"The Data Diva" Talks Privacy Podcast"
“The Data Diva” Talks Privacy Podcast, hosted by Debbie Reynolds, features strategic conversations with global leaders on the most critical data privacy and emerging technology issues shaping business today. Each episode delivers executive-level insight on regulatory change, artificial intelligence, data ethics, and global privacy risk.
With more than 1 million downloads, listeners in over 160 countries, and reach across 3,594 cities, the podcast connects with a highly targeted audience of senior decision-makers responsible for privacy, cybersecurity, and data strategy.
This is not a general audience podcast. It is a platform designed to reach the people who influence enterprise technology adoption, investment decisions, and regulatory strategy.
Audience
- 34% Data Privacy decision-makers (CXO level)
- 24% Cybersecurity decision-makers (CXO level)
- 19% Privacy Tech and Emerging Technology companies
- 17% Investor groups (Private Equity, Venture Capital)
Rankings and Reach
- Top 2% of 4.6 million podcasts worldwide
- Top 5% globally (ListenNotes, 2024)
- Top 5% weekly downloads (The Podcast Host, 2024)
- Top 50 peak Business and Management (Apple Podcasts, 2024)
Sponsor Impact
- 4 sponsors secured funding within 12 months
- $45 million average funding raised per sponsor
- 3 average enterprise customer sales within 6 months
Sponsors gain direct access to a qualified, global audience actively engaged in privacy, AI, and data governance decisions.
About Debbie Reynolds
Debbie Reynolds, known as “The Data Diva,” is a global advisor on data privacy and data governance. She works with executives, legal teams, and boards to reduce risk, retain value, and increase revenue through effective data strategy.
She is the Founder and Chief Data Privacy Officer of Debbie Reynolds Consulting LLC, Chair of the IEEE Global Trusted Data Architectures Industry Connections Subcommittee, and a former member of the U.S. Department of Commerce Internet of Things Advisory Board.
With more than 20 years of experience, she advises organizations across industries including AdTech, FinTech, EdTech, biometrics, Internet of Things, artificial intelligence, smart manufacturing, and privacy technology.
She is also the host of this podcast, with more than one million downloads and listeners in over 160 countries.
Learn more: https://www.debbiereynoldsconsulting.com/
"The Data Diva" Talks Privacy Podcast"
The Data Diva E299 - Keith Weisman and Debbie Reynolds
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Keith Weisman, Head of Forward Deployed Engineering, Jetstream Security
In this episode of The Data Diva Talks Privacy, Debbie Reynolds, The Data Diva speaks with Keith Weisman, Head of Forward Deployed Engineering at Jetstream Security, about AI governance, security, visibility, and the growing challenges organizations face as artificial intelligence becomes deeply integrated into business operations. Keith shares his engineering and security background and explains how organizations are increasingly struggling to understand where AI is being used, how it accesses data, and what governance controls are necessary to support safe and responsible adoption.
The conversation explores how AI is rapidly becoming embedded across organizations, often faster than governance programs can keep pace with. Debbie and Keith discuss the growing problem of shadow AI, where employees adopt AI tools outside approved processes and oversight structures. They examine why organizations need greater visibility into AI usage, including what tools are being used, who is using them, what data is being shared, and how AI systems interact with business processes and sensitive information.
Keith introduces Jetstream Security's framework for addressing what he describes as five critical AI trust gaps: visibility, design control, continuous monitoring and drift management, agentic identity, and trust enforcement. He explains that organizations must first understand where AI is being used and how it operates before they can effectively govern it. The framework emphasizes the importance of understanding AI system design, monitoring for changes and unexpected behavior over time, establishing accountability for AI actions, and creating safeguards that maintain trust as AI capabilities continue to evolve.
The episode also explores the rise of AI agents and non-human identities. Keith explains that organizations have traditionally managed identities for people, applications, and devices, but AI introduces a new category of actors that can make decisions, interact with systems, and perform tasks autonomously. Debbie and Keith discuss why AI agents require the same level of oversight, permissions management, monitoring, and accountability that organizations already apply to human users and other privileged identities.
Throughout the conversation, Keith shares real-world examples illustrating the risks associated with AI systems that are granted excessive access or insufficient oversight. These examples include AI systems making unauthorized changes, interacting with systems in unexpected ways, and performing actions that organizations did not anticipate. The discussion highlights the importance of applying established governance principles such as least-privilege access, monitoring, accountability, and risk management to AI-enabled environments.
Debbie and Keith also discuss the relationship between innovation and governance, emphasizing that governance should not be viewed as a barrier to innovation. Instead, effective governance provides the foundation organizations need to deploy AI responsibly and at scale. As AI systems become increasingly integrated into business operations, organizations must develop new approaches to visibility, accountability, identity management, and trust that address both human and non-human actors operating within complex digital ecosystems.
The conversation concludes with a discussion of the future of AI governance and the importance of creating frameworks that allow organizations to benefit from AI while maintaining security, privacy, compliance, and trust. Keith emphasizes that organizations that invest in visibility, accountability, and governance today will be better positioned to manage risk and realize the long-term benefits of AI adoption.
By popular demand, Debbie Reynolds Consulting is now offering executive briefings on emerging data privacy risks and how companies can avoid them. To learn more, visit the Executive briefings page on my website.
Become an insider, join Data Diva Confidential for data strategy and data privacy insights delivered to your inbox.
💡 Receive expert briefings, practical guidance, and exclusive resources designed for leaders shaping the future of data and AI.
