Episode

Busting DLP Myths - Justin Bortnick - Ep 164

Podcast
Tech Interviews
Published
Nov 17, 2021
Duration seconds
2285
Processing state
processed
Canonical source
https://soundcloud.com/techstringy-580399274/busting-dlp-myths-justin-bortnick-ep-164
Audio
http://www.podtrac.com/pts/redirect.mp3/feeds.soundcloud.com/stream/1160468749-techstringy-580399274-busting-dlp-myths-justin-bortnick-ep-164.mp3
JSON
/v1/public/podcasts/tech-interviews/episodes/busting-dlp-myths-justin-bortnick-ep-164
Markdown
/podcast/tech-interviews/busting-dlp-myths-justin-bortnick-ep-164.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/tech-interviews/episodes/busting-dlp-myths-justin-bortnick-ep-164/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/tech-interviews/busting-dlp-myths-justin-bortnick-ep-164.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Data loss prevention is often misunderstood as a mere compliance checklist rather than a core security necessity. This episode explores how to move beyond reactive breach responses by implementing a governance-first strategy.

Topics

  • Data Loss Prevention
  • Data Security
  • Enterprise Governance
  • Cybersecurity Strategy
  • Data Privacy
  • Incident Response
  • Information Protection
  • Compliance

Highlights

  • Main idea: Compliance and security are not synonymous; checking regulatory boxes does not guarantee protection against breaches
  • Practical takeaway: Adopt a 'crawl, walk, run' methodology to identify data locations before attempting complex enforcement
  • Failure mode: Implementing DLP tools without an internal governance process leads to unmanageable incident volumes
  • Main idea: Effective DLP requires maintaining a chain of custody and context, even for encrypted or unstructured data
  • Practical takeaway: Focus on cultural change and employee education to make data protection a shared organizational responsibility

Chapters

  1. 1:00 Introduction to DLP Myths: An introduction to Justin Bortnick and the goal of correcting common misconceptions in data loss prevention.
  2. 3:50 The Drivers of Data Security: Distinguishing between compliance-driven security and the reality of reactive security following a breach.
  3. 6:50 The Importance of Context: Why understanding the metadata and identifiers of data is critical for accurate monitoring.
  4. 9:30 Data Discovery Challenges: Addressing the difficulty of locating all enterprise data and how to prioritize known data sets.
  5. 12:30 Chain of Custody and Encryption: How to maintain visibility and tracking even when dealing with encrypted files.
  6. 15:10 The Crawl, Walk, Run Approach: Implementing an informed strategy by collecting data incrementally rather than relying on guesswork.
  7. 18:00 The Necessity of Governance: Why a technical solution fails without a defined governance program to handle security incidents.