Lessons Learned from Analyzing 100 Data Breaches – Terry Ray, Imperva
What types of data are stolen most often in a breach, how are bad actors gaining access, and what steps can companies take to protect their data? Terry Ray, Imperva SVP and Field CTO, discusses the latest research from Imperva revealing shifts in credit card and personal information compromised in successful attacks. Terry shares the questions every company must be able to answer about their data. Imperva’s Lessons Learned from Analyzing 100 Data Breaches for more information.
Transcript
This is Textron TV. Well today I have the great pleasure be joined by Terry Ray Terry is SVP data security GTM and field CTO with imperva. Welcome Terry.
Thanks Mitch. Thanks for having me. And welcome to 2023.
Yeah, right. Here. We are.
Yeah, but we jump right back into it. Right don't we? So before we do that tell us a little bit about yourself and a little bit about Improvement sure.
If you're not familiar with imperva imperva is a data security and application security company usually people know us as either a WAFF company to simplify it or a data security company. The fact is is our mission is to protect data applications just happen to be an Avenue to it with that. That's really our core.
I've been with imperva for 20 years in May this year and purpose is 20 and a half years old. So I've been at this for quite some time and I just been my days talking with customers potential customers analysts personalities and others talk about my passion, which is protecting data. Fantastic.
Yeah, it data is kind of the fuel right before you get up something to run those engines with. Well, let's talk about I know you had some research done where you're looking at some of the ways the data gets stolen both the mechanisms of how that happens, but also the consequences of it and and maybe some preventative measures as well. Do you adjust a little bit about that?
Yeah, we spent we have a pretty pretty extensive research team and a lot of what they do is look for bad behavior bad things happening on the web and all this and periodically they go and Rewind their their, you know calendars back a little bit and look over time. What have they seen in you know in overtime and and build in some of the statistics that they would normally look at maybe daily or monthly and expand that out over a decade or so and say well what what has changed and how has it changed? So we bring this we brought this report out.
I guess not long ago a few months ago and one of the great things about the ability to go back and look at things is obviously we can learn from the past. We can learn from the mistakes. We've made in the past and successes that we've had.
And if I if I pull one piece of data out that was pretty interesting to me was you know, I talk all the time about credit card theft and medical record theft and and all of this but then the type of data theft is actually changed quite a bit not surprisingly. But one of the things they found was that for example personal information pii pii is always been pretty high because it overlaps so many things pii can be medical. It can be PCI.
It can be other things but pii was almost half of the data that we saw stolen on a 10 year period but at the same time what we saw is credit cards actually tended to go down quite a bit. 4% of the day. That's that's breached.
Is that kind of data and medical is only about five percent. One of the takeaways from the report was that well, why why is that? Well, it's maybe obvious to a lot of people but you know, the the big factor is is pii doesn't go away.
My name doesn't change my address kind of changes, but you still my data that doesn't mean I'm instantly gonna move but I will change my password. I will change my credit card. So there's some things that can just really be short-lived in terms of the Monet how quickly someone can monetize that data and others have a very long life cycle of how long they can resell and others.
So what's the thing is one of the things when we talk about the Genesis of Privacy Law My privacy, you know compliance regulations around the world. We've seen an explosion of those over the last five or six or seven years and a lot of that has come from the fact that my name and my address for many organizations without regulation. Honestly, isn't that important but with regulation attached to my name and my address at least my stuff becomes very important.
So I think the constituency that you see and a lot of countries have said enough is enough if you're gonna ask me for my name and address at least do something to protect it. So that was one of the things I mean, we there's a lot of the report that we have. I'm sure we'll get to some of that as we get through this but that was a big takeaway that I had from the report was I don't think everybody is completely aware that there's data you need to protect because you have to because compliance as you need to then there's other data you need to protect because people are gonna go after your environment and try to take that data and whether it's regulated or not, it's likely going to give you a black guy or a bloody nose somewhere in the news or somewhere else.
You know, it's interesting did and enough this is part of the report or not. But the also think about the the Privacy aspect of how much we aren't practicing privacy insurance so much on social media it rising up and increasing and maybe maybe we're seeing a little bit of a rebound from that as well. But I think your point of you know, the life life span or of credit card is pretty sure when that information gets stolen right?
It's on it's value on the market. I'm sure drops pretty fast. Whereas you're you're living you're moving on you're doing more things.
