Data Privacy Automation – Peter Brass & PD Prasad, LightBeam.ai
Leadership of LightBeam.ai explains how open source data trustee security model advances data privacy automation using AI.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Peter brass and PD Prasad from Light Beam dot Ai, and we're talking about a dated trustee maturity model that these guys have open source. So let's just get started with one of you maybe explaining exactly what that is. Yeah, hey, am I pretty here?
So what are the problems that we have been here from customers is a lot of privacy regulations these days that are coming up which is CCPA gdpr has been out there for a long time. Obviously, they're all identity-centric and they're all about it's the individual essentially, um on the other hand all the pools and products and solutions that I have been there in the market for the last 10 years. They're all about.
Unfortunately just about attributes meaning they just care about if there is a sensitive information somewhere, but they don't really link that back into the identity the individual and so what the data trustee maturity model helps. Our customers understand is well, you're probably caring you probably care about the what which is what sensitive information is present here then everywhere. Do you really understand who's information it is that's out there and that's important because you know every now and then we keep hearing about one or the other data exposure and companies are after that exposure figuring out.
Whose data is it that we actually exposed so that we can actually take care of such individuals the data trusting maturity model is a step in that direction essentially for the for the community and Industry, right Peter. What's the challenge? I mean to PD's point.
We are seeing a lot more of these regulations but fundamentally, what is the challenge when it comes to managing privacy that you're out seeing and the data and the things that people are trying to do I mean we've been at this for four or five decades now, so the question is is you know, what exactly is the challenge and the problem that we're not figuring out. Yeah, absolutely great questions. So, um, you know, the challenges I think a lot of security-minded folks are still looking at how to secure data by setting up, you know, larger fences bigger Gates if you will figuring if nobody can get inside.
Nobody can see my data. So the problem of controlling this for all of that data is insurmountable. So we'll just be build bigger fences.
And of course what we're seeing Industry is those fences aren't working because the breaches are still occurring even at very large very well funded organizations. So what we're trying to address here at light beam is really helping people uncover where that sensitive data is and taking it a Step Beyond that through you know, the intelligence that we offer with artificial intelligence is not just doing pattern matching for it where it's going to throw up a million false positives to the point that we as humans will just ignore all of those false positives. We're really bringing in a different level of intelligence towards identifying that sensitive data and to PD's Point helping them know who it belongs to so it's much more actionable from a compliance standpoint a regularly regulatory standpoint.
PDD you think that you know to Peter's point that we over invested and then network security and didn't secure the data enough or is it merely just a matter of we need to do both and frankly. It's just going to cost more and we got to secure the data and the network and there's no getting around it. It's an it's an interesting dichotomy and it's a wonderful framing of that question.
Really? Um, To be honest the if you look at the last 20 years. There isn't a way where companies could actually look inside the data.
You couldn't you just use regular expressions and pattern matching and that's pretty much it and that's not sufficient. You could program your system to say if you have a nine digit number flag that as an assistant and guess what it will work for a few days after that. You will just get bombarded with thousands and thousands of false positive.
So what has happened in the last two years in industry is good. Ml models have actually come out and thanks for some of the organizations that actually open source those models which is now enabling companies like like being ourselves to actually take advantage of those ml models and help customers look in the data. So really data security.
I mean companies have been doing network security because that is what it was possible essentially data security was not possible unless you count pattern matching his data. Images, you know, okay for step I suppose now it is possible and what organizations are realizing to Peter's point is just building big walls, you know firewalls and so on. It's not sufficient.
Obviously. It's in point this every day. There is one or the other breach happening.
You really need to understand. What data is that you have where is that data and most importantly whose data is it that you're carrying inside your walls and what data is actually leaking out or getting shared outside of your own system. Peter what's the level of maturity of the AI models themselves these days because initially there was a lot of you know AI is going to save us from ourselves.
Then there was a lot of skepticism and you know, we kind of go back and forth across these different polls and it's kind of a whiplash effect in some regards, but you know, what should people expect and what's real and what's not it's a great question. So, you know myself I I tend to be what we're doing with AI here at light beam as magic candidly and you know and speaking with the people who are who are actually writing the code leveraging it they sort of laugh and like yeah, we think it's magic too. Um, you know, the old rub any any sufficiently advanced technology is gonna be like magic at any point in time, right?
