Shadow Access Impact Report – Venkat Raghavan, Stack Identity
Venkat Raghavan discusses the new Shadow Access Impact Report released by Stack Identity. The report provides real world findings about how the 10 different types of Shadow Access – unauthorized, ungoverned and invisible access – has been exploited to breach cloud environments and exfiltrate data.
Transcript
This is Textron tv. Hi everyone. Welcome back to Textron tv.
I'm really happy to have Venkat Raghavan, and I probably mispronounce that my voice is not good today. I apologize. But Venkat is the founder and c e of Stack Identity.
Vankat. It's a pleasure to have you on again. How are you?
I'm fantastic, Alan. Thank you for having me. Most grateful Vankat.
I, I, I apologize. Raghavan is, is that the right pronunciation? Absolutely.
Perfect. You've nailed it. Okay.
Okay. Um, so Van got your founder ceo, as I said, of Stack Identity. Not everyone out here is familiar with Stack Identity, though.
Why don't we start with a little bit of your background and a little bit about the company? Yes. So my name is Van Raghavan.
I'm the founder and CEO O of Stock Identity. Uh, we are a barrier based startup with India based r and d operations. My background has been with cybersecurity for the last 25 plus years.
Uh, my first, uh, involvement with cyber, uh, was with a startup called dcom, uh, which, which the SCOM pioneer then a web single sign-on technologies back 20 years ago, which is now part of a bigger IAM suite. Mm-hmm. And so, uh, we were acquired by ibm and I had a chance to build up many security products within ibm, which is now IBM Security.
And then it spent three, four years in, uh, in Blue Code Systems, uh, transforming the portfolio, uh, into the next generation, um, advanced threat, uh, management product line company. I spent several years in AI research and Watson Labs. And then, um, I started the startup, uh, you know, three years ago, primarily on the basis of two, uh, two trends.
One is, um, I saw the, uh, the movement of cloud, uh, cloud native, the new era of cloud native starting. Uh, and it was a big, uh, challenge in terms of how do we operationalize risk and compliance for identities. And the second big trend I saw was the emergence of data clouds, like snowflake, massive amounts of data in the cloud.
So these two big trends, cloud native and large data processing, uh, all require identity and access and entitlements. So we felt that there was a substantial opportunity and a pain point the market for, uh, those capabilities. So we start our stack identity based on that intuition.
Excellent. Excellent. All right.
com. That's right. Exactly.
Okay. Hi, let's jump in. We wanna talk today, Venkat, about shadow access and its impact on cloud security, cloud operations, governance, et cetera.
Let's start with, when we talk about shadow access, what are we talking about? Shadow access is really a term, uh, which is actually an evolution of the term called shadow it, which a lot of people are very familiar with the term shadow it, which came about as part of the SaaS era. Mm-hmm.
The shadow access, we are talking about access that is unauthorized, unmonitored, ungoverned and invisible access to your cloud environments, your data, your software and applications. This shouldn't exist fundamentally. And so that's what we're trying to figure out is we call it a shadow access.
And we focusing on that. I got it. Um, let's, so let's now talk about its impact on cloud security, cloud operations and governance.
Yeah. I mean, shadow access, essentially identity, if you, if you wanna talk about shadow access more fundamentally, identity has become the new parameter in the cloud. That is, what I mean by that is that everything is spin up on the cloud as an identity attached to it.
Uh, whether it's your cloud services, whether it's your administrators, DevOps, anybody who operates in the cloud has to have an identity. And that identity is put entitlements, these entitlements give the identity permissions and privileges to do things. And so what we are seeing is a huge rise in the, in the number of identities that's called lot of access, lot of, uh, unauthorized access, lot of powerful access that is, can easily be weaponized by attackers to export rate data, uh, to conduct ransomware attacks and things like that.
And data has proven that, that the last, you know, 20 data breaches, everything has got a direct attribution to identity in the cloud. So that's what the impact is. So fundamentally, from an impact perspective, it impacts cloud operations, uh, cloud risk management, and cloud governance.
These are the three big areas where this has got a direct impact. Sure. Sure.
Look, in today's, in today's economic environment, anything that is adding cost, right? To our, it's a big thing in cloud, right? This whole, uh, finops kind of movement where we're trying to get a handle on cloud expenses is, is huge because there's a lot of people saying, you know what?
This, this cloud thing, for some reason, people thought cloud somehow was gonna be less expensive. I don't know anyone who ever said that cloud was less expensive. There are some real advantages that cloud offers, right?
Flexibility, burstability elasticity, uh, scalability. But it's not necessarily less expensive than, than a third party data center or your own data center. But nevertheless, there's a, there's a big spotlight on this.
