
Stay Calm, Move Smart: Leading Through Data Risk Without the Knee-Jerk Reaction | Data Xposure - Ep 21
Host: Mike Hamilton, VP, Marketing - Exterro
Guest: Tom Mullane, Associate Director of E-Discovery & Cyber Investigations - RTX
When a legal hold breaks down, a cyber investigation escalates, or a new technology challenges an established workflow, the pressure to act immediately can overwhelm the need to act wisely. For data risk leaders, the difference between a measured response and a reflexive one can determine whether an issue is contained—or compounded.
In this episode of Data Xposure, brought to you by Exterro, Thomas Mullane, Associate Director of eDiscovery & Cyber Investigations at RTX, draws on nearly two decades of experience spanning information governance, eDiscovery, privacy, and legal technology. He explores how leaders can maintain perspective under pressure, separate urgency from panic, and make defensible decisions when facts are incomplete and stakeholders are demanding answers.
The conversation also examines the tension between innovation and the status quo: when established processes provide necessary discipline, when they become barriers to progress, and how teams can introduce change without creating unnecessary risk. Listeners will leave with a practical framework for staying composed, challenging organizational defaults, and moving forward with clarity rather than reacting out of fear. It reflects Data Xposure’s focus on candid, actionable lessons from practitioners managing real enterprise data risk.
Apple Podcasts | Spotify | YouTube
Mike Hamilton (00:00:08): Hello, welcome to Data Exposure, the podcast for data risk leaders, brought to you by Exterro. I'm Mike Hamilton. A legal hold breaks down, a cyber investigation escalates. A new technology walks in and challenges the way you've always done the work. In every one of these moments, the pressure to act immediately can drown out the need to act wisely. And for a data risk leader, that difference can decide whether a problem gets contained or gets a whole lot bigger.
My guest today has spent nearly two decades living in these exact moments. Tom Mullane is Associate Director of eDiscovery and Cyber Investigations at RTX, with a career spanning information governance, eDiscovery, privacy, and legal technology. He's the person in the room when everyone else wants to hit the panic button. We're going to talk about how you stay measured when the stakes are high, how you tell real urgency from the manufactured kind, and how you challenge "This is how we've always done it," including all the noise around AI, without creating new risk in the process. Hey, Tom. Welcome to Data Exposure. Thank you for joining us here today.
Tom Mullane (00:01:35): Hey, thank you for having me. Good to be here.
Mike Hamilton (00:01:38): It's funny, Tom and I were talking before this, and we've known each other for 15 years, so I think in eDiscovery years, that puts us as... really old senior citizens.
Tom Mullane (00:01:49): Yeah. Back when nobody knew what they were doing, everybody was trying to figure it out.
Mike Hamilton (00:01:55): Well, that's a great segue, Tom, to my first question. I don't think anyone grew up, I know I didn't, and say, "I want to run eDiscovery and cyber investigations." What was your path, and was there a moment you realized this was the career and not just a job?
Tom Mullane (00:02:12): Yeah, definitely. My path, well, going way back, I was always a history, economics guy, like a liberal arts guy in college, liked that stuff. Liked the idea of precedent and that kind of thing, but ended up going into IT and building a career in IT up until around 2005, when somebody tapped me on the shoulder and said, "Hey, we're going to bring eDiscovery in-house, and we think that you might be a good fit for that." And I said, "That's really cool. What the hell is eDiscovery?" I had a lot of learning to do. I read for the first two or three months on the job, just to bring all that up and figure it out. And it was really like, "We need you to come in and stand this up and make this thing, and then it's just going to run, and that's going to be good." And I'm thinking, "All right, so I'll go do this, and maybe I'll go do something else."
