Insights on Cloud Data Security Posture Management – Matt DiAntonio, Immuta
Matt DiAntonio, VP of Product Management at Immuta joins Mike Rothman to discuss the current state of Data Security Posture Management and why tracking data usage should be a priority for organizations embracing the cloud. They also discuss the pros/cons of extending CSPM to focus on data and how to provide coverage across all cloud platforms.
Transcript
This is Textron TV. Hi everybody, Mike Rothman here Chief strategy officer of tech strong group with another tech strong TV interview. I'm really excited to be joined today by Matt.
D'antonio. He is VP of product management at immuta Matt. How are you doing today?
I'm doing great. Thanks for having me. All right good.
So we're gonna talk a little bit about kind of data security and you know kind of how that whole market and and opportunity is really evolving. But before we kind of dive into that, I want you to introduce yourself for a sec to the folks on the show listening to the show and what background a little bit really a little bit about immutas and we never make assumptions that folks know you know who were talking about when we bring on guests to the show. Absolutely.
That sounds great. So hey everybody. I'm at the Antonio.
I'm the vice president of the product over at amuta been with the company for roughly three years at this point in time. My background is one that is a rich in data platforms. Been enabled the partner with some really exciting companies in the early days of my career.
I worked with Trend Micro and more of a traditional cybersecurity background. A muta is was born in 2015. It was born really under the the mission to be able to build the best data access point solution in the market and we've grown into becoming what I think of as an emerging leader in the data security space we partner with the US government.
We have Enterprise customers some of the large complex organizations in the private and public sector really excited about what we're doing to help companies enable the creation value in their data. It's very fulfilling Mission. Yeah.
No, that's great. And you know being a guys don't security for 30 something years and Cloud for the last, you know 10 to All it's really been interesting to see folks kind of go through this logical progression, which is oh we're moving stuff to Cloud. We really should start thinking about how we can figure, you know, this kind of environment and making sure that again we're not opening up stuff to you know, kind of the great on washed and you know that we've got the right policies in place and tracking that especially as you get more agile and increase the velocity changes happen all the time in humans, you know kind of make mistakes.
So we need to track that and then we started to get towards this SAS thing, right? Everybody's using sass. You know, we got all you know.
Oh did anybody think about the fact that we're configuring this stuff? And this is some of the most valuable information in our environment that's in Microsoft 365. It's Salesforce and work day and service now and a bunch of these other, you know big ones.
So, all right, let's you know have a little widget that's gonna you know, help us make sure that our posture is is, you know, kind of strong from the standpoint of our sass environment and now it seem Early in 2023 everybody's focusing, you know kind of there there, you know eyes on data, right? You know, so you're gonna start here in the term data security posture management. I would suspect that'll be a big one when we get to RSA in a couple of months as folks start to realize.
Oh my God, I got all these storage buckets and I got all these, you know kind of data, you know pass services and I've got you know kind of these other Cloud native infrastructure where I've got all my stuff in how do I keep contact? I'm tracking that right? How do I make sure that I've got the right, you know kind of policies in place to restrict access to this stuff.
How do I track whether it's being actual traded? So I would guess that's kind of the general problem that that you know, you guys are solving with with the muted detect but I'm pretty sure you didn't get there because you dealt with cloud and then you dealt with SATs and now you're like, oh they just kind of interesting. So how do we do that a little bit about you know, kind of how you guys got to the point where you realize data security and data security posture management.
Or something you wanted to focus on. Yeah. Yeah, it's been a it's been a really exciting Journey for us.
We had started working with these large complex Enterprises who had this Dynamic happening over and over inside of their environments where the data consumers were really putting an incredible amount of pressure on those data platform teams who are sitting in the crosshairs. They need to be able to move fast to be able to create value from the Strategic data in the organization. And we see this phenomenon that's happening where the older technologies that were that were present where you know centralized it was Well pretty well locked down by traditional security, but it was slow.
It was slow to get access. It was low to be able to to do all the things that the data teams needed to do. So the data teams start taking it upon themselves to use this new technology Cloud Tech as springing up all over these organizations data is being put in the midst of these things analysis that's happening and value is being produced but you have the poor data platform teams and compliance groups of the middle of it saying what is happening here?