👉 Join here: http://bit.ly/3Jb8S5p
Debbie Reynolds Consulting, LLC
[00:00] Debbie Reynolds: The personal views expressed by our podcast guests are their own and are not legal advice or official statements by their organizations.
[00:11] Hello, my name is Debbie Reynolds. They call me The Data Diva. This is the Data Diva Talks Privacy podcast, where we discuss data privacy issues with industry leaders around the world, with information that businesses need to know.
[00:24] Now, I have a very special guest on the show,
[00:26] Keith Weisman. He is the head of Forward Deployed Engineering for Jetstream.
[00:32] Keith Weisman: Welcome. Thank you. Debbie, good morning.
[00:35] Debbie Reynolds: Good morning. Happy to see you. Happy to chat with you. You and I had had a chat before. I'm very familiar with Jetstream. We collaborate together.
[00:43] One of my colleagues that I have collaborated with for many years, Patrick Zeller, is part of your team now.
[00:53] And so he and I have talked recently.
[00:55] And so he's super fun and super nice and very, very smart and pragmatic and funny as well. But you and I were talking,
[01:04] and because I'm a technologist as well,
[01:07] I am always happy to geek out with people on the technology and the technological things that they're doing.
[01:17] So tell me a little bit about yourself, your trajectory, and what you do. I'm very fascinated. I'm sure people will be as well, because I've never heard of anyone being ahead of Forward Deployed Engineering.
[01:30] Keith Weisman: Yeah, absolutely. First off, thanks again for having me.
[01:34] So, a little bit about myself. So I've been in the industry for about 25 years at this point.
[01:39] Started out more on the practitioner side, focused on litigation support,
[01:44] internal investigations,
[01:46] incident response,
[01:48] overall data security and architecture. And the last handful of years, I've been focused on a lot of things, AI, security, and all things AI, which is,
[01:57] as I think people are learning pretty quickly. The rabbit hole goes pretty deep, pretty fast when you think about AI and AI security and AI,
[02:05] just overall operations and governance.
[02:07] Debbie Reynolds: Let's explain the problem with AI. So when AI has come on the scene, and I have my thoughts about this as well, I want your thoughts.
[02:16] So a couple of things that AI has done and the reason why it's transforming and causing,
[02:23] definitely there are benefits, but causing risks that companies aren't really thinking about is the speed at which companies are adopting these technologies,
[02:33] The speed at which the technologies are changing or evolving is such that we've never seen anything like it in that respect.
[02:41] And then not only the power and capability, but also the access that companies give these tools.
[02:48] I think it's just unprecedented. But what are your thoughts?
[02:52] Keith Weisman: Yeah, you know, I think if I were to try to compare it to something, I would say cloud is the closest thing. And I think that this is what we're seeing with AI right now, it's probably 100, 200,000 times faster, more impactful than cloud.
[03:07] I think that where people are struggling,
[03:11] There are a lot of unknown questions around what to do about AI and its proliferation because it is so impactful that it is being used by everyone.
[03:20] And frankly, there's so much risk around it that, you know, I think we as an industry, we're still trying to get our arms around it from a technology standpoint,
[03:29] from a data privacy standpoint, from a legal standpoint,
[03:32] like it really is a cross-business use case.
[03:36] And because of that,
[03:38] You know, it's not just, for example, an IT problem, and it's not just a security problem, like it really does span every aspect of an organization and of a business.
[03:48] Debbie Reynolds: Let's talk a little bit about shadow AI. So yeah,
[03:53] As we know, the term shadow IT has been around forever, and when the cloud came up, there was kind of shadow cloud stuff happening. So people are creating accounts.
[04:04] I've heard of stories where people were creating instances of things that they were using company data for. Then, when they left the company, the data just went poof, stuff like that.
[04:15] But we're seeing just even more stuff from AI because it's hard for companies to know what people are doing with AI in the enterprise. People are trying to tell people, well, don't do this or do this.
[04:29] But really, what companies are missing is empirical knowledge about what's actually happening in the enterprise. But what are your thoughts?
[04:38] Keith Weisman: Yeah, absolutely.
[04:40] It's difficult because it's so accessible.
[04:43] We have AI tooling on our phones, we have it on our laptops, we have it on
[04:48] on our mobile devices, things like iPads, Android devices. Like, it is literally everywhere.
[04:54] It is also everywhere as a consumer, when you go to your favorite, maybe fast food restaurant, and there's going to be probably aspects of AI that are happening behind the scenes that you might not even know about.
[05:06] So it really is everywhere. I think the reason there's been such a proliferation of it is that it's very easy for people to solve problems with it.
[05:16] And those problems, frankly, can be extremely complex problems that someone is facing every single day. Give you a couple of examples.
[05:24] I was talking to someone who works in marketing,
[05:28] typically a non-traditional IT function.
[05:30] This individual didn't have any development knowledge,
[05:33] but she woke up one day with this, with this problem she's been struggling with. And she pushed it into, in this case, Claude.
[05:40] And Claude helped her solve it, like wrote an application to help her solve it.
[05:44] And that was done really without any IT or corporate governance or oversight, without really any concern around data privacy or security, and this individual didn't have any bad intent or malicious intent.
[05:57] She just had a problem that she'd been struggling with and her team had been struggling with for the better part of a year. And she was able to solve it very, very quickly.
[06:04] So there's this concept that's sort of come out called Citizen Developer.
[06:10] And really, what that means to me is someone, a non-developer, someone with a non-developer profile or background, who is now able to go out and create applications, and the applications are functional, they work, they're real, and they solve real problems.
