How Compliance Became Cool: Richa Kaul on Security, Privacy, and AI
Welcome back to “Data Driven,” the podcast where we explore the cutting edge of data science, AI, and the rapidly evolving world of data governance.
In this episode, we sit down with Richa Kaul, founder and CEO of Complyance, an AI-driven platform transforming governance, risk, and compliance for enterprises. Drawing on her experience as a data privacy enthusiast and leader in the compliance space, Richa Kaul dives into the pressing challenges of securing sensitive data, the complexities of global compliance frameworks, and how AI both complicates and protects our interconnected world.
We discuss the pivotal role of the Chief Information Security Officer, the importance of proactive, layered security measures, and why compliance is rapidly gaining attention—not just as a regulatory checkbox, but as a central business strategy. With practical advice for both enterprises and individuals on maintaining digital privacy and security, this episode is essential listening for anyone navigating today’s high-stakes data landscape.
Links
- Richa on LinkedIn –https://www.linkedin.com/in/richa-kaul/
- Complyance Web site –https://www.complyance.com/
- Complyance on LinkedIn –https://linkedin.com/company/complyancehq/
- Watch on YouTube –https://www.youtube.com/watch?v=CFsUcm5u4MY
Timestamped overview
00:00 Privacy and security frameworks overview
03:54 Impact of Equifax data breach
06:21 Focusing on data security
09:58 Managing complex enterprise security controls
15:53 Focus on AI and information security
18:37 Learning from Fire Safety Education
20:47 Phone security in modern cyber warfare
24:48 Concerns about IoT device security
29:10 Protecting Privacy from Algorithms
30:44 Security and privacy concerns
35:23 GTA’s social commentary on privacy
39:11 AI’s Role in Cybersecurity Awareness
41:03 Global connectivity and surveillance issues
44:47 Ending on a positive note
Transcript
Because all of these privacy controls, they really have— or these privacy
Speaker:frameworks, right? They have almost 2 sides. The first side
Speaker:is the security side, which is how do we actually keep this
Speaker:consumer's data secure and thereby keeping it private?
Speaker:The other side of it is more of the pure privacy stuff, which is
Speaker:things like how do we let them opt out? How do we let them retrieve
Speaker:their data when they want to? Those are sort of the— how do you make
Speaker:the experience for the consumer almost like more seamless, more in control? But
Speaker:we really focus on the security side. How do you really lock down your environment
Speaker:to make sure that there's never, you know, something to be worried about,
Speaker:right? Of course, there's always risks in every enterprise, but there's never, you know, you
Speaker:do as much proactive preventative work as possible. And
Speaker:that happens by keeping an eye on all of the different security controls that you
Speaker:have across your complicated enterprise, all in one single pane of
Speaker:glass. And that's a really hard job to do, but that is what we have
Speaker:set out to accomplish. Your biggest security risk may be
Speaker:closer than you think. Rich Akall reveals how AI,
Speaker:privacy, and smarter compliance are changing the way companies protect
Speaker:data.
Speaker:Hello and welcome back to Data Driven, the podcast where we explore the emerging industry
Speaker:of data science, AI, and of course, it's all not
Speaker:possible without data engineering. And unfortunately, my favorite data engineer
Speaker:in the world, Andy Leonard, can't make it today, but I am here today with
Speaker:Richa Kaul, who is the founder of and
Speaker:CEO of Komplianz, an AI-driven platform
Speaker:transforming governance, risk, and compliance for enterprises.
Speaker:Previously, she held leadership roles at ContractPal AI, where she scaled
Speaker:global compliance solutions. I'm noticing a theme here. Under her leadership,
Speaker:Komplianz has raised $30 million in total funding, driving
Speaker:rapid growth and the development of multiple new AI agents.
Speaker:Richa's expertise— Richa expertise, because she's going to be richer than
Speaker:Bill Gates, as we said in the virtual green room. Your
Speaker:expertise has been featured in Authority Magazine, GRC
Speaker:Pod, and several leading industry
Speaker:podcasts. So welcome to the show, Richa. And I was
Speaker:going to say, we joked around in the virtual green room how
Speaker:compliance is cool again. And then I realized, wait a minute, It's never really been
Speaker:cool before. So, but it certainly seems to
Speaker:me to be a growth industry given all the compliance
Speaker:mechanisms. So particularly in AI governance, right? And AI
Speaker:governance is something that I'm passionate about. I didn't,
Speaker:I never thought I'd be passionate about governance, but so what
Speaker:brought you to compliance? Oh yeah, great question and
Speaker:happy to share. I have always thought that compliance was cool and I will tell
Speaker:you exactly why. I don't know how much you, are
Speaker:kind of worried about your own data privacy, but I consider
Speaker:myself a data privacy nut. And I've been that
Speaker:way for many, many years. So I would
Speaker:rather not give any of my data to companies or even
Speaker:governments. You know that whole TSA thing now where they just scan your face?
Speaker:I hate that. I hate that. I hate that. In today's world,
Speaker:if you don't do that kind of stuff, you have to live as a hermit.
Speaker:So again, I'm out there giving my data away. And I feel
Speaker:like when the breaches started happening, do you remember the big
Speaker:Equifax breach almost 15 years ago now? That was the
Speaker:first big breach that caught everyone's attention and made us realize that, wait a
Speaker:second, this data that we're just handing over is at risk. Right. And it
Speaker:made me realize that we may not be able to
Speaker:protect our data by not giving it, but we should really hold the
Speaker:enterprises who have it accountable And we should help them stay secure.
Speaker:And that was really the why behind compliance with a Y.
