Data Security Posture Management with Imperva’s Terry Ray
Terry Ray focuses on data security risk prioritization and the evolution of data security posture management (DSPM). Terry Ray, data security CTO and Imperva Fellow, emphasizes the need for organizations to move beyond compliance-driven security to comprehensive data protection. He highlights the importance of understanding and addressing the entire enterprise’s risk, including both cloud and on-premises systems. Terry explains that DSPM tools now provide quantifiable metrics to assess and reduce risk, enabling CISOs to build a compelling case for increased security investments. He also discusses the consolidation of posture management tools into comprehensive data security platforms.
Transcript
This is Textron tv. Welcome everybody. We're having a great conversation today with Terry Ray.
Terry is data security, CTO and Imperva fellow at Imperva, who's now a thas company a while back that changed. Welcome, Terry. It's gonna be talking with you again.
Thanks. Thanks for having me here, Mitch? Yeah.
In Imperva fellow. I don't remember that part. Maybe you were Imperva fellow before, but congratulations.
Either way, tell us about you, your kind of background and, and what you're working on at Perva. Well, you know, I, so I live in Texas and sometimes they just call me an Imperva fellow. Not a fellow does cement or cement, right?
Uh, yeah, no, no. But you know, my, uh, you know, now, as, as you noted, Imperva is a Tallis company now, the, the acquisition closed, uh, earlier this year. And, uh, so my new role really is about looking at the, the strategy of data security, where the, the, the, the Cyrus suite, the imperious suite, how they come together, how they mix together, and, and all the interesting synergies that come from that.
And then of course, spending my time, uh, talking about the value and the reason why organizations should be doing data security today in, uh, in these types of conversations here. And certainly on the road all the time. You know, it, uh, oftentimes we talk about data protection, but data security is a much bigger topic.
And that's part of why we're talking about is we have so much data everywhere, right? It's proliferating everywhere. Applications are generating data we don't even know about half the time.
It's, it's hard to, to get our arms around it, more or less talk about the security of it. So maybe, maybe the best place to start is what is the start? How do you get going?
I mean, we probably already have tools that can help us do at least a good part of this job. Maybe most of it. Yeah.
I mean, you're, you're right. I mean, we, this, this whole industry forever has been called data security. Data security is a gigantic umbrella conduct.
If you were to say network security, what's part of network security? That's a lot of different technologies. And the same thing is true here in data security under that umbrella.
And, and I'm gonna leave out, other people could add more things to it for sure. But in my world of data security, as you said, data protection is one of those items. Data compliance is another one of those items.
Even data classification and, and other pieces that fall underneath. There are all part and parcel of this umbrella of data security. We just kinda lump it all together.
And I think organizations traditionally have begun in one of those areas. We see it all the time where someone has a driver of compliance. Well, it depends on which compliance as to where they begin.
If their compliance that starts their journey in this is, is, uh, a privacy A-G-D-P-R-A-C-P-R-A or something else. And in that case, probably they're gonna begin with the, the identification and classification of where do they have private data so that they can answer a data subject access request. If privacy is not their thing, if it's public, you know, payment card industry, PCI or something else, then likely they're gonna say, well, I still need to find my data, but I know I need to protect, protect becomes an important aspect here.
I need to encrypt my credit cards and make sure they're protected. The point is, is the journey that people begin in data security for most organizations began in 2003, 2004, or, or even a little bit before with the advent of PCI and hipaa. And some of these, uh, others as their version ones kind of came out.
And so you see a lot of organizations today that their journey began with compliance. And I think a big part of maybe what we talk about today is why are, why is their, why did their journey begin with compliance and why is that still the only thing that they do? Well, let, let's go there.
I, I mean, truly regulatory actions or, or consequences, um, that also show up in contracts, right? There's sort of long, long technicals to the compliance side of it. So sometimes that does prompt us to take action, you know, we need to classify data, get the, get the house in order.
