Skip to content

How Compliance Became Cool: Richa Kaul on Security, Privacy, and AI

Welcome back to “Data Driven,” the podcast where we explore the cutting edge of data science, AI, and the rapidly evolving world of data governance.

In this episode, we sit down with Richa Kaul, founder and CEO of Complyance, an AI-driven platform transforming governance, risk, and compliance for enterprises. Drawing on her experience as a data privacy enthusiast and leader in the compliance space, Richa Kaul dives into the pressing challenges of securing sensitive data, the complexities of global compliance frameworks, and how AI both complicates and protects our interconnected world.

We discuss the pivotal role of the Chief Information Security Officer, the importance of proactive, layered security measures, and why compliance is rapidly gaining attention—not just as a regulatory checkbox, but as a central business strategy. With practical advice for both enterprises and individuals on maintaining digital privacy and security, this episode is essential listening for anyone navigating today’s high-stakes data landscape.

Links

Timestamped overview

00:00 Privacy and security frameworks overview

03:54 Impact of Equifax data breach

06:21 Focusing on data security

09:58 Managing complex enterprise security controls

15:53 Focus on AI and information security

18:37 Learning from Fire Safety Education

20:47 Phone security in modern cyber warfare

24:48 Concerns about IoT device security

29:10 Protecting Privacy from Algorithms

30:44 Security and privacy concerns

35:23 GTA’s social commentary on privacy

39:11 AI’s Role in Cybersecurity Awareness

41:03 Global connectivity and surveillance issues

44:47 Ending on a positive note

Transcript
Speaker:

Because all of these privacy controls, they really have— or these privacy

Speaker:

frameworks, right? They have almost 2 sides. The first side

Speaker:

is the security side, which is how do we actually keep this

Speaker:

consumer's data secure and thereby keeping it private?

Speaker:

The other side of it is more of the pure privacy stuff, which is

Speaker:

things like how do we let them opt out? How do we let them retrieve

Speaker:

their data when they want to? Those are sort of the— how do you make

Speaker:

the experience for the consumer almost like more seamless, more in control? But

Speaker:

we really focus on the security side. How do you really lock down your environment

Speaker:

to make sure that there's never, you know, something to be worried about,

Speaker:

right? Of course, there's always risks in every enterprise, but there's never, you know, you

Speaker:

do as much proactive preventative work as possible. And

Speaker:

that happens by keeping an eye on all of the different security controls that you

Speaker:

have across your complicated enterprise, all in one single pane of

Speaker:

glass. And that's a really hard job to do, but that is what we have

Speaker:

set out to accomplish. Your biggest security risk may be

Speaker:

closer than you think. Rich Akall reveals how AI,

Speaker:

privacy, and smarter compliance are changing the way companies protect

Speaker:

data.

Speaker:

Hello and welcome back to Data Driven, the podcast where we explore the emerging industry

Speaker:

of data science, AI, and of course, it's all not

Speaker:

possible without data engineering. And unfortunately, my favorite data engineer

Speaker:

in the world, Andy Leonard, can't make it today, but I am here today with

Speaker:

Richa Kaul, who is the founder of and

Speaker:

CEO of Komplianz, an AI-driven platform

Speaker:

transforming governance, risk, and compliance for enterprises.

Speaker:

Previously, she held leadership roles at ContractPal AI, where she scaled

Speaker:

global compliance solutions. I'm noticing a theme here. Under her leadership,

Speaker:

Komplianz has raised $30 million in total funding, driving

Speaker:

rapid growth and the development of multiple new AI agents.

Speaker:

Richa's expertise— Richa expertise, because she's going to be richer than

Speaker:

Bill Gates, as we said in the virtual green room. Your

Speaker:

expertise has been featured in Authority Magazine, GRC

Speaker:

Pod, and several leading industry

Speaker:

podcasts. So welcome to the show, Richa. And I was

Speaker:

going to say, we joked around in the virtual green room how

Speaker:

compliance is cool again. And then I realized, wait a minute, It's never really been

Speaker:

cool before. So, but it certainly seems to

Speaker:

me to be a growth industry given all the compliance

Speaker:

mechanisms. So particularly in AI governance, right? And AI

Speaker:

governance is something that I'm passionate about. I didn't,

Speaker:

I never thought I'd be passionate about governance, but so what

Speaker:

brought you to compliance? Oh yeah, great question and

Speaker:

happy to share. I have always thought that compliance was cool and I will tell

Speaker:

you exactly why. I don't know how much you, are

Speaker:

kind of worried about your own data privacy, but I consider

Speaker:

myself a data privacy nut. And I've been that

Speaker:

way for many, many years. So I would

Speaker:

rather not give any of my data to companies or even

Speaker:

governments. You know that whole TSA thing now where they just scan your face?

Speaker:

I hate that. I hate that. I hate that. In today's world,

Speaker:

if you don't do that kind of stuff, you have to live as a hermit.

Speaker:

So again, I'm out there giving my data away. And I feel

Speaker:

like when the breaches started happening, do you remember the big

Speaker:

Equifax breach almost 15 years ago now? That was the

Speaker:

first big breach that caught everyone's attention and made us realize that, wait a

Speaker:

second, this data that we're just handing over is at risk. Right. And it

Speaker:

made me realize that we may not be able to

Speaker:

protect our data by not giving it, but we should really hold the

Speaker:

enterprises who have it accountable And we should help them stay secure.

Speaker:

And that was really the why behind compliance with a Y.

Speaker:

I like that because you're right. Like you— and again, we can debate

Speaker:

philosophically about, hey, that seems like a system of control where you have to live

Speaker:

as a hermit if you don't want to give away your data. But that's a

Speaker:

whole other conversation. But you're right. Like, I think the Equifax thing, I think, really

Speaker:

woke people up because, you know, I don't know

Speaker:

where your thinking was before that versus post that, but

Speaker:

I would imagine that if you were passionate about privacy, anyone who was passionate about

Speaker:

privacy and awareness about what's going on there probably seemed a

Speaker:

little cuckoo before that breach. And then afterwards,

Speaker:

not as cuckoo, right? Okay. And as these breaches go on, the Target

Speaker:

breach is the one that really kind of made me go sit up and

Speaker:

realize, wait a minute now, they know what about me? You know, and I'm not

Speaker:

a regular Target shopper, but, you know, I go there often

Speaker:

enough that they clearly would have data on me. And

Speaker:

then obviously also the, the whole thing where they reverse engineered, uh, who was

Speaker:

pregnant and who wasn't based on buying patterns.

