Extended Technologies Complete – Gil Hecht, Continuity Software
Continuity joins Dell’s ETC (Extended Technologies Complete), a very exclusive partner program. Continuity is the only vendor that can scan storage networks for vulnerabilities. This is a market that is sure to heat up in the near term, but the barrier to enter is high, hence Dell’s willingness to partner at this level.
Transcript
This is texturing TV. Hey everyone, welcome back here to techstrong TV. Our next guest is Gil Hecht Gill's coming to us from Tel Aviv today and and we welcome him.
Hey Gil. How are you? Not too bad.
Excellent. So Gil you're with continuity software and we were gonna want to hear all about continuity software. But before we do, let's hear all about Gillette.
All right. So it all started many many years ago when I was eight years old. I fell in love with computers fell in love with a Commodore and started programming simply because the you know with Commodore, you know, in order to do anything you had to do programming.
Yeah, and since then that's pretty much my profession it developed over the years, but that's where it all started. So from there I later served as a software developed Bearer for the Israeli Defense Forces after that. They ran research and development for a software security company called Aladdin which ended up being acquired like three times.
And then fast forward a couple of years in 2004. I became a venture capitalists for for a little bit. Joined us earr to VC firm in Israel called Giza and about a year later started continuity.
Really? We're so true. That's right around 2005.
So that's in 2005. Yes. I have been I've been doing it for some time.
Now another overnight success. Yeah, you know. I you people you know my family or people not in the tech industry.
They think oh all these they hear the terms start up. So they think it started yesterday and it sold the day after that for a billion dollars and they're like almost happens this way. Yeah exactly it always happens.
Anyway, that's a great story though. It's it I always say if you do something you love doing you don't you never worry or you know fret going to work you you enjoy going exactly that's great work for day in your life. Exactly.
So Let's talk about it's continuity software continuity. com is the website. Correct, correct?
Let's hear what continuity does. so so continue they actually started I'll give a bit of background but then jump right into it continuity started post 9/11 to help companies deal with the fact that their Disaster Recovery wasn't working properly in their data wasn't protected. Well.
And we created a product initially called recover guard which later was called availability guard which which helped Enterprises mostly to make sure their systems are always available. They never suffer downtime. And they can always recover the data.
We had a great business greater run sold to pretty much every large Financial in the US and in most of the western world and had a very nice success. Went through a couple of things. I'll skip the financial pieces, but around in 2018 or 2019 we bumped into a very large Financial one of the top three in the US.
And they share the story with us. They basically told us that they went through an annual security audit and they failed the annual security audit and they failed because even though they had something called security posture management for absolutely everything they have they didn't have security posture management for storage. They didn't have security posture management for backup and and not for storage networking and storage Management Systems so they came to us.
And and they prepare the spec of what they needed and they came to us and asked us to develop a product for them. And we we obviously said, you know, of course not we are not a service company. We are a software companies so you resisted and rightfully so and then they came with a very big check and said it's really important for us whether you do it for us and when we see larger some large sums of money, we immediately get convinced and do whatever we are told.
So that's exactly what we did. We went and developed. This what to call security posture management for storage and backup for this top three Financial in the US.
It was a very nice success. It took us a couple years to actually make it properly successful. And then when we finished with the project, we kind of set down and started to take great.
If if security risks are such a big deal in storage and backup for this large Financial. Maybe other customers also care about it. So we started to go to other cecils into other storage people and other backup people and all kinds of other companies and started to ask them if if they're doing security posture management today and the answer was always.
Oh, yes, of course, we do security posture management for absolutely everything. And then we asked you know, that's awesome. Where you also doing it for storage for backup for storage management system storage networking.
And the answer was in 90% of the cases no, and in 10% of the cases, it was yes, we wrote a home-grown system. It gets old. It doesn't really work very well.
We're not very happy with it. So fast forward a little bit we decided to bet the farm on this Storage security space. And we started to do our own research.
We wrote the nist guide in in this area. So there is an East guide for Storage security, which was co-authored by our CTO. And we released the product and it's catching amazingly nicely.
So customers need stores security posture management. They are buying Storage security posture management and it became 80% for business. It's actually what a great that's a great story, but you know it also.
And this is something I've learned personally. Fortunately, not the hard way. but so many companies You know, they think of disaster recovery and backup storage.
I sort of a commodity business if you will and they check the box. Right got it. But then when something hits the fan.
and you got to actually use it. You find out that bargain shopping and and what you thought was just a checkbox. Go wind up bringing your whole business down if it doesn't work.
The way it you think it should. Right and then all of a sudden you start cursing well what you know, but hey, you're the one who signed up for it without really. Understanding what a vital why it is so important.
And I I think that's probably one of the biggest and you're much more into it than I am. Obviously, it's what you do for a living, but I think it's one of the biggest. Issues out.
There is you don't know what you have until you need it. And then you find out and that oftentimes that's too late. Yeah, so if you look at the storage security, you know, and so until a few years ago.
