In this episode, Frank La Vigne sits down with Sandeep Pauddar, Head of Digital Trust at DQS, to explore the fast-evolving world of digital trust, compliance, and data security. From the growing complexities of global regulations, to the increasing intersection of AI, cybersecurity, and enterprise risk, Sandeep Pauddar shares real-world stories—including personal experiences with AI-driven phishing—and breaks down how organizations can foster a security-aware culture. Whether you're leading a startup or a global enterprise, tune in for actionable insights on building digital trust, navigating the compliance landscape, and why organizational leadership plays a crucial role in keeping data secure.
00:00 Introduction and guest welcome
05:00 AI data security in various industries
06:44 Department collaboration on AI and compliance
10:58 Information security standards overview
14:23 Balancing Innovation and Standardization
18:14 Navigating global AI regulations
22:14 Regulatory advice for startup founders
25:33 Discussing common patterns in failures
28:24 Discussing link metadata in apps
33:09 Security threats and personal story
37:11 Challenges in adopting security systems
38:32 Insurance and breach response policies
43:21 Promoting Extreme Ownership on Audible
45:01 Finding more about Claude Academy
In my family, we have a code. So if somebody calls
Speaker:with an urgent need for help, we first have to ask for that code.
Speaker:And this came off a real incident that happened last
Speaker:December. I was in Austria for an audit, and my son, who is here
Speaker:in Texas, he got a call saying, son, I've been in an accident.
Speaker:So he hung up, called me back. He said that, Dad, it
Speaker:was your voice.
Speaker:Hello and welcome back to Data Driven, the podcast where we explore the emerging
Speaker:industry that is artificial intelligence, data science, and of course, it's
Speaker:all not possible without the importance of data
Speaker:engineering. Fortunately, my favorite data engineer in the world
Speaker:cannot make it today, but I am gonna carry on without
Speaker:him. Today we have an interesting guest, and, uh, he's been
Speaker:super patient because of scheduling snafus on his end, my
Speaker:end. We've had a lot of those. I am speaking today with Sandeep Padar,
Speaker:and, uh, he is Head of Digital Trust at DQS.
Speaker:He is coming to us from deep in the heart of
Speaker:Texas at, uh, the Dallas-Fort Worth Metroplex. Welcome to the
Speaker:show. Thank you for having me, Frank.
Speaker:Hey, no problem, no problem. So what is digital trust
Speaker:to you? What does that mean? So
Speaker:in the past, in the realm of compliance,
Speaker:people were chasing different standards based on what
Speaker:the requirements were there. There could be regulations requiring a certain
Speaker:standard. There could be clients' contracts requiring
Speaker:certain regulations. And this was all
Speaker:piecemeal. Now, as the effort grows and
Speaker:multiple dimensions come together, use of AI models, AI
Speaker:data, various regulations from different agencies and
Speaker:clients, and then of course the important
Speaker:dimension of security, they all come together. It becomes
Speaker:overwhelming to do this piecemeal, and it's best
Speaker:to aggregate this together. in one cohesive compliance
Speaker:effort. And this is what we are calling digital trust.
Speaker:That makes sense. Do you think, it may be too early to ask this question,
Speaker:but based on what you said and kind of reading the tea leaves
Speaker:and reading the room, I could easily see there being a need for a
Speaker:chief trust officer at some point in the future at the C-level. Do you
Speaker:think, is that looking too far ahead or
Speaker:just right on target? You are so right. We are there now.
Speaker:You are correct. So more and more organizations are having these questions.
Speaker:How do we face all these compliance dimensions and how do we fulfill our
Speaker:requirements? I have written a white paper recently on the
Speaker:top of this topic, and we have some webinars coming up as well where we
Speaker:address this very same topic for different verticals, not just
Speaker:for IT companies or AI companies, but say
Speaker:for example, we have a webinar coming up on medical devices
Speaker:because every sector is facing the same difficulty. So I
Speaker:fully agree there is need for a dedicated
Speaker:organization led by a compliance officer in
Speaker:digital trust. I can see that. And, and,
Speaker:and you're right, when you mentioned medical devices, there's obviously a certain level of trust
Speaker:in there. And trust, because to me, and you kind of said
Speaker:this in the intro, When you describe what you do, like, the AI is
Speaker:part of trust, identity is part of trust,
Speaker:obviously cryptography, security, all that stack, right? So there's a
Speaker:security probably foundation of that. What else,
Speaker:like, what else would be involved with trust? So
Speaker:it varies from sector to sector. There are so many
Speaker:verticals that share the same foundation of using
Speaker:AI responsibly and ethically because everybody is using it.
Speaker:And of course, they have the responsibility to protect their data.
Speaker:So security is another dimension.
Speaker:The 3rd dimension that varies a lot is regulations. Every
Speaker:sector, every vertical has their own set of regulations to meet,
Speaker:and therefore the mix of standards that will go into their
Speaker:compliance there Integrated management system would
Speaker:be different.