But to your point, point, there's a lot more other things to do. So maybe even if you start a compliance, where is the next logical step? How do you, how do you kind of tackle the bigger problem for all the parts you talked about?
Yeah, no, I, I, I, I see this as, as I'm, I'm here in my, in my home office, right? When we build a house, we build the front door because we know people are gonna come to our house and visit us. Uh, we don't think windows are optional.
We have windows. And so we need to make sure we have them there. And I think security is, has moved away from the perimeter, really.
But still, there's, there's the blocking and tackling of security in every other aspect of security, network security, endpoint security and everything else. We wouldn't say that I have five networks, but the most important network is network A. I'm not gonna worry about networks B, C, D, and E because, you know, they're not the most important network.
I'm just gonna leave them open. We wouldn't do that. And the same thing is true of, of antivirus or anti-malware and anti ransomware tools, these sorts of things.
I wouldn't say that I'm only gonna put them on Terry's laptop because he clicks links like nobody's business. We're gonna put them on everybody's laptop 'cause I don't trust anybody not to click a link. But in data security, we come to this world where we say, for data security, I'm just gonna put my controls on my PCI server, because that's where I was told to put my controls.
The world of data security is one where someone recognizes for some way, somehow they say, you know what? I could do better. I should be doing better.
And I recognize, I admit that I've got SharePoint, I've got OneDrive, I've got all of these other places where my data is located, where there aren't any credit cards. But shouldn't I be watching what's going on there? I mean, what else could somebody steal outta my network that's more important than the data in my network, yet maybe I don't have controls there.
And it's not even a, maybe most organizations just don't have controls around their data as broadly as they do around their network and their endpoints. Well, you mentioned malware. Uh, certainly ransomware is going after data, right?
I mean, so so much of our attack surface is going up at, at the data, trying to get to that data, whether it's for ransomware or other things. It, it, you know, I don't hear that nearly as often the term ransomware. I think we've sort of got a little bit, a little bit, uh, immune to it.
But is that a big driver or stepping outta the bounds of just protecting my credit card data or my healthcare data? It, it tends not to be, uh, well, lemme put it this way. Uh, ransomware tends to focus on file servers and file servers already.
The, the primary driver for protecting files is actually security. It's not regulation. It's this weird, you know, uh, split industry of, if I have structured data databases and I have files, servers and the cloud are OnPrem, interestingly, they're very different worlds.
And the drivers behind security for each of those worlds is actually, uh, opposite, diametrically opposed whatever. But in file servers, the reason people monitor and quote protect file servers is because they recognize that there is insecurity there. Ransomware is a big driver.
We may not hear it as much, to your point, we get desensitized to it. There were some big ones recently. Um, but it's security.
But as soon as you shift to the world that honestly, most security people, most security experts don't have as much experience in the databases, all of a sudden security takes a second seat and compliance becomes the primary driver just to do what you have to with compliance. And I think the big factor here is, is from a, from both a file server perspective, but more so even from a database pers perspective, the world is changing a little bit to where people are beginning to ask questions of themselves and, and their executives are asking questions, why is it that I can be compliant and still be breached? That doesn't make sense to me.
Why, if I'm compliant, am I not doing all the right things? And that's a big question that people are trying to answer. Yeah.
How much more is needed? What's the gap? How far do I have to take it?
You raise an interesting point too, of i, is it a knowledge understanding gap of why we don't take those further steps of how to secure data better if it's in a structured medium, like a database, um, is it just a training education or is it a tools problem? How, how do you tackle this? If you, if you ask a a, I'm just gonna say a, a security expert, if you ask a security expert, expert is one of your primary objectives, the protection of data, is data security important to you?
Their answer is almost always, almost always a hundred percent, yes, it is. Okay. So is a strategy of yours to monitor and protect all of your data, and you'll get a mixed, mixed response.
Most of the time you'll say, well, that's a strategy, but in reality, I don't have the budget, I don't have the staff, I don't have the skills. There's a bunch of different reasons. They'll, they'll keep on making reasons for it, and they're valid reasons as to why I can only do a little bit of this work.
