Skip to Content
Find dismissed updates here
Edit My Preferences
21:58 Video

Veeam + Everpure RSAC Podcast: Key Insights on Cyber Resilience from the Press Club

Everpure CISO Rick Orloff joins Veeam’s Wake Up Podcast to discuss ROT data risks, GRC alignment, and security as a business enabler.
Click to View Transcript
00:17
This is the Wake Up Podcast, powered by Veeam. I'm your host, Rick Vanover, the Rickatron. Today, Rick Orloff is joining us to share fresh perspectives to wake up to. Thanks for joining us, Rick. Thank you for having me. Appreciate it. So, first time on the show, I'm a longtime fan,
00:33
but take a moment and introduce yourself, your role, and, and what you, what your current responsibilities are. Sure. Rick Orloff, Vice President and CISO at, EverPure, which is formerly Pure Storage, and I'm responsible for all of the cybersecurity, the zeros and ones, and bits and bytes. It's funny, I'm glad you said EverPure, 'cause I know I woulda messed it up.
00:54
formerly Pure Storage, you know, household name in the Veeam neighborhoods, if you know what I mean. So longtime partnership, but what we wanna talk about here today are some really interesting perspectives that you have in your role, which is unique because as CISO and in your prior experience, you've, you've seen some things. So I say we jump into it, and the first thing
01:15
I wanna highlight is really a claim that data may not be fully trustworthy or even untrustworthy. welcome to you to, to challenge me on it, but kinda what's your thought about data and the trust level today? I understand the, the reference to the question because it used to be that you would
01:35
have somewhat two types of data. You would have your source of truth data, and then you would have copies of that data that other people manipulated, and so depending on what you were trying to do, you may be tying to the wrong piece of data. Today, with, data accessible from anywhere, any time,
01:57
it's really about what are you trying to do with it and which set should you be hooking into. That's a really important point, accessible anywhere, any time. I mean, I've heard the, you know, the proverbial phrase that the walls of the data center aren't really there anymore, and from a connectivity standpoint.
02:15
yes, they're there, but in terms of how people access and the accessibility, I mean, at least what, what we do at Veeam and what, you know, I, a lot of the orgs I work with, yeah, everything is very available. So I could see that perspective, and then o- one of those next things that I wanna kinda bring up is around the, the compliance of these conditions.
02:37
So, let me start kind of with a generic question. When you look at data, IT professional, you know, practices that you and your teams work with, and I'm sure you work a lot with, like, a CIO-type group and department and, and such, but what does audited and compliant mean from your management perspective today when it comes to IT services and more?
03:03
From a, from an overall, governance program a- and data, at the end of the, at the end of the day, you know, what we want is access to the data in a secure, compliant fashion. And so the way I structure programs, I think about it, on the governance side, I really think about it as a swim lane for, as an analogy where the, the rail on the left is the GRC compliance rail.
03:31
The rail on the far right is real-world technical security, and if you control the two rails, then the business can go as fast as they want in that swim lane. They can race, or they can tread water, right? But we own the rails. Oh, I love that analogy.
03:47
That, speaks a lot to one of the things I say about AI programs. A lot of people We are gonna talk about AI, but not just yet, but when I talk about AI programs with folks, I use this phrase, "Business benefit first, compliance always," and it's kind of a similar thing, where you, you go into it with those two guardrails and then that speed. I love that from a GRC and then a pure
04:10
technol- security side, and the technology thrives in the middle of that. That's, that's really good. Hey, he's almost a expert in these things. That might be why he's on our show. But when you look at that type of approach, Rick, do you ever see, groups maybe
04:26
hesitant on going the extra mile to really fully unlock and enable? 'Cause that really, that velocity is business benefit with compliance in mind, with security and- Right. Do you ever, you know, have you ever managed scenarios where you might have inhibitors of going the extra mile to do, do that to its full potential? Generally, the, the, the folks that might be
04:50
inhibitors are A- and this is interesting from a security perspective, but there, there's kind of view, two views for the security space. there's leaders that are risk adverse and leaders that understand how to accept calculated risk, and so usually an inhibitor is somebody that is risk adverse, potentially 'cause they don't necessarily have the right tools, or controls,
05:16
