Transcript
I'm your host, Rick Vanover, the Rickertron. Today with fresh perspectives to wake up to, I'm joined by Jan de Klerke. Thanks for joining us, Jan. Thank you, Rick, and thank you for inviting me. Tell me a little bit about your role, you know, great partner of Veeam. Tell us and introduce everyone to your role. Well, I work in the services division of HPE, and I've been in the services business for quite a while. I started with this company called Digital, if you remember, a long time ago. So I've been in the industry for about 30 years. I've been doing a lot of customer-facing stuff. I currently, I'm the CT for cyber services, and I'm also leading one of our sub-teams that is focusing on integrated cyber services. So basically making sure that in all the engagements that we do, that security is not an afterthought, that cyber is embedded in everything that we do. I love that because, and we chose these guests, like you and some of the other guests we'll have this season, to really challenge what you think of a brand, and Veeam's going through that as well, and you think HPE. These are some very specialized services that you and your colleagues are representing, and I think that's a really good setup for the topic we're going to have today, really talking about data and stuff to wake up to. So I'm excited for it. Now, we did a little bit of pre-work. You're based in Belgium, but you have a global role, I take it? Yeah, correct. Yeah. We have a multinational team of specialists around the globe, focusing on different facets of security. As you know, security is a very broad area. Yeah, and I'm convinced also that it's one of those things that security never sleeps. Everyone's on the cybersecurity team, and that is something to wake up to. Always new challenges, always new threats. Indeed, indeed. So let's jump into it. So I've got a, I don't want to say a bold claim, but a rather strong assertion, and I want your opinion on it. Challenge me on it. That, you know, an organization, and you and I have plenty of stories. The challenge is that an organization's data may be untrustworthy, and if you could think about everything from cyber resiliency to their AI journey and more, what's your initial reaction to that challenge, that an organization's data may be untrustworthy? I think organizations, most organizations still have a problem with data security overall, and I think it all starts with knowing what your data is, where they are, where they are stored, how they are used. So a lot of organizations still, they don't know where their data is, how it is used. That's a key problem, I think. And then after that, you have, of course, the need for data classification and data labeling, which is, of course, missing as well if you don't know what you have. And I think that will only, that problem will only become more bigger because of the rise of AI. So AI, it consumes a lot of data and generates new data. So I think it will become even more challenging to secure your data and to know what you have. I totally agree with that. And I look at what Veeam's doing in the market, and especially the recent acquisition of security AI, and we're at this really amazing time where our product portfolio is converging and solving some of these problems. But I honestly feel that that problem is real, that you just described. However, the only practical way I think that organizations can really get their minds and their hands around the problem is with the power of AI. And there's going to need to be products, there's going to need to be expertise. And I'm absolutely convinced there's going to be a combination of reactions like, aha, oh, wow, I didn't know that about my data, or maybe, oh, no, we're into some compliance or sensitive data situations that we didn't know about. So I think there's going to be potentially some discomfort. In your experience, when you talk to decision makers, leaders, a board level, CISO level, do they really understand? Do they really have the comfort of some of those risks of their data, their footprint, the quality of it, the security of it? Well, I think there's still a lot of ignorance there, I think, in organizations, or maybe that's a bit of an extreme word. Maybe I should say that they don't have enough oversight of what they have, how it is secured. And I think another key problem, I think, is that a lot of what we see today in security and resilience is C-level people, they often do make a lot of assumptions. So they don't have real evidence to know whether their data security, their data resilience is in good shape. And I think that's pretty important, and it's also a very complex discipline. So data resilience is a very, very complex, tricky thing. I think that's very much in line with research that Veeam has done for many years. I'm in my 16th year here at Veeam. I remember the availability gap, the data resilience gap, and so many other shortcomings of the expectations versus the reality of what's been implemented. Now, this is the Wake Up Podcast. We're not all doom and gloom. The reality is the products, the expertise, the way forward to tackle this is out there in the market. And that's why I want to highlight some of these different perspectives. But when you talk about this gap, and I think it's the best way to explain it, I think one of the ways that it's come about, there's a certain understanding of the business, and the business grows, and the business changes. But do you see a problem where decision makers maybe don't verify completely what they've implemented, or maybe represent certain parts a lot better than others? I don't want to kind of lead the witness, but that's kind of what I see. I'm just curious if that matches what you see. I think it's, when you want to do proper data security, data resilience, it's very important that you look at the whole spectrum in a very complete, holistic way, right? I