October 07, 2026

00:40:13

Episode 388 Deep Dive: Dean Saunders | The Breach That Won't Look Like a Breach: Why AI Security Starts With Your Data

Episode 388 Deep Dive: Dean Saunders | The Breach That Won't Look Like a Breach: Why AI Security Starts With Your Data
KBKAST
Episode 388 Deep Dive: Dean Saunders | The Breach That Won't Look Like a Breach: Why AI Security Starts With Your Data

Oct 07 2026 | 00:40:13

/

Show Notes

Most boards approved AI for the productivity gains, and far fewer asked what it would expose.

Dean Saunders says conversations with large organisations usually start with models and end up on data: where it lives, who can reach it, and how quickly an agent can move it once staff have gone home.

KB and Dean talk about shadow AI, approved tools used on personal accounts, and trusted apps that quietly add AI features without security knowing. They also get into why compliance keeps getting mistaken for security, and why regulators now want proof of what you did rather than the policies you wrote.

About Dean: Dean Saunders is the Regional Director for Australia and New Zealand at Forcepoint, where he supports customers and partners in protecting sensitive data across modern cloud, SaaS and AI‑enabled environments. He focuses on expanding Forcepoint’s data security footprint in the region, helping security leaders strengthen visibility and control over high‑risk data through the company’s portfolio.

With more than two decades of leadership experience in enterprise software, cybersecurity, SaaS, channel strategy and go‑to‑market execution across Australia and the broader Asia Pacific, Dean has built a strong track record driving regional growth. His background includes leading high‑performing sales teams, developing partner ecosystems and supporting technology organisations competing in complex markets.

Before joining Forcepoint, Dean held senior commercial and leadership positions at Cyara, Forticode, Unitrends/Kaseya, Teradici, CommVault and Total Defense. His diverse experience spans direct sales, channel and alliances, partner‑led growth and strategic market development, complemented by advisory work focused on improving sales execution and market strategy. He holds an MBA from the University of the Sunshine Coast and has completed extensive professional development in enterprise selling, leadership, key account management and media training.

Keywords: AI data security, data security posture management, agentic AI, shadow AI, data loss prevention, DLP, data discovery and classification, AI governance, compliance vs security, insider risk, Forcepoint, cyber risk, board cyber governance, KBKast

