Data Security for the Digital Business | Chris Porter | CIO Talk Network

CIO Talk Network
CIO Talk NetworkApr 24, 2026

Why It Matters

Translating data risk into dollar terms forces executives to prioritize security investments, protecting both revenue and reputation in an increasingly data‑centric economy.

Key Takeaways

  • Data now resides everywhere; governance must map all locations.
  • Encrypt data at rest, in use, and in transit.
  • Quantify cyber risk in monetary terms to gain business buy‑in.
  • Identify crown‑jewel data and tailor protection to its value.
  • Adopt layered defenses and proactive hunt teams for breach detection.

Summary

The CIO Talk Network interview with Chris Porter focuses on the evolving landscape of data security in today’s digital business. As organizations migrate data to cloud services, mobile devices, and SaaS platforms, the traditional perimeter has dissolved, leaving data scattered across countless environments. Porter emphasizes that effective protection now requires comprehensive governance to locate and classify every data asset. Porter outlines a practical framework derived from PCI standards—secure storage, processing, and transmission—highlighting encryption at rest, in memory, and in transit as baseline controls. He stresses that merely treating security as a technology issue stalls investment; instead, he advocates quantifying cyber risk in monetary terms using the FAIR model, which translates potential breaches into concrete financial losses that resonate with business leaders. Illustrative examples include calculating breach costs for 50 million records at $20 per record, yielding a $30‑$100 million exposure, and deploying web proxies to block risky sites while monitoring attempts. Porter also notes the importance of a crown‑jewel approach—identifying critical data such as personal information or intellectual property—and tailoring defenses, from availability‑focused resilience to IP‑theft detection. He highlights the rise of proactive hunt teams that seek compromises before they materialize. The discussion underscores that data security must become a cultural priority, aligning data owners with protection teams, embedding security into end‑to‑end business processes, and adapting risk appetite to industry context. Organizations that adopt risk‑quantified, data‑aware strategies will better safeguard their digital assets and sustain competitive advantage.

Original Description

In this CIO Talk Network conversation, Sanjog Aul speaks with Christopher Porter, Senior Vice President and Chief Information Security Officer at Fannie Mae, to explore how organizations can secure data in an increasingly distributed digital ecosystem.
As enterprises accelerate digital transformation, data is no longer confined to traditional boundaries. It exists across cloud platforms, endpoints, applications, and third-party environments. This conversation reframes data security from a technical function into a business-critical discipline that demands governance, cultural alignment, and risk-based decision-making.
Topics covered
Why traditional security perimeters no longer work
The “stored, processed, transmitted” framework for data protection
Turning cybersecurity into a business conversation through risk quantification
Rethinking the crown jewel approach to data security
Practical strategies to prevent data loss and leakage
The role of encryption, access control, and data minimization
Building a data-aware culture across the organization
Aligning business, IT, and security for enterprise-wide protection
Timestamps
00:00 Introduction to data security challenges
00:00:55 Current state of data across cloud and ecosystems
00:04:28 Why data security must become a business priority
00:08:26 Rethinking the crown jewel approach
00:11:34 Practical strategies to prevent data loss
00:14:40 Break
00:15:41 Aligning data ownership and protection responsibilities
00:18:42 Role of tools and the “find, protect, transform” model
00:23:45 Building a data-aware culture
00:26:18 Leadership alignment and collaboration
00:27:37 Closing remarks
Cross Links
About CIO Talk Network
CIO Talk Network is a global platform where technology and business leaders share insights on leadership, innovation, and enterprise transformation. Through conversations with CIOs and senior executives, the network explores how organizations can navigate complexity and drive meaningful outcomes.
Connect with us on:
Don’t forget to like, share, and subscribe for more insightful discussions.

Comments

Want to join the conversation?

Loading comments...