Skip to content
PodcastsBusinessData Security Decoded

Data Security Decoded

Rubrik
Data Security Decoded
Latest episode

66 episodes

  • Data Security Decoded

    Downtime in Healthcare is Fatal: Achieving Resilience in Health & Life Sciences

    29/09/2026 | 25 mins.
    Please enjoy this encore of Data Security Decoded.

    Cybersecurity in healthcare is undergoing a critical shift. What was once viewed as a back-office IT concern is now directly tied to patient safety and clinical outcomes. In this episode of Data Security Decoded, host Caleb Tolin sits down with John Fokker, Vice President of Threat Intelligence Strategy at Trellix, to explore new findings that reveal a significant increase in inpatient mortality rates following cyberattacks on hospitals, reframing cybersecurity as a life-or-death issue.

    The conversation dives into how attackers infiltrate healthcare environments, often through familiar entry points like email, before moving laterally across interconnected systems. From HVAC units to supply chain logistics, even nonclinical systems can disrupt care delivery when compromised. The discussion highlights how adversaries blend into hospital networks using legitimate tools, making detection increasingly difficult.

    We also examine the alarming dwell times seen in healthcare environments and what defenders can do to identify subtle anomalies before they escalate. The episode outlines practical strategies, including stronger email defenses, network segmentation, and proactive threat hunting.

    Finally, we confront two uncomfortable truths: apolitical healthcare and humanitarian organizations remain prime targets, and AI introduces both powerful defenses and new risks. The takeaway is clear. Cyber resilience is not optional. It is essential to maintain trust, ensure continuity, and ultimately save lives.

    What You’ll Learn

    Why cyberattacks in healthcare directly impact patient mortality

    How nonclinical systems can disrupt critical care delivery

    What long dwell times reveal about attacker behavior

    How threat actors use legitimate tools to evade detection

    The most effective ways to reduce healthcare attack surfaces

    Why email remains the primary entry point for attackers

    How to reframe cybersecurity as a patient safety priority

    Episode Highlights

    00:00 – A Shocking Statistic A 29 percent increase in mortality reframes cyber risk

    02:30 – From IT to Patient Safety Why CISOs now have a stronger voice at the board level

    05:10 – The Backdoor Problem Nonclinical systems and third parties as attack vectors

    09:00 – Living in the Network Understanding long dwell times and stealthy attackers

    13:45 – Spotting the Signals Key behavioral indicators defenders should watch

    18:20 – Three Steps to Resilience Email security, segmentation, and attack surface reduction

    23:10 – Two Inconvenient Truths AI risk and the myth of healthcare immunity

    27:00 – Final Takeaway Cybersecurity as operational resilience
  • Data Security Decoded

    The Terrorist Designation: A New Red Line for Ransomware with Cynthia Kaiser

    15/09/2026 | 29 mins.
    Please enjoy this encore of Data Security Decoded.

    In this episode, host⁠⁠ ⁠Caleb Tolin⁠⁠⁠ explores the battlefield of enterprise defense, which has moved from simple data theft to ultra heinous crimes that put patient outcomes at risk. Guest⁠⁠ ⁠Cynthia Kaiser⁠⁠⁠ shares Battlefield Stories from her time at the FBI and her current work as SVP of the Ransomware Research Center at⁠⁠ ⁠Halcyon⁠⁠⁠, illustrating how the industrialization of cybercrime has reached a tipping point. They dive into the alarming reality of modern dwell times, specifically looking at how groups like Akira move from initial access to full encryption in as little as one hour.

    The conversation challenges the industry to face the inconvenient truths of cybercrime and ransomware. Kaiser shares case studies of how modern cybercriminals are adopting multilateral techniques to gain access to and exploit your network. By adopting an Assume Breach mindset, elite defenders can build the defense in depth required to combat malicious threat actors who follow their own rules to cause disruption and destruction.

    Resources

    House Homeland Security Committee Testimony: ⁠⁠Online Scams, Crypto Fraud, and Digital Extortion⁠⁠

    Halcyon Analysis: ⁠⁠Akira Ransomware Attacks in Under an Hour⁠⁠

    Halcyon: ⁠⁠Sicarii Ransomware Encryption Key Handling Defect⁠⁠

    Previous Episode Referenced: ⁠⁠Downtime in Healthcare is Fatal: Achieving Resilience in Health & Life Sciences⁠

    What You’ll Learn

    Why designating ransomware as terrorism helps influence adversary target selection.

