Data Security in the Cloud – Hillary Baron, CSA & Tyler Young, BigID
CSA, in partnership with BigID, surveyed 1,500+ IT and security professionals to better understand the industry’s knowledge, attitude and opinions regarding data security in the cloud and found that organizations are struggling to track and secure sensitive data in the cloud.
Transcript
This is Textron TV. Hi everyone. Welcome back to Tech strong TV.
I've got another great texture on TV segment to talk bring to you right now. I want to introduce you to two people from the CSA the cloud security Alliance first. Let me introduce you to Hillary Baron.
Hillary and Tyler Young Tyler welcome Before we get started, I guess you guys need to introduce yourselves a little bit to the audience Tyler. I'm gonna start with you. Why don't you give people the kind of the Tyler young story?
Yeah for sure. So everybody I'm Tyler young. I'm see so at Big ID where I'm currently kind of in charge of building out their security program helping guide their big Ideas products helping our customers essentially protect and understand and discover their data prior to big idea.
I was at relativity the leading Discovery company building out their security team and program and I have about a decade in Tech mainly an instant response cyber security friends. Excellent and my mistake I said CSA, it's CSA and big ID. Tyler Millie with big ID.
Why don't you give us a little big ID background too if you don't mind. Yeah. Yeah.
So big is essentially a data intelligence platform it what we do is we enable organizations understand where their data is connecting to your SAS applications understand dark data connecting to your Cloud environments understand where your data May persist connecting to your file shares your on-prem data stores, whatever they may be it really helping you understand where your data is at so you can take secure actions on it, whether it's removing duplicate data or deleting data or remediating access to files in your Cloud environments, whatever. It may be it's it's a holistic data security platform. Thank you, you know unfathered intelligence.
Great. I appreciate it. Hillary.
How about you? All right, so I come from a research background. Want so a lot of my work is in our ad hoc survey research, but I do Focus as well on some of the emerging Technologies within CSA.
So looking at well emerging Technologies isn't necessarily totally. Okay, they become mature at a certain point but looking at iot blockchain Quantum safe security. It's kind of an Ever evolving portfolio of research that I'm focused on but that's primarily what I do.
I use to run our webinar program as well, but I have since handed that off. So it's mostly just research all day every day for me. Good for you.
So emerged technology. And you know before we get started in case I forget. com request a demo see more about the products or if you have questions about our security program.
Feel free to reach out directly to me on LinkedIn. It's probably the best Avenue. excellent and Hillary CSA Cloud security Alliance Yeah, we do a lot of different things.
So, you know CSA is focused on providing research and best practices on cybersecurity, you know, we're focused on cloud but also anything that's kind of related to Cloud as well. As I mentioned. I am interested in iot and lead a working group on that.
So we're really focused on just trying to help the community and you know the tech community and also end users to be able to utilize Cloud securely all of our research is free. That's a big thing at CSA that we're really proud of and we have a lot of great members like big ID that help us make that possible. org I believe right?
Yeah cloud. org is where you can find us. Actually, all right, we've got all the housekeeping out of the way.
Let's Dive In Here recently CSA released a report believe it was done. Was done in conjunction with big ideas that fair. Guys, tell us about the report.
Star so initially we were approached big ID was like hey, what's kind of going on in the in the data security space? You know, it's been I feel like it's been a topic that's picked up quite a bit over the past year. I I don't know what's really been the initial cause of it, but it seems to be one of those topics that's really top of mind for a lot of organizations.
So they're like help us understand what's going on in this space a little bit. We want to know a little bit more about kind of get a lay of the land of what people are struggling with why is this talk kind of coming around right now and that was more or less what we found is people are struggling with data security. So they're more interested in it right now.
They're when we did this survey. One of the big findings was like, you know, we were looking at You know how confident folks are because we're talking to the Security Professionals, right? The people that are boots on the ground doing this day and day out and you know, we were seeing that the confidence levels were they were okay and then we asked them about sensitive data and then they were like, oh Yeah.
only four percent Of us are like, yeah, we've got this in the bag. I don't know how much of that is to just being somewhat cynical, you know, they always say in the industry that you know prepared to be breached or assume breach or something along those lines. So I don't know if that's our cynical nature.