Speaker:I like that because you're right. Like you— and again, we can debate
Speaker:philosophically about, hey, that seems like a system of control where you have to live
Speaker:as a hermit if you don't want to give away your data. But that's a
Speaker:whole other conversation. But you're right. Like, I think the Equifax thing, I think, really
Speaker:woke people up because, you know, I don't know
Speaker:where your thinking was before that versus post that, but
Speaker:I would imagine that if you were passionate about privacy, anyone who was passionate about
Speaker:privacy and awareness about what's going on there probably seemed a
Speaker:little cuckoo before that breach. And then afterwards,
Speaker:not as cuckoo, right? Okay. And as these breaches go on, the Target
Speaker:breach is the one that really kind of made me go sit up and
Speaker:realize, wait a minute now, they know what about me? You know, and I'm not
Speaker:a regular Target shopper, but, you know, I go there often
Speaker:enough that they clearly would have data on me. And
Speaker:then obviously also the, the whole thing where they reverse engineered, uh, who was
Speaker:pregnant and who wasn't based on buying patterns.
Speaker:I know. Um, and again, like, early on I
Speaker:probably looked a little tinfoil hatty, right? But,
Speaker:you know, if it— if time is— I guess given enough time, even the mo—
Speaker:most conspiracy theorists are proven not as wrong,
Speaker:if not right, not as wrong as we thought originally.
Speaker:I think my friends still think that I'm a bit cuckoo, to be honest, when
Speaker:it comes to my data privacy. But it's because you have these days,
Speaker:you know, agents going out outside their sandbox and
Speaker:infiltrating Hugging Face. And you have— it's just
Speaker:there's a lot of threats out there. And I think that it is really
Speaker:important that we can, you know, we need to be able to trust the enterprises
Speaker:who have the world's data. And so from our perspective, we
Speaker:went at that mission from day one, and we're really proud to be
Speaker:working with those companies every single day. How do you track—
Speaker:now that governments and politicians are realizing that privacy matters, right?
Speaker:We're seeing obviously the GDPR is the one that gets all the attention. But
Speaker:in a previous role, I worked with
Speaker:some folks in Latin America, and apparently Latin American countries have
Speaker:not as strict as the GDPR, but it's definitely in that direction. The US is
Speaker:more of a healthcare data is treated one way, this type of data is treated
Speaker:another way. What do
Speaker:you— what else is you're seeing in the world? And like, how, if you're an
Speaker:international enterprise, this is starting to become a very
Speaker:tricky field to navigate. Yeah, agreed.
Speaker:So one thing just to clarify is that we really focus on the
Speaker:security side of things. So we focus on the security
Speaker:side of privacy, I suppose you could say, because all
Speaker:of these privacy controls they really have, or these privacy frameworks, right?
Speaker:They have almost 2 sides. The first side is the security side, which
Speaker:is how do we actually keep this consumer's data
Speaker:secure and thereby keeping it private? The other
Speaker:side of it is the more of the pure privacy stuff, which is things
Speaker:like how do we let them opt out? How do we let them retrieve their
Speaker:data when they want to? Those are type sort of the how do you make
Speaker:the experience for the consumer almost like more seamless, more in control? But
Speaker:we really focus on the security side. How do you really lock down your environment?
Speaker:to make sure that there's never, you know, something to be worried about,
Speaker:right? Of course, there's always risks in every enterprise, but there's never, you know, you
Speaker:do as much proactive preventative work as possible. And
Speaker:that happens by keeping an eye on all of the different security controls that you
Speaker:have across your complicated enterprise, all in one single pane of
Speaker:glass. And that's a really hard job to do, but that is what we have
Speaker:set out to accomplish. Oh, okay. And I think, That brings up an
Speaker:interesting point because when you say compliance, I immediately, I live in the DC area,
Speaker:right? So immediately I go towards the legal aspect of it. And I had a
Speaker:previous guest, we talked about the need for a
Speaker:chief or a digital trust officer at the C-level of a company. And my
Speaker:kind of initial, and I do agree that it gets needed, but my first kind
Speaker:of thought being a realist is, well, that's both technical
Speaker:and the legal department have to get along. And I can't imagine,
Speaker:I mean, it is implicitly cross-functional. I would say if you have a
Speaker:chief trust officer, but those
Speaker:people tend not to see eye to eye. I say this as someone who
Speaker:did work in the— I spent some time in the legal department at Microsoft, which
Speaker:was a very odd experience of being one of the few
Speaker:technologists in a company that was a technology
Speaker:company, but like being one of the few technologists
Speaker:in a very large legal organization. That was a Quite kind of like, I
Speaker:don't know if you ever watched like the old Mr. Wizard shows where he'd like,
Speaker:or whatever the science YouTubers were, you put your hand in like
Speaker:one hand in hot water, one hand in cold water, and then like you put
Speaker:your, you mix them and like your brain's all confused. That was kind of like
Speaker:what it was like working there. But so
Speaker:what, how do you, do you,
Speaker:are there industry standard privacy controls? Is
Speaker:there something above and beyond that? Like, is there some kind of ISO
Speaker:certification for it? Like, what, what does that look like? Yeah, there's many,
Speaker:many, many controls, many certifications. Uh, we support
Speaker:all of the out-of-the-box frameworks that you would expect, all the
Speaker:security frameworks, some of the privacy frameworks, or all the privacy frameworks. I
Speaker:think that, again, there's a lot of tools out there that focus on the
Speaker:operationalization of privacy controls. So things like cookie
Speaker:management, you know, data subject access requests.
Speaker:We really focus on the security side. So we're really focused on saying,
Speaker:you know, an average enterprise has about 1,100 controls
Speaker:that they manage, security controls. And controls, of course, are just
Speaker:commitments to things like we will put antivirus on all of our employees'
Speaker:endpoints, we will have encryption on in transit, we will
Speaker:XYZ, XYZ, right? Every one of those is a control. And if you
Speaker:have 1,100 commitments that you are making from a security perspective,
Speaker:based on what is required of you by regulation, based on what you decide that
Speaker:you need to commit to as an organization. How do you keep track? 1,100 is
Speaker:a lot. Right. And especially when the source of truth behind every one of those
Speaker:1,100 controls is completely disparate. Because
Speaker:if you're a complex enterprise, then for one control, you might have to look at
Speaker:13 systems. You might only have to look at 2 systems, but in, you
Speaker:know, 30 accounts across those 2. So the point is, it starts to get very
Speaker:messy. And instead, what we do We integrate with the
Speaker:sources of truth that send the signals for each of those controls
Speaker:so that an enterprise can look and say, okay, I have 1,100 security
Speaker:commitments or controls that I make every day.