where my view is we should be enabling the business, as best we can in a secure envelope. Do you ever see maybe the skills gap come into, be a factor here? You mentioned some of the tools, and I'm kinda digging into that as one outlet, but is, is the skills gap for staff, is that a factor sometimes? Or is it, one of those things that has to be kinda managed in front of or such?
05:43
I don't really think of it as a skills gap. I think of it as a hiring plan, right? You should be hiring for the skills that you need today and tomorrow. so I, I, I don't really get into the skills gap piece. That's great because, you know, I think s- certain organizations struggle with,
06:03
the hiring, um- Let's just say the fulfilling, getting the right people in the roles. I, I was talking to one of the development teams here at Veeam, and, specifically running site reliability engineering type roles. And the big challenge was not so much we can get people, but getting the right people. So, you know, being selective, I think, is, is super important on that to get the right
06:30
people for the role. So I think a hiring plan is the right way to get at that. A- yeah, and, and if I can add to that just a, a little bit. if, if you have a really solid team and technology is moving, like what's happened with AI, enterprise data cloud, if you have the right people, and you have a solid company, then the company should be investing in the
06:53
training programs and development programs for those folks. at EverPure, that, that has just not been an issue for us. You know, we, we continuously train. Yeah. I, I'll, I'll share a joke. One time, I was at the airport, and I, I actually love this mechanism, and, you know,
07:10
love or hate the airport, you can, you can appreciate the takeaway here. But I was going through, you know, security screening, and it's going frustratingly slow. And I'm, I'm the most patient person that you will ever meet. But there are some other fellow people in the, you know, enhanced security line that were not as patient as I.
07:35
And then we got up close, and we determined that they were training someone on the equipment. And honestly, the other passenger was kind of dismissing that. And then the one, one of the persons, she said, "We train every day." And I actually love that mindset.
07:54
Yeah. I love that mindset, and I think you could apply that to building teams, investing in teams every day, and, and you've actually motivated me already to train up on something, so I like that. Well, and you can train without having a negative impact to your stakeholders. In, in your example, right, the customers coming through are the stakeholders. Yeah.
08:15
The training is important, but you ought not be impacting negatively your stakeholders. That's true. I mean, I think running an IT operation or, you know, checkpoint C might be a little bit different, but I think that, you know, that's a, that would be a, a business benefit to kind of put at the onset of not disrupting- Right the overall service and output.
08:35
Super. Now, if I was to ask about disrupting the status quo, I think it's probably something you've had to deal with at some point in your career, but sometimes when you look at systems that have just been there, r- run well forever, not had to fiddle with it for years, have you ever had to disrupt the, you know, question the status quo or even ask stakeholders, "What would happen if something went wrong with
09:02
this?" So that's interesting 'cause it, this really starts to get into, you know, critical, critical activities. When you have something that's been running forever and it's the status quo, really the, the standard ought to be is your data persistent? Is your identity persistent?
09:22
Are your critical services redundant and resilient? And the standard I kind of get to is can you take the data that you need for this critical function, move it or stand it up somewhere else, and continue to run the function? And if it's been status quo, often companies haven't tested the services that are required to, to run that, and that's really kind of the next layer
09:49
that people need to get to. I think that will naturally just discover blind spots in, in the processes. Correct. But the, the challenge is you don't wanna be discovering those blind spots while you're trying to recover from some sort of a hardware outage or a, a, a system outage. That ought to have been tested, reviewed, and mapped out ahead of time.
10:11
And, you know, in your role as a CISO, does that get into dealing with, like, the CIO side of your, your operation? Or, you know, I'm starting to see, personally, I'm starting to see a lot of organizations combine what may have been some of the infrastructure CIO type functions into CISO org functions. Are, are you seeing any type of, or at least
10:33
tighter inner workings? how's that look in your practice? the, the workings are, are really tight, i- in a good way. good CISO programs, the CISO really should be cutting across the entire business. It, it should be moving horizontally through every vertical of the business, 'cause the
10:53
