Artwork for podcast Data Driven
Digital Trust in Practice: Compliance, AI, and Human Factors with Sandeep Pauddar
Episode 138th September 2026 • Data Driven • Data Driven
00:00:00 00:47:03

Share Episode

Shownotes

In this episode, Frank La Vigne sits down with Sandeep Pauddar, Head of Digital Trust at DQS, to explore the fast-evolving world of digital trust, compliance, and data security. From the growing complexities of global regulations, to the increasing intersection of AI, cybersecurity, and enterprise risk, Sandeep Pauddar shares real-world stories—including personal experiences with AI-driven phishing—and breaks down how organizations can foster a security-aware culture. Whether you're leading a startup or a global enterprise, tune in for actionable insights on building digital trust, navigating the compliance landscape, and why organizational leadership plays a crucial role in keeping data secure.

Links

Time Stamps

00:00 Introduction and guest welcome

05:00 AI data security in various industries

06:44 Department collaboration on AI and compliance

10:58 Information security standards overview

14:23 Balancing Innovation and Standardization

18:14 Navigating global AI regulations

22:14 Regulatory advice for startup founders

25:33 Discussing common patterns in failures

28:24 Discussing link metadata in apps

33:09 Security threats and personal story

37:11 Challenges in adopting security systems

38:32 Insurance and breach response policies

43:21 Promoting Extreme Ownership on Audible

45:01 Finding more about Claude Academy

Transcripts

Speaker:

In my family, we have a code. So if somebody calls

Speaker:

with an urgent need for help, we first have to ask for that code.

Speaker:

And this came off a real incident that happened last

Speaker:

December. I was in Austria for an audit, and my son, who is here

Speaker:

in Texas, he got a call saying, son, I've been in an accident.

Speaker:

So he hung up, called me back. He said that, Dad, it

Speaker:

was your voice.

Speaker:

Hello and welcome back to Data Driven, the podcast where we explore the emerging

Speaker:

industry that is artificial intelligence, data science, and of course, it's

Speaker:

all not possible without the importance of data

Speaker:

engineering. Fortunately, my favorite data engineer in the world

Speaker:

cannot make it today, but I am gonna carry on without

Speaker:

him. Today we have an interesting guest, and, uh, he's been

Speaker:

super patient because of scheduling snafus on his end, my

Speaker:

end. We've had a lot of those. I am speaking today with Sandeep Padar,

Speaker:

and, uh, he is Head of Digital Trust at DQS.

Speaker:

He is coming to us from deep in the heart of

Speaker:

Texas at, uh, the Dallas-Fort Worth Metroplex. Welcome to the

Speaker:

show. Thank you for having me, Frank.

Speaker:

Hey, no problem, no problem. So what is digital trust

Speaker:

to you? What does that mean? So

Speaker:

in the past, in the realm of compliance,

Speaker:

people were chasing different standards based on what

Speaker:

the requirements were there. There could be regulations requiring a certain

Speaker:

standard. There could be clients' contracts requiring

Speaker:

certain regulations. And this was all

Speaker:

piecemeal. Now, as the effort grows and

Speaker:

multiple dimensions come together, use of AI models, AI

Speaker:

data, various regulations from different agencies and

Speaker:

clients, and then of course the important

Speaker:

dimension of security, they all come together. It becomes

Speaker:

overwhelming to do this piecemeal, and it's best

Speaker:

to aggregate this together. in one cohesive compliance

Speaker:

effort. And this is what we are calling digital trust.

Speaker:

That makes sense. Do you think, it may be too early to ask this question,

Speaker:

but based on what you said and kind of reading the tea leaves

Speaker:

and reading the room, I could easily see there being a need for a

Speaker:

chief trust officer at some point in the future at the C-level. Do you

Speaker:

think, is that looking too far ahead or

Speaker:

just right on target? You are so right. We are there now.

Speaker:

You are correct. So more and more organizations are having these questions.

Speaker:

How do we face all these compliance dimensions and how do we fulfill our

Speaker:

requirements? I have written a white paper recently on the

Speaker:

top of this topic, and we have some webinars coming up as well where we

Speaker:

address this very same topic for different verticals, not just

Speaker:

for IT companies or AI companies, but say

Speaker:

for example, we have a webinar coming up on medical devices

Speaker:

because every sector is facing the same difficulty. So I

Speaker:

fully agree there is need for a dedicated

Speaker:

organization led by a compliance officer in

Speaker:

digital trust. I can see that. And, and,

Speaker:

and you're right, when you mentioned medical devices, there's obviously a certain level of trust

Speaker:

in there. And trust, because to me, and you kind of said

Speaker:

this in the intro, When you describe what you do, like, the AI is

Speaker:

part of trust, identity is part of trust,

Speaker:

obviously cryptography, security, all that stack, right? So there's a

Speaker:

security probably foundation of that. What else,

Speaker:

like, what else would be involved with trust? So

Speaker:

it varies from sector to sector. There are so many

Speaker:

verticals that share the same foundation of using

Speaker:

AI responsibly and ethically because everybody is using it.

Speaker:

And of course, they have the responsibility to protect their data.

Speaker:

So security is another dimension.