View Full Transcript

Episode Transcript

Dean Saunders [00:00:00]: They then enhanced it with an AI functionality. But of course that AI functionality had access to all the information that that user had. And without anyone from security authorizing it or even being aware, you've got an app, an AI application within a previously approved application accessing a whole bunch of information. VO [00:00:20]: From KBI Media, I'm Karissa Breen, and this is KBKast. KB [00:00:27]: My guest today is Dean Saunders, Forcepoint's Regional Director for ANZ, who sat in on a lot of meetings where the room goes quiet once people work out their AI rollout is sitting on data nobody's checked in years. We talk about why the next wave of breaches probably won't look like breaches, why so many organizations still treat being compliant and secure as the same thing, and whether we can close that gap before AI starts making its own calls about our data. VO [00:00:58]: If you find these conversations useful, hit follow. It's the single best way to make sure the next one lands right into your feed, and it helps other execs find the show. KB [00:01:09]: Alrighty, let's get into it. So Dean, I'm really curious to understand, you say that there's a data problem but not a model problem. So what does building security from the data up actually require in your eyes? Dean Saunders [00:01:23]: So we're very fortunate that we get the opportunity to speak to several large organizations a day. And typically we're talking to them about data security, obviously. But the thing that they've become very focused on is ultimately AI security and how they're going to protect themselves around AI releasing and/or sharing sensitive data that wasn't expected. Invariably, the bit that I want to talk about first is their model and sort of what they're doing with AI. They're somewhat disappointed when we first introduced the idea that it all begins with data. Given that data's the oxygen for AI. They then often sort of want to take the conversation to talking about DLP or data loss prevention. And then we actually lift the lid on the unsexy part, which is discovery and classification. Dean Saunders [00:02:10]: The reality is if you don't know where your sensitive data is living and what it looks like, what the context of it is, as well as the posture of that data, like who has access to it, Obviously that leads into potentially the agents having access to it. Then you can't protect what you can't see and/or know where it is. We often see that sort of sideways glance from one person to another when we're in a meeting with these large organizations. And that's often one person in the organization already understood that it is going to be about protecting the data, that the data is somewhat exposed after years of somewhat neglect around understanding who or what had access to data and where it was stored across the organization. There's another person sort of within that prospect or customer that has that realization that agents are able to access it much quicker and/or more efficiently than what people had. And so for us, it's about somewhat taking the customer on that journey, understanding that it really is about the data and who has access to it and/or who can move it around. The issue now has become that their models want to do it at enterprise or industrial grade, right? They're doing it at scale very quickly. The agent doesn't go home at 5 PM like the employees did, which is what the models were built for. Dean Saunders [00:03:24]: Unfortunately, now it's all about, yeah, what's happening with the data 24/7. KB [00:03:29]: So I want to understand, given your role and your level of talking to people like customers, what, what's sort of happening in your part of the world at the moment? Like, give us a bit of an update. Dean Saunders [00:03:41]: Yeah, many organizations have kicked off with AI. In a sort of a trial slash, you know, how are we going to make the most of this? That sort of trial and/or information was fed back to senior management and/or the board, and they gave a big thumbs up for productivity gains and what they were going to do and achieve with AI. There wasn't nearly as much consideration or discussion around the risk or the exposure that was going to come along with that productivity gain or change within the organization. And now organizations have been tasked with going off and actually implementing these AI projects. And/or transformations within an organization. And what's been left lagging is that bit around the risk. Often, you know, we're hearing organizations now executing on AI and/or shadow AI being the other issue that's happening as well. And they just haven't fully understood the governance, compliance, and/or risk around lack of visibility to what's happening within the organization. Dean Saunders [00:04:42]: The 3 use cases we're often talking to organizations about now is ultimately what information's going into prompts. And then, you know, ultimately what's coming out of the AI. What are you doing around agentic AI? And not uncommon for us for an organization to say, oh, we've got very limited to no agentic AI within the organization, but then someone else within the organization come straight over the top and actually share that yes, it is underway and or they're unfamiliar with how many agents they've got running. In their organization. And then last but not least is ultimately that issue, shadow AI, or employees downloading their own AI application and/or off looking for those productivity gains, not necessarily with sanctioned applications by the organization. And in that regard, the one that we're seeing more recently is employees using this sanctioned application, but with their own personal account. And so that's creating a whole other issue