Data Privacy and Security Regulations – Spencer Kindt, Optiv
In this discussion with Alan Shimel, Spencer Kindt, senior leader, Data: Privacy, Governance and Protection at Optiv, leads a healthy debate between the pros and cons of regarding data privacy and security regulations.
Transcript
This is Textron TV. Hey everyone. Welcome to Tech strong TV back here.
Our next guest for today's show is with Spencer Kent Spencer is with optav. It's Spencer's never been on texture on TV before so we'll welcome them. Hey Spencer nice to meet you.
And nice to meet you as well. Thanks for having me on our pleasure. So Spencer, I guess we should start off with a little bit about you and your background if you don't mind.
Yeah, I'd be happy to so Spencer can't I'm a senior manager here at optiv and our data governance privacy and protection practice. I've been in Consulting the majority of my career been Consulting for 10 plus years and really just help clients with any of their data related issues and problems usually focus on the programmatic or advisory side of things but also get involved with tools and Technology as well. So working with octave who's a software reseller, but also provides Professional Services related to software implementation and maintenance and support but also, I'm some of that Consulting and Professional Services side of things especially related to cyber security data privacy and data governance.
I love it. Fantastic. Let's talk a little bit about Optive and well, let's start with the website for people who want to dig into more money, but more information.
Excuse me. com and we've got an overview of our services and and the different offerings we have for our clients. So you'll see a little bit information.
They're related to what I do in the data governance pricing protection space and yeah any questions one happy to help with those you know, I said money Spencer my last interview we were Actually jumping into this whole what's going on in the banking industry and then somehow from there. We segued into cybersecurity regulations. You know both the the recent cyber security.
Regulation coming out of the White House as well as this that's currently a bill. I'm sure you're probably where a billing Congress bipartisan support. It's past committee.
It'll be really kind of the First Federal level Congress like real law not just an executive order or something that we've seen coming out in in some time. And there's also there's new legislation door coming out of the EU Etc. You know the knee-jerk reaction to cyber breaches is we need more regulation.
We need more. Government control we need more, you know oversight same thing with the banks actually too, right? We got two lakhs.
We let these Banks You know and I had another the previous interview today people were like, well, you know Industries can self-regulate. I'm not a big fan of Industry self-regulating every time I've seen it it doesn't work, but I'm interested. Let's hear your take is someone in the trenches on this, right?
What do you think? Yeah, so that's a great question. And as you kind of know to L and there's a little bit of kind of philosophy at play there and different perspectives.
So I generally my personal opinion here is that I think for I think regulations at least in the Cyber and privacy space or positive. However, it's not a one-size-fits all it's not an end-all be all. It's not gonna you know, magically take care of everything.
Right? So for example, just thinking through in the Privacy space, right? I'll start there privacy at it's root is usually seen by organizations as a cost center.
It's seen as more check the box activity from time to time and I don't think it necessarily carries the same weight as say something, you know security May usually say right organization typically understand the value of security. They understand. Hey, we gotta have a lock on the front door because we want to understand who's coming in and out and we got assets we got to protect those privacy is a little bit different a little more Nuance a little more Shades of Gray but organizations.
Excuse me, clients and consumers within the United States and across the world really are becoming more and more aware of what data they're exchanging with organizations and they're becoming more and more aware of how the data is being utilized after they exchange their data with an organization with that comes some concerns and some questions. And what do we do there? And what control do I have right?
So One area where regulations at least in the United States have helped a little bit is there are some regulations specifically starting in California right with the CCPA the California consumer Privacy Act, which went into effect in 2018 or excuse me was passed in 2018 and effective in 2020. I was recently recently enhanced and revised by the cpra the California privacy Rights Act which went live January 1st of this year. So it was a great Happy New Year.
And that has provided some control for individuals to maintain control of their personal data and has provided them with rights related to kind of the manage the relationship they have with organizations to control their data through access and correction and deletion and opting out a certain use cases where now some organizations offered some of those rights before but not very many. So in that facet, I think that regulations have been positive and provided some additional rights to individuals, but then on the flip side, right? Some with in terms of regulations, it could be a little tricky because there's different nuances for different Industries, right?
So there's going to be different considerations for a financial institution. Like you mentioned Ellen versus say a retail organization from a privacy or security perspective. So don't expect that regulations are going to solve all problems and address all concerns, but I think they can help increase awareness and kind of help us go in the right direction.
Agreed, you know, I I actually have a similar Viewpoint Spencer. I I think some of the one of the problems with compliance especially privacy but a lot of security compliance is it sets up least common denominator security where? Oh, okay.
We'll just check that box and and we're good, right and We and we move on and we don't really we dig in there and I think that look I remember the PCI stuff. Right and that wasn't even government. That was Private Industry, but You know it did it did some good.
I'm not saying it doesn't but we we needed to move Beyond least common denominator security that compliance kind of forced on us. Said I find that we live in an interesting times. Right because a lot of like my kids, you know, they're in their twenties, right?
They think nothing of putting intimate details of their life online. But fill something out for a store or a provider or something all of a sudden they get very very concerned about my privacy their privacy and what are they telling these people and what did they doing with it? Never mind that these people can probably go.
Find out this kind of information by a quick scan of their tiktok or Instagram or whatever, right? So there's this kind of Jekyll and Hyde attitude of consumers around privacy. and you know I would I would hope that they were so concerned about their privacy in terms of what they give.
That they wouldn't do be so free with it on on a lot of their social media channels. you know, it just makes no sense to me, but What it is, right? No, I I totally agree with you all and it's I'm old enough to remember when social media was kind of in its infancy.
