Amer Deeba, Normalyze | Black Hat USA 2023
End-to-end visibility into your cloud data and more! Due to the rapid increase in data volume, cybersecurity teams can no longer overlook data protection. Sophisticated hybrid cloud setups need help to achieve a complete risk overview across all data stores. A holistic data security platform is essential, putting data first in cyber defenses. Join Normalyze CEO & co-founder Amer Deeba as he discusses: top challenges to data security in cloud, on-prem, and SaaS environments; what it takes to build a data-first security framework; practical do’s and dont’s of data security.
Transcript
This is Textron tv. Hi everyone. We're back here on Thursday in Las Vegas for Black Hat, you know, Thursday of Black hat.
Weeded Week is always an interesting day. 'cause a lot of the people are transitioning to Defcon. Yes.
And The Red, red retired The rest of them. And the rest of them are Right. And the rest of them are, are heading home.
They've been here all week. Yeah. So it, it's a, it's always a, a fun day like that.
Of course, my friend sitting here with me has had, he's seen his share of black hats over the years. I'm having to introduce you to Amer Diva. Amer Amer's.
Been a fixture in cybersecurity for as long as I've been in cybersecurity. Hard to believe, but it's probably 25 years. Yeah, It is.
Um, and it's a pleasure to have 'em on here. Armor is the c e o and co-founder of a company called Normalize. And that's N O R M A L Y Z, Correct?
Yes. Right. Correct.
com. Ai. Ai.
Excuse me. You know, they didn't have AI com five years. Yes.
But it's normalized ai. Yeah. Yeah.
And, um, look, we, we could sit and reminisce about all times, all day, but we're not gonna do that to you. We're gonna talk about Normalize, but just, you know, before we do Amara, as I mentioned, you're in Cyber InfoSec 25 years. What got you excited about Normalize, right?
Because every entrepreneur I know, and you're an entrepreneur, we, we, we can't just look starting a company, you put your guts into it. Right. It's not something you do.
'cause eh, I'll take a shot, right? Yeah. You do it 'cause you feel it.
Correct. Yes. Yeah.
Tell us about, you know, I mean, I, I was, a lot of people know I was at Quass for 18 years almost. And, uh, we had the great product there. A lot of focus on, the focus was on infrastructure security.
Yes. So, uh, and after Qualys and, uh, doing some soul searching, talking to customers, and of course interacting with my co-founder right now, Ravi Itel, um, it, the, the, the, the, the focus around data kept coming up again, again and again. Each time we talk to a customer, to a, a chief security, uh, officer.
And it felt like it's really the right problem to, that needs to be solved. Uh, now considering, yes, all the changes that are happening in, in, in customers environments and moving to from on-prem to the cloud and all that transformation that's happening, data is becoming a big focus, uh, for many, many reasons that we can talk about today. And that, that, that's really what got me excited.
It's a big problem that needs to be solved. That requires a lot of innovation and a lot of new ways to address it. Uh, because the old ways, the way we were doing the LP before just does not work.
Yeah. It has a lot of efficacy issues and costs and deployment and all of that. So, um, it just, as an entrepreneur and someone is a cybersecurity lover, aficionado, whatever you want to call me.
Mm-hmm. Uh, it felt really this is the next problem that, that we need, that I wanted to tackle. Absolutely.
So I look at it, there's two big drivers for this, to me anyway. Number one, I would say for the last, let's say 12 years, 15 years even, there was a big shift. And it's funny, we're here at Black Hat, black Hat's the recipient of it.
We, we, you know, when you and I first came in, it was network security. Yes. That was where security was.
Um, we moved to application security. Yes. AppSec became king.
Yeah. Black hat is is the big part, prime example of it. Right.
And we focused on the application. Was the application coded correctly? Correct.
Was it deployed on the right infrastructure? Was there buffer, overflows? Was there back doors?
Was there, you know, it was all about the application. Correct. At the same time with the cloud storage, data storage Yeah.
Blew up. Correct. Right.
We'd store, I mean, I know our, we're a nothing company here, but the amount of video data we store is mind boggling. So you had this huge amount of data that a lot of people couldn't even wrap their head around. And all of a sudden someone's at some point, and it happened during Covid, people started realizing it's about the data.
Stupid. Right, exactly. The app is good.
You need a secure app. Right? Yeah.
But it's the data that are the crown jewels. They only, the app is a means, correct. Yes.
To an end. Correct. Yeah.