    The impact of Akira's accelerated dwell time on traditional incident response.

    How AI enables clumsy amateur "wannabes" to conduct messy attacks.

    The critical role of phishing resistant MFA in securing the identity perimeter.

    Why Assume Breach necessitates deep defense in depth strategies.

    The overestimation of readiness among CISOs compared to actual red team performance

    Episode Highlights

    [00:00] - The Case for Designating Ransomware as Terrorism

    [04:20] - Modern Extortion and the Shortening of Dwell Time

    [08:30] - Ransomware Recovery in Interconnected Cloud Environments

    [11:45] - The Impact of AI on the "Wannabe" Attacker

    [17:45] - Three Actionable Steps for Modern Defenders

    [21:30] - Inconvenient Truths for Government and Private Sector
  • Data Security Decoded

    Agentic AI and Identity Sprawl

    08/09/2026 | 24 mins.
    Please enjoy this encore of Data Security Decoded.

    In this episode of ⁠Data Security Decoded⁠, join host ⁠Caleb Tolin⁠ as he welcomes back ⁠Joe Hladik⁠, Head of Rubrik Zero Labs, to unpack the findings from their new report, Identity Crisis: Understanding & Building Resilience Against Identity-Driven Threats, Joe breaks down how the explosion of non-human identities, from API keys to AI agents, is rewriting the threat landscape and forcing security leaders to rethink the perimeter itself.

    He explains why identity resilience is the new foundation of cyber defense, how to prioritize recovery when every system matters, and what steps teams can take now to stay ahead of emerging agentic AI-driven attacks.

    What You'll Learn:

    Why identity has replaced the network as the modern security perimeter

    How non-human identities outnumber humans 82 to 1, and what that means for control and monitoring

    Practical steps to build recovery plans around dependency mapping and minimal viable operations

    Why ransom payments remain high and how better resilience planning can reverse that trend

    How threat actors exploit backup systems to gain total business leverage

    What agentic AI really means for cyber defense and how to prepare for its impact

    The episode offers a clear framework for leaders to transform identity resilience from a reactive measure into a proactive pillar of enterprise security.

    Episode Highlights:

    [05:13] The 82:1 Ratio: Why Non-Human Identities Now Define Risk

    [07:03] Prioritizing Recovery: Building for Minimal Viable Operations

    [10:53] Declining Recovery Confidence and the Rise of Ransom Payments

    [15:46] Backups Under Attack: How Threat Actors Seize Business Control

    [16:32] Agentic AI and the Shifting Nature of Cyber Threats

    [25:32] What Defenders Can Do Now to Build Identity Resilience

    Episode Resources

    Caleb Tolin on ⁠LinkedIn⁠

    Joe Hladik on ⁠LinkedIn⁠

    Rubrik Zero Labs report, ⁠Identity Crisis: Understanding & Building Resilience Against Identity-Driven Threats⁠
  • Data Security Decoded

    AI Moves Fast. Privacy Has to Move Faster.

    25/08/2026 | 25 mins.
    Enjoy this encore of Data Security Decoded.

    AI promises speed, scale, and efficiency—but it also magnifies privacy risk in ways many organizations aren’t prepared for. In this episode, ⁠Caleb Tolin⁠ welcomes ⁠Ojas Rege⁠ of ⁠OneTrust⁠ for a practical, wide-ranging conversation on how data privacy and governance must evolve alongside enterprise AI adoption.

    Ojas explains why AI fundamentally changes the privacy conversation: the same systems that enable organizations to move faster can also cause harm faster when guardrails aren’t in place. From agentic AI systems that dynamically repurpose data to general-purpose models that blur traditional notions of “intended use,” the challenge isn’t just compliance—it’s trust.

    The discussion dives deep into purpose limitation under GDPR and the EU AI Act, clarifying where organizations commonly misunderstand consent and where AI training introduces entirely new risks. Ojas emphasizes a simple but powerful test: are you using personal data for the same purpose you originally received consent for—or has AI quietly expanded that purpose?

