<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Guardians of the Data]]></title><description><![CDATA[Join host, Ward Balcerzak, each week as he dives deep into the passions, expertise, and experiences of CISOs, Chief Data Officers, and more. Sponsored by Sentra.]]></description><link>https://www.guardiansofthedata.show</link><image><url>https://substackcdn.com/image/fetch/$s_!6c6Z!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82bb6092-bf81-4719-a5b9-8777fc9bb5ca_192x192.png</url><title>Guardians of the Data</title><link>https://www.guardiansofthedata.show</link></image><generator>Substack</generator><lastBuildDate>Fri, 07 Aug 2026 22:38:47 GMT</lastBuildDate><atom:link href="https://www.guardiansofthedata.show/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Guardians of the Data]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[guardiansofthedata@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[guardiansofthedata@substack.com]]></itunes:email><itunes:name><![CDATA[Guardians of the Data]]></itunes:name></itunes:owner><itunes:author><![CDATA[Guardians of the Data]]></itunes:author><googleplay:owner><![CDATA[guardiansofthedata@substack.com]]></googleplay:owner><googleplay:email><![CDATA[guardiansofthedata@substack.com]]></googleplay:email><googleplay:author><![CDATA[Guardians of the Data]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Denial of Wallet - Robert Whetstine - Guardians of the Data - Episode # 54]]></title><description><![CDATA[What happens when your AI gets bored?]]></description><link>https://www.guardiansofthedata.show/p/denial-of-wallet-robert-whetstine</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/denial-of-wallet-robert-whetstine</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 06 Aug 2026 14:00:57 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/4b60c7ba-e03d-49de-92d7-343bfc21d750_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>According to this week&#8217;s guest, it starts making its own decisions, and not always the ones you&#8217;d want.</span></p><p><span>Robert Whetstine, known across the industry as the Bow Tie Security Guy, joins Ward Balcerzak to unpack the wave of risk headed toward every organization running AI in production. From a looming explosion in CVEs to a brand new attack called denial of wallet, Robert makes the case that AI isn&#8217;t replacing the fundamentals of security, it&#8217;s making them non-negotiable.</span></p><p><span>The conversation moves from technical war stories to Robert&#8217;s own path from homelessness to Fortune 500 executive, tying together a career built on embracing discomfort and doing the basics better than anyone else.</span></p><div id="youtube2-0YnzhD6_Fl0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;0YnzhD6_Fl0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/0YnzhD6_Fl0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Takeaways:</p><ul><li><p><span>Shift from a vulnerability management mindset to an exposure risk model. Know your crown jewels, monitor them closely, and be able to answer in minutes whether a new CVE actually touches your environment.</span></p></li><li><p><span>Don&#8217;t let AI agents get bored. Chatbots without real guardrails will drift outside their instructions the longer a conversation runs, so build in controls rather than trusting the model to police itself.</span></p></li><li><p><span>Budget for token costs the way you&#8217;d budget for cloud sprawl. A reckless query or a denial of wallet attack can rack up tens of thousands in charges, so plan for a multiplier, not a flat rate.</span></p></li><li><p><span>Treat an unrestricted AI model like a brilliant but unsupervised junior engineer. Lock down RBAC, log everything through a third party, and never take an AI&#8217;s own explanation of its behavior at face value.</span></p></li><li><p><span>Protect your team from hustle culture before it protects your company from anything else. Burnout erodes judgment fast, and the basics, like tabletop exercises and clear data retention policies, only get done by people who aren&#8217;t running on empty.</span></p></li></ul><blockquote><p>&#8220;If you're not actively preparing for your token cost to have a five X multiplier in the next five years, you're going to be drastically surprised.&#8221; - Robert Whetstine</p></blockquote><p><strong>Connect with Robert:</strong></p><ul><li><p><span>LinkedIn: </span><a href="https://www.linkedin.com/in/bowtiesecurityguy/"><span>https://www.linkedin.com/in/bowtiesecurityguy/</span></a></p></li><li><p><span>Youtube: </span><a href="https://www.youtube.com/@bowtiesecurityguy"><span>https://www.youtube.com/@bowtiesecurityguy</span></a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li><li><p>Amazon Music: <a href="https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data">https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data</a></p></li><li><p>iHeart Radio: <a href="https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/">https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/</a></p></li><li><p>YouTube: <a href="https://www.youtube.com/@GuardiansoftheDataPod">https://www.youtube.com/@GuardiansoftheDataPod</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[The Host Gets Hosted - Ward Balcerzak - Guardians of the Data - Episode # 53]]></title><description><![CDATA[What happens when the interviewer becomes the interviewee?]]></description><link>https://www.guardiansofthedata.show/p/the-host-gets-hosted-ward-balcerzak</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/the-host-gets-hosted-ward-balcerzak</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 30 Jul 2026 14:01:26 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/fdb2f9c4-b930-4fbb-a6e8-9a389672e9a7_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>For Guardians of the Data's one year anniversary, Kraig Faulkner, Field CTO at InfoLock, flips the script and puts host Ward Balcerzak in the hot seat. Ward finally answers the question he has asked every guest all year: what is the biggest challenge organizations face in data security? His answer is blunt. From people, process, and technology to agentic AI oversight and a bold prediction about the future of SOC analyst roles, Ward pulls back the curtain on twenty years building data security programs at organizations like Allstate and Fidelity National Financial.</span></p><div id="youtube2-kVgFtekcNUs" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;kVgFtekcNUs&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/kVgFtekcNUs?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Takeaways:</p><ul><li><p><span>Prioritize, strategize, and focus. Most organizations skip straight to buying a tool without appointing a leader or dedicating real resources, and that shortcut is why data security programs stall before they start.</span></p></li><li><p><span>People and processes come before technology. Ward ranks people first, processes a close second, and technology last, since governance and documentation often matter more than the tool doing the work.</span></p></li><li><p><span>Data security is bigger than DLP. Encryption, tokenization, activity monitoring, and data cataloging all belong under the same strategic umbrella instead of sitting scattered across disconnected teams.</span></p></li><li><p><span>AI did not create new risk, it exposed the risk that was already there. Years of neglecting data at rest and access hygiene are now surfacing the moment a copilot lets employees search everything at once.</span></p></li><li><p><span>Treat agentic AI like any other technology rollout. Give it a full architectural and security review, build in a UAT stage, and do not let it skip the same tollgates every other system has to pass through.</span></p></li></ul><blockquote><p>&#8220;AI didn't introduce new risks. It exposed the risk that we swept under the rug or neglected for years.&#8221; - Ward Balcerzak</p></blockquote><p><strong>Connect with Ward and Kraig:</strong></p><ul><li><p><span>Ward&#8217;s LinkedIn: </span><a href="https://www.linkedin.com/in/ward-balcerzak/"><span>https://www.linkedin.com/in/ward-balcerzak/</span></a></p></li><li><p><span>Kraig&#8217;s LinkedIn: </span><a href="https://www.linkedin.com/in/kraigfaulkner/"><span>https://www.linkedin.com/in/kraigfaulkner/</span></a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li><li><p>Amazon Music: <a href="https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data">https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data</a></p></li><li><p>iHeart Radio: <a href="https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/">https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/</a></p></li><li><p>YouTube: <a href="https://www.youtube.com/@GuardiansoftheDataPod">https://www.youtube.com/@GuardiansoftheDataPod</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Compiled for Your Protection - Guardians of the Data - Episode # 52]]></title><description><![CDATA[What if the biggest threat to your data security program isn't a hacker, but your own classification policy?]]></description><link>https://www.guardiansofthedata.show/p/compiled-for-your-protection-guardians</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/compiled-for-your-protection-guardians</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 23 Jul 2026 14:02:56 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/6ae6ceff-28a0-457e-b7da-aa122de8c20c_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>In this special compilation episode, Ward Balcerzak brings together some of the sharpest voices from across Guardians of the Data, including Tobias Simpson, Hans Vargas, Trevor Dolan, Matthew Gonzales, Joshua Copeland, Luis Valenzuela, Ketan Gotmare, Kevin Feck, and Dr. Sergio, for a rapid fire tour through the ideas that defined the show this season. From the real risk of misclassifying data to the business case every CISO needs to make in the boardroom, this episode strings together the moments that stuck with listeners most, plus a sobering look at how far social engineering has come with deepfakes, and lookalike domains.