Data Hoarding Equals Liability - Dameon Sherman - Guardians of the Data - Episode # 56
GOTD - Dameon Sherman
===
Speaker 2: [00:00:00] Welcome to Guardians of the Data. I'm your host, ward Balza. Each episode will explore the passions, expertise, and real world experiences of security leaders who are helping the future of data security and governance. Guardians of the data is made possible by support from Centro. To learn more about our AI powered data security platform, please visit sentra.io.
Let's dive in.
Ward Balcerzak: Welcome back to another episode of Guardians of the Data. My guest today has over 15 years of experience in the industry. His experience spans military, contracting, consulting, and the enterprise. Currently an SVP of information protection within financial services, Damian Sherman, welcome to the show
Dameon Sherman: Ward, thank you for introducing me and I am excited to be here and I'm looking forward to this great episode of Guardians of the Data
Ward Balcerzak: Oh, it's gonna be great. We're gonna make it so, for sure. For sure. So Dameon, in your professional opinion, what's the biggest data security challenge organizations are facing?
Dameon Sherman: [00:01:00] Ah, there's so many, but you know, if you look at it, it's people understanding what data they have, where it's located at, and the type of data, and the classification of data. I, I see, you know, that is a, a huge challenge, you know. I remember there's an old adage says, "You cannot protect what you don't know," or, "You can't protect what you don't know that you have."
So, you know, closely some of the things that goes with, you know, data, you know, for say data protection. So, you know, that's a huge challenge and making sure that people understand, you know, their data, but also, you know, data quality is a, you know, some of the other things that come to mind. So those are the main things.
But, you know, but knowing where your data, knowing where your data is
Ward Balcerzak: two good ones. Two, two very good ones. So let's start with the first. We're gonna come back. I wanna,
Dameon Sherman: Yeah. Yeah
Ward Balcerzak: the what and the where, right? I mean, y- y- you've been in the industry 15 years, I've been in the industry 20.
Um, it's, it's not a new concept, right?
Dameon Sherman: Yes
Ward Balcerzak: you know, many [00:02:00] organizations that that's kind of a, a 101 fundamental. You know, know what your data is, where it is, its criticality, who has access, the whole nine yards.
Dameon Sherman: Yes
Ward Balcerzak: we're talking about it. You mentioned it's one of the biggest challenges, which means we haven't solved for it. So, or not everybody at least has solved for it.
So for our listeners, Damian, like what do you think folks should do? What are the foundational items people should be doing today if they aren't already?
Dameon Sherman: Well, one of the, the, the things, you know, is just like how you catalog your physical asset, right? You catalog, you put them in some kind of CMDB or something. You probably should look at the same thing for your data management because you need to know where your data lies, right? Whether it's in the cloud, whether it's on-prem, whether it's hybrid.
And you need to keep good records of it because here's the thing. There's one thing that's constant in the industry is if you look across all the ch- AI meaning place right now, change is just constantly [00:03:00] going. So when people leave the, your organization, then you should still know where that data is.
Because if you don't, then how are you gonna protect it later? How are you gonna find that important data for, you know, regulatory response? So, you know, catalog your data, find a way, you know, to... And I'm not here to promote or sell any systems or any CMDB per se, but I think, you know, we should treat data just like how we treat asset management.
We gotta inventory, we gotta catalog it, we gotta mark it, we gotta tag it, you name it. That's, I mean, those are some of the things that you need t- that comes to mind that you need to make sure you're uniquely aware of.
Ward Balcerzak: I, I think that's a great perspective. And, uh, uh, it's funny, I've had this conversation a few times, uh, well, say recently, but, you know, really over the last year with, with many different organizations. And what I find funny when we all talk about CMDBs, just in general,
Dameon Sherman: Yes.
Ward Balcerzak: generalized CMDBs, you [00:04:00] usually get a laugh when you bring that up at like a, a co- a, a talk or something like that, because most organizations, not all, most, are unable to trust their CMDB, right?
It's
Dameon Sherman: That's true.
Ward Balcerzak: That's true.
They have multiple. Um, I, I
Yes
last company joined and I said, "Hey, do we have a CMDB?" And, and the person I was talking to, same thing, he laughed. He goes, "Well, we have three."
Dameon Sherman: Yes.
Ward Balcerzak: like, like, okay. He's like, "You're gonna get X data from this, X data from
Yes.
Between all three."
So, let's, let's stay on the CMDB topic for a
Sure, sure
I, I agree, I think a data inventory, a data CMDB, incredibly important.
Maybe it's the same
Mm-hmm.