around what's happening with the entity's information once it's been shared with that AI application. They're the sort of 3 that we're seeing at the moment. Dean Saunders [00:05:47]: It's quite interesting to watch the reactions from customers and/or prospects when you start asking them these somewhat loaded questions. I mean, invariably somebody in the room knows the answer. It's often whether they're prepared to speak up in front of their colleagues. KB [00:05:59]: There's a couple of things in there that I want to explore a bit more. So going back to the risk side of things, now I know that even a couple of months ago, I think there was a US government official that had uploaded sensitive document into ChatGPT, for example. Would you say nowadays people are more cognizant though of what they are uploading, or do you still think that concept is not there for employees because they're so focused on the efficiency? Yeah, but if I upload the P&L, I don't have to do as much work and I can kick back a little bit on the Friday afternoon because the machine's doing the work for me. Dean Saunders [00:06:31]: So absolutely seeing that. And if I can, I'll sort of dig a little bit deeper into it. So your question was in relation to, are people more aware of it? And the answer to that one is absolutely yes. But then sort of that next step, if you like, or that next layer down is often it's employees that are looking to be more productive. They're not, you know, have any malicious intent or they're not looking to do the wrong thing. They genuinely want to be more productive and/or aware there's a more efficient way of doing it. And they're somewhat naive that they're putting the organization at any substantial risk. So they're thinking, well, I can upload this document. Dean Saunders [00:07:09]: And/or data into my personal version of whatever application, what are the chances we'll get caught? Or what are the chances we're going to get exposed? And it's that lack of sort of responsibility, if you like, that people are still ultimately treading that fine line of, okay, will this be okay or will this actually cause a breach? One of the interesting conversations we're having at the moment with a lot of security leaders is the next wave of breaches won't actually look like a breach. It'll look like an AI application doing exactly what it was designed to do, but an employee uploading the wrong thing and/or not having the right safeguards in place. You won't find out about the breach or the overexposure, if you like, because it didn't look like a breach. KB [00:07:55]: Yeah. Dean Saunders [00:07:55]: The AI tool was put in place and/or they were using a shadow AI one that didn't necessarily breach any policies or governance pieces that are in place. And yet there's going to be something overshared. And away it goes. The last piece I would add to that is, or double down on, is not out of malice. We're seeing employees genuinely looking to do the right thing. Governance and/or compliance hasn't necessarily kept up to speed with it so that those breaches aren't going to look like breaches. They're literally just oversharing and/or an accumulation of over-access, if you like, where people haven't gone back and restricted access to information over many years, and that's now going to be exposed. KB [00:08:37]: Okay, this is interesting. So not only do people have to worry about a traditional breach, let's call it that, but now they have to worry about some sort of somewhat manufactured breach unnecessarily as well. Dean Saunders [00:08:50]: Yeah, and we're sort of not putting them as worry about it, it's factor it into the equation. Cybersecurity, if you like, or cyber risk has been around for a long time, and it is often sort of framed as worry about the this or worry about that. Our piece has been locally anyway, raise your awareness and/or right up to the board level around what you're running the gauntlet around ultimately, around what data's being shared by what applications and/or who's making these decisions around AI coming into use. I mean, that point, I'll share a little bit more about that one. I'm sure we saw an organization recently that had an application running from a particular vendor already in their environment. As so many of these applications do, they then enhanced it with an AI functionality, but of course that AI functionality had access to all the information that that user had. And without anyone from security authorizing it or even being aware, you've got an app, an AI application within a previously approved application accessing a whole bunch of information. So we're sort of very much staying focused on raising the awareness of just how broad this issue can be and how many doors this issue can come through. Dean Saunders [00:10:05]: To your point, we've spent a long time on sort of malicious or bad actors, if you like, doing the wrong thing. We've then gone to, hey, be aware that people are attempting to do the right thing and still exposing you. And then we've taken it one step further to go, hey, even people within your organization that have approved apps that have changed in terms of the technology within them are now also exposing them. So it's not even necessarily just the employee inadvertently sharing something within another AI application. It's potentially an application you've already approved that's somewhat changed in terms of bringing an AI feature within it that's also causing that issue. So we're really trying to stay focused on broadening people's understanding of where this risk is going to. But to the earlier point that we made, right, the common theme around this is it all stems from, you know, your data and knowing what is where and the context of it. KB [00:10:58]: Okay. So there's a couple of things because