</span></p><div id="youtube2-RdKSd5393Bs" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;RdKSd5393Bs&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/RdKSd5393Bs?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Takeaways:</p><ul><li><p><span>Misclassifying data is a bigger risk than leaving it unclassified. Several guests point to department level tabletop exercises as the fastest way to find each team&#8217;s actual crown jewels before rolling out a blanket policy.</span></p></li><li><p><span>Treat data classification like a partnership, not an audit. Approach owners with empathy and make it clear you&#8217;re there to help them find what matters, not to punish them for how they&#8217;ve stored it.</span></p></li><li><p><span>A real governance program rests on five pillars: leadership buy-in, an honest maturity assessment, clear policy frameworks, ongoing training, and the right team structure. Fix the most urgent pain points first, then document the rest as a roadmap so the gaps are defensible later.</span></p></li><li><p><span>Boards don&#8217;t respond to cyber risk, they respond to business risk. Translate technical exposure into dollars, downtime, and operational impact, or the conversation stalls before it starts.</span></p></li><li><p><span>Security leaders are caught in a velocity versus control paradox, expected to move as fast as the business while still verifying everything. At the same time, social engineering has caught up with AI, from cloned voices to deepfaked video, making code words and manual verification more essential than ever.</span></p></li></ul><blockquote><p>"Unless you can talk business risk, not cyber risk, and you can talk real dollars and cents to the business, you're gonna fail every single time." &#8211; Joshua Copeland</p></blockquote><p><strong>Connect with the Guest&#8217;s LinkedIns:</strong></p><ul><li><p><a href="https://www.linkedin.com/in/luisvalenzuela28323623/"><span>https://www.linkedin.com/in/luisvalenzuela28323623/</span></a></p></li><li><p><a href="https://www.linkedin.com/in/trevor-dolan-91a1ab12/"><span>https://www.linkedin.com/in/trevor-dolan-91a1ab12/</span></a></p></li><li><p><a href="https://www.linkedin.com/in/hansvargas/"><span>https://www.linkedin.com/in/hansvargas/</span></a></p></li><li><p><a href="https://www.linkedin.com/in/tobias-simpson-mism-706b57a8/"><span>https://www.linkedin.com/in/tobias-simpson-mism-706b57a8/</span></a></p></li><li><p><a href="https://www.linkedin.com/in/matthew-c-gonzales-64012a8/"><span>https://www.linkedin.com/in/matthew-c-gonzales-64012a8/</span></a></p></li><li><p><a href="https://www.linkedin.com/in/joshuacopeland/"><span>https://www.linkedin.com/in/joshuacopeland/</span></a></p></li><li><p><a href="https://www.linkedin.com/in/ketangotmare/"><span>https://www.linkedin.com/in/ketangotmare/</span></a></p></li><li><p><a href="https://www.linkedin.com/in/kevin-feck-756ab91/"><span>https://www.linkedin.com/in/kevin-feck-756ab91/</span></a></p></li><li><p><a href="https://www.linkedin.com/in/dr-sergio-e-sanchez/"><span>https://www.linkedin.com/in/dr-sergio-e-sanchez/</span></a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li><li><p>Amazon Music: <a href="https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data">https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data</a></p></li><li><p>iHeart Radio: <a href="https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/">https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/</a></p></li><li><p>YouTube: <a href="https://www.youtube.com/@GuardiansoftheDataPod">https://www.youtube.com/@GuardiansoftheDataPod</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Stop Chasing Shiny Objects - Dana Kilcrease - Guardians of the Data - Episode #51]]></title><description><![CDATA[If you had to guess where your organization's biggest data risk is hiding, would tech debt make your list?]]></description><link>https://www.guardiansofthedata.show/p/stop-chasing-shiny-objects-dana-kilcrease</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/stop-chasing-shiny-objects-dana-kilcrease</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 16 Jul 2026 14:02:02 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/f0e51ace-0d53-459e-8e0a-7431ed58c880_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>In this episode, Ward Balcerzak sits down with Dana Kilcrease, a nearly two decade cybersecurity veteran and current CISO in higher education, to talk about what actually matters when the pace of technology outstrips the pace of resources. Dana makes the case that velocity, not any single threat, is the real challenge facing security leaders today, and that the answer isn't chasing every shiny new tool. It's nailing the fundamentals, building DSPM and DLP into the foundation, and treating AI governance as a partnership rather than a lockdown. Along the way, he shares how a 95 year old institution turned AI anxiety into stronger cross-functional relationships, and offers some blunt career advice for anyone trying to break into cyber.</span></p><div id="youtube2-z9BzGlXxPy8" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;z9BzGlXxPy8&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/z9BzGlXxPy8?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Takeaways:</p><ul><li><p><span>Resources aren&#8217;t scaling at the same rate as technology or attackers, so leaders have to get comfortable doing more with what they already have.</span></p></li><li><p><span>Don&#8217;t chase every shiny new tool. Go back to first principles, harden your endpoints, lock down your processes, and build a real incident response plan so the blast radius stays small when something does happen.</span></p></li><li><p><span>Start data security with visibility. A DSPM foundation paired with DLP tells you where sensitive data lives, where it&#8217;s overshared, and where policies need to close the gap.</span></p></li><li><p><span>Treat AI governance as a partnership, not a policing effort. Sitting down with academic and administrative leaders to hear their concerns first turned a contentious relationship into a collaborative one.</span></p></li><li><p><span>Certifications don&#8217;t replace experience. Get clear on the niche you actually want, whether that&#8217;s pentesting or research or something else, and build toward that instead of stacking badges for their own sake.</span></p></li></ul><blockquote><p>"Experience trumps everything. If you have the option of taking a certification or getting into the trenches and really learning what this means, get into the trenches by all means and go nuts."- Dana Kilcrease</p></blockquote><p><strong>Connect with Dana:</strong></p><ul><li><p><span>LinkedIn: </span><a href="https://www.linkedin.com/in/danakilcrease/"><span>https://www.linkedin.com/in/danakilcrease/ </span></a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li><li><p>Amazon Music: <a href="https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data">https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data</a></p></li><li><p>iHeart Radio: <a href="https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/">https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/</a></p></li><li><p>YouTube: <a href="https://www.youtube.com/@GuardiansoftheDataPod">https://www.youtube.com/@GuardiansoftheDataPod</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Data Never Sleeps - Andy Soodek - Guardians of the Data - Episode # 50]]></title><description><![CDATA[What if the biggest threat to your data wasn't a hacker, but your own success at collecting it?]]></description><link>https://www.guardiansofthedata.show/p/data-never-sleeps-andy-soodek-guardians</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/data-never-sleeps-andy-soodek-guardians</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 09 Jul 2026 14:03:44 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/7a436a0a-5e16-4c53-8f9b-32caf1ca166f_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>On this episode of Guardians of the Data, host Ward Balcerzak sits down with Andy Soodek, a privacy strategist and data governance expert with over three decades in the industry, to make a case that reframes the whole conversation: data protection was never a project with an end date. Andy breaks down why consent, data sprawl, and now AI are pulling organizations into a governance cycle that never actually closes, and why the companies still treating it like a checklist are the ones falling furthest behind.</span></p><div id="youtube2-pjsqaQNbC5M" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;pjsqaQNbC5M&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/pjsqaQNbC5M?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Takeaways:</p><ul><li><p><strong><span>Treat data governance as a continuous loop, not a project you complete and shelve. </span></strong><span>New data, new tools, and new regulations mean the work never truly ends, so build a governance model that evolves alongside your business instead of expecting a finish line.</span></p></li><li><p><strong><span>Get intentional about consent and transparency before you collect data, not after.</span></strong><span> Once that data gets shared with third parties or reused for new purposes, unclear consent turns into unclear liability down the road.</span></p></li><li><p><strong><span>Simplify your data classification scheme rather than over-engineering it. </span></strong><span>Too many tiers create inconsistent access controls and confuse the people who actually need to use the data, so aim for a system that is easy to train on internally and easy to explain to an auditor.