I think if you're looking for a moment in time when I was like, "This could be a place where I could stay and make a home," I think I would trace that back to a meeting at Morgan Lewis, sort of a little meet and greet thing, bunch of other eDiscovery people from some large organizations. And realizing that everybody was right at the beginning of this thing. That this is just the tip of the iceberg. There's a lot of runway here, and that being impacted by changes in the law as the courts figured things out and set precedent, built some case law, and changes in the technology in terms of how people store and use data, and then also technology and the tools of how people were going to be able to actually do eDiscovery. That between these three things, that there was always something that was going to be changing, and this was going to take a long time to unravel. At that point, I was like, "All right. I'm going to be here for a while, and I may as well dig in and try to get as good at it as I can."
Mike Hamilton (00:04:08): And now you sit at a place-- This podcast is called "Data Exposure" because it's for data risk leaders. Back then, 2005, it was more of a litigation support type of job, I would imagine. How did you evolve as the profession started to grow, change, get bigger?
Tom Mullane (00:04:29): Well, I think it became starting out as trying to figure out how to handle it, how to get data. How to gather data. And as you began to realize that not a lot of people really had a lot of education in this and that a lot of outside counsel that came in wanted to do things their own way, and that there were going to be problems in standardizing and creating something that was repeatable and defensible, and that there sort of needed to be a focal point, a center of information, center of excellence, if you will, who can really kind of quarterback all that and pull it all together. That's a tall order for me at the time. It still is, because I'm not a lawyer. I can't just whip out my JD. I have to build my credentials in other ways, in terms of just credibility in the organization. But having support at high levels within your organization, if you're in a position that I'm in, is tremendously helpful. But trying to centralize the knowledge and centralize the process and building that out was when all those things are going to come together, and you're going to have to build that into something.
Mike Hamilton (00:05:40): I want to touch on something that you just referenced, credibility. You've been in this industry for a long time. How did you go about building that credibility?
Tom Mullane (00:05:50): Yeah. That's a really good question, actually. Really what it has to do, for me, most of the credibility that I built is, number one, certifications are helpful, benchmarking with peers, heavy interaction with peers, getting to know people at conferences and wherever else, reading the case law, everybody puts out a case law digest, even if it's the same case. Maybe Exterro releases something, and maybe Shook has a different take on it, Morgan Lewis says something else. But keep digesting all of that stuff so that either you can say, "Mr. Attorney, I know you're saying this, but you really ought to look at this because this is a case that might align with the direction that you should not be going in, and maybe you ought to turn around." Things like that. But I think really sort of knowing what the tools are, knowing what the data sources are, knowing what the case law is, and having the answers when you're on a call or in a meeting, and eventually getting it turned around to the point where people are coming to you for an opinion and saying, "We think we're going to do this. Is there any reason why we shouldn't do that?"
Mike Hamilton (00:06:55): And Tom, he's spoken at Exterro's user conference, I don't even know how many times, Tom. I'm thinking I see five or six times. And I know you've spoken numerous times at the eDiscovery Institute's conference. You're a thought leader. You've really built out and really worked on honing that credibility, which in networking, you should see Tom at some of these events, he knows everyone. That's really great advice that I've seen Tom put into action. One thing I do want to kind of have you compare and contrast is when you first started in eDiscovery, everything probably is, in most cases, in some organizations, is a fire drill. Everything's on fire, everyone's wanting an answer. Everyone probably thinks, "Hey, just go out and collect that, that's easy." Even though it might be structured data or somewhere in the cloud or something that you can't easily get to. What did that pressure actually feel like, and how has your relationship to that feeling changed over the last 15, 20 years?
