Guardians of the Data
What happens when a ransomware threat actor claims they have 380 gigabytes of your data and you have no idea what is actually in it? That was the reality Zach Lewis faced, and it became the catalyst for one of the most thorough data governance journeys you will hear on this show. In this episode, Ward sits down with Zach Lewis, CIO and CISO in the healthcare and higher education space, author of "Locked Up," and a 15 year veteran of the industry. Zach breaks down how a ransomware incident forced a complete reckoning with data classification, what a real multi year DSPM journey actually looks like from the inside, and why normalizing open conversation about cyber attacks might be the most important thing the security community can do right now. Takeaways: * Don't let a good crisis go to waste. A ransomware event, while devastating, can unlock budget, leadership attention, and organizational urgency that would have taken years to build otherwise. The smartest move after an incident is to channel that momentum into the data governance work you already knew needed to happen. * Data classification is not a policy problem, it is an execution problem. Having a policy on paper means nothing if the data isn't actually tagged, governed, and tied to access controls. The real work starts when you move from defining classifications to enforcing them at scale, and that is where tooling and AI become non negotiable. * Data governance is a forever journey, not a project. Even after years of work, Zach's team is still tackling retention, deduplication, and classification accuracy. The goal is not perfection on day one but consistent progress, eating the elephant one bite at a time. * Legal is your secret weapon. General counsel carries a kind of organizational gravity that IT rarely does. When you can align data hygiene and retention efforts with legal risk, people listen and things actually get deleted. * AI is shifting the math on what is even possible. Tasks that would have required a team of analysts reviewing files around the clock can now be handled automatically and accurately. Leaders who lean into AI for data security today are building the foundation that makes everything else, from Copilot adoption to regulatory compliance, far less terrifying tomorrow. Quote of the Show: * "A data governance journey never ends. It's a forever journey. Much like zero trust, the heavy lifting gets done and then it's about setting the right processes in place." - Zach Lewis Links: * LinkedIn: https://www.linkedin.com/in/zacharylewis1/ [https://www.linkedin.com/in/zacharylewis1/] * Book Link: https://homesteadingciso.com/getlockedup/ [https://homesteadingciso.com/getlockedup/] Ways to Tune In: * Transistor: https://guardiansofthedata.show/ [https://guardiansofthedata.show/] * Spotify: https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ [https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ] * Apple Podcasts: https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323 [https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323] * Amazon Music: https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data [https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data] * iHeart Radio: https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/ [https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/] * YouTube: https://www.youtube.com/@GuardiansoftheDataPod [https://www.youtube.com/@GuardiansoftheDataPod]
48 Folgen
Kommentare
0Sei die erste Person, die kommentiert
Melde dich jetzt an und werde Teil der Guardians of the Data-Community!