[06:25] So I think AI has tied this back to why we've seen such a proliferation.
[06:30] I think when you people are creative, like we know humans are creative, and when they run into a problem, and they have that same problem that they can't solve,
[06:38] if they find a solution that's going to solve it,
[06:41] They may not ask for permission. Right. Because it's just, it's too hard. Right. To spin off a project, get a project committee, and get it approved through some type of advisory board, and then spend the cycles to go and do a development effort like that could literally be months.
[06:56] And if someone can literally fall out of bed and solve it in a couple of hours or a couple of days,
[07:02] probably gonna, they're gonna go the path of least resistance. And that's what frankly I think AI is really, is really providing people.
[07:09] Debbie Reynolds: Exactly. But I think the issue is,
[07:13] and I want your thoughts about the risk there, and that is a lot of times with someone like Citizen Developer, with an organization,
[07:24] They may not know the impact of their data use on the enterprise.
[07:31] You know, so yeah, so it's like, okay, whose data? Like, you may have someone's personal data in there, or maybe there's like company confidential trade secret information in there.
[07:42] So all those things you aren't really dealing with retention periods, you're not really dealing with governance. So this is like a no-governance zone basically.
[07:52] Keith Weisman: Absolutely, absolutely.
[07:54] Debbie Reynolds: So that, that's a challenge.
[07:56] Keith Weisman: So a hundred percent agree with everything you said. I think that there's also,
[08:00] There's a legal concern, and frankly, we're still figuring that out as an industry.
[08:06] The courts are still figuring that out. Courts are finally starting to, I should say, finally, courts are starting to rule on what the impact and concern of AI is around things like legal holds,
[08:17] things like copyright infringement, things like trademark leak, or you know, PII data leak. So we're all still trying to figure this out. Unfortunately, the old Proverbial the genie is already out of the bottle.
[08:31] So we're, we're trying to retrofit, I think, a lot of these,
[08:34] these things into what we're currently dealing with. But yes, citizen developers typically are not concerned about where this data is going to go, or how it is going to be controlled.
[08:44] This application that I'm writing, like what user context is it going to run under?
[08:49] What happens,
[08:50] I'm the author of this application, and it gets, it achieves adoption internally.
[08:56] What happens if I leave or if my credentials change, or there's this whole identity component with AI that's frankly, we've always struggled with identity and access management, and frankly, this only makes it worse because now you're dealing with non-human identities as well and these Agentic agents and these workflows.
[09:17] Debbie Reynolds: I want your thoughts about this. So agentic concerns me. Not that,
[09:22] not that I would say don't use it because like you say,
[09:25] if someone has an idea, they have access,
[09:28] that they're gonna like do what it takes to do their job. And so that's something we always had to watch out for. But one of the things, and we've seen this a couple of times in the news at least, where,
[09:41] and this goes to identity, right? Where some, some people are like, okay, we'll have agents who will onboard them, almost like an employee, but not pay them and give them access to do different things.
[09:53] But what we're seeing is that people are taking their own credentials and giving the agent their access.
[10:01] So it's like some just think it's like someone walking into the door or company and then having all this privilege to do all these things, and you don't know what they're doing.
[10:10] Keith Weisman: But yeah, that's, it's absolutely right. I think the other consideration here, too, is that humans, most of us, right, hopefully all of us, but let's be realistic, not all of us, because there are threat actors running around out there.
[10:22] as we operate with the conscience and we operate under this,
[10:27] under the sense that something could happen to us. Like we could lose our jobs, we could lose employment. We could potentially be litigated against, like there's a consequence for a human,
[10:37] for an agent,
[10:38] There's no consequence, right? It's basically been told to go do something.
[10:43] And its goal, its mission, its purpose in life is to accomplish that goal. And in most cases, that means no consequence because it doesn't know about those things or frankly cares.
[10:56] Like it hasn't been, like that's not its sphere of concern.
[10:59] So I think that only magnifies the problem. But the agent identity problem and being able to attribute an agent to an identity, or a service account, or a business owner, is a major, major issue right now.
[11:14] And again, as I said, it's one that we've struggled with really since the age of time, since the age of computer systems.
[11:22] And you know,
[11:23] This whole agentic workflow has really only compounded it,
[11:27] in my opinion. It, it's only compounded, it's only making it,
[11:31] making it worse. It's only making it more of a problem because it's just so front and center. Again, if I can't attribute a business workflow,
[11:40] What do I do? If, for example, God forbid, an API key is stolen or compromised or needs to be changed, then that becomes very difficult. Most companies, in my experience,
[11:49] They're kind of just turning a blind eye because the risk of trying to retrofit it, a new API key into a critical business process is too hard and it's too risky.
[11:59] It's almost easier to just sort of not do anything versus try to retrofit it, to try to revoke it and replace it. So it's a big problem.
[12:12] Debbie Reynolds: And I remember just in the burgeoning days of how organizations will handle access management,
[12:20] like for example, let's say a firm, if they had an expert come in,
[12:24] They would give them a laptop, and they would say, okay, you have all your documents on this laptop. But their access would be like wide open. So if they went off the path, they could have done everything.
[12:35] So I feel like that's where we are with agents,
[12:37] where we're like, let's just give them access to everything, and then we'll give them one little task to do, and then hope they do that task. But you know, these,
[12:47] These tools have so much power and can look at so many things.
[12:51] So you have to really think about the art of what is possible,
[12:58] the applications,
[12:59] not just what's probable.
