Different Perspectives on the Same Risk: Josh Lewis on Cybersecurity, Law, and Building CybrLaw Central

Cybersecurity does not happen in a vacuum. The best security conversations are not just about tools, controls, or frameworks. They are about business decisions, legal exposure, governance, trust, and the people trying to make the right call when the answer is not always simple.

That is one of the reasons I’m so glad to feature Josh Lewis on Tech She Secures and introduce the work he is building through CybrLaw Central. I’ve known Josh for years, and one thing I’ve always appreciated is the way he connects the dots across cybersecurity, governance, risk, compliance, and now law. His perspective is practical, thoughtful, and grounded in how organizations actually operate.

As a licensed attorney and with a career spanning IS audit, cybersecurity leadership, GRC, and compliance, Josh brings a much-needed lens to the conversations happening across cyber, privacy, AI, legal risk, and business strategy. In this feature, he shares more about his journey, the vision behind CybrLaw Central, what leaders should be watching around AI and governance, and why the future of cybersecurity requires us to break down silos and speak a more connected language.

Career Journey & Origins

You’ve had such an interesting career path, from IS audit to cybersecurity leadership and now becoming a licensed attorney. What inspired those pivots, and how has each chapter shaped the way you think about security, governance, and risk?

All the moves within my career have come down to taking advantage of the opportunities that present themselves – and trying to do the little things ahead of time so I'm ready when they come. I’ve never been one that has my career planned out multiple years in advance. I just try to do the best I can in the role I’m in, try to identify my blind spots and where I need to improve, and work on those things. That approach has seemed to lead me into more and more opportunities. As far as becoming a licensed attorney, law school was always in the back of my mind. As I gained more and more experience in the GRC space, I realized that having a law degree would be another way to open up future opportunities. Once I had the degree, I decided to sit for the bar exam. I figured if I didn’t, I’d end up regretting it later on. Even though I’m not practicing, I look at it like another arrow I have in my quiver should more opportunities come along down the road.  

At Tech She Secures, we talk a lot about being bold, authentic, and driven. What has been your “BADdest” career moment so far, the challenge or decision that really pushed you, shaped you, or made you proud?

There are several throughout my career, but the one that most comes to mind is going to law school. I live in Nashville, TN and we're fortunate to have the Nashville School of Law here. It’s a four-year program and all the classes are at night. That allowed me to stay in my full-time role and also attend law school. Classes were two nights a week (three nights in the last year), so on those nights I worked and then went to class from 6:30 to 10:00 pm. The first few months were definitely challenging, but I got in a pretty good rhythm after that. I started the program in the fall of 2019, and COVID hit during the last part of my first year. The entirety of my second year was remote, which also added a different challenge. At that time, my work was also remote, so I was spending a lot of time in my home office on class days. The program really helped me with time management, prioritization, and how to focus on the most important things. I’m really proud of the way I was able to manage everything and successfully navigate personal, work, and school life.

Law, Cybersecurity & Governance

Now that you’re a licensed attorney, how has your legal training changed the way you approach cybersecurity, compliance, and organizational risk?

I think my legal training helped me see cybersecurity as more than a technology problem – it’s really a governance and business risk problem. It also helped me think of different questions to ask. For example, who owns this risk? What assumptions are we making? How would we defend this decision to a regulator, a board, or a court if we had to? I also think legal training makes me a better translator between technical teams, legal resources, compliance professionals, and executives.

Where do you think organizations still struggle the most when it comes to understanding the connection between cybersecurity, legal exposure, regulatory risk, and governance?

I think organizations still struggle because they are treating cybersecurity, legal, regulatory compliance, and governance as separate disciplines. These aren’t separate disciplines – they are different perspectives on the same enterprise risk. The organizations that do well are the ones that work to break down these silos and bring the right stakeholders together to make informed, risk-based decisions.

Legal, technical, and business teams often speak very different languages. How do you build trust and collaboration across those groups, especially when the stakes are high?

I believe one way is to help everyone recognize that all these teams want the same outcome – to achieve their objectives, identify and reduce risk, and be compliant. They just view these through different lenses. If you’re able to create a common language around business risk and help the conversation rise above debating technical details or legal terminology, you can help the groups come together to make informed decisions. To me that’s how you can build trust and collaboration when the stakes are high.

CybrLaw Central

You recently launched CybrLaw Central. What inspired you to build it, and what do you hope it brings to the legal, technology, and cybersecurity community?

There were a couple factors that drove me to build the site. The first was a desire to stay informed of changes in the cybersecurity regulatory environment and general cybersecurity industry. Setting a public commitment to put out valuable content on a regular basis is a great way to force you to stay current within the industry. The second is the opportunity to share some of what I’ve learned so far over my career with those just starting their career journey. I also want the content to be delivered in a way that seasoned leaders within and outside the industry will get value from the perspective I’m bringing.

What gap did you see in the market, community, or broader conversation that made you think, “This needs to exist”?

There are a lot of great cybersecurity attorneys out there posting content. And there’s a lot of great cybersecurity experts out there doing the same. But I’m hoping that as someone that has spent time in Internal Audit, GRC, compliance, and is an attorney can bring a little different perspective to the conversation and that perspective can bring value to at least a few people.

As CybrLaw Central grows, what kinds of conversations, resources, or practical tools are you most excited to create for professionals working at the intersection of law, cyber, privacy, compliance, and risk?