It's the data And, and, and ba and basically the, the, the, the understanding or the preface that, that we had, okay, if we secure the infrastructure or we secure the application and we secure where the data is, where we think where the data is, then we secure the data. Right? As you know, that breaches continue to happen.
And, and more and more breaches are happening. And fundamentally that model where, okay, if we, we secure where the data is then means it's, it's secure. It's no longer valid, especially in cloud environments.
Why? Because the data is moving everywhere. Um, you have now engineering teams and development teams, they're in control of just pushing for, pushing more and more workloads and more applications and doing updates, you know, twice, three times, four times a day.
And with all of that, new data comes, new sensitive data comes and it moves around within the cloud environments and a multi-cloud environment at a very fast and speed. So that model where, okay, I'm gonna secure that infrastructure where the data is, or the app itself is gonna secure me from breaches, it will help of course, and will help, you know, and it needs to be done. But also understanding where your data is, where your crown jewels are, what's in them, who has access to them, um, and, and the contact and the environment that they're in, that they're in.
And connecting all these dots together in an intelligent way to give you that notion where the risks are around your sensitive data is really a very important aspect right now to protect yourself and secure yourself from breaches. Sounds like a great reason to start a company. Exactly.
And that's kinda what normalize is. Focus is, uh, when we started, we call it data first, cloud security. Mm-hmm.
Data security for the cloud. Um, and really it's now evolving, uh, Gartner calls it Data Security, posture Management, which is kind of a new category, very much focused on understanding posture secu, the security posture around the data. D S P M D S P M.
Yes. So that's a new term for you guys out there to focus in on D SS p m, data security, posture management, posture management. Yeah.
God bless Garner when they come up with D data. Complicated name maybe. But it, it captures the essence of what we're trying to do.
And it's good to have a category and, and analysts now are all kind of rallying behind it, which is, which is very helpful. Absolutely. And that does, look, I, I saw it, you know, when we did nac mm-hmm.
We, we had some silly name for it. They named it network access control. We said, okay.
Okay. That makes sense. Go, let's go for it.
So D S P M. It is. Exactly.
So let, let, let's, I think we've set that table. Let's now talk about what Normalize does to help with D S P M. Great.
Yeah. So what people need to know. Um, So the, the other also thing, big, big, big, uh, requirement and shift that we've seen is when, when you're looking at data, you can't just look at, at it in one place.
You have to look at data everywhere. You have to understand data across ISAs, across your past environment, across SaaS, across on-prem. So you really need to have that vision that really allows you to get visibility of your data everywhere.
And fundamentally at Normalize, this is our mission, is to really help you understand where all your data is, what's in your data, what, where are the risks around your data? Where are the privacy gaps and compliance, uh, issues around your data. And then build kind of this dashboard where everything you, you know, that you need to know about your data in one place that can give you that ongoing continuous visibility and, and, uh, ability to proactively know where the risks are and address them around your data.
Um, we started, of course focusing on the, on the, um, on cloud environments at when we did, when we launched the company. But now we are expanding our presence specifically on-prem also because, and hybrid cloud environments, because we, this is where customers are. Like, we, we need to know everywhere where our data Is.
You gotta go where the data is correct. Wherever it is. So, uh, so the first thing we do, which is the use cases we help customers with, first of all, getting discovery, discover where, where your data stores are structured and unstructured.
Um, and then understand what's in them, what's the sensitive data they contain, what's the monetary value of that data. So, so you understand data store A has maybe $300,000 worth of sensitive information. And so How, how do you put a price on that?
A very good, very good question. So we have a research team. So as we identify the sensitive, different sensitive data within, within these data stores, we assign a monetary value to each of these entities based on research that, um, and, and various, um, approaches that our research team has gathered from, uh, public sources and data breaches and other reports, third party reports.
So we can assign a specific value, a dollar value for each sensitive data that we identify. And then you combine it all together on a data store per data store to give you what is the actual monetary value within that data store. It's an indication, of course, that doesn't mean it's worth that, but it really helps.
And customers love the fact that they have associated, associated a monetary value for Yeah. For their sensitive data. And then they can use it to prioritize and drive remediation when needed.
Um, and of course, we let customers customize it based on their own environment and how they, how they wanna, uh, how they wanna value the data within their environment. But it's a great start for Absolutely. For, for, I mean, it kind of reminds me of like C V E C V S S scoring in a way, In a way, exactly Right.
