63 episodes
- Enjoy this encore of Data Security Decoded.
AI promises speed, scale, and efficiency—but it also magnifies privacy risk in ways many organizations aren’t prepared for. In this episode, Caleb Tolin welcomes Ojas Rege of OneTrust for a practical, wide-ranging conversation on how data privacy and governance must evolve alongside enterprise AI adoption.
Ojas explains why AI fundamentally changes the privacy conversation: the same systems that enable organizations to move faster can also cause harm faster when guardrails aren’t in place. From agentic AI systems that dynamically repurpose data to general-purpose models that blur traditional notions of “intended use,” the challenge isn’t just compliance—it’s trust.
The discussion dives deep into purpose limitation under GDPR and the EU AI Act, clarifying where organizations commonly misunderstand consent and where AI training introduces entirely new risks. Ojas emphasizes a simple but powerful test: are you using personal data for the same purpose you originally received consent for—or has AI quietly expanded that purpose?
The conversation then shifts to cloud and data sovereignty, particularly for European organizations navigating geopolitical uncertainty. Ojas outlines why data mapping, prioritization, and software supply chain visibility matter more than ever—and why perfection is less realistic than smart prioritization.
Ultimately, this episode reframes governance as an enabler. When privacy and data governance are embedded early, organizations can innovate faster, build lasting trust, and deploy AI with confidence in an increasingly complex global environment.
What You’ll Learn
Why AI scales privacy risk just as fast as business value
How purpose limitation breaks down with general-purpose AI models
When AI use requires new consent—and when it doesn’t
Why transparency is foundational to long-term customer trust
How data sovereignty concerns extend beyond cloud providers
Where software supply chains create hidden privacy blind spots
How good governance can accelerate, not block, AI deployment
Episode Highlights
[00:02:00] AI Scales the Good—and the Bad How AI accelerates both innovation and privacy harm.
[00:04:00] Purpose Limitation Meets AI Reality Why general-purpose models challenge traditional consent frameworks.
[00:06:30] Trust as a Business Risk Why transparency matters as much as legal compliance.
[00:07:30] Cloud & Data Sovereignty Explained What European organizations can do today to reduce risk.
[00:10:30] The Software Supply Chain Blind Spot Why third parties make sovereignty harder in the AI era.
[00:12:30] Data as Economic Power How nations now view citizen data as an AI asset.
[00:14:00] Governance That Enables Speed Why governing early helps organizations move faster later. - Please enjoy this encore of Data Security Decoded.
As enterprises race to adopt AI, many are discovering that traditional security models no longer hold. In this episode of Data Security Decoded, host Caleb Tolin is joined by Camille Stewart-Gloster, CEO of CAS Strategies and former Deputy National Cyber Director, to unpack how AI is redefining cyber risk at every layer of the organization.
Camille explains why identity-based attacks are so effective and how non-human identities (from APIs to AI agents) are quietly expanding the attack surface. She emphasized how critical MFA is for organizations to enable as they scale up AI operations., and why conditional access and governance must be foundational, not optional.
The conversation also tackles ethical AI head-on. Camille argues that AI ethics and AI security are inseparable, and that removing humans from the loop introduces both legal and operational risk. From shadow AI to agent autonomy, she offers a clear-eyed framework for deploying AI systems that augment human teams rather than replace them.
This episode is a practical guide for security leaders and learners navigating AI adoption, focused on resilience, trust, and long-term enterprise readiness.
What You’ll Learn
Why identity has become the dominant attack surface
How AI agents and non-human identities increase risk
Where EDR falls short in Identity-driven attacks
Why AI ethics is foundational to AI security
How governance enables secure AI deployment
When AI should augment—not replace—security teams
Episode Highlights
[00:03:00] Cyber offense and the evolving national strategy
[00:07:30] Identity eclipses malware as the primary threat
[00:10:00] AI systems as high-value targets
[00:12:30] Human judgment vs. automated response
[00:14:00] The ethics–security connection
[00:15:30] Why AI governance can’t be an afterthought - Please enjoy this encore of Data Security Decoded.
Welcome to Data Security Decoded. Join host Caleb Tolin in conversation with Morgan Adamski who leads Cyber, Data, and Tech Risk at PwC and is a former US national security leader who spent 16 years tracking nation-state threats inside the US government. Coming out of a career spent inside secure facilities without windows or phones and working to address China’s prepositioning in US critical infrastructure, Morgan shares a direct view of how geopolitics is now shaping cyber risk decisions in boardrooms.
What You'll Learn:
Why only 24% invest in proactive defense, even while 60% call cyber a top priority
How AI agents are cutting breach timelines to under 80 days
Why cyber insurance is now a hygiene scorecard, not just financial protection
The real reason leaders lack confidence in resilience
Where legacy systems and supply chain dependencies expose blind spots
How public–private collaboration changed the response to China’s infrastructure campaign
What CISOs must confront now to avoid being blindsided by the next crisis
The conversation gives security leaders and decision-makers a clear view of where current strategies fall short and the choices required to build real resilience before the next crisis forces it.
