Illumio’s John Kindervag Breaks Down the 2023 Cloud Security Index
Illumio partnered with technology research specialist Vanson Bourne for their 2023 Cloud Security Index, which presents the findings of global research into the current state of cloud security, the impact of cloud breaches, and why traditional cloud security technologies fail to keep organizations secure in the cloud. Using this data, Illumio provided insights on where organizations should focus their efforts to overcome the most common and pressing cloud challenges.
Transcript
This is Textron tv. Hi everyone. Welcome back here to Techron tv.
You know, my next guest, I don't wanna embarrass them, but, um, you know, there are some people that I know in the security world for a really long time, right? And that whole time that I know them, they have been a kind of go-to person, a person that other people in the security world. And I say security, we didn't call it cyber that in the security world that other people looked to and asked.
And, you know, quoted weren't a lot of people we quoted. I look back at the people you know, who came up with me in the early two thousands, late 19 hundreds, and all the way through in, in security. And, and this gentleman's one of them.
I want introduce you to John Kinder bag. John today is the chief evangelist at Lumio. But you know, John, you know John's one of those presidential Medal of Honor kinda winners in in cyber.
I'm gonna let him give his his background for you, and he'll tell us a little bit about Illumio. John, welcome to Tech Drunk tv. It's a pleasure to have you here, Alan.
It's great to be with you again. As you mentioned, we go back a long, long ways. I don't want to date either one of us.
Yeah. Uh, we're both much younger than we look, let me just tell you that. Um, absolutely.
Well, you have more hair than me though, so good for you. Well, but That's a short term thing, let me tell you. Oh, uh, don't I know it, but John, I mean, seriously, I I think most people probably know John Kind, kinder, the industry analyst, right?
For many, many years, uh, with Forrester. And, and, uh, well, what, why don't you, I don't want to you give him your story, John. Yeah.
So, you know, I worked at Forrester for eight and a half years, but before that I was just a, a security guy and a network guy. Uh, but, uh, I'm best known for creating Zero Trust. So I created the Zero Trust model at Forrester.
Uh, wrote the first paper in 2010, uh, after two years of primary research. Back then Forrester was an actual research company, so it was great fun. And, uh, I did eight and a half years there.
And then I went over to Palo Alto Networks for four years as the field CTO Mm-Hmm. And got to travel around the world designing, building, evangelizing, zero trust environments. Then I went over to a Dutch company called OnIt to, uh, figure out how to do Zero Trust as a managed service.
Got that figured out. And then, uh, I got a call from my old friend, Andrew Rubin of Illumio. And if people aren't familiar with Illumio, uh, our company, this company that, that I'm at now has been around for 10 years.
And it's really, uh, turned out to be, you know, one of the primary things I've used to build zero trust environments because it focuses on micro-segmentation technology, but really, uh, adjusting for the purposes of doing zero trust. So we have a zero trust segmentation platform. And I came over here because I wanted to take the Zero Trust narrative back to where it originally began, began what I call authentic zero trust, which is about how do you protect something, right?
I mean, you talked about why do we call it cybersecurity? What's a cyber and why do we protect it? Uh, we, we've even created problems in the naming structures here.
It was better when it was information security. 'cause at least we knew what we were securing, right? Sure.
So I wanted to get back to one of the core tenets of zero trust, which is to create segments in the network to define, protect surfaces so that you, you, you know, what you're protecting. And that's why I came to Illumio, and I'm excited to be here. I'm, I've been here a little over two months and, and it's a great company, great culture, and I'm having a lot of fun.
Absolutely. You know, I, I've been aware, I've actually been out to Illumio's headquarters. The reason I remember was like across the street from where Apple was working on the Apple car at one point.
I don't know if they still are, but I remember peeking in there and trying to see if I could see what Apple was doing around building cars and then went into Illumio. They had just come outta stealth. It was, it was a while ago.
And, um, so I followed them ever since then, you know, and they, they've had an amazing journey. Um, what I love to see those, the maturity of their product, of their go-to market, right? Compared to when I, I was first in, you know, working with them.