But you also, again, give the customers a chance to up or downgrade Up or down and say, you know, um, yes, it has that value, but this data store, for example, is in my, for example, it's not in my production environment. So I can, I can reduce, reduce that amount. Um, so the first, the first use case again, is discovery.
And then we take it into classification to understand where the sensitive data is and, and what type of data. P ii. Mm-hmm.
Uh, you name it, G D P R we cover, we have hundreds of these sensitive entities and we connect them together via, via proximity to, to show, for example, your name and social security number and credit card number are within the same proximity. So that even it's definitely considered p i i data. So it really helps increase accuracy of these results as well as the, you know, reduction of false positives, which is, can be a very problem problematic.
Let Me, let me talk a a a question a little bit on the discovery phase. You know, there's the old saying you don't know what you don't know. Mm-hmm.
How do, how do you find data that you may not know about that's there? It's, you know, now with the beauty with in cloud and using the cloud APIs, this is, it's, it helps you in looking into logs and understanding, you can interrogate the entire environment very easily and grab a lot of telemetry and information from the cloud environment that allows you to really identify in a very accurate way where the, your data stores are, what type of data stores they are structured and unstructured. And then from there, you, we connect to these data stores in a very transparent way through IM roles in order to scan that data and to classify it.
And the scanners are orchestrated in a way where they come to you where the data is, we don't take any data out, we don't copy it out, we don't transport it out of the environment. So they come to you where the data is, perform the classification and disappear. And all of that is done in a very cost effective, efficient way to help customers really scan the data quickly and get the information they need.
So What about scale? 'cause that, that, as I mentioned earlier, that's the second part of this conundrum Correct? Is there's so much Data.
So How do you scale? And, uh, you know, there's, there's a lot of mechanisms that you have to think about when you're thinking about data and scanning data and scaling for data, which is, um, you know, again, and cloud really helps you kind of, which is from the grounds up. When we built the platform, scale was a big part of our mission.
'cause we wanna do it everywhere for small, medium, large customers across all the clouds and, uh, wherever their data is. So, uh, you know, we've, we've, we've built the backend, it's a graph based backend to house all that information. And that can scale very, very well as, as customers add more data and more information.
Um, and it allows, it allows us also to share, to share the results very quickly and to provide the information. Like it, you can go in and find, show me where all my data stores that have this type of information, that have this type of risk associated with them or this privacy issue. And the graph can gives you the information pretty much momentarily in, in real time basis.
So, um, and, and everything is kind of built at the, at the scale of the cloud to allow us to, um, you know, discover quickly, scan quickly. And when you're scanning the data, we have a lot of techniques that we use, like data sampling. For example, if it's a data store that has a lot of machine generated data, you really don't need to do a hundred percent scan.
Right. But you can do it 10, five even percent scan. It gives you very good understanding of what's the data and what, what's data.
The data is in it. However, if it's a very custom type of a s three bucket that's collecting a lot of information from individual users and many, many sources, then you might wanna do a, a, a more extensive scan on that and all of that. We do a one pass scan through the file where we collect all the information in one pass.
We don't go, we don't do like a pass for p i i data. Exactly. So it's one time it goes through the file one quickly.
We read it, we ident understand the sensitive entities and we classify it, and all that information is processed in our backend. So the results come out very quickly and customers can start seeing it and interacting with it and deciding how to, how to, how to take actions on the risks that were identified and drive remediation. Got it.
So we discover, we categorize, if you will, Classify, Classify better. Yes. Next step is protect is Risk, understanding the risks.
Okay. So you need to understand where that data is, the context it's in it, and the who has access to access to that data, which is a huge risk factor to around it. If Alan has access to a data store, for example, that had contains sensitive information and HIPAA data, p i i data, but you haven't accessed that data for six months, eight months, why do you need to have access to it?
Removing that access immediately helps eliminate risks associated with that access that you have. So understanding access to the data and applying least privileged access to it is a big use case that comes in that phase followed by understanding all the risks around it. In other words, are there any vulnerabilities, configurations, misconfigurations, or any attack paths by connecting all these dots around it that could lead to a, to a, to a compromise data compromise.
So we, we, we immediately cla uh, uh, present all these risks to the customer based and, and prioritize based on the type of risk, the impact of the risk and the monetary value associated with the data. It's, it, it, it comes with it and we provide all the remediation actions that you need to do in order to resolve that issue or to resolve that risk and help you drive remediation. Let me stop you here.
When you say you provide all the remediation actions, again, I'm going back to our old vulnerability management days. You're telling them these are the actions you could take. Exactly.
