Serious Privacy
The PICCASO award winning Podcast, for those who are interested in the hottest field of human rights and laws on the digital frontier. Whether you are a professional who wants to learn more about privacy and privacy laws, data protection, GDPR or cyber law or someone who just finds this fascinating, we have topics for you from data management to cybersecurity, from social justice to data ethics and AI and digital identity protection. In-depth information on serious privacy topics including interviews with privacy leadership, privacy culture, serious discussions, and more.
This podcast, hosted by Dr. K Royal, Paul Breitbarth and Ralph O'Brien, features open, unscripted discussions with global privacy professionals (those kitchen table or back porch conversations) where you hear the opinions and thoughts of those who are on the front lines working on the newest issues in handling personal data. Real information on your schedule - because the world needs serious privacy.
Follow us on BlueSky (@seriousprivacy.eu) or LinkedIn
Serious Privacy
Data Data Everywhere!
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Are you a digital hoarder? Are you someone who always has a full mailbox? Then you know that finding the right data isn’t always easy. In this episode, K Royal chats with Kevin Ogrodnik, president of Sherpa Software, about the challenges of data discovery and finding data across systems.
Contact us at SeriousPrivacy@trustarc.com with comments or suggestions.
If you have comments or questions, find us on LinkedIn and Instagram @seriousprivacy, and on BlueSky under @seriousprivacy.eu, @europaulb.seriousprivacy.eu, @heartofprivacy.bsky.app and @igrobrien.seriousprivacy.eu, and email podcast@seriousprivacy.eu. Rate and Review us!
Subscribe today HERE
Back the Board Game!
https://www.kickstarter.com/projects/seriousprivacy/serious-privacy-the-data-game
Powered by TrustArc
From Season 6, our episodes are edited by Fey O'Brien. Our intro and exit music is Channel Intro 24 by Sascha Ende, licensed under CC BY 4.0. with the voiceover by Tim Foley.
Are you a digital folder? Are you standards who always add a full build off? Standard documents called a desktop in various folders and not know what it is drives. And you must also note that finding the right data is not always easy. Welcome to the driver, finding is not the right product. And in today's episode, my colleague K Royal will talk about the challenges of data discovery. For that is Kevin O'Brock, the president of Copeland Software. I will hear Kevin has a background in data retention and e-discovery, but will now tell you all there is to know about finding data across your system. Enjoy the episode.
KHello and welcome to Serious Privacy. Today I have the pleasure and the honor of talking with Kevin O'Brodnik, who is the CEO of SERPA Software. Kevin's specialty is in data discovery, which is a topic that in privacy is something that we absolutely love. So welcome, Kevin. Thank you for joining us.
Kevin O'BrodnikThanks for having me, K.
KBeautiful. So I'm going to dive into a couple of questions up front before we get into the meat of it, because one thing I love to do, and Kevin, don't shoot me for this, but I like to ask people an unexpected personal question, one that you're not prepared for. Let me know. What is your caffeine of choice? Tea, coffee, or a soft drink?
Kevin O'BrodnikActually, I don't drink caffeine, but I do drink tea. So I'm actually caffeine-free on the tea, but that's that's for me. It keeps me going though. I like uh arouse tea.
KOh, oh, I love aroibos tea. That is fantastic. So, what do you do for energy then? Do you don't tell me you drink energy drink?
Kevin O'BrodnikI run around at my desk and run around work all day to get my energy, right?
KOkay, I love it. I was gonna say if you're gonna tell me chocolate, I can completely understand. Okay. So did you start Sherpa Software or did you join them?
Kevin O'BrodnikI joined them actually a year after they started.
KBeautiful. And what brought you to show uh Sherpa Software? What was your specialty and your interest?
Kevin O'BrodnikMy specialty and interest was just the company itself and the uh the industry they were in. So I like to say we were kind of doing data governance before it was a buzzword uh in the last few years. So I was interested in what they were doing, and they were a small startup. We they had about six people when I joined, and uh been here ever since. It's been uh 20 years now.
KWow. So 20 years ago, privacy wasn't even really a thing. I mean, we vaguely had HIPAA. Um well, and I can't say it wasn't because frankly, we just celebrated 50 years of privacy, but it wasn't really a publicly accepted or or something knowledgeable that people worked with in everyday life. Now privacy is pretty much everywhere you look, or maybe the lack of privacy is everywhere.