fact that they're there means there's something critical that they're performing for the company. Whatever that is, we need to identify it and make sure it, it's backed up, it's resilient, all, all those types of things. So there's a lot more probably under the umbrella of a CISO today than, than I think most people realize. And that is something to wake up to.
11:13
When you look at those types of under the umbrella, I love that phrase, when you look at those types of responsibilities, is, you know, it pro- Okay, I don't wanna lead the witness, but I've seen a lot of organizations where it is a us versus them. You know, have you had, had that maybe, or have you solved for that or had to fix that- Uh- any type of scenarios? I, I've been doing this a long time.
11:37
I, I've certainly seen those environments. it's, it's us versus them, and, a lot of times, an olive branch goes an awfully long way, to kind of reset. usually those environments don't last. At some point, it's going to get corrected, and it really takes,
11:59
both organizations to align on what is the mission for the business. It's not you versus us. Right. Right? What is the mission of the business, and let's go get aligned on that. I have a, a quick story of where us versus them is no good.
12:14
I was, uh- Debriefed of a, a ransomware scenario of a healthcare provider, and this particular client of Veeam uses a storage integration very similar to what we have with EverPure, and our support team was going on and on. "Do you have another copy?" "No." "Do you have anything off-site?" "No." Which, by the way, are number one and number two rules- Right broken.
12:37
Right. "Did you use different credentials?" "No." Okay, that's number three. Don't use that. So everything that was the worst practice, it was This was a, a part of this healthcare provider that was acquired, and it was kind of hastily integrated. You may or may not have seen that story play out.
12:52
Anyways, long of the short, our support team was running out of questions and just getting no and no and no. And kinda the last guess' answer was, "Are you using the storage integration?" And the client said, "What's that?" Turns out, who was the classic Veeam administrator, was not talking to the, storage team, was not talking to the server team, was not
13:13
talking to the network team. All those us's and them's, right? And what happened was luckily, and you never wanna bank on luck, but luckily the client had a, a reseller partner when they implemented the storage automatically take, I think, a four-hour storage snapshot for a week, and they were able to stand up a
13:36
new Veeam server, plug those in, recover everything. I mean, it's luck. It- That's just dangerous. The diff- it, it You know, it's really two points, you know, that I'd like to comment on, right? The, the difference between, teams talking to each other and understanding what their different capabilities are instead of this us
13:56
versus them stuff. when they do that and, and they have a better understanding of each, you know, side of the fence, so to speak, it's really a, a force multiplier on what all the different capabilities are. The time to discover that, like what you were describing, the time to discover that is not in the middle of an incident.
14:17
So had they had all these conversations and were to collaborate, prior to that, right, they, they, they probably would've had a better plan faster to recover. Yet today, the way, backup and, and data cloud is working, it's really easy to be able to go grab your data, fall back to it, you know, from five minutes ago, two weeks ago, whatever you need to do, and get up and running.
14:43
It's a lot easier, but collaboration helps. Yeah. You know, I, I don't know that much about you, Rick. We just met, but I feel like you're talking to me in technology terms like some of my favorite TV football coaches, you know?
14:56
They see things that most don't, right? And, and that's really one of those signs of a leader, when you can, like, take a circumstance and a scenario, and I've told that story about luck probably five times, but I've never thought about it the way you just explained it. So that's fantastic. It's like, it's our own personal, you know, s-
15:15
sports show here, where we're like- breaking down the plays in ways you never thought. So that's great perspective. I wanna change a little bit to this thing that's happening nowadays, AI. And, you know, everyone's got their story and their explanation and their kind of, priorities around AI.
15:33
But are you seeing that as a, as a priority? Are you managing or putting the guardrails, as you said, around AI initiatives with your stakeholders? You know, there's a data explosion, both, how it's moved and how it's created. There's, there's a lot to it.
15:48
But, before I get into AI a little bit more, what's kinda your assessment of the current state? the velocity of AI is amazing. And I think from a security perspective, we want to embrace it and enable it, right? You have enterprise data cloud. You can get to any data from anywhere.
16:10
