Is Zero-Trust a Thing? – Paul Martini, iboss
Paul Martini, CEO of iboss joins Mike Rothman to discuss the latest on zero-trust, and they get into whether ZT is a product, service or philosophy and how to get started. Surprisingly they also sing the praises of the NIST zero-trust guidance. Wonders never cease!
Transcript
This is texturing TV. Hi everybody, Mike Rothman here Chief strategy officer of Textron group and I am pleased to welcome Paul Martini, who is CEO of ibos to techstrom TV. We're gonna chat about zero trust, right?
We're kind of getting into RSA conference season. So that means that you know, we're gonna start here in about what the themes are gonna be and I don't know a hell of a lot but I'm pretty sure that zero trust will continue to be a big theme insecurity. So we're gonna pick through that we're gonna you know, excavate it and understand exactly what it means Paul is a long time Security executive and very experiencing can help all of us really understand what you need to worry about relative to zero trust or Paul.
Welcome to Tech strong TV. Why don't you take a couple of minutes and and you know, introduce yourself and as well as eyeballs, I don't never assume that, you know, folks know about the companies that are here. Yeah, absolutely.
Yeah great to be here. My name is Paul Martin. I'm the CEO of ibus we're Cloud security company connecting users to Applications as well as basically sassifying but I like to say network security appliances vdi VPN.
So basically moving Legacy types of connectivity contracts to a more modern fast-based approach. Now that's that's fantastic. So let's kind of talk to your trust right because one of the things that's interesting and being a long time security person.
I've kind of seen, you know, buzzed words and Concepts, you know come and go and you know something get overheated and then you know the next year it's something different and then it comes back and then it's a different again. So the pendulum continues to swing back and forth. So if I say zero trust to you, what does that mean?
Right, how do you kind of frame it out in terms of you know, kind of business benefit to customers. Yeah, and it's I think it's a catch 22 right when something becomes very popular. It starts being used in a lot of different ways.
Sometimes abused quite a bit as well. But you know for for me it's on I like the nist 800 to a seven which is the zero trust architecture that's been defined by Nest. It's a it's a large document but I like about it is it's a very simple construct which means the way we approach securing our data and services needs to be different and inverted from the way we typically protect those things and use this concept of an airport security checkpoint.
That's what they use as an analogy where in an airport security checkpoint. The airplane is what you're trying to protect and to do that you put a checkpoint right in front of it. And the only way to get to that plane is to go through the checkpoint.
So very very tight access controls to the thing you're trying to protect. I think it's a very inverted model to the strategy that was used before which is hey, let's look at the public internet and figure out you know, where the attackers are, you know, what types of policy should we create what kind of anti malware types of policies should Play as well. And the reason it's inverted is you're you're not focusing on the data and applications.
You're trying to protect are just trying to look for applications and data. That might be randomly scattered on the internet that might try to harm you. I think it's a very similar Concept in an airport.
I mean if we try to figure out who an attacker might be how do you where do you start? I mean there's billions of people on the planet. Is it Regional is a type of person anybody can be an attacker?
Right? But if you flip that construct around and use the nist 800 to a seven model what there's only 200 people are 300. They're gonna board that plane.
You don't have to look at anybody else. So if you can tightly control access to the thing you're trying to protect and Run Security controls in our world. It's anti-malware data loss prevention and the airport's model is let's look in the bags or their weapons the Mona Lisa stuffed into luggage, right?
We're trying to look for for different things, but it's the same constructs, right? And so I I always start with this 800 2007's or a trust architecture. I also like it because it's part of the risk manager at framework from this very very powerful contract that helps with compliance.
It's also something That's been in the executive order that was benjam mentioned by executive order that was just signed. That's that specific publication has mentioned 10 to 20 times throughout which means regulation is likely following and on I think that's important. If you can do a security strategy, it also meets compliance.
It really makes makes it so that you just you get better security as well. As you know more secure robust approach. Yeah, you know, that's interesting and and I kind of would take it even one step further and the difference between zero trust and the most right, you know, so if you think about how most airports work today, it's still the most, you know, you come in through and I live in Atlanta, right?