Speaker:Previously, I had to sample test those and hope that my sample testing
Speaker:either proved compliance or pointed me to some risks that I was
Speaker:having. Now I can actually say with
Speaker:confidence that these 1,100 controls are operating
Speaker:effectively as desired. And if there's an issue with one of them, I
Speaker:can reach in, look at what's behind the curtain, fix it, come
Speaker:back out and just make sure everything else is going okay. And that's that
Speaker:preventative, proactive model that we strive for. Okay,
Speaker:so how do you fix it? Is it— you fix inside that platform or is
Speaker:that like a something else? Are you raising these awarenesses or
Speaker:are you part of the solution too? Yeah, we're part of the solution in so
Speaker:much that we actually give step-by-step guidance on how to address the
Speaker:problems. Usually it's not so easy as, you know, turn it on again or something.
Speaker:So there's something going on. And so we do do that. Actually, the
Speaker:agents we're releasing in:Speaker:sneak peek. I will— I'll leave that for next year. Yeah, and I
Speaker:would imagine that you're probably already being asked, how do you make sure your agents
Speaker:are compliant with— because we're hearing all over the news about
Speaker:agents breaking their container and things like that. And I have
Speaker:a— I just installed actually this week, I've had OpenCLAW running for a couple months
Speaker:and I installed Hermes and I'm impressed with its tenacity.
Speaker:Actually, both of them, but more Hermes than that. And I know really has more
Speaker:to do with the underlying model than, than the harness. But like, how do you—
Speaker:the tenacity, I think, is both admirable and a little dangerous because I've
Speaker:seen it. I've asked it to—
Speaker:we were looking at moving and I asked it to research a property and it
Speaker:was red. One site blocked it, but then it found another
Speaker:way to like send a proxy to that site. And I'm kind of like— sipping
Speaker:my coffee, watching it work, like, seems a little—
Speaker:I wouldn't say shady, but it's definitely
Speaker:questionable. I should probably give it guardrails, like, as I see it kind of go
Speaker:off. And to me, as a developer, AI builder,
Speaker:AI engineer, I just made a simple request. I didn't
Speaker:think I would have to tell it not to break the law or do anything
Speaker:kind of questionably ethically, like screen scrape or anything like
Speaker:that. But I would imagine that's given your background and passion for
Speaker:compliance is probably top of mind. Like, how do you make sure your
Speaker:bots behave? Yeah, it's a big topic.
Speaker:Gosh, our CTO could talk about this for hours, but I think the,
Speaker:the top line is that we
Speaker:feel like we get to be on the good side of AI these
Speaker:days. It almost feels like a lot of AI products
Speaker:and a lot of AI use cases are quite scary,
Speaker:have a lot of potential for bad. Our AI agents'
Speaker:missions are to stay compliant. And so it becomes a
Speaker:little bit of the nature of the task is also
Speaker:quite sound. And I think that actually helps quite a
Speaker:lot, right? There's, there is just that fact. We've put in
Speaker:guardrails at the development layer so that the agents basically have really,
Speaker:really small jobs, each of them. And there's kind of checks and
Speaker:balances on each of the agents. And each of them have such a small
Speaker:purview that you actually kind of seek protection in that as well.
Speaker:There's another And there's a number of other things that we've done from a more
Speaker:technical perspective. But to be honest with you, we've, we've been lucky to
Speaker:find that obviously with all the controls that we've put in place on our own
Speaker:agents, we've seen really good results both from a security, privacy,
Speaker:as well as just efficacy perspective. Security in depth
Speaker:seems to be the answer to a lot of things, right? Yes, layered security,
Speaker:whether it's the locked door, the alarm system, you know,
Speaker:the spiky bushes outside the windows, right? Security is
Speaker:not a one and done. It's a multi-phase approach.
Speaker:And I would imagine compliance probably
Speaker:not the same, but pretty close to that, right? I mean, what,
Speaker:what does— who's your ideal customer? Like, is it the CTO? Is
Speaker:it the legal department? Is it some combination? Is it the—
Speaker:I know some companies now have chief privacy officers. Sorry, I cut you off.
Speaker:But like, who is this? It's the CISO, actually. So the
Speaker:Chief Information Security Officer is usually our target, kind of
Speaker:target buyer. Obviously, usually reporting to them, they have some sort
Speaker:of Director of GRC or Governance, Risk, and Compliance. And so that's
Speaker:actually a perfect buyer for us, or a VP of Information Security. And
Speaker:so typically, again, these folks are sitting in partnership with
Speaker:the legal team or the privacy team. They are doing the protection
Speaker:of customers' data, and the privacy folks and legal folks are doing,
Speaker:I know, something slightly different, like making sure that they're meeting the privacy
Speaker:regulation in terms of data subject access or other things like
Speaker:that. And these CISOs and their teams are really focused on how do we
Speaker:protect, how do we stay proactive. And that's really what we do. We give
Speaker:them the avenue to monitor their controls live, to
Speaker:basically get a continuous monitoring across their entire
Speaker:environment and tell them when something's astray, and then they can
Speaker:go in and proactively address it. And that is That means a lot for them.
