In this podcast discussion, the conversation centers on navigating AI trends for business, emphasizing the need to balance innovation with security, compliance, and functionality. A key example is passwordless authentication, which meets security needs without hindering productivity. The speakers stress that AI implementation should not start with technology alone but by identifying specific business problems, such as automating mundane tasks, to ensure meaningful outcomes. Data governance is highlighted as foundational; without proper controls, AI tools can expose sensitive information, making solutions like Microsoft Purview essential for data cataloging and protection. The dialogue warns against viewing AI as a silver bullet, advocating instead for a phased approach beginning with minimal viable products. Additionally, it distinguishes between compliance as a baseline and cybersecurity as an ongoing cultural practice, urging organizations to prioritize long-term security over rapid AI adoption to maintain trust and avoid data breaches.
Welcome to ECI Pulse, a podcast where we break down the latest trends shaping the business world. I'm Rich Eatery, the Chief Innovation Officer at ECI, and today we're happy to be joined by Jason Kaufman, Principal Solution Architect at Tularis. In this series, we're exploring the key trends that will define 2026 for partners, which changing, why it matters, and how to stay ahead. We'll focus on the most impactful shifts, including AI-driven analytics, security, compliance, and the move towards outcome-based selling. Our aim is to help partners understand where the market is headed, what risks to avoid, and how to build a reputable sales motion around this innovation. We'll share practical examples, lessons learned with Jason and I both have a lot of, and actual insights to help you navigate this ever-changing landscape. Whether you're refining your strategy or looking for new ways to enable your team, this series is designed to deliver clear and valuable takeaways. You talked about earlier around that balance between security, compliance, and functionality, people have to do their work, and I do think passwordless fits into that really well. You can make it more seamless for people to do their work, but you can meet those security needs, you can stay compliant with what the IT framework are, what the regulars are expecting, and people can still do their jobs. That, to me, is a really good example of something that meets that trifecta, because a lot of times, it's a trade-off. Look, I got to loosen things here so people can function a little better year, and the business is willing to accept that risk. It's harder to accept those risks now. It's really hard. As you mentioned, the AI tooling, and we talked about in depth today, it's gotten so powerful that it's really hard to mitigate it if you don't have those layers. A lot of times, when you're looking at getting the buy-in for an AI deployment, the first question we ask is, "Okay, how does this look culturally and politically?" You got to see, "Oh, that's trying to force efficiency, trying to make everybody, we need to scale, we need to scale fast without hiring, and we need to get all this revenue in the building. How to do that without going to get a ton more personnel, which is the most costly resource that we can have?" Then, you got the cybersecurity team and the risk manager and all of them, like, "Hold on, hold on, hold on." Before we started automating everything and giving access to all the data to somebody real-time, let's see what we could do to mitigate the potential risks and threats that come out of this. It's exactly that. There's really ever that one specific solution that comes out that satisfies both needs. How do we minimize that threat? Then, also, max efficiency and password lists is one of those that pleases everybody. It's one of those things that commonly get to come and ask for, "We need to go password lists because everybody determines that this is what they need. We're in a media agreement on this, so immediately we got budget on this. Let's move forward with this." Then, we start talking about, "Okay, what's all the other things that we could do? How is your data sitting today? Who has access to it? How are you controlling? Who has access to what? Are you following least privilege and all that stuff?" It opens up a bigger conversation when they first come in and say, "We just want password lists." It's amazing how many people come in just asking for that one thing. We all want that one-point solution. Look, I've been doing this for almost 30 years. I feel old when I say that, but AI has never seen a technology that has engaged the business like AI. I mean, business leaders are so engaged in technology. For years, I've fought to have to get budget, and now anything that's related to AI, all of a sudden, they open up the commoto. But I think to your point, when you think about defense and layer, and we talked a little bit about password lists, but now it's also, let's talk a little bit about the data layer. You mentioned least privilege, when we engage with clients around AI projects, we're using this opportunity to remind them about best practices. I've been talking about data security for years, and people are like, "We'll get to that when we get to it." Now with AI and wanting to leverage this advanced tooling, the business is really pressuring them to go out and leverage these tools, and a lot of them are SaaS products. I can probably opine for hours about my view on bringing the technology to the data, not vice versa, but the business is really driving them to bring, oftentimes, their most confidential data. Prioritary data, up to the cloud, so they can leverage it with AI tooling, understanding your data, and securing that data, leveraging tools like Microsoft purview. Oftentimes, people don't realize with your Microsoft license, you actually have the capabilities