Episode
Busting DLP Myths - Justin Bortnick - Ep 164
- Podcast
- Tech Interviews
- Published
- Nov 17, 2021
- Duration seconds
- 2285
- Processing state
processed
Actions
POST https://stenobird.com/v1/public/podcasts/tech-interviews/episodes/busting-dlp-myths-justin-bortnick-ep-164/transcription-requests
Idempotently request low-priority transcript generation for this episode.GET https://stenobird.com/podcast/tech-interviews/busting-dlp-myths-justin-bortnick-ep-164.md
Read the agent-friendly Markdown representation of this episode resource.
Summary
Data loss prevention is often misunderstood as a mere compliance checklist rather than a core security necessity. This episode explores how to move beyond reactive breach responses by implementing a governance-first strategy.
Topics
- Data Loss Prevention
- Data Security
- Enterprise Governance
- Cybersecurity Strategy
- Data Privacy
- Incident Response
- Information Protection
- Compliance
Highlights
- Main idea: Compliance and security are not synonymous; checking regulatory boxes does not guarantee protection against breaches
- Practical takeaway: Adopt a 'crawl, walk, run' methodology to identify data locations before attempting complex enforcement
- Failure mode: Implementing DLP tools without an internal governance process leads to unmanageable incident volumes
- Main idea: Effective DLP requires maintaining a chain of custody and context, even for encrypted or unstructured data
- Practical takeaway: Focus on cultural change and employee education to make data protection a shared organizational responsibility
Chapters
1:00Introduction to DLP Myths: An introduction to Justin Bortnick and the goal of correcting common misconceptions in data loss prevention.3:50The Drivers of Data Security: Distinguishing between compliance-driven security and the reality of reactive security following a breach.6:50The Importance of Context: Why understanding the metadata and identifiers of data is critical for accurate monitoring.9:30Data Discovery Challenges: Addressing the difficulty of locating all enterprise data and how to prioritize known data sets.12:30Chain of Custody and Encryption: How to maintain visibility and tracking even when dealing with encrypted files.15:10The Crawl, Walk, Run Approach: Implementing an informed strategy by collecting data incrementally rather than relying on guesswork.18:00The Necessity of Governance: Why a technical solution fails without a defined governance program to handle security incidents.