Full Tech Ahead
On this podcast, I sit down with business leaders, researchers and executives to explore innovative technology solutions and products, whether they’re transforming industries today or still in development. But we go far beyond the tech itself. From real-world use cases and business implementation journeys to cybersecurity challenges and future trends, we uncover what’s shaping the digital landscape.
We also dive into topics that matter to every tech professional: Work/life balance, business communication, education and training. Think of it as your one-stop shop for meaningful technology discussions that inspire and inform.
Full Tech Ahead
Control Your Data and Stop AI Leaks
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode of "Full Tech Ahead," host Amanda Razani interviews Ward Balcerzak, Field CISO at Sentra. They explore how AI is fundamentally transforming data security posture management (DSPM) and exposing long-neglected operational hygiene, such as outdated access rights and forgotten data repositories.
Balcerzak highlights the evolution from basic Large Language Models (LLMs) to fully Agentic AI systems capable of autonomous reasoning. He warns that threat actors are using advanced frontier models to chain together low-and-medium severity vulnerabilities to breach perimeters and exfiltrate IP.
To counter these AI-driven external attacks and internal data overexposure, Balcerzak advises business leaders to move past "opening the floodgates," establish strict data provisioning based on specific use cases, build trust-based partnerships across departments (Legal, HR, Privacy), and master basic data and identity security fundamentals.
Key Quotes
- "Sentra... we are a data security posture management software vendor. And what that really is, is we're finding where your sensitive data is at, what it is, how it's exposed."
- "AI is exposing things that we forgot about for the last twenty years or we ignored... hygiene, data hygiene, access rights."
- "Frontier models are able to chain exploits together in a way that humans really didn't think about... You need to focus on the mediums and lows, first and foremost."
- "Security leaders... you need to find your champions out there in the organization... Start reaching out... make them your best friends."
Takeaways
- Address Medium and Low Vulnerabilities: Traditional vulnerability management focuses exclusively on high and critical risks. However, threat actors now leverage AI models to string together multiple minor, unpatched exploits into sophisticated breach pathways, making low-and-medium vulnerability remediation mandatory.
- Avoid Opening Data Floodgates: Deploying copilots or agentic AI across an entire corporate dataset by default creates severe overexposure. Companies must restrict training and input data to a minimal, highly specific subset tailored strictly to defined business outputs and permissioned user roles.
- Bridge the Security-Business Communication Gap: Security professionals cannot protect an organization without understanding operational goals. CISOs should establish non-transactional, human relationships with non-technical leaders in Legal, HR, Privacy, and specific business units to identify champions and align security posture with actual daily usage.
- Master Identity and Data Fundamentals: A strong AI defense relies on basic digital hygiene. Organizations must clean up authentication infrastructure (such as Active Directory) to enforce need-to-know access, tokenize or encrypt sensitive data in databases, and run continuous discovery to locate forgotten corporate data assets.
Find Amanda Razani on LinkedIn. https://www.linkedin.com/in/amanda-razani-990a7233/
Follow the FTA LinkedIn Page: https://www.linkedin.com/company/full-tech-ahead/
Visit the FTA website: https://fulltechahead.com/
Check out the Substack Channel: https://fulltechahead.substack.com/
Hello and welcome to Full Tech Ahead. I'm your host, Amanda Razzani. And with me today, I'm excited to have Ward Balsterzak. He is the field CISO at Centra. How are you doing today?
SPEAKER_00Doing pretty good. Thanks for having me on, Amanda.
SPEAKER_01Happy to have you on the show. Can you share a little bit about Centra? What services do you provide?
SPEAKER_00Sure. So, Centra, we are a data security posture management software vendor. And what that really is, is we're finding where your sensitive data is at, what it is, how it's exposed. And that's especially important in the day and age of AI, right? There's there's this concept of AI data readiness, and we are a big, big portion of that.
SPEAKER_01Wonderful. Okay, well, we're actually talking about how AI is changing data security. So you're you're the right person to talk to.
SPEAKER_00Love it.
SPEAKER_01All right. So let's just start off with why are AI agents changing the security field? And what should business leaders be looking out for in this new day and age?
SPEAKER_00Yeah, it's a it's a very loaded question, a big question. I could probably speak for hours, but to be concise, um, it's it's new shiny technology coming in that a lot of leaders don't understand. And and what I mean by that is AI is incredibly powerful. I equate it to cloud once upon a time, right? A lot of organizations brought in cloud, they weren't really sure what it was, but they said, you know what, I'm all in, and they went all in. And for cloud, they said, Oh my goodness, this is expensive, right? That that was that was cloud uh about a decade ago. It is really the same thing with AI, and and a lot of people are getting the oh my goodness, that's expensive with with AI, right? Token spend and all that. But the other piece that the people are finding is AI is exposing things that we forgot about for the last 20 years or we ignored, and that's it, hygiene, data hygiene, access rights, old and and whatnot. So there's just a lot that security leaders have not focused on because it wasn't the perimeter, it wasn't that zero-day attack. And now they're saying, oh my goodness, what do I do?