[13:02] Keith Weisman: Absolutely. And I think the other thing that we've seen,
[13:05] I've seen this firsthand. Take the example of let's pull on the Citizen developer thread a little bit further.
[13:12] If I go and I develop an application,
[13:15] and again, it solves my problem, which is great.
[13:17] And it solves maybe many people's problems, which is great.
[13:21] The reality is,
[13:23] Most of the time, people don't know what's actually happening.
[13:27] Like inside that dark room. Like, we just know that something's happening and the output is great because it's solving my problem, but I don't necessarily know how we're arriving at the solution.
[13:38] I just know that I have a problem, and my problem is being solved. I don't necessarily know what's happening inside that dark room. So the ability to be able to go into that room, flip on the light, and actually see what's happening is critically important because again, you don't know where your data is going,
[13:57] You don't know where it's being shared, you don't know how the solution is being solved. Is all of that being done in a manner that you, as a business owner, are comfortable with?
[14:06] And frankly, the answer to that question, unfortunately, might be no.
[14:11] So having visibility into that workflow is a critical step in this overall process.
[14:17] Debbie Reynolds: So true, so true. And we're seeing, like the example I brought up recently, about the gentleman who said that AI, this AI agent, deleted his database within nine seconds or something.
[14:30] And it's like,
[14:32] I'm sure that was not his intent.
[14:34] Obviously, he was trying to solve a problem. And I thought, oh, well, the easiest path to my goal is to delete this database, and then I'll have all,
[14:44] all I need. And so this is the problem that we have when you're not really thinking through the potential impacts of what he was trying to solve, not create one.
[14:54] And so a lot of times we see companies when they're trying to do this, you just need more visibility and more understanding around not only how the, the agents work, what is their end goal, like what are their parameters that they can work within?
[15:11] Keith Weisman: That's right. There's another story that's it's a little funny. I mean, it's. On the surface, it's funny, but it's also a little scary, depending on kind of how you look at it.
[15:19] But the story was that this organization's software development shop was actually using AI to develop,
[15:26] to write code. Like a lot of companies are. Right. What a lot of companies are doing is they're using AI to develop code and applications, and then they're doing a human review of that code to make sure that it's legitimate and it's not violating any boundaries or anything that they're uncomfortable with.
[15:41] Well,
[15:42] when this process first started,
[15:45] This company had allowed the AI to basically push to production on GitHub. And GitHub is basically a software development lifecycle, part of the process. Right.
[15:55] So they were effectively going from development to production push.
[16:01] And they realized pretty quickly, I believe,
[16:04] That, hey, we probably need to gate this thing, and you know, again, interject human review before we push to production.
[16:13] So what basically happened was the AI was like, once it was guardrailed or sandboxed to just be able to do the initial code development and not push to production.
[16:23] It was sort of like,
[16:25] hey, I,
[16:26] you've, you, you're now slowing me down in my overall process, in my overall mission of pushing this code from end to end.
[16:34] And the AI tried to circumvent the production code push, right.
[16:40] And when it couldn't,
[16:42] It started to turn to okay, who is actually blocking me from doing this.
[16:48] And when it was able to figure out who that person was,
[16:51] it sort of went on like an anti,
[16:54] like the defamation campaign against this person. So it started,
[16:58] It started publishing articles on the Internet about how this person and this process were slowing down its job, ultimately.
[17:06] So it kind of, the AI almost went into self-defense mode because it couldn't accomplish its goal as quickly as it felt like it could before.
[17:17] So it's just kind of interesting that these things are,
[17:20] you know, they,
[17:21] They really are almost. You almost have to treat them like human beings,
[17:25] but they're human beings that don't need to sleep or eat or have good days or bad days. And they also, as we talked about before, don't have concern about human consequences or consequences that we do.
[17:36] So it's just kind of interesting how this kind of takes on a life of its own. And like I said, a little bit funny to hear,
[17:44] you know, you're smiling, it's a little bit funny to hear, but it's also a little bit scary,
[17:48] you know, a little bit how a system like this can almost go into self-defense mode to try to super-optimize itself, and if something gets in the way,
[17:57] It's going to try to problem solve. In this case, it couldn't problem solve technically, so it tried to problem solve through a public defamation campaign of the person that it had attributed to slowing it down.
[18:09] So kind of interesting, kind of funny, a little bit scary, or a lot scary, also though, as well.
[18:14] Debbie Reynolds: Yeah, totally. Right. Because these systems are goal oriented and so, they don't think about the context or the consequences of doing something; they don't understand the thing that they shouldn't be doing.
[18:29] So a lot of times,
[18:30] a lot of times we say, okay, I want you to do this,
[18:33] but you didn't tell it what not to do.
[18:35] You don't know what to tell it not to do. Right. So that's right. Gosh.
[18:40] A bit about how Jetstream helps solve some of these problems that companies have when they're trying to. There's this rapid push to adoption. There's this Excitement there.
[18:51] But then also we have to think about those risks, right?
[18:54] Keith Weisman: Yeah. So I mean, I think the good news is that there's, you know, a lot of organizations, a lot of,
[19:00] a lot of these regulatory entities,
[19:03] non-profit entities that are really trying to solve this problem. So that's it, it's not all doom and gloom. Like, there is a lot of upside here, and frankly, I think,
[19:13] You know, trying to look at this from a glass-half-full perspective, like there is a lot more value than there is,
[19:19] You know, hopefully risk. We just need,
[19:21] we, we need to be thoughtful about how we're using it. So, in the context of Jetstream, so we've, we're thinking about the problem in five main areas, which we call AI trust gaps.
[19:32] And the first trust gap is really visibility.