I’m most excited about creating practical content that professionals can actually use in their daily work. I’d also like to follow your example and periodically include interviews with other industry professionals. I’ve had the privilege of working with many great cyber and legal thought leaders over my career and would like to bring their voice to this platform. Ultimately my goal is to help bridge the gap between business priorities, regulatory obligations, and technical realities.

Trends, AI & What Leaders Should Watch

What cybersecurity, privacy, legal-tech, or governance trends do you think leaders should be paying closer attention to right now?

The obvious answer is AI, but I think the trend to pay attention to is the changes occurring in the wake of AI adoption. Both the regulators and businesses are still trying to get their arms around AI. For businesses, they are not only still trying to figure out how to use AI, but what AI adoption means to the areas of cyber, privacy, legal, and governance. Those areas have to wrestle with how to use AI themselves, but also understand what policy and process changes need to occur to minimize the business’s AI risk. Regulators are trying to get their arms around AI also. I believe the acceleration of AI is also making regulators rethink the cyber-related legislation written a decade (or decades) ago. We’re seeing that in the healthcare space with the proposed changes to the HIPAA Security Rule. It’s very possible AI changes bring about other cyber-related legislative changes that don’t directly have anything to do with AI.

AI is moving fast, and organizations are trying to balance innovation, risk, compliance, ethics, and trust. From your perspective, where are we still behind when it comes to AI governance, legal frameworks, or practical risk management?

I think for most organizations AI adoption has outpaced AI governance. Companies are really pushing AI adoption. There’s a lot of potential value there, and in most cases they can’t wait around to figure out the best ways to use it. And in a lot of cases you’ve got to get it into the hands of the workforce to then figure out how it can help your business. This comes at the cost of governance and I think that’s going to show up even more next year. Those organizations that have given their employees access to an enterprise version of an LLM have likely given them pretty free rein on how to use it in an attempt to quickly see where they can get value from it. But there’s a cost associated with the queries by way of token utilization, and I think most end-users don’t yet understand tokens. We’re going to see pretty quickly that organizations are going to have to put some governance models in place around how their employees are using LLMs and which model/levels they use for different kinds of tasks because companies are going to see their licensing costs skyrocket. Then there’s the shadow IT risk – if you get your workforce used to using an LLM and then their usage is curtailed, there’s the risk they turn to their personal version to do the same kind of tasks they were doing before.

From a legal standpoint, I would say most organizations have likely implemented AI-related language into their contract templates. One thing I’m not sure has played out yet though is what happens when this language is breached. For example, if a third-party uses a company’s data to train their AI model in violation of the contract, what’s the remedy? Is it even technically possible to remove the data from the model? I think we’ll start to see the answers to these questions in the coming year.

Finally, from a governance and risk management standpoint, resiliency is going to become even more important. As companies move to replace human labor with AI and automation, system or network downtime becomes even more impactful to operations. An AI agent can’t turn to paper or work offline if the system is down like a person could.

Human Side & Looking Ahead

You operate in spaces that require a lot of focus, responsibility, and constant learning. What is one habit, activity, or reset ritual that helps you recharge and stay grounded?

There are the macro things I do like making sure I spend as much time with family as I can and taking time off from work at various points throughout the year. But on a micro level, the one big thing for me is making sure I get in some type of exercise every day. I’m a cyclist, and that’s what I enjoy most. Being able to get an hour bike ride in after work for me is a great way to reset and recharge. Funny enough I probably do some of my best problem solving and reflecting on those evening rides.

What’s next for you in this new chapter? Is there a bigger mission, vision, or impact you’re hoping to create at the intersection of law, cybersecurity, governance, and technology?

Since I’m just officially launching CybrLaw Central, really for me I want to build a habit of creating regular, meaningful content to post on the site. From there I’ll do what I’ve always done in my career – focus on getting a little better each day and see where it takes me. Thank you for having me on your platform!

Closing Reflections

What I really appreciated about this conversation is how grounded Josh’s perspective is. Cybersecurity, law, governance, privacy, AI, and business risk can all feel like big, complicated spaces on their own. But Josh has a way of connecting them back to practical decisions, real organizational challenges, and the need for teams to speak a more common language.

His perspective on AI especially stood out to me. So many organizations are moving fast, but governance, risk management, legal frameworks, cost considerations, and resiliency still need to catch up. That is exactly why conversations like this matter. We need more people who can help bridge the gap between innovation and accountability.

Thank you, Josh, for sharing your story, your perspective, and the vision behind CybrLaw Central with the Tech She Secures community. I’m excited to see how the platform grows and the practical conversations, resources, and voices it brings into this space.

If you haven’t already, I definitely encourage you to check out CybrLaw Central and follow along with what Josh is building. It is such a needed space for anyone trying to better understand where cybersecurity, law, governance, AI, and business risk are headed.

Maliha



























Disclaimer: The content on this blog and website reflects a combination of my personal experiences, perspectives, and insights, as well as interviews and contributions from other individuals. It does not represent the opinions, policies, or strategies of any organization I am currently affiliated with or have been affiliated with in the past. This platform serves as a personal space for sharing ideas, lessons learned, and meaningful reflections.

Next
Next

Carrying Hope Forward: Heidi Floyd on Patient Voice, Trust, and the Human Side of Healthcare