Speaker:

The 3rd dimension that varies a lot is regulations. Every

Speaker:

sector, every vertical has their own set of regulations to meet,

Speaker:

and therefore the mix of standards that will go into their

Speaker:

compliance there Integrated management system would

Speaker:

be different.

Speaker:

So is this rolling out

Speaker:

in some industries more, right? So you obviously have regulated industries, right?

Speaker:

Healthcare, finance, I would assume. You mentioned healthcare. I'm assuming finance is going to

Speaker:

be a big player in this, but also public sector, right? I mean, defense

Speaker:

and anything related to government, I would imagine, would really

Speaker:

require Well, requires is a loaded word—

Speaker:

demand or need some level of

Speaker:

enhanced trust. I fully agree, and

Speaker:

we cater to a very diverse set of

Speaker:

verticals. We have aerospace audits, we have

Speaker:

automotive industry, food, environmental health and

Speaker:

safety, quality, and all of these verticals

Speaker:

now need to address the data security

Speaker:

regulations around data security regulations around AI use.

Speaker:

And then depending on the geographical area which they are

Speaker:

catering to, the flavors would change as well,

Speaker:

whether you are, you are complying to

Speaker:

European Union AI Act or whether you are in California

Speaker:

or Texas, and then you have to look at the state-level AI

Speaker:

regulations. Right. And the regulation market

Speaker:

is getting far more complicated, right? Obviously, everybody knows the

Speaker:

European Union. I know Switzerland has their own scheme,

Speaker:

but also at the state level, at the second-level government, right? In the United

Speaker:

States, California. I know that different states have different— you said

Speaker:

that's Texas. I think Maryland is— I live in Maryland, which is why I'm bringing

Speaker:

it up— is also bringing up a lot of these types of

Speaker:

regulations too. It sounds like this is getting

Speaker:

It's a growth industry, isn't it? Or a growth concern.

Speaker:

It is. The rate of change of information, data,

Speaker:

knowledge is increasing. So

Speaker:

vulnerabilities are increasing as well. And then everybody has the

Speaker:

responsibility to, to address it. It's a make or break

Speaker:

situation for many organizations. And you know what's

Speaker:

interesting? This seems inherently cross-discipline and

Speaker:

cross-functional. Isn't it? That is correct. Yeah.

Speaker:

Because it seems to me like a lot of this is going to be—

Speaker:

and I'll ask you questions about like how

Speaker:

best— obviously there's no best way, but obviously

Speaker:

just as soon as you say regulation, that translates to a

Speaker:

legal department, right? There's also a security

Speaker:

aspect, right? So that's IT operations aspect. There's also, you

Speaker:

know, as AI gets looped into this, there's going to be

Speaker:

veracity kind of concerns and, you know, model provenance and

Speaker:

kind of the— it sounds like this is inherently going to

Speaker:

involve at least 3 departments, probably more. But off the top of my

Speaker:

head, I see the legal department get involved, IT operations, and however

Speaker:

organizations break out their AI people, right? And data engineers

Speaker:

obviously need to be a part of that. Shout out to you, Andy. But what

Speaker:

How is that going to be structured? Because lawyers don't like to share the room.

Speaker:

IT operations don't like to share the room. AI people certainly do

Speaker:

not like to share the room, right? Or share the mic, as it were. How's

Speaker:

that going to work out? Like, is this going to fall under compliance? Is this

Speaker:

going to fall under each individual business unit? Or it really depends

Speaker:

on the problem and the regulations? You said

Speaker:

it right. And what a wonderful question it is, because I get this question all

Speaker:

the time. clients get a requirement from somebody

Speaker:

to come up with a certificate, and they come to us,

Speaker:

and their first thought is that information security

Speaker:

is IT's responsibility. So they bring IT people

Speaker:

into the initial call, and that's when everybody learns

Speaker:

in the room that information security is everybody's

Speaker:

responsibility. These standards that we typically

Speaker:

audit against ISO 27001 or

Speaker:

TISAX for automotive industry.

Speaker:

They are organization-wide regulations or standards.

Speaker:

So it's not just IT, but we look at the

Speaker:

overall awareness about information security throughout

Speaker:

the organization. We are talking to

Speaker:

legal, like you said, we are talking to procurement.

Speaker:

How are you securing the information that you are sharing with your vendors?

Speaker:

HR, how are you hiring people? Are you conducting background checks

Speaker:

and stuff like that? So it's, the controls

Speaker:

of these standards are organization-wide, and information security is

Speaker:

everybody's responsibility. It's in some industries

Speaker:

which are a little bit behind the curve. It's

Speaker:

an awakening for them. How do they—

Speaker:

what's that awakening process look like? Aside from being painful,

Speaker:

right? What do they kind of— do they

Speaker:

get a cease and desist letter? Do they get an

Speaker:

RFP or an RFI and they have to fill out sections of

Speaker:

the form where it's like, what's your compliance controls? Like, how does that look like?

Speaker:

How do they go from, we don't need this, to, we really need this, we

Speaker:

need this yesterday? I agree with you. So

Speaker:

in short, I could say that it's a culture that needs to

Speaker:

be developed in the organization, and it's

Speaker:

the top management or leadership that defines that culture.

