Data Security Decoded provides actionable, vendor-agnostic insights to reduce data security risk and improve resilience outcomes. Designed for cybersecurity and IT professionals who want practical insights on preparing for attacks before they happen, so they can respond effectively when they inevitably do. Episodes feature insights from researchers, crafters of public policy, and senior cybersecurity leaders, to help organizations reduce risk and improve resilience. Data Security Decoded provides practical advice, proven strategies, and in-depth discussions on the latest trends and challenges in data security, helping listeners strengthen their organizations' defenses and recovery plans.
Building Automation Frameworks and Tackling Cloud Archiving with Fred Lhoest
This episode delivers operational insights from the frontlines of global telecommunications, drawing on Fred Lhoest's experience managing IT infrastructure across 60 countries at PCCW Global. The discussion begins with the realities of consolidating an environment that previously relied on more than 10 disparate backup tools into a single, unified data protection platform. Fred details his journey as a self-described automation junkie, explaining how he developed an open-source PHP and GraphQL framework to query APIs, detect unprotected virtual machines, and streamline automated recovery tasks.
The conversation transitions into the operational boundaries of automation and cyber resilience. Fred warns against unvetted, fully autonomous failover triggers, emphasizing that false positives can lead to catastrophic outages if fallback systems are out of sync. He advocates for a human-in-the-loop validation model to maintain control over critical infrastructure decisions.
Looking toward future infrastructure shifts, Fred examines the risks of migrating complex systems to hybrid cloud environments. He highlights the necessity of strict data residency compliance across global jurisdictions, including the European Union and the United States. Finally, Fred raises a critical warning regarding long-term digital archiving. He challenges the industry to solve the file format and hypervisor obsolescence trap, where compliance regulations require holding data for 30 years, but modern software renders the underlying files unreadable.
What You'll Learn
Strategies for consolidating fragmented backup tools into a single management interface.
Methods for leveraging GraphQL APIs to build custom security automation frameworks.
Risks of false positive automated failovers and human in the loop requirements.
Key data residency considerations for migrating workloads across international jurisdictions.
Practical guardrails for controlling employee and developer interaction with AI models.
Uncovering software obsolescence risks hidden inside long term digital data archives.
Why continuous recovery testing is essential to validating enterprise incident response plans.
21 Jul 2026
Securing Research Infrastructure and Managing Shadow AI with Kevin Mortimer
This episode explores the technical hurdles of protecting academic research environments and navigating the shift to automated cloud architectures, drawing on Kevin Mortimer's twenty five years of technical leadership experience. The dialogue focuses on how higher education institutions face escalating threat profiles, moving from initial denial of service events to targeted supply chain compromises aimed at extracting student records. Kevin details how his team rapidly deployed mandatory multi factor authentication overnight and altered storage topologies by isolating valuable research data inside protected cloud vaults.
The discussion pivots to the operational reality of managing generative artificial intelligence across distributed campus networks. Kevin breaks down the friction between supporting early stage vibe coding for rapid proof of concept deployment and preventing shadow AI data exposure. He highlights the engineering required to build agent to agent communication platforms where firewall alerts automatically interface with backup systems to trigger live mounts and dynamic network segmentation.
In addition to addressing autonomous agent architectures, Kevin challenges the prevalence of vendor AI washing, emphasizing the need for technical leaders to scrutinize underlying mathematical models and prepare for shifting OpEx financial models driven by tokenization.
What You'll Learn
Core strategies for securing academic research data within isolated cloud topologies.
Methodologies for implementing emergency multi factor authentication policies across large user bases.
Identifying supply chain vulnerabilities in third party student data record providers.
Engineering autonomous agent to agent communication models between firewalls and recovery platforms.
Frameworks for governing shadow AI usage and evaluating Model Context Protocol platforms.
Utilizing vibe coding techniques for rapid scaffolding and proof of concept application development.
Evaluating vendor transparency regarding underlying mathematical models to eliminate artificial intelligence washing.
14 Jul 2026
Shifting Security and Protecting the Pharma Supply Chain with Andy Hillis
This episode provides a technical exploration of security engineering within highly scrutinized life sciences environments, drawing on Andy Hillis' decades of operational history at The Almac Group. The discussion centers on the practical realities of shifting security left. Andy explains how his organization integrated rigorous info security reviews directly into the initial request for information and request for proposal stages, effectively establishing an unyielding baseline of evidence for third party vendors.
Listeners will gain access to battlefield stories regarding the navigation of sudden structural oversight from global regulatory bodies, including the FDA, EMA, and the post Brexit MHRA. The narrative moves past high level compliance abstractions to focus on the technical enforcement of GXP principles, least privilege role based access control, and centralized configuration change management across distributed international networks.
Andy challenges conventional industry perspectives on cloud adoption and rapid automation, outlining a calculated, use case driven approach to infrastructure management. The conversation covers critical recovery metrics, defining the architecture required to build a provable, immutable backup position capable of supporting a minimum viable company operational state during an incident. Finally, the dialogue addresses the integration of automated security operations centers and the governance frameworks needed to control decentralized citizen development.
What You'll Learn
Core methodologies for integrating security teams into early procurement and RFI cycles.
Operational frameworks required to support over 200 diverse compliance audits annually.
Tactical application of GXP guidelines to digital data retention workflows.
Engineering immutable backup states to secure a minimum viable company position.
Governance mechanisms for regulating generative AI and managing rogue asset development.
Automated SOC implementation techniques designed to suppress alert noise effectively.
Value of network discovery tools in mapping complex assets internationally.
Host of Data Security Decoded?
Claim your podcast to manage its listing and keep your show details accurate.
Pod Engine is an independent podcast discovery and analytics service and is not affiliated with or endorsed by this podcast. Artwork and show content belong to their owners. Full legal notice.