Innovation in Compliance: Brian Holyfield on Reducing Cybersecurity Blast Radius

Innovation comes in many areas and compliance professionals need to not only be ready for it but embrace it. Join Tom Fox, the Voice of Compliance as he visits with top innovative minds, thinkers and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom visits with Brian Holyfield, Chief Product Officer at SendSafely.

Holyfield discusses about why the right compliance question on cybersecurity is not whether a breach will happen but when and what data will be exposed, often through vendors. Holyfield explains “blast radius” as the scope of access and data reachable during an incident and argues organizations should prioritize architecture, data minimization, and retention controls alongside prevention. Holyfield highlights risks from accumulated file attachments, over-broad user access, interconnected systems using OAuth tokens, and “standing access” via long-lived machine credentials that can be abused without obvious login anomalies. Holyfield discusses the examples involving ServiceNow and Salesforce illustrate platform vulnerabilities, trusted upstream vendor connections, and end-user compromise. Holyfield advises leaders to inventory connections, define retention/archiving, and move sensitive data out of frontline platforms; SendSafely positions itself as an end-to-end encrypted trust layer, including for AI chatbot attachments.

Key Highlights

  • Assume the Breach
  • Blast Radius Explained
  • ServiceNow and Salesforce Lessons
  • Board-Level Questions
  • AI Changes the Game
  • Compliance and Governance Fit

Resources

SendSafely

Brian Holyfield on LinkedIn

 

Innovation in Compliance was recently honored as the Number 4 podcast in Risk Management by 1,000,000 Podcasts

Leave a Reply

Your email address will not be published. Required fields are marked *

What are you looking for?