Interviews 10.10.2024
Five Minutes With: A Global Data Governance Officer
Jakub Lewandowski is a lawyer, and data privacy and security counsel, currently representing Commvault as its global data governance officer.
Interviews 10.10.2024
Jakub Lewandowski is a lawyer, and data privacy and security counsel, currently representing Commvault as its global data governance officer.
I wear two hats: legal director and data regulator, and then compliance. I focus on our internal compliance, and about 60-70% of my time is spent on DORA and NIS2.
I studied Law in Warsaw, specialising in public law, policies, data privacy, and data regulation. The latter was a natural entry into the IT world. I wrote my thesis on the digitalisation of public administration. That was 18 years ago, though, and a lot has changed. In my summer vacations, I worked at Microsoft as an intern.
I was exposed to something completely different and loved switching from theory to practical and binary. I preferred the concrete material.
Yes, absolutely. After Uni, I worked at HP for over ten years before joining Commvault four years ago. I was attracted to Commvault’s decision to enter the SaaS market – that was one of the critical elements for me.
Being at the forefront of technological changes and the constant exposure I have to international regions, jurisdictions, and problems. It’s fascinating.
Time zones mean that I’m always on. I live in Poland, but speak with our global teams around the clock.
Getting various teams to speak to each other. You have to bring people from various departments and roles around the same table – especially when it’s legal. How do you get those people talking the same language? That’s the biggest unresolved challenge.
GDPR for sure. But the biggest shift has been moving from simple checklist compliance to managing risks. Awareness and how much businesses are prepared to spend on compliance have made the difference. Again, we find ourselves at the forefront of a tsunami wave of legislation, which will further evolve risk management.
The biggest correction that needs to be made is posing the right questions. We hear customers simply asking if they’re compliant. That’s valid, but it doesn’t address the real concerns beneath it. We need to focus on assisting organisations in complying with DORA and helping them understand that there’s no single solution to making them 100% compliant.
Understand your business. Figure out the data and assets you have and the associated risks. Understand what the impact on your environment would be if there were an incident. Set security objectives and understand your risk appetite. Talk with vendors who understand your complexity and requirements.
It’s more about learning from our customers and the sectors they serve. You can find somewhere to learn from everywhere.
I like tangible results, which I think is a natural fetish for most people in this industry. I’d like to be an archaeologist. With new technologies, there’s so much to discover.
Brace yourself for a fun ride. Cybersecurity reminds me of the fashion industry – certain things are rediscovered time and time again, and you see renewed interest in old terms, like business continuity. So be ready to look back.
DORA and NIS2 take up around 70% of my time.
Jakub Lewandowski is a lawyer, and data privacy and security counsel, currently representing Commvault as its global data governance officer. He has previously represented various leading technology companies, including Huawei, Microsoft, and Hewlett-Packard. This extensive experience has led Jakub to become an expert in global data protection law, cross-border data transfer strategies, and cybersecurity.