Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

CISO Insights: Data Protection and Cyber Resilience

Varonis
09/29/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Yeah, because it will happen. It's not a matter of if, it's a matter of when. And so you just want to make sure that when it does happen, like you said, you've kind of minimized the blast radius, you've locked down everything that you can so that the impact is a lot less significant. Right, and you can recover faster. Yes, exactly. Welcome to Speed Data, quick conversations with cybersecurity leaders. I'm your host, Megan Garzep. My guest today is John Barrow, Chief Information Security Officer for J.B. Poindexter & Co. Thanks for joining me today, John. Sure, I'm glad to be here. John oversees security for the leading motor vehicle manufacturing group, ensuring the cybersecurity program runs like a well-oiled machine. Before joining J.B. Poindexter & Co., John led security teams at Texas Children's Hospital and Caesars Entertainment Corporation and was an intelligence analyst for the United States Army and NSA. In his free time, he somehow learned to speak Portuguese and he has his CISSP and BS in business and IT management. That's quite an impressive resume you've got there, John. What made you want to get into cybersecurity? Well, it was a natural transition from the intelligence community to cybersecurity. Same mindset, just different focus. Yeah. And so it's kind of happened naturally, like organically. Yeah. And what's your favorite aspect of cybersecurity? I would say my favorite aspect is the people. Working with people, communicating, making sure that we're aligned with their business objectives. I think a lot of times in IT and cyber, the focus is always technology. But you can't be successful in any cyber program unless you focus on the people, right? Yeah. So that's your most valuable asset is the people. Yeah. What do you think most organizations misunderstand when it comes to cloud security? What they misunderstand is they assume that the cloud provider provides all the security. Mm-hmm. But there's still – it's a shared responsibility, right? Yes. Like the organization still has to protect their assets and the data and all their applications within that cloud environment. Yeah. I think that shared responsibility model seems to confuse a lot of folks, unfortunately. But you do have your own responsibilities. And what do you think is the number one rule for data loss prevention? You need to work with the business. You need to make sure you minimize the operational impact when you're implementing DLP. I think that's where a lot of people are starting to not shy away but not focus so much on DLP because it's so hard to implement because they try to force it. They don't work with the business. They don't make sure they do proper testing and kind of do it methodically to minimize that operational impact. Yeah. And what type of data breaches or exploits keep you up at night? Like what are you worried about the most? Ransomware, obviously. But any time our business users are sharing sensitive data externally, things like that, that puts me up at night. Yeah. We do have protections in place for that and controls, but I know it's still happening, right? Yeah. So we're trying to minimize that and it's just training and education. Yeah, because a lot of times they'll share it externally or unintentionally. Right. And sometimes it's required as part of their business processes. So just ensuring that it's protected, it's encrypted in transit and things like that. Right. And what do you predict to be the biggest shift in cybersecurity? I think the biggest shift will be from having a cyber prevention mindset to cyber resilience because forever and ever everyone's been focused on preventing an attack. Yeah. Which is important, but it's going to happen. It's going to happen, yes. So I think cyber leaders and programs and organizations, they're going to need to really double down on their resilience. Yes. And I think it's going to be a shift even in investments and budget where it's going to be maybe 50-50 on prevention and resilience. Yeah. But I think that's going to be a huge focus. I mean, every day you read in the news another company has been compromised or whatever. I mean, I know that's what we've been focused on at my organization. Yeah. I mean, we did have an attack, and luckily we had made those investments in resilience for when it would happen rather than just hoping it doesn't happen. Yeah. Yeah, because it will happen. It's not a matter of if. It's a matter of when. And so you just want to make sure that when it does happen, like you said, you've kind of minimized the blast radius. You've locked down everything that you can so that the impact is a lot less significant. Right, and you can recover faster. Yes, exactly. And how do you think the threat landscape has changed since you began your career? It's actually much faster now. For a long time, I think the mean dwell time was like 15 days or months or sometimes even years where they would just sit persistent in your environment and wait for the perfect time to actually enable or execute whatever malware. But now with AI and everything else, that dwell time is a lot less where in personal experience with the tech we had, the second they got in our environment, they were already moving laterally. They were already trying to go to their objective. So it's immediate. So the speed. Yeah, AI has been such a game changer. Right. For both good and bad, really. Right, right. And you and I, you know, we've kind of chatted a little bit about our passions and your passion for running and my reluctance to do so. But if you weren't in cybersecurity, what would you be doing? I would probably be playing music, actually. Oh, yeah, because you said you're a drummer. I play drums and sing, and my dad was a musician in Nashville and all that. Oh, wow. So I'd probably be playing music. That's another one of my passions, yeah. Yeah. What kind of music do you play? Everything more rock and roll, but I've played country and hip-hop and funk. Hip-hop. Yeah. Wow. I did a world tour when I was in the military, actually, for six months where we toured the world playing in a top 40 band. I like to play everything, but rock's kind of my default. But I do love the rock, yeah. Yeah, yeah. Well, thank you so much for joining me today, John. I've loved chatting with you. And for our audience, if you would like to be a guest on Speed Data, please visit varonis.com slash speed hyphen data. Thank you, John. Thank you. Thank you.