As your asset CMDB, maybe
Sure
whatever. But from an accuracy perspective, any thoughts on how folks can actually stay on top of that?
'Cause it's not a one-time thing
Dameon Sherman: No, it's, uh, it's continu- same thing as continuous monitoring. [00:05:00] Just like you monitor your firewalls, just like you monitor your IDS systems, right? You just don't go put it in and left it and says, "Eh, got a gate here." It doesn't need to go and inspect the gate or inspect the fence, right? It's kind of the thing.
Well, when it comes to CMDBs, and one of the issues is, is integration, right? You gotta make sure these things integrate, you know, with your thing, with your other prospective tools that are collecting data, correct? So the integration is one. Interoperability is another. You know, you don't want some agnostic or ad hoc system that just seems to be that standalone thing that you get, you know, information out of.
And so, you know, so the thing is this, it's gonna take continually monitoring of the system that you have. But one of the thing is, you know, as you know, when you integrate systems, you use APIs to integrate to another system. So you gotta... it's like balancing act. Now, why do you not trust the data? Because you have disparate system.
You're not sure if this other system that's the so-called CMDB [00:06:00] one or the so-called CMDB two is the one to trust, right? But if they're, if you make sure that they're integrated, interoperable, then it's a little bit better because you can sort of balance what the information is getting. Now, is there a one-size-fits-all approach for CMDB?
The answer is no. But the key thing is integration is the key. How does this integrate with other upcoming systems, whether it's your JIRAs, whether it's your, uh, audit tools, uh, can't think... Archer. You know, like I could think of the Archer, but you know what it...
Ward Balcerzak: man, you went old school on that
Dameon Sherman: That's exactly it. You know, or your Archer like GRC t- you know, there's, there's others out there, whether it's that.
But see, you know, making sure that the system can integrate with these things, you know, seamlessly, and making sure that these things are automated. There's an automated flow, right? Not a manual input, because if you do manual input, you know, you're gonna slow the system. But you know what a big thing that creates accuracy is [00:07:00] actually the design.
Sit down on paper, make sure you design the flow, make sure you design the elements that are being captured. Make sure you can get a standard that you can agree to that this is the elements, these are the things, this is what's necessary. You know, making sure, don't do that last. You know, design the elements, design the things that you want to capture, document the things you want to capture, and making sure that it's available for others who come later, either after you or new joiners or, you know, that when they're onboarded, they can see these things.
So that's how you improve the accuracy
Ward Balcerzak: I like that. And, and, and I, and I like your, your concept there of actually designing something first. I think far too many folks are building the vehicle as they're driving, you know, 100 miles
It's
the highway, right? It's
like, no wonder, no
Yes.
Problems.
Um, Exactly
you actually, in, in, in, in your answer at the end, you went to where I was gonna go [00:08:00] next.
So you mentioned, you know, people onboarding, they can find the information. W-
Mm-hmm.
I was gonna be curious on your thoughts. So a CMDB, incredibly important. Incredibly important to have that data for many, many reasons. But if you don't actually use that data, what's the point? And you teased out new people onboarding, find it, use it.
So um, you know, if, if we have a CMDB, hopefully our, our listeners do, what should you actually do with it from a next step perspective for data security?
Dameon Sherman: So from a, you know, if you have one, one of the things now you're gonna, you know, test, you know, s- do some sample, see the quality of the data that's in there. And, you know, making sure that it's connecting, collecting, uh, pertinent data, not some, you know, to be collecting this stuff, to be collecting that.
Make sure that, you know, it's useful data, it's actionable data, you know, not you're collecting data... There was a saying I heard from a, a, [00:09:00] a talk, you know, years ago. It was from a Navy, you know, when I was working with the military. It was from a Navy, uh, instructor. She said, "Ten thousand feet view is not actionable."
So you gotta, you know, don't think of just the high level. Think of how, you know, you can design stuff to be accurate. So when you go to your CMDB, make sure that it's collecting useful data. Make sure... And also make sure you cl- go back and clean it up. You know, make sure you have periodic cleanup schedules and making sure that, you know, it's not collecting erroneous stuff.
And also to, you know, to purge stuff, because if there's assets in there that are no longer of value or retired or decommissioned. So, you know, I think when you have your CMDB also, make sure you have active, uh, to be decommissioned, decommissioned, or expired, whatever categories. You know, I'm not saying those are perfect categories, but think of it in that sense, you know, with your CMDB.
So that's...
Ward Balcerzak: cycle is
Dameon Sherman: Yeah.
