Backup Everything — Including Identity and Configuration
Everyone backs up their data. Almost no one backs up the configuration around it — and that’s why a single misconfigured DNS record, deleted Route 53 zone, or wiped Okta tenant can take an entire business offline even when the data is safe. Aharon Twizer, CEO and Co-Founder of ControlMonkey, joins Alan Shimel on Techstrong TV to walk through the resilience gap most cloud teams don’t see until an incident hits. Drawing on his journey from co-founding Spot.io (acquired by NetApp for $450M) through AWS to launching ControlMonkey in 2022, Aharon explains how the platform reverse-engineers live configuration into code across AWS, Azure, GCP, Cloudflare, Akamai, Okta, Entra ID, CrowdStrike, Zscaler, Palo Alto, and even Datadog dashboards. He and Alan dig into the shared responsibility blind spot for SaaS identity providers, why 100 hallucinating AI agents with admin permissions are the new ransomware-class threat, and how to actually plan an RTO for the systems that bring a business back online.
Transcript
Hey everyone. Welcome back here to another Techstrong TV interview. I'm really happy to be joined right now by Eran Tewzer.
Eran is the CEO, founder, or co-founder of a company called ControlMonkey. Eran, welcome to Techstrong TV. It's great to have you on here.
Hey, Alan. Nice to meet you, and thank you for having me here. My pleasure.
So Eran, I always like to give people a sense of who they're listening to here on Techstrong TV. Give us your story, leading up to founding ControlMonkey. Absolutely.
So, I'm the CEO and co-founder of ControlMonkey. ControlMonkey is actually my second startup. io that got acquired by NetApp back then in 2020.
Then I spent a few years working for AWS, where I got exposed to the next problem I want to solve, which is around cyber resilience. And this is where me and my co-founder, Ori, founded ControlMonkey back then in 2022. I love it.
Yeah. I remember Spot, actually. We covered Spot a bunch here.
And we still do with the NetApp folks. So, look, I've been in cyber 25 years myself, right? Resilience, when I first got into security, we didn't even call it cyber.
It was all about prevention. Correct. Right?
And then maybe 10 years ago, 15 years ago, we started thinking more along the line of response. And now that's led to resilience. What about the whole resilience kind of motion led you to found ControlMonkey?
So, I think what you're saying is spot on, right? Organization historically prioritized prevention over recovery, and I think these days we're going to talk about gen AI and ransomware, but I think today disruption is not if, it's when, and this is the mindset of CISOs and CIOs. Something is going to happen at some point.
Can I recover from that, and how fast can I recover, right? What's my RTO? And I can tell you a little bit about what we do and what the gap that we see in the market is.
Everybody backs up their data, right? You back up your databases and your storage account and everything that is data with all kind of tools, right? It could be the cloud-native tool, like AWS Backup or Azure Backup, or Rubrik or Commvault.
Nobody backs up the configuration around your data. And when I say configuration, think about DNS, CDN, load balancer, firewall, security groups. When you think about it, if there's an attack and you need to recover your environment, so having your data up is great, but it doesn't bring your business back online.
And this is a huge gap that we see in the market, that organizations can't fully recover their environment, and this is basically what we do. I love it. And you're right.
Most people, when they think of backup, they think of backing up your data, the docs that you were generating, your spreadsheets, your databases, if you will. Mm-hmm. But your configurations and so forth, without those, it makes life very hard.
It is. So what we know to do is basically, again, reverse-engineer live configuration to code and creating a snapshot. " Let's say they're running on AWS.
"Someone will delete your Route 53 record set. " And most of the time, they don't have a good answer for that, and not because they're bad, right? It's just something that they don't think about.
But when there's an incident, it's something that they will absolutely need to take care of. And again, this is what we're here for, right? We're the one-stop shop that knows to create a backup and snapshot of configuration to any kind of vendors.
And when I say any kind of vendor, it's basically your cloud, so your AWS, your Azure, and your GCP. But what about backing up your Cloudflare configuration or your Akamai configuration or your identity configuration, your Okta or Entra ID, even your Datadog dashboards, if you think about it, right? Think about organization with hundreds of Datadog dashboards.
They invested a lot of time and money to build those dashboards. Right now, there's a cyberattack, over-permissive AI agent that deletes those dashboards. What's their plan to bring back those dashboards alive?
I get it. Yeah. For sure.
Now, you guys have also really kind of specialized in identity providers, right? Mm-hmm. So look, back in the day with the security company I started, we were NAC, network access control.
1X technology, right? 1X to put you in quarantine, test you, put you in, out, whatever. And of course, Active Directory was sort of a monopoly.
Everybody was on Active Directory a day in, and that was not just identity, but access control. Yeah. Today, we have things like single sign-on and federation.
My friend Raj is the founder of JumpCloud. It's more of a directory as a service and stuff like that. Okta.
There's more than one. Active Directory is still huge, right? Yeah.
