

She Said Privacy/He Said Security
Jodi and Justin Daniels
This is the She Said Privacy / He Said Security podcast with Jodi and Justin Daniels. Like any good marriage, Jodi and Justin will debate, evaluate, and sometimes quarrel about how privacy and security impact business in the 21st century.
Episodes
Mentioned books

Jul 6, 2023 • 37min
The Far-Reaching Risks of the Emerging Framework for AI Deployment With Jim Dempsey
Jim Dempsey is the Senior Policy Advisor to the Stanford Program on Geopolitics, Technology, and Governance. Additionally, he's a lecturer at the UC Berkeley School of Law, where he teaches cybersecurity law in the LL.M. program. Before joining the UC Berkeley staff, he was the Executive Director of the Berkeley Center of Law & Technology. Jim previously served as a part-time member of the US Privacy and Civil Liberties Oversight Board — an independent agency within the federal government charged with advising senior policymakers and overseeing the nation's counterterrorism programs. Jim is the author of Cybersecurity Law Fundamentals, a summation of cybersecurity law for practitioners in the field. His other publications include "Cybersecurity Information Sharing Governance Structures: An Ecosystem of Diversity, Trust, and Tradeoffs" and "The Path to ECPA Reform and the Implications of United States v. Jones." He also pens articles on cybersecurity for Lawfare, a non-partisan, nonprofit publication dedicated to national security issues. In this episode… With the emergence of innovative technologies, cybersecurity continues to be a topic of discussion. And as the constant evolution of AI further transforms our lives both personally and professionally, the products and services we rely on are at risk of becoming fundamentally insecure. Jim Dempsey, a cybersecurity expert, explains that many users with ill intent are on a mission to steal our information and disrupt AI technology. A particular intentional attack to be wary of is prompt injection attacks disguised as programming instructions. This occurs when a hacker hijacks a language model's output, allowing the hacker to get the model to say anything they want. There are, however, privacy and security best-practices companies can adopt as a means of prevention. In this episode of the She Said Privacy, He Said Security Podcast, Jodi and Justin Daniels welcome Jim Dempsey, the Senior Policy Advisor to the Stanford Program on Geopolitics, Technology, and Governance, to discuss the risks of AI deployment. Jim explains why Open AI is suddenly a tech phenomenon, AI's potential risks without US regulation, advice for privacy and security best practices, and more.

Jun 22, 2023 • 31min
AI Governance and Responsible AI With Dr. Emre Kazim
Dr. Emre Kazim is the Co-CEO and Co-founder of Holistic AI, an AI governance, risk, and compliance (GRC) start-up focusing on software for auditing and risk management of AI systems. His PhD in philosophy and undergrad in science cleared a path for his role as a Research Fellow at the University College London's computer science department. Dr. Kazim explains that curiosity, exploration, and experimentation helped him enter the AI space. In this episode… Artificial Intelligence is a tool that has already revolutionized many aspects of our lives. As AI systems become more sophisticated, ethical implications become an increased concern. So how can we, as developers and users, ensure the systems are used safely, ethically, and responsibly? Dr. Emre Kazim explains how implementing policies and procedures, also known as AI governance, is one solution to protect AI integrity. AI governance includes addressing privacy, safety, and bias. While some organizations have created their own internal policies, others have adopted frameworks developed by governments or industry groups. When drafting AI governance policies, some general policies to consider are transparency, accountability, fairness, and explainability — meaning AI systems should aim to be explainable, so users can understand how it works. Listen to the She Said Privacy/He Said Security Podcast as Jodi and Justin Daniels welcome Dr. Emre Kazim, Co-CEO and Co-founder of Holistic AI, to discuss AI governance and AI responsibility. Dr. Kazim explains the meaning of AI governance and why companies need it, the challenges organizations face using AI, his best privacy and security practices, and more.

