Data Security as the Final Defense with Bedrock Security’s Bruno Kurtic
Newly appointed Bedrock Security CEO Bruno Kurtic explains why data security has become the last line of defense for organizations trying to cope with cybercriminals that today easily bypass other layers of the cybersecurity stack.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Bruno Knick, who is newly appointed CEO and president of Bedrock Security, and we're gonna be talking about data security specifically, which has becoming a much bigger issue in the age of ai.
Hey Bruno, welcome to the show. Thank you very much. It's great to be here.
Alright, you just joined the company and, uh, you've been around the industry a while now, and we can all talk about our shared gray hair, but, um, my question to you, I guess is, uh, what attracted you to bedrock security and what is the problem we're trying to solve? I mean, it's this, the age old problem of what, what is all of security in the enterprise, uh, for, it's all for protecting sensitive data, right? That's what we are all trying to do.
Um, and up until recently we really couldn't put data at the center of a enterprise security strategy because it was really hard to figure out where all the data lives and even harder to figure out what is sensitive and what is important. So we basically couldn't do that effectively in the past. And now is a time when we can apply modern techniques and technologies such as generative AI and other, uh, techniques like that to actually put that data at the center of the security strategy.
Well, how do we do that? Exactly, because to your point, we've invested massive amounts of dollars into perimeter security, whether that's at the end point or the networking, I feel like data's become the last line of defense, but how do we defend something that has so much of it that we are not even sure what it is? It's a very, very good question, and I think that's sort of that, that goes to the heart of the problem here.
Data is changing very quickly, right? Data is growing at the rate of Moore's law. Digital companies generate a tremendous amount of digital exhaust, which has all kinds of sensitive data, private data, uh, financial data, customer data, all of this stuff that constantly is generated and stored in cloud systems and developers generate a lot of it.
And so how do you keep up with it? How do you know where it is? How do you know what to even focus on, right?
At the rate of change of agile development is just driving changes in your data environment so quickly. So the challenge here is first knowing where it is, um, and knowing where it is requires a technology that can actually keep pace with this exponential growth in data. Um, and then the problem of how we've approached it so far by doing, you know, infrastructure security, network security, user security and things like that, is that that is all designed to try to secure systems where sensitive data might live, might live.
So the way to actually keep pace with this is to try to overlap these diagrams, these Venn diagrams, meaning prioritize the work on infrastructure by knowing where sensitive data is. So you first security infrastructure where, you know, you have sensitive data, where you have important data, and that's, that's the way to approach the securing of the infrastructure to improving your posture management. That's the same way of approaching, uh, reactive securing meaning when a sim fires an alert that says, you know, there's malicious activity or there's a threat that I'm detecting, you know, SIM is notorious of firing so many alerts that enterprise and SOC teams can't keep up.
So how do you prioritize alerts? Well, if you know that those alerts are related to your sensitive data sets, then you can prioritize the alerts and the work that that is needed to secure those environments, right? So data is a contextual input into security, and if you can figure out what's sensitive, then you can improve your activity on securing that data.
So are you helping me discover what sensitive data is where, and then apply the encryption or you're just doing the discovery part? So we do multiple things. So first what we do is we do discovery part.
We have a hyper paralyzed approach in discovering data, which is sort of, um, at the core of our platform. So we discover all the data, we interrogate your, uh, technology stack, the systems, APIs, configuration management databases, and discover where all the data could live. Then we crawl and essentially discover what's in those data stores.
We then build a picture of your data environment. And once we have the full picture, we have a full map of where everything lives. We then start interrogating the dataset itself to, to classify, to determine what's sensitive, what's the lineage, where did it originate, is it moving, and things like that.
So we now build a picture of not just where your data is, but what is in that data and which parts of your data are sensitive and important. From there we go and we determine what is the, what are the entitlements who can access the, this data, which services can access to which users, you know, is there access that's over-provisioned underprovision? Can it be, can we reduce the access and exposure of data?
So we go all the way from discovering data to classifying data, to understanding access, and then providing a picture to the enterprise of how they can approach reducing access, reducing exposure, and reducing risk. A lot of folks are trying to figure out if we can spend more time securing the data, would that mean that we would spend less on perimeter security or is this just the latest in a more of a defense approach that we've been implementing? But it's just been too hard to add this layer.