I can't do a lot. And so there's, there's always these reasons and it's, it's actually created a new industry that's bubbled up over the last three or four years, um, that I think is trying to help answer this question for them and give them finally some tools at their fingertips that they can take and say, okay, quantifiably, I don't have to have my eyes open. I don't need to be looking somewhere else.
There is, there are systems that are telling me I'm not doing a good job, or I am doing a good job, and if I'm not doing a good job, what should I be doing to get better? So say a little bit more about this coming together as kind of focusing on this problem. How is that helping it get better?
So being able to focus on the problem. I mean, fir first off, it was hard. I, I think it took too long for us to recognize that the problem is a lack of, of just awareness of the current status of the environment.
That, that if, if we, if we, if we boil it down to distill it down to what is the problem, the problem is that the people that are in charge, or the people that are responsible, more importantly for data security, those people traditionally had no quantifiable metrics to tell them are they being, are, are they doing a good job or not? The only metric that they had to go by a true quantifiable annual usually metric was did I pass my audit? Right.
That, that's guaranteed to happen. Someone's going to give you a thumbs up and that person's supposed to be an expert and say, you did a good job. Well, I think over the years, that got to be the, create this feeling of, well, if the auditor's telling me I do a good job, I must be doing a good job.
And the reality is, is with these, these new technologies, so these technologies are called Data Security, posture Management, DSPM, at the end of the day, this is just about being able to build a map of organizational risk in a way that the data security experts can, can answer that question, am I doing a good job? Well, for the whole organization, you get a score, and the score could be good or bad. I mean, it's, there's some numbers and things involved in it, but it could be good or bad.
And you can see a trend line if you're getting better, are you getting more risky or are you getting less risky based on the work that you're doing? At the end of the day when a, a security person comes in, or security team comes in and they talk to, uh, their leadership or their leadership says, what are we doing over the next quarter? They want to be able to give them an answer back and say, here are the things we're going to do over the next 90 days and over the next 90 days, the outcome of that should be, we should reduce our risk a certain amount, and we're gonna do that again next quarter, and we're gonna do that in next quarter.
And I can now have a predictable model of where my risk is going to be. And the expectation is that it's going down based on the work that we're doing before you had the ability to model risk in this way and the configuration of your, your security assets and the tools that you have and the configurations in your, your databases and all of this. Before you could do all of that, imagine what you might have at your fingertips.
You go in and say, well, what we wanna do is we wanna buy some new products, we want to install them, put them in a few places. But there's no metric to tell you, is it, is it being successful? Is it not successful?
Did you do it right? Did you do it wrong? And that's what the power is here, is to be able to finally put a quantifiable model together to where you simply can say, yes, you have five things you can do over the next three weeks, four weeks, whatever it is.
And if you do these things, your risk is gonna go down. And then you do those five, three or four things, you'll give you five more to do. And we can keep on reducing that risk.
You'll never get to zero because you're on the internet. This is the world we live in, but we can get that down to an acceptable risk. Interesting.
You know what, part of what you're saying also, I think, tell me if I've got this right, is security people know about risk management, security people know about posture management. We just haven't been applying that comprehensively to our data. So half of this, we know how to do this in other domains, we just need to apply it here.
Now, what are the specific steps that help us bring those, that security risk down, increase our posture in terms of security around our data, where our biggest threats, et cetera. So that part of it, we don't, we know how we've gone through that before. That's, that's something we can apply.
We just need to know how to apply it. Am I on track here? You are.
You are. And I think when, when you look at the, the, the, this new industry of posture management, and I say new, but you know, three or four years or so, but this, this new industry of posture management, there's cloud security, posture management, the whizzes of the world and those sorts of things. And this data security posture management is really kind of part and parcel of of of that.
