Adaptive Identity Management – Lior Yaari, Grip Security
Fresh from raising $41 million in additional funding, Grip Security CEO Lior Yaari explains why managing identities requires an approach based on the level of risk a cybersecurity threat represents to the business.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Leonor Yari, who is c e o for grip security, and they just raised another $41 million.
We're a platform that helps manage identities and keep everything secure. And we're gonna be talking about, well, just where are we on this adventure with managing identities? 'cause I feel like we've been at it a long time, but maybe not making as much progress as we should.
Leora, welcome to the show. Thank you. Thank you for having me today.
Everybody and his brother is talking about zero trust, and everybody nods their head, but then when they get into the weeds on it, they discover it's all about managing identities, and it doesn't seem like we have the infrastructure to manage that. So from your perspective, what really needs to be done to connect the dots between managing identities and better security? Yeah, so a Gartner who originally defined Zero Trust as the, the biggest buzzword of, uh, 2020, uh, announced the the new zero trust, what they call the cyber security mesh architecture.
And they say in the world, well, data is everywhere and access is anywhere. Identity and context have become the ultimate control surface. So for them, because now in the world that we live in, the applications are everywhere spread on the internet, the users are everywhere, spread between different networks, and the data moves from anywhere too everywhere.
Identity is the only thing we have left as a, as a barrier between, uh, data. And I'll use those, uh, sensitive applications and our workforce. So this, this sudden goth in identity and how much people are talking about the identity fabric, those identities that are connected to each other through different systems and applications, uh, it is not a coincidence, um, when we cannot rely on our boxes, on our firewalls, on our eds antiviruses to monitor user activity because the users can use a different computer from a this network, the identities, all that we have left.
Um, and it's a huge challenge for companies to overcome. And what makes that so challenging? Is it just that there are so many variations of identity and so many things that people are trying to access?
I mean, theoretically we've been managing access for decades, but maybe not so well. So if you look at traditional identity management, they had one advantage that doesn't exist anymore. And that when the user left the company, even if he didn't do anything, they lost access to their identities within corporate systems.
If a clerk in the bank left the left the bank, they wouldn't have the ability to log in, even when the identity, the user still exists and still has access. Um, what happened in SaaS and uh, and a term we like to talk about is identity debt. When same like tech debt, when users create identities or when the organization create identities, they take this debt on themselves that one day they need to pay, removing those identities and access.
Um, what's changed is that if in the past the IT and security organization was both creating debt and paying it back today with the barrier for adoption for new application, the ability to create another identity is a sign up form. So the users, the workforce creates identity debt, but IT and security are still responsible for making sure that they don't have a SaaS for when someone leaves the company, same equivalent as we had before, the they can still access all those applications that they sign up to because those applications are now on the internet. And the unaware of the, of the workforce change that just happen, Who's in charge of this?
Is it the security people or is it supposed to be the application owners or does it seem to fall in between them? And as a result, nobody seems to do enough. Uh, so the problem is who's in charge of this is the application owners.
And, and again, the the marketing app that that drives the marketing organization used to be managed by it, but now is managed by an APPLI distributed application owner, could be the head of marketing and then the head of dev on the development side, the C F O for procurement applications or finance applications. Um, and while they are responsible, if you ask who is to blame if there's a security breach, it's definitely not them. It's a security team that's responsible for all of it.
So from their perspective, they need to change the model of how they distribute responsibility audit applications to adjust to distributed local management of the applications themselves. It seems like the bad guys are getting better at compromising identities and now they have these lowly new generative AI tools to play with. So is this gonna become a bigger problem?
Uh, the bad guys, uh, it is fascinating to look at them 'cause of the innovative, the, uh, criminal innovation is faster than, than the Good guys innovation, meaning we were chasing them and understanding how they adapt in order to secure things. Um, what they found, found out is that corporate identities are now equal to private identities. com identity.
We sign up to applications on a weekly basis when we buy groceries, all the gift cards travel. And when one of those identities is compromised, statistically there's an equivalent corporate identity that uses the same username password. Um, what the tackles now that they they can do is that they're now not bound to a single system.
If one of those single system is breached, they can just take the username and password pair and try to log into the rest. In 2016 as an example, one of, uh, um, Uber's employees lost their credentials to, uh, LinkedIn to a phishing attack. And the same credentials were used then to log into the GitHub account instead.
This is how Uber was breach in 2016, happened to Chick-fil-A just a few months ago. Um, and the challenge it creates is now your private life and corporate lives are connected in, in the risk that it presents to the company and the, the risk surface of the organization change. And going back to the identity fabric, this is the fabric.
The identities are connected to each other. When one of them is compromised, it affects all of the other system that they use. And when the organization not, doesn't necessarily know what those applications are, because again, they don't need to ask for permission, users don't need to ask for permission before adopting a new application, using a new identity, it becomes very hard to secure them.
