Data Security in the Cloud Era with Nikhil Girdhar of Securiti.ai
Nikhil Girdhar, senior director for data security at Securiti.ai, explains why securing data, as volumes continue to increase, is a much different challenge in the age of cloud computing.
Transcript
This is Textron tv. Hey guys, thanks for the throw. ai, and we're talking about, well, all the challenges that go with securing data in the cloud.
Nikhil, welcome to show. Thanks for having me. We are seeing massive increases in the volume of data, and a lot of that has to do with the cloud because, well, it just makes it easier to create data, but are we underestimating what it takes to secure all that data?
Because the faster we create it, I think we're just being overwhelmed. We don't have enough people to figure out how to secure it, and we're not all that good at security of the cotton in the first place. Yeah, Mike, I mean, certainly a huge problem that we're, uh, hearing from every single, uh, company that we are talking to, right?
Uh, the, the volume, uh, velocity and the variety of data sets that people have to deal with in the cloud really makes it difficult to find and protect sensitive data. It's a huge challenge for organizations. So what's the best advice for approaching that?
Because the problem's everywhere, and I don't think anybody's quite got their arms wrapped around it, but, um, are there a set of best practices for figuring out how to do all this? Um, yeah, certainly lots of best practices and, uh, kind of peeling the onion, right? Like there are, let's start with the problems, right?
So number of issues that people have to address. Um, one is, okay, how do you find different data, uh, data sets in the cloud, right? And there's so much variety.
So one of the first pieces, okay, think about you may be using many multiple clouds. How do you get the breadth of datasets? And the other piece is that, uh, data is not like workloads, right?
Data moves from one environment to another. Uh, people are constantly moving production to non-production from warehouses to SaaS AppSec and so on, even on-prem environments as backups and so on. So how do you kind of understand the connections between dataset?
So thinking about the breadth of data coverage in the cloud and other environment that a company is kind of, um, very critical point to have a holistic security approach. Then the next speech, I think is, uh, kind of very, very critical is, um, yes, we need to have visibility into data, which means discovery classification, but the higher order of value is how do you get the context about data to truly make security decisions, right? Uh, putting ourself in the shoes of a security practitioner, the questions we ask need us to know, okay, more than what is sensitive data?
Like what are the users, what are the vulnerabilities around that data? All that context has to be instantly accessible. So getting the infrastructure and the stack in place to get that context is another critical area.
Third area is thinking about the entire lifecycle of how you operationalize controls, right? Uh, from detection to investigation of issues, to alerting and taking actions. Today, this happens in many different places.
So how do you stitch together workflows? So automation and orchestration becomes very, very critical. And Mike, finally what we hear a lot from customer, uh, companies is that security is one aspect of data, and there are many obligations that are related.
Think about privacy and governance challenges, which, and reality is that most of these teams need to have an understanding of data, so they need to collaborate. So how do you kind of build that, uh, more coordinated approach, almost like a data command center? Um, I mean, we have heard the term soc, right?
Security Operations center, then noc. Uh, I feel that the time has come for the data teams to think about a data command center. Is this whole data security issue in the cloud, an extension of our data management issues that go back as long as I can remember, we never really got good at managing the data in the first place.
So how can we be expected to be any good at security? Certainly, these are very, very related topic, and especially as we kind of speak to like CDO offices on the data management types and on the CISO offices, what we are hearing from these teams is often their responsibilities converge. They're working on shared projects, um, the frame and the best practices they need to implement, overlap, and often to implement their specific best practices.
They're leaning on each other teams to actually, for example, think about, um, if you have to actually go and mitigate the vulnerability that you have found in your data, you need to understand that who's the data, what, right? Uh, you need to surface that context to the, uh, data owners and the, and share the privacy context and security context to the, uh, analysts and users. So certainly these areas, uh, kind of overlap, uh, both in terms of issues that teams are facing as well as kind of solutions that we need to solve these problems.
