Data Security: Protecting What Matters Most | DataOps Day
The accelerated pace of cloud migration has facilitated innovation across all technology domains. This widespread shift to the cloud has also impacted information security as organizations’ data proliferated across multi- and hybrid-cloud environments. “Where is my sensitive data, who accesses it, is it at risk, and are we compliant?” – these are the questions CISOs, and their security teams struggle to address at scale.
Data Security Posture Management or DSPM is a new framework that provides security teams with visibility into data security across all cloud and hybrid environments as well as the ability to monitor and respond to threats in real time.
In this session, Gautam Kanaparthi will discuss why data security needs to be a top focus for organizations and how that focus puts the information back in information security.
Transcript
Hello everyone. Welcome to this session on Data Security. I am Gotham Kanati.
I lead product at Normalize. Prior to Normalize, I've spent more than a decade building security products, um, at Symantec and Netscape and other companies specializing in data security across endpoint devices and SaaS applications and so on. So today I want to talk to you about, um, the trends that we are seeing across organizations, the challenges that, um, security teams are dealing with from a data protection perspective and potential solutions that are on the cusp that every organization need to be thinking about.
So before we dive into the data specific challenges, let's take a look at how the technology landscape has changed, uh, in the recent years. Uh, we are all aware of, um, the adoption of cloud, uh, infrastructure, uh, and data, uh, platforms in general. But the reality is every organization is not just using one of these platforms.
They are in multiple, if not all of them. Uh, and we see this time and again, across organizations, more than two thirds of the enterprise organization, uh, two thirds of the enterprise infrastructure is in the cloud. A huge volume of corporate data over 60%, uh, is also stored in the cloud, and that's doubled from 2015, and it is only expected to go up.
Um, compared to where we are today, we expect a 60% increase just in the next couple of years in terms of the volume of data stored inside the cloud. So effectively there's an explosion of data happening in enterprise environments, um, especially in the cloud. So let's look at some of these technological trends, um, that are happening across the board and talk about what is the implication for security for each of these.
So we all know that, um, we all know the talk about AI and ML happening, but even prior to this year where generative AI has really become a buzzword, every organization has been investing in adding an intelligence layer across their products. So there's a lot of investment in AI ML tools, uh, in many organizations. So what that means practically is there's a lot of different teams that are accessing your data, uh, copying data for training purposes, um, and testing their models and so on.
And in most cases, they cannot do this with mock data. They do need to actually use the production data that has sensitive information. So for a security team, they need to be aware of who's actually using this data and whenever copies are being made, is the data lifecycle actually being followed?
C I C D has been, um, a much talked about topic for many years in the engineering circles. Organizations have moved from a waterfall based development lifecycle to C I C D, so continuously integrating and continuously developing, uh, their products. So this constant iteration basically means that, uh, what used to be a once in a month or once in a quarter update to the product now means there's a lot more frequent updates.
So there could be multiple updates in a single day to the application. So if you're a security team, uh, responsible for data security, what, uh, you were aware of, um, as the status quo of how the application operates and interacts with data yesterday may not be true today because of how frequently the applications are being updated, compliance regulations have been in the news. Um, every time there's a big data breach, there's talk about how compliance regulations are more stringent and enforcement is much higher, which is very much true.
Uh, post G D P R every, uh, geographic region has a new compliance standard coming out, um, and with a higher rate of enforcement as well and much more, um, the much more, um, focus on, uh, enforcing the fines as well. Right? Aside from this, um, there's a big shift that has happened over the last 10 years, uh, from in how applications are architected.
Uh, what used to be a model. The application now has hundreds if not thousands of microservices. So if you are a security team, it was much easier, maybe 10 years ago to say, this is application A that is accessing my database, and this is a purpose of that access.
But with many microservices, it's much harder to actually get that level of clarity as well. Uh, so to even enforce, uh, hey, who needs to really access this data? It's much harder to really understand that picture from a data security standpoint.
Uh, we talked about data proliferation earlier in the slide. So there's a diversity of data stores with a lot of data workloads being available across multiple cloud platforms. There's a rich set of choices for engineering teams, and we see now enterprise data spread across the board.