Speaker:

So as we audit hundreds of organizations through,

Speaker:

through the year in various different sectors, we can see the difference.

Speaker:

Some organizations have a very robust, mature

Speaker:

information security culture, and that is driven by the

Speaker:

interest and commitment from their top management. And some others

Speaker:

are not at that level yet, and it's very clear that the top

Speaker:

management has not awakened, or they are not forcing it as

Speaker:

much through policies, processes, and their involvement,

Speaker:

not just yet, but it's coming to every sector.

Speaker:

Is there, like, an ISO standard for this yet, or

Speaker:

is that in process? Or I know there's like Six Sigma, there's ISO

Speaker:

9000. I know those are different animals, but you think that—

Speaker:

is there a standard like that in the works, or is there already one?

Speaker:

Just like you mentioned ISO 9001 for quality, for

Speaker:

information security, which is organization-wide, we have had

Speaker:

ISO 27001, which is a mature standard.

Speaker:

Very recently revised to its latest version in 2022,

Speaker:

and it addresses various aspects of the organization end to

Speaker:

end, and involvement and

Speaker:

commitment of top management is addressed at the foundation of

Speaker:

the standard. So that's one. But for different

Speaker:

industries, there are specific standards, such as for

Speaker:

automotive, there is a standard called TISAX, which is governed

Speaker:

by a German company, ENX, and it is

Speaker:

tailored to information security within the

Speaker:

automotive industry. At the design level, there's another

Speaker:

standard called ISO 21434, which is

Speaker:

gaining momentum in addressing all the current requirements because the

Speaker:

automotive sector is realizing that vehicles

Speaker:

are becoming intelligent and they're holding and transmitting a lot

Speaker:

of data. So information security has to be

Speaker:

considered in the design of the vehicle itself so

Speaker:

that it can receive over-the-air updates securely, for

Speaker:

example. So these are the 3 that, that come to top of my

mind:

27001, TISAX, and ISO

mind:

21434. Interesting. And

mind:

you mentioned one of those standards, it was the 27001.

mind:

Came out in 2022, which I would imagine that they're gonna— because

mind:

ChatGPT obviously was released to the world in end of

mind:

2022, so they probably didn't factor that into. And

mind:

obviously it's a fast-moving field, right, this AI

mind:

thing, um, as it were. Uh, there's agentic, there's a

mind:

lot of debate about this. How long does it take for a standards

mind:

body to agree on, like, and coming up with a certification?

mind:

And it seems to me like there's a tension between the

mind:

technology releasing capabilities and

mind:

the standards body taking a certain amount of time to come up with

mind:

criteria? That is such a good question, such an

mind:

interesting topic for me. So the latest version of

mind:

ISO 27001 came out in 2022. The previous version

mind:

was in 2013. Oh, okay. ISO

mind:

has to consult with a lot of different sectors

mind:

to distill the requirements into the standard. It takes time. It

mind:

takes time to review it. It takes time to get the feedback and then

mind:

finally release the standard. So it's an inherently very

mind:

involved process across all of the verticals.

mind:

Therefore, it takes time. But you are so right. This field

mind:

is changing so fast. The standards need to keep

mind:

up with it. So ENX, that

mind:

publishes the TISAX standard. They have come up with a

mind:

scheme to revise their standard every year,

mind:

not at a very large scale, but fine-tune it every

mind:

year based on the best practices that are needed. So this is very new.

mind:

From next year, they are going to have an annual release of their

mind:

catalog, which is called TISAX Catalog, and they are going to

mind:

fine-tune it based on the requirements and

mind:

best practices in the automotive industry. That's

mind:

a good hybrid approach because you want the standards,

mind:

you want the standards to change relatively slowly, but you also need them

mind:

in this ridiculous pace of innovation, which who knows how long

mind:

this might be the new normal. This might just— the AI bubble may pop

mind:

and we'll all be like scrambling for the pieces in a couple of

mind:

months or whatever the doom people say, right? AGI

mind:

may come out last week, if you believe everything

mind:

Sam Altman says. So I think

mind:

it's a clever strategy because the standards have to be some kind of

mind:

baseline in reality, right? It has to be like a true

mind:

north, right? It has to be the standards. And by definition, they're not

mind:

supposed to change that often, but they also have to adapt. So

mind:

that does seem like an interesting tension. And was it I

mind:

wonder, I guess we'll see how it all plays out, right? Is

mind:

this a good idea or not? It's a

mind:

challenge to strike that balance. I mean, anyone who has

mind:

looked in their car glove compartment for a

mind:

USB charger knows that the struggle, and

mind:

that's only between what, 3, 4, maybe 5 different

mind:

formats to look for a phone charger. You don't want the

mind:

standards changing that much. Right? You don't want— if you're old enough

mind:

to have been in this industry long enough, you probably have a drawer of wires

mind:

and obscure connectors ranging from the old PS/2

mind:

port to RS-232 and

mind:

the printer parallel port. Those were standards too,

mind:

but you can't— if you have too many standards, they defeat the purpose.

mind:

That's cool. What is the biggest challenge that you see in

mind:

your customers and in your space about,

mind:

do they acknowledge that they need to have some kind of control

mind:

around this space? Do they understand the

mind:

concept of digital trust? Do they—

mind:

I imagine it's a spectrum, but where do you find most people?

mind:

Yeah, some industries are more mature than others.

mind:

So obviously technology based

mind:

industries, highly technical markets, they are more

mind:

mature in this area because they see it on a daily

mind:

basis. But some other older industries, they are

mind:

having a hard time catching up. The progress is there, of course,

mind:

but as, as this field grows, and I mentioned

mind:

multiple dimensions, AI is everybody's business. Right. If you are

mind:

not producing, you're not providing AI, then you are at least using it.

mind:

How do you make sure that your employees are using it in an ethical and

mind:

responsible manner and not exposing yourselves to any legal

mind:

ramifications later? AI technology is growing, models are growing, and

mind:

these models— some people say that they are producing wrong outputs, some people

mind:

are very happy with how they're using it. Where's the difference? The difference

mind:

is that AI readiness is

mind:

a metadata problem. Everybody is struggling to make sure

mind:

that the data that goes as an input to the model is

mind:

correct. It's unambiguous, it's truthful.

mind:

Otherwise, you cannot trust the output. Right. So that's one part

mind:

of this puzzle. Various industries are struggling at a

mind:

different level and meeting the requirements at different level. Of

mind:

course, all of this is based on regulations and requirements. So

mind:

contractual requirements are telling people what to do. Or

mind:

federal or statutory requirements are telling

mind:

people. In this industry, people don't take

mind:

proactive approach to do the right thing unless somebody's

mind:

requiring it. So, European Union, I

mind:

mentioned the AI Act earlier. It's a good example, but

mind:

you might remember GDPR. When GDPR came through European

mind:

Union in the beginning, All the member

mind:

countries had a different flavor to implement. They

mind:

all had their own individual requirements, and that's how it combined.

mind:

Same thing is happening with the AI Act. So all member

mind:

countries are going to have a little bit variation in how they

mind:

implement and require the AI penalties and

mind:

how they enforce it. In the US, same thing

mind:

at the federal level. We moved back

mind:

from regulations a little bit so that innovation could take place, but then

mind:

different states are requiring it at different levels.

mind:

So this is a nightmare for a

mind:

company that's trying to fulfill the requirements, and they have,

mind:

say, worldwide business. They are catering to European Union citizens

mind:

as well as they have Asian markets and United States. So

mind:

they have to have, like you said, a dedicated

mind:

group, a dedicated leader who can ensure that they are

mind:

meeting the regulations. And

mind:

that group has to have pretty wide authority over product.

mind:

It sounds like— I like to put on my optimist hat and my

mind:

rose-colored glasses, but I also know that only goes so

mind:

far, right? It sounds like there's going to be a lot of

mind:

territorial arguments over

mind:

this, and I foresee a lot of

mind:

internal inside of companies like fighting over this, right? So

mind:

I mean, it makes sense. You have to have board-level buy-in on this

mind:

to tell the kids to not— to stop fighting with each other

mind:

and get something done. Have you seen that happen, or

mind:

are people mature enough not to get into these little territorial arguments?

mind:

I see different interpretations of this and different

mind:

implementations. So in short,

mind:

what I recommend to various organizations is that we have to

mind:

take all this together. We have data protection,

mind:

cybersecurity, AI governance, and

mind:

these all need to converge into the

mind:

enterprise risk model together. We cannot have separate risk,

mind:

risk registers and separate risk analysis for

mind:

various different dimensions. So they have to converge

mind:

as the overall

mind:

enterprise risk function instead of 3

mind:

different dimensions that are treated differently.

mind:

That way, an organization can holistically address

mind:

all of these issues. and move forward in a, in a

mind:

continuous improvement, productive way. Otherwise,

mind:

it becomes very challenging to merge it all together. Yeah,

mind:

I mean, that makes sense. That makes sense. Do you think that

mind:

all of these regulations— I have mixed feelings about this because I think

mind:

regulations are important, but I think you could make that— I can

mind:

go either way, right? Do regulations encourage innovation? Do they

mind:

stifle innovation? I think the answer is kind of

mind:

nuanced, but I want to get your take on this, right? Because like you said,

mind:

no one does this because they want to do it. They do it for compliance

mind:

reasons. It's not— it's driven by legal and

mind:

contractual obligations. What's your take on that?

mind:

It's a question that everybody is struggling to answer depending on which

mind:

geography you are in. Different cultures, different countries

mind:

have a different balance. Some want to be more

mind:

forceful in the regulations. Some others want to let the

mind:

innovation run free till we run into certain pitfalls. And

mind:

then as a knee-jerk reaction, as a, as a reactive

mind:

way, regulations come up. But most important thing

mind:

is to have a good balance. Regulations will always come

mind:

after the innovation comes. So innovation will always precede.

mind:

Yeah, it's What would be your advice to

mind:

smaller companies and small founders, right? That they're kind of—

mind:

what would be your advice? Obviously, if you're starting a medical

mind:

device company, you know you're walking into a

mind:

regulatory— I don't want to say minefield, but you know regulations are going to be

mind:

part— regulatory compliance is going to be a big part of your workday.

mind:

Every day. But what about,

mind:

you know, AI startup founders,

mind:

right? Like, obviously they— I would imagine— well, I

mind:

guess if you're doing— if you're starting in 2026, regulations has

mind:

to be at least in the back of your mind, right? Uh, it's not

mind:

like social media had the clean, wide-open spaces for

mind:

as long as they did. I think those days are over. What would be your

mind:

advice to someone who's starting a company and they think, I

mind:

don't need to worry about this regulation stuff?

mind:

I see it across various industries all the time.

mind:

Clients come with all types of questions and thought process.

mind:

Some want to be overambitious and achieve it all, and

mind:

some don't really understand how many requirements

mind:

would be there in front of them. So in general, I

mind:

always say keep it simple. Identify the

mind:

minimal set of requirements that they need to meet because it does

mind:

not have to be overwhelming to the organization. And then

mind:

a continuous improvement process is important.

mind:

You cannot reach maturity in the first attempt. So what we

mind:

call it as a PDCA cycle, or Plan, Do,

mind:

Check, Act cycle. which can have different frequencies

mind:

for different standards, but that cycle needs to be in place.

mind:

So keep it simple, start small, and then mature

mind:

that management system into a highly

mind:

mature compliance system depending on what their

mind:

requirements are.

mind:

Interesting. So it shouldn't be this big scary thing you ignore,

mind:

or your big scary thing you're— this big scary thing you ignore, because that sounds

mind:

like Bad idea, right? But like, what—

mind:

so you're saying that they should embrace it and understand it, don't fear it?

mind:

Exactly. Open communication is also important. Many

mind:

organizations come to us with questions that, oh, we have this requirement,

mind:

but we don't know what to do with it. Of course, we cannot consult

mind:

and implement it for them because then we will not be able to go back

mind:

and audit it. We show them the roadmap and then they can go

mind:

find consultants in the area. figure it out and then come back

mind:

to us for certification audits when they're ready.

mind:

And is that what your company does? DQS? DQS is

mind:

a global organization. We have offices in more than 60 countries.

mind:

We have more than 2,500 auditors,

mind:

and wherever clients are, whatever are their compliance

mind:

needs, we can definitely help them with the certifications.

mind:

Oh, very cool. And not just the digital

mind:

trust aspect of it, right? Like everything. This is just one vertical. Yes,

mind:

that's right. Okay. Interesting. Interesting. Have you

mind:

noticed any patterns yet? You know, any patterns of,

mind:

do companies, obviously not giving any names, do people fail around the

mind:

same things or it really runs the gamut of what's possible?

mind:

Like, you know, like, oh, they left credentials out on an

mind:

open server or something like that, right? Or is there very, is

mind:

it specific? specific to what people are doing? Is this specific to

mind:

the industry? Like, are there any common, common, like, if

mind:

you had to come up with a list, what they call listicles, like the top

mind:

10 things everyone's doing wrong, right? Like, what would that be?

mind:

I agree with you. So in different sectors, in

mind:

different verticals, we see different weak areas.

mind:

And this aligns with many annual reports that you see from,

mind:

say, Verizon or FBI, they

mind:

issue annual cybersecurity reports, and you see

mind:

that people are the weakest point. According to the latest

mind:

FBI report, more than 2/3 of data breaches

mind:

occur when somebody falls prey to a phishing

mind:

email. So people need to be more aware. The security

mind:

dimension is challenging as well. It's changing

mind:

quite a bit. The attackers now use AI. So in the past,

mind:

we could tell a phishing email because of the poor grammar or

mind:

misspelled names and the words. But now they're using AI

mind:

to automate and scale their attacks in a very efficient way.

mind:

So it's a cat and mouse game. We have to make

mind:

sure that our employee base, our contractors play base, our vendors

mind:

are keeping up to the challenge. So that's, that's one big area.

mind:

If you ask me to name the top area, I would say

mind:

information security awareness is the topmost item.

mind:

It's always the social engineering, the human element that breaks first.

mind:

Yes, sir. You know, that it's, it's, I don't think that's

mind:

changed for a couple of decades,

mind:

actually, you know, in terms of the social engineering aspect is

mind:

something that, yeah. And I think you said it like, We need more

mind:

education around that, right? I know a lot of companies, they do

mind:

intentional red teaming. When I was at Microsoft, I,

mind:

you know, I got caught up in, not caught up, but I got, they had

mind:

like an internal like phishing attempt. And

mind:

because I was looking at the email on my phone, I

mind:

didn't see that it was obviously a bogus link. And they, you know, when you

mind:

click on it, it says you got caught. Like, was kind of like, it was

mind:

kind of like, oh yeah. So like to this day, like if I ever get

mind:

an urgent thing, I'm like, All right, I am not touching this link with my

mind:

phone. I'm gonna mouse over it with, you know, on my

mind:

computer, which is interesting. I think that is also, I know it sounds

mind:

stupid and it'll probably sound absolutely crazy, but if phones had the ability,

mind:

the phone apps, when you click on a link, you would get some metadata

mind:

about it. I think that would go a long, obviously if you know to look

mind:

for it, right? Like it would go a long way to stop it, right? 'Cause

mind:

like when I did look at the, when I went back to my desktop and,

mind:

you know, looked at the message inside of, browser, I could

mind:

see it was obviously going to, you know, some bogus site.com or something like that.