I remember I I had two groups of friends one group was this is awesome. This is great. I can exchange information.
I can meet people I can maintain relationships and then the other group of friends. A little more along the lines of who's gonna see my pictures who's gonna see this he's gonna be that I might comfortable with them saying that am I comfortable with strangers not only things about my life, right and and to your point, I think we've navigated, you know, there's been a little bit more acceptance and comfort with some of those practices and maintaining a large digital footprint and I think we all have members in our family that we wish would wouldn't share so much right? And so there's you.
Amen. Amen. Hey, man, you know what?
Let me let me another observation and I'm interested in your opinion on this one. Maybe it's because of the of the regulations over in EU. But I find that.
Here at Tech strong, right? com Security Boulevard container journal and such a you know, and we serve a global audience. I find that our European.
consumers visitors a much more savvy about the nuances of privacy Right. Hey, I gave you my name and email and maybe my company name because we're B2B. But I don't want you to share that with this one that one or this one.
So I'm much more they're much more. Savvy I guess is the worried about You know the the layers of privacy here and what what's entailed in that. Is that something you see as well?
And do you think having more regulations in the US will make us more smarter about it. Yeah, absolutely. There's definitely some interesting kind of cultural components as it relates to Attitudes for privacy and security could go for hours on the topic.
But suffice it to say, you know in Europe privacy has seen more of a human rights and some of that goes back to World War Two and some of the practices there and targeting a specific groups and those types of things so that within history and kind of the cultural component. That's a little bit more real I think over there. Whereas maybe we haven't that there's been some, you know other things and at stake here and it's a little different but Um, and so privacy is correct kind of defined as a human right over in the European Union.
Whereas the closest we kind of get over here as well. We have you know, the the Bill of Rights and the fourth amendment protects against the reasonable search and seizure similar principles a little bit different outline there. But and as we kind of saw right with the past couple years right with the Snowden Revelations that set off a lot of alarms over in Europe and has led to a lot of concerns about cross-border data transfers.
And what is your transfer data to the United States? Who has access to that specifically from a surveillance or national security perspective, right? Whereas in the United States?
I don't want to overgenerize but You know, I think there's a little bit of a desensitive. We've been a little desensitized right where it's all someone. There's another breach.
Well, okay, well whatever right and it's happened again. It's happening again. This happened again.
So I do think though that as use cases progress and change and evolve. I think privacy will continue to become a bigger part of the conversation, right? It's been really fascinating for me to think about and follow some of the conversations related to say and artificial intelligence and machine learning.
Right? So chat GPT. We've kind of seen roll out and there's been a lot of fun the stories and articles about that and some of the things I follow there's individuals kind of speaking up and thinking about what are the privacy considerations that go into this, right if if there's you know machine learning or it's those types of things taking place is it's our use case for someone's going an algorithm that's gonna make decisions on my behalf.
And do I feel comfortable about that. So I I expect that again is these advancements take place awareness? Names as awareness increases I think so.
We'll kind of the you know nature in which individuals want to be a little bit more judicious similar to our friends over in the U. I think that will kind of get there. Yeah and go that direction.
I I think I see that happening too. Well, hopefully it will anyway. Spencer I would like let's I don't mean to be make you a shell for Optive.
But where does where does rubber meet the road for optav on this stuff? Yeah, thank you. So with octave, we really just try and help our clients from any other data management needs, you know, again being cybersecurity data governance data privacy, really just want to help them along their Journey because it is a journey it's not hey, I address these items once and I'm good because as we kind of touched on the only constant has changed so because as cliches that is it's true, especially as it relates to data and data is becoming more more valuable and it's becoming more regulated.
So organizations are having more data, but they need to be able to utilize that data as an asset and understand how to kind of navigate some of those those hurdles and obstacles that make sure that they're using it appropriately So with optav, we really help our clients to a number of things from a programmatic perspective. But a lot of times organizations just need help kind of wading through the nuances associated with regulations. Right so and that's not necessary from a legal or a legal interpretation perspective.
But more of just an operational. Hey, here's what I have. Here's what I'm trying to do.
What are Best Practices within the industry? Hey, can you help me understand? You know how to streamline this a little bit right?
So we understand we have all these requirements but this conflicts with that. So how do we kind of solve across the board right, especially in the United States right now again from a privacy perspective. By the end of this year, there will be five states that have privacy regulations effective and most the most of the requirements overlap, but there's a little bit of deviation, right?
So that's one area where we help our clients understand how to develop a strategy. How do we kind of solve for all of those and try not impact the business too much right? So that's a big piece of what we do helping our clients understand where they are where they want to go and how to get there from a data management perspective.
And if there's a tooling conversation to be had to kind of support some of that if there's a application that can help facilitate the management of their program and their obligations as a relates to data then we're more than happy to do that and it's again, it's a very quick changing industry or subject matter. I should say. And so a lot of times we're there to just kind of help collaborate and help our clients make sure that they feel comfortable with where they're going and what they need to do.
I love it. Hey, we're patched our 15-minute Spencer blade. I wanted to get that in there again.
com for people who are wondering are you guys can be out at the RSA conference for security? I guess it's next month already. Yes.
Yes, I will not be there but my colleague Toby Zimmer will be there. I believe he's presenting and speaking. So be sure to say hi for me, but we'll be at some other conferences as well.
So look forward to it. Fantastic Spencer. Thanks for coming on the show.
You've got an invitation and come back and I'd love talking about is compliance really working. And and where did you know? How do we balance all of that really wind up with?
Optimum security we're going to take a break here on text drug TV. We'll be right back.