Kevin O'BrodnikRight. That's a good way to describe it.
KRight. I mean, it's not about protect your privacy, it's about reclaiming your privacy. So when you first started, was it e-discovery?
Kevin O'BrodnikYeah, we actually, believe it or not, we actually started doing uh email retention policy. And so back then, if you remember, storage was expensive, right? Instead of uh the cheap jump drives now you can get for you know less than a hundred bucks and get a terabyte of storage. Storage was very expensive back then. So we ended up doing retention policies within, you know, sit-down lotus notes, uh, and when exchange was kind of getting up and running. Yeah, so that's obviously 20 years ago it goes back away. And then that evolved into the e-discovery realm, which is our customers were requesting more than just doing things based upon sender, recipient, date received, and uh doing retention policies on it. So they wanted to start searching for content and do doing different things within the uh the the messages of the email.
KOh, and that's interesting because nowadays we want to do email retention, but based on the fact that you shouldn't keep data for very long. And the reason why they typically fail is because storage is cheap.
Kevin O'BrodnikThat's true, that's true. And and again, it's interesting how the the industry has has come around. So when we started to do email retention 20 years ago, everyone wanted to get rid of email because storage was expensive. And then probably about seven or eight years later, in the late, you know, 2002-00, like 08 to 10, uh, everyone wanted to save email. So you had the federal rules of civil procedure that came out and everyone wanted to save everything and archive everything, and nobody wanted to delete everything. Well, now it's coming full circle again, and now people want to delete things again because of the obviously the astronomical storage growth and the risk and everything that goes along with that from security and privacy aspect.
KRight. And I know that when I talk to IT people about um, and I hate to say it's email retention, but in most cases it's email retention, and it's the proliferation of you've got 20 draft versions of a document floating around and everybody has one. And it's just that, you know, information just replicates, as I said, once like bunnies in the dark.
Kevin O'BrodnikGood way to describe it.
KRight. And you know, don't feed your email after midnight. But when I was speaking to IT people, they say the reason they like to save everything because the legal department will contact them and say, give us all the information you have on Paul Breitbart. And so IT goes, How are we supposed to answer that if we're not retaining email? We'll have to go back and say we don't have it. And I say bite me on this one typically when I talk to an attorney, because to me, an attorney would much rather contact IT and say, give me everything on Paul Breitbart. And if IT comes back and says, we don't have anything on Paul Breitbart because we have a record retention policy or a data retention policy of this many years, three years, and we have nothing with him now because we delete data according to our maximum retention policy. The and this is where I'm gonna ask you if you come across any surprises because an attorney would rather hear we don't have data because we deleted it according to our policy, as opposed to that one little gem that's gonna save the company is so rare, you're gonna come across 50 bombs that are going to explode the company first. So you'd rather get rid of data the way you should, unless, of course, you know, something traumatic happened, and then you're keeping the data in anticipation of litigation. But otherwise, you should have a good retention. So I'm gonna ask you about any surprises, and I of course I know I don't want you to violate any client complexity, but in doing data discovery and assessing companies and what they've retained, have you had any surprises come up?
Kevin O'BrodnikYeah, we've had a few come up, and obviously one is related to legal, as you say, K, that the I don't want to say the funny thing, but sometimes we've actually been on calls where you will have attorneys arguing with each other as to, you know, how long we should save it, what we should save, and what we should do. So the surprising thing is that sometimes there's not the same consensus across what they view as what should be kept, what should be disposed of. I agree with your aspect and and your viewpoint on it is that if they're under a ongoing records retention policy that they're enacting and enforcing on a regular basis to show that you have the history there, you know, it's it's a lot better, we believe, for the organization to sponge of that of that data to make sure those risks are gone, right? Reduces the risk and it allows you to comply with those regulations as well. Some of the other uh surprises we've seen too is that I'll say more so in small and medium organizations, and and I'll tell you why in a minute, why it comes back to this. But you know, sometimes I don't want to say they're not paying attention to this, but I think it's a resource issue, is that some of you know there's so many things going on these days, they have a fa a thousand things going on, they can barely get to half the things. And so when you have these security and privacy professionals running around just trying to put fires out, you know, they they don't have the time or the resources to put forth some of this proactive effort to doing things like data discovery data and data inventorying, those types of and so what they're missing in that is the aspect of where where the risk is in the organization, of course, like we just talked about. Because it's growing so fast, it's hard for them to wrap their arms around where it is and what they need to do with it, and then how they can comply with these regulations.