Jun 15, 2023 • 36min
Cybersecurity, Risks, and Why Your Company Needs a vCISO With New Oceans Enterprises Donna Gallaher
Donna Gallaher is the President and CEO of New Oceans Enterprises. New Oceans Enterprises is a Cyber, IT, and Operational Risk Management Advisory Service that facilitates collaboration among your company's business units to develop policies and operational risk mitigation strategies appropriate for your risk tolerance. Donna was recently recognized as one of the top 12 vCISO Influencers to watch and inducted into EC Council's 2023 C|CISO Hall of Fame. Donna currently serves on the Board of Advisors for the FAIR Institute and is President of the Atlanta FAIR Chapter. She is one of the founding members of vCISO Catalyst, a professional association for vCISOs. She holds CISSP, CCISO, CIPP/E, CIPM and ITIL, and Open FAIR certifications and is designated a Fellow of Information Privacy by IAPP. She is a graduate of Auburn University with a Bachelor of Science in Electrical Engineering. In this episode… In this age of technology, it's wise for companies to have some sort of cybersecurity expert on staff to protect the organization's data from theft and damage. But what happens if you're a startup or small company and unable to afford a full-time expert? Or perhaps you're a larger corporation with cyber technology in need of updating? Whatever your company's needs are, you may want to enlist the services of someone like Donna Gallaher, a securities strategist who owns a securities advisory firm that contracts out services. Firms like Donna's can provide a list of options to protect your company's data, intellectual property, and assets. Tune in to this informative episode of the She Said Privacy/He Said Security Podcast as Jodi and Justin Daniels welcome Donna Gallaher, President and CEO of New Oceans Enterprises, to discuss the role of a CISO. Donna explains the services a CISO offers, why smaller companies are prime targets for hackers, and how to prevent cybersecurity threats.

Jun 8, 2023 • 38min
A Conversation About the California Delete Act and Future of AI With Investor and Author Tom Kemp
Silicon Valley-based entrepreneur Tom Kemp is the Managing Director of Kemp Au Ventures, an angel investment firm where he and his business partner invest their personal funds into seed and early-stage companies. As an angel investor, he has funded over 15 tech startups. Prior to becoming an investor, Tom was the Founder and CEO of Centrify, a leading cybersecurity cloud provider. As a result of his nearly 15 years in privacy, Tom devotes his time as a policy advisor for Californians for Consumer Privacy. His first book, Containing Big Tech: How to Protect Our Civil Rights, Economy, and Democracy, a definitive book on Big Tech, will be available for purchase in August. In this episode… In April, the California Delete Act was introduced in the California State Senate, a measure seeking to give state residents the right to have their personal information deleted from websites and apps. While some people believe it necessary to protect privacy, others believe the legislation could be a burden for businesses. The California Delete Act risks creating a mass exodus for California companies — it could also jeopardize future investments in new products and services to collect personal information. With the ever-increasing collection of personal information by businesses, it's safe to say more needs to be done to protect individuals' privacy. So, is the California Delete Act too harsh or a step in the right direction? In this eye-opening episode of She Said Privacy/He Said Security Podcast, our hosts break down the California Delete Act with guest Tom Kemp, the Managing Director of Kemp Au Ventures. Together, these three privacy advisors inform us about everything we need to know about Senate Bill 362, the challenges of enforcing privacy laws, tips for reducing geolocation trackers, and more. This is one episode you don't want to miss, so get comfortable and tune in now!

Jun 1, 2023 • 31min
Where Privacy and Security Overlap
Robin Andruss is the Chief Privacy Officer at Skyflow, a privacy data vault dedicated to isolating, protecting, and governing sensitive data. Robin has 20 years of experience as a protection leader in the privacy, risk, audit, finance, strategy, and compliance space. She is a sought-after speaker on privacy, technology, and leadership. Additionally, Robin is a privacy tech advisor and sits on the Advisory Board of emerging tech startup Evident ID and is part of the Privacy Engineering group advisement team for Data Protocol. In this episode… With the combination of personal electronic devices, swift Wi-Fi and 5G, we can purchase medicine, airline tickets, and check our payslips online. As convenient as technology is, it can also be a curse, considering our personal data is at risk anytime we make online transactions. So, what can we do better to safeguard our private information? Like all technology, improvements in privacy are ever-evolving. But it's important to understand the types of privacy risks that exist to understand how to protect our data. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels welcome Robin Andruss, the Chief Privacy Officer at Skyflow, to discuss the current challenges privacy faces. Robin, along with Jodi and Justin, discusses AI in the privacy space, building scalable privacy programs, and the overlapping of privacy and security in data breaches.