Speaker:So is this rolling out
Speaker:in some industries more, right? So you obviously have regulated industries, right?
Speaker:Healthcare, finance, I would assume. You mentioned healthcare. I'm assuming finance is going to
Speaker:be a big player in this, but also public sector, right? I mean, defense
Speaker:and anything related to government, I would imagine, would really
Speaker:require Well, requires is a loaded word—
Speaker:demand or need some level of
Speaker:enhanced trust. I fully agree, and
Speaker:we cater to a very diverse set of
Speaker:verticals. We have aerospace audits, we have
Speaker:automotive industry, food, environmental health and
Speaker:safety, quality, and all of these verticals
Speaker:now need to address the data security
Speaker:regulations around data security regulations around AI use.
Speaker:And then depending on the geographical area which they are
Speaker:catering to, the flavors would change as well,
Speaker:whether you are, you are complying to
Speaker:European Union AI Act or whether you are in California
Speaker:or Texas, and then you have to look at the state-level AI
Speaker:regulations. Right. And the regulation market
Speaker:is getting far more complicated, right? Obviously, everybody knows the
Speaker:European Union. I know Switzerland has their own scheme,
Speaker:but also at the state level, at the second-level government, right? In the United
Speaker:States, California. I know that different states have different— you said
Speaker:that's Texas. I think Maryland is— I live in Maryland, which is why I'm bringing
Speaker:it up— is also bringing up a lot of these types of
Speaker:regulations too. It sounds like this is getting
Speaker:It's a growth industry, isn't it? Or a growth concern.
Speaker:It is. The rate of change of information, data,
Speaker:knowledge is increasing. So
Speaker:vulnerabilities are increasing as well. And then everybody has the
Speaker:responsibility to, to address it. It's a make or break
Speaker:situation for many organizations. And you know what's
Speaker:interesting? This seems inherently cross-discipline and
Speaker:cross-functional. Isn't it? That is correct. Yeah.
Speaker:Because it seems to me like a lot of this is going to be—
Speaker:and I'll ask you questions about like how
Speaker:best— obviously there's no best way, but obviously
Speaker:just as soon as you say regulation, that translates to a
Speaker:legal department, right? There's also a security
Speaker:aspect, right? So that's IT operations aspect. There's also, you
Speaker:know, as AI gets looped into this, there's going to be
Speaker:veracity kind of concerns and, you know, model provenance and
Speaker:kind of the— it sounds like this is inherently going to
Speaker:involve at least 3 departments, probably more. But off the top of my
Speaker:head, I see the legal department get involved, IT operations, and however
Speaker:organizations break out their AI people, right? And data engineers
Speaker:obviously need to be a part of that. Shout out to you, Andy. But what
Speaker:How is that going to be structured? Because lawyers don't like to share the room.
Speaker:IT operations don't like to share the room. AI people certainly do
Speaker:not like to share the room, right? Or share the mic, as it were. How's
Speaker:that going to work out? Like, is this going to fall under compliance? Is this
Speaker:going to fall under each individual business unit? Or it really depends
Speaker:on the problem and the regulations? You said
Speaker:it right. And what a wonderful question it is, because I get this question all
Speaker:the time. clients get a requirement from somebody
Speaker:to come up with a certificate, and they come to us,
Speaker:and their first thought is that information security
Speaker:is IT's responsibility. So they bring IT people
Speaker:into the initial call, and that's when everybody learns
Speaker:in the room that information security is everybody's
Speaker:responsibility. These standards that we typically
Speaker:audit against ISO 27001 or
Speaker:TISAX for automotive industry.
Speaker:They are organization-wide regulations or standards.
Speaker:So it's not just IT, but we look at the
Speaker:overall awareness about information security throughout
Speaker:the organization. We are talking to
Speaker:legal, like you said, we are talking to procurement.
Speaker:How are you securing the information that you are sharing with your vendors?
Speaker:HR, how are you hiring people? Are you conducting background checks
Speaker:and stuff like that? So it's, the controls
Speaker:of these standards are organization-wide, and information security is
Speaker:everybody's responsibility. It's in some industries
Speaker:which are a little bit behind the curve. It's
Speaker:an awakening for them. How do they—
Speaker:what's that awakening process look like? Aside from being painful,
Speaker:right? What do they kind of— do they
Speaker:get a cease and desist letter? Do they get an
Speaker:RFP or an RFI and they have to fill out sections of
Speaker:the form where it's like, what's your compliance controls? Like, how does that look like?
Speaker:How do they go from, we don't need this, to, we really need this, we
Speaker:need this yesterday? I agree with you. So
Speaker:in short, I could say that it's a culture that needs to
Speaker:be developed in the organization, and it's
Speaker:the top management or leadership that defines that culture.
Speaker:So as we audit hundreds of organizations through,
Speaker:through the year in various different sectors, we can see the difference.