to secure that data better, to catalog that data better, to label that data better. Are you seeing now similar trends that I'm seeing where clients are more open to those projects? They understand they're a little more foundational to leverage AI? We generally take them down a couple different paths. Here's the risk that you're exposing by leveraging AI and just turning it on. We've all heard the stories on the bottom-level employee getting access to HR data like salary information for a C-level, or getting into financial information of a private entity, or PII of everybody else within the company, or customers, or all that stuff. We take them down a couple different strategies. One is, hey, let's have a data posture management conversation and say, hey, let's talk about all the different data where it's at, how to protect it, how to tag it to make sure that the LLMs and for all the million glissers around the world, large language models, the whole part of chatbot functionality is access to the data. Taking that information and saying, hey, how do we protect it, because if you're just turning it on, it doesn't understand, hey, this is confidential and this information cannot leak outside of the business, or outside of this person that's accessing it. It just knows, hey, I need to go make this as efficient as possible and get all the data and give a relevant answer that I'm confident in. That's all I just programmed to do. Taking that information, hey, where do we start with this? If the data maturity models and data standardization, cleanliness, protection, and all that stuff, or now we have the gateways that could sit in front of it and have it in here in DLP. We talk about, what does it look like from a go-to-market strategy, do you want to build a data posture management strategy culturally within the business and have all these different tool sets and all the stuff built in, or do you want something that's going to be more of a gateway. A lot of people choose having that security posture management to where they want to build out, they're taking Microsoft purview within the Azure Data Fabric, putting all their data within one central repository, if they need to keep it distributed, how is that going to work? Do you need to stream the data, do you need to batch it, how is it going to look to give somebody real-time access to it, and that just allows you to do much more with it. So it's not just protecting the data just to make sure that the right actors can't get in it, but now it's protecting the data to make sure that something alive moves quicker than a human can access it and make those people more efficient. Yeah. I think it's so important now to have real visibility into your data and AI state. To that point, people hear things like chat, GPT Enterprise or Anthropic Enterprise, and what I try and tell them, I even wrote a white paper on this because I thought it was generally a problem I was hearing, which is they see Enterprise right away, they think secure, compliant, it's okay to use. I'm like, actually, it's not. All those systems have to be configured. You still need to understand your data because once your data goes up to those platforms, you lose all the controls you spend time implementing over here, right? So you need that visibility because, look, I think to your point around like the comp thing, I could add access to the comp file, but you don't. I upload that to chat GPT Enterprise. I can now share that with you, right? Like, you lose that kind of continuity for your data control. So using certain DLP tools like per view, allow you to understand where that data is going, who's sharing it with, who, in some cases, you could actually prevent that. Other cases, you could just be alerted on it, but at least now you have visibility around it and you can take some action and remediate around, you know, those items. But I think people really need to be cognizant of, you know, how those other third party platforms are being used, right? Because I can tell you, too, the threat actors are targeting those platforms because they know you're putting your most confidential data there, right? And they're looking for, for loopholes around that. Like, so I think with that rush to be able to leverage AI, you know, what I try and tell people is like, don't forget security and compliance. You may move a little slower, but you're going to be in a better place because no one's going to remember that you enable AI fast when you've had a data issue, by data leak or your data is compromised in some way, they're just going to remember your most confidential data was compromised, right? Yeah, and it loses trust and those are the indirect cause of a breach. But we also don't want to confuse security with compliance, you know, compliance is just that baseline that says, yes, you hit these check boxes and you mitigated all these controls that we want you to do as part of this framework, let's sign you off and now you get the stamp of approval. But still, you know, cyber security being that continuous innovation and continuous mitigation and, you know, the culture around cyber security, you know, that's something that I loved about ECI when you guys came in was, you know, the first thing you guys ever said was, you know, when a customer is first on board of ECI, they're going to have X amount that they're going to pay us to, you know, manage everything, mitigate all the threats and everything. By the time they're done, it's going to be less than that because we're going to do all this automation, we're going to, you know, put all this stuff into place to where it's not going to be the same thing as when they came in. And we're used to the, if it ain't broke, don't fix it model. And that's, that's the cool part about ECI is it's always, you guys are always innovating with your customers to make sure that when they first come in, when they leave, or I don't say the word leave, that's