You can move it, shift it, recover it. you have to embrace that with the different AI tools now. And I start to fall back into the two rails I explained earlier of GRC and identity, or the technical controls. And now with AI, what really seems to be magnified is how well you're controlling
16:32
identity, what identity is being used by the AI tools and platforms, and what data is the identity services being pointed at or the AI services being pointed at. Is it a system of truth data? Is it a copy of the data? it's, it's really important to have a clear understanding of what the AI is doing and what
16:54
the AI should not be doing. Oh, I love that because I think, and this is something that's elevated to be s- central to the Veeam message nowadays around en- enabling safe AI at scale and, and more. So I think that practical perspective is really, really on point. You know, I started with the question about untrustworthy data.
17:18
If you take these scenarios with AI initiatives and, you know, data moving around at high velocity, what's your take on the, on the quality of the data, the relevance of the data, the, just even the do we even need it? Is it maybe obsolete, you know? There's a lotta data out there.
17:37
what about the quality of the data for AI projects today? it's a, it's a great question. when it comes to the quality of the data, let, let's just take a- an example of a, a really huge data set. You're running some AI, agentic, service. it's really important that the fidelity of that database is what
18:02
you're intending it to be. There could be another version of that database that's been augmented with several other pivots, and if you didn't know that and you're connecting to the wrong database, you're not gonna get the intended result A hundred percent. And I think one example that folks can really relate to is take your, your co-pilots,
18:23
your GPTs, your Geminis, your Clods, whatever kind of con- I don't wanna say consumer, but single user interaction AI tool. I've found that if you spend a little bit more time with a better prompt, you get a much better answer, right? That is very true. And, and it's not like just doing a web search
18:41
where, you know, a couple of words will get you to where you need to be. But if it's more of a In fact, I personally like to use the speech narration. I, I'm, pretty good on typing, but I can t- I can talk faster than I can type, and I find it easier to explain that way. So just a little pro tip if you're looking to build better prompts.
19:00
But when we look at the data, you know, I don't know if you get into this too much, but I, I feel like every IT professional, IT organization out there has an opportunity to kind of get their, I don't wanna say their head and their mind, but get their IT practice aligned to looking at redundant, obsolete, or trivial data, what we call ROT data. I personally think that's kinda risky sometimes if it, first of all, if it exists.
19:29
And then second of all, if it's fed into A- AI models, and then third of all, it might make the whole estate that much bigger and harder to manage and protect and consume resources and stuff. Do you have any perspectives on this notion of ROT data? I do. I, I think that, I think when you have platforms where you can get to any data from
19:51
anywhere, and you can move data around, you know, Ev- Everpure is, you know, Enterprise Data Cloud. and you start complementing that with AI tooling, you can start to identify, the databases that are sitting out there maybe really aren't useful anymore. Maybe you can push them out.
20:11
Maybe you can get rid of them. you can reduce your footprint. And the other thing with data that's sitting out there as, as you're describing, that also generates risk, and, and it's the type of risk where you got a bunch of different databases sitting out there. Maybe nobody's touched them in a while.
20:30
However, if that database was suddenly published in the media, would that be a problem for you? And the answer's probably yes. So now you have a database that hasn't been touched but yet would be risky if it were exposed.
20:43
So AI tooling, and being able to sh- move data, you know, from anywhere to anywhere is an opportunity to really reduce that risk. I love the risk reduction just mindset there. And I guess, leading the witness a little bit, but I s- I'd say it's worth the effort to just disrupt the status quo to get that right to prevent and reduce those types of risks.
21:06
Yeah. The, the From my perspective, anyway, you know, having the right controls in place, you know, we wanna do two things: stop the bleeding. Let's not create disparate databases anymore, so that's one. And then two, go ahead and start cleaning up the, the technical debt as a, as a structure. you know, if I were advising a company, you know, that, that would be the path.
21:31
Hey, Rick, thanks so much for joining us here today on the podcast. Really appreciate having me on. Had a great time. All right. That wraps this episode of the Wake Up Podcast powered by Veeam. Find this episode and more at a podcast platform near you and more information to wake
21:47
up to at veeam.com.
  • Podcast
  • Video
  • Veeam
  • Cyber Resilience

