Application Workloads and IaaS – Rich Dandliker, Veza
Rich Dandliker, chief strategist for Veza, explains why even after more than a decade of cloud computing the number of cybersecurity challenges organizations face continue to abound as more application workloads are shifted toward infrastructure-as-a-service (IaaS) platforms.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Rich Den Liker. Who is Chief strategist for visa? And we're talking about Cloud Security in the lack thereof of Rich.
Welcome to the show. Thanks Mike. It's great to be here.
We've been talking about the cloud and the security in the cloud now for a decade and I don't feel like a lot of progress is being made and the issues seems to be it's not so much the infrastructure which we obsessed about but rather the processes and the way we secure data in the cloud that seems to be an issue. So explain to me if you would what you see from your perspective is what is the fundamental problem? We're having with Cloud security.
Yeah, that's a great question Mike and I think you could see it all around. I think there's you know ransomware is getting worse and worse. The number of breaches seems to be getting more frequent and I actually came most recently from OCTA where I was there for about four and a half years and love the PM team.
So I sort of have identity on the brain and the great thing is that there have been a lot of Innovations in identity around authentication around single sign on and multi-factor authentication, which is great and has really improved the world. But you know, it's it has been enough and so I think what really became clear to us here at baysa is that identity needs a second act like we haven't really gone far enough and we've done a lot around authentication around sort of like the the front door making sure we have, you know, we're getting rid of passwords and moving towards password list and we have second factors all over the place. But really it's that fundamental question around who can it should take what action on what data and particular that authorization.
Or that has really been a missing piece of identity Solutions today. And what don't we gonna do to solve that issue? Because I mean we have identity access management forever and we have authorization but are these things just not aligned with each other?
And what does it take to actually kind of implement that on platforms that don't really belong to us? Yeah, you're you're right Mike but we have authorization but the reality of you look at some of the tools on how you manage authorization. So you look at you know, IAM tools like OCTA or you know, IGA identity governance and administration tools like sale point and really the way that almost every organization is trying to manage these things is simply with roles and groups, right?
That's really it. And so when you're asking simple questions, like hey, you know who can go edit my customer database which incidentally is the most relevant question when you're thinking about ransomware who can actually apply encryption on really really critical customer data. They actually have a hard time answering that question because they're they're down to when they do things like access reviews.
They're actually reviewing hey, you know is Fred a member of the marketing marketing team. Yep friends a member of the marketing team. So we should be in the Marketing Group, but does that mean Fred has the ability to go and edit the customer database?
Gosh, I don't know. I hope not because I know Fred and I wouldn't trust him without level of access. But what ends up happening is that people are forced to guess just based on the name of the group and they say well marketing does that mean they have edit access to the customer database?
You just don't know and so they're there tend to be gapsed and these gaps are then exploited by attackers. It's really this Promised Land of least privilege. That's the thing that everybody knows they want to get to everybody dreams about everybody talks about and says, yes, that's a good thing but almost nobody can operationally get there.
All right with all due respect to Fred. It's not really his fault who's in charge of all this because without a bit of yeah. It seems a great it's a great question the business people are in charge of giving authorization their delegating who should be able to access what data the IT people salute and they just give that access and the security people hope that the people accessing things are actually the people who they say they are but it seems like maybe there's another way of thinking about this.
That's right. No, it's it's very insightful. Is it is it is today a shared responsibility which means practically it's nobody's responsibility, right?
Because there are so many pieces and that's that's actually one of the complicated parts of the cloud is now to really get the answer that question to really understand it. It's all these different systems getting woven together. It's identity systems like OCTA or Azure ad that are linking into these massive Cloud platforms like AWS and Azure and Google Cloud that are then hooking into individual systems like snowflake that's running on any one of those clouds or any one of the the many many hundreds of services that exist here and each of those has a piece in this problem of authorization.
So you really got to stitch it together. So it's a little bit of the identity. It's a little bit of the security team.
It's sometimes it's the data owners and it the people who are actually running and in charge of the system the system system administrators. And so it's that classic sort of problem that that fills the between everybody and so no one is really typically tasked to solve it until you get someone. Very often to see so that says hey this is such a big problem and a threat and a risk the organization that we're going to step up and solve it.
Do you think the bad guys are laughing at us? Because we spend all this time trying to secure these Cloud environments. We spend a fortune and all they're really trying to do is fish.
Somebody's username and password to get access to the data and they're just like, you know, well glad you guys are doing all that but we're going with the path of least resistance. Yeah, that's right. And really it is about making it.
You know, it's you can never fully keep the bad guys out. But you want to make it as hard as as humanly possible for that beginning and limit what they can get. It's a it's about limiting that Blast for you.
So what then they when they do get to a successful set of credentials. They get fishing. They only get what the minimum if they get Fred's Fred's credentials, you know, Fred doesn't have privilege to access if Fred doesn't have the ability to really do what needs to be done force them to go farther force them to to keep roaming around in the environment because that gives you a better chance to actually catch them and stop.
There's a school that thought that says we're supposed to encrypt everything that's in the cloud and crypt everywhere. We've heard cloud service providers say how feasible is that? You know, it comes back to the same problem of the classic issue with encryption has always been not not the core technology of encryption, but it's really been Key Management, right?
