Data Never Sleeps - Andy Soodek - Guardians of the Data - Episode # 50
GOTD - Andy Soodek
===
[00:00:00] Welcome to Guardians of the Data. I'm your host, Ward Balzerzak. Each episode will explore the passions, expertise, and real-world experiences of security leaders who are helping the future of data security and governance. Guardians of the Data is made possible by support from Sentro. To learn more about our AI-powered data security platform, please visit sentro.io.
Let's dive in.
Ward : Welcome back to another episode of Guardians of the Data. My guest today has over three decades of experience in the cybersecurity industry. He's a privacy strategist, data governance expert, and AI risk management leader. Currently a managing principal of data security and privacy, Andy Sudek. Welcome to the show
Andy Soodek: Thanks for having me, Ward. Appreciate it
Ward : So glad you're able to join me this bright, shiny morning. So Andy, in your professional opinion, what's the biggest challenge organizations are facing with regard to data security?
Andy Soodek: I-- honestly, I [00:01:00] think it's the, uh, balance between business objectives, there's a reason that everybody collects all the data that they do, and keeping it protected. Um, you know, there's so much data sprawl all over everywhere, um, and it's a challenge to keep all that data safe when it's getting legitimately shared for authorized purposes, it's tough to control what your third parties and business partners are doing. Uh, and even internally, you've got, um, uh, stakeholders with legitimate business cases for processing data like they do. But keeping control of that is a, a tough spot to be in, um, particularly when that same data gets replicated over and over again and creates new metadata and determining what the authori- uh, uh, authoritative data sources are. all of that combined is, uh, I think the biggest [00:02:00] challenge today
Ward : I mean, I, I heard lots of pain points in that statement and, um, you know, definitely, definitely agree with everything you said. So I'm, I'm curious, I mean, you've, you've been around, you've been in the industry for a while. What are your thoughts on, on how folks can solve for it? Be- because my opinion a- a- and the opinion of others I've spoken to is it, it's, it's only sort of, kind of getting worse, right?
You know, AI proliferation is, is making, um, exposure and data creation and data duplication, you know, really happen at hyper speed. Yeah, it's, it's getting crazy. So what should folks do?
Andy Soodek: well, the first thing we do, um, is really try and get-- W- w- we really depend a lot on, um, getting consent from consumers to use their data. B- you, you gotta be super transparent about what it is you're gonna do with the data, that's notice, and then you gotta get consent to use the data. Uh, even [00:03:00] so, even when that happens, um, y- again, it's still difficult when you're sharing that data with other parties who are doing different things with it.
You just don't wanna be the ones with-- caught with your pants down, right? So, so our data is everywhere, right? The, the idea that a Social Security number, I, I recognize that it's non-personal informa- non-public information. the fact of the matter is my Social Security number is all over everywhere. I am constantly getting contacted by who wanna give me loans for a business that I haven't been involved in for 10 years. Um, you know, the, the, the, the ability to combine data that we've got internally as an organization with data broker data, 'cause we've gone out and sweetened that data, uh, really just is rife for misuse, for mispurpose. A- [00:04:00] and I get that people have legitimate reasons to collect that data and, and process that data.
But, um, now with AI, that adds new layer of complexity to it, right? Where, you know, you got, you got one agent that is processing data for one purpose, maybe it's in a training phase and, um, it outputs some data, and some other agent then goes and picks it up and misuses that for some other purpose. And suddenly you've got, you know, distorted data that can reveal bias, result in discrimination. Um, these are, these are all the challenges of the day. Um, what we're, what we're seeing companies do is, um, A, try and identify where all that data resides right now. And B, um, we're helping, uh, companies to deploy knowledge graphs to, uh, apply semantic layering, [00:05:00] clean up the data, determine authoritative data sources that then can be used in AI models and for various processing purposes. it's a continuous loop though, right? It doesn't ever end. even though you've got a clean data set that's going into a model or some data processing, the outputs of that then, you know, may be, uh, not as clean. It's gotta go through that continuous loop where you're, you're, you're re- rerunning that through the knowledge graph, determining what, you know, uh, uh, outputs are correct, what needs to be translated, um, put into a clean data set for re- reprocessing
Ward : Yeah. H- 100%. And I, and I like something you said right there, the continuous loop. Um, you know, I, I myself, a few times in my career, my leaders have come to me and said, "Hey, Ward, when are we done with, with that project, that initiative?" Well, whatever it ends up being. And I, I've always laughed and said, [00:06:00] "Never."
