909Exec

← 909Exec21 jun · 40 min

Episode 63: Rethinking DLP: Nightfall AI’s Rohan Sathe on Data Protection in the Age of AI Agents

Episode 63: Rethinking DLP: Nightfall AI’s Rohan Sathe on Data Protection in the Age of AI Agents21 jun40 min

<p><strong>Introduction Summary</strong></p><p>Hosted by CEO Den Jones, &quot;909 Exec&quot; is a leadership podcast from 909 Cyber. Jones uses his 30+ years of enterprise security experience at companies like Adobe and Cisco to help executives navigate risk and transformation. Episode 63 features Nightfall AI co-founder and CEO Rohan Sathe for a deep dive into Data Loss Prevention (DLP).</p><p><br></p><p><strong>Main Topics Covered</strong></p><ul><li><p><strong>Entrepreneurial Journey:</strong> Sathe discusses his Silicon Valley roots and transition from the Uber Eats founding team to a cybersecurity founder.</p></li><li><p><strong>Consumer-Grade Enterprise Software:</strong> Sathe applies lessons from Uber Eats—building scalable products for low-switching-cost markets—to drive Nightfall’s enterprise product quality.</p></li><li><p><strong>Fundraising Strategy:</strong> Outlining Nightfall’s $65M total raise, Sathe emphasizes prioritizing investors who offer cybersecurity expertise and founder empathy over just capital.</p></li><li><p><strong>Flaws of Legacy DLP:</strong> After interviewing ~100 CISOs in 2018, Sathe found legacy tools were noisy, unpopular, and unsuited for modern cloud apps like Slack and Google Drive.</p></li><li><p><strong>Skepticism &amp; Pain Points:</strong> Jones details his historical skepticism of DLP, citing lost employee productivity, high false-positive rates, blind spots, and a heavy reliance on user-driven classification.</p></li><li><p><strong>Design Principles:</strong> Nightfall aims to make DLP &quot;invisible&quot; to end-users unless an incident occurs. Jones relates this to his view that security should be &quot;invisible, invincible, and inexpensive.&quot;</p></li><li><p><strong>Frictionless Architecture:</strong> Unlike SASE vendors that rely on latency-heavy network proxies, Nightfall targets optimal insertion points to eliminate user workflow delays and efficiently handle false positives.</p></li><li><p><strong>AI-Driven Risk Modeling:</strong> Replacing legacy regex rules with neural-network NLP and computer vision, Nightfall uses a comprehensive risk model evaluating identity, data lineage, and destinations to identify true incidents.</p></li><li><p><strong>Board-Level AI Concerns:</strong> As boards push for rapid AI adoption, AI data protection is now critical. This demands strict governance over autonomous agents operating at machine speed.</p></li><li><p><strong>Expanding Customers:</strong> Initially successful with tech-forward health and fintech companies, Nightfall&#39;s customer base has expanded into traditional sectors like manufacturing due to new AI security needs.</p></li><li><p><strong>Deployment &amp; Value:</strong> Nightfall ensures rapid deployment via lightweight endpoint agents and system APIs (avoiding proxies). It integrates directly with SaaS apps and AI platforms to track prompts and agent actions.</p></li><li><p><strong>Managing Data:</strong> Nightfall tracks data movement between corporate and personal environments, including AI tools like ChatGPT. It can monitor or block personal AI usage and track file lineage to determine corporate ownership.</p></li><li><p><strong>Policy Enforcement:</strong> The platform uses customizable policies to block risky actions, present user justification prompts, and offer optional bypasses tailored to organizational philosophies.</p></li><li><p><strong>Startup Strategy &amp; Compliance:</strong> Both agree expensive conference booths yield low ROI, favoring targeted events like dinners. Jones advises pursuing compliance primarily to unblock deals, noting it does not equate to actual security.</p></li><li><p><strong>Selling to CISOs:</strong> Acknowledging that CISOs are overwhelmed with pitches, they emphasize humility, understanding the customer&#39;s specific problems, and building long-term trust.</p></li><li><p><strong>Closing Reflections:</strong> Sathe admits he initially underestimated the importance of go-to-marke