Discover
Data Security Decoded

Data Security Decoded
Author: Rubrik
Subscribed: 6Played: 143Subscribe
Share
Copyrights © 2024 All Rights Reserved by Rubrik 794942
Description
Data Security Decoded provides actionable, vendor-agnostic insights to reduce data security risk and improve resilience outcomes. Designed for cybersecurity and IT professionals who want practical insights on preparing for attacks before they happen, so they can respond effectively when they inevitably do. Episodes feature insights from researchers, crafters of public policy, and senior cybersecurity leaders, to help organizations reduce risk and improve resilience. Data Security Decoded provides practical advice, proven strategies, and in-depth discussions on the latest trends and challenges in data security, helping listeners strengthen their organizations' defenses and recovery plans.
65 Episodes
Reverse
Please enjoy this encore of Data Security Decoded.
In this episode, host Caleb Tolin explores the battlefield of enterprise defense, which has moved from simple data theft to ultra heinous crimes that put patient outcomes at risk. Guest Cynthia Kaiser shares Battlefield Stories from her time at the FBI and her current work as SVP of the Ransomware Research Center at Halcyon, illustrating how the industrialization of cybercrime has reached a tipping point. They dive into the alarming reality of modern dwell times, specifically looking at how groups like Akira move from initial access to full encryption in as little as one hour.
The conversation challenges the industry to face the inconvenient truths of cybercrime and ransomware. Kaiser shares case studies of how modern cybercriminals are adopting multilateral techniques to gain access to and exploit your network. By adopting an Assume Breach mindset, elite defenders can build the defense in depth required to combat malicious threat actors who follow their own rules to cause disruption and destruction.
Resources
House Homeland Security Committee Testimony: Online Scams, Crypto Fraud, and Digital Extortion
Halcyon Analysis: Akira Ransomware Attacks in Under an Hour
Halcyon: Sicarii Ransomware Encryption Key Handling Defect
Previous Episode Referenced: Downtime in Healthcare is Fatal: Achieving Resilience in Health & Life Sciences
What You’ll Learn
Why designating ransomware as terrorism helps influence adversary target selection.
The impact of Akira's accelerated dwell time on traditional incident response.
How AI enables clumsy amateur "wannabes" to conduct messy attacks.
The critical role of phishing resistant MFA in securing the identity perimeter.
Why Assume Breach necessitates deep defense in depth strategies.
The overestimation of readiness among CISOs compared to actual red team performance
Episode Highlights
[00:00] - The Case for Designating Ransomware as Terrorism
[04:20] - Modern Extortion and the Shortening of Dwell Time
[08:30] - Ransomware Recovery in Interconnected Cloud Environments
[11:45] - The Impact of AI on the "Wannabe" Attacker
[17:45] - Three Actionable Steps for Modern Defenders
[21:30] - Inconvenient Truths for Government and Private Sector
Please enjoy this encore of Data Security Decoded.
In this episode of Data Security Decoded, join host Caleb Tolin as he welcomes back Joe Hladik, Head of Rubrik Zero Labs, to unpack the findings from their new report, Identity Crisis: Understanding & Building Resilience Against Identity-Driven Threats, Joe breaks down how the explosion of non-human identities, from API keys to AI agents, is rewriting the threat landscape and forcing security leaders to rethink the perimeter itself.
He explains why identity resilience is the new foundation of cyber defense, how to prioritize recovery when every system matters, and what steps teams can take now to stay ahead of emerging agentic AI-driven attacks.
What You'll Learn:
Why identity has replaced the network as the modern security perimeter
How non-human identities outnumber humans 82 to 1, and what that means for control and monitoring
Practical steps to build recovery plans around dependency mapping and minimal viable operations
Why ransom payments remain high and how better resilience planning can reverse that trend
How threat actors exploit backup systems to gain total business leverage
What agentic AI really means for cyber defense and how to prepare for its impact
The episode offers a clear framework for leaders to transform identity resilience from a reactive measure into a proactive pillar of enterprise security.
Episode Highlights:
[05:13] The 82:1 Ratio: Why Non-Human Identities Now Define Risk
[07:03] Prioritizing Recovery: Building for Minimal Viable Operations
[10:53] Declining Recovery Confidence and the Rise of Ransom Payments
[15:46] Backups Under Attack: How Threat Actors Seize Business Control
[16:32] Agentic AI and the Shifting Nature of Cyber Threats
[25:32] What Defenders Can Do Now to Build Identity Resilience
Episode Resources
Caleb Tolin on LinkedIn
Joe Hladik on LinkedIn
Rubrik Zero Labs report, Identity Crisis: Understanding & Building Resilience Against Identity-Driven Threats
Enjoy this encore of Data Security Decoded.
AI promises speed, scale, and efficiency—but it also magnifies privacy risk in ways many organizations aren’t prepared for. In this episode, Caleb Tolin welcomes Ojas Rege of OneTrust for a practical, wide-ranging conversation on how data privacy and governance must evolve alongside enterprise AI adoption.
