OPSWAT’s George Prichici on File-Related Breaches and Insider Threats
Transcript
Hey guys, thanks for the throw. We're here with George Pritchett, who's the vice president of products for Ops swat, and we're talking about a new report that they have that shows that there's a lot of malicious insider activity involving files and it seems to be getting worse. George, welcome to the show.
Hello, Mike. Hello everyone. Thanks so much for having me.
Alright, Walk us through the report a little bit, but uh, insider threats have always been an issue, but is it getting worse or better? And um, what is the fundamental issue with these files? Sure.
So maybe we'll break the conversation like three different parts, but to start with like malware's oil's been a problem. I don't think that's, I dunno ever gonna go away. It's always like a cat and mouse activity.
Whatever new measures you put in place, there's new ways to um, evade the existing ways or the new ways to get uh, into the organization. Especially like with the consumption of new applications, AI and so on and so forth. And we'll talk ai, it's a huge new world that's well to discuss with and when it comes to like the risk on the employee side and so on, um, there's a lot more, again, being inside tr um, risk or not.
You know, I think the important part is that there's a huge diversity, right? Like regardless how well you're training your organization, you have a very dispersed technology stack that's trying to solve the same problem for each of your entry points, right? So you have a very different thing for from email to web traffic to file transfers to collaboration tools to success versus on-prem and so on and so forth.
You don't have a unique way of handing those things. You have don't have a very easy way to manage across the board enterprise wide and so on. And the idea of a defense in depth is uh, implemented or some level is with zero trust and so on, uh, technologies.
But at the same time there are a lot of workloads these days that never touch even an end user. They actually go into application application and then you actually end up being hack because you are relying on the endpoint security product to kick in and do its uh, job and contain the risk and so on and so forth. And when it comes to the AI part, and I think this is the part that's getting more interesting and we've seen that in the report as well, there's a lot of adoption.
Everybody's trying to adopt ai. There's a lot of push for like adopting AI for file security as well, but it's only like 25% actually have like a formal process on how they can handle ai. And 29% are actually banning gen AI as part of the organization.
So they're like exactly the opposite sides or like less than a third are restricting access to ai but the quarter only have like a formal process out of the 70% that actually are allowing gen AI usage and so on. So then the risk becomes a lot more work. People are empowered to use gene AI to like simplify their work, right?
I can, I easily have a copilot or like have an integration for my email with the like of open AI Gemini, like GPT and so on so forth, right? But at the same time they're sending the data and the emails they might be like find them uploading to generate a report or representation for me and so on and so forth. And that increases the risk a lot more.
So it's a matter of like you are empowering, you give new tools to your organization, what is the risk associated with that one and how efficient are the guards that are put in place on that? And I think the most important part I saw like a very good, um, presentation a while ago where there was an entire revolution for cloud, the entire revolution for mobile and so on. The AI is the first one that nobody's pushing back.
Almost like everybody on the border organization are saying you need to adopt, need to adopt, right? But at the same time there there's a speed of the business that needs to be allowed to grow fast on the AI side and security is trying to find measures to contain the risk there because people are starting uploading even sensing documents and so on. Um, through this, um, again, chat bots and um, I know AI tools and so on.
Mm-hmm. Hopeful. That makes sense.
So coming back for a minute, these insider threats, are they actually malicious people who are going out to do something or is it just more accidental because people are not aware and as a result, uh, you know, we don't go looking for that as aggressively as we might, but maybe the bigger issue is the fact that well people are people and they're just gonna do stuff that's the path of least resistance, right? Uh, sure. So it's a mix of both, right?
Like I, I think we've all seen in the news in the last six, 12 months if no longer with like, uh, remote employees that are US based, but they're actually more North Koreans and so on and like how they're bypassing some um, employment background checks and so on and so forth, right? So there are some of those cases like cyber espionage and things like that, but I think a lot of them are, I don't want to call it ignorance, but it's actually trying to work faster, easier, better. And we, they don't realize they're actually exposing company to a risk, right?
So I want to say that a big chunk of them, I want to give them the benefit of a doubt, but yes, there are some inside traders as uh, sorry, inside risk as well where people have a malicious intent from the beginning. You talked about AI and how do I strike a balance there? 'cause I think we uh, do want people to use AI but we want it to be done responsibly.