It's been too hard to add this layer. And I don't think it's it's separate from perimeter or infrastructure security or, or things like that. I think it's an integral aspect.
It's an integral vector of informational, how to approach perimeter security, how to approach infrastructure security, how to approach vulnerability management, right? When you know where your data is and what's sensitive, and you've got the sprawl infra of infrastructure, the overlap of where that data is and which infrastructure affects the sensitive data gives you a way to prioritize what you do. So I don't think it's separate.
I don't think it removes the need for perimeter security or sim or, or user management, but it gives you a way to reconcile what you are focusing on what matters and what you do first. A lot of folks also would just say, well, encrypt everything, but it's not clear to me that A, that's economically viable, and b um, even if I lose my credentials, somebody can then see my encryption. So, um, how should I think about data security these days?
Well, encryption is of course, important. It's one of the tools in our war chest or securing data, right? But there is, you know, just like you said, you can encrypt it, but if something's compromised that has access to the encryption keys, your data is still at risk, right?
So, so you have to think about it, um, in, in a, in a multi-layer way versus you have to know where everything is. You have to encrypt what you can encrypt, and then you have to secure things that access that data, whether it's encrypted or not encrypted, right? Because, you know, it's things that access that data services that might have vulnerabilities.
You know, think about a situation where you have a data, data set that living somewhere, let's say in the cloud, uh, there, there are a bunch of users who access it. You can secure those users, but then there's a bunch of services to access access programmatically. Maybe those services live on some containers or I two instances that might have vulnerability.
So it really, you have to, once you pull the thread, you have to go look, go deep and understand what are all the ways of expo all the exposure could happen. You know, if a service is vulnerable and it can be compromised, it doesn't matter if your data is encrypted because if, if the service has access to the encryption keys in order to do, to read the data, because to perform the service, whatever the function is, you know, your data is still at risk. So, so encryption wherever you can, of course, right?
But you have to go much beyond just encryption to secure data. Data. Do you think the rise of ai, specifically generative AI, has kind of shown a spotlight not just on data security, but data management and the whole way we think about data, because for some reason, I feel like we took all this for granted?
It's a great question. Uh, absolutely. In fact, AI and the rise of generative AI is very much, uh, at the core of data security, um, awareness right now.
It, it does two things, actually. It, and these two things are your opposing forces. Number one is that generative ai, the black blocks that it, that it is, right?
The neural network that it creates once it consumes your datasets in order to be able to answer questions, in order to be able to serve as a co-pilot or an agent and things like that, it is very hard to understand what's actually inside of that black box after the data has been consumed, which means that it, it is an exposure risk if you accidentally by unknowingly provided that your large language models training data that has sensitive information, you have no idea how to protect whether it's going to be exposed to people who are on the other end consuming that model, right? And so there's a huge amount of, um, awareness that needs to be brought and technology needs to be brought forward that make sure that the stuff that generative AI is leveraging to produce business outcomes that you're seeking is the, the right stuff. That it doesn't contain sensitive information that it is segregated in, in, in the right ways that permissions are set, that, that you are aware of what's in it, right?
So that's one thing. So that's what's, that's one of the reasons why the majority of generative AI efforts today in the enterprise, everybody's talking about it, but most of those efforts don't end up in production. Everybody's got pre-production, generative ai, uh, initiatives, but they're all scared to turn it on to production because they're not sure what's the exposure risk of those systems.
The second aspect to this is that genea creates an, an amazing opportunity to technologies like ours to actually have a far better way of understanding that data to essentially to classify it to learning, learning similarities so that we can classify similar things in a way that goes far more far far beyond what rules could do, right? And so basically the way we think about it's, if you're gonna use generative AI to improve, improve your business and deliver new capabilities, which creates risk along with it, you have to bring generative AI to that fight. You have to make sure that you have a as powerful of a system that secures your data as you are building to deliver functionality.
And so that's how we're approaching this problem. Uh, we bring forward an extremely powerful AI model that is able to tell you, actually, this is what you're feeding to your generative AI systems, and this is how we can help you make sure that it's secure. So in effect, I kind of need a AI model to govern and secure the AI models.
Exactly. You, you can bring a knife to a, to a gun fight, right? This is kind of how we think about it.
