Data-Centric Approach to Cybersecurity with Virtru’s Mike Morper
Mike Morper, senior vice president for product and product marketing for Virtru, explains why a data-centric approach to cybersecurity has become an absolute necessity, as cyberattacks continue to increase in sophistication.
Transcript
This is Techron tv. Mike speaks with Mike Moper, who's a senior VP for product and pro product marketing at virtue or Virtue, and they explain why a data-centric approach, a data-centric approach to cybersecurity has become an absolute necessity. Uh, as cyber attacks continue to increase in sophistication, data is where it's at.
Check it out. Hey guys, thanks for the throw. We're here with Mike er, who's senior vice president for virtru, and they are a provider of a platform that specializes in data security.
And we're gonna be talking about, well, why is data security suddenly all the rage? Hey, Mike, welcome to the show. Hey, I'm glad to be here.
Thanks For so long. We invested heavily in firewalls and the perimeters, and we had this whole castle and moat kind of mentality to security. And suddenly we woke up one morning and we discovered that, um, the good guys were basically flying over the castle wall and stealing all our stuff.
And it was like we had no roof. So why now are we shifting towards this data centric approach? And does that mean we spent less on the perimeter and more on the data security?
What's going on here and what's the right balance of things? Yeah, that's a, that's a great point. I think, uh, there's a few things that are, is driving this change.
Uh, it probably all started as more and more SaaS based applications started to be the tools that organizations were using. Uh, shortly thereafter, we had that, that thing that, uh, we all lived through the pandemic where we had, uh, remote workforces. When you reflect on those remote work floor forces, uh, applications are up in a cloud, uh, not back in a a rack, you know, in the organization, in the building where you used to work, you realize now that there is a need to be able to, uh, protect this data wherever it exists, because it is now no longer just on the bare metal that is sitting at the end of the hallway in each of these organizations.
So as a result of this, uh, organizations started, um, evolving their, uh, their posture. We had gone from a perimeter centric, uh, uh, methodology. And, and by the way, about 98% of cybersecurity's investment, according to Gartner, is still rooted in this perimeter centric, um, uh, motivation.
But what we're now starting to see is, um, more and more collaboration is absolutely required with this data. So we like to think of this as, um, there's the data you store, but there's also that data that you need to share. And there's really a distinction there.
And I think that is where we start recognizing that there is a, a need to be able to have a comprehensive set of zero trust controls, not only to prevent data theft, but to also be able to promote the sharing of that data itself. So we think of this as, you know, playing both offense and defense. So defense is really equated to that perimeter centric security that we're all familiar with the, the moats and the walls, and probably pouring tar over the side of the, the, the wall itself.
But playing offense is how do I encourage the sharing of this data and to be able to still ensure its governance? Uh, I want to be able to get it to you because our two organizations are trying to, uh, conduct business together. Maybe there's merger and acquisition, or you're just trying to buy some software from us.
So we wanna be able to encourage that offensive posture, uh, associated with, uh, data-centric security. And it's the culmination of these things that we're absolutely seeing more and more interest around a data-centric security posture, uh, becoming a larger and larger share of wallet, uh, when one thinks of a comprehensive zero trust investment for their organization. How do I know what data requires?
What level of security and what level of policies? Because not all data is created equal, but too often the IT and the security people have no idea. It's just all data to them.
So, um, how do I kind of go in and figure out what data represents my actual level of risk? Yeah, that's a great point. Uh, we absolutely should not be depending upon, uh, the IT staff for figuring that out.
It is the subject matter experts that really need to be responsible for that. In fact of the matter is, it's those data owners themselves that know more about that information than anybody else in that organization. So a best practice is to start tagging or classifying this content.
So, um, you know, from from hashtags on Twitter, that's probably the place that the vast majority of, of consumers or frankly the, the larger population of those that work in commercial organizations are familiar with this concept of, of tagging content. So you can find it. Um, you're now starting to see these capabilities manifest themselves in the applications that we use today.
And, and I'll give you a a great example. Um, Google Workspace now has a label capability that is, uh, pervasive across their applications, whether it's docs, whether it's slides, et cetera, by applying a label. This is confidential.
Uh, this is internal only. This can be shared with external parties. Taking advantage of that attribute that simply describes the intention or the sensitivity of that information is a fantastic first step.
Can we do that given the volume of data that we're looking at? It seems like every time I turn around and somebody's reporting that the amount of data that they're trying to manage has exponentially increased yet again, and are we just getting overwhelmed? Yeah, that's a, that's a great point.
Uh, here's how I like to think about this. Um, if I'm creating a new document, again, as that subject matter expert, uh, it should be my responsibility to my organization to go ahead and label that document. You know, this is for internal audiences, external, et cetera.
And that's pretty easy to do. Uh, in fact, even tools like, uh, Microsoft Office 365 can prompt for that. You know, you can't save the document until you put a a label on it.
Google's workspace does, does the same thing pretty easy to do. However, to your point, there is that fire hose of content that's being produced every single day. And it's not reasonable for us mere mortals to be able to keep up with that.
That's where I do believe, uh, machine learning is going to play more and more of a vital role in the way we classify and label content. Um, the proliferation of LLMs is a very natural place for us to be able to accelerate that. So while DLP does a great job today, uh, I do believe we're going to see a next generation of data-centric labeling that is going to take place by having, uh, an LLM that has been trained on your corpus, your information to not only go through your data at rest and give recommendation for labeling back to the subject matter experts anytime it's, it's opened or attempting to be shared.