And I think the issue is that sometimes they're not thinking through a sensitive information that might be in a file or just kinda uploading stuff to get some help from AI to help them write an email or whatever it may be. But um, is there a way to think about that smarter and maybe make sure that sensitive data isn't going out to the AI model that eventually might wind up using that to train some model down the road? Sure.
So two aspects there, right? Like the organization that do have like enterprise licensing and they're making sure they're not uh, uh, using their data. Like the organizations, the, I dunno, the providers not using their data for training and so on, but a lot of people are using their personal accounts, right?
A lot of people are even like uploading in free accounts and so on and even paid accounts. And I think that's where the biggest risk comes to play. Um, yes there are mechanisms to put in place.
So like regardless how much you're gonna trade the people, let's start with that. Like regardless how much you're gonna trade them, someone is gonna sleep, right? Like someone is gonna make a mistake.
It's very similar to like don't click a link and someone still in these days are still clicking like phish links and so on. Same thing here. People are gonna upload.
Now there are guard you can put in place, there are measurements, measures that you can put in place to make sure what is getting uploaded doesn't have sense information and so on. DLP market's been a while around for a while, like everybody's repurposing DLP for like AI guard rails, but it's not a one-to-one match, right? And I think it's a matter of like how well these mechanisms are put in place but also how, what kind information you allow people to, um, access, right?
And I think it gets back to that common I know framework on like how you look at these files and their risk associated with that one. Also how you look at the business from a performance perspective, right? If you're not using, I know AI these days, you're kind of like seeing almost like a dinosaur, but in the same time you want to be able to like restrict the risk, right?
So, which it still like still puzzles me is that we're going, even for us as like an organization when we go and we have like kind know a master agreements with very large organizations, there's a team that wants AI and there's a team like the legal AI risk that's restricting in those agreements, like what you can do with AI and so on and so forth. So they're trying to put those guards from both legal OSA technology perspective, but at the same time they need to have a fast adoption to that as well. So it's a very hard thing to balance.
But I do think that the taking a step back and identifying what, who can have access to what and what tools they are allowed to use as part of that will be, um, a more balanced way of actually approaching this than actually saying you have access to everything, let's say in our CRM and then, I dunno, download the Salesforce database, upload GPT to generate a new fenced report I can show in the next, I dunno, presentation or something like that, right? Like that will be a really bad thing. But at the end of the day, yes, people can go and like redact some things, simplify the content, anonymize some things, and then generate reports.
But the more work you're asking them to do, the less likely they're gonna do it, right? Because the entire idea is to move fast and so on. So, um, I'm not trying to preach now that everyone should go and buy enterprise licenses for these tools, but at the same time there is a risk in allowing people to use their personal or even like free accounts, uh, with that.
Mm-hmm. Um, People are sharing files, files probably more aggressively than, uh, anyone cares to admit without much care for various uh, regulations. But, you know, do you think the auditors are gonna get savvier about this and start cracking down a little bit more?
And um, and if so, maybe how long might that be? Um, it's still a relatively new thing, right? Like they, and I think this is still a, a very hard decision, right?
Like EU adopted like AI risk laws and so on, right? Like us adopted a couple of things and so on. So it's still a little bit of back and forth.
I do think that uh, 'cause we have literally this conversation part of our legal reviews as well with those domestic agreements I was telling you about and so on. I still think like in it should normalize in less than two years, to be honest. Like I've seen, um, a lot of pushback.
There's still some pushback that, but they already start like trying to figure out ways to like, I don't know, align. Um, there've been conversations. For instance, I'll give you a quick example with FS iec, if, uh, the audience familiar with FS iec, um, if financial services, information sharing and so on, there've been discussions on like how they should tackle AI risk and how, what are some recommendations if not even regulation to put in place on how to use AI as part of financial services and so on.
So already the industries are trying to look into like, I dunno, not necessarily regulate, but normalize how they're using these tools for them to be able to move faster as well. 'cause otherwise these organiza some organizations like Healthcare Financial and so have a lot of PIIA lot of information that it's very, I dunno, appealing for threat actors, right? And they don't want to be able to, like, they want to move fast on the ai, they don't have to be the dinosaurs that we talked about, but at the same time, they want to make sure that there is a guideline, uh, blueprint.
