Orca Security’s Neil Carpenter on Data Security Posture Management Challenges
Orca Security Field CTO Neil Carpenter describes the data security posture management (DSPM) challenges organizations face as cyberattacks against data lakes, such as the Snowflake platform, continue to increase in both volume and sophistication.
Transcript
This is Textron tv. Hey guys, thanks for the throwaway here with Neil Carpenter, who's a field CTO for ORCA security, and we're talking about specifically data security, posture management as it applies to data lakes. And in the case of Snowflake in particular, Neil, welcome to show.
Thanks, Mike. It's good to be here. You guys recently added support for Snowflake.
What's driving that? And Snowflake itself is saying that, well, we're gonna require MFA in the future, but it seems like there's multiple layers of security that need to be put in place here. What's going on?
Yeah, I think, no, no doubt. From our point of view, you know, Oracle is already a, a cloud security platform for all the stuff you're running in, in AWS Azure, Google, Oracle Cloud, Alibaba, sort of wherever you're running, your, your PAs and SA or, or PAs and ias, excuse me, workloads. Um, and one of the components of that is in all of those spaces, really looking at what data you have, how it's classified, where you've got sensitive data.
And so what we've done is expanded that to include Snowflake as part of that visibility. So not only can I see that I have, uh, I don't know, credit cards or, uh, healthcare identifiers or French ID card numbers or whatever in my VMs in data I'm storing in the cloud, um, in, in buckets of data. But now I can also see that where I've stored them in Snowflake.
And so we, there's, it's one part of the security story, right, is knowing what I have, where it is. I can't protect if, if I don't know it's there. And when we look at data lakes like Snowflake, you know, what's so common is, is we're, we're throwing a lot of data in there because we want to, we wanna store it, we want it to be available for our use, and we don't always have a clear understanding of what the taxonomy of that data is and what we're actually putting in there and how we need to protect it.
One of the issues seems to me at least, is that, um, there's a lot of complexity in these platforms, and more so than people think, and it's easy to misconfigure them. And sometimes we think that, um, you know, somebody did the right thing when they didn't. And a lot of the issues we saw in the last year seems to come down to just the people didn't understand how to configure these things, and then bad things happen.
How do we make all this stuff simpler to secure and, and what is the right level of understanding of our data security posture as it goes with that? Yeah, it's, um, that's a, that's a really interest, interesting question for me. Uh, I said for a long time, one of the things we're doing in a more general sense, but also here is taking a, uh, our constituents security teams and who know security very well, but don't always know cloud concepts very well in bridging that gap.
So being able to say, you know, I may look at any, any number of issues in, in the cloud and go, well, I, I understand why this is a problem, but I don't really understand how to fix it or how the pieces go together. And that's where a platform like Orca fills in the gaps and says, all right, this is a problem because we've, we've generated this alert. We're telling you where, what the problem is, we're showing you how to remediate it.
We're bringing it into a language that security teams understand. Uh, and, and for, for Snowflake, it's no different, right? That's, that's one of the reasons we look at this as being a really smart thing to integrate into our platform, is to extend that visibility and that reach for where are all my, where are all my sense, where in this case, where's my sensitive data?
What is it? How do we get to it? Uh, and being able to see, uh, all, all the sorts of things that go in there, whether it's data sprawl, you know, I've got the same sort of sensitive data here and here and here and here, and, and I don't know why that is, or simply illuminating it.
Somebody's put something outside of a, a security boundary. You know, I, I may have, for instance, if I have credit card data, I'm almost certainly covered under PCI dsfs and I have some very strict rules around how I'm gonna manage that stuff. Finding, finding credit card data, sitting in a Snowflake database because it's been copied from somewhere else and, and it's unexpected is gonna be a big, a big shock.
And one that I would rather get proactively by scanning it and, and identifying that data rather than reactively when something happens and, and it gets exposed. Where are we on this journey? Because I would poit that we spent a billions of dollars securing a proverbial perimeter, and we've discovered that, you know, basically the bad guys are just coming over the wall as they see fit when they steal credentials or whatever it is.
I think people understand conceptually that they need to kinda retreat maybe to securing the data itself based on it's criticality, but I feel like we run into challenges making that happen. So what exactly are the hurdles here and what do we need to do to get smarter? Yeah, I mean, you know, one of, one of the hurdles is, is simply velocity.
