Cloud Permissions Management Platform – Ron Nissim, Entitle
Entitle is exiting stealth with $15 million in seed funding and launching its cloud permissions management platform, which fuses a security-first approach with a commitment to business enablement. Its self-service platform automates provisioning and establishes access governance across complex, highly dynamic, multi-cloud environments.
Transcript
This is Textron TV. Welcome everyone back to techstrong TV. My name is Sharon Florentine.
I am the managing editor here at techstrong group. I am joined today by Ron Neeson. He is.
Well, I'm gonna let Ron tell you a little bit about himself and his company entitled and Ron. Take it away. You'll say it better than I ever could.
Sure thing sure thing. Thanks for hosting me Sharon. I'm Ron nice to meet you.
from I grew up in Dallas Texas moved to Israel and this sit in a unit 200 to which you might be familiar with did classic operational cyber security there for many years along with Avi my co-founder both did a long journey together and research and development and we really really drawn towards permission management as honestly kind of The combination of something super important and yet so boring. Nobody wanted anything to do with it. It's kind of the unsexy part of security and yet we felt that it was you know, everyone was talking about like all this next-gen security stuff.
But when you look at what companies were getting compromised for even the most recent OCTA and Uber compromises, it was very much boring old like it or customer success having too many Privileges. And so we knew there was something interesting to be done there and we started our journey very humble just interviewing a ton of Security Professionals asking them what their challenges were and they all kept drawing us back towards the challenges of governance of access. So knowing who has access to what taking away access when it's no longer needed and we really lucky that we spoke with the item devops side as well.
And we realize that many of the challenges that security teams face and governance of access actually originated Upstream in the it and devops departments and how employees got permission to begin with so when you join your A what was the process that you went through? Excuse me to get access and we're all familiar with the you know old story of opening a ticket to it. And oh it's taking them forever to give me access.
And so there are a lot of direct challenges with the manual way that permissions their processed today, whether it's just employee efficiency and how long it takes them to get access but you know somewhere around 30% of tickets that it devops purpose process or access requests. And so that manual process obviously becomes a burden but what we learned is that the biggest challenge it actually is the security side of things. So because it and now offs are doing their things manually, it's become really hard to know exactly who had access when they had that access.
Is it still relevant? And so we realize that if we automate that process ideally everyone will love the business will be more efficient 19 Davos won't have to do this manual work and security quarterly. We will to know exactly what's going on get this ability into the different applications different processes.
And that's kind of what led us to where we're doing what we're doing today. We raise a total of 15 million dollars. and now I have a lot of companies that trust us to become to be the backbone of their company from permission manner perspective.
Awesome. Well, congratulations first of all on that raise and you know, I understand you're coming out of stealth with this. So you've talked a little bit about the the problems that led you to to developing this solution.
But how does that tie into these the buzzwords that were hearing of you know, zero trust security and principle of least privilege and all of those things, you know, because I know a lot of it and Business Leaders aren't gonna really get down into the nitty-gritty. They're gonna hear those buzzwords and go. Okay.
Well, how does this solve that problem? Yeah, absolutely. And it's a great question because that's one of the things that you know, I'm honestly a little buzzword allergic.
I always scared to name drop us words and to the point where it's probably playing against us right people kind of need to know what category to put you in but but at least privilege and zero trust is the Big Driver of why to manage access in the first place, right? Because you know, if I was joke that stereotypically what it want is to give everyone access to everything because that's the easiest and what security is no one to have access to anything because then you know, you don't it's secure because no one can do anything. Yeah, and and the question is always how do you strike that balance and these privilege and zero trust speaks towards The Importance of Being granular and defining exactly what people actually need but the challenge is often the business implications and how to make sure that you you're not restraining the business by restraining people people's access and That's exactly what we're looking to strike the balance exactly what entitles looking to do.
So being on the one side both of business enabler by driving the business forward by reducing sla's by improving the process but also giving security the least privilege approach that they're looking for and a big part of that is just in time access or temporary access to sensitive resources because you know, you're always security teams. It teams are gonna Define some sort of policy, but the challenge is what happens to that policy over time the business changes it shifts in creating a just in time approach has enabled companies to be much more agile on one hand. So giving people what they need when they need it, but on the other hand making sure that people don't have what they need for longer than what they need.
So whether it's admin roles and removing that access when it's no longer needed or pii databases or production access all these Services which are very important to know exactly who's admin there exactly what's going on and removing that when it's no longer needed. So is this a cloud-based SAS delivered solution? Is this a?
On-premises, how does how? Logistically, does it work? So that's the beauty of how we're tackling things.
So by being very cloudcentric we're able to provide an out-of-the-box solution for what companies need to manage their Cloud access. Now the challenge is often trusting a vendor with the ability to manage access to your company's is challenging like it's not something that's not that's not taken lightly. We don't take that trust likely lightly and so we've built build security into the product both from an organizational perspective and just creating policies in place that enable to make and and that make sure that we're held account hold ourselves accountable, excuse me for that but mainly and this is kind of what usually people are looking for is, excuse me.
We have a hybrid deployment model. So we do have a fully Cloud hosted model and that's often easier to install but a lot of companies will sit will want to self host a certain part of the solution which ensures that the API tokens never leave their environment. And so if Basically what ensures that it's just much more secure and that if one customer gets compromised or one vendor compromat gets compromised.