Speaker:Interesting. Yeah. Is this something that smaller, mid-sized
Speaker:companies also need to like think about too? Like, or are you targeting the global
Speaker:2,000? Or, I mean, everybody, privacy becomes
Speaker:everybody's business. Yeah, it really does these days. And especially
Speaker:now, I mean, really, like it is, we're seeing everyone's focus
Speaker:be more and more on AI governance, on AI security, on information
Speaker:security in general. What we have found is it's quite industry-specific. So
Speaker:I think that we serve a lot of the companies that, of
Speaker:course, you know, if they get breached, there are serious consequences. So healthcare is
Speaker:probably our biggest industry, and we have a lot of healthcare clients that are
Speaker:also mid-market because they obviously have to protect patient
Speaker:data, and that is such sensitive data, and they're really just like
Speaker:quite prone to be, to be hacked or breached because, you know, people are
Speaker:attacking them. And so from our perspective, that's been historically one of
Speaker:kind of the best, best industries for us to really
Speaker:work with because they care. And we really like to work with the people who
Speaker:care. Well, that, that's a good point because I think you probably can
Speaker:tell right away of who has a metaphorical gun to
Speaker:their head versus actually care about privacy, right? Exactly.
Speaker:You really can. And healthcare is interesting because
Speaker:implicitly you have to share the data, right? Like, you know, my insurance company has
Speaker:to know what my X-ray does. the X-ray
Speaker:or imaging center has to send the report back to the doctor, right? So it's
Speaker:a very data-centric business. Yeah. But
Speaker:obviously we've heard horror stories about local
Speaker:hospitals, smaller hospitals being ransomwared. And I know strictly
Speaker:speaking compliance is not protection against
Speaker:ransomware directly, but I would imagine there's probably some
Speaker:kind of side effect that would, if they are compliant, they
Speaker:probably would be less susceptible
Speaker:to ransomware. Yeah, exactly. And I mean, again, of course,
Speaker:you— we don't like to breed breach shame, as we say, but I
Speaker:think the reality is that a lot of the breaches that have
Speaker:happened in the last 15 years are preventable.
Speaker:And they're from, you know, they're a mixture of certain
Speaker:configurations not being on. And then there's just security training.
Speaker:And I think that part of it is that a lot of security professionals are
Speaker:so busy doing what's urgent that they don't have
Speaker:time for what's important. And oftentimes really good security
Speaker:training for the wider organization falls into the important but not
Speaker:urgent. Right. And so what happens is that they don't have capacity for it. And
Speaker:one of the things that I like to tell people is like, look, your biggest
Speaker:liability is actually the rest of your organization. Like those, those social
Speaker:engineering emails are getting really good. And you need to be able to train them.
Speaker:And they're like, we don't have time for that. That's not even on the radar
Speaker:of things we need to accomplish. It's like, okay, well, our AI agents do a
Speaker:lot of your manual work for you so that you have time to focus on
Speaker:what's important. And that honestly makes a really big difference.
Speaker:Well, it's kind of like fire safety training, right? Like, why do firefighters go to
Speaker:schools and stuff like that and talk to kids about smoke alarms and stuff? It's
Speaker:because they are literally fighting fires, right? And
Speaker:that's obviously a good example. But like, I think it's— I think we— I think
Speaker:the IT security field can learn a lot from public
Speaker:safety in terms of the PSAs and like the community work that
Speaker:they do and teaching this type of safety because they clearly deal
Speaker:with urgent literal life and death issues, but they also take time out
Speaker:to realize like slowing down the pipeline
Speaker:by educating kind of the masses goes a long way
Speaker:to hopefully make it easier. I don't mean
Speaker:I don't know how I don't know if they track metrics that you know. firefighter
Speaker:Joe and Sally, they did a thing in this
Speaker:elementary school and, you know, house fires went down by 10%. I don't know if
Speaker:they track it to that degree, although that would be an interesting privacy, I guess,
Speaker:case right there. Right. But, um, but yeah, like how does that—
Speaker:and, and, and the Target breach, for example, was
Speaker:credentials that should have expired for, I think from an HVAC
Speaker:company, like something like really mundane. Yeah. And
Speaker:it's the mundane stuff. Yeah, it's always the mundane stuff. But I mean,
Speaker:again, user access reviews can be automatically checked in our platform. So it's things like
Speaker:that which we can really easily automate. And so those breaches actually
Speaker:get prevented and it's just kind of, yeah, it's kind of crazy,
Speaker:honestly. And just going back to the fire alarm example, it would be like if
Speaker:your fire alarm, you know, randomly went off and you had to
Speaker:have enough knowledge to know when it was real and when it was fake. That's
Speaker:the example, making it a like for like with social engineering. Sometimes we get these
Speaker:emails, we don't know if it's real or fake. So we have to suddenly become—
Speaker:all of us have to become cybersecurity experts to know, you know, is
Speaker:this real? Do I need to be worried about this? And that's why you're seeing,
Speaker:you know, I worry about my parents and them falling for a scam sometime
Speaker:because, yeah, it's just crazy. It's crazy what you have to know these days.
Speaker:And so, yeah, it's— You have to have like street smarts about you
Speaker:just because the internet is as far away as your phone.
Speaker:Yeah, exactly. Interesting.
Speaker:One of the things that I would say
Speaker:that sounded crazy when I said it originally
Speaker:was like the front line of the next conflict is as far away as your
Speaker:phone. And like we're seeing kind of like cyberspace is
Speaker:an active kind of, even if there is no, what
Speaker:the cool kids in DC call kinetic warfare going on, it is still very
Speaker:much an open field in the cyber realm. So you really have to,
Speaker:you really have to be very mindful of your phone is a connection
Speaker:to the world, but it's also the world's connection to you.
Speaker:Yeah. And sometimes, sometimes the world does not have
Speaker:your best interests, right? Or there's going to be bad actors in it. Agreed. It's
Speaker:very scary, actually. It's
Speaker:interesting how you're seeing a lot of kids opt into the older style
Speaker:clamshell phones or flip phones. It's kind of like that's
Speaker:the new retro is going back. I'm thinking of
Speaker:it myself, to be honest. Maybe keeping like an iPod Touch
Speaker:with me for other stuff. But honestly, it's like, yeah, I
Speaker:get it. I don't think we all want to be reached so much anymore either.