Ward Balcerzak: like. Yeah
Dameon Sherman: approach. Correct. That's [00:10:00] it. The, you know. But making sure that you have a lifecycle design, you know, around retention, you know, and all these things
Ward Balcerzak: I, I, I think you said something there that I really wanna highlight bold, italicize for our listeners.
Sure.
I, I kinda mean it as a funny ha ha, but I also mean it very seriously 'cause this is
Okay.
A conversation I have many times. You mentioned deletion as part of that, So not only the asset, but data itself. Listeners,
Yes
keep data or assets forever.
Yeah.
Purge every now and then
Dameon Sherman: And your deletion should follow your retention schedule, right? Because your retention schedule is going to be governed by what? Legal, regulatory, contractual, right? Whatever those things are. But as soon as those things are expired, you need to go and get rid of it. And also, you know, you don't want data that's not...
should be around anymore. You're storing it, then you're, you [00:11:00] know... What about breach? You got to think of these things. What's the risk here? What's the risk if there's a breach, you know? And with now, with the upcoming quantum, you know, phenomenon that's here, you know, harvest non-decrypted data. So, you know, and didn't mean to side in that, but, you know, these are the risks, and this is a very, you know, high risk, you know, to your data that if you're storing that you don't need, you know.
Hey, here comes quantum. So
Ward Balcerzak: Yeah. Yeah, absolutely. I wanna come back to that, too.
Sure, sure. Sure, sure
back to your second answer, 'cause your second answer is actually something, you know, 50-plus episodes of, of this show now we haven't really talked about, and you mentioned data quality,
Sure.
I think is interesting.
Mm-hmm
And data quality, at least in my opinion, would love to hear yours, uh, for sure. In my opinion, data quality, not really a security [00:12:00] thing, but
It is. Yeah
about a Venn diagram, right, overlapping circles, there's absolutely
overlap, right? I mean, obviously, you know, common denominator is data,
Perfect But, uh, so I, I, I wanna, I wanna touch on that. Data quality, you mentioned it. Um, this is something I hear more and more lately the age of AI,
right? Data quality with that. So tell us more about your thoughts on data quality and how that's a problem these days.
Dameon Sherman: It's a problem these days because we have all these tools that are collecting data at record speed, right? We're ingesting this data. You know, because if you, if you think of it, think of all the... With AI and even prior to AI, one of the things that has happened to our society is the interconnection, right?
Interconnectivity. And because of that, you are gonna be faced with a record and a collection of data. Now, how much of that data [00:13:00] is useful data? How much, you know, what's the risk to that data? So right, you're identifying it. And also, what is it that's operational data, data that you can use, data that's meaningful, not, you know.
Because the reason why you need to do that, because if you don't do that, you're gonna increase your storage costs, right? Because you're gonna be storing a lot of stuff that you don't need to store, right? So you're gonna look at it and says, "Okay, is this a bunch of erroneous things that I'm collecting?"
So then, you know, so in data quality, what you're doing, right, you identify the data that's of importance. You identify the, the data that's useful. You identify through all of that, that's gonna drive the protection mechanism, right? Would you, uh, uh, ca- uh, catalog or store non-sensitive data that's out in the public domain that, you know, is just public data.
Why are we storing that data? Is that, you know, is that a waste of our time? But the other thing is to what protection mechanisms are you gonna have [00:14:00] around that data now. If it's sensitive data or, you know, or, you know, in the government sense, classified data, it's a little different case, right? Because then you need to separate the data, right?
You'd separate where you're storing that, you know, how you're protecting it, the access controls to it. So those are all part of data quality because if you can't identify the data, because what's gonna lead to data quality? Also, you're gonna tag the data, right? You can identify it, but you wanna tag it, so you can find the data.
But, you know, it's gonna drive what your security apparatus is gonna look like. So that quality, you know, incorporates a lot of things, a lot of reviews, a lot of understanding, you know, and a lot of definition, you know, what is useful, what is not.
Ward Balcerzak: Completely agree, and, and, and I'm glad that's, that's where, where, where we went with that because I, I, I think that is probably one of the most important pieces or facets of data security. You know, again, I've been doing this for a very long time. I've worked with organizations and they say, "Protect the data."
Like,
Yeah
[00:15:00] cool. What, what am I protecting?
There you go
all of it." Like, really? All of it? Like, all of it. 'Cause we can, right? We could build castle. You know, again, years ago you built the castle, right? Everything was in the data center. Like, we could build a castle, and we can make it, uh, very, very fortified, and nobody's ever gonna get in, and only what's allowed out is allowed out.