And so that's sort of what we're doing and it's really the magic of being able to take The context of what that data is in and being able to identify it as something that you should care about and you know, we're leveraging not just Ai and ml but also natural language processing. So an image of a driver's license, you know, no smart robot is going to look at an image and know what's going on, but being able to use natural language processing to look at the text within that and identify as an identity based document and then be able to even tell which fields in there matter and then you know, the really unique thing that we do at lightning is take it that step farther if we find that we have automation available to our customers to be able to automatically redact that so again, it's not just relying on alerting humans humans are really bad at repetitive tasks. We don't like it.
It's boring. So we stop doing it at some point or we do it inaccurately by offloading that to the computer so that when we find that sensitive data if the customer so chooses we can automatically redact it in addition to notifying and that's just a level of Simplicity and Nation that has an existed historically Phoebe. I can't help but wonder if the tail is wagging the dog here in this regard.
I think a lot of the Legislatures around the world are passing laws about data privacy with some assumptions of capabilities that maybe don't exist. And that's going to force the issue. Then we're people are going to have to go look for more Automation and AI to go solve the problem.
Is that a fair assessment of the situation? It's right on point. Actually.
It's right on point. In fact, I was just reading an article about how in in Europe over dead it tend to be a little ahead of the curve when it comes to caring about consumer privacy and data privacy regulations are being written and some people are wondering well, what are the Technologies? What are the tools that are available to help companies to comply as you note it?
Well, there are Technologies and tools that are becoming available rapidly. I would say in the last two years. The landscape has changed dramatically in terms of going from a patent matching and I'm just going to quickly repeat that pattern matching to as Peter was noting a more AI Model where you're really my favorite example is showing someone a nine digit number and saying well an existing tool flag that as a SSN and the answer is well, it might well be someone's assistant and probably eat.
Well, you can't just look at the content you have to look at the context is that number as part of a text message of WhatsApp message and an email a database where it's present in a field you have to look at the context and that's where AI helps and you know regulations are coming. Yeah, they're already there the old excuse of well, I'm doing the best I can works until you actually get hit by a ransomware attack and you come to know you wake up one fine morning and say oh, wow, I leaked five million customer accounts data, which was present in some S3 bucket. I have no clue about and well now my reputation is, you know down the rain unfortunately, so, you know to your point regulations out there.
They're a little bit ahead of time. Which is great that's where they need to be and they need to push the industry including ourselves to actually help customers comply with those regulations. Peter do organizations need to change the way they think about data it used to be I would collect data and I would give people these really long forms to fill out and they check the box and somewhere in that form.
It said, you know, you're surrendered your rights to your data. I don't think most people view it that way these days I think maybe they perceive it that they're lending data to these organizations and some regard or form. So is the whole approach to the way that we need to think about being custodians of data change.
yes, absolutely, you know as we've been talking about some of the legislation that exists today and some of the additional legislation that's coming right to be forgotten is something that is going to have consequences for companies if they aren't able to actually perform that request and so as you look at it and again this problem, we're trying to solve around identity-centric view of the world if a customer comes to a company and says Been great doing business with you, but I'm not going to anymore and you need to delete all of the data that you have on me. What possible way could a company do that a sufficiently large company that has multiple places to share and exchange and store data. How can they solve that if they don't know where that customer's data is and that it belongs to that customer and that's the real challenge that we're seeing our customers struggle with is that they do not have a way of doing that today.
It's it's exhaustively manual and again as a sort of already articulated, you know with all of the efficacy of manual efforts by humans. PD in my experience, at least I'm very few organizations. I know would get a Good Housekeeping seal of approval for the way they manage data.
So we have a lot of conflicting data. So how does we approach that whole thing where you know people's names are spelled differently companies names are spelled differently actual values attached to contracts or different and different things. No one seems to know what they're real state of the truth is so can we get there faster with AI?
What do you think? We are getting there. I wouldn't say we are a hundred percent there, but we are getting there rapidly to just give an example AI the difference between you know, sometimes a lot of companies and in people and Technology people that I talk to a number of them are pitching their solution as Ai and it's great.
It's good to picture solution. Is that great the difference in a regular software program between a regular software program and an AI model is that you can train the AI model you couldn't like I used to write code 20 years back for you know controllers that control our cars the cars that we drive and feeds today. Um, it's you one and done.
You're right the code you ship it. That's pretty much it that code is not going to learn on its own no matter what the situation conditions are AI on the other hand actually has this Active Learning capability. So what we are seeing in customers environment is obviously, you know, we train and we unlike like many AI organizations provided what truly doing AI that train the model to the best of their abilities, you know to keeping in mind biases and checking those biases and so on so forth, but when you actually deploy that model in a customer environment guess what every customer is slightly unique they have slightly different types of data, they've got different kind of challenges you were alluding to which is sometimes names are different spelled incorrectly and so on so forth the AI model learns over a period of time and that's what makes it.