But you're not proactively doing the remediation. Yeah. So we, we connect with, with Soar Eng, with soar, with SOAR workflows, with Sims, with ticketing, with, um, JIRA, ServiceNow, slack, um, any, uh, uh, the, we, we help basically take that intelligence and help drive DevSecOps to, to remediate the problem.
Uh, there were certain actions that we can help from within the product to remediate, for example, removing access. You can remove that from if you have the right access of course to do it. But fundamentally, when you're in production environments to do remediation and automated remediation, scary, it's a process that you have to orchestrate Yeah.
With your change management and DevOps team. So we wanna integrate into that and facilitate it as much as possible. Um, and of course, talking with customers and discussing with customers, remediation will become a big, big part of the platform.
As true as, as we grow the, the product, It was the same thing they gave in vulnerability management. Exactly. It wasn't enough anymore just to find the vulnerabilities or to tell you what to do, Get a batch and, and apply.
There were so many vulnerabilities, right. You had a batch you had to start automating. Yeah.
It's, it's, again, goes back to scale. Exactly. So that's, that's an area that we will work with customers to mature it.
Um, for example, you know, like if a recurring issue comes, keeps coming up again and again, and then each time you apply a certain automation to do it, why can't you just apply that automatically and fix the problem? But this has to be, of course, designed and orchestrated the right way and will we will, it's, it'll become a big part of what we do also in the future. So, I get it.
Yeah. If you don't mind, I wanted a black hat specific question. So here we are in the, in the, the kingdom of AppSec, right?
Yeah. The, the capital of application security. You're here all week, you, the whole normalized team is here all week.
Do the AppSec people get it? Are they understanding that data is king and they gotta protect the data? They've gotta recognize data, protect data.
It's a big, it's a big focus. So I, I think just walking through the hall and seeing some of the sessions here and all of that, there's a big focus on a p i security Yes. On data security.
Um, app security of course is a big thing. And for all of cloud centric, you know, with, with that, with, with that in mind, um, and also kind of orchestration and workflow and remediation and all of that. There's, we see the, I saw a lot of innovation in this space, um, and just kind of getting the vibe of the show.
I feel like same at r s A by the way this year. Yeah. We thought it's all gonna be about AI and all of that.
And, and it was, there was so much focus on data and, and data security. So. Excellent.
So you mentioned the AI word now you mentioned it, we gotta talk about it. Of course. Yeah, let's do it.
So It's gotta be a role here for ai. It's Absolutely, I mean, we already use it, uh, as part of the platform to help, uh, provide better remediation and, uh, guided remediation for customers on problems. Uh, we are, we use it a little bit in our scanning engine also.
Um, and then we are gonna use it more in the future to better, uh, better understand like similarity of objects. And, um, so for example, if you're looking for a specific type of an agreement or type of a document, we can use AI to really help us immediately understand, uh, when we scan the data and identify it fastly, but in a, in a faster way. Um, so, uh, it's gonna play a big role I think in, in data security when it help when in, in driving guided remediation.
And also making sure that data that's going into your models in and out of your models and what's in your models, that if you contain sensitive data, that this data is not gonna come to bite you in the future. So I think that right there is a, could be a product in and of itself. Everyone I speak to, whether it's in the media business that we're in or in other businesses, they're, they all want to create their own LLMs, right?
They're taking their data, putting it into a vector database, dumping it into an L l m, they put a chat bot in front of it and now voila. Right. Exactly.
I have my own custom data set understanding what data got in there and what, you know, what privacy issues we have of, of course that comes With it. Yeah. Is, is very important.
I don't know if people are thinking about that yet. Uh, We, we, customers are definitely thinking about it and we hear it quite often coming from customers, but the way they're approaching it also, it's like, if we have the right visibility and we know where our sensitive data is and what's going in and out of these data stores and are they being used in data modeling and big LLMs, then that's a great start to get started. Yeah.
And again, with all customers, when, when, I think the most important things, when you start with, with trying to, with with understand your data security landscape, you can't boil the ocean. You have to focus on what's important first and get that visibility the number one thing. 'cause that helps you put the blueprint for how you wanna address it and what controls you should put in place and how you manage the entire process in a way that makes you achieve success one step at a time and reaching your final destination.
So, And look, this is best practices in security. You mentioned a p i security. We saw this with a p i security, uh, two years ago.
All of the a p i security vendors were talking about, do you know what APIs you're even using? 'cause we can't secure what you don't know you even have. Correct.
