Protecting Sensitive Data – Ravi Srivatsav, Inside Out Defense
With the increase in layoffs, quiet quitting and potential for increase in nation-state espionage to steal IP, as China gears up to go after Taiwan, the threat of insider risk is fueling cyber attacks as companies need to turn inward when assessing cyber risk.With the ability to leverage and increase privileges for credentials and move laterally within an organization, Ravi Srivatsav, CEO of privilege access abuse company, Inside Out Defense, is working directly with CISOs to show how employees, current and past, are potentially accessing sensitive data.
Transcript
This is Techstrong tv. Hey everyone. Welcome back here to techstrong tv.
I've got a a, it's a new company for our techstrong TV audience, never been on before. I want to introduce you to, I want to introduce you also to Ravi Shva, and if I mispronounce, I apologize. Ravi is the c e o of a company called Inside Out Defense.
And Ravi, welcome to Text on tv. Thank you so much. It's an honor to be here.
Our pleasure to have you on. Ravi. Um, we're gonna get into Inside Out Defense, so we're gonna talk a lot about insider threats and risks today.
But before we go there, I wanted to, you know, you've not been on before, you're an unknown to our audience, who's Ravi, right. Give, give us a little bit of your journey. I've been a, a technologist through my life.
Uh, been a programmer, started my journey at IBM m and Microsoft. Uh, I've, this is my second venture. My first venture was in the area of DevOps.
Um, I've served as a Chief product officer in the telecom industry before I was a Chief Product Officer at N T T, uh, a group, but is based out of Tokyo. And most recently I was a partner at Bain and Company. Sure.
Very famous company. What company were were you with, with DevOps? Uh, the company was called Elastic Box.
It was acquired by St. Inc. Sure.
com. That's Right. And, uh, elastic Box.
They were ear one of the early, one of the early players there. Um, we've done webinars. Yeah.
That takes me back a couple of years. Anyway, talk to us about Inside Out Defense. You're the ceo O are you the founder, co-founder as well?
That's right. I'm a co-founder of Inside-Out Defense. I play the role of A C E O in the company, but at the end of the day, we are all technologists, programmers, building a state-of-the-art technology.
My co-founder, um, is Veka Toi, uh, p is a practitioner himself, uh, was with r s A as a chief architect of Net Witness was the head of engineering at Schneider in the I o t, uh, security ISSA 99 space. And also a, a practitioner in the area of healthcare compliance at trio. Um, we started our journey about a year ago, uh, primarily based on the problems that we've all had as practitioners, despite millions of dollars being spent on security.
Our fundamental quest was why is it always a catch up game for us? Um, it, um, um, the more dollars that we invest, there's always some gaping holes in the industry. Um, so we were, we were in the quest of solving that particular problem.
And, um, we very quickly recognized that privilege access abuse was at the center of all of this. And, uh, it was validated again, uh, this year by Verizon's D B I R report that, that is at the, uh, center of the problem. And, um, we said, okay, how, you know, we need to re-look at this particular problem because if you go about solving the same way of plugging holes, you're not gonna solve the problem.
Uh, so we have a fresh perspective on how to solve that particular problem, and we are out with a solution. Excellent. Excellent.
Excellent, excellent. All right. So look, I, we've heard the term insider threats, insecurity for a long time.
And look, when I first became aware of it, it was, it was a lot of disgruntled employees, right? Where your typical sort of insider threat and, you know, uh, a lot of the early, uh, data leak prevention d l P providers, right? That was a big focus for them, understanding what employees are exfiltrating out of an organization, right?
What are they downloading, what are they mailing, what are they uploading? And, and, but it was primarily disgruntled employees. But that, you know, that was also in the world where we had kitty scriptors and, and you know, we didn't have the organized nation state stuff that we have now.
We didn't have the really kind of organized crime element that we see in cybersecurity today on a worldwide basis. We didn't have the financial mm-hmm. Kind of, uh, cause you know, in my mind there's nation state espionage, but there's also industrial espionage.
And, and sometimes they're very closely related, especially when you're working with countries where they own the corporations that are producing industrial inventions as well. And we're not naming them by name maybe, but you know who they are. Um, it's, it's changed that whole, it's, it's a game changing thing for insider threat, right?
You, you're not just worried about someone downloading some files to their thumb drive and walking outta the office with it. Talk to me about it. Yeah.
Now, thinking of this problem as an insider threat or an external threat actors, um, leads us to a wrong way of actually approaching that particular problem. Now, let's l take a step back and understand what actually happens inside an organization, um, whether it's a malicious insider or it could be a human error. As people leave organizations, you see a bunch of mishaps, like they choose to steal data, as you mentioned, uh, for their next role.
Or, uh, without a proper foolproof, uh, decommissioning of the users. There is a residual footprint, um, of these users across their footprint, across the perimeter of the organization. It's an open invitation for nefarious actors to take advantage of the privileges that are associated with these identities, and they leverage that to cause destruction to the organization, like, uh, data exfiltration.
Um, from our perspective, it is, this happens due to a lack of governance structure put in place from a privileged standpoint of view. Now, um, take an insider, for example. Um, if they fall prey to a phish attack or a social engineering scheme, or, uh, it could be a blatant human error.
