Data Protection for Cybersecurity with Rubrik’s Arvind Nithrakashyap
On the 10th anniversary of the founding of the company, Rubrik CTO Arvind “Nitro” Nithrakashyap explains how data protection has evolved as an IT discipline for ensuring cybersecurity and resilience.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Arvin Nitra, also known as Nitro, who's CTO for Rubrik.
And we're talking about the 10th anniversary of a company that kind of helped pioneer the whole notion of data protection as a service. And well, we've come a long way since then. Nitro, welcome to the show.
Great to, uh, great to meet you, Mike. And thanks, uh, thanks for having me on the show. I think if we go back in time 10 years ago, even though you guys kind of pioneered that notion of, uh, putting it up in the cloud and managing it centrally, a lot of people said, boy, do we really need another data protection platform?
'cause there was plenty of them out there already. Um, looking back at it now, 10 years, I mean, what's your sense of why did it gain traction and what keeps it having that traction? Absolutely.
I think, uh, when we, when we started on this journey, when you looked at, when you looked at this area, especially back up, there were, there were two issues there. One is there was a lot of complexity, right? If you think about most, most organizations running the applications in the data center, they were often buying backup software from one vendor, backup storage from another vendor, media sales from a third vendor, putting it all together and making it all work.
And after all of this, if you ask them, do you have conference that you can recover your data when you need it? Um, most 90% of 'em said no. I, I don't know.
I don't know whether it'll work or not. Um, so there was a lot of complexity with no guarantee that it'll work, right? So this is, this is problem number one.
Now, if you go back 15 years and you ask people, why do you, why do you care about data, data, data protection? Most people would say, I'm worried about human error. I'm worried about disaster like flood earthquake, where I lose all my, my data center, and how do I recover from that?
Fast forward to, to now, even five years back, I think the, if you, if you ask the question, what are you most worried about? Most people say, I'm worried about cyber attacks. I'm worried about, uh, attackers coming into my organization, deleting my data, or potentially exfil the data, right?
So, uh, one of the, as, as a, as a new company looking at the space and we had a, you know, clean sheet of paper and we could everything from scratch, we felt that we could solve both of these problems, right? So the one thing was how can we modernize this whole area and bring in a single stack of software that removes all this complexity and makes it very easy for customers to go and protect their data. Um, if you, I mean, our inspiration was, if you think about it, all of us have our mobile phones and our lives depend on it.
But if you lose your mobile phone, uh, I actually sent mine for a war cycle. Uh, it took 15 minutes to buy a new phone, recover all my data because it was automatically being backed up to the cloud. So one aspect was, can we modernize this and bring a completely simple modern user experience, operationally very easy, uh, solution to the market.
And the second big, uh, realization we had was backup and recovery is not the same as cyber resilience. These are, these require two different solutions and two different solutions at an architecture level. Uh, very often when you have a, when you have a cyber attack, you are not trying to go and say, okay, let me get the latest backup and restore it.
What you're trying to do is you are trying to answer a few questions. What was the, what was impacted? Was my sensitive data impacted?
What is the blasted use of the attack? Was there any data that's exfil exfiltrated? Um, is, is the attacker still at large?
If I restore all my systems, I still back to square one where that attack would come and do this to me again. So what this required is a is a very different architecture which can provide answers to these solutions. And these were the problems we were, we went out to solve.
And because we were starting a threat, we could build a brand new architecture that could address all these problems. And we believe that's why it came fraction. Initially, we gained our fraction because of our simplicity and the, and the complexity that we removed.
But very quickly people realized that with cyber attacks becoming a bigger and bigger threat, we had a platform that could, that could address these, these issues and help them recover from cyber attacks. Flash forward to today, I think when you started, the person who was in charge of this decision was fairly lower on the it totem pole, and there might have been a storage person or an admin. Has this whole platform become a, a much more strategic conversation in the age of ransomware and who's involved in making these decisions these days?
Absolutely. I think the, there are two, two big trends we've seen, and this has, this has changed in the 10 years we've been business. Um, the whole ransomware question has become a board level question that are board members now asking there the CEOs, are you prepared for ransomware attack?