Because you have that same problem of like well, then who has the keys who should have the keys who gets access to actually see this stuff. And so you're back to the same fundamental problem. It's very rare that an attacker is taking advantage of core gaps in the security infrastructure.
As you point out. It's really about misconfigurations. It's about someone having access to something.
They shouldn't it's about someone, you know, someone leaving the door open not that they're fundamentally breaking down the door. And so I see encryption as a nice thing, but it's not the fundamental problem. It's really that that gap between the technology and the people and how they fit together that that really is.
It tends to be the Gap. That's most often exploited by attackers. You cannot walk down the street today without somebody telling you about their brand new spanking AI platform.
We hear a lot about AI in cybersecurity. What is the current state of the art from your perspective and can AI save us from ourselves? It's a Wonderful question and one I am just I'm both What it's it's wonderful and terrifying to see all the things that that AI could do, but I think there's a there's a tremendous amount of really interesting things.
None of which I've really seen yet to be fair. But I think the core thing is is really when you think about managing policy like the amount of complexity there is really really hard. And so and so it's it's making really the the connection between these plain English language Common Sense types of security policies, like hey, you know, as you know, if I'm a see so and I want to say I don't want anybody no contractor in China should have access to my source code.
That's great. And that's a very reasonable thing for many organizations that that it might make some decision like that. But then trying to translate that plain English language security policy and really understand like now, what does that imply in technical controls down to the level of actually implementing these policies in days on blobs and configurations and figuring out how all these systems fit together.
That's I think the big challenge that we're seeing again and again for organizations that I think Ai and ml types of solutions will be able to help with right things like natural language processing things like really be able to understand all this complexity and boil it down to a fairly simple thing about who who can it should take what action what data I think fundamentally those technologies will advance a lot. I don't think they're there yet, but we're we're definitely getting much much closer and you know, we're certainly much closer than I thought we were two months ago when when chap GPT and and being chat show it off some of the the really interesting things that they've that they've a integrated with We've seen bad guys start to hack those platforms a little bit to figure out if they can use them to create more elegant fishing messages that will then steal credentials have we reached a point where I think people have it in their heads that you know, we give people username in the password that they're responsible for that and that they will safeguard that and act accordingly but I mean reaching a point now where that's just not a reasonable expectation because people can be easily full now and even the most sophisticated end user is gonna find out one day that they, you know gave up the keys to the kingdom. I think that's absolutely right.
It's gonna be it is a very scary time especially when you when you think about the the what what these these types of Technologies enable in terms of really really sophisticated targeted spearfishing attacks that you can now start to integrate in computer generated images potentially sound and audio potentially video and and leave, you know, and linking together deep fakes into these kinds of security and spearfishing attacks. I think it's it's gonna be it's gonna be a rough time especially for end users because as everybody knows it's you know, it's not just about whether an end user can do it, but it's just that you know at your weakest time when you're the most stressed and you're the most under the gun that's when you're you're liable to say. Well, you know, maybe this is good enough you just you let your guard down for one bit and that's when the attackers take advantage.
So I think it is a question of really making sure that that we support and users with as any tours as we can because depending on the end user to really keep all this together is it's a big ask for everyone across every minute of the day. where we naive in our early approaches to cybersecurity where we had this kind of Castle and moat kind of metaphor and we were going to defend all the access to the castle without made me realizing that the castle has no roof and people are just going to go throw stuff over the walls and you know, it's kind of feels like we obsessed about the perimeter without really thinking through all the way to the data. Yeah, I I think it's it's certainly not even retrospective.
I think you're right. I think the other thing though is like a lot of these things you have to see how it works in practice and you know, a lot of these things work in an ideal world, but when you get into a real-world situation or when you get with real users and you see what people do day in and day out that's when you learn really what's sufficient and what's not and we've plainly found that what we have in place in the current way. We're going about all this is not yet sufficient and that attackers are able to to really keep a head.
So, you know again, it's the difference between you know, how would this work and in an ideal State on on paper versus what actually happens in real everyday organizations and and that's that's I think the big difference. It's just the reality of the world. So, once that one thing you still see people doing that makes you shake your head and go I can't believe that we're still seeing this behavior in this day and age.
you know, I I think it is just Really not it's not implementing some of the basics. I mean, you know, like I think there are a few instances where you know I know there's a bit of a security walk thing. But you know SMS is a secure second Factor like man that that kills me.
There's been way too much going on where like, you know, and sometimes like, you know would even with my own personal my personal personal way if I have financial institutions and all they offer is SMS is the second Factor. I'm like, oh gosh, I really I really wish they wouldn't just because the account takeovers too easy. There's just way too much stuff to be a really secure second factor, and that's one that sort of not.
It's maybe not commonly thought of as that but certainly when you've been around security long enough, that's the that's the one that makes me cringe. All right, folks date is like a diamond you can buy security guards and you can bolt every door and every window that you want. But sometimes you're better off just putting that diamond in a safe and calling it even hey Rich.
Thanks for being on the show. Yeah, it's been great Mike and I really appreciated the time. All right.
Thanks to you guys in the studio.