Tom Mullane (00:07:59): That's a good question. Everything starts out as a fire drill. It's evolution, learning to, from an IT mindset, to go work with folks on the legal side. At the risk of making enemies, I'll say I don't think that there's any other profession that I can think of that rewards procrastination like the legal profession, because something could always settle. Something's going to change, right? So lawyers, eventually good lawyers, eventually figure out that they need to know stuff, but they don't really want to do too much work out ahead of something because... the rules are going to change. Something is going to change, something's going to settle, something's going to go away, or they're going to get some other demand letter. From an IT perspective, where you want to be prepared and especially on the security side, where your preparation, proactivity, and everything else, to come at it from that mindset and understand that you've got to dial that back. You've got to be prepared for what might happen in terms of mental preparedness and thinking about it. But to go and do a bunch of work out ahead of something that may or may not happen is definitely a path to sadness and wasted time. Learning that and learning that when there's a fire drill, assessing what's really the problem. Do we need to evacuate the building, or is it really just a garbage can that we need to go shoot it with a fire extinguisher? What really is the problem, and what do we need to do right now to make it better? And focus on kind of baby stepping the thing and okay, we're supposed to do this giant eDiscovery project for this, that, and the other thing. What do we need to do today? What do we need to do by the end of the week? And is that realistic? And if it's not, how can we adjust that? How can we help our attorneys or our coworkers or outside counsel make a case that what is being asked for is not realistic, and maybe what is realistic out of that? I think really kind of taking it apart when you have a fire drill, and remaining calm and trying to figure out what is the emergency? Is the place burning to the ground, or do we just have a turkey that's burning in the oven? What's the problem?
Mike Hamilton (00:10:11): Mm-hmm. That's a really good point around real urgency versus manufactured urgency. And what I kind of deciphered from your answer was that collaboration, that transparency. Is that how you kind of came to tell those things apart in your experience?
Tom Mullane (00:10:30): I think you have to understand what you're working on. Prioritize it. This sort of speaks to prioritization. How do you spend your time? Is the emergency a class action lawsuit? Is it a government subpoena? Is it some sort of patent case where one of your key pieces of technology is being challenged? Well, you're going to sit up and pay attention to that because that's something that you need to prioritize. If it's a smaller matter, you certainly can't ignore anything, but you're maybe going to figure out maybe the bar is a little bit lower on where you need to get something that's reasonable and how you're going to approach it. But to me, a lot of it is qualifying what the matter you're working on is. Almost anybody in this is going to work on everything from massive stuff that's significant litigation to small stuff. I also think that if you've got outside counsel involved, or if the attorney internally that you're working with is very focused on their project, it's the most important thing in the world to them. And you have to step back from that and say, "What's the most important thing in the world to the business?" And tying back to these are the things that I'm working on. What are the ones that impact the business the most? And prioritize along that, again, with no case left behind.
Mike Hamilton (00:11:51): And I'm guessing some of those conversations are tough conversations to have with some of those attorneys, with outside counsel. How do you go about having those conversations and creating that transparency across the business?
Tom Mullane (00:12:05): Yeah, I think nobody wants to be told their kid is ugly. So it's really a great deal of tact. And again, it goes back to what you can do. Instead of saying, "You don't matter, Mike," but it's like... "I don't have a lot of time. This is what I can do for you today." Perhaps they certainly don't want to hear that something else is more important, but just this, "There are other constraints on my time, and I realize this is important to you. It's important to me as well. Here's what I can do today. Again, here's what I can do tomorrow, and where we're going to be in a week." Try to figure out what you can do and set an expectation rather than go, "Hey, man, I just don't have time for you." So context is king.
Mike Hamilton (00:13:00): Speaking about legal, it's a slow-moving field. I think we both can say that sometimes it doesn't innovate as fast as other industries. And that phrase of, "This is how we've always done it," precedence- all those things come into play in the legal profession. How do you tell when it's time to question how we've always done it? And how do you bring that up? How do you issue spot that, Tom?
Tom Mullane (00:13:30): I think you have to be wary of that every day. And I know you're kind of blaming legal, but there's plenty of that in any organization. Change is not something people get comfortable with. But I do think that, again, the change is driven by the case law, which, as you say, it is slow. It's a building process, something built on top something else. By nature, it's slow. You have to accept that. By contrast, though, is technology on the other side, particularly the tools that we have now to doing e-discovery, the tools that have been built in. Look at what Exterro was 15 years ago versus what it is now. And some of the other products, Relativity, all the big data products, the AI stuff that's now coming to bear. That's some fast-moving stuff, and I think that you don't necessarily have to argue with the, "This is the way we've always done it." You can nuance that and say, "We're going to kind of do it the way we did it, but we're going to add something." And I look at things like predictive coding and how that was going to be it, right? That's 10 years ago, 10? But that was it then. I think that largely flopped because of its name. If that had been like review prioritization, which is really what it is- or something like that- that would've been a different story. But predictive coding was a scary name. So where I'm going with that is I think that how you present that change so that you don't freak people out, and these aren't stupid people, they're smart. It's just... presenting it in a language they can understand and really present it to them on their own terms, I guess is what I'll say.
