SecureEdge SASE – Fleming Shi, Barracuda
Barracuda chief technology officer Fleming Shi discusses the launch of Barracuda’s new SASE offering SecureEdge. This new solution is delivered as a service, making it easy to manage and connect any device, application, and cloud/hybrid environment to secure users, sites, and IoT devices. Fleming also shares some highlights from Barracuda’s Spear-Phishing Trends Report about the continued growth of spear-phishing and how these attacks can lead to breaches.
Transcript
This is techstrong tv. Well, the great pleasure to be joined by Fleming. She, Fleming is c t o with Barracuda.
Good to talk with you again, Fleming. Absolutely. It's great, uh, to be here, Mitch, and Nice, uh, to catch up.
Yeah. It's been a little while since we've at least been in person. Uh, I guess it was year before last at, uh, R S A C.
So you've been a busy guy. I know we're gonna talk about some of the things that, uh, come out from Barracuda, but before, before we do that, would you, uh, introduce yourself, us a little bit about you, and for folks that who might not know who Barracuda is, I to believe there might be a few? Yeah.
Um, you what Barracuda does, Absolutely. Barracuda networks. Um, I have been with Barracuda, uh, since 2004, uh, and obviously, uh, did an intro about me.
I'm the Chief Technology Officer for the company, and we're here innovating all kinds of solutions from, uh, email protection to data network application security to protect our customers, uh, from cyber attacks. So, um, exciting times for us, uh, of course, um, you know, especially when we are looking at what we can put together with all the experience we have and, and make the user experience even more, uh, more approachable, more accessible to our customers. Yeah.
Yeah. There's definitely been a trend is, you know, point solutions evolving into, you know, a solution that involves a much more, uh, software element of that cloud software element of it, and managing it and doing those kind of things. So, I'm, I don't mean to jump ahead, but tell us about your announcement.
Yeah. So, uh, you know, first of all, if you think about Barracuda, um, probably if you know us in the very early days, we, we had, uh, spent firewalls and spiral firewalls, web filters, different kinds of appliances in the early days. But if you see the days that, you know, years that we have actually transformed into a very much SAS delivered cybersecurity solutions that covers all the tax services.
The one that I wanted to catch on, um, before everyone is, uh, uh, Barracuda just launched our secure edge, uh, SASSI platform, which is very comprehensive from the perspective of interconnecting your devices, your networks, your regions, um, and your, your offices, um, uh, all the way to actually securing the traffic all the way from, uh, you know, I would say transport level, transport layer, all the way to application layer, right? So we actually have, we're filtering capabilities in there. We have zero trust access control in there.
And, and in the past we had these things, but they were all different parts. Um, in this case, secure Edge really, uh, identifies a, a new platform allow us to actually serve our customer through a single administration, uh, uh, interface, and think about this as a platform for, for, uh, for really securing your users that could still be working in hybrid mode as well as your, your branch offices and, and multitude of hyper scaled environments you may have in, you know, in different hyperscalers out there. Mm-hmm.
So, that said, this offering is pretty, pretty exciting for us, uh, because we are, uh, we believe this is gonna make, uh, life much easier, uh, to, to, you know, uh, you know, walk away from, you know, existing N P O S, uh, circuits, the expensive deployments that, that helps you inter interact or interconnect your offices, right? Doing this will actually provide security and the full comprehensive layers of what we do, uh, in network security and access control, uh, for our customers. Yeah.
That's fantastic. I can't wait to see it. I, I'd love to get your thoughts, um, some more about the software part element of this, and the reason why I ask about that is everyone's concerned about budget.
Everyone's concerned about efficiency, making our jobs easier, reducing friction, helping security teams get, do more with less, you know, all of those kind of things. And I would imagine, you know, with that kind of a, a new interface in management software in the cloud that, you know, you're managing all these locations and configurations and all of those functionality together, console one dashboard, if you will, has to be a big plus. Yeah.
If you think about the evolution of how people connect, uh, their networks together, it's gotten to a point. It's really true hybrid where there will be people at home, there will be people using ISPs that you may not be, you know, comfortable with, but, you know, thinking about how to actually get those folks to be productive. And also, uh, one thing about hyperscalers, they, they grow very fast and they're always available all the time and all over the globe.