Because everybody's come to realize that a cyber attack is, it's a matter of, you know, when and not if, and I mean you just have to go into the news to see the number of very, very large organizations that have been, uh, you know, victims of cyber attacks. So every board is asking these questions of the CEOs and this has become a top priority. Secondly, what we are seeing is, um, this realization that data is, is the most critical asset that the business has.
Everything they do today is built on the data they have. So that has become strategic in terms of protecting the data. And what used to be, as you said, um, a storage admin or backup admin in the CIO organization, this is now bubbled up both at the CCIO level, but also to the CISO who is a heavy influencer.
Or sometimes even we have even seen cases in large organizations. But ccio and CSO roles have been merged because they believe that if the CIO is managing the data, that's the most critical asset. The, the security aspect is very important as well.
So now we are actually having conversations much, uh, you know, much higher in the management chain about how this is strategic, uh, solution for, for their needs and how this gives them peace of mind that they have protection against cyber account. I think, um, there's no shortage of data protection solution options out there. And I sometimes joke that this is the category that refuses to consolidate 'cause we keep adding new players, but nobody seems to go away.
What is your sense of, um, are customers thinking about this in a way where they wanna rationalize some of these motions? 'cause there are so many different, um, applications that people are using even within the same organization. So how do I bring some order to what is, uh, maybe a little bit of a chaotic process at the moment?
Yeah, so, um, so if you go back 10, 15 years, there were tons of applications within the data center that cus customers worried about. Fast forward to now, it's not just data center. You have cloud, you have a bunch of organizations that are in the process of transitioning from data center to the cloud, but it's still many large organizations are 80% of the data center, 20% of the cloud, right?
So it's, it's, it's a hybrid world that they live in. And to add to the mix, now we have SaaS applications that are coming in. So each, each SaaS application provide by different vendor.
But from, from an overall data perspective, the organization still responsible for all the data they have. It doesn't matter whether they're using Salesforce for like a, for their, for the customer data or some other, uh, you know, SaaS application for their, uh, you know, purchase orders and things like that. All this data sensitive information that they have to worry about.
So the complexity has, uh, has only increased. Um, I think the, the reason we are seeing a lot of success, and we have about, in, in our 10 years, we have more than 5,000 customers who are, who are, who are using Rubrik today in across enterprise cloud and SaaS. Um, I think the reason that they go with us is that we offer a single platform that can provide these services across enterprise, uh, uh, applications, cloud applications, and SaaS applications.
Uh, it's a, we provided through our rubric, security cloud, and this is actually a transition we made as our customers made this ion in the cloud. We took our product and we also delivered through the cloud. So now they have a single portal that they log into and they can see all their applications across, uh, whether it's data and applications, cloud applications, SaaS applications, and they can apply the same kind of policies, they can use the same kind of security applications we provide across all of these.
So consolidating all of this into a single solution and a platform that actually has a capability to deliver the single solution is, is the reason. And we have customers in every vertical you think of, we have customers in healthcare, in financials, in insurance, retail, you name it, be pretty because all of them have this concern that what happens with a cyber attack and how protect myself, uh, in such a situation. And it's not enough to just protect your Oracle database in data center.
You've gotta worry about your Office 365, you've gotta worry about your cloud native applications running in AWS or Azure or gcp. So, um, it's, the problem has actually gotten even, even more complex, say from 15 years ago. Aren't we watching some sort of convergence of data protection and data management?
Because I think historically we had data protection was kind of a task, but with ransomware, we're starting to realize that, uh, we need to protect the data. But has that forced everybody to kinda revisit their whole approach to data management, which sometimes is, shall we say, uneven at best? Yeah, so I think the, what has happened is I think customers are slowly beginning to realize that when you look, when you think, when you think about security, you know, traditionally you thought about these like firewalls, you thought about ID systems, malware detection, right?
