#210 Cyber Technology Cannot Hide Bad Risk Management episode artwork

EPISODE · Jul 11, 2024 · 34 MIN

#210 Cyber Technology Cannot Hide Bad Risk Management

from Embracing Digital Transformation · host Dr. Darren Pulsipher

Check out my new book AI Augmented Teams on Amazon or on my website paidar.ai/books.In today’s tech-driven business world, balancing the use of SaaS platforms and maintaining robust cybersecurity is like walking a tightrope. In this podcast episode, we chat with Richard Hollis, Director at RiskCrew, about the practical application of Zero Trust principles and a holistic approach to risk management in the digital age. We explore the importance of data-centric security, the challenges posed by cloud-based SaaS platforms, and the necessity of evolving our cybersecurity strategies.In the technology-rich environment that dominates today's business world, leveraging the full potential of Software as a Service (SaaS) platforms while simultaneously achieving robust cybersecurity seems like walking a tightrope. In an intriguing podcast episode, we are joined by Richard Hollis, a seasoned Director at RiskCrew with extensive experience in cybersecurity. Together, we delve deep into this captivating subject, offering practical insights into the pragmatic application of the principles of Zero Trust and a more holistic approach to risk management in the digital era. Zero Trust: More Than a BuzzwordThe concept of Zero Trust is based on the principle of 'don't trust anyone' when it comes to cybersecurity. While this might seem like a strong security measure, it's important to note that some experts, such as Hollis, have pointed out that implementing Zero Trust through technology can lead to complex and inefficient solutions. Going to the extreme with Zero Trust could potentially hinder a business's operations with overly burdensome security measures that end up creating more obstacles than safeguards. It's crucial to find the right balance when implementing Zero Trust.However, this doesn't mean that Zero Trust is entirely impractical. Instead, the emphasis should be on using it as the basis for a data-centric approach to risk management, a strategy that is becoming increasingly crucial in the digital era. The true value of Zero Trust lies in understanding that nothing can be trusted and recognizing the need for a fundamental shift in how we approach data security. This means focusing on a proactive and continuous approach to security rather than simply relying on perimeter defenses. Data: The Real PrizeIn the modern approach to security, there is a growing emphasis on prioritizing the protection of data as opposed to focusing solely on securing all devices and architecture. This means that companies are starting to recognize the importance of safeguarding sensitive information such as customer data, financial records, and intellectual property. However, it's still common for companies to put too much emphasis on securing the physical infrastructure and individual devices rather than prioritizing protecting the data itself. This shift in focus reflects an understanding that data is often the primary target for cyber threats and should thus be the central focus of security efforts.The key to effective security lies in understanding and tracking the data. Companies must assess their information assets, including their value and location. Regular holistic risk assessments should be conducted to identify who has access to these assets, aligning the principles of Zero Trust with the nature of the company's data ecosystem. The challenge then becomes finding the right balance between accessibility and security. When Zero Trust principles are implemented correctly, they ensure that "the right people have the right data at the right time," effectively striking this delicate balance. The Cloud ConundrumThe widespread use of cloud-based SaaS platforms poses a significant issue that companies often overlook despite their effectiveness. According to Hollis, the control paradigm shifts once data is transferred to these platforms, as much of it falls outside the organization's jurisdiction. This means that data hosted on these platforms may be more challenging to monitor and secure.Furthermore, discussions about data security often need to address the everyday SaaS platforms that companies extensively utilize. This oversight can be detrimental, as Zero Trust principles have limited application in this context due to the difficulties in accurately tracing data stored on cloud platforms. As such, companies need to reassess their approach to data security to adequately address the challenges posed by the widespread use of cloud-based SaaS platforms. Toward a Pragmatic FutureIn the face of an ever-expanding digital landscape, Hollis's insights remind us of the imperative need to adjust and evolve. The shift towards a more targeted and pragmatic approach to data security is no longer a mere option; it has become essential to successful business operations in the modern era. Understanding data's value, location, and significance can provide a clear pathway for effective cybersecurity management. By incorporating a level-headed and practical application of the principles of Zero Trust, we can establish a robust template for navigating the complex maze of cybersecurity, particularly within a landscape dominated by cloud platforms and Software as a Service (SaaS) solutions. This approach safeguards organizations' digital assets and information, fostering a secure and resilient digital ecosystem.As content creation and engaging discussions continue to gain momentum, we extend a warm invitation for you to participate actively and share your thoughts. Your contributions are not just welcome, but they are instrumental in upholding a dynamic and interactive community, allowing diverse perspectives to enrich our shared experiences. We encourage you to immerse yourself in the ongoing dialogue and assure you that your contributions will help shape it. Your insights are invaluable to us.Take advantage of the opportunity to explore the latest episode of our podcast. It provides a platform to delve deeper into relevant topics, fostering a deeper understanding of the issues. We envision it as a valuable resource that not only keeps you informed but also serves as a catalyst for thought-provoking discussions and new insights. Your engagement with the podcast will play a pivotal role in further enriching our vibrant community and advancing our collective knowledge and understanding.

