Episode Details

Back to Episodes
Episode 63: Rethinking DLP: Nightfall AI’s Rohan Sathe on Data Protection in the Age of AI Agents

Episode 63: Rethinking DLP: Nightfall AI’s Rohan Sathe on Data Protection in the Age of AI Agents

Episode 63 Published 3 months ago
Description

Introduction Summary

Hosted by CEO Den Jones, "909 Exec" is a leadership podcast from 909 Cyber. Jones uses his 30+ years of enterprise security experience at companies like Adobe and Cisco to help executives navigate risk and transformation. Episode 63 features Nightfall AI co-founder and CEO Rohan Sathe for a deep dive into Data Loss Prevention (DLP).


Main Topics Covered

  • Entrepreneurial Journey: Sathe discusses his Silicon Valley roots and transition from the Uber Eats founding team to a cybersecurity founder.

  • Consumer-Grade Enterprise Software: Sathe applies lessons from Uber Eats—building scalable products for low-switching-cost markets—to drive Nightfall’s enterprise product quality.

  • Fundraising Strategy: Outlining Nightfall’s $65M total raise, Sathe emphasizes prioritizing investors who offer cybersecurity expertise and founder empathy over just capital.

  • Flaws of Legacy DLP: After interviewing ~100 CISOs in 2018, Sathe found legacy tools were noisy, unpopular, and unsuited for modern cloud apps like Slack and Google Drive.

  • Skepticism & Pain Points: Jones details his historical skepticism of DLP, citing lost employee productivity, high false-positive rates, blind spots, and a heavy reliance on user-driven classification.

  • Design Principles: Nightfall aims to make DLP "invisible" to end-users unless an incident occurs. Jones relates this to his view that security should be "invisible, invincible, and inexpensive."

  • Frictionless Architecture: Unlike SASE vendors that rely on latency-heavy network proxies, Nightfall targets optimal insertion points to eliminate user workflow delays and efficiently handle false positives.

  • AI-Driven Risk Modeling: Replacing legacy regex rules with neural-network NLP and computer vision, Nightfall uses a comprehensive risk model evaluating identity, data lineage, and destinations to identify true incidents.

  • Board-Level AI Concerns: As boards push for rapid AI adoption, AI data protection is now critical. This demands strict governance over autonomous agents operating at machine speed.

  • Expanding Customers: Initially successful with tech-forward health and fintech companies, Nightfall's customer base has expanded into traditional sectors like manufacturing due to new AI security needs.

  • Deployment & Value: Nightfall ensures rapid deployment via lightweight endpoint agents and system APIs (avoiding proxies). It integrates directly with SaaS apps and AI platforms to track prompts and agent actions.

  • Managing Data: Nightfall tracks data movement between corporate and personal environments, including AI tools like ChatGPT. It can monitor or block personal AI usage and track file lineage to determine corporate ownership.

  • Policy Enforcement: The platform uses customizable policies to block risky actions, present user justification prompts, and offer optional bypasses tailored to organizational philosophies.

  • Startup Strategy & Compliance: Both agree expensive conference booths yield low ROI, favoring targeted events like dinners. Jones advises pursuing compliance primarily to unblock deals, noting it does not equate to actual security.

  • Selling to CISOs: Acknowledging that CISOs are overwhelmed with pitches, they emphasize humility, understanding the customer's specific problems, and building long-term trust.

  • Closing Reflections: Sathe admits he initially underestimated the importance of go-to-market strategies in cybersecurity. He warns that auton

Listen Now

Love PodBriefly?

If you like Podbriefly.com, please consider donating to support the ongoing development.

Support Us