bad, but like when they come down to renewal, it's not the same infrastructure. It's not the same environment. It's not the same methodologies and everything is when they came in. So I love that continuous innovation that we have. And the AI talk track, the reason why I'm talking about this now, the AI talk track that we're always doing, that continuous innovation, how to protect it, always changing and all that stuff, is just the model that you guys have already built out and that, how you guys have scaled. So I think it aligned really well. And that's why you guys are one or more of most successful AI consulting, you know, implementation practices that we have. And I think that's great. That's really great to hear. Thanks, Jay. You know, we invested a lot of time in AI about two and a half, three years ago. And at the time we were doing it, we were at an event, and one of our competitors came up to us and was like, Hey, I think you guys know all stuff around AI. Really? AI. Like laughing. And I'm like, what? Keep laughing. Because we'll see you. I'll see you in the rear view mirror, because AI is here to stay, right? And, you know, as MSPs and that convergence between MSP and MSSP, it's our job, right, to bring those secure compliant solutions to the table. You know, I'm a big fan of, you know, the Microsoft stack. And I think with AI, like they've really done a really good job with fabric and foundry. You know, you integrate things from co-pub studio, like down to teams and, you know, look, you can integrate almost any data source into fabric. You can use almost any model you want in foundry. They integrate really well together. And Microsoft purview, right, from a data perspective, sits across the both of those, right? And like when you think about like enabling that type of stuff, right, for clients, like we give them those real conversations and say, Look, I'm happy to support you around chat, GPT enterprise. Here's what you need to do though, but if you're looking for a slightly better solution, you can do this over here, right? But it's really understanding the business, like what their risk appetite is and really working with them. So we create that balance, right, that we talked about earlier around security, compliance and functionality, because you know, we want people to be satisfied with the technology that you're delivering to them. You don't want them to feel like there's hurdles, but you also have to kind of protect them, right? Kind of like your kids, right, like, you know, I'd love, you know, to give my kids chocolate cake for breakfast, right, but, you know, they, they need healthy food to grow, right? Yeah, you got to save them from themselves, unfortunately, that's the name of the game. So, I mean, we're all, we always want to do right by the customer. We always want to make sure we enable them, you know, be competitive advantage, but make sure it's still done securely. And I think that's like the big, the heaviest conversation is making them realize, Hey, there's a lot of this due diligence we need to put in here before just flipping on a switch that, you know, to get up to what the market says now is standard, and just like you were saying, you know, AI is here to stay, you know, it's a bad, just like the internet, you know, it will go away soon. Ultimately, now we're seeing a ton more investment in AI to where people are going, you know, multipliers out in the investment world that are unheard of just because somebody has got AI on the back end. Right. That's, it's really it's saying, Jason, you spend a lot of time with partners. And look, you have a lot of great experience, and you know, you talked a little bit about, you know, some of the frameworks, you know, that you kind of, you know, interact with, you know, a lot of clients and partners around, but there's a partner listening and, you know, they have clients interested in engaging with them around like AI, like what would be some helpful tips like you would get them. It's more instead of implementing AI as a skew, you know, start with the conversation on, okay, you know, what is driving the AI? Is it, is it ROI, is it competitive advantage? Find out what that meaningful conversation is to the customer and start asking them, you know, what have they done already? Have they determined where the biggest problem points like everybody's done some research on AI? They know, hey, I can have a chatbot. I can automate certain processes. I can, you know, I can effectively take out the human and put a bot in that area. So like a most conversation I hop in, like most of the customers have that form of understanding. They just don't know where it's going to fit in their business. They think, hey, give me, give me that use car salesman catalog on everything that AI can do. And I'll figure out what's going to fit within the business. And that's not a great conversation to have. It's, let's turn that upside down and let's say, hey, where are the problems today? Do you have mundane tasks that people are doing that they could be doing something more strategic? Do you need to give access to, to people to give more data because you're having high turnover because they're getting frustrated, you know, working from home and they can't turn to the person next to them and ask them a question and they're getting visibly frustrated with whoever's on the phone with them. Or is it, you know, whatever's enabling those people to be better and quicker and make them more satisfied with their job? You know, what is the real problem you're looking to solve here? And then let's take AI as the potential solution to that problem, but there's many different definitions of AI. It's not just one and defining that with a partner in order to have that conversation to the customer, that's what's landing with everybody is, hey, AI is not just a skew on where we just flip it on, can solve every problem. There's different forms of AI. It's