Let's say that they're using, that they're gonna reduce the risk and they're gonna get the buy-in from the organizational as well. Hmm. How much of this is something that requires a technology solution versus how much of this is something where, well we just need to train people better and get them to think about the fact that there is sensitive data in those files and they should be careful.
I mean I I feel like if, let's say if training would work properly, 90% of the cybersecurity industry would not exist. Maybe I'm exaggerating, I'm sorry, but I'm, I don't wanna make like bombastic statements here, but at the same time, like again, phishing is still a thing, right? Like the fact that people are still clicking on links that coming from we, I know random people and so on, or like even spear phishing person see and so on, those mechanisms are still working.
It means that training if a checkbox is not fully efficient, and again, you are as weak as your weakest link, right? Like there's enough one person organization to do it and you're gonna um, be exposed anyway. So I do think that yes, training is definitely mandatory.
You're gonna probably cover let's say 80% or so, but you still need to have a proper measures in place, right? Like you're not gonna eliminate the risk completely just by doing training or relying on people's common sense. It also seems like the bad guys are getting a little more sophisticated in the sense that um, they're stealing credentials and then they're logging in and hanging out for a while and maybe you starting to look like they're an actual insider that should be trusted and then they start doing stuff that is malicious.
But um, is it hard to distinguish now between an insider and an external threat? Well I would like to believe that, um, like we've seen that in the report as well, right? It, it's not an instant detection.
It takes a week sometimes takes even a lot more than a week to actually detect, uh, if you, uh, have a breach. Now the entire I important part is that once you have access on the network side, you're trying to lateral movement, you don't want to like, I dunno, start dosing left and right to see what you can get, right? You are slowly moving and try to identify a bit more and so on and try to see how much access you can get to like what relevant information and so on.
They will have the patience, right? Because you're going after the crown jewel, you're not going for like a, a small bit and so on, right? So I think this is where things become more tricky and again, I don't want to uh, call like doomsday or not, but um, also the way we're using AI to optimize our workload and so on, there was also report, uh, a report from Atropic, uh, couple weeks back on how they're using um, their cloud solution to actually try to build more malicious content and so on and like optimize their solution and so on.
Um, there's also been like a couple of, um, things on the software supply chain instead of for them to try to uh, get an organization, they're rather just like kind of poison one of the repositories and then they'll walk them in with crypto miners special sniffers or things like that as well. So there's been a lot more mechanisms where there are to some level like some blind spots for the organization, right? Because for instance, on open source, uh, libraries, the main focus in the past was actually vulnerabilities.
Do I have a critical vulnerability? I should patch it and so on. But right now a lot of them you're seeing almost on a daily basis, like this week has been, um, the rapport affected like 2 billion, um, uh, downs and so on.
So as you think this through, what's your best advice to folks or what's that one thing that kind of makes you shake your head and go, folks, we need to be a little smarter. I think we to like take a step back and look at the probably more holistic, right? Instead of saying that, hey, we have measures in place in for X, Y, and Z, it's more like, what is the risk for any of these data exchanges either coming in or going out and how we can, um, have a more holistic view on, on that one.
Because if we're just relying to have like, I don't wanna call them like point solutions, but there are some level, there are like point solutions without clear visibility like what they're doing, um, then you're not gonna have a good view. And I think this is the part that we had the, like a good conclusion of the report as well where people are un unhappy that, that they don't trust necessarily on how they have this uh, set up right now and they need to have a better, I dunno, overview let's say on like what happens in the organization and better control over their files as well. And this is not a data discovery problem.
This is more of a threat and, uh, security risk, uh, assessment than anything else. That's how I see it. Um, the long game, it's still, again, if email, like malicious files on emails, let's say it's no longer that big of a threat, but phishing is everybody's rushing to address phishing, but the threat actors are moving to something else to walk in the organization or like, I know compromise a user and so on and so forth.
So again, it's still a moving target, but from that perspective, you can like always move your focus one project toward the other, to more or less patch different, I know potholes instead of like looking to like how we can actually build a proper highway. All right. That sense, sense?
Well folks, folks you heard in here they say that sharing is caring, but you need to be careful out there because you don't know what you're sharing, you don't know where it might wind up. George, thanks for being on the show. Thanks much for having me, Mike.
All right, thanks everyone. You Guys in the studio.