Guardians of the Data

Ward Balcerzak

Welcome to Guardians of the Data! Join host, Ward Balcerzak, each week as he dives deep into the passions, expertise, and experiences of CISOs, Chief Data Officers, and more. Guardians of the Data is sponsored by Sentra - AI-powered data security platform that discovers and classifies all your data accurately and automatically to achieve enterprise-scale data protection without the fuss.

  1. 5d ago

    The AI Data Trap - Guardians of the Data - Episode # 62

    Ask five security leaders for the biggest data security challenge and "AI" is the easy answer. In this compilation episode, Ward Balcerzak talks with Dana Kilcrease, Brent Bigelow, Jason Torres, Anand Pallapalayam, and Dameon Sherman, and they go a layer deeper. The real problem is velocity. The old gaps, from unstructured data nobody can measure to assets nobody can name, are now growing at a pace that resources can't match. The group covers why fundamentals still win, how governance turns InfoSec into a place of "go," what data quality has to do with protection, and why "harvest now, decrypt later" should be on your radar as AI and quantum computing start to meet.   Takeaways: Slow down and go back to first principles. New tools show up weekly, but hardened endpoints, solid processes, and a tested incident response plan shrink the blast radius when something goes wrong.Set up an AI governance committee before you scale AI use. Define what data can go into AI, what outcomes the business expects, and back it with clear policies and education. Without that, you are running the Wild Wild West.Get honest about your unstructured data. If you can't see it, you can't protect it, and you can't keep AI from ingesting it. Stop adding storage to data you don't understand and start discovering what is actually in there.Treat data quality as a security control. Decide what is useful, tag it, and separate what is sensitive, because that drives your access controls and keeps you from paying to store data you never needed.Plan for tomorrow's threats today. Attackers are already hoarding encrypted data to crack later, and AI paired with quantum could shorten that timeline. Keep learning and keep your training modules coming, because the basics never stop mattering.Quote of the Show: "All of a sudden these gaps and these technical debts are just growing exponentially, and it's difficult for us to keep up because the resources aren't growing along with the threat." - Dana KilcreaseGuest’s LinkedIn: Anand PallapalayamBrent BigelowDameon ShermanDana KilcreaseJason TorresWays to Tune In: Transistor: https://guardiansofthedata.show/  Spotify: https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ Apple Podcasts: https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323 Amazon Music: https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-dataiHeart Radio: https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/YouTube: https://www.youtube.com/@GuardiansoftheDataPod

    The AI Data Trap - Guardians of the Data - Episode # 62
  2. Sep 24

    Data Security Is a People Problem - Shanief Webb - Guardians of the Data - Episode # 61

    What happens to your data security program the day your most experienced person walks out the door?  For most organizations, the honest answer is chaos. In this episode, Shanief Webb, interim CISO and security engineering leader at a digital healthcare organization, breaks down why data security is a people problem before it's ever a technology problem. Shanief walks through how tribal knowledge, uncontrolled data volume, and stale documentation combine into a perfect storm when something goes wrong, whether that's a breach, an audit, or an outage. He also shares the career path that took him from reverse engineering malware at the FBI to building security teams at Google, Slack, Dropbox, Okta, Meta, and Headspace, and explains why he intentionally builds generalists instead of specialists on every team he leads.   Takeaways: Documentation isn't red tape, it's insurance. When institutional knowledge walks out the door with an employee, well maintained data documentation is what keeps your team from scrambling during a breach, audit, or outage. Lean on AI to lighten the workload without cutting corners.Assign real ownership over your data. Retention, classification, and lifecycle decisions stay stuck in fear, uncertainty, and doubt until one person is actually accountable for understanding what the data is and why it exists.Build generalists, not silos. Give people stretch projects that push them into new domains like incident response or vulnerability management, because the strongest defenders are the ones who can connect the dots across teams.Treat documentation as a living process, not a one time project. Pair onboarding reviews with periodic audits so your records stay accurate as tools, contacts, and regulations change.Slow down long enough to notice what you've built. Growth and impact are easy to miss when you're constantly moving to the next challenge, so take time to recognize the ground you've covered and the people you've helped develop along the way.Quote of the Show: "Out of date documentation will slow you down." - Shanief WebbLinks: LinkedIn: https://www.linkedin.com/in/shanief/Ways to Tune In: Transistor: https://guardiansofthedata.show/  Spotify: https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ Apple Podcasts: https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323 Amazon Music: https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-dataiHeart Radio: https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/YouTube: https://www.youtube.com/@GuardiansoftheDataPod

