Controlling the SaaS Attack Surface – Russell Spitler, Nudge Security
Mike is joined by Nudge Security’s CEO, Russell Spitler, to discuss the current state of protecting SaaS applications and why the current solutions like vulnerability scanning and CASB are insufficient.
Transcript
This is Textron TV. Hi everybody, Mike Rothman here GM of tech storm research with another text wrong TV interview. I'm actually very pleased to welcome my old friend and not restaurant that you're old, right, but we've been friends for a long time and and it's great when I can do text from TV interviews with with folks that I've known for a long time.
So Russ Fiddler CEO of nudge security Russ introduce yourself. Tell us a little bit about nudge. Thank you.
Mike. Always great to talk with you. So happy to be here today to talk a little bit.
No security is a company that's really focused on the biggest shift that we've seen over the last five years in cybersecurity and a lot of people when you say that think oh well Cloud security infrastructure is code all of this stuff, but the reality is it's really focused on how work gets done in organizations. We have seen every single company move to a model where we have completely distributed adoption of Technology. You give an employee a week's worth of work.
They turn into an hours worth of work and a hundred dollars subscription and your customer database is now in another SAS service and so on edge we have technology that allows you to discover every SAS account created by every employee in your organization ever been created and then we'll give you ongoing monitoring to detect whenever new accounts new activity happens within those services. And we do this with the idea of embracing that employee choice of making sure that we are solving the problem without trying to change human behavior beyond what we can do. That's right.
And I know you guys take a little bit of a novel approach to that Discovery right most folks in there trying to you know, kind of do passive monitoring on the network or tap into, you know, kind of the web proxy or you know doing you know some mechanism to identify out traffic is going to that sass service you guys take a different approach right? That's when you help us understand that yeah. Totally that that was like one of the big Revelations that we had when we started the company is We're not gonna put the genie back in the bottle here employees are used to working from too many devices too many locations, especially today you grab your kids iPad or you're using your iPhone or your laptop at home or your computer work.
We're never gonna go back to the reality where people drive down the highway sit down at their desktop at work plugged into local. That works great when you're doing network monitoring and there's only 15 Services out there and it's Salesforce and they only update once a year these days. We have more than 20,000 different SAS Services.
We have employees all over the place. So we realize we needed a new approach. We can't rely on network as a consistent point of monitoring anymore.
So what we do to begin job is the design pattern that's consistent every single SAS provider out there and if you think about your experience, but literally any service you sign up and that service wants you to use their service more and so what they do is they start communicating with the one universal communication mechanism on the internet that's email. And so we look into the Enterprise email server. We have this beautiful long history.
You could nobody deletes email anymore of everything you ever did and then we have this beautiful side channel in the monitor as we go forward and get to see new activity as it comes through. So yeah, so that that is a novel approach, right, you know kind of didn't occur to most folks to you know, think wow all the information that I have to worry about is is with an email but the fact is you know, kind of a lot of folks continue to be focused on visibility, right and and the newfangled term for visibility because the security marketing machine always has to be coming up with something, you know new and shiny is a tax service management, right? So these are the tools that you know kind of are out there both scanning, you know providing agent tree really trying to give you an idea about your exposure, you know where we're really a lot of of your assets are out there.
But again, I mean, I think that that the ability to handle a lot of the cloud activity that is happening can be kind of limited right? I mean, you know how you're gonna integrate with, you know kind of 9,000 or 20,000, you know different, you know sass offerings from from that stand without taking you know this old approach of doing Acid monitoring. So let's dig into what you know kind of effective attack surface management is gonna look like, you know kind of in this new remote mostly SAS based world.
Yeah. It's a really interesting shift. And when I think of the tax service management, I sort of feel like we're staring at the car wreck and the side of the road not looking at the bridge that's about to go out because the reality is if you think about what we're actually doing with those products, we're giving them Network ranges.
We're giving them domains. We're having them discover largely traditional and Legacy it and that's really important and a lot of organizations have a big problem there and they need to get ahead of it. There's a lot of great Solutions, but the reality is most organizations have left the building and they have been charging for the last five years in that piece has increased over the last couple years and they're moving those Technologies to assess-based service.
So whether that's next week or zero for your Finance information or you know, Dropbox and Google Drive and Microsoft OneDrive fit to replace your old SharePoint servers. We're not using on-premise operating anymore. But the most important thing is each.