But that's gonna be expensive. Expensive, high operational costs, need people to do it, versus, "Hey, organization, what are we protecting?" "Oh, this data in this location is highly sensitive." Cool. Let's talk about that, right? You've, you've minimized the scope and now
Yeah
can actually define controls around that scope
Dameon Sherman: Correct. Correct. And, and, you know, as you stated, you're, you, you're defining the controls. And controls is a loo- loosely used word, you know, we hear con- because what do we tend to do? The over application of controls to [00:16:00] everything. I need a control for this. I need a control to open the door. I need a control to close the door.
But the thing is this, once you identify and you catalog and you, you know, you make it meaningful, then your controls are gonna be applicable to that off instead of all these plethora of controls that it's a nightmare to manage. 'Cause controls, you can get into controls heaven if you're not careful here.
So
Ward Balcerzak: yes. And it's never fun, I mean, you're in financial services, I've been there too. It's never fun when you go through an audit and now you have to produce
Yes.
Statements and
Exactly. And all that. It's
Dameon Sherman: Exactly.
Ward Balcerzak: to deal
Yeah
All right. Dameon, you opened the door slightly.
Like I said, I'm gonna kick it open. this is part of your, your day-to-day. So you mentioned harvest now,
decrypt later, right? [00:17:00] I kinda sorta hate that I'm bringing it up
No, that's not right
you started it because I mean, look, you go to a conference, there's at least one talk, right, out there about quantum computing.
I think it's gonna be one of the biggest, um, discussions, right? Going, going forward. I think AI is, is kind of forefront, and now we're gonna be in, in quantum in the near future. So let's talk about that. Harvest now, decrypt later. It sounds super scary.
Dameon Sherman: It does. It does. I'm sorry. Go ahead. I didn't mean to cut you off, but it does
Ward Balcerzak: Well, I was gonna say, what, what do we do about it, right? I mean,
Dameon Sherman: It's
you know-
so, you know, one of the things, if you go back and read the federal government memo and, you know, especially the ones that came out of NIST, and then you read, you know, the presidential memos that followed through. And, and when I say, I should say NIST memos, what I mean is NIST directive. You know, what is the special publications, uh, correction on that.
But, you know, when you look at the different executive orders, and there is plenty that [00:18:00] has been released, one of the things that you will know at the forefront, inventory, right? Inventory, inventory. So that is one of the first things. Again, what did I mention? Know where your things are, where your data lies, where your assets is.
That's another thing, right? Another thing is making sure that people understand. You know, you have to do education. That's another thing. But the, the whole premise behind this Harvest Now is that it sounds scary, but what it is that's happened, the, the bad guys or, you know, the malicious, uh, folks have changed their strategy, right?
Because instead... Before, when I wanted to hack a system, I'm hacking for what I can get from it right now. Uh, you know, you know, how much can I get? How much can I get? How much of that hacking data? You know, you're not interested in encrypted data. You're interested in unencrypted data at best, you know, because it's easier to move.
You know, and you can s- you can do something with it right now. Now, the threat actors are [00:19:00] saying, "Oh, no, no, no, no, no." If you have encrypted data, then there must be some sensitive stuff, something you don't want other prying eyes to see. So with, with that said, they're like, "Hmm, you know, let me hold, go ahead and hold onto this information right now till the technology matures, so then I can possibly crack it later."
Or crack, you know, or possibly defeat the crypt, you know, the cryptography, you know, controls. When I say controls, I'm talking the cryptography technologies and stuff that's built to protect that data. That's what you're looking to do with harvest now. So, you know, if you think of the quantum computing phenomenon, and if you look at what's happening is, with the qubits and the superposition, and not getting into the whole technical, you know, aspects of it and what a quantum computer can do because of the way, you know, it, you know, processes computation com- you know, compared to traditional sequential computations.
You realize that you, [00:20:00] it's what used to take years to de- defeat, and now is just gonna be a matter of, you know, maybe an hour or two hours, you know, depending where the technology goes. Now, one of the things with the quantum computing, I know we are all fixated on the qubits and so on, but I think, you know, the way I'm looking at it, as AI gets better, what happens when you pair AI with quantum?
Because, you know, it's either gonna be AI on steroids, is what some people are calling it. So, you know, so pairing those two together and looking at how you can defeat, you know, encryption technologies or controls is a real thing. And, you know, and if, I don't know if you noticed, there was a... I can't remember the executive order number.