It doesn't transfer into in Challenger into into under other vendors, excuse me. And so basically basically you can go either way you can self host you can have the hybrid deployment which was by the way very easy to install like, you know, one click from the GUI. It's rough and running inside your own cloud environment.
You can host it in AWS gcp Azure, whatever you'd like very flexible. awesome works for everyone. Yeah, that's the idea.
So what else did you want to discuss here? What else should people know about entitled about the Security problems you're trying to solve. I think it might be worth outlining how the product works to factor like what this actually looks like and and so the solution actually take a step back permission management has two core aspects right governance the retrospective provisioning the operations and a big driver.
We mentioned at least privilege a big drivers that often permission management is often the compliance side of things but we believe that you know, good governance good compliance is a byproduct of an automated in tight provisioning process. So we want to make sure that employees are actually getting what they need and not more than that. And so we've created a platform that has four core aspects one is a self-service aspect meaning employees can request access through what they need slack teams Jr.
Service now, it doesn't matter we call it front and agnostic exactly for that reason and basically an employee puts in a requests. It's processed by the policy engine. So security teams have a no good policy engine where they can define a different approval processes based off the risk profile.
So if you are on call that might be a Lenient approval process because that's an emergency and if you're requesting access to a database that has pii information maybe that should be treated with more care because that's very sensitive access with it's an admin or if it's a read-only Rolls. Those are two different very different risk profiles that entail different approval processes. And so this is a very flexible tool that you can take and adapt into whatever your environment whatever is right for you because different companies do permission management differently.
And so it's a very flexible tool third aspect is the actual API fulfillment. So we come out of the box with a ton of Integrations into basically everything. Hopefully everything that you need that companies need.
And so this is everything from corporate SAS applications to Dev SAS applications. Database is cloud infrastructure, very wide range of Integrations that enable us to provide very quick time to Value. So we have very wide coverage for whatever the company needs within a few hours.
It's already up and running and so that removes the need for it devops to provision that access because when you on access to gitlab, we will go to that gitlab repository get you that access you want access to mongodb table. We will go to mongodb and get you that access and sending me said obviously for many of the other applications. And the fourth aspect is the governance is and that's the kind of retrospective because once we're the source of Truth once we're the ones that are again giving and taking away access.
It's really easy to know exactly who had when they had what's what was going on why they got it. Is it still relevant? Should I remove it?
That's kind of a byproduct of all the different Automation and and Central sorts of truth that we've defined and so one of the powerful ways that we've been tackling this is that we've been pulling into information from a lot of different sources. So we integrate with your HR management system so we know exactly what's going on. We integrate with your identity providers.
So, you know, which users exist we have obviously researched these different applications. So, you know exactly what the permission model is there and we integrate with you know page or Duty opportunities, you know who's on call with training system so we know which training you've gone through with data tagging Solutions so we know which information sensitive or there's Pi is so on and so forth. And so pulling all this information to a central platform enables you to create policies across organization that couldn't be done before wow.
I've where do you store all that data? How does that work? So again this it goes back to whatever if the customer wants to self-host that this information or they want to completely post it for them.
The idea is again quick time to Value quick implementation time. And so, you know, whether either way you choose within like let's say a day up. Usually we call it a few hours but let's say a day.
It's just it's fully operational fully integrated with a lot of your applications. That's amazing. I think especially like in a permission management World historically, you know permission management projects are in renowned for taking forever and ever seeing success.
And that's been that's been our biggest challenge or our biggest goal is to create a product that a I am professional a devops professional it security professional whoever's responsible for this organization can see real success within a few hours already rolled this out to employees if there's anything else that you wanted to talk to us about maybe one more thing I wanted to add is Um, I mentioned the that there are a lot of different stakeholders and permission management, right? There's security that care about permission management. They're the ones that care about lease privilege.
There's it and devops that do the actual work and provisioning that access and there is there's the business units that are the ones that actually know what's going on. Right the person that knows whether or not eat access is often not the IAM guy that's sitting wherever it's the manager that knows what's going on and so being able to create a collaboration platform with all these different stakeholders can define a centralized policy and every business Community can all of a sudden be the control their own destiny, you know, what's going on and the ability to recommend ownership. So basically decentralizing or delegating the responsibility empowering the business units with the ability to make the right decision on that acts.
Excuse me in that access and from a security perspective that makes much more sense too. And that's one of the things that we've been that's been driving us, you know, we're all security researchers by training. We've all come we all come.
About security background and permission management often a very it world, right and so being able to bring the two together and bring a security-centric mindset to an IT operations world and enabling the business while we're at it. I think that a lot of security products are we're lucky in that a lot of security products are often seen as taking away from the business, right? It's only adding burden and entitle is one of those few security platforms where you know, our security experiences enabled us to create a very very powerful security solution, but we're all so in enabler of the business as well.
All right. Well, thank you Ron so much for coming on and talking to us about entitled today and I am sure we're gonna be hearing a lot more about you guys and the company in the future. So congratulations again, and we will be talking to you again soon.
Thank you very much. Sharon is great meeting you. Thanks for having as well you as well and stay tuned folks because we've got a lot.
more great content coming up for you on Tech strong TV stick around