May 25, 2023 • 27min
Compliance Scalability: Tips and Tools From RadarFirst CEO Don India
Don India is the CEO of RadarFirst, a company that helps businesses and their clients leverage emerging technologies. He has a strong and successful background as a sales executive and operator, with over 20 years of experience in delivering value to clients through cloud-based and on-premise solutions. Don has transformed organizations' business strategies at a global scale, specializing in C-suite relationships, sales management, and direct sales. He is well-known for his boundless energy, unwavering passion, and exceptional coaching abilities. Don is also deeply curious and knowledgeable about artificial intelligence, cloud, and disruptive technologies. In this episode… If you're a leader in a regulated industry, you know how challenging it is to keep up with the ever-changing regulatory compliance landscape. You need to scale your compliance program to meet the demands of new regulations, standards, customers, and products. You also need to make proactive decisions that align your compliance activities with your security objectives and business operations. To scale compliance effectively, organizations need to align their compliance activities with their security goals and business operations. They need to be prepared for the worst-case scenario — a data breach that could expose their sensitive data and damage their reputation. In this episode of She Said Privacy/He Said Security Podcast, Jodi and Justin Daniels talk to Don India, the CEO of RadarFirst, a software solution that helps organizations automate their incident response and compliance processes. Don shares his insights on how to scale your compliance culture, how to leverage technology to optimize your time and resources, and how RadarFirst can act as a lifeboat in case of a breach incident.

May 18, 2023 • 16min
Jodi and Justin's Top 5 Must-Haves in Your Company's AI Policy
Jodi Daniels is the Founder and CEO of Red Clover Advisors, a boutique data privacy consultancy and one of the few certified Women's Business Enterprises focused solely on privacy. Since its launch, Red Clover Advisors has helped hundreds of companies create privacy programs, achieve GDPR, CCPA, and US privacy law compliance, and establish a secure online data strategy their customers can count on. Jodi is a Certified Informational Privacy Professional (CIPP/US) with over 20 years of experience helping a range of businesses — from solopreneurs to multinational companies — in privacy, marketing, strategy, and finance roles. She has worked with numerous companies throughout her corporate career, including Deloitte, The Home Depot, Cox Enterprises, Bank of America, and many more. Jodi is also a national keynote speaker, a member of the Forbes Business Council, and co-host of the She Said Privacy/He Said Security podcast. Justin Daniels is a cybersecurity subject matter expert and business attorney who helps his clients implement strategies to better manage and recover from data breaches. As outsourced general counsel for Baker Donelson, Justin advises executives on how to successfully navigate cyber business and legal concerns related to operations, M&A, incident response, and more. In 2017, Justin founded and led the inaugural Atlanta Cyber Week, where multiple organizations held events that attracted more than 1,000 attendees. Justin is also a TEDx and keynote speaker and co-host of the She Said Privacy/He Said Security podcast with his wife, Jodi. In this episode… Artificial intelligence is transforming our world in many ways, raising ethical questions about its impact on human rights, privacy, fairness, and accountability. How can we ensure that AI respects our values and principles and does not harm or discriminate against anyone? AI can be a remarkable tool that can enhance our lives in various domains. However, it also requires responsible and ethical use. Companies that create and deploy AI systems must adopt policies that guarantee that these systems are reliable, transparent, fair, and secure. In this episode of She Said Privacy/He Said Security Podcast, join Jodi and Justin Daniels as they discuss the key aspects of AI systems. They reveal the essential AI policies companies need to implement to address data collection and use, transparency and accountability, and fairness and unbiasedness.