Uh, and that introduces, uh, attack surfaces that could potentially, uh, you know, uh, be very, uh, problematic, uh, from, from a view of the network flow perspective, right? And if you think through that, um, in order to, um, to, to handle a security kind of, uh, uh, uh, you know, kind of practice or even a, a security operations, uh, kind of capabilities, you need to find a platform that you can trust and you, you probably don't wanna have multiple brands and vendors in there, and that basically can pass integration issues and things don't fit together. So if you think through all that, I think, um, this is why vendors have been going after, uh, platforms, uh, that like, such as what, what Barracuda is doing right now is really kind of, uh, extending to multi-layered, uh, network protection.
Uh, also, um, identifying, uh, a solution that makes it easier for people to administer. Um, to that degree. We also have like a saka service through like our XDR platform.
We understand the, the need to actually, uh, harvest all the signals and telemetry, and you do some federation on the actual, uh, attack surface signals and to actually drive, um, you know, I I will say, uh, better ways to defend yourself. Um, this is why this is not, this is just the beginning for Barracuda in a sense where imagine I, I have a email security signal represents, um, a particular contact over that signal can be utilized in, in, in our secure edge to prevent a user with a device that potentially have been compromised from accessing assets in the network or your SaaS, uh, uh, SaaS applications. So, to that degree, um, I think if you think through all this, uh, it is one of the, uh, the important trends and, and, and, and vision that we have to make it, uh, a holistic in protection.
Yeah, That's a really good point, cuz it, it isn't just the software that's sort of integrated together into one, you know, one view. It's the data, the data sharing across all of that and knowing what, what happened here has an effect here, or can have a security control implement somewhere else. Yeah, exactly.
And, uh, and to many degrees, um, a lot of these things are built with software. Um, and, and one nice thing about our secure edge, uh, offering, one additional thing, uh, we can talk about is that in the past better could have had the secure connector that protects OT devices. Now we actually containerized that software made it available as secure edge, uh, SD one connector that can actually be deployed as a container in any environment that makes it much more flexible in, in interconnecting, uh, uh, a network or, or, or a, a node or server or, or a, a type of, uh, you know, environment into your secure edge, uh, cluster.
Uh, if you think about it, the mesh of, uh, all the devices working together, um, Listen, sounds like it might be really helpful in a cloud or hybrid, hybrid or, or on-prem and, and cloud situation, Correct? Absolutely, absolutely. And, uh, the other advancement is better.
Could have been producing SD one, uh, solution for a while. Um, we actually focused quite a bit on utilizing, uh, Microsoft Azure's environment in the backend, so working with their virtual one. But in this particular release, it's, uh, we also made it available through, uh, private cloud.
So you can actually deploy your, um, your entire setup through your, uh, pri private, you know, could be a data center, could be a, a environment that you choose, uh, to actually run it. So, uh, a the attachment to Azure is, is not necessarily a requirement anymore. Yeah.
Mm-hmm. Very nice. Very nice.
Well, a lot of advancements, all, all happening very rapidly. It's great to see. Great to see.
That's right. Yeah. Um, a anything else you wanna mention about that?
Cuz I wanna talk a little bit about your, your fishing report, you know, Fisher Report that came out also. Oh, Sure. Yeah.
You, uh, please, please look out for, um, you know, uh, you know, news related to our secure edge. Um, because if you have a, uh, SD one solution today that probably have, let's, let's say challenges related to security or even, uh, support, um, you know, uptime or any problems that you may have related to performance, uh, uh, what we have produced here is based on, uh, 20 years of knowledge we have in our, uh, uh, uh, cloud G and firewall and, and technology behind it is very robust and, and produce, uh, the best results for you. I have seen customers, uh, you know, reducing outage times from, uh, days to seconds because we have ability to, to four checking, uh, uh, all the other conditioning of the, of the connection and, and security, uh, parts.
So I think it's important to, to consider that, uh, as you move forward. Yeah. Excellent.
Good, good point as well. com. They can check out Secure edge there, of course.
