Ghost Data – Yotam Segev, Cyera
Cyera CEO Yotam Segev explains how “ghost data” has become a major cybersecurity problem.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with jonum Sega who's CEO for Sierra? And we're talking about ghost data and how much there is where it all is and what the implications are from a cybersecurity perspective. You want to welcome the show.
Thank you so much for having me Michael where does all this ghost data come from? It's hard enough to secure the data that we know about but how much more of this data is running around out there that we don't know about. So I think the problem starts with the way we store it.
So we used to thinking about storage as as we think about our garage. It has four walls and you can buy up stuff in there. But at some point it gets food and then you notice that you have too much but the cloud the cloud is not like that it's extensible.
And essentially you can keep on going the garage as you collect more and more stuff. And I think that when we think about ghost data, that's the first thing that we have to understand the change in the world. Essentially the cloud providers are always happy to accommodate more and more accumulation of data in different formats and ways in their services and this allows for a new reality with data can get piled up the continuously with no limit.
Is this data, you know part of the whole notion of end users are just firing up their own applications. And there's all this Shadow it and is this where all this stuff is ultimately coming from and if so, are there means or mechanisms to track it find it secure it can or do I have to you know, just kind of suck it up and hope the best. So first of all means to to find it and secure with and that's part of let's say that does and Baba Mission and to help you keep the data hygiene your Cloud environments at the highest level possible.
I think that what's causing this phenomena is something that's almost human nature. We always like to to keep a little spare. We always like to keep something for any day on the side and when there's no mechanism that comes in and validates that we get rid of that at some point then we just become holders and we hold and we hold and what we're doing insane is having organizations realize this be able to tell the useful things about the things that haven't been used for years.
Nobody's been touching them and they're just sitting around exposing us to whisk and costing us money and helping organizations get rid of them in a way that they can really accept highly we know that nobody's been touching this for years maybe. Time to Say Goodbye how where are people of this issue? I mean, I think you guys have some recent data points on this but is it a big problem little problem or is it a problem?
We just don't know about. So we think that it's a much bigger problem than we have an imagined when we started going down this path and we're saying that 30% of the cloud data plane for many of the organizations. We're walking with just goes data and it's snapshots databases whether the database itself the original database no longer it exists, but the snapshots are still around sometimes I'm injected sometimes in the long regions and this exposes the organization to cost but it also exposes the organization to risk because it goes that tax service and exposes the organization to have someone with this poses that organization to preach risk and these are all things that we did avoid.
Didn't bad guys know about this or they out actively looking for ghost data. Do they have a suspicion in exists? And do they know how to find it?
I don't think the bad guy is the care that much whether that data is ghost or not ghost they care about what's easy to access and what's not being monitored. And the fact of it is that goes data is usually both of those things and it's lying around nobody's monitoring it oftentimes. Nobody's a whale fit and it can easily be manipulated stolen and gifted by a malicious actors or different uses and as we're saying that somewhere Community involve into what what's called that the double extortion right?
I encrypted the data, but I also stole the daytime and I'm trying to use to leverage both of those elements and to extort the the company go State exposes us basically significantly to the second one to the data being stolen. I'm not even aware of it. I find out one day when they when I get an article on there on the Washington Post the my organizations day that's been exposed on Facebook, you know.
the website who's in charge of securing the data these days is the security team or is it supposed to be the people who created the data in the first place? I mean ultimately doesn't somebody have to take responsibility for their own actions as they say. So I think that you hating on one of the most painful topics and the modern Enterprise reality and and it comes from responsibility and accountability, which I'll always the coalitions for many of the things we face as big organizations.
What will hearing from the practitioners is that the security teams the Seesaw office feel that they're responsible to enable the data owners and to take responsibility for the security of the data. So it is a joint collaboration and a joint effort between the business owners and the security teams and what we're trying to do with sayela. Is bridge that Gap create a conversation that's understandable to both parties and enables the democratization of the responsibility of the security responsibility from the security team to the actual business owners data owners, of course organization.
Do you think someday we might be able to apply machine and deep learning algorithms to help solve this problem? What might be the role of AI and all of this in the future? Why someday I think the days today?
Hey, I am machine learning a pretty much mature Technologies. They have a lot of impact on Modern and software Solutions and model software products. And I think that the they have a lot of value to provide us in being able to identify data a lot of value to provide in being able to analyze the normals and anomalous data being stored and enormous access and to daytime different environments.
And this is just the beginning. I think that the ability to prioritize intelligently the ability to correlate between different data and different places in the environment all of these and more things that are available and becoming reality today in one case when DLP was the hardest and biggest term in data security 15 years ago. As we go along do you think that all these data privacy regulations that are starting to emerge is going to force this issue because organizations are being held more accountable for where data is regardless of who created it or whether it's ghost data or not.
Yes, I I believe that and with all my heart and I I add to that I think that privacy relations that we're saying in my mind the tip of the Iceman. The change that I see the change that I see around me is much more fundamental. I think that it's fair to say that the world's outlook on data has changed.
It's not the same outcome and the Privacy regulations are one aspect one means in which a countries or states are trying to push companies commercial organizations to take more responsibility for the data. They're collecting but I think that we're going to see many more aspects and many more facets of this fundamental change about the way people look at that the way people understand the value of data in the way people demand that if you going to be collecting a lot of private personal information about me about my children about my family, you're going to have to take good care of that information what else we have a problem. Well as we do not give him about the way we move forward and I think that the Privacy regulations are the tip of that today, but we're going to see many more data regulations and data the requirements becoming more stringent.
Yeah over the next there you interior point a lot of organizations seem to think that when they collect data that somehow or other they now own that data when in reality perhaps they're just Mira custodians of that data and we need to change our mindset accordingly. Yeah, I think that that's that's one of the the basic changes that the privacy and regulation in the Privacy. Almost I would say syntax side like the way we talk about privacy and brought about and more and more organizations are realizing this that there are custodian and what is their role as in as such?
So yes, I feel that's absolutely right. Yeah, so what's your best advice to folks then go deal with ghost data and this new age of data that we're looking at. Where should they get started?
What do you look at and just makes you shake your head these days. I think that. There is a conception and for a lot of security people the data is an advanced layer of security.
That it's something that you get to once you mature. And I think that that conception is one of the worst things that are happening to organizations today because the reason they feel that way is because there was no easy way to deal with the data in the past but those ways exist today and we should like we would like we said about machine learning AI data science and it'll be all of these Technologies as well as the cloud migration. I'm making the ability to access data understand data and know your data so much more accessible than it was in the past and I think that being open to that change accepting that change trying that change is going to be the greatest things that move security forward and when it was focused around the infrastructure the way it should be focused around data.
No, how do I drive that change? Do I just throw everybody in the room and lock the door until we get agreement or is there somebody else who's taking control are going to be in charge of all this? I think the sea souls are going to remain in charge of this for quite some time and the office of the CEO the privacy officer and have a lot of impact on what the organization needs to achieve, but they're less in the technical controls and the technical operational aspects of the achieving that inside of the organization and I think that joining hands coming together to solve this problem all of the different stakeholders the business and that it security and what we see as the data office the Privacy office joining hands and tackling this together is the way to go to go forward.
You know them thanks for being on the show and sharing your knowledge and insights. Thank you for having me Mike. It was a pleasure.
All right back to you guys in the studio.