Episode Highlights:
[03:43] Why China prepositions inside US critical infrastructure to trigger disruption and panic in a crisis
[04:20] Collective defense in action: how victims and industry exposed the campaign
[09:27] The truth behind cyber budgets: only 24% invest in proactive defense
[11:57] How AI agents are shortening breach lifecycles to under 80 days
[13:07] Why cyber insurance is now a security scorecard, not a safety net
Episode Resources
Caleb Tolin on LinkedIn
Morgan Adamski on LinkedIn
PwC’s 2026 Global Digital Trust Insights report - This episode delivers operational insights from the frontlines of global telecommunications, drawing on Fred Lhoest's experience managing IT infrastructure across 60 countries at PCCW Global. The discussion begins with the realities of consolidating an environment that previously relied on more than 10 disparate backup tools into a single, unified data protection platform. Fred details his journey as a self-described automation junkie, explaining how he developed an open-source PHP and GraphQL framework to query APIs, detect unprotected virtual machines, and streamline automated recovery tasks.
The conversation transitions into the operational boundaries of automation and cyber resilience. Fred warns against unvetted, fully autonomous failover triggers, emphasizing that false positives can lead to catastrophic outages if fallback systems are out of sync. He advocates for a human-in-the-loop validation model to maintain control over critical infrastructure decisions.
Looking toward future infrastructure shifts, Fred examines the risks of migrating complex systems to hybrid cloud environments. He highlights the necessity of strict data residency compliance across global jurisdictions, including the European Union and the United States. Finally, Fred raises a critical warning regarding long-term digital archiving. He challenges the industry to solve the file format and hypervisor obsolescence trap, where compliance regulations require holding data for 30 years, but modern software renders the underlying files unreadable.
What You'll Learn
Strategies for consolidating fragmented backup tools into a single management interface.
Methods for leveraging GraphQL APIs to build custom security automation frameworks.
Risks of false positive automated failovers and human in the loop requirements.
Key data residency considerations for migrating workloads across international jurisdictions.
Practical guardrails for controlling employee and developer interaction with AI models.
Uncovering software obsolescence risks hidden inside long term digital data archives.
Why continuous recovery testing is essential to validating enterprise incident response plans. - This episode explores the technical hurdles of protecting academic research environments and navigating the shift to automated cloud architectures, drawing on Kevin Mortimer's twenty five years of technical leadership experience. The dialogue focuses on how higher education institutions face escalating threat profiles, moving from initial denial of service events to targeted supply chain compromises aimed at extracting student records. Kevin details how his team rapidly deployed mandatory multi factor authentication overnight and altered storage topologies by isolating valuable research data inside protected cloud vaults.
The discussion pivots to the operational reality of managing generative artificial intelligence across distributed campus networks. Kevin breaks down the friction between supporting early stage vibe coding for rapid proof of concept deployment and preventing shadow AI data exposure. He highlights the engineering required to build agent to agent communication platforms where firewall alerts automatically interface with backup systems to trigger live mounts and dynamic network segmentation.
In addition to addressing autonomous agent architectures, Kevin challenges the prevalence of vendor AI washing, emphasizing the need for technical leaders to scrutinize underlying mathematical models and prepare for shifting OpEx financial models driven by tokenization.
What You'll Learn
Core strategies for securing academic research data within isolated cloud topologies.
Methodologies for implementing emergency multi factor authentication policies across large user bases.
Identifying supply chain vulnerabilities in third party student data record providers.
Engineering autonomous agent to agent communication models between firewalls and recovery platforms.
Frameworks for governing shadow AI usage and evaluating Model Context Protocol platforms.
Utilizing vibe coding techniques for rapid scaffolding and proof of concept application development.
Evaluating vendor transparency regarding underlying mathematical models to eliminate artificial intelligence washing.
More Business podcasts
Trending Business podcasts
About Data Security Decoded
Data Security Decoded provides actionable, vendor-agnostic insights to reduce data security risk and improve resilience outcomes. Designed for cybersecurity and IT professionals who want practical insights on preparing for attacks before they happen, so they can respond effectively when they inevitably do. Episodes feature insights from researchers, crafters of public policy, and senior cybersecurity leaders, to help organizations reduce risk and improve resilience. Data Security Decoded provides practical advice, proven strategies, and in-depth discussions on the latest trends and challenges in data security, helping listeners strengthen their organizations' defenses and recovery plans.
Podcast websiteListen to Data Security Decoded, The Diary Of A CEO with Steven Bartlett and many other podcasts from around the world with the radio.net app
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features

Data Security Decoded
Scan code,
download the app,
start listening.
download the app,
start listening.
Data Security Decoded: Podcasts in Family





























