What if someone asked you right now where your most sensitive data lives? Most organizations would struggle to give a confident answer.
In this episode, Tony Schimizzi draws on years of consulting experience to make a point that cuts to the core of modern data security: this is no longer just a cybersecurity problem. It has become a large-scale business operations and governance challenge.
Tony breaks down why data sprawl across SaaS products, cloud apps, and collaboration tools has made it nearly impossible for most companies to know where their data is, let alone where the crown jewels are and how well they are protected.
Takeaways:
~ Do the Fundamentals First: Asset management, visibility, access control, data classification. These have not changed, and they will not. Most breaches happen because the basics were not in place.
~ Security Is a Double Negative: IT can point to uptime as value. Security cannot point to revenue. Understanding that dynamic and learning to communicate in KPIs and measurable outcomes is how security teams earn their seat at the table.
~ Say Yes, And: The most effective security professionals are not the ones saying no. They find the compensating control that lets the business move forward safely. Never no, but. Always yes, and.
~ Build a Risk Council: Instead of having security engineers fight business decisions above their pay grade, bring the right leaders together: CISO, IT, HR, marketing, legal. Let them hash it out. Decisions made there carry weight decisions made at the engineer level never will.
~ If It Matters, It Should Be Measurable: KPIs taken to the board quarterly, along with examples of incidents that did not escalate because controls were in place, are how security teams demonstrate value without a direct revenue line.
~ Understand How the Business Makes Money: Before you can evaluate risk, you need to know what the business actually runs on. If your initiative would slow down the revenue engine, you need to know that going in.
~ Take Risks When You Are Young: Professionally and personally, the window to experiment, grind, and separate yourself is in your 20s. It is easier to course correct early than to try to change direction later.
Quote of the Show:
"Companies no longer fully understand or control identity, access, and the data movement across their environments." Tony Schimizzi
Links:
~ LinkedIn:https://www.linkedin.com/in/anthony-schimizzi-cissp-ccsp-cism-issap-045b7a82/
Ways to Tune In:
~ Transistor: https://guardiansofthedata.show/
~ Spotify: https://open.spotify.com/show/5gZXInkb12Qrs2Lyv0hstQ
~ Apple Podcasts: https://podcasts.apple.com/us/podcast/guardians-of-the-data/id1826819323
~ Amazon Music: https://music.amazon.com/podcasts/0754cdde-f1c4-4f6c-92a2-e263f7840eb8/guardians-of-the-data
~ iHeart Radio: https://www.iheart.com/podcast/269-guardians-of-the-data-285972170/
~ YouTube: https://www.youtube.com/@GuardiansoftheDataPod