SPEAKER_01So, can you kind of describe what is the difference? Because these tools are rapidly advancing over the last couple of years. And so now we are speaking about AI agents. What is the difference between the previous AI tools and now businesses are using these AI agents? How is that changing data security?
SPEAKER_00Yeah, yeah. So, I mean, there's there's the changing of what I'll call blue team are good and kind of the red team or the bad. And I'm gonna focus, and actually, there's there's the middle, right? There's the business usage. So I'm gonna focus a little bit on the business usage, which is really kind of hitting hitting both here. So what what is the change? So AI really isn't new or the concept of AI, it's been around for a very long time. Um, what was first commoditized? You know, the the chat GPTs of the world, the bards and whatnot, those were really large language models. They weren't really AI. They seemed like it, right? You were asking questions, you were getting a response, but it was based on language models, either LLMs or SLMs at the end of the day. So large language and small language models. The agentic AI that is really hitting today, you know, some would argue still not, you know, full-fledged AI. I think the frontier models, I think folks are saying, oh my goodness, it could be Skynet in the future, especially with uh with some of the news here. But agentic AI uh has a little more or a lot more smarts to it, right? It is able to actually think and think through responses and give answers. It's all still prompted, though, at the end of the day, right? It's all still trained on something, whether it be trained on those large language models that are already out there, or whether it's trained on organizations' data. And I think that right there, to really kind of answer your question around you know, security leaders thinking about this, as they're bringing in these agentic AI agents, it's got to get trained on something. And some organizations say, you know what, here's all my organization's data. Go do your thing, and that's where folks are starting to run into problems because they're not first stopping and thinking, what are we trying to solve, right? What are the use cases? What data does it actually need, right? The input, and then what are we expecting for the output, right? What what is what is going to be good looking like coming out of that? And if you skip those steps, you start to fall in a lot of the not only data security issues, but issues in general with AI hallucinations and all of that.
SPEAKER_01What is one of the biggest mistakes that a lot of leaders make when they start implementing these AI tools?
SPEAKER_00I would say just opening the floodgates is is one of the one of the biggest mistakes there, right? The business says, hey, we need this thing, whether it be an actual uh agencai tool, just an AI-enabled tool, or even just a copilot, right? They just say business says we need it, they implement it. Maybe security tried to stop it, but they lost the battle, and there it is. I would say that's the biggest mistake because they didn't first stop and say, okay, what are we using it for? Right? And in in you know, copilot, for example, maybe the four is just business enablement, and that's okay, right? That is a-okay. We're just gonna give it access to most of our data, keyword being most. So, first, understand the use case. Second, what data does it actually need? Because I would bet nine times out of ten, the all data is not the right solution, it's gonna be a subset. So it goes back to that security leader, that business leader, really understanding what do we need? Where is it? How do we give it access, and how do we give it that access securely so it's not overexposing data either internally to the workforce or externally to a third party?
SPEAKER_01Yeah, and that brings up my next question. So, you know, not only do we have to worry about this internally, but with these AI tools, now there are all the threats from bad actors. How do we protect the data when they have these AI tools at their disposal as well? So, how does that change as far as keeping data secure from the outside?
SPEAKER_00Man, you went right for the throat on that question. It's I I think it's the right question. And you know, for many, many years in security, you know, security practitioners would say it's not if, but when we we are gonna get breached. And and I think that's even more so these days. It is truly when an organization, you know, these these frontier models are able to chain exploits together in a way that humans really didn't think about or really didn't do, right? Red teamers really didn't do those low severity vulnerabilities. Let's chain six you know, exploits together to finally get in, right? To get to that juicy morsel in in the organization. So the idea of from a vulnerability management perspective, organizations saying, you know what, we're gonna focus on highs and critics. Um, guess what? Like you need to focus on the mediums and lows, you know, first and foremost. And how does that all relate to data security? Well, everything we do in security relates to data, essentially, right? Unless you're in energy or you know, maybe even some uh some defense or military applications, like data is your intellectual property, it is your crown jewel, it is what you're protecting. So it is starting to really focus on those things we haven't for many years. So vulnerability management, make sure to do good, you know, use AI for good in that, you know, try try to leverage AI to understand the actual exposure, try to leverage that to actually do the remediation where possible. Identity and access management, right? Really shoring up our identities, what access people should have, and have really good re-verification cycles on ensuring that data is appropriately provisioned out through uh through identities. And finally, you know, bring bringing it in, right? Those concentric circles going in, you know, now really focusing on the data, so making sure it's encrypted in databases, making sure it's tokenized where possible or or masked even, and really locking down the data to truly a need to know by data sensitivity. So again, it goes back to truly understanding where is your data, what's its criticality, and how it's exposed.
SPEAKER_01Do you think from your experience, is there still a communication issue between departments when it comes to these AI tools?
