TinyTechGuides

Attackers Are Winning the AI Race | Stuart Madnick, MIT

Data Faces Podcast — On Location · CDOIQ Symposium 2026

Stuart Madnick, professor at MIT, on why attackers use AI better than defenders, the lesson of the Target Wi-Fi breach, and treating data as a manufactured product.

YouTube player

Listen: YouTube  ·  Spotify  ·  Apple Podcasts  ·  Amazon Music

About Stuart Madnick

Stuart Madnick on the Data Faces Podcast at 20th Annual CDOIQ Symposium

Stuart Madnick is a professor at the MIT Sloan School of Management and founding director of Cybersecurity at MIT Sloan (CAMS). He co-founded MIT’s data quality program with Richard Wang and helped shape the information quality field from its start, and his research sits at the intersection of data and cybersecurity. He received a Lifetime Achievement Award at the 20th annual CDOIQ Symposium.

In this interview

  • How the Total Quality Management movement inspired treating data as a manufactured product
  • Why the risks of new technology stay an afterthought, from in-store Wi-Fi to AI
  • Why data you accumulate and never use is a liability that cannot be stolen if you delete it
  • How one cost-saving security decision ended up costing a company $1 billion

→ Browse all on-location interviews: Data Faces Podcast — On Location

Full transcript

David Sweenor 0:00 talking about crappy data. That part’s the truth, that’s part’s the truth. We’ll go, you know, five, 10 minutes or whatever. When we’re done, we’re done. I’ll do a quick, I’ll do an intro. Do you have any, just professor? Do you have any titles you want me to?

Stuart Madnick 0:18 Professor’s fine. Okay. Let’s just do it back there.

David Sweenor 0:21 All right. Erin, is everything on?

Stuart Madnick 0:23 Everything’s rolling.

David Sweenor 0:24 All right, we’re all centered? All right, here we go. All right, here we go. Hello and welcome to the Data Faces podcast on location. We’re here coming to you live at the CDO IQ event in Cambridge, Massachusetts, right next to MIT. Today I am here with Professor Stuart Madnick. Welcome to the Data Faces podcast.

Stuart Madnick 0:46 Pleasure. Glad to be here.

David Sweenor 0:48 So can you tell us a little bit about this event? You’ve been here since the beginning. Yes, actually before the beginning. And there was a standing ovation for you today and your colleague, Lifetime Achievement Award. That must feel pretty good. Yeah, a big surprise actually. It must be hard to keep surprises these days. So could you just tell us a little bit about the journey and the journey that got you here today?

Stuart Madnick 1:14 Well, I’ll try to keep it short because there’s many parts to it. But what I explained in the keynote I gave this morning, it goes back maybe almost 20 years before we started this CDL IQ symposium. About 40 years ago, maybe a little more than 40 years ago, many of you may remember, there was a thing called the TQM, Total Quality Management Movement. Oh, I remember that. And it had interesting insight. Prior to that point, people’s assumption was if you improve the quality of the data, it must increase the cost of the data, or cost of the product. Right, right. Cost of the product. But some people noticed that there’s so much wastage in normal manufacturing that if you eliminated the wastage, the product will be higher quality and could be less expensive. So this was a big revelation back in the era. So Rich Wang and I thought about it a bit and said, well, data is a kind of manufactured product. And the same kind of principles that could apply to making better quality cars or better quality equipment could be applied to producing better quality data. Okay. So that started us on this journey over the past 40 years.

Speaker 3 2:24 Wow.

Stuart Madnick 2:25 So we started off, we called that at the time, Total Data Quality Management, TDQM program at MIT. Then later on we became the MIT Information Quality Program. And then finally 20 years ago we started the CDOIQ program here. So that was kind of the initial idea and kind of how it’s evolved over the past 40 years.

David Sweenor 2:50 Right, so you sort of invented almost a whole category of both the market and professional careers now. You know, there was zero CDOs, and now there’s, I don’t know, probably a couple thousand of them out there, at least.

Stuart Madnick 3:02 Well, one of the important reasons why we created, and I give Rich Wang really the credit. He’s the guy, we talk about things, and he makes things happen. We talk about it. is that 20 years ago, CDOs did exist, but they were rare and far between. And having an opportunity to get together, meet others, share experiences, and basically build an emotional support network on the market is very important to establishing a new profession, a new environment. So I think that has been a subtle and maybe not well understood, but a very important role that this symposium has served.

