Innovation in Compliance with Tom Fox podcast

Brian Holyfield on Reducing Cybersecurity Blast Radius

0:00
25:39
15 Sekunden vorwärts
15 Sekunden vorwärts
Innovation comes in many areas, and compliance professionals need to not only be ready for it but also embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom visits with Brian Holyfield, Co-Founder & Chief Product Officer at SendSafely. Holyfield discusses why the right compliance question on cybersecurity is not whether a breach will happen but when and what data will be exposed, often through vendors. He explains “blast radius” as the scope of access and data reachable during an incident and argues organizations should prioritize architecture, data minimization, and retention controls alongside prevention. He also highlights risks from accumulated file attachments, overbroad user access, interconnected systems using OAuth tokens, and “standing access” via long-lived machine credentials that can be abused without obvious login anomalies. Holyfield discusses examples involving ServiceNow and Salesforce that illustrate platform vulnerabilities, trusted upstream vendor connections, and end-user compromise, and advises leaders to inventory connections, define retention/archiving, and move sensitive data out of frontline platforms; SendSafely positions itself as an end-to-end encrypted trust layer, including for AI chatbot attachments. Key highlights: Assume the Breach Blast Radius Explained ServiceNow and Salesforce Lessons Board-Level Questions AI Changes the Game Compliance and Governance Fit Resources: SendSafely Brian Holyfield on LinkedIn Innovation in Compliance was recently honored as the Number 4 podcast in Risk Management by 1,000,000 Podcasts

Weitere Episoden von „Innovation in Compliance with Tom Fox“