    The conversation then shifts to cloud and data sovereignty, particularly for European organizations navigating geopolitical uncertainty. Ojas outlines why data mapping, prioritization, and software supply chain visibility matter more than ever—and why perfection is less realistic than smart prioritization.

    Ultimately, this episode reframes governance as an enabler. When privacy and data governance are embedded early, organizations can innovate faster, build lasting trust, and deploy AI with confidence in an increasingly complex global environment.

    What You’ll Learn

    Why AI scales privacy risk just as fast as business value

    How purpose limitation breaks down with general-purpose AI models

    When AI use requires new consent—and when it doesn’t

    Why transparency is foundational to long-term customer trust

    How data sovereignty concerns extend beyond cloud providers

    Where software supply chains create hidden privacy blind spots

    How good governance can accelerate, not block, AI deployment

    Episode Highlights

    [00:02:00] AI Scales the Good—and the Bad How AI accelerates both innovation and privacy harm.

    [00:04:00] Purpose Limitation Meets AI Reality Why general-purpose models challenge traditional consent frameworks.

    [00:06:30] Trust as a Business Risk Why transparency matters as much as legal compliance.

    [00:07:30] Cloud & Data Sovereignty Explained What European organizations can do today to reduce risk.

    [00:10:30] The Software Supply Chain Blind Spot Why third parties make sovereignty harder in the AI era.

    [00:12:30] Data as Economic Power How nations now view citizen data as an AI asset.

    [00:14:00] Governance That Enables Speed Why governing early helps organizations move faster later.
  • Data Security Decoded

    The Real Risks of Agentic AI in the Enterprise

    18/08/2026 | 27 mins.
    Please enjoy this encore of Data Security Decoded.

    As enterprises race to adopt AI, many are discovering that traditional security models no longer hold. In this episode of Data Security Decoded, host ⁠Caleb Tolin⁠ is joined by ⁠Camille Stewart-Gloster⁠, CEO of ⁠CAS Strategies ⁠and former Deputy National Cyber Director, to unpack how AI is redefining cyber risk at every layer of the organization.

    Camille explains why identity-based attacks are so effective and how non-human identities (from APIs to AI agents) are quietly expanding the attack surface. She emphasized how critical MFA is for organizations to enable as they scale up AI operations., and why conditional access and governance must be foundational, not optional.

    The conversation also tackles ethical AI head-on. Camille argues that AI ethics and AI security are inseparable, and that removing humans from the loop introduces both legal and operational risk. From shadow AI to agent autonomy, she offers a clear-eyed framework for deploying AI systems that augment human teams rather than replace them.

    This episode is a practical guide for security leaders and learners navigating AI adoption, focused on resilience, trust, and long-term enterprise readiness.

    What You’ll Learn

    Why identity has become the dominant attack surface

    How AI agents and non-human identities increase risk

    Where EDR falls short in Identity-driven attacks

    Why AI ethics is foundational to AI security

    How governance enables secure AI deployment

    When AI should augment—not replace—security teams

    Episode Highlights

    [00:03:00] Cyber offense and the evolving national strategy

    [00:07:30] Identity eclipses malware as the primary threat

    [00:10:00] AI systems as high-value targets

    [00:12:30] Human judgment vs. automated response

    [00:14:00] The ethics–security connection

    [00:15:30] Why AI governance can’t be an afterthought
More Business podcasts
About Data Security Decoded
Data Security Decoded provides actionable, vendor-agnostic insights to reduce data security risk and improve resilience outcomes. Designed for cybersecurity and IT professionals who want practical insights on preparing for attacks before they happen, so they can respond effectively when they inevitably do. Episodes feature insights from researchers, crafters of public policy, and senior cybersecurity leaders, to help organizations reduce risk and improve resilience. Data Security Decoded provides practical advice, proven strategies, and in-depth discussions on the latest trends and challenges in data security, helping listeners strengthen their organizations' defenses and recovery plans.
Podcast website

Listen to Data Security Decoded, Inside Business with Ciaran Hancock and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
Data Security Decoded: Podcasts in Family