May 12, 2023 • 26min
Mitigating Security Breaches Through Distributed Data Command and Control
Andrew Hopkins is the President of PrivacyChain, a data security platform that encrypts each data record with a unique key, making it useless for hackers. Andrew believes that data security should start from the data itself and not from the perimeter. With his team of innovators at PrivacyChain, he is challenging the status quo and creating a safer online environment. In this episode… Data security and privacy are becoming more challenging in the digital age, especially with the rise of AI and data security threats. How can you protect your data from cybercriminals and AI-associated privacy breaches? How can you manage your data at a granular level without compromising its quality and usability? PrivacyChain offers a modern data security and privacy solution. It can prevent breaches, leaks, and tampering by ensuring that only authorized users can access and edit the data. PrivacyChain can also protect data from AI-generated threats by verifying its source and authenticity. Through distributed data management, you can store your data in centralized locations. In today's episode of She Said Privacy/He Said Security, Jodi and Justin Daniels interview Andrew Hopkins, the Founder of PrivacyChain, to talk about data encryption, control, and management. Andrew shares his insights on data security, privacy, AI, and how PrivacyChain can help safeguard your data.

May 4, 2023 • 24min
The Upsurge in Ransomware and Voice Phishing: How Managed Security Services Can Help
Krista Hollingsworth is the Chief Revenue Officer at Consilien, a managed services security solutions provider helping organizations protect their data from cyber attackers. In her role, she creates a security awareness culture through an integrated approach to cybersecurity awareness training for employees. Krista is also the CEO of Boutique Marketing Group, a digital marketing company providing mid-size B2B businesses with content, strategy, and lead-generating sales funnels. In this episode… Traditionally, organizations have relied on cyber insurance to protect against attacks. But as marketing and technology have become more elaborate, ransomware has intensified, leading to a 79% increase in cyber premiums. How can you develop a calculated security approach that addresses compliance and risks? As Krista Hollingsworth observes, cybercriminals are skilled marketers, with 82% of attacks involving human elements. Additionally, Krista predicts that the emergence of AI chatbots will lead to sophisticated voice phishing attacks, so businesses should implement two-factor authentication and other verification systems for maximum protection. Managed security service providers such as Consilien help businesses create and manage cybersecurity programs. In today's episode of She Said Privacy/He Said Security, Jodi and Justin Daniels invite CRO of Consilien, Krista Hollingsworth, to speak about the role of managed security services providers in developing cyber programs. Krista shares how the cyber sales cycle has evolved since the rise of ransomware, how AI could lead to voice phishing attacks, and advice for strengthening your passwords.

Apr 27, 2023 • 47min
AI and Privacy: A Future of Privacy Forum Conversation
Jules Polonetsky is the CEO of the Future of Privacy Forum, a nonprofit organization advancing principled data practices to support emerging technologies. FPF is supported by more than 180 leading companies and foundations. Jules has led the development of numerous codes of conduct and best practices and assisted in drafting data protection legislation. He is an IAPP Westin Emeritus Fellow, the 2023 recipient of the IAPP leadership award, and the Co-editor of The Cambridge Handbook of Consumer Privacy. With 30 years of experience in consumer protection, Jules has served as Chief Privacy Officer at AOL and DoubleClick, a consumer affairs commissioner for New York City, and an elected New York State Legislator. In this episode… The emergence of ChatGPT and other AI chatbots has added another layer to the convoluted privacy landscape, further solidifying the need for comprehensive regulations. So what should corporations and lawmakers consider when protecting consumer and public privacy? Companies often have a superficial understanding of customer data, lacking consideration for the nuances and categories of each set. But ChatGPT has introduced additional bias, which can lead to legal consequences. Privacy law advocate Jules Polonetsky says that to ensure AI remains compliant, organizations must apply data protection laws to public data sets. The Future of Privacy Forum offers a collaborative space to create and enforce policies and resolve pressing issues in the space. In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels welcome CEO of the Future of Privacy Forum Jules Polonetsky to discuss AI's privacy ramifications. Jules explains how to incorporate AI into global data protection laws, privacy's nuances and industry developments, and how to protect privacy when using AI chatbots.