And lastly, with the adoption of cloud, um, what it really means is, um, security controls, which were much more finite in the world of on-premises, are much more spread out, and there's a higher chance of something being misconfigured and something being potentially exposed in the world of cloud infrastructure. So that's really the challenging environment that every data team and, uh, teams responsible for data security face in the organizations today. So in that context, uh, from a data security program standpoint, uh, what really are the top questions?
So we see security teams constantly try to understand, um, these pieces of information. Firstly, where exactly is all my data? As we talked about, there's a lot of data proliferation.
So to really even understand something as basic as what are all the different locations my data is stored becomes a pretty, uh, tough task. Uh, the second aspect of that is, which of these do I really need to care about? If I know I have hundreds, if not thousands of data stores, which of those do I really need to care about?
It's not an easy question to answer, because that involves understanding a lot of the business context, which not every team has readily available. It involves talking to a lot of people, uh, understanding why is it being used, how is it being used? How do I, how long do I need to retain this data and so on.
That in itself is a challenging task. And lastly, the most important question from a risk management standpoint is if there is a data exposure, uh, or the data breach around this data store, what does it cost the organization? Um, this has historically been a challenge even in the world of on-premises where the risk isn't necessarily quantified, but when your data is spread across the board and your risk of data exposure is higher, it becomes really imperative to understand what is the actual financial cost of a data breach?
And as we talked about, data is everywhere. So even answering the basic questions that we laid out in the earlier slide becomes much more challenging. 10 years ago when most of the data was in an enterprise, um, data center that is private to the organization, um, today, you see most of the data is actually in public cloud environments.
Um, whether it is a SaaS application or a data platform like Snowflake or a Databricks or cloud infrastructure like a W S T CPA Azure. So in such an environment where the organization isn't necessarily controlling the underlying infrastructure or even, uh, how data workloads are actually running, it becomes much more challenging to answer, um, the basic security questions that are required for your data security program. And it's not like organizations are not aware of this.
Um, every organization that is looking at their data landscape is, um, well aware. I was at Black Hat last week, um, and had many conversations with CISOs of large organizations as well as, uh, small businesses. And it, they're acutely aware that their data is not fully secure.
And this is also validated by some of the research that, um, uh, an analyst firm that has done, uh, this is E S G in this particular case, more than half of the organizations, according to them, believe that their cloud distant resident data is insufficiently secured. Uh, they have a little higher confidence in SaaS applications, but even in that case, they believe a third of that data is not really secure. But when it comes to, um, infrastructure, service and platforms as a service, um, there's much less confidence that their data is actually secure, right?
So the valuable data is actually being exposed. Um, this is being reflected in the incidents that are actually happening in the cloud and incidents that security teams are working across various organizations, um, um, pretty much every single day. And these incidents are not cheap.
Um, as we've seen, um, the size of data breaches has only gone up, uh, just in the last two to three years. Uh, if you look at the list of data breaches that have happened, um, they are in the order of hundreds of millions of records. And if you add on to that, what is the loss in revenue?
What is the financial, uh, impact to a company due to fines imposed and other, um, business risks? It adds to a massive, uh, a massive impact to every organization. And this is not just, uh, an organization that doesn't really have a mature security program.
Some of the names you see here on this list are highly sophisticated organizations with well-funded security teams and, uh, pretty extensive data security programs. Um, but it's clear that this challenge is something that, um, needs to be tackled in a little bit different way than what was done maybe 10 years ago. This is where, uh, a new space has started to emerge.
D S P M, um, is what, um, Gartner has started calling it. D S P M stands for Data Security, posture Management. Um, and, and let's look at what are the challenges that D S P M solves and how it solves in a little bit.
The way Gartner has laid this out is data security. Posture management technology is meant to uncover all the unknown data, as we talked about earlier. There's a lot of proliferation of data.
So the fundamental thing that D SS p M technologies need to be able to do is continuously and automatically discover data. So there is no blind spots from a data security, uh, monitoring perspective. The second piece is identifying the security and privacy risk of this data as well.
Uh, so first piece is discovery, and then secondly, understanding is there a risk from a security standpoint or a privacy standpoint to this data? Uh, so that also helps identify what exactly is the criticality of this data, where should security teams focus on? And lastly, there is, um, uh, there is a call out here to actually, uh, look at how data is moving through that data pipelines and also across geographical boundaries.