I was first kind of exposed to them. John, as part of your work with Illumio, uh, you guys have partnered with, uh, the van and born, right? The technology research specialist, van Andour, and you have something out called the 2023 Cloud Security Index.
Now, correct me if I'm wrong, and I realize you're only there two months, so I don't mean to put you in a bad spot, but the, the cloud security index is something that Illumio has been working on for a few years though, hasn't it? Isn't that been kind of their flagship kinda research or No, You, you caught me on there because, alright. Yeah.
I, I'm pretty sure, I don't know if it was called this, but I do remember over the years, Illumio having some sort of project like this. So Illumio is, is very dedicated to protecting data and assets wherever they lie. So the core, core technology we call it, is for data centers.
And on-premise technology, there's a workstation component. And then we just released our cloud secure, uh, technology. And so we're, we're providing protection, segmented protection of data and assets across every place that you can put data and assets, which are, you know, hybrid clouds, multi clouds, uh, on-premise data centers, private clouds, endpoints.
That's it. And so they've, you know, they've been building this technology for, uh, over a decade. I've been, I've known them and worked with them, you know, when I was at Forrester and kept in touch with them and built out some, some projects with them over time.
And so, uh, the cloud security index is, is this latest set of research is to highlight some of the things that we sometimes don't think about in the cloud. Like how, for example, uh, we find out that that nearly half of all data breaches originated in the cloud. Well, that's a pretty scary statistic, right?
And I know from having been around since the beginning of the cloud, before it was called the cloud, uh, there's maybe a lack of, of security awareness in that, you know, a lot of people think that the cloud provider, the hyperscaler, whatever you want to call it, is going to provide all the security. You're just gonna put your stuff there, it's good to go. I don't have to worry about it.
And that's not true. You are responsible for securing the stuff that you put into the cloud, right? They talk about, uh, the, the shared responsibility model at Forster research, we called it the uneven handshake, right?
Because they are providing significant value in terms of being able to spin up and down workloads in real time, uh, patching the underlying operating system, providing you some tooling that you can hook into. But in terms of responsibility, that's the responsibility of the people who put stuff in the cloud. You know, why it, and it's been the story since day one, when when, when someone comes looking for a throat to choke or a butt to kick, they don't really care what the cloud provider was sharing with you.
Or was, you know, giving you access to it was you are responsible for your data and your applications and your customers, and you could try to blame Amazon, Microsoft, Google, or anyone else you want, but at the end of the day, they're your customers and the buck stops there. So it really is a, an uneven to, to say the least, because beyond hoping that you know, that they're gonna do what they say they're going to do for many, many years, the visibility into what they were doing and how they were doing, it wasn't, let's say, it wasn't optimum right. In, in terms of, of what was happening.
So it's tough. John, I I wanna go back to something you said though, and you said that according to this, uh, latest version of, of this index, more than half of of security breaches are taking place in the cloud. They, when you say, are they originating in the cloud?
'cause my impression is They Yeah. Originating in the cloud. Yeah.
That's the, that was what the respondent said to us. And, and you know, one of the things that's interesting, Alan, about our businesses is that we don't have transparency into what's really happening from a cyber crime or incident perspective like you would in the physical world, right? And so we have to get that data from, from people who aren't necessarily reporting it to the FBI or to the Secret Service or some other, some other, uh, legal entity.
These aren't things that are known in the legal world, but this is things that they're sharing with us about what's happening in the real world that is sometimes obfuscated. So not only do we not have visibility in what's happening in the cloud, we don't often have visibility of the impacts of the cloud, both positive, although I think that's more transparent, but certainly the negative parts of that Agreed. And it, and it, it kind of is what it is.
It's been a, it's just the model we've learned to operate in, unfortunately. Well, I mean, you know, I think I, I think once you've, if you think about it from a perspective of you're just using someone else's hypervisor, that's how I tell people to think about it. And then what would you do to secure any workload on any hypervisor?