Speaker:Some organizations have a very robust, mature
Speaker:information security culture, and that is driven by the
Speaker:interest and commitment from their top management. And some others
Speaker:are not at that level yet, and it's very clear that the top
Speaker:management has not awakened, or they are not forcing it as
Speaker:much through policies, processes, and their involvement,
Speaker:not just yet, but it's coming to every sector.
Speaker:Is there, like, an ISO standard for this yet, or
Speaker:is that in process? Or I know there's like Six Sigma, there's ISO
Speaker:9000. I know those are different animals, but you think that—
Speaker:is there a standard like that in the works, or is there already one?
Speaker:Just like you mentioned ISO 9001 for quality, for
Speaker:information security, which is organization-wide, we have had
Speaker:ISO 27001, which is a mature standard.
Speaker:Very recently revised to its latest version in 2022,
Speaker:and it addresses various aspects of the organization end to
Speaker:end, and involvement and
Speaker:commitment of top management is addressed at the foundation of
Speaker:the standard. So that's one. But for different
Speaker:industries, there are specific standards, such as for
Speaker:automotive, there is a standard called TISAX, which is governed
Speaker:by a German company, ENX, and it is
Speaker:tailored to information security within the
Speaker:automotive industry. At the design level, there's another
Speaker:standard called ISO 21434, which is
Speaker:gaining momentum in addressing all the current requirements because the
Speaker:automotive sector is realizing that vehicles
Speaker:are becoming intelligent and they're holding and transmitting a lot
Speaker:of data. So information security has to be
Speaker:considered in the design of the vehicle itself so
Speaker:that it can receive over-the-air updates securely, for
Speaker:example. So these are the 3 that, that come to top of my
mind:27001, TISAX, and ISO
mind:21434. Interesting. And
mind:you mentioned one of those standards, it was the 27001.
mind:Came out in 2022, which I would imagine that they're gonna— because
mind:ChatGPT obviously was released to the world in end of
mind:2022, so they probably didn't factor that into. And
mind:obviously it's a fast-moving field, right, this AI
mind:thing, um, as it were. Uh, there's agentic, there's a
mind:lot of debate about this. How long does it take for a standards
mind:body to agree on, like, and coming up with a certification?
mind:And it seems to me like there's a tension between the
mind:technology releasing capabilities and
mind:the standards body taking a certain amount of time to come up with
mind:criteria? That is such a good question, such an
mind:interesting topic for me. So the latest version of
mind:ISO 27001 came out in 2022. The previous version
mind:was in 2013. Oh, okay. ISO
mind:has to consult with a lot of different sectors
mind:to distill the requirements into the standard. It takes time. It
mind:takes time to review it. It takes time to get the feedback and then
mind:finally release the standard. So it's an inherently very
mind:involved process across all of the verticals.
mind:Therefore, it takes time. But you are so right. This field
mind:is changing so fast. The standards need to keep
mind:up with it. So ENX, that
mind:publishes the TISAX standard. They have come up with a
mind:scheme to revise their standard every year,
mind:not at a very large scale, but fine-tune it every
mind:year based on the best practices that are needed. So this is very new.
mind:From next year, they are going to have an annual release of their
mind:catalog, which is called TISAX Catalog, and they are going to
mind:fine-tune it based on the requirements and
mind:best practices in the automotive industry. That's
mind:a good hybrid approach because you want the standards,
mind:you want the standards to change relatively slowly, but you also need them
mind:in this ridiculous pace of innovation, which who knows how long
mind:this might be the new normal. This might just— the AI bubble may pop
mind:and we'll all be like scrambling for the pieces in a couple of
mind:months or whatever the doom people say, right? AGI
mind:may come out last week, if you believe everything
mind:Sam Altman says. So I think
mind:it's a clever strategy because the standards have to be some kind of
mind:baseline in reality, right? It has to be like a true
mind:north, right? It has to be the standards. And by definition, they're not
mind:supposed to change that often, but they also have to adapt. So
mind:that does seem like an interesting tension. And was it I
mind:wonder, I guess we'll see how it all plays out, right? Is
mind:this a good idea or not? It's a
mind:challenge to strike that balance. I mean, anyone who has
mind:looked in their car glove compartment for a
mind:USB charger knows that the struggle, and
mind:that's only between what, 3, 4, maybe 5 different
mind:formats to look for a phone charger. You don't want the
mind:standards changing that much. Right? You don't want— if you're old enough
mind:to have been in this industry long enough, you probably have a drawer of wires
mind:and obscure connectors ranging from the old PS/2
mind:port to RS-232 and
mind:the printer parallel port. Those were standards too,
mind:but you can't— if you have too many standards, they defeat the purpose.
mind:That's cool. What is the biggest challenge that you see in
mind:your customers and in your space about,
mind:do they acknowledge that they need to have some kind of control
mind:around this space? Do they understand the
mind:concept of digital trust? Do they—
mind:I imagine it's a spectrum, but where do you find most people?
mind:Yeah, some industries are more mature than others.