Andy Soodek: Yeah. Right
Ward : and you know, i- i- if it's in person or a video meeting, I always get a weird look, right? Raised eyebrow or something else, 'cause they, they don't like that answer, right? Folks don't like that answer that it's never done. And it's true. You know, the, the organizations that, w- with everything that you just said, right, that, that go through that loop and call mission complete and then move on, right, set it on a shelf, move on with their day, c- c- congratulations.
Like you, you did the good in, in the moment, and now what are you gonna do, uh, I would say six months from now, but like, even, even now, these days, like what are you gonna do a week from now
Yeah.
When it's all a mess again?
Andy Soodek: mean, it's never-ending loop, right? A, a, a, a never-ending governance cycle too. And, um, and not only that, the governance cycle needs to evolve, right? You gotta keep up with what the latest and greatest thought process [00:07:00] is, what the newest challenges are, uh, because the next challenge is right around the corner, right?
So, um, boy, you know, I, I go back to times where, um, I, I, I ran my own data center. Everything was sort of controlled, right, within an on-premise environment and, you know, uh, we were, we were, we were just trying to keep on top of that. a- and then, then cloud comes along, and now that, that data is distributed further. um, AI comes along. Uh, you know, it, it's, it's never-ending. You, you gotta just keep up with what you've got going on now as I said, the next challenge is on its way.
Ward : Absolutely. Absolutely. So
Andy Soodek: and education of your, of your business stakeholders, um, is super important. Um, they need to understand what the potential risks are, uh, what the, what the real risks [00:08:00] are.
And, um, and they, and they need to, they need to continuously get educated on what the latest and greatest thinking is in business terms so that they're protecting the data, um, much as possible. And, and that's a challenge
Ward : Unfortunately, it's becoming an, an industry phrase, right? That, that users are the weakest link, which, you know, there's plenty of argument, no, that's not true, but education is, is still paramount for, for everybody, both the defenders, both the business folks, you know, e- e- everybody involved, because to the point you made a few times now, the landscape is changing, uh, at, at hyper speed.
Um, funny that you, you, you were reminiscing a little bit, right, at the data center. You know, I, I too started my career where, when data centers were the thing, right? Uh, that, that's where all your data was. It was the whole, uh, you know, castle methodology, right? We're gonna firm up the, uh, the walls. We're gonna have all the protections, the, uh, moat and all, all that good [00:09:00] stuff.
And, uh, you know, when, when cloud kinda came out, I remember thinking to myself, "Who, who the heck is gonna do that?" Right? "Who, who is going to put their..." And I wasn't even thinking compute at the time, I was thinking data, right? Who the heck's gonna put their data into basically somebody else's data center?
And then it just exploded, right? Uh, basically overnight. so c- c-
Andy Soodek: I was working as a federal, uh, for a federal contracting firm. and boy, the federal government wouldn't let us put anything in the cloud. I mean, it, it all had to be locked down, right? Um, and man, that changed fast.
Ward : Right.
Andy Soodek: Yeah.
Ward : Yeah, DISA Cloud came out, right? They, they figured out what's the appropriate way for doing all that. And, and you are correct. I mean, I, I too was in, uh, government contracting for a while, and when I first joined it was like, "Oh, here we go. We're, we're back to [00:10:00] on-prem, on-prem only. We're good."
Andy Soodek: Mm-hmm.
Ward : but, but similar to what you were just saying, like I was, I was there when the shift started, and then boom, it was there.
And it was almost, uh, cloud first i- in a way, at least as cloud first as, uh, uh, the federal government could be back then. Um, it was, it was a strange time to, to be in that space, uh, at least in the space I was in when I was there
Andy Soodek: It was a strange time for us too, and, and, and not only for that reason. Um, boy, when I was, when I was doing that work, it predated the NIST Cybersecurity Framework. So I, I should say I'm a frameworks nerd, and really I'm a GRC guy, more so than a technical... I, I, I've always been fortunate to work with really strong technical people, who could the controls.