Mike Hamilton (00:15:21): Tom, we talked about predictive coding, and I was thinking, really, e-discovery professionals were kind of at the forefront of AI, if you really think about it. We were pushing for this 10, 12 years ago, and now it's really hit the mainstream. Let's talk about AI in its current form, and there seems to be a lot of tension right now around AI and what it can do, what it shouldn't do. As a practitioner, you've seen a lot of hype cycles, as you've noted. How do you personally decide what's real and what's noise when it comes to modern AI?
Tom Mullane (00:16:02): Yeah, I think that there's a couple ways to interpret that question. What's a real tool that really works versus maybe what's real content versus a hallucination coming out of AI? I'll start by saying I think that we're at the golden age of AI right now- that the tools are okay. They could be better, but in terms of the content that AI has been built on, what it's ingested- that's been sort of real content created by human beings, whether it's movies or the entire internet, and now apparently ripping through books and reading books and then destroying them. But taking that information in as well. So it's all human-created stuff, but at the same time, generative AI is starting to create its own content- whether it's Facebook posts or stuff on the internet, articles, whatever, and AI is going to literally start breathing in its own exhaust and taking in its own content and learning on that. If the content is bad, if it's hallucinations, then that's going to dilute the quality and the purity of the AI by just ingesting garbage and turning it into more garbage. And obviously, there's been a couple of people who have tested that by seeding fake reports and things like that, and all of a sudden they're showing up cited in articles. So I think right now, the quality in terms of generative AI may be as good as we see it. I've a very large mistrust for AI going forward. I'm really worried about how it is going to be able to separate fact from fiction as it creates things going forward. That said, in terms of what AI can do in terms of cutting through garbage and giving it hundreds and hundreds of documents and asking it, keep confining it and saying, "Based on this, give me information out of that," I think the quality there is going to be very good, and I think that is only going to get better. So I think in terms of what it can do for you to give you information, making order out of chaos, taking a big thing and making it a sentence is tremendous. But if you're looking for it to create on your behalf, I think you need to be very careful where you draw the boundaries- and increasingly so going forward.
Mike Hamilton (00:18:31): In your perfect world, the AI would be quarantined to a set of documents or data where it couldn't live outside of that to bring in false data or hallucinations. Would you agree? And so what are those areas within e-discovery where you're excited about AI?
Tom Mullane (00:19:54): I think really in terms of excited, I think automating. I think there's a lot of runway. Again- pulling back instead of looking at how I can do my job better- but how AI can help the business and the company and the profession better. I'd love to see the AI just take the complaint, give it the complaint, and say, "Based on this, go look at all the email that is here. Go look at all this, that." Confine it, again. And based on this complaint, tell me if this complaint has any legs, or if this accusation has any legs. Tell me if we have this. Tell me if we're in a lot of trouble. Tell me if we're not. Give me the top 10 documents to read that are really relevant to this. So I think if you're going to back it off to that point, who are the custodians that I should put on hold for this? Are there SharePoint sites that I should go-- I think in terms of looking at the data in aggregate and focusing in on stuff that can really help you do your job- I think that really could be extremely effective. You could kind of leapfrog across a lot of the process. Somebody's got to be making sure that the AI is doing the right thing. If for no other reason, just for the optics of the whole thing. You kind of let the AI just run it, and that was it? So yeah, I do think you need some guardrails, some human guardrails. You've got to figure out what are appropriate, where you want to apply them. But I don't think it's too hard to apply them, and I think you can have the AI help build them even for you.