On Veeam's Wake Up Podcast, host Rick Vanover sits down with Everpure CISO Rick Orloff to explore how organisations can turn security into a business enabler. They discuss the hidden risks of ROT (redundant, obsolete, and trivial) data, the importance of aligning governance, risk, and compliance (GRC) initiatives, and how strong cross-functional collaboration helps teams move faster, reduce risk, and build long-term resilience in an increasingly complex threat landscape.

08/2026
Everpure FlashArray//X: Mission-critical Performance
Pack more IOPS, ultra-consistent latency, and greater scale into a smaller footprint for your mission-critical workloads with Everpure™ FlashArray//X™.
Data Sheet
4 pages
Continue Watching

* indicates a required field.

We hope you found this preview valuable. To continue watching this video please provide your information below.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Your Browser Is No Longer Supported!

Older browsers often represent security risks. In order to deliver the best possible experience when using our site, please update to any of these latest browsers.

Personalize for Me
Steps Complete!
1
2
3
Continue where you left off
Personalize your Everpure experience
Select a challenge, or skip and build your own use case.
Future-proof virtualisation strategies

Storage options for all your needs

Enable AI projects at any scale

High-performance storage for data pipelines, training, and inferencing

Protect against data loss

Cyber resilience solutions that defend your data

Reduce cost of cloud operations

Cost-efficient storage for Azure, AWS, and private clouds

Accelerate applications and database performance

Low-latency storage for application performance

Reduce data centre power and space usage

Resource-efficient storage to improve data centre utilization

Confirm your outcome priorities
Your scenario prioritizes the selected outcomes. You can modify or choose next to confirm.
Primary
Reduce My Storage Costs
Lower hardware and operational spend.
Primary
Strengthen Cyber Resilience
Detect, protect against, and recover from ransomware.
Primary
Simplify Governance and Compliance
Easy-to-use policy rules, settings, and templates.
Primary
Deliver Workflow Automation
Eliminate error-prone manual tasks.
Primary
Use Less Power and Space
Smaller footprint, lower power consumption.
Primary
Boost Performance and Scale
Predictability and low latency at any size.
What’s your role and industry?
We've inferred your role based on your scenario. Modify or confirm and select your industry.
Select your industry
Financial services
Government
Healthcare
Education
Telecommunications
Automotive
Hyperscaler
Electronic design automation
Retail
Service provider
Transportation
Which team are you on?
Technical leadership team
Defines the strategy and the decision making process
Infrastructure and Ops team
Manages IT infrastructure operations and the technical evaluations
Business leadership team
Responsible for achieving business outcomes
Security team
Owns the policies for security, incident management, and recovery
Application team
Owns the business applications and application SLAs
Describe your ideal environment
Tell us about your infrastructure and workload needs. We chose a few based on your scenario.
Select your preferred deployment
Hosted
Dedicated off-prem
On-prem
Your data centre + edge
Public cloud
Public cloud only
Hybrid
Mix of on-prem and cloud
Select the workloads you need
Databases
Oracle, SQL Server, SAP HANA, open-source

Key benefits:

  • Instant, space-efficient snapshots

  • Near-zero-RPO protection and rapid restore

  • Consistent, low-latency performance

 

AI/ML and analytics
Training, inference, data lakes, HPC

Key benefits:

  • Predictable throughput for faster training and ingest

  • One data layer for pipelines from ingest to serve

  • Optimised GPU utilization and scale
Data protection and recovery
Backups, disaster recovery, and ransomware-safe restore

Key benefits:

  • Immutable snapshots and isolated recovery points

  • Clean, rapid restore with SafeMode™

  • Detection and policy-driven response

 

Containers and Kubernetes
Kubernetes, containers, microservices

Key benefits:

  • Reliable, persistent volumes for stateful apps

  • Fast, space-efficient clones for CI/CD

  • Multi-cloud portability and consistent ops
Cloud
AWS, Azure

Key benefits:

  • Consistent data services across clouds

  • Simple mobility for apps and datasets

  • Flexible, pay-as-you-use economics

 

Virtualisation
VMs, vSphere, VCF, vSAN replacement

Key benefits:

  • Higher VM density with predictable latency

  • Non-disruptive, always-on upgrades

  • Fast ransomware recovery with SafeMode™

 

Data storage
Block, file, and object

Key benefits:

  • Consolidate workloads on one platform

  • Unified services, policy, and governance

  • Eliminate silos and redundant copies

 

What other vendors are you considering or using?
Thinking...
Your personalized, guided path
Get started with resources based on your selections.
My Updates
No updates at this time.