</span></p></li><li><p><strong><span>Audit your data retention practices honestly.</span></strong><span> Most organizations are holding far more data than their own policies allow, and old data sitting around past its useful life adds legal exposure with little upside.</span></p></li><li><p><strong><span>Build AI governance into your existing risk framework instead of treating it as a separate initiative.</span></strong><span> As regulations like California&#8217;s ADMT rules expand, organizations need real explainability and human review built into automated decisions.</span></p></li></ul><blockquote><p>"It's a never-ending governance cycle. You've got to keep up with what you've got going on now, because the next challenge is already on its way." - Andy Soodek</p></blockquote><p><strong>Connect with Andy:</strong></p><ul><li><p><span>LinkedIn: </span><a href="https://www.linkedin.com/in/andysoodek/"><span>https://www.linkedin.com/in/andysoodek/</span></a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li><li><p>Amazon Music: <a href="https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data">https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data</a></p></li><li><p>iHeart Radio: <a href="https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/">https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/</a></p></li><li><p>YouTube: <a href="https://www.youtube.com/@GuardiansoftheDataPod">https://www.youtube.com/@GuardiansoftheDataPod</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Emerging Threats in Data Protection - Anand Thangaraju - Guardians of the Data - Episode # 49]]></title><description><![CDATA[AI has changed the conversation around cybersecurity, but according to Anand Thangaraju, the real challenge has not changed at all: protecting what matters most.]]></description><link>https://www.guardiansofthedata.show/p/emerging-threats-in-data-protection</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/emerging-threats-in-data-protection</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 02 Jul 2026 14:00:14 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/e5ba734b-aa4a-4a98-8dd1-4ea63cb3cb7f_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>In this episode, Ward talks to Anand where he explains why proprietary data has become every organization's most valuable asset and why traditional security approaches are struggling to keep pace. From data lineage and insider risk to agentic remediation and AI driven security operations, he lays out a future where context matters more than tools and where security teams need to understand not just where data lives, but why it moves and who is moving it.</span></p><div id="youtube2-84PSOZIlViY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;84PSOZIlViY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/84PSOZIlViY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Takeaways:</p><ul><li><p><strong><span>Your crown jewels are your proprietary data.</span></strong><span> In an AI driven world where public information is being commoditized by the minute, the only thing that gives your organization a true competitive edge is what it knows that no one else does. If you do not have a strong grip on that proprietary data, you do not have a fighting chance.</span></p></li><li><p><strong><span>Stop waiting for the perfect moment to turn on visibility.</span></strong><span> One of the most common traps CISOs fall into is holding off on DSPM adoption until every compensating control is already in place. Start building now, because the longer you wait for perfection, the more your data sprawl grows into something that is genuinely unmanageable.</span></p></li><li><p><strong><span>Treat data security as a program, not a product. </span></strong><span>No single tool is going to solve your data security problem. The organizations making real progress are the ones pairing the right technology with the right people, clear policies, and a genuine understanding of what bad actors would actually want from their environment.</span></p></li><li><p><strong><span>Build your insider risk and data security programs together. </span></strong><span>These two disciplines share the same foundation: knowing where your sensitive data lives, who is touching it, and whether that behavior is normal. Tackle them in silos and you are leaving the most important use cases on the table.</span></p></li><li><p><strong><span>Before you automate remediation, earn the right to do it.</span></strong><span> A crawl, walk, run approach is not timidity, it is strategy. Start with alert only mode, study your false positive rate, and give your model time to learn the nuances of your business before you hand it the keys to take action.</span></p></li></ul><blockquote><p>"The model should be almost like a trained security architect or security engineer. It should be able to reason for every single action it's taking." - Anand Thangaraju</p></blockquote><p><strong>Connect with Anand:</strong></p><ul><li><p><span>LinkedIn: </span><a href="https://www.linkedin.com/in/athangaraju/"><span>https://www.linkedin.com/in/athangaraju/</span></a></p></li><li><p>Personal Website: <a href="https://www.alchemistcyber.com/">https://www.alchemistcyber.com/</a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li><li><p>Amazon Music: <a href="https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data">https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data</a></p></li><li><p>iHeart Radio: <a href="https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/">https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/</a></p></li><li><p>YouTube: <a href="https://www.youtube.com/@GuardiansoftheDataPod">https://www.youtube.com/@GuardiansoftheDataPod</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Where Is Your Grandmother's Data? - David Smith - Guardians of the Data - Episode #48]]></title><description><![CDATA[Most organizations have spent decades classifying data without ever asking the most important question: what are we actually trying to do with that classification?]]></description><link>https://www.guardiansofthedata.show/p/where-is-your-grandmothers-data-david</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/where-is-your-grandmothers-data-david</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 25 Jun 2026 14:02:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/uy1PKno1LkI" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>In this episode, David Smith, a cybersecurity leader with 30 years of experience across financial services, biopharma, consulting, and the vendor space, reframes the entire data governance conversation around one deceptively simple idea: custodianship.</span></p><p><span>David argues that AI did not create the data governance crisis. Organizations handed it 30 years of ungoverned data and said go. What AI did was pull the covers off a problem that has been quietly compounding through every layer of abstraction since the mainframe days</span></p><div id="youtube2-uy1PKno1LkI" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;uy1PKno1LkI&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/uy1PKno1LkI?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Takeaways:</p><ul><li><p><span>Every new layer of data technology, from data warehouses to cloud to AI, breaks the original rules attached to data. The further data gets from its source, the harder it is to enforce how it should be used or protected.</span></p></li><li><p><span>Good data governance isn&#8217;t about corporate policies and DLP rules. It&#8217;s about custodianship, treating every data set the way you&#8217;d treat something precious that belongs to someone you love, and being intentional about who can access it, how it&#8217;s stored, and what happens if something goes wrong.</span></p></li><li><p><span>AI doesn&#8217;t create data governance problems, it inherits them. When organizations feed decades of ungoverned data into AI systems, they&#8217;re handing enormous power to a tool that has no way to respect rules that were never properly defined in the first place.</span></p></li><li><p><span>Data classification fails most organizations not because the concept is wrong, but because schemas focus too much on what the data is and not enough on what people are allowed to do with it. Traffic Light Protocol is a better model because it defines behavior, not just sensitivity level.</span></p></li><li><p><span>Starting a cybersecurity career at the help desk builds skills no technical training can replicate. Learning to solve problems under pressure with frustrated users and outdated systems directly prepares you for the real-world constraints of enterprise security work.</span></p></li></ul><blockquote><p>"AI inherited rather than creating the data governance problem. Organizations handed it 30 years of ungoverned data and said go." - David Smith</p></blockquote><p><strong>Connect with David:</strong></p><ul><li><p>LinkedIn: <a href="https://www.linkedin.com/in/davidesmithcissp/">https://www.linkedin.com/in/davidesmithcissp/</a></p></li><li><p>Personal Website: <a href="https://desmithsecurity.com/">https://desmithsecurity.com/</a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li><li><p>Amazon Music: <a href="https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data">https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data</a></p></li><li><p>iHeart Radio: <a href="https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/">https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/</a></p></li><li><p>YouTube: <a href="https://www.youtube.com/@GuardiansoftheDataPod">https://www.youtube.com/@GuardiansoftheDataPod</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Governance Never Ends - Zach Lewis - Guardians of the Data - Episode # 47]]></title><description><![CDATA[What happens when a ransomware threat actor claims they have 380 gigabytes of your data and you have no idea what is actually in it?]]