So you go into Arts field, you know, you pass through one checkpoint, then you can get pretty much anything you want so similar to our mode, right? So you get through the mode that you're in the data center and you know, you can run rough shot if you wanted to obviously you're trying to make sure that people don't have you know weapons when they get in there, but but all the same worse I do about you international travel and in a lot of cases with the international Airport you you actually go through security. You'll do an initial screening when you get into the airport, but then you actually have to go through another screening before you get to the gate specifically for that plane.
Right? So they're looking, you know for that specific plane to ensure that there are no no risks and and really so they can afford to enforce different rules. If it's a plane going to Europe.
There's one certain set of rules. It's a plane going to the states. They have to adopt, you know, kind of the TSA rules.
And yeah, I view that as similar to how we think the best you're trust which is, you know, kind of making sure that you are scrutinizing all of the traffic to a specific destination and you can have different rules for different things. Right. So my Finance in general ledger, I can have different, you know access rules for that versus something that would maybe be my HR, you know kind of document that would be, you know more applicable to all of the different environment.
So so how do you get started with it? Right. Is it a matter of you know, hey trying to figure out what you're trying to protect and then, you know setting the right access rules in order.
That is there, you know some other Magic Bullet to get there because again when you can pretty much set policies for everything that you access to it can kind of be overwhelming for a customer that you know wants to start getting their feet wet with zero trust. Yeah, I mean you bring up a lot of great points. The first one is this isn't a light switch, you know flip a switch in your church.
This is an auto Journey right? But but I think you know one of things that net 800 207 brings up is the goal is to continue to shrink what they call implicit trust zones if the implicit treasone could be the entire boarding area in front of the plane, but eventually you want to keep shrinking that and shrinking that until you're really getting right to that door of the plane. They're checking your ticket and making sure the right person there and the goal is the same with your applications and data is that today?
The castle remote has been around a building like anything in this building is fine. You're really Shifting The Castle remote to the application Level and the data level. So you're building them but in a world where their staff applications there's AWS and Azure, there's on-prem applications.
And actually I think that's one of the key things with and what are the challenges with these terms when they start getting kind of loosely applied. So for example on dtna zero trust network access, right? But the whole idea is you're Interesting Network.
So, you know the Nifty hundreds are 207 calls it zero trust access not network access so they drop the end, but I think that that's pretty important because you also see products that are very Niche talked about GTA to replace VPN when it reality. It's it's actually zero trust access is more than that. It's actually making all applications private and all data private including SAS applications on Prem applications data center.
So location of the users are relevant the location of the data and applications also relevant as well. And so they you know, we want to continue to treat those those implicit trust zones and the surface area in front of those data and front of those applications and I I do think that the good side of this idea of like a ztna replacing VPN is that we also need to look at consolidation of Technology. Where what is the money come from?
And how does it how do we make what looks like today and current better better engages your experience better security a better a better pricing better cost through consolidation and simplicity. And so I think of Three core areas that are Legacy VPN proxy appliances and network security appliances and vdi vdi's missed a lot. But they talk about that in the next 800 207 vdi is putting a pane of glass to remote desktop in front of data replacing that with modern strategies.
For example, vpnet VPN VPN can be replaced with something like vtna or is there a tax? Proxy appliances of the network security appliances which are designed for buildings gets replaced with something like security service edge. It's a SAS based approach of that and duratrust and then finally vdi getting replaced with browser isolation.
And I think what's interesting with the browser isolation piece is normally people think about that as protecting you from Risky websites. So put browser isolation in front of it. I think about it as the bigger use cases call center agents any situation where you have contractors third party guests that you want to give access to Applications, but you need to separate that data from their device because their devices is unmanaged.
It's untrusted. You can't let the data Cut That device so you need a way to connect them but isolate so browser isolation has a much bigger use case just like the next day under 207, which is vdi replacement. Yeah.
Yeah. Now that's interesting because and you know kind of dig in a little bit because you mentioned SSE or I still call it sassy because I'm a dinosaur, you know, they change these sacraments all the time. I can't keep up but you know to me that construct makes sense.
Because you know folks have a lot to do right. I mean networking people, you know again, they just have a lot on their plate from that standpoint. So having someone else really manage the access to manage the security of the pipes, you know, kind of provide an effective managed networking service that make sure that the folks get to the right stuff whether it's on-prem whether it's in Cloud as you mentioned AWS Azure, whether it's in a SAS type of environment, but you know, really a much more curated and managed type of experience there would seem to to make things a lot easier rather than this assembly job, you know a variety of different Technologies to to get there or are you starting to see folks moving that direction?