Speaker:

I know. Um, and again, like, early on I

Speaker:

probably looked a little tinfoil hatty, right? But,

Speaker:

you know, if it— if time is— I guess given enough time, even the mo—

Speaker:

most conspiracy theorists are proven not as wrong,

Speaker:

if not right, not as wrong as we thought originally.

Speaker:

I think my friends still think that I'm a bit cuckoo, to be honest, when

Speaker:

it comes to my data privacy. But it's because you have these days,

Speaker:

you know, agents going out outside their sandbox and

Speaker:

infiltrating Hugging Face. And you have— it's just

Speaker:

there's a lot of threats out there. And I think that it is really

Speaker:

important that we can, you know, we need to be able to trust the enterprises

Speaker:

who have the world's data. And so from our perspective, we

Speaker:

went at that mission from day one, and we're really proud to be

Speaker:

working with those companies every single day. How do you track—

Speaker:

now that governments and politicians are realizing that privacy matters, right?

Speaker:

We're seeing obviously the GDPR is the one that gets all the attention. But

Speaker:

in a previous role, I worked with

Speaker:

some folks in Latin America, and apparently Latin American countries have

Speaker:

not as strict as the GDPR, but it's definitely in that direction. The US is

Speaker:

more of a healthcare data is treated one way, this type of data is treated

Speaker:

another way. What do

Speaker:

you— what else is you're seeing in the world? And like, how, if you're an

Speaker:

international enterprise, this is starting to become a very

Speaker:

tricky field to navigate. Yeah, agreed.

Speaker:

So one thing just to clarify is that we really focus on the

Speaker:

security side of things. So we focus on the security

Speaker:

side of privacy, I suppose you could say, because all

Speaker:

of these privacy controls they really have, or these privacy frameworks, right?

Speaker:

They have almost 2 sides. The first side is the security side, which

Speaker:

is how do we actually keep this consumer's data

Speaker:

secure and thereby keeping it private? The other

Speaker:

side of it is the more of the pure privacy stuff, which is things

Speaker:

like how do we let them opt out? How do we let them retrieve their

Speaker:

data when they want to? Those are type sort of the how do you make

Speaker:

the experience for the consumer almost like more seamless, more in control? But

Speaker:

we really focus on the security side. How do you really lock down your environment?

Speaker:

to make sure that there's never, you know, something to be worried about,

Speaker:

right? Of course, there's always risks in every enterprise, but there's never, you know, you

Speaker:

do as much proactive preventative work as possible. And

Speaker:

that happens by keeping an eye on all of the different security controls that you

Speaker:

have across your complicated enterprise, all in one single pane of

Speaker:

glass. And that's a really hard job to do, but that is what we have

Speaker:

set out to accomplish. Oh, okay. And I think, That brings up an

Speaker:

interesting point because when you say compliance, I immediately, I live in the DC area,

Speaker:

right? So immediately I go towards the legal aspect of it. And I had a

Speaker:

previous guest, we talked about the need for a

Speaker:

chief or a digital trust officer at the C-level of a company. And my

Speaker:

kind of initial, and I do agree that it gets needed, but my first kind

Speaker:

of thought being a realist is, well, that's both technical

Speaker:

and the legal department have to get along. And I can't imagine,

Speaker:

I mean, it is implicitly cross-functional. I would say if you have a

Speaker:

chief trust officer, but those

Speaker:

people tend not to see eye to eye. I say this as someone who

Speaker:

did work in the— I spent some time in the legal department at Microsoft, which

Speaker:

was a very odd experience of being one of the few

Speaker:

technologists in a company that was a technology

Speaker:

company, but like being one of the few technologists

Speaker:

in a very large legal organization. That was a Quite kind of like, I

Speaker:

don't know if you ever watched like the old Mr. Wizard shows where he'd like,

Speaker:

or whatever the science YouTubers were, you put your hand in like

Speaker:

one hand in hot water, one hand in cold water, and then like you put

Speaker:

your, you mix them and like your brain's all confused. That was kind of like

Speaker:

what it was like working there. But so

Speaker:

what, how do you, do you,

Speaker:

are there industry standard privacy controls? Is

Speaker:

there something above and beyond that? Like, is there some kind of ISO

Speaker:

certification for it? Like, what, what does that look like? Yeah, there's many,

Speaker:

many, many controls, many certifications. Uh, we support

Speaker:

all of the out-of-the-box frameworks that you would expect, all the

Speaker:

security frameworks, some of the privacy frameworks, or all the privacy frameworks. I

Speaker:

think that, again, there's a lot of tools out there that focus on the

Speaker:

operationalization of privacy controls. So things like cookie

Speaker:

management, you know, data subject access requests.

Speaker:

We really focus on the security side. So we're really focused on saying,

Speaker:

you know, an average enterprise has about 1,100 controls

Speaker:

that they manage, security controls. And controls, of course, are just

Speaker:

commitments to things like we will put antivirus on all of our employees'

Speaker:

endpoints, we will have encryption on in transit, we will

Speaker:

XYZ, XYZ, right? Every one of those is a control. And if you

Speaker:

have 1,100 commitments that you are making from a security perspective,

Speaker:

based on what is required of you by regulation, based on what you decide that

Speaker:

you need to commit to as an organization. How do you keep track? 1,100 is

Speaker:

a lot. Right. And especially when the source of truth behind every one of those

Speaker:

1,100 controls is completely disparate. Because

Speaker:

if you're a complex enterprise, then for one control, you might have to look at

Speaker:

13 systems. You might only have to look at 2 systems, but in, you

Speaker:

know, 30 accounts across those 2. So the point is, it starts to get very

Speaker:

messy. And instead, what we do We integrate with the

Speaker:

sources of truth that send the signals for each of those controls

Speaker:

so that an enterprise can look and say, okay, I have 1,100 security

Speaker:

commitments or controls that I make every day.

