Monitoring Cloud Data – Yotam Ben Ezra, Dig Security
Yotam Ben Ezra, CPO of Dig Security, discusses the importance of monitoring cloud data in an organization, and the consequences he has seen first hand from not doing so.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with yodum Ben Ezra Who's chief product officer for dig security and we're talking about data security in the lack thereof, because well, I guess we're still obsessed with the network perimeter Yoda, welcome the show. Hi happy to be here. We've been talking about data security for as long as I can remember, but it doesn't ever seem to get much better because well security people seem to be focused still in the perimeter and they think somebody else's securing the data and the people who are creating the data don't think about security at all.
So how can this situation get any better? But I think organizations are in experiencing and explosion in whatever data means when they move to the cloud. And so the number of data stores that organizations are facing today across the different clouds.
They're using the different data services. Everyone is using micro services. So it's microservice interacts with their own data store.
And so the number of data assets that organization has today is simply a staggering across manage data assets unmanaged data assets and databases service. And so I think it's not only the fact that people have forgotten about data security, but the nature of the environment has changed and so the problem is moving a little bit. Traditional approaches to cybersecurity don't seem the work.
So what do we need to be doing differently? I think a lot of folks are trying to apply Legacy mindsets to what essentially is a new Computing environment, whether it's personal machines in the cloud or as you just described all these Cloud native environments, but what fundamentally needs to change Yes, I think traditional data security is around either the endpoints or the network as you mentioned in the beginning and those simply don't really scale to the cloud environment. And so of course there is no read perimeter.
There is a lot of areas or places in the cloud where you cannot deploy an engine an agent. And so some different approaches need in terms of understanding the answers to a few fundamental questions. So effectively most organizations today don't have good answers to the question first.
Where is my data? What kind of data do I own in the cloud? How is that data moving who is consuming that data?
How is it flowing across the organization and then eventually how do I secure it from data exfiltration datum is used compliance breaches and and all of the bad things that can happen. Now as you mentioned there are dedicated solutions for protecting our endpoints with edr's protecting our networks with ndrs, but there's never been a dedicated solution such as DDR to protect our data and so I think the focus on a data Centric approach in terms of understanding the answers to all of those questions is something that is well called for who is in charge of that because the people who create the data don't seem to think much about security and yet they have a better understanding of what data might be more valuable than others and it's hard for security team to kind of understand or appreciate that so how do we need to kind of organize ourselves going forward to achieve that goal? Well, what we see happening in organization is kind of a return of the data security team.
So definitely the organizations are starting to think about and build data security teams out of the security team. So those will be ones which are responsible for protecting data for complying with data regulations. Sometimes a little bit with privacy.
So in we will see in either a part of the cloud security team, which is responsible for data security or in large organizations a proper data security team being built today. This assumes that I have some ability to monitor the data itself. So how does that get achieved in the cloud where I can't necessarily, you know, put a lot of resources in place or I may not have permissions or whatever else I require.
Yeah, so in in that is exactly a why we've built dig or why I've joined the selected to join dig and it's the that huge problem of understanding the answer to these questions and having a platform which can make it easy to actually do it and today things like that. We simply don't have the tools to monitor. So if you think about all of the interactions which happened legitimately in organization in even if you manage your security posture with data a hundred percent, which no organization actually does but even if you did we actually have to Grant legitimate access to thousands of entities today in the cloud environment with the whether it's customers.
It can be our own developers. It can be applications or vendors but essentially data is moving across thousands of instances of data stores across thousands of entities in normal Enterprise organization, and that access goes completely unmonitored. We simply don't have the tools or didn't have the tools today to figure it out and so dick monitors all data interactions, whether it's connections admin events data events and protect data protects data in real time, and there are interesting stories of what organizations find out once we connect.
art monitoring those interactions We have seen the new National cybersecurity strategy document from the Biden Administration and calls for more accountability of how data is managed among other things. What impact do you think that's gonna have Oh, we definitely see a growing awareness as a result of those regulations across the globe. So across the different countries new privacy or data security regulations mandating organizations to take better care of the data.
They are holding either for the customers or for their business and that definitely drives a higher awareness in terms of understanding and securing with an awareness or data Centric approach. Will artificial intelligence play a larger role in all this as we go forward. It seems like every time we turn around somebody is applying AI to security.
So what role we see this as things of all I think that as a the space evolves we'll be able to see more and more. A ability to apply a business context into the data and that might be a good room for artificial intelligence. So the first question is what data do I even own does this data need to comply with a certain regulation or a certain standard as you mentioned like do I have am I processing payment information which means I have to adhere to some PCI regulation and so on but then there are a lot of additional questions that can be asked towards.
How does that data match it what business processes in my organizations and I think that the better we understand the business processes across the data that we own the better we can manage security. Given all that once your best advice to organizations then about how to approach this and think about this. What do you see them doing today?
That just makes you shake your head? So I I think an interesting approach to maybe tackling this question is around, you know opening your eyes because in I'll tell you a story we onboarded. And we onboarded one of the larger Financial organizations in the US to the platform and they essentially in one day started a understanding what happens with their data and what we saw is that there was an automated procedure in that environment a crime job essentially which was copying the financial data of that company to an AWS account, which was not theirs.
Now that happened every 24 hours for three years three whole years. Now how can that happen? Simply because no one monitors that that type of interaction and we didn't have the tools until until that day to monitor that interaction.
I'll say by the way, it was a former employee which was decided that they needed to keep seeing the keep seeing the data. In but for three whole years, they had their data living the organization on a daily basis and no one was it was showing so as soon as you open your eyes to essentially start understanding how data is moving across the organization that brings it brings to light a lot of things that well then oh s*** moments in some cases. All right, folks.
Well, you heard it here seems like we're not focused enough on the core asset. We're trying to protect which is the data we're seem to be protecting using the traditional castles and most scatter mindset, but the roof is wide open. So maybe we hunt in a whole different approach.
Hey, you know them thanks for being on the show. Thanks for having me was a pleasure. All right back to you guys in the studio.