Mike Hamilton (00:23:36): Another question I have for you, Tom, is around, I think something you touched on, is AI in an open box. For me, when ChatGPT, all these, Claude, came out, you could ask it anything, and you didn't really know what you could do with it. So for e-discovery professionals, and I know I needed this, would it be helpful to have AI that is templatized? That's almost like a workflow, a set use case that it asks you, it prompts you with these questions that the user can see where it needs to go rather than kind of thinking in the back of their head, "Well, I really am curious about this. Can AI do this for me?" How much of a prescriptive path do you think we need to put professionals on so they use AI responsibly and effectively?
Tom Mullane (00:24:25): Yeah. It's funny. I think on one side of my brain is going repeatable, defensible- and that's leading to a templatized or agentic sort of approach to using AI. And then the other side of my brain is reminding me that I just tried to fill out an online insurance quote form and like- none of the fields are right, the information wasn't there, and it was completely useless to me. I think that there's some room for templatization and- certainly standardization of some sort. But I do think that having enough flexibility in that approach to make sure you're getting the answers you want, and you're not limited in your professional activities to try to get things done by the construct of whatever you've made to drive this forward. So somewhere there's sanity where there is enough construction for repeatable defensible, but enough flexibility to take on almost anything and give meaningful answers.
Mike Hamilton (00:25:22): We had another guest, he was just on a couple of weeks ago. His name was Andy Hansel. He was director counsel at Target. And he brought up a really interesting point that I want to pass by you and get your thoughts on. So his thoughts around AI is we're going into an AI arms race, and he looked at it from a plaintiff's attorney perspective. That serial litigation is going to become a lot more prevalent. The complaints are going to be coming a lot more fast, a lot more furious. It's going to be hard for the in-house legal departments and law firms to keep up with the amount of litigation that could come from leveraging AI to automate and streamline how you file a lawsuit. What are your thoughts on that? Do you agree with that? And if you do, how would you, if you were looking in your magic eight ball in the next five years or so, how would you go about protecting the organization from a large increase in litigation?
Tom Mullane (00:26:22): Yeah, I think that's interesting. And my perspective is different than Andy's on that- simply because he's a consumer, right? They're a consumer product company- Yeah.
Tom Mullane (00:26:33): ... where they're going to have a lot of that. They've got a gazillion employees, very transactional employee base. They've got a lot of customers that are human beings that are in their stores, real estate, they've got all kinds of stuff, and so they're going to have those transactional sort of things. My experience has been different where there's very few customers, there's no customer data, product liability is definitely not of a serial nature. My experience in aerospace is that it's a problem with an engine, potentially, or an alleged problem with an engine, God help me. But that sort of thing, where contract disputes and intellectual property disputes. So it's definitely a different perspective, and I can see where that would be a problem for him and potentially, employee matters are always a thing, right? It's almost now, you wait until you get a DSARs request from somebody who was just terminated, and you go, "Oh, that's probably a reason to issue a legal hold, because they're not asking for fun." And so I think that it does open the door to that, to the potential where people who, whether it's individuals or whatever, can start saying, "What are my avenues of attack here? Or how can I litigate? Can I make some money off of this?" So I think it really depends on what industry you're in, but I certainly see Andy's point, and I would be very concerned if I was him.
Mike Hamilton (00:28:03): We're running out of time here, but you're one of the most seasoned professionals in e-discovery that I've met. You've been in the industry for a really long time, Tom. You know your stuff inside and out. One question I want to ask you is around just how you kept your sanity. I think a lot of people in this industry, not to say that it's more stressful than others, but it's like we've talked about, it's continuously changing. Is there some technique or something personal that you do that's, "Okay, I take 10 deep breaths, and then I come back and I look at my computer." Are there any things that you do that's unique that could help out other people that are in your position?