Like the industry is moving so fast into the cloud, into ai, and, and those are both things that data is driving, right? What am I using Snowflake for? Almost certainly some, some combination of both of those things.
Um, you know, if, if in, in a typical organization, in my mind, I divide it sort of into the business and the security teams and the business wants to go move forward and do these things very quickly. They want to generate revenue, they want to generate features, they want to, they want to deliver things. And, and the security team is having to figure out, how do I manage this whole process?
How do I, how do I bake security into this and, and get ahead of it? Um, you know, your question, where, where are we and how do we get there? I I think this is just gonna be a continuous, um, uh, cycle of things.
But there's a couple of key pieces. You know, I, I think the first one is having visibility into what's there. That's gotta be the starting point for any security team and, and whatever we're securing, if I don't know where it is, if I don't know, uh, what it is, I'm not gonna get there.
And I'll, you know, I'll tell you a quick story. I used to be an instant response analyst and, and lead, and we used to ask a question every time we went into a, a new security incident, we'd ask the, the company or the board we were working with, Hey, how many machines do you have? How many servers do you have?
So whatever was, was relevant. And it's said, we didn't really care. We were gonna find the ball anyway by the time we were done.
What we did care was the delta. Normally somebody would say, oh, well, we have 2000, and somebody else would say, we have 2,500, because they just didn't know. They, everybody was looking at different things.
And it, the, the bigger that difference was, the harder that week was gonna be on us. So, you know, I think that visibility is, is the first piece. And, and the good news is platforms like ours, we can get very detailed, very accurate visibility right off, right off the bat covering, we're talking about Snowflake today.
So, you know, covering in your Snowflake tenant, what, what databases do you have? What sensitive data's in them? Giving you all that visibility along side, what have you got deployed in the cloud?
How is it configured? What's in those workloads? Where's your other, I, where is your other data?
What does identity look like? What have you exposed to the outside world? Putting that all together into, into one picture.
Now the, the second piece of that then is, is really around posture and making sure that we have configured things correctly. Um, I'm gonna assist, uh, is, is talking a lot about secure by default and secure by design. I think that's a, that's an incredibly key piece of this.
And for our customers, it's often, uh, you know, now that things are deployed running, it's finding out where they weren't secure by default, weren't secure by design, highlighting those things and finding where, where those problems exist. We've got credit card data here where it shouldn't be. We've got something that's publicly readable, it ought not to be.
Those, those sorts of things. Um, you know, that's a, and, and that's a hard, uh, that's a hard set of problems, not necessarily because it's, it's hard to find those things. I think we do a very good job of, of finding all of them.
But the next step in there is if, if it's a, if it's a brand, or if it's, if it is an existing environment where we're bringing in a security platform, there's almost certainly a, a lot of problems existing. And so the third piece of, of where we are on that journey and how we get to where we want to be is about prioritization. It's about not just finding that there are 20,000 problems in my cloud, because that's all I do.
I'm gonna overwhelm all of my teams. Nothing's gonna get done, because you're gonna have this huge paralysis of this is too much stuff, don't listen to nail. So the next big piece is prioritization.
It's how do I make sure, if I can only do 10 things today and I'll get 20,000 problems, how do I find the 10 that are most impactful, most meaningful? And that's an area where we've been doing a ton of work, doing data, doing ingesting something like Snowflake into Orca is a big piece of that, so that we can continue to apply all of this, all of this context as priority. So knowing not just that we've got a misconfiguration, but it's a misconfiguration that affects credit card numbers or affects health info or whatever it is that drives the teams to say, all right, here's what I've gotta focus on.
Here's a misconfiguration. But it doesn't impact any data. There's no identities that are, that are elevated, there's no exposure, whatever else those I can get to later.
But these are ones that I really have to focus on. So for me, as I talk, as I talk to companies and, and organizations about the path they're on, those are the, those are the first things. It's, it's visibility.
I've gotta figure out everything I have. It's where do I actually have problems and how do I, how do I get, how do I get those nailed down? And then it's what's the full context of what's there so I can accurately prioritize and really run my business.