mean, when you do data resilience, you must make sure that you have controls in place that cover both the technical aspects, technical controls, but also the people, the process aspects. In case you have an incident, it's very important that you have trained, exercised people that know how to run the playbooks that you have prepared before. In the best case, some organizations don't have those playbooks, unfortunately. So you need to make sure that you have beforehand a very well preparation, that you are very well prepared, that you cover the different controls that you need, people, process, technology, and that you always take a risk-centric approach. Risk-centric is, it's not a one-time thing, it's a continuous thing that you, that it's basically part of GRC, right, Governance, Risk, and Compliance Management. So Governance and Compliance Management is not a one-time thing, it's something that you must continuously evolve and maintain to make sure that exactly, for example, in the AI space, or in the AI time that you are living, that you keep pace with the changing threats and the new challenges that come up there. I think you walked right into something that's super important to Veeam. You mentioned people, processes, and technology. Now I'm going to fast-forward, rewind myself back to VeeamON last year. We announced the Data Resilience Maturity Model, which is really an important way that organizations can assess their resilience from a standards-based approach. And we are very closely collaborating there, right? Yeah, exactly. We will have a Cyber Resilience Workshop soon together? Yeah. And I always say at Veeam, partnerships are in our DNA. And whether, you know, HPE, true story, one of the most longest-running integrated primary storage partners actually is the single longest-running integrated primary storage partner. And it's expanded to so many other things now. We're talking hypervisors, industry standard servers, as well as some of the expertise around the cybersecurity practice. So yeah, definitely, the maturity model will align very well there. Now, bringing this topic kind of home, will decision leaders kind of proceed without verifying some of their risk and take that gamble? Do you see that happening? Yeah. Unfortunately, we see that happening. We were involved in a huge recovery a couple of years ago, where we saw a lot of very basic things that were not okay, not in place. Very basic things like firewall rules that were out of date, systems that were unpatched. Also, they didn't have a routine to do regular incident testing, tabletop exercises. So yeah, it's definitely still a problem. The basics will always get you. I talk a lot to organizations about immutability, you know, securing remote access, phish awareness training, doing updates, always, always watch out. It's much more than just having a backup. It's much more tricky than that. So one of the other things that come up, and especially now, we're both on global roles, but I've realized, and you and maybe some of your near line colleagues deal with that a little bit more often, is data sovereignty. And I'm convinced that this is one that some organizations might not give it enough priority. What's your kind of short take on sovereignty? Yeah, I'm from Europe. So in Europe, sovereignty is an incredibly hot topic for the moment, but it's not only in Europe. I think data sovereignty is hot around the globe in the current geopolitical climate we're living in. On the data sovereignty level, I think it's what we often see is that data sovereignty is confused with data locality or knowing where your data is stored. But data sovereignty is much broader than that, much more complex than that. And in fact, sovereignty itself is also much more complex than data sovereignty. You need to look at platform technological sovereignty, operational sovereignty, and data sovereignty is a key part of that. Can you give me an example? Because I really, really love that. I've got my own perspective, but maybe one specific example where locality isn't the complete story. Well, I think there are kind of different tricky aspects related to data locality, right? There can be legal issues. I'm sure you have heard about the U.S. Safe Harbor Act that allows access to data by the U.S. government, data that are hosted by a cloud provider even if it is in a secure country, in a sovereign country. Another problem is remote access. We have a follow-the-clock model in most operational companies where your data may be accessed depending on the time of day by different geos, from different geos. And related to that, there's also an issue with instrumentation data and billing data that often flow back to the mothership, call back to the mothership. So also in that area, I think locality is a pretty tricky thing to enforce, which makes this whole data sovereignty in many cases much more complex than just data locality. I agree 100%. And you walked into that example perfectly, Jan, because organizations have to think end-to-end in the sense of, I talk to a lot of folks that, in the Veeam conversation maybe, they're putting backup data here and so we're really intentional not just about the locality but the encryption and then who has access to it. And I love those other examples of billing, follow-the-clock, global team of admins. Those types of things all matter and are all touch points. Is there any example of a big policy gap that maybe you've had where, when it comes to data sovereignty, the biggest maybe surprise that people have had that they thought they were on a path, but then one very important detail came up and really changed the game? Yeah. Well, I think another thing that makes this data sovereignty a bit more complex is the current application model and cloud model that is used by a lot of applications and services today. So we don't have monolithic applications anymore like we used to have. It's