    Data Security Is a People Problem - Shanief Webb - Guardians of the Data - Episode # 61
  3. Sep 17

    Guardrails in the Wild West - Ronak Patel - Guardians of the Data - Episode # 60

    What happens when the security foundations we spent decades building suddenly have to work against an entirely new kind of adversary? In this episode, Ward sits down with longtime friend and 25 year cybersecurity veteran Ronak Patel to unpack why AI has turned data security into the Wild West all over again. Ronak walks through how the rapid, ungoverned adoption of AI tools across organizations is recreating the same chaos we saw with early cloud migration, just at a much faster pace. From foundational guardrails like CASB and DLP to the shift from preventing data loss to preventing data exposure, Ronak makes the case that the technology has changed, but the fix still starts with the same thing: understanding your data. The conversation closes with Ronak's candid, hard earned advice for security professionals navigating one of the toughest job markets the industry has seen in years.   Takeaways: AI adoption is moving at hyper speed, and most organizations are rolling it out without the checks and balances that real enterprise adoption requires. Treat AI the same way you'd treat shadow IT: understand what platforms your people are actually using before you try to control them.The conversation around data protection needs to shift from just stopping data loss to preventing data exposure. Copilots and AI agents don't need to move your data outside the org to create risk, they just need inappropriate access to it.Before you can put guardrails around AI, you need the same foundation good data security has always required: understanding your data, who owns it, where it lives, and who's allowed to touch it.Foundational controls like email inspection, CASB, proxy, and DLP still matter. Layer AI detection on top of that foundation instead of trying to solve for AI in isolation.In a brutal job market, your network matters more than your resume. Use AI to tailor your resume and cover letter for every role, but go through your connections before you apply cold through a portal.Quote of the Show: "A data protection program is not a tool at all. It is a program that has tools, but it also has processes and people, all of this living in harmony to actually be able to protect." - Ronak PatelLinks: LinkedIn: https://www.linkedin.com/in/ronaksf/ Ways to Tune In: Transistor: https://guardiansofthedata.show/  Spotify: https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ Apple Podcasts: https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323 Amazon Music: https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-dataiHeart Radio: https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/YouTube: https://www.youtube.com/@GuardiansoftheDataPod

    Guardrails in the Wild West - Ronak Patel - Guardians of the Data - Episode # 60
  4. Sep 10

    Stop Blaming the Human - Sam Wolf - Guardians of the Data - Episode # 59

    What if the biggest vulnerability in your security program isn't a missing patch, but the friction you built on purpose? In this episode, Sam Wolf, assistant director of engineering and data security in financial services, makes the case that security teams have been pointing the finger in the wrong direction. It is not the human who is the weakest link, it is the systems built without the human in mind. Sam breaks down why the "department of no" mindset creates the very workarounds that put organizations at risk, and why the fix starts with understanding what the business is actually trying to accomplish before adding another   Takeaways: Stop blaming the human for finding the path of least resistance. If people keep bumping into the same workaround, that is a design problem, not a training problem. Build controls around how people actually work, not how you wish they worked.Retire the instinct to solve every gap with more training. A secure workflow should not require a class to use safely. If the right way is harder than the easy way, people will find the easy way every time.Before greenlighting the next AI request, ask what happens if you say no. That single question separates a real business need from FOMO, and it gives you a starting point for mapping the request back to strategy and mission.Treat tech debt like a product problem, not just a technical one. Look for the pieces you can decouple and simplify before adding another layer on top, and use contract renewal windows as a natural point to consolidate tools.Document decisions the moment you make them, not after the fact. A shared record of what was agreed protects both security and the business, and it turns "why didn't you catch this" into "here is what we agreed to."Quote of the Show: "Attitude, aptitude, and initiative. I can figure it out, you can figure it out." - Sam WolfLinks: LinkedIn: https://www.linkedin.com/in/samuelwolf/ Ways to Tune In: Transistor: https://guardiansofthedata.show/  Spotify: https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ Apple Podcasts: https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323 Amazon Music: https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-dataiHeart Radio: https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/YouTube: https://www.youtube.com/@GuardiansoftheDataPod

    Stop Blaming the Human - Sam Wolf - Guardians of the Data - Episode # 59
  5. Sep 3