KAnd then I want to bring you back because you said you had something in particular about small to medium organizations.
Kevin O'BrodnikYeah, I think it comes back to that resource restraint is that they have so many things going on if they they they view this on their list and they know they got to get to it, but they're they're plugging holes, right? Think think on a wall, right? You're putting your fingers in the in the leaks and your toes in the leaks and you run out of fingers and toes. So I I think some of it is the fact that you know some people are believed that that because they're a smaller organization, they may not get hit with regulatory fines or they may not get hit with a breach based upon these you know the risk that's out there. And so, I mean, as you know, you know, things are gonna happen, and whether it's a breach or it's a private privacy regulation that uh that they may get caught on, you know, organizations need to find this information to figure out how they need to respond to things like like CCPA and GDPR and uh where their risk is in the organization. So I think a lot of it comes back to it being the size that they are and uh how they can tackle these problems.
KOh, I love that. And you're absolutely right. Most privacy people, especially, have no idea where the data is. Well, I mean, it's not the privacy, the privacy is the one that wants to find it, but no one in the organization knows where all the data is and where it where it lives, where it's replicated, where it's linked to, where it's been combined, where it's been separated, where it's been assessed and analyzed and built into metrics, and it just, you know, information is everywhere. One thing you said I do love though is you said it surprises you that attorneys don't agree, they don't have a consensus. Get three attorneys from the phone, you're gonna have five different opinions.
Kevin O'BrodnikYeah, it's true. Not only sometimes you get disagreement within the department, you get disagreement across the departments too. So you'll have legal that'll want to do one thing, and you'll have privacy that says we need to do another, and then you'll have security that wants to do another, and then IT wants to do something totally different. So it's a matter of getting all those stakeholders together and trying to get them to agree.
KOh, absolutely. And typically security wants to get rid of stuff because it doesn't want to have to put controls over it. IT loves a delete button. If you give them a delete button, they'll press the delete button, boom, gone. You're right, because not all attorneys understand privacy requirements. So when we're talking about finding data, which is one of the big things for for data discovery, I mean, duh, is finding the data. But there's no law that actually requires data inventory, right?
Kevin O'BrodnikWell, when you look at uh GDPR and CCPA, so there's the data registries and there is data inventory. So there are some as it relates to that. Now it it relates back to you know personal information too. So there can be, you know, again, it depends upon your viewpoint, and you'll get different interpretations of it. But most of these companies want to inventory the data to know where this personal information is so they can respond to these privacy requirements within the time period, you know, that they are required to do, because otherwise, you know, once you start getting outside of that, you start not being able to respond. That's whenever the uh the I think the regulators are going to come down hard on them.
KRight. And the fact that you can't really respond to individual rights requests unless you know where the data is. I've heard you know, stories that companies have received individual rights requests, for example, and let's say it's a retailer that may have a loyalty program, and they'll give the individual, they'll find them in their loyalty program, they'll give them their shopping history. Well, maybe the person worked there for 10 years. So one of the biggest complaints, and you can go pull up the metrics uh across Europe, especially for these metrics, is one of the biggest complaints is the fact that the agencies or the companies aren't responding in full. They're only responding in part. And so, is that something that a data discovery software can help you solve? Is that if you put in someone's name, you'll be able to find everything around the comp in the company around them.
Kevin O'BrodnikYeah, that's absolutely right, K. And that that is one of the big things. Obviously, it's that speed to response, but it's also the breadth of it. I mean, you don't you don't want to miss you know any information because then that could come back against you. And like you're saying, whether they're a customer and an employee, there may be information there that they know the company has on them that when they pull that request out, they they believe and they know that they're not getting the information that the company has on them. So at that point, they can escalate it. And so, yeah, you have to be able to go out there and and search wide, wide and far and be able to ensure that you're capturing information of each each individual. But yeah, to answer your question for sure, you need to be able to do that. And it and data, data discovery, data inventory can do that with in these types of situations.
KNow, can it find data anywhere? So you always hear, and of course, this may be old, heaven knows, I may be completely out of sync with this, but you always hear, well, we can find data that's stored in the company systems, but of course we can't find data stored on someone's laptop.