That's, that's the question you should ask yourself. And, and I think that, uh, you know, we're seeing 60% of those people that, that responded to the survey say that they think cloud security is, is lacking in their organization, and they consider it a, a pretty significant risk to their business operations. But then we see the con converse of that, where over 70% of, uh, it and security decision makers say that that security slows down their cloud adoption, right?
So now we have this tension in the cloud, and there's a big data breach. I won't talk about it publicly, but I know a lot of things. I mean, I won't mention the name of it, but there was one that happened that was really significant and, uh, everybody was kind of blaming a misconfiguration of the cloud.
You hear that all the time, right? Well, there was a misconfiguration, and in looking at the legal documents and, and doing some deep investigation, I discovered, no, it wasn't a misconfiguration, it was a deliberate configuration where a leader said, no, having security is slowing this down. Let's just give everybody who has, uh, an account in our company access to this everything data set so that we can speed up DevOps.
So this tension, so it wasn't a bug, it was a feature. That's right. Yeah, absolutely.
You know, the old story, but John, this, this is, this is not a new story, unfortunately, right? It, it, it, it happens. And, and look, I'm fresh off of reinvent, right?
You know, this, I spent the last week in reinvent. And here's what amazes me though. I also tell people it's just a hypervisor.
You're responsible for everything above that. Yet we read CrowdStrike has sold a billion, billion with a BA billion dollars worth of product on Amazon marketplace. Uh, if you walk that huge floor of, of reinvent, there were no shortage of security people who are hawking their cloud security solutions when you use AWS and get 'em through the AWS marketplace.
So I, I think though sanity may dictate telling people this, that's not the message that we see on all those Vegas neon flashing boards and everything, right? I I saw a term there, data Security Lake, that wasn't the new one. I heard your Security Lake, one of the Michigan Superior Erie security.
Um, but, you know, well, I think the cloud is a little bit like the data center was in the early 1990s, if you remember that. I mean, you and I go back, I was in that business. I know you were, and we knew each other back then.
So, uh, but uh, if you think about it, we were just trying to figure things out early on and, and maturity was lacking. And, uh, everybody was excited about just setting up these networks and the transport and, and how we could, you know, digitize things and, and make things digitally aware. I mean, I myself was involved in, in some of the early work to turn SCADA into IP enabled, you know, you could control it via the network, and there's a negative consequence to that.
But as a result of, of this, uh, we're, we're seeing that, that people are just moving to the CL cloud quicker than they're thinking about how to secure the cloud. And that's, that's an issue. And they're not under, you know, the, the goal of the cloud is cost savings, right?
1 million. That's a significant amount of money just in the raw cost. And then no one considers the legal and regulatory costs.
Because if you have, uh, if, if some of that data belonged to a citizen of the eu, for example, now you're under E EU, GDPR jurisdiction. And I've got friends who are lawyers in Europe who do nothing but look for those kinds of events so they can file lawsuits and get money. So there's a lot of consequences to not doing security, right?
And when you have the attitude that security's just slowing us down, we heard that in the early days all the time, didn't we? Mm-Hmm. And people finally had to give up and say, yeah, well we have to have security.
And so my goal, you know, coming to Illumio is to show how easy it is to build a a a a zero trust environment in, in clouds or pretty much anywhere, so that we can secure these ways, these uh, environments in ways that are transparent to the end users and then don't, Right. And don't slow us down business. Right.
You know, John, I remember doing a study myself. I dunno if we, I did it here at Techstrong or before I was with techron, but here was the interesting, the soft white underbelly of it. Yes.
They believed, especially developers and the ops folks said, oh yeah, security. The people who say no, they slow us down. Do you want security to let you go faster?
No. I need them to slow us down for a couple of reasons. Number one, it takes the pressure off how quick I gotta deliver this.
I always blame security in essence. But number two, they recognize that they don't want to, no one raises their hand and says, I want to, I wanna have something that's vulnerable, or I want to put out something that's gonna have the Vic make us the victim of a data breach. Right?
And they recognize that security's job is maybe to be the, I forgot what they call the brakes and e in electric cars that return energy to the system, whatever it's called, Right? But security is those brake that, you know, allow a little sanity. And, and, and they know that, but they like to say, security's slowing us down.