Um, but the, you know, prior to NIST Cybersecurity Framework, you know, we were [00:11:00] doing everything just by NIST 853 and the control families. Um, man, it was hundreds of pages of documentation that we had to put together every year. that thinking evolved, um, really rapidly over the course of, you know, about five years, fortunately for, for the folks who are sort of still in that racket. Uh, yeah. But, you know, CMMC came along and, you know, we were advising companies and s- to, to, to, you know, get up to compliance with CMMC and things have evolved, that's for sure. Um, and I will imagine they will continue to as well. would expect it
Ward : so Andy, going back to your, your answer of, you know, the biggest problem, you know, balance of, you know, receiving data, creating data, and keeping it protected.
Kinda your first step, um, that, that you, that you outlined was getting consent, right? To, to get that data, to use the [00:12:00] data. And then you went into, you know, understanding where that data is right now, and you, you further said, um, that it can be duplicated and moved around and, and certainly, um, probably everybody listening, that's, that's where all the organizations are at, right?
Data's everywhere, and understanding the, the duplication, all that is kind of, kind of nuts, uh, when, when you start digging into it. So Andy, um, in, in that step, what, what are your tips and tricks for, for any organizations that are trying to kinda understand what, what that looks like?
Andy Soodek: first thing is, uh, you really need to understand where all those data collection points are. Um, and they're coming in in lots of different ways, right? So we've-- So I work in, primarily in financial services, right? Um, and, and I, I think this is the case for most organizations, regardless of, of sector. but you've got data that's coming in via [00:13:00] web, um, formats.
So, um, uh, pe-people are, are interfacing with your, you know, website. They're interme-i-interfacing with your social media sites. Um, you've got customer care representatives who are collecting data. Um, they are-- The, the, the data that they are collecting isn't always the same as what somebody might enter into a website. then that data is getting used for production purposes, transaction processing. So it's in those systems. Then some, some, you know, da- cool data scientist will take that data and process it in some sort of analytics platform, whether it's a data lake, a, a data warehouse. so it's, it's residing there.
Um, that gets output to shared drives. You've got unstructured data that's sitting all over everywhere, which may conflict with your [00:14:00] s-structured data. Um, so it's all over a-and that's, that's
one of the problems that we're, that we're, you know, getting asked to solve with a lot of our clients is how do we control that data sprawl?
How do we know which data we can trust? Um, and, and so that's why, you know, we're coming in and helping, uh, advise on strategies to help sort of sort that data out, clean it. Um, but then that needs to get put into some sort of centralized repository. So again, there's another copy of it. and, and hopefully that becomes the authoritative data source, but it's still gotta get distributed out to all those systems that are processing it, right?
So, um, uh, you know, again, knowledge graph is the latest and greatest, um, the, the, the way for us to solve and clean up that data. But, you know, there's also something to be said for [00:15:00] good old-fashioned data retention and data deletion processes, which we alwa- we, we typically see companies just don't do as well as they would like to, right?
You, you've got regulatory obligations to delete data at the end of its useful life. We see more times than not, most organizations have more data than they should, which creates legal liability for them as well, right?
Ward : I think, uh, you know, probably 95%, and, you know, all percentages are made up, right? When you, when you come up with them on the fly. But most of the organizations I talk to when, when we're talking data security as a whole, I, I, I, I tend to ask about data retention, and I always get the laugh back.
It's, it's usually, "Yes, we have a policy. Um, yes, that policy is updated on a regular basis, usually annually. Um, yes, majority of folks know about it, but no, it's not actually being followed,"
Andy Soodek: Yeah.
Ward : They have data [00:16:00] retention for five, seven, 10 years, whatever it is, that's their policy, but survey says they've actually got, you know, 20, 30-plus years of data sitting around
Andy Soodek: Yeah, this is, this is a struggle for everybody and, um, I think everybody thinks it's-- You know, the business folks think it's, it's better to, to retain that data, because I don't know, they might-- they think they might face some sort of an audit or, uh, some sort of, some sort of a regulatory finding or need it for some legal protection. Uh, and you know, I mean, there are those rare cases where that happens, but, um,
Right
part, it's, it's, it's less than you would think, uh, less than they would think, I should say
Ward : Yeah, I think a lot of this goes back to, you know, really the third point you had made, which was the continuous loop of governance, right? Good, good old governance that I think a lot of organizations, um, I, I don't wanna say ignore, you know, because most organizations do have a GRC group, and that [00:17:00] GRC group is incredibly busy.
