out.

ward_1_07-14-2026_083941: Great tips. Veena, if folks want to connect with you, what's the best way to do so?

squadcaster-b457_1_07-14-2026_083941: they can always ping me in LinkedIn and also, you know, connect with me. I'm there to help people, mentor people, share my experiences and, uh, help them to grow too. Here to help. You know, I want to-- Here's what I would say, [00:42:00] Ward, right? This, uh, country and different organizations have given a lot to me, right?

I do believe, I strongly believe in paying it forward. And if there's any way, uh, that I can pay it forward, I would do it. Without hesitation, I would do it. Yeah

ward_1_07-14-2026_083941: Well, I feel like you're probably gonna get an influx of connection requests, so there you go. Love it. Love it. Well, Veena, thank you so much for joining today. This has been a great episode

squadcaster-b457_1_07-14-2026_083941: you so much. Well, thank you for the opportunity. Uh, have a great day and good luck in everyone's career and endeavors. Thank you so much

ward_1_07-14-2026_083941: And big thank you to the audience. Hope you enjoyed the episode today. Please tell others in your network to follow and listen. This has been another exciting episode of "Guardians of the Data." See you next time

Speaker: That's a wrap on another episode of Guardians of the Data. Thanks for tuning in for show notes and more Visit Guardians. The data do show Guardians of the data is made possible by support from [00:43:00] Centro to see how we help organizations discover and classify all of their data accurately and automatically while quickly achieving scale data protection without the fuss, please visit sentra.io.

Catch you next time.

Risk Isn't Static - Guardians of the Data - Veena Nagarajan - Episode #55
Broadcast by