Transcript
Manoj Tandon:
Hello everyone, I’m your host, Manoj Tandon. Welcome to another episode of Dark Rhiino Security’s Security Confidential. Before I introduce today’s guest, I have to remind you — we all work for the algorithm. Please hit the like and subscribe button so we can continue bringing you this content and these incredible guests who generously share their knowledge.
Today’s guest is Tiffini Smith. Tiffini is a patent attorney licensed in the United States as well as in England and Wales. She has deep experience in privacy, cybersecurity, and AI governance. She has led global legal teams and advised executives and boards on cybersecurity legal strategy, incident response readiness, vendor risk programs, AI model risk reviews, and board-level governance. Tiffini, thank you for being here.
Tiffini Smith:
Thank you for having me. I’m thrilled to be here and excited for the conversation.
Manoj Tandon:
We learned off air that you’re originally from Louisiana, yet you’re licensed internationally and have worked all over the world. Tell us how that happened.
Tiffini Smith:
Yes, I was born and raised in Baton Rouge, Louisiana. I’ve lived in Ireland, the UK, France, Argentina, and Myanmar, among other places. My background is in electrical engineering — signal processing and software — before I went to law school.
In law school, I became fascinated with how legal systems evolve. Louisiana is unique because its legal system is influenced by French and Spanish civil law traditions, unlike the common law system used in most of the United States. That sparked my interest in comparative legal systems globally. Combined with a love of culture and working with people from different backgrounds, I pursued international opportunities. Living and working in different jurisdictions expands your perspective — and you become very aware of your own cultural lens.
Manoj Tandon:
You don’t realize how American you are until you leave the country. Especially when it comes to entrepreneurship and innovation.
Tiffini Smith:
Exactly. The U.S. regulatory model often allows innovation first, then regulation follows in response. Europe tends to regulate more proactively. That cultural and legal evolution shapes how business operates in each region.
Manoj Tandon:
Europe feels highly regulated — GDPR, for example. We don’t have a uniform federal privacy law in the U.S. How does that difference impact cybersecurity posture?
Tiffini Smith:
In Europe, when a directive or regulation is introduced — such as the Digital Services Act or EU AI Act — organizations are given a compliance timeline. Businesses evaluate impact, prepare, and adjust before enforcement. There’s a more structured, uniform approach.
In the U.S., frameworks like NIST provide guidance, but they aren’t mandatory unless tied to industry requirements. So cybersecurity often becomes driven by insurance requirements, vendor contracts, or regulatory triggers.
That said, regulation alone doesn’t prevent breaches. Large, highly regulated companies still experience major incidents. Compliance mitigates risk and liability — but it doesn’t eliminate vulnerability.
Manoj Tandon:
We’ve seen huge breaches across both Europe and the U.S. So what does compliance really get you?
Tiffini Smith:
Compliance provides mitigation — legally and operationally. If you’ve taken reasonable proactive measures, that reduces regulatory fines and potential damages. More importantly, readiness impacts response time.
A breach may still occur. But if you detect it quickly and respond effectively, you can limit the scale of damage. That reduces financial exposure and reputational harm. The reputational damage often lasts longer than any fine.
Think of it like insurance. You hope you never need it. But if something happens, preparedness can mean losing the garage instead of the entire house.
Manoj Tandon:
You mentioned people repeatedly. I firmly believe employees are the most underutilized cybersecurity asset in any organization.
Tiffini Smith:
I agree completely. Cybersecurity is not just technology — it’s a living system. Employees come and go. Training matters. Repeated training matters. IAM hygiene matters — turning off credentials when employees leave.
Often, vulnerabilities arise from identity and access management rather than sophisticated external hacking. And attackers can sit dormant in systems for months before activation. Human awareness is critical.
When employees understand why policies exist, they buy in. It becomes cultural — not just compliance.
Manoj Tandon:
How do you advise boards on mitigating cyber and AI risk?
Tiffini Smith:
Governance is foundational. Boards must establish structured decision-making around cybersecurity and AI usage. Risk is inevitable — the goal is rapid detection and effective response.
I strongly believe CISOs should have direct visibility to the board. Cyber risk is enterprise risk. Boards need technical insight translated into business impact — regulatory, financial, operational, reputational.
It’s about informed decision-making. The board must understand the tradeoffs and exposures.
Manoj Tandon:
Let’s talk AI. Once data is fed into an AI system, you can’t “untrain” it. How does that align with GDPR or CCPA?
Tiffini Smith:
This is where governance becomes critical. Organizations need AI usage policies. Employees should not be inputting confidential company or customer data into public AI tools without understanding the implications.
Every AI tool has terms and conditions that define how data is used, retained, anonymized, or incorporated into training models. Most people don’t read them. But those clauses matter.
Once data is ingested into a model, it may become part of residual knowledge. You cannot fully extract it. So organizations must consciously choose what data is allowed into AI systems and negotiate vendor terms where possible.
Blanket bans rarely work. Controlled adoption with policy, oversight, and vendor diligence is more realistic.
Manoj Tandon:
So adopt strategically rather than prohibit outright?
Tiffini Smith:
Yes. Evaluate tools. Pilot them. Understand data flows, retention, hosting locations, and vendor rights. Train employees on acceptable use. Make conscious decisions about what data categories are allowed.
AI governance isn’t optional anymore. It’s an extension of cybersecurity governance.
Manoj Tandon:
Are you training other attorneys on these issues?
Tiffini Smith:
Yes. I’ve trained commercial lawyers, employment lawyers, and others on how AI clauses, data usage terms, and intellectual property provisions impact risk. Understanding technical risk allows lawyers to draft stronger contracts and advise more strategically.
Legal support often prevents losses that never become visible. That’s hard to quantify — but extremely valuable.
Manoj Tandon:
Tiffini, this has been fantastic. Before we close, anything you’d like to share with our audience?
Tiffini Smith:
I’m launching a newsletter focused on practical insights around AI governance, privacy, and cybersecurity — both for businesses and individuals. I’ll be sharing speaking engagements and updates on LinkedIn, so please connect with me there.
Manoj Tandon:
Thank you so much for being here. This conversation opened many doors we didn’t have time to fully explore. We’d love to have you back.
Tiffini Smith:
I’d love that. Thank you for having me.
Manoj Tandon:
Thank you, Tiffini. It’s been a pleasure.
Chapter Titles:
00:00 Intro
02:28 Our Guest
05:48 Regulation across states and countries
09:48 Cybersecurity regulation culturally
14:00 Employee training and teaching them the Why
23:07 How do you mitigate against AI?
25:00 CISOs don’t understand how the business works
29:11 Does being compliant actually reduce your exposure?
34:00 Regulations on AI in your business
50:10 More about Tiffini
About Tiffini Smith
Tiffini Smith is a strategic legal executive and board advisor with over 20 years of cross-border experience in privacy, cybersecurity, and AI governance.
A U.S. Patent Attorney with bar admissions in the U.S. and England & Wales, she helps organizations navigate global regulations like GDPR, CCPA/CPRA, NIS2, Schrems II, and the EU AI Act while aligning legal risk with business strategy.
Tiffini has led global incident response readiness, vendor risk programs, AI model risk reviews, and board-level briefings, and is known for translating complex legal and cyber risk into actionable guidance for executives.
She also authors a newsletter focused on emerging data, AI, and regulatory risk.