Speaker:

Previously, I had to sample test those and hope that my sample testing

Speaker:

either proved compliance or pointed me to some risks that I was

Speaker:

having. Now I can actually say with

Speaker:

confidence that these 1,100 controls are operating

Speaker:

effectively as desired. And if there's an issue with one of them, I

Speaker:

can reach in, look at what's behind the curtain, fix it, come

Speaker:

back out and just make sure everything else is going okay. And that's that

Speaker:

preventative, proactive model that we strive for. Okay,

Speaker:

so how do you fix it? Is it— you fix inside that platform or is

Speaker:

that like a something else? Are you raising these awarenesses or

Speaker:

are you part of the solution too? Yeah, we're part of the solution in so

Speaker:

much that we actually give step-by-step guidance on how to address the

Speaker:

problems. Usually it's not so easy as, you know, turn it on again or something.

Speaker:

So there's something going on. And so we do do that. Actually, the

Speaker:agents we're releasing in:Speaker:

sneak peek. I will— I'll leave that for next year. Yeah, and I

Speaker:

would imagine that you're probably already being asked, how do you make sure your agents

Speaker:

are compliant with— because we're hearing all over the news about

Speaker:

agents breaking their container and things like that. And I have

Speaker:

a— I just installed actually this week, I've had OpenCLAW running for a couple months

Speaker:

and I installed Hermes and I'm impressed with its tenacity.

Speaker:

Actually, both of them, but more Hermes than that. And I know really has more

Speaker:

to do with the underlying model than, than the harness. But like, how do you—

Speaker:

the tenacity, I think, is both admirable and a little dangerous because I've

Speaker:

seen it. I've asked it to—

Speaker:

we were looking at moving and I asked it to research a property and it

Speaker:

was red. One site blocked it, but then it found another

Speaker:

way to like send a proxy to that site. And I'm kind of like— sipping

Speaker:

my coffee, watching it work, like, seems a little—

Speaker:

I wouldn't say shady, but it's definitely

Speaker:

questionable. I should probably give it guardrails, like, as I see it kind of go

Speaker:

off. And to me, as a developer, AI builder,

Speaker:

AI engineer, I just made a simple request. I didn't

Speaker:

think I would have to tell it not to break the law or do anything

Speaker:

kind of questionably ethically, like screen scrape or anything like

Speaker:

that. But I would imagine that's given your background and passion for

Speaker:

compliance is probably top of mind. Like, how do you make sure your

Speaker:

bots behave? Yeah, it's a big topic.

Speaker:

Gosh, our CTO could talk about this for hours, but I think the,

Speaker:

the top line is that we

Speaker:

feel like we get to be on the good side of AI these

Speaker:

days. It almost feels like a lot of AI products

Speaker:

and a lot of AI use cases are quite scary,

Speaker:

have a lot of potential for bad. Our AI agents'

Speaker:

missions are to stay compliant. And so it becomes a

Speaker:

little bit of the nature of the task is also

Speaker:

quite sound. And I think that actually helps quite a

Speaker:

lot, right? There's, there is just that fact. We've put in

Speaker:

guardrails at the development layer so that the agents basically have really,

Speaker:

really small jobs, each of them. And there's kind of checks and

Speaker:

balances on each of the agents. And each of them have such a small

Speaker:

purview that you actually kind of seek protection in that as well.

Speaker:

There's another And there's a number of other things that we've done from a more

Speaker:

technical perspective. But to be honest with you, we've, we've been lucky to

Speaker:

find that obviously with all the controls that we've put in place on our own

Speaker:

agents, we've seen really good results both from a security, privacy,

Speaker:

as well as just efficacy perspective. Security in depth

Speaker:

seems to be the answer to a lot of things, right? Yes, layered security,

Speaker:

whether it's the locked door, the alarm system, you know,

Speaker:

the spiky bushes outside the windows, right? Security is

Speaker:

not a one and done. It's a multi-phase approach.

Speaker:

And I would imagine compliance probably

Speaker:

not the same, but pretty close to that, right? I mean, what,

Speaker:

what does— who's your ideal customer? Like, is it the CTO? Is

Speaker:

it the legal department? Is it some combination? Is it the—

Speaker:

I know some companies now have chief privacy officers. Sorry, I cut you off.

Speaker:

But like, who is this? It's the CISO, actually. So the

Speaker:

Chief Information Security Officer is usually our target, kind of

Speaker:

target buyer. Obviously, usually reporting to them, they have some sort

Speaker:

of Director of GRC or Governance, Risk, and Compliance. And so that's

Speaker:

actually a perfect buyer for us, or a VP of Information Security. And

Speaker:

so typically, again, these folks are sitting in partnership with

Speaker:

the legal team or the privacy team. They are doing the protection

Speaker:

of customers' data, and the privacy folks and legal folks are doing,

Speaker:

I know, something slightly different, like making sure that they're meeting the privacy

Speaker:

regulation in terms of data subject access or other things like

Speaker:

that. And these CISOs and their teams are really focused on how do we

Speaker:

protect, how do we stay proactive. And that's really what we do. We give

Speaker:

them the avenue to monitor their controls live, to

Speaker:

basically get a continuous monitoring across their entire

Speaker:

environment and tell them when something's astray, and then they can

Speaker:

go in and proactively address it. And that is That means a lot for them.

Speaker:

Interesting. Yeah. Is this something that smaller, mid-sized

Speaker:

companies also need to like think about too? Like, or are you targeting the global

Speaker:

2,000? Or, I mean, everybody, privacy becomes

Speaker:

everybody's business. Yeah, it really does these days. And especially

Speaker:

now, I mean, really, like it is, we're seeing everyone's focus

Speaker:

be more and more on AI governance, on AI security, on information

Speaker:

security in general. What we have found is it's quite industry-specific. So

Speaker:

I think that we serve a lot of the companies that, of

Speaker:

course, you know, if they get breached, there are serious consequences. So healthcare is

Speaker:

probably our biggest industry, and we have a lot of healthcare clients that are

Speaker:

also mid-market because they obviously have to protect patient

Speaker:

data, and that is such sensitive data, and they're really just like

Speaker:

quite prone to be, to be hacked or breached because, you know, people are

Speaker:

attacking them. And so from our perspective, that's been historically one of

Speaker:

kind of the best, best industries for us to really

Speaker:

work with because they care. And we really like to work with the people who

Speaker:

care. Well, that, that's a good point because I think you probably can

Speaker:

tell right away of who has a metaphorical gun to

Speaker:

their head versus actually care about privacy, right? Exactly.