SPEAKER_00Yeah, I think so. I think, I mean, that's kind of the mantra for many years, unfortunately, that that's happened within organizations is communication stinks. Um, and I think that's organ uh business unit to business unit, right? They don't always talk, right? They're super focused on I'm doing this thing, you're doing that thing. Yeah, we we enable each other, enrich each other, but you know, not really speaking across aisles, and especially so still between security and the business. And I think that's the biggest piece that uh I continue to beat that drum I have for many years, right? Security folks need to talk to the business because you cannot adequately secure or adopt AI technology without knowing how the business intends to use it, right? If if you build the big fortress for this use case you think they're gonna do, but but really their use cases, the farmlands outside that fortress, you've lost, right? You you haven't secured it. Uh, there's there's nothing preventing good or bad usage at that point.
SPEAKER_01So, uh, what advice do you have to improve in that area?
SPEAKER_00I think the big advice is this. So, security leaders, and when I say leader, I don't mean managers, I don't mean people leaders. I'm really saying really everybody, right? All security practitioners need to start having conversations with the business. So now locking it to leaders for a second. Security leaders, you need to find your champions out there in the organization because they do exist. There are people out there that do want to do good security. They do not want to see the business wind up in the front pages of hey, the latest breach has happened. So start reaching out from a security perspective, from a data security perspective. Kind of the the the first, uh, the first folks that I would say is gonna be your legal team, your privacy team, your HR folks. Start there, make them your best friends, start to have real human conversations, not just transactional. Hey, I need this from you. What do you need from me? Actually try to get to know each other as humans because building that trust is going to help. Once you actually trust those folks or get them to trust you and make friendships there, uh or at least partnerships, you don't have to be best friends. Uh, you will start to um understand the other folks out in the business that you need to do the same with. If you're in financial services, maybe it's gonna be your call center head. If it's, you know, maybe it's gonna be your head of investments, if you're in healthcare, it's probably gonna be the doctors, right? The the folks that are uh uh dealing with them over them. So find those business leaders that you can build relationships with. And again, the end result is to truly understand what they're doing, how they're doing it, so you can help them.
SPEAKER_01Okay, great. Well, looking toward the future, we mentioned how quickly this is evolving. So looking toward the future, what do you see as next? How are AI agents or AI tools going to change the landscape?
SPEAKER_00Yeah, this is an interesting one. Um, and one that I was actually in Texas last week and we had this conversation a few times. So that there's a lot of fear out there with regard to AI coming in. And really the fear is hey, AI is gonna take my job, right? It's gonna take my job, it's gonna do my thing, and I'm gonna be in the unemployment line. We are seeing some of that, right? We are seeing some organizations that are leaning into AI and uh reducing headcount because of it. Um, I think we're gonna see a shift. Um, you know, not only cost, but also understanding that we do still need human in the loop with regard to decisions and um and actions. So, with all that, I see a AI augmented workforce, maybe the term I'll use for it. So um, and with that comes true understanding how to leverage AI capabilities, not use like a Google search, right? How do I do X? But truly understand how to engineer prompts to enrich your work product, whatever that may be. So, from a business perspective, you know, whatever you're actually providing, um, either to other businesses or consumers will be enriched that that product by AI. From a security perspective, I see us getting quicker and better, right? Quicker investigations, better outcomes, better understanding instead of just using threat intelligence of what's happening in your industry, being able to truly understand, hey, I saw this thing, bump it up against my own telemetry plus threat intel, plus whatever other you know, OSINT information you can get, and now truly understand, oh, this is what happened, whether it be an actual event, incident, or just a false positive, you know, bring in that additional context. And then to take that a step further, use AI to actually help um, you know, triage some of that, whether that be tune out false positives or or tune out your detections, or even create new detections based on activity that you just weren't thinking about, whether it be malicious outsider, insider, or insider risk.
SPEAKER_01Wonderful. Well, if there was one key takeaway you could leave our audience with today, what would that be?
SPEAKER_00Ooh, one key takeaway. All right, do the fundamentals. That would be kind of the baseline. And what I mean by fundamentals, it's gonna be identity and it's gonna be data security. So from identity perspective, clean up your AD, whatever you're using for your um, you know, authentication infrastructure, really clean that up and make sure that you're doing access based on need to know and based on the idea of um you know family membership within the organization from a data security perspective. Do today understand where your data is at and what it is. Many organizations I talk to claim they know, but as soon as they get certain technologies, survey says they don't actually know, right? They see something and say, Oh my goodness, I forgot about that. That's been out there for a decade. I don't even know if it's accurate, right? Data uh sitting around is risk, and organizations need to get their hands around it.
SPEAKER_01All right, wonderful. Well, thank you so much for coming on the show and sharing your insights with us today.
SPEAKER_00Thank you. I was glad to be here.
SPEAKER_01And thank you to our audience. If you have any questions or comments, leave those below, and I'll try to respond back as soon as possible. Have a wonderful day.