API Integration Security – Yoni Shohet, Valence Security
Organizations automate processes by integrating multiple SaaS applications via direct APIs, SaaS marketplaces, and no/low-code workflows, expanding the attack surface and threat to software supply chains. Yoni Shohet, Valence Security CEO and co-founder, discusses the results of their recent survey of CISOs on the state of SaaS-to-SaaS third-party integrations and current security best practices and the resulting 2022 Shadow SaaS-to-SaaS Integration Report.
Transcript
This is Textron TV. The great pleasure be joined by Yanni showhat. Yanni is CEO and co-founder of valence security.
Welcome. Yeah. All right.
It's great to be here. Great to have you here first. Let's have a little bit about yourself.
Tell us a little bit about valence as well. So valence is the second cyber security started. I'm starting after serving in desert intelligence forces in various cyber security roles in focusing on securing it basically SAS applications that they interconnectivity.
So what valence helps organizations is secure what we call the SAS smash this network of interconnectivity that is established through apis therapy Integrations of tokens in different no code no code workflows that allow different third-party vendors to gain access to our course ass applications like Microsoft Office Salesforce and others in our platform helps organizations detect and secure this mesh of interconnectivity by applying a zero trust principles are Tell us a little bit about you, too. You said you were you're in the intelligence service this served in the military. Do you have any specialty that you focused on there?
And so, you know, when you shove into this a lot of it also change the confidential and stays with you but afterwards are really starting my first day startup focused on Industrial iot cyber security called skid offense and a business for several years afterwards. I really started embraced my new Journey focusing on Valence and shifting towards more cloud and tough applications, but I've been in this cyber security industry for the past, I think almost 15 years and from the from the beginning of my career in entirely focused on securing security and understanding the risks and how to help organizations improve the security posture it when it comes to to Modern digital threats. Fantastic.
Well, this is a talk about a prime opportunity prime time for SAS applications low code no code automation through all kinds of tools. You know many many organizations have been accelerated their use of, you know, 365 and team and slack and you name it, you know a different cloud service for General General productivity use as well as you know, the applications so that attack surface, you know, they don't stand alone. Right?
We may use those apps, but we're constantly integrating with them time together doing automation all these Diane and that's part of my role in doing that. I'm sure you find that a lot too. You have any kind of perspective on the market about about the security risks that poses?
Yeah, so I think you're exactly right eventually when we think about the shared responsibility model that we share with these soft applications that we purchase the assess the SAS vendor is in charge of their platform the security of their own infrastructure, but once we get access to their platform and we start to configure it, it's our responsibility and how we secure our identities our data and our basically our most critical business applications and processes and with the growing use and Adoption of Staff applications. There's a lot of benefits in interconnecting these different applications. For example for us even as a young company.
We have our Salesforce connected to HubSpot connected to gong and we have our GitHub that's connected to our gr. That's connected to our slack have commonly that's going to zoom kind to Google and all these different types of Integrations are starting to establish and creating this network of shift of how you can not only utilize a platform where staff applications but how you can leverage full smooth the player of connecting them together and establishing the autom The workflows and dataflows that allow you to save time save money and run a much more efficient and productive organization. And these types of processes are eventually established.
Usually when it comes to South using API based integration between these platforms and it creates a lot of benefits but also challenges because eventually security attackers inversaries identified this as the weakest link when it comes to securing these applications because even if you put the multi-factor indication and you strength your ability to strong for strong indication and authorization Within These platforms eventually if you authorize a third party event or in their breach you're as secure as that third party event or in a typical organization can have hundreds if not thousands of these third-party Integrations and it's very difficult to ensure that all of them are properly secure in your standards and how you expect your organization to be secure. I'm curious were you talking about API access into the services doing integration doing automation? There's there's us building things that utilize the apis of those Services of those SAS Services Etc.
There's also third-party service like a zapier to pick one and easy one, right? It's doing the integration and helping us you consider that also services like that as part of this fabric that that presents this kind of a expanded attack surface. Yes, I think all these basically a hyper automation or no code local platforms like the zapier and workato and Microsoft Power Platform and others they create a lot of indirect connectivity from a security standpoint if I have jira and let's say Monday connected to ASAP here zapier and that's connected in this trading some kind of an interconnected the workflow between the two maybe from a security standpoint.