mind:So obviously technology based
mind:industries, highly technical markets, they are more
mind:mature in this area because they see it on a daily
mind:basis. But some other older industries, they are
mind:having a hard time catching up. The progress is there, of course,
mind:but as, as this field grows, and I mentioned
mind:multiple dimensions, AI is everybody's business. Right. If you are
mind:not producing, you're not providing AI, then you are at least using it.
mind:How do you make sure that your employees are using it in an ethical and
mind:responsible manner and not exposing yourselves to any legal
mind:ramifications later? AI technology is growing, models are growing, and
mind:these models— some people say that they are producing wrong outputs, some people
mind:are very happy with how they're using it. Where's the difference? The difference
mind:is that AI readiness is
mind:a metadata problem. Everybody is struggling to make sure
mind:that the data that goes as an input to the model is
mind:correct. It's unambiguous, it's truthful.
mind:Otherwise, you cannot trust the output. Right. So that's one part
mind:of this puzzle. Various industries are struggling at a
mind:different level and meeting the requirements at different level. Of
mind:course, all of this is based on regulations and requirements. So
mind:contractual requirements are telling people what to do. Or
mind:federal or statutory requirements are telling
mind:people. In this industry, people don't take
mind:proactive approach to do the right thing unless somebody's
mind:requiring it. So, European Union, I
mind:mentioned the AI Act earlier. It's a good example, but
mind:you might remember GDPR. When GDPR came through European
mind:Union in the beginning, All the member
mind:countries had a different flavor to implement. They
mind:all had their own individual requirements, and that's how it combined.
mind:Same thing is happening with the AI Act. So all member
mind:countries are going to have a little bit variation in how they
mind:implement and require the AI penalties and
mind:how they enforce it. In the US, same thing
mind:at the federal level. We moved back
mind:from regulations a little bit so that innovation could take place, but then
mind:different states are requiring it at different levels.
mind:So this is a nightmare for a
mind:company that's trying to fulfill the requirements, and they have,
mind:say, worldwide business. They are catering to European Union citizens
mind:as well as they have Asian markets and United States. So
mind:they have to have, like you said, a dedicated
mind:group, a dedicated leader who can ensure that they are
mind:meeting the regulations. And
mind:that group has to have pretty wide authority over product.
mind:It sounds like— I like to put on my optimist hat and my
mind:rose-colored glasses, but I also know that only goes so
mind:far, right? It sounds like there's going to be a lot of
mind:territorial arguments over
mind:this, and I foresee a lot of
mind:internal inside of companies like fighting over this, right? So
mind:I mean, it makes sense. You have to have board-level buy-in on this
mind:to tell the kids to not— to stop fighting with each other
mind:and get something done. Have you seen that happen, or
mind:are people mature enough not to get into these little territorial arguments?
mind:I see different interpretations of this and different
mind:implementations. So in short,
mind:what I recommend to various organizations is that we have to
mind:take all this together. We have data protection,
mind:cybersecurity, AI governance, and
mind:these all need to converge into the
mind:enterprise risk model together. We cannot have separate risk,
mind:risk registers and separate risk analysis for
mind:various different dimensions. So they have to converge
mind:as the overall
mind:enterprise risk function instead of 3
mind:different dimensions that are treated differently.
mind:That way, an organization can holistically address
mind:all of these issues. and move forward in a, in a
mind:continuous improvement, productive way. Otherwise,
mind:it becomes very challenging to merge it all together. Yeah,
mind:I mean, that makes sense. That makes sense. Do you think that
mind:all of these regulations— I have mixed feelings about this because I think
mind:regulations are important, but I think you could make that— I can
mind:go either way, right? Do regulations encourage innovation? Do they
mind:stifle innovation? I think the answer is kind of
mind:nuanced, but I want to get your take on this, right? Because like you said,
mind:no one does this because they want to do it. They do it for compliance
mind:reasons. It's not— it's driven by legal and
mind:contractual obligations. What's your take on that?
mind:It's a question that everybody is struggling to answer depending on which
mind:geography you are in. Different cultures, different countries
mind:have a different balance. Some want to be more
mind:forceful in the regulations. Some others want to let the
mind:innovation run free till we run into certain pitfalls. And
mind:then as a knee-jerk reaction, as a, as a reactive
mind:way, regulations come up. But most important thing
mind:is to have a good balance. Regulations will always come
mind:after the innovation comes. So innovation will always precede.
mind:Yeah, it's What would be your advice to
mind:smaller companies and small founders, right? That they're kind of—
mind:what would be your advice? Obviously, if you're starting a medical
mind:device company, you know you're walking into a
mind:regulatory— I don't want to say minefield, but you know regulations are going to be
mind:part— regulatory compliance is going to be a big part of your workday.