Yeah, you may be opening new accounts and and you know, and you you're addressing your things you're talking about really lead you to other things that are valuable that they can explain. I'd love to hear more about it. So the other half of it that wasn't about personal information.
We're there some Trends in that aspect of it. Well, I mean the the there's Are the Trends on the data that we talked about right medical and PCI and otherwise right credit cards and that sort of thing the other the other angle on the on the on the trends was how the data was taken, right? So was it taken from an Insider thread was it taken from hacktivism or from hackers or just an unprotected database on the web and I think to me again the the interesting thing when you think about the the target if you will or the way the data was ultimately exposed was interesting and that we always like to talk about well, I got hacked or hacktivism.
I mean hacktivism still exist. We're I think we're a long way from the from the days of the past with you know, the anonymous and the little sack and some of the others back in the in the early tins and things not that they don't exist. It's just there you don't hear them hear about them as much anymore.
And I think we still try to focus on on the hacks. I don't want to get hacked and that extent kind of comes from the angle of an external threat an external threat can be B2B. It can be through my web applications.
It can be through my apis. And as we Explore More, you know to share more and otherwise and expose more than we broaden our overall landscape of what we need to protect but I thought what was interesting in the model here was that the the largest percentage of data breach actually came from still yes to be fair from hacktivism and hacking but a lot of that kind of overlaps the second largest which is from just simply unprotected databases and when I mean by unpredicted databases talking about data, Because as people make this transition to the cloud and I think it's fair to say that everybody uses cloud in one way or another in their organization. Yes, you may not have moved your databases to the cloud.
But you may be using a cloud service or something else that they're using in the cloud and you don't know it but you're still exposing your data. So all of us are using the cloud and as we move to the cloud one of the things that this this report exposed was the the lack just sheer lack of security not not, you know a a reduction in security but a complete failure to provide security where Posture management was in play. Right?
What is your security posture on a database when you have databases that are publicly available to anybody to access them? That's not just a lapse and security that's a complete failure of security and that's the big challenge I think is people who change and move from on-prem to the cloud is saying I'm gonna apply the same security controls. I'm going to use the same in some cases people are skill sets that I know on-prem.
And I'm going to apply those in the cloud. I think what a lot of organizations have misunderstood and what this this report's also highlighting out. Is that as you move to a major cloud provider whoever it is each one has their own different configurations their own different capabilities and their own skill sets that need to go into that capacity to be able to secure that data as you're moving up there and I think organizations need to be aware as well that there's a lot of great security that exists in the cloud security vendor as well at the infrastructure level almost none of them.
In fact, none of them actually provide. Actual security for your data your data and your security on your data is a hundred percent your responsibility and I'm not sure that that necessarily that message trickles all the way down to the organization level to say so when I put this in CSP provider a I actually need to set up my own configuration and my own security and my own monitoring and all this that's not already provided. No, it's not and so I think that's one of the things that we see here and that was a I forget what the number is.
I've got it around here somewhere. 14% that we saw of unsecured databases overall. It's that's half as much of the day that we saw lost was lost through that as what we saw from hacktivism and hacking as a whole as an aggregate.
So we see a lot and that's just just misconfiguration simple things to fix but still it exists out there. Yeah, how much of is through Mis configuration still today? It's interesting.
I think the cloud is really also demonstrated the fallacy of shared responsibility model. No, it's all ultimately your responsibility whether security seriously or you know, they're flippant about it. But you're the one that pays the consequences no matter what the contract says what you know, what remedies there may or may not be.
It's probably your job. It's not true the impacted your customers. So I think to me your point about the cloud and there are differences and they all have great capabilities right for the most part but they are different, you know, you're gonna control access management how you gonna do data protection back up and Recovery it distribution now down to putting databases that containers right and different ways of where we put in managed data.
I think that's part of sort of the complexity of our options whether it's cloud or not, but that's part of what we're dealing with that and multiple providers, but also, Technical ways that we can what we can take for approaches. It does well and there was a statistic in the in the article that talked about so as we get so complex, right you got stuff everywhere what that translates to from a from a solution perspective. We talked about the security solution perspective in most organization it translates to now a lot of other Solutions.
So I need one for containers. I need one for virtual, you know, whatever's and I need one for the cloud and I need so you wind up with this huge ecosystem of security Technologies. And the expectation is that now you have people that are hopefully experts on all of those or you're spending a fortune Outsourcing all of that to other people and there was a statistic in there that talked about as organizations.