Um, so the core really that Gartner is trying to get at is no matter where your data is, you really need a technology that is able to offer data security across the board rather than trying to do it in silos. So for every security team, that is really the, uh, big imperative, uh, need here is how do you prevent data breaches in a world where your data infrastructure and, um, data environment in general is extremely complex and proliferated across many different platforms? How do you really strengthen your data security posture if you don't really understand what is critical to you?
And no matter where your data sites, you need to be able to do this. So that's really the number one challenge for every data security team today. And with A D S P M, uh, the fundamental, um, aspect here is, hey, let's start with data.
Historically, if you've looked at security products in general, the focus has been on a secure this endpoint device or secure a user or secure an application or secure the infrastructure. At the end of the day, all of these security tools are trying to protect the data that an organization caress about, but they've approached it from an outside in standpoint on what does the attacker get access to first, which may be a, a compromised user or a compromised device, or a compromised application infrastructure. So what that has led to is security teams spending a lot of time on risks that may not necessarily reduce the risk of a data breach.
While they're all important initiatives to secure all the surface areas, it it has proven, um, to not necessarily reduce the risk of a data breach, as we've seen with the list of data breaches that have happened in the last few years. So this construct is a little bit flipping the existing approach to cybersecurity and saying, Hey, why not start with data? Let's actually start with understanding what is your most critical data?
Where do you need to focus your efforts on? And then work outwards on there and say, is my most critical data actually secure? Uh, is the risk of a data breach for that critical data minimized?
And then move on to, uh, the next piece and so on. And this way, the cybersecurity program in general is organized around securing, um, whatever is the most important and what could potentially cause the highest business impact to the organization. Uh, as I mentioned earlier, historically, um, various security tools, uh, while um, they've been adopted in organizations have not had a data centric approach to security.
Um, even the DA data security tools have really focused on solving data security in a single surface area. For example, there have been, uh, data security tools for the endpoint device. Uh, your laptops, for example.
Uh, there have been data security tools that were built for on-premises databases, uh, data security tools that have been for, been built for emails or network traffic or a SaaS application. But what they've really done is handle data security in silos. So if you are a CISO or a data security practitioner trying to understand, Hey, tell me where all my sensitive data is, you would have to do all of that work yourself.
The organization is trying to manually piece together information across these multiple tools. And not to mention there isn't really, uh, a, a data security solution that is solving for data platforms in the cloud, infrastructure in the cloud, data workloads running in the cloud. So you have those big gaps.
And also the existing solutions are doing it in silos. So not necessarily addressing the actual need for data, data security teams today. So, which is where, again, D S P N platform, um, is, uh, addressing this core need.
And if you think about what are the components of a data security program, um, really looking at what are all the surface areas that, uh, we need to monitor for sensitive data on. That includes your IAS platforms like a W S G C P and Azure as, um, like Snowflake or database, Databricks SaaS applications like Office 365, box, Dropbox, Salesforce, and so on. And also not to forget the databases and file shares deployed on premises.
The second piece is monitoring who's actually using this data. It's not enough to just say, Hey, I'm looking at this data. I know what is sensitive and I'm continuously monitoring what is happening around this data.
But you also need to understand who's actually accessing this data and what are they doing with it. And that involves looking at who are the users that have access to sensitive data, what are the applications that are accessing this data? And potentially other third party users roles and applications as well with access to this data, those need to be accounted for in, um, the data security platform.
And lastly, the piece in the middle that is referring to data and motion as well is critical because data may be secure at rest, but once it's actually, uh, being used, being accessed, is it really secure? So that cannot be missed as part of this overall data security program. So that's really how, um, data D S P M tools need to be architected, uh, because from a data security standpoint, those are the core needs that need to be addressed.
Diving in a little bit, um, thinking about how should um, uh, D S P M platforms really do this, um, this is at a very high level components that need to be present. As you think about, um, data security tools that you may want to introduce in the organization starting at the left, um, the first piece is really coverage. As we talked about, data proliferation is really a big challenge, and that has made data security programs a lot more complex and challenging to incorporate.