Now, once you get to past that, I think the, the next stage, like, you know, I'm giving people like in, in five minutes, I'm like, yeah, here's all this stuff that, this is a, this is a journey and a lot of work. But once you start to feel good about that, the next step then is, is really guardrails, uh, guardrails and paved paths, right? We call it the idea being move a lot of this stuff earlier so that things never get deployed.
Misconfigured, make sure that at least in your organization, you are in fact secure by default and secure by design. What's getting deployed is in good shape. It lacks critical vulnerabilities.
It lacks critical misconfigurations. You've applied appropriate sort of, uh, controls around data and around everything else there. And that's, I think when you, when you start to really hit your stride and become mature because now you are closing more issues before they ever become a problem, your security teams can get out of that hamster wheel of just responding and start focusing on larger problems, emergent problems, and, and really get to a good state.
So the organizations I know that have moved past that, that first visibility, find the problems, prioritize the problems into getting ahead of the problems, are I think the, the, the organizations that are doing the best job and, and they're really positioned to continue to grow as, as new technologies hit the market. And as their business grow, you know, their business wants to do, wants to drive new things into, into what they're doing, they're well positioned to get there. Data lakes are only one part of the issue, right?
I mean, it's nice that we're kinda centralizing the management of that data, but the data's everywhere. And then to make things even more complicated, doesn't the data lake kind of just create one big fat target and make it easier for everybody to kind of go after To, to some extent, yes. I think in, in 2024, and, and not just with Snowflake, but certainly with Snowflake, we did see that as a problem.
Um, we, we saw, so 20 23, 20 24, we saw some pretty big compromises of data lakes that I think were pretty embarrassing for your organizations. Um, this is an age old problem though, right? I, I wanna centralize things because the more they're decentralized, the more management problems I have, the more sort of complexity I have.
If I have five or six or eight or 10 different data stores, no, it's all fragmented. I don't know where anything is. I've got lots of, lots of problems there.
So we wanna centralize it. And then as you said, I've got one juicy target. I I think a lot of this is around, no matter what approach you take, it's, it's around first step posture management.
It's around ensuring, um, you know, that you've done, you've met you secure by design, secure by default. I, I feel like the end of this year, I'm repeating those words over and over and over again, right? It's, it's about making sure that I'm in a good state to begin with.
Um, and, and then for data, it's, it's, it's so much about access control. It's about, um, you know, ensuring that I've got appropriate protections. Um, you mentioned Snowflake moving to force MFA for, for Snowflake.
Um, it's, it's a good move, but every organization already has that option. Snowflake's just taking, just taking it off the table and, and making sure that they're all in, in the right configuration. So even though that's a future move today, you can be in a secure configuration.
You just have to take the time to make sure that you are. Mm-hmm. Um, so for me, I don't, I don't think it's like, you know, centralizing all my data in one data lake.
There's a lot of drivers to do that. You have to do appropriate threat modeling and figure out where you're, where you, you have potentially problematic configurations. You have to understand what, what the impact of, of compromise anywhere in there is.
How you take a, an approach. I, I talk with Bud Zero trust a lot lately too. Um, which is, I think an important philosophical, it's not a, it's not a product, it's not a technology.
It's really a philosophy in how we approach things. And I think you have to take the same approach here, right in, in looking at how do we, how do we make it so that any one thing that gets compromised is, is limited to just that being impacted, and we have time to detect it and make sure it doesn't move elsewhere. So in, in Snowflake, for example, how you manage administrative credentials that would have that org wide, tenant wide, um, access is obviously a, a major piece of, of your strategy to, to securing it.
You've gotta make sure you've got MFA and, and incredibly strong passwords and they're in a vault, and, you know, you've taken appropriate measures to, to manage those and to monitor the use of those, those credentials and, and, and to respond quickly if there's misuse of them. We hear, of Course, a lot about AI generating more data that needs to be secured, but is there some way to think about using AI to help secure the data that is being generated for ai, Um, maybe long term. Um, my, my sense right now, and, and this is both in terms of, of what or has done and we've done a lot with, with AI to both detect threats, uh, for our customers and to make security teams more efficient.