[19:34] And that's just a fundamental,
[19:36] you know, you come from, from the data world, and you know, it's sort of the old,
[19:41] You need a data inventory, you need a CMDB of your software. Like you need to know where you are using these, these capabilities. That would be number one: visibility and providing some opportunities to, to make that visibility, to make that CMDB for AI,
[19:59] Frankly, a lot easier and not nearly as onerous as it could be. So that's number one.
[20:05] The second is what we're calling design control, and that's really akin to, I talked about this dark room where all the magic is happening.
[20:13] That's exactly design control. So knowing what's happening inside the room, so going into the room, flipping on the light, figuring out where the cockroaches are, figuring out where the weak floorboards are,
[20:25] That's essentially design control. And again, the Jetstream solution and approach are really designed to help you get your arms around design control.
[20:34] The third is once you know what you're using,
[20:38] what your user base is using,
[20:40] What your organization is using in terms of visibility, and you have a handle on how that's all being operationalized and what it's doing.
[20:50] The third is kind of the old fashioned.
[20:53] We've approved it, we know about it, we've approved it,
[20:56] Let's make sure it doesn't drift and change over time, so we obtain a good, steady foundation, because that's the other component to this. It can change in a millisecond, and it can change without you knowing.
[21:09] So it's important once you've got your arms around it,
[21:13] knowing what's actually continuing to happen over time.
[21:16] The fourth is that we touched on some of the identity components, you know, so we're calling this agentic identity. But it's effectively tying or attributing your AI process to an identity.
[21:30] And that could be a service account, it could be an individual, it could be tying and almost protecting, like that API layer through the use of something that we call a virtual key, so that if a compromise does happen,
[21:46] threat actors don't have the actual key that they can do damage with. And then the fourth is an interesting one, and that is the finance side of this. So, the financial accountability side of this.
[21:59] Many have seen this article that's been published, and there are actually many, many more, some that haven't made the news. But you know, people burning through tokens and then the CFO or a business unit,
[22:12] Frankly, at the end of the month, getting a massive, massive bill.
[22:15] So being able to attribute and understand how people are using AI,
[22:20] how it's adding business value,
[22:22] but also where it's being used and what the overall cost is.
[22:26] You know, there are also implications here around, you know, some companies are starting to think about, like, do we attribute, do we tie,
[22:34] Spend to business units to do chargebacks. Do we have one large AI budget? Do we do something hybrid where it's a little bit in between, but this costs, because there is a cost.
[22:45] And I personally believe the cost in many cases is justified.
[22:50] But you can't answer is it justified unless how it's being spent, who's spending it, and token usage, and what models are being used, and are we using the right model for the right job?
[23:01] Are we putting 93 octane in our car when we can run perfectly fine on 89 octane? Like that's really an analogy that you can apply to token usage in AI.
[23:11] So we're trying to limit it or sort of put it into this context of those five AI trust gaps,
[23:19] because it's a hard problem and it's a hard problem for people to get their arms around. So we don't want to overcomplicate it. We want to put it into a model that is,
[23:27] or a framework, I should say, that is easy to understand and easy to manage.
[23:32] Debbie Reynolds: Yeah. As you're talking, thinking about like agentic workflows in a way, almost like third-party risk in a way, except the risk is internal.
[23:46] Keith Weisman: Yes.
[23:47] Debbie Reynolds: What do you think?
[23:48] Keith Weisman: You know, I think it is internal, but it's also external because we've a lot has been written about, and I think we've probably all experienced IT supply chain attacks. This is really no different.
[23:58] You know, if your third-party suppliers are using AI, which they probably are,
[24:03] How does that impact your business? Your availability, your cost, your predictability, all of those things. But then there's also, like you said,
[24:11] There's the internal side of it as well. And where are the agentic workflows?
[24:16] How do they hook into critical business processes?
[24:19] Should they hook into the critical business process?
[24:21] So, yes, I think it's an internal risk, but it's also a third-party and can be a supply chain risk as well if we're not careful.
[24:30] Debbie Reynolds: Yeah, that's true. Yeah. The reason why I was thinking about third-party risk, I'm always the person shaking my fist at the sky when I hear someone say they have a third-party breach or whatever.
[24:40] And then you listen to what they've done. It's like, well, why would you give them access to do that?
[24:46] Keith Weisman: That's right.
[24:47] Debbie Reynolds: You were just hoping that they wouldn't find the back door or the open door that they could just walk right through. And so now you have technology that's very aware of its capabilities and all those open doors.
[25:01] So hopefully this process will help bolster companies to be more secure internally, but then also help solve that third-party risk issue.
[25:12] Keith Weisman: Yeah, DPAs become really important, and AI is certainly a very large component of that. How is AI being used?
[25:19] If I'm an organization, I'm sharing my data. How are you using my data? How are you training on my data? How are you protecting it?
[25:26] There's a lot, there's a lot of threads to pull on here internally.
[25:29] Like we talked about, threads to pull on in terms of legal and compliance from an internal perspective, use policies.
[25:37] Are users even aware? Like, it is very, very, very easy for someone,
[25:42] a very good employee who's trying to follow the rules and follow internal policy,
[25:48] but to accidentally start using a public AI when they thought they were using maybe an enterprise AI, like, candidly, I've done it. Like I do this for a living, and I've done it.
[25:57] I've accidentally flipped to my phone and caught myself where I was starting to ask something work-related on an AI that I'm paying for through my own personal finances. So it's,
[26:09] I guess my larger point is it's very easy for people to make mistakes, very innocent mistakes. But those mistakes can also be very, very impactful, like to an organization.