Speaker:

You really can. And healthcare is interesting because

Speaker:

implicitly you have to share the data, right? Like, you know, my insurance company has

Speaker:

to know what my X-ray does. the X-ray

Speaker:

or imaging center has to send the report back to the doctor, right? So it's

Speaker:

a very data-centric business. Yeah. But

Speaker:

obviously we've heard horror stories about local

Speaker:

hospitals, smaller hospitals being ransomwared. And I know strictly

Speaker:

speaking compliance is not protection against

Speaker:

ransomware directly, but I would imagine there's probably some

Speaker:

kind of side effect that would, if they are compliant, they

Speaker:

probably would be less susceptible

Speaker:

to ransomware. Yeah, exactly. And I mean, again, of course,

Speaker:

you— we don't like to breed breach shame, as we say, but I

Speaker:

think the reality is that a lot of the breaches that have

Speaker:

happened in the last 15 years are preventable.

Speaker:

And they're from, you know, they're a mixture of certain

Speaker:

configurations not being on. And then there's just security training.

Speaker:

And I think that part of it is that a lot of security professionals are

Speaker:

so busy doing what's urgent that they don't have

Speaker:

time for what's important. And oftentimes really good security

Speaker:

training for the wider organization falls into the important but not

Speaker:

urgent. Right. And so what happens is that they don't have capacity for it. And

Speaker:

one of the things that I like to tell people is like, look, your biggest

Speaker:

liability is actually the rest of your organization. Like those, those social

Speaker:

engineering emails are getting really good. And you need to be able to train them.

Speaker:

And they're like, we don't have time for that. That's not even on the radar

Speaker:

of things we need to accomplish. It's like, okay, well, our AI agents do a

Speaker:

lot of your manual work for you so that you have time to focus on

Speaker:

what's important. And that honestly makes a really big difference.

Speaker:

Well, it's kind of like fire safety training, right? Like, why do firefighters go to

Speaker:

schools and stuff like that and talk to kids about smoke alarms and stuff? It's

Speaker:

because they are literally fighting fires, right? And

Speaker:

that's obviously a good example. But like, I think it's— I think we— I think

Speaker:

the IT security field can learn a lot from public

Speaker:

safety in terms of the PSAs and like the community work that

Speaker:

they do and teaching this type of safety because they clearly deal

Speaker:

with urgent literal life and death issues, but they also take time out

Speaker:

to realize like slowing down the pipeline

Speaker:

by educating kind of the masses goes a long way

Speaker:

to hopefully make it easier. I don't mean

Speaker:

I don't know how I don't know if they track metrics that you know. firefighter

Speaker:

Joe and Sally, they did a thing in this

Speaker:

elementary school and, you know, house fires went down by 10%. I don't know if

Speaker:

they track it to that degree, although that would be an interesting privacy, I guess,

Speaker:

case right there. Right. But, um, but yeah, like how does that—

Speaker:

and, and, and the Target breach, for example, was

Speaker:

credentials that should have expired for, I think from an HVAC

Speaker:

company, like something like really mundane. Yeah. And

Speaker:

it's the mundane stuff. Yeah, it's always the mundane stuff. But I mean,

Speaker:

again, user access reviews can be automatically checked in our platform. So it's things like

Speaker:

that which we can really easily automate. And so those breaches actually

Speaker:

get prevented and it's just kind of, yeah, it's kind of crazy,

Speaker:

honestly. And just going back to the fire alarm example, it would be like if

Speaker:

your fire alarm, you know, randomly went off and you had to

Speaker:

have enough knowledge to know when it was real and when it was fake. That's

Speaker:

the example, making it a like for like with social engineering. Sometimes we get these

Speaker:

emails, we don't know if it's real or fake. So we have to suddenly become—

Speaker:

all of us have to become cybersecurity experts to know, you know, is

Speaker:

this real? Do I need to be worried about this? And that's why you're seeing,

Speaker:

you know, I worry about my parents and them falling for a scam sometime

Speaker:

because, yeah, it's just crazy. It's crazy what you have to know these days.

Speaker:

And so, yeah, it's— You have to have like street smarts about you

Speaker:

just because the internet is as far away as your phone.

Speaker:

Yeah, exactly. Interesting.

Speaker:

One of the things that I would say

Speaker:

that sounded crazy when I said it originally

Speaker:

was like the front line of the next conflict is as far away as your

Speaker:

phone. And like we're seeing kind of like cyberspace is

Speaker:

an active kind of, even if there is no, what

Speaker:

the cool kids in DC call kinetic warfare going on, it is still very

Speaker:

much an open field in the cyber realm. So you really have to,

Speaker:

you really have to be very mindful of your phone is a connection

Speaker:

to the world, but it's also the world's connection to you.

Speaker:

Yeah. And sometimes, sometimes the world does not have

Speaker:

your best interests, right? Or there's going to be bad actors in it. Agreed. It's

Speaker:

very scary, actually. It's

Speaker:

interesting how you're seeing a lot of kids opt into the older style

Speaker:

clamshell phones or flip phones. It's kind of like that's

Speaker:

the new retro is going back. I'm thinking of

Speaker:

it myself, to be honest. Maybe keeping like an iPod Touch

Speaker:

with me for other stuff. But honestly, it's like, yeah, I

Speaker:

get it. I don't think we all want to be reached so much anymore either.

Speaker:

Right. It was— it had a certain appeal back in the day, but now that

Speaker:

we've gotten it, it's be careful what you wish for. Totally agree.