So powerful. Is that day one you might only get 194% accuracy. Well day 30, you might get 99% and it's 65 you will be at 100% accuracy with automation base.
So that's what really exciting at least, you know to to us in this field. Peter who's in charge of this mess these days. It seems like the security people should be in charge but we see Chief data officers.
Sometimes the IT people will point back at the business people because the IT people will say hey, we just store the data. We don't know what the value of the data is from one thing the next so who is gonna take the leadership role in all of this? It's a fantastic issue that we're seeing a lot of our customers struggle with exactly that problem.
There can be a bit of a hot potato approach to this the more the more modern organizations have Chief privacy officers and teams that are dedicated to ensuring that they're meeting the needs and really truly safeguarding customer and privately identifiable data and they really doing that ultimately the responsibility for setting it up and providing access to the systems is going to be traditional it the security department within it. They're the ones who have those systems and our responsible for the security. So I think what we're seeing is an increasing need for companies to collaborate and you know decide what they're going to do the policies as far as how they're going to handle private sensitive data is gonna be up to you know, data governance privacy officers those teams, but when it comes time to actually executing on those policies and and doing the work that's gonna definitely require the help of it to again start looking at a different.
Lens for the problem of security than just setting up, you know more difficult barriers. Feeding the maturity model is clearly a step in the right direction. But what's your best advice to folks about how to get started with all this?
What should they be thinking about? What is it? You wish most customers knew going in versus figuring out six months later.
Yeah, thank you for that question Mike. If you as a customer any organization just start with a simple question checkbox privacy, if that's all you do, which is ask consumers and customers like ourselves to you know, fill in and check a lot of boxes. It is a very cya approach it found.
Unfortunately help you when your data gets exposed in that exposed as three bucket or Google drive or slack or send us to so on whatever it is. Essentially you have to start with what is the best for your customer because guess what and you just alluded to this which is there's a concept of data trusty ship that is evolving and that's what the data trustee. I'm sure you model have some companies understand just ask yourself two simple questions if I don't have the checkboxes, but I take care of customers set up properly.
I secured them. I know where it is. I know it's not Exposed that is situation one situation 2 you have all the checkboxes in the world, but you keep leaking customer's data, which organization is a consumer going to trust more and do more business with that's a very very simple if you ask me.
I would do business with customers who don't leak my data who understand where my data is who secure it properly and of course if they give me all the Privacy check boxes, it's great. It's great to get a privacy compliance notice once a year from a big organization. It's good as long as you don't leave my data.
I'm happy with you. All right. Hey Peter.
Do you think the courts are fingering all this out? Because many times, you know, people would go to a lawsuit and the judge would say, you know, well, where's this data who accessed all this and the IT people would sit there and say, you know, we have no idea and we have no way of finding out so do you think the courts are going to turn around now and say we understand that there's this AI thing and maybe you can figure this out. I don't know that'll be overly optimistic.
They'll find it figured out quickly, but one would hope that they will you know again that you know part of the reason why I'm here at light beam is this is a subject that I care quite a bit about the absolute expansive amount of data that all companies are capturing on us in every aspect of our life and just knowing how easily exposed that is. It would be nice if there was a little bit of teeth to this, you know, the increasing legislation that's out there. It would be nice.
If I as a customer could go to a company and say hey I am interested in doing business. So you I have been for a year now, would you please show me what data that you've collected on me? Is there a way that you can expose that to me?
We're starting to see the world move in that direction somewhere. It's interesting to see the amount of resistance. There is you know, there's two very very large vendors out there one makes Hardware with operating system control.
They're very concerned about privacy and then there's a large social. Immediate organization that is well. Of course, we need all of this private data because how else are we going to Market to you and somewhere in there as with most saying somewhere in there is the truth and where we need to be and without the controls in place for companies to be able to expose.
What data they actually have of mine Beyond just to market to me is going to be a really hard thing. So, yeah, hopefully we are evolving to a point where there's teeth to this legislation at the end of the day. That's probably the only reason why most companies there, you know, they're driven by shareholder value most of them.
So at some point there's got to be a little bit of teeth to make them care and hopefully the judges will come along to support this absolutely. All right, folks. You heard it here first, you might want to rethink your strategy before you are held in contempt of court someday may not happen tomorrow, but it's probably gonna happen one day sooner than you think gentlemen.
Thanks for being on the show. Thank you very much. Thank you so much.
Mike pleasure. All right back to you guys in the studio.