Again, this is why grip is going so fast. We, we give our customers the visibility into what systems are in use, where identities are created, and automate the mediation and identity management piece for them. Um, and it's a huge problem for every company today.
Do you think that maybe AI will save us from ourselves one day? I mean, you guys have a platform that has visibility into all this stuff, so you must see a lot of telemetry data and things that suggest anomalous behavior. What can we really expect from ai?
Um, will it save us from ourselves? Uh, yes, but it would also help the other, the bad guys, uh, create new problems. Mm-hmm.
So ai, AI is a blessing and a curse, and it's just, it's another, another weapon we use in the cyber wall, uh, both to defend and, and attack on those side. So we, we leverage AI for almost everything that we do. And there's some amazing capabilities and, and insights you can, you can generate from ai, especially on the, especially generative AI that, that we are now, uh, experimenting with or building capabilities with it, it still wouldn't affect how the workforce operates.
So AI helps when you need to create content or create new things for the company or make decisions in a smart way, but the users themselves are the one operating it and they would operate it insecurely like they've done for years and years. Now, Is it your sense that the attacks are coming in and the attackers are kinda, uh, living off the land as it were, and they are basically acting like normal end users for a period of time and then, you know, quietly doing things on the side that they hope nobody notices? Or is it still more of a smash and grab kind of thing?
Well, you know, the came all shapes and sizes. Um, I think the smash and grab, um, is usually what we see out there just because you never know what's gonna change on that side. So especially when it comes to compromised SA applications, you hackers don't break in.
They log in. So they log in, download everything that they can and land as fast as they can. If the smart about it or if the attacking a certain type of organization, sometimes, um, being in the application for a long time has a benefit.
I can give you, I can give you a good example for this as a, you know, complicated smart financial fraud. com, uh, which is a boardroom management application. It helps you create slides for your board.
A smart attacker that gains compromised credentials to a Fortune 500 companies diligence account, can, um, see the numbers before they're published on, on the NASDAQ and buy and sell stock. They can make more money doing that with, uh, smart, uh, earning calls than, than packing into the bank account. And this is an example where we don't, you don't need to steal any data.
You need to download a presentation once every three, three months, and you can make millions of dollars every time without, without doing damage, visible damage to anyone and without the company even knowing you are there. But you need to be stealthy in order to stay there for a long time. And diligence.
For us, this is a good example just because it's a, it's an application we're well familiarized with as it has its own exposures. Well, almost by definition this application is not managed by security, doesn't have the proper source, but also the people who are using it are so important to the company that you cannot tell them now it's the C F O and the c e o and the c o o who are using the application. They would do whatever they want.
They definitely don't, don't ask for full permission before they do it As we go along. Do you think that it's gonna be easier to secure identities if we use things like multifactor authentication and biometrics and all these other things? But, and I know we've been talking about it for a while and I'm not sure I'm seeing a lot of progress on that front, but, you know, what's the relationship between using those tools and maintaining identity?
Yeah. Um, so using, uh, S S L M F A is definitely the right thing to do when you secure identities with online. The challenge is, it, it becomes this ongoing chase where a user is creating an identity security need to understand that, find them, force 'em to enforce M F A, and by the time they, they're finished with this project, this new applications is popping up.
It's a, it's a whack-a-mole kind of situation. You find one and there's another one that you need to, to go and chase. So without automation, there's no reasonable way to enforce an M F A M F A M F A everywhere policy.
And you can see that, uh, for example, new N Y D F SS regulation in the financial sector in the us um, require every financial organization to enforce an M F A policy M F A everywhere policy. But the, there's a realistic difference between the requirement on paper and the ability of the organization to actually do that. And without automation that they, they wouldn't see success.
Um, the reason you, on the other hand, see so many identity startups being born is because without automation they wouldn't see success. So there's opportunities to automate some of those big projects. Is the end goal here to prevent all these identity-based breaches and attacks?
Or realistically, am I just trying to kind of contain the blast radius of the inevitable? Um, I would say prevent is, is the goal. Um, I don't think it's inevitable.
Uh, in general, uh, learning a security program is like chasing from a burn. You just need to make sure you're not the slowest. So enforcing M F A controls, enforcing, um, reasonable identity hygiene within the organization dramatically helps to reduce the risk.
Um, there's so many exposed organization out there that bypassing M F A is just, is not worth the time for, for the average, uh, attacker. All right, folks. Well, you heard it here.
You don't necessarily have to be a victim. Somebody else might be the victim instead, but you gotta take the right precautions to make sure that doesn't happen. Leo, thanks for being on the show.
Thank you so much. All right. And back to you guys in the studio.