SEC Readiness Tips with Normalyze’s Abhinav Singh
Transcript
This is Textron tv. Hey, everyone. Welcome back here to Textron TV today.
Um, and my next guest on Textron tv is Abhinav Singh. Abinov is the head of security research at Normalize Normalize, uh, of course, a company founded and CED by my friend Amer Diba. Um, and we've covered them in the past, but Abinov here to tell us today or talk to us about some recent, uh, regulations rising out of a breaches or a series of breaches.
Anyway, um, at s you know, regarding SEC abinav, welcome to Tech Drunk tv. It's great to have you on. Thanks a lot, Alan.
Happy to be here. Yes. So, Abinav, before we jump in, I, I said we're gonna talk about this, uh, SEC res and stuff, but I always like to do a little, you know, background and kind of table setting.
So you are head of Security research at Normalize, and, you know, let, let's hear a little bit about your background and how you came to be head of security research over here. Sure, sure, Alan. Yeah.
Um, so yeah, I pretty much, uh, focus a lot on the security brains that goes into Normalizes product. Um, you know, the way customers would interact with the product, the security aspects that we want to show them, the value add that we provide them. So coming up with all those, uh, ideas and bringing them live into the product is what I primarily focus on.
Um, before Normalize, I was, um, one of the advisory consultants at AWS, um, Amazon Web Services. And, uh, prior to that, I also worked for four years at Netskope. I was part of the security research team over there too.
So that's where the connection comes from. Um, one of the, uh, co-founders at Normalize Robbie, uh, he was also the co-founder at, uh, Netskope. Um, got it.
So yeah, I was, I was, I was, I was pretty much doing a lot of, uh, uh, consulting work at AWS, and then I met Ravi and Am, and I kind of realized that problems that they were trying to solve at Normalize were exactly the ones that I was facing back with, uh, Amazon's biggest customers, hence. So it just felt like a natural switch to what to normalize. Good.
All right. Let's, um, you know, what we've mentioned normalize a few times, but it, it's still a relat relatively new company, and not everyone out here in our audience is gonna be familiar. So why don't, if you don't mind, Avanav, and I realize you're not from the marketing team and all of that, and, and maybe that's a good thing.
Give us, you know, share with us what, what is normalized, you know, you mentioned the problems they're trying to solve. Give us the normalized background. Sure.
Yeah. So the company primarily focuses on, uh, uh, data as the, uh, core component. Um, so, uh, anything circling around data security is how I envision normalize to be.
Um, and that's, that's what the core competency of the product is in. Whether that data is in your, uh, is infrastructure, whether it's in your SaaS infrastructure, whether it is on-Prem, or whether it is in technologies like Snowflake and Databricks, um, normalize helps you, uh, understand the data, classify it, and helps you build up a risk around that particular data. How can that data be accessed within the company or can be exposed outside of the company?
Um, what type of restrictions are there and missing from the data? So those are the key components that helps normalize build up, um, uh, uh, a risk profile around data. So it's more like an inside out approach where data is sitting at the center.
And from there on, we slowly pivot out, connect all the dots together to, um, uh, frame the picture for our customers. Excellent. Excellent.
And just before we jump into this, for people who wanna maybe go jump and, uh, get more information on Normalize, what's the website? ai, um, everything, uh, about the product, all the details, our architecture, the way we, uh, get deployed and, and, and things like that. All of that information is available on the website.
Okay. That's N-O-R-M-A-L-Y-Z-E normalized ai. Okay.
I'm glad we've got that out of the way. Ivanov. Let's jump in.
Um, so we're gonna talk about some recent, uh, actions from SEC around compliance and stuff. Why, you know, better than I, why don't you kind of frame it up for the audience? Sure.
I think a lot of it is around, um, um, elements like disclosing breaches and, and, um, the, the use of term material in, in that whole, uh, uh, recent ruling that came out of, uh, SEC. Um, I guess that is where the, the, the main focus has been over the last, uh, uh, couple of years. Um, so far it primarily targets, uh, public companies in the us.
So all the publicly companies in the US as per the new regulations, they have to make sure that once they have identified that there is a material breach in the company, they have four days to report it to SEC. Um, some feel like it's too aggressive. Some, some feel like that is a much needed step that SEC is taking.