Speaker:Right. It was— it had a certain appeal back in the day, but now that
Speaker:we've gotten it, it's be careful what you wish for. Totally agree.
Speaker:So what
Speaker:What do you— so you mentioned something, you talk about the, your smoke alarm going
Speaker:off or your fire alarm going off all the time. I worry about that because
Speaker:I think alarm fatigue is very real or dialogue fatigue, right? How many times you
Speaker:go to a site and it says, hey, we have cookies.
Speaker:Like, I'm a cookie— Always reject them. Always reject them. Even if it
Speaker:has an extra screen you have to click through, just do it. It's worth it.
Speaker:It's worth it. Protect your data. Okay. I
Speaker:always choose, um, except necessary only. Is that
Speaker:not safe enough? No, that's the only one that you can really do in the
Speaker:US, so that's fine. But, uh, even if it makes you click through a
Speaker:screen to validate it, go through it. Sure.
Speaker:Toggle things off and yeah, just don't give them your cookies.
Speaker:Yeah. I know I saw something very disturbing is a,
Speaker:um, there's a YouTube video. I haven't verified it, but, um, smart TVs
Speaker:Yes. Are also notorious. They
Speaker:actually will report back what it
Speaker:sees on the screen. And they're probably
Speaker:listening as well, to be honest. I think this is the reality of our phones
Speaker:these days. There's a lot of, a lot of sneaky apps in
Speaker:there. We carry our phone with us all the time. There's a lot of sneaky
Speaker:apps in there that are listening. And they say that it's for, you know, accurate
Speaker:advertising or whatever, but they're literally listening. It's crazy. That's why when you
Speaker:talk about something, all of a sudden you get an ad about it. Yeah, I've
Speaker:noticed that too. And it's fascinating
Speaker:that those stories are so anecdotally well known
Speaker:or come across so often, like there has to be a grain of truth to
Speaker:it. No, it is true. Yeah. Yeah.
Speaker:I mean, it's just— and it was one of the major TV manufacturers did get
Speaker:caught listening in on people's conversations because I think the remote control had a
Speaker:voice-activated feature or something like that, and I saw that
Speaker:and I was like, uh, I don't know if I want that. You know, I
Speaker:think our fridges are gonna start too. That's the whole smart fridge thing. Crazy.
Speaker:I, um, I— my fridge was like, hey, connect
Speaker:me to the internet, I'll do this. No thank you,
Speaker:I'm good. I don't need that.
Speaker:Well, there's a meme going around, it's like, you know, IT people tend
Speaker:not to have automated homes, right? Exactly, because we know the
Speaker:risks. We know the risk. Yeah, yeah. I mean, the only thing that I would
Speaker:want in terms of automation is to know
Speaker:if a door is left open. Yeah, great. You know, just because I got
Speaker:dogs and— And be able to monitor the temperature from far away,
Speaker:so in case your pipes freeze. That's another good one. Right, right. Or water
Speaker:sensor. Or water sensor. Yeah, exactly. Like basic safety stuff.
Speaker:For the temperature thing, I actually have a little robot over there with it I
Speaker:can tilt and it shows me that this is within view of it.
Speaker:Kind of analog, but again, because even then, like,
Speaker:you know, I, I have these thoughts and I'm like, oh, maybe I'm paranoid, right?
Speaker:You see these IoT sensors, right? And you've probably heard this
Speaker:joke, the S in IoT stands for security. And
Speaker:you know, all these smart devices and you hear about these breaches, even if
Speaker:the manufacturer had the most noble intentions, right?
Speaker:You are putting data, whether it's your heart rate data, if it's a smartwatch,
Speaker:in the hands of somebody who their priorities
Speaker:was getting to market, not necessarily— Yeah.
Speaker:Security. Agreed. There's a lot of health tech
Speaker:companies where when they've gone out of business now, you notice that they
Speaker:can sell the data. Of the companies, and that is really
Speaker:scary— of the consumers, sorry. That's really scary. So there's just basically
Speaker:health tech companies out there who even, you know, even if they put a bunch
Speaker:of— let's say they have the best of intentions and they put a bunch of
Speaker:privacy and security things. Right. Well, when things go under and they don't do
Speaker:so well, they can literally sell that data. It's a— it's an asset,
Speaker:and they can sell that data as part of their, you know, closing down of
Speaker:the company. That is crazy to think about. And that's— even— yeah, I'm
Speaker:sorry, go ahead. Didn't mean to cut you off. Even if, even if during the
Speaker:process of closing down, they may have the best of intentions, but their
Speaker:creditors will be like, I don't care about these people's privacy, right? Even,
Speaker:even if someone's the most noble person in the world. And, um,
Speaker:I'm glad you mentioned that because— and if we're getting off too far off topic,
Speaker:let me know, because if you listen to the show, Andy and I are known
Speaker:to do that. But Spirit Airlines in the US? Yeah, that's right.
Speaker:They sold the Customer data. Yeah. Or part of it at least. Yeah.
Speaker:Well, not just the customer data, but also the private emails. I think
Speaker:either Meta or Google was trying to buy it. So they, all the private emails
Speaker:in there. Now I think somebody, one of the, I think the flight
Speaker:attendant unions or somebody, one of the unions is assuming like, no,
Speaker:these are private conversations. But it's interesting. Like it's just kind of
Speaker:like, who would think when a company goes
Speaker:under, like you expect like the desks and the chairs and stuff like that to
Speaker:be kind of auctioned off. But you know, the emails, the data, I mean, that's
Speaker:Just not something I think the average person would've thought
Speaker:about. Agreed.
Speaker:So what can people do
Speaker:to, to do a better job of securing their privacy, right?
Speaker:Individuals? Individuals, right? Like if you're an individual, if you're somebody
Speaker:listening to this, and a lot of our listeners are data engineers or data
Speaker:scientists and, or AI engineers.
Speaker:they're probably more aware than your average bear. And that
Speaker:rhymes. Maybe we'll put it on a t-shirt. But, um,
Speaker:what can people do, right? I mean, obviously you reject the cookies that you can.