Kevin O'BrodnikWell, you know, laptops from the standpoint of it being a corporate laptop, you know, they're thin, I'm sorry, an employee laptop as they work for the company. Yes, you can. Actually, we've we've got a lot of use cases, and that's one of the main things that um we hear about from our customers a lot. So they want to be able to get to those because you know, when you think about the employees, they're you know, our greatest benefit and sometimes can be our greatest threat too, right? Right. So bre breaches that happen, believe it or not, 40% of breaches come from they call them uh insiders. And so whether it's accidental or malicious, you know, most of you think about accidental, 60% of that comes from accidental insiders that do something with that data. But uh yeah, it's it's extremely important to be able to get out and get that. And so a lot of inform a lot of companies will also say, oh, well, we have laptops locked down, you know, we that's that's no problem, or we don't support them, you know, they're they're not backed up, so we're not worried about them. What we've seen is, you know, what employees will do is obviously they want to save information out there, whether they're traveling or they want to take something and work work on it at home. You know, there'll be information sitting out there that's not supposed to be out there. So a lot of times the customers that we see, they'll do a trust to verify policy. And so they'll go out and they will they'll want to search within local laptops and machines to make sure that this one is out there. And when you think uh, you know, a simple example might be from an HR perspective. So the director of HR has their laptop and they want to work from home or work remotely, and you know, guess what? There's a spreadsheet with all the employees' information, whether that just be, you know, social security numbers, date of birth, anything else that might tie to them personally. You know, he or she has it on on their laptop and they go work from home. And the this story I've used before is when you they go and they buy coffee at a at a coffee place, they walk inside, they walk back out and their laptop's gone. Um you have a yeah, I mean you could potentially have a multimillion dollar problem just in that five minutes you were gone to get your get your cup of coffee. You know, you're at home and your uh your kids want to work on your laptop to play games. Well, you know, your that sheet is still sitting out there. Maybe they accidentally grabbed that. So yeah, there's a lot of uh holes and things that that can directly affect privacy and security when it comes to uh local machines and laptops of employees. So we we see that a lot and we see a lot of companies they do want to enact and enforce policies and make sure that that sensitive and and uh personal information is not located out there. And if it is, either get rid of it uh by remediating it or move it to the more secure location of where they they may dictate it to be.
KOh, I love that. So does that mean that when you do the data discovery, it can come back and actually identify where sensitive data is, or do you need to program it with certain phrases and search parameters?
Kevin O'BrodnikYeah, there's uh usually you know preset things you can put in there, whether it's based upon personal information. So it's it's typically it runs the gamut, right? Lots of people will will search for just so security numbers, but then some people will do the whole gamut of personal information. Again, think of you know date of birth, addresses, uh names, you know, different things. And so they'll have all different kinds of things that they can put in. But yeah, it'll automatically go out and search that. And you can do do it in any combination of uh where it is, what's next to other things, what's in the what's proximity in a proximity to the other. So yeah, you can you can pull those up and as you should pull those up to find out where your where your risk lies.
KDoes it actually tell you what security controls are around the areas that you found it? Like if you search laptops, will it come back and confirm that a laptop is encrypted or not?
Kevin O'BrodnikSometimes it can. So with with with encryption, it can tell you that it's encrypted. So typically when it's encrypted, you you won't see the uh the actual content within that, which is good, right?
unknownRight.
Kevin O'BrodnikAnd then it'll also it'll flag you that, hey, here's here's where the information is. You know, we could not get into it because it's encrypted. So so that is a good thing.
KOh, so it could be a case that if a laptop has hard disk encryption, a person could have movies stored on it, but you wouldn't be able to tell what what they are.
Kevin O'BrodnikRight, but you can always tell, you know, typically based upon what the file type is. Now, granted, it might be a different difference of so think of an MP4, right? You could have someone who has an MP4 movie on there, but then you could also have someone doing QA testing that's uh that's recording things for uh uh for work. So, you know, and it kind of runs from one end to the other.
KI'm gonna explain that one because recently I had an individual tell me that a coworker, and this was not at my company and it wasn't at a client, let's get all that out of the way. An individual told me that IT contacted him and said that one of his employees had Lord knows how many, but it was a huge amount of MP4s on his laptop, and he might want to talk to the employee before IT took the laptop to assess it because they suspected it was porno. And it turns out it wasn't. Turned out it was a bunch of QA recordings. No one should have that many QA recordings, but that was what popped up is that there was a bunch of MP4s. So I I suppose that's a little bit of a surprise that may pop up. So tip for anyone listening: please don't store a bunch of movies on your computer or you will be suspected of having porn. Okay, what about downloaded then? So is this something that will automatically tell you if data has been downloaded out of systems or databases?