Um, uh, there, there are some additional, uh, uh, requirements as well. Things like every year public, uh, publicly traded companies in the us they should disclose their security policies, things they're doing around data governance and so on. So really bringing up all those, uh, regulations, uh, and enforcing it strictly is what SEC is really trying and, and that is understandable.
Looking at the amount of cyber attacks that American businesses face, uh, I think, I think there is a lot at risk. Uh, you know, a lot of times it can actually become a national, uh, security issue for the country altogether. Uh, even the Biden government, they have been pretty active as well, and not just at the publicly traded companies level, but even at K 12 levels, we, you know, so they're, they're kind of covering a huge spectrum of audience over here, bringing up security regulations, making sure that they are strictly enforced, um, uh, for, for, for businesses that are running within the us.
Um, now a lot of this incentives around a recent breach with Blackboard, not everyone in our audience is familiar with it. If, and, and, and again, let, before you even start, let me say, we're not here blaming Blackboard or anyone, right? Yeah.
Yeah. When, when it comes to breaches, it's not, if it's went, we're all, could be the next Blackboard, right? Or some of us already were.
So I want to say that upfront, but why don't you give us kind of the, the, uh, particulars around that particular incident. It Sure. Uh, so Blackboard, the reason why it has been getting so much attention, I'll, I'll go a little bit into the incident itself, because it happened in early 2020.
Um, so, um, the company, uh, got compromised somewhere around February of 2020, and they realized that they've been breached around May of 2020. So there was this huge three month gap before they could actually figure out that they, they were under attack. And in this attack, um, uh, the threat actors, they were able to steal almost all the sensitive data that, uh, like bot had, uh, store for their customers.
First of all, uh, the company itself, it works primarily with nonprofit, um, and, um, uh, institutions and nonprofit companies, uh, who, who are primarily focused on, uh, doing work around good, uh, things like education, welfare and so on and so forth. So they had a huge customer base. They work with universities, hospitals, uh, a lot of, uh, uh, NGOs and so on.
So they had a huge customer base, and the platform was primarily used for fundraising, reaching out to people. So they had a lot of critical information about who the donors are, what kind of fundraising events are happening around, and so on. So, uh, and because they were also working with some hospitals, so they even had a lot of PHI information, so along with PII, they also had PCI, they also had PHI, so wealth of information.
So for any attacker, it was pretty much a gold mine to get into. Uh, during that breach, um, the attackers were actually able to copy out, uh, all the data. Um, now the pro, there were, there were a couple of problems.
First one I already mentioned, it took them three months to actually understand that there has been a breach. Uh, once they detected that there was a breach, the attackers were immediately alerted and they told Blackboard that, Hey, if you pay us, uh, um, uh, the ransom money, we make sure that we'll delete the copy of data that we have and we'll not release it to the public. And blackboards, uh, executive teams, they agreed to it.
They, uh, I read in the recent, uh, FTC report that came last month, it said that they paid around 24 Bitcoins, which was somewhere around $300,000 maybe, uh, back in 2020. Um, so they actually paid the ransom money and, uh, the second pro, so that this is the second problem, they, they agreed to paying the ransom, which is, uh, which is not really looked upon as a good move by SEC or FTC. Uh, so that was a second problem.
Uh, the third, third problem was, Let me stop you a second. Uh, Micha AB enough, back in 2020, it was sort of official policy, don't pay the ransom. Correct.
But we've also, I did a report last week, I forgot who I interviewed, more than a billion dollars in ransoms have been paid, I think, in the last year. So I, I don't know if that's still the official policies. Don't pay the ransom.
Oh, you know, especially That's if you have cyber insurance, right? 'cause the cyber insur, it, it really has become the cyber insurance company's decision. Yeah, yeah, yeah, exactly.
Yeah. Cyber insurance company decisions. A lot of times, um, companies will quickly involve, um, uh, a quick two day ransomware forensic team to come in and see what is the impact on the data, and quickly calculate whether the data is more valuable or can they just, just pay that ransom and get things back online.