mind:Every day. But what about,
mind:you know, AI startup founders,
mind:right? Like, obviously they— I would imagine— well, I
mind:guess if you're doing— if you're starting in 2026, regulations has
mind:to be at least in the back of your mind, right? Uh, it's not
mind:like social media had the clean, wide-open spaces for
mind:as long as they did. I think those days are over. What would be your
mind:advice to someone who's starting a company and they think, I
mind:don't need to worry about this regulation stuff?
mind:I see it across various industries all the time.
mind:Clients come with all types of questions and thought process.
mind:Some want to be overambitious and achieve it all, and
mind:some don't really understand how many requirements
mind:would be there in front of them. So in general, I
mind:always say keep it simple. Identify the
mind:minimal set of requirements that they need to meet because it does
mind:not have to be overwhelming to the organization. And then
mind:a continuous improvement process is important.
mind:You cannot reach maturity in the first attempt. So what we
mind:call it as a PDCA cycle, or Plan, Do,
mind:Check, Act cycle. which can have different frequencies
mind:for different standards, but that cycle needs to be in place.
mind:So keep it simple, start small, and then mature
mind:that management system into a highly
mind:mature compliance system depending on what their
mind:requirements are.
mind:Interesting. So it shouldn't be this big scary thing you ignore,
mind:or your big scary thing you're— this big scary thing you ignore, because that sounds
mind:like Bad idea, right? But like, what—
mind:so you're saying that they should embrace it and understand it, don't fear it?
mind:Exactly. Open communication is also important. Many
mind:organizations come to us with questions that, oh, we have this requirement,
mind:but we don't know what to do with it. Of course, we cannot consult
mind:and implement it for them because then we will not be able to go back
mind:and audit it. We show them the roadmap and then they can go
mind:find consultants in the area. figure it out and then come back
mind:to us for certification audits when they're ready.
mind:And is that what your company does? DQS? DQS is
mind:a global organization. We have offices in more than 60 countries.
mind:We have more than 2,500 auditors,
mind:and wherever clients are, whatever are their compliance
mind:needs, we can definitely help them with the certifications.
mind:Oh, very cool. And not just the digital
mind:trust aspect of it, right? Like everything. This is just one vertical. Yes,
mind:that's right. Okay. Interesting. Interesting. Have you
mind:noticed any patterns yet? You know, any patterns of,
mind:do companies, obviously not giving any names, do people fail around the
mind:same things or it really runs the gamut of what's possible?
mind:Like, you know, like, oh, they left credentials out on an
mind:open server or something like that, right? Or is there very, is
mind:it specific? specific to what people are doing? Is this specific to
mind:the industry? Like, are there any common, common, like, if
mind:you had to come up with a list, what they call listicles, like the top
mind:10 things everyone's doing wrong, right? Like, what would that be?
mind:I agree with you. So in different sectors, in
mind:different verticals, we see different weak areas.
mind:And this aligns with many annual reports that you see from,
mind:say, Verizon or FBI, they
mind:issue annual cybersecurity reports, and you see
mind:that people are the weakest point. According to the latest
mind:FBI report, more than 2/3 of data breaches
mind:occur when somebody falls prey to a phishing
mind:email. So people need to be more aware. The security
mind:dimension is challenging as well. It's changing
mind:quite a bit. The attackers now use AI. So in the past,
mind:we could tell a phishing email because of the poor grammar or
mind:misspelled names and the words. But now they're using AI
mind:to automate and scale their attacks in a very efficient way.
mind:So it's a cat and mouse game. We have to make
mind:sure that our employee base, our contractors play base, our vendors
mind:are keeping up to the challenge. So that's, that's one big area.
mind:If you ask me to name the top area, I would say
mind:information security awareness is the topmost item.
mind:It's always the social engineering, the human element that breaks first.
mind:Yes, sir. You know, that it's, it's, I don't think that's
mind:changed for a couple of decades,
mind:actually, you know, in terms of the social engineering aspect is
mind:something that, yeah. And I think you said it like, We need more
mind:education around that, right? I know a lot of companies, they do
mind:intentional red teaming. When I was at Microsoft, I,
mind:you know, I got caught up in, not caught up, but I got, they had
mind:like an internal like phishing attempt. And
mind:because I was looking at the email on my phone, I
mind:didn't see that it was obviously a bogus link. And they, you know, when you
mind:click on it, it says you got caught. Like, was kind of like, it was
mind:kind of like, oh yeah. So like to this day, like if I ever get
mind:an urgent thing, I'm like, All right, I am not touching this link with my
mind:phone. I'm gonna mouse over it with, you know, on my
mind:computer, which is interesting. I think that is also, I know it sounds
mind:stupid and it'll probably sound absolutely crazy, but if phones had the ability,
mind:the phone apps, when you click on a link, you would get some metadata
mind:about it. I think that would go a long, obviously if you know to look
mind:for it, right? Like it would go a long way to stop it, right? 'Cause
mind:like when I did look at the, when I went back to my desktop and,
mind:you know, looked at the message inside of, browser, I could
mind:see it was obviously going to, you know, some bogus site.com or something like that.