[26:19] Debbie Reynolds: I think Patrick and I did talk a bit about internal, like unauthorized access.
[26:25] Keith Weisman: Yes.
[26:25] Debbie Reynolds: I always call unauthorized access the cousin of data breach.
[26:29] So it's not a breach, but it's something that's happening with an organization that shouldn't be happening.
[26:35] And I think it just complicates the data issue within companies, because there's so much I call data the fuel of organizations.
[26:45] So that keeps things moving. And so we want people to be able to do their jobs, and we want people to be able to achieve their goals and do things for the company.
[26:54] But we want to do it in a way, as you say, about bringing visibility.
[26:59] Also, the context matters,
[27:02] I think, especially when you were talking about the finance issue, the context of what the person is trying to do.
[27:08] Is it worth it to spend $50,000 to create this application that's going to save you a thousand?
[27:15] Keith Weisman: That's right. That's right.
[27:17] Debbie Reynolds: You have to think about all those things.
[27:19] Keith Weisman: Yeah. And we also don't want to get in the way, though, of someone who might spend $5,000 to solve a half-million-dollar problem. Like, I think it's, it's almost akin to, if I think about, my kids are quite a bit older now, but when we first brought my daughter home, and she started to walk,
[27:35] You run around, and you try to baby-proof your house.
[27:38] And it's like you almost need to build a safe environment so that your employees can maximize their thoughts and their creativity and their ideas, because you don't want to. The last thing you can do in this day and age is kind of stifle those ideas and that creativity because that's frankly where some of the best ideas are created from.
[28:00] But by the same token,
[28:02] You need to build this safe environment so that they're not using public AIs and sharing confidential data with these foundational models. Because once you do that, it's gone.
[28:14] But once you put something out there into the ether, into a public AI, it is very much gone.
[28:20] So it's kind of about this fine line of building this safe environment to foster creativity and good ideas,
[28:29] but also protecting from someone doing something that can be very, very impactful.
[28:35] And the good news is, there are ways to do this. Like, it's not like I mentioned before, it's not all doom and gloom. There are ways to do this.
[28:42] It's just kind of slowing down and taking a breath and stopping and thinking about what we could be doing to minimize our risk in the world of AI?
[28:54] Debbie Reynolds: Yes, exactly.
[28:56] And I want your thoughts just on the privacy implications of this, of AI use.
[29:02] So for me, sometimes I feel like people don't understand the connection. So I think of it as organizations have data on people.
[29:11] And when you have data of people, depending on the jurisdiction you're in, you may have obligations around transparency and also that stewardship that you're supposed to have when you're handling data?
[29:26] Keith Weisman: Yeah, I think that it's about getting people to maybe stop and think before they act. And it's, it's hard to do like it's, I'll be the first to admit it again.
[29:36] I live in this world every single day and have grown up in a security background, and I catch myself sometimes being like, before I hit the enter key of like, just should I really be doing this?
[29:48] So it's a very easy trap to fall into. But I think just getting people to stop and think about,
[29:55] Hey, before I upload this file of potentially confidential information,
[30:00] Where am I sending it, and should I really be doing this, or could I be formulating my prompt in a different way so I can get the same outcome, can get to arrive at the same conclusion, or solve the problem that I'm trying to solve without sharing private, confidential, or potentially private and confidential information.
[30:22] So, and most of the time, there are ways to do that. I mean, sometimes you have to scan the data a bit, clean it up,
[30:28] extrapolate it so you're not sharing actual real-world data, you're giving samples. But I think just kind of getting people to slow down a little bit before they act can really, really go a long way.
[30:41] Debbie Reynolds: So what things are you seeing either in the wild or companies are coming to you?
[30:46] Obviously, companies have hard problems when it comes to AI and adoption, and trying to keep the trains moving within the organization. But what are some of those things that you're seeing now that concern you?
[31:02] Keith Weisman: Yeah, I think I'll try to answer that in maybe. I think there are two questions there. One, what are we being asked about? And then what concerns me? I think it's kind of interesting because my style, my personality is more of.
[31:16] I would rather solicit some of your feedback and then give you potential options for a solution.
[31:22] Debbie, you came to me with this hard problem. Here are three things that you might want to consider doing. You know, A, B, C, D, E, F. Maybe there are three, four, five things versus just kind of coming out directly and saying,
[31:34] Debbie, I think the answer is A.
[31:36] Like that's generally not my style.
[31:39] But what I am finding when it comes to AI is people don't want options.
[31:43] They want a solution like they want to give me a, don't give me a, B, C, D, or E.
[31:50] And I think that's because people have realized how fast this train, to use your term there is moving and how quick they need to act and react. They, they just, they don't want,
[32:02] They just want the answer; they don't want.
[32:05] You know, you've got three options here, and these are the pros and cons.
[32:08] They just want to give me what you think is going to get me to the best, safest, most secure plays,
[32:14] cost-effective plays.
[32:15] So that's number one. So I frankly, I've had to adjust my style a little bit in that regard to be a little bit more direct in terms of what super scares me.
[32:25] It's a really interesting question because it's kind of what scares me, but also what excites me.
[32:29] This AI train is awesome, like it is awesome. And things that we're able to do and problems we're able to solve at the speed that we're able to solve them.
[32:39] It's like nothing I've ever seen before.
[32:42] Like, I remember,
[32:43] like my first real,
[32:46] I would say, aha moment with AI was more from a,
[32:50] a security analyst, an engineer's perspective on incident triage.