You can't have your cake and eat it too. And, and in essence, that's what they do. And, and in the modern regulatory environment and the modern legal environment, you just don't have a choice but to do security.
Yeah. We're seeing the SEC and the Department of Justice get involved in, uh, in things. We've seen, um, criminal complaints against CISOs.
Yep. So The consequences are so much larger than anybody else thinks. And we're so enamored with speed right now.
You know, my joke is that, that DevOps are, those are the Ricky Bobbys of it. They just want to go fast, right? They were shake and bake.
I've got Speed kills, man. Speed kills. Yeah.
But you know, the enlightened DevOps people say two outta three ain't bad, but we need all three. You need speed, you need automation, you need security quality. 'cause you speed by speed without quality.
And in this case, quality being synonymous with security, speed without quality is nothing. It's just, I mean, unless you're, you know, a Ricky Bobby who like wants that adrenaline rush, right? They, they should get an electric car and just, you know, bang it, right?
Sean, we, we got, we got down the, no surprise, we got down the rabbit hole a little bit. What else in this security index report can we share with our, our audience? Well, you know, I think that, uh, what we're seeing with the, the zero trust segmentation platform specifically that, that people are liking is that it gives them confidence in their ability to secure the cloud.
They have visibility into what's going on. Uh, so they, they, they go, oh yeah, I, I can see what's happening in the cloud. I can, I can control it, right?
So that kind of visibility, that kind of confidence and, and validation of the security is something that's been missing from a lot of security technologies that just provide you some data inputs, but you gotta figure out how to operationalize it. Um, we're seeing a lot of people getting real benefits in terms of business continuity, uh, because they can again, see how things are working and, and security helps you understand the system so it doesn't break as often. And then finally, you know, there's a need for cyber resilience in the cloud across the entire cyberspace for every organization.
This is now a board level topic. This isn't just back when, when I started, engineers got to do whatever they wanted to, you know, when I was early on deploying firewalls, I got to not only deploy the firewall and, but decide what the policy is gonna be. Now, if I was in that business, if I was a firewall, um, you know, manager, somebody else would define the policy and there'd be a separation of duties and things like that.
So that stuff hasn't caught up. But it is going to catch up because, because the legal and re legal and regulatory requirements and the, the need for cyber oversight at the board level is gonna change the game force moving forward. No doubt about it.
I, I agree with you, man. Anyway, Hey, John, we're, we're, you know, we're outta time here. These are only 15 minute interviews.
We probably have done 20, but let me ask you for people, or put it out here for people who maybe want to go check out this report and find out more about this. com, but specifically the report is there, is it off the front page of Illumio or where can we get it? We're gonna send you a link that you can provide to all of your listeners.
How would that be? That would be great if you guys could, uh, so folks at home, if you look in the notes on Text Drunk TV here, you'll, you'll see a clickable link for that. com though is the main we, 'cause we didn't mention that earlier.
com John? com. com, you'll probably find something on there as well.
John, I know you're only two months in, but they're lucky to have you there. Um, I'm lucky to be here too, Alan. Yeah, well look, especially in this crazy world we live in these days, but, um, I'm hoping maybe I'll see you at RSA.
I'll be there. Maybe I'll see you at other places too. And I may before that down to Boca.
I lived there, uh, when I first got married, so I, well, any, look, anytime you want to come visit, you're more than welcome. Yeah, you can do these in person. There we go.
That might give me an excuse to go down there and, uh, and hang out on the beach again sometime. Absolutely. com resource center slash cloud dash security dash index dash 2023.
com. You'll find it. And we'll put that link in there.
John, it's always a pleasure to see you, man. Keep doing what you're doing and I'll be in touch. Thanks for joining us.
Thank you so much for having me. Alrighty. John Kinderg, father of Zero Trust.
I know you hate that. Um, but he's chief evangelist at Illumio. Now go check out some of the great work he's doing there as well as our friends at Illumio.
We're gonna take a break on Text Drunk tv. We'll be back in a moment.