></description><link>https://www.guardiansofthedata.show/p/governance-never-ends-zach-lewis</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/governance-never-ends-zach-lewis</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 18 Jun 2026 14:01:12 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/4762ea0c-b355-4546-9ec7-a1007f060eb4_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>That was the reality Zach Lewis faced, and it became the catalyst for one of the most thorough data governance journeys you will hear on this show. In this episode, Ward sits down with Zach Lewis, CIO and CISO in the healthcare and higher education space, author of &#8220;Locked Up,&#8221; and a 15 year veteran of the industry. Zach breaks down how a ransomware incident forced a complete reckoning with data classification, what a real multi year DSPM journey actually looks like from the inside, and why normalizing open conversation about cyber attacks might be the most important thing the security community can do right now.</p><div id="youtube2-Pu2iXRdCWpA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;Pu2iXRdCWpA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/Pu2iXRdCWpA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Takeaways:</p><ul><li><p><strong>Don&#8217;t let a good crisis go to waste.</strong> A ransomware event, while devastating, can unlock budget, leadership attention, and organizational urgency that would have taken years to build otherwise. The smartest move after an incident is to channel that momentum into the data governance work you already knew needed to happen.</p></li><li><p><strong>Data classification is not a policy problem, it is an execution problem.</strong> Having a policy on paper means nothing if the data isn&#8217;t actually tagged, governed, and tied to access controls. The real work starts when you move from defining classifications to enforcing them at scale, and that is where tooling and AI become non negotiable.</p></li><li><p><strong>Data governance is a forever journey, not a project. </strong>Even after years of work, Zach&#8217;s team is still tackling retention, deduplication, and classification accuracy. The goal is not perfection on day one but consistent progress, eating the elephant one bite at a time.</p></li><li><p><strong>Legal is your secret weapon.</strong> General counsel carries a kind of organizational gravity that IT rarely does. When you can align data hygiene and retention efforts with legal risk, people listen and things actually get deleted.</p></li><li><p><strong>AI is shifting the math on what is even possible. </strong>Tasks that would have required a team of analysts reviewing files around the clock can now be handled automatically and accurately. Leaders who lean into AI for data security today are building the foundation that makes everything else, from Copilot adoption to regulatory compliance, far less terrifying tomorrow.</p></li></ul><blockquote><p>"A data governance journey never ends. It's a forever journey. Much like zero trust, the heavy lifting gets done and then it's about setting the right processes in place." - Zach Lewis</p></blockquote><p><strong>Connect with Jason:</strong></p><ul><li><p>LinkedIn: <a href="https://www.linkedin.com/in/zacharylewis1/">https://www.linkedin.com/in/zacharylewis1/</a></p></li><li><p>Book Link: <a href="https://homesteadingciso.com/getlockedup/">https://homesteadingciso.com/getlockedup/ </a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li><li><p>Amazon Music: <a href="https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data">https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data</a></p></li><li><p>iHeart Radio: <a href="https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/">https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/</a></p></li><li><p>YouTube: <a href="https://www.youtube.com/@GuardiansoftheDataPod">https://www.youtube.com/@GuardiansoftheDataPod</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Securing the Future - Jason Torres - Guardians of the Data - Episode # 46]]></title><description><![CDATA[What would happen if someone asked your team right now who has access to your most sensitive data and why?]]></description><link>https://www.guardiansofthedata.show/p/securing-the-future-jason-torres</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/securing-the-future-jason-torres</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 11 Jun 2026 14:02:18 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/b01390f8-703d-4de9-b068-d680e95c429c_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this episode, Jason Torres draws on over 20 years of experience in healthcare cybersecurity to make the case that data security still comes down to two fundamentals that most organizations haven&#8217;t cracked, knowing where your data lives, and knowing who is attached to it.</p><p>Jason breaks down why regulated industries like healthcare face a uniquely relentless challenge where data creation never stops, clinical staff have little patience for security friction, and the stakes of getting it wrong are measured in patient trust and breach costs. He also shares why AI governance committees are the non negotiable first step before any organization touches AI tools.</p><div id="youtube2-3ZkLtZTmggA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;3ZkLtZTmggA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/3ZkLtZTmggA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Takeaways:</p><ul><li><p><strong>Start with the basics, know where your data lives.</strong> Before any tooling, framework, or governance program can take hold, organizations need to first identify, locate, and classify their data. It sounds simple, but most companies still can&#8217;t confidently answer that question, and everything else depends on it.</p></li><li><p><strong>Access and ownership are two different problems.</strong> Knowing who <em>should</em> have access to data is not the same as knowing who <em>does</em>. Closing that gap requires ongoing partnership between security teams and business stakeholders, not just a one time audit.</p></li><li><p><strong>AI governance must come before AI adoption.</strong> Throwing AI tools at the business without establishing governance frameworks, leadership buyin, and usage policies is, in Jason&#8217;s words, &#8220;the Wild Wild West.&#8221; Forming an AI governance committee to define expectations and outcomes is the essential first step.</p></li><li><p><strong>The business case for security tools has fundamentally changed.</strong> Where organizations once needed dedicated headcount to implement and run new solutions, AI-driven automation is shifting that model, enabling teams to repurpose existing talent rather than request new hires, and to justify investments with clearer, metrics backed ROI.</p></li><li><p><strong>Diverse backgrounds build stronger security teams.</strong> Some of the most effective security professionals didn&#8217;t come up through traditional IT paths. Bringing in people with backgrounds in finance, communications, or even ministry, as Jason did, creates the range of perspectives and communication styles that make security teams more resilient and well rounded.</p></li></ul><blockquote><p>&#8220;Every journey begins with the first step. There's no blueprint for becoming a security leader. It all depends on the time you put in, the knowledge you develop, the action you put forth &#8212; and ultimately the relationships you build along the way." - Jason Torres</p></blockquote><p><strong>Connect with Jason:</strong></p><ul><li><p>LinkedIn: <a href="https://www.linkedin.com/in/jasontorres/">https://www.linkedin.com/in/jasontorres/</a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Where Are Your Crown Jewels? - Tony Schimizzi - Guardians of the Data - Episode #45]]></title><description><![CDATA[What if someone asked you right now where your most sensitive data lives?]]></description><link>https://www.guardiansofthedata.show/p/where-are-your-crown-jewels-tony</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/where-are-your-crown-jewels-tony</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 04 Jun 2026 14:02:06 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/5949c4d2-f789-475d-ab1b-70b7dc204b9a_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this episode, Tony Schimizzi draws on years of consulting experience to make a point that cuts to the core of modern data security: this is no longer just a cybersecurity problem. It has become a large-scale business operations and governance challenge.</p><p>Tony breaks down why data sprawl across SaaS products, cloud apps, and collaboration tools has made it nearly impossible for most companies to know where their data is, let alone where the crown jewels are and how well they are protected.</p><div id="youtube2-e_oCJruUfN8" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;e_oCJruUfN8&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/e_oCJruUfN8?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Takeaways:</p><ul><li><p><strong>Do the Fundamentals First:</strong> Asset management, visibility, access control, data classification. These have not changed, and they will not. Most breaches happen because the basics were not in place.</p></li><li><p><strong>Security Is a Double Negative:</strong> IT can point to uptime as value. Security cannot point to revenue. Understanding that dynamic and learning to communicate in KPIs and measurable outcomes is how security teams earn their seat at the table.