SaaS Application Security Insights – James Lippie, SaaS Alerts
James Lippie, CEO of SaaS Alerts, talks with Alan about the Third Annual SaaS Application Security Insights (SASI) Report, which offers a detailed look at the major threat vectors and security gaps that exist in SaaS Application security targeting small businesses.
Transcript
This is texturing TV. Hey everyone, welcome back to techstrong TV. Our Guest for this segment is I think it's well, it's his first time here on Tech strong.
Let me introduce you to James Jim Lippy Jim is the CEO of a company called SAS alerts. And we're gonna welcome them on here and here a little bit about it. Hey, Jim, welcome to text strong TV.
Hey Ellen. Thanks for having me. Really?
Appreciate it. Alright our pleasure, man. So Jim, let's start off with a little of kind of the gym Lippy story if you know mine.
Yeah, so I'm actually CEO of sass alerts. I've been in the Text based since 2003. I was present CEO of an MSP managed service provider in Boston, Massachusetts.
It's called Thrive networks. We sold that business to Staples in 2006. And then so we're the first MSP to be acquired by a Fortune 100, which is pretty I stayed on Rand that business for them for another six years and then in 2013.
I got into the software business. So started selling software the main to service providers. So I've been on both sides of this fence and I joined a company in 2013 as president of Independence it we did Cloud workspace then from there went to caseya I spent her.
And from ended to 2016 to beginning of 2021. I was GM the senior vice president I could say yeah. It was learned a lot.
It was a great run and January 21 and became CEO of sassler. And we we started in January of 21 Allen within a service providers on the south Source platform today. I'm happy to announce.
We have 750 MSP. It's great platform and growing very fast. That's that's a really great story.
I had actually had friends who sold the company to to say. Well, we'll talk offline about it. Okay what I want to focus on stats alerts today, so Let's let's dive a little deeper into what stats alerts does if it's okay and how it works.
Yeah. So we allow managed service providers to protect and monetize the SAS applications. Their customers are using so think of us as a robotic employee.
And what's great about robotic employees is it they don't take vacation. They don't ask for breaks, right? And this robotic employee will scan a sass tenant like a three Office 365 Google workspace sales force Dropbox slack, right?
Those are sass tenants. We scan those tennis back and forth every 90 seconds and then only alert the NSP to what they have to act on and behalf of their customer so now and as you know, we're in an Edelman Haystack type of business most of the events that we see logging information and so forth every single day is, you know, really inoculus not much to see there but about 2% of the time Something happens that an MSP managed service provider needs to act on behalf of their customer you alert them to that. We're able to report on it.
And then our platform has a respond module that allows them to do set up customized rules engine essentially automatically responds to those security events. So we do automated remediation within the platform. Excellent.
Thank you for that Jim. I appreciate the the explanation and for we're going to jump into this third annual insights report you guys did before we do. Why we got people thinking about it if they want to go check out sassalerts and you know, maybe engage what what's the best website for that?
com. com, correct? Thanks, man.
All right. So talk to us about this acts application security insights report. Yeah, so when we started the business we've figured that we're gonna be collecting a lot of really valuable information a lot of really valuable data, right?
And specifically but by the way, we only sell through manager service providers just to be 100% clear. Do not sell directs the small mid Market or Enterprise customers. So what's great about?
Msps is that their primary customer is the SMB? Companies between you know, call it 10 to 250 customers, you know our employees I should say and they scale up, you know in some cases but for the most part they're kind of in that sweet spot call it, you know 50 to 100 users. So we figured look we're gonna have access to a lot of really great data.
So what we did is we created The Sassy report. Sassy is sasi SAS application security insights. And what we've done is we've aggregate every year that we've been doing this we've aggregated in anonymized the data that we get from our own platform.
So it's real this isn't survey information on this is real hard data. And we look at all the data that we collect and then we essentially summarize and to trends for the MSP and the small business Community if we're not aware, look there's great information out there for a lot of really great sources. They tend to focus on Enterprise.
And what makes our report different it's real data. It's not survey data and it really focuses on the SMB. So we've in this moving aggregated the 2022 results to create the 23 report.
We will be looked at 728 msps that were on the platform. They brought to us about 7,500 businesses. right averaging from One Employment averaging about 1550 users per customer, but Yeah, their companies on there as small as one user believe it or not all the way to you know, almost 12.
Oh, he's just I I served this in that market as well it is it's a mixed bag and 50 is probably that's a decent sized company within that. You know within that vertical or was it that horizontal whatever you want to call it, right that size. Yeah.
Yeah, so that and that's the core Constitution see that most MSP serves today. Yeah, and so we've been able to aggregate the data. Put together the trends and then published report.
So people have access to what we're finding. Okay, so let's talk about some findings. Yeah.
So one of the things that people always like to know is that you know, who are the bad guys that are trying to get in right? Yeah. So first of all, it's important to note that our platform looks at both internal and external threats.
Most people really focus today in most companies in terms of mitigation strategies focus on really external Bad actors and make in rightfully. So there's a lot of bad people trying to get into you know, companies environments that being said one of the things that we found is that we really need to be also as equally focused on internal threats and you know recently a story was published about one of our Midwest managed service providers company called ArcLight was able to identify a Chinese firing. Inside one of their customers.