They look at each platform the separately and I see only are connected to zap connection to zapier. But in fact what happens is that there's an indirect data flow or transitive dataflow between these two platforms now, maybe that's a flow that I can accept in that in terms of the data that's flowing out and data flowing in it's approved from security governance standpoint. But once you have dozens or hundreds of these data flows configure, then one of these robust integration platforms as a service, it eventually can create an exposure to the organization in terms of how are these how is the data flowing between these platforms and whether That proves in terms of who's what platform or receiving these integrated these types of the data sets.
So for example, they just example is always pii if I'm taking pii out of platform and I'm pushing it to a different platform. I need to ensure I have the proper implications steps and the proper coverage in terms of whether or not that additional platform can accept process and store Pi might be half. And if I don't follow all these different data flows and how these Integrations are made I could have different exposure both from regulatory perspective.
But also in terms of a just sending data to the wrong recipient, we've seen a lot of misconfigurations and these platforms because eventually they're configured by citizen developers. It's not they that they classic engineering software development organization is configuring them, but it's more decentralized and managed by the citizen Developers. And it's in it's all you know, whatever experience to is with these tools.
It's an all or nothing. I think, you know authorization token that you get to do this integration. You could be doing a thousand use cases all related or unrelated and growing at their own pace and who knows what's happening inside of that integration.
So one integration can mean you know your whole business and you know hundreds of functions that are operating on that so it gets complex very fast. I know you've done some some research some surveying talking to see I see those tell us a little bit about some of the findings in this area. Yeah, so since we're startup focused on this problem space and we're talking with a lot of customers about it, and we're trying to understand what's the perception about the market the we've realized after speaking with hundreds of cisos that eventually there's a certain perception about this Market which is usually lack of visibility lack of understanding of how big of a scale this problem is within organizations.
And once we connect to an organization and they onboard our platform, they get a lot of visibility into the problem space that contextualizes. How big is their wrist surface and in order to kind of highlight how big the perception versus reality is we a surveyed a group of cisos based on the US that are understand how many Integrations they think they have. How often do you think they think they actually being used how often or what's the pace of adding new Integrations into the organization the option of no code no code and then we compare that to the actual results.
We see from live tenants just to high. It how big the perception I think of the difference there is between the perception and the reality of these environments and to help organizations are encourage organizations to ask this questions such as what's connected to my Microsoft 365 what's connected myself Force what's connected to my slack whether or not organization has proper governments documentation and compliance of all these different staffs after part Integrations. And these procedures are today missing and all of organizations and that's what surveys eventually it designed to highlight for musicians kind of a awareness and the health leadership part a piece that will help organizations in Breaking that question of How does how does my staff's mission looks like look like what type of risk do I have Incorporated in these surprising Integrations?
Now is it also helped with you know, the Integrations you don't know about the apis that folks are using you may have view into your own Department. Maybe it's inside or outside of it. But you know, this is often happening all over the organization not everywhere.
Yeah, so what we're seeing is that it is going through decentralization the process where a lot of the decisions that used to be centrally managed by it and managed by citizen by end users business owners across the board within the organization. So we have the Salesforce administrator that may be in the marketing or Sales Group. We have worked at administrator and HR Group.
We have a lot of different administrators that are located within the organization and once the it is going to really centralization process security also needs to realize how it can go through this centralization process to allow proper visibility detection and response in a decentralized organization. One of the challenges is that it or security may think that they have a certain risk surface, but they're not aware of things that their users of consented on behalf of the organization because everybody's can get this type of pop-up to you consent for this and that to gain access to your data to your privileges and a lot of users happily click. I agree because they have actual productivity benefits from But they're a cons they don't think about the concerns or the risks that are associated with the whether or not this veterans have been there is approved.
They go through the proper security questionnaires and whether or not this type of vendor should be used within the context of the scope of the organization. So the ease of creating any Integrations creates a lot of blind spots for ceases and security teams because they just they don't know what they don't know that's connected into their environment and this is probably one of the major reasons that we see such a difference between what csos assumed they'll have compared to what they actually have. And I know enough for just some experience too that oftentimes those agree to you know, interconnect as I'm done with the users account, right exactly who knows what happens when you know, they move on they change departments, whatever.
Okay. Well, let's talk a little bit about I'd love to hear more about valence and you obviously working this space and bringing all your expertise current past them. How do you approach this problem?
Yeah, so what we hope organizations eventually a manager decentralized process of remediation within the organization. So we realized that after we connect to the course of applications of organizations that we highlight the risks. The biggest piece that is missing for security teams is not a better tool to find more risk, but they're missing business context is just doesn't exist in the platform because if I go into connect to someone and say Microsoft 365 or Google workspace and they showed that for example calendly is connected maybe it should be connected.
