Stop Blaming the Human - Sam Wolf - Guardians of the Data - Episode # 59
GOTD - Sam Wolf
===
[00:00:00] Welcome to Guardians of the Data. I'm your host, Ward Balzerzak. Each episode will explore the passions, expertise, and real-world experiences of security leaders who are helping the future of data security and governance. Guardians of the Data is made possible by support from Sentro. To learn more about our AI-powered data security platform, please visit sentro.io.
Let's dive in.
Ward: Welcome back to another episode of Guardians of the Data. My guest today has over a decade of experience in cybersecurity. He's a cybersecurity leader, data security strategist, and risk management expert. Beyond his core role, he's active in the community through advisory roles, mentorship, and industry engagement.
He's currently the assistant director of engineering and data security in the financial services industry. Sam Woolf, welcome to the show
Sam Wolf: Awesome. Great to be here. Thanks for having me
Ward: Excited that we're doing this today, sir. So in your professional opinion, what's the biggest data security challenge that organizations [00:01:00] are facing?
Sam Wolf: You know, I, I love this part or the reason you have the podcast, right? I love the question. Um, you know, m-my, my play on something that maybe has a little better hook and, um, something that's been coming up quite a bit is, you know, the human's the easy answer, right? It's always something to do with the human. Um, my, my twist is it's us. I'm gonna point the finger back at us as security practitioners in this case, as humans.
nobody panic. Don't swerve the car, whatever it may be you're doing. But, as we think about how we're kind of evolving the space, right? We, we regularly put in the controls, the friction, the complex systems and places, and, um, forest through the trees problem maybe, right?
That did we make it easy to do, and did we ever ask that question, right? We're, we're security practitioners, we're control folks, we're risk folks. Um, rarely are we user experience driven, did we ask that question? Like, did they just find the workaround because the thing that you said they should do [00:02:00] sucks and is complicated and hard to navigate and has 12 forms and six links, and I don't know which one's right 'cause we have legacy information there? Um, but I would love to spend a little time, and maybe we can unpack that a bit farther and, you know, figure out why Sam thinks it is us and,
Ward: I was about to make you. I was about to make you. So yeah, I mean, I think most of my listeners are probably security folks. So listeners, pi-
out.
Yeah, pitchforks down, guys. Pitchforks down. Sam's gonna educate us on why that's the case and what we can do about ourselves here
Sam Wolf: Let's-- Well, let's-- Maybe there's a few points we could-- So humans are the weakest link. We'll break down that one, right?
Ward: Yeah
Sam Wolf: I, I'm a human, I guess. I'm a practitioner. I fit the mold. But, you know, systems and controls should maybe anticipate our behavior a little more, right? What's the definition of insanity?
Same thing over and over, right? If somebody keeps bouncing up against the same thing, they're probably not malicious, right? In our day-to-day as, you know, data security [00:03:00] folks, I'm gonna guess we don't find as many malicious people as we do, you know, "I just didn't understand. I didn't know," period, and full stop, right?
That we need to understand human behavior and help them navigate way they wanna work, right? I'll probably just repeat the phrase: how do you make it easy for them, right? The right thing is the easy thing long term. So that's maybe one of the first points, and I might pivot that into the training aspect, right?
We default to, "Let's just teach them a lot more," right? Take the class, fill out the thing, attest that you took it and you did a good job. Um, within the secure workflow shouldn't require training, right? We pick up certain devices, we engage in experiences in our day-to-day as just humans, and sometimes you're like, "Wow, that was a great experience." gonna guess that was never in authentication. guess that wasn't the logon experience or, right, changing your password or adding new credentials. I'm gonna guess no one ever sat back and thought, [00:04:00] "Wow, that was-- I really feel good about how that happened." and maybe that's the pivot that I'm, you know, driving from.
Some of my background has some of that digital product experience, right? And it, it has not taken a, a firm hold in some of these, um, security experiences that are usually under the covers, in the back door and whatnot, but they take time, right? And, as we-- I'm trying not to say the AI bingo word, but as more of that comes into play, that
Mm-hmm.
Consider some of those experiences, um, that people are gonna still need to interact with, right?
That won't have agents and whatnot
Ward: I was gonna say, I've never once had a great login experience. Um, I, I, I actually would love to have one now. Man,
Sam Wolf: Make you sit back and you're like, "Man, what, what would a-- what would make me like that was, hmm." 'Cause security requires some level of friction, right?