Speaker:

So what

Speaker:

What do you— so you mentioned something, you talk about the, your smoke alarm going

Speaker:

off or your fire alarm going off all the time. I worry about that because

Speaker:

I think alarm fatigue is very real or dialogue fatigue, right? How many times you

Speaker:

go to a site and it says, hey, we have cookies.

Speaker:

Like, I'm a cookie— Always reject them. Always reject them. Even if it

Speaker:

has an extra screen you have to click through, just do it. It's worth it.

Speaker:

It's worth it. Protect your data. Okay. I

Speaker:

always choose, um, except necessary only. Is that

Speaker:

not safe enough? No, that's the only one that you can really do in the

Speaker:

US, so that's fine. But, uh, even if it makes you click through a

Speaker:

screen to validate it, go through it. Sure.

Speaker:

Toggle things off and yeah, just don't give them your cookies.

Speaker:

Yeah. I know I saw something very disturbing is a,

Speaker:

um, there's a YouTube video. I haven't verified it, but, um, smart TVs

Speaker:

Yes. Are also notorious. They

Speaker:

actually will report back what it

Speaker:

sees on the screen. And they're probably

Speaker:

listening as well, to be honest. I think this is the reality of our phones

Speaker:

these days. There's a lot of, a lot of sneaky apps in

Speaker:

there. We carry our phone with us all the time. There's a lot of sneaky

Speaker:

apps in there that are listening. And they say that it's for, you know, accurate

Speaker:

advertising or whatever, but they're literally listening. It's crazy. That's why when you

Speaker:

talk about something, all of a sudden you get an ad about it. Yeah, I've

Speaker:

noticed that too. And it's fascinating

Speaker:

that those stories are so anecdotally well known

Speaker:

or come across so often, like there has to be a grain of truth to

Speaker:

it. No, it is true. Yeah. Yeah.

Speaker:

I mean, it's just— and it was one of the major TV manufacturers did get

Speaker:

caught listening in on people's conversations because I think the remote control had a

Speaker:

voice-activated feature or something like that, and I saw that

Speaker:

and I was like, uh, I don't know if I want that. You know, I

Speaker:

think our fridges are gonna start too. That's the whole smart fridge thing. Crazy.

Speaker:

I, um, I— my fridge was like, hey, connect

Speaker:

me to the internet, I'll do this. No thank you,

Speaker:

I'm good. I don't need that.

Speaker:

Well, there's a meme going around, it's like, you know, IT people tend

Speaker:

not to have automated homes, right? Exactly, because we know the

Speaker:

risks. We know the risk. Yeah, yeah. I mean, the only thing that I would

Speaker:

want in terms of automation is to know

Speaker:

if a door is left open. Yeah, great. You know, just because I got

Speaker:

dogs and— And be able to monitor the temperature from far away,

Speaker:

so in case your pipes freeze. That's another good one. Right, right. Or water

Speaker:

sensor. Or water sensor. Yeah, exactly. Like basic safety stuff.

Speaker:

For the temperature thing, I actually have a little robot over there with it I

Speaker:

can tilt and it shows me that this is within view of it.

Speaker:

Kind of analog, but again, because even then, like,

Speaker:

you know, I, I have these thoughts and I'm like, oh, maybe I'm paranoid, right?

Speaker:

You see these IoT sensors, right? And you've probably heard this

Speaker:

joke, the S in IoT stands for security. And

Speaker:

you know, all these smart devices and you hear about these breaches, even if

Speaker:

the manufacturer had the most noble intentions, right?

Speaker:

You are putting data, whether it's your heart rate data, if it's a smartwatch,

Speaker:

in the hands of somebody who their priorities

Speaker:

was getting to market, not necessarily— Yeah.

Speaker:

Security. Agreed. There's a lot of health tech

Speaker:

companies where when they've gone out of business now, you notice that they

Speaker:

can sell the data. Of the companies, and that is really

Speaker:

scary— of the consumers, sorry. That's really scary. So there's just basically

Speaker:

health tech companies out there who even, you know, even if they put a bunch

Speaker:

of— let's say they have the best of intentions and they put a bunch of

Speaker:

privacy and security things. Right. Well, when things go under and they don't do

Speaker:

so well, they can literally sell that data. It's a— it's an asset,

Speaker:

and they can sell that data as part of their, you know, closing down of

Speaker:

the company. That is crazy to think about. And that's— even— yeah, I'm

Speaker:

sorry, go ahead. Didn't mean to cut you off. Even if, even if during the

Speaker:

process of closing down, they may have the best of intentions, but their

Speaker:

creditors will be like, I don't care about these people's privacy, right? Even,

Speaker:

even if someone's the most noble person in the world. And, um,

Speaker:

I'm glad you mentioned that because— and if we're getting off too far off topic,

Speaker:

let me know, because if you listen to the show, Andy and I are known

Speaker:

to do that. But Spirit Airlines in the US? Yeah, that's right.

Speaker:

They sold the Customer data. Yeah. Or part of it at least. Yeah.

Speaker:

Well, not just the customer data, but also the private emails. I think

Speaker:

either Meta or Google was trying to buy it. So they, all the private emails

Speaker:

in there. Now I think somebody, one of the, I think the flight

Speaker:

attendant unions or somebody, one of the unions is assuming like, no,

Speaker:

these are private conversations. But it's interesting. Like it's just kind of

Speaker:

like, who would think when a company goes

Speaker:

under, like you expect like the desks and the chairs and stuff like that to

Speaker:

be kind of auctioned off. But you know, the emails, the data, I mean, that's

Speaker:

Just not something I think the average person would've thought

Speaker:

about. Agreed.

Speaker:

So what can people do

Speaker:

to, to do a better job of securing their privacy, right?

Speaker:

Individuals? Individuals, right? Like if you're an individual, if you're somebody

Speaker:

listening to this, and a lot of our listeners are data engineers or data

Speaker:

scientists and, or AI engineers.

Speaker:

they're probably more aware than your average bear. And that

Speaker:

rhymes. Maybe we'll put it on a t-shirt. But, um,

Speaker:

what can people do, right? I mean, obviously you reject the cookies that you can.

