Data as the Foundation: Leveraging AI While Maintaining a Solid Cybersecurity Footing

By Haines Eason

Aug 21, 2025

Share this post

AI graphic

The right data insights at the right time—every marketer out there will tell you these are the key ingredients to organizational success. But, with the advent of AI and the AI-ification of everything, what and who can see your data (and your clients’) is becoming harder and harder to pin down.

Leaders from the GTIA Data Advisory Council, GTIA AI Advisory Council and Cybersecurity Task Force discuss what may be the most important challenge of the day, one every IT service provider (ITSP), MSP and tech vendor is likely wrestling with: How to structure, secure and govern data in an era when AI demands more of it—and faster access to it—than ever before.

Moderated by Robert Buda, President, Buda Consulting, the conversation at ChannelCon 2025 between Corey Kirkendoll, president and CEO, 5K Technical Services, Marc Menzies, president and CTO, Overview Technology Solutions and Danny O’Hanley, founder and CEO, Delmar Insights moved quickly from technical architecture shifts to cultural change, regulatory pressures and the risks of once-fringe-now-dominant edge computing.

From Data Lakes to Data Discipline

O’Hanley opened the conversation by noting that, in some ways, data architecture is coming full circle.

“We’re in a place now where with some of the risks of AI, like hallucinations or whatever the case may be in terms of some of the outcomes that are unexpected, we’re starting to find a new balance between having access to as much data as possible while at the same time structuring it in a way that actually makes sense,” he said.

For those who remember the data warehouse era, then the surge toward unstructured data lakes, the pendulum is swinging back toward structure.

Models need data in a specific format to perform reliably, and loose “dump it all in” strategies are colliding with security and compliance realities.

Kirkendoll added that the shift is not about past architectures being better so much as companies and organizations want to have greater control over what data can be seen by who ... or what.

“What we’re finding is the access to the data and the speed at which you’re able to do it and what it needs is really causing us some challenges. We see a lot of people wanting to shift back to central control, not an in-the-cloud kind of server. It’s kind of a hybrid model.”

From the cybersecurity vantage point, Menzies warns that the sprawl of structured and unstructured data—especially in AI-driven environments—is now a major attack surface.

“It’s not about protecting a file storage server anymore. If there’s sensitive information, that’s very hard to defend.”

The AI / Security Tension

Even as some voices are beginning to tout AI specialization, the majority still seems to believe that AI models thrive on more and more data. However, security frameworks aim to limit exposure, and friction is inevitable.

If a client dumps all their data into a lake for a new AI tool to crawl, then all bets may be off when it comes to accountability, something Menzies was blunt about.

“The challenge with AI is that you can’t hold it accountable. You can hold a person accountable. You can’t hold AI accountable with consequences. Maybe we’ll stop using the product—that’s really the only type of consequence.”

Kirkendoll said the only way to avoid compounding risk is to think about security before a single model is trained.

“If you don’t have it classified, protected, governed before you enable AI on it, all AI does is expand upon that and it’s very much harder to deal with. You need to know what your AI is touching, what it’s doing and where it comes from.”

O’Hanley brings the point back to fundamentals.

“I don’t know that we necessarily have to always reinvent the wheel. Data governance is certainly key in the process. Still to this day, I would say that there’s a renewed emphasis on training. At the end of the day, it’s just another tool.”

Regulatory Lag and Governance Gaps

Asked about evolving compliance frameworks, all three panelists agreed: Regulations aren’t moving as fast as AI adoption. Menzies pointed out that most major frameworks remain largely static.

“It’s more about interpretation and the tools that you’re using. I don’t see a ton of movement quickly on them, but sure, over time… maybe what you’re allowed to use AI for and what type of data it might be allowed to access.”

Kirkendoll noted that industry-specific rules are surfacing faster than general frameworks.

“We’re seeing in the legal industry and the healthcare industry, things from an HR and hiring perspective, I believe strongly (these) are going to influence some of the frameworks going forward.”

And O’Hanley believes the next big governance battleground will be data ownership. “I do think that we’re going to start to see an area of governance around ‘do we actually have permission to use this data that we want to implement as part of this model?’”

Building Cross-Functional Competence

Panel participants also agreed that data, AI and security can’t live in silos. O’Hanley believes there needs to be a base level of understanding of what the security requirements are, something that GTIA Member of the Year Matt Lee has also said. O’Hanley also emphasized that requirements should touch on what data tools like AI actually are going to have access to and what it should and shouldn’t do with it.

As for how to arrive at the right requirements, Menzies argued that mature change management is the best vehicle for building that shared understanding. “If all the teams are talking to each other in a structured format with a common goal, then they’ll all learn from each other. Communication is key,” and ensuring there’s an expert in place to guide the process is essential.