Move over the 50 Mark and I'm sure there's some you know standard deviation in there. But over that 50 Mark of ecosystems security vendors actually the security that they're actually providing reduces and gets less by about eight percent. So as the more security Technologies you have you actually become slower and being able to respond and and the the inability for your experts to truly be experts now, they're kind of jacks of all trade but masters of none and that starts to become an issue where if you start to compress that down consolidate down and have a smaller set of vendors which we see so many companies still trying to do not from a security perspective, but from a cost perspective.
I just let's reduce and get smaller and smaller to save me money. Well, there's another benefit to that whole world is now you have a level of focus as well and where you need to be but that is you know dependent on of course vendors being able to interoperate work together and be able to solve multiple problems and single Technologies and that was a big problem that we saw on and noted in there as well. We're a lot these breaches the the response time to the breaches the response itself to the breaches were limited by the large scale of a lot of these organizations just general security ecosystem itself.
Unitary before we wrap up. I helped found our analyst business and we just did a wrap up show for it's actually being broadcast before the before the holidays and when I was asked so what do I think was one of the most consequential things that's changed in the last year and one of my answers was for the Security Professionals to have application security risen kind of near the top if not the top of one of their one of their priorities now, I mean, how long did we work at protocols and security devices operating systems things like that. It's been that way for a long long time and the fact that Securities engaged and apis and application security.
Now you're getting into yes containers and micro services and service mesh and all kinds of things. We weren't talking about a few years back. How do you see as a data security company?
And yes application is Securities important for that as well. Yeah. I look for For Us application security and I love application security into everything that sits in front of your data.
It might be to your point of service. Mesh. It might be a function.
It might be Lambda. It might be an API or your web application sitting up front whatever it is if it's Community to the back end application security. This point in my opinion's table Stakes.
You have to have it. It's like a network firewall. It's like something on your endpoint when you develop something new you now have to have at least three pieces of Technology arguably more but a firewall something on your endpoint something in front of your applications.
You can't go public without something in front of your applications and that same thing is starting to now lead. I think to a lot of organizations to the back end where Regulatory Compliance has driven for years the the desire and in some cases the requirement for organization to at least be able to answer rudimentary questions about their data. For example, we talk about credit cards PCI has been around for 20 years at this point.
PCI says you need to know everybody who accesses your credit cards and track data and all of this. So what an organizations do and frankly still do to a degree, they would put controls around the credit cards not around anything else, but around the credit cards because that's what's gonna get them fined if there's a breach Now what we're seeing is so much more regulation still regulation. Sadly still drives a lot of true what I consider data security and what I consider data security is if you can't answer.
Where is your private data? And I don't mean I know it's in this this Pride this PCI credit card server. I mean, is it possible you have credit cards anywhere throughout your ecosystem.
If you don't know that that's key. If you don't know who's accessing your data every time they access it when they access it not just privilege users but also your apps and your apis because I need to be able to compare Mitch from Terry and Terry from an API and I need to look at them all if you can't have visibility on all of your data and know where exactly all of that data exists. You don't actually have a data security strategy.
I think a lot of people have always assumed that encryption is a day to security strategy because every almost every compliance as you must encrypt your data encryption in my opinion is identity access management, you either allowed to see the data or you're not allowed to see the data you're either allowed to log in or you're not allowed to log in that's not a data. Strategy, that's an identity mechanism. And that's okay and as part of it, but being able to answer these questions are critical for security the critical for compliance and I think we're seeing more and more of these organizations today realize that data theft is not a perimeter problem.
It's an inside problem and they have to have visibility to solve it and that's what we're working on. That's what we continue to do day by day. Never make any assumptions a few years back.
I took over it for an organization and found out we were storing people's credit card information in notes in the accounting system. So when they signed up for the next conference Okay, we need to not do that. But you just don't know where you find it.
It's amazing. It's I can laugh now wasn't funny that that's requirements. Well, Terry has been fascinating talking with you as a report of available on the website or what's a good place to to grab that and of course work and people find out more about it?
Perfect. Absolutely. com and there's a white paper section.
You can jump right into there and grab it. You can probably Google it as well. It's called more lessons learned from analyzing 100 data breaches.
Fantastic great. Well, thanks for coming on Textron TV and being with us today, and we look forward to having you back. Thanks Mitch.
Appreciate it.