mind:But yeah, and the way these are written,
mind:they give a sense of urgency. So you want to— you can't—
mind:it almost is like if you wait until it's too late, until you wait until
mind:you get to your desk, that alone is a flag right now.
mind:I kind of think about that, you know, fool me once, shame on you. Fool
mind:me twice, you know, shame on me. But I
mind:have noticed that some companies will intentionally do these.
mind:And so I think that's actually a useful exercise right there, right?
mind:Because it becomes a teachable moment of this was not—
mind:it's kind of like the broadcast messaging. If this were an actual emergency,
mind:right? If this were an actual phishing attempt. But
mind:you're right, and AI is getting better. And most people, when they hear about how
mind:AI is getting better at these phishing attacks, They think, oh, it's a
mind:3D-generated real-time voice of somebody or
mind:avatar of somebody, but it doesn't have to be. If the
mind:grammar's— if it's written persuasively and the grammar doesn't
mind:look off, that
mind:alone could do it. And that's just basic LLM stuff.
mind:It is. And don't feel like the Lone Ranger. I had to
mind:take remedial training earlier this year because I clicked on a phishing link myself.
mind:So, you know. what you said. It's just,
mind:it's so persuasive, and there is this sense of urgency, and
mind:then you are multitasking so many things, and then you
mind:happen to open that email. Yeah, that's— it's funny. And then
mind:in my current job, there's often the saying of,
mind:if you get an email and it says so-and-so asked
mind:for this, call them up. Because
mind:it's probably bogus. That's the best remedy.
mind:Yeah. There have been a couple of—
mind:I haven't failed a test since the one I was at Microsoft,
mind:at least that I know of. I could have clicked on a not test,
mind:but I think just admitting that you were caught in that,
mind:you had to take remedial training. I got caught up in something and I
mind:think taking away the shame of even smart people get caught up in
mind:because these things are getting better and they're using AI. Right.
mind:And they don't have to mimic your voice. Right. It's funny, the other
mind:day, it was like about a month ago,
mind:my wife texted me on Signal, which she never does.
mind:Right. And she wanted to know the password for one of my accounts.
mind:And I was about to give it to her and I'm like, wait a
mind:minute now. So I called her up.
mind:and spoke to her directly. And she goes, why'd you call me to get this?
mind:And she works in cybersecurity, right? So like, that's her business. I was like, well,
mind:you reached out to me on the channel you never do, and you asked for
mind:a password. That immediately made me suspicious enough to call
mind:you and find out verbally it was you. And at first she was
mind:annoyed, and then she stopped and she's like, no, you're right.
mind:And it's not just the enterprise either, right? I mean, this, These phishing scams can
mind:affect you personally too.
mind:Yep, yep. In, in my family, we have a code. So
mind:if somebody calls with an urgent need for help, we first
mind:have to ask for that code. And this came off a real
mind:incident that happened last December. I was in Austria for an audit,
mind:and my son, who is here in Texas, he got a call saying, son,
mind:I've been in an accident. So he hung up and he called me back.
mind:He said that, Dad, it was your voice. Wow. Frank, your
mind:voice, my voice, we are on the web, so it's very easy to emulate that.
mind:Right. It's that we've given it all the training data and we can't get it
mind:back. Yeah, yeah, yeah. No, I mean, that's a great idea, the code
mind:word. It's funny you mentioned that because one of my
mind:youngest son's daycare, there's this a code word that you have to give
mind:them for certain transactions or certain kind
mind:of like changes to the schedule. And I was like, first I was
mind:like, well, that's unusual. And I'm like, no, that's actually quite brilliant. It is.
mind:Yeah, yeah. Because I can easily imagine somebody's voice getting
mind:cloned. And yeah, I mean, it's,
mind:it's, I would say we live in dangerous
mind:times, but I think The dangers always evolved, right? We're not worried
mind:about Vikings raiding our villages anymore, but we do have to
mind:worry about someone doing some kind of weird crypto scam. Or,
mind:you know, one time, a long time ago, I
mind:had my own server in my house that I had exposed to the public internet,
mind:and I took the password protection off it temporarily, and then I forgot.
mind:And long story short, within couple of weeks, my
mind:internet connection ground to a halt and I'm like, what's going on? And I
mind:did some traffic sniffing and hey, there's a lot of FTP traffic
mind:and I saw my hard drive was getting full and I'm like, what's going on?
mind:And it was basically all these PS2 ROM files.
mind:Basically people were using my open server as a place to pirate
mind:PlayStation 2 games. This was a while ago. So
mind:even I got caught up in that, right? Like the whole
mind:convenience, lack of convenience is a security feature.
