Cybersecurity Challenges in a Data-Centric Approach – Dan Benjamin, Dig Security
Dig Security CEO Dan Benjamin explains what makes cybersecurity so challenging in a cloud native era that requires a more data-centric approach to creating controls.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Dan Benjamin. Who's the CEO for dig security and we're talking about. how Native data detection and response and security and how all this is going to come together Dan, welcome the show Thank you for having me Michael.
These days what exactly do we mean by Cloud native when it comes to security because we have Cloud native applications and then we have Cloud native security and or they want in the same or they kind of slightly different topics. So when we come and talk about data security in the public clouds customers want to answer three main questions. What data do we even own across our AWS Azure gcp so flick infrastructure.
How is that data being used and by whom and lastly? How do we protect that data either at rest and motion or use? And those are kind of predominant questions that's organizations need to answer both because of security standpoints, but also compliance standpoints.
And with the cloud native solutions that are being offered either by AWS Azure gcp, they just can't answer these types of questions. They have too many different types of data store types too many different types of datastore Technologies and they lack the visibility and controls that they need to essentially adhere to to build data security program or a data compliance program. and that's what we do here at the When I think about the history of cybersecurity, it was very much dependent perimeter kind of notion.
We were going to build castles and moats and all that good stuff that almost seems obsolete in the age of the cloud. I think maybe we're needing approach. That's a little more granular and focused on the data.
Is that finally coming to fruition? I think so. I think that's we're now seeing kind of a shift into Data Centric security.
How do we build controls from the data outwards versus kind of building the modes and the castles that we were talking about earlier at Google we had to say that there is no mode in the public clouds. It's all kind of a soft gel and with one kind of big issue that it that we essentially have with our controls. Everything is completely exposed.
So building the controls around the data and looking from data outwards. It's kind of the better solution when it comes to Cloud. Almost feels to me that people lifted and shifted their applications into the cloud and they lifted and shifted their cybersecurity mindset along with it and discover that that wasn't going to work so well, so are you starting to see people have a better understanding of what it takes to successfully manage Cloud security.
I think that organizations are encountering the problems. I think that's not everyone already has the answers of how to tackle these types of problems. But I think that there is a realization that we need to do things differently in the cloud.
There is no kind of the traditional modes. Most companies that they don't have network security products in the public Cloud they used to have that's on-prem. Right they have where data security controls they have cspm solutions.
They have synapse like synapse protections and and all kind of comes to the fact of how do we essentially manage our applications into the public cloud and how do we kind of adhere to the fact that Data bytes still might still kind of remain in the same location, but if you kind of share. Us a database backup with an external account that doesn't belong to the organization. All of your controls are completely gone.
I mean, it doesn't really matter. What mode you have. It's a permission issue, right?
So building the right controls around your data your applications your apis. Your VMS is kind of the better approach today in the public clouds, and we need to shift to more of a zero trust model. As we think all that through for a minute zero trust seems to be the buzzword of the moment, but it's not clear to me that people kind of understand exactly what that means.
And so from your perspective, how do we kind of apply identity which in my mind is what zero trust kind of ties to to a very granular assets such as a piece of data. It seems like these are really small artifacts to be working with. So, how does that actually come together?
So in general when we come into a customer environment. We kind of do this in a phase approach first off. Of course, we come into a customer environment and help them visualize and understand what they do.
They even know. So we start off by first discovering any type of data asset that they have whether it is a past solution like an RDS and an Azure SQL is a solution. So any developer can boot up at VM and it's still mongodbiana, right and databases as a service then of course, we classify the entire set of information.
So what do we have pii or Phi or PCI or any type of regulated data that they need to essentially adhere to a specific compliance regulation? What do they have sensitive information? And then essentially build controls around types of information.
So I want to build specific types of controls on social security numbers. I want to build specific types of controls on PCI regulated data. So once you kind of understand what pieces of information you own you can essentially build better controls both from an identity standpoint from an access standpoint from a posture standpoint and from a detection response standpoint.
So the key to this is understanding first off. What data do you own doing this and kind of the ephemeral nature of the cloud doing this in a and an ongoing phase ongoing kind of okay. We have a new data store.
Let's immediately kind of Discover it and classify it and essentially build the actual controls on it. and once you are able to kind of Automatically do that you are able to build the right Motes around specific pieces of information. As we can manage this whole process.
It feels like no one's quite sure who's in charge of security in the cloud these days. We kind of let developers provision whatever they want to do using whatever tool they have and then suddenly we're surprised when we have data everywhere. So who's kind of stepping up to take charge of data security specifically Excellent question.
So up until now Enterprises had data and form a locations and that kind of expanded. Like into five in recent days. So initially we had endpoint which was kind of DLP right email, which is email DLP.
I'm pram which you used to have the dams and baroness and And improve us you have to have staffs which is the castes and in public Cloud we have big now. Typically what we see in the larger organizations. They have a we have a dedicated data security team and if they have a dedicated data security team that team essentially manages all the different types of data security products across any place that data lives and some organizations where they don't have a data security team.
We see it's being split into two main types of teams either Cloud security. Or Joseph depending on what is the kind of driving Factor inside the organization GRC is more compliance standpoint and Cloud security is more security standpoint. But all of them basically have the same needs.
How do we discover understand how it's being used? And how do we protect that data either at restored motion? Service providers have been talking about shared responsibility models forever in a day.
Do you think organizations really understand that they get that or they still assuming that the cloud service provider is doing more to protect that environment and they really are. I think that's a little bit of a fallacy today. I think that's our organizations that are understanding that the cloud is not necessarily more secure.
It's easier for the topic standpoint. It's easy to essentially provision and build faster. But you need to have a different mindset to essentially protects data or applications in the cloud.
