Expanded Attack Surface Management – Marc Gaffan, IONIX
Threat actors set on penetrating an organization don’t care whether they’re attacking internet-facing assets directly or exploiting a vulnerability from an exposed third-party digital service. On March 21, Cyberpion announced its new name and expanded attack surface management functionality that discovers more organizational assets than any other provider and helps organizations dramatically improve their security posture.
Transcript
This is texturing TV. Hi everyone, welcome back to techstrung TV. I am really happy to introduce you all to Mark Gaffin.
And you know, we were talking off camera. Mark reminded me that we had met. I don't know 15 years ago 10 years a long time ago at a previous company.
He was responsible for and you know, that's the great thing about this security or cyber security Community we all live and it's it's six degrees of separation. And we you get to really meet people. Hey more so let me into introduce you to him and welcome to text drug TV, Mark.
Welcome. Thank you for being here. Thanks elements great to be on the program today.
I appreciate you coming on. So Mark, you know what? I I said a little bit but why don't you give people a little bit of your background?
Absolutely. So I I started my my career as a techie. I actually wrote code for a bunch of years.
I study computer science. I need to realize later on that. I actually enjoyed selling more than I enjoyed building.
I like building but and then in 2005 I got Pulled into a cybersecurity company. That was my first cyber security gig a company called sciota that got acquired by RSA two years later. I spent a couple of years years at RSA and after that I found that a company called encapsula, which was a cloud-based application delivery.
I competitor to cloudflare and Akamai we ran that for all Six years, we've got applied by imperva. We took that business too from 0 to about 100 million dollars in air or so, really really big outcome there. And as you said I've been in this cyber security space since 2005 you say that there's six degrees of separation.
I actually think that they are six orthogonal paths between two people in the cyber security space you can get to people in six different ways totally unrelated to each other. That's how small the spaces or how tightly not this ecosystem is. I agree with you 100% you know, it really is I with RSA coming up here in a couple weeks, you know, it's traditionally where I get to see a lot.
Well there in Black I get to see a lot of my my cyber friends and really looking forward to it. I'm actually just announced we'll be doing the security bloggers meet up there again Wednesday night, but Anyway Market it really is and it's good to have you on. So ionics talk to me what tell us or not just to me talk to our audience.
What give us a little bit of the ionic story? Ionics is a new name. Actually that we unveiled about a week ago on Tuesday last week and ionics is the new brand for a company that was founded just have a five years ago by the name of cyber pione.
The company was founded before. Before a tax surface management or external attack surface management was even a category that was coined. It was founded by our founder and Nathaniel who was a hacker who let's look at companies from the outside the same way as an attacker would find all the things that attacker would and then obviously bring them to the the company so that they can stay one step ahead of the attacker the company operated as I said for about five years VC standard.
We are 60 people strong today. Most of our R&D has done in Israel. We have a Presidency in the US as well with our sales and marketing team.
And as I mentioned last week is when we announced the Rebrand of cyber client to ionics ionics fanatically is pronounced I on X. So keep your eye on X or keep your eye on what's important and it's a cool name. That would be the the word ionics but also have and has a meaning to it which always helps us, you know, give some substance to the the, you know, the selection of why we went down that that really crystallizes what we're trying to to do in the market and how we want to help customers.
It's all about in our opinion understanding your Through attack surface and we'll talk about your true or your real Attack surface. But on the other hand also making sure that we can focus on what's important. We realize our customers are telling us we can't do everything we can't get to every single vulnerability.
We can't deal with every single issue help us prioritize what's important so that we can deal with the most important and urgent things first so we can make the most of the resources that we have and that's really what ionics tries to help customers work. What we do is we discover your entire attack surface typically from the outside in the way an attacker would be literally scan and find all the assets of an organization that an attacker would see if they are trying to to talk at the the organization and what we do after we find all the the assets as we look for vulnerabilities or things that attacker would exploit. These could be misconfiguration posture issues.
Vulnerabilities in the in the infrastructure in order to essentially be proactive Point things out to our customers in a way that's easy for them to consume. And I would say that what really makes us special are two things. One is the way we look at an organization's attack surface.
Typically, the the definition of an attack surface management platform today is help me find the assets that we own and control but fall in between the cracks. These have been spun up by Teams within the organization without them truly being sanctioned. It could be a provider that we've used he's gonna be assets that we've forgotten these could be as a result of our migration to the cloud.