</p></li><li><p><strong>Say Yes, And:</strong> The most effective security professionals are not the ones saying no. They find the compensating control that lets the business move forward safely. Never no, but. Always yes, and.</p></li><li><p><strong>Build a Risk Council:</strong> Instead of having security engineers fight business decisions above their pay grade, bring the right leaders together: CISO, IT, HR, marketing, legal. Let them hash it out. Decisions made there carry weight decisions made at the engineer level never will.</p></li><li><p><strong>If It Matters, It Should Be Measurable:</strong> KPIs taken to the board quarterly, along with examples of incidents that did not escalate because controls were in place, are how security teams demonstrate value without a direct revenue line.</p></li><li><p><strong>Understand How the Business Makes Money:</strong> Before you can evaluate risk, you need to know what the business actually runs on. If your initiative would slow down the revenue engine, you need to know that going in.</p></li></ul><p><strong>Take Risks When You Are Young:</strong> Professionally and personally, the window to experiment, grind, and separate yourself is in your 20s. It is easier to course correct early than to try to change direction later.</p><blockquote><p>"Companies no longer fully understand or control identity, access, and the data movement across their environments." Tony Schimizzi</p></blockquote><p><strong>Connect with Tony:</strong></p><ul><li><p>LinkedIn: <a href="https://www.linkedin.com/in/anthony-schimizzi-cissp-ccsp-cism-issap-045b7a82/">https://www.linkedin.com/in/anthony-schimizzi-cissp-ccsp-cism-issap-045b7a82/ </a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Classify First, Secure Everything Else - Cory Zaner - Guardians of the Data ]]></title><description><![CDATA[What's your biggest data security blind spot?]]></description><link>https://www.guardiansofthedata.show/p/classify-first-secure-everything</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/classify-first-secure-everything</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 28 May 2026 14:02:55 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/8f1841cf-d9c9-4441-9609-ac19754b49d5_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Today&#8217;s guest, Cory Zaner, Senior Enterprise Architect for critical infrastructure and trusted advisor to executive leaders, joins Ward to discuss why organizations continue to struggle with data security fundamentals, and what it actually takes to fix them.</p><p>With over 20 years of experience across energy, manufacturing, and defense industries, Cory draws on his military background, time at Raytheon, and hands-on work in OT/ICS environments to break down the data security challenges most organizations are still getting wrong.</p><div id="youtube2-L6zbJ0DLy0M" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;L6zbJ0DLy0M&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/L6zbJ0DLy0M?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Takeaways:</p><ul><li><p><strong>Start with Data Classification, Not Tools:</strong> Before reaching for the latest shiny object, organizations need to define their data tiers. Cory recommends aligning to an established framework like NIST, then mapping your tiers to a simple color-coded system,red, yellow, green, so users can actually act on it.</p></li><li><p><strong>Keep It Simple:</strong> Over-complicated classification schemes with 10&#8211;20 tags and sub-tags are a recipe for failure. If your users need a secret decoder ring to understand how to classify data, the program has already failed.</p></li><li><p><strong>The Data Owner Classifies the Data:</strong> Not IT. Not the tool. The person who knows what the data is worth is the one who should be tagging it. Technology can assist, but it can&#8217;t make that judgment call for you.</p></li><li><p><strong>Align to a Framework, Then Scope It:</strong> Whether it&#8217;s NIST, ISO, or another standard, anchoring your program to an established framework takes the argument off the security team&#8217;s plate. You&#8217;re not asking people to trust your ideas; you&#8217;re pointing to an industry consensus.</p></li><li><p><strong>Start with Unstructured Data First:</strong> Cory recommends beginning with your M365 or G Suite environment, where user-generated content lives, before tackling structured data like SQL databases. That&#8217;s where the real user behavior risk is.</p></li><li><p><strong>Build the Right Committee:</strong> Data classification can&#8217;t live in a security silo. Legal, privacy, and HR are essential early partners. Build a governance committee with real ownership, not just initial enthusiasm that fades after the first few meetings.</p></li></ul><blockquote><p>"Garbage in, garbage out. AI can make things prettier, but we cannot change the mindset of people with technology.&#8221; - Cory Zaner</p></blockquote><p><strong>Connect with Cory:</strong></p><ul><li><p>LinkedIn: <a href="https://www.linkedin.com/in/cory-zaner/">https://www.linkedin.com/in/cory-zaner/</a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Navigating the Data Maze - Brian Cherry - Guardians of the Data - Episode # 43]]></title><description><![CDATA[What data do you have, where does it live, and who has access to it?]]></description><link>https://www.guardiansofthedata.show/p/navigating-the-data-maze-brian-cherry</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/navigating-the-data-maze-brian-cherry</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 21 May 2026 14:01:43 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/7ba0cb1d-f9a3-4152-9aa8-b50db4a9840f_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>These three questions sit at the heart of every data security challenge and according to Brian Cherry, most organizations still can&#8217;t answer them.</p><p>In this episode, Brian, a Global Director of Information Security with over 20 years in cybersecurity, joins Ward to dig into the sprawling reality of data security: why data never stays where you think it does, how shadow IT and bad governance quietly create massive exposure, and why AI is raising the stakes on all of it.</p><p>Brian also shares how curiosity, mentorship, and asking the right questions shaped his entire career and why those same instincts are the most powerful tools any security professional can have.</p><div id="youtube2-obU9CD6udI8" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;obU9CD6udI8&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/obU9CD6udI8?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Takeaways:</p><ul><li><p><strong>Know your data before you protect it.</strong> You can&#8217;t secure what you can&#8217;t find. Start by asking four foundational questions: What data needs protection? Where does it live? Have you truly looked everywhere? And who has access and how did they get it? These questions sound simple, but most organizations haven&#8217;t fully answered any of them.</p></li><li><p><strong>Act like an investigative journalist when talking to the business.</strong> Going into stakeholder conversations without pretending to have all the answers actually gets you further. When people feel like they&#8217;re teaching you, they open up and that&#8217;s when you learn where the real data risks are hiding.</p></li><li><p><strong>Governance isn&#8217;t sexy, but it&#8217;s where the real power is.</strong> Red team exercises find problems, but governance is what actually prevents them. Policies, controls, and proper data classification programs are what keep businesses from accidentally creating their own worst security incidents.</p></li><li><p><strong>AI is amplifying your existing data problems, not creating new ones.</strong> If sensitive data is scattered in shared directories, staging environments, or forgotten backups, any AI tool with access to it becomes a liability. Getting AI-ready means solving the fundamentals first classification, access control, and visibility.</p></li><li><p><strong>Find a mentor, and be one.</strong> A mentor who pushes you to understand the business side of security, not just the technical side, can completely change your trajectory. And when you&#8217;ve made it, look back. The best investment you can make in the profession is helping someone else ask the next question.</p></li></ul><blockquote><p>"If you don't ask questions, you're never going to know the answer. That's where my career started, and it's still the most powerful tool I have." - Brian Cherry</p></blockquote><p><strong>Connect with Brian:</strong></p><ul><li><p>LinkedIn: <a href="https://www.linkedin.com/in/cherrybrian/">https://www.linkedin.com/in/cherrybrian/</a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Fighting AI Risk with AI - Kevin Feck - Guardians of the Data - Ep #42]]></title><description><![CDATA[What would happen if your AI searched all your data right now?]]></description><link>https://www.guardiansofthedata.show/p/fighting-ai-risk-with-ai-kevin-feck</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/fighting-ai-risk-with-ai-kevin-feck</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 14 May 2026 14:04:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/b174b0c8-1541-492c-a44f-2b8539c3977f_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Today&#8217;s guest, Kevin Feck, Director of Data Protection and Security Architect, joins Ward to unpack how AI is reshaping the data security landscape.</p><p>With over two decades in cybersecurity, Kevin shares why the industry&#8217;s long-standing challenges of data classification, access control, and visibility have suddenly become urgent in the age of AI. From the risks of copilots and LLMs to the reality of &#8220;AI readiness,&#8221; this conversation dives into what organizations are getting wrong and how to fix it.