Data Protection, Security and Privacy – Terry Ray, Imperva
Terry Ray, Imperva SVP data security GTM, field CTO and fellow, shares his insights into data security, protection and privacy and how organizations weave them into a coherent data protection strategy.
Transcript
This is techstrong tv. Well, the great pleasure being joined by Terry Ray, Terry, s v p, data Security, GTM Field, CT O and Imperva, fellow at Imperva. Welcome.
Good to see you again, Terry. Thanks. Good to see you again, Mitch.
Well, we're talking about data and then fill in like data security, data privacy, data protection. There's a lot of terms that, of course, you know, security, we, we like to say it's about protecting the data, right? That's a big part of it.
But those terms kinda get thrown around interchangeably, and maybe they are to a degree, but they all have kind of very specific meanings. I'm wondering if you can, maybe you can parse out security, privacy, protection, and maybe any other term we might use in that lexicon or what maybe the, the differences are. Yeah, absolutely.
You know, I think it's interesting. Yeah. You know, I hear all the time, we, I mean we, at Imperva we use the term data security, and that's, that's, what do you do?
We do data security. Uh, data privacy is one of these that's also interesting and that it's a little bit newer, but it's nuanced. And then data protection is one that, that, the way I use it, the way I hear it used, it's kind of the, the ultimate goal of what we're trying to achieve.
It's not technologies and everything else, but we're trying to protect data. That's really what it comes down to. And you have to define what protecting data means to you.
And what I mean by that is, when I, when I hear these, these somewhat interchangeable terms, specifically data security and data protection, very interchangeable privacy is this other kind of, uh, you know, uh, uh, piece to that when I hear, let's, let's begin with data security and data, data protection. So the majority of organizations that come to Imperva and say, Imperva, I need you two, and this, that this's the other, fill in the blank. We hear two different questions here.
Sometimes three, but two different questions are, I need you to help me secure my data. I need you to help me comply with a regulation. Those are the two primary reasons why organizations even start thinking about, I'm gonna use the term data security here.
Start thinking about data security, is because they came together and either determined due to some incident, due to some incident of a peer, due to some revelation that they need to actually, and I'm gonna use the term protect. They need to actually protect their data using best practice and technology and processes. It's their choice.
They need to go do it. Or more commonly, unfortunately, more commonly, someone else has told them, you're not doing enough. You need to go do more when it comes to protecting your data.
So you should go look for data security technologies that will help you protect your data. So when I put this in the, and then that third, that third one out there is you need to be pri you need to meet privacy regulations. And that kind of falls hand in hand with the classification or the, the compliance piece.
But it all boils up to I need to protect data for some reason. Usually falls into two buckets, compliance, regulation, whatever you want to call it, and security. And this is when we start to use these terms, the, they're very commonly used interchangeably.
And I don't, I wouldn't say there's a right and wrong, but I just think that there's a little bit of a, of a hierarchy, right? You've got protection. That's what we're trying to achieve.
Data protection. I'm trying to protect my data because I want to or because somebody told me to. The way I do that is leveraging data security, whether that be data technologies or knowledge or expertise or whatever.
And then even though privacy has this dotted line, a very thick dotted line, in fact, to data security, in fact, all privacy regulations say you need to secure your data, but also go do a data subject access request and some other processes and hire some people. Uh, it, it fits into that piece. That's kind of a sidecar to the side, to the, uh, to the security piece.
But that overarching piece is about data protection. I like that structure a lot cuz if, if data protection is sort of the umbrella, security is the technology and methods, processes, et cetera, people, right? That we use to protect that.
And then privacy, as you said, with that thick dotted line from compliance and regulatory seems like it also nuances into, uh, what can you, how can you use my data when you're talking about, you know, like personal identifiable information. Um, and, and of course that varies across region, geography, country, maybe universe, global planets. I'm not sure where it's gonna go for someday, but you know, it it, they all have kind of their own nuances, but that gets into, um, other nuances of use and, uh, protecting people's, uh, information as well as customers and partners and things like that.
Yeah, definitely. I mean, it's, it, it is, it's one of these interesting things where when you talk to so many customers over time and the conversation immediately shifts in the conversa in the, in the discussion to what are you trying to protect? Okay, you said I need data protection, therefore I'm talking to you about data security technologies.
What can you do for me? And then there's a whole myriad list of technologies that fall into that. But what, what ultimately happens in these organizations is they say, I have a thousand databases and that's a large, pretty large organization.
I have a thousand databases. And then I ask, okay, so you need to protect, we're talking about protecting all 1000. And they say, no, not really.
What really what I wanna do is I want to protect the databases or data stores, file servers, whatever, where I have blank p i I personally identifiable, E P H I, healthcare information, P c i, what name your flavor, whatever it is. That's what I want to protect. And that's the, that's the other hurdle.
I think ultimately organizations have to get over. Sure. They need, you know, you don't have to use the right terminology as long as you get to the right place and talk to the right people.