Uh, but to be able to also further evaluate, uh, any inbound messages as well to potentially, uh, give recommendation to that, that control plane as well. Do we need to converge data management and data security management? 'cause it seems like, uh, many of the principles we're applying here are concepts that might have been first used in the space of data management.
I mean, what's the relationship between these two motions? I, I do think we're going to see a logical convergence. Again, if you think about a control plane from identities through, uh, the devices that individuals use, the networks themselves to the applications and to the data that control plane is going to be, um, collapsed, and there's going to be, uh, uh, best of breed applications that are used for governance across that continuum.
So I think it's very reasonable to expect to see that evolve. Absolutely. In effect, are we not deputizing other arms of the enterprise team to help manage security because, well, we're shorthanded on the security side.
So do we need more IT operations people and database people and developers to all pitch in here? That's a good question. The way I like to think about this is, uh, this is a natural evolution of, uh, intellectual property and governance.
And as a result of that, each of us, uh, whether you are a DBA, uh, whether you are in finance, each has an obligation to ensuring the integrity of our most precious asset. And that, and that's the data that our organizations possess. So, um, you can, you know, if we had this conversation 10 years ago, we would've not been talking about LLMs and how ML would be playing a role in our businesses.
Look where we are today, uh, we are still going to absolutely need to have, um, CISOs that are, uh, making policy decisions across the integrity of this data. We're gonna still have SMEs that understand this data, um, most intimately. But Eva, each of us played a critical role in ensuring that we can store this data safely, we can share this data safely, and that we can go ahead and accelerate the outcomes for our organizations by getting this data exchanged with whatever that other party is that's, um, needing to help be able to conduct that, that particular role or business.
You mentioned LLMs. Um, can we use AI to save us from ourselves here and apply that to data security? Um, like everything, um, AI is absolutely not a, uh, a crutch.
It's just a tool, and it is a tool that, um, much like, you know, maybe RegX, you know, what, 30, 40 years ago started to become some, uh, uh, uh, a, a tool in the, uh, toolbox. Uh, LLMs are gonna absolutely become another one of those tools in the toolbox. What we absolutely expect to see very, very soon is organizations, um, developing their own, um, corpus of data and then training it against, uh, an LLM, an open source model, et cetera, but keeping that running only within their perimeter so that they have no leakage outside the perimeter itself.
By building that model, training it on your own corpus, you can start to do some really, really powerful things. Uh, as I had mentioned previously, the idea that you could use it to intelligently start identifying content and giving recommendation to that SME, here's how this should be labeled. So go ahead and proactively label it.
Uh, we're gonna be seeing, uh, LLMs used for that purpose very, very soon. But again, like so many things, it is a tool, not a crutch, uh, crawl, walk, run and implementation. Learn how your end users within your organization are taking advantage of it, and then find those next logical spots to be able to, um, address more productivity and efficiency gains that will be absolutely recognized, uh, by tools such as that.
All right. On the face of it, data security seems like, you know, intuitively obvious thing to do. So what's the issue that holds people up when making this transition?
Yeah, that's a great question. I, you know what it is. Uh, I think the transition is largely rooted in, um, making sure that you've got internal stakeholders that are convicted to moving this forward.
Obviously, if you're in a regulate, uh, a regulator regulated industry, uh, uh, whether it's, uh, CMMC or IAR or you know, HIPAA data that you're managing, uh, the, the stick that you get hit with, um, can really hurt. So by ensuring that your policy folks, um, are constantly working with line of business and there is collaboration there, but most importantly you make it easy for the users, the moment there is a high degree of friction for those end users, that's when mistakes happen. Uh, we saw this back in the, you know, early ts with, um, um, rogue IT where, uh, individuals started going out and, you know, getting licenses to SaaS applications that it knew nothing about.
It's because they had friction in the process. You wanna make sure that there is not friction in that process. You wanna make sure that data-centric security is, uh, complimentary to the existing business processes in the tools that your, uh, end users are using.
Don't force them into another tool. Uh, this should be as transparent as possible to them, maybe a little popup to say, Hey, this is, you know, a confidential document and that's it. Let 'em get back to their day job, let 'em be able to hit send as quickly as possible.
It's probably one of the most important things you can do. Well, you mentioned the word conviction, so, um, I think if we have broken this up over the years, we always assume that highly regulated industries will have more, uh, robust security policies and tools like these to go enforce that. But it seems like lately, if I watch how regulations are evolving, especially say data privacy, isn't every organization kind of now in a highly regulated industry, I mean, won't this just become a pervasive requirement?
Data security is everyone's responsibility. Uh, even in our personal lives. Uh, I personally, uh, I am, and I'm in this industry, I am numb to the number of massive exploits we hear about day in and day out, whether it's in our own government or in the private sector itself.
This is not going away. Um, things such as, um, um, two FA, uh, is not even enough anymore. We need to be able to use other tools to, again, make it as easy as possible for PB people to be able to adopt and to be comfortable with being able to secure their own information.
Um, passphrases, um, pass keys, et cetera, um, will continue to help advance this, but it is everyone's responsibility to make sure that that precious jewel, uh, the crown jewels that are inside that castle that are are being protected, um, are so, and um, and still yet at the same time, being able to ensure that that information can be shared with the right people at the right time, yet be able to pull that data back at any point in time as well. All right, folks, you heard here data is the asset. So you start there from security and work your way out.
'cause I think historically we've been working from the outside in, in a way that maybe, uh, makes it too easy for the bad guys to do whatever they need to do whenever they wanna do it. Hey Mike, thanks for being on the show. Appreciate it.
Thanks a lot. All right, and back to you guys in the studio.