I mean, it's, it's just looking at the configuration. And even those kinds of companies that were born in the cloud, they're gonna do the same thing for the cloud. What we're finding is a lot of organizations will, I mean, there, there are the organizations that have, have been created over the last decade, and they may only have stuff in the cloud and that's fine.
But the overwhelming majority of organizations have a pretty good mix of legacy systems that are still, I call 'em legacy, but they're still buying more mainframe. It's not legacy. They could have bought one last week and it just installed it.
They've just been trying to get off of it for 30 years as much as anything, right? They're running a lot of the business still buying more, but it's still there. So all of that, that, that on-prem technology, if you will, has to be part of that risk.
When you have a bad actor that comes in, they're not deciding, I'm only gonna go after cloud. There just tends to be a lot of misconfigurations in the cloud. 'cause people don't know that.
Some no know it as well as they do on-Prem. But when you build a risk model, that model has to take into account the entire enterprise, all aspects of the enterprise. And that's what we're seeing now is we see a lot of posture management solutions that spend a lot of time focusing in the cloud because the cloud is pretty easy.
You, you can download the configuration, you can download everything and everything goes in. And that makes it pretty simple. It's when you start to make that shift and say, my risk is more than the cloud.
My risk is cloud and on-prem. How do I make that equation to, to find that intersection between these two and build a risk model to include on-prem and cloud. And then more importantly, when we look at posture management solutions, nine outta 10 of them, if not more, will say, I'm gonna tell you where your problems are.
And if your solution is just a flip of a switch, I'll tell you how to do that. And I might even do that for you. If you want me to, I'll flip a switch for you in AWS or Azure.
But if your problem is that you're, you're not monitoring any of the activity going into a database, you have no visibility, well, you can go collect logs, but you need to put them somewhere. You have to do something with them. Most posture management solutions don't in fact actually have a solution.
Their posture management information tools, they're gonna tell you what you need to go do to solve your problem, but then you need to go and figure out the tools you need to buy to solve that problem. And the analogy that I like to use is, I've got a garage full of tools and you're telling me I need to go buy two more tools, or you're telling me I need to get better at the tools that I already have and all of that's fine. But right now the majority of posture management is exactly that.
It is, let me tell you what you need to go do, but I'm not the one that's gonna solve your problem for you. You need to either go buy or use other products. What we're seeing in this space now is a little bit of a consolidation where those posture management tools, if you will, are being consumed by platforms, data security platforms.
And those platforms might be for files, they might be for databases that might be for both. And now those platforms typically will have that capacity to say, I can tell you what you have wrong in your environment or how you could get better. And because I'm a platform, I have either the tools readily available for you, just go turn this on, turn that on, do these other things, or I have an ecosystem of partners that we can plug right into the system and here's your plugin and go get this done.
And I think that's how we're seeing this market start to consolidate a bit to where data security, posture management, which was its own little area for the last four years, is now being kind of spread apart and it's becoming really a feature, a required feature, an important feature in data security platforms. It's interesting, I spend a lot of time also in the software creation world and very much the same things happening there, right? Things are moving to platforms where the data that's used across workflows and things like that are consuming data to help you in that process are integrated in away from a model to get access to it and leverage it, but also integration of tools and workflows and things like that.
It sounds like very much the same thing around data security, posture management. I like your analogy or not, and not your description of is posture management. That assessment part of it is what I call mm-Hmm.
Is, is a feature of part of the overall process. I don't want to, I don't wanna get a report. It's like doing a penetration test and here's all the faults with your network, but not knowing what to do about it other than some, maybe some basic what about the things that are harder, but, uh, endpoint production, what do I do for that?
Or what do I do for, you know, data in the data places as you're talking about. So that's much more of a comprehensive platform approach, if I've got what you're saying. Yeah, no, for, for sure.