But certainly it's alarming when you think about how much data over organizations have access to and how much sensitive data we have within our organization. So that was really the big thing that we're like, oh this is concerning and something that the people need to be aware of and also be tackling head on Tyler yeah, and I think going back to like the it's not it if but when you're gonna be breached and and it's really preparing for that and understanding that if you know where all your data's at and you can remove the low-hanging fruit whether that's sensitive data that's exposed externally whether you s***, whether you have external data on your OneDrive or G drive or whatever you're using for data store. remediating some of those simple those simple data exposures can go a long way and release and kind of alleviating some of that pressure from breaches.
And so whether it's malicious or accidental, it's the entry point and then the networks have expanded now where data is really becoming your perimeter. So it's no longer the days of like reaching in a network move laterally and you can find data potentially like a file server. It's now that your data is your perimeter with SAS applications and they might have data we're storing in SAS applications and the connection between SAS app and SAS app and the leveraging of the cloud and it's the ability for a misconfig a simple misconfiguration to essentially just purged or poor data out throughout your the network or wherever you may be storing it.
It's just the organizations need to start focusing on this because there needs to be a more data of centric approach to security versus the days of like like I said securing the perimeter securing the endpoints that's gone it So look, we've certainly seen a Resurgence. I think over the last year or a year and a half of the Primacy of data, right? It was almost like someone put up the sign that said it's all about the date is stupid.
Right and for a while we forgot that I've been in security 25 years 30 years, right? We got all focused on the app absec if it was an app SEC it wasn't. Just didn't matter right we got focused on a lot of things and almost kind of lost focus on.
It's about the data. The data is the crown jewels. The data is the payload, right the mother load and and you know people may use the app or other vectors or Tax Services, right?
But you know, they they're Target is the data at the end of the day even even ransomware and stuff right there ransoming. They're encrypting your data. That being said though.
I'm good. I perverse is this may sound I'm glad to hear that 96% of people recognize. That you know when it comes to sensitive data, they've got work to do.
I mean it would be great if the work was really done but it would be a lot worse if 80% of the people said. Oh, no, we're good and we damn well know they're not good. right, so it you know The 12 step rule right number one is recognized.
You have a problem. At least we recognize we have a problem right better than not recognizing. You have a problem.
Of course the question now. Yeah. Now the question is what do we do about it?
And I always find though with these kinds of surveys. So there's like three things that are really important that take away. So we hit one of them here.
What would two other big takeaways from this report? I think another big one that's pretty relevant to what's going on right now with what we're kind of seeing in the news is we're seeing a too much access for third parties and suppliers and that they actually have similar access levels to our employees which you know in some cases maybe they do need that access. Maybe there's valid reason for it.
But realistically I think we have some work to do there in particular and I think those breaches have really drawn our attention to that. So a lot of organizations are starting to take that more seriously now, but we were kind of caught on the wrong foot there and it you know, we had breaches that made the news unfortunately because Yes, we did Tyler thoughts on that. Yeah, I mean I think.
So there's a few problems here one, we're giving third parties way too much access and no one's vetting it. So whether you're whether it's a more static thing that's happening in a procurement process and just doing a review of this third party that's becoming in and what they're doing. Why do they need access to your data or whether it's I mean look at your apps, you're connecting on your smartphone.
Do they really need access to your call list. Do they really need access to your text messages to run Facebook? Probably not but we're giving that access and most people just click next and accept they don't actually think about what's actually happening or think about how many things are connecting to your sales force.
Whether it's some type of Revenue Ops tool whether it's your slack even I mean, you're you're sass brawl is happening and you're just having applications to connect the applications. There's data interchanging. No one's actually looking at what date is interchange between those things.
So now you offboard you offboard an app or you off board an employee and that data still living somewhere and that connection still there and no one's actually severing that connection because most people aren't even aware of it. And so these things are never gonna go away, but you need to make it considered an effort to start discover. Where that data is at so you can take action on it because if you don't know or something's at or you don't know what's happening, how can you take action on it?