Nobody was thinking about it. And and the thinking was you're gonna buy a firewall you're gonna do antivirus on some end points and that's as much security as you need. But then people started to get ransomware attacks and they started to see their data floating all over the Internet and they started to see you know hackers asking them to pay Bitcoins in order to decrypt data the encrypted for them, right and they started to think about this whole area of security and security of data and security of storage.
But what happens is that if you go to most Enterprises today some of the storage arrays that they purchased they brought in. They never even bothered to change the default route credentials. So they still have admin and admin or whatever.
It's going to be. And if you know just a tiny bit about it management and storage, you know, you you'll see that you go on the network. The servers are secured pretty nicely for the last 20 years there have been doing all deeds and improvements and Antivirus and call it whatever you want and they Harden those servers very well and those server store 100% of the data on the storage.
And the storage is available on the same networking. If you know just a little bit of it. You can go to the storage arrays use the default credentials for the vendor login and do as you see feet you can erase all the backups.
You can erase all the storage you can encrypt whatever you want. You can leak whatever you want. You can basically in in a typical Enterprise storage array May support a thousand servers.
So it's not like, you know getting a ransomware attack on a specific server if your storage is hacked you basically lost a thousand servers if all your storage area network is hacked. There is no data in the organization anymore. It's you're done.
Doomsday. It's over. You know I listening to you go.
I think part of the problem is traditionally most security models were like M&M candies and they have them you know, what an M&M candies hard on the outside soft and chewy on the inside. And and that's where Security's been you you mentioned it when you stop the fire. Well, we had that mote and castle where we had to check for a choke point where we could stop people in in folk coming in and out because there was only one way in or out and then the emphasis became abstract.
Everything was about securing the application and the application servers, right and the laughs and all of these things that we did for web applications. But again, that was the shell. The applications are only as good as the data they're running on.
And we didn't we didn't think about the data. So if you did Pierce the Veil, you did pierce the Apple you did Pierce. a server or an endpoint You know, it was run wild and and that's exactly what we saw in ransomware.
A lot of these ransomware attacks once they were in Done, right they had to run to the place. Okay, but we are seeing data security becomes, you know, we're doing a virtual event. I think it's in August on data Ops because I think data security is is part of this whole data Ops thing where we have just got to We got to give data.
It's all about the data stupid. You know what? I mean it that's to paraphrase a political campaign once it's all about the data and if we don't how we handle that data how we secure that data how we move that data because it's all distributed and all you know.
Is critical and as you say if you lose the data go home, you're done. Totally. If you look at most Enterprises today, their first priority in terms of security is being ready for ransomware, which is really if you wish is divided between two pieces right one is making sure that you safe God your system.
So the attackers will not be able to get in. In and encrypt your data the lit your data ruin your data or do something else whatever with your data and we have storage going to help people on the storage font on hardening the storage and backup devices. And then the second line of defense is they would like to know that they are able to recover the data from a safe copy or you can call it an immutable some people call it immutable copy.
Some people call it a safe copy a clean copy or whatever but but you really having in ransomware two lines of Defense one is You want everything to be hardened? Meaning you want to have security posture management and two you want to know for a fact that your data is recoverable. No matter what.
If you have those two lines of Defense covered you're in good shape and your data is safe and sound and you'll be able to recover it in life will be good. If you don't have that nothing else you're doing security matters at all because you'll find yourself. Having no clue.
What's the name of the company worked for? Exactly, but look I and this is again. I've been insecurity twenty three years 24 years.
It's protection and response and you can't put all your eggs in either basket. You've got it. You got it, you know balance that because if you just think I'm just gonna Harden everything to protect it from attack and this way I don't have to worry about response you kidding yourself.
Right, they get away in on the other hand. If you have it all about response and no protection in the Louisville whelm you so so you need you need both of those kind of the end of the egg, right? You need them in balance.
You know what we did mention, you know for people who want to get information about this. How do they how where do they go? So they have a couple of Fortunes.
First of all, it depends if they need a product or a service. So some customers will want to have one time or date of the environment. They should go to their favorite system integrate or and ask them to do a Storage security risk assessment, which essentially is a one-time scan.
You get a report, you know, what's wrong you go and fix it. And if you want to buy a product and basically know that every day when you wake up in the morning that everything is perfect. And if you change anything, it's very fried.
And you always follow vendor best practices industry best practices CVS and whatnot. Then buying the product you can either purchase directly from continuity software. You can purchase from all kinds of Channel Partners around all you can even purchase it from Dell.
So there is selling the product worldwide. That's great and it's available as part of the daily MC product line. That's that's that's a big Channel partner just for you guys.
That's good for you guys gets. Yes. Absolutely.
Hey Gil. I want to thank you for coming on and and talking about this with us. It's important.
It's important for our audience. Very much appreciate it. com for people who want to you know, figure out whether they need the service the product or have you or both and keep up the great work.
I know, you know. It's security if nothing happens. We did our job.
So sometimes it's unthankful, but it's an important job. Yes. Thank you very much Ellen.
All right Gill hack continuity software storage guard here on techstrong TV. We're gonna take a break. We'll be right back.