And if you kind of think that that the actual cloud is going to protect you the severely wrong and I think that the larger organizations already understand that smaller startups are still kind of in the discovery phase of that specific phase but in the larger organizations that we work with the day. and they already have an understanding that they need to build better controls for their Cloud infrastructure and the controls that they had on Prem just aren't aligned with what they need to have in the public cloud. Do you think the bad guys are getting smarter about looking for unprotected data or data that has valuable content in it.
I mean are they scanning these environments actively and to what degree? Definitely. So first off 60% of the world's data is now sending in public clouds.
That's the place that data is now going at it at an exponential state. Now the good thing for attackers at least is that cloud is the same AWS is the same for customer a and AWS is the same for customer B. so once you build a proper attack paradigm that essentially allows you to scan customer environments scan AWS infrastructure scan Azure infrastructure.
That allows you to kind of build better controls. I mean better attack patterns for the attackers themselves, but that's also why we need to essentially protect ourselves. as an organization I was recently sent a website.
I can check in a second. What was that website, but it was from one of our security researchers. There's a public website that essentially tells you every single piece of public files that exist across AWS Azure gcp and all you need to pay is $40 a month to get access access to that specific website and find any single public file that is supposed to across these three main infrastructures.
That's not right. We didn't have something like this on-prem. So the need for data security controls in the public Cloud, I think are more parents because that's an easier Target for attackers.
And that's also where most of the data is now moving into so attackers understand that attackers understand that that once they build a good attack plan that they can actually propagate that across multiple customers, but that's also kind of the opportunity that that we have today in the cloud data security space and they're on purpose or by accident a lot of organizations now have data and multiple clouds. Can I create a set of consistent policies for managing all those Cloud environments that would work from a security perspective because that seems to have been an issue for a lot of organizations. Definitely.
So the problem is that each Cloud vendor today or ecsp today doesn't allow you to kind of apply consistent controls across the other clouds. And I think that's why we're kind of seeing this boom of multi-cloud security multi-cloud data security. Where you have solutions that span across the different clouds and apply consistent controls across these different clouds.
Otherwise the csps are not helping you there. I would say that the only kind of vendor. The only CSP that also have a security program is probably Microsoft and even they are lacking kind of in the controls that they're allow customers to kind of apply on AWS and and gcp there's still very early on in that Journey.
And I think that's where we're kind of seeing how this boom. Of companies like us companies like Wiz companies like Orca that essentially apply consistent like consistent controls across two clouds or three clouds of work clouds depending on what the customers have. It seems like we kind of want to have our cake and eat it too.
We want to be able to continue to build applications quickly. But we wanted to be more secure are these two goals compatible with each other or do you have to slow down at some point kind of let the security guys catch up? I think that if Security will try and slow down development that creates misalignment inside an organization.
Of course, the best thing is the if we can build securely faster, I think that's kind of the end goal that all of us have But I don't think that as a security organization, we can slow down our development process. I think we just need to adapt and understand that we need to put the proper guardrails in place whether it is. AWS SCP policies Azure policy, right?
So putting the guardrails in place so bad things wouldn't happen and essentially putting controls that will give you the visibility and controls across specific segments of your Cloud whether it is Data whether it is applications, whether it is containers or whether it is VMS. We just need to be able to have consistent visibility and consistent controlling of every type of category that we want to protect. There is some folks who are proponents of the cloud who would argue.
Well, we'll just encrypt everything and we won't have to worry about it from there. I mean to what degree is encryption the answer. So encryption is great, but you're still gonna have hundreds of not thousands of people machines vendors and contractors that still need to have access to the data.
They will have access to the KMS because they'll need to to actually decrypt the data to do whatever they need to do. And even our kind of share an interesting story. When you enable encryption today on AWS?
And a specific bucket, for example, it doesn't actually encrypt the old files. It only encrypts any new file that essentially comes into the bucket. So a lot of organizations don't understand this and having kind of this visibility that tells you what is actually being encrypted.
And then who has access to what type of information where do we have access to sensitive information? And how is that sensitive information being used across my organization as super important? There is some folks who would argue that AI will save us from ourselves.
What's the current state of AI in cybersecurity from your perspective? I think it started very very early on organizations want to be able to understand why they're taking a specific piece of action. Instead of kind of automating this I think that where we've kind of seen.
Good automations come into place and is in the sewer systems, right? So if this happens I want to take this specific type of action, but having kind of an AI system that would say Oh. Just react however, you will.
Just react. However, you feel like you should react. I think that doesn't really work with human nature.
We need to understand what kind of actions we want to think for every type of scenario. Because the biggest downfall is what happens today, if we kind of block a specific team from doing their day-to-day job people will hate security our goal. Is that security and engineering and the business units will love each other.
We want to work together and essentially build better security together. And not separately. Yeah, there's not a lot of love lost between developers and cyber security.
So what's your best advice for can I accomplishing that goal though? I just throw everybody in a room and lock the door and hope for the best or is there something way to go after this? I think that eventually security means to understand the business really really well and if you understand the business really well and understand, how can you security me and enabler versus a blocker?
I think then then that can cultivate the right relationship between the two different sites of the business. I've seen many organizations that it works really really well, so there was a dinner. And the season said, oh the CTO is the best friend of mine.
I mean, we work together, we build all of our programs together. That's amazing right some organizations. That's a little bit slower and clunkier, but I think that's the end state that we need to get to.
All right folks here in here. It's incumbent upon the cyber security people to make some friends because the other guys know they're well meaning but they don't really know what they're talking about. Hey, Dan.
Thanks for being on the show. Thanks so much for having me. Thanks, Michael.
Alright in back to you in the studio.