Increased Focus on Data Security – Yotam Segev, Cyera
Cyera CEO Yotam Segev explains why there is now a much greater focus on data security in the wake of raising $100 million to help finally unify it in an era where cybersecurity has become a top of mind issue.
Transcript
This is Techstrong tv. Hey guys, thanks for the throw. We're here with Yom Sege, who is c e o for Sera.
They just raised a hundred million in funding for data security, and we're gonna jump into not only what they're doing with that, but why is it that maybe we haven't been paying enough attention to data security all this time. Yo, welcome the show. Thank you, Mike.
Thank you for having me. All right. So a hundred million dollars, even today is still a lot of money, and I'm sure after you bought a round of beer for everybody, what's the plan?
What's the strategy and what are you guys thinking about doing here and what will make you different? So I think that when we talk to customers about their data security journeys, what they're trying to achieve in data security and what they want the market to provide them, they're talking about a very siloed and wide problem, right? In order to build a data security program today, you probably have to stitch together tens of different vendors, tens of different workflows in order to make all of that work.
And that's very hard for enterprises to do. Sierra is, has a very big ambitions and is hoping to build many of those capabilities for the customers and to be a one-stop shop for data security Today, how many technologies or products are people trying to stitch together and what does that look like? Because it seems to me you might wind up spending more time stitching stuff together than you actually do spend on data security.
Well, it really depends on the type of enterprise and, uh, how sensitive the data is to them. But I've heard numbers that are as high as 30 products. In order to build a data security program today, I feel at least personally, that we have invested billions, trillions, maybe in network security over the years, and we were all obsessed with the perimeter, and then we shifted to endpoint security, and then maybe we finally came to the conclusion that we can't defend those things.
So now in some ways are we engaged in something that feels like a strategic withdrawal to defend the data more granularly rather than trying to defend the perimeter? So it's funny, Mike, earlier this morning I, I spoke with a CISO and he told me something like, it seems like everybody focuses on data security after they get hit, before they get hit, they don't really realize how important it is. Uh, so, so maybe there's a bit of that in it.
But also when you look at how the world around us is changing, the move to the cloud, the move to platform as a service software as a service models is really making data that the only, the only perimeter the last line of defense. If you don't know what data you have out there and you don't know who can access that data and how that data is being shared, what exactly are you protecting? And I think you kind of touched on the root cause of an issue that nobody seems to want to talk about all that much, but most of the IT people and even the security people have no idea what data has been generated cuz the business users did that and the business users don't share with the IT and the security people.
What's more sensitive data? And so as far as the IT and security people are concerned, all data is roughly equal. So do we need to have a serious conversation about what data is more valuable, what's risk levels, and what to protect when with what resources?
So you are touching on a super important point here, and that's how do we understand our ground jewels? How do we understand what data matters most of our organization? And how do we know where that data lives, how it's supposed to behave and how it's not supposed to behave?
And these are not easy questions. Some organizations are disciplined enough, advanced enough that they were able to answer these questions through internal processes, interviewing the business owners, digging into the applications, and really getting, uh, an amazing inventory of what data they truly care about and where it's supposed and not supposed to live. Ciera can help shortcut that process.
Why? Because we flipped the paradigm on its head. Instead of asking the business what data they care about, having to go deploy a network scanner, connect it to all of the databases, configure the rexs in order to try to find that data, negotiate with the DBAs for a scan time, and then maybe be able to find a bit of data, Sarah is able to show you your entire data plan and enable you to have a, a conversation with your business counterparts with you showing them what they have and ask them, okay, so what's important out of everything we see here, what, what should we really focus on?
What should we really monitor? And that's a very different paradigm to, to walk in. Of course, you cannot walk down the street today without somebody talking to you about how they've invented some AI thing that will solve all our problems.
But it does seem to me that there's a role for AI in all of this because we have algorithms that can crawl across all this data. So do we need some help from the machines? Yeah, I think US AI has been a huge enabler for our technology and also a huge need for our customers.
So first and foremost, we've been leveraging AI and machine learning in our classification engine and in our product from the get go. And that's enabled us to do data classification much more accurately than in the past, much more automatically than in the past, but also to contextualize the data for the customer because just telling you that you have private information there, it's not enough. There are many other things you wanna know about that information.
Is that information identifiable? Is it real information or syn or synthetic information that was generated for test purposes? Is it, does it belong to US citizens or does it belong to European citizens?
Is it data of my employees or data of my customers? All of those questions are, uh, extra dimensions context around the data itself that without that context, it's very hard to make it actionable. It's very hard to take that finding and really do something about it.
And we are leveraging AI and machine learning to be able to understand that context automatically and bring all of that context together for the customer so they can really focus on the action. How much of data security and data management will there be a convergence thereof? Because at least in my experience, a lot of organizations don't really manage data all that well.