Kevin O'BrodnikSometimes you can do that, yeah. There's different systems that will tell you that when things are downloaded, or if there's a jump drive attached. So, yeah, there's different layers of security that that you can enact to uh to find out what what's happening with that information and where it's moving.
KBeautiful. So let's go back to the small and medium companies when you said that you know they don't have the resources to be able to do everything. Is data discovery a resource heavy or resource intensive project to do?
Kevin O'BrodnikTypically not. But you know, when you have companies that create these things, you know, such as Trust Arc and Sherpa Software, I mean, we we create these things to be as automated as possible. Of course, there's no, I'm gonna say there's no easy button, right? Everybody wants an easy button, but we make them as automated and as simple to install and run as possible. And once they're installed, they're typically, you know, they can go on a scheduled basis. So when you think about a data inventory and data mapping, they can automatically update that as it goes forward. So I it's not a set it and forget it because you don't want your program to be that way. You want to have audits and you want to have checks on, you know, to make sure everything is running right, and then you want to make sure data is fine where it's supposed to, um, and also seed to make sure there's data where where it needs to be and where it is, where it's not, somewhere where it shouldn't be. But most of the time um these things are set up so it's not a not a heavy lift to get these things installed. I think I think the organizations, you know, just think of it and they think of the uh the implications of it and the risk. And I don't know if they relate it to being heavier and a heavier implementation too, but uh really it's it's not that difficult to get going. And I mean, I you know, what we see what I think is good is a lot of people will try will start this in one location and so they at least get started.
KRight.
Kevin O'BrodnikAnd once they realize how that is, then they can start moving it out to other locations based upon uh what it is and and you know take take it in steps.
KOkay. So does it send alerts if you program something like always alert me if a nine-digit number goes outside the system?
Kevin O'BrodnikYeah, there's differ again, there's different layers of security. So uh uh a DLP system can catch things coming in and out of the system from a security standpoint, and when it catches things like that. Then there's also data at rest. So when you save some things and there's, you know, again, nine-digit number can tell you where that is and and what the risk is behind.
KRight. Because I know that I I built the library for a DLP when I worked at a healthcare company, and so of course they wanted to probe one of the preset things for a DLP was a nine-digit number to catch social security numbers. Well, their medical record numbers were nine digit numbers, which of course we wanted to know because HIPAA applied, but on the other hand, there was a whole lot of false there was thousands of false positive for social security numbers. What about if you run it? And and I don't know how often you would run a data discovery if it's once a week, if it's once a month, but will it show you the changes from the last time that ran, or you just see the entire what the data discovery is?
Kevin O'BrodnikIt's really up to you. You know, sometimes you can do the the delta on it, sometimes it you know, people want to run the whole thing again. Typically, you know, I think from a data discovery standpoint, most of it is usually searching data at rest. So typically, if you can do it even from a date-based standpoint, where you can get a delta, you most companies are are happy with that. Some, you know, are are over I don't say over cautious, but they're more cautious and they'll go out and they'll scan the whole thing, you know, every time.
KOkay. And I like that. So how often should they run it? I mean, what what do you think is optimal without being crazy security conscious?
Kevin O'BrodnikYeah, I think optimal is typically again, it could depend upon the size of your organizations, but you know, once a week from data at rest usually is pretty good. You know, some are more stringent and they'll run it every night, some are a little less and they'll run run it, you know, once a month. But uh typically as it relates to this, and especially once you get through the first run and then you start to remediate that information, so you start to reduce your risk, um, I think they become a little less there's less exposure there, so they can they don't have to run it as often. But that's typically what it is, probably once a week on on average, is when most most people, uh most of our customers run that.
KAnd do you see a prevalence of companies in particular sectors that are more data inventory or data discovery conscious than others?
Kevin O'BrodnikYeah, I think like you said, okay, was uh you know, healthcare is a big one, obviously, because there's a lot of sensitive information around there. Uh healthcare, insurance, and financial, those those are ones. And then A lot of times government as well, too. So a lot of these organizations will have that personal information. Those are they're more, I'll say they're riskier in the or they pose a higher risk than some of the other organizations.
