Cloud Security – Amer Deeba, Normalyze.ai
The rise of cloud computing has increased the complexity of the enterprise attack surface. Modern development pipelines deliver continuously, while the move to “infrastructure as code,” as well as microservices, makes it all too easy to misconfigure workloads and cloud services as configurations change, identities and their privileges evolve, and data stores become increasingly intricate. Alan and Amer discuss understanding all the challenges that surround cloud data security and new approaches to tackle this new frontier and win.
Transcript
This is texturing TV. Hi everyone, welcome to another text drug TV interview, you know, one of the nice things about being in Tech as long as I have and and in the security now we call it cyber security space as long as I've been in it is I I've met some amazing people along the way. And you know what they say about cyber security folks.
Well, most of them they never die. They just kind of get recycled or they do new companies. They're continually doing new things because they see new issues new problems new ways of solving them.
My next guest is one of those people. It's my friend. I'm here Diva.
I know Amir 20 years but is the first time we're going to be talking to him that his new company, which recently came out of stealth called normalized. Amir. Welcome.
Good morning, and welcome to you, too. So I hope I didn't embarrass you but give people a little background. Yes, of course my pleasure.
First the great Thirty connect and it's always fun to talk to you Alan. So my background on the cyber security person. I've been in this industry for over 20 years.
My I spent 17 plus years that Wallace was pretty much I think the one of the very early employees and worked over there which will be quoteau and the company over the years to build the product with the platform starting vulnerability management and making it basically a cloud security platform taking the company public in 2012 and expanding globally. I was pretty much in charge of a lot of to go to market activities. And it was an amazing amazing ride an amazing experience and now I'm on to my new adventures, which is very related to also Cloud security but very much focused on the data on the data side.
Absolutely. Well, it is all of that. The data is one of the lessons that would seem to be relearning now.
Yes, we used to know it and we somehow forgot it. But yeah, you know it and and on on-prem but in Cloud, that's all right. It's a little bit of a different animal.
Okay. Yes, but nonetheless equally or is more important because it's still all about the data. Excellent.
I don't want to spend a lot of time on cause but I'm here was being armor was being. humble, he actually I mean him and Philly brand Wallace for a very long time from the product to the go to market marketing and sales to And and you want to talk about pioneering Cloud they were doing Cloud before there was Cloud, right you you know, keeping stuff up in up there rather than on Prem. Oh many sessions on those at some point.
Absolutely over beer. Let's let's talk normalized, which is the new company. I'm here.
Tell us share with me armor. Great. So one, you know my co-founder Ravi ital and myself aravi also is a fantastic cyber security Pioneer.
He was a Palo Alto networks one of the early engineers and then the co-founder and chief Art Attack at net Scope when we got together. I mean we were just both of us, you know looking at kind of what what's the next problem to to attack and you know, he started on his own first and then I joined him a little bit afterwards but talking to see souls and to customers and we did so many customer calls and interviews with Security Professionals, that's professionals and the big problem that kept coming out is like data. Where is my data who has access to my data what type of access they have?
What where's my sensitive information? Are there databases on data stores and Cloud environments that are popping up that I'm just kind of not aware of and what type of information they contain. So this was sort of the recurring theme that kept coming up with sort of really set us to move in this direction.
And this is what fundamentally normalized is all about. And this is the problem. We want to solve how things Security Professionals and deaf stack of themes to really understand where data is in Cloud environments all type of data structured and structure infrastructure as a service platform at the service you name it understand Discover It classify it so you can oversensitive information.
It's but most importantly connect all the dots around it in terms of accesses and identities and configs and ones and anything that touches the data from resources to assets to ask, you know, that really can can end up. Providing an attack back to that data and help you model it and visualize it and understand it. So you can really prevent data breaches from happening, you know data is is hard and complex and complicated and especially in Cloud environments.
Once you move it from on-prem to data to the cloud all trust factors disappear and you really need to have the ongoing continuous visibility so you can control that it's really data's eating the cloud and that's going to be you know in the cloud one of the cloud data cheating the world, right? You're right. Yeah, and you know, and now everything is moving and so the cloud so, you know we so this is really our mission.
We're sad to kind of solve it at scale ease of views make it really accessible to the to board the security teams as well as the best soccer teams because at the end of the day, they're the one responsible to fix it to or to you know to to To basically make it all operational. So that's kind of what normalizes all about. Excellent.
I want to talk more like business stuff money raise and all that but we'll come back to it in a second. I want to focus right now a little bit on data and the mission you're right. You know, it used to be the world was easier at some level when everything was on Prem all you data resided in your data center.
And it was really, you know, the old mountain castle right we built we built the motor around it was a drawbridge in her out and that's all we had to worry. What data was going in and out over that. Yeah drawbridge.
Yeah. Today we live in a world of cloud and it's not just a cloud. We have some data over in Amazon.
We have some data in Microsoft Azure. We have some data in Google. Maybe we still have some data in the data center.
Yes, we have we have data on the endpoints and people are working from anywhere, you know, and the new thing now is The Edge right? We're building stuff on the edge and 5G is gonna enable The Edge and what's gonna be there? The date is gonna be there, right and what else you what day did shall we move to the cloud?
What day did should we keep in the edge all of these questions around it? However, it's hard day today to everywhere. How how do you how do you get your hands around that at normal life?
So I mean Discovery basically is the the kind of Holy Grail at the beginning to really understand where the data is within your Cloud environment. So, you know, we connect to the cloud environment and an agent plus way and pretty much the able to query the environment to understand again in a way like we used to say fingerprinting devices and and infrastructure world. You cannot really try to understand where the data is through certain techniques that we have developed and give you tell you where you have an RBS where you have a nasty bucket that could contain sensitive information.