    Guardrails, Not Gadgets - Todd Covert - Guardians of the Data - Episode # 58

    What happens when the same piece of data is highly sensitive on Tuesday and public knowledge by Friday?  In this episode, Ward Balcerzak sits down with former CISO Todd Covert, who brings over 25 years of experience across healthcare, insurance, and fintech to unpack why data security still hasn't been solved. Todd breaks down the human side of the problem, from employees just trying to do their jobs without clear guardrails, to the challenge of protecting data whose sensitivity changes by the hour, to how AI tools have made it easier than ever to put information at risk without meaning to. The conversation moves from the technical to the deeply practical, covering how security leaders can build influence, communicate across different audiences, and turn their toughest critics into advocates.   Takeaways: Most employees aren't trying to misuse data, they're trying to do their jobs, and often security hasn't given them a clear, easy path to do it safely.Data sensitivity isn't fixed. A document can be highly confidential today and public tomorrow, and organizations still haven't solved how to manage that shifting risk.AI tools have made it dramatically easier to expose sensitive data, often without any bad intent involved, which raises the stakes on getting guardrails right.Winning adoption for a security process means identifying your toughest critics early and working to turn them into advocates, rather than avoiding them.Communication style matters as much as the message itself. Data driven leaders, emotionally driven leaders, and different departments all need to be approached differently to build real buy in.Quote of the Show: "If I can take my toughest critics and turn them into advocates, that's where I can have that success." - Todd CovertLinks: LinkedIn: https://www.linkedin.com/in/toddcovert/ Ways to Tune In: Transistor: https://guardiansofthedata.show/  Spotify: https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ Apple Podcasts: https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323 Amazon Music: https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-dataiHeart Radio: https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/YouTube: https://www.youtube.com/@GuardiansoftheDataPod

    Guardrails, Not Gadgets - Todd Covert - Guardians of the Data - Episode # 58
  6. Aug 27

    Security Beyond the Code - Omar Sangurima - Guardians of the Data - Episode # 57

    What happens when you ask a data security expert to skip the buzzwords and get plain vanilla? You get inventory. In this episode, Omar Sangurima sits down with Ward to unpack why so many organizations are still stuck on the most basic question in data security: do you actually know what data you have and where it lives? Omar draws on his background in sales, finance, and now healthcare cyber governance to explain why the real work isn't technical, it's people and process. From navigating legacy environments to earning the trust to push back on executive mandates, Omar breaks down how understanding the business first, and the technology second, is what separates real data protection from what he calls kabuki theater.   Takeaways: Start with inventory, not tools. Before buying another platform, get honest about what data you have and where it lives. Most organizations already own tools that can do this, the real gap is appetite and follow through.Understand the business before you try to protect it. Every organization has a core engine, whether that's patient care, transactions, or something else, and knowing what fuels that engine tells you what data actually matters. Work backwards from there to build your protection strategy.Pair conversations with telemetry. Relationships give you context, but data gives you proof. Combine both so you can walk into any executive meeting with the problem, the solution, and the ask.Don't just lift, shift, and plop into the cloud. Migrating without optimizing just moves your old problems to a new address. Listen to the people who know where the risks are buried before you make the leap.Earn the right to push back. Build a reputation for actually getting things done, then use that credibility to challenge a mandate at most twice, respectfully, before executing anyway. Nobody trusts an advisor who only says yes or only says no.Quote of the Show: "You have to have the receipts and you have to have the ability to show that you can be trusted, trusted to get stuff done, trusted to only push back when it matters." - Omar SangurimaLinks: LinkedIn: https://www.linkedin.com/in/dromars/ The Cyber Mettle Podcast: https://www.youtube.com/channel/UCyf4TYnc-0AKW79TbxfK3zw Ways to Tune In: Transistor: https://guardiansofthedata.show/  Spotify: https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ Apple Podcasts: https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323 Amazon Music: https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-dataiHeart Radio: https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/YouTube: https://www.youtube.com/@GuardiansoftheDataPod

    Security Beyond the Code - Omar Sangurima - Guardians of the Data - Episode # 57
  7. Aug 20

    Data Hoarding Equals Liability - Dameon Sherman - Guardians of the Data - Episode # 56