just all under one umbrella and hey, we need AI. Yeah. I think there's this kind of rush to check the box with the sea level that they've implemented something. And they're shooting to the solution, right, without identifying, you know, the problem first. And then they said, I think is really spot on, you know, we'll get a very similar question. And my answer is, you know, the oftentimes want to know like, hey, can you give me AI use cases? I'm like, I have thousands of them, but give me some examples of some problems that you have. You know, we had a call with a client, you know, several months back, you know, and they were talking about, you know, hey, we want to know some AI use cases. And, you know, I'm like, look, you hear some use cases, but tell me like some problems that you're having today that aren't very efficient. And women's like, well, every day I get these, you know, documents from, you know, these individuals, I have to read those, summarize them and send them, you know, throughout the day. When I go on vacation, no one can do that. I'm like, that's a really good AI use case. She's like, yeah, I'm like, we could do that for you. We could even do it in the tone of your email. So people don't even know that you're on vacation, right? But, you know, I wouldn't have even suggested that because I hadn't seen that use case before, right? If I didn't hear what, you know, the problem was, right? I could have rattled off, you know, 30 or 40 things. And I think that's really, you know, people understanding where the most pain points are, you know, with, you know, business processes. That can really drive like the most efficient use of tools like AI and, you know, not trying to boil the ocean, you know, as well, like I think to your point, everyone thinks AI is a silver bullet. But it's no different than implementing any other technology that all of us have done like throughout our careers, you know, you got to identify the problem, understand the impact across the organization, you know, understand what the requirements are, and then like build an MVP that, you know, makes sense, right? And start small and you can build from there, right? And that's the, the most successfully AI projects we've seen over the last two years have done that. Like, we start out with very simple use case and now they have, you know, a number of different initiatives across the organization that are providing real value and freeing up time for people. The best one is when we hop on the call and we're like, Hey, we're having these pain points, but AI doesn't work for us. We tried implementing it and it just didn't work out for us. And they're like, what's the next conversation? We're like, Hold on. You know, what, what was the actual issues that you had there and they're all coming back to the same thing, you know, just what we were talking about earlier, like, Hey, we just turned it on and all of a sudden all this data was going everywhere and we had to immediately turn it off because people were getting access to things we didn't want them to or the, it was breaking because we were trying to take data from this system and putting in this system and it just wouldn't work. So we figured they're incompatible and they're not going to work. And like, there's many things to do in the middle of that, like the transformation of data. There's, there's ways to parse it to where one wreck, one system would recognize it and then there's also what we were talking about earlier, the data, the data maturity of classification and DLP and all that stuff that, you know, make sure the data can't go to where it's not supposed to. So a lot of that stuff on just educating on, Hey, did you do any of these things before you just turned it on because you got told you need to turn it on all the time that every time I have it, this is without fail so far on, Oh, we did try that. Like nobody, nobody has ever said that. Everybody's like, all surprised like, Oh, we need to do all this stuff before we implement it. And it's just taking all that stuff from somebody who knows how to do it, just like ECI. You know, Hey, you know, take all these due diligence, put it into your successful implementation, it may not be something that you trigger on immediately. You know, let's have some, you know, stuff that we do beforehand and then enable the business to scale quickly, leveraging AI, now you're going to have a successful implementation. But we also have those conversations where yeah, it doesn't work for us. Why not? And it's always the same, same stuff over and over again. It's funny how many times we have that, you know, that continuous wheel, you know, that mouse wheel everybody's talking about, that broken record, everybody's having the same issues when they implement it on their own. Yeah, they don't think about, you know, the data and all, you know, who has access to all of those like prerequisites. Like we've spent the last two and a half years implementing AI and have really built a pretty thorough enablement, you know, program around it and you know, corporate security, compliance, incorporates like knowing your data, I always say like before we get into this, like I need to know your data, the who, what, where, when, why around that information, because oftentimes people turn on things like co-pilot, and like co-pilot is terrible, you can't answer any of my questions. And then we go in, we're like, okay, let's take a look. And well, you don't have permission to that data, you're not asking the questions in the right way. Like if you ask co-pilot to compare it to documents, but you don't tell it, you only care about these 12 things, you want to see the differences between those things and you want to see it in a table. It's going to give you a bunch of items that are different in the document, right? And I think, again, people just think, it's AI, I could just talk to it and it knows like what I, I wanted to do type of