And we believe that only AI can keep pace with the rapid rate of change in data and the rapid rate of explosion of generated AI models that are using that data. How will data security and data management ultimately converge in this era? Because a lot of the things we're talking about are, um, you know, frankly, we didn't really have a lot of great data management protocols.
Um, business people would create data, and as far as it was concerned, all data was pretty much the same, and now it's not. So how do we kind of think about the convergence of data management and security ultimately? You know, it's a great question.
Uh, spend a lot of time thinking about this. Um, on the, the start of this journey at Bedrock here, the way I think about this is that data management as a core enterprise capability is what I would call a data management platform. And core capabilities of, of that, of that layer of the SAC are discovery and classification.
Those two create essentially a metadata repository, metadata lake or or, or a data catalog, if you wanna think of it that way. Once you have that player built, and that player is capable of keeping pace with the scale of data generation, keeping pace with the d diversity of data, and being able to classify it all, like we just talked about, using AI models and things like that. Once you have those two resolved, now you have a, uh, the baseline capability that allows you to ask all kinds of questions of this data.
Like, first of all is, you know, who's using it? Is it secure? Do I have vulnerabilities?
Um, do I have the right governance of access? Am I compliant with regulations that, that I have to comply with? And then beyond that, you can also ask non-security questions.
Do I have the right data to perform business functions? Do I have the right data to understand impact of new product launches? Do I have the right data for this type of a BI report?
Essentially, the foundational capability of data management are discovery and classification. And then on top of that, you can build all kinds of powerful things that we could not do effectively before. That's why in the data catalog world, there's not a whole lot of effective data catalogs today because they're all out of date because they can't keep up with the data changes.
So who's in charge of data security ultimately? Is it gonna be a cybersecurity team or will it be some sort of expansion of a data management role? How, who's gonna step up and take control of this?
Because otherwise everybody's in charge and then nobody's in charge. Yeah, fundamentally, you know, in digital companies, there is a shared responsibility in who owns data and infrastructure, right? It, it straddles the line of business and the security teams and the line of business.
When we talk about line of business people in the line of business who actually own the data, who put the infrastructure down, who manage, uh, the stack, who manage the applications that generated, um, and store it, are the developers in the CTO group underneath the line of business. So we see already that when we interact with our customers, there is a collaboration between the security team who knows what needs to be done to effectively protect data. It is the technologists in the company who usually are the ones deploying, shifting, left and pulling, pulling the, the technology into the development process so that it can be properly deployed and keep up with the change that developers, uh, make upon the data.
So it is a collaboration between the call 'EM developers or DevOps teams and the security teams. That's how it works today. There is unfortunately almost a breach every other day these days.
And, um, are we just getting to a point where we're enured of those breaches and maybe we're not thinking through, um, just how accountable we can be for data security because well, we do have the tools and I think maybe we're thinking that, um, well, once they got in, they got in. But does, do we need to change our attitude about data security? I think we do, and I would say we, we have a lot of tools, but we don't have, and most companies don't use the right tools.
And, and I think that, you know, everything has to start with do I know where it is? Do I know what it's like? Those are the fundamental things that, that have to be done, right?
If you do not know what you have and where it is, you cannot protect it, right? So in a lot of these data breaches that we've seen over the last few months, you know, the awareness has been, has been raised, but the fundamentally the questions to be asking is, did these companies know, number one, what was in their data? And my, my my bet is that they didn't, they didn't know that there were partial social security numbers and phone numbers and things that are unencrypted in these data stores.
And second, did they know was there vulnerable access? Some of these things were accessed through demo accounts and things like that, that, that simply should not have, uh, had as wide an access. So, uh, uh, a technology that can tell you what's in there and then what is the exposure, who has access, what are the entitlements, would've very quickly, uh, illuminated the problem to the right teams, right?
But I don't think those technologies are deployed at this time, and I think that's one of the reasons why DSPN as a technology is in such high demand, uh, as of this year. All right, folks, you heard it here. You know, data security is really not much different than any other crime scene.
The first thing any investigators are gonna ask is, who saw the victim alive last? Well, we touched the data last. It's probably gonna tell you where the source of the breach was.
Hey, Bruno, thanks for being on the show. Thank you, Mike. All right, and back to you guys in the studio.