But I think as people start to understand what is the motivating factor for doing data security? And then once you've gotten that motivation, okay, somebody told me I need to go do this, or I'm told I have to do this cuz we just lost a million records and I'm told it better not happen again or else, so I've gotta go get this done. So how do I solve for this?
Unfortunately, in most organizations, that solve four speaks to the privacy angle that you talked to. Mm-hmm. For years and years.
The solution to the breach or the solution to the compliance was go protect that data. It's not the data that's just important because we know it's important. It's the data that's important to that regulation.
And every other bit of data, frankly, isn't in scope. I'm not gonna spend money on it because I don't have a pain. There's no pain associated with me losing anything other than this data that's regulated.
So why would I spend money on it? Now, I have a thousand reasons why you would spend money on it, but organizations tend not to. And that's how we got to privacy regulations, is people protected what financial records for.
So P C I records, HIPAA records, et cetera, but they lost names, addresses phone numbers, names, addresses, phone numbers over and over and over and over and over again. So now we saw exactly this, right? Not only do you need to protect, as you said, not only do you need to protect data that frankly isn't really relevant to the organization, it's relevant to the users and the customers and the employees of that organization.
You have to protect this because of your fines. But at the same time, you then have to go back and answer those questions around privacy. Should you have this data at all in the first place?
Mm-hmm. What are you doing with this? Are you selling this data?
That's a whole nother set of requirements. Are you capturing it for mar whatever? The reason being, you have to have well-defined processes and answers around why you're collecting this traditionally unregulated data now regulated because organizations unfortunately failed to prioritize the security of this data for a couple of decades or so.
And so now we're, you know, now laws are in place to say, well, it's gonna, it is gonna put some pain in place if you're not doing it. I, I'm curious, as as customers approach, you are, are they, what, what are they getting caught up on through, like, I'm trying to put together my strategy for how we do data protection. You know, my technology organization steers me one way, the regulatory group steers me another way.
Do they need some help sorting this out? Or they have a pretty good idea, I've got this pain point today, next I need to solve that. Is there a set of problems they're looking for help with?
Yeah, so it's a, it's a challenge, right? So I spend a lot of my time talking to, uh, audit rate audit organizations, trying to educate auditors. I think if you talk to a, in fact, I know some credit card companies, so I know if you go talk to some credit card companies themselves, they have pretty, pretty good idea of exactly what they mean by the letter of, of payment card industry, pci, I, what have you.
If you go talk, you know, the, the, you know, o c i in, in, in the US government about HIPAA and what they mean by it, they're pretty clear. From there, it trickles down. It's kinda like one of those, those, uh, those those programs where you line up a bunch of people and they pass a secret down the line and you see if you got the same answer at the other end.
Mm-hmm. The same thing. And so we see the exact same thing in this win driven by security, I'm sorry, when driven by compliance organizations have a lot of, uh, flexibility and interpretation that they can take in it.
It doesn't say go buy a waf. It doesn't say go deploy a database security solution. It doesn't say, you know, go, go do explicit things.
Most of the time there's some very explicit things. It does say, every regulation out there will tell you you need to go encrypt data, go encrypt your data. Now we know HTTPS exists just about everywhere.
If you don't have it, then you're, you're definitely falling through the cracks. Um, you know, but you have to go do certain things that are out there. And I think that's the challenge that organization leaders have is what do I do when they have to use their own auditors, their own internal people to try and interpret what does it mean when it says go do best practice and secure your data?
This takes us to data security and data security. If you go to R s A, I know you've been to R s A, so if you go to r s A, there are hundreds to thousands of vendors that will claim data security and they might not be wrong. So where do I begin in this journey?
And this is one of the things that, that I've recognized over the years and, and, and Pervis doing a lot of work toward this, to be able to start to put kind of risk measures in place to be able to tell an organization, look, you, you've told me that you want to secure, sorry, you wanna protect your data and you want to do it using data security technologies. Maybe not just Imperva, but a bunch. So Imperva has a platform, right?
We brought this PA platform to play to be able to say, this is a data security platform. And there are others, you can talk to Gartner or Inger Cole, whomever, right? But there are others.
But when you look at this platform, it starts to answer questions like, do you have encryption? Is your data encrypted? Do you know where all of your private data is?
I wanna be able to catalog and have a map of all of my private data. Do I know where all of my servers are? I thought I only had five, but lo and behold, I have 10 or a thousand or 10,000, whatever it is.
So do I know where my servers are? Do I know where my private data is? Have I encrypted that private data?
Am I monitoring it? Am I putting, taking that data and applying controls to it? All of these things fall into data security.
Arguably identity access. Is it Terry? Is it supposed to be Terry?
There's all these pieces. And so one of the things, and what we, we've been working on here recently has the ability to give you a score to say, what's your risk? What's your percentage?
What's your percentage chance of, of a breach, and what's your percentage chance of noncompliance? Those are two different things. Mm-hmm.