So there, there, there are a lot of things, and as you said, you know, billion dollar worth of ransom pay, it means that things are still broken over there. The, the, the ransomware underground market is still flourishing, and it's going By way. That was only one sliver of the total ransomware market.
There's probably much, much more than that paid out. Yes, exactly. It's crazy.
Yeah, yeah, yeah. Probably there is, there is a lot out there which doesn't come into public live light. Mm-Hmm.
Um, so that, that was the second problem. The third one was, um, when Blackboard was able to identify that the breach, uh, happened in February, they found it in May. It actually took them end of July before they could actually send out a detail, um, uh, notification to its customer saying that, Hey, we have been impacted.
That was the third problem. It took them way longer than the regulatory guidelines of notifying about, uh, a breach in the company. Um, then comes the fourth problem, which I feel was probably the biggest problem of all of these.
They were all quite big, but the fourth one was where it, it kind of went really against them. And that was the fact that they, they kind of tried to downplay it. I don't know whether they tried to downplay it or whether the forensic investigation was still going on.
So they had no clarity. They just said that nothing critical was gone. It's only name, email address.
Um, those were the only information that were lost. No, PII, no PCI every, no social security, no credit card information, everything was intact. Um, this is what they said in their July 21st a release to all their customers.
And when the investigations happened, it turned out that all of these critical data was also leaked. So that is, that is where the SEC angle comes into picture now that, that's the, that's the problem that SEC is really trying to solve. They wanna make sure, um, because, you know, SEC primarily deals with all these things like, you know, uh, uh, money flowing into businesses, the impact of market manipulations and so on.
So they really want to control such, um, you know, wrong news or, or or wrong reports that might go out. So SEC, um, because it was incomplete investigation, they were not really clear about what, what, um, what was the extent of breach and so on. Uh, I think that's, that's what, uh, really led to a big, uh, lawsuit, which, um, uh, which was I think probably covered like in 49, uh, in 49 states out of 50.
So it was a mass, uh, class action lawsuit that was finally filed against Blackboard. And, uh, when the investigations happened, it turned out that yes, there was some serious lapses in security. Uh, Blackboard had encryption in place for the, uh, databases that were connected to the application, but whatever backups they were making of that database, they were not properly secured, and the attackers were able to get hold of that backup data.
So, series of problems that, you know, um, um, uh, probably there were, there was some lack of transparency as well. Some of the customers also expressed, uh, uh, discontent saying that they were not properly told about what's the extent of breach and so on. So that's the reason why it kind of became, uh, uh, a bigger issue.
And SEC then ended up finding them, and even FTC, uh, uh, uh, they, they also, um, I think, I think FTC did not impose any financial fines on the company, but they did publish a detailed report saying that, uh, there was some serious lapses that accompanied it. Hmm. Absolutely.
And I think, you know, I think they went easy on 'em not finding them because it was early. Exactly. Yeah.
Uh, the EU has, has done fines through this. So, so that happened in 2020, as you said now? Yes.
Let's, let's take a more recent situation. I don't know how familiar you are with Okta. The Okta, uh, breaches, Okta's a public company, right.
Um, subject to, uh, SEC, they, and they actually had multiple, unfortunately, multiple breaches. Yes. And, you know, we've covered them here at Textron.
Um, I don't think they, their disclosures met the, uh, the, the timelines here as well. But I haven't heard of any SEC action against that. And to me, that that's, so that's the thing about these kinds of regulations and compliance issues.
Either they apply to everyone or they, or if it's selective, like Right. You know what I'm saying? Yeah.
I get Blackboard did four or five things here, right? Yeah. From what I know about the Okta situation, they probably are guilty of most of those as well.
Yet we have not seen SEC action there. So a toothless tiger is, is no tiger. And yeah, you know, what, what do you make of that?
I, is it like, how are they deciding when to enforce and when not? Um, so there is, there is one fine print, which I don't, I, I, I, I, I don't really know if Okta is really using it, but most likely, I feel like that could be one reason why SEC is, is still working with them on the filings and all. And that, uh, fine print says that if the breach involves matter of national security, then you have 120 days of, uh, uh, uh, uh, time period before you can actually, uh, once you have identified that, that there is a material breach 120 days before you file it with SEC, if it is a matter of, uh, national security.
