Hypori CISO Connects AI Risk to Data Sovereignty
Mike Vizard talks with Matt Stern, chief security officer for Hypori, about why digital sovereignty and data sovereignty are becoming more urgent as AI, mobile work and cloud platforms expand where sensitive data can travel. Stern explains why organizations must know where data resides, which cloud and SaaS providers process it and whether technical controls can keep it within required legal boundaries. The conversation also examines CMMC, GDPR, AI auditing, shadow IT, data integrity, model trust and why enterprises should move users to data rather than move data across uncontrolled devices and locations.
Transcript
Hey guys, thanks for the throw. We're here with Matt Stern, who's the chief security officer for Hypori, and we're having a little chat about digital sovereignty and data sovereignty and how these things need to come together. Matt, welcome to the show.
Hey, thanks for having me, Mike. Appreciate being here. I think we all nod our heads when we hear the phrase digital sovereignty as if we all know what we're talking about.
But once you get into it, I think you quickly realize that it's a lot more complex than people necessarily appreciate, because, well, I'm not sure where the data is. I think most people are not sure where the data is, and I'm not sure they understand what it might take to move that. One wag once told me nothing good happens when you move data.
And yet, we are trying to figure out how to put data within the boundaries of certain geographies, and that suggests we need a map. So walk us through, what exactly do we need to do here to achieve this goal, and how hard is it? So we've already been working on this, at least on the government side, when it comes to, for instance, probably heard of CMMC and controlled unclassified information environments, where US defense industrial base partners have to keep their data in the US.
And that's how we got involved in this topic. And so what it goes to is your SaaS provider, your cloud service providers, have to identify where they're putting your data. And so if you have this as a compliance issue for data sovereignty, then you have to go to your vendor, ensure that literally where the data center is, the physical location of your data and the systems that process and store your data are within the legal constraints of whatever data sovereignty laws you need to comply with.
Whether that's here in the US or GDPR or the data sovereignty laws that exist in Europe, in every single case, you have to go back to their cloud service provider and ensure that you're meeting that compliance. Hopefully that makes sense, Mike. It does.
Of course, a lot of this conversation starts with what's going on in Europe these days and their concerns. There's a lot of arguments about what constitutes digital sovereignty, and some people are saying, as long as you got your processes right, and if your data's in a certain cloud platform, and that's okay. And others are saying, nope.
Everything's got to be within a data center that is residing in Europe, and it has to be completely managed by Europeans. And I think this conversation plays out in other countries as well. Is there some rational way of thinking about this, or is every circumstance different?
What we're finding is it comes down to every circumstance is different when that's invoked. So for instance, we have a customer, it's on the customer. When we provide that service to a customer, it's on that customer for them to give us where the data needs to reside so we can be in compliance, so we can help them be in compliance.
And so we're finding that for instance, if we have a SaaS capability, and a customer in Europe wants to use that, we have to provide them with that same capability within wherever their data sovereignty lies. And sometimes it's just Europe, they're okay with it being in Europe. Sometimes it's in the country of origin, so they want it in a specific country.
And that gets to be hard for the service providers, because in some cases, there may not be a data center that meets those requirements. And then also you have to worry about where the data's moving. So for instance, if the data center's there, but I'm traveling to US.
I'm a European customer. My data is in the European data center, but I'm traveling to the US or someplace else. Am I pulling the data onto my device, or do I have the constraints in place, the conditional access policies and the technical controls in place to keep it where it needs to reside?
So there's so many nuances to this. It gets very complicated very quickly. Do you think that this has been a long-standing issue, and we're just finally now getting around to addressing it, not only because of legal concerns, but also everybody's worried about, well, where is that AI running with my data?
And people are now having these conversations that probably should've been had a decade ago. I think the evolution of the mobile system. So the mobile platforms of today is where people are moving in that direction.
So COVID opened up the door of working remotely, right? So the whole idea of going into an office and staying within that security perimeter in an office and doing all that is changed dramatically. And now people want the convenience to be able to move and to go where they need to go for their lives, and still be able to access their corporate data or their personal data.
And the networks now with 5G and 6G are really becoming much more conducive to enabling that behavior. So all those things are coming to, I guess you could say, a perfect storm of recognizing, hey, where is the data? Because before we didn't think about it because we didn't have all these options of moving data, and being able to see data the way we can today.
" And that's I think the driver for this. How quickly do you think it will be before auditors start looking at this stuff more aggressively? And it would seem to me, at least, that they too, like everybody else, is going to have an AI agent, and maybe they'll be able to figure out where this data is or isn't supposed to be more readily.
And maybe, I don't know, should we be concerned that the number of fines are about to go up because the auditors are going to get better at catching everybody? Well, I think having been through our technology is in... We have it in a variety of different government environments.
And the number one question on the audit is: where's the data residing? So I think we're there. I think to your point, we're there, and the auditors are asking the question.
They want to know where your data resides. They want to make sure that it's in compliance. It's question number one on the test.