But more often than not, I've seen a general lack of data governance, right? They've got great GRC processes around third-party risk and internal security controls and, and yada, yada, yada. But when it comes to data risk and, and data governance, it's either not there or, or not followed, uh, uniformly. So again, going back to yourself, Andy, you've been doing this for a while.
Um, wh- when you start working with an organization on setting some of those initial frameworks, um, or, or guardrails, what, what are the first couple things that, that you look to enable there?
Andy Soodek: Well, you know, I, I actually think that, um, at, at least it's been my experience in the last few years that, um, most organizations do have some form of data governance in place. And, and in [00:18:00] fact, the organizations we come into, into-- or that we encounter, uh, are looking for some sort of tactical, approach to address the holes that they have already identified that they've got.
So, retention is
Sure
of those areas. Um, data classification, they may be over-classifying the data, and it's creating so much, uh, overhead that they really need to, figure out how to simplify that so that it makes more sense for the business because business is evolving. Um, you know, uh, growth through merger and acquisition creates all kinds of agita because, you know, this organization was doing it one way, the other organization was doing it another, and they need some way to, uh, cohesively put all that together to make a logical sense and anticipate for additional changes that are coming. Um, [00:19:00] and then, you know, putting in the data protection controls around all of that, um, to, to make sure that they are their regulatory obligations as closely as possible. And then we always try, or I always try to, uh, um, get them to think about the customer and, um, what they're gonna do for-- to, to, to make that customer Trust them, uh, to engender loyalty, uh, and, and, and stickiness. Um, so I, I, I'm looking at it from a, a privacy perspective or privacy lens because, well, I mean, I'm, I'm sort of a hardcore privacy wonk, if you will. again, it's, it's a matter of playing catch-up or at least trying to, to stay caught up. Uh, and, and so, you know, it's really about maturing the data governance capability.
And I do think that part of that is, you know, yes, [00:20:00] you've put in a data governance, um, uh, program. And as we discussed earlier, uh, it, it's, it's not a one and done. It's making sure that that's a continuous repetitive loop. And that's part of, you know, developing an operating model, uh, for a business to make sure that that continues to go on and on and on.
Now, increasingly, we're adding in the AI governance lay- layer.
you know, making sure that you're, uh, you know, preparing that data, making sure that you're monitoring the, the business case for an AI use case. Make sure you're monitoring the design and the development, and then the outputs and the, the, you know, a- adequate training, testing, validation of the model. Uh, that, that all has to become part of the data governance and enterprise risk management framework
Ward : I wanna go back. You, you said something very, very interesting, and th- this [00:21:00] actually came up in another episode too, so I wanna go back to it. You said over-classifying data, and the reason I wanna go back to it, it, it's interesting. Um, you know, also in my career, you know, data classification has been one of those initiatives that's been tough, right?
And, and I don't think its difficulty has gotten any less over the years. Um, you know, certainly not from a tooling perspective, but just in general. Um, you know, a lot of organizations have a data classification schema, right? So they've, they've done the good on, on getting that sorted. They might have some sort of mapping of, you know, data types, data elements to, uh, that, that classification.
Um, but there, there's often the struggle on, okay, great, we have these things, now, now what do we do next? It's kind of struggle number one that I've seen, but also struggle number [00:22:00] two, in a conversation I had very recently, actually was going against what you said on over-classification. I had a client that wanted to do that.
They felt having more classifications would make it easier to be, um, you know, hyper-focused on certain controls for certain classifications, right? They, they felt the, the standard three-tier or four-tier system was, was not sufficient. So, so going back to you, Andy, um, first I agree, right? Over-classifying is bad, but I'm, I- I'm curious on, you know, let's dig into that more.
What, what do you mean? What have you seen, and how can folks get out of that situation if they're there?
Andy Soodek: uh, they're, they're just putting in too many layers where, you know... I mean, and there are too many, um, granular rules within e- within each classification set that result [00:23:00] in, role-based access controls being, inconsistently followed across different business groups.