One of those new accounts is a new place that somebody can Target a new place that somebody can get into and frankly doesn't have a lot of the traditional security controls that you did have in place when you had networks implementations things were locked in closets you had to draft to work again and get in there. And so when you think about this new world you have this ephemeral Tax Service that spread all over the Internet. You don't know which resource belongs to you or not.
And that's really what we try to solve for organizations. How do you figure out exactly who has what what accounts are out there what you need to worry about what you can ignore and that's a big challenge in every organization particularly as you think about how broadly use these services are today. Yeah, it sure is so what's kind of contrast that to what folks think they have with caspi, right?
So Cloud access security Brokers, you know, that was kind of the first day in a great way with API. Maybe do you know kind of a proxy? Really this catch-all and you know pretty much every network security provider has some type of you know, kind of CAS me offering now that they're using to try to control these, you know the usage of these SAS services.
So what are the limitations in in that kind of approach relative to what the real issue is in this remote-centric, you know kind of SAS focused world. There's kind of two fundamental flaws in the premise of a network-based control for this problem. The first is it's completely antithetical to the SAS problems.
The SAS promise is do anything anywhere on any device and I'll give you the business context that you need in one right? You know Salesforce was created because the sales guys didn't want to have to go back to headquarters to enter in their sales activity. They wanted to do it on the road on their iPhone on their iPad.
We didn't have that then but what we're on their laptop over their house back Etc. And so when we kind of look at that First Fundamental premise the idea of routing back through the network is one that's trying to be solved by a lot of companies out there, but the reality is and I look this at probably the most network-centric security company in the world at my last job and I'm not gonna name names but it's easy to figure out. Yeah.
No one thing employees did when they couldn't get to a service is turn off their corporate VPN and go on the guest life. Bye and go ahead and start doing their Of any place and so that's fundamental flaw number one, but that kind of keys into that second block, which is employees are using these services not because they're trying to you know, make a headache for security and ID it's gonna try to get their job done and if it's more efficient if it's easier if it means another hour at you know home with the kids or like another hour to go walk their dog. They're gonna do in that's gonna be a huge disservice to them if they feel like their employer is getting in the way of getting their work.
Yeah. The last is more of a technical limitation which is as a good friend needs to run security AT&T remark, you know internet monitoring. Your network monitoring is melting Ice Cube SSL everywhere projects, like let's incrypt have driven the the traffic that we're seeing and monitoring to a point where we now have upwards of 80 90% of the traffic on the internet being encrypted and so really the only resolution you have DNS unless you want to do a decrypting proxy, which is another ball of wax at Nightmare.
And so what you need is a preconceived notion of what domain names are SAS Services what they're doing exactly what they're doing. And you know, there's 20,000 some odd. Our database has 34,000 different SAS Services we've detected this is an incredible number and to think about how you stay ahead of that and actually understand what they are and understand what activities going on it's a real big disconnect in terms of the signal you get from that network monitoring approach if you magically got everybody back to work and working on the same network compared with what you can do with with the completely not intrusive approach.
Yeah and given the fact that again we do have these disconnected remote, you know Centric environments now, you know kind of this idea of being able to you know, really Leverage The the techniques that the actual user is, you know. Focused on right so it's the difference between, you know, kind of the no knowns right and the unknown unknowns, right? And right now if you don't have control of the network, there's no real way to start to isolate those unknowns in terms of what they're using in terms of what they're doing.
So and again, I do think it really requires a different approach. It's absolutely true. And and that's really where we're also trying to embrace the realities of human behavior.
Which again if you're trying to get your job done, you're gonna do what you can in order to get your job done. And so what we actually found we did some great research with professor of Psychology from duke where we're actually able to see the difference between what happens when you try to block an employee from going to assess Service as opposed to when you proactively engage with that employee as they're trying to get their job done and the rates that we saw which is 70% of people would work around being blocked compared with 80% actually complying with that productive engagement. And that's the fundamental approach with that the piece that really comes to mind what really sort of hit this for me is when you think about the rate of sasis we see on average about three quarters of his ass application for an employee.
So if you have a thousand employees at 750 apps already once you get up to 5,000 employees you talking about thousands of applications now go to anybody in 13 ITT they're probably sitting there with you know up to their eyeballs and work with hundred applications. They're managing. And you say well, I'm going to 10x that with all the other things that you haven't been managing an organization and they're probably just gonna quit right and so right just, you know, kind of go through the motions.
Yeah exactly. I'm just gonna have another coffee not do this work today. And so what we really need to approach is like how do we enlist those employees to help start solving that problem?
How do we get them to take? The small steps needed to actually give more information to the centralized team. Hey who's the administrator of you know, the HubSpot instance that just got set up, you know.