mind:And I was, I was talking to some security people on, on the Impact of
mind:the Quantum Computing show, Impact Quantum, and he
mind:said like, if it's convenient, it's not secure. I think that was basically what he
mind:said. And I was like, he's right. Yeah. Ah,
mind:I wanted him to be wrong, right? Because we all love the convenience of
mind:you scan your fingerprint or whatever. And I'm not saying
mind:that's not secure, but having the knowledge of a PIN, even though
mind:that's not perfect, as inconvenient as
mind:it is for it to ask you a PIN every time you want to restore
mind:a password or show a QR code or give it a random number,
mind:semi-random number, it's inconvenient. But that inconvenience
mind:is a mark of security. Very well
mind:said. Yeah. And then Amplified over the whole organization
mind:to convince everybody to make sure that this culture is
mind:required. How do you— that's a good question. So,
mind:so how do you get people to a culture of security?
mind:I don't want to say culture of security, but security awareness. Is it training?
mind:You know, what is it? I
mind:think training and testing both are very important.
mind:So having campaigns to train people with the latest
mind:threats, what are the best practices today, because they
mind:keep changing. Right. And then making sure that that
mind:training took place, that training reached the
mind:recipient. So test them through, like you said, phishing
mind:campaigns or a variety of other means
mind:to ensure that we have enough evidence to show that
mind:100% of the people who have access
mind:to confidential data are aware and have
mind:completed the latest training requirements.
mind:Interesting. It all gets back to people, doesn't it? Or the old
mind:people, process, and things, right? You know, the fundamentals.
mind:As much as things change in the day-to-day in technology, it's just the fundamentals always
mind:come back. You're always going to have people, right? You're always going to
mind:have processes, and you're always going to have things, whether those things
mind:are logins or agents doing things
mind:autonomously. It just seems like there's a lot
mind:we can learn from the history of it, if that makes sense.
mind:Yep. Interesting. We're getting close to
mind:the top of the hour. What would you tell—
mind:what do you tell customers who are skeptical? Because I'm sure you still
mind:encounter that. And it's probably different in different industries, right?
mind:Obviously, if you're in finance or healthcare,
mind:although that's probably— that probably leads to a type of complacency that's
mind:dangerous, doesn't it? It is a
mind:difficult concept for some organizations, right? And
mind:it's just, it's mind-boggling. I know organizations
mind:who have had
mind:scare who have had
mind:ransomware across their whole network,
mind:and yet they do not see the point of why they need to
mind:implement a management system to address information security.
mind:So even an adverse
mind:experience in the past is not sufficient to implement it for some
mind:organizations. Others are proactive, and they want to make sure that
mind:There's no impact to their reputation. There's no financial
mind:consequence. There's no legal consequence. So they go ahead and
mind:implement it. So the culture varies quite a bit.
mind:Have you noticed any patterns of
mind:people in this industry tend to be very much on point,
mind:or is it kind of evenly distributed across that spectrum? Some
mind:industries are more mature than others. I think that if you look at the
mind:annual reports from Gartner or
mind:FBI, sometimes they have these charts depicting different
mind:sectors and state and local governments always come
mind:at the bottom of the list. Interesting.
mind:I guess that's a list no one wants to be on.
mind:But then you're right, like, I guess some people
mind:or some organizations never learn, even if after they've had a breach or after they've
mind:had an incident. Although,
mind:from what I've seen, and I can't share too much about this, I suspect that
mind:there are insurance companies that, I guess, offer some kind of protection
mind:against this. And then part of the remediation, they'll pay out the policy
mind:and you're like in typical insurance, the fee goes up, but you also
mind:have to implement certain very specific training and changes to
mind:company policy in order for you to for them to still
mind:insure you after an incident. I would imagine that that
mind:helps. Folks listening can't see the air quotes,
mind:but I've seen that happen.
mind:Can't say where, but if you use LinkedIn, you probably figure out—
mind:LinkedIn and Google, you'll probably figure out who I'm talking about. But
mind:the— what fascinates me is
mind:the human element of what makes
mind:someone proactive voluntarily and what makes
mind:somebody complacent in spite of the evidence,
mind:in spite of experience. I mean, that's obviously not a technical question, and
mind:this is probably something that digital trust alone
mind:can't— I don't know. It just fascinates me, that human element of what makes
mind:some people and some organizations
mind:overly compliant versus what makes them,
mind:for lack of a better term, complacent in spite of evidence.
mind:I think whoever figures that one out has the next billion-dollar business, right?
mind:Totally. Because you could teach people who are
mind:complacent to a self-destructive degree, you can kind
mind:of hypnotize them or snap your fingers and they'll be
mind:closer to Reasonable. You're right. It's a
mind:complex puzzle. And it's always the people, right? Yes.
mind:Even in this age of AI, this age of data,
mind:people still have the agency to be
mind:stupid or ignorant or willfully— like, there's
mind:ignorance and then there's willful ignorance, right? Ignorance is, I think you can
mind:excuse to a certain degree, but willful
mind:ignorance of, oh, now we had that happen already. It won't happen again.
mind:Right? Thinking that lightning doesn't strike twice. This isn't
mind:lightning. That's true. And then, you know, you have to
mind:get— we have to give grace to people who are working in different areas of
mind:the organization. Some are more technically oriented and some are not.