Maybe it shouldn't but the security team just doesn't know and what's missing is the business context that only the business users and the end users actually know what we help organizations is besides detecting their assassination understanding how everything is in the connected is also to execute that scare remediation workers that allowed to engage with the end users collect their business justifications business context and continuously validate the actual Need in order to help remediate unnecessary or risky Integrations and configurations based on the continuous engagement with natural business. So it's a trying to apply the same methods for security rendition workflows such as the business is already applying for onboarding new sass applications. nice, and we also work with developer the developer part of the organization.
So it's both citizen, you know SAS tools as well as app integration developers. Is there a difference with how you work with engineering resources versus citizen developers or basically the same approach? So it's similar approaches.
I think that it's always important to meet users where there are. So if a user is very used to using slack instead of Google emails, for example, so it doesn't help if you email them about notification, they'll probably never read it. So it's very important for the organization to adopt their a workflows to how they're organization operates.
So maybe it's less whether if it's a developers or citizen developers, but more about the culture of the organization if it's a tech Focus organization and it has a certain set of the South applications that may work in one way. But if it's more of our traditional organization that has a different set of sex application, maybe a little operate and a different way is a really depends on on the culture of the organization how they tries to enable Innovation within the company. Excellent.
Well, we're by the where are you in your kind of product life cycle? Yeah, you've been around for a couple years. You have product and Market, I assume and general availability.
Are you still in a kind of early access where you and your your life cycle of where you are roadmap? Why is yeah, so we're at the general Liberty mode. We already have multiple customers using our platformer worldwide and we've utilized a lot of these different Keys cases across the board with a few dozen the SAS applications and then they really showed how the organizations can Define policies and applied in that scale when it comes to securing and remediating SAS risks.
So it's something that they were their proven. So definitely General availability. We have presence engineering and product development a presence in Israel.
And our go to market team is based out of the US and definitely seeing more more requirements and requests for these types of the solutions. And are you assess yourself or you open source on Prem or what on the cloud but with software, what's your solution? We're pure assess there.
We need to eat our own dog food and eventually we're happy to secure South applications. But the we're very focused, of course on securing our our customers data and Privileges and what's up to type to compliant and we've invested from the early get go and compliance security best practices to ensure that we earn our the trust of our customers of the time. Yeah, I remember Mr.
Going back ways. When we first introduced intrusion prevention and detection and vulnerability scanning and management the the first aha was just what was going on. And how much of it was going on.
I think for security organization similar effect with when you run your product or they're different and other sort of aha moments. Yeah, so I think the biggest ha moment. Usually when our customer connects just to scale of their exposure through their body Integrations.
Most organizations just don't realize how big of the problem they're having how many of these Integrations were set up in the first place in our service example, we found that the cesos underestimate the number of sector about integration. They have by four to five times. So average number was left in 200.
We're in fact, we see almost 1,000 Integrations in place within the organizations almost five times the number of assumed or estimated by thesis. That's scary. So how do you find out about all this stuff?
I mean I can imagine in a back in a in a network that we managed. We could put a device and kind of watch traffic Ingress and egress go out and see what's happening how you do this in this world of completely distributed applications SAS, and maybe I don't even use vpns for a lot of this for my end users. Yeah, So eventually how we imagine the modern Network.
It's in the cloud between SAS applications. A lot of modern organizations don't even have an on-prem environment. Therefore.
We identify the core SAS applications the business critical ones that we connect to them and through discovering their configurations and activity logs. We can find out to the edge of the mesh what type of third party integration exist and what other vendors are connected to these courses applications. You can imagine start with your email start with your collaboration start with your CRM some of those at many things are going to interconnect with those.
Right. Yeah, exactly. Okay makes a lot of sense.
Well, very cool. It seems like a great space to be in and wish you much success. Hope you'll come back and keep this up to date when new things happen and maybe share some more data.
Imagine. If you do additional surveys working folks either go find the the report that you referenced and I'm sure you have some resources some goodies that can find on your website. com.
So it's v a l e n c e security calm and we also offer for organizations today are free assessment to help understand their own risk surface and to do this type of initial risk analysis to understand what the what's their resurface and whether or not they or how they should basically tackle this type of problem space to make it more contextualize more real and to contextualize more of this it threats the war trying to highlight for the report. Sounds really interesting other coming to check it out. Thanks a lot.
I appreciate having you on Yanni showmet and Yanni. Is Yoko founder of valence security. Thanks for joining us.
Thanks, Mitch.