We've got a bunch of Assets in a data center that were that up and running. We acquired two or three companies and as we brought things into the fold, we didn't really take a you know, take account for all the assets. You've got lots of assets that we don't know about an attack.
We could find them. They Foster could be very very challenging and therefore that's the way an attacker would find their way. That's what traditional I'd say.
Oh classic attacks up as manage. It is help me find the efforts that I own and control and understand my posture there. We've taken this to her to a different extent essentially by not just looking at the assets that you own and control but looking at what we call your entire digital supply chain.
So these are all the assets and infrastructure that you don't own and you don't control those you're Reliant. These are service providers that you use. These are all your DNS Services.
These are web services that you include these could be third-party mail servers that you use. They're all part of your attack surface from an attacker's perspective. And what we are doing is not just looking at the assets again that you own and control but looking at their dependencies and they're dependencies in a recursive Manner and if we find across those theoretical attacks a vulnerability that can be used and then better kill chain back into your environment.
Those are the things that are interesting and those are the things that we will push to out to our customers in order for them to try and and remedy as quickly as possible. What makes us all possible is also underlying technology, which we've coined now as part of this Rebrand, we've called this connective intelligence. And what this means is that when we look at your attack surface, we don't just look at an inventory of assets that you own and look at them discreetly or one by one.
We actually understand the connections between we understand that a website is reliant on a DNS server that's reliant on an interest piece of infrastructure. Maybe on the third party and a website could be including a script from a certain third party website that could be actually pulling the code from an S3 bucket or an Azure blog understanding those connections actually helps us understand the risk in context because if you just look at the asset itself, it could be it could have really good posture itself. It could be patched and therefore you think you're in good shape, but it's connected to a vulnerable asset if that vulnerable asset that you're connected to all you're reliant on is breached the blast radius of that.
Spools over to you as well. And therefore it's really important to be able to understand the connection between the assets to be able to really understand the risk that they are able to eat that they potentially introduce. As a result of of being vulnerable.
This is really what sets us to parking away. We look at the attack surface or the way, we look at the assets that belong to an organization or an organization relies on. That's fascinated Mark.
That's great stuff, you know. Look, I'm sure we'll hear it at RSA this year. Everybody talks about software supply chain security, right?
Where'd you get because I was software is Frankenstein made up of many components and those components have dependencies and this one got pulled from a repo and that one. You know, it's a container somewhere else and and all of these things. This is the it's not it's important for people to realize it's not just our software.
That has these supply chain potential weaknesses. Let's call them. our infrastructure Allen I'd say even more than that not every organization builds software.
So if you're a software building organization you after absolutely need to take care of your software supply chain, but they're more organizations that actually don't build their own software, but they have infrastructure. They have a digital supply chain that they are reliant on even more because they don't build things themselves. In fact, I would say that the in our view the digital supply chain is actually the bulk of the attack surface of tomorrow because the more and more modern applications and systems that we build today are more reliant on these third parties the the in order to build quickly today or to get a market quickly today within you application you want to build as little as much as possible yourself, right you more through microservices and apis and and other types of infrastructure therefore the Reliance on the digital supply chain is only going to get bigger and that's when things start getting complicated.
Absolutely. It doesn't look we've seen the rise of API security API security is a big thing. We were talking about our history in many places.
API is kind of the new wife if you will, right? It's it's just you know, it's that's the but. It goes back to why I first got into devops, right?
This is the way we do Tech today. This is the compute of today and it demands different ways of looking at our security of what security is what it is. We secure and these other things so I I agree with you 100% right we need to be All over this all over it and you know, just what what one of the biggest things we're hearing from from customers is that they feel that the goalpost has moved in terms of their problem used to be this is my infrastructure.
There's a scope project here. Please tell me what's what's wrong with it to hey, I don't even know where my infrastructure is today or what constitutes my digital supply chain on my channel is the edges of my infrastructure. There is no border.
That's you know what I mean first help me figure out act and then let's look at actually what's you know, what the the challenge of the biggest problem today is? Let me understand the scope of my tax service. Absolutely.
I love it Mark. We we went a little over time. io?
What is it? io. I love it Mark.
It's first of all, it's great reconnecting with you. Second of all best of luck with ionics. We you know, this is this is a real problem.
I'd love to have you back on and we can maybe spend some time digging in a bit, or maybe we'll see you in our same maybe we can do a stream there. That's okay. I'd love to do that.
Love to see you in person again. Absolutely. All right.
Check it out. I O N I X that IO we're gonna take a break. We'll be right back.