John Graves is an innovative legal leader and Senior Counsel at Nisos Holdings, Inc. He has a diverse legal background at the intersection of law, highly regulated industry, and technology. John has over two decades of legal experience advising business leaders, global privacy teams, CISOs and security teams, product groups, and compliance functions. He is a graduate of the University of Oklahoma.
Here’s a glimpse of what you’ll learn:
- John Graves shares his career journey from litigation to founding his law firm and in-house privacy leadership to Senior Counsel at Nisos Holdings, Inc.
- How AI enables threat actors through synthetic identities, impersonations, and large-scale attacks
- Ways AI tools help defenders analyze data to uncover risks
- The risks of adopting AI without proper governance
- When companies should employ human risk management
- How tabletop exercises help teams evaluate and prepare for AI-related risks
- Guidance on when tabletop exercises should be conducted and who should participate
- John’s personal cyber tip
In this episode…
AI is fundamentally changing the cybersecurity landscape. Threat actors are using AI to move faster, scale attacks, and create synthetic identities that are difficult for companies to detect. At the same time, defenders rely on AI to sift through large amounts of data and separate the signal from noise to determine whether usernames and email addresses are tied to legitimate users or malicious actors. As businesses rush to adopt AI, how can they do so without creating gaps that leave them vulnerable to risks and cyber threats?
To stay ahead of evolving cyber risks, organizations should conduct tabletop exercises with security and technical teams. These exercises help business leaders understand risks like prompt injection, poisoned data, and social engineering by walking through how AI systems operate and asking what would happen if certain situations occurred. They are most effective when conducted early in the AI lifecycle, giving companies the chance to simulate attack scenarios and identify risks before systems are deployed. Companies also need to establish AI governance because, without oversight of inputs, processes, and outputs, AI adoption carries significant risk.
In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels chat with John Graves, Senior Counsel at Nisos Holdings, Inc., about how AI is reshaping cyber threats and defenses. John shares how threat actors leverage AI to scale ransomware, impersonate real people, and improve social engineering tactics, while defenders use the technology to analyze data and uncover hidden risks. He explains why public digital footprints of executives and their families are becoming prime targets for attackers and why companies must take human risk management seriously. John also highlights why establishing governance and conducting tabletop exercises are essential for identifying vulnerabilities and preparing leaders to respond to real-world challenges.
Resources Mentioned in this episode
- Jodi Daniels on LinkedIn
- Justin Daniels on LinkedIn
- Red Clover Advisors’ website
- Red Clover Advisors on LinkedIn
- Red Clover Advisors on Facebook
- Red Clover Advisors’ email: info@redcloveradvisors.com
- Data Reimagined: Building Trust One Byte at a Time by Jodi and Justin Daniels
- John Graves: LinkedIn | Email
- Nisos Holdings, Inc.
- “Real AI Risks No One Wants To Talk About And What Companies Can Do About Them” with Anne Bradley on She Said Privacy/He Said Security
Sponsor for this episode…
This episode is brought to you by Red Clover Advisors.
Red Clover Advisors uses data privacy to transform the way that companies do business together and create a future where there is greater trust between companies and consumers.
Founded by Jodi Daniels, Red Clover Advisors helps companies to comply with data privacy laws and establish customer trust so that they can grow and nurture integrity. They work with companies in a variety of fields, including technology, e-commerce, professional services, and digital media.
To learn more, and to check out their Wall Street Journal best-selling book, Data Reimagined: Building Trust One Byte At a Time, visit www.redcloveradvisors.com.
Intro 0:01
Welcome to the She Said Privacy/He Said Security Podcast…
Jodi Daniels 0:15
Hi. Jodi Hi. Jodi Daniels, here…
Justin Daniels 0:34
Hello. I am Justin Daniels…
Jodi Daniels 0:59
And this episode is brought to you by…
Justin Daniels 1:52
You, once again, scrolled while I was reading.
Jodi Daniels 1:58
You’re supposed to know what we say.
Justin Daniels 2:02
I think you’re doing that just to try to confuse me.
Jodi Daniels 2:05
I think the summertime of recording in the afternoon…
Justin Daniels 2:15
Okay, we’re gonna have an interesting guest today.
Jodi Daniels 2:20
All our guests are interesting.
Justin Daniels 2:22
This is a topic we don’t cover as much…
John Graves 2:55
Hey guys. How are you doing?…
Jodi Daniels 3:03
Add a could be a dog…
John Graves 3:17
Sure. So I started out of law school…
Jodi Daniels 4:53
Ooh, that is interesting…
John Graves 5:08
It’s been exciting. Never dull…
Justin Daniels 5:15
At Nisos, you’ve got a unique vantage point…
John Graves 5:33
The obvious is that the use of the AI…
Jodi Daniels 8:15
Can we talk a little bit more about some example use cases…
John Graves 8:37
And so, you know, AI, as you can imagine…
Jodi Daniels 10:20
Thank you for sharing that…
Justin Daniels 10:32
So kind of a little bit about how, you know…
John Graves 11:01
Yeah, yeah. I think the first step is…
Jodi Daniels 13:09
John, when should companies think about bringing you in…
John Graves 13:18
Yeah, so for misos, specifically…
Jodi Daniels 15:33
That was really helpful…
John Graves 15:44
Yeah, it’s really important…
Justin Daniels 15:54
Like, for example, Jodi, if you’re a large publicly traded company…
John Graves 16:36
That’s right. And I think we’ve seen too…
Justin Daniels 17:57
So what is advice that you might have for maybe business leaders…
John Graves 18:17
I think tabletops are really important…
Jodi Daniels 21:16
John, I’m curious people do all different length tabletops…
John Graves 21:32
Yeah, so that’s a really tough question to answer…
Jodi Daniels 23:29
Helpful. Thank you so much for sharing…
Justin Daniels 23:37
So John, do you have a best cyber tip…
John Graves 23:44
Yeah, so my best cyber tip is not a technical tip…
Jodi Daniels 24:37
That works really well…
John Graves 24:59
I think that’s always a good idea…
Jodi Daniels 25:18
I actually think that is accurate in any field…
Justin Daniels 25:53
I think my podcast was being podcast host…
Jodi Daniels 25:59
I don’t know. Maybe we should ask our kids…
John Graves 26:13
So I’ve got some really talented kids…
Jodi Daniels 26:35
That sounds so fun…
John Graves 26:47
Sure, so our website@www.nisos.com…
Jodi Daniels 26:59
Amazing. Well, John, we’re so excited that you came…
John Graves 27:07
It was absolutely a pleasure…
Outro 27:17
Thanks for listening to the She Said Privacy/He Said Security Podcast…
Privacy doesn’t have to be complicated.
As privacy experts passionate about trust, we help you define your goals and achieve them. We consider every factor of privacy that impacts your business so you can focus on what you do best.