TL;DR

  • Cloud security operates on a shared responsibility model—organizations must protect their own data and applications even when using cloud providers.
  • Successful DLP implementation requires close collaboration with business units and methodical testing to minimize operational disruption.
  • The cybersecurity industry is shifting from prevention-focused to resilience-focused, with budget allocations moving toward 50-50 splits between the two.
  • AI has dramatically accelerated attack timelines, reducing dwell time from months to immediate lateral movement upon initial compromise.

Summary

In this Speed Data episode, John Barrow, CISO of JB Poindexter & Co., shares practical perspectives on building effective cybersecurity programs in manufacturing environments. Drawing from his experience across healthcare, gaming, and military intelligence, Barrow emphasizes that successful security programs prioritize people over technology, working collaboratively with business units rather than forcing compliance. He addresses common misconceptions about cloud security, particularly the shared responsibility model that many organizations fail to fully understand. The conversation explores data loss prevention implementation challenges, the importance of minimizing operational impact through methodical testing, and why the industry is shifting from a prevention-focused mindset to cyber resilience. Barrow candidly discusses his organization's experience with an attack, noting that prior investments in resilience capabilities proved critical for rapid recovery. He also highlights how AI has dramatically accelerated the threat landscape, reducing attacker dwell time from months to immediate lateral movement upon initial compromise.

Chapters

0:00 - Cyber Resilience Teaser
0:31 - Guest Introduction
1:17 - Career Path and People Focus
1:55 - Cloud Security Misconceptions
2:20 - Data Loss Prevention Rules
2:48 - Ransomware and Data Sharing Risks
3:27 - Shift to Cyber Resilience
4:38 - Evolving Threat Landscape
5:22 - Personal Interests

Key Quotes

1:45 "You can't be successful in any cyber program unless you focus on the people."
2:03 "What they misunderstand is they assume that the cloud provider provides all the security."
3:36 "I think the biggest shift will be from having a cyber prevention mindset to cyber resilience."

FAQ

Why do organizations struggle with data loss prevention implementation?

According to Barrow, DLP implementations often fail because security teams try to force solutions without working collaboratively with business units. Successful DLP requires proper testing, a methodical approach, and minimizing operational impact on day-to-day business processes.

What is the shared responsibility model in cloud security?

The shared responsibility model means that while cloud providers secure their infrastructure, organizations remain responsible for protecting their own assets, data, and applications within the cloud environment. Many organizations mistakenly assume the cloud provider handles all security.


Categories:
  • » Webinar Library » Varonis
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Data Security
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Cloud Security
  • Security Operations
  • Executive Briefing
  • Interview
  • Cyber resilience
  • Shared responsibility model
  • Data loss prevention
  • Cloud security
  • Ransomware
  • People-first security
  • Threat landscape evolution
  • AI in cybersecurity
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: CISO Insights: Data Protection and Cyber Resilience

              Industry Events (Sponsor Hosted)

              • Oct
                01

                Meta Muse 101: Embracing the Arrival of the Agentic Internet. What's Next?

                10/01/202601:00 PM ET
                • Oct
                  13

                  Interactive Q&A Session on DatasecAI 2026 Insights and Innovations

                  10/13/202602:00 PM ET
                  • Oct
                    15

                    Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                    10/15/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: A Comprehensive Approach to Visibility and Control
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-a-comprehensive-approach-to-visibility-and-control/
                    • 10/01/2026
                      01:00 PM
                      10/01/2026
                      Meta Muse 101: Embracing the Arrival of the Agentic Internet. What's Next?
                      https://www.truthinit.com/index.php/channel/2144/meta-muse-101-embracing-the-arrival-of-the-agentic-internet-whats-next/
                    • 10/13/2026
                      02:00 PM
                      10/13/2026
                      Interactive Q&A Session on DatasecAI 2026 Insights and Innovations
                      https://www.truthinit.com/index.php/channel/2141/interactive-q-a-session-on-datasecai-2026-insights-and-innovations/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version