Speaker:

Yep. You— but there's got to be

Speaker:

more, right? I've seen ads for DeleteMe,

Speaker:

I think, is it? And there's a couple of firms that kind of offer that.

Speaker:

But I mean, are services

Speaker:

like that Valuable, right? You know.

Speaker:

The problem is that your data is constantly being actually taken from

Speaker:

you and being put back in. So even when you are doing some of those

Speaker:

things, you, you're living your life on one side and then you're

Speaker:

continuously giving your data back in to the, to the

Speaker:

ether. There's— it's really challenging. I do think that over time you can

Speaker:

chip away at it. I really do think that simple things that you can do

Speaker:

is, you know, just being conscious about it. So things like rejecting

Speaker:

cookies, things like making sure that you're not signing up for extraneous

Speaker:

things. There's also a setting on your phone. Let me pull out my phone so

Speaker:

I can get the clicks right. So you can go to your phone and if

Speaker:

you go to your settings, I have an iPhone. If you go to your

Speaker:

settings and then you go to, if you search

Speaker:

privacy. Yep. So you get a privacy and security option.

Speaker:

See if it's here. Yep. And you scroll down and you find microphone.

Speaker:

And it should have a list of all of your apps that have access to

Speaker:

your microphone. And you can go in and like turn off a lot of

Speaker:

microphone access because there's a lot of apps in there. I don't think Uber needs

Speaker:

access to your microphone. I don't think LinkedIn needs access to my microphone. So

Speaker:

there's things like that. And that actually prevents some of the listening that's happening

Speaker:

under the guise of like, oh, better targeting of ads and stuff like that. And

Speaker:

the same thing with the camera. And over months, sometimes

Speaker:

more than months, you start to notice that the algorithm actually doesn't

Speaker:

have you not locked down as much. which actually is kind of a proof

Speaker:

point of you protecting your privacy and your personal data a little bit more.

Speaker:

Of course, there's a lot more you can do from the perspective of just like,

Speaker:

as simple as it sounds, like having better passwords, not, you know, using different— I

Speaker:

mean, all of those are basic things, but this is a little extra tip that

Speaker:

I usually tell my friends and family. Oh, that's good to know. I was looking

Speaker:

through the Android settings earlier this week for a different reason, and I

Speaker:

noticed like, hey, there are a lot of apps in here that want access to

Speaker:

the camera. I don't remember authorizing that. Yeah, usually it

Speaker:

gets authorized at the beginning. So yeah, exactly. And you can always turn it on

Speaker:

again if you need it, but I just— right, all of mine are off.

Speaker:

No, that's a good point. And, and, um, I find it fascinating that the only

Speaker:

way you can kind of like proof it, prove it, is you wait

Speaker:

a few months and see, do they have you now on lockdown? It's like

Speaker:

naive. You're like, wait, we don't have any visibility into this? And then I'm like,

Speaker:

oh yeah, we don't have any visibility into this. Like, it's crazy. Even with the

Speaker:

GDPR and things like that, you don't really have that. And I'm glad you

Speaker:

mentioned Apple because Apple really doubled down on privacy as a

Speaker:

feature. You know, I have an Android phone and God only knows what

Speaker:

goes on under the hood on that one, right? It's pretty good.

Speaker:

I don't know. I should probably do some more research on it, but. It depends

Speaker:

on the vendor because the beauty of open source is,

Speaker:

you know, anyone can modify it. The horror of open source is

Speaker:

Anyone can modify it, right? Apple does do a better job of

Speaker:

locking things down, but even then it's not, I mean, you hear stories about

Speaker:

there's companies that will, you know, break in iPhones. I know Apple took

Speaker:

a pretty big stand when, uh, I think the FBI or

Speaker:

one of the US federal government basically said, you need to create a patch

Speaker:

for this, for the iPhone so we can break into this guy's phone. And they

Speaker:

refused. And they were taken to court. And then one day they

Speaker:

just, the government dropped the case quietly. And you're like, hmm,

Speaker:

oh, there's a startup out of this country that has a tool that breaks

Speaker:

iPhones, right? So it's, um, it's interesting because as convenient as

Speaker:

these devices are, they have a lot of information on us.

Speaker:

And even if everything is done right, if you have an

Speaker:

advanced persistent threat that's

Speaker:

well-funded like a nation-state, not really much you can do,

Speaker:

right? Aside from moving to a cabin in the woods, right? Mm-hmm. Exactly.

Speaker:

Full circle back to the beginning of the conversation. Right. Unless you wanna be a

Speaker:

hermit. It's just a, it's a fascinating and terrifying world,

Speaker:

I think. But back to like the business angle of it, what,

Speaker:

you know, we saw Apple really pivot to privacy at Union

Speaker:

Station in DC. There was a huge ad I remember seeing that was,

Speaker:

had the Apple, you know, Safari private by default. Right now the browsers

Speaker:

are starting to do this. Yeah. With, in terms of alerting you about these super

Speaker:

cookies and things like that. So it seems like privacy, if

Speaker:

not now, in the near future could be a business strategy,

Speaker:

right? We're seeing Apple kind of use that to good effect. What do you

Speaker:

think that people will finally seek out

Speaker:

compliance solutions because like, hey, we're

Speaker:

compliant, right? That becomes something they can put on their brochures?

Speaker:

Yeah, I think so. And I think you're already seeing that. So obviously there's this

Speaker:

big push around SOC 2 compliance, which, you know, really matters.

Speaker:

We usually serve B2B companies because B2B companies, you know, to have

Speaker:

to serve a B2B customer, you have to have some proof of compliance. So there

Speaker:

is already that mentality. And I think the question is, will that bleed into

Speaker:

B2C? Honestly, I think most B2C companies now also seek those types

Speaker:

of compliance certifications because to them, it's peace of mind, as

Speaker:

it is for founders, for others. Like, it really is peace of mind. And

Speaker:

I think it is surprising how much that can— how much peace of mind it

Speaker:

can get you. Getting an external assessment, getting an external pen test,

Speaker:

getting external SOC 2 or ISO, there is something about it if,

Speaker:

especially if it's a good auditor, that really makes you feel like, okay, amazing. Like,

Speaker:

I do at least have some type of check on this. And yeah, and it

Speaker:

matters. And much of those things are also about incident response and business

Speaker:

continuity in the event of a disaster. Right. And so it's not all about

Speaker:

preventative. It's also about preparing you if something is to happen.