And so when you get something like shadow access, you know, and we, and we're trying to cut corn pennies here and there, this becomes a big thing, right? This is a major focus, but in my mind, and I'm not downplaying how important money is, money's important, but the security risk of it, and your risk in terms of governance and compliance, et cetera, is probably a bigger potential impact even than the financial impact, right? And I think that's what people need to wary of and, and aware of A hundred percent, Alan, because fundamentally, the cloud is all about transformation.
And so you want to transform your businesses, you wanna monetize your, your opportunities here, and the cloud gives you the, the best agility to do that. So what happens is that identity becomes, uh, the huge, uh, you know, driver of the transformation because you're creating new services all the time. And, you know, and these identities connect cloud services with the data and other applications.
So what happens is, how do we create responsible ways in which the customers can drive transformation, yet manage the risk? That's where we are coming into play, is that, is we are helping customers to give them visibility into the shadow of access. They can take appropriate measures upfront, proactively, and, and at the same time, they do not wanna slow down their DevOps or the digital transformation initiative.
That's the, that's the, you know, you know, kind of the, uh, the, uh, the balance we create with our, with our shadow access, automation, detection, remediation technology. Agreed. Agreed.
Man. Um, so let, let's talk about how does Stack Identity help? How do you, you know, how do we get a handle on Shadow access?
I think the first thing is, you know, we give you awareness and, uh, we are releasing this report, the Shadow Access, uh, you know, impact report. It's under, uh, embargo in July 12th. We can give you a copy of that.
But the idea is to really understand live environments and create data, you know, in this environment. So we have taken, you know, 60 plus, uh, uh, cloud accounts, live accounts and built data that shows exactly what is shadow access, where is it happening, why is it happening, and how do I get handle on this? So customers can then look at this report and, uh, start to baseline their own environments, uh, in this.
So for example, uh, you know, we are finding some very interesting things, Alan, you know, we are seeing, for example, in the cloud, only 4% of identities are actually human identities. Mm-hmm. Remaining at all non-human identities, APIs, cloud services and whatnot.
A lot of automation is having that, that discussion. As you know, we're seeing, interestingly, a lot of the, have a lot of admin permissions, which you never see in old school data center days because of automation, people don't understand these things. And we are seeing almost 16% of the cloud accounts in production accounts.
We have highly privileged access, but essentially on account takeover for a data breach and whatnot. So these are all data points. We, we are finding out, and we are creating simple patterns for customers to understand at an aggregate level, this is what's happening, and your environment might be better or worse, but you can run an assessment tool against that to give you a sense of where, where it is.
And without visibility, you can uncover these things. So the primary thing we're showing is visibility and the impact report. Got it.
Now, I just want to make sure for our audience, we didn't confuse them. The report you guys have coming out is July 12th. Correct.
com. Exactly. Exactly.
Um, but some of the ways that you can start getting a handle on this now, Woodstock identity, that they could go to the website right now and start putting that Use. Exactly, exactly. There is a, there is an option to download, uh, a tool.
Uh, you can run this tool, uh, in your cloud accounts. You'll give an assessment of, uh, where the shadow access gaps are, and you start there. It's a, it's a free assessment tool.
You start there and start to work your way towards, uh, giving. You get the visibility first, and then you can start to figure out, what do I do about it next? Excellent.
You know, it, so I've been in security as long as you have Vankat, right. And as though it, it, it, it seems, you know, security is like dancing the chacha. It's always two steps forward, one step back.
Sometimes it feels like it's two steps back too. As soon as we get our handle on one kind of potential security risk, we see other risks coming up. Governance is always kind of increasing, becoming more complex.
Um, it, it's just the nature of the beast. I mean, it, you know, it, it's, it's, it's why it's what we do and it's, it's what we deal with. I want to thank you for coming on today's show.
Uh, you know, but for people beyond Shadow Access, people wanna know more about Stack Identity. Where else do you help beyond, beyond this kind of thing? Yeah, I mean, primarily we are provide an end-to-end approach to managing identities and access and entitlements across the cloud environments.
That's where we focus on, uh, shadow access is a term we use to call out attention to this problem. But the bigger problem is customers have today. The tools they have today do not address an ability for them to govern the cloud accounts.
And identity is the single biggest risk in the cloud environments because the cloud is completely entrepreneur identity and entitlement. So we are bringing attention to the problem, and we're bringing, bringing an automated approach to the problem. At the end of the day, customers can control their intimate life cycle of identities and access in the cloud environments.
That directly impacts their operations, their compliance and their governance. That's what we offer to our customers. Absolutely.
All right. Van Cat, thank you very much. I apologize for my voice being a little horse today.
It's been a, it's been a week. I think you were under the weather as well. I appreciate you coming on.
Come back, you know, maybe after July 12th when this report is out, we can hear what some of the audience and, and what you're seeing with it some more. Absolutely, Absolutely. Talk with Shadow Access.
All right. Thank you. Founder CEO Stack Identity here on Techstrong tv.
We're gonna take a break. We'll be right back.