Speaker:Yep. You— but there's got to be
Speaker:more, right? I've seen ads for DeleteMe,
Speaker:I think, is it? And there's a couple of firms that kind of offer that.
Speaker:But I mean, are services
Speaker:like that Valuable, right? You know.
Speaker:The problem is that your data is constantly being actually taken from
Speaker:you and being put back in. So even when you are doing some of those
Speaker:things, you, you're living your life on one side and then you're
Speaker:continuously giving your data back in to the, to the
Speaker:ether. There's— it's really challenging. I do think that over time you can
Speaker:chip away at it. I really do think that simple things that you can do
Speaker:is, you know, just being conscious about it. So things like rejecting
Speaker:cookies, things like making sure that you're not signing up for extraneous
Speaker:things. There's also a setting on your phone. Let me pull out my phone so
Speaker:I can get the clicks right. So you can go to your phone and if
Speaker:you go to your settings, I have an iPhone. If you go to your
Speaker:settings and then you go to, if you search
Speaker:privacy. Yep. So you get a privacy and security option.
Speaker:See if it's here. Yep. And you scroll down and you find microphone.
Speaker:And it should have a list of all of your apps that have access to
Speaker:your microphone. And you can go in and like turn off a lot of
Speaker:microphone access because there's a lot of apps in there. I don't think Uber needs
Speaker:access to your microphone. I don't think LinkedIn needs access to my microphone. So
Speaker:there's things like that. And that actually prevents some of the listening that's happening
Speaker:under the guise of like, oh, better targeting of ads and stuff like that. And
Speaker:the same thing with the camera. And over months, sometimes
Speaker:more than months, you start to notice that the algorithm actually doesn't
Speaker:have you not locked down as much. which actually is kind of a proof
Speaker:point of you protecting your privacy and your personal data a little bit more.
Speaker:Of course, there's a lot more you can do from the perspective of just like,
Speaker:as simple as it sounds, like having better passwords, not, you know, using different— I
Speaker:mean, all of those are basic things, but this is a little extra tip that
Speaker:I usually tell my friends and family. Oh, that's good to know. I was looking
Speaker:through the Android settings earlier this week for a different reason, and I
Speaker:noticed like, hey, there are a lot of apps in here that want access to
Speaker:the camera. I don't remember authorizing that. Yeah, usually it
Speaker:gets authorized at the beginning. So yeah, exactly. And you can always turn it on
Speaker:again if you need it, but I just— right, all of mine are off.
Speaker:No, that's a good point. And, and, um, I find it fascinating that the only
Speaker:way you can kind of like proof it, prove it, is you wait
Speaker:a few months and see, do they have you now on lockdown? It's like
Speaker:naive. You're like, wait, we don't have any visibility into this? And then I'm like,
Speaker:oh yeah, we don't have any visibility into this. Like, it's crazy. Even with the
Speaker:GDPR and things like that, you don't really have that. And I'm glad you
Speaker:mentioned Apple because Apple really doubled down on privacy as a
Speaker:feature. You know, I have an Android phone and God only knows what
Speaker:goes on under the hood on that one, right? It's pretty good.
Speaker:I don't know. I should probably do some more research on it, but. It depends
Speaker:on the vendor because the beauty of open source is,
Speaker:you know, anyone can modify it. The horror of open source is
Speaker:Anyone can modify it, right? Apple does do a better job of
Speaker:locking things down, but even then it's not, I mean, you hear stories about
Speaker:there's companies that will, you know, break in iPhones. I know Apple took
Speaker:a pretty big stand when, uh, I think the FBI or
Speaker:one of the US federal government basically said, you need to create a patch
Speaker:for this, for the iPhone so we can break into this guy's phone. And they
Speaker:refused. And they were taken to court. And then one day they
Speaker:just, the government dropped the case quietly. And you're like, hmm,
Speaker:oh, there's a startup out of this country that has a tool that breaks
Speaker:iPhones, right? So it's, um, it's interesting because as convenient as
Speaker:these devices are, they have a lot of information on us.
Speaker:And even if everything is done right, if you have an
Speaker:advanced persistent threat that's
Speaker:well-funded like a nation-state, not really much you can do,
Speaker:right? Aside from moving to a cabin in the woods, right? Mm-hmm. Exactly.
Speaker:Full circle back to the beginning of the conversation. Right. Unless you wanna be a
Speaker:hermit. It's just a, it's a fascinating and terrifying world,
Speaker:I think. But back to like the business angle of it, what,
Speaker:you know, we saw Apple really pivot to privacy at Union
Speaker:Station in DC. There was a huge ad I remember seeing that was,
Speaker:had the Apple, you know, Safari private by default. Right now the browsers
Speaker:are starting to do this. Yeah. With, in terms of alerting you about these super
Speaker:cookies and things like that. So it seems like privacy, if
Speaker:not now, in the near future could be a business strategy,
Speaker:right? We're seeing Apple kind of use that to good effect. What do you
Speaker:think that people will finally seek out
Speaker:compliance solutions because like, hey, we're
Speaker:compliant, right? That becomes something they can put on their brochures?
Speaker:Yeah, I think so. And I think you're already seeing that. So obviously there's this
Speaker:big push around SOC 2 compliance, which, you know, really matters.
Speaker:We usually serve B2B companies because B2B companies, you know, to have
Speaker:to serve a B2B customer, you have to have some proof of compliance. So there
Speaker:is already that mentality. And I think the question is, will that bleed into
Speaker:B2C? Honestly, I think most B2C companies now also seek those types
Speaker:of compliance certifications because to them, it's peace of mind, as
Speaker:it is for founders, for others. Like, it really is peace of mind. And
Speaker:I think it is surprising how much that can— how much peace of mind it
Speaker:can get you. Getting an external assessment, getting an external pen test,
Speaker:getting external SOC 2 or ISO, there is something about it if,
Speaker:especially if it's a good auditor, that really makes you feel like, okay, amazing. Like,
Speaker:I do at least have some type of check on this. And yeah, and it
Speaker:matters. And much of those things are also about incident response and business
Speaker:continuity in the event of a disaster. Right. And so it's not all about
Speaker:preventative. It's also about preparing you if something is to happen.