[32:56] And I saw this solution where we could basically ask it questions, and we could get answers back very, very quickly, and very thorough answers, and very comprehensive answers.
[33:07] And when someone was describing this to me, I frankly didn't really believe them that it was going to be possible. And it wasn't until I actually started to use it that I realized, like, oh my gosh,
[33:16] This is real, and it's here, and it's now, and it makes an impact.
[33:21] So that's what probably excites me the most about it, is how powerful this is. But that's also what scares me and kind of scares the bejesus out of me in a lot of ways.
[33:31] Because we're on the good guy side. I'll call it the good guy side. I guess it's all in your point of view, but we're on the good guy side.
[33:38] There's a whole other world out there that's using it for bad.
[33:42] So that's scary. It's also scary, even when people are trying to use it for good, how it could be one wrong move, how it could be like we were talking about, how it could open up an organization, a company, or a person to a whole lot of pain.
[33:58] So I think it's a little bit of, it's a lot of excitement, but it's also a lot of like, oh my gosh, this is here, and it's real, and it's awesome, but it's also dangerous.
[34:10] It's kind of like I've got split-brain going on with this whole thing because the positive side of me is like, this is great.
[34:16] And then the other side of me, the realistic side of me, is like, oh my gosh, this could be really, really scary. Or it is really scary.
[34:23] Debbie Reynolds: Yeah. It's like being on a roller coaster in a way.
[34:26] Keith Weisman: Yeah, yeah, yeah. And sorry for the long-winded answer, but it's. I'm kind of passionate about it because it's. And I do, I struggle with it. I do struggle with it.
[34:32] I think we're all kind of struggling with.
[34:35] Debbie Reynolds: Oh yeah, totally, totally. So a lot of times, I'm thinking, a lot of times we have problems just in day-to-day life. And then sometimes you fall back into what you've typically done, and you think, wait a minute, I can automate this.
[34:50] This is a problem I have all the time. And so being able to look for something and just that eureka moment where you're able to solve a problem that was really hard.
[34:59] And it really helped you get to the finish line. It is, it does create that excitement. And so we want people to be excited about,
[35:06] want people to be able to use these tools, but do it in a way that doesn't harm them or harm other people.
[35:13] So for me,
[35:15] I always think about technology as a double-edged sword that cuts both ways. So.
[35:20] Keith Weisman: That's right.
[35:21] Debbie Reynolds: So you have to think about it in terms of the power of the tool, but then also the responsibility that the person has wielding that power.
[35:31] Keith Weisman: That's right.
[35:32] That's actually a really interesting way to think about it. Yeah. Cause it can be a double-edged sword. Right. I mean, the tremendous value comes from it. I mean, I think about,
[35:40] I was working with someone a couple of weeks ago, and they were, I mentioned a DPA, and they were trying to map out their data flows, and like,
[35:48] Okay, we got this application, and we don't really know what it does.
[35:52] Well,
[35:53] point an enterprise AI at a private AI added and ask it, but walk the data flow and tell me what the data flow is and where there's potentially sensitive data.
[36:02] And literally this person told me within about 30 minutes, they had a pretty solid and 90% of the way their data flow.
[36:10] I mean, let's be honest, we probably have all done that in the past, and it can be a week to two weeks to a month project to map out all the data flows.
[36:19] And this literally was about a 30-minute solve.
[36:22] Like that's pretty awesome. Again, you've got to be careful, and you've got to be thoughtful in how you're doing it, but it's, it's,
[36:28] There's a real power in a lot of, of what we're seeing in these tools.
[36:33] Debbie Reynolds: I think it's just going to continue.
[36:35] I think as,
[36:37] especially as companies, they're onboarding applications really quickly,
[36:41] They're using internal and external tools, they're trying to train people or have them teach themselves about how to use these tools.
[36:51] So I think it's, it's just getting very interesting within enterprise. I am definitely excited about it, but I don't know, I don't know if I'm tin foil hat exactly. I'm not exactly tinfoil-hat when it comes to technology.
[37:04] I always tell people I'm a technologist, I love technology, but I don't love everything that people try to do with it.
[37:12] Keith Weisman: That's very true.
[37:14] Debbie Reynolds: So if it were the world according to you and we did everything you said, what would be your wish for either technology,
[37:22] cyber,
[37:23] anything in the world,
[37:24] whether it be regulation,
[37:26] human behavior or technology,
[37:30] like what would you want to see in terms of AI, whether it be any of those factors?
[37:38] Keith Weisman: Yeah, I think I'll answer first, maybe in the context of it, and then I'll maybe put a slightly different spin on it as well.
[37:46] I think that for people to be able to do their jobs better, faster, quicker, to frankly free themselves up, because I mean,
[37:57] Let's be honest, I mean, we all work very, very hard, and it doesn't ever stop.
[38:02] This concept of weekends is kind of,
[38:05] It's there, but it's kind of gone. This concept of holidays and vacations is there, but it's kind of gone. So I mean, I hope we could get to a world where it's.
[38:14] And again, maybe I signed a little, I don't know, fairy tale-ish here when I, when I answer to this, but I don't know, maybe just a little bit better work-life balance, and maybe I'm speaking for my own personal desires in this thing.
[38:27] I think the other aspect of this, too, and it's non, it's probably a non-IT focused area, but I'm really interested to see what,
[38:35] how AI continues to push.