So again, it goes back to like maybe that's step two admitting you have a problem is is the step one and step two is like what do I even have? What is my problem? Like, it's so really understanding and being able to discover.
It is very important. I agreed agreed and that you know comes right from the first thing too. Right the first the first step is always awareness of the having the problem.
third thing Hillary third thing one of the big things that we thought was interesting was that a lot of the issues that organizations felt were contributing to to the proliferation of dark data was really around issues with Staffing whether that was like just not having the knowledge about how to kind of get their arms around that whether it was we just don't have interdepartmental cooperation. So we've got competing priorities going on or just we just don't have enough staff to kind of get our arms around this because we're creating we're creating so much data on a daily basis. So really a lot of those issues are coming back to you know, staffing issues and some of that's gonna be the skills Gap and then and part of that is going to be understanding.
How do we supplement our teams then and give them the information that they need and give them the skill set and give them the tool so that they are able to get their arms around this because this is a this is a solvable Along, but we have to kind of come up with a plan and if our people aren't on board and we don't have enough people then we need to figure out how to how to supplement them and how to how to help them because we can't just let this continue to grow and grow because that's what we've been doing unfortunately. So I have some views on this but Tyler I'm gonna let you go first if it's okay. Yeah, so I think with dark data, there's an additional problem here outside of the Staffing and like that we don't we we may not have an idea of how to even start securing this problem.
It's the fact that any employee can connect to a SAS application and directly connect just using their basic username and password to anything else that they have access to and so it's nearly impossible for security teams without the correct visibility to secure this problem or even stop the problem because I can go on right now and I can sign up for a free demo or a free staff application for 20 different tools directly connect them to my sales force environment my slack and three other things I think can enable my team and now I think you know, most of the time people are doing this for the right reasons. They're trying to either generate revenue or reduce some type of friction in the business or enable the business in some way but as they do that as you connect, the more more sass applications more data is being exposed. And then again, the security team doesn't even know what's happening because they have no way of actually, you know, discovering that data or even looking at the data.
You're right the road to hell is paved with good intentions. So, but I have an interesting take on this. So part of it is the skills Gap.
I think part of it is during covid. We hired we hired a lot of remote people God knows right a lot a lot of remote people. You know and you hear he's such horror stories about the quiet quitters.
Like people just do the minimum amount of work they got to do. But they're probably only working three or four hours a day or people who have two full-time positions working at home. Right?
And neither the twenty chummed me and you know realize it the bottom line is we don't know our employees. And and everyone else was actually so our Network. anymore, it's not like oh, yeah, that's you know, that's Hillary down the hall or something, right?
We've never seen Hillary from the waist down. So he's not zoom. Oh wait for all we know God, you know.
and so I think that has made a bad situation worse right in that we seem to have less. I don't want to say control but let's insight. Into who who's who are people are right as a CEO.
I'll tell you I like it having people in the office. I think it just functions better. Charlie you disagree I could say I don't know that I disagree I think.
I think when it when it comes down to it, it's we've potentially relaxed because there's this Talent shortage. We've relaxed what our expectations are and High Performance Management isn't necessarily happening anymore the days of these really hyper growth high-paced tech companies holding people accountable and essentially reducting we're doing reductions in their Workforce of low performers and only keeping top performers has essentially went by the wayside. And again, this is just my opinion and what I've seen but it seems that as the case and and now we see these large scale reduction in Force at the at these large tech companies and it may be this we Mass higher during covid.
We didn't know what we were getting or who these people are because we've never actually worked with them more than a few hours and zoom we don't know how many hours they're even putting it. We don't know what their output looks like into something that we see bodies and seats to write code and it may only take them a few hours a day to do this. And so the rest of you we don't care we're getting what we needed out of them.
And so some of this is I think some of it could be the repercussions of that as well. I absolutely think it is. And then the other thing is you know Tyler you headed earlier on is you want to call it Shadow it because that's what we were calling it first, but I don't know if that's still the right name even for it, but I don't mind that I do see.
Teams can't wait around. You know for the proverbial phone to ring. Hey, it's it's Joe over in development.
We just signed up. You know, we got this new tool. We really like we've been using it for a week.