Hey, can you click this button and integrate that helps body Institute to our Central monitoring program or hey, you can spend 30 minutes with Mike over here and get it onboarded to octet. There's a little steps that every employee can do every employee can take but we don't know who didn't talk to you know, what apps they're using. We don't know when to make that request and that's really our focus when we look at that.
Yeah, that's kind of talk about You know, we talked a little bit of a ripple effect, right? But you know kind of sasses is one piece of it, but then we start talking a little bit about you know, kind of Supply chains and and how you know, a lot of these different services are used to build additional services that I'm getting delivered to customers. Right?
So if you started to see in in your customer base folks really starting to focus on again not just that attack surface in terms of their own employees using some of these SAS services, but the SAS Services being used as part of an offering then it goes out to customers which would again create a totally different type of exposure and candidly, you know, kind of a much more severe environment or situation if they were to get compromised from that state because then you're talking about customer data and the life if you started, you know, your folks talking about, you know, that sass supply chain concept as well. Yeah, and this is again such a great analogy back to the tax service management right when you're worried about the server. You just discovered you would need to worry about well.
Is there an old you know log for J. The library in there? Is it vulnerable to you know a dozen of other supply chain attacks with the open source opportunity rate when you turn that proxy over this ass world.
What are you concerned about there? And yeah, perhaps you worried about the composition of the actual software that you're leveraging but more importantly and what we've seen in terms of attack Trends is what are the Upstream services that are being leveraged in order to provide that and that could be as simple as they're running on AWS or they're using male gun to send out their notifications and emails or it could be more complicated. Like they you Circle CI in order to actually run there on CI process.
And so that's an area. We've invested a lot of effort in in order not only give people insight into what are the first party providers that you're leveraging your organization. Hey last pass gets popped.
It's not our corporate standard who in my organizations. Well these five years you brought it from home and they love it right? So I need to talk to those five years now.
You get a more complicated situation, you know sendgrid gets popped. I don't use sendgrid but there's 50 providers that are in my list that are leveraging Century. Do I need to be worried about the communication from those providers and being part of that or Circle CI, right?
I don't use circles yet. But now there's two providers in my SAS supply chain. They're leveraging Circle CI Upstream.
Those are the opportunities. Those are the conversations. You need to start having because that's the modern attack Factory.
That's what we're seeing consistently over the last year and we you know shock up laps this group to you know, script kitties and you know, you know, but the reality is they're taking advantage of one fundamental reality of modern organizations massive complexity massive unmapped Integrations between all those services and a whole lot of employees trying to get their job done. Okay, I can find a way in and then start to take advantage. A complex ecosystem they're going to be able to compromise your systems and that might be through a first party a second party or you know a supply chain region.
Yeah and suffices Sam pretty comfortable here carefully wait for it. All right, here's what here's one of my big research epiphanies. There's gonna be more SAS tomorrow than there is today and when you think about that is as just Blatantly obvious.
Is that is it again it highlights a lot of the issues that we've been talking about right really understanding what your environment getting visibility over all of those different SAS Services understanding, you know, what each of the employees is doing with those SAS Services. We don't even have time to talk about it. But obviously decommissioning, you know, kind of wants an employee leaves, especially just one of these orphan, you know types of obsess services that wasn't necessarily, you know, kind of run through, you know, the corporate Machinery, especially smaller companies, you know have a lot more of that stuff.
So just a lot of of issues in terms of trying to build a more curated and managed sass environment and our Pals and nudge are again helping to you know, folks understand what's going on and then, you know giving you the tools to be able to really start to control that over time in both a manual and automated Action, so so Russian folks are interested in learning more about nudge and how do they get in touch with you guys? All right. com click two buttons and you're in a free trial and you can see how it works for you.
and easy to integrate so it's just really matter of integrating in with your Office 365 or Google workplace and and you're in That's part of the magic trick. We haven't had a diploma to take more than five minutes. We'll get you first results within an hour.
What's beautiful about that, especially historical analysis as well as ongoing analysis. So a little bit of a standout in cyber security products compared with the three to six month rollout, and then we face it. That's right.
That's right. Well, let's thanks again for for being on Tech strong TV. We'd love to chat with with you guys.
I think you're doing some really Innovative stuff. com. Check it out.
And again, Sasa Tax Service stuff is gonna be an issue. You're hearing a lot more about in here. So get back.
Thanks again for us really great to see you. Nice to talk with you Mike. Thanks a lot.
Alright now we'll send it back to the studio for our next interview.