Right
if I just click and I'm there and I'm in my bank and I'm like, "What happened?" Like, oh, I've clearly been taken advantage of, right? But nothing happened.
I'm just in, right?
Ward: How [00:05:00] did I get here? What happened?
Sam Wolf: Yeah, we all know that we did 52 things for you on the back end, and we know you're walking down the street in this particular city, and it's your phone, and you hold it with your right hand, right? back to the, the panicky part of the other side of it, not just us as security practitioners, but as users, we want to balance that
Ward: You know, that actually brings up a very interesting thought. I, I, I'm, I'm stuck on that whole, like, what happened, right? Great user experience. Like, you, you are right. Like, you would almost think that you're had at that point, right? If magically tomorrow you logged into a system, I l- I love the idea of banking 'cause we all use it, we can all resonate with it.
In fact, I just logged in this morning to do something to my bank. So, I would be very taken aback, being a trained monkey at this point, if I just opened up my laptop, went to the website, and bam, I was in there. I'd be very taken aback.
Sam Wolf: He'd be like, "Um,
yeah, I'd be like,
call."
Ward: like, "What, what's going on? Who's watching me?
What's, what, what did I opt into that I didn't mean to opt [00:06:00] into at that point?" Um, I, I'm curious, kind of sticking on that for a second, because, like, y- you hit the nail on the head. We want, or in the past, we've wanted security to be a, you know, have a little bit of friction because kind of the idea there was they'll think about it, right?
They'll think about what they're doing, they'll think about whatever. I'm curious your thoughts. So if we made it easy, right? Made, made a login experience, for example, that's transparent, do you think people would stop thinking about security at that point, right? Just second nature?
Sam Wolf: trade-off question, and
Just
about it
round and rounds?
In the lead-up to this thinking, "Hmm, like, h-how do we continue to have a mindset of security where, you know, we have small parts of the organization that focus on it, and we democratize that out to the rest of the organization through those trainings and things so we are aware, we're paying attention to things that are odd and, you know, abnormal?" Um, it is a great flip of, you know, kind of where we started to [00:07:00] say, "Oh, that is-- How do we not lose that?" Right? That maybe the things that cause the friction that provide us controls, uh, might just be me, but when I'm in that moment and facing the friction that I or my peers put in place, right, we're users usually of the thing we did, that's not the time that I'm thinking about being vigilant and watching for stuff.
I'm thinking, "This is annoying, and I just need access to the thing that I need to do my job." And we probably need to do a better job r-reflecting those in the appropriate context to say, "This just needs to not be so," you know, whatever phrase you wanna put in there, bleep, et cetera. Um, it, it should not be that difficult in some of these cases, right?
And, I, get the pitchforks are probably still out for some, like, system was built 50 years ago, right? We layered, we stacked, we, we just kept adding. Is it worth the investment now to go, "Let's just rethink it and rethink it with what is the outcome, what's the problem, and how do we build a [00:08:00] system and an architecture that supports that so they can do the thing they need to very simply," right?
If I just need access to something, there's probably some tech debt that's built in, right? I get the pain, I get the layers and the peeling back, um, but there's math problems to be had for ROI too, right? How much time did they sit there? It might be harder to get that information, right? I don't know how much time I've spent trying to figure out which authentication thing I need or which entitlement. there's a, there's a problem to be had and solved there, I think, as well
Ward: So that actually goes, and you probably meant to do it this way, goes right back to your first point, which was, you know, understanding human nature, right? You know, build something for how they're doing. And so this is probably where the pitchforks are out, right? 'Cause a lot of security folks, at least front lines, right, early in their career, they kind of joined assuming, "I don't have to talk to people," right?
"I can sit back. I can be the department of no instead of K-N-O-W." So let's [00:09:00] get those pitchforks put away. How, how do you think that we solve that for us, for the security folks, how to actually understand human behavior and better relate to the folks that we're trying to help protect?
Sam Wolf: again, we've probably been in some of those positions ourselves trying to accomplish something, right? There's probably some framework or cool mnemonic we could come up with here, but, essentially it's how do we align to the work that's being done, right? What are they trying to complete? Why is there time pressure?
