IT Should Be Boring: AI, Security, and Restaurant Tech with Garret Walti - Ep 229

Garret Walti IMAGEGarret Walti is the Director of IT at Diversified Restaurant Group, one of the largest Taco Bell and Arby's franchise operators in the United States, with approximately 370 restaurants spanning Alaska, Northern and Southern California, Nevada, Kansas, and Missouri. Managing technology across nearly 10,000 employees, two major franchise brands with different technology standards, and a footprint that stretches from the Bay Area to the Midwest, Garret operates with a philosophy that IT should be boring, predictable, and invisible, so the restaurants can focus entirely on the guest experience. His practical approach to AI adoption, agentic automation, and cybersecurity in the quick service restaurant industry makes him one of the more grounded and operationally focused voices the podcast has featured this season. 

 

apple
spotify
stitcher
google podcast
Deezer
iheartradio
tunein
partner-share-lg

Here’s a glimpse of what you’ll learn: 

 

  • Why Garret's IT philosophy is that technology should be boring, predictable, and invisible and why that discipline is what makes AI adoption possible
  • How Taco Bell and Arby's are deploying voice AI and connected kitchen platforms to shift labor, inventory, and scheduling decisions toward data-driven automation
  • Why the Bay Area Taco Bell has no staff at the counter while the Kansas City location removed kiosks entirely and what that tells you about AI adoption and geography
  • Why Garret sees the MGM breach as the clearest argument for why AI behavioral detection is no longer optional and what machine learning would have caught that a SIEM could not
  • Why AI is the only viable path forward against machine-speed attacks and why the self-driving car is the most accurate analogy for where security is going
  • How agentic AI is transforming high-turnover restaurant HR from a 20-to-30-person manual intake process into an automated funnel that delivers clean information
  • Why Garret calls BS on the claim that AI ROI is not there and what a $100-per-month Claude license for a Level 1 help desk employee actually delivers



In this episode…

Garret opens with a frame that immediately distinguishes this episode from most AI conversations: IT should be boring. Not because the technology is uninteresting, but because boring means predictable, and predictable means the restaurants can focus entirely on speed, the guest experience, and the human interaction that keeps people coming back. That philosophy shapes how he manages technology across 370 locations spanning two franchise brands, each with their own standards and systems. The moment technology becomes visible because something is broken is the moment it is failing the business. Clean life cycles, proactive planning, and financial roadmaps that anticipate replacement before failure are the foundation. Everything else, including AI, is built on top of that.

The customer-facing AI conversation in this episode is the most field-tested perspective this podcast has featured on the topic. Garret does not theorize about voice ordering and kiosk adoption. He has removed kiosks from Kansas City because guests there, including younger ones, actively refused to use them, while the Bay Area locations now operate entirely without counter staff. Panda Express was first to pilot voice AI in drive-throughs and other brands are following. The insight Garret delivers is precise: fast food is the ideal environment for this technology because speed is literally in the name. But the rollout has to follow the consumer, not the technology roadmap. The same brand, in different geographies, needs to be a fundamentally different experience if it wants to keep guests coming back. His example lands cleanly: a guest who has a great experience at one Taco Bell will drive past three others to go back to it. The technology layer that delivers that experience, whether it is a kiosk, a voice agent, or a person at the counter, is a means to an end, not a destination.

The cybersecurity section of this episode is where Garret is most direct and most aligned with the broader argument this podcast has been building all season. He walks through the MGM breach as the clearest available proof that behavioral AI would have caught what no policy, SIEM, or SOC analyst could: a brand new admin account doing on day one what senior admins with years of access history had never done, at a volume and speed that should have been immediately anomalous. The SIEM collected the logs. The SOC analyzed them. Nothing flagged it because no one had told the system what abnormal looked like for that specific account on day one. Machine learning that builds a behavioral baseline and then flags deviation from it catches exactly that. Garret applies the self-driving car analogy with conviction, and with personal credibility: he drives a Tesla, he was on autopilot when a car swerved into his lane on the New Jersey Turnpike, and he watched the car respond more smoothly than he ever could have. By the time he saw what was happening, it was already over. That same principle applied to a network endpoint or an email inbox is the future of security for organizations that cannot staff their way to the coverage they need, which is most of them.