Speaker:And so there's peace of mind that also comes from that, from actually having good
Speaker:processes in place if the you know, the worst is to happen and you'd
Speaker:get breached. And that's also just good to know.
Speaker:So all of that, I think, is, you know, it's just part of the— part
Speaker:of how I think the industry is maturing, part of how we're all learning.
Speaker:And I'm really glad that it's headed that way. No, I mean, that makes a
Speaker:lot of sense in terms of— I would imagine
Speaker:companies that have cyber
Speaker:risk insurance, probably the insurance companies are going to wise up
Speaker:and start demanding better paper trails of
Speaker:like what's going on, right? Because if you don't know, you don't know, right? And
Speaker:if you don't know, you don't know to fix it, right? So
Speaker:just even, I think I would encourage everyone to at least do one of these
Speaker:audits because then, you know, then you know
Speaker:what the risk profile is, right? Maybe, maybe you have a high-risk profile.
Speaker:Maybe it's better than you think. Probably not, but maybe it's better than you think.
Speaker:Exactly. And then you at least have a list of things to
Speaker:work on, right? Yep. I think in the virtual green room, we, we both mentioned
Speaker:moving, but it's like getting a home inspection, right? You wanna make sure that, hey,
Speaker:the foundation's okay. Or, you know, you're worried about this leak in
Speaker:this room and it's like, ah, it turns out to be nothing, right? It's, um,
Speaker:it's, um, it's, it, it's interesting. And I, I
Speaker:find it fascinating that, um,
Speaker:we are in that phase of why are we—
Speaker:why is compliance making, if not a comeback, like, like it's
Speaker:finally becoming in vogue. And it's because compliance touches a lot of things
Speaker:that touch a lot of our lives. Yeah. Whether it's straight up security,
Speaker:privacy, right? And everyone, I think, has a slightly different definition of what
Speaker:privacy is, right? One of the funniest things in, uh,
Speaker:one of the GTA games, I think it was 5.
Speaker:They, they don't mention Facebook by name, but the site is called
Speaker:Privacy Invader, which is, um, they certainly, um,
Speaker:social commentary is a big part of the game as much as carjackings and
Speaker:things like that. Uh, I don't know if you've ever played it, but like, if
Speaker:you, even if you just like listen to the radio stations on there, the social
Speaker:commentary is pretty biting. And, um, But,
Speaker:um, I, I just think it's fascinating
Speaker:that we all have to think about this, right?
Speaker:And you mentioned your parents, you know, my mom would fall for things. And
Speaker:even though, like, you know, eventually I gave her a lockdown
Speaker:Linux laptop because
Speaker:she would get a lot of scam calls. Yeah. And it's
Speaker:really, you know, it's really a malware thing that happens. Well, and,
Speaker:and they're getting better at it. Like they're cloning voices. Really sad. Doing— I
Speaker:know. It's just really upsetting. And you think like, you know, the
Speaker:human capacity for creativity, you have to step back and admire it
Speaker:if it was only focused on something non-destructive.
Speaker:Yeah, I know. It's really upsetting. I mean, and it, it really is. And it's
Speaker:kind of like I would get these calls too. And
Speaker:I'm like, I kind of know. I, one of the common themes when I worked
Speaker:for Microsoft was people would, mess with the scammers
Speaker:because they say, hey, I'm calling from Microsoft. Really? What building are you in?
Speaker:Really? What org are you in? Like, where are you in the GAL? I was
Speaker:like, I'm sorry, sir, I don't know what the GAL is. Well, if you don't
Speaker:know what the GAL is, you don't work here. And for those who don't know,
Speaker:GAL is Global Address List. It's basically the, um, the thing that Outlook was
Speaker:hooked up to. So if somebody said they work for Microsoft, you would
Speaker:ask them that or what their alias was. But no, I think, I think we
Speaker:all have to be street smart. Even if you—
Speaker:because I think humans are really
Speaker:good to adapting to their environment generally,
Speaker:right? Someone who grew up in
Speaker:Staten Island is going to be a bit more street smart than someone who grew
Speaker:up on a remote desert island, right, where everybody knows each other,
Speaker:right? That's an adaptation. But
Speaker:there are no remote desert islands anymore. Yeah. Your
Speaker:phone, your watch, I mean, everything, your fridge. My God, your fridge
Speaker:is spying on you or could be spying on you. Like, what sort of weird
Speaker:cyberpunk dystopia have we found ourselves in? Right? I often
Speaker:wonder that. Like, you know, we don't even have the flying
Speaker:cars like they did in Blade Runner, you know?
Speaker:But, you know, here we are in this kind of this something that I think
Speaker:even Orwell would be like, Dude, if, if you would write about it, he goes,
Speaker:nah, that's not believable. People willingly bring in like these devices that
Speaker:listen to everything they say. They wait and they carry it around with them. Come
Speaker:on. No one would believe that. Right. Yet truth turned
Speaker:out way stranger than fiction. Right. And I'm not, I say
Speaker:this, I feel like I'm a hypocrite because I have a couple of, I don't
Speaker:wanna say her name cuz she'll wake up. Yeah. I have
Speaker:Amazon Echos, right? I have a couple Amazon Echos and I
Speaker:eventually will get rid of them,
Speaker:but I certainly don't have a Ring camera. Right.
Speaker:And now that we're on the topic of cameras, and I know we're coming close
Speaker:to our time here, what— I don't know if you've been tracking this, but
Speaker:there's been a big pushback in the US against flock cameras. Yeah.