It was all you know internal Espionage if you will and you know, our software was able to essentially identify the issue and then alert the MSP that cases with the authorities right now, but I bring that to light because we should be focused as much on the internal thrust as the external threat, right? So yeah, but with all that being said, you know coming back to where the bad guys they're trying to get in from a country perspective. So are people within countries trying to get into you know, small medium sized businesses.
So China is the number one. Bad actor. Okay, and these are attempts.
I'll give you the the list of folks that get in the most. Okay. So China attempts the most followed by Vietnam.
in the Brazil and Korea South Korea yeah, so that Is the list of folks that want to get in or literally, you know? Doing social engineering attacks. Brute Force attacks every single day on businesses all over the world.
And Jim I I feel obligated. Yeah. And that we're not saying it's these governments from these countries that are Behind These we're saying that's where these Bad actors are coming from exactly.
Right? Exactly. Oh, look there may very well be government involvement in some of them, but we're not, you know, we we're not saying that here.
Exactly, right. Thank you for clarifying Alan because I think that is the popular misconception, you know. Yep.
There aren't necessary nation state, you know activity coming from these countries on small businesses, but these are where the bag that actors are living right now. Yeah, one of the things that you know, people are surprised by because last year Russia was number one on the list in terms of you know, trying to get in and the various activity. that activity drops significantly this past year ever since the Ukraine war started and we believe it's because They got really preoccupied with you know, they have another Target.
Yeah, exactly. Exactly. So they're not focusing the question how much of that is state.
Response yes or not. What state state supported or whatever you have? Right but to be fair and like you Jim I've been in security while there was.
A decent of malicious traffic that came from Ukraine prior to the war. Yeah, probably dropped down those people have other things. They're doing Eastern European General had a lot of this kind of definitely definitely, you know, it's Christian the ransomware is and stuff like that.
It's a huge business. I mean, you know, yeah any business that makes a lot of money right draws a lot of folks a lot of Smarties money, right? And there's a lot more folks in those countries that are technically adapt and can figure out how to, you know, get into environments and extort money.
Absolutely, that's unfortunate. But true the company, excuse me, the country is that bad actors that got in the most this past year actually was a little surprising. It was India Vietnam.
China was number three. So they attempted most and got in the third most Brazil the Philippines. So, I mean I'm not gonna say I'm shocked.
I'm not shocked right again to the thesis that where you get a lot of technically adapt I don't even want to call him smart necessarily because I don't think smart people should do stuff like that, but technically a debt people there's a lot of them in India and Okay, so not not a surprise there. What kind of what kind of attacks were they? I don't know.
I haven't seen the report what kind of attacks were they do a gym and which ones like were the most successful kinds of attacks? You know? Yes.
Yes, so it's traditionally it's Brute Force attacks. So a lot of password spray type stuff and we can see in the pattern of data that we have. There's a lot of reconnaissance that goes on.
Um, and those are the people that take their time. Through the reconnaissance and then apply the you know these popular methods. they can be quite successful because one of the other findings in the report one of the reasons people are so successful is only 32% of small businesses are actually applying multi-factor authentication to their environments.
So we're making it much more. We're making it easier on them than it should be right because we're not we're not adopting tried and true methodologies that can mitigate the risk. I mean, that number should be a lot closer to 100% than 32% Um because MFA is a known.
Known tactic we can leverage to mitigate risk, right? So that's that was certainly. Interesting finding and one that's disappointing and hopefully that number will go up next year.
cool Jim we're believing or not coming up on time. I apologize, but I got to ask you a question because I see it, you know testing a shadow on so much of what we're seeing here like AI the chat GPT stuff. How is this affecting?
What you what you what you're seeing on the front lines? Yeah. well The good news is it helps a good guys in the bad guys, I guess so it potentially equally right it's not good one way or the other right?
Like they have access to it. We have access to it. Right?
So we're gonna try to leverage it to protect businesses and they're gonna try to leverage it to compromise businesses, but we all have access to it. So like we In our business, we're leveraging, you know, we're in the process of leveraging some of those Technologies today to make our platform that much more robust. So I think in the end.
It'll be a you know, a net equal scenario zero zero some zero some exactly but it will but look it's out there and it's gonna become more pervasive for sure. Absolutely, Matt. Hey Jim.
I want to thank you for coming on here today and giving us the information enlightening us. com. I assume they could get the report from there from the website.
Yes exactly. What that's alerts sells to msps mssps right to channel only play. you can't go sign up as a sasolar customer, right, you know as a direct and Well, if you're in MSP, I mean, excuse me, if you're in SMB you may not have the resources really.
To make use of it. Anyhow, but Jim keep up the great work man. I I you know, we I actually in a previous company operated in mssp aimed it.
Yes MB market so I know yeah, you know the space it's it's good work you're doing I we appreciate it and come back and keep us posted. Absolutely now. Thank you so much for having me.
Appreciate you. Our pleasure. All right.
Thank you. com here talking about SAS application security insights. com.
We're gonna take a break on textrong TV. We're going to be right back.