more the Lego model with different blocks, possibly hosted on different platforms in different geos. In some cases, even the owners of the service, the application, they don't know very well that a certain component is provided by a small company in, I don't know, a part of the world, and they don't have insight in all the details there. And that brings me to the importance of third-party risk management, right? So it's very important, and that's where most of the gaps are today. So a lot of organizations, they don't have enough insights in the third parties that they are using or their partners are using, and that's often how risks are introduced and gaps are introduced, and that's often used as a stepping stone then to attack or to compromise some of the corporate data or services. So that leads me to a really important example that I want to share. I speak a lot to customers and partners, likely as you do as well, and there's a word, I've made up a word, sometimes I do that, and those who know me know that, explainability. And I think whether an organization is on an AI journey or on a data sovereignty initiative, having that explainability of what's been implemented, I think, is a massive, positive way to maybe dispel any gaps between the policy and then what's expected from the organization. And the devil is in the detail there, right? It's very important to understand every detail of your application, of the solutions that you're using. For example, last week I was involved in the evaluation of an XDR solution, and the vendor they claimed that they can detect encryption of data. And the way that they do this is basically they check whether there's an external piece of code that is unsigned or is not using a trustworthy certificate, that is trying to access one of the local encryption engines or key generation engines. So based on that, they detect when a ransomware encryption attack would take place. But then how would you handle, for example, if the malware brings its own encryption key? So they cannot detect that. When you're evaluating solutions, it's very important that you look at all the details, that you make sure that you... And that also requires, I think, a deep understanding of the attack kill chain, how they are carried out. I think in many cases you need to adopt a mindset of a hacker to make sure that you can fully understand what's happening and how you need to protect yourself. And that is a wake-up moment for sure. And I totally agree with you there, Jan, because this aligns to what the resiliency aspect of Veeam is bringing to market today. But I think there's a cost, there's a human cost in the details, the sheer volume of information that managers, CISOs, even admins and day-to-day end users have to deal with. There's a massive human cost for this. Do you see bigger risks up the chain of organizational structure, or do you see everyone really absorbing this risk? What's your take on that human cost? Well, I think on the human side, one of the key problems still today is the shortness of expertise and experts. It's hard to find certain technical profiles, certainly when you are looking for very focused and specialized roles. But the good thing is that hopefully, and it's already the case, I think AI will come to the rescue there. So I think AI will, and certainly now in the days of agentic AI, may fill some of those gaps. But again, we shouldn't over-trust AI, right? So we still need to be very confident, we need to double-check and check again. But I'm hopeful that AI will fill some of the gaps there that we have today. I think you're onto something. I'm cautiously optimistic, very optimistic, but also yet cautious at the same time. Two things come to my mind. One is simply the workforce. If you look today, Generation Z is entering the workforce, it's really the first AI-native generation. Yes, it's an incredible set of capabilities that they have at their disposal, but they don't have decades' worth of institutional knowledge. So there's a digital dependency maybe to watch out for, a blind spot or a wake-up moment to be aware of. But the skills gap, the knowledge gap, that is a real thing, and that's a shimmer of hope where AI can help with that. I look at what Veeam's done, everything from Veeam Intelligence, putting it in several of our products to really save some time as well as give contextual information. So that's a good way to really tackle that. I really hadn't thought about AI as one of the solves for the knowledge gap, but it comes up a lot. But then with great power comes great responsibility. And that also brings other problems like shallow AI. Gen Z, they are inclined to use AI very much, but in some cases beyond control of the organization, so that can be tricky as well. Indeed. And I think if we look at the bigger message here with Veeam, the message we're bringing to market now is really around this third generation of risk. You and I both have been in the market for a long time. I grew up preparing for fire, flood, and blood. Then ransomware was the second generation, the cyber resiliency type initiative. And right now, we're on this edge of the agentic era that has risks we don't maybe know fully all how they may be. And again, I think the key thing there is data security. I think primarily data integrity and data confidentiality become more important at the age of AI. Absolutely. So, Jan, I want to really press in a little bit to something about how do you drive change in an organization? So, if you're walking in to a decision maker today, what are some of the questions that you're going to ask that will identify the biggest opportunity to improve, in this case, cyber resiliency and more? I think the key thing that I always fall back to is, again, GRC, right? Does the organization have a permanent GRC office in place or process to manage GRC? Because if you don't have that, then you have a big