Data Security and Governance Risk Management – Ani Chaudhuri, Dasera
Dasera raises $12 million in Series A funding to pioneer a new era of data security and governance risk management.
Transcript
This is Techstrong tv. Hey guys, thanks for the thrill. We're here with Annie Chad, who are you?
C e o for Daer. They just picked up 12 million for a platform that automates data security. And we're gonna jump into, well, why do we need to automate data security these days?
Annie, welcome the show. Thank you so much for having me over. Uh, excited to share our journey on where we are going.
I think it's pretty obvious that we're all choking on the vast amounts of data that we are creating and trying to store. So the question then becomes, well, once we store it, how do we secure it? Cuz it seems like every time we wake up in the morning, somebody's trying to steal it.
So how do we kind of automate this in a way that we can maybe win this battle? Um, well, the way to think about it is, um, a lot of the processes that we deal with every day have been automated. But if you think about data, the way companies drive value from data is by collecting a lot of it and then giving their people access to that data.
The challenge is that if you were to draw a line of risk, it continues to go up. The more data you have, the more risk there is. The more people you have, the more, more risk there is.
Now we need to bend that, that line, we need to convert it into a curve. And the way you do that is by putting enough automated control so that if you had 20% more people or 200% more data, the amount of risk is flatlined. It's not going to go to zero.
But what happens is that it does not incrementally keep going up. And so, uh, at Daer what we are trying to do is we are trying to bring in a level of, uh, context awareness of the data lifecycle in, and then provide a bunch of controls that will take care of things that are manually done today. So it's not just best effort, it frees up your people to do the value add work while the commodity work.
The boring work, the demotivating work is in automated workflows. You come to the point that I think we all avoid or ignores that, um, we have so many people accessing data and they have so many privileges and everybody seems to be overprivileged, but we don't wanna manually go in and deal with this issue. And we don't even know if it's an IT issue or an HR issue or somebody else's issue.
So how do we begin this process to figure out, you know, what we should be thinking about and what we should be doing? Uh, again, a great question here. I, I think that when you think about data, you have to think about the variables that you need to control if you were to control the data lifecycle.
And so the variables, for example, are four. The first one is data infrastructure. It's like, where do I keep my data?
How is that organized? Do I have on-prem, do I have in the cloud? Are there platforms like Snowflake and Databricks setting on on that?
So that is the data infrastructure. That's a very big variable. The second variable is data, and its connected attributes.
And by attributes I mean things like, is this p i i, is this P h I? Because every time you have data, that's not enough. Knowing your responsibilities towards that data becomes key.
So that's the second variable. The data itself. The third variable is data users, people who are touching that data, people who use it every day.
So a profile of those people is the third variable that you have to deal with. And the fourth one, which is the most underinvested and where we have a strategic technical advantage is data usage. And when I say use usage, it's not a combination of activity and access.
It is primarily how do people use the data when they're given access. So for example, is there a person who is writing a select start query versus another person who's writing a count query? The count query is statistical in nature while the select start query brings down raw data.
Right now, imagine if you could control where your data is, what data is there, who has access, and how they are using it. You have the first building block of true data security on top of that, the second problem that we see is that the number of stakeholders who are responsible for the data, I would call them custodians and stakeholders of data, they sit in different functions with very different drivers and incentives. For example, the data science science team is trying to use that data to drive, uh, business decisions.
The security team is trying to close it down, uh, in terms of protecting that data. When you think about the compliance team, they are looking at making sure that you're doing the right things. The challenge is that sometimes because their drivers are different, they can't collaborate.
So the second piece that you have to think about is, do you have a platform which allows you to create policies that work for everybody and not everybody's running with a separate tool. And then finally, you know, once you have policies in place, either people are following it or they're not. When they are following it, you want to know that it is being followed.