Is there somebody who's in charge of data security in these organizations? Is that a role within the security team or an extension of the people managing the data itself? I mean, it almost seems to me like we don't have anybody who's really taken ownership of this issue.
Yeah, I mean, um, so I mean, first of all, as with everything in security, it has to be a shared responsibility, right? But when it comes to kind of prioritization, uh, the ultimate responsibility, uh, in terms of answering the security questions falls within cybersecurity department, starting from the cso, uh, because data is one of the key assets, crown jewels that the company needs to protect, right? And there are many different parts of the organization, um, the analysts in the vulnerability management looking at the data and prioritizing the vulnerabilities, uh, SOC team looking at the events and trying to understand what events are actually impacting by most sensitive data, right?
Uh, incident response team, when a breach happens, how do you kind of respond to that? So there are many different teams within these, uh, cybersecurity department who are just looking at data as, uh, one of the critical assets that they need to protect as a part of the IT infrastructure now goes without saying that, uh, these teams certainly need the help outside the organization, uh, not only within the governance team, the CD offices, the privacy and compliance office, but the actual, the application owners who are managing and collecting data, uh, uh, collaboration from the, uh, data analysts and scientists, uh, not only producers of data, but users of data. Uh, so it does span across these, uh, uh, boundaries of just the security department and strong collaboration framework is needed to kind of protect the data.
Are the cloud service providers helping with any of this? I mean, I know we have that shared responsibility model, but what exactly are they helping organizations do or do they just have a vested interest in seeing as much data as possible in the cloud? And that's about as far as they go?
Um, certainly, I mean, uh, depending, again, going back to as you mentioned, shared responsibility, right? Cloud providers are helping out and they have lots of native controls. Uh, think about, uh, anonymization techniques or masking techniques, right?
Uh, um, the classification. So a lot of these capabilities sometimes come from the cloud providers, sometimes provide, uh, come from the vendors, but cloud providers are doing their best to engage with the cybersecurity vendors and ecosystem to kind of, um, help come up with that holistic strategy, right? And it's in the best interest for both innovators because ultimately there's a reason why we are collecting data.
It's to monetize and to innovate using it. And providers benefit from more data coming into, uh, their platforms. Uh, so certainly they're helping out at the same time.
The challenge is that the, going back to the original kind of point, which is the diversity of landscape data sets in so many distinct environments, uh, from a customer lens, it becomes just very complicated to kind of, uh, rely on every single native capability. So you need almost like an orchestration layer on top to, um, understand, um, and ask questions. Um, think about a simple, uh, question.
If as an organization, I wanna know, okay, where am I storing social security numbers in my company? A simple question is so difficult to ask because going in different environments and understanding controls become very, very challenging. So the, you almost need to think about, okay, how do I have a common language for understanding and protecting my data across these environments?
What about the bad guys? Are they getting better at targeting data in the cloud? Especially, I mean, there's a sea of it.
So, um, how are they going about determining what data to get? And are they able to figure out what's more valuable sooner than we are? Uh, certainly, I mean, uh, there's, I mean, I wouldn't say they're necessarily getting better, but certainly, right?
We see with the number of breaches, it's easier for an attacker, right? Uh, if I'm a, um, vulnerability analysts, right? I, I may have to go through a list of spreadsheet with so many issues to tackle, but the attacker just needs to find one of those, something that's publicly exposed to go through it.
So certainly attackers do have an advantage, and this is where our role comes in in terms of helping, uh, our security champions to kind of prioritize data based on context, right? Focus on the, uh, most critical sensitive data first, and then make that the basis of prioritizing all the controls, whether it's about, uh, reducing the public exposure of data or implementing zero trust controls, least privilege access, all of those, um, best practices that we have been doing, uh, across my it, uh, infrastructure and asset over time for data, we need to start looking at data first, right? Sensitivity first, uh, and then take that approach so that we can be more efficient in kind of protecting most critical data assets.