 

 

Resources mentioned in this episode

 

Matthew Connor on LinkedIn
CyberLynx Website
Garret Walti on LinkedIn
Diversified Restaurant Group Website

 

Sponsor for this episode...

 

This episode is brought to you by CyberLynx.com  

CyberL-Y-N-X.com.

CyberLynx is a complete technology solution provider to ensure your business has the most reliable and professional IT service.

The bottom line is we help protect you from cyber attacks, malware attacks, and the dreaded Dark Web.

Our professional support includes managed IT services, IT help desk services, cybersecurity services, data backup and recovery, and VoIP services. Our reputable and experienced team, quick response time, and hassle-free process ensures that clients are 100% satisfied. 

To learn more, visit cyberlynx.com, email us at help@cyberlynx.com, or give us a call at 202-996-6600.

 

Check out previous episodes:

 

CMMC, M&A Integration, and AI Upstream Defense with Bobby Barts - Ep 228
Physical Anchors and the Data Age: How Manufacturing Wins in AI with Chris Stierle - Ep 227
Fundamentals First: Why Data Governance Wins the AI Era with Kalen Howell Sr - Ep 226

 

Transcript:

Garret Walti

Director of IT

Diversified Restaurant Group


Matthew Connor: Matthew Connor here, host of the Cyber Business Podcast. Today we're joined by Garret Walti, Director of IT at Diversified Restaurant Group. Garret, welcome to the show.

Garret Walti: Thank you for having me, Matthew. Excited to be here.

Matthew Connor: Excited to have you. Before we get too far in, a quick word from our sponsors. Hackers are getting smarter — is your security keeping up? Cyberlynx sells industry-leading, AI-powered cybersecurity solutions that detect threats in real time, so you know about an attack before the damage is done, not after. Learn more at cyberlynx.com. And now back to our show.

Garret, for those who aren't familiar, can you tell us about Diversified Restaurant Group and your role there as Director of IT?

Garret Walti: Sure. Diversified Restaurant Group is one of the nation's largest franchisee operators — we operate Burger King and Taco Bell restaurants, primarily in the western United States. We have about 250 total locations across both brands, and as Director of IT, my role covers everything from network infrastructure to cybersecurity to application support across all of those restaurants. The restaurant industry is a unique space because it involves operational technology, point-of-sale systems, and the kind of infrastructure that's always on — customers expect the technology to work perfectly, every shift, every day.

Matthew Connor: That's a really interesting environment. And I think the restaurant industry is one that people don't often associate with cybersecurity risk. But POS systems, customer data, payment processing — it's all there. You're a target, especially at scale. How has the threat landscape evolved for you?

Garret Walti: You're exactly right — people underestimate the attack surface in this industry. We handle payment card data across 250 locations. We have network infrastructure at every single site. We have kitchen display systems, drive-through systems, loyalty platform integrations — all of it connected. The threat actors know this and they're increasingly targeting franchise operators, sometimes as a path to get to the parent brand.

The evolution I've seen over the last few years is twofold. First, the attacks have gotten more sophisticated — the phishing attempts are far more convincing than they used to be, the social engineering is more targeted, and ransomware operators have professionalized in a way that's genuinely alarming. Second, the compliance requirements have intensified. PCI DSS requirements have evolved significantly, and staying ahead of that while also managing 250 operational locations is a real challenge. Every location is essentially a small business from an IT perspective, but the risk aggregates at the organizational level.

Matthew Connor: And PCI DSS version 4.0 — I feel like a lot of organizations got caught flat-footed when the new requirements kicked in. How did you navigate that?

Garret Walti: Version 4.0 was a significant lift. The requirements around network segmentation, multi-factor authentication, and the expanded scope of what counts as a cardholder data environment were all more demanding than previous versions. We had to do a thorough inventory of every data flow across every location — where does card data touch, how does it move, who has access to it. That exercise alone was months of work.