There's always time pressure. I needed that, you know, before I go home for the day. It's Friday, it's 5:00. Um, that, that should resonate. Uh, why do they need it, right? Do we maybe summon it all up? What's the business need, right? That is the core concept that maybe some of the programs are missing as folks are getting to the entry level, that we don't understand what we're holding up or the trade-off, whether it's financial, whether we're gonna lose business, whether we're not going to, you know, secure and keep the business. But if [00:10:00] we have a better understanding of the intent and the why, we could probably design a better experience or flow, right, that doesn't have, you know, workarounds. That's a whole 'nother tangent if whatever you have, you have a workaround, right, to get s- like the break glass procedure. I'm like,
Mm-hmm.
Just make the, make that the one, right?
How do you add controls that are more transparent to that thing? 'Cause if you have a workaround and people are using it regularly, that tells me your original control design wasn't that great to start with. Um, and then what-- how do they like to work? Uh, someone... I wish we had a call-in segment where someone could tell me what the principle is, right?
You're on the campus of the university and people walk across not on the sidewalks, right? Design for that path. They f- they found the path of least resistance. So, um, pivot your mindset, your control philosophies around the path that they want to take and are taking, and help find that common ground. It's, uh, it's really a business compromise, right?
You're there to help support the business
Ward: yes, [00:11:00] right? First off, yes, I like it. I think at least for me, I'm sure for yourself, I'm sure for your listeners, like sometimes easier said than done, right? Um, I, I too am gonna use that buzzword that I, I hate using, but it always comes in, you know, AI, right? A- AI is, you know, forcing a lot of conversations.
Um, and I think, I know I experienced this, this, this particular conversation back when I was on the practitioner side. I think it's still happening today. Business says, "I wanna use AI." I say, "Great. Let's talk about it. What are you doing?" And it's, "I wanna use AI," right? They don't know. know that.
So
Sam Wolf: more AI minutes and
Ward: Yeah. Yeah. I, I, I need to use more tokens, right? I've got X amount of dollars. Let's, let's use more. So when you run into, you personally, Sam, when you run into those conversations where you're working with somebody, you're trying to understand, they don't know how to articulate it to you, or maybe they don't have a [00:12:00] clue in the first place, right?
To, to your point, maybe they're just told to do something. H- how do you break through that noise to actually come to an understanding?
Sam Wolf: Yeah. I think that's a, an excellent question. So I want to use the thing, let me use the thing.
Mm-hmm.
That's probably almost verbatim how folks have heard, heard that brought to them. that sounds great. You don't know why you want to use the thing, so how are we gonna process this together? So, um, what happens if we don't use the thing?
Would probably be one place I would start. If I said no and I dug my heels in, what doesn't happen, right? What risk are we introducing? Not security risk, but to you, right? Maybe immediately you're gonna panic and go, "I'm gonna lose my job because I was told to do the thing." Okay. sometimes we might wheeze our way into a solution that wasn't there before, right?
That maybe there is value and we understand what your process is, and I'm gonna probably circle back again here and go, what does your business need to accomplish? What are the goals? What are the objectives? What does this align to, right? [00:13:00] Can we do the mapping exercise together? Um, I usually walk all of my directs through the here's the mission, here's the strategy that supports the mission, the core values, and then here's the work we do, and we need to figure out how to map from where we're sitting to there.
If we do that effectively, you don't need me as much, right? You can look up that chain and go, "Is the thing that I was asked to do in alignment with those? Can I draw lineage down to know that the work I'm doing matters?" And then you should be able to decide if you should prioritize X or Y, right? And I would expect the business to be able to step through that process. It's not a normal thought process for most of us that we've done, but if we can do that and you want to use the thing, well, hopefully it, it supports that. If not, I think we have to take it a different route, right? And what-- whether it's escalations or bringing the folks that told you to, uh, use the thing in, uh, I think we have to understand that we're getting some return. Um, happy to have the conversation [00:14:00] at whomever, right? Um, 'cause I, I think my model's defensible, right? Why we exist as a company and the mission and the core values seems like a pretty high calling for most of us. I can tell you what my work supports, hearing we can't articulate what this supports.
So happy to sit in whatever, you know, council room or robes or whatever need to be present to have that discussion
Ward: Now, am I hearing more meetings? Is that what I'm hearing you say?
Sam Wolf: Yeah, we discussed it in this one, but then we had to schedule another one to do the work 'cause there wasn't
yeah
for it. hopefully not, right? I, I hope folks can see the value in the work they're doing and the tools they're trying to blend in and apply to it, and they're not just chasing, at least vastly different than maybe we were six months ago.