And I think, you know, we, we began this conversation about where do people begin, right? And, and like I said, people begin around compliance and from from my world, while I really am happy to finally have a quantifiable model for what can you do today to get better at data security, the other value there, the other, the other important factor I think of just having this model is now as a ciso, a good ciso, I think a good CISO is the one who, who has been saying for years, but maybe hasn't gotten any traction, has been saying to his executive staff, we are meeting compliance, but I'm telling you guys we need to do more around security. Please give me budget and people so we can do more.
Because I know my phone is gonna be the phone that rings when there's a breach. Even if that breach isn't on my compliance servers. I know that there are CISO out there that have been saying this and yelling this from the rooftops, but haven't had proof to be able to hand over to it.
And I think this is one of those elements of two of, of, of truth where now finally the CISO has some discovery, some valuable information that they can take and they can say, look, I've got a hundred servers, I 10 of them, I'm doing everything we're supposed to do. And these have very low risk on them, and we're not at risk of non-compliance. We are, we, we passed our audit on those 10 servers because they're the only 10 that our auditors look at.
However, I just want to be super clear to all the executive staff, there are 90 other servers in this environment that have no monitoring, no cryptography, no threat detection, and their risk is astronomical. I can, it's calculated. It's right here, front and center, they're all bright red, we're doing nothing for them.
And you might say, well, why aren't we doing anything for them? And the answer is, is it takes time. It does take some money, probably takes some people.
But if we want to be in business, these 90 servers serve our business. If we want to do business, this is the cost of doing business. So as an executive staff, do we all agree that our strategy is a compliance strategy, which is what we have today?
Or do we wanna go through a maturity and begin the journey of having a data security strategy? And this finally gives them some ammunition to go back to that executive staff and say, here's what we need to do, here's what we need to get. If we need to get anything.
And in, in, in three months time, in six months time, I'm gonna come back to you and I'm gonna show you how we've reduced this risk and we'll continue that journey until it's on down. Do we all agree? And finally, I think you'll be able to get some buy-in and they can move the needle on data security and it's quantifiable.
I can show you demonstrating where we were, where we are today because of these steps that we took. That's right. It's not just more money poured into it, we think we're doing better.
Yeah, I mean, it, it, it can, I, I get it from an executive. I, I remember once I was in our executive staff and our CISO came to us and said, guys, we're a seven. And we're like, what does that mean?
They know what that means. Help me out here. Right?
And so even, even back then, and this was seven or eight years ago, they had some capacity to, to build some kind of a metric, but they didn't have the context around it to talk about the difference between compliance and regulation and, and security and all this. And bringing all of that context in allows them to really have an effective story that, you know, I'm, I'm excited about. And I think it's something that, that's whole industry.
'cause we're not the only ones. There are other, other technologies, but fact is, is this industry is growing rapidly and I can only see that this technology finally is going to, um, accelerate that process of the companies that I've worked with for the last 21 years at this point. Finally, we'll start that, that move from compliance to security.
Very nice. Well, tell us a little bit, how can folks get ahold of you or get ahold of the right person at, at Imperva to help them understand how to take these next steps and, yeah. No, I mean, so, so as, as part of tlu now, you can certainly go to, to Tali and, and, and find the perva in in that portfolio.
com still exists. com. We've got all the appropriate information there and everything that you could have there, um, always reach out to us, uh, if you've got those questions, we put out lots of videos like this, uh, lots of information, lots of, uh, uh, data, data portfolio of, uh, of different documents and things and white papers.
We're constantly trying to be a thought leadership organization, share what we learn as we learn it with everyone. So, you know, join our feeds, look at our blogs, all of the, all the standard stuff is certainly there. com is a great place to go.
And the good thing is we're talking about this and there's hope you, you, you have some ability to move forward now. Maybe, maybe all that, you know, waving hands and screaming and you know, we need to do something now, we can do something about it. Merry Christmas.
Hey, and active thanks. But alright Terry, it's been fantastic talking with you and, uh, we hope folks will, will definitely check out Infa, you know, they work with very large financial organizations, enterprises, et cetera. So, you know, we're talking about folks that know what they're doing.
Thanks, we'll talk again soon.