John Santana
speaker
30 appearances
1 recordings
1 series
first heard May 2025
last heard May 2025
John Santana’s voice in public audio — every appearance, attributed to the second.
Trend
recordings per month · last 12 monthsNo recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.
Appearances
So, you know, those are a couple elements, but another direction I take that to is, you know, PE firms should absolutely build out their own internal security capabilities to an extent, right? I mean, they're dealing with, a lot of personally identifiable information, right? They're not necessarily providers, but they are still dealing with a fair amount of sensitive information.
So they should be drinking their own Kool-Aid there, so to speak, if they're going to be mandating requirements for the portfolio. But centralized sort of entails micromanagement, but in reality can be a lot more nuanced and a lot more complex Subtle of a baseline.
Again, kind of getting back to those minimum standards or establishing that centralized and agreed upon security framework and just measuring against that and applying the requirements where it makes sense ultimately.
Yeah, so when I think about our portfolio monitoring program, I mean, we really... started making this a dedicated service back in 2022 and had some good luck right off the bat with that and some good traction. But really the change healthcare breach was sort of a catalyst event in the space and industry.
And a lot of firms that we were talking to, but couldn't quite get traction with now said, oh my gosh, this is crazy. We need to do something about this. So really in the last couple, a couple of years and since change. Our portfolio and the number of private equity firms we're working with has grown quite a bit.
And the exciting thing there is as we continue with these ongoing assessment cycles and this ongoing management, we're building a heck of a data set. And the more time that trespasses, A, two things. A, it's great watching all the portfolio companies that I'm working with get more mature and actually seeing those results cycle over cycle. That brings me a lot of joy.
But two, working with so many different companies now and having that data set and that pool of companies only continuing to grow, we're able to see some really interesting trends. And that's really the the thinking behind that, that trend report that we put out earlier this year, that was really the first of its kind.
Cause we were able to aggregate a lot of data across a lot of different companies, a lot of different types of companies. And we're able to really sort of identify some like general findings and top areas of risk across the board. So yeah,
A couple of those were around incident response capabilities, data protection, loss prevention, and just overall just having good security policies and governance. So I won't jump too much into that. I mean, we certainly can, but all of the meat and potatoes there are available in that report.
But all that to say, I'm just really excited to continue to work through these program cycles, continue to identify more trends, and ultimately get results. get our clients to a more secure, resilient, and compliant state.
Showing 21–30 of 30 · page 2 of 2
← Previous