But when they're not following those policies, can you not create a situation where you've got a lot of alerts? And so you need to break it down into words commodity and can be automated and what's unique and needs to be reviewed before it is automated. And so once you have all of these pieces in place, you will have a solution that, uh, you know, meets our vision of bending that curve where you can add more data, add more people, and guess what?
Your risk has plateaued. Right? Right.
There's a lot of this trace, its history back to the fact that we never really had a decent approach to data management in the first place. Cuz it, you know, treated all data equally and nobody on the business side made any differentiation. So are we kind of paying the price with all that now?
It's a, it's a yes and no answer. It's a yes answer because everything that you said in a binary sense is yes. Right?
It is also a no answer because the way we handle data, how many people handle data has changed. So for example, uh, people keep on saying data is the new oil, but I challenge that, uh, that, uh, statement. I think that data is the new guard garden.
So the way to think about it is, you have a garden, you have a fence around it, that's your perimeter defense. But once you're in the garden, people have different roles. Somebody is putting in sapling, somebody's watering, somebody's pruning, somebody's harvesting, somebody's taking out the junk.
The same thing is happening with data. Like you have a data lake, you bring in stuff into the company, and then different people have different roles. If the roles are organic, any solution that is not just as organic and as dynamic cannot solve the problem.
We haven't had this need before, but now with regulations, with the amount of data companies are handling that re this is more urgent. This is something that we need immediately. So, so yes, we have never had this.
So I do agree with your statement that we didn't do it. Now we are paying the price for it, but it's also, you know, in business it's already always trade-offs. We have reached a point where that trade-off of not doing something with data today may be really harmful for your business.
Mm-hmm. When we think about all this, um, have we reached a point where, um, the data that we're trying to manage, every company runs around and says, well, I'm not a regulated industry, but it seems to me we're reaching a point with the regulations where everybody is in a regulated industry these days. I I agree with you.
I I I was having that same, uh, part. So, you know, when you think about regulated industries, people would generally say the regulated industries are healthcare, financial services, some, uh, e-commerce or online gaming companies that have, uh, users are less than 12 or 14 years old. Like there are a few regulations there.
But if you think about it at the federal level, at the state level, at the international level, every company is regulated. They have responsibilities. What is even more important is that I think consumers today care a lot more about their data than they did 10 years back.
Like if you just pick up your, your cell phone, right? Your cell phone has what, thirty, thirty five, uh, apps. Each of those apps has your data.
And the way we think about data is you have a digital twin, right? In each of those companies, one digital twin represents how you play games. Another digital, uh, twin represents what kind of shoes you like.
Another maybe what kind of movies do you watch? What has happened is with data science, a lot of people have created multiple copies of that in their own companies. And then they're poking around, uh, those digital twins.
If it is not all right to poke around a person in their physical form, why is it okay to do it in with their digital twin? And so as we think about it, I think the, the elevation of this space is going to happen when our mission is not just solving a technical problem, but the emotional human problem of managing a person's digital twin. Like you would treat that person, right?
And so, um, it is, it is not just a plain, simple, uh, technology solution. It's like if we lose the bad guy's win, we have to think about it like that. Mm-hmm.
How hard is it to set something like this up? I think a lot of people have been deterred in the past because they've been confronted with these rather complex systems that are more painful to manage than the problem itself maybe. Um, see, the thing is that if you look at all of the solutions in this space, whether it is, um, the infrastructure on which data is sitting, the databases that they're being run on, uh, if you think about active directory or Okta, the directory services or things like data catalogs, each of that had a specific purpose.
There are great solutions in this space. The problem is like they're efficient islands. So what has happened today is that you've got all of these efficient islands, you bought all of these products, but they don't have bridges to each other, right?
The lack of bridges, what it does is that it is not doing anything to tell the next solution. Some insights it gathered, right? And they speak a different language.
So what that means is even when you have an api, the API is actually not delivering insights that is useful. So unless you are able to get away from manually creating, uh, trying to connect different, um, uh, different solutions, this is going to be broken. And so when we started the Sarah, we understood that and we said, you know what?