Like we have no control, you know, it's proliferating at incredible rate and there was this I think underlying hypothesis that like in the traditional Legacy environments you benefited from traditional security perimeters, but that's the typical Network layers cyber security kind of created this world Garden where it allowed people to move on fettered but in the cloud environments, that's no longer the case. so you have this, you know growing need to be able to keep up with the speed of innovation that's happening in the with the data consumers and then start to put in place and improve security posture so that but you don't want to do is wake up one morning and find your brand or your your company splashed over the front page of you know, the New York Times and look at like drizzly for example, which is the local company and in Massachusetts and You know you have this phenomenon that happens We're Not only was there a data security breach that impacted the brand it actually impacts the senior executive who is responsible with it. And now no matter where this individual goes.
They have to you know, carry The Scarlet Letter with the really a profound it they have to register with the data the data, you know kind of security offender registry every right, right and I mean think about these companies who are like, okay, we can make an executive, you know hiring decision. Are you taking the one with a Scarlet Letter? Are you going to take somebody who may have a clean track record?
It's The new age that's not something we don't want before. So how does it work Matt? So, you know you guys have access to you know, kind of the day to because you're you know, providing mechanisms to you know, kind of unlock or you know, kind of again just make a lot of this data accessible.
Do you do like some machine learning the the usage patterns the how do you identify that something, you know could be malicious and/or, you know focus on on expel creation. Where do you get you know, where do you insert right is a matter of I got to put your stuff in between, you know, the date is it you just monitoring kind of the day to resources. So give us a sense of actually how the product works.
Yeah. It's a great question. So the answer for us as we start with log file ingestion.
If you are an existing of you to secure customer, which is our data governance and policy building enforcement module great you get benefit from being able to have all that extra information that secure provides. But you don't need to be so what we found was. There's there's like one basic pain point that if you have a data security issue those poor people who are stuck in the middle of trying to go, you know deal with meantime to Discovery meantime to remediation type issues.
They have to parse through these log files. They typically do that. They grab some amount of the information they drop it in a scene.
They may start to explore it with some tools. The mod files aren't enriched. They're not harmonized in any way.
They're all different from one technology to the other so it becomes really really painful. So the there's a little secret sauce that we have underneath the need to detect which is our Universal audit model. So we pull these these log files out of the system because through a process where we harmonize it into one universal audit record or set of Records, which allows us to do kind of cloud technology comparison really really easily and that alone I think for this poor people who are stuck doing these hand-o-matic reconciliations would be like wow like, oh my God, I don't have to fight with this thing anymore, but then we take it a next step further.
And in that enrichment process we start to create events as somebody is, you know, acting these events fire off and we create a continuous security posture monitoring environment. So if somebody is running a query of somebody is changing something at the identity level. Maybe you have an individual who goes in and changes a group right?
This is it's one of those things people don't think about but you have a highly entitled group and your identity management provider and you're like, well these people need access. Let me just chunk this, you know this role in there all of a sudden you've opened up the you know, the world and given given all these folks access and that you know, that could be wildly problematic maybe fine, but it may be problematic. So being able to attract all of those environmental factors that could create and User to sensitive information.
We will pull all of that in and then create a really easy to use Easy to look at. A set of dashboards or reports that help you prioritize, you know, what's my current security posture today? Where do I have potential issues?
You know help me spend the I don't know if it's 15 20 minutes or maybe somebody has the benefit of 45 minutes a day. Let me spend that time making and informed decision on how I improve my daily security posture as opposed to what we see in people either just groping and hoping or they just kind of stick the finger and they wind and like I think that sounds good. Let's roll out this policy in the did it work and that's right.
And I think you bring up a number of pretty, you know important points, right and and one is The whole data environment really has to be looked at holistically, right? You know, it's not a matter of just that you know, this data store or that, you know set of buckets or that, you know, kind of containerized environment and and kind of the storage that's used there because again how the attackers work right? It's you know, get in gain a presence and a foothold in the environment start to Recon and then pivot and then you know, basically see what you know, you can pull out of that environment.