So it was about discovery of a p i security. Um, attack surface management is another big area. It's the same thing.
Yes. If you don't know your surface, how could you manage it? How could You secure that?
Yes. And, and so it, it is the, it is the same thing with data. Um, we only have a few minutes left.
I, if you don't mind, look in the camera for people who are out there saying, yeah, it's time. We, we gotta get serious about data. Yeah.
What's the on-ramp? What, how do they engage with normalizing and get started here? Great.
Very, very good questions. And I, I, it's a discussion I have with, with CISOs all the time. First of all, there's, there's a lot of innovation in this space.
So, um, there's a lot of, uh, uh, uh, new, new ideas and great, great tech coming out to help solve this problem. So the CISOs now, like, you know, especially if they have a bad experience from before on D L P mm-hmm. Uh, I think it's, they really need to, you know, stop and, and consider and listen to us and to, you know, of course, uh, at normalize, we, we, we are at the forefront of it and we are having these discussions all the time.
Time, uh, and it's easy to get started, especially in cloud environments. It's just, it makes it much easier to get, it's always, of course, you know, it's never easy, but it's much easier to get started and to, you know, a small, like a, uh, have a small P O C in an environment that you have good control on to start testing these technologies and see the output and the value that that, that it provides to you and to your organization. And the good thing, like if you engage with us that that's not months, it could be days if not weeks, where for you to get started and, and, and, and see and see value right away, um, What, what's involved Is it, I put a couple agents on my system, let Run?
No, no, it's, it's, we're hundred percent agentless. We, when we, we basically, you connect your cloud accounts into our back, into our platform, and, um, we deploy within their environment and in a very special, secure way, very similar to like C S P M tools. Sure.
S sim tools and all of that. And that deployment can be literally, sometimes we do it over zoom, you know, really you have the right access and, and you have the right people on the call. And then from there it's scan running and often and running.
And then you can start tuning it a little bit more, understanding the results a little bit more, and then making changes and then connecting it, for example, to your value to Jira accounts. If you wanna orchestrate ticket integrated and integration or integrating it into a sim or in order or store from there. But, uh, it's a pretty, um, frictionless process.
And um, it's, uh, it all happens where the data is, we don't take any data out. We don't transport it, we don't aggress it, none of that. So it's, uh, They call that liability.
Yeah. Well, yeah. I mean, some approaches before, that's how we Addressed it, the problem.
And it was a liability. Yeah. And it created, it created it, didn't it?
It, it didn't help also kinda, uh, no. With, with certain, certain, with certain customers. But, um, that, so that's how we do it.
And um, uh, we encourage you, come to our website, join our freemium, which is you can get started on your own or we can help you get it started. So On that note, so there might be people out here who say, look, I'm not a large enterprise. I don't have PETA petabytes of data.
You know, we have gig gigabytes, we're not even Terabytes. Terabytes. Yeah.
I mean, we see it across, but they all say that, oh, we only think we have that. And they got started and, oh, we didn't know about this and that data store and someone added that somewhere else within Azure and I didn't know about it. And a new project popped in, in a G CCP that, that would actually be an interesting survey.
So the before and after, the new customer says approximately how much data do you have? And then how much data do you really have? And the beauty is that that's again, getting that visibility.
Yeah. It really immediately gives you that ability to, to make, to understand better what you have. And from there you can decide if you wanna tackle it all or tackle part of it or how you, and we help, it's our model is, uh, licensing model is very, uh, simple.
It's all like you start small, you start large, whatever you want, and then you can grow with us. Alright. So you're not too big or too small to use Normalize.
Everyone has good sensitive data. Everyone has wants to protect their crown jewels and the data. In fact, we have a campaign here at the Black Hat with uh, track what matters most for you.
And if you come to our booth, we give you, uh, an air tag so you can use it to really, yes. That's great. That's a good, I thought it was a good one.
So come get a demo and you'll get a nice be beautifully branded air tag so you can be part of that campaign to track really what's important and what matters to you, your, your data. Fantastic. So, alright, we're here with Amer Deber normalized.
io though. Dot com will work, but it's normalized. Do ai, ai, ai, all of these.
com. Yeah, it works too. Works as well.
Yeah, of course. Yeah. But most importantly, your data is important and, and you need to use a tool like Normalize, uh, to, to get, get your arms around that.
We're gonna take a break. We're live here Thursday, wrapping up Black Hat Week. We'll be back in a little bit.
Thank you. Thank you Amer.