Uh, I talked about the, uh, idea of these privileges being, uh, exposed in the open. It is open for malicious outsiders. Now, leading to data exfiltration, in our experience, we have seen employees leave organizations.
And in the process, their residual footprint that I talked about is taken advantage of. You saw in the recent example with a failed bank where the employees stole the data as they left the organization. Now, this malicious, uh, if these malicious external actors are state sponsored, um, they are taking advantage of the greater LLMs that are available, where that could be, they could be a creator of these or users of these LLMs as well.
Malicious actors can cause greater havoc to these organizations. So understanding that the problem that we live in the world with a remote workforce, remote operations, and an ever increasing attack, uh, surface, uh, and patterns, we need a fresh look at this problem where the problem is the solution should look at a way of, um, preventing the attack chains. Um, I'll, I'll pause here to get your reaction.
Yeah, no, I, my reaction is you're dead on, right? This is, this is exact exactly what we're dealing with. My, not my fear, but my, like, what my gut tells me and what I've observed is that the, like, in much of, as the threat becomes more sophisticated as their means becomes, uh, better, higher, it beco, it, it, it almost sometimes feel like I'm fighting a losing battle.
And I don't mean to be a pessimist, but it like, can we, can we stop this? Can we, and maybe the answer is no, we can't stop it, but we, we've gotta be able to react to it better, and we've gotta be able to recover from it faster, right? Maybe we shouldn't fixate on stopping it, but it just seems like it, this is a really hard problem.
Um, it is a hard problem, and it is evident by the number of companies that are trying to solve this particular problem, right? Um, the, the market is crowded, the messaging is very crowded. But, uh, to answer your question, um, when it comes to attacks on privileges, it's a here and now problem.
A minute late is a little too late, uh, because an nefarious actor needs very little time to gain ad take advantage of that, uh, privilege that has been compromised. Um, now, in this world that we live in today, every user is a privileged user to some extent. We have access to both our, uh, internal applications, cloud environments.
Employees are there on SaaS applications. So your behavior is, um, of your employee is different across all of these environment and at varied level of privileges. So, so far the problem has been looked at, the solution space has looked at, okay, so how do I, uh, plug the, uh, gaps in the market?
So how do I understand, uh, who has access to what, what kind of controls can I put in place so that I can have them have the least privilege at all points in time? The reality is that all of these frameworks and, uh, hygiene is extremely critical. But you also need a solution that looks at it from a holistic perspective.
Who is this user? How did they obtain the privilege and understand every single access request and give, uh, a proof of trust, um, for every single access request? What I mean by that is making sure that the request that is coming in to access a resource is coming from a known entity that has a good intent.
And you have to determine that intent. Gone are the days where just because I was, uh, in the highest end in the totem pole of the organization, from a role-based perspective, I had access to everything at the highest level of privilege. But irrespective of who you are, you have to determine the intent of that particular user.
And if it is nefarious, you have to have a realtime detection of that and an inline remediation of that particular access request. And that is exactly what we do. So to answer your question, is it solvable?
Yes. With the advent of, uh, data sciences, we are in a position to put a, get a clear perspective of who this particular user is, how is that privilege being used? Is that malicious or not?
And you can detect that without causing any disruption to the business in real time. And of course, have a remedial solutions in line. Just know, just knowing that there is a problem, um, uh, causes a lot of alert fatigue in the organization.
If I, if I am in the SOC team and I'm getting a million alerts in a day, there's only that many alerts that I can actually attend. You need a solution that can actually detect this in real time and remediate that also in, in line. Fair enough.
A agreed, Robbie, 15 minutes goes incredibly quick here, and, and we're, we're kind of running low on it. Before we go any further, I want to make sure we've got this out. com?
Is that, uh, no, no hyphen or anything, or There is, Uh, it's one word inside out. com. Okay.
Now for people who want to engage with Inside Out Defense, what, what's kind of the on-ramp? How, how do you engage here? Um, so we are going to be out with a, a freemium version of the product for people to try out, uh, before they engage with us formally.
But, um, our onboarding process is fairly straightforward. We give you a an instance, uh, we are a staff solution. So we create a tenant for you where you can plug in your environment, see how vulnerable your organization is, understand your user footprint, uh, where all have the proliferated across, uh, in the perimeter of your organization, what are they doing at all points in time in a single dashboard.
And then, uh, the next step is of course, you can start your remedial policies that you can actually build into the product. Excellent. And, um, you, you mentioned this, uh, freemium version.
Any I timeframe on that? Yeah, we are planning to launch this in the first week of July. Listen, just about less than a month from now.
That's Right. Because, you know, by the time, I mean, we recorded this, but by the time it plays, it'll probably just be two weeks or so. Excellent for that.
That's excellent. All right. Hey, Ravi, I want to thank you for coming on text on TV and, and discussing, you know, the new flavor of insider threat and the risk it involves.
And, you know, uh, at least there are companies out here who are recognizing it and trying to come out with new solutions on, on solving this hard problem. Well, thank you so much for the opportunity. Thank you.
All right. com. We're here on Tech Shrug tv.
We're taking a break. We'll be right back.