David Sweenor 3:37 Okay, okay. This is sort of an off-topic question.

David Sweenor 3:40 So the name of the show is Data Faces.

David Sweenor 3:43 And it was designed to get behind the people in their professional careers. So I always like to ask, it should have been an icebreaker, but we missed that one. So what did you want to be when you grew up?

Stuart Madnick 3:55 Oh, God. Besides being a fireman or something? That’s a valid answer. Everyone didn’t want to be. No, no, no. I’m not sure if it’s relevant to this. Actually, it turns out I… originally thought about going into medicine. Okay. But it turns out I fainted the sight of blood. I thought that might be an occupational hazard. Someone did suggest I could specialize in hypochondriacs. Right. But I don’t know if that works out well or not. So that went away. The second thing is when I actually arrived at MIT, now almost 63 years ago, my original plan was was become a nuclear engineer. I don’t know how many people in your audience go back that far in the past, but this is kind of the early stages of the nuclear era. Sure. And I remember there was, I don’t know, ready kilowatt, we’re going to make electricity, it’s going to be free. Yes. Things would get fantastic and so on. It seemed like the way of the future. So I arrived at MIT as a freshman with that in mind. And while I was taking some classes, they had this thing called, I think it was called a computer or something. Right, right. You might want to take it out for a run and see what you think about it. And it seduced me. Okay. So, so much for my nuclear engineering profession.

David Sweenor 5:06 Well, you know, we can be thankful that you took the path you did because you’ve added a lot to the industry and just the whole world. So we’re appreciative of that. You do a lot of work in cybersecurity. Yes. So… What do enterprises need to think about with AI and agentic systems in terms of cybersecurity? Is it changing the game? Is it creating more risk? Probably all of the above, but I’d love to hear your perspective on this.

Stuart Madnick 5:34 Well, I’m going to kind of step back away and address another topic we talked about briefly about change in general. Sure. And there’s the old cliche, the more things change, the more they stay the same. Right. So in many ways, there are movements forward, but there’s some overarching things that tend to persist over time. So taking your notion both on data quality, so a lot of data quality issues we identified 20, 40 years ago are better now but not totally solved. So some of the things persist for a long time. answering your first question, I’ll address this other one. One of the things I mentioned in my keynote is the issue of data quality so much easier if we could standardize things. For example, some people do things in metric systems. Sure. People do things in the imperial system, whatever you want to call it. One of the things I asked a quiz question for the audience here, who in the United States first recommended or proposed that the U.S. goes metric? The answer was George Washington. Okay. That goes back a ways. It does. It didn’t take off then. Well, it should have because I think we crashed some spaceships, you know, due to some errors in systems along the way. Exactly. So some things take a while, 250 years and counting. Right. But getting back to your question regarding cybersecurity and AI. Mm-hmm. One of the things we observe regarding cybersecurity is whenever there’s a new shiny ball, people want to run with it. Right. And thinking about what are the possible consequences tends to be very much of an afterthought. The example I use before I get to AI, many of you may remember Target, which is a large department store chain. Sure. was hit by a major cyber attack, I want to say 18, 20 years ago, well back. It turns out one of the reasons why, they were one of the first retail organizations to install Wi-Fi throughout their stores. So they knew all the great benefits, you don’t have to worry about cabling, moving wires around, They didn’t say, oh, may there be any risks? May there be any opportunities for thefts to break in? The answer was nobody thought about that until after the day.

David Sweenor 7:45 They were looking for the efficiency gains and the productivity gains.

Stuart Madnick 7:48 Exactly.

David Sweenor 7:48 Okay.

Stuart Madnick 7:49 Roll the clock forward. What do people think about AI? How much more will it save us? How many people can it displace? is it going to create any dangers for us, is not the first thing that comes to their mind. And we have seen time and time again that in many ways, AI has been a great example because it is a multi, what’s the typical, there’s a name for this, multi-purpose tool. It can be used by the defenders and it can be used by the attackers. Right. And it turns out, by all measures we’ve seen, the attackers are being much more aggressive and much more efficient at using it than the defenders are.

David Sweenor 8:27 Okay.

Stuart Madnick 8:28 So you’ve just given them a better weapon to attack you with.