Yeah, absolutely. Yeah. Fantastic.
Let, let's jump to the, uh, the annual fishing report Yeah. Uh, that you released. I think it came out about the same time that your spear edge was released.
Yeah. Any, any, any sort of surprises or new trends we're starting to see? I mean, we all hear about fishing spearfishing and, and, uh, you know, leading to ransomware and whatever else, you know, could happen from that.
But how real is it? How big is it? Is it, how fast is it growing?
Any, any insights into that? Yeah, actually the report, uh, highlights some of the numbers that continues to not surprise me, but just like, okay, reinforce the, the fact that the bad guys are very active. Um, like for example, um, uh, 50% of the organizations were victimized, uh, by spearfishing in the last 12 months, right?
And most of those fishing tend to lead to either credential theft that eventually leads to ransomware attacks, right? So if you think about fishing, it is the first thing they're doing. Um, I, I, I call it it out on the most, uh, left most element in the mire attack framework.
And, and if you think about that signal, uh, it could be, uh, very important to actually short circuit, uh, uh, uh, cyber coaching, if you can do that. So that prevents from lateral movements and actual ransomware attacks. Uh, the other thing is, um, I will say, you know, on average you get 10 suspicious emails or reported in organization, it, uh, departments on a regular, uh, workday.
That's like, that's every day you're gonna see this. And I can also relate to some of the conversations I have with our, uh, uh, you know, customers, uh, some of them, you know, get, uh, get attacked multiple times, uh, to ransomware. And unfortunately, the, the second time I also hear is due to, uh, Phish link, people clicked out and, and these are, these are basically just happening constantly.
Um, to me, I think this is, uh, one of the biggest, uh, area people can actually put investment in to actually stop the attack early. Uh, again, um, this year, um, uh, we invested quite a bit in, uh, in participating in federating some of the email signals. So some of these things we find, uh, are absolutely published, uh, in a, in a way that can be consumed.
So one example would be, uh, we're partnering with, uh, Amazon, Amazon Security Lake and utilizing the O C S F, uh, standard to publish a signal into the security lake. So when, when it becomes available, um, someone can actually take that signal from the security lake and utilize it for, uh, action. Right?
So, so those are things that we're doing. Uh, we believe, uh, uh, you know, fishing is gonna continue to be a problem. Yeah.
Yeah. On the rise. I remember seeing the stat from the report, it's like 66%, I believe, of all breaches were tied to initiated through some kind of spearfishing attempt.
Absolutely. They are targeted. I mean, they, they're effective.
I mean, they can be, they can be very effective. Right. Certainly a big threat.
Yes. Yeah. Um, I think if you look at the report, we also talk about the company organizational size, like how many, um, attacks you see based on the size of the company.
Hmm. So those are also in interesting to, to read through, uh, as you might be thinking, okay, um, you know, as my company grow, am I actually exposing more and am I actually having a higher risk? Uh, and, and the type of tools may have to change as your company, uh, increasing size and maybe even coverage globally.
Um, you know, that, that, that level of exposure, um, it's important to really get a, get a good handle on because, uh, what you had when you're smaller organization may not be necessarily, uh, sophisticated enough to protect you. Um, and I've seen smaller in terms of number of users, uh, in organizations, uh, uh, but large in operations under more attacks. So it's not just purely based on number of users you have, but of course, when you have more users, there's more, uh, attack surface in general.
Yeah. Yep. Yep.
Lots of people to go after. Um, I'm curious too, there was, there was a number in there I saw around something like a hundred hours that it takes to identify track down, remediate. Absolutely.
Kind of go through the whole incident response process, um, or if is a successful, uh, spear visual breach, I guess. Yeah, that's a lot. That's a lot of time and money.
Yeah. I, I, I think that's the other part. Um, I have seen, um, scenarios where customer have tools, but the signal is there, but it is not, let's just say it's orange, but it's not red enough, right?
Mm-hmm. Like, so, so what happened is, in those situations, unfortunately, um, you will start to have to, uh, analyze how much, uh, cybersecurity resource you need on a daily basis, right? Because if you're not on attack, they might be just looking at signals and me remediate them, but if you're actually under an incident, those, the resources requirement goes up like crazy.