I think it's like 1449, where, you know, the government's like, "Listen, federal agency, we need you to get your act in order. We need you to know about your data. We need to know what your roadmap looks like. When are you gonna, making sure that you're implementing [00:21:00] these quantum, you know, algorithms and stuff, you know, in your system?"
I mean, that was directed by the president and, and his team. So, you know, it's, uh, it's very real. And then he's saying rest of the industry by 2030, you need to be do- have something similar. So it's, you know, when the president... And I mean, if you look at that memo, it's very prescriptive. You hear what I said?
It wasn't high level. It was very prescriptive. So that should tell you that, hey, we have a real threat right here
Ward Balcerzak: Absolutely. Absolutely. So, you know, y- your thoughts for our listeners on preparing for that. Is that more of what we already talked about?
Dameon Sherman: Yes,
Ward Balcerzak: and where it's at. Anything else?
Dameon Sherman: Definitely. I mean, those are the main things because it, it's very easy to get overwhelmed by the ask. And when you're getting, you know, you... depending on your contractual requirements or the regions you operate in your regulatory local jurisdiction laws, it's very easy to get overwhelmed by the requests by these different bodies.
[00:22:00] But, you know, simplicity, start with what you already know, right? Instead of trying to, you know, there's a saying, "Don't try to eat the elephant whole. Be like an ant, eat the elephant, you know, piece by piece at a time." So that's what you have to do. You have to start with the basic things that you can con- that's in your control.
Once you get those things sort of, you have your handle on these things, then you can proceed to the more, you know, uh, things like, you know, looking how these algorithm... 'Cause remember, these algorithms, they require more computational speed or comp- not speed, but computational resources to operate effectively.
And these algorithms require more overhead because of the way they're designed, you know, compared to traditional, you know, uh, encryption as what we know of today or the algorithms and the ciphers. You know, the, the quantum algorithms and stuff, they're gonna require a lot more overhead. So then, you know, it could be a performance impact that you're looking at throughout your network.
So those are the things you're gonna have to study and to [00:23:00] understand how these algorithms, uh, behaves in your network and, you know, and the interoperability with other systems and so on. So, you know, and, you know, technology is of course moving forward with the firewalls and how, you know, some people are using like a hybrid, you know, approach, you know, when solving for this, you know, quantum, you know, phenomenon.
So there's things that's being done, but to me, start off with the, the basic. Know what your systems are, what they have, what they contain, as we spoke earlier on, you know, and then identify the critical ones and id- you know, look at the data that you have. The other thing is how long... Look at your re- remember I said retention schedule because, you know, if you're gonna have data around that needs to be protected, then you wanna make sure that it's protected by the, the, the right, you know, quantum algorithm.
And also, remember we talked about the deletion. That's the thing. So, you know, you wanna start looking at, you know, what you [00:24:00] don't need and what you can, you know, get rid of and stuff. And it's not necessarily, you know, when I, I hate using the word de- deletion because sometimes people says, "Oh my God, I gotta go delete everything."
You know, if you need to store something in a cold storage or something, well, figure that out. If that's your way of deletion, where you move it off the active network, move it to a cold storage or put it on tapes or whatever, but just making sure that is not part of your active data set. And even then you should go through and look, even if you have tapes, you might be storing data that's 30 years old and the retention schedule's only five years old.
I mean, do the math. Do you really need that? 'Cause chances are
Right
You know, you hadn't accessed it in the last five to six years. So those are some of the things
Ward Balcerzak: I mean, data hoarding is a real thing,
Dameon Sherman: It is
Ward Balcerzak: it time and time again. "Hey, I've got a, a, a data retention policy." Cool. Do you
actually follow it? Number one, do you actually follow it? Number two, do you follow it each and every [00:25:00] time?
And I think the answer to number two is, well, no, not really.
Like, okay, let's talk about that.
Dameon Sherman: Exactly. Definitely. Definitely
Ward Balcerzak: So, so Dameon, y- you've been around for a while, like I said in the intro, 15 years, right? And, uh, you know, certainly, um, you know, I was looking at your LinkedIn, it's, um, an, an interesting journey. So us about that. How did you get to where you are today?
Dameon Sherman: It's very interesting, you know, looking back at how I started. You know, when I- I was in the National Guard when I was going through college, and one of the interesting thing was I was doing some IT things that I didn't even understand why I was doing certain things in terms of data security.
And, you know, excuse me, sorry. Working with the different frameworks, I remember working with different, you know, back the... Not to date myself, but you know, there was the DISA CAP, the DIA CAP, then it became the RMF. You know, it's, then you have CSF, you know, these different, you [00:26:00] know, risk management frameworks, you know, cybersecurity framework, and the DIA CAP, I'm sure of all the, the, the long acronym.