Kirkendoll tacitly agreed but zoomed out, stating he feels the starting point isn’t technical at all – it’s all about business alignment. “This is not a technical conversation. It’s a business conversation that’s saying, ‘where do I have the challenge?’ But he circled back to the common refrain of the day: “If I don’t set the stage and say what (AI) is going to do, then I could have an HR problem or something that is not even the cause causing me a whole other business problem.”

Edge Computing and Distributed Data

More and more, it seems speed wins —the tech world hasn’t quite gotten over its “move fast and break things” era. And, while that mantra is driving the advancement of AI products, should it apply to AI deployments? Yes, pushing AI to the edge—close to data and to desired audiences—promises faster insights and localized decision-making, but also magnifies risk.

Kirkendoll said pushing AI out to the edge is almost something “you have to do because of the power and the speed that AI is requiring you to come up with. But then it causes me an issue with security of how do I ensure the data is intact and encrypted. How am I going to protect (my data) and what makes sense for what I’m trying to do?”

To this end, O’Hanley underscored one first needs to know exactly what the business intends to do with its data before deciding where it lives or who or what can access it, a seemingly foundational process decision that, for the sake of speed, is not always addressed.

Menzies added an interesting idea here—that organizations revisit endpoint security and lifecycle management.

“When should (data) be purged and what process should it be purged with?” he mused. “You’re kind of taking some principles on endpoint computing and just applying it in a slightly different way.”

Operational AI: Lessons from the Field

Kirkendoll shared how his own company uses AI to capture, analyze and act on customer interactions. Their AI-enabled phone system records and transcribes every call, feeding consistent case notes into their PSA tool. The surprise benefit? It surfaces sales opportunities hidden in support conversations.

“What was crazy about that is it was shocking how much sales opportunity came out. That’s what we’ve been able to do—leverage it to figure out what it is that we’re missing and what it is that we have going down.”

However, Menzies immediately saw security implications.

“When something has access to everything, sometimes those conclusions shouldn’t be shared with certain people in an organization. Limiting what data it might have access to and what types of filtering the conclusions (go through)” are critical.

The Skills AI Can’t Replace

As the discussion headed towards its conclusion, the future became the topic of focus. Specifically, when the automation of entry-level tasks becomes commonplace, how do you grow the next generation of talent?

“As you start to solve level-one tasks,” O’Hanley asked, “how are you going to create the next level-two, level-three tech that’s going to own and operate and push the future of your business?”

In response, Kirkendoll envisioned a hybrid future. “I believe that they’re going to have to jump in when (AI) goes (down). ‘I’m a level one tech with a minor in AI. I’m a level two tech with a minor in AI.’”

But Menzies cautioned that removing too much trial-and-error from early careers could weaken skills. “We learn through failure. If something is doing that grunt work for you, you’re not getting that training that you would’ve gotten.”

Guardrails for the AI-Everywhere Era

From customers experimenting with every “shiny” AI tool to the reality that most small MSPs can’t handle every security demand in-house, the panel closed on pragmatic advice.

Menzies suggested treating unsanctioned AI tools as shadow IT: “Most of the time (clients) just sign up for something because it looked cool,” and they forget about it, effectively leaving open a backdoor to who knows where or what.

So, what’s a leader to do?

Kirkendoll said there’s no shame in outsourcing to fill expertise gaps. “You have to go find the expertise that you can partner with and figure out how to deliver. One day I may bring this back in-house, but before then I need you to come in and you are my expert.”

The takeaway? AI is no longer a side experiment—it’s embedded in nearly every business’ stack. But speed without structure is risky, and structure without cross-disciplinary buy-in invites chaos or worse. Whether data lives in a warehouse, a lake or on the edge, these panelists agreed: Security, governance and a clear business purpose have to come first.

How can you adopt AI?

GTIA Members: Check out these top AI use cases on the Member Portal.

Watch the ChannelCon 2025 rebroadcast!

Related Posts:

Artificial intelligence is a part of almost every tech solution or business process today. We asked IT industry leaders what to expect for AI in 2024.
By Scott Campbell / Jan 4, 2024

10 Artificial Intelligence Predictions for 2024

Did anyone have a tech conversation this year that didn’t touch on artificial intelligence? The consideration or adoption of AI functionality has filtered into almost any tech solution or business process today. And if not, likely soon. As we start a new year, GTIA asked leaders from its AI Industry Advisory Council, as well as other councils and GTIA regional communities, for their predictions on what to expect for AI in 2024. Here’s what they had to say:
MSPs across Hawaii are scrambling to help businesses impacted by the Maui wildfires. In some cases, their own lives have been upended too.
By Scott Campbell / Aug 22, 2023

Hawaiian Wildfires Are a Reminder for MSPs to Be Ready for Anything

Uli Kirkegaard was working from his home Aug. 8 in Lahaina, on the western shore of Maui, Hawaii, when the alert came in: Wildfires on the island were spreading rapidly and the town had to evacuate.