I think there was a lot of that need it because everyone else is doing it. I got FOMO or the board has that, whatever it may be, that it is fundamentally different now. That it is, you know, AI is advancing the things we're [00:15:00] doing. It's simplifying work, and the use cases are vast and abundant. And even if it's a savings of 10 minutes a day, adds up across thousands of employees.
So the ROI gets, in some cases, easier. I don't know what model you're running, but it might be less if you pick a certain one and are churning through the money at a, a clip. But, I haven't experienced a lot of that, I guess, even to go back to your original question where folks just scream, "I want the thing."
Now they might want shiny version of the thing that's like the one we have, but the color scheme's different. and we talk about the-- and the risk reward and the value again, right? It all comes down to a few simple concepts
Ward: I've had plenty of that, right? I, I always kind of equate it to, I guess for car folks, like Ford versus Chevy, right? They, they always want that shiny thing that has, to, to your point, that color scheme, that logo, whatever. But we've approved this thing. So like for me it's like, all right, tell me why you need the Ford over the Chevy, why this thing with four wheels can't get you where you're going and you need that thing with four wheels.
Sam Wolf: In this case, you're putting the friction [00:16:00] in place for yourself. Like I have a, I have one ready to go. The keys are in it. It's warmed up. Help me find that for you, um, at least in the interim, right? Let's prove it out. Um, you can test drive this one. I don't have to go through a lot of, you know, months of risk review and assessment and architectural design to determine if the other one that, gosh, it looks, it looks the same to me, but you know, I'm not in the business.
Help me understand
Ward: Absolutely. Absolutely. You said something else, again, very early on in your answer about the biggest challenge, and that was, I mean, you glossed over it quick, so I'm coming back to it. You mentioned tech debts, right? And, um, that resonates a lot with me personally, right? I've seen over the years, um, people have gotten really good or got really good, not gotten, got, past tense, uh, at building the castle, right?
I mean, think back before cloud, um, it was relatively easy, right? I've got my data center, you've got the physical security that goes [00:17:00] with it. You've got your traditional perimeter security. Cloud came in, many could argue we still haven't secured that well, but at least cloud these days, right, is more tangible, a little more tangible.
You can kind of at least conceptualize that. You can whiteboard it. You can think where those controls were. Um, but I think the point you're really driving to is through those, uh, evolutions over the years, we've generally just stacked on more tools, and maybe there's, you know, duplication or triplication, and certainly there's probably gaps, and there's probably point solutions and all of that.
So Sam, what do we do about that?
Sam Wolf: you know, it's easier articulating the product world is go, "What's your grand vision? What's the castle we wanted to build?" And we go, "Okay, what's the cupcake version," right? The analogy is the, the cupcake to wedding cake for product, right? So you wanna build a wedding cake, you wanna build a castle.
What's the, the minimum thing you can do? What's this-- [00:18:00] Like, I could probably make a room, I can make a cupcake. Uh, but in the analogy you're talking to, it's like, well, I built the... I just started Waterfall, and I built the wedding cake, and then I just started just chucking cupcakes into it at some terminal velocity, and now I'm have to go take it and show it to somebody and go, "See, look at my pretty baby.
Look what, look what I made." Um, we have to unstring that, um, in the context of, you know, what I'm saying is important for us as practitioners to maybe at least consider a little more about, you know, time, to complete our experiences and some of the pretty things that we don't get to think about very often.
And I, I understand the, heartburn, the pain, the, right, what we're talking about is tech debt, right? The things that I pull out this little straw and it's like kerplunk and the marbles fall, right? That this is propping up a critical regulatory process, that we have to think a little harder back to the, uh, what's, what's the value of keeping it, and for how long does that not become sustainable, right?
Like [00:19:00] hardware assets, they have a, a predetermined lifespan. we need to back up and plan for those. Are there parts that we can go back and can I get the cupcake maybe back out and make that its own thing again and, you know, put it in its own little container and have that part function? And can I start to, you know, strip away some of the legacy, and I'll say integration.