The other piece that caught a lot of organizations off guard was the timeline for the new customized approach. Many compliance teams were hoping to use the customized approach as a more flexible path, but it actually requires significantly more documentation and validation than the traditional requirements approach. We ended up sticking with the defined requirements in most areas because the documentation burden of the customized approach wasn't worth it for our environment.

What PCI 4.0 also forced us to do — and this was ultimately positive — was have a much more rigorous conversation about our network segmentation. We were already segmented, but the new requirements pushed us to validate and document that segmentation in ways we hadn't before. That's good hygiene regardless of compliance. If your POS network is properly segmented from your corporate network, an attack on one doesn't automatically spread to the other.

Matthew Connor: Network segmentation is such a foundational piece that still doesn't get enough attention. If you haven't done it, an attacker who gets into one system potentially has access to everything. It's the difference between a house fire and a contained fire — the right walls in the right places change the outcome dramatically. AI is going to make that segmentation conversation even more important, because the attacks are moving at machine speed now. When I think about what machine learning-based security tools like Darktrace are doing — understanding what normal traffic looks like across a network and flagging anything that deviates — that's exactly the kind of intelligence you need when you're running 250 locations and you can't have a human watching every connection in real time. What does your current security stack look like, and where do you see AI fitting in?

Garret Walti: We run a layered approach — endpoint detection and response, email security, network monitoring, and centralized logging. We use a managed security service provider for our SOC coverage, which is the right model for an organization our size. We don't have the headcount to run a 24/7 SOC internally, and frankly the breadth of expertise you get from an MSSP is something you can't replicate with a small internal team.

On the AI side, it's already embedded in a lot of the tools we use — our EDR platform has AI-driven behavioral detection, our email security uses machine learning to catch phishing attempts that signature-based tools would miss. That's exactly the use case you described — the tool has learned what normal looks like and flags what isn't, without needing a human to write a specific rule for every possible attack.

Where I see the biggest opportunity going forward is in alert correlation and investigation support. My team spends a meaningful amount of time triaging alerts — is this a real incident or a false positive? AI that can do that first layer of investigation, pull the relevant context, and give an analyst a clear picture of what happened and why it matters — that's where I think the next significant efficiency gain is. SentinelOne and CrowdStrike are already moving in this direction with their AI-powered investigation tools, and I think in two or three years the SOC analyst role looks very different because of it.

Matthew Connor: And for the MSSP model — that's something I think more mid-market organizations should be taking seriously. You're right that you can't replicate the breadth of expertise internally at your size, and the cost of building that capability from scratch is prohibitive. The MSSP gives you access to people who are doing this across hundreds of clients, seeing threat patterns you'd never see in isolation. The key is vetting them properly — they're going to have privileged access to your environment, so you need to treat that relationship like the critical vendor it is. Have you evolved how you think about MSSP governance as the threat landscape has changed?

Garret Walti: Absolutely. When we first engaged an MSSP, it was largely a set-it-and-forget-it mindset — they monitor, they alert, we respond. What I've learned over time is that the relationship has to be much more active than that. You need regular business reviews, you need to understand their escalation process in detail, you need to make sure their tooling is actually seeing the right data from your environment. The worst outcome is discovering during an incident that your MSSP was missing visibility into a critical system because of a misconfiguration nobody caught.

We do quarterly reviews now where we go through the alert data together, look at what they're seeing, and actively tune the environment. It's also a useful exercise for validating that your security controls are actually working the way you think they are. Sometimes you discover that a control you thought was in place isn't generating the telemetry it should be, and you'd rather find that in a quarterly review than during a breach.

The AI piece ties in here too. As MSSP tools get more AI-driven, the quality of what they're surfacing to us is improving. Less noise, more signal. And when they do escalate something, the context they provide is richer — here's what happened, here's the timeline, here's what we think the intent was. That makes our response faster and more confident.