You use the SaaS version of it, or you're on What about that particular, just the identity space kind of demands its own special challenges when it comes to backing up and recovering that? Yeah. I think the biggest difference with identity provider is the operational impact when users cannot access critical system.
If you think about it, let's say you're an organization with thousands of employees, and right now someone messed up with your Okta configuration. You have thousands of employees that can't access any of their system. They can't access their production environment.
They can't access their back office systems. Basically, the entire organization is shut down. So the impact is really, really, really huge.
And we also see surge with attackers that actually try to attack the identity providers because that's their gate into the organization. So that's one thing. The other thing I think it's, people are not kind of aware of that, of the need to back up their identity provider.
So they use a lot of manual processes. They have lack of visibility to configuration changes, limited testing, right? Again, most organization, when they do a DR drill, it's mostly about, can I recover my data?
But nobody actually tests, hey, what will happen if my Entra ID configuration is malformed? Can I actually recover that? Can I actually spin up a new tenant of my Entra ID or my Okta and reprovision the configuration that allows the entire organization to be able to log into their system again?
Got it. Now, there are people out here, Eran, who are going to say, "Hey, I'm using a SaaS provider for my identity," and isn't this really their responsibility? That's a great question.
We get it a lot, to be honest. There's this thing called shared responsibility model. Yeah.
Which means that the SaaS provider is going to be up and running, and their API is going to be available all the time, and they're responsible to be active/active. " Right? It's up to you to make sure that you can recover that.
Now, there are some vendors, I must say, that they will help you with that, right? They will try to help you with recovering specific stuff. But if you look at an organization, at a typical CIO, they manage dozens of vendors, and they can't rely on each of those specific vendors to be there when something happens.
And when something happens, you want to make sure that you can recover as fast as possible. And that's why we believe that each organization should have their DR plan for identity providers specifically, but also all of their other vendors in general. And again, when I say other vendors, think about your Route strike configuration, your Zscaler configuration, even your Palo Alto firewalls.
So I think that's kind of like the shared responsibility model that people should be aware of when they use either cloud or any SaaS vendor. Absolutely. We're at an interesting time in identity.
So when I first got, again, when I first got involved in security, identity meant people, right? We knew Eran was Eran, and because he was Eran, he was in this class, and he could go here. Then we started assigning identities to IoT devices, right?
And that kind of thing. OT devices. There were more of them than there are people.
Then we started assigning identities to machines- Mm-hmm ... to containers, to instances, and machine identities blown things up. Now we're assigning identities to agents.
Yeah. We're talking about having 100 agents to every person maybe. How does that complicate this whole thing?
So I think AI is changing the threat landscape, to be honest. In every call that I talk with CISOs and CIO, everybody's worried about it, right? Because just like what you said, if up until two years ago, if I'm an employee, I can make a mistake.
Right now, I have 100 agents that can make a mistake. And those 100 agents that I run, they use my local permissions. Let's say I'm an admin.
So you have 100 agents, which are non-deterministic, they're hallucinating, and they have my admin permissions. At some point, something is going to blow up, right? You take non-determinism, you put admin permission to it, something is going to happen eventually.
And I think that this keeps a lot of CISOs and CIOs awake at night. And this is something that they should consider. Now, we believe that you need to have a plan, right?
Something is going to hit you at some point. How fast can you recover? You can't really protect from that because...
Or you can try to protect from that, but you can't, I would say, give up on the advantages that they are bringing. But the advantages and the benefits and the velocity brings a lot of risk with that. So you need to make sure, again, as a C-level, that you can actually recover from any incident.
Again, if up until two years ago, the ransomware was the biggest threat, it's still a big threat, but I think there are a lot of... I think there's statistic around it, like 88% of those misconfiguration happens from humans and not from cyber attacks and ransomware attacks. Now it's going to be a lot more because, again, there is 100x employees instead of just one that can actually make such mistakes.
I love it. Hey, Eran, we're almost out of time. It's only 15 minutes.
Yeah. For people who want to get more information, where do they go? So they can go to our website.
io. By the way, one thing that we do with new people that want to actually get information about their DR posture and where they have blind spots is we offer a free assessment report. Right.
Yeah, it's read-only, it's free, it's 30 minutes to set up. And then they can get understanding of where their blind spots and resilience gaps, both for their cloud and their third-party configuration, their identity as well, vendors. io.
We'd be more than happy to kind of show you and help you work on your resilience gaps before they become an incident. I love it. io.
They could sign up for that right from there? They can sign up, yeah, exactly. They can ask for the free report just from the website.
Absolutely, yeah. I love it. Hey, Eran, I wish you all the luck and success- Eran, thank you for having me ...
with ControlMonkey. What a great thing. Thank you very much.
Thank you. Thank you. Eran Twezer, co-founder, CEO, ControlMonkey.
Back up and recover everything, including identity. You're watching Techstrong TV. We'll be back in just a little bit.