But these, most of these are operating as kind of almost like a perimeter outside organizations preventing the bad guys from getting in. One of the realizations we have had, um, through some of the, you know, some of the research, uh, that our teams have done is that 80, 90% of attacks actually apple through credential leakage. So this is actually, somebody's laptop was lost, you know, remote working and all of that, and now they're coming into legislative means.
They're not breaking in through some vulnerability, they're actually logging in into your organization. And once they get in there snooping around there, they're trying to find the s uh, uh, and attack that. So I think people are being realized that there is infrastructure security, but then which, you know, stops 9, 9, 9 or thousand attacks.
But then one attack that gets to can do severe damage to your data and then that can actually be ed the business. So, which is why now the beginning understand, and this is the message, we, we are also, you know, educating customers that there's infrastructure security, which are extremely important, but you also need something for data security. And that's, that's kind of, uh, where we come in and people are concerned about what are the cyber attack and they delete all our data or they encrypt all our data, or even worse, the exfil data sensitive information, customer information that now they, they threaten to release on, on, on the web.
And for that, you've gotta take, it's not just actions that you take if there's an attack, there's also actions you need to take prior to the attack. You need to understand your, the scope of your sensitive data, who has access to it. Um, why, why is somebody from engineering access h taxing HR information is this some, this is an attack of masquerading as a, as an engineer.
So it's, these kinds of questions are becoming more commonplace. And so it's, you have to look at data more holistically, uh, and as you said, it's not just we're protecting data, it's about managing the data, it's managing the access, it's managing, monitoring the activity on the data so that you can, you can catch, uh, you know, cyber attacks before they actually do some damage. So it's both proactive actions you need to take before any attack happens, as well as if that attack has happened.
Uh, you know, recovery actions you need to take to bring your business back up. We hear a lot about all things AI these days. Will we be applying AI to the whole, uh, data protection, data resiliency motion, and what might that look like?
We have actually been, uh, using some form of AI net products since I would say 20 70 20 18. Uh, we actually released, one of our first security products we released was, uh, was failure around anomaly detection. Uh, we track data changes over time and we capture the data, all the enterprise data for customers, and we can actually be introduce a product that uses machine learning to, to understand ous changes in data.
5% and suddenly jumps to 10%, it's probably an attack, probably gone an encrypted, uh, some, some data, uh, as part from cyber attack. So we actually introduced this, this product, and the reason we were able to do it is that because number one, we built a single, this platform was a single stack of software that understands not just the data, but also captures the metadata about the application. So when we, when we protect a vm, it's not just a vm.
We are protecting a protecting, we know that it's a Windows VM that runs active directly. If you protect a, a VM in the cloud, we know, oh, that's actually running a SQL server database inside, uh, inside of Windows VM in, in the cloud. So because of that, because we understand the, the metadata about the, uh, about the application, we are actually able to apply build a, we built a AI based data threat engine on top that, uh, that can actually, um, you know, look, use machine learning models to determine an analyst stack and warn the customer.
So that was the first security product we built in. After that, we have built whole bunch of, uh, products that leverage the same AI based data threat engine to detect sensitive information, uh, detect, you know, malware that might have come into various applications. So we've been doing this for a while now, obviously with the introduction of generative ai, we actually recently announced, uh, uh, what we call, uh, uh, generative AI system for our customers called Ruby, because a lot of these, one of the challenges that we are seeing with customers is that there's a lot of stuff going on, a lot of complexity in terms of data and customers themselves.
When when, when there's anything that happens, they're, they're struggling to figure out what is the action they should take. So what we have introduced is basically, think of it as an assistant or a co-pilot that assists you, oh, hey, I found, I found this malware in your tech, uh, in this, in your, in your application. Uh, I immediately questioned the customer come to a chat and say, okay, what is this malware tell me more about?
And we'll, we'll answer the question and say, okay, what action should I take? And we'll actually come up with a recommendation. They'll say is, is this malware a avail, uh, present in other applications and say, okay, these are all the applications we found.
So what that does is that it, it makes it very easy in a conversation way for our customers to take action when they, when they see something that that's off. And, and, and this is obviously we increased the product recently, and we're gonna add more and more skills to this as we build more security products. All of these will be, will have a companion that can guide you through how to, how to resolve any issues we see After 10 years of watching customers.