it's like, there's like hub and spoke, where the main problem, but then these other sort of spoke problems that seem to draw off it. Dean Saunders [00:11:07]: Right. KB [00:11:07]: Okay. Would you say then companies are focused on stopping AI from leaking data, like number one, or would you say that they're ignoring the earlier question on whether the agent should have been allowed to access that data at all or in the first place? So to add to your point just before there, Dean, because it seems like Yes, they're both important, but perhaps if we fix the latter problem, the former somewhat may be resolved. Dean Saunders [00:11:37]: Yes. Coming back to your hub and spoke analogy, for us, the hub is ultimately the data, right? And for us, all those spokes going out are ultimately awareness around how they're exposing their data by all these other avenues. Now, If we go back to call it 2 years ago, those spokes were purely email, web, you know, sort of traditional ways, if you like, where data could be overshared. What we're doing now is assisting organizations understand the industrial scale at which AI can access all of your sensitive information, as opposed to previously humans initiating email or USB, that it's now an application that's driving all of this, as well as AI not being one of those spokes, that it's several of them, that the AI is coming in via other applications that have been approved by the organization, but that no one necessarily from the IT security team approved that. That was someone in marketing or sales going, yep, we, you know, we would get some productivity benefits out of this. Tick that box, start using AI via that other application, just as an example. So yes, it is about that hub and spoke. The reality for us is the hub again is the data. Dean Saunders [00:12:58]: The difficulty at the moment is organizations understanding all these spokes and all the nuances that are being presented very quickly that AI is bringing to the table. Does that help? KB [00:13:10]: Yeah, because then my next question is, even if we go back 10 years ago, like there weren't as many tools that were coming out and now with like AI, to your point around shadow AI, because now everyone's got their favorite tools that they want to use or a new one pops up that may be more suitable for requirements for marketing. marketing or finance or whatever it is. So, is it really hard now for companies to ensure, well, we've got to stay top of mind and maintain competitive edge against other players in the market? I get that. But then at the same time, we don't want to disadvantage our staff in keeping it, yes, but safely, so to speak. But then also, it's a lot faster now than before. So, it's not as easy. I mean, you and I talking about it sounds easy, but in practical sort of terms, it's a lot harder. Dean Saunders [00:13:55]: One thing we often are hearing from prospects is exactly that conundrum, that the tool selected by a particular department or executive wasn't fit for purpose across, call it, 2 or 3 different departments and/or didn't meet the compliance or security requirements, ultimately by IT or the cyber team. And so our positioning to that has been, you need each, you need a stakeholder from each part of the organization ultimately going on this journey. You know, having the world's most secure AI application, to your point, doesn't necessarily lead to the most productive employees. And then even within that, one department, say sales, may have a very different view on what the most productive AI application is compared to marketing. And so it becomes about having stakeholders across each of them understand, A, what's best for their department, but then B, you know, what is ultimately required to safeguard the whole organization. And so IT department heads and governance all coming on that journey together so that you, you're somewhat sort of rising tide and everybody being elevated, if you like. That said, the good news around a lot of this is that whilst we're talking today about AI being the risk and what it's all exposing, it's also somewhat the remedy. You know, obviously organizations or vendors like Forcepoint have included AI within our applications to assist. Dean Saunders [00:15:26]: So when it comes to discovery and classification, we've got proprietary tools that we call AI Mesh, essentially 50 small language models that you can tune and adjust to go off and do that discovery and classification so that not only is AI industrializing the risk, it's the reality is it's also industrializing the remedy. And that's the bit that, you know, where IT teams and all people that we're talking to sort of take a sigh of relief going, okay, it's, it's not all bad news. AI is here to help as well. And there's some other really great examples around the legacy in this space is that, you know, these products are typically quite noisy, a lot of false positives and that type of feedback. We've built AI into our applications as well to hear the alerts and/or analyze them and make suggested policy changes so that you don't have to have a human on the other end adhering or attempting to process all of these false false alarms or false positives, clearly you can get an AI tool to analyze that and make suggested changes to assist. So the point there being, you know, AI's, it's not all risk. There's some good news about it as well. But it's about taking each department within the organization on that journey. KB [00:16:41]: And Dean, you say that visibility without control is not security. So if a company can detect an agent, for example, transferring sensitive data, but can't stop it in real time or the whole kill switch thing, would you say its security function has then kind of failed? Because if people are aware of it, we want to try to intervene