So it's not just looking at one system. It's not just looking at you know, kind of the cloud posture and I love the point about I am right, you know kind of folks don't realize one I get said I am policies to protect pretty much any of these data stores, but I also you know kind of provision entitlements to you know, kind of get at what through that time environment. So so getting a handle on all that stuff right holistically across the Enterprise that's absolutely critical and you know, you sit there and go as in this the day to person's problem right shouldn't they be you know, kind of Charge of this but at the end of the day, right, you know kind of you gotta worry about it from a compliance and Regulatory posture as well.
But any kind of protected information, you've got to be able to substantiate to the assessors that are going to come in that. Hey, I've got all this stuff moving into my cloud estate or states right multi-cloud, right? You know, how am I gonna really substantiate kind of the policies that are in place, you know around that.
So again, I think that that there's no question. There's a huge need for data security posture management. Again, it's really an interesting kind of position to take to come at it more from the data Centric side of the world as opposed to the again Cloud configuration side of the world, which is where I think most of the noise is gonna come from this year.
Yeah. I think that sounds right. I like how we're Uniquely positioned I think what makes our approach to it very different than potentially some of those larger traditional players is we already sit in the query path.
We are we're in that if we think about the data supply chain that's happening in these organizations. You have the suppliers. You have the consumers and access control is right in the middle at that point of exchange between between the two groups and you have this very unique opportunity to not just help somebody, you know, make an informed decision on should should the square even be run right but One of the things that we see what two phenomenon that really really interesting in the space.
The first one is what we call contextually aware sensitivity. So it picture yourself in a HIPAA environment and you know, there's an analyst who's trying to run a query and they query a whole bunch of relatively benign information, but then they join it into a personal record that has a social security number now under the rules the compliant that whole thing query becomes sensitive, right? We're in a position where we can see that we can act on that in in the moment which is which is a really really cool and interesting world and what we see, you know, a lot of the traditional players think of this world is very static you go through and you pull a bunch of you know, metadata, you kind of declare something sensitive or not sensitive, but the reality is this is always emotion that data supply chain is deeply recursive.
It's always looping back on itself and you need to evaluate that continually and you know, I'm really excited about what that does for us the other piece of context that's really important in that in that Loop is purpose. So if that person who is running that query was operating under a purpose that granted them that privilege great. Right?
Let's let them go do their job and we can record that and we can prove to those compliance and Regulatory people that you mentioned that yes, we saw this happen, but they were operating under the right purpose. So like it's good. Let him let him go do their thing.
But if they don't have that purpose, we're gonna block it and say well go get that, you know go get approvals to get this information. That's I don't think people who are on the periphery of that technology that they had mentioned. I think they're used to those conversations or how those workflows work in these crazy complex Enterprises that we partner with.
Yeah conditionals, right? That's what we're, you know kind of in and that's one of the things that cloud environment added to a lot of things that we can start to build policies and access rules based upon attributes, right right different attributes that we can use from that standpoint. So another interesting take that's fantastic.
Matt product is available. Now people can test it out or yeah Madison product is available today. It's in a private preview state.
If you are a snowflake user in particular it is available. We will have support for databricks coming very shortly. But if you're interested in your databricks user raise your hand, we'd love to talk to you and have A part of that early preview, that would be great.
com. There's a potpourri of confection on the website. They will take every opportunity to collect your information and have somebody reach out and you know, you're always welcome to reach out to me directly through email or you know, Lincoln would be and and we can have a conversation.
We'd be excited to help you get started. Yeah, great. Let's back really appreciate taking the time showing up on Tech strong TV this week.
That's fantastic. Congratulations on getting this thing over the Finish Line. I've been there been in this salt mine.
I know what it's like, you know get a new a new product out there and and you know start to be able to talk about stuff you probably working on for you know, 12 to 18 months. So always always great to to be able to talk about that kind of stuff check out immuta. com go check that out.
See what you can about him you to detect and If that's about it, so we'll we'll send it back to the studio. But thanks again, Matt. Really appreciate you being on.
Thank you.