Tom Mullane (00:28:40): That's a good question. I think the discipline requires a person of a certain temperament who is not a fire alarm puller, right? And so I think that my demeanor has served me well in just that I'm not someone who's going to... I'm pretty calm when things are going sideways. So that's helpful. And I think in terms of staying calm, it's always about, "Okay, we've got this big problem. Everybody's running around. What can we do right now that we can make some inroads?" And try to, how do you eat an elephant one bite at a time? Figure out what bites you can take now that'll move it forward instead of backing up and looking at the enormity of the thing and going, "This is just incredible. How are we ever going to do this?" So, a measured approach and calm demeanor. Don't obsess. So when you're done, take some time to get away from it, to the extent that you can. But keep your head, I guess, is where I would say.
Mike Hamilton (00:29:51): Well, last question I have for you, Tom. What advice would you give to people that are looking to make a career out of e-discovery or somewhere in the data risk field? What can they do to see the success that you've had, and how could they build on that?
Tom Mullane (00:30:09): That's a really tough question because I think that the potential for AI to change this field so rapidly in the next few years is, am I going to even exist in three years, right? Is my position gone? Do we not need someone who's going to marriage counsel between counsel and the data people, and try to figure out where things are? And a lot of what my position is is trying to look at the data, look at the matter, and consult on a path, and I think that that may be drying up. So I think in terms of somebody who wanted to get into this and learn about it and do it, certainly read a lot. Read about case law, take some legal classes, learn about IT. Try to listen a lot and go to a lot of conferences, listen to a lot of smart people talk, read a lot on the internet. But in terms of what the profession's going to look like in the future, that's anybody's call. That's a blue sky.
Mike Hamilton (00:31:18): Well, Tom, you've talked on a variety of different panels at different conferences, and I think as professionals, we get stuck in, "Okay, I'm doing my work, head down, just going to do what's asked of me to get things done." Going to conferences can be tough for some people, and I think hearing that is great advice. What are some conferences that you would suggest to our listeners that you think you would get a ton of value? It's really easy to meet people. What are those conferences that stand out to you?
Tom Mullane (00:31:52): Well, I, of course, would probably be kicked off the podcast if I didn't start by saying the Exterro Conference, which is good. I think, to me, the Exterro Conference is a very good practitioner-level conference, right? Some conferences are very heavy lawyer-based and pontificating about the fine points of the law and other stuff. I think the Exterro Conference is sort of more trenches level, right? Certainly, the legal element is there, but it's operations, and it's a little bit more on the IT side. So I think that's a pretty good one for someone who's doing a little bit of both. I love EDI. I'll do stuff with the eDiscovery Institute. I think their stuff is really, really good, very focused on connecting people and helping people build networks, which is what a big part of being successful in this business. The SoCal is great. David Cowan's stuff is really, really good. A lot of energy there, never the same format twice, a lot of changes, very interesting. And I think that I didn't go to Georgetown for a number of years, but I went last year, and I think that there's been a lot of new life breathed into the Georgetown Conference, and I really enjoyed that. For me, I really like to focus on e-discovery-based stuff, and I think that sort of leads me in that direction. I think if you were more like a legal ops-type person, or you were looking to maybe grow out of e-discovery or expand, then you start to look at ILTA and things like that to try to get more into the legal ops side. But those are sort of a few of my favorites.
Mike Hamilton (00:33:27): Well, thank you, Tom. It's been a pleasure to have you on the podcast. Always engaging, and really enjoyed talking with you again.
Tom Mullane (00:33:36): Same here. Good to talk to you, Mike.
Mike Hamilton (00:33:38): Well, thanks, Tom. Take care.
Mike Hamilton (00:33:41): This is exactly the kind of steady, been-there thinking this show's for. If there's one thing I'm holding onto, it's that first reaction in the room is usually the wrong one, and that staying measured isn't about being slow. It's refusing to let manufactured urgency make the decision for you. Thanks for listening to Data Exposure, brought to you by Exterro. If this episode was useful, follow the show on Spotify or Apple Podcasts, and pass it along to someone in your legal, security, or data team who could use a calmer head in harder moments. You'll find every episode at exterro.com/resources/inside-data-exposure. I'm Mike Hamilton. We'll see you next time.