problem. And again, I already mentioned it. It's very important that you have ongoing risk management, risk assessment, know your risk appetite that may change over time, evaluate the new risks that are introduced with AI. It's also very key that you understand your compliance requirements, which is not easy today either. I mean, the regulatory landscape is incredibly complex. So, if you look at my region, it's crazy like hell to know what applies to your business. And then, yeah, again, this is not a one-time thing. You need to govern it. You need to have a permanent process that assures that you have permanent risk management, permanent compliance management in place for your entire IT stack. I think this is a super important maturation of the process. And I look at my own Veeam journey, and it's an interesting one. I love it. Every day is like my first day. I come in with incredible enthusiasm, but I do have good remembrance of the history. And what really sticks out to me, Jan, is that GRC conversation. Because I'd like to say that some of the buzzwords of the past have actually come true. Take digital transformation, maybe 10, 12 years ago, that's what we were talking about. And we're there. And the logic is that when we have these digital entities that are driving our business, maybe even making decisions on their own, and then further, our business is absolutely depending on it, we can never be too far from these GRC types of requirements. And one of the things I personally like to say, you probably have already figured out I make up my own little, they call them rickisms, these little phrases. One of the things I like to say, and I'm giving this advice to folks who are on the AI journey, real simple, business case first, compliance always. Never forget the business case, and always be aware of the compliance requirements. Real simple rule. And it protects you from so many other things. You can have compliance risks. You could have the cost bottle not aligned to the expectations, which is a real problem if you've already implemented it, because it's too late. But I think those are some really serious questions, and just a mature aspect of the technology for sure that will make the difference. And you don't need to be so hard on Europe about that. The US has its own sets of standards as well. I just found out there's a Colorado AI Act, okay? So we have our own across the world. But I also think you might be walking into something of, let's just say the public sector is catching up with the times in a way. And besides GRC, I think another important thing to mention is I don't forget the basics, right? I mean, in data resilience, cyber resilience, a stupid example, a couple of years ago we had a customer that was over-digitalized, and when the rubber hit the road and they had this big incident, they only had a digital copy of their playbooks and of their SPOCs. So that was a big problem, right? They basically didn't have nothing to get started with the recovery. So make sure that you still have some analog in your environment. I love the basics. In fact, I could write a whole book on the basics, because that truly is one of those things that will be the biggest blocker. And I like to say the only way to learn how to swim is by swimming. You can't read it in a book. And the thought here is only by being comfortable with the uncomfortable, going through those drills, those will be the moments that organizations can really prove that they are able to handle some of the risks in front of them. And I'll be one step further, Jan, a lot of times it's going to happen when the subject matter expert is hiking in the mountains and completely unavailable, because the threat actors know those types of things. These drills and tabletop exercises are critically important, and I think it's better to suffer during an exercise than to suffer when you have a real incident, right? We have customers that have very good habits there. We have other customers that have very bad habits. One of our customers is doing monthly recovery drills, tabletop exercises, which is very good. We still have customers that maybe do them once a year or even worse than that. I can even confirm that that is effort worth doing. In the 2025 Data Resilience Maturity Model, we talked a lot about organizations who are mature in these things are actually, believe it or not, even more profitable and more efficient across the board. This is one of those things that truly the juice is worth the squeeze. So I highly recommend organizations, you know, pressing on in that manner. One more kind of broad question for you, Jan. What about accountability? Anything you can add about how organizations are managing all of these scenarios, all of these details? What about accountability? Well, I think organizations have come a long way on the level of accountability. The only issue with accountability is what happens if you have something that has never been experienced before, unprecedented? Then it becomes kind of tricky to finger point and to know who is exactly accountable. I think sometimes in the data resilience space, it's also very tricky because you have different actors that need to work together. You have the cyber people, you have the data protection officer, the governance people, the legal people. So it's sometimes tricky, very tricky, to come to an exact alignment of this accountability. But the good thing is I think that over the last decade, I think we've come a long way. Most organizations, they have RACI matrixes up to date. But again, it may be tricky when something unprecedented happens, unforeseen. The unprecedented becomes a lot more common, I think, is the real takeaway. Jan, thank you so much for joining us here today. Welcome. That wraps this episode of the Wake Up Podcast, powered by Veeam. Find more episodes at a podcast platform near you and more information at veeam.com.