That's kind of the first part giving you that overall visibility and we do sort of this Cloud. We'll Cloud scan that just where is the entire environment and in a very efficient and quick way to give you that full visibility and show you where everything is and what's connected to these data stores the second part we do. That is is which is really our kind of.
We spent a lot of time and effort to do it and to do it. Well is scanning the data at rest where it is. So if it's if your data store within kind of an AWS environment in Europe, that's where we scan it.
So nothing none of the data or sensitive information would leave your environments stay where it is and we scan it in a way. We have a One path one time pass can or that goes through the file and the data store in a very quick way and allows us to understand where sensitive entities are and we connect them together via sensitive profile so we can add proximity also into the classification process so we can show you for example that you have your name associated with a social security number and credit card within the same principity and we're still the same proximity and within the file which basically tells you here. This is you have sensitive information that you need to be aware of all of that information.
We've taken we put it in a graph along with all the information from the environment including the config. students on vulnerabilities that could be around the data and connected together in this intelligent graph that allows us to Traverse any attack path to sensitive information and we have built behind that kind of the prioritization engine based on AI and ml that allows us to walk that graph very quickly and intelligently and immediately pinpoints to the customer where sensitive information is in any attack path that can lead to it that can be to it and that sort of at the end becomes kind of your actionable lists of intelligence that you can act upon and rather mediation with your either with your compliance themes or would your death cycle teams and that brings I guess another complication or not a complication, but you know the way the world is changing it used to be that Company like normalize would produce this day that would produce these. Intelligence for you know actionable intelligence for a security team to act upon but you know one of the reasons I think we weren't really a successful as we could be in Security in the past is it wasn't just the security team that had to act here.
We need we need the Ops Team to call SR reads. We want to call me. Sorry.
We find the Ops Team. We need these deaths Tech Ops teams. And so what we've seen successful companies do is their Interfaith their ux.
They're the way they present their findings is optimized not just for the security pro. You know who's very interested in maybe compliance or you know? Straight up security, but to present it in a way that the deaf Secaucus that the SRE folk right are understand what they need to do.
Correct you to protect the data to correct to remediate so potential situations. You're absolutely right. And that was also one of kind of the what we learned as we started deploying the product and working with customers that opening the platform with specific workflows.
So that data becomes actionable in different formats for different users including the that set up teams the security teams the compliance or data teams, you know each sort of each Canada because data that's a lot of these kind of different groups compliance have their own and sort of their own use of it. When especially if they're trying to meet gdpr compliance or see where they're exposed for pii data and whatnot. So we have to sort of build very specific workflows on top of the day and intelligence we've collecting and we spend for devops and they are sorry teams.
We connect the product basically with the tools that they're using for and Order driving mediation or just like we connect into slack and jira and different workflows to help them take the data and the form Want it and then use it to to either remediate or to drive actionable basically processes on top of that one of the things we learned like for example, the same data problem is occurring again. And again, why can't I run the same automation each time and make that available out of the box and the product so we can add adding these so these these actionable workflows on top of the data to support these behaviors and help the security teams really collaborate with the different groups within their organization and kind of connect them together through the platform using that intelligence that we're providing. Actually armor, if you don't mind I wanted to turn now to kind of the business end of things around normal lights.
You guys recently came out of stealth. Yes and announced I guess was like a combined seed and a round or yeah, I mean we is a little absolutely so we got the seed the round was leather initially by like Steve Ventures and then the a round was led with that from the battery Ventures with full participation from live feed. We close the seed round and December 2020 and we just closed the a round and in June of 2022.
We were 25 around we're gonna be 25 people next week. In fact and the hiring globally we're now across the Geo between here and India and we have positions open everywhere check. Website you can find all the details.
Now go to market motion is a bit different where we're starting basically with the bottoms up. But motion we have a freemium offering that way anyone can sign up for on our website. And so we can get it really in the in the hands of devops folks and have them start using the product love it and deploying it with security engineers and then just kind of once they want to do more they can come back to us and then we can discuss about the options are but it's it's a it's a bit different and that sense from from everyone else in this space and we think it's going to be actually a game changer.
You know, I I agree. It's the deaths that got sway. So but of course this begs the question of yes, I'm a so if they want to go do this, where did they go?
I normalize dot AI this is where everything is the water. You find a lot of information on our website. The freemium offering is available from from the homepage.
And you know, we encourage everyone to try it want it we want to get as much feedback as possible specifically from the deaf SEC Ops Community. We want to see how we can you know help any great this product within did that all cycle and make it more help them really from the beginning as they're building applications in the cloud and connecting with the various data and stores and data environments that we can become part of that process so they can verify what they're doing first and as they roll it out and to production it becomes the tool to help them enforce security and better security ongoing basis. And just for the audience, it's normalized.
ai. You said correct? Yes.
Okay. ai slash premium in which you know, we we will be highly again showcasing it at the next conference that black black hat next month. So that that brings it up.
It's not even that next month. It's next week already here. It's coming up.
Yeah, so and actually there was some news around black cat you guys were selected is not a company to watch I forget what they call it. But what exactly yes, we are one of four companies that got selected for the Innovation black hat Innovation award. Very prestigious.
We're very excited about it, you know in terms of also there was so a bunch of companies. That I applied and we're one of the final four we'll make our final presentation at the show floor on August 10th, and it's very excited about it. Check out normalize dot AI.
We're gonna take a break. We'll be right back.