You know, what else? Yeah, look, I think the key Point here is this is for network teams and security teams. It's to make their life so much simpler and easier and faster.
If you if you're used to putting gear in a data center deploying these types of infrastructure, you're going to get the same capabilities, but it's going to be fast. I I personally don't like to set up a DVD player anymore. And but I still like though I still like to watch the movie right?
I still want streaming movies everywhere. And so I think of this is streaming Network and security which means that as a as a network of security admin, I can connect anybody to whatever they need on the on the network side, but on the security side what it means is I get a log event for every single interaction with data applications. I get now, we're dealt compliance controls.
I get all of that stuff, but at scale where I can decrypt as much as I want enough to worry about how much gear I have or fighting with the network team because you know, we're saturating vpns or saturating appliances, but I do think that Concepts like zero trust architecture from this have almost a direct overlap with Concepts like sassy, I mean they're There's this content there's a concept of zero trust which is basically everything's contested and untrusted but the reality is zero trust architecture, which is from this which is an implementation of the concept means people processes and technology. So I do like to you know, going back to the loud question, which is how do you start? What are the three things that are interacted when you when you have a potential risk of losing data a user a device wants access to a resource.
The resource isn't the public Internet. It's something you own so you need to catalog those resources. Applications and data services like RDP and ssh what I find what's pretty interesting is some organizations if you ask them because they have to go through this for sock 2 compliance.
And so it's called continuity planning and interconnect. Yeah, that's spreadsheets never spreadsheet with all the applications, but they update it once every six months how fast are people consuming applications and how fast are these things being brought into an organization? So having a having a digital version to just catalog those resources and then introducing the users and the devices so that anytime any of those users devices touch the data you now know who's touching what just that alone reduces your risk because you're by cataloging you're also on labeling, you know, what's high risk low risk.
What's moderate risk? Is this catastrophic or is this something we can live with and let's play this label labeling process. That's 199 talks about that is a really important process.
But I like this journey of catalog first. I'm introduce the users the devices and then start to shrink the zones. I actually in some of the suggestions we give is, you know, look connect someone to a network if you want to start but at least they're separation so you can use that for Discovery and then start to tighten down those applications.
So every single application gets gets cataloged and identified. Yeah, and then you figure out what you break, you know as you tighten up the rules and then yeah, right that exactly you know that way and just wait wait for the calls, right, you know kind of that's how I used to clean up Fireball rules, right just blow them all away and then you know, wait for somebody to start screaming up. I guess that was important and you get rid of a lot of the Croft that way and that's you know again and interesting approach.
It's funny. I tend to you know, not really rely on a lot of the nest, you know kind of structures because I I find them, you know, you kind of mention it's a big document. I you know if I have trouble sleeping they're great, but you know kind of if I'm trying to be productive and get stuff done I tend to You know going and and do stuff but but I do think that structure right that approach of you know, kind of understanding catalog cataloging and then really, you know, defining our classifying what the sensitivity is is critical not enough organizations do that because it's hard right?
It's hard to want to understand where all your resources are. It's also hard because if you ask a senior manager if their stuff is important it pretty much always say yeah, my stuff is important care about their stuff. I care about my stuff and you talk to the other person and they're like, yeah I care about my stuff.
I don't care about their stuff. So it's difficult to kind of eat a lot of those things. But but it is critical because you know, again one of the things that played this is security folks for the first 20 years of my career was reading everything equally, right, you know regardless of who's device.
It was regardless of the date. It was accessing. It was all kind of secured in the same way.
So, you know, we ended up with the lowest common denominator, which clearly was not good enough over time. So this approach Categorizing, you know starting to reduce and focus the implicit trust zones. I mean, I think that that, you know makes a lot of sense and again this idea of streaming your networks as opposed to, you know, having to build it out.
I wish you would have told me about that maybe 20 years ago when I had racks and racks of CDs that I ended up, you know again, I now I pay 15 bucks a month and I get all the music I could possibly want in a lossless thing. And and I you know, it's somewhere in my basement. I have you know, kind of probably about you know, 500 or 600 different CDs.
I need to get rid of at some point. Yes this discussion 10 years ago. I wouldn't that, you know worry about that stuff, but that's great job both get started with my boss.