Speaker:I think that's interesting. Do you think this will be the moment we look back
Speaker:on and people realize, We kind of already live in a surveillance
Speaker:state. Yeah, it's a tough one. I think
Speaker:that these types of things are all adding up in a moment where AI is
Speaker:becoming kind of an avenue that makes everybody understand what
Speaker:cybersecurity means. I think that honestly, cybersecurity has been
Speaker:such a, uh, techie word and phrase
Speaker:and concept for so long. And so people didn't really have something that they
Speaker:understood, you know, other than the breaches if it affected you maybe. But even
Speaker:then, there was a lot of just, you know, okay, it is what it is.
Speaker:Like, well, what you gonna do? My information's already out there. I think that when—
Speaker:I think that a flock camera is— of course, I mean, it's also like you're—
Speaker:it's literally filming you. So I think that it would have probably been a big
Speaker:deal regardless. But I think that it's just adding up and adding up on top
Speaker:of everything that's going on. And people just are quite anti-AI right now
Speaker:in a way of saying, you know, they're anti-data centers, they're anti-that type of
Speaker:thing. Everyone just kind of wants that control back. I feel it too. You know,
Speaker:we used to live in a simpler world. And AI innovation is amazing for
Speaker:so many things. And again, I think we've— I feel really lucky
Speaker:because I get to be on the good side of AI. We get to use
Speaker:AI innovation to keep companies secure. That is an excellent
Speaker:reason to use it. And there's a lot of reasons that I don't really know
Speaker:if it's worth the gallons of water that it's using. And so,
Speaker:right, that's— I think that's kind of to each their own. But anyway, I know
Speaker:we're at time, but I just wanted to— No, no, no, no. I mean, it's—
Speaker:I think it's interesting. I think more people need to have these conversations. And you're
Speaker:right, people, they hear cybersecurity. My wife works in that field and
Speaker:she worked in it way before it was cool. And
Speaker:it's one of those things where no
Speaker:one wants to get a report from security. That's
Speaker:kind of the mentality. Like no one wants to talk to anyone in security, whether
Speaker:it's physical security or whatever, but
Speaker:they're there to protect you, right? Like save you from yourself. I don't know. I
Speaker:think it's interesting because I think people have to wake up and
Speaker:realize, like, there is no remote place on Earth anymore, right?
Speaker:You can get an internet signal pretty much anywhere on the
Speaker:planet, right? Um,
Speaker:and if you are within reach of a cell tower, then you are
Speaker:within reach of, you know, the machine. And
Speaker:I think maybe we're going to realize, I think slowly
Speaker:people, the way people are pushing back against AI, The way people are
Speaker:pushing back against the surveillance cameras and things like that. I
Speaker:don't think people realize, the general public didn't realize that AI
Speaker:basically gives you a kind of intelligence that's not just smart,
Speaker:but a plate reader, a
Speaker:human plate reader can only do but so much. You can only
Speaker:hire but so many human license plate readers, but you
Speaker:have this one kind of I don't want to say mind or
Speaker:consciousness because that, that's a loaded word, but there's one system that
Speaker:can act like it's watching you everywhere, right? It
Speaker:gets to a very— was this Foucault? One of the— there was a French philosopher
Speaker:that talked about this, and they designed a prison
Speaker:where everything could be seen from like one central point. Yeah. And it
Speaker:freaked people out. And it was like, I think they've banned the
Speaker:use of, or that design, but But I don't know, I think we kind of
Speaker:like walked into it and kind of we were sold convenience
Speaker:and in a deal with the devil almost like our
Speaker:convenience for privacy. It's interesting. Yeah. So,
Speaker:ending on not such a positive note, I think what you're doing is important because
Speaker:I think it makes people aware
Speaker:at the C-suite level more and more about their privacy,
Speaker:what their security should be. And it sounds like you make it easy, right? It
Speaker:sounds like you make it— We do. A dashboardy experience.
Speaker:That's what it should be. And I think you— and
Speaker:if you have your agents coming out soon, which you don't want to talk about,
Speaker:I understand, you know, you can actually— oh, go ahead. We have
Speaker:21 agents already live that are doing a lot of monitoring. And yeah, so this
Speaker:is just the next wave of agents on the remediation
Speaker:side. But yeah, we have a wide range, wide array of
Speaker:nts that we've had live since:Speaker:curve on that front. Fortune 500 companies use our AI agents every day
Speaker:to stay secure, monitor third-party risk, monitor their own
Speaker:risk. Yeah, it's good stuff. Very cool. Well, awesome. Where can folks find out
Speaker:more about you and Compliance? Yeah, compliance.com.
Speaker:Easy enough. Compliance.com. With a Y? With a Y. Compliance with a Y dot
Speaker:com. Exactly. And that's where you can find us. Awesome.
Speaker:Awesome. Well, thank you for your time and really enjoyed our conversation.
Speaker:And if your CTO wants to come and Geek out for a couple hours, let
Speaker:me know. We'd love to have that because I think I think as
Speaker:agents become more and more capable, I think
Speaker:conversations like this are going to be even more important. I mean, they're
Speaker:important today, but I think once you give these
Speaker:things that have no
Speaker:ethical constraints,
Speaker:have no conscience. so to speak, and have
Speaker:no fear of being— even the most
Speaker:worst person you can think of
Speaker:had some kind of concern about being
Speaker:caught, captured, and punished for their crimes. I don't think
Speaker:AI has that, right? And we've seen the
Speaker:horrible things humans can do, right? And that's with, quote unquote, a
Speaker:conscience. of some sort, whether it's broken or not is another question,
Speaker:right? So you could just imagine what a machine could do with
Speaker:that kind of thing. So again, another positive note to end on, but
Speaker:not everything ends like a good Disney movie. With that in mind, I'll let the
Speaker:outro play. Thanks again to Rich Akowal for joining
Speaker:us and breaking down the evolving world of AI, privacy,
Speaker:security, and compliance. If you enjoyed the
Speaker:conversation, be sure to subscribe, share the episode, and join us next
Speaker:time on Data Driven.