David Sweenor 8:32 Okay. So then how do, like, What are the security leaders supposed to do? I mean, do they need to put that at the centroid, like before the data? I mean, security is a big topic in general. And so, like, how should I think about getting started with this? Because people, like here, we’re at a data conference. Data, data, data.

Stuart Madnick 8:52 And you do security, security, security. Well, you don’t want the eight-hour answer, so I’ll give you just a couple pieces of it. Sometimes things are so… incredibly simple and obvious after the fact. Let me roll back the clock to Target. I think it was Target, I may have the company wrong. But one of the companies that was cyber attacked getting billions of bytes of data from their data centers to Latvia, except they have no stores in Latvia, they have no suppliers in Latvia, they have no customers in Latvia. Why are billions of bytes of data being shipped there every single day? Nobody thought to ask that question. And we see that over and over again. So in other words, a lot of times, just open your eyes and think about what can go wrong. We often use the term resilience. It’s one thing to try to keep attackers out. It’s another thing to say, well, you can do as best you can and try as you can, but if they do come in, how do you minimize the danger? I’ll give you one last example, because I don’t want to take too much of your time. When we did our early work in data quality, one of the first thing we did, what are the things you want to measure? One of the ones on our list, we came up with 20 different measures, was curation. How do you safeguard, or not, how do you store your data essentially? Sure. Safeguard it, if you will. One of the things you realize, in the case of the Target case, data was being stolen that Target had been accumulating for 20 years and never used. If you didn’t have that data, guess what? It couldn’t be stolen. So that’s just a simple example from data quality that carries over to cybersecurity. And there are lots of these overlaps. A lot of basic principles apply.

David Sweenor 10:42 Well, speaking of data quality, I sort of asked you as a joke in the beginning. You’ve been talking about crappy data on the record. We’ve been talking about this forever. Are we going to continue to talk about crappy data forever?

Stuart Madnick 10:55 Or has it gotten better, or has the dimensions of crappiness changed? Well, the answer is yes and yes. Because on the one hand, and this is one place where AI can often be some help to you, it can help to improve your data. It can help to identify data that looks suspicious, it doesn’t make sense, it’s not consistent. The trouble is, AI systems need data. They’re data hungry. So the need for data is even larger. So the question is, maybe the amount of current data you have, maybe you cut down on the croppiness of it. But all the new data you’re gobbling like crazy with, what’s going on with it? So I think we’re winning in some circles and losing in other circles. I don’t have the score. It’s like the World Cup. I don’t know what the latest score is.

David Sweenor 11:41 Okay. But the race is on. There we go. Here we go. And then maybe lastly, there’s a lot of CDOs here, so it’s not just in the event name. They’re actually here. For CDO walking out of your keynote, what should they do differently when they walk into work the next day? Get a license.

Stuart Madnick 11:58 Well, unfortunately, the list is quite long. And one reason why we have so many speakers here over the next two days is hopefully there’s lots of lessons that we pick from other people. So I’ll just put one or two of them on the table to be thinking about. And one of them is what I just said before. I can realize the emotional desire to move forward as fast as you possibly can. But at the same time, you know, running out the door to realize there’s no stairs there is not a good idea. In fact, there was an article, I just read it, I think a day or so ago. It was an open letter or whatever it is from 120 Nobel Prize winners of last number that says, hey, AI guys, slow down. Oh. Think where you’re going. Think. Think. So I think the idea is whether it be AI, whether it be new data initiatives, whatever it is, doesn’t mean it’s the bad idea, but think hard about all the benefits you’re hoping for, but at the same time, put on the same scale, what risks am I going into? One of the examples I use, I won’t go into it, it was a major cyber attack. I won’t mention the name, it’s public, but I won’t mention the name of it. And there were a number of decisions that were made, like we could do A or B. B is cheaper, and we can do A next year. Sure. No one’s satisfied, but that decision turns out is going to cost you $1 billion. Right. Because by doing B instead of A, you’ve opened yourself up to a risk that’s going to be a major consequence. So the idea is pause long enough so you do an intelligent risk assessment. How fast to move forward is safe, and when do you want to slow down? I think that is one of many, but hopefully that’s one useful thing to think about.

David Sweenor 13:38 All right, that is super useful. So Professor Stuart Madnick, we are coming to you live from the CDO IQ Conference, co-founder, Lifetime Achievement Award. Thank you for joining the Data Faces podcast on location. Thank you. Pleasure being here. Cheers.

Speaker 3 13:53 Bye.