What are you know you guys offer these kind of things and so give us a sense of how you work customers do that process. Yeah. It's actually pretty simple.
I mean we do we do the largest organization the world and what I like about it is the cost savings are pretty tremendous as well. We have customers that if they figures of savings just an infrastructure and actually once you get Taste of Netflix or streaming it's kind of hard to go back just because you can consume all you want but basically it's a it's a cloud Security Service, which means it's instant. You can get an account going up very quickly and then you end up connecting users to the service.
I like it because it's also not just about a VPN replacement or about you know policies you connect those users and what you're doing is you're now able to both connect them to what they need, but then start getting the logging the visibility the malware defenses. It actually goes by pretty quickly. I start with Discovery.
So just connect the users and see what what is what shows up and you're gonna find a lot of stuff throughout actually what are things that I find really interesting as well is when customers say man. I have a thousand applications. How am I supposed to do that?
I'd like to immediately comes to my mind is you realize you can wake up any morning. Any one of those applications could be an absolute critical critical application. If you get an email from a ransomware attacker saying pay me, you know, five million dollars or like what's better knowing what those things are locking them down ahead of time.
Or just you know, praying that nothing will happen. So it's it's a process on but if you're not gonna have to do it over time, I even think start with a it. Could you imagine if there's five applications or 10 maybe an organization that has critical catastrophic effects on organization, imagine getting those five applications.
You might reduce your risk by 80 percent because the last 20% is all the rest of the stuff but you know, you could just just by doing just a little bit you could get great reduction in risk, and that's what I would suggest to start with the risky stuff first. Maybe there's five to ten applications lock those down and then take your time. You can you can get the other ones over time go to Modern go to low and you'll be a much much better shape and you never get to low half the time you never get to moderate right because things that are you know screaming at you but it is a good place to start and really think about which your mind most critical applications my most sensitive day.
How is it that I you know, make sure that I'm restricting access appropriately to those folks. And again, we live in a remote first world now, you know For for most organizations and you know, you've got folks coming in from you know again, who knows where you know, they're hopefully it's a home network that somewhat curated but you can't that right, you know, they can come in from anywhere and and we have to really, you know, assume that those desktops are unmanaged. We have to assume that you know kind of their compromise in some way shape or form.
I've got to protect our data and we've got to have the ability to investigate stuff when things go wrong. So I do like the idea of having a managed environment that you know, you're pulling that Telemetry you have a mechanism to do that. So so that that all sounds good and again to me one of the more important takeaways and tell me about I I got this right is that you know, zero trust is a philosophy right?
It's a concept. It's not a thing, you know, you don't necessarily go out there by thing. Right?
What I'm buying is access to a certain application. I'm buying, you know, kind of a VPN replacement or you know, kind of approximate placement or some way to you know, kind of modernize my vdi environment. Of the things you really buying when you're trying to do is build it within a structure that allows you to control access to these sensitive resources in a much more scalable effective efficient and cheap way.
I sort of right, you know kind of closer. Yeah. No.
Yeah. Exactly. Yeah, you're exactly right.
I think you know that on the flip side sometimes I hear things like it's purely a concept. The reality is the concept is denial attackers and only allow authorized users. Right if you could do that who care if something was vulnerable, they just can get to it but eventually you have to go and Implement and that include that involves, you know, sometimes they say, well it's not a technology.
Well, it isn't because it's people process and Technology. You need to make those all come together so that you as you implement your implementing something that's real intangible versus just an idea in a concept so really there is processes and there's approaches and and Technology you can use to basically get yourself in a better secure position in a world where everybody's remote and you're out your resources are scatter. You know everywhere throughout the cloud and on-prem.
So it's a really challenging environment. It is well great Paul. Thank you showing up on textual TV helping us understand a little bit more about zero trust and access and even, you know a shout out for nist, right, you know, kind of we don't we don't hear a lot of that every day, you know, kind of folks say hey go go check out a disc guy.
So that's great. They give us a sentence. You know, how do we get in touch with with eyeballs?
If somebody wants to check out what you guys are doing. They're a link or you know some other mechanism to to track you guys down. Yeah pretty easy.
com. I've lost calm you heard it right here fairly straight forward. So Paul Martini, really appreciate it CEO of eyeballs.
Thanks for your time and and helping us understand a little bit more about zero trust. And with that we will send it back to the studio for our next interview.