But- I was, you know, performing elements of these accreditations and authorizations that I didn't understand at an early age. You know, "Go secure this ring," you know, "Go follow these requirements, and then when you're done, report back to us what your findings are." And, you know, you, you had this checklist, you get it done, you submit it to someone who submits to someone else and, you know, "Okay, you're ruined now, you can operate."
You know. You know, I didn't understand it completely. So while I was in college in the State was, you know, I worked with the National Guard. I worked with them at first, then I joined them. That was interesting. And then also after s- after... You know, one of the funny things that, you know, I got deployed right at the end of my, you know, my senior year at, you know, right before I gradu- right after I graduated.
Right after I got deployed to Iraq. And that opened up a [00:27:00] lot of interesting possibilities because, you know, after I got deployed there, did all kind of different things, you know? You know, you started doing some of the IT work, then next thing you know, you're doing operations work. Next thing you know, you're doing security work with, you know, with the military as, you know, as a soldier.
So when I came back stateside, I had someone who came to me with an interesting, you know, proposition after I came back from about a year and a half. They said, "Hey, would you interested in being a contractor working overseas?" I said, "Okay, I'll think about it." You know? And at the time, I had a couple offers.
I had offers to go work with Northrop Grumman, uh, Lockheed Wa- you know, Lockheed Martin, so I had a couple interviews. So of course, you know, I was like, "Okay, let me see how these things work out." So I end up accepting, you know, working overseas in Afghanistan and working with NATO. And I started working with command and control systems, you know, they call them C2 systems.
[00:28:00] And what you're doing, you capture the common operating picture. And there's a... I've seen a lot of these different phenomenas here now become people very obsessed with, oh, you know. But we're doing this stuff, not to brag, the military were doing this stuff a long time ago. And but it was interesting because now you have disparate IT systems that you have to connect on.
The funny one was I had to troubleshoot a, a c- a VPN concentrator for VPN connections. It was written, it was in French to connect it to the sy- English got a part, and I tell you what, I didn't know a lick of French, but somehow I struggled through it and it connected. I still can't remember how it got connected, but it did.
But, you know, but those, you know, opened up my eyes to like, okay, there's a world out here with different possibilities. And so, of course, you know, did that for a while, worked overseas for a while, so I left that. After about a year and a half, and I went to work in military contracting. Now that was a brand new [00:29:00] area Because I knew nothing about government contracting.
You know, you cannot-- You know, one of my favorite things I learned in contracting, you cannot, you know, uh, you cannot s- you cannot say something that I'm gonna... I want you to do this, but if you don't put it in writing You cannot blame the executing part. It goes, it always goes against the offerer because you cannot imply what you want.
You have to put it in writing, you know, because you're the one that construct- control that instrument. So, you know, you know, so if, if, you know, they said if it's, it cannot be implied, therefore it goes against the offeror, you know, the offeror which is you. So those are some of the things. So I had to learn about contracting from a writing perspective and operation perspective prior to fixing the IT system that's associated with it.
You s- you said something earlier in, in this, uh, podcast, was the thing is this, you cannot go design the solution and you don't co- define [00:30:00] your requirements, right? Just like we talk about design your elements. Well, that, that's some of the problems you'd have in contracting was, you know, you have the software that was designed and then you try to stuff everything else to make it work according to the requirement.
It, it doesn't work. It creates issues because, you know, the process has to be designed and then you design the software around the process because then it works better that way. Then it, you know, allows integration. So those are some of the things that I had to do. And I mean, I had to learn about the FAR, you know, the f- you know, you know, the Federal Acquisition Regulation and Defense Federal Acquisition Regulation.
So, you know, I had to learn a lot of contracting rules. And I tell you, it's not for, for a technical person, it's not easy learning that stuff because you wanna poke your eyes out because it's unlike anything you're doing. And, you know, but you have... But those are important because those are important life lessons that you'll carry with you, especially when responding to regulators because that's your first taste of responding [00:31:00] to regulators.
So one of the things, you know, the interesting journey, I was doing what they call you a combat IT contractor because you're in austere conditions and you're in dangerous situations also, you know. And, uh, you know, I will never discuss or say some of the things, you know, that happened, but it's, it's quite interesting because, you know, you have to keep these systems up and running regardless of what's going on with you.
So you have to learn to tune out the noise, which sounds a little bit crazy, doesn't it? Because you're in these dangerous situations, but you have to do that in order to make these systems work. So did that for a while, spent like a good few years, good five years plus overseas. Then when I came back, you know, I was like, "What, what do I do now?"