Speaker:

And so there's peace of mind that also comes from that, from actually having good

Speaker:

processes in place if the you know, the worst is to happen and you'd

Speaker:

get breached. And that's also just good to know.

Speaker:

So all of that, I think, is, you know, it's just part of the— part

Speaker:

of how I think the industry is maturing, part of how we're all learning.

Speaker:

And I'm really glad that it's headed that way. No, I mean, that makes a

Speaker:

lot of sense in terms of— I would imagine

Speaker:

companies that have cyber

Speaker:

risk insurance, probably the insurance companies are going to wise up

Speaker:

and start demanding better paper trails of

Speaker:

like what's going on, right? Because if you don't know, you don't know, right? And

Speaker:

if you don't know, you don't know to fix it, right? So

Speaker:

just even, I think I would encourage everyone to at least do one of these

Speaker:

audits because then, you know, then you know

Speaker:

what the risk profile is, right? Maybe, maybe you have a high-risk profile.

Speaker:

Maybe it's better than you think. Probably not, but maybe it's better than you think.

Speaker:

Exactly. And then you at least have a list of things to

Speaker:

work on, right? Yep. I think in the virtual green room, we, we both mentioned

Speaker:

moving, but it's like getting a home inspection, right? You wanna make sure that, hey,

Speaker:

the foundation's okay. Or, you know, you're worried about this leak in

Speaker:

this room and it's like, ah, it turns out to be nothing, right? It's, um,

Speaker:

it's, um, it's, it, it's interesting. And I, I

Speaker:

find it fascinating that, um,

Speaker:

we are in that phase of why are we—

Speaker:

why is compliance making, if not a comeback, like, like it's

Speaker:

finally becoming in vogue. And it's because compliance touches a lot of things

Speaker:

that touch a lot of our lives. Yeah. Whether it's straight up security,

Speaker:

privacy, right? And everyone, I think, has a slightly different definition of what

Speaker:

privacy is, right? One of the funniest things in, uh,

Speaker:

one of the GTA games, I think it was 5.

Speaker:

They, they don't mention Facebook by name, but the site is called

Speaker:

Privacy Invader, which is, um, they certainly, um,

Speaker:

social commentary is a big part of the game as much as carjackings and

Speaker:

things like that. Uh, I don't know if you've ever played it, but like, if

Speaker:

you, even if you just like listen to the radio stations on there, the social

Speaker:

commentary is pretty biting. And, um, But,

Speaker:

um, I, I just think it's fascinating

Speaker:

that we all have to think about this, right?

Speaker:

And you mentioned your parents, you know, my mom would fall for things. And

Speaker:

even though, like, you know, eventually I gave her a lockdown

Speaker:

Linux laptop because

Speaker:

she would get a lot of scam calls. Yeah. And it's

Speaker:

really, you know, it's really a malware thing that happens. Well, and,

Speaker:

and they're getting better at it. Like they're cloning voices. Really sad. Doing— I

Speaker:

know. It's just really upsetting. And you think like, you know, the

Speaker:

human capacity for creativity, you have to step back and admire it

Speaker:

if it was only focused on something non-destructive.

Speaker:

Yeah, I know. It's really upsetting. I mean, and it, it really is. And it's

Speaker:

kind of like I would get these calls too. And

Speaker:

I'm like, I kind of know. I, one of the common themes when I worked

Speaker:

for Microsoft was people would, mess with the scammers

Speaker:

because they say, hey, I'm calling from Microsoft. Really? What building are you in?

Speaker:

Really? What org are you in? Like, where are you in the GAL? I was

Speaker:

like, I'm sorry, sir, I don't know what the GAL is. Well, if you don't

Speaker:

know what the GAL is, you don't work here. And for those who don't know,

Speaker:

GAL is Global Address List. It's basically the, um, the thing that Outlook was

Speaker:

hooked up to. So if somebody said they work for Microsoft, you would

Speaker:

ask them that or what their alias was. But no, I think, I think we

Speaker:

all have to be street smart. Even if you—

Speaker:

because I think humans are really

Speaker:

good to adapting to their environment generally,

Speaker:

right? Someone who grew up in

Speaker:

Staten Island is going to be a bit more street smart than someone who grew

Speaker:

up on a remote desert island, right, where everybody knows each other,

Speaker:

right? That's an adaptation. But

Speaker:

there are no remote desert islands anymore. Yeah. Your

Speaker:

phone, your watch, I mean, everything, your fridge. My God, your fridge

Speaker:

is spying on you or could be spying on you. Like, what sort of weird

Speaker:

cyberpunk dystopia have we found ourselves in? Right? I often

Speaker:

wonder that. Like, you know, we don't even have the flying

Speaker:

cars like they did in Blade Runner, you know?

Speaker:

But, you know, here we are in this kind of this something that I think

Speaker:

even Orwell would be like, Dude, if, if you would write about it, he goes,

Speaker:

nah, that's not believable. People willingly bring in like these devices that

Speaker:

listen to everything they say. They wait and they carry it around with them. Come

Speaker:

on. No one would believe that. Right. Yet truth turned

Speaker:

out way stranger than fiction. Right. And I'm not, I say

Speaker:

this, I feel like I'm a hypocrite because I have a couple of, I don't

Speaker:

wanna say her name cuz she'll wake up. Yeah. I have

Speaker:

Amazon Echos, right? I have a couple Amazon Echos and I

Speaker:

eventually will get rid of them,

Speaker:

but I certainly don't have a Ring camera. Right.

Speaker:

And now that we're on the topic of cameras, and I know we're coming close

Speaker:

to our time here, what— I don't know if you've been tracking this, but

Speaker:

there's been a big pushback in the US against flock cameras. Yeah.

