Security1 distinct publisher3 min readPublished
Erika Dean says the alternatives are good enough now, and gives two questions that get an AI vendor rejected. The published excerpt names no technique to support the first claim.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The load-bearing word in Dean's rule is "almost." She recommends keeping production data out of QA and testing environments as much as possible, and says the technology has come a long way, so there is almost always another way to solve the challenge [7]. The historical excuse she cites is load testing against check images and SSN validation processes, where the data has to be very accurate and carry unique characteristics [4]. Those are also the cases where a substitute is hardest to trust, because the burden is proving the generated set still holds the awkward records that break the job. The published excerpt does not say how her team establishes that, and names no specific technique or tooling [14].
The claim is still worth something, just not as a citation. Coming from someone who says she has watched multiple employers do the opposite [3], including firms in financial services and healthcare [5], it moves "we cannot test without real records" out of the category of engineering constraint and into the category of decision. A team that keeps a production copy in QA now has to write down why, knowing the controls there are sometimes weaker than the ones in production [6].
The vendor filter is the most portable thing in the interview, mostly because it is cheap. Dean says what gets an AI vendor rejected is mostly vague answers about where data lives and how long it is kept [10]. Both questions have checkable answers, and neither requires the buyer to be capable of assessing a model. A vendor that cannot name a location and a retention period is telling you about the state of its own record-keeping, which is the thing you were trying to measure. She declines to name the product her team delayed [13], so the filter, not the case study, is the transferable part.
The one number in the piece is a week. Her team flagged prompt injection risk while agentic chatbot capabilities were being rushed out, red-teamed before launch, found exactly that gap, and held the release until it was closed on the backend [8]. She puts the cost at one added week, against a data leak as the alternative [9]. The mechanism worth copying is not the finding. It is where the test sat: in the pre-launch path, with the standing to move a date.
The headcount question has an answer in the same interview. Dean says governance and compliance is where she spends the least hands-on time day to day, and defends that on the grounds that evidence gathering and audits were automated with self-service elements built in [11]. The freed time goes to enterprise and product security, on her argument that attackers are using AI to exploit vulnerabilities faster [12]. Whoever ends up rebuilding a QA data set has to come from somewhere on a small team. In her account, the hours came out of the audit work.
Ranked by verification strength, evidence, and original report placement.
In a Help Net Security interview, Erika Dean, CISO at Tricentis, discusses keeping production data out of test environments and why she thinks the alternatives are good enough now.
Per the interview write-up, what gets an AI vendor rejected by Dean is mostly vague answers about where data lives and how long it is kept.
Dean says her internal requirement is the same one she recommends to Tricentis customers: do not use production data in lesser environments.
Dean says load testing for things like check images and SSN validation processes has historically been hard because the data must be very accurate and have unique characteristics, so companies defaulted to using production data.
Dean says the controls within a QA environment are sometimes not as strong as they are in production, and that segmentation should be maintained.
Dean says she always recommends keeping production data out of QA and testing environments as much as possible and finding alternate ways to test, because the technology has come a long way and there is almost always another way to solve for the challenges.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One self-reported interview, anecdotes anonymized
All content traces to a single Help Net Security Q&A with the subject. The policy statements are clearly attributable, but the load-bearing claims are not verifiable from the supplied material: the prevalence assertion is a career recollection, the held release and the rejected vendor are both explicitly unnamed, and the asserted adequacy of alternatives to production data is backed by no technique, tool, or test result. The excerpt is also truncated before the advertised small-team guidance.
Practice disclosed at one organization
The only adoption signal is one organization's self-described practice: an internal prohibition on production data in lower environments, red-teaming used as a release gate, and automated compliance evidence gathering. None is quantified, audited, or corroborated, and the article's own framing says the opposite practice remains common industry-wide, so ecosystem-level adoption of the recommended control cannot be scored higher than this single disclosure.
Verdict outruns the named mechanism
The framing that the excuse for production data in test environments 'has expired' and that alternatives are 'good enough now' is a strong, categorical verdict. The supporting material is one sentence — 'there is almost always another way to solve for the challenges' — with no technique, tool, or validation evidence for the very cases the answer identifies as hard (check images, SSN validation). The rest of the interview is sound practitioner guidance that is not overstated, which keeps the gap moderate rather than severe.
Vendor executive advising in her employer's market
The sole source is a sponsored-adjacent format — a vendor-executive Q&A — in which the speaker states she gives Tricentis customers the same test-data requirement she applies internally, so the guidance sits in her employer's commercial conversation with customers. There is no direct product pitch, pricing, or named competitor in the excerpt, and the vendor-diligence answers cut against easy AI adoption, which moderates the reading. The excerpt discloses no sponsorship or commercial relationship either way.
Attribution clear, verification limited
Confidence is moderate-low. What was said is unambiguous — the quotes are direct and the publisher and date are clear — so claims about Dean's stated policies and criteria are reliable. Confidence in the substantive assertions is much weaker: one publisher, one self-interested speaker, two anonymized anecdotes, no data behind the prevalence claim, and a truncated excerpt.
security
GitLab 19.3 puts agent runtime, inference models and secrets under one permission model1 distinct publisher
security
An agent guard that runs on your laptop, and cannot tell you whether anyone keeps it on1 distinct publisher
security
OpenAI's Computer History writes a plaintext log of the workday. Decide before staff opt in.1 distinct publisher
security
The customer is genuine and the payment is authorized: 55% of banks say scams dominate fraud1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026