Categories
Compliance and AI

Compliance and AI: SendSafely’s Brian Holyfield on Shrinking the Blast Radius

What is the intersection of AI and compliance? What about Machine Learning? Are you using ChatGPT? These questions are just three of the many we will explore in this cutting-edge podcast series, Compliance and AI, hosted by Tom Fox, the award-winning Voice of Compliance. In this episode, host Tom Fox visits Brian Holyfield, Co-Founder & Chief Product Officer at SendSafely.

Holyfield’s background in ethical hacking and real-world security testing shapes his practical view of cybersecurity. He believes compliance should reflect how breaches actually happen, especially through vendors and service providers, which means organizations must look beyond their own perimeter. For him, data minimization and retention controls are essential: companies should keep only the data they truly need, delete unnecessary copies, and limit where sensitive information lives. Holyfield also stresses reducing the blast radius, arguing that the best defense is to assume a breach will occur and design systems so attackers can access as little data as possible for as short a time as possible.

Key highlights:

  • Preventive AI governance through data minimization
  • Deliberate configuration choices that shrink breach blast radius
  • Aging Out Data Into Secure Backend Archives
  • Native end-to-end encrypted storage for regulated attachments
  • Trust Layer for End-to-End Encrypted Regulated Data

Resources:

SendSafely

Brian Holyfield on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
AI Today in 5

AI Today in 5: April 30, 2026, The Last Mile Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. AI drives demand for cybersecurity compliance. (Security Brief)
  2. The last mile problem in AI security. (FinTech Global)
  3. AI redefining AML. (AML Intelligence)
  4. AI driving compliance from static to living. (The National Law Review)
  5. EU AI Act reform stalling. (IAPP)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Compliance Into the Weeds

Compliance into the Weeds: Failure to Have Effective Compliance Program

The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the recent DOJ enforcement action involving Verizon Business Network Services for failure to have an effective cyber security compliance program.

The recent case of Verizon’s non-compliance with cybersecurity standards and subsequent remediation efforts has sparked a significant conversation in the realm of cyber compliance. Tom views this case as a roadmap for companies to enhance their cybersecurity programs, emphasizing the importance of gap analysis and pressure testing. He draws parallels between cybersecurity compliance and the Foreign Corrupt Practices Act (FCPA) compliance, suggesting that Verizon’s case could serve as an example for other companies.

Matt applauds Verizon’s voluntary self-disclosure and extensive remediation efforts. He underscores the importance of disclosure, cooperation, and remediation in both cybersecurity and corruption cases, viewing Verizon’s actions as a positive example for other companies. Join Tom Fox and Matt Kelly as they delve deeper into this topic in the latest episode of the Compliance into the Weeds podcast. 

Key Highlights

·      Verizon’s Cybersecurity Program Failures

·      Enhancing Cybersecurity Compliance through Remediation Measures

·      Automating Compliance Efforts with GRC Tools

·      Potential Penalties for Non-Disclosure of Cybersecurity Issues

 Resources

Matt in LinkedIn

Matt on Radical Compliance

Tom 

Instagram

Facebook

YouTube

Twitter

LinkedIn