I'm not saying throw away the legacy at first. Let's see if we can decouple it a little bit so we don't have so many subs and issues, um, over time. And when we get those opportunities to revisit contractual agreements, we can, you know, invest again, add another, or we can maybe deduplicate, right? Maybe something might be best of breed in one and good enough in another, right? business is unique and different, and the risks they need to solve don't all require, you know, the top-of-the-line Cadillac for every single situation, and that some of the things you likely already own have overlap or have improved since you did [00:20:00] the last, you know, POC. that good architectural practices and reviewing those, you know, going out to market, asking what's out there, just like us, everyone's moving at a pace that is just crazy between, you know, mergers, acquisitions, and advancement of product, likely it's different than the last time. And if you're framing it with simplicity in mind, you might make a different choice for how you're gonna deliver a service to your business partners along the way. Now I-- there's no silver bullet. That's a hard question and a hard thing to solve for a lot of us in our, our organizations
Ward: And I certainly don't have an answer, so I'm definitely putting you on the spot with a question. That's for darn sure. Appreciate the, the thoughts on it. I mean, pr- probably like yourself, I have this conversation a lot with folks and, um, you know, the, the common refrain, and I've been hearing this for years too, I think it's only getting worse.
It's the velocity of business versus the velocity that we can secure the business, uh, essentially. And [00:21:00] it feels like, at least for me, right, in conversations I have, it feels like that gap's getting bigger in, in many cases, right? You know, the, the, the business going at, you know, warp 10 and, and we're stuck at like warp four or five essentially on the security side, just trying, trying to keep up.
Are, are you, are you kind of seeing the same or, or are you able, or if you are, you know, how, how are you trying to close that gap?
Sam Wolf: feel like you're teeing me up.
Oh,
we're a victim of our own design still, right? That those, those processes that we put in place aren't easy for us either, right?
Mm-hmm.
Um, as we grew departments from three to five to 10, and if you're lucky, you've got 100 that have distinct functions, and those things have morphed and changed over the time, and we have trouble navigating them, so we can't keep up either, right? Um, maybe another parallel is the, six months ago in AI is very different than [00:22:00] today. and what we're trying to accomplish was at one point, like a human needs to look at everything, right? Well, fast-forward to the frontier models that, uh, crack every vulnerability over the weekend. can't look at it all, right? We have to have additional, like, and confidence in the processes we're building to keep up at this machine speed. Um, that's gonna cause us some, quite frankly, scary security concerns if we can't, right, adopt the processes and adjust that usability, that ease of use internally, as well as what we're putting out for our practitioners to say, "Yeah, there's a risk on both sides, but I think we should patch," right? That we're not gonna wait X days and test X days and... Right. I think one is worse than the other, and a little downtime because the patch got pushed and closed the hole, and it gave some undesired functionality is something we can recover from versus, uh, I usually say is, "Let's not be on the front page of the New York Times."
That's [00:23:00] our job. That's-- I think patching's the right thing. So some of these human-in-the-loop things still are applicable, but in some of this security process, uh, we have to find different, better, um, and, less friction-inducing ways to accomplish the same things we're trying to do, right? Risk reviews and architecture reviews.
We put so many gates in place, um, that probably cause you to do a thing, write a thing down, touch a button, click a thing. Um, if it takes two minutes to automate, why are we not doing that? Those time savings will add up quickly in our space
Ward: So I've had this conversation a few times, and I, I think it, it directly relates to what you're saying. And the conversation I've had, um, with, with some of my peers out there is, and this is good, at least in my opinion, that many organizations, because of all this, everything we're saying, many organizations are revisiting what they claim is their risk tolerance, right?
Like I'm sure you have too, Sam, like you join an [00:24:00] organization, "We have zero tolerance for any downtime, or zero tolerance for impacting the business." And I feel like, again, it's not 100% across the board from my conversations, it's definitely a few. I would say it's a few that are kind of on the edge. Um, they're starting to revisit that kind of, kind of to your point and saying like, "No, in order to try to keep up, we have to be okay with a potential blip, right?
In, in our five nine availability of this app and patch it, right? Patch it immediately." 'Cause it's no longer necessarily the critical vulnerability, it's those five low to medium vulnerabilities that are chained that, you know, is, "Voila, we got in." Like w- would you agree with that, the whole idea of revisiting just the risk tolerance, risk acceptance?
Sam Wolf: my only challenge would be that they had something thought of ahead of time would be cool, that they've actually thought about and documented a risk tolerance. I think[00:25:00]
Hmm.
Most organizations have one that we operate under the guise of if, not written down. Um, I, I think both rely on a tone from the top, right?