You know, "What do I move on to?" So, you know, went and interviewed at a local job fair and, uh, I, it was between, you know, uh, uh, it was between Boeing and the Navy contractor that I worked for. [00:32:00] So I ended up going with them and it was funny because here I'm an Army person all of a sudden going to work on And, uh, with the nuclear program, especially the aircraft carriers.
And, uh, that was quite interesting because, you know, that's a whole different level of accreditation systems, you name it, secrecy, you name it, and all these things. And it was very interesting that, you know, you had to understand how those technology affect the people that are using it. But the interesting journey was I had to, again, here's another learning process.
I have to learn how the Navy does something, why. Even though I was prior military, but that was a whole different aspect because, you know, especially the nuclear. Nuclear, it's its own thing, and it's, you know... And it's one of those industry which is quite unique because you have two different body, right?
While the Navy might be the user of it, but guess who regulates it, right? The Department of Energy, 'cause it follows. So, like the [00:33:00] Navy's, uh, leader is what's called dual hatted because he's, he tends to report to both people. So he's like a civilian and military at the same time, you know, which is kind of unique itself.
So, you know, using that and learning the different system, the different technology, and understanding risk, what's risky and what risk means in that context. And, you know, those are some of the, the things, and trying to keep yourself abreast of the different, you know, things that are changing, emerging technology and how that impacts your work.
You know, it is again, you know... And then so did that for a while and, you know, after about several years there, I decided to do something new. I wanted-- I've always wanted to do healthcare and I always wanted to do the financial industry. So, you know, when I did about a year, you know, I did-- I started off with a financial organization, then I switched over quickly to the healthcare sector.
Did that for a little while, and then I switched back to the [00:34:00] financial industry where I'm at back again. But it was interesting just looking at the different parallels, because one of the things that these work have in common from where I came from the Navy, they're highly regulated. That's the key word right there.
They're highly regulated. Those three industries are highly regulated. There's a lot of eyes, a lot of interested parties. You know, a lot of people want to know, "What are you doing with my data, and how are you protecting my data?" That's the commonality that I've noticed with all three i- uh, industries. that's
Ward Balcerzak: was, I was just gonna say, you spent a lot of time in highly regulated, um, environments for sure, for sure. Some people might call you crazy for doing that, but, uh,
Dameon Sherman: Yes. I know, I know, I know
Ward Balcerzak: I too have done some of that, and I tell you what, for me, I, I wouldn't trade that experience for anything 'cause I think it was definitely good.
So
Yes
on that vein, I wanna ask you, I, I ask some of my guests this, I wanna ask you for sure. So knowing what you know [00:35:00] today, right, all of these years of, of dealing in, in highly regulated environments, um, if you can go back in time, would you give yourself any advice or make any changes?
Dameon Sherman: Sure. It's, you know, hindsight is 20/20, right? Hindsight is always 20/20. And if you say, "Oh, you know, everything is perfect, wouldn't change a thing," I think my approach and how I tackle the education aspect of The things I've learned over the years. And when I say the education aspect, I'm not me- me- merely speaking about in a classroom or, you know, the education comes to the business of what you're doing, right?
So looking back and understanding, you know, one of the things that I think that has been taught to you when you were, you know, like you, I figured you have a computer science degree, something in there. You're taught so much technical, right? [00:36:00] Technical, technical, technical, technical. Technical this, technical that, technical organization, technical...
And I think one of the thing is that you need to have a balance. And then, you know, what I would look back at is networking. How do I network with other peers and non-peers, right? Because there's something to be learned. And I remember I said to you earlier in this conversation about taking things from the government contracting realm that I've learned about contract and procurement that actually helps me today.
So it was not IT related, right? Remember I said I had to learn to go read the FAR, but now when I see a contract, I'm not scared of a contract. How can I read through a contract? I will understand it, and understanding what's of importance. And if I don't understand, I know who to go and get some, you know, possible help.
You know, forget AI, but, you know, reach out to someone, you know, to give me more, more insight. So going back and look, what I would change is just the education aspect in networking, [00:37:00] you know, meeting with folks of, you know, different, you know, mindset, whether, you know, they're in the industry you work in or just a totally different industry.
Understand that. You know, because what it is, is, you know, going forward right now, you have to be flexible in terms of what you know, right? Because with AI, one of the things that you still have to understand, you still have to understand the business and what's some of the best things for... that makes the business work.