So coverage should be top of mind, uh, for data teams or security practitioners thinking about data security tools in the modern environment. So being able to discover data across SaaS applications, cloud data platforms, cloud infrastructure, as well as on-premises is key. And then once that discovery is done, being able to say, Hey, these are the data stores that are potentially abandoned or potentially not being used, uh, detecting sensitive data automatically and doing the access and privilege analysis to say, Hey, these are all the users or roles or applications that have access.
These are potentially the ones that don't need access or have accessive privileges. So the team can then go in and quickly, uh, assess and do a security or access audit and say, let me reduce the risk of, um, um, excessive privileges here and enforce the least privileged principle across my company. And as you get all of this information being able to correlate and say, Hey, these are the key risks.
This is potentially the path and attacker can take. These are the risks that are opening up my organization for a data breach is critical. Having visibility is great, but really comes down to are you able to use that intelligence to reduce the risk of a breach or even assess that risk of a breach?
So that's really where having a good risk engine and being able to prioritize is critical. Without that, a security team may just be undated with thousands of alerts like any other security tool. Uh, so being able to do that correlation and taking that attacker view to say, this is how my data is potentially exposed, so I do need to fix these 10 risks in order to reduce the risk of my data breach is important.
And prioritization is key. Um, we talked about security teams being overloaded earlier on, so being able to quantify, hey, this is the risk of a data breach, or being able to highlight which data store is important in a quantified manner. For example, um, we talked about how, um, the business impact being able to assess the business impact, right?
So being able to say, this data store contains my p i i information or customer information, and this is exactly the business value to my organization. If there is a, um, loss of data in this data breach helps organizations prioritize, um, as well. So that should be a key consideration for security teams to, uh, assess, um, hey, how do I prioritize my risks once I have visibility in the platform?
And the last piece we hear from many organizations is there is a shortage of skillset, shortage of, um, um, manpower on the teams that are implementing data security programs. So automations becomes critical. Um, getting to, Hey, what do I need to fix is very important, but also you need to be able to actually do it.
Uh, it is not enough to say, I have 10 things to do, but if you have nobody working on it, then that doesn't really help you improve the posture. So being able to automate some of these tasks and saying, Hey, I know that data store A should actually have encryption turned on, versioning turned on, uh, should not have, um, access open to external rules. Uh, that is all important, but every one of them does not have to need an individual to spend hours on it to actually resolve.
So you could either have something integrating into an existing workflow or even have the tool trigger some kind of remediation so your team doesn't have to actively think about it and be able to automatically, uh, affect changes in the underlying platform or the data store. So the, the issue itself is addressed right away. So if you think of it end-to-end, uh, on the left, you're doing automatic discovery and then doing classification, uh, and then doing an access governance audit, and then getting into using all of that context to do risk detection, uh, and automation.
Uh, the last piece, which isn't really highlighted here, but a key concern for, uh, every team that is using the data is compliance. Uh, beyond just mitigating risks, compliance is a big factor for, uh, data governance teams and data security teams as well. Um, so you need to make sure that, uh, whatever risk engine and prioritization engine, um, that you are evaluating for your data security also takes into compliance, uh, needs that are important for of the organization.
Right. And lastly, um, as I mentioned earlier, data addressed is important to secure, but you cannot lose sight of data in motion. So it is also important to understand, hey, where is this data coming from?
Where is it actually going, and how is it being accessed during those transactions? So you have, uh, full visibility into how is that, uh, data moving and is it really secure when it is actually moving? So we've talked to many organizations about their data security programs.
Uh, this is one example, uh, from Ginkgo Bioworks. Uh, ginkgo Bioworks, if you're not aware, is a biotech company. They work, um, a lot with, um, genetic engineering.
Uh, so they have some, uh, gene sequencing information that is, um, critical for them or for their ip. So there's a lot of sensitive data that they really care about. So what they've done is, um, actually implement a D S P M solution across their cloud environments to really understand where all do I have my data?
Where, where is it that I have really critical data that is important to my business that I need to prioritize and make sure that it is secure first? Um, and the compliance was a big need for them as well. Uh, and D S P M solutions have, uh, helped them achieve that compliance and also a full visibility into their data security posture.