versus the thing just keeps going. Dean Saunders [00:17:05]: Yes. And more often than not, the way we're having this conversation with more organizations is that they're somewhat confusing governance and/or controls with security. Or the other way we frame it is it's one thing to be compliant. It's another thing to actually be secure. Not to dismiss or, you know, take any focus off the requirement around governance. And in that end, we're talking about sort of the frameworks and the policies and all the documentation that's required because they're all still very important pieces. But does those actually make you secure? And the short answer to that one is ultimately no. You know, if you don't have something that can respond to a potential oversharing of sensitive data in near real time, and in that, to that end, we're talking about within seconds. Dean Saunders [00:17:55]: The reality is it's not actually making you secure. It's just making you feel good that you sort of ticked a compliance box. And coming back to the previous point made, the good news there is, you know, that organizations like Forcepoint have included AI within our solutions to be able to assist with near real-time alerting and/or changes within your policies to ensure that, you know, should you get a situation where information that's been shared that's sensitive, that there's a near real-time change in terms of ensuring that the organization's as secure as possible. KB [00:18:31]: And then why would you say people confuse the two? Dean Saunders [00:18:34]: Yeah, this one stumped me for a long time because it seems obvious. But having said that, when we get out of bed in the morning, that's all we talk about is security versus governance. The terms get thrown around and interchanged. Within customers, and they think that compliance ultimately means that they're secure, that because if they are compliant, they are secure. That said, what we're seeing is policy and regulators move away from show us what you did to be compliant to prove and show us auditable reports around what you did to actually be secure. We're seeing that across various regulations. There's sort of 2 or 3 of them here in Australia where they're moving off Show us the tools you've purchased and/or, you know, the policies that you set to show us the actions you took to actually be a good custodian of your data, as opposed to just purely purchasing a product and, you know, fingers crossed that, you know, allows you to be compliant. One of the more recent fines, the majority of the fine actually for the organization was the fact that they hadn't actually taken steps to be secure as opposed to purely tick that compliance box. Dean Saunders [00:19:47]: The other one is, you know, to one of the points you made earlier, this stuff is really tricky. It's hard to do. So organizations often embark on this project of going, hey, we're going to secure our data and we're going to be compliant going forward. You know, they lift the lid on it or get into the project and realize just how difficult it is to do this work and/or achieve this. And the project loses momentum over an extended period and sort of only gets delivered 50%, 60%, 70%. And it's that last 30% that was the critical piece to actually be secure, not just compliant. KB [00:20:21]: We'll come back to that in just a moment after a quick word from our sponsor. For remote-first companies, maintaining a strong security posture across distributed teams can be a challenge. That's why thousands of modern, remote-friendly firms turn to Vanta. Vanta automates the heavy lifting for ISO 27001, SOC 2, GDPR, and more, keeping you compliant and audit ready wherever your team logs in from. Visit vanta.com/kbkast, V-A-N-T-A.com/kbkast, to learn more. Your commentary there, Dean, around custodian of your data. So would you say nowadays it's a lot harder for companies to conceal whether they did not show that they've done reasonable endeavors in protecting the data. Whereas historically, it may have been easier to say, we really care about your security, but we had a massive breach, like even 10 years ago perhaps, or we care about customer trust. KB [00:21:21]: Whereas now, to your point, people have to prove and show that they're actually doing it. Because it's very easy for companies, big companies to say, well, we really care about it. We care about it. And then when something happens, well, we really care about it now because We got bad press, where stock prices plummeted, customers are leaving. So what are your thoughts then here? Because now it has to be a little bit more than just virtue signaling to say, oh, well, we've sort of done this stuff. Now you have to back it up. Dean Saunders [00:21:49]: So as I understand it, the question is, is it harder for organizations now to prove they're actually secure as opposed to years gone past when larger organizations in particular could And to your point, virtue signals are, yeah, you know, we're doing all we can and we care about you as a customer. The answer for that one to me would be yes. And that's been coming even prior to sort of this acceleration piece or this multiplier effect of AI is brought to the equation. The reality is over the last few years, cyberattacks and/or bad actors were increasing in complexity anyway. So it was getting harder and harder to sort of stay secure. What we're seeing though, since AI has ultimately taken effect, is the industrialization both at scale as well as in the complexity of what these attacks look like, as well as the speed. It's the compound effect of those that ultimately has made it somewhat incredibly difficult to actually keep your data secure. A lot of organizations that we're talking to might have You know, one or two out of the 3 required steps. Dean Saunders [00:22:56]: Very few have all 3 totally buttoned up across their entire estate. Larger organizations that have been sort of going on this data security journey for an extended period haven't necessarily buttoned up to 100% at any point in time. And so that compound effect ultimately is what's getting exposed now by purely because of the, yeah, the scale, the speed, and the complexity at which the threats are now presenting. And that's, you know, just taking the bad actor effect into it, right? You know, one of the points we made earlier was the reality is it could even come within and not necessarily be a bad actor. It could be someone, you know, purely with good intentions oversharing in an AI tool on a personal account within a sanctioned AI tool. And all of a sudden, you know, that data has been shared and out the door it goes. KB [00:23:46]: Do you want to come back to the governance side of things again? Would you say, can an organization actually really claim that they govern AI if it can't immediately revoke an agent's access? Because again, that goes back to the virtue signaling. You say you can govern it, but then when something goes wrong, you need to be able to intervene. Dean Saunders [00:24:06]: Yeah, a highly loaded question and a good one. Look, from our perspective, the answer is no. Look, if you can't point to an auditable report that shows the steps you took to understand where your data is, what the context of it was, who had access to it, and what happened to it when it moved around, then ultimately, no, you're not fully compliant. Because to the earlier point, regulators are requiring you to show what you did to actually be secure, not just compliant. And where this is going now is AI exposing sort of these doors that have been left open as at the same time, regulators and compliance somewhat moving forward as well with being compliant isn't enough. You actually need to be secure. And in addition to that, show us what you did to be secure. And therein lies the problem, we feel like. KB [00:25:05]: So would you say going back to show us what you've done, what you're doing, What's implemented. Would you say this is where most companies are probably going to fall down? Because like I said, it's easy to say here on this, but it's hard to implement, especially in a large organization. You've got different teams, you've got different opinions and egos and all sorts of things. It's not as easy for people to implement these things. And therefore they may get tripped up when there's an audit that comes around or something happens post-breach that someone needs to go and investigate. Dean Saunders [00:25:37]: Yeah, good question. And I actually haven't thought of it in terms of what's going to be hardest or what's the part that's actually going to trip them over. For us, we're sort of seeing it through a lens of sharing the entire issue, right? Like if you don't have these technologies in place is the first step. If you're not doing all you can to implement them effectively, sort of the second step. But then third, if you're not tuning them along the way, being the third step. But then fourth, and the point that you're asking here, are you documenting that piece along the way as well? For us, we're probably stuck at step one, to be fair. You know, we're talking to a lot of organizations that recognize they've got a gap in the technology that they're using to even out of the gate, you know, do discovery and classification, let alone DLP, you know, let alone the next piece on top, you know, AI data security. And so I actually haven't gone through that, those steps with an organization to sort of say, here's the, here's the 4 steps, you know, what can you show around this 4th one? We typically just open that, open that door and see if they want to step in. Dean Saunders [00:26:47]: The bit I would say to that is we're coming across very few that are doing sort of a representative from each of the stakeholders of the business. And all of them going on that journey. What we're often seeing is it's left to cybersecurity or, you know, the new AI and data person that's been appointed in the organization to ultimately provide this silver bullet for the organization. And I guess, you know, to your question, one thing I need to be thinking about is how do we include those 4 steps for that person and understand what their level of awareness around showing that reporting and or those actions taken. Good question. KB [00:27:25]: Because it sort of, it reminds me of like when people doing an IRAP assessment, you can't just tell people what you're doing. You got to show it. And part of getting, you got to prove it and show all the documentation and all the steps. So it's quite an arduous process. But then would you say if people do this correctly, to your comments around all tides? Dean Saunders [00:27:44]: Yeah, yeah, rising tides. KB [00:27:46]: That's it. Yeah. That will be a byproduct of all the work that companies are doing. So we should hopefully see less breaches. We should have less customers upset, et cetera, less fines going around because people have done the work in the beginning. But then my next question would be, because I've worked in this space historically, it's really hard to do documentation all the time because you've got to keep your head above the water, so much stuff going on, and now it's not every 6 months or every year. It's going to be more continuous on updating things because things do change more. Would you say that's another issue? Because again, no one really, end of the day, wants to update documentation unless you're probably a policy writer. KB [00:28:30]: But in saying that, do you see that as another potential drawback for companies? Dean Saunders [00:28:35]: I'd say no to that one. And the more I thought about