KRight. What would be a sign of failure in a company? So if they wanted to implement a data discovery program, what would be some of the things that if they did certain things, their data discovery program is going to fail? And that might not be a simple answer. It's the opposite of, you know, what are the best practices around it? But a sales call and a company is looking at buying a data discovery. If they are asking certain questions or they're not asking certain questions, does that tell you, oh, this client is not going to be a good data discovery client?
Kevin O'BrodnikYeah, I think some of that might come back to the human element. You know, I I I may have been thinking about the technology side of it as well, but I think a lot of it does come back to the human element where we talked about the lawyers, you know, disagreeing. So to get yeah, so yeah, to do the inventory and to do discovery is one thing, but to actually set up the remediation and and do things with that data, that's where you get into some of the disagreements on on the human side. And so a lot of times we will have people again on the calls disagreeing, and if they've disagreed for a long time, they they may never come to an agreement to get this done. And so that's probably been one of the failures or impediments, and that might be a better word, uh, as to why people don't don't enact and push this forward. And and that's you know, it's it's I'll say disappointing and sad for them because they there's a lot of risk sitting there on the table that if they could just come to some agreement, they should at least find where that is, decide if that information is important, sensitive, business critical, you know, however they want to classify them to actually be able to do something with it. So they'll at least know where their risks are, you know, as we talked about from a data inventory standpoint, and to be able to enact upon them if they need to.
KSo I love it. And I almost want to ask you that if you're on a potential uh client or you're on a client call, potential sale, are there are there certain things that when you hear them, you're like, oh, hang this one up, this isn't gonna work, or this is gonna be a nightmare.
Kevin O'BrodnikWell, nightmare and uh maybe just longer installation and uh you know trying to work through some of their issues might uh might entail some of that. But uh a lot of it is if is that disagreement and it could be disjointed disjointed technologies too. So that's one of the difficulties too, is a lot of you know, with the growth in data, lots of people have a whole bunch of repositories where data is. And so I I don't think that's that's not a failure because obviously uh you know there's a lot of platforms out there like ours that we can get into these different repositories and search for, but that that sometimes makes it difficult and and they're unsure of whether they want to migrate that data into a central location or more of a central central system so they have it under one roof, or if they're going to keep these all all these disparate data locations. So yeah, those are probably some some speed bumps we'll call them as we get into them.
KI I like that. Not impossible, just make it more complex.
Kevin O'BrodnikYep.
KThere's an example I usually get when I talk to people about doing data inventories, is typically you'll have a marketing person that they like to use a certain tool, so they build this big database and then they leave or move on, and there's another marketing person that comes in and they don't like that tool, they like another, and now you have a marketing database that may or may not be held on-prem, it may be cloud-based, but no one is supporting it anymore. There's no IT person, there's no business person, there's no one that uses it. Would you be able, I know you can't go find that database if there's no longer an active link in the company, but would you would your um data discovery be able to pick up the fact that at one point there was sharing going to this database?
Kevin O'BrodnikYeah, you know what's funny, K, is um this kind of goes back to our original roots when we talk about Lotus Notes. So we see a lot of people migrating from Lotus Notes over to you know Exchange or Office 365. And that we encounter that a lot, these legacy systems all the time. So with these legacy systems, if you can access them, then they will need to get into that legacy information to make sure that they're able to find this information, do the data inventory, find if there's sensitive information, if there are requests. But yeah, we see that all the time.
KOh, I love that. Thank you, because that that's my nightmare is having this uh quicksand of data out there that no one knows exists anymore, and how do you locate that? And so knowing that there's breadcrumbs that you can follow to say, hey, we can't go find this database, but we see where data for four years was shared to this database and then it stopped, or something like that. So now I'm looking at your example use cases, uh, Sherpa Altitude example use cases, and this is something that we can load in the description of the podcast to give you the resources as well. I'll make sure that I give the link to Sherpa itself. But um I'm just gonna pick a couple of these out because I think there was one that I absolutely loved. Uh yes, the secure confidential data from a flight risk employee. I like the one right above it that finding and securing um intellectual property from a terminate employee. But you have in here an example that, you know, unhappy employees can be perpetrators of leaks. We already know that 40% of breaches anyway are from insiders. And so with silent deployment on their user workstation, so your tool performs ongoing periodic checks to see what kind of sensitive personal confidential data employees are storing to take the necessary prepared preparatory, whoo, you'd think I could say that word, measures in the event the employee leaves the organization. So is this something that speak to me more about this? Is this something that they would need to identify what their flight risk employees are, or is this something they would deploy in general because any employee can be a flight risk?
