
Sanjay Castelino is President of Skyhigh Security, bringing 30+ years of technology and product leadership. Before Skyhigh: Chief Product and Customer Officer at Snow Software; VP Marketing and Revenue Operations at Spiceworks; VP Product Marketing and Management at SolarWinds. He oversees Skyhigh's full product and customer lifecycle.
Sanjay Castelino is helping organizations protect sensitive data as AI, SaaS, cloud, remote work, and agentic systems expand the modern attack surface. At Skyhigh Security, Sanjay focuses on Secure Service Edge, data protection, AI governance, and helping enterprises control how people and systems access and use critical information. Skyhigh Security recently won a Fortress Cybersecurity Award for its work protecting organizations from internal and external data threats.
In this episode, Russ and Sanjay discuss why data protection has become central to enterprise security. Companies want to move faster with AI, but they fear sensitive data leakage, unauthorized access, and loss of control over intellectual property, customer information, and regulated data.
Sanjay explains how Skyhigh helps organizations unify protection across web, cloud, SaaS, private applications, endpoints, mobile devices, browsers, and AI services. A key starting point is visibility. Organizations need to know where sensitive data lives before they can protect it, which is why DSPM, or Data Security Posture Management, has become so important.
Russ and Sanjay also discuss shadow AI, secure browser controls, WebSockets, copy and paste risks, and why traditional web protection is not enough for modern AI use. Sanjay shares how Skyhigh can identify sensitive data, apply policies across environments, and block risky actions like copying protected content into public AI tools.
A major theme is zero trust for AI. Sanjay explains that companies can no longer think only about users outside the network coming in. With AI agents operating inside systems at machine speed, security teams must also think inside to inside and inside to outside. That means applying zero trust controls to human and non-human users, specific applications, specific data sets, and specific moments in time.
Topics Covered:
[00:01] Welcome and intro, Sanjay Castelino and Skyhigh Security
[00:31] What Skyhigh does in Secure Service Edge
[01:00] Protecting data from internal and external threats
[01:49] Why data protection became central to Sanjay's work
[04:18] Explaining value to CISOs with crowded security stacks
[05:00] Secure browser controls without disrupting users
[06:18] Reducing incident resolution time from hours to minutes
[08:01] Why data protection was overlooked during the SSE rush
[10:07] Why data now lives across web, cloud, private apps, and AI
[11:39] DSPM and finding sensitive data across environments
[12:20] Connecting data visibility with policy enforcement
[13:42] What surprises customers after AI governance goes live
[14:30] Why organizations underestimate AI service usage
[15:13] Why WebSockets create new AI data protection challenges
[16:00] Blocking sensitive copy and paste into AI tools
[17:49] Best-of-breed versus platform consolidation
[18:30] How to test whether a platform is truly integrated
[19:00] Processing massive data sets fast enough to protect them
[21:14] Shadow AI and unapproved employee tools
[22:00] Different corporate risk tolerances around AI
[22:53] Zero trust for human and non-human users
[23:22] Rethinking zero trust for agentic AI
[24:00] Inside to inside and inside to outside security models
[25:15] Why agentic AI makes zero trust more urgent
[25:45] Human-targeted attacks and AI-targeted attacks
[26:42] User behavior, impossible travel, and access controls
[27:33] Moving from blocking AI to enabling it safely
[28:19] Final thoughts on secure AI adoption









