Data in Motion: Security Concerns and How to Handle Them – Digital CxO Podcast EP107
In this episode, Amanda Razani speaks with Vinay Prabhu, director of products at Graphiant, about how data in motion has become one of the biggest security challenges, and how business leaders can best handle this issue.
Transcript
Hello, and welcome to digital CXO. I'm Amanda Ani, and with me today I have Renee Pbu. He is the Director of Product at grapht.
How are you doing? Good, Amanda. Thank you for having me.
Happy to have you on the show. So today's topic is data assurance, but before we get into the topic, can you share a little bit about grapht and what services do you help provide? The grapht, uh, network as a service platform.
And what I mean by that is we provide con any to any connectivity, whether it's from your private space to the private domain, the private space to the cloud or, or, or the public domain and the services that you can consume. So it's a consumption based model, so, uh, you don't have to worry about the network itself that's built out for you. So we provide our graphene backbone, uh, as a service.
You consume bandwidth on that, uh, backbone to get you from point A to point B, and we get you to the cloud. We provide you B2B connectivity. We provide, uh, provide you the data assurance service, uh, all on top of it.
And we, uh, provide you the SD-WAN capabilities that, uh, uh, are already prevalent in the industry. So we have a bunch of services that we provide on top of this backbone. All right, wonderful.
Well, so let's talk about data. And I wanna share, first of all, um, your stance is that data in motion has become one of the biggest, uh, security risk in the enterprise today. Can you explain a little bit more about that and why you think that?
So, data lives in three states. Like, uh, you mentioned data and motion. The data is addressed, the data is in processing, and then the data is most vulnerable when it's set in motion, because for the first time, it moves out of your private domain into the public domain.
So data address is sitting still in your domain, in your, within your parameter data. And processing is still within your parameter. It's when it exits your parameter and into the ether of the internet, that's when it's most vulnerable.
And hence, we think that, that, that's the most critical aspect from a security point of view of where data needs the most protection. With the industry going into the AI world today, the data is getting a lot more disaggregated. It's no longer just your data.
You need to share this data with your B2B partners, with LLMs, with GPUs, so on and so forth. So, uh, you are almost extending your parameter beyond your boundary with, uh, places where you are exchanging this data and graphene data exchange platform. So with that in mind, we need to really protect this disaggregated data and extend your security posture and your risk appetite beyond just the perimeter, uh, into the business domain of things as well.
So that, that, that's where aita sharing story, uh, begins. Okay. So can you share some of the top vulner vulnerabilities and risks associated with data in motion that business leaders should be concerned about?
So, data in motion there, there are, uh, a bunch of things that they need to worry about, right? One, uh, is it encrypted? Is it, uh, there's a spatial component and, uh, there's a temporary component to every conversation.
So contextualizing data is first, uh, the first pillar that's key to protecting your data. So knowing what the intent of the data is, and then really plotting it on a map, right, of a, of space and time. Am I consuming the data where it's supposed to be consumed?
So let's say, Hey, I need to, uh, my servers, uh, are located globally, but if I'm authorized to only access servers in North America within sovereign boundaries, then that's the spatial component of where I should be consuming that data from and not going beyond those sovereign boundaries. There's a time component of it. If I'm allowed to au uh, access data, I need to access it during workers.
If I'm accessing it out of workers, that might be anomalous. So you need to really contextualize when you're accessing it, where you're accessing it and how you're accessing it. So those are the three pieces of the puzzle that a, any CIO cso, uh, of an enterprise or a service provider would be looking out for in terms of how to protect and what to protect, uh, your data in motion for.
Are there any tools or technologies that you recommend that, um, would help safeguard this data in motion Graph? I, I would recommend graphene and the, the data assurance offering itself. Uh, what we've try, tried to do for the first time is get security to govern routing, extending your security parameter into the network space.
Uh, so what I mean by that is data is your most sovereign asset and giving that, uh, the treatment like any sovereign asset, uh, deserves, uh, data should stay within data embassies that extend your sovereign boundaries from point A to point B. So let's say you, you have GDPR data that's critical to you. Uh, GDPR states that this data needs to stay within boundaries or within trusted entities that extend those boundaries.
So keeping that kind of risk posture within your network of where this data travels from Point A to point B, who's the producer, who's the consumer, and those are entities that are GDPR compliant is key. Uh, and that's the control, uh, graph games to give you, you, uh, with a click of a button, uh, of where your data moves, how it moves, and who produces it and who consumes it. So would you think that corporate boards play a role in shaping policies for data protections?
And, um, if so, how? Uh, both, uh, uh, corporations, uh, influence, uh, compliance, uh, needs as well as governments, right? And these constantly keep adapting and changing.
So, uh, having your enterprise ready and your network ready to adapt to these flex, uh, or these modifications on, uh, data governance and compliance is key, right? It's hard to, uh, rip and replace infrastructure, say, uh, a government changes in a region, the compliance and regulation or encryption regulations change. It's hard to rip cables apart and reroute it around that region if it's not compliant to your, your enterprise.
So having a programmable network that can really just add a click of a button reroute that, uh, path around that region is what's key. Uh, so it, it's a mix of both The regulations are the compliance needs of an enterprise. Example, financial in institutions have PCI, kind of regulations.
Governments may have the GDPR and HIPAA kind of regulations. So, uh, but, uh, businesses have to comply to both. So they, it, it's a mix of both and giving you that adaptability is key and giving you that control pack is key.
Wonderful. Well, um, out of all this, what is, um, what is, say one key takeaway that you could leave our audience with today? The key take takeaway is, uh, just protecting your perimeter isn't enough.
Having a network that extends your segmentation from your boundaries, from your edge, uh, really getting your business, uh, traffic, the business internet. Uh, so the internet was inherently built for, uh, open communication, but enterprises need a different kind of internet. That's the business internet and Raffin aims to provide you that with its, uh, uh, backbone as a service offering, allowing you to program the business internet based on how you are consuming and producing, uh, data and how you govern that data is key.
So I, I, I would really encourage folks to focus on how security can really govern the routing, uh, in, in the age of the business internet. All right. Well, thank you so much for coming on and sharing your insights today.
Thanks. Thanks for having me, Amanda. All right.
And thank you to our audience. Stay tuned. There's more.