it since we spoke about it, if we go back to those 4 steps I shared, I think I think step 1, incredibly difficult, you know, getting the right technology in place. Step 2, equally as difficult almost to get it deployed and get it working. Step 3 should be part of your business as usual around refining it. Step 4, that documenting it piece, you know, this is where AI really becomes the remedy, right? As opposed to the risk. I mean, this is, you know, one of the probably stronger use cases of AI is ultimately feeding it the data. And/or it having insight into what people are doing with their data security applications. And to the point made, provide really efficiently and quickly, you know, the documentation around what the organization was doing and the steps they were taking. Dean Saunders [00:29:26]: It should actually help industrialize that bit, make it relatively easy as long as you've clearly got a human in the loop effectively reviewing it and/or sort of giving it the tick. the actual production of that documentation should actually be somewhat easier. Could be slightly naive from my part, but you know, to me, that's where AI steps in to actually help. KB [00:29:46]: That part I get from doing the hard labor of the machines doing like writing majority of it. But do you think that, and I ask this because I've been speaking to people that say humans are getting conditioned now to just accept what the machine sort of says without really thinking through it. So if I'm reading a document and I'm the person that's running it and responsible for that area, I may just be like, oh, well, it kind of got it right 80% last time. It should be okay this time. And that may not be the case. Do you see the word isn't lazy, but perhaps people got other stuff that they need to do. This may fall to the back burner and maybe there's too much assurance left with these machines to be like, I still need to go through it quite meticulously because this is what we fall back on then as a company. Dean Saunders [00:30:28]: 100% agree with you. In the very early days when AI was getting going, there was a phrase coined called AI slop. And it was one that I sort of went, you know what, I'm probably personally going to be prone to that one. And I sort of went, you know what, it's going to be up to me to ultimately take responsibility for emails that I press send on and, or, you know, work that I present as being done by myself. And having said that, not all individuals are necessarily Taking the time to do that, and yet I'm absolutely seeing firsthand organizations do exactly what you just mentioned there: that AI goes off and does the work, presents something as a given, or you know, is factually what's happening when ultimately it's far from the reality. We're seeing that from prospects. We're seeing it in tenders coming back from partners. We're seeing it all over the place. Dean Saunders [00:31:26]: It's quite interesting when you have debriefs and/or calls with them and you ask them about documentation. That was produced. We've even had one just point blank saying, "Look, apologies. That was produced by AI. Put a pen through that. Pretend you'd never read that." So it's absolutely happening, and I think it'll be in part of the next wave of how quality workers will sort of elevate themselves above those that are just passing on essentially AI slop as their own work. I think those that are sort of already cognizant of it and or taking responsibility will absolutely. Differentiate themselves from those that purely pass on what AI is generating. Dean Saunders [00:32:04]: We had a classic example here, I think it was 6 or 12 months ago, a very large piece of work done by a large GSI for the government, you know, several hundred thousand dollars worth of consulting. And the report was generated in part by AI or part of the work was done by AI. And of course it made its way into the final report only for them to ultimately have to acknowledge That it wasn't necessarily a person that had generated it, even though they'd charged an exorbitant amount of money for the work and had to refund it. So it's absolutely happening. It's more about sort of taking responsibility for what you're sending out the door. To that end, for organizations, it's going to be more about them understanding that this governance and compliance paperwork that gets generated is going to get exposed at board level. And if you don't have it right, it's going to be exposed at that level. if not before, caught by the executives that are reviewing it. KB [00:32:56]: And then another sort of interesting scenario would be, and what comes up in my mind is, what happens when an agent performs an action it was sort of technically authorized to take, but uses the data in a way like nobody anticipated? So would you say companies are starting to scenario plan, okay, if it uses this, because again, Jobs agents' jobs are to do the tasks most efficiently. Like I've heard other agents railroading the other one and all sorts of things going on. So are people mapping this out then to see what could happen? Dean Saunders [00:33:31]: This is absolutely not. And the primary issue there is the fact that they haven't even got awareness and/or visibility to what that current issue looks like at the moment because they haven't taken that first step around understanding where their sensitive data is and even which people have access to it, let alone, to your point, an AI agent. And it's often not until it's actually happened and then someone ultimately sees what was produced by an agent. But to the point we just made in that previous question, that somebody actually does something about it, you know, recognizing that it did something wrong and somewhat just turning your back on it and going, oh, well, that was, that