And I think we're gonna go company-wide with it, right? That's not the way it happens anymore. The security team has to kind of be involved and want the development teams.
The devops teams the Ops teams, but that's the teams. The marketing and business teams in the HR teams. What are these people doing?
Where are they going? What apps are they using if we wait for one of these apps to pop up and bite Us in the butt. We deserve what we get.
Right? We've got to be more proactive business the business moves too fast for us to be reactive or just like sit back and Think people are going to tell us things. They don't yeah, I think.
It's it's a hundred percent accurate and and the only way you can start to solve some of this problem with the onboarding of it or Shadow it or Shadow SAS or whatever you want to call it. The thing that we've done over the last few months is we've injected ourselves directly to the procurement process where finance will not cut a check or sign off on a PO unless security and legal have fully reviewed the MSA. We've reviewed the tool we've reviewed the architecture and how it's gonna be implemented.
And so this is just it's very strenuous process and it does take you know manual effort and resources, but it's the only way you can start to kind of suppress this issue a bit. I don't know if suppresses even the right word, but hopefully, you know, make it liveable look you still you got people whipping our credit cards and signing up for this stuff and And the the balance and I you know, I talk a lot about this with people the balance that you got to strike here. Is you don't want to drag the business right?
You don't want to slow the speed of business down, but you don't want to expose the business unnecessary risk. And so there's a balance. Right.
Hey, if you know what security of you're gonna look at everything before we sign on you got 24 hours. If I didn't hear from you in 24 hours, I go forward right we do it. I got a little nothing of a company here, but that's the kind of stuff we do here, right?
You've got you've got a window to object or forever. Hold your peace kind of at a shotgun wedding and and you know, I don't know bigger organizations have a hard time moving at that pace, but that's the pace of business today and it's something we need to you got to find your equilibrium. We're running.
low on time He'll send the in the findings. You want to share. The last big thing that we really had was just that a lot of Security Professionals are assuming that they're going to get breached in the next year.
I don't think that's a particular surprise and based on what we found. It's like that makes sense and that probably will be but yeah, but you know, definitely one of those things that it's like well we know some of the problems that we need to talk on what we need to get our arms around. So hopefully the report kind of helps organizations identify those problems within their you know, within their own organizations and and be able to help them talk with them in the coming year.
You know, it would be interesting take these same set of questions now and go ask non-security people go. Where's the developers the devops? the the system the sres that I forgot what the new thing now is system Architects or whatever not architects.
Infrastructure, whatever go. Ask the other people not security people. And see if they share that level of pessimism because they may just be whistling, you know, happy Daisy here again blue skies, right and and platform Engineers is what I was thinking of.
I apologize, you know, it would be that would be a really interesting contrast. Good stuff. I didn't pay for good Tyler.
I said I think that's exactly what you'll get. I think it's security honestly like the like you couldn't have said it better enabling the business. That's that's really what we're here to do right build guardrails, whether they're devops or platform Engineers so that they can't make mistakes that they do make mistakes security catches it and stops IT and continuation continuation of the development process or if it's employees and making sure that you have the fence in depth to block attacks and block potentially clicking a fishing link to make sure that doesn't happen.
It's really about like enabling the business to work securely and that's on security and there's also an education aspect whether it's you know, working with your developers to understand vulnerabilities in code or whether it's working with all of your employees just to understand fishing and just basic concepts. I think that goes so far because then like we mentioned really you will get those calls from you know, John and devops to say, hey somebody sharing a password in the slack Channel those those things start to happen when you educate the business absolutely everybody wants to do the right thing. At least I fundamentally believe that most people want to do the right thing.
Amen, I hope so. Hey last thing for people who want to get more info on this report and check it out. Where can they go?
org and go to our research section, there will be recent Publications that'll be listed in that hero bar and it'll be right at the top there. The title of the of the report is understanding cloud data security and priorities in 2022. I love it.
All right guys. Thank you. Both Tyler Hillary for coming on And discussing this a little bit with us good work.
Looking forward to more reports and more info to come. We're gonna take a break here on techstruck TV. We'll be back in just a moment.