That
Right
who said we have no risk tolerance obviously, uh, made sure that the financial person was not in the meeting that day because the, the dollar bills that go along with that are great, right? But we're not Amazon. We don't have that kind of four minutes of available downtime, um, that we need to articulate the same trade-off, that risk to business i-is the same as cyber risk in this case.
That, you could experience an outage from a patch. outage is far different than, you know, X points of stock value or that front page article. Like that, that is a much steeper hill to climb from a value loss perspective, and that tone needs to come from your, you know, your CIO or whoever is leading that technology organization to say that, "I've talked with my business partners, and we've agreed that this is actually pretty important." [00:26:00] Um, I-- we can't dictate it to them. We can lay out the risk. Our job is to do that as risk and data practitioners. Lay out the situation, try to not hit the fear, uncertainty, and doubt, but at some point it's hard not to get there in some of these and be like, "This, this could not be great. So do you want an hour of downtime, or do you want an undetermined amount of exposure over here?" Right? "What we'll promise you is we'll, we'll fix it quickly, um, and we'll get to the next patch or whatever it may be, or if it's a rollback, but we need to close those gaps pretty quickly." And most of them get on board, um, in short order
Ward: I like it, I like it. Well, we started diving down pretty quick into, into some of what you're saying. I'm curious, so you, you started off, uh, the episode saying we, right, we humans, the security humans are, are the biggest challenge for data security. Any other items that you're, you're thinking that, uh, we as security practitioners need to think about and, uh, you know, maybe do better to not be that biggest [00:27:00] challenge?
Sam Wolf: Yeah, I think laying in there or laying it out is really how are we communicating with our business partners. So that entry-level person hoped they didn't have to talk to anybody. Spoiler alert, someone should have told you, uh, most of my job is that, right?
Hmm.
While I'm drafting policies or standards, the business partner's in that room with me, right?
'Cause they're the ones impacted by those policy or standards that then turn into controls that they have to adhere to, that they have to evidence, that they have to turn into the regulators. Um, and when we talk about friction and they're trying to rush, guess who I'm talking to? I'm talking to a business partner or stakeholder.
So we need to start with what's really important to them, um, and arrive at some common agreement of what we as security can do for them and will do for them. Um, and maybe put it down in writing, right? Maybe that's a good place to start. This is what we agreed I would help you with. Whatever role you're in, in the security organization, this is the service I'm providing 'cause in reality, they could go buy it from some vendor, right?
They [00:28:00] could hire out whatever the thing is in the seat we're sitting. the hope is that we provide a better service because we're part of the business and we have a common and shared goal back to the mission, strategy, all those things we have in common. can agree when you come and yell at me like, "Why didn't you catch this?"
I'm like, "'Cause you said, this is where we play. We're gonna hit you on email and endpoint and this, and this, and this. We talked about the other, we didn't agree to it." So what's the trade-off? There's that cost again, right? That one's gonna say, "Uh, X months I'll help build it for you, but you have an investment as the business.
I need you to bring somebody to sit with me to make sure we do it right and it meets your, your business need, your outcome, that we're not adding more friction, that it does what you want of just slinging a control, putting a rule out, and hoping it works, right? And waiting for the tickets to come in when it doesn't. Uh, and then we fix them or you get exceptions or we tune. Um, I think that work needs to be upfront, will help us be much more successful on this journey of, you know, security [00:29:00] practitioners chasing a more unified, um, plan. Maybe, maybe we'll draw a picture of a maze and go, "That's the path we're in today.
We're navigating the maze." Maybe just need to drive a bulldozer down the middle and pave a nice road, right, through whatever that experience is and try it again.
Yeah
we can circle back to the whole tech debt problem, like can we build, build in parallel? Can we unravel it? Um, some of these are, are very difficult issues to solve depending upon your organization and its size
Ward: A- and I think, you know, I, I didn't ne- necessarily hear you call it out this way, but I definitely heard you, you dance around a little bit. It's, it's also documenting throughout, right? Documenting some of these decisions, some of these conversations. Um, I've been in plenty of organizations where you have a conversation on Monday and either because everyone's busy or they, uh, on purpose forgot, right?
Friday they no longer remember that conversation, that decision. They, they wanna have the conversation all over again. Right. Exactly. Oh, man. That's, that's great [00:30:00] that you, you literally forgot everything. Fantastic. And, and that's actually where I'm personally seeing, again, I know there's a lot of controversy here, A- AI note takers.
