Achieving Zero-Trust Cybersecurity with AppOmni’s Brian Soby
AppOmni CTO Brian Soby dives into why achieving and maintaining zero-trust cybersecurity needs to go well beyond simple identity management.
Transcript
This is Textron tv. Hey guys, thanks for the thrill. We're here with Brian Sobi, who's CTO for App Omni, and we're talking about Zero Trust and well, it may be a little more complicated than we think.
Hey, Brian, welcome to the show. Thank you. Appreciate having me.
There's an assumption that all I need to do is kind of figure out how to manage identities and the way I go, I've got the whole Zero trust thing mastered, but if it was that simple, we probably would've done it a long time ago. So Brian, what are the challenges with Zero Trust and what are we not thinking enough about? Well, I think a lot of organizations just stomp a bit short.
And so if you're looking at your identity, you're looking to say, here are my corporate users. They can go all these places. Maybe you have, um, single sign-on, you have MFA locally for them, and then you probably have solutions to get them different places, whether it's zero trust, network access, or, uh, solutions to get them into different applications.
But you most of the time kind of stop looking to see what happens after you get them those places so you can get them, you know who they are, you make sure that they have their hardware token or whatever, and then you deliver 'em to a place and you, you sort of stop paying attention. What a lot of organizations don't do is to monitor the whole life cycle of that user's activities, what they have access to, what they are doing, and feed that back into the rest of the system to say something like, um, hey, that user has been acting suspiciously. Maybe they're pulling down all their data from these different applications, or something to that effect.
Perhaps I want to think about a different policy for them to be on with respect to MFA. Okay, maybe they were on SMS, which is, you know, possible to, to forge and uh, or to, to hijack in those things, perhaps based on their recent activity, that's an indicator that they should be stepped up to a stronger policy or their access should be restricted from getting to these key places because they, you know, they're in the potentially compromised bucket or potentially insider threat bucket at this point. So that's kind of what we see a lot is that the identity story doesn't go far enough, especially when it ties into zero trust because people just, um, don't have the right level of visibility and what they're actually doing.
It kind of sounds like, um, we're not managing the entitlements and so it's roughly equivalent to I'm selling, you know, first, second, and third class seats on an airplane, but once the plane takes off, everybody can move wherever they want regardless of what they actually purchase. So, um, how do we kinda wrap our heads around where all these things are supposed to be, how to track them because, um, it's not already built in the system. So how do I add that after the fact?
That is one of the core tenets of zero trust. If you go back to zero Trust, one of the key things that it says is you need to be making authorization decisions, uh, at the most granular level possible. And to your point, it is very all or nothing right now.
We just say, I, you know, I don't know. Once they, once they get to that place, they can just do whatever and we don't really know. And the decision is really at the level of whether or not they can get to the place, uh, which is not even remotely the intent of what we're supposed to be doing with, I mean, going back out of zero trust world to, to just basic concepts such as lease privilege.
We're supposed to say, do we actually understand what entitlements they have within each of these places that the enforce entitlements separately and autonomously. So when they get into an application, their entitlements within that application are enforced exclusively by the application. And there are, you know, we have other proxy type solutions that attempt to like reverse engineer certain parts of applications and, and block at least a corporate users block them from doing different things.
So it's like an external entitlement management system in effect. Uh, but for the most part, the source of truth is those destinations and whether it's, um, you know, a SaaS application or AWS if you go into the entitlements engine, so I am an AWS or whatever bespoke thing in each SaaS application, um, that's where those enforcement points are and that's really what you need to understand to have good visibility into granular authorization decisions in line with what you were supposed to have put in for zero trust principles. Uh, just understanding those, what they mean at a, at a useful level instead of just, oh, they, they're, they're a member of this active directory group.
Okay, well what does that translate into specifically for M 365 or ServiceNow or whatever? Because it, it means a whole lot of application specific things that you need to understand. Uh, just bringing that into the fold gets you much closer to where you're supposed to be.
And there'll never be such a thing as kind of perfect security everywhere. There's always gonna be some sort of incident involving credentials and identity, but I think we don't think through what the blast radius implications are as it relates to what you were just describing. 'cause the bad guys, one of the things they love is once they get credentials, they can go anywhere.
Yeah, I mean, we saw that, uh, we saw that recently with the, the Snowflake breach. They got credentials like just kind of running the mills stolen credentials stolen by malware, and they took those and decided to go directly to the targets, um, bypassing what would otherwise have been all the enterprise controls. And I mean, a lot of, a lot of those customers that were involved, they could have had, you know, VPNs stacked on top of sass e stacked on top of SSC and these other products.