mind:

But yeah, and the way these are written,

mind:

they give a sense of urgency. So you want to— you can't—

mind:

it almost is like if you wait until it's too late, until you wait until

mind:

you get to your desk, that alone is a flag right now.

mind:

I kind of think about that, you know, fool me once, shame on you. Fool

mind:

me twice, you know, shame on me. But I

mind:

have noticed that some companies will intentionally do these.

mind:

And so I think that's actually a useful exercise right there, right?

mind:

Because it becomes a teachable moment of this was not—

mind:

it's kind of like the broadcast messaging. If this were an actual emergency,

mind:

right? If this were an actual phishing attempt. But

mind:

you're right, and AI is getting better. And most people, when they hear about how

mind:

AI is getting better at these phishing attacks, They think, oh, it's a

mind:

3D-generated real-time voice of somebody or

mind:

avatar of somebody, but it doesn't have to be. If the

mind:

grammar's— if it's written persuasively and the grammar doesn't

mind:

look off, that

mind:

alone could do it. And that's just basic LLM stuff.

mind:

It is. And don't feel like the Lone Ranger. I had to

mind:

take remedial training earlier this year because I clicked on a phishing link myself.

mind:

So, you know. what you said. It's just,

mind:

it's so persuasive, and there is this sense of urgency, and

mind:

then you are multitasking so many things, and then you

mind:

happen to open that email. Yeah, that's— it's funny. And then

mind:

in my current job, there's often the saying of,

mind:

if you get an email and it says so-and-so asked

mind:

for this, call them up. Because

mind:

it's probably bogus. That's the best remedy.

mind:

Yeah. There have been a couple of—

mind:

I haven't failed a test since the one I was at Microsoft,

mind:

at least that I know of. I could have clicked on a not test,

mind:

but I think just admitting that you were caught in that,

mind:

you had to take remedial training. I got caught up in something and I

mind:

think taking away the shame of even smart people get caught up in

mind:

because these things are getting better and they're using AI. Right.

mind:

And they don't have to mimic your voice. Right. It's funny, the other

mind:

day, it was like about a month ago,

mind:

my wife texted me on Signal, which she never does.

mind:

Right. And she wanted to know the password for one of my accounts.

mind:

And I was about to give it to her and I'm like, wait a

mind:

minute now. So I called her up.

mind:

and spoke to her directly. And she goes, why'd you call me to get this?

mind:

And she works in cybersecurity, right? So like, that's her business. I was like, well,

mind:

you reached out to me on the channel you never do, and you asked for

mind:

a password. That immediately made me suspicious enough to call

mind:

you and find out verbally it was you. And at first she was

mind:

annoyed, and then she stopped and she's like, no, you're right.

mind:

And it's not just the enterprise either, right? I mean, this, These phishing scams can

mind:

affect you personally too.

mind:

Yep, yep. In, in my family, we have a code. So

mind:

if somebody calls with an urgent need for help, we first

mind:

have to ask for that code. And this came off a real

mind:

incident that happened last December. I was in Austria for an audit,

mind:

and my son, who is here in Texas, he got a call saying, son,

mind:

I've been in an accident. So he hung up and he called me back.

mind:

He said that, Dad, it was your voice. Wow. Frank, your

mind:

voice, my voice, we are on the web, so it's very easy to emulate that.

mind:

Right. It's that we've given it all the training data and we can't get it

mind:

back. Yeah, yeah, yeah. No, I mean, that's a great idea, the code

mind:

word. It's funny you mentioned that because one of my

mind:

youngest son's daycare, there's this a code word that you have to give

mind:

them for certain transactions or certain kind

mind:

of like changes to the schedule. And I was like, first I was

mind:

like, well, that's unusual. And I'm like, no, that's actually quite brilliant. It is.

mind:

Yeah, yeah. Because I can easily imagine somebody's voice getting

mind:

cloned. And yeah, I mean, it's,

mind:

it's, I would say we live in dangerous

mind:

times, but I think The dangers always evolved, right? We're not worried

mind:

about Vikings raiding our villages anymore, but we do have to

mind:

worry about someone doing some kind of weird crypto scam. Or,

mind:

you know, one time, a long time ago, I

mind:

had my own server in my house that I had exposed to the public internet,

mind:

and I took the password protection off it temporarily, and then I forgot.

mind:

And long story short, within couple of weeks, my

mind:

internet connection ground to a halt and I'm like, what's going on? And I

mind:

did some traffic sniffing and hey, there's a lot of FTP traffic

mind:

and I saw my hard drive was getting full and I'm like, what's going on?

mind:

And it was basically all these PS2 ROM files.

mind:

Basically people were using my open server as a place to pirate

mind:

PlayStation 2 games. This was a while ago. So

mind:

even I got caught up in that, right? Like the whole

mind:

convenience, lack of convenience is a security feature.

mind:

And I was, I was talking to some security people on, on the Impact of

mind:

the Quantum Computing show, Impact Quantum, and he

mind:

said like, if it's convenient, it's not secure. I think that was basically what he

mind:

said. And I was like, he's right. Yeah. Ah,

mind:

I wanted him to be wrong, right? Because we all love the convenience of

mind:

you scan your fingerprint or whatever. And I'm not saying

mind:

that's not secure, but having the knowledge of a PIN, even though

mind:

that's not perfect, as inconvenient as

mind:

it is for it to ask you a PIN every time you want to restore

mind:

a password or show a QR code or give it a random number,

mind:

semi-random number, it's inconvenient. But that inconvenience

mind:

is a mark of security. Very well

mind:

said. Yeah. And then Amplified over the whole organization

mind:

to convince everybody to make sure that this culture is

mind:

required. How do you— that's a good question. So,

mind:

so how do you get people to a culture of security?

mind:

I don't want to say culture of security, but security awareness. Is it training?

mind:

You know, what is it? I

mind:

think training and testing both are very important.

mind:

So having campaigns to train people with the latest

mind:

threats, what are the best practices today, because they

mind:

keep changing. Right. And then making sure that that

mind:

training took place, that training reached the

mind:

recipient. So test them through, like you said, phishing

mind:

campaigns or a variety of other means

mind:

to ensure that we have enough evidence to show that

mind:

100% of the people who have access

mind:

to confidential data are aware and have

mind:

completed the latest training requirements.

mind:

Interesting. It all gets back to people, doesn't it? Or the old

mind:

people, process, and things, right? You know, the fundamentals.

mind:

As much as things change in the day-to-day in technology, it's just the fundamentals always

mind:

come back. You're always going to have people, right? You're always going to

mind:

have processes, and you're always going to have things, whether those things

mind:

are logins or agents doing things

mind:

autonomously. It just seems like there's a lot

mind:

we can learn from the history of it, if that makes sense.

mind:

Yep. Interesting. We're getting close to

mind:

the top of the hour. What would you tell—

mind:

what do you tell customers who are skeptical? Because I'm sure you still

mind:

encounter that. And it's probably different in different industries, right?

mind:

Obviously, if you're in finance or healthcare,

mind:

although that's probably— that probably leads to a type of complacency that's

mind:

dangerous, doesn't it? It is a

mind:

difficult concept for some organizations, right? And

mind:

it's just, it's mind-boggling. I know organizations

mind:

who have had

mind:

scare who have had

mind:

ransomware across their whole network,

mind:

and yet they do not see the point of why they need to

mind:

implement a management system to address information security.

mind:

So even an adverse

mind:

experience in the past is not sufficient to implement it for some

mind:

organizations. Others are proactive, and they want to make sure that

mind:

There's no impact to their reputation. There's no financial

mind:

consequence. There's no legal consequence. So they go ahead and

mind:

implement it. So the culture varies quite a bit.

mind:

Have you noticed any patterns of

mind:

people in this industry tend to be very much on point,

mind:

or is it kind of evenly distributed across that spectrum? Some

mind:

industries are more mature than others. I think that if you look at the

mind:

annual reports from Gartner or

mind:

FBI, sometimes they have these charts depicting different

mind:

sectors and state and local governments always come

mind:

at the bottom of the list. Interesting.

mind:

I guess that's a list no one wants to be on.

mind:

But then you're right, like, I guess some people

mind:

or some organizations never learn, even if after they've had a breach or after they've

mind:

had an incident. Although,

mind:

from what I've seen, and I can't share too much about this, I suspect that

mind:

there are insurance companies that, I guess, offer some kind of protection

mind:

against this. And then part of the remediation, they'll pay out the policy

mind:

and you're like in typical insurance, the fee goes up, but you also

mind:

have to implement certain very specific training and changes to

mind:

company policy in order for you to for them to still

mind:

insure you after an incident. I would imagine that that

mind:

helps. Folks listening can't see the air quotes,

mind:

but I've seen that happen.

mind:

Can't say where, but if you use LinkedIn, you probably figure out—

mind:

LinkedIn and Google, you'll probably figure out who I'm talking about. But

mind:

the— what fascinates me is

mind:

the human element of what makes

mind:

someone proactive voluntarily and what makes

mind:

somebody complacent in spite of the evidence,

mind:

in spite of experience. I mean, that's obviously not a technical question, and

mind:

this is probably something that digital trust alone

mind:

can't— I don't know. It just fascinates me, that human element of what makes

mind:

some people and some organizations

mind:

overly compliant versus what makes them,

mind:

for lack of a better term, complacent in spite of evidence.

mind:

I think whoever figures that one out has the next billion-dollar business, right?

mind:

Totally. Because you could teach people who are

mind:

complacent to a self-destructive degree, you can kind

mind:

of hypnotize them or snap your fingers and they'll be

mind:

closer to Reasonable. You're right. It's a

mind:

complex puzzle. And it's always the people, right? Yes.

mind:

Even in this age of AI, this age of data,

mind:

people still have the agency to be

mind:

stupid or ignorant or willfully— like, there's

mind:

ignorance and then there's willful ignorance, right? Ignorance is, I think you can

mind:

excuse to a certain degree, but willful

mind:

ignorance of, oh, now we had that happen already. It won't happen again.

mind:

Right? Thinking that lightning doesn't strike twice. This isn't

mind:

lightning. That's true. And then, you know, you have to

mind:

get— we have to give grace to people who are working in different areas of

mind:

the organization. Some are more technically oriented and some are not.