Ojas explains why AI fundamentally changes the privacy conversation: the same systems that enable organizations to move faster can also cause harm faster when guardrails aren’t in place. From agentic AI systems that dynamically repurpose data to general-purpose models that blur traditional notions of “intended use,” the challenge isn’t just compliance—it’s trust.
The discussion dives deep into purpose limitation under GDPR and the EU AI Act, clarifying where organizations commonly misunderstand consent and where AI training introduces entirely new risks. Ojas emphasizes a simple but powerful test: are you using personal data for the same purpose you originally received consent for—or has AI quietly expanded that purpose?
The conversation then shifts to cloud and data sovereignty, particularly for European organizations navigating geopolitical uncertainty. Ojas outlines why data mapping, prioritization, and software supply chain visibility matter more than ever—and why perfection is less realistic than smart prioritization.
Ultimately, this episode reframes governance as an enabler. When privacy and data governance are embedded early, organizations can innovate faster, build lasting trust, and deploy AI with confidence in an increasingly complex global environment.
What You’ll Learn
Why AI scales privacy risk just as fast as business value
How purpose limitation breaks down with general-purpose AI models
When AI use requires new consent—and when it doesn’t
Why transparency is foundational to long-term customer trust
How data sovereignty concerns extend beyond cloud providers
Where software supply chains create hidden privacy blind spots
How good governance can accelerate, not block, AI deployment
Episode Highlights
[00:02:00] AI Scales the Good—and the Bad How AI accelerates both innovation and privacy harm.
[00:04:00] Purpose Limitation Meets AI Reality Why general-purpose models challenge traditional consent frameworks.
[00:06:30] Trust as a Business Risk Why transparency matters as much as legal compliance.
[00:07:30] Cloud & Data Sovereignty Explained What European organizations can do today to reduce risk.
[00:10:30] The Software Supply Chain Blind Spot Why third parties make sovereignty harder in the AI era.
[00:12:30] Data as Economic Power How nations now view citizen data as an AI asset.
[00:14:00] Governance That Enables Speed Why governing early helps organizations move faster later.
Please enjoy this encore of Data Security Decoded.
As enterprises race to adopt AI, many are discovering that traditional security models no longer hold. In this episode of Data Security Decoded, host Caleb Tolin is joined by Camille Stewart-Gloster, CEO of CAS Strategies and former Deputy National Cyber Director, to unpack how AI is redefining cyber risk at every layer of the organization.
Camille explains why identity-based attacks are so effective and how non-human identities (from APIs to AI agents) are quietly expanding the attack surface. She emphasized how critical MFA is for organizations to enable as they scale up AI operations., and why conditional access and governance must be foundational, not optional.
The conversation also tackles ethical AI head-on. Camille argues that AI ethics and AI security are inseparable, and that removing humans from the loop introduces both legal and operational risk. From shadow AI to agent autonomy, she offers a clear-eyed framework for deploying AI systems that augment human teams rather than replace them.
This episode is a practical guide for security leaders and learners navigating AI adoption, focused on resilience, trust, and long-term enterprise readiness.
What You’ll Learn
Why identity has become the dominant attack surface
How AI agents and non-human identities increase risk
Where EDR falls short in Identity-driven attacks
Why AI ethics is foundational to AI security
How governance enables secure AI deployment
When AI should augment—not replace—security teams
Episode Highlights
[00:03:00] Cyber offense and the evolving national strategy
[00:07:30] Identity eclipses malware as the primary threat
[00:10:00] AI systems as high-value targets
[00:12:30] Human judgment vs. automated response
[00:14:00] The ethics–security connection
[00:15:30] Why AI governance can’t be an afterthought
Please enjoy this encore of Data Security Decoded.
Welcome to Data Security Decoded. Join host Caleb Tolin in conversation with Morgan Adamski who leads Cyber, Data, and Tech Risk at PwC and is a former US national security leader who spent 16 years tracking nation-state threats inside the US government. Coming out of a career spent inside secure facilities without windows or phones and working to address China’s prepositioning in US critical infrastructure, Morgan shares a direct view of how geopolitics is now shaping cyber risk decisions in boardrooms.
What You'll Learn:
Why only 24% invest in proactive defense, even while 60% call cyber a top priority
How AI agents are cutting breach timelines to under 80 days
Why cyber insurance is now a hygiene scorecard, not just financial protection
The real reason leaders lack confidence in resilience
Where legacy systems and supply chain dependencies expose blind spots
How public–private collaboration changed the response to China’s infrastructure campaign
What CISOs must confront now to avoid being blindsided by the next crisis
The conversation gives security leaders and decision-makers a clear view of where current strategies fall short and the choices required to build real resilience before the next crisis forces it.
Episode Highlights:
[03:43] Why China prepositions inside US critical infrastructure to trigger disruption and panic in a crisis
[04:20] Collective defense in action: how victims and industry exposed the campaign
[09:27] The truth behind cyber budgets: only 24% invest in proactive defense
[11:57] How AI agents are shortening breach lifecycles to under 80 days
[13:07] Why cyber insurance is now a security scorecard, not a safety net
Episode Resources
Caleb Tolin on LinkedIn
Morgan Adamski on LinkedIn
PwC’s 2026 Global Digital Trust Insights report








