Remote Access Security – Renuka Nadkarni, Aryaka
Renuka Nadkarni, chief product officer for Aryaka, explains how remote access security is evolving in the managed secure access service edge (SASE) era.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
com. Use Chief product officer for ariaka. We're going to be talking about sassy and specifically manage chassine where we are in the evolution of that whole shift in Trend.
But before we get there, I'd love to get your opinion renew good about what are we seeing at the edge? Because right now, you know, everybody was supposed to have gotten rid of their vpns and we were supposed to have moved on The Sassy because of covid and the world was shifting and yet I still see all these vpns out there that people are still using. So what seems to be the hurdle to getting rid of vpns in favor of something that loses down towards that zero trust path.
We're all trying to get You know Mike that's a very interesting observation. We are we live in very interesting times. And what we are seeing is while there is a desire to move to Sassy while there's a desire to do modernization and digital transformation call it, you know new application era as I call it.
We are still very deeply rooted in what I call as infrastructure era where all the decisions and the way the businesses were structured were very network-centric. So all the users used to be in the offices all the you know assets or the applications used to be in the data center. So a lot of design the operations the way we thought about security everything was deeply rooted in the infrastructure way of thinking and as our you know as the industry in general and the customers are moving towards what I call is application era there are applications which are anywhere and users are anywhere thanks to covid and all the hybrid Workforce needs.
So now we are Trying to figure out how do I make this the decisions that we had made which are very rigid and very starting. How do we make them agile? And how do we make them adapt to this new reality of application era and that's where we see a lot of cloud adoption and so on but what we what we really believe is the conversions era which is instead of just thinking about compute.
We are now thinking about networking and security and that's what is zero trust Loosely speaking. But then how do you get to the applications? You do need something and VPN.
Is that something today? So there is infrastructure in places networking place there is equipment in place and we cannot just repent replace everything that we have. We have to gradually take that Journey from infrastructure area to application to eventually what we call is conversions of compute Network and security everything together.
To your point, we have had internal it teams installing all that infrastructure all these years. And of course, we have a shortage of not just it talent but especially security Talent. So do you think we're at some point where more organizations are going to shift towards that managed Services model and Reliant somebody else to help them co-manage the environment versus say yeah trying to roll everything themselves.
Yeah, I mean that's a great. You know, that's like one of the biggest challenges in back in the day when we talked about Advanced threats and ransomware. They usually targeted high profile customers like in financial and you know, you knew who the targets were but now the security attacks are very prevalent.
They do not discriminate actually anybody and everybody is actually subject to or you know an advanced threat today. 5 million open requisitions in the cyber security World, which we believe it's they're gonna be hard to feel even in the next five years. So where customers are at is they're pretty much don't have a choice but to figure out how to protect themselves and with this skill labor shortage of you know, people who can configure who can understand security there is really not many choices, but to essentially take help from you know, the outside it's not ideal Outsourcing but it's really to get help from Consultants or try to get help to Just design but also to manage day-to-day operations.
We also see a lot of new modern companies which are being formed. They do not actually have a networking team. So there is no such thing as a network team or network security team because they are using infrastructure as a service mostly for compute and they are actually offloading a lot of these Network as a service as we call it SD man as a service and Sassy which is actually combination of networking and security as a service.
So yes that is going to be more prevalent. It's like somebody mentioned this to me. I really like that analogy.
It's like you want sassy and It's it's about the party in your ordering up birthday cake and somebody brings to you eggs and flour and sugar. Right? So that's where the oil is today customers want the cake but most vendors are offering them either egg or flour or sugar which doesn't work.
Like do you also think that the way we think about manager Services has evolved because it used to be that man essentially Outsourcing the whole thing to a third party services provider and now it feels like to me it's much more of a co-managed kind of experience where you're handling the infrastructure, but the IT team is still handling the users and the applications and the things that go along with that. So we found some sort of happy balance between complete Outsourcing and internal it teams. That's a great way to call it Go manage.
That's something that we also use as a term and the important pieces the responsibility the accountability for the compliance the Regulatory Compliance making sure the audit is the auditorials are available all of that that always lies with the end Enterprise or the customer. So there are things you can Outsource But ultimately there are things that the Enterprises and the customers need to have and own and this is where it's very important to be able to have automation where you can automate what you need in terms of declarative apis or even a simple email or a template or whichever format, you know is agreed upon but once you do that all the provisioning all the network surgery all the routing all of it is done by someone else so you don't need to have the expertise on how to you know, configure a BP route. All you need to know is if I want to run my business successfully What is the customer sensitive data that I own and how am I making sure that it's protected?