I might be fully compliant yet still be very vulnerable to a breach because I'm really just protecting P c I cards and the other 90 of my hundred servers aren't under regulation. So I'm doing a great, great job on one and not on the other. But following right along that is to say, why do you have the score that you have?
Well, you have the score that you have because you've told me you have credit cards, but you're not encrypting it, and that's a requirement of p c. So your score is a little bit higher of a non-compliance because you haven't done these things. So the goal here is to be able to identify, um, from a, from a data protection perspective, kind of their posture.
Where are you, what's your status and what do you need to do next? When you come in on Monday, you have a list of these are the things you can do to make this score better, to better this, this rating, if you will. And that's something that, that I think the organizations have missed for a long time is giving, being provided some level of instruction to be able to say, you can interpret it the way you want, for sure, but we have a lot of expertise and we can do it as well.
It it, it seems to me to run this idea by you, it seems to me also those are, those are many, many benefits By having that scorecard, having that process of developing that risk profile and, and where you are and what you need to do to improve. Also, we know we're working in a fluid environment, right? Yes.
Regulatory things are changing then not as fast as business is changing, right? What the company wants to do with that data. Um, we now have a thousand more databases this week than we had last week.
Who did that? How did that happen? How does it fall onto this?
So, you know, you've got a framework to work from to say, well, here's what we do, here's how we do it. Do those same, uh, processes, technologies, people, et cetera, apply to those things? Or do we need to adapt?
Right? The, what we're doing with that data is a slightly different, okay, maybe there's a compliance or privacy, uh, thing that we need to do and validate versus without that you're just kind of, everything is dealt as a one-off and now you really don't have a, a good sense of, you know, have we done enough? Are we doing enough of the right things to both be compliant, be protected, as well as serve our customers without losing their p i?
Yeah, you're right. And, and I'll I'll keep this one short. I mean, the, the, the reality is, is as you, as you recognize in an organization that there aren't a lot of data security, data protection, data privacy from a, from a technology and security perspective, experts that are out there.
And so trying to rely on your own expertise is fine. I can, I can name on maybe one hand the number of companies I talked to that have truly a data security expert that I would say that guy knows what he's doing. The rest have to rely on automation.
They have to rely on the technology of the vendors that they've brought about sometimes their services organizations, et cetera, that they have. But it, it provides them, particularly the automation provides them that capability to not have that inkling in the back of their head that's always back there saying, uh, am I missing something? What am I not doing?
What, what, mm-hmm. What gap do I have? Having that automation in place as part of a, as part of a platform to be able to say, yeah, you just spun up.
We, we've just recognized cause we scanned every day or week or month, whatever it is. I've just recognized five new data stores. I automatically classified those data stores.
And when I did, I found some PCI data inside those data stores. These are not listed as PCI data stores yet. There's credit cards over here.
I can automatically apply controls, I can already bubble this to the top and I can already give it a score and say, highly risky, not risky, whatever. And that becomes an an important piece that says, I don't have to remember every single thing. I can have a process, but I can recognize that the technology is gonna keep me current and make certain that like, like ways or anything else taking me somewhere.
If, if the, if the, the the, um, the status of the freeway changes, it's gonna automatically say, here's a better route. And we wanna be able to do the same thing when it comes to data security to be able to say, you're stra, you're your, your environment has changed. There's a different route you need to take.
There's some things that you need to do. We've already done a lot of 'em for you. Just follow this path.
Um, last question is, uh, how do, how do people engage with you? Because we've talked about it's pretty wide swath of, you know, all the different, you know, different target areas, you know, lexicon of terms, uh, things to deal with. When people approach Imperva, what are the, what's the best way, if I'm saying I'm wrestling with some questions or I need a better strategy in place, a better risk profile, how do they do that?
They call up their local 1-800-IMPERVA. Uh, no, I'm being facetious. How, how do we engage with Imperva to get the, the best, uh, experience and value from that engagement?
Yeah, yeah, absolutely. I mean, like, like any organization, we have a sales arm in all of this, right? And you can certainly always reach out to that.
But I find most commonly the organizations that we work with, with work with have trusted partners that are already out in the ecosystem, right? So, you know, in America, there's, there's lots of partners in Europe around the world. There are value added resellers, distributors, uh, system integrators, whoever it is you normally work with from a data protection, data security.
And I'll argue data privacy perspective. Ask them about Imperva and they'll be able to get, get in touch with you. If they don't know anything about Imperva, absolutely reach out to us and we can not only educate you, but certainly your partner as well, um, and make sure they're aware of it also.
Yeah, I know you, I'm aware you have a very large partner network and between that and your customer base, so there's someone who's gonna know about Imperva. Yeah, for sure. Definitely.
Great. com and find out more. Terry, it's fantastic, uh, talking with you again.
We look forward to our next conversation. Until then, uh, be safe protecting that data and helping customers do that. Appreciate it.
All right, we'll talk to you again soon.