mind:

So it's obvious that groups which are

mind:

not more technically oriented, they are not keeping up with the latest threats.

mind:

It takes additional effort for them to go read up on what are the

mind:

best practices today. That's fair. That's fair. But I, and

mind:

I would imagine that the, the

mind:

bad actors know that and they're probably being

mind:

targeted. So it's almost like an ethical, almost an ethical

mind:

responsibility for the organization to take care of them,

mind:

right? Because the, you know, what did they say? The, the slowest antelope

mind:

gets eaten, right? Right. I think it's, I think

mind:

it's ethical for, you know, the, the, the the organizations to

mind:

be mindful that they're going to have some slow antelopes, if you will,

mind:

right? And you have to teach them how to protect

mind:

themselves. That's where leadership or the

mind:

commitment of leadership comes in, not just with information

mind:

security training and developing the information

mind:

security culture within the organization, but also the other question

mind:

that we were addressing a few minutes ago. Why are some industries more

mind:

prone to getting certifications and creating these management

mind:

systems and some others are willfully ignoring it. And that is

mind:

also, if I'm allowed to point fingers here, I would point fingers at

mind:

the leadership again. 100%. Well, I mean, the leadership's—

mind:

leadership in any organization, commercial, private,

mind:

anywhere, combination thereof, their job

mind:

is to lead, right? And if they don't lead,

mind:

things will happen more on their own. Exactly.

mind:

The stars are not going to align that things are going to magically work out.

mind:

It might every few billion years, but it's not going to happen on a regular

mind:

basis. So if you are in leadership, part of

mind:

that is you have to take on the

mind:

responsibility. I've had this

mind:

argument with one of my sons where it's like, well, it's not my fault that

mind:

happened. It's not your fault, but it's your responsibility to make sure that

mind:

doesn't happen. Right? You know, clean up the mess or do this.

mind:

Like, you know, it's not your fault, you're not being blamed, but it's your responsibility.

mind:

And I think, I think a lot of organizations have lost the sight of that

mind:

in their leadership, right?

mind:

Um, one of the things that really changed my mind on

mind:

that was Extreme Ownership, and it was by, I think, Jocko Willink, former

mind:

Navy SEAL guy. And it's an audiobook. So

mind:

Audible is a sponsor of the show. So if you go to thedatadrivenbook.com,

mind:

You'll get routed to Audible. You get one free audiobook on us, and I highly

mind:

recommend that one. It basically mentions, like, you know, that's where

mind:

I might have gotten that line where it's not your fault, but it's your responsibility,

mind:

right? So if you take responsibility for things, even if they're not really your

mind:

fault, you're going to end up in a better place, right? And I think

mind:

organizations have to really take that to heart. They should take it to heart

mind:

on everything. Should, right? But when it comes to IT security and, and,

mind:

and matters like this, they definitely need to, because if they don't, no one

mind:

else is gonna. Yep. All right, I'll

mind:

get off my soapbox now. That was wonderful. I'm thinking

mind:

of finding that audiobook and listening to it, so thank you for pointing me

mind:

to it. Oh, no problem, no problem. It's, it's a really good audiobook. Do you

mind:

have any audiobook recommendations, or— Not in this area.

mind:

Okay. Very dry area, so— Fair enough.

mind:

But there are a lot of good, uh, AI training,

mind:

especially. I was just looking at Claude.ai

mind:

recently, and they have Claude Academy, which is free for people to

mind:

learn how to, how to use AI responsibly

mind:

and ethically. That's a good point. I've heard

mind:

about Claude Academy, but I've not looked at it. So one of these afternoons when

mind:

I have a free calendar hour or 2, I'll definitely take a

mind:

look at it. But where can folks find out more about you and

mind:

what you're up to? Reaching out to DQS is the

mind:

best option. We have a lot of webinars, we have white papers

mind:

on our website, and as,

mind:

as I gather more and more questions, I am available

mind:

for individual conversations as well as group

mind:

conversations during one of the webinars. And that's

mind:

dqsglobal.com. You're right, thank you for saying

mind:

that. Yes, dqsglobal.com. Cool website too.

mind:

And you're right, it's not just about

mind:

information security. It seems like you cover all kinds of different certifications

mind:

and things like that, including 9001, which I remember. And

mind:

yeah, very cool. And now I see how to spell TISAX,

mind:

T-I-S-A-X. That's cool. Oh, and it's

mind:

interesting because I'm looking at the site and like there's a lot of certifications out

mind:

there. And there were things I'd never even heard of.

mind:

Yeah. Just ISO has more than 60,000

mind:

standards published. And then there are others outside of

mind:

ISO. Wow. I'm impressed.

mind:

I'm impressed. So definitely check it out, dqs-global.com.

mind:

And any parting thoughts?

mind:

Thank you very much for having me. I encourage everybody to visit our

mind:

website and Feel free to reach out to me with any and all

mind:

questions. And we'll make sure to put your LinkedIn profile in

mind:

the show notes as well, in case they have any questions directly. And with that,

mind:

we'll let the outro music play.

Links

Chapters

Video

More from YouTube