Getting to high impact, uh, risks is one of those key criteria that I talked about earlier. What we see across many organizations is when you do a full discovery, you end up with hundreds and maybe thousands of data stores. Uh, so the first thing you really need is, which of these data stores do I need to focus on?
So making sure that you have a mechanism to prioritize is really critical, especially which of those could be high impact to the organization. Um, a big challenge for security teams has really been to, um, quantify the effect of the work that they've been doing or quantify even, how are you prioritizing certain things rather than take the first thing that comes, um, on your plate. So prioritizing and being able to say, this is the data store that actually has the highest impact.
These are the risks that actually would cause the most damage to my organization is critical. And that's what, uh, I would recommend, um, data teams and security teams focus on as you start your data security journey. Uh, quantification of business risk is critical as well, uh, from a couple of different, um, uh, standpoints.
Firstly, if you are thinking about how to organize your work, uh, rather than chasing down every single alert, being able to quantify the business risk would help you to say, Hey, when I started this quarter, I had $20 million, uh, of data at risk, but because of all the work that I've done, um, I'm able to now bring that, uh, dollars bus business value at risk to 1 million, maybe from 20 million. So that would help really the effectiveness, uh, communicate the effectiveness of security program to executives or board, um, uh, and really get, um, a sense of achievement and, uh, progress as well. So it'll be clear in the executive management's mind where, um, the funds that they're actually putting towards security are going and what is the progress they're getting out of it.
And secondly, from a tactical prioritization standpoint as well, for security teams, they would be able to use this quantification to say, if I resolve risk A versus risk B, this is the business impact that I would actually be able to achieve. So helps, um, the teams achieve a higher r o i for the time they're putting into data security as well. Uh, another example, um, is, um, an organization named ChargePoint.
Um, if you're not familiar with them, they're on, uh, electrical vehicle charging networks, um, across, uh, the country. Um, almost critical infrastructure at this point, given how much electric vehicles are are being used. So as you can imagine, they have a lot of, uh, data on, uh, customers, partners, um, payment information and so on.
Um, so they have a similar need to really say, what is the most critical data for me? Uh, who actually has access to it? And can we continuously monitor those risks without teams really being, uh, involved, uh, extensively on every single risks.
And D S P M has been an answer for them as well, and it helped them really understand, uh, what, where is the data exfiltration risk, uh, across my environment? Uh, how can I prioritize those for the most sensitive data stores? Another quick example, uh, here is Sigma Computing.
Um, Sigma Computing is a business intelligence, uh, solution, a technology company that is helping organizations build, uh, analytics. And as you can imagine, for a company that works a lot with data, they have a ton of internal data as well as their customer data as well. Sigma is a SaaS platform.
So, uh, customers, um, are using a product that's actually running in Sigma's cloud environment. Uh, so there's a ton of customer data that is being stored in their environment. So for their customers to gain confidence in their platform, they need to understand who actually has access, are those secure, do, are there vulnerabilities in Sigma's platform that are exposing, uh, my data to a breach?
And that is something Sigma has solved with by putting in a D S P M solution as well. So as we wrap this up, um, in, in terms of next steps, what I would recommend for anybody thinking about data security, um, today is start with discovering data across all your environments. Don't treat data security as something that can be done in silos.
You really need to do data security in a comprehensive fashion because attackers don't care whether they're getting data from your on-premises database or a an a W S environment or a snowflake environment. It's sensitive data no matter where it resides. So discovering data across all your environments is really critical.
And once you know where your data is, uh, then start getting into, okay, let's classify this data and understand what type of data do I have? Do I have more of p i i do I have more of P C I or healthcare information and so on. So, you know, um, where, what type of compliance regulations you may potentially be, um, um, liable for as well.
And then get into access audits to say, um, hey, who, who has actually access to it? Um, and take that forward to understand what are the top risks, um, am I, um, do I have in my environment? And what is the monetary impact to the organization based on all these risks?
And all of this together will help you really understand what is the compliance posture, uh, against regulations that matter to the company. And then you can focus on remediating the top priority risks, but discovery and classification would be the key, and then you can take it forward from there. Thank you very much.