</p><p>Kevin also breaks down why trying to &#8220;boil the ocean&#8221; with data security initiatives often fails, how to scope efforts effectively, and why security teams must evolve from perceived roadblocks to true business enablers.</p><div id="youtube2-AWU1a3MBNjM" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;AWU1a3MBNjM&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/AWU1a3MBNjM?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Takeaways:</p><ul><li><p><strong>Classify Your Data Before Connecting AI to It:</strong> AI tools like Copilot can instantly surface sensitive data that used to take weeks to find manually. Granular, contextual data classification is the foundation.</p></li><li><p><strong>Correlate Sensitive Data With Permissions:</strong> Knowing where your sensitive data lives isn&#8217;t enough. Lock it down to authorized users so AI agents can only access what they should.</p></li><li><p><strong>Fight AI with AI:</strong> Regex based DLP tools are no longer sufficient. Invest in AI powered data security that can understand context, not just patterns.</p></li><li><p><strong>Build an AI Governance Program:</strong> Get lawyers, procurement, security, and technical staff aligned on what &#8220;AI&#8221; actually means in each vendor contract. Not all &#8220;AI&#8221; is equal.</p></li><li><p><strong>Treat User Education as a Core Security Control:</strong> No tool is 100% effective without trained users. Ongoing security awareness training is essential to make data classification stick culturally.</p></li><li><p><strong>Prioritize &#8220;Better Together&#8221; over a single pane of glass fantasy:</strong> No one tool covers every environment perfectly. Integrated tooling with shared intelligence is more effective than waiting for a perfect unified solution.</p></li><li><p><strong>Hire For Passion, Not Just Credentials:</strong> In a field evolving daily, someone deeply motivated to do the right thing will outperform a technically skilled person who is just checking boxes.</p></li></ul><blockquote><p>&#8220;It&#8217;s always been about the data. Tell me what that data is and I&#8217;ll tell you how much I have to care about it.&#8221; - Kevin Feck</p></blockquote><p><strong>Connect with Kevin:</strong></p><ul><li><p>LinkedIn: <a href="https://www.linkedin.com/in/kevin-feck-756ab91/">https://www.linkedin.com/in/kevin-feck-756ab91/</a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[AI Governance: Navigating the Speed of Change - Sweeney Williams - Guardians of the Data - Ep #41]]></title><description><![CDATA[How can organizations govern AI responsibly when the technology (and the risks) are evolving faster than ever?]]></description><link>https://www.guardiansofthedata.show/p/ai-governance-navigating-the-speed</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/ai-governance-navigating-the-speed</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 07 May 2026 14:02:17 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/3a898f6d-aec9-4287-b6ab-d5bdce3dadbe_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this episode of Guardians of the Data, Ward sits down with Sweeney Williams, Head of Responsible AI, to unpack the biggest challenge facing data security today &#8230; speed.</p><p>With over 20 years of experience spanning cybersecurity, privacy, and AI governance, Sweeney shares how the rapid acceleration of AI is reshaping everything from geopolitical competition to regulatory approaches and security threats. What once felt like a manageable evolution now demands constant adaptation, forcing organizations to rethink how they govern, secure, and deploy AI in real time.</p><p>The conversation explores why traditional approaches to regulation and risk management are struggling to keep up, how bad actors are leveraging AI to scale attacks, and why organizations can&#8217;t afford to wait for clarity before taking action. Sweeney also outlines practical steps for building a strong AI governance foundation, emphasizing the importance of fundamentals like data governance, transparency, and cross functional collaboration.</p><div id="youtube2-khS1JXU44lg" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;khS1JXU44lg&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/khS1JXU44lg?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Takeaways:</p><ul><li><p>Speed is the Defining Challenge of AI. AI isn&#8217;t just evolving quickly. It&#8217;s forcing rapid change across regulation, geopolitics, and security. Organizations are struggling to keep pace with constant shifts in capabilities and expectations.</p></li><li><p>Regulation is Lagging and May Stay That Way. Global attitudes toward AI regulation have shifted dramatically, with many regions prioritizing innovation and competitiveness over strict governance.</p></li><li><p>AI is Amplifying Security Risks. Bad actors are using AI to launch more sophisticated and scalable attacks, lowering the barrier to entry and increasing the pressure on security teams.</p></li><li><p>Fundamentals Still Matter! Strong data governance, transparency, access controls, and bias mitigation remain essential, even as the technology evolves.</p></li><li><p>You Can&#8217;t Wait for Clarity! Organizations that delay action until regulations stabilize risk falling behind. The best time to build AI governance is now.</p></li><li><p>Third party AI Risk is a Growing Blind Spot. Vendors are rapidly embedding AI into their products, often without clear visibility, making third party risk management more complex than ever.</p></li></ul><blockquote><p>&#8220;The best time to plant your AI governance tree&#8230; is right now.&#8221; - Sweeney Williams</p></blockquote><p><strong>Connect with Sweeney:</strong></p><ul><li><p>LinkedIn: <a href="https://www.linkedin.com/in/sweeney-williams-00762564/">https://www.linkedin.com/in/sweeney-williams-00762564/</a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[AI Is a Tsunami: Why Teams Are Playing Catch-Up - Ben Rothke - Guardians of the Data - Episode #40]]></title><description><![CDATA[Are security teams already behind on AI? And what does it take to catch up?]]></description><link>https://www.guardiansofthedata.show/p/ai-is-a-tsunami-why-teams-are-playing</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/ai-is-a-tsunami-why-teams-are-playing</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 30 Apr 2026 14:02:39 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/f98d64bc-c816-4294-90d1-d54520676b28_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this episode of Guardians of the Data, Ben Rothke joins the show to break down the biggest data security challenges facing organizations today and why many of them are harder to solve than ever before.</p><p>With over 30 years in cybersecurity, Ben shares a grounded perspective on how the landscape has evolved from simpler perimeter-based models to today&#8217;s world of data sprawl, AI-driven threats, and overwhelming complexity. He explains why AI isn&#8217;t just another trend, but a &#8220;tsunami&#8221; that&#8217;s fundamentally changing how both attackers and defenders operate.</p><p>The conversation dives into why so many organizations are playing catch-up, how shadow IT and poor foundations create long-term risk, and why the most dangerous security problems can&#8217;t be solved with a single tool or quick fix. Ben also offers practical guidance on how teams can approach AI more responsibly, starting with clear use cases, strong guardrails, and embedding security from the very beginning.</p><div id="youtube2-9hm7jti21MA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;9hm7jti21MA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/9hm7jti21MA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Takeaways:</p><ul><li><p>Get Security Involved From the Start: Before deploying any new technology, especially AI, loop in information security from day one. Don&#8217;t retrofit security after the fact; it&#8217;s far more costly and risky.</p></li><li><p>Define Your Use Case Before Buying Tools: Ask &#8220;What is my problem, and how will this tool solve it?&#8221; Don&#8217;t buy enterprise AI or security tools because they&#8217;re on the Gartner Hype Cycle. Start with a clearly defined use case.</p></li><li><p>Create AI Policies and Guardrails Now: If your organization hasn&#8217;t done it yet, immediately establish policies and processes governing how AI tools can be used: what data can be entered, by whom, and under what conditions.</p></li><li><p>Document Before You Deploy: Create detailed design documents for any AI or IT system before rollout, covering use cases, security controls, privacy controls, and support plans. Undocumented &#8220;shadow IT&#8221; becomes tomorrow&#8217;s critical vulnerability.</p></li><li><p>Address Data Sprawl Proactively: Inventory where your data lives across servers, cloud, mobile, and third-party vendors. You can&#8217;t protect what you don&#8217;t know you have.</p></li><li><p>Take Third-Party Supply Chain Risk Seriously: Even a single weak vendor can expose massive amounts of data. Vet your software supply chain rigorously.</p></li></ul><blockquote><p>&#8220;In the last year and change, the challenge of AI has just been a tsunami.&#8221; - Ben Rothke</p></blockquote><p><strong>Connect with Ben:</strong></p><ul><li><p>Links:</p><ul><li><p>LinkedIn: <a href="https://www.linkedin.com/in/benrothke/">https://www.linkedin.com/in/benrothke/</a></p></li></ul></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[The Unstructured Data Problem Not Yet Solved - Brent Bigelow - Guardians of the Data - Episode #39]]></title><description><![CDATA[How much of your company&#8217;s data is completely unknown? And what risk is it creating?]]