And because what happened with Okta clearly looked like, um, a very advanced, uh, persistent nation, uh, state sponsored attack, uh, they probably might have used that as an argument to buy up some additional time before the investigation can happen. And because the, the, the more interesting part with that whole breach is that it was CloudFlare who came up with, with all the investigations and, and, and they were the ones who actually went to Okta and told them what really happened. Uh, similar breach with Okta had happened, uh, a few months back as well.
Yeah. I don't know whether it was with CloudFlare or someone else. I, I don't recall that.
Um, but again, the same reputation of similar attack, Okta didn't realize that it was going on, and CloudFlare was the one who did all the investigations, and then, uh, they came back to Okta with, with the detailed reports. So, but I mean, uh, kudos to cloud, uh, Cloudflare for coming up with, with such a detailed technical guidance around that. Um, but I feel like there, there, there is still more to the story.
I'm sure Okta might be working with SEC on, on how that whole disclosure is going to look like, and if, if, if they're still figuring out if there are other companies like Cloudflare which might be impacted. Hmm. I guess the book is not finished yet.
We will have to wait for the last, last chapter. Yeah, it's interesting. But, You know, look, I've been in security 20, 25 years and, you know, I remember the debates around responsible disclosure back in the, you know, 2 0 0 4, 2 0 0 5 maybe.
And, um, and now, you know, it, it's, it's much more well settled, what responsible disclosure means. Yeah. But there's, there's been, uh, regulations on the books, not just SEC, that public company, I don't know if it was public companies, but that companies had to disclose a material, you know, to disclose a breach.
They had to offer credit monitoring and stuff like these. Right? Now, a lot of them were not at the federal level.
They were state laws. Right. And there was a patchwork of different states with different rules and regulations.
Nevertheless, it, you know, it is what it is there. Um, you know, I, I welcome, I think we should have one rule, and as I said before, it should apply to everyone. And everyone knows kinda where the lines are, what the boundaries are, and what they have to do.
I think that's Yes. Yeah, Exactly. You know, clarity.
Yes. Yeah. Yeah.
I, I totally agree with that, Alan. And, and there have been instances where SEC has now slowly moving from, uh, publicly listed companies to private companies as well. They have, uh, there have been, uh, i, I, I don't remember the name of the company, but there wasn't, uh, financial advisor firm, which, which got compromised.
And they had a lot of critical data about really high profile individuals within the us. So it's a matter of big risk for, for, for for sure, uh, such, uh, business owners in, in the country. So SEC got into action, it was a private company, but they still went to them and asked about all the investigations, all the reports and so on.
So I'm pretty sure slowly, as you said, you know, one law to cover all these spectrum of companies. I'm, I'm pretty sure, we'll, uh, I don't know when, but I, I feel like probably that is the end goal for SEC that they, they, they, they just don't want to put the public companies in the scandal. They are definitely the most critical ones because they're handling a lot of, uh, uh, data that is of national importance.
But there are so many small private companies, even, even, you know, company like Normalize. We are working with such big, uh, uh, public customers. And if anything wrong happens in the supply chain, if there is an attack or anything of that sort, where someone is able to, one, use one of the private third party companies and get into the, uh, critical data of a public company, who do you blame now?
Do you blame the public company or do you blame, blame the private company? So I'm pretty sure this, this, this, this, this book is not over. This story is not over.
And to your point, this will slowly, you know, slowly grow into other, other areas as well. Absolutely. Abinav, we're outta time.
It was a great discussion though. You know, I, I think, think people watching this understand, you know, what, what went on and, and, and what they're going to need to, you know, bring back, normalize into their own organizations around breach and breach disclosures and so forth. Thank you very much for coming on and helping us with us.
Best of luck back at Normalize. Say hello to all of our friends there, and we'll, and thanks for being on Text Drunk tv. Definitely.
Thanks a lot, Alan. And thanks for all your viewers as well. Okay.
Abhinav Singh, head of security research at Normalize here on Text Drunk tv. We're gonna take a break. We'll be back shortly with some more news and interviews and information.