Speaker:

I think that's interesting. Do you think this will be the moment we look back

Speaker:

on and people realize, We kind of already live in a surveillance

Speaker:

state. Yeah, it's a tough one. I think

Speaker:

that these types of things are all adding up in a moment where AI is

Speaker:

becoming kind of an avenue that makes everybody understand what

Speaker:

cybersecurity means. I think that honestly, cybersecurity has been

Speaker:

such a, uh, techie word and phrase

Speaker:

and concept for so long. And so people didn't really have something that they

Speaker:

understood, you know, other than the breaches if it affected you maybe. But even

Speaker:

then, there was a lot of just, you know, okay, it is what it is.

Speaker:

Like, well, what you gonna do? My information's already out there. I think that when—

Speaker:

I think that a flock camera is— of course, I mean, it's also like you're—

Speaker:

it's literally filming you. So I think that it would have probably been a big

Speaker:

deal regardless. But I think that it's just adding up and adding up on top

Speaker:

of everything that's going on. And people just are quite anti-AI right now

Speaker:

in a way of saying, you know, they're anti-data centers, they're anti-that type of

Speaker:

thing. Everyone just kind of wants that control back. I feel it too. You know,

Speaker:

we used to live in a simpler world. And AI innovation is amazing for

Speaker:

so many things. And again, I think we've— I feel really lucky

Speaker:

because I get to be on the good side of AI. We get to use

Speaker:

AI innovation to keep companies secure. That is an excellent

Speaker:

reason to use it. And there's a lot of reasons that I don't really know

Speaker:

if it's worth the gallons of water that it's using. And so,

Speaker:

right, that's— I think that's kind of to each their own. But anyway, I know

Speaker:

we're at time, but I just wanted to— No, no, no, no. I mean, it's—

Speaker:

I think it's interesting. I think more people need to have these conversations. And you're

Speaker:

right, people, they hear cybersecurity. My wife works in that field and

Speaker:

she worked in it way before it was cool. And

Speaker:

it's one of those things where no

Speaker:

one wants to get a report from security. That's

Speaker:

kind of the mentality. Like no one wants to talk to anyone in security, whether

Speaker:

it's physical security or whatever, but

Speaker:

they're there to protect you, right? Like save you from yourself. I don't know. I

Speaker:

think it's interesting because I think people have to wake up and

Speaker:

realize, like, there is no remote place on Earth anymore, right?

Speaker:

You can get an internet signal pretty much anywhere on the

Speaker:

planet, right? Um,

Speaker:

and if you are within reach of a cell tower, then you are

Speaker:

within reach of, you know, the machine. And

Speaker:

I think maybe we're going to realize, I think slowly

Speaker:

people, the way people are pushing back against AI, The way people are

Speaker:

pushing back against the surveillance cameras and things like that. I

Speaker:

don't think people realize, the general public didn't realize that AI

Speaker:

basically gives you a kind of intelligence that's not just smart,

Speaker:

but a plate reader, a

Speaker:

human plate reader can only do but so much. You can only

Speaker:

hire but so many human license plate readers, but you

Speaker:

have this one kind of I don't want to say mind or

Speaker:

consciousness because that, that's a loaded word, but there's one system that

Speaker:

can act like it's watching you everywhere, right? It

Speaker:

gets to a very— was this Foucault? One of the— there was a French philosopher

Speaker:

that talked about this, and they designed a prison

Speaker:

where everything could be seen from like one central point. Yeah. And it

Speaker:

freaked people out. And it was like, I think they've banned the

Speaker:

use of, or that design, but But I don't know, I think we kind of

Speaker:

like walked into it and kind of we were sold convenience

Speaker:

and in a deal with the devil almost like our

Speaker:

convenience for privacy. It's interesting. Yeah. So,

Speaker:

ending on not such a positive note, I think what you're doing is important because

Speaker:

I think it makes people aware

Speaker:

at the C-suite level more and more about their privacy,

Speaker:

what their security should be. And it sounds like you make it easy, right? It

Speaker:

sounds like you make it— We do. A dashboardy experience.

Speaker:

That's what it should be. And I think you— and

Speaker:

if you have your agents coming out soon, which you don't want to talk about,

Speaker:

I understand, you know, you can actually— oh, go ahead. We have

Speaker:

21 agents already live that are doing a lot of monitoring. And yeah, so this

Speaker:

is just the next wave of agents on the remediation

Speaker:

side. But yeah, we have a wide range, wide array of

Speaker:nts that we've had live since:Speaker:

curve on that front. Fortune 500 companies use our AI agents every day

Speaker:

to stay secure, monitor third-party risk, monitor their own

Speaker:

risk. Yeah, it's good stuff. Very cool. Well, awesome. Where can folks find out

Speaker:

more about you and Compliance? Yeah, compliance.com.

Speaker:

Easy enough. Compliance.com. With a Y? With a Y. Compliance with a Y dot

Speaker:

com. Exactly. And that's where you can find us. Awesome.

Speaker:

Awesome. Well, thank you for your time and really enjoyed our conversation.

Speaker:

And if your CTO wants to come and Geek out for a couple hours, let

Speaker:

me know. We'd love to have that because I think I think as

Speaker:

agents become more and more capable, I think

Speaker:

conversations like this are going to be even more important. I mean, they're

Speaker:

important today, but I think once you give these

Speaker:

things that have no

Speaker:

ethical constraints,

Speaker:

have no conscience. so to speak, and have

Speaker:

no fear of being— even the most

Speaker:

worst person you can think of

Speaker:

had some kind of concern about being

Speaker:

caught, captured, and punished for their crimes. I don't think

Speaker:

AI has that, right? And we've seen the

Speaker:

horrible things humans can do, right? And that's with, quote unquote, a

Speaker:

conscience. of some sort, whether it's broken or not is another question,

Speaker:

right? So you could just imagine what a machine could do with

Speaker:

that kind of thing. So again, another positive note to end on, but

Speaker:

not everything ends like a good Disney movie. With that in mind, I'll let the

Speaker:

outro play. Thanks again to Rich Akowal for joining

Speaker:

us and breaking down the evolving world of AI, privacy,

Speaker:

security, and compliance. If you enjoyed the

Speaker:

conversation, be sure to subscribe, share the episode, and join us next

Speaker:

time on Data Driven.