Data‑First Security Strategies for Enterprise AI
This interview evaluation is sponsored by Securiti and was written, edited, and printed in alignment with our Emerj sponsored content guidelines. Learn extra about our thought management and content material creation providers on our Emerj Media Services page.
The promise of enterprise AI meets a actuality the place fashions and brokers can entry delicate information quicker than organizations can see, govern, or clarify that entry — a spot that leaves leaders unable to show compliance, comprise publicity, or defend how AI is utilizing their information.
Stanford HAI reports 88% of organizations now use AI in a enterprise perform, whereas documented AI incidents jumped to 362 in 2025, up from 233 the yr earlier than. The GAO found that AI use in monetary providers introduces information high quality, privateness, and cybersecurity dangers regulators are actively analyzing.
The Cloud Security Alliance reports that solely 35% of organizations have full visibility into the place unstructured information resides. Just 9% have actual‑time scanning capabilities, and 23% can not scan unstructured information for dangers in any respect — structural limits that constrain what any AI system can do nicely.
Emerj’s Yolandi de Weerdt not too long ago hosted a dialog with Chris Joynt, Director of Product Marketing at Securiti; James Dean, AI Specialist at Google Cloud; Mark Crean, Regional Vice President of Sales at Securiti; Dr. Oscar Rodriguez, Vice President, Data Analytics at Citi; and Todd Vancil, Vice President of Veeam’s Securiti AI Sales Engineering Team.
This article outlines 4 insights that outline the core information, governance, and safety necessities for secure and scalable AI in monetary providers:
- Real‑time mapping of delicate information flows for pre‑ingestion management: Stops ungoverned unstructured information from getting into AI techniques by revealing the place delicate info lives and strikes.
- Unified governance for AI‑prepared information throughout groups: Ensures fashions and brokers solely function on compliant, licensed info so monetary AI can scale past remoted pilots.
- Pre‑growth accountability frameworks for AI resolution‑making: Establishing possession earlier than fashions are constructed prevents governance failures that stall deployment as techniques transfer towards manufacturing.
- Data‑degree safety controls for AI ingestion and retrieval: Restrict and sanitize delicate information on the supply so AI techniques entry solely licensed info and breaches could be contained immediately.
Real‑Time Mapping of Sensitive Data Flows for Pre‑Ingestion Control
Episode 1: Why Granular Visibility and Data Control Determines AI Success in Financial Services – with Chris Joynt of Securiti
Guest: Chris Joynt, Director of Product Marketing at Securiti AI
Expertise: AI Security, AI Trust, Product Marketing, Go-to-Market Strategy
Brief Recognition: Chris Joynt is Director of Product Marketing for AI Security at Securiti. Previously, he led product advertising for Cloudera’s Data in Motion portfolio, held a number of AI and IoT management roles at PTC, and commenced his profession in superior analytics at IBM. He holds a bachelor’s diploma in Business Administration with concentrations in Marketing and Finance from Temple University.
Chris Joynt describes information estates the place unstructured content material has grown past what conventional governance practices can examine. He factors to prospects working throughout greater than 200,000 information techniques, producing billions of information and producing a petabyte of logs per day. At that scale, even figuring out what delicate info exists in these information turns into a structural problem — and that problem seems earlier than any mannequin is constructed or evaluated.
Joynt’s central level is that when unstructured information is ingested, reworked, or vectorized, organizations lose significant visibility into how it’s getting used. The authentic kind turns into obscured, by-product copies proliferate, and governance groups can not reliably hint how delicate info reached an AI system.
Pre‑ingestion visibility turns into the one place the place management could be exerted:
“Unstructured information turned gold in a single day. Institutions generate monumental volumes of it — logs alone can attain a petabyte a day. You can’t throw that into AI and hope the mannequin figures it out. You have to know what’s in these information, how delicate they’re, and the place they’re transferring. Once the info is contained in the mannequin, you’ve misplaced management of it. Visibility into the flows is the primary layer of security.”
— Chris Joynt, Director of Product Marketing at Securiti
AI exercise might already be occurring exterior formal oversight, in keeping with Chris. Shadow AI turns into doable when groups lack discovery into the place information goes or which techniques are processing it. Mapping flows is step one towards understanding how content material strikes, how it’s reworked, and the place delicate info might already be uncovered.
His sensible steering for C‑suite leaders kinds a transparent pre‑ingestion framework:
- Map delicate information flows — Establish factual visibility into the place unstructured content material resides and the way it strikes throughout techniques.
- Classify and label unstructured content material — Identify PII, transactional information, regulated content material, and enterprise‑confidential info earlier than AI techniques ingest it.
- Define AI entry boundaries — Specify which fashions, brokers, and retrieval pipelines can entry explicit classes of delicate information.
- Monitor transformations and by-product paths — Track how content material is merged, vectorized, or copied so governance groups can see the place publicity originates.
- Detect shadow AI — Surface AI techniques already processing delicate info exterior formal governance.
Joynt’s takeaway is structural: pre‑ingestion visibility is the inspiration of AI governance. Once delicate information enters a mannequin, its transformations and derivatives develop into tough to trace, and management turns into reactive moderately than preventative. Mapping flows, classifying content material, and defining boundaries upstream offers leaders the factual baseline required to manipulate AI safely at scale.