And it doesn't matter if somebody just grabs the credentials and goes directly to the target bypassing everything. So understanding, understanding where that can happen and having really end-to-end integrity behind your identity management is another key part because you can have, you can have great identity provider policies, you can have great MFA, you can have great, all of those things supported corporately, but if the destinations to which users are going and, and bad guys are going view those as optional, or they view those as bypassable, you know, you can go around the ips that are, that your, your SSE egress is going to use and just go directly to the targets, then you don't really have effective identity management if somebody can grab stolen or phished or whatever credentials and go directly to the targets and use them, um, you know, and undermines the, the integrity of the rest of your system that you're trying to put in place. And doesn't it undermine the return on investment in security As a lot of people asking difficult questions these days that we poured all this money and we don't feel like we're any more secure than we were.
And a lot of that just comes down to the fact that the bad guys are just stealing credentials and they're not bothering with let me go, you know, do 19 levels of code engineering. They're launch some malware thing. They're just like, Hey, you guys made it easy.
Thanks. Certainly all of the customers involved in the Snowflake breach that thought they had single sign on, zero trust and ZTNA and those types of things set up, protecting them from stolen credentials and Phish passwords and all of those things probably realized that they, those investments didn't actually pan out because they stopped too short and they put in a, you know, a 75% solution and the bad guys are living in the land of that other 25% and whatever investments they may have made, you know, very, very clearly turned out not to be worth what they thought they were. And I think a lot of folks that are doing especially zero trust projects, um, they're stopping too short and they're, they're really undermining the entire project by not going all the way and saying, great with what we just put in place.
It's like putting in, you know, putting in a big fence around a construction, a building under construction or something and leaving just a massive gap. Like the massive gap undermines the entirety of the rest of the fence and somebody can just walk into your construction site. Um, that's exactly I think what people are experiencing.
Well, the fence is three feet tall, but it's the same idea. Um, what, um, so where should people be on their zero trust initiatives? What is the spectrum of the effort?
'cause I think a lot of people simply don't know and, uh, they're confronted with a million zero trust things, and so they buy a couple of them here and there, but maybe they don't really have a full idea in their head as, you know, what is the beginning and the end of this thing? I think they need to realize that it is, their goal is that is an end to end implementation, and it's not. There's not gonna, in all likelihood, there's not gonna be one product that just does the zero trust.
Uh, you need to look at what your requirements are, what your organization does. I think most organizations at this point are, are fairly distributed or have to at least support distributed concepts. I think a, most organizations have heavy usage of cloud and heavy usage of SaaS, and they need to incorporate that, and they need to recognize that yes, we do need to know, uh, what's happening on the endpoint.
We do need to know what's happening with authentication. Uh, so how the users are authenticating and do we have MFA and do we have, um, you know, passwords configured how we want or totally disabled? And then where are our users going?
Are they going there securely? And then in the places that they go, are those also locked down? Because a lot of organizations also have these external collaborate collaboration use cases, whether you're talking, um, sharing files and folders and stuff out of something like an M 365 or a Box or a Dropbox or, or G Suite or it's, you know, you have a lot of your collaboration products, whether they be Slack or Salesforce or, or, or serves now that have these portals and external communities with external users that will never go through any of this.
A lot of this, like the zero trust network access stuff, they'll never use that because they're external by nature. Um, and bringing them into the fold and saying, here, here's the totality of users that I'm observing, not just my corporate users, but my corporate users plus our customers and partners or maybe just, you know, external anonymous users. Let's bring all of them in a fold, let's make sure we're end to end.
We understand everything from the device through the user, through the transport to the applications, and then things plugging into our applications from the other side, cloud to cloud. We've seen a lot of supply chain breaches and cloud, cloud connections immediately become problematic. You need to have visibility around all of that, uh, in order to really know that your, your zero trust project is, is hitting your goals.
When I talk to a lot of folks, part of the problem is the business side itself. Um, a lot of the access is granted by a business exec who says, these people need to be able to access X, Y, and Z and then six months later, half those people are working on some other project or they've left the company, but they never kind of circled back with anybody in it to say, you know, deprovision, this, that, or the other. So how much of this is a process cultural issue versus a technical issue?
So I think with the new, the new distributed model that a lot of organizations are taking on their businesses, are they primarily own first line administration of a lot of these systems? And that's gonna include provisioning, de provisioning, movers, leavers, things like that. It's also gonna include, um, the, the, the configuration of lease privilege and, and all of those other things.