First, You work for a company that has this little thing hanging off the back of it called ai. So will AI save us from ourselves or how's that gonna get applied? Certainly, uh, I mean, uh, gen ai, uh, kind of the most latest flavor of ai, right?
Uh, has, uh, all of us excited. Um, and there are two aspects of ai. One is how does AI really help us secure, uh, our data better?
And the second piece is also equally important, which is how do we harness ai because data is a critical component to ai. Um, and I, I'll kind of talk to both of those, right? The first aspect being, uh, even before LLMs became popular with Chad, GPD, right?
Our company has been training LLMs for years now to really kind of classify data, right? Uh, it's no longer about, uh, just doing simple project matching. It takes and a lot of LLMs advanced techniques, LLP to really understand the context around data.
Uh, so certainly, uh, when it comes to using ai, it helps you, um, become more accurate when it comes to understanding the true, uh, kind of nature of data. Uh, and then the other piece is, uh, where another huge advantage for companies is we talk about complexity, uh, of the tooling itself, right? The co-pilots are really making it easy for organizations to kind of, uh, engage, um, rather than just figure out all the nuts and bolts.
Now you can simply ask question, okay, show me where is PI in my environment? But human language interface is something that we have been kind of innovating and making it easier for tool, uh, companies to understand. Another area is the regulatory landscape, which happens to be very complex.
Uh, another area where AI really kind of plays a huge role in understanding the depth of the law and also find out, uh, how does the law apply to my data? So lots of innovation and uh, kind of help coming, uh, for security teams when it comes to, uh, using ai. But the other aspect, which is equally important and every single company is, okay, I gotta embrace gen ai, right?
To kind of drive efficiencies. But hey, we gotta remember that data is a key input. It's used to train the model.
It's true, it's part of the prompt, it's the output. So protecting that data, having a data strategy first becomes a prerequisite. That's another lens.
So almost thinking about data security controls before you jump into Gen ai, because we don't wanna repeat the mistakes that we did with cloud, right? Uh, not having a plan and jumping in, and we have all seen that story pulled out. Ultimately, what is your best advice to get started here?
'cause I feel like I gotta pull together the data management team, the security team, security team, the cloud service people, the DevOps teams. There's data engineers running around, how do I get them all in a room and figure this all out? So my best advice would be kind of to take a step back, right?
Oftentimes what we have done is, uh, we see a problem and we try to just look, come up with a solution. Okay, I've got a privacy issue. Let me find a solution for that.
We've got a challenge. Let me provide a way to give my users access to data. But the reality is there is two sides, right?
One, we have to have controls over data. Second, we need to use that data, which is very, very important. The sta being that nearly only 30, 30% of the data in an organization gets used today, right?
How do you drive adoption of more data for innovation? And if you think about that problem, it starts from the top down, right? Having unified controls over your data, right?
Most of the problems that, uh, our teams, whether it's security, team privacy, the problem that they're trying to solve, they span across multiple teams. They need input from the actual data stewards, input from your privacy and compliance counterparts, input from your, the wellness teams that have to actually operationalize these controls. How do you give them a common way of thinking?
And that's, that's not just about technology. It starts with kind of a governance committee, right? Is there a forum to engage better and kind of help formulate a standard set of data policies for the organization?
Um, then thinking about the processes, every single policy has to touch many teams. How do you operationalize those processes? Um, and that ultimately needs to think about, okay, what is my data architecture for governance, right?
Uh, can I live with so many different tools or how do I simplify that? And, and this is where I go back to my earlier point this time, that we almost need like a data command center that kind of starts thinking about providing shared context to the organization and automated controls that ultimately make it frictionless for teams to access data. It's all about making data accessible and usable within the company.
All right, folks. Uh, if you don't have some sort of approach to managing data, bad things are just gonna happen. So it starts maybe with that command center and figuring out, Hey, what do we got?
Where is it? Who's using it and why? And thanks for being on the show.
Thanks, Mike. Great to be here And back to you guys in the studio.