Unified Governance for AI‑Ready Data Across Security, Data, and Business Teams
Episode 2: Why Financial AI Can’t Scale Without Unified Governance with James Dean of Google and Mark Crean of Securiti
Guest: James Dean, AI Specialist at Google Cloud
Expertise: Generative AI, Enterprise AI Strategy, Go-to-Market Strategy, AI Sales
Brief Recognition: James Dean is a Generative AI Specialist at Google Cloud, the place he has additionally led world AI go-to-market technique and suggested enterprise leaders on AI adoption. Previously, he held AI and enterprise gross sales management roles at H2O.ai, SAP, and WealthEngine. He holds an MBA in International Business from Pepperdine Graziadio Business School and a bachelor’s diploma in Finance from Northeastern University.
Guest: Mark Crean, Regional Vice President of Sales at Securiti AI
Expertise: AI Security, Data Security, Identity & Access Management, Enterprise Sales
Brief Recognition: Mark Crean is Regional Vice President of Sales at Securiti AI, the place he leads strategic enterprise gross sales throughout the Americas. Previously, he held gross sales management roles at Ping Identity, ForgeRock, and Oracle, specializing in identification, cloud, and information safety options. He holds a bachelor’s diploma in Marketing and Management from the University of Delaware.
Scaling AI in monetary providers stalls when safety, information, and enterprise groups function from totally different definitions of AI‑prepared information. Mark Crean and James Dean each level to this fragmentation as the rationale pilots stay trapped in innovation labs whereas excessive‑worth use circumstances battle to succeed in manufacturing. Productivity instruments and coding assistants transfer rapidly; enterprise‑degree AI doesn’t — as a result of governance just isn’t unified.
James Dean underscores the operational hole: put up‑POC deployments fail when establishments can not safe petabytes of delicate information or reconcile siloed datasets. Half of banks, by his estimate, nonetheless have information locked in remoted techniques, stopping fashions and brokers from accessing compliant, licensed info. Crean provides that even when AI proliferates internally, organizations lack shared guardrails for entry, context, and rollback — leaving groups uncertain tips on how to undertake AI safely at scale.
Their mixed framing is obvious: AI governance turns into scalable solely when safety, information, and enterprise groups align on a single definition of AI‑prepared information and implement it constantly throughout the enterprise.
“Aligning stakeholders is at all times the first step. As fashions and brokers proliferate, what guardrails and controls are you putting in to make sure customers can safely undertake these instruments? What information safety practices guarantee the info integrity could be trusted?”
— Mark Crean, Regional Vice President of Sales at Securiti
“It begins by aligning the CISO, information scientists, and enterprise leaders on a shared definition of AI‑prepared information. From there, they map governance to each section and automate information classification earlier than coaching or cloud migration.”
— James Dean, AI Specialist at Google Cloud
Their steering kinds a unified governance mechanism that C‑suite leaders can operationalize:
- Define AI‑prepared information throughout features — Establish a shared definition utilized by safety, information, and enterprise groups to find out what info fashions and brokers are permitted to entry.
- Automate classification earlier than coaching — Use NLP‑pushed scanning to tag hidden PII, KYC, and controlled content material so restricted info by no means enters coaching pipelines.
- Embed entry controls into mannequin operations — Enforce strict authorization boundaries and auditability straight inside mannequin workflows, not as an exterior afterthought.
- Establish guardrails for agent adoption — Define context necessities, error‑dealing with expectations, and rollback mechanisms so brokers function safely as they proliferate throughout the enterprise.
- Integrate governance with compliance readiness — Align governance practices with rising state‑degree and world rules to make sure fashions and brokers function inside accredited boundaries.
The structural result’s fashions and brokers solely function on compliant, licensed info, enabling monetary establishments to maneuver past remoted pilots and into enterprise‑scale AI deployment with out compromising safety, compliance, or information integrity.
Pre‑Development Accountability Frameworks for AI Decision‑Making
Episode 3: How Financial Services Leaders Operationalize Safe AI – with Dr. Oscar A. Rodriguez of Citi
Guest: Dr. Oscar A. Rodriguez, Vice President, Data Analytics at Citi
Expertise: Data Analytics, Enterprise Data Strategy, Business Intelligence, AI Governance
Brief Recognition: Dr. Oscar A. Rodriguez is Vice President of Data Analytics at Citi, the place he leads enterprise information and analytics initiatives for the monetary providers sector. Previously, he held information management roles at Liberty Mutual Insurance, Blockchain Strategy Group, and FCCI Insurance Group. He holds a doctorate in Strategic Business Leadership from Regent University and a grasp’s diploma in Management Information Systems from Florida State University.
AI tasks inside monetary establishments usually collapse on the precise second they need to scale. Dr. Oscar Rodriguez factors to a easy trigger: groups construct earlier than they determine who owns the outcomes. When accountability is undefined, governance turns into a scramble, and the scramble begins solely after the mannequin already exists, when it’s too late to form its assumptions, its information, or its threat posture.