So there certainly has to be a new style of conversation that happens between security teams and their business counterparts. So security teams are, are all likelihood are not going to be the ones that are, are in those applications day to day. They're logging directly into 52 different products.
Um, they do need visibility. They need to understand, hey, we have a portal into which we can see everything that is happening within all the systems that our businesses are, are administering, and they need ways to look for anomalies such as, you know, this user was de provisioned out of 10 systems, but not these other three. Okay, that's probably an issue.
And if you have that visibility and you do have your, your folks that are at the end of the day accountable for security, which ultimately that does come back to the security organization. Uh, if they do have visibility and they do have the ability to identify either bad and bad practices with respect to least privilege, you know, why does everybody in this particular organization's application or whatever it is, have admin access or they are able to see it appears we have a, a deeper visioning problem or a movers leavers problem because these systems over here do not reflect what has been changing in these other ones. Or, you know, there, there's no reason why these systems over here of random access, random logins from Russia and the rest of 'em don't.
That's probably another issue and we need to get visibility around it. You cannot walk down the street these days without somebody telling you about their new great AI thing. Can AI be applied to any of this?
I mean, can we use tech to save us from ourselves? I think there's a, there's certainly a role for AI to play. AI does a great job.
Um, certainly a lot of the LLMs that we see getting, getting more and more popular, they do a great job in summarizing a lot of information into something, uh, much more concise. They do a, a pretty good job correlating things together, provided the data volume's not too high. You know, you wouldn't want to give a raw event stream to a, to an LLM if you, you know, wanted to safeguard your, your pocket and your checkbook.
But, um, they, they do a pretty good job of like a first level analyst could do in presenting information or to say, you know, it appears that there is an event going on because of X, Y, and Z. Um, and to save our first line defense some time by presenting to them customized, summarized, and initially correlated data out of the vast swath of data that is available to that, especially as they gain responsibilities to have security oversight roles for a large number of different business applications that are now starting to do their own thing. Anything that they can do to save themselves time and just make sure that they're looking at the most important places for them to spend their time is gonna be a benefit.
And it feels that AI is mature enough where we can get there and we can get their effectively without running into what everybody realizes are, are some of the pitfalls. You know, it's not always dependable. Sometimes things are just absolutely fake and made up.
Um, those don't matter when it's acting in a role that you would have people otherwise doing. Where those types of errors are also acceptable, that kind of first line triage, What is your sense of how to walk this fine line? But, um, on the one hand, we don't wanna blame the victim.
On the other hand, sometimes it feels like we have done not enough to the point of being negligent. So, um, where are we on this kind of journey between, you know, should I just assume now that uh, there are bad guys in the world and I need to do something to protect my environment? And if I don't, whose fault is it?
Or is it the bad guys? Or to what degree are we co-responsible? I think, I think we as an industry are a little behind, a little behind the ball.
We, we transformed the industry very quickly. We transformed, we were kind of going to cloud and kind of going to distribute it, and then everybody went there really fast over covid. Uh, we're a little behind the ball catching it.
And I think that's probably, you know, that's a, that like anything that's a shared responsibility. But at the end of the day, customers are the ones that primarily and organizations using, using technology are the ones that need to understand what they're using and adopt practices, techniques, tools to implement their intent across whatever technology choices they're making. And so, uh, as they go to cloud and SaaS and distributed offices and no offices, um, those are explicit, the explicit decisions for them at the time to do that.
And a responsibility that you have when you do that is to update and upgrade all of your practices, your tooling and your programs in order to track with those decisions. And we got out a little off in front of ourselves. Uh, now we just need to catch up.
So it sounds like we at the very least know what needs to be done, but perhaps we're in a situation where things might get worse before they get better. So how much worse in the short term? I think we're gonna continue to see a series of breaches until folks realize that these trends that they're seeing do in fact affect them.
Um, and the choices that they have made are probably not too dissimilar than the choices that the companies that they're seeing in the news have made. And that if it can happen to them, it can most certainly happen to, um, to the, the all the companies that are spectators or believe themselves to be spectators to these breaches, not realizing that they need to probably catch up quickly with their security practices. Otherwise, like they, they're in the exact same position as those companies that they see in the news.
They just haven't identified that reality yet. All right, folks, just like in real life, yes, you are the perfect right to take your fancy car, drive it into a neighborhood that is somewhat unsavory, and leave the keys in it and unlock those doors. But don't be surprised when bad things happen.
Hey Brian, thanks for being on the show. I appreciate having me. Thank you.
All right. And back to you guys and Steve.