Kevin O'BrodnikYeah, it's both. Okay. So yeah, typically it could be any employee. So that was some of that trust but verify we spoke about earlier, to make sure that there's not intellectual property or sense of information that's out, you know, that that employees are doing things with it that they shouldn't be doing. There are also sometimes, you know, they're whether they're a remote employee or you get some signs that they may be leaving, it's to go out and make sure that that the information from the company is secured. We do see this often, and it's coming up more and more, obviously, when people read about these breaches and everything that's happening nowadays, they will go out and they will proactively start searching, whether it's based upon you know client information, client names for those types of documents. I mean, that's one of the biggest things is because you don't want to lose your client information because if that gets out uh and you know that whether it was accidental or not, that's gonna give you a reputation, you know, uh a bad reputation and it could affect your your new clients, let alone your current customer, you don't want to lose any of them as well. So yeah, it's it's it's a proactive measure that these companies are starting to take more and more to make sure that they uh they're securing that data.
KSo knowing that if an employee quits and it may be on good terms, they you know they find something else, would this be something that you might want to go back and look at their um laptop activity or their data activity for the prior 60 days to see if they knew they were going to resign, so they started scraping information off. Is that something used for?
Kevin O'BrodnikYeah, that's exactly right. So you could have them bringing information and files in from the network, for example, to their local machines, again, whether it's client lists, client names, things like that, and then they end up taking that with them when they leave, which is not a good thing for the company they're at. So yeah, taking a proactive measure on this is is extremely important when when it comes to these things, especially companies that that have, I mean, we we all have clients, but you know, you think about, for example, consulting companies that they have clients out there that they work with every day and they want to make sure that they're in secured.
KRight. And uh I love it. I mean, because you know, as a privacy professional, and I don't know, Kevin, do you consider yourself a privacy professional?
Kevin O'BrodnikAbsolutely. I think you have to be nowadays with everything going on, for sure.
KYour thing. So that's one thing that I look at as a privacy professional, finding data is critically important. Doing a data inventory is critically important. You know, even if the laws don't explicitly state DAO must create a data inventory, you kind of have to. It's a foundational element of all programs. I was talking about this in one of our prior podcasts about with Peter from Stockberger from Denton's about how a data inventory is a foundational element of any privacy program. How to secure your data, not even responding to individual rights requests, but how can you even secure your data or know what to do with your data, what kind of policy in place if you don't know what the heck you have? So I'm gonna move on to a couple of questions because my co-host Paul Breitbart wasn't able to join us today, but he did send some questions in, and I want to make sure he says, let's see, how do you ensure okay? So we addressed that. So how do you ensure data inventory is kept up to date over time? And is it something organizations are able to do? I want to build off of that a little bit. If someone was to switch data discovery vendors, is that easy to do or is that hard to do?
Kevin O'BrodnikWell, as a data discovery vendor, I'd love to tell you it's very difficult and you should buy if you buy us first, right? But don't ever change.
KEver ever.
Kevin O'BrodnikYeah, right. Yeah, you know, I think it it depends. You know, it depends if you have integrations with other other applications. So for example, with with Trust Arc, we have an integration with TrustArc. And so our data, data discovery, and data mapping will go into the data inventory hub, and so there's a nice flow there. So when you break that and you switch to something else, then you know it just kind of it can interrupt what that looks like and where the data discovery information comes. I mean, data discovery is data discovery, right? But it's a matter of what that information is and how it's reported and potentially those trends as it goes. And so those trends may be broken if you end up switching.
KOh, I love that. So I'm writing down a couple of things that I want to make sure that I touch on because we're coming uh close to the end of our time. Lord knows we could talk about this for a few hours. Let's talk about the integration first. So when you use data inventory to populate a data inventory repository, when you use data discovery to populate a data inventory, you're not giving TrustArc the data that you're searching from someone's network. You're actually, or systems, you're giving us the categories of how you've translated what finds, right?
Kevin O'BrodnikRight. And yeah, but actually you you could, yeah, it's not the actual data, it's showing where that data is. So with the data inventory hobbik, it'll show the uh where where the data is and how it flows. And what we can do is we can get more granular to say, to show in that data, data mapping to give them a better view of their say their environment of where their data is and what it is. So down to the file level. So if you think about, you know, these are emails and this what it this is what it looks like, and this is what it might be about. So the actual information is not passing from us to TrustArc. However, we're reporting them and giving giving that to them so when TrustArc brings up their data map, they will know exactly where that data is.