Um, but we've been, we've spent a lot of time really looking at what, what are the AI engines good for today? And right, we use machine learning, we use generative ai. People tend to mix them up today, but there's sort of two different disciplines, but they're both good at some things and not necessarily good at other things.
Um, you know, for us today, what they're good at tends to be finding things. Um, so we use like natural language search based on, on generative ai. Uh, and I think that does really well for, for our users.
They tend to be good at synthesizing data. So we use generative AI to, to help rate remediation, to tell somebody, and that's one of those I talked earlier about bridging what security teams know and cloud knowledge, we view generated AI as a, as a big piece of that, a security person can say, I understand this is a problem. I want to solve it, but I don't know how to solve it in Terraform, or I don't know how to solve it with this UI or this CLI tool.
And we can use generative AI to bridge that gap. I don't think we're at the point yet where it's sort of, you know, we have AI competing and there's an AI writing zero days and, and attacking things, and there's another AI adaptively changing configure. I, I don't think we're there yet.
I think right now we've got, uh, sort of a rules-based approach and a, um, a standards-based approach that says you should have MFA enabled for, for admins and for all accounts. You should have this configuration, you should have data encrypted at rest. You should have data encrypted in flight, and we can go and look and check that all of those things are true and that you are in a configuration that is best suited to, so to, to, uh, secure that whatever that asset is.
Um, and then I think, you know, that's one piece of it is, is what, what I always called, um, prevent breach. How, how am I gonna configure everything to make it hard to, to breach me on the assumed breach side That is, you know, always looking, saying no matter how well configured I am, I have to make the assumption somebody smarter than I am. We see that's a, that's an area we use machine learning at, at orca.
Um, so we'll look at, at known patterns of behavior. Now, here are bad IP addresses. If somebody does this, this, and this, it means they've dropped a web shell.
So that sort of thing. But we also use machine learning to build pat, build models of good patterns of behavior, standard patterns of behavior, and then identify anomalies outside of it. That's one of the areas I think that today, uh, is an important piece of defense and it's, that's gonna continue to grow as, as part of how we, how we protect things and, and we're gonna use AI to, to drive that.
Ultimately, who's in charge of data security? Is it really the security team or is it the people who are actually creating the data in the first place? Because Yeah, we've had this debate as long as I can remember, right?
The people who created the data, um, didn't have much understanding of where it was going and the people who stored it didn't understand what it was in the first place. They were just stored it. Yeah.
Um, yeah, so I mean, part of the answer to that is, is gonna be org specific, but my take on it is, in particular, as we move into the cloud and cloud computing and, and serve all of the things that come with it is security is, is more and more a shared responsibility. You can't point at any one person and say that's the person. Um, security teams sort of in my mind have the architects and the analysts, they have to write the policy.
They have to say, we're always gonna encrypt data at rest. We're always gonna do this, we're always gonna do that. Um, and maybe have an exception process, right?
Manage, manage all of that. Um, but I think our security teams are also responsible really for providing the tools and putting the intelligence in front of people who have to make decisions. And so in this case, it's about, you know, being able to scan, doing right back to Snowflake, it's about the security team having tooling that scans Snowflake and says, you've got critical data here, you've got sensitive data here, sensitive data here.
And then being able to say, that means you're gonna have to take these steps, you're gonna have to protect it in this way, you're gonna have to think about these sites. And so none of it exists in isolation. We can't just say the data owners have to know what's there and have to take appropriate, um, action.
You know, sometimes they don't know what's there. Sometimes they don't know what the appropriate action is. The security team may not have direct ownership over any of that, but they can provide the tooling, they can provide the policy, they can make sure that the intelligence is, is re reaching the right people.
And, and so for me it's really a question of, you know, once again, visibility. Like, I gotta, I gotta know what's there. I gotta know what's there.
Finding the misconfigurations, prioritizing them, and putting that, all of that in front of the people who can, who are, who have the ability to take action on it so that, so that we can make sure that it, our responsibilities get that Role. Well, folks, you're hearing in here, in some level, these are not new problems, but we are taking a more concerted effort to secure the data rather than just kind of securing the perimeter and hoping for the best. And to Neil's point takes a village, so everybody's gotta be involved.
Neil, thanks for being on the show. Thank you for having me. Looking forward to next time.
All right. And back to you guys in the student.