
Sign up to save your podcasts
Or


In this episode, Manish Ahluwalia, the field CTO of Skyflow, discusses the technical aspects of data residency and the usage of a data privacy vault.
He explains the concept of data residency and data localization. He noted that with the increasing amount of data being generated and shared, it is becoming increasingly important for organizations to ensure that their data is being stored and processed in compliance with local laws and regulations. However, this is a technically challenging problem because data typically ends up all over the place and companies lose track of what and where they’re storing it.
Ahluwalia then discussed the role of a data privacy vault in addressing data residency concerns. He explained that a data privacy vault is a secure, centralized repository for sensitive data that can be used to enforce data residency requirements.
He also discussed how companies can use the data privacy vault to ensure that data is only accessed by authorized parties, and that the data is only used for specific purposes. He also explained that data privacy vaults can be used to track and audit data access, which can be useful for compliance and regulatory purposes.
Topics:
Resources:
Historically, backup and recovery has been a job relegated to a junior person on the team. It’s the kind of grungy work that all companies know they should do, but no one wants to own it. As such, many companies have a poor backup and recovery posture and aren’t even sure they can recover from a disaster. Additionally, in recent years, homegrown backup systems have been the target of more and more ransomware and cyber attacks.
Attackers target the backups, either deleting them completely and then attacking other parts of the system or steal the backups, break the encryption, and now have access to tons of company data.
W. Curtis Preston has been working in backup and disaster recovery for nearly 30 years and has written five books on the subject. He joins the show to discuss backup and recovery missteps, best practices, and how Druva, the SaaS-based backup and recovery platform helps businesses offload backup responsibility.
Topics:
Resources:
In this episode, we discuss the topic of secure multi-party computation. Since its introduction in the eighties, secure multi-party computation – also known as SMPC – has evolved into a subfield of cryptography for which a variety of protocols have been developed. SMPC is a technique used to allow multiple parties to jointly compute a function on their private inputs without revealing any information about those inputs to the other parties.
Liz Acosta, Developer Advocate at Skyflow, joins the show to explain SMPC and share her recent research into the subject. We begin by explaining the basic concept of SMPC and how it differs from traditional methods of computation.
We also discuss the practical applications of SMPC, such as in the financial industry for secure trading and in the healthcare industry for secure sharing of patient data. We also highlight the challenges that still need to be addressed in the field, such as scalability and ensuring the security of the computation.
Topics:
Resources:
Most of the news and conversations around data privacy, security, breaches, and the impact to consumers and businesses is centered around big tech. However, big tech only makes up a small percentage of total businesses and privacy and security is something that has the potential to impact all businesses.
Denise Farnsworth has an incredibly diverse background in privacy, from big tech to small businesses and everything in between. She served as Deputy Data Protection Officer for Facebook, Chief Privacy Officer at Jazz Pharmaceuticals, Lead Privacy Counsel for NetSuite and Head of Legal, Data Privacy and Compliance Officer for Microsoft, and is now CEO and Founder of Inspire! Privacy and Security, a company focused on helping SMBs with privacy challenges.
Denise joins the show to discuss some of her past experience working at Microsoft and Meta during both pre and post GDPR and how she’s transferred those skills and experiences to what she does today. We discuss how privacy impacts small and medium businesses, why they should prioritize privacy, and how Denise’s company helps them operationalize and build out a privacy program.
Topics:
Resources:
Imagine being able to perform any computational operation over any kind of data but do it while the data is fully encrypted. That is the promise of fully homomorphic encryption.
Fully homomorphic encryption was first theorized in the 1970s, but the first proposal for a plausible construction of a fully homomorphic encryption scheme didn’t arrive until 2009. We are now in the fourth-generation of fully homomorphic encryption and although performance is still a blocker for many applications, there’s been a series of major breakthroughs allowing real world application to take advantage of the approach.
Dr. Avradip Mandal received his PhD from the University of Luxembourg where his research focused on cryptography, in particular homomorphic encryption and theoretical symmetric key cryptography. He joins the show to describe what homomorphic encryption is, how it works, the history, and breakthroughs.
Fraud can be crippling to a business. It hurts your revenue, reputation, and customers. Fintech fraud is a super complex space, with bad actors using a variety of attacks like identity attacks, credit card theft, and phishing scams, it’s a lot for any company to tackle on their own. Sophisticated fraudsters leverage weaknesses in protocols like SMS, the phone system, email, and DNS.
Soups Ranjan, CEO and Founder of Sardine, joins the show to discuss the different types of fintech fraud attacks that take place and how Sardine uses machine learning to automatically detect and prevent fraud.
Soups has a PhD from Rice University in denial-of-service attack prevention and has been working in fraud detection for a decade across companies like Yelp and Coinbase. With a strong background in data science and a ton of real world experience, Soups is an expert in this space.
Topics:
Resources:
The technology industry has changed a lot over the past 10 years with the move from on-prem systems to the cloud. With that came new types of challenges from a privacy and security perspective. Controlling access to data was no longer just about putting up a firewall, but you needed to know who and what was accessing the data at all times for audit purposes. Authorization models had to adapt and become flexible to support more fine-grained access.
With new challenges comes new opportunities. There's been a growth in startups focused on developing solutions that help companies address privacy and security challenges. Privacy is shifting left and becoming an engineering effort. Additionally, there's an increased interest in venture funding available to companies attacking these privacy and security challenges.
Rak Garg, Principal at Bain Capital Ventures, joins the show to discuss his prior work as a product manager working on Atlassian's data security and governance products. He also shares his thoughts on trends he's seeing in the industry as an investor interested in the data privacy and security space.
Topics:
We launched the Partially Redacted podcast in 2022 and since then have published 17 episodes with industry experts covering everything from the basics of tokenization and encryption to differential privacy. We've had shows about privacy engineering training and how to build and scale a privacy engineering program.
In this final episode of 2022, we're breaking format. This is a special episode where we look back at the 17 episodes we’ve done and discuss some of the biggest themes and notable insights that our guests had.
Ashley Jose, Product Lead at Skyflow joins as Sean's guest to share his thoughts on the themes and trends from the first collection of episodes.
We'll be back in January with a new collection of episodes. Happy Holidays and Happy New Year!
With the changing landscape of privacy regulations and the growing consumer awareness about the collection and management of personal data, more and more companies are prioritizing privacy earlier in their lifecycle than ever before. This is fantastic news for privacy practitioners, but as a founder or product leader, how do you go about building, operationalizing, and scaling a privacy program?
Pramod Raghavendran, Director of Privacy and Data Protection at Coinbase, joins the show to share his thoughts and experience about building privacy programs. Pramod worked as an engineer, solutions architect, technical programs manager, and engineering manager before finding his way into privacy. With deep technical expertise and privacy experience from Amazon, Google, and now Coinbase, Pramod is uniquely positioned to have insights into building privacy functions and establishing a culture of privacy.
Topics:
Resources:
Ari Hoffman has spent his career helping businesses implement and solve technically challenging problems at companies like Cisco and Fivserv. Today, he serves as the Director of Customer Programs at Skyflow, where he helps Skyflow customers tackle their privacy and security challenges.
Ari joins the show to share his expertise about the common privacy challenges and use cases businesses are facing today and how to break apart these challenges into bite-sized and manageable pieces.
Ari discusses his career path, why he joined Skyflow, Skyflow Data Privacy Vault, and how companies are using this technology to address some of the biggest privacy and security challenges that face them today. Talking through specific examples, like PCI compliance, PII data protection, data minimization and governance, Ari provides actionable advice for businesses looking to get a handle on data privacy, security, and compliance.
Topics:
Resources:
From the publisher's feed