mind:So it's obvious that groups which are
mind:not more technically oriented, they are not keeping up with the latest threats.
mind:It takes additional effort for them to go read up on what are the
mind:best practices today. That's fair. That's fair. But I, and
mind:I would imagine that the, the
mind:bad actors know that and they're probably being
mind:targeted. So it's almost like an ethical, almost an ethical
mind:responsibility for the organization to take care of them,
mind:right? Because the, you know, what did they say? The, the slowest antelope
mind:gets eaten, right? Right. I think it's, I think
mind:it's ethical for, you know, the, the, the the organizations to
mind:be mindful that they're going to have some slow antelopes, if you will,
mind:right? And you have to teach them how to protect
mind:themselves. That's where leadership or the
mind:commitment of leadership comes in, not just with information
mind:security training and developing the information
mind:security culture within the organization, but also the other question
mind:that we were addressing a few minutes ago. Why are some industries more
mind:prone to getting certifications and creating these management
mind:systems and some others are willfully ignoring it. And that is
mind:also, if I'm allowed to point fingers here, I would point fingers at
mind:the leadership again. 100%. Well, I mean, the leadership's—
mind:leadership in any organization, commercial, private,
mind:anywhere, combination thereof, their job
mind:is to lead, right? And if they don't lead,
mind:things will happen more on their own. Exactly.
mind:The stars are not going to align that things are going to magically work out.
mind:It might every few billion years, but it's not going to happen on a regular
mind:basis. So if you are in leadership, part of
mind:that is you have to take on the
mind:responsibility. I've had this
mind:argument with one of my sons where it's like, well, it's not my fault that
mind:happened. It's not your fault, but it's your responsibility to make sure that
mind:doesn't happen. Right? You know, clean up the mess or do this.
mind:Like, you know, it's not your fault, you're not being blamed, but it's your responsibility.
mind:And I think, I think a lot of organizations have lost the sight of that
mind:in their leadership, right?
mind:Um, one of the things that really changed my mind on
mind:that was Extreme Ownership, and it was by, I think, Jocko Willink, former
mind:Navy SEAL guy. And it's an audiobook. So
mind:Audible is a sponsor of the show. So if you go to thedatadrivenbook.com,
mind:You'll get routed to Audible. You get one free audiobook on us, and I highly
mind:recommend that one. It basically mentions, like, you know, that's where
mind:I might have gotten that line where it's not your fault, but it's your responsibility,
mind:right? So if you take responsibility for things, even if they're not really your
mind:fault, you're going to end up in a better place, right? And I think
mind:organizations have to really take that to heart. They should take it to heart
mind:on everything. Should, right? But when it comes to IT security and, and,
mind:and matters like this, they definitely need to, because if they don't, no one
mind:else is gonna. Yep. All right, I'll
mind:get off my soapbox now. That was wonderful. I'm thinking
mind:of finding that audiobook and listening to it, so thank you for pointing me
mind:to it. Oh, no problem, no problem. It's, it's a really good audiobook. Do you
mind:have any audiobook recommendations, or— Not in this area.
mind:Okay. Very dry area, so— Fair enough.
mind:But there are a lot of good, uh, AI training,
mind:especially. I was just looking at Claude.ai
mind:recently, and they have Claude Academy, which is free for people to
mind:learn how to, how to use AI responsibly
mind:and ethically. That's a good point. I've heard
mind:about Claude Academy, but I've not looked at it. So one of these afternoons when
mind:I have a free calendar hour or 2, I'll definitely take a
mind:look at it. But where can folks find out more about you and
mind:what you're up to? Reaching out to DQS is the
mind:best option. We have a lot of webinars, we have white papers
mind:on our website, and as,
mind:as I gather more and more questions, I am available
mind:for individual conversations as well as group
mind:conversations during one of the webinars. And that's
mind:dqsglobal.com. You're right, thank you for saying
mind:that. Yes, dqsglobal.com. Cool website too.
mind:And you're right, it's not just about
mind:information security. It seems like you cover all kinds of different certifications
mind:and things like that, including 9001, which I remember. And
mind:yeah, very cool. And now I see how to spell TISAX,
mind:T-I-S-A-X. That's cool. Oh, and it's
mind:interesting because I'm looking at the site and like there's a lot of certifications out
mind:there. And there were things I'd never even heard of.
mind:Yeah. Just ISO has more than 60,000
mind:standards published. And then there are others outside of
mind:ISO. Wow. I'm impressed.
mind:I'm impressed. So definitely check it out, dqs-global.com.
mind:And any parting thoughts?
mind:Thank you very much for having me. I encourage everybody to visit our
mind:website and Feel free to reach out to me with any and all
mind:questions. And we'll make sure to put your LinkedIn profile in
mind:the show notes as well, in case they have any questions directly. And with that,
mind:we'll let the outro music play.