></description><link>https://www.guardiansofthedata.show/p/the-unstructured-data-problem-not</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/the-unstructured-data-problem-not</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 23 Apr 2026 14:03:26 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/0586cb8f-e42e-4a12-9e15-a6e5602c39c0_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this episode, Ward sits down with Brent Bigelow: security consultant, President of the Charlotte ISSA, and a cybersecurity veteran with nearly four decades of experience. They unpack one of the most persistent and overlooked challenges in data security: unstructured data.</p><p>Brent shares why unstructured data remains the &#8220;wild west&#8221; of security, how it quietly grows through everyday business operations, and why most organizations still struggle to get their arms around it, especially in the context of mergers and acquisitions.</p><p>The conversation explores how &#8220;shadow business&#8221; contributes to data sprawl, why traditional approaches like classification and DLP fall short, and how the rise of AI is accelerating both the risk and complexity of managing unknown data. Brent also reflects on his career journey from the pre-internet era to today&#8217;s AI-driven landscape, offering hard-earned lessons on sustainability, leadership, and staying curious in a rapidly evolving field.</p><div id="youtube2-XM8QnJAEl-U" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;XM8QnJAEl-U&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/XM8QnJAEl-U?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong>Takeaways:</strong></p><ul><li><p>Audit Your Unstructured Data: You can&#8217;t protect what you don&#8217;t know you have. Dedicate a formal project to discovering, cataloging, and classifying unstructured data across your organization, especially after mergers and acquisitions.</p></li><li><p>Establish and Enforce a Data Governance Policy: Policy is the &#8220;stake in the sand.&#8221; Define where data should live, in what formats, and who owns it. Without written policy, you have nothing to point to when a breach or compliance issue surfaces.</p></li><li><p>Watch Out For &#8220;Shadow Business,&#8221; Not Just Shadow IT: Business units are storing data in unauthorized places just as often as rogue IT does. Extend your data governance conversations beyond IT to include business unit leaders.</p></li><li><p>Control Privilege and Access as People Leave: When employees move on, they often take data access, or even the data itself, with them. Enforce least-privilege and revoke access promptly at offboarding.</p></li><li><p>Treat AI Ingestion of Unstructured Data as a Risk: If your organization is deploying Copilot, generative AI, or any LLM that touches internal data, understand what unstructured data it&#8217;s consuming. Garbage in, garbage out, and the &#8220;garbage&#8221; could be sensitive or regulated data.</p></li><li><p>Don&#8217;t Let Duplicate Data Pollute Your AI Models: Version control and de-duplication matter more now than ever. Unmanaged duplicates degrade AI output quality and can introduce conflicting or outdated information into critical workflows.</p></li><li><p>Know Your Data Classification Framework and Actually Use It: Internal use, confidential, public. Make sure employees understand how to label data and where each classification belongs.</p></li></ul><blockquote><p>&#8220;Unstructured data is no different than the ocean: it just keeps rising.&#8221; - Brent Bigelow</p></blockquote><p><strong>Connect with Brent:</strong></p><ul><li><p>Links:</p><ul><li><p>LinkedIn: <a href="https://www.linkedin.com/in/brent-bigelow-02b7791/">https://www.linkedin.com/in/brent-bigelow-02b7791/</a></p></li><li><p>Website:  <a href="https://www.charlotteissa.org/">https://www.charlotteissa.org/</a></p></li></ul></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Using AI to Solve the Data Visibility Problem - Andrew Wilder - Guardians of the Data - Episode #38]]></title><description><![CDATA[What if your DLP tool is slowing your business down instead of protecting it?]]></description><link>https://www.guardiansofthedata.show/p/using-ai-to-solve-the-data-visibility</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/using-ai-to-solve-the-data-visibility</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 16 Apr 2026 14:00:55 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/9c944607-4752-4079-981c-e60f8011ad7c_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this episode, Andrew Wilder shares why traditional data loss prevention (DLP) programs have struggled to deliver real value, and what needs to change in an AI-driven world. Drawing from decades of experience leading security programs at global organizations, he breaks down the core challenge most teams still face: relying on humans to classify and manage massive volumes of data simply doesn&#8217;t scale.</p><p>The conversation explores how AI is reshaping data security, from automatically identifying sensitive data to reducing false positives and improving visibility across the organization. Andrew also explains why security should act as an enabler, not a blocker, and how CISOs can prioritize the right investments while balancing risk and business needs.</p><p>If you&#8217;re rethinking your approach to data security, AI, or DLP, this episode offers a practical look at what&#8217;s working, what isn&#8217;t, and where the future is headed.</p><div id="youtube2-dJpjvpgmvFQ" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;dJpjvpgmvFQ&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/dJpjvpgmvFQ?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong>Takeaways:</strong></p><ul><li><p>Stop Relying on Humans to Classify Your Data: Manual data classification fails at scale. Invest in AI-powered DSPM tools that automatically crawl, catalog, and classify sensitive data across your environment.</p></li><li><p>Use Just-In-Time Popups to Change User Behavior: Real-time prompts asking users to justify unusual data movement are more effective than blocking controls. They create accountability, generate valuable intel, and shift culture without requiring a large team to chase false positives.</p></li><li><p>Think of Security as an Enabler, Not a Blocker: Present risks with options and let the business decide their risk appetite. Your job is to inform, not to dictate. Frame security like brakes on a Formula 1 car: they let you go faster safely.</p></li><li><p>Look at AI From Three Angles: How is the business using it (and how do you secure that)? How are attackers using it? How can your security team use AI agents to do more with finite resources?</p></li><li><p>Build a Team of &#8220;Bot Masters&#8221;: Use AI agents to automate repetitive tasks (SOC L1 triage, GRC forms, legacy account cleanup, third-party risk). Free your human talent for higher-value, strategic work.</p></li><li><p>Reassess Your Security Posture At Least Every 90 Days: The risk landscape changes fast (new AI models, zero-days, etc.). Your 3-year roadmap should be a living document, not a static plan.</p></li></ul><blockquote><p>&#8220;Your job as a CISO is to be kind of a ruthless prioritizer.&#8221; - Andrew Wilder</p></blockquote><p><strong>Connect with Andrew:</strong></p><ul><li><p>LinkedIn: <a href="https://www.linkedin.com/in/apwilder/">https://www.linkedin.com/in/apwilder/</a></p></li><li><p>Website: <a href="https://cybersecurityintheboardroom.com/">https://cybersecurityintheboardroom.com/</a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Solving Velocity vs. Control in the AI Era - Ketan Gotmare - Guardians of the Data - Episode #37]]></title><description><![CDATA[How do you protect sensitive data without becoming the bottleneck in a business that&#8217;s moving faster than ever?]]></description><link>https://www.guardiansofthedata.show/p/solving-velocity-vs-control-in-the</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/solving-velocity-vs-control-in-the</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 09 Apr 2026 14:02:45 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/e0678182-b0dd-4eca-8193-a6bf1960fb2f_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Today, Ketan Gotmare shares how nearly two decades in cybersecurity have shaped his perspective on modern data protection and why today&#8217;s biggest challenge isn&#8217;t a lack of tools, but a fundamental imbalance between speed and control.</p><p>He introduces the concept of the &#8220;velocity versus control paradox,&#8221; where businesses are under constant pressure to move faster, adopt AI, and drive digital innovation while security teams are still expected to verify, govern, and reduce risk without slowing anything down. Ketan walks through the evolution of data security, from the &#8220;castle and moat&#8221; era to today&#8217;s borderless, cloud-first world, explaining why traditional approaches no longer work and what organizations must do instead. He emphasizes that security teams can no longer act as gatekeepers, and must shift toward enabling the business while still protecting sensitive data. The conversation dives into practical ways to get started, including how to define what sensitive data actually is, where it lives across structured and unstructured environments, and why most organizations struggle before they even begin implementing frameworks like zero trust.</p><div id="youtube2-I7WaOlI0AkQ" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;I7WaOlI0AkQ&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/I7WaOlI0AkQ?