Um, when it gets to be too, uh, o- overclassified, you end up with, know, p- some people who are, um, maybe at different levels and have different needs for that data getting unequal access to that data. Some people should, you know, legitimately get access to the data that don't have that capability, uh, that are barred from using the data, and their peers, you know, have too much access to the data. Uh, and it's, you know, it's, it's because of those granular rules. It, it, it also makes it difficult for, uh, uh, sort of the executive level to be able to make those decisions, um, around who should be able to do what with the data, where should we be able to share that data or [00:24:00] not. Uh, and so simplifying that and, you know, I, I, I, I think it gets down to that sort of four-tier level. Um, I, I've heard, uh, the, the, you know, the, the white, red, green, yellow, it's-- I, I thought that was a real, real strong approach where, you know, you're specifically defining what people can do with the data, who they can share it with. and, and what we're trying to do is just help organizations to, again, simplify that so that it's real clear, um, it's real explainable what you're doing with the data. Um, you can be transparent around the data use, and, um, uh, uh, and it's, and, and it's trainable internally and it's also explainable externally
Ward : I like that. I like that. I mean, tr-trainable internally, hallelujah, right? 'Cause if, uh, if your users [00:25:00] don't e-either know how to classify or use data that is classified or understand, you know, data sensitivity awareness essentially,
Right
you failed, right? Number one, right? Why the heck are you doing it if people can't actually understand and use it?
Uh, but certainly from an audit perspective, because, I mean, I always enjoyed auditors coming in, not really. If, if you can't easily explain it to an auditor on here's how we meet this, here's how we do this, then again, you've, you've, you've failed, right? What, what you, what you built is not, has not been successful.
Andy Soodek: Fair
Ward : so you teased out AI governance as, as another facet, and, and certainly, um, my opinion, there's a lot of data stuff that goes in the right data security, data governance. There's a lot of overlap, right? If it's a Venn diagram, those circles are, are definitely overlapping quite a bit. So, [00:26:00] um, from, from a da- from an AI governance perspective, is there anything else that, that folks should be thinking about that we haven't discussed already?
Andy Soodek: I think the, a, a, a big, uh, point with AI governance is this notion of inference and prediction, right? So it's not just that you're processing the data because, well, we're not, right? Machines are, and they're making inferences about people, maybe based on legitimate rules. Um, but, you know, um, uh, there, there's a lot of probability, uh, uh, in there, um, that again, distort Or show bias, um, result in discrimination.
I know I've said that already before, but, but those things are, are, you know, uh, are very important to somebody who is associated with privacy. Um, we, [00:27:00] we've been helping organizations, uh, um, get ready for, you know... They're, they're-- In the United States, unfortunately-- Well, sorry. The U- you know that the EU has a lot more tolerance for regulation, the EU AI Act has done, you know...
I mean, it's, it's a pretty solid framework for, um, uh, know, governing b- based on risk of the AI models. we've been doing a lot of work with, uh, um, organizations, helping them prepare for the California ADMT regulation, which really is the first AI governance regulation that is really going into effect in the US. Um, so we, you know... And that, and that, that's really concerned with, um, automated decision-making technology, right? So, um, where a, where a machine is making a decision about a person that can impact a [00:28:00] person's, you know, well-being, whether they can get a loan, whether they qualify for, you know, a bank account, whether, um, um, decisions about medical health, you know, diagnoses, whether they can get housing. you know, the, the, the-- A- and particularly without human-in-the-loop controls, where, where a human, um, makes a, you know, conducts some sort of a review of the decision, a- and that decision then gets made without that, that human in the loop. Um, so what we've been doing is helping organizations kind of plot out, um, what they should do to prepare for this regulation, um, what controls they should put in place. Honestly, um, whether or not they need-- First of all, they do need to disclose that they are using these automated, uh, uh, [00:29:00] decision-making technologies. Um, and they need to give, um, consumers the right to opt out, or they need to be able to explain on the back end, um, why, what decision was made, how that decision was made. Um, it's basically a right to appeal, right? It doesn't only cover AI, it also covers, um, legacy processing too. So,
Hmm.
Um, in the, in the, in the banking and credit space, you know, uh, uh, for 30 years, the, the credit decisioning has been, you know, an automated process, right? So if, if, um- If a consumer is denied an ability for a credit card, y- you know, they're, they're not gonna undo, you know, 30 years of legacy processing to, you know, suddenly review everybody's, uh, application for a credit card, right? But they need to be able to explain how they came to that
Right.
[00:30:00] And, and there's a lot of, you know, there's a lot of automated, um, review of, of a person's credit history against, uh, um, the, the, uh, the three major credit bureaus and data brokers and, you know, there's a lot of modeling and there's a lot of logic that's gone into that. um, so, you know, we've been helping them. So, so, so a lot of, a lot of organizations will say, "Hey, you know, you take it up with your credit bureau." And what California asks you to do is to add this additional layer on top of it, which is, okay, um, y- you don't need to necessarily change that, but you do need to add on the layer that says, you know, here's how we came to that decision, right?