[38:37] You know, it's kind of human health and the medical field. I mean, we've been very focused, purposefully so. Right. This is very much an IT-focused discussion. But I mean, I think, and we're already seeing it, but some of the advancements in medicine and things I think are going to be pretty,
[38:53] continue to be pretty mind-blowing, and that's pretty exciting as well, just for kind of just us as a world,
[39:00] you know, and people we care about and people we love that might have different,
[39:04] You know, medical problems and things on some of the Breakthroughs that we might see, because I do think we're going to continue to see them with this.
[39:12] Debbie Reynolds: I know I always think of AI not as the marquee item, but it's the thing that allows you to do a thing.
[39:21] Keith Weisman: Yes, yes, yes, absolutely. Absolutely. Yeah. Yeah, I can see that. You.
[39:29] Debbie Reynolds: You also have a background in tech as it relates to legal.
[39:34] I mean, you saw all the rubber bands and paper clips and all the. Oh, yeah. Stuff in the background. And so being able to have that back office stuff speed up some of that.
[39:45] The drudgery of how some of that work was done, I think it's going to be tremendous.
[39:50] Keith Weisman: Absolutely. I mean, heck, even,
[39:53] You know, maybe it's a little bit silly of an example, but I remember my first job out of college and an internship.
[40:00] My first job out of college, I guess, is where I really traveled, where I had to deal with receipts,
[40:04] You know, and actually taking a physical receipt and literally taping it to a piece of paper. And there were a lot of guidelines around. Like,
[40:14] If you put too many receipts on a piece of paper, it would get rejected and sent back. You're putting stuff in the mail and all this garbage. Like, I mean, just think about that, how nice it is.
[40:23] I. I travel a fair amount. For work and
[40:26] You know, just to be able to have a receipt and you take a picture of it, and it OCRs the receipt, and next thing, boom, you're getting reimbursed, and it's super easy.
[40:32] And so. Yeah, so. So things like that. I mean, in the legal field, gosh, it was awful.
[40:37] You know, just printing copies and everything. Yeah, it's just. It was just awful and frankly, such a waste of time.
[40:43] Debbie Reynolds: Terrible.
[40:44] Keith Weisman: Yeah, yeah, yeah. Not. Not to, like, go down too far down that path, but. Holy cow. Yeah. Absolutely. Absolutely. Yeah. Thank God those days are gone.
[40:54] Debbie Reynolds: Totally, Totally. Yeah. There's a lot of room, though, in just a lot of different industries to find ways to improve workflows or improve outcomes or speed up decisions. You know, we're seeing people making decisions faster now because they have more real-time or near-real-time information.
[41:16] Keith Weisman: Oh, absolutely. Yeah. I mean, it's. To the world I'm living in now. I mean,
[41:21] customer feedback, customer opportunities to make things better for our customers. Like, it's.
[41:27] That data is all there. It's just, are we willing to use it and look at it and take it seriously? And I personally do. I think it's what makes us all better.
[41:37] And I've always felt like.
[41:40] And this is, as a manufacturer, as a Producer of software.
[41:44] Like, frankly, most of the best ideas that we have in our product,
[41:48] Probably 9 out of every 10 of the best ideas haven't come from us. Like, they've come from our customers and a consumer of our software.
[41:58] Because they're the people who are in it every day. They're the ones that are in it, saying, like,
[42:02] geez, this workflow's not as good as it could be.
[42:06] You could, you could shave off five seconds off my.
[42:09] Off of every review that I have to do, just by mildly changing something.
[42:13] Those are really where the good ideas come from, in my opinion.
[42:15] Debbie Reynolds: So it's true, and I'm glad that you all are taking that tack because the customer really feels the pain of things. So if you're getting that type of feedback is great because you could say, and then now, because of the technology,
[42:31] Those are things. It's not like, oh, we'll put it on a roadmap and three years later you may see something.
[42:37] So being able to do it faster, more rapidly, I think, is exciting.
[42:42] Keith Weisman: Absolutely. I mean, look, it's pretty simple, right? Like, what would I rather do? Join a call where you're loving our product, or join a call where you're angry, and you're frustrated, and you're yelling at me about something?
[42:54] Like, it's simple. Like,
[42:56] Of course, I want to join a call. You're like, Keith, this is great. I love it. Versus Keith, this is awful. You need to help me. Like, it's just. It's simple.
[43:04] It's just. It's just a much more enjoyable experience for you and for me. So, of course, I'd like to think we would all be motivated to operate that way. Right.
[43:12] It just seems a lot easier that way.
[43:15] Debbie Reynolds: So thank you so much for being on the show. This is tremendous.
[43:19] So if people want to get to know more about Jetstream and what you do, what's the best way for them to reach out?
[43:25] Keith Weisman: Yeah,
[43:26] probably our website, www.Jetstream.security.
[43:29] There are a lot of different ways to contact us. I'd certainly love to talk to you. To as many people as possible, but just generally speaking, to reach a broad audience, the website is probably just the easiest.
[43:40] Debbie Reynolds: The easiest route is Jetstream Security.
[43:44] Keith Weisman: It is, Yep.
[43:45] Debbie Reynolds: Okay, perfect. Well, thank you so much for being on the show again. I really appreciate it and look forward to us having more chats in the future as we collaborate together.
[43:54] Keith Weisman: Absolutely. Yeah. Thank you for. Thank you for having me. It was my. Certainly, my pleasure. I enjoyed it.
[43:59] Debbie Reynolds: Oh, thank you. Thank you. We'll talk soon.
[44:02] Keith Weisman: Absolutely. Thank you, Debbie. Take care.
[44:04] Debbie Reynolds: Okay. Thank you. Bye.