    If someone deleted your organization's data today, would you even know what you lost? For Dameon Sherman, SVP of Information Protection in financial services, that question sits at the center of a career spanning military service, government contracting, and highly regulated enterprise environments. In this episode, Dameon joins Ward Balcerzak to make the case that data security still starts with the fundamentals most organizations think they've already solved: knowing what data you have, where it lives, and whether it's actually trustworthy. Drawing on lessons from combat IT work in Iraq and Afghanistan, nuclear program accreditation with the Navy, and years navigating federal contracting rules, Dameon breaks down why disparate CMDBs, data hoarding, and reactive retention policies leave companies exposed. He also unpacks the looming "harvest now, decrypt later" threat posed by quantum computing and why treating data like a physical asset, cataloged, tagged, and continuously monitored, is the only way to stay ahead of it.   Takeaways: Treat your data like a physical asset. Inventory it, tag it, and catalog it the same way you would any piece of hardware, because you cannot protect what you do not know you have.A CMDB is only as good as its design. Map out the elements you need to capture before you build the system, not after, or you will spend years fixing accuracy problems.Data quality is a security issue in disguise. If you cannot identify what is useful versus erroneous, you cannot apply the right protections or control your storage costs.Retention policies mean nothing if you do not enforce them. Purge data on schedule, because anything sitting past its retention window is pure liability with no upside.Quantum computing has already changed attacker behavior. Encrypted data is being harvested now for decryption later, which makes inventory and deletion discipline more urgent than ever.Quote of the Show: "You cannot protect what you don't know that you have." - Dameon Sherman  Links: LinkedIn: https://www.linkedin.com/in/dameonsherman/ Ways to Tune In: Transistor: https://guardiansofthedata.show/  Spotify: https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ Apple Podcasts: https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323 Amazon Music: https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-dataiHeart Radio: https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/YouTube: https://www.youtube.com/@GuardiansoftheDataPod

    Data Hoarding Equals Liability - Dameon Sherman - Guardians of the Data - Episode # 56
  8. Aug 13

    Risk Isn't Static - Guardians of the Data - Veena Nagarajan - Episode #55

    If someone tried to onboard a new vendor tomorrow, would your organization know exactly which questions to ask before granting access to sensitive data? For most teams, the answer is a scramble, not a process. In this episode, Ward sits down with Veena Nagarajan, interim CISO of a healthcare organization with 15 years in cybersecurity, to unpack why data protection has become as much about disciplined process as it is about technology. Veena walks through how she screens new solutions before they ever touch the environment, why a lean ten question risk assessment beats a bloated 100 question form nobody finishes, and how ongoing reassessment, not a one time checkbox, is what actually keeps organizations safe. She also opens up about her journey from India to becoming a healthcare CISO, and the mentors who shaped the way she leads. Takeaways: Start every new solution with a short, focused risk questionnaire. Ten well chosen questions about hosting, data elements, and exposure will tell you more than fifty scattered ones ever could.Know your regulatory baseline before you assess risk. Whether it's HIPAA, PCI, or SOX, identifying which frameworks apply first helps you pinpoint your organization's true crown jewels.Risk assessment isn't a one time event. Reassess after a vendor moves from proof of concept to production, since environments and exposure change fast.Defense in depth still wins. Layer email security, EDR, DLP, and network detection together, because the human clicking a bad link remains the most common entry point.Don't let perfect automation be the enemy of consistency. A well maintained spreadsheet process beats a fancy automated one that nobody checks. What matters most is doing it regularly.Quote of the Show: "It doesn't matter if it's manual or automatic. What matters is keeping it regular and consistent. That is the key." - Veena Nagarajan Links: LinkedIn: https://www.linkedin.com/in/veena-nagarajan/ Ways to Tune In: Transistor: https://podcast.guardiansofthedata.show/ Spotify: https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ Apple Podcasts: https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323 Amazon Music: https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-dataiHeart Radio: https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/YouTube: https://www.youtube.com/@GuardiansoftheDataPod

    Risk Isn't Static - Guardians of the Data - Veena Nagarajan - Episode #55

Ratings & Reviews

5
out of 5
4 Ratings

About

Welcome to Guardians of the Data! Join host, Ward Balcerzak, each week as he dives deep into the passions, expertise, and experiences of CISOs, Chief Data Officers, and more. Guardians of the Data is sponsored by Sentra - AI-powered data security platform that discovers and classifies all your data accurately and automatically to achieve enterprise-scale data protection without the fuss.