Categories
Compliance and AI

Compliance and AI: SendSafely’s Brian Holyfield on Shrinking the Blast Radius

What is the intersection of AI and compliance? What about Machine Learning? Are you using ChatGPT? These questions are just three of the many we will explore in this cutting-edge podcast series, Compliance and AI, hosted by Tom Fox, the award-winning Voice of Compliance. In this episode, host Tom Fox visits Brian Holyfield, Co-Founder & Chief Product Officer at SendSafely.

Holyfield’s background in ethical hacking and real-world security testing shapes his practical view of cybersecurity. He believes compliance should reflect how breaches actually happen, especially through vendors and service providers, which means organizations must look beyond their own perimeter. For him, data minimization and retention controls are essential: companies should keep only the data they truly need, delete unnecessary copies, and limit where sensitive information lives. Holyfield also stresses reducing the blast radius, arguing that the best defense is to assume a breach will occur and design systems so attackers can access as little data as possible for as short a time as possible.

Key highlights:

  • Preventive AI governance through data minimization
  • Deliberate configuration choices that shrink breach blast radius
  • Aging Out Data Into Secure Backend Archives
  • Native end-to-end encrypted storage for regulated attachments
  • Trust Layer for End-to-End Encrypted Regulated Data

Resources:

SendSafely

Brian Holyfield on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Innovation in Compliance

Innovation in Compliance: Brian Holyfield on Reducing Cybersecurity Blast Radius

Innovation comes in many areas, and compliance professionals need to not only be ready for it but also embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom visits with Brian Holyfield, Co-Founder & Chief Product Officer at SendSafely.

Holyfield discusses why the right compliance question on cybersecurity is not whether a breach will happen but when and what data will be exposed, often through vendors. He explains “blast radius” as the scope of access and data reachable during an incident and argues organizations should prioritize architecture, data minimization, and retention controls alongside prevention. He also highlights risks from accumulated file attachments, overbroad user access, interconnected systems using OAuth tokens, and “standing access” via long-lived machine credentials that can be abused without obvious login anomalies. Holyfield discusses examples involving ServiceNow and Salesforce that illustrate platform vulnerabilities, trusted upstream vendor connections, and end-user compromise, and advises leaders to inventory connections, define retention/archiving, and move sensitive data out of frontline platforms; SendSafely positions itself as an end-to-end encrypted trust layer, including for AI chatbot attachments.

Key highlights:

  • Assume the Breach
  • Blast Radius Explained
  • ServiceNow and Salesforce Lessons
  • Board-Level Questions
  • AI Changes the Game
  • Compliance and Governance Fit

Resources:

SendSafely

Brian Holyfield on LinkedIn

Innovation in Compliance was recently honored as the Number 4 podcast in Risk Management by 1,000,000 Podcasts