Not, not, not at the, not, not at the, um, you know, super incremental detail, but you need to be able to explain the logic that says, "This is what we did with your data get to the decision," um, and give [00:31:00] the right for an appeal. And so th- what, what
organizations have to do is actually add some people in there who have the authority to be able to review the decision and to potentially reverse the decision. Um, that's not gonna happen all that often, right? These, These,
models are pretty, pretty fine-tuned.
Ward : would hope so by now.
Andy Soodek: yeah, right?
Ward : They've been used for many, many years at this point
Andy Soodek: Yeah. Yeah, yeah, yeah. So, those are sort of the, some of the things that we've been working on in, in the recent, you know, within the last year, let's say
Ward : Like it. And, and yeah, I mean, y- yet again, uh, you know, California's trailblazing, uh, s- some of those things, which is, which is great, right? It's, it's great to see some of those controls in. I mean, they did it with CCPA,
Andy Soodek: Yep
Ward : Um, and, and now we've got, uh, many states that, that have their own versions.
Um, and I'm sure
Andy Soodek: we,
we'll see this on the AI front
and they, [00:32:00] um, and they all sort of mirror California with maybe some, you know, minor, uh, uh, um, state-specific, um, uh, nuances. Uh, Colorado ended up changing its AI law to look a whole lot more like California. That comes into effect, uh, in 2027. I, I, I expect that we're gonna see more of the same, right? With, on
the
I agree.
I mean, A- AI's exploded, right? So now, uh, some people love it, some people hate it, but let's, let's be real. You know, regulations and, and guidance do need to evolve. Um, it, it'll never be as quick, right?
Right?
Ward : right? Try, try to catch up a little bit to, uh, to get there
Andy Soodek: Well, it's unfortunate we can't get a, a federal privacy law and, um, and I don't think we're gonna see a federal AI protection law, um, anytime in the near future either. So,
Ward : Agreed. Agreed. Not, not [00:33:00] until... So my opinion is not until we have a majority, right, of the states that have their own, and then maybe, just maybe, um, at the, uh, uh, the federal level, they'll say, "Oh, hey, may- maybe we do need something." Or, you know, maybe they'll take the other approach, be like, "You know what? The states already have their own thing.
Let them, let them keep it that way." And, and it makes it difficult, right, for the organizations that are defending across states to have to bring out that kind of like, that, that map of what are the differences between this state and this state, what do I need to do, versus, "Hey, I know if I do this thing, it's applicable across the board, right?
Across every state."
Andy Soodek: we try and get organizations to, um, uh, meet the high bar as much as possible. Because you should an- we should anticipate as the additional states come on with their privacy laws, it's only gonna get tougher. so, you know, uh, uh, go for the high bar and then you know that you're, you can comply with all the other [00:34:00] states that are, are coming into play.
Ward : Andy, y- you've been doing this for, for quite a while, you know, l- like the, uh, the intro was, over three decades of, uh, of time.
We, we talked about, uh, you know, you and me, right? Back in the day, data centers, then cloud, now AI. But, um, what's been your journey? How did you get to where you are today in your career?
Andy Soodek: it's sort of a circuitous path. I, I, and I actually hear a lot of your guests say a similar thing. I didn't start out as a technician. Um, I actually came up through project and program management, and have always been interested in regulatory compliance. Um, even when I was doing my MBA at Georgetown, I ended up taking classes in the School of Foreign Service and, uh, and the law school. I, I, you know, kept working up through the pro- project and program management spot until all of a sudden I found myself at this federal contractor and they... And I could [00:35:00] see that they, they had just won this federal contract, and I could see that they didn't have what they needed to comply with, uh, all of their NIST obligations, and felt like I could do it.
And the next thing you know, they hired me as their CISO. and, and my job was really, you know, working through all of their regulatory obligations and sort of running the security shop for, for, you know, f- for that organization. I, I, I did that for about five years and then, um, uh, we went through a private equity takeover and suddenly we had two CISOs and two CIOs and, and I had an opportunity with, uh, a technical partner to do some consulting work, um, for a few other organizations.