When do you see them doing that just makes you shake your head sometimes and say, folks, we need to be better than this. I think, I mean, the one thing I've built in these last 10 years is a lot of empathy for the customer because I see the complexity that they're dealing with, um, whether it's IT organizations, security organizations, they're not getting like, you know, tons of new headcount, but they're asked to do more and more. So what's happening is there is a lot of, uh, you know, they're just trying to keep their head about water, and so stuff gets dropped by the wayside.
It's easy to point and say, Hey, you should have done this. But then the problem is they're dealing with thousands such, uh, uh, issues every day, and they're often drowning in alerts that are coming from various security systems. So I think the approach we are trying to do is simplify this whole thing.
Can we make it extremely simple where we bubble up the most important issues to our customer so then they can take the actions usually when, if you can do that effectively, if we can kind of eliminate the, the noise from the, from the actual issues that they need to focus on, people will take actions and people, people are, people want to take those actions, they wanna protect their organizations. So I think it's more about, um, we can talk about best practices and you should do this and you should do that, but we, I think we also have to make it easy, uh, for our customers to be able to deal with the, the thousands of things that I get thrown that get thrown at them every day. Uh, and the complexity only keeps increasing.
There's nothing, nothing that decreases. So, um, I, I feel that there are a lot of, obviously there's a lot of room for improvement, but I think the, the tools also have to step up to be able to help the customers. And our goal is how can you keep innovating to make, make it, give peace of mind to our customers that, you know, they're taking care of their most important assets.
So what is your best advice then, given those issues? If I am in charge of this, or I'm part of the team that's in charge of this, or I'm the CISO or the CTO, sometimes, you know, you hear people say, if everybody's in charge of something, nobody's in charge of something. So how do I kind of bring it all together?
I, it's a great point. I think it's, uh, extremely important that there is somebody who's accountable for, for the data. Because I think every, you go up wake every, somebody from the state, they say, what's the most important asset you have in the organization that gets data, right?
But I think, um, not that many organizations have somebody who's accountable for, you know, to ensure the data's protected. It often rolls into different organizations. It depends, depends on the organization.
Um, so I think it's, it's important to have focus saying, Hey, if there is any kind of a cyber attack, is my data protected? Can I make sure that I'm doing everything in my power to prevent data acceleration? So these are high level questions that the organization has to be able to ask and usually have somebody who can, who's accountable for this and can, and then can, can actually go focus on this and solve, solve this.
Um, I think then it, it lets them step back, take a picture, take a picture of what, where the data, how the data's laid out in the organization, what are the, uh, what are, what are the most critical assets that they need to secure? Make sure that those are secured first. And then, you know, keep, keep, keep going through this process.
It's a, it's a long process. It's not something you can solve overnight. It requires, um, focus.
It requires patience. It requires dedicated focus for a long time to go solve, solve this. Um, and uh, obviously there are new organizations that come to your, you can through acquisition and other means can come to your organization.
Now you need to go and solve it for those organizations. So having a process, which you can then, which is repeatable, is very important. Uh, the other important thing that, uh, that, uh, again, we have learned over the last 10 years is that it's very important when, when something like when an attack has happened, it's probably the most stressful day in your, in your life.
You want to be prepared. So if you, the more you can actually go through some dry runs and have some simulation activities to understand what you would do, how would you, if there's an attack, what, what are, what are the steps you would take? Including whom, whom would you inform about this and what is the process?
A lot of this is something that organizations don't have the time to go and figure this out, but doing that kind of exercise, I think will have them much better prepared than when they have to take action. Uh, it's not easy, but I think with some preparation, I think we can, you know, we can rest easy, that we're better prepared for any such immature. All right folks.
Well, you heard it here. We've come a long way in the last decade for sure, but there's still no substitute for doing the actual work. Hey Nitro, thanks for being on the show.
Thank you again for the opportunity, it talking to you And to you guys in the.