was no good. Hopefully next time it doesn't create that issue again isn't going to get you across the finish line. Right. And so part of that AI slop that I mentioned is people not necessarily taking the time to enforce changes within the data security posture based on what they're seeing the AI agents produce. And then to your actual question, are they then modeling it? No, because of the lack of awareness and/or visibility to what's actually happening in their environment. Dean Saunders [00:34:39]: It's sort of primary issue there. KB [00:34:41]: And then Dean, from my understanding, Forcepoint describes the layer between AI agents and business applications as a new control point, for example. So what must happen at that layer that an existing DLP and access control can't already do? Because that might be some of the questions that people are asking you in the market, just so we're clear on what that means. Yeah. Dean Saunders [00:35:07]: So the technologies that have been in place for years have ultimately been for a human interacting with data, right? They did it sort of one at a time. It wasn't necessarily at a particularly significant scale. Now, because it's the application doing it at scale, and then it's going straight into the data, it's that connection in there. And often at that sort of MCP piece, if the agent doesn't understand the context of the data, so coming back to the very first point that you need to understand not just where your sensitive data is, the context around it, who has access to it, but now also what has access to it, i.e., the agent, as well as what happens when that information moves. Those pieces in that in-between now have become absolutely critical because AI is doing it at such a scale and such a speed that it's out the door and run. A lot of it very quickly if you don't understand what's happening in between. KB [00:36:13]: And would you say that people still are trying to wrap their head around this concept? And do you think they still refer back to traditional DLP solutions? Dean Saunders [00:36:22]: I'm going to say yes, but invariably when we're meeting with customers and prospects, one or two people in the room understand it. It's that necessarily not everyone in the organization is going on that journey. So you might have one or two people that understand just how much exposure these agents have to the data and also how quickly they're doing it. And to the point being made, the technology required to stop it, but it's not necessarily widely understood within the organization. But the crux of the issue for this one is it hasn't got to people that are allocating budgets to understand what technology is required to stop it. And that's the bit that we're seeing consistently within organizations. Coming back to one of the original points that organizations are funding projects around AI to ensure that they're getting the productivity gains. What didn't necessarily go along with that was a clear understanding of what the risks were, what additional technology was going to be required to mitigate those risks, and ultimately allocating budget to ensure that you you've got technology to address those risks. Dean Saunders [00:37:31]: And so the conversation that we're having consistently at the moment is sharing what's required at that layer. In fact, showing some organizations what's happening with a data risk assessment, but then ultimately getting to a commercial conversation around the types of budgets that need to be set to ensure that they've got technology in place to address this. And that's the big bit where we're seeing most organizations grapple with at the moment. KB [00:37:57]: And Dean, final question. What do you sort of think moving forward? What do you sort of sit back at the end of the week and think, this is how the industry's going, where it's headed? Dean Saunders [00:38:06]: Quality question. And I think it's in a couple of parts for me. AI has sort of already delivered and exposed so much as it is right now. You know, when we get to general intelligence and/or superintelligence, What is that going to look like? Where is this actually going? And in that instance, purely framing it from a data perspective, we're sort of reacting and/or we're suggesting technologies and changes for AI as we know it now. What happens when we get to general intelligence and/or that superintelligence and it starts somewhat controlling the environment and/or making suggested changes itself? We're talking about humans not necessarily having enough control or enough discipline around what they're doing with AI now. What happens at the next layer? You know, when AI ultimately takes on not necessarily more responsibility, but it has more ability to have greater influence on both the organization and the technology. That bit concerns me already. And it's like, okay, let's quickly close the gap because we've been sort of left behind with AI adoption compared to data security. Dean Saunders [00:39:13]: We need to quickly close that gap because coming down the line is general and superintelligence, which I think is potentially going to widen that gap again. KB [00:39:22]: That was Dean Saunders, everybody. I'll be reflecting on his point about agents for a while, mostly because it's so simple. We built our security around people who went home at 5, but agents just don't go home. So all the over-access we've let slide for years is now open all night to something that moves a lot faster than any employee ever did. If you're a board director listening to this, next time someone tells you you're compliant, ask them to show you what they've actually done to be secure. VO [00:39:55]: I read every reply. If you've got some thoughts on this one, send me a message on LinkedIn. KBKast, Cyber for The C-suite.

Other Episodes