Transcript
I'm the Vice President of Product Strategy for Really Everything Database Activity Monitoring. Damn. Honestly, compliance doesn't change that often or that frequently, but what does change is the impression or the way people interpret compliance. Take an auditor. An auditor years ago would say, do you know where your private data is? Today, a good auditor would say, I know that you know where your private data is. My question is, is it possible that any of your private data is anywhere you don't expect it to be? Legacy DAM technologies tend to create islands without bringing everything together into one platform. The alternative is as an organization, you're using one, two, three or more technologies to solve what really should be a simple problem. And that's identifying who is accessing the data, where you have sensitive data, and who has access to it. It should be really easy to do across all your data. And the reality is, is one platform gives you the ability to do that in one place. The alternative is it's many places, many products and many gaps. Regulations, like I mentioned earlier, don't change too much. 10 years ago, we didn't have GDPR. Today, we do have GDPR. And that really made a massive change to the industry. So typically, regulations all tend to ask about the same question. So bringing automation into all of that is important because it means that I can use one piece of automation and answer the same question, even if that question is posed just a little bit differently. They tend to all be copies of each other in most cases. The thing that worries me most about the way organizations are leveraging AI right now is the AI itself doesn't have the appropriate guardrails in many cases. So many organizations still lack basic, fundamental visibility into any user going into the database. If there are no controls around Terry, Ann, and John accessing a database, what makes an organization think there are going to be controls about the AI that they're giving that same access to? AI knows everywhere that you have access to and will access all of it. To me, the crazy ones are the ones you don't really think about. There's a public story about a judicial system in a particular country in the Caribbean. They recognized that they had privileged users, DBAs, that were changing one number in a database. And they were getting paid a quarter of a million dollars to change one number in a database. That number was the prison sentence years that prisoners were expected to serve in prison. Stealing a million records, people can see that really well. But if you're not watching someone who's fully authorized to make a change and be able to identify that that's not normal, that's a crazy attack. I don't call those really cyber attacks, but those happen far more frequently where people violate the trust that they have with an organization and use the data that is private for their own personal gain. The reality is, is there is no CISO that has an army of data security experts. Automation is that ability for a CISO to acknowledge, I don't have the expertise or the people to do this well. Technology can help me do it. And this is what technology has been about for years, about simplifying something that you can't do or that you can't do easily. And that's what automation is. That's what automation is.