thing. And when you start training people and you give them access to the right data and things are aligned, the results are our exponential, right? And people start seeing the value and the power of it, right? It's, but look, it isn't an investment, right? That's why people say like, what's the ROI? Can't forget the ARP, the eyepiece, right, which is like investment, investment in time, and investment in effort in implementing it correctly. So, look, Jason, I think we're getting up on time here. Was there anything you wanted to leave your partners and the audience with? Yeah, I mean, there's tons of resources to help here. You're not, you know, if you ever get into a roadblock, there's multiple, you know, avenues you could take it, you know, we're happy to have an agnostic conversation on what AI is, what's going on in the marketplace, you know, what's real, what's not? You know, there's the art of the possible conversation, then there's also the art of the impossible conversation, you know, what's real, what could you do, the impact of business, let's talk about, you know, where's that ROI that, you know, the maximum ROI directly or indirectly, you know, what, let's prioritize this. And then let's see, you know, where's the fit, you know, what's going to be the best thing that's going to, you know, help the business. And then you also have companies like ECI or AI specialist, you know, not only can you guys consult on it, but you can also implement it. Yeah, so we work hand in hand together, you know, most of the time the ag conversation start with us, they end with you. So, you know, let's, you know, collectively come together sometime to have that conversation of the customer needs to move quickly. We could both be on the same conversation at the same time. So, yeah, there's many different ways that we can help out customers here, whether it's through Tularis, through ECI, through both, and we're always happy to do that. The ag conversations are really fun, and there's many things that we could talk about that customers didn't even think of previously from use cases that we've done. So happy to help. Well, thanks, Jason, you know, we at ECI really enjoy working with you and the Tularis team, and I encourage everyone listening if you're interested in cybersecurity, AI solutions to reach out to us. Like, we're always happy to get on the phone, happy to share our experiences with you, and help guide you down this journey, because it is a journey, right? And these things aren't going to, you know, all materialize your overnight, and it starts with really talking with people who are in the weeds on a day-to-day basis to help you develop strategies for your clients. So thanks again, Jason, I look forward to doing this again. Same here, thanks for having me.
Podcast Summary
Key Points:
AI adoption requires balancing innovation with security, compliance, and functionality, avoiding trade-offs where possible (e.g., passwordless solutions).
Effective AI implementation starts with identifying specific business problems, not just deploying technology as a generic solution.
Data security and governance are critical foundations for AI; tools like Microsoft Purview help manage data posture and prevent leaks.
Organizations must move beyond compliance checkboxes to foster a culture of continuous cybersecurity innovation and risk mitigation.
Successful AI projects begin with small, focused use cases, then scale based on measurable value and organizational learning.
Summary:
In this podcast discussion, the conversation centers on navigating AI trends for business, emphasizing the need to balance innovation with security, compliance, and functionality. A key example is passwordless authentication, which meets security needs without hindering productivity. The speakers stress that AI implementation should not start with technology alone but by identifying specific business problems, such as automating mundane tasks, to ensure meaningful outcomes.
Data governance is highlighted as foundational; without proper controls, AI tools can expose sensitive information, making solutions like Microsoft Purview essential for data cataloging and protection. The dialogue warns against viewing AI as a silver bullet, advocating instead for a phased approach beginning with minimal viable products. Additionally, it distinguishes between compliance as a baseline and cybersecurity as an ongoing cultural practice, urging organizations to prioritize long-term security over rapid AI adoption to maintain trust and avoid data breaches.
FAQs
Passwordless authentication allows users to access systems without traditional passwords, enhancing security and compliance while improving user experience. It balances functionality, security, and regulatory requirements effectively.
Businesses should start by assessing cultural and political impacts, then implement data security measures like least privilege and data classification before deployment. Using tools like Microsoft Purview helps protect data and maintain control.
Third-party AI platforms may lack built-in data controls, risking exposure of confidential information. Businesses must configure these platforms properly and use data loss prevention tools to monitor and secure data transfers.
Companies should first identify specific business problems or inefficiencies, such as mundane tasks or data access issues. AI should be tailored as a solution to these problems, not implemented as a generic technology.
Data visibility helps track where data is stored, who accesses it, and how it's shared, preventing unauthorized leaks. Tools like Microsoft Purview enable better data cataloging and protection, especially when integrating AI.
Compliance involves meeting regulatory checkboxes, while security is an ongoing process of risk mitigation and innovation. Both are essential, but security requires continuous adaptation to threats.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.