Check out my new book AI Augmented Teams on Amazon or on my website paidar.ai/books.In today’s tech-driven business world, balancing the use of SaaS platforms and maintaining robust cybersecurity is like walking a tightrope. In this podcast episode, we chat with Richard Hollis, Director at RiskCrew, about the practical application of Zero Trust principles and a holistic approach to risk management in the digital age. We explore the importance of data-centric security, the challenges posed by cloud-based SaaS platforms, and the necessity of evolving our cybersecurity strategies.In the technology-rich environment that dominates today's business world, leveraging the full potential of Software as a Service (SaaS) platforms while simultaneously achieving robust cybersecurity seems like walking a tightrope. In an intriguing podcast episode, we are joined by Richard Hollis, a seasoned Director at RiskCrew with extensive experience in cybersecurity. Together, we delve deep into this captivating subject, offering practical insights into the pragmatic application of the principles of Zero Trust and a more holistic approach to risk management in the digital era. Zero Trust: More Than a BuzzwordThe concept of Zero Trust is based on the principle of 'don't trust anyone' when it comes to cybersecurity. While this might seem like a strong security measure, it's important to note that some experts, such as Hollis, have pointed out that implementing Zero Trust through technology can lead to complex and inefficient solutions. Going to the extreme with Zero Trust could potentially hinder a business's operations with overly burdensome security measures that end up creating more obstacles than safeguards. It's crucial to find the right balance when implementing Zero Trust.However, this doesn't mean that Zero Trust is entirely impractical. Instead, the emphasis should be on using it as the basis for a data-centric approach to risk management, a strategy that is becoming increasingly crucial in the digital era. The true value of Zero Trust lies in understanding that nothing can be trusted and recognizing the need for a fundamental shift in how we approach data security. This means focusing on a proactive and continuous approach to security rather than simply relying on perimeter defenses. Data: The Real PrizeIn the modern approach to security, there is a growing emphasis on prioritizing the protection of data as opposed to focusing solely on securing all devices and architecture. This means that companies are starting to recognize the importance of safeguarding sensitive information such as customer data, financial records, and intellectual property. However, it's still common for companies to put too much emphasis on securing the physical infrastructure and individual devices rather than prioritizing protecting the data itself. This shift in focus reflects an understanding that data is often the primary target for cyber threats and should thus be the central focus of security efforts.The key to effective security lies in understanding and tracking the data. Companies must assess their information assets, including their value and location. Regular holistic risk assessments should be conducted to identify who has access to these assets, aligning the principles of Zero Trust with the nature of the company's data ecosystem. The challenge then becomes finding the right balance between accessibility and security. When Zero Trust principles are implemented correctly, they ensure that "the right people have the right data at the right time," effectively striking this delicate balance. The Cloud ConundrumThe widespread use of cloud-based SaaS platforms poses a significant issue that companies often overlook despite their effectiveness. According to Hollis, the control paradigm shifts once data is transferred to these platforms, as much of it falls outside the organization's jurisdiction. This means that data hosted on these platforms may be more challenging to monitor and secure.Furthermore, discussions about data security often need to address the everyday SaaS platforms that companies extensively utilize. This oversight can be detrimental, as Zero Trust principles have limited application in this context due to the difficulties in accurately tracing data stored on cloud platforms. As such, companies need to reassess their approach to data security to adequately address the challenges posed by the widespread use of cloud-based SaaS platforms. Toward a Pragmatic FutureIn the face of an ever-expanding digital landscape, Hollis's insights remind us of the imperative need to adjust and evolve. The shift towards a more targeted and pragmatic approach to data security is no longer a mere option; it has become essential to successful business operations in the modern era. Understanding data's value, location, and significance can provide a clear pathway for effective cybersecurity management. By incorporating a level-headed and practical application of the principles of Zero Trust, we can establish a robust template for navigating the complex maze of cybersecurity, particularly within a landscape dominated by cloud platforms and Software as a Service (SaaS) solutions. This approach safeguards organizations' digital assets and information, fostering a secure and resilient digital ecosystem.As content creation and engaging discussions continue to gain momentum, we extend a warm invitation for you to participate actively and share your thoughts. Your contributions are not just welcome, but they are instrumental in upholding a dynamic and interactive community, allowing diverse perspectives to enrich our shared experiences. We encourage you to immerse yourself in the ongoing dialogue and assure you that your contributions will help shape it. Your insights are invaluable to us.Take advantage of the opportunity to explore the latest episode of our podcast. It provides a platform to delve deeper into relevant topics, fostering a deeper understanding of the issues. We envision it as a valuable resource that not only keeps you informed but also serves as a catalyst for thought-provoking discussions and new insights. Your engagement with the podcast will play a pivotal role in further enriching our vibrant community and advancing our collective knowledge and understanding.