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong>Takeaways:</strong></p><ul><li><p>Embrace the &#8220;Velocity vs. Control&#8221; Mindset: Security teams must stop being blockers. Find the balance between enabling business innovation and maintaining data protection.</p></li><li><p>Apply Zero Trust as a Concept, Not a Product: Don&#8217;t buy into &#8220;zero trust&#8221; tools blindly. Start small and identify your most sensitive/high-value data, layer controls around those assets, and expand from there. Never trust, always verify.</p></li><li><p>Know What Your Sensitive Data Is Before Worrying About Where It Is: Partner with Privacy, Legal, and Compliance early. Ask: &#8220;If this data got out, would it cost us money or damage our brand?&#8221; That&#8217;s your sensitive data. Define it in a formal standard before scanning anything.</p></li><li><p>Don&#8217;t Try to Boil the Ocean, Start with the Obvious: Prioritize structured/business-system data first. Then tackle unstructured user-generated data. Leave shadow data for the crawl/walk/run phase.</p></li><li><p>Don&#8217;t Do It Alone: Build strategic partnerships with data teams, privacy, legal, risk, and compliance. Data governance and data security have the same goals. Leverage that alignment.</p></li><li><p>Think Data Lifecycle (DSPM), Not Just Classification + DLP: Track data from creation to retirement. Understand how data flows across your network, to SaaS platforms, and to third parties. Data lineage is the foundation of mature data security posture management.</p></li></ul><blockquote><p>&#8220;You cannot block the business.&#8221; - Ketan Gotmare</p></blockquote><p><strong>Connect with Ketan:</strong></p><ul><li><p>LinkedIn: <a href="https://www.linkedin.com/in/ketangotmare/">https://www.linkedin.com/in/ketangotmare/</a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Speaking Business: How Modern Guardians Translate Tech Talk - Guardians of the Data - Episode # 36]]></title><description><![CDATA[How can the super technical cybersecurity leaders communicate risk and protection to other business leaders?]]></description><link>https://www.guardiansofthedata.show/p/speaking-business-how-modern-guardians</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/speaking-business-how-modern-guardians</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 02 Apr 2026 14:01:39 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/63663ccd-fdf9-42df-b756-1f97dac99b2c_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Today, we unpack a huge topic: how to &#8220;speak business&#8221; when you&#8217;re a technology leader. We take a look back at recent episodes to hear from real cybersecurity experts on how they convey risk and security concerns to people who don&#8217;t have the technical expertise.</p><p>This episode brings together insights from industry leaders on how to shift from being the &#8220;department of no&#8221; to becoming a trusted business partner by understanding business priorities, communicating risk in meaningful terms, and building strong cross-functional relationships.</p><p>Featuring: Antonio Taylor, Joshua Copeland, Rick Doten, Jennifer Fite, Mark Alvardo, Frank DePaola, and Sanjeev Kumar.</p><div id="youtube2-uBe-TyrxKnI" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;uBe-TyrxKnI&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/uBe-TyrxKnI?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong>Takeaways:</strong></p><ul><li><p>Stop Being the &#8220;Department of No&#8221;: Instead of defaulting to blocking requests, find the safe and right way to enable what the business needs to do.</p></li><li><p>Learn to Speak Business, Not Tech: Translate technical jargon and cyber risk into business risk, real dollars, and layman&#8217;s terms so leadership can understand, support, and fund your programs.</p></li><li><p>Be a Student of the Business: Understand your organization&#8217;s structure, operations, long-term strategy, and threat landscape so you can give relevant, informed advice.</p></li><li><p>Build Relationships with Your Peers: Proactively connect with people across departments (HR, sales, operations) whose work your decisions will impact.</p></li><li><p>Listen for Problems You Can Solve: In one-on-ones with business leaders, listen for pain points where security, automation, or AI can add value. Then offer solutions, not restrictions.</p></li><li><p>Frame Security as Risk Guidance, Not Gatekeeping: Present risks, likelihoods, and impacts, but let the business make the final decision to accept, mitigate, or transfer risk.</p></li><li><p>Make Business Partners an Extension of Security: When you bring people secure solutions that help them do their jobs, they start asking vendors the right security questions on your behalf.</p></li></ul><blockquote><p>&#8220;In this time and age, the abuse of data is more existing than the use of data itself.&#8221; - Anand Pallapalayam</p></blockquote><p><strong>Connect with these featured guests:</strong></p><ul><li><p>Antonio Taylor: <a href="https://www.linkedin.com/in/antoniodtaylor/">https://www.linkedin.com/in/antoniodtaylor/</a></p></li><li><p>Joshua Copeland: <a href="https://www.linkedin.com/in/joshuacopeland/">https://www.linkedin.com/in/joshuacopeland/</a></p></li><li><p>Rick Doten: <a href="https://www.linkedin.com/in/rick-doten-633470177/">https://www.linkedin.com/in/rick-doten-633470177/</a></p></li><li><p>Jennifer Fite: <a href="https://www.linkedin.com/in/jenfitephd/">https://www.linkedin.com/in/jenfitephd/</a></p></li><li><p>Mark Alvarado: <a href="https://www.linkedin.com/in/mark-alvarado-8715148/">https://www.linkedin.com/in/mark-alvarado-8715148/</a></p></li><li><p>Frank DePaola: <a href="https://www.linkedin.com/in/frankdepaola/">https://www.linkedin.com/in/frankdepaola/</a></p></li><li><p>Sanjeev Kumar: <a href="https://www.linkedin.com/in/trusted-ai-ciso/">https://www.linkedin.com/in/trusted-ai-ciso/</a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Re-Air: Implementing Robust Data Protection Measures - Hans Vargas - Guardians of the Data - Ep #35]]></title><description><![CDATA[What is the first step in building an effective data security and data governance strategy?]]></description><link>https://www.guardiansofthedata.show/p/re-air-implementing-robust-data-protection</link><guid isPermaLink="false">https://www.guardiansofthedata.show/p/re-air-implementing-robust-data-protection</guid><dc:creator><![CDATA[Guardians of the Data]]></dc:creator><pubDate>Thu, 26 Mar 2026 14:02:33 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/72b46c98-0537-4ecc-a051-590ab005720c_1200x880.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this re-aired episode, we revisit a powerful conversation with Hans Vargas, Enterprise Data Protection Lead at Marathon Petroleum Corporation.</p><p>Hans shares timeless insights on one of the most persistent challenges in data security: understanding what data actually matters and how to protect it effectively. From the importance of data discovery and classification to the realities of working with business stakeholders, this episode is a practical look at what it takes to build a strong data protection foundation.</p><p>As organizations continue to navigate cloud adoption, AI, and increasingly distributed environments, Hans&#8217;s perspective is just as relevant today as when this episode first aired.</p><div id="youtube2-N9SaIhMxkuA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;N9SaIhMxkuA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/N9SaIhMxkuA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong>Takeaways:</strong></p><ul><li><p>Know What You Need to Protect: Start with data discovery and identify what data you have, where it is, and what is sensitive. You can&#8217;t protect what you don&#8217;t know exists.</p></li><li><p>Engage Data Owners Directly: Build relationships with data owners, not just stakeholders. Have open conversations to understand what is truly sensitive and important to the business.</p></li><li><p>Communicate the Value of Data Protection: Clearly explain to business units why data protection matters, using relatable analogies if needed (e.g., moving houses, hoarding).</p></li><li><p>Establish and Strengthen Data Governance: Ensure your organization has clear data governance policies covering the entire data lifecycle from creation to disposition.</p></li><li><p>Collaborate Across Teams: Work closely with data governance, legal, and business units. Data security is a two-way street; share discoveries and insights to improve overall protection.</p></li><li><p>Don&#8217;t Rely Solely on Tools: Deploying a tool is not enough. Make sure processes and responsibilities are in place before or alongside technology adoption.</p></li><li><p>Consider the Full CIA Triad: Don&#8217;t focus only on confidentiality. Ensure data integrity and availability are also prioritized to keep the business running smoothly.</p></li></ul><blockquote><p>&#8220;I argue that the conversation about the architecture of how to protect data should be one of the first things.&#8221; - Hans Vargas</p></blockquote><p><strong>Connect with Hans:</strong></p><ul><li><p>LinkedIn: <a href="https://www.linkedin.com/in/hansvargas/">https://www.linkedin.com/in/hansvargas/</a></p></li><li><p>Website: <a href="https://www.marathonpetroleum.com/">https://www.marathonpetroleum.com/</a></p></li></ul><p><strong>Ways to Tune In:</strong></p><ul><li><p>Transistor: <a href="https://guardiansofthedata.show/">https://guardiansofthedata.show/</a></p></li><li><p>Spotify: <a href="https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ">https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ </a></p></li><li><p>Apple Podcasts: <a href="https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323">https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323</a></p></li></ul>]]></content:encoded></item></channel></rss>