Eldad Chai, Satori | AWS re:Invent 2022
Eldad Chai, Co-founder and CEO of Satori, joins Mitch Ashley at AWS re:Invent to discuss how to implement a modern data security strategy, and key considerations around securing sensitive data in multi-cloud/hybrid environments. They also talk about strategies to achieve data democratization, trends in zero-trust data access, and the evolving concepts of data ownership.
Transcript
This is texturong TV. Welcome back. We are here at AWS re:invent 2022 in Las Vegas, Nevada at our Tech strong secret location for not bad Secret at the win for her studios here interviewing some great gas and thought leaders people talking about what's happened.
Not only at the conference but in the industry, so it's speaking of which the pleasure being joined By aldad Thai who is CEO co-founder with Satori. Welcome. Thank you.
Thank you pleasure to be here. Good to have you here. Tell us a little bit about yourself a little bit about Satori.
Yeah. I've been cyber security for last I think 15 years starting from application security part of the team to build a really cool CDN application delivery. We're acquired then work for a couple years for improva and then just started my own Satori.
Okay and purpose pretty big company too. So interesting. All right.
Well, we're talking data security, you know. Remember the days of should we go to the cloud isn't secure enough. We kind of got past that, you know, just taking our applications, but I think data security in the cloud is still.
Still a concerned not the security isn't but it's still you know, we don't know where all of our data is. We don't know what it is. We don't know who's using it as access to we don't know what's being created because it's so easily peripherent proliferates.
And I mean, how do you see the the state of the challenges? What are people struggling with? Yeah, and I agree.
With you know, tying this to back to other similar migrations to the cloud. So if you go to again, I'm coming from vacation security space before like we saw how that really drove a lot of business value for companies, but then everything around people and process just broke the minute that you move so you can't hire fast enough. You can't train people fast enough and any manual process around security governance quality just management of the infrastructure just breaks and then, you know, amazing companies grew like New Relic and Chef and puppet and Capstone improve Etc.
So we're kind of seeing the same thing with data, I think so, there's a huge business incentive to put data in the cloud. I think snowflake did an amazing job convincing the industry that it is safe in that proved out, but you can't hire enough data Engineers you can train if fast enough and every man in your process you had around data security just breaks. So even if you have the tools and the capabilities, they're not just Air from an operational perspective and that's kind of where we decided to focus on really help companies streamlined their security operations.
You can call it Theta secops and just be able to scale their data infrastructure. How is it primarily access control? Is it per state of protection what it were some of the probably not new challenges is just things have changed and now we're doing different things in the cloud.
Yes. So the two answers to that one is I I think one of the mistakes the biggest mistake companies do is they try to like split it into these capability driven. A domains and then attack them like I'm gonna classify all the data.
They don't figure out the rest that usually fails because you classified the data then what how do you make that in action? And if you classify the data, how real time is it is it so can you actually make use of that data? So we're kind of doing access management.
We're all so doing classification. We're also doing visibility and the idea here is focused on the business use cases the business use cases. There's an analyst they need to go and do their job with a blow on your data warehouse.
There's a bunch of context around the data. Is it sensitive is it relates to a specific customer? There's a bunch of contexts around the person that accessing the data.
What team are they in what kind of profile they have? Can they? So unless you have the full context on the identity and the data and be able to be in that moment and force an action.
It's really really hard and that's what we do. So you can say we're focused on data access but it ties into classification it ties into the identity part and the idea is to provide a solution and not just a bunch of capabilities. You need to piece together.
There's role-based access plan play a role. No pun intended here or is it is it so mixed in what the various use cases are. Yeah, role-based access controls play a big role in modeling how you want to interact with your data.
The challenge with role-based accessibility is just it's really hard to scale it because and we've seen this with many of our customers. They start that with that as a model, but then eventually people move jobs new projects are launch. You just hire more people and becomes a monster that's really really hard to manage.
So I don't want to say that role-based access controls. Inefficient tool it is an effective tool but it effective tool for specific use case. If you have Engineers that need access to production databases for five hours.
It doesn't make sense to manage that through arbuck. You want to have something more efficient and that's kind of how we help customers. We do temporary access we do persistent access, but again based on the business use case and not try to kind of do everything with one model which again doesn't scale in different scenarios.
Yeah. It's either the force fitted down a certain role based or everything's then exception. So now you're no longer exactly that zone exactly.
What what do you see happening in the conference? I mean, it's you know, we're back to fairly good size what they say about 60,000 people here and you know, there's a buzz there's an energy on the phone the show floor and it's not it's not like walking around last year when it's 20,000. It's a much bigger conference.
What are you seeing happening? So definitely it's the great event in If you haven't been to reinvent, I encourage everyone to join there's a really good opportunities to engage with all sorts of people from the industry. So that's that's amazing.
I'm happy to see that security is getting like a nice piece of attention. There's a section around security. There's a section around data that says tells you how important that is from obviously from an AWS perspective because that's going to drive their business and growth but from a market perspective they have been You know proven to be really customer oriented.
So you see that so I think just walking around aisles and looking at the different security products and data product is is phenomenal and I think that I love to see the focus on the business outcome. So it's less about I have this feature in this capability. It's really around how do we drive growth for our customers with data and through security even security companies are starting to use that narrative.