Suddenly these, these opportunities fell into my lap and ended up, we ended up leaving and starting a, um, an MSSP and security, um, advisory consulting [00:36:00] firm. Uh, I'm gonna give them a little plug, Secure Compliance Solutions. They're still in business today. Uh, really strong people there. Um, good people. so, so I, I did that for a couple years, and it was right around the time that GDPR, um, was sorta going through its, you know, coming into existence, like 2016. Um, at that time, I sorta realized that what I really cared about more than anything was protecting our data And I, and I wrote a manifesto about why, why not the GDPR for the US? Um, it was just a philosophical document and, and what I really wanted to accomplish with my life and, and help organizations accomplish. the-- what I found was that I didn't really have the stomach for sales, and I really wanted to just deliver. I came into an opportunity at a bigger consulting firm [00:37:00] just doing basically privacy consulting, and that's where I wanted to be. So I, I left Secure Compliance Solutions and, and started work in that space. I've had all kinds of really great opportunities working with a lot of really great organizations facing a lot of very big challenges. Um, you know, and I, I think, and I think I've helped a lot of organizations, um, to meet their compliance obligations and again, um, build trust with their customer bases. Um, I've learned a lot along the way and, uh, I think I've helped to, um, teach a whole lot of people about some really practical things that they can do to uplevel their privacy games. when we first started out, you know, in, in around 2018, uh, doing this kind of work, we were building whole privacy programs.
Um, since [00:38:00] then, we've been helping companies with tactical, uh, deployments of, of controls and systems. Again, a lot of universal consent and preference work because so many companies are, are dependent on, on consent from consumers, particularly where the processing is outside of their sort of core business.
So, you know, if you've got-- if you're in financial services, you know, you collect non-personal public, non, non, non-public information, um, KYC, AML informa- you know, information that's, that's part and parcel of sort of core processing, transaction processing. marketing use cases, data analytics use cases, aren't core processing activities, and for that you need to collect consent. so we've been helping companies with a lot of that, and as I said, now, you know, increasingly getting [00:39:00] into AI governance.
Ward : Ve- very interesting journey. I'm, I'm curious 'cause I've, I've, I've talked to a lot of folks that have, that have made this shift. So you went from the enterprise side, right? You s- you said you were a CISO and, and a leader there,
Mm-hmm.
And then you, you shifted into consulting essentially. So, I mean, a- a- any, uh, any regrets or have you been loving the consulting life since then?
Andy Soodek: I, yeah, yeah, yeah, sure. I've got some regrets. Number one, uh, I, instead of an MBA, I wish I had gotten a law degree, um, m- more so than anything. I, I feel like, uh, uh, at this point I would be a privacy or data protection officer for a, a, a company as opposed to in consulting. Consulting has taught me-- It's, it's given me exposure to a lot of different use cases, a lot of, lot of different challenges. I, uh, I'm 57. Uh, I feel like I've got one more big run in me point. And, um, y- and honestly, I would like to go back to an [00:40:00] industry role at some point.
Ward : Amazing. Amazing. And it's, it's never too late, right?
Andy Soodek: It's
Ward : I've,
Andy Soodek: late,
Ward : I'm on LinkedIn far more than I should be for sure. And,
Andy Soodek: Right
Ward : I keep seeing those, those stories, right? Of, of folks that have, uh, you know, jumped around and they're, they're still grinding, whether it be 37, 47, 57, even 67, right? I've seen some folks in the 60s, you know, ma- make a pivot.
Andy Soodek: Yeah.
Ward : it's never too late
Andy Soodek: Yeah, that's right. That's right. And, uh, and I'm not giving up hope. It's, it's gonna happen at some point,
Ward : Well, Andy, I really appreciate you joining the show. This has been a great episode, sir
Andy Soodek: Yeah. Thank you. I really, really appreciate it. I, I really do
Ward : Absolutely. And big thank you to the audience. Really hope you enjoyed the episode and learned something today. Please tell others in your network to follow and listen. This has been another exciting episode of "Guardians of the Data." See you next time.
That's a wrap on another episode of Guardians of the Data. Thanks for tuning in. For show notes and more, visit [00:41:00] guardiansofthedata.show. Guardians of the Data is made possible by support from Sentro. To see how we help organizations discover and classify all of their data accurately and automatically while quickly achieving petabyte scale data protection without the fuss, please visit sentro.io.
Catch you next time
Creators and Guests