So that division of accountability and ownership is very important and critical for the core managed aspect. Also seems to me one of the issues with the vpns we have is scaling and the amount of infrastructure at the throw at that and I never seen to know how many workers are going to be out of the officer in the office anymore. So has the whole equation become more Dynamic and is that kind of eventually finally force people to a different cloud-based architecture?
Because the one that we haven't placed today was great for when 5% of the workers were outside the office, but when half the companies out of the office just doesn't really work. Yes capacity planning is one of the most interesting challenge that we have been facing off lately because earlier when remote users were at home, they're expectations from the service was it was slow and it was difficult to access applications. It was acceptable because it was used it was used rarely when you're sick or you know, when this few periods of time and you want to work from home, but now working from home is a de facto.
So what users expect is they want to land like experience over the man. So I want to I want to have the same response time from the applications when I click on something. I want things to work fast just like they used to work when I was sitting in my office and it has multiple implications because guaranteeing the bandwidth and the user experience is actually one of the hardest problems to solve and normal security VPN Solutions never took that into account that was never part of the equation because vegans always wrote on top of the internet and internet as you know, the bandwidth and the latency Not predictable and are not deterministic.
So we are seeing an evolution where we call secure remote access solution, which is a combination of because of this demand capabilities a combination of guaranteed performance. Security which is a normal encryption that you do between end to end tunnel. So what we what we believe is getting the user from their home to the to the middle mile or to the cloud from SSE vendor or yaka Cloud one of those is actually the only variable now so what we do is we can have the user have same experience, even if they are sitting in some office in in China or in Japan to access the workloads, which are now based in say us west region.
So just like a US West employee would have an experience with the workloads in US West regions of Amazon a worker who is in China or Japan or any other country in the world. We'll have the same experience with low latency. And I think that's where we are evolving.
We are not the industry is not looking for vanilla remote access which just gives you a tunnel. We are actually looking for a complete customer user experience, which is like I said, experience on one right and there really should be no need to back all traffic through data centers that people are trying to access the cloud for if I can give them direct access so that somebody sitting in Green Bay Wisconsin can have the same application experience as somebody halfway around the world and they don't all have to live on top of a point of presence somewhere, right? That's exactly right.
What's your best advice that folks who are experiencing some sort of cyber security shortage, which I think is everybody but it seems to me the way folks are going about solving that problem is they're relying more on the it operations team to take more responsibility for executing security operations. So do you think is these two things come together that those teams will look at new architectures in new ways of providing access because ultimately they need something that is more converged. Yes, I think the the most important thing that we have seen change over.
The years is the organizational silos back in the day. There was it team there was a networking team network security and whenever vendors were selling the products they were buying there were different buying centers. They were different decision makers there was a different Cloud architect team and that caused a lot of operational overhead and it also caused a lot of you know unnecessary expenses which made the solutions overall extremely expensive.
So this is what I always tell customers is when you go from infrastructure to application the focus is on agility and you end up buying like four different things. But as you run them for a couple of years, you quickly find out that the cost of operations gets very high. So now in the conversions there are not on not only are we looking at technology integration.
We're also looking at operational integration making sure that we don't have written and processes. We don't Have written and her gown that is you know, probably actually getting in the way instead of accelerating the process. So to your point one of the things we we see customers who are more towards the right on this journey of the adoption of digital transformation.
One of the things we see is they have converged decision making they may still have different different teams, but the decision making is converged and they are looking at the the complete picture of how am I gonna get the most delightful customer experience? It's not about home and I get the best networking or how am I gonna get the best security in the world? It's really more customer-centric on the best user experience and the best application experience overall.
What's your best advice to folks or more importantly? What do you wish that they new going in when they make this transition to sassy that they learn the hard way. I think the first thing is to accept the except that it's a journey.
There are always people who have contracts with providers. There are you know appliances which have certain lifecycle like four to five years of yeah, you know if recycles so it's kind of it's really nice good thing that one son one day you just you know, turn on the button and say okay now I'm you know adopting sassy. So we talk about meeting customers where where they are we talk about if you have mpls and you was coming up you start from that because you have to do the complete and to end planning and it it may take multiple years.
It may take multiple cycles and all of these different pieces of the puzzle. How's your network design? Who are your providers?
How is it terminating? Is it going to the you know, the nearest walk? What is where is the nearest mom?
Is it secure and then what services are you offering on that particular service all of these need to be planned out and there are multiple integration options with different vendors. I think the vendors also need to play play nice with each other. There is you know, different protocols which are being set up and so on.
So so I feel it's very important to think of this as a journey and and try to move Move fast, but when you try to move fast sometimes to go slow. That's that that's what my advice would be. Sassy doesn't happen in a day.
Hey renuka. Thanks for being on the show. Thank you Mike.
It was a pleasure. All right back to you guys in the studio.