NOW PLAYING

#210 Cyber Technology Cannot Hide Bad Risk Management

0:00 34:08

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Solving for Change MOBIA Technology Innovations Solving for Change welcomes business and technology leaders to share stories of bold business transformation within complex organizations. In an era when technology and markets are changing around businesses, the key to staying competitive is to evolve in response to those changes.  MOBIA’s Mike Reeves and Marc LeBlanc investigate business transformation, deconstructing the challenges, ambitions, and market disruptions that drive companies to embark on transformation journeys, and exploring their unique approaches to achieving meaningful outcomes.  What sparks leaders to pursue business transformation? How do they overcome the challenges along the way? What are the keys to creating enduring change?  Through in-depth conversations with business and technology leaders, Mike and Marc answer these questions and explore how businesses evolve by pulling four key transformation levers: people, process, technology, and culture. Darknet Discussions Darknet Discussions Welcome to "Darknet Discussions," the podcast that gets into the shadows of the internet to bring you the most intriguing, enlightening, and sometimes unsettling stories from the dark web. Hosted by seasoned darknet aficionados, each episode of "Darknet Discussions" explores the intricate dynamics of darknet markets, cybersecurity threats, and the digital underworld. Join us as we interview experts, discuss the latest trends in cybercrime, and shed light on the technologies that operate beneath the surface of everyday internet use. Also, we occasionally go off on a tangent about something completely unrelated. The Digital Experience Show by Enonic Enonic All you need to know about digital strategy, digital experiences, and CMS are covered in this podcast. Powered by NotebookLM. Tips, News and Stories for Older Adults Esther C Kane CAPS, C.D.S. "Tips, News, and Stories for Older Adults" delivers weekly insights tailored for seniors. We bring you summaries of curated news, practical advice, and inspiring stories that matter to the 55+ community. From health and finance to technology and lifestyle, our content keeps you informed and engaged. Sourced from trusted outlets, each episode offers valuable information for navigating your golden years. Join us as we explore aging with positivity, wisdom, and engaging stories. Your perfect companion for staying active, learning, and embracing life's later chapters.

Frequently Asked Questions

How long is this episode of Embracing Digital Transformation?

This episode is 34 minutes long.

When was this Embracing Digital Transformation episode published?

This episode was published on July 11, 2024.

What is this episode about?

Check out my new book AI Augmented Teams on Amazon or on my website paidar.ai/books.In today’s tech-driven business world, balancing the use of SaaS platforms and maintaining robust cybersecurity is like walking a tightrope. In this podcast episode,...

Can I download this Embracing Digital Transformation episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!