So, mm-hmm. Um, two days to a hundred hours, actually, in many ways, I, I, I caught the, the, what, what what's being, basically being talked about is the recovery time objective, right? If your business is designed to, to last, uh, attack for three days, maybe a hundred hours is not too bad, right?
Like, but if your business requires you to operate and get to your database and work with your, uh, applications, um, maybe it's within 24 hours. So the tooling becomes really important. Um, and this is why Barracuda offers to, uh, small, medium size, uh, uh, uh, you know, enterprises through M S P, uh, uh, SOC as a service, uh, solution because we believe at some point, um, you might wanna focus on what you do, and when you get attacked or under some kind of stress when the signals is in orange, you might wanna mitigate that right away.
So you, it prevents the, the tail end of the, the right side of the Mitre attack framework, right? Mm-hmm. So that's, that's our scout, uh, stock as a service through our M S P, um, service, which is available today.
Um, so thinking through that, I'm glad you touched on a hundred hours and at the amount of time, uh, to actually get, uh, you know, get something moving and start recovering, right? Uh, but, uh, I tell you, some of the ransomware attacks, if you don't have the right tool, it will be, uh, weeks and months to actually get everything back. Absolutely.
Well, and two, I mean, u using a SOC service, like you're talking about, you know, the amount of times I might go through a ransomware attack or, or a successful breach that we have to deal with, hopefully, hopefully it's not a lot of times, right? So we don't do this every day, but stocks are very used to, uh, pursuing those, investigating it, giving you the data, help identify what's going on. So they do that every day.
So it's also the expertise that's valuable, I think, too. Definitely. Um, and the other thing I'm pushing for is phishing is obviously an important, uh, aspect of what we have to pay attention to, but also education.
So awareness training. Uh, one, one of the things I am pushing for a lot in my messaging and producing some features to do this someday we'll catch up on that, is to actually just in time training. Yeah.
If you are doing, I have heard incidents where someone got attacked basically 30 minutes after they got got the awareness training, which is simulated, right? Not the real thing. Uhhuh.
So it would be awesome if we get to a point where the attacks are being prevented at the same time you might be facing a blockage, you're educating you, your access to this link was dangerous because that link actually has a hidden hypo squatted domain, for example, in that situation, we could actually train the user, right? So if you do that level of just in time kind of education, uh, it will help a lot, uh, in the future of protection, uh, uh, and, and awareness training. So we're looking to do that in a, uh, in the near future as well.
Yeah. Okay. We look forward to some of that.
I wanna have you back, uh, cuz I'd love to pick your brain about ai, generative ai, what's happening. I'm sure you have some interesting things going on, so I'm just gonna put that teaser out there. We'll get you back on Yeah.
Chat about that another time. That's a very exciting topic. Then we can use it, uh, uh, in a positive way to, to defend our, uh, our customers and, and, uh, love to, uh, share that with you next time.
Okay. Good. Good.
We'll, we'll set up a time to do that. Well, congratulations on the, uh, secure edge announcement and, and launch. Absolutely.
And, uh, also another interesting report with some great data, useful data. Yeah. I think that's, you know, those kind of, those data points are great elements for people to maybe do their business case of why they need to, you know, invest in something or exactly more resource or, or use resources a little bit differently.
So it's good to have that data, um, that you can fall back on as part of your, your case, you know? Yeah. It, you're, you're absolutely right.
A lot of times the, uh, people only react to, uh, incidents, but if you look at the world, it is proven where the problem is now. So helping the CISO is helping the SOC team, uh, with data is well, uh, we're happy to provide more information. And, and one other thing about Secure Edge is that, uh, look forward the webinar series that we're gonna be, uh, be launching to talk about in more detail and share some of the insights, uh, related to Secure Edge.
Yeah, Fantastic. Definitely look forward to that. Now we'll put a link to the report, the fishing report in the description so people can get to that page to download it.
So Fleming Fleming, sheet CTO with Barracuda. Thanks again for stopping by. Look forward to talking again soon.
Thank you, Mitch. It's great to be here. Take care.