And that's part of the reason why we don't know what data is where, and then that leads to all the security issues. So you know, how much of this is two sides of the same problem? So I think they are really intertwined, and I would even add to that, data privacy and data governance, all of them together, uh, have a say, have a claim to the data and have a need around the data.
What we've found is that security is an amazing driver to action, right? Because you know, your house is a mess, it's a problem. But if you think that somebody's gonna be coming in at night and stealing your wallet, that you are gonna do something about it, right?
So security can, can help enterprises take action, can help enterprises, uh, generate enough energy, enough focus to move something forward. And we feel that security can be an enabler for the other needs in the enterprise, like data management, data governance, data privacy, data retention. And we are trying to leverage cera, which is primarily a security product in order to support these other, uh, stakeholders in the organizations and these other initiatives.
And when we have, uh, let's call it, uh, coalition of the willing or coalition of, uh, willing to act, then we are seeing amazing results from enterprises because suddenly you can really fight the, the steep, uh, uh, increase in your cloud bill. You can, uh, have much better compliance by not keeping data that you shouldn't be keeping and also improve the, the, the security of the existing data that you have. Are we on the cusp of some great convergence?
And I ask this because we have seen historically IT operations teams and a lot of them are now managing security operations, but we also have all these governance folks and risk management folks and compliance folks. Are all those roles gonna converge? And is the way we think about managing data gonna change inside these organizations?
Mm, I think that there's still time for that. Uh, many organizations are just getting their, their feet under them just getting started in really turning data into a first class citizen. For many, many years, data was a subsidiary.
It was a subtenant of our applications. Uh, and organizations are making the change to turn it into a first class citizen into a business asset that we're managing, securing and, uh, uh, running the full life cycle for. And that's the change that is happening now.
I do see that it could lead to this convergence down the road, but I think that, uh, my hair will be a lot white by the time we get there. Um, do you think the bad guys are laughing at us because it seems to me they get out of bed in the morning thinking about how to steal the data and we get out of bed in the morning thinking about how to protect, uh, some sort of perimeter abstract that they don't even know exists or care about. So first of all, I think we're all seeing the news, right?
We're all seeing the occurrence of data breaches in a very, very, very, uh, consistent, uh, manner. The biggest organizations in the world that have tremendous cybersecurity budgets are still getting hacked day in and day out, right? Like the results, the reality is, is very clear.
Why is that happening and why is there such a big gap around data security? I think that historically it was very hard, it was just hard to do, and the cloud and AI have given us an opportunity to make it much easier. Do you think that tenor of the conversation between security people and the business folks is changing?
It doesn't seem to me like business folks are ever gonna get cybersecurity lingo, but maybe the security guys are getting better at talking to the business. I think security people are getting much better at talking to the business, and I'm seeing many CISOs conduct themselves and lead organizations as a business unit, uh, with a, uh, with a p and l and with clear business objectives and have a huge impact on the company's overall success. Uh, I see that transformation happening in the industry.
I also think that data is actually an amazing bridge because when you try to explain to a business owner that you have a vulnerability in one of your machines, they don't really know what you're talking about, but when you tell them that our customer data is exposed to the world and anybody can access it, they understand exactly what you're talking about and they can relate to that and understand the business impact that could potentially have. So you've been at this for a while around the block a few times and there's, you know, a little touch of gray in there. But, um, what, uh, do you see people doing today that makes you shake your head and go, folks, we should be better than this?
I think that there's still an attitude in this security industry of I don't want to know if I know I'm liable. And that frustrates me because I think that the industry has matured to a place where we can do things about it. We can really improve the security, and I feel like it's an ethical, moral obligation for each of us in this industry to really strive to secure, right?
We can't fix everything. We can't solve everything that's the way things are. But if we, if we don't have the intention of doing that, I feel like we, we've missed something in, in, in our world, in society at large, And we win this fight.
There's some folks out there who say that, you know, there's certainly nation states and other organizations that have more capabilities than we do, than if they're determined they will steal our data. But on the other hand, there's a lot of routine cyber criminal gangs running around doing things with info stealers or whatever it is. So the question is, is, you know, what is the definition of winning?
First of all, I don't think we have a choice, right? And when there's no choice, uh, the, the outcomes, uh, clear. I think, uh, America has, uh, has worn much more difficult battles, uh, or wars than, than this one.
I think it's not a war that's going anywhere. It's a battle that will continue to be a part of our life, uh, as far as I can see. But we don't have a choice except winning and winning in the sense that keeps our society safe, right?
Data protection, cybersecurity, if these things are not, uh, are not invested in, if we don't get to a place, uh, that's adequate, that the very fundamentals of society trust, uh, starts to crumble. And that's not a world I want to live in. That's not a world I want to raise my children in.
And I think that we have to do everything in our power to make sure we, we don't get there. All right, folks, you're hearing it here. Losing is unacceptable.
So act accordingly. Hey, Yoda, thanks for being on the show. Thank you, Mike.
Thank you for having me. All right. And back to you guys in the studio.