KRight. And so then when a company is searching for an individual for an individual rights request, they can bypass our inventory and go straight into their portal with y'all to search for that person.
Kevin O'BrodnikThat's correct. Yeah, that's correct.
KSo it does it offer a security risk to the company by using a data discovery?
Kevin O'BrodnikNo, I actually think it's the other way around because it actually shows you where your risks are. You know, it actually illuminates where your risks are, where your dark data is hiding without without showing that, I I feel like you're more at risk of of not doing anything.
KRight. Because one of the things, I was an early proponent of cloud services back in the day, you know, not quite 20 years ago, when everybody hated cloud service providers. And I'm like, why wouldn't you hire someone that has a specialty in an area that you don't? That to me made made a lot of good sense. So one of the things that I, and maybe this is a good closing question, Kevin, is when someone is looking at hiring a data discovery vendor, what should they look for?
Kevin O'BrodnikOne would be, you know, what what is your reach, right? Can you get to, like we talked about laptops? I mean, that that's a big thing. Can you reach areas where data may hide or where it may be hard to get to? That's one of that's one of the big things for sure, because obviously there's, I'll say, nooks and crannies and crevices that where things can hide that they'll be hard to get to, and that's where risk can pop up too. You know, the other thing is that they just, you know, hopefully that they have uh high touch service. So again, if you go back to those small and medium, medium companies, I mean, it's pretty much everyone out there is going to say, hey, we have great service, but do they actually you know show you that they can do it and they can help you work your way further and and relieve your resources to get your data discovery and data inventory done? I think those are a couple of the key issues to make sure you're you're getting what you need to meet your uh requirements, whether it's to a privacy regulation or some of your recru your security requirements, but then also alleviating the resources to make sure that you're able to do the other things. That like I said, you have your fingers in your toes plugging the other the other leaks and fires, putting the other fires out, and so you have enough resources to do that to do that as well. So I think those are a couple of the key things that uh the people should look for when they're looking for data discovery.
KOh, I love it. I love it. So before we say bye, I I will first say thank you so much. This has been very, very informative. Is there anything you want to make sure that our listeners know about data discovery before we say goodbye?
Kevin O'BrodnikYeah, I think one of the things we touched upon is that a lot of people will think, oh, well, I have to get my uh retention schedule down, or I have to get my privacy requirements all lined up, you know, before I do this. I I think that's that's definitely good advice, but I also believe that by doing a data inventory with data discovery, you will find where those holes and where those risks are. So it could lead you down a more thorough path to being compliant and having your security policies laid out to make sure you cover all your risks and you can answer the regulations.
KI love it. Don't wait until you have everything perfect and you're just looking for your data. Use this as a tool to strengthen the rest of your program.
Kevin O'BrodnikThat's right, exactly. Use it proactively ahead of time, and it'll actually make the program better as you set up the program.
KI love it. Well, Kevin, I can't thank you enough for coming on. Thank you so much. So many people have questions about data discovery and when they should and shouldn't use it and what benefit it offers. That this has been a wealth of information, and you have been a fantastic speaker. You just have so much information to share. That part is so very clear. You're a very natural uh sharer of information and wisdom.
Kevin O'BrodnikThanks again, K.
PaulI appreciate it. It's been fun.
KThanks, Kevin. Take care.
PaulThank you, K and Kevin, for this interesting conversation. This is the end of yet another episode of Serious Privacy. I would like to thank all of you that are listening to us already. It is so exciting to see the number of listeners grow by the week. And of course, if you like what we are doing, feel free to tell your friends and colleagues about serious privacy as well. If you want to get in touch with us, feel free to reach out via seriousprivacy at gastop.com or on Twitter where you will find us at add podcastprivacy. You can tweet at AMSL directly via add hard off privacy at add girlv. And we very much welcome ideas for future episodes for guests. Don't hesitate to generously offer yourself if you would like to be on the podcast as a guest. If you would like to know more about Shirtasoftware, you will find all the information you need at shirtasoftware.com. The documents they spoke about in our conversation with Kevin will be linked in the show notes. Thank you again for listening today and talking to link in our next episode.