So when I say meet with people, you know, other than your mindset, technical mindset, what they can give you, they can give you what good looks like in an operating environment for the industry you're in or the industry you're not in. So when you do get there, then you can quickly identify some of the things that are, that are out of place.
Like you can says, "Okay, this might be..." Like you, you're a field CISO. I know you, when you walk into an organization, you have a 90-day plan. So what does... [00:38:00] So it's like, you know, what does my 90-day plan looks like when, you know... And that 90-day plan shouldn't just be for the CISO, it should be for me when I walk into any organization.
You know, it doesn't matter what stature, what title you have, you still have to have that kind of focus. So, you know, you know, when you can spot what good looks like and what bad looks like real quick, it saves time and it saves the churn that you would, you know, normally experience, and it saves the burnout, 'cause burnout is a thing, you know.
So- That's what I would do, you know, in a nutshell,
Ward Balcerzak: That's very good advice, and very good advice for our listeners. You know, I, I, I mention a l- a lot of the same to a lot of younger folks I'm talking to, right? A
Sure. Sure.
That are, uh, either have graduated or about to graduate, and they're like, "Ward, I want to get in industry. What should I do? What job should I go after?"
I was like, "Hold on, hold on. Before, before you focus on what job, how about you focus on getting some contacts, right? Meeting
Yes.
And, you know, that's, that's how you get to that
Exactly
job or second [00:39:00] job or whatever at that point.
Dameon Sherman: That's-- No, that is so true. And I've, I experienced that on my walks, my daily walks. I've had run into a few, you know, graduates or about to be graduates and, you know, they'll ask, you know, "Well, you know, what should I do?" And, you know, the questions I ask is, "Well, you know, about your studies, who have you talked in the in- to in the industry in your field?
What did they say? You know, what are some of the things, the challenges? You know, can you address those challenges when you walk in?" You know, today is not just enough to say, "I know about it," but what can I do about it? Wrong or right, you're not gonna have the answer because once you get in, the pre-canned notion that you have with, uh, uh, of the solution that you have may not be the correct thing.
It may need to be, you know, revised, revamped, and go at it again. So but how do you know about the challenges that are affecting it if you don't go and speak with someone in that industry? And you know, and it's not about, you know, what should I do? What are your strengths? How [00:40:00] does... You know, don't go somewhere where your strengths are not applicable to that environment.
Now, if you're looking for a challenge, you can do that, but my advice is look at your strength, hone your strength, craft your strength, and use that to work for the be- you know, i-i- you know, in the best, you know, possible vantage point as I, you know, as I stated earlier
Ward Balcerzak: I like that. I like that. So speaking of networking, Dameon, if folks want to connect with you, what's the best way to do so?
Dameon Sherman: LinkedIn. I'm always on LinkedIn. And, you know, and also, you know, I notice one of the things that I'm trying to do a little bit better on is the different forums, you know, because there's some interesting forums out there, and you learn stuff by attending different forums. So you can connect to me on LinkedIn if you see- if you're part of a forum that you think I would benefit from or, you know, let me know.
I mean, that's, you know, I'm always up for, up for that. That's the-- You know, it's, it's funny, when you reached out to me and I started watching all your, your, your episodes, it's like, "Wow, there's a lot of good information here." So, you know, [00:41:00] I'm not trying to promote Ward, but what I want to say, Guardians of the Data has a lot of great information.
Ward Balcerzak: Lot of great info, a lot of great folks, right?
Dameon Sherman: Yes
Ward Balcerzak: networking. And now, Damian, you are one of those individuals. You're one of my data guardians.
Dameon Sherman: Definitely. Thank you. Thank you, Ward. Appreciate it
Ward Balcerzak: So hey, this has been a great episode, Dameon. Thank you so much for joining me
Dameon Sherman: Sure, Ward, and I appreciate it. And thanks for having me here also. This has been, you know, as I speak to you, you know, it just reminds me of things that I need to do to, you know, hone my own skills in. So this is actually always, this cuts both ways.
Ward Balcerzak: Appreciate that. And thank you to the audience. Really hope you enjoyed the episode today and learned something. Please tell others in your network to follow and listen. This has been another exciting episode of Guardians of the Data. See you next time
Speaker: That's a wrap on another episode of Guardians of the Data. Thanks for tuning in for show notes and more Visit Guardians. The data do show Guardians of the data is made possible by support from Centro [00:42:00] to see how we help organizations discover and classify all of their data accurately and automatically while quickly achieving scale data protection without the fuss, please visit sentra.io.
Catch you next time.
Creators and Guests