I think that's really really smart. And yeah, it's it's great. It is very very crowded.
It's definitely busy. How would you describe massatoria's kind of place in the market where you fit in? Yeah, so we're data security company, right?
I think like sneak if you take sneak as an example, there's security company, but they sell to developers. So we work with data Engineers. We work with data Architects because they eventually Make the decision of whether that's part of their Tech stack.
So we're data security company are focused within data security is really on this authorization a piece of the whole security stack. So you have your identity providers that's figured out you have your single sign on but then your authorization into Data is just fragment and distributed. So that is the problem that we solve and yeah, we fit within that category.
Do you span everything from you know applications and what you have within applications to just general access to data lake or at data resource or certain parts of that? So today we focus on anything that sits within the data store. So our customers have snowflake or Rich if Azure synaps Mongo elastic RDS and a bunch of other databases the idea there is companies are no longer building like monolith data stores.
They're building a data infrastructure and security should be consumed as part of that infrastructure. So we want to be that layer that solves security for all your data infrastructure. Not just one database.
We're starting to see more I would say application oriented. We're not going to cover the Erp for now and these kinds of applications but many of the applications just have a data interface with the backend. Like some of the customers have of our customers have support Engineers that need access to customer data through an application so we would cover that.
So basically our focus is data and anywhere data is is going to be stored today. We're really honed on the data infrastructure. Hey, you mentioned like Data stock apps almost the data Ops approach right the platform-based approach versus you know back in databases and application access to that.
How would you see people applying the idea of data Ops to what they're doing? Automation is the big big deal. I think.
People are learning more and more from devops. I think that devops. Principles are you know well accepted and people want to borrow them.
I think you see a lot of data engineers. Being less like dbas and more like software Engineers, which I think is a good the good thing. So it's really around automation DBT.
I think is a great example of how a company came in and helped just manage the whole data pipeline Landing Zone creation automatically and I think security needs to follow the same path. Mm-hmm. It's interesting.
I think early devops. I don't know if it's too strong to say that it kind of forgot about data but it wasn't a big part of how we thought about the pipeline and the workflow security elevated, you know with depth secops and like data and data Ops is starting to enter into that Fray too and to that perspective of how does data fit into the whole development workflow the pipeline and applications and infrastructure aspects because we have we have data we're capturing user experience Telemetry now in applications that go into observe. body tools but it's still data that we use for other purposes to Absolutely, I think once you move your data infrastructure to the cloud.
It's really easy to ingest a lot of data and it's really easy to open that infrastructure up for many many use cases. If you have your apis and you have all the tools that connect. That immediately creates like a next level of scale.
So unless you have a really good handle and how you're gonna operate that infrastructure. It's gonna be really hard for you to scale. We've seen companies that we're trying to like create this weird scenario where they're gonna move to snowflake, but they want to borrow the same.
Database Administration process they had and apply them there it doesn't work. So I think again just like devops was the answer for scaling your application infrastructure. It's the same with with data.
I guess it just takes it it takes time because a lot of these data Engineers were dba's Oracle dba's or sapdas and it takes time to educate and learn new practices and security is not different there. It's not just about query option anymore. Right exactly important, but not only thing exactly and I think what we're seeing now, so not ignoring the economical situation companies have invested a lot and got a lot of returns and now thinking about how to optimize I think that is where data operations really play a big part.
I think there's gonna be a lot of focus there because it's it's not about am I going to use the product or not? It's how do I optimize the usage for there? And these teams are gonna be spending a lot of time in thinking about how to eventually cut costs and be more efficient but how do they streamline a lot of things are doing today in a more efficient cost-effective way you mentioned DBA second, thinking more like developers.
What do you see that that kind of a role evolving to is it almost like a data devops engineer kind of role? Is it more just thinking about scripting your ID code and how you create, you know date manage data and almost data is code if you will sort of an idea. Where do you think that role is going?
I think we're going to see like if I like an abstract perspective on that more layers on top of the sequel. Like what's the difference between a data engineer software engine like SQL is a big big difference because eventually the way most people want to interact with their databases, you know, unless they're on Mongo is SQL and that's a very common language. But again going back to the DBT example.
They're building software leaders on top of that. So these are templates Python scripts code that's built and I think the data engineer you can get further and further away from crafting sequels. Those are going to be automated the crafted until you're just using apis and you're going to build more software layers to automate that.
So that's a shift that's happening. And you see now data Engineers using more Python and more of the more devops kind of oriented tools definitely fits more of a cloud-native and also a kind of API first right start thinking about a data access as an API and graphql being a good example. Yeah moves away from a sequel and maybe sequel in the back end or whatever in the back end, but think about if that is an API interface or that mindset of how we Access Data exactly worrying about the storage or the language to get to it.
Yeah, and you've seen I mean gcp from day one there. They have an API just alongside the sequel snowflake release to me. So it's it's becoming more common.
Yeah egrp, and a lot of interesting things. Well, great. Oh that's been fantastic talking with you and hope you have a great show and thank you for sharing your perspective on data security.
com and look at demo and we'll tell you more about it. Okay? Fantastic.
Please check it out, and we'll be back again with another great guest. Thank you for watching. We'll see you in a few.