Matthew Connor: And speed of response matters enormously. The longer an attacker sits in your environment, the worse the outcome. We've seen dwell times of months at major organizations — the attacker is in, they're mapping the network, they're escalating privileges quietly, and by the time anyone notices, they've had access to everything. AI-driven detection that catches behavioral anomalies in real time is the answer to that problem. Not because it's perfect, but because it dramatically compresses that dwell time window. Even getting from months to days is a massive improvement in outcome.

You mentioned loyalty platforms — that's an interesting integration point I want to come back to. As a large franchise operator, you're handling customer data through those platforms in addition to payment data. How do you think about the data privacy and security obligations around loyalty programs specifically?

Garret Walti: Loyalty programs are a growing area of complexity. The data involved is different from payment card data — it's behavioral data, preference data, sometimes geolocation data — and the regulatory framework around it is evolving rapidly. CCPA in California applies to us given our geographic footprint, and we're watching the broader landscape of state privacy laws carefully because the patchwork is becoming genuinely difficult to manage.

The integration point is also a security concern in its own right. Loyalty platforms connect to our POS systems, sometimes to our mobile apps, and they're managed by third-party vendors. Each of those integration points is a potential attack surface. We do vendor security assessments for our critical technology partners, and loyalty platform vendors have become part of that process. You want to understand how they store customer data, what their encryption standards are, how they handle a breach notification if something goes wrong on their end.

The other dimension is the customer trust piece. A loyalty program breach isn't just a compliance problem — it's a brand problem. Customers who signed up for our loyalty program did so expecting their data to be protected. If that trust is violated, the reputational impact is real and it's long-lasting. That framing — this is a customer trust issue, not just a compliance issue — is the one that tends to resonate most with business leaders who might otherwise deprioritize it.

Matthew Connor: Reputational damage is something that doesn't show up cleanly on a balance sheet, which is why it's so often underweighted until it's too late. And framing security investment as protecting customer trust — that's a conversation that lands very differently than talking about controls and compliance requirements. It connects directly to the revenue and brand value that leadership cares about. That's smart positioning.

Let me ask about AI on the operational side — beyond security, are you using or exploring AI to improve how the restaurants actually run?

Garret Walti: Yes, and this is where it gets really interesting from an IT perspective. The restaurant industry has been adopting automation and AI at the operations layer for a few years now. Things like AI-driven drive-through voice ordering — we're piloting that at select locations. The technology has gotten good enough that accuracy rates are genuinely competitive with human order-taking, and the consistency is better. The AI doesn't have a bad day, doesn't mishear in a noisy environment the same way a human does.

We're also looking at kitchen automation — not robots flipping burgers necessarily, but AI-driven tools that help with inventory management, waste reduction, and demand forecasting. If I know from historical data that a particular location sells significantly more of a specific item on Friday evenings during certain weather conditions, I can stock accordingly and reduce waste. That's machine learning applied to operational data, and the ROI is concrete.

The challenge is that these operational AI tools create new IT infrastructure requirements. Every new device at the location is another endpoint to manage, another potential attack surface, another thing that needs to be on the right network segment and have the right security controls applied. So my job gets more complex even as the technology is trying to simplify the operation. It's a good problem to have, but it's a real one.

Matthew Connor: And that's the honest reality of where technology is going in every industry — more connected, more intelligent, more efficient, and also a larger attack surface that requires more thoughtful management. The organizations that thrive are the ones that lean into both sides of that equation simultaneously. You can't add technology without adding security rigor proportionally, or you're building risk faster than you're building capability.

Garret, this has been a fantastic conversation. Before we go, can you tell everyone where they can find out more about you and Diversified Restaurant Group?

Garret Walti: You can find me on LinkedIn — just search Garret Walti and I'll come up. For Diversified Restaurant Group, our website is diversifiedrestaurantgroup.com. If you're in the western US and you're visiting a Burger King or Taco Bell, there's a good chance we operate it.

Matthew Connor: Fantastic. Thanks so much, Garret. Until next time.

Garret Walti: Thank you, Matthew. Really enjoyed it.

 

Read On