Rodriguez sees this repeatedly. Business models race to experiment. Data groups work from disconnected sources. Security and compliance arrive after the actual fact. Leadership focuses on future threat whereas groups deal with proving worth. The consequence just isn’t technical failure however organizational misalignment. Models show promise in early testing, then stall below scrutiny as a result of nobody agreed on requirements, possession, or governance earlier than growth started.
A pre‑growth accountability framework prevents that stall. It forces readability earlier than code, possession earlier than modeling, and governance earlier than enthusiasm.
Rodriguez’s steering is sensible:
- Define who owns mannequin choices — Identify the accountable get together for outcomes, failures, and escalations earlier than any mannequin is constructed.
- Align groups on shared requirements — Prevent duplicate efforts by agreeing on information high quality, threat tolerance, compliance necessities, and success metrics upfront.
- Embed governance into design — Treat governance as a part of the construct course of, not a late‑stage add‑on.
- Document accountability pathways — Make accountability specific: who approves, who screens, who intervenes, and who carries penalties.
- Plan for regulatory change — Build buildings that may regulate as rules evolve moderately than retrofitting compliance after deployment.
Rodriguez’s emphasis is that accountability just isn’t a compliance requirement — it’s the basis that determines whether or not a mannequin can survive the journey from proof of idea to manufacturing. When possession is outlined early, governance turns into structural moderately than reactive, and AI techniques can transfer towards manufacturing with out collapsing below regulatory or operational stress.
“Teams experiment independently. They wish to get there first. Leadership is concentrated on various things. You find yourself with duplicate efforts, inconsistent requirements, and competing priorities. Governance will get launched after the mannequin is already constructed, and that’s a components for catastrophe.”
— Dr. Oscar Rodriguez, Vice President, Data Analytics at Citi
Data‑Level Security Controls for AI Ingestion and Retrieval
Episode 4: Preparing Enterprise Data for Safe AI Deployment – with Todd Vancil of Securiti AI
Guest: Todd Vancil, Vice President of Veeam’s Securiti AI Sales Engineering Team
Expertise: AI Security, Data Security & Privacy, Sales Engineering, Go-to-Market Strategy
Brief Recognition: Todd Vancil is VP of Veeam’s Securiti AI Sales Engineering Team, the place he leads world presales and enablement efforts targeted on serving to enterprises securely undertake AI and data-driven applied sciences. Previously, he held senior management roles at Fortinet, Amplitude, and Conga, main gross sales engineering, presales, and go-to-market organizations. He earned a bachelor’s diploma in Management from the University of Tampa.
“Walk into the library, scan and classify each e-book, perceive who has entry, the way it acquired there, the place it moved. Label the e-book so ingestion insurance policies respect it. That’s how you retain delicate information out of the improper LLM, and the way you comprise publicity when one thing goes improper.”
— Todd Vancil, Vice President of Veeam’s Securiti AI Sales Engineering Team.
Todd Vancil’s metaphor is easy, however the operational actuality behind it’s not. As enterprises transfer workloads into cloud platforms, SaaS environments, information lakes, and shared techniques, delicate info sprawls throughout areas that perimeter controls can now not meaningfully shield. AI techniques ingest and retrieve content material at machine velocity, and the standard mannequin of securing networks, endpoints, or entry pathways can not hold tempo. The solely management level that scales with AI is the info itself.
Vancil argues that safety should shift from guarding the doorways to governing the contents. If delicate information just isn’t labeled, labeled, and restricted on the supply, AI ingestion pipelines will take in info they need to by no means see, retrieval workflows will floor content material they need to by no means entry, and breaches will propagate quicker than any human response. Data‑degree controls develop into the mechanism that determines what AI can learn, what it will probably retrieve, and what it mustn’t ever contact.
Leaders who undertake this posture begin upstream, lengthy earlier than prompts, brokers, or retrieval workflows come into play:
- Scan and classify delicate information at scale — Treat the enterprise as a distributed library and browse each file, dataset, and doc to find out sensitivity, lineage, and entry.
- Label unstructured content material earlier than ingestion — Apply sensitivity labels to PDFs, textual content information, shows, and different unstructured sources so LLMs and brokers can not practice on or learn restricted info.
- Enforce ingestion insurance policies on the information layer — Ensure coaching pipelines respect labels and redactions moderately than counting on mannequin‑degree controls.
- Secure retrieval‑augmented technology — Restrict what brokers can retrieve, how context is filtered, and which techniques could be queried.
- Use information‑degree visibility for prompt containment — When publicity happens, classification and lineage make it doable to find out what moved, who accessed it, and the place containment should be utilized instantly.
- Eliminate redundant, out of date, and trivial information — Remove stale content material that creates authorized publicity, storage value, and pointless threat — and hold it out of AI techniques fully.
The shift Vancil describes just isn’t beauty. It is a redefinition of the safety management aircraft. AI techniques can’t be anticipated to interpret enterprise insurance policies or navigate legacy entry buildings on the velocity they function. Security should be embedded within the information itself — labeled, labeled, and ruled on the supply — so ingestion and retrieval workflows function solely on licensed info, and breaches could be contained the second they happen.