It's going to be harder, it's going to create some friction, but how about we create a solution that is end to end? It, it protects the entire data life cycle, but we also created an open API system. So if you've already invested in something, we would pull insights from that.
If you've got some system, uh, down the pipeline that you are comfortable with, we will push context into that. And so we have to kind of think about it like that. So there are different companies.
They are just using different types of Lego blocks, and what we have decided to do is try and standardize it and make it a whole, We hear a lot about artificial intelligence these days. Where might that be applied to the way we think about data security and management? It's, it's a great question.
So artificial intelligence, if you really think about it, is the ability of a system to look at two types of inputs, which is data that it, it captures itself and when people interact with it that it gets better, right? This has existed in other places. It's simply become more fashionable today, especially in the last one year because consumers are getting to touch it for the first time, right?
Uh, chat is an example. You know, it's brought artificial in intelligence to, uh, consumer forefront. But does it change things for B2B companies, uh, or B2B two C companies?
The answer is yes, but it is not going to be something that's going to be overnight. It has to be, uh, there are places that where statistics is better. You don't need to do artificial intelligence and machine learning, and there are places where you have to do artificial intelligence and machine learning.
Uh, picking that, picking the right tools, that tools that scale don't create additional problems. Like, so for example, if you remember the, um, a few engineers in Samsung, they released, they used chat G P T, and it pushed out some proprietary data. So it is also another tool.
You can't get in a car and start driving it. You need to, uh, train, you need to get your license, you need to know the rules of the road. I think the same process is going to happen with artificial intelligence, but the journey has started.
We are optimistic. In fact, in our own product, our query analysis engine loses, um, uh, uh, I wouldn't say a lot, but it does use AI as a foundational piece. Um, so that's our position.
As far as AI is concern concerned, Who drives this conversation these days? Is it their risk officer, the security people, the IT people, somebody who owns the applications, who's kind of waking up in the morning and go, we gotta solve this, Solve this. As in, I assume you're meaning data security, right?
Mm-hmm. So data security by its name, uh, has got two stakeholders, data and security. So they are the ones who will touch the system every day.
But because this is so important, you also have compliance and general management, uh, that want it to be solid, uh, in terms of trade-offs. So if you, if you think about, um, think about a data like a data security solution. Your primary buyer could be the head of security, but it would also be somebody associated with data.
And we've seen both of those happen. It depends on the maturity of the company. How well do security people understand data and how well do under how, how well do data people understand their responsibility towards data, towards, uh, yeah, data sec, data security.
And so these two, when you combine, you have that combination of data and security. All right, you raised the 12 million. What's your plan for that?
I mean, I'm sure you know, everybody's happy in the company. What, what's the strategy from here? Yes, we are happy and we are hungry.
Uh, the, the, we are one of those companies who have, uh, picked our customers, early customers very, very deliberately. We have picked the harder companies to go work with so that each vertical that we enter, we know what they require. So we've taken on complexity upfront.
If you are going to build a platform and you, you've got the wrong, uh, initial customers, that's not going to happen. So we decided to take that on. With the 12 million, what we are planning to do is we are planning to take the large core customer base that we have and grow it two to three times this year.
That's our plan. Uh, again, as you can imagine, this is, uh, tough times. Not only for us, for almost every company, there are budget cutbacks, but, uh, with budget cutbacks, the work does introduce, right?
You'll have fewer people, you've got fewer resources, but you still have to protect the incoming data that is, that is humongous. And so we are perfectly placed because we automate data security and governance controls to take advantage of the current business environment as well as the amount of data that is still being collected. All right, folks, the only thing worse than the declining economy is to be fined for something that gives you even less money to invest.
So that's where your ROI is with this whole thing. But at the end of the day, um, you're gonna have to do it one way or another. So now's time to get started.
Annie, thanks for being on the show. Thank you for having us on the show. Sure.
All Right. Back to you guys in the studio.