And whether or not there's a grace period, whether or not there's fines attached, that remains to be seen. But certainly the one thing that I know for sure is if you report that you're in compliance and then the auditor finds that you're not, or somebody finds that you're not, then certainly those fines and that could be determined as fraud and people are being held accountable for that today. Is this going to change the relationship between the IT and the security people and the compliance people, and for that matter, even the business people?
Because I think everybody kind of... Let's be honest, there's been a lot of winking of eyes at this issue for a long time. And a lot of end users have sensitive data that's probably on some machine that it should not be there for one reason or another.
But do we need to finally have, I guess, or will there be a more adult conversation across these groups? Because historically, one group would say something and there'd be a policy, but whether it was enforced was another issue altogether. I think you're going to see more and more of those different groups converge and certainly work more and more together.
We're seeing it. We're a small company, so that team is actually all under my purview. I own IT, compliance, and security, and we all work together because I don't, to your point, the gotchas of wrote a policy, security had the security controls in place, but IT failed to enforce those, whatever those controls were, that puts you in jeopardy.
And I think to your point, a mature organization is going to have that crosswalk and ensure whether they do a continual audit. I think AI is becoming a very big tool that teams can use to look at their documentation, look at and see if their documentation compares to actually what's been put in place. And I think that's actually a really good fit for AI, of being able to look at your policies and ensure they're enforced correctly.
And there's different vendors out there that are also offering those kind of capabilities. But I think that is going to be something that's going to be relied on more and more heavily as we move forward. On the flip side, we've talked about AI, and people, of course, are using data to create the AI, but at some point, will we not also rely more on AI to manage the data?
And that will be a good thing, because right now, the volume of the data just overwhelms us to begin with. So a lot of people are just too paralyzed to do much anything at this point. It's a great point.
I have a philosophy that we need to stop moving the data around where, in old days, everybody had a copy of a Word doc, right? You had one, I had one, six other people had it because we didn't trust the system. We didn't trust access.
" And I think more and more with the proliferation of networks and different technologies, we're moving to not worrying about different copies of it, but how do I get access to a single copy and maybe a backup copy. So we're all manipulating the same file. We're all using the same data, and we're not moving the data around.
We're moving to the data versus moving the data. So that's what I think we're going to be evolving to, and I think AI possibly can help there, because you also, deduping storage. How much money do you spend on storage of your data, and transmitting it and everything else?
And can we get to the point where we're accessing the data remotely and just getting views to the data and manipulating the data without having to actually move it and send it across wherever it needs to go? Do you think the bad guys have been laughing at us all these years? Because we do keep so many copies of the data strewn around that even when we say we've secured the data, there's probably eight other copies somewhere that we didn't.
Oh, yeah. How easy is it for somebody to use some social engineering to get in and get a copy of the data? And then now the big worry is, especially in AI, different AI engines, is the security of whether or not you can ingest something.
So take a copy of some data, manipulate it, and push it back in, and now you're going to be affecting the integrity of the data. So I think data integrity has been for a long time something that we haven't done a good job on, and certainly something that we need to get better at. What is your best advice to the folks who manage data out there about how to have this conversation?
Because I feel like a lot of them right now, they feel like the person who's telling everybody at the AI party to maybe go easy on the punch, but ultimately, they got to have this conversation with somebody and make them listen. So how do they sit down with somebody and say, "Hey, this is a serious thing"? Well, I think number one is having the conversation, making sure people understand the threats.
AI isn't the be-all, end-all for everything. It's not the answer for everything. And certainly, having the conversation about how AI will affect your data, whether the positives and negatives to everything.
You have to have the conversation, and you have to have everybody on board. Everybody needs to understand the rules of behavior around use of AI, what goes into it, what models you use, and the reputation of the model, the integrity of the system. You still have to do all that due diligence you've done before.
" Well, that's great. Good for your brother Bob, but I don't know if I can trust the integrity of that. And have you done any due diligence about the data stores that are coming in?
How do they secure it? All those things. So I think it's definitely an honest conversation that you have to have with all the business leaders in your organization to ensure that everybody understands those rules of behavior and can protect the data that needs to be protected.
So let me ask you this. " I think the thing that keeps me up at night is the shadow IT, the stuff where people, and it's not just organizations, it's people in general, where, "I don't like this. It's taking me too long.
" Okay. "Why can't I use the Google Gemini engine? " And then they start putting their company IP or something that's sensitive into there, or they decide they're going to share information over a text message that they probably shouldn't be sharing over a text because you don't know where that's going to go and end up.
" Because the risks are great now. The threats, when we used to see threats, we're working in weeks, months to get into a system. Now with AI, they're getting in minutes and seconds.
So we really have to be more diligent than we ever have been before about where we're putting our data, how we're protecting it, and know where it's at. All right. Well, folks, you heard it here.
All the good things and the bad things all revolve around how we manage the data. So start there and then work backwards. Matt, thanks for being on the show.
Yeah. Thank you for having me. Appreciate it.
All right. Back to you guys in the studio.