Cribl’s Nick Heudecker on LLM and Data Security

Written By
James Maguire
James Maguire
Jan 16, 2025
1 minute read

Transcription

hi I'm James Maguire and on today's video we're talking about cyber security Trends here in early 2025 we'll take a look at issues like large language model security data harvesting employee education and we'll also offer advice on how to handle the this year's biggest cyber challenges to discuss that I'm joined by Nick Hugh Decker senior director Market strategy and competitive intelligence at cribble Nick very good to have you with us today thanks for having me James appreciate being here so cribble may not be as known as as some players yet I know we're in the process of changing that but before we get to our questions today tell us a little bit about cribble what exactly does cribble do yeah cribble has been around since about 2017 2018 um and we are specifically Building Solutions for I security folks to better manage and deal with the onslaught of data that they have to cope with uh whether that's feeding data into uh a Sim product or an APM giving them more control over what shape that data takes what format it's in how it might get enriched or redacted or reduced before it lands there that's really our mission giving people better uh choice and control over those data over that data set yeah there there's a need for that no doubt about it um all right so let's talk about some key cyber security Trends obviously there's a lot going on early in this year uh large language model security that's a that's a key one and it's a lot going on in terms of you know an employee might put a piece of confidential information into the model there's bias you know we don't know who built the model perhaps so so what are some of the large language model security issues well so purple's got its own uh co-pilot uh that it has as part of its overall product suite and you know some of the questions that our customers actually ask us about you know how do you use llms what security concerns they have it's really who provides that foundational model right so where are you actually going to get that llm from that helps to shape some of the security questions you may want to ask next um what are your policies around data retention right so how long is that you know model provider going to be using your data or how long might we retain that data um and then what kind of data are you actually collecting right so those are some of the the high level questions that we always see on you know rfps or security questionnaires things like that and I think that as companies start to adopt more llms I think most of them will be coming from service providers right service now is a great example here you know they'll want to be asking those questions of those service providers to ensure that they're not you experiencing pii leakage or or other things like that and understanding how that data is going to be used beyond the context of their own consumption of an llm do you think companies when they they look at the idea of an llm they should think to themselves oh goodness security alert I mean is it is it rif with security issues or not necessarily I I would say it's it's not more rif with security issues than anything else right which is the upside because then you can use the same policies that you have used before to ensure that you're securing an llm right and that might be like um partiz inputs where you can only say all right well you only get to access this one piece of information that I want you to use for generating a response uh data govern right I'm I'm a data management person right I'm I I view the world as like it's either a data management issue or an integration issue are you to remind people you were a gardner analyst in that area correct yeah so I covered uh data management uh bi analytics a number of those kind of data topics around around dat analytics um and so that's still very much my background and and so when I look at the world it's like well that that's your issue um the things that people should be doing around data as far as metadata lineage all of you know Access Control governance all of that blocking and tackling while it's not super sexy you have to do those things if you want to be successful and secure with llms right it's just another algorithm it really depends on how you treat your data and how you teach your employees to use that data that's really going to make the difference over time right what about the issue of data harvesting sometimes I think our entire world is just one constant data Harvest we don't know who's harvesting their data and why and what they're doing with it what what are the issues there well the issue exactly what you said right how is that data going to be used where does it go beyond the first party collector I get an email or not an email I I I will get physical mail about once a month once a quarter saying oh we experienced the data breach we're going to buy you you know identity theft protection for the next year I have no idea who that company is right right yeah somehow they ended up with my data uh either VI you know from uh from Health Care insurance or something else right so it's often not even like the direct first-party data collectors it's everywhere else that it goes you know you don't know how that's going to be used how they're going to secure it or in the case of the people that send meem mail not secure it there's a lot there's a lot of issues there um and this is something that you know our customers you know while they're not dealing with data harvesting per se they're very concerned about you know things like gdpr and other data privacy rules and regulations so you know everybody ends up with some kind of data and it's how you going to deal with that on the back end how are you going to ensure that it's anonymized and so on I think one of the advantages of of llm is going back to the earlier topic is people are now really using a lot of synthetic data right to train these models because real world data is messy and you know has varying quality characteristics and could have bias part of it so while that the data harvesting is still definitely happening um I think you're seeing a lot of different diverse types of data being used in the AI llm space also what about the issue of educating employees by cyber security because I always think about the human element as the really really weak element in security what should people know about this well I mean you you've got to you got to put yourself in the employees shoes right you know we're all dealing with like a lot of cyber security expectations right don't click on this link ensure it's not a fishing attempt and so on and I still have work to do right I I've got you know policies that I I need to follow but I still have to do things immediately so I'm looking for convenience sure um what policies are still really going to be relevant and I think you know that's one reality that cesos need to come to terms with the other is that if I break a security policy who cares right I'm not going to suffer you know I'm not going to be accountable for that so it's not really something I have to be terribly concerned about right I may click on a fishing link and I have to go through a training program but after that it's forgotten so I'm not really accountable that's something else people need to think about when they're building out these programs you're saying the the employees themselves are not accountable is that what you mean that's correct yeah okay yeah um and the