Like I, I love them for tho- now I love them for those types of things where we can literally say, "Hey, here was what we talked about." Some of those note takers can give you some pretty good like, you know, call to actions out of there. Like, "Here's what we said, here's gonna do it." And, you know, you don't necessarily have to have, right, notebook and pen to scribble everything out, read your chicken scratch, have time to go back and read it in the back to backs and say, "Here's what we talked about.
What are we doing?"
Sam Wolf: is my gotcha.
Yeah
I can't imagine that anyone would look at me and go, "Wow, I bet you're really good in a conversation while you're writing things, and I'm sure you go back and read those." So the answer would be no, no, and no, right? Most people who multitask aren't good at one of those. So if we can be present in that conversation for those decision points, because they are [00:31:00] probably important decisions, hopefully we're good stewards of the meeting process, right?
There's an agenda, and there's a clear reason why you are there, uh, that we can have a common place to work from, which is what I love. It's not your interpretation of the meeting in your personal notes in your repository. It's a collective note with collected action items and things that we agreed right then and there is a little harder to dispute. I think it drives some really good accountability for both security and the business to say, "Well, this is, again, what we agreed upon. This is what I'm artifacting." whether it be for audit purposes, compliance, right? All the things that we have to do in our roles to make sure we're checking all the right boxes and doing what we say we do
Ward: Absolutely. Absolutely. Well, through this conversation, Sam, it's very clear, you know, you've been around the block a time or two. So tell us about that. How did you get to where you are today in your career? What was your journey?
Sam Wolf: Oh, that's a, a loaded question, as you know. Sa- Sam's not a technology person, um, a tinkerer by trade. I grew up [00:32:00] in a family of, you know, manufacturers and folks that worked on cars. Um, so I started as a welder, um, for almost nine years before I figured life out. Um, and I'll air quote the "figured life out" that we all-- any of us have that done. Probably still reflecting internally like, I don't know, did I still choose the right profession anymore? I think we could build an agent for what it is I do sometimes. but yeah, started as a welder, so again, building things, figuring out how things work is a, a common theme, and also some just dumb luck and following where the wind blows.
But, um, I love to share that. So I'm, I'm a taller person, and my wife is, like, more than a foot shorter than me. So I grabbed an A+ book 'cause I wanted to build a computer to play some video games, which, uh, sounds great. We can all probably resonate with that as well. If she was
Oh, yes
over and talk to me like I was a child, is where the height part comes in to be funny.
Like, "Hey buddy, you bought a textbook for fun. Guess who's gonna go to school?" Uh, so a little bit of that was, uh, gentle encouragement that somebody at [00:33:00] least saw that I could maybe figure it out, even though I had self-doubt. So, um, picked, like, the smallest school with the simplest program and maybe the least amount of math 'cause I was not sure I was cut out for college, um, based on maybe my upbringing and what I had done to then.
But, um, you know, kind of the la- rest is almost history. I loved it. Uh, had no issues with school at that point. Um, learned a lot, tons of internships, lots of great experiences along the way. I think I've got a, you know, a lifetime of experience and exposure, um, over the years and what's now been, you know, more than 12 years, I guess, in the security space.
Everywhere from help desk, software developer, digital experience design, to now, you know, leading data security programs. So I think it's been a fun journey. I wouldn't trade it for anything. Although, again, I'm questioning maybe I need to go back and dust off those welding skills as this world evolves around us
Ward: So I'm, I'm curious. It's funny that you ended your story like that. So I am curious though, so knowing what you know [00:34:00] today, right, your knowledge here in 2026, is there any wisdom you'd impart on yourself if you could go back in time to when you were in welding? We'll say 15 years ago, right? Well,
15.
You started this journey
I might even taken it farther back just to kid who's taken everything apart
Ward: Okay
Sam Wolf: " You're gonna be an engineer of some kind. Follow that path directionally," right? If we're picking a direction on a northwest-ish, right? Just head that way. Um, and I would, I would keep that theme, right?
