Is your company’s AI policy actually protecting your data, or is it completely worthless?
In this episode of The Signal Room, host Chris Hutchins sits down with cybersecurity expert Aaron Puckett (Executive Vice President at Managed Services Group) to expose the massive AI security risks that corporate boards and internal IT teams consistently miss.
Many organizations believe they are safe because they signed off on an official AI governance framework. But as Aaron explains, a paper policy means absolutely nothing if your technical infrastructure lacks real data loss prevention (DLP) and identity access controls. From well-meaning employees accidentally leaking Protected Health Information (PHI) into free versions of ChatGPT, to fast-paced AI-driven cyber attacks that bypass traditional perimeters, this video is a critical wake-up call for business leaders, CISOs, and operational executives.
---
Key Takeaways From This Video:
The "Shadow AI" Threat: How internal staff inadvertently expose proprietary data and customer intellectual property to public Large Language Models (LLMs).
The Illusion of Compliance: Why writing an AI policy is the easy part, but proving execution to auditors, SOC 2 inspectors, and HIPAA verifiers is where most companies fail.
AI vs. AI Warfare: How threat actors leverage artificial intelligence to execute sophisticated network breaches in milliseconds—compressing what used to take hours into seconds.
The Cyber Insurance Trap: Why configuration drift and loose employee permissions can completely void your corporate cyber insurance policy when a data breach occurs.
---
Chapters
00:00 - The dangerous mistake companies make with AI risk
09:07 - Why your AI policy means nothing without infrastructure controls
17:03 - Technical guardrails you need to set up right now
24:55 - The "Shadow AI" nightmare: How employees leak data
32:38 - Your first line of defense against modern AI attacks
44:44 - The critical question every business leader must ask this week
--
About the Guest:
Aaron Puckett is the Executive Vice President at Managed Services Group (MSG), a SOC 2 Type 2 and HIPAA-verified Managed Security Service Provider (MSSP). With over two decades of experience managing IT environments for highly regulated industries like healthcare and finance, Aaron bridges the gap between cyber security, operational compliance, and business EBITDA.
Connect with Aaron & Managed Services Group:
LinkedIn of MSG: https://www.linkedin.com/company/managed-services-group-inc/
LinkedIn: https://www.linkedin.com/in/aaronwpuckett
Subscribe to the channel for more expert insights on enterprise technology, data privacy, and executive leadership strategy!
---
#AISecurity #Cybersecurity #ChatGPT #DataPrivacy #AIGovernance #ShadowAI #HIPAACompliance #SOC2 #ManagedServices #BusinessStrategy
In this episode of The Signal Room, host Chris Hutchins sits down with cybersecurity expert Aaron Puckett (Executive Vice President at Managed Services Group) to expose the massive AI security risks that corporate boards and internal IT teams consistently miss.
Many organizations believe they are safe because they signed off on an official AI governance framework. But as Aaron explains, a paper policy means absolutely nothing if your technical infrastructure lacks real data loss prevention (DLP) and identity access controls. From well-meaning employees accidentally leaking Protected Health Information (PHI) into free versions of ChatGPT, to fast-paced AI-driven cyber attacks that bypass traditional perimeters, this video is a critical wake-up call for business leaders, CISOs, and operational executives.
---
Key Takeaways From This Video:
The "Shadow AI" Threat: How internal staff inadvertently expose proprietary data and customer intellectual property to public Large Language Models (LLMs).
The Illusion of Compliance: Why writing an AI policy is the easy part, but proving execution to auditors, SOC 2 inspectors, and HIPAA verifiers is where most companies fail.
AI vs. AI Warfare: How threat actors leverage artificial intelligence to execute sophisticated network breaches in milliseconds—compressing what used to take hours into seconds.
The Cyber Insurance Trap: Why configuration drift and loose employee permissions can completely void your corporate cyber insurance policy when a data breach occurs.
---
Chapters
00:00 - The dangerous mistake companies make with AI risk
09:07 - Why your AI policy means nothing without infrastructure controls
17:03 - Technical guardrails you need to set up right now
24:55 - The "Shadow AI" nightmare: How employees leak data
32:38 - Your first line of defense against modern AI attacks
44:44 - The critical question every business leader must ask this week
--
About the Guest:
Aaron Puckett is the Executive Vice President at Managed Services Group (MSG), a SOC 2 Type 2 and HIPAA-verified Managed Security Service Provider (MSSP). With over two decades of experience managing IT environments for highly regulated industries like healthcare and finance, Aaron bridges the gap between cyber security, operational compliance, and business EBITDA.
Connect with Aaron & Managed Services Group:
LinkedIn of MSG: https://www.linkedin.com/company/managed-services-group-inc/
LinkedIn: https://www.linkedin.com/in/aaronwpuckett
Subscribe to the channel for more expert insights on enterprise technology, data privacy, and executive leadership strategy!
---
#AISecurity #Cybersecurity #ChatGPT #DataPrivacy #AIGovernance #ShadowAI #HIPAACompliance #SOC2 #ManagedServices #BusinessStrategy

Comments