last is you know sometimes it's okay to violate policies but when and so I think you know you need to make it much more relevant you know when you're training uh employees on cyber security for their jobs you have to kind of put you know ensure that they're understanding the kind of data they're dealing with like if this is your data how would you want it managed you know you have to teach your your employees to be a little more empathetic maybe but at the same time you have to also get rid of all the useless policies that are just noise right and so ensure you know you're only following maybe the 25 30% that are actually relevant for your business don't just create policy to create policy right uh and then last time you know the last thing is you know ensure that one employees are being held accountable I don't know what that looks like depending on a given organization or industry um and then lastly you know when you've got company or you got employees that are trained up they should have some leeway to decide you know what for expediency uh whether it's my own work or for the business when can I violate these policies and how far can I go is it something you should do day obviously not but this you know kind of All or Nothing when there's no accountability it's hard to get Buy in from the employees under all those circumstances does that make sense yeah well it does fact makes a lot of sense it's very real world is what I would say it's beyond making sense I think but the question I would raise about it is I've never known a company that said it's it's okay to violate the rules sometimes based on even though we know in the real world it has to be that way but the the companies don't tend to IGN a knowledge that fact uh they don't but look we live in a real world you know it's not you know we're not automatons we're not llms you know even though they have varying results um you've got to make security more practical if you expect your employees to follow those policies right you can't just throw out a bunch of policies and agents on your machines and so on and just expect that everything's going to go well you you need to develop empathy you need to create accountability and also know when hey you just got to get work done right right all right so let's let's move on to what might be referred to is the advice portion of our talk if the what's the advice in terms of when executives are grappling with this year's risk what what should they prioritize how do how do they do it in other words well it's a tough question to answer because every industry is going through different types of risk right what I I think it it's really difficult to give hard and fast advice right now right we've got a new administ ation coming in there's questions about the Chevron Doctrine right the organ the the entities like the SEC and the FTC and and others can they actually enforce the regulations that they create anymore so we've got to you know you've got to build for a certain amount of resiliency and also flexibility you know when I'm talking with cesos and cios I'm really trying to advise them like look you got to modernize how you're dealing with all of this data right Telemetry data right the ex exhaust that comes out of business processes is 20 to 30 times more voluminous than the business process data itself how do you manage all that right do you need to put all that data in one place do you tiar it based on cost and value so you know trying to think about like how do I you know what advice am I sharing it's really rethinking you know in a in an environment with a lot of uncertainty coming how do you better manage your data so that you can react to that faster M so build with you know data tearing in mind around cost and value and then keep your options open as long as possible uh you know using abstraction layers between you where data is coming from and where it's Landing um and that message has has resonated really well it seems like part of it would be the the compliance question like how how hard do you do you lean on the compliance piece I mean is that Absol we talked about this I real so it's if you make it absolute I mean what what what is the compliance piece of this issue you cannot budge on compliance like you have to keep that data you know it might be for three years or seven years so you need to have a copy of all of that data available does it need to be in the hottest tier of storage no it doesn't um some of our customers are keeping all that data on Prem they're just rolling storage array networks into the data center there's a better way to do that right you can put that data in the cloud encrypt it leave it in a place where you can still get hot access to it and still query that data for compliance purposes so you don't always have to take kind of the Legacy approach but you still have to comply right whether you know you're in Insurance Health Care Finance right you still have to deal with that data and manage it appropriately all right last question what do you see is is the near to midterm future of cyber security is AI plays an Ever greater role and it feels like kind of a wild card because we don't really know how AI is going to shake out it's evolving even as we speak so what it's going to be 9 months from now is not what it is going to be now so it's hard to make blanket statements but still yeah cyber security in in the face of AI I think you're going to see AI get used in cyber security as a force multiplier right it's going to help triage alerts it's going to help um elevate your kind of level one analyst to you know a level two maybe level three analyst you should look to AI to remove some of the drudgery from the job right AI or sorry cybercity is a very high stress job right so if there's anything that you can do to lower that stress retain staff uh lean into those opportunities also keep in mind that a lot of AI efforts today are not you know formally funded by it right that that's coming out of an innovation budget so as you kind of promote them from The Innovation budget to it make sure the controls are in place but I think that you know you're going to see much more use of AI in cyber security but to your point it's early right people ask you know what inning are we in in AI we're still in batting practice right true we're really just getting started um and so you know measure your investment right and and analyze it are we getting the results we expect if not maybe back off a little bit revisit it in 12 months six months depending on on what you can do Nick I think you said it uh it's going to be a really interesting sector to follow um thank you for sharing expertise uh please come back and talk with us again sometime anytime thanks for having me I'm really appreciate it

This transcript was generated automatically from the video's captions and may contain errors.

eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Nick Heudecker, Sr. Director, Market Strategy and Competitive Intelligence at Cribl, discussed how to address cyber risks in LLMs and data harvesting, and also made predictions about the future of cybersecurity in the age of AI. Watch the video:

James Maguire

James Maguire has been reporting on emerging technology for more than 15 years. He has won two ASBPE Awards of Excellence for in-depth feature articles about cloud computing and artificial intelligence. He has covered the gamut of enterprise and consumer technology, and regularly communicates with leading IT newsmakers, vendors and analysts.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.