That there's building, there's problem-solving, and these are extensible across all these, right? And that if you show up with what I-- HR would never let me, but I would put only three things on any of my applications: attitude, aptitude, and initiative, right? It would just be three bold words. Um, I can figure it out, you can figure it out. Um, I wish someone would've told me that, given me some of those, like, technology, I think is a thing for you. [00:35:00] Here are some, you know, s- things you can experiment with or figure out. That's the advice I would give, right? Find the passion
Ward: That's great advice. That's great advice. So, you know, I, I noted when, when I was introducing you, uh, you're, you're big into the community. Um, you know, mentorship is something that you do. Um, as you know, we all see it, including my listeners, there's a lot of folks out there trying to break into the industry.
There's a lot of folks that unfortunately have lost their jobs due to reasons, right? Are struggling to find their, their next opportunity. So do you have any words of advice for either group or both in, in today's day and age?
Sam Wolf: some of my experience that I, I spent a lot of time in, with, um, kids transitioning either in high school or through the college experience to help them find some of those placements. Um, a lot of it is less about the tools and experience, and it's really back to those three things, right?
How are you demonstrating attitude, aptitude, and initiative when you're not forced to [00:36:00] do it, right? That you are experimenting, you're learning, and you're constantly doing, whether you needed to for a class. Um, I'll be honest, I don't really care about that. We all had to go to school for something. Um, I am pretty, uh, passionate about those folks who switch careers, right?
That you bring a different viewpoint into the experience, um, that is helpful. So if you lost a job or are figuring yourself out along the way, that the places you land might be slightly different than where you started, that it doesn't have to be so rigid security thing, that companies that are out there that aren't on this AI wave that could really benefit, spend 40 minutes, get yourself some VS Code, some whatever it may be, figure it out, and go help somebody, right? you can demonstrate your ability to do that, I, I think you'll find a path that hopefully pays something at some point. Um, and then for those folks that are [00:37:00] really coming into this industry, I, you know, I, I feel for you. It is quite the world.
Mm-hmm.
I, I, I think that the advice is still sound, that if you can demonstrate your ability to figure it out and adapt when y-you're not required to for your paycheck, I think that, that shows a lot about your character and who you are as a human being first, and your ability to adapt to whatever role you're put in, you will likely be successful. Um, maybe my dream job is kinda like a micro dirty jobs thing where you just every couple weeks you just pick me up and just throw me in something else, right, with the knowledge I have now. and it likely has nothing to do with security. But your ability to, adapt and figure out the thing in front of you sounds very interesting to me, but that probably sues some type of diagnosis in my brain that not everybody has either
Ward: It actually sounds r- like a lot of fun to do for at least a time. I think I, I might want to come back to my day job eventually, but that would be kind of fun to get picked up and, and to drop into something else a few times.
Sam Wolf: my flavor would be [00:38:00] could you take a whole team that you consider high-performing and like, "Hey, next week you're gonna run a fast food chain for two weeks. Uh, figure it out," right? Talk about documentation and fig- being able to find your way through. Those things become pretty important, right? And I think some of those viewpoints might be interesting to apply back, um, if someone comes new to your team or you enter that new role.
Like, can you figure it out?
Ward: I mean, that could be a new reality show, man, based on what you're saying. And it c- it could have a comedy spin too. I mean, think about it, right? You drop some, uh, I- I'm just gonna say, like, IT nerds into a fast food. How do I turn on the fryer? How do I do this?
Sam Wolf: I'd probably watch that, but
Ward: Oh, that sounds amazing. Yeah. Well, well create it. You can make some money on it now.
Sam Wolf: Let's do
man.
I'm in
Ward: Well, Sam, really appreciate you joining today. This has been a great episode
Sam Wolf: I, I appreciate the time. It's been fun
Ward: If folks want to follow you, what's the best way to do so?
Sam Wolf: can hit me up on LinkedIn. I'll do the double check and make sure I'm available to be found before we, we post this [00:39:00] and everyone's like, "I can't find that guy." but yeah, that's the best place
Ward: LinkedIn, I love it. Awesome. Well, again, thank you for joining, sir.
Sam Wolf: Yeah. Thanks so much
Ward: And big thank you to the audience. Really hope you enjoyed today's episode and learned something. Please tell others in your network to follow and listen. This has been another exciting episode of Guardians of the Data. See you next time.
That's a wrap on another episode of Guardians of the Data. Thanks for tuning in. For show notes and more, visit guardiansofthedata.show. Guardians of the Data is made possible by support from Sentro. To see how we help organizations discover and classify all of their data accurately and automatically while quickly achieving petabyte scale data protection without the fuss, please visit sentro.io.
Catch you next time
Creators and Guests
