Silver Linings in Malicious Attacks – Adam Gavish, DoControl
Adam speaks to the silver linings in malicious attacks and how CISOs are beginning to fully grasp the growing challenge, and quickly realizing the need to address both human and non-human entities effectively and comprehensively in order to maintain a healthy SaaS security posture. In addition, Adam will speak to identifying trusted workloads, flagging high-risk events, and preserving productivity.
Transcript
This is texturing TV. Hey everyone, welcome back to Textron TV. I've got a new company to introduce you to here on Tech strong and Company we haven't covered before.
Right there co-founder CEO who puts also a first-time guest here. Let me introduce you all to Adam gavish. io is the website get that out of the way if you guys want to check it out.
Hey, Adam, welcome to Tech strong TV. Hi Alan, thank you for having me. I said pleasure to have you on we always love to hear of new companies or companies that are new to us coming into Market, but I always like to start off before we jump into the company a little bit about the guests.
So Adam, if you don't mind share share with our audience, give us a little bit of the Adam gavish story. Yeah, 100% I'd like to speak about myself. So I'm making a quick.
So I've been the US for seven years, but clearly I'm from Israel. You can stay by horrible accent. I've been the security space for a little bit over 18 years.
Now. I started as a network security engineer firewall route bonifers everything you put in Iraq. I installed probably moved my way up to something engineering hardcore back in engineering and then I moved to the US to become a product manager.
Most recently at Google Cloud security team. Sure. I have launching the golf Cloud solution to have corporate with Amazon and Microsoft over the federal market and you know when I worked there.
I had to collaborate with a bunch of third-party vendors to push the business side. I work with marketing agencies and researchers and Consulting and of course I had to share information with them over Google Drive and you know anyone wants to know a while Security will ultimately a ticket telling me. Hey, I moved up a permission.
They're not employed. And like what are they talking about? I'm working with them little legit and you haven't again and again and again until I got to a point where I'm like, okay, let's put an end to end.
I did. What a good googler. I would do.
I took a bunch of cookies. I want to infotech and ask them. Why did like that?
And it only look you know, we have compliance requirement. We have liability. This company information can be exposed Forever Until I add okay.
Why don't you have a tool that can fix it up? Why do you need me the end user to help you out everything your time and they said something like no it's not so simple. You know and and you know for good and bad, I'm Jewish and we hear somebody say it's not so simple immediately.
We want to solve it, right? That's like how you respond like, okay, let's fix it should be so yeah, so that way we started, you know to control at a very high level that way. I am able to a little boy.
I like to ski to run to what good movies. Good for you. Where in the US are you now?
I live in New Jersey. I just outside of okay very cool. Because I see you don't do a lot of skiing in Israel.
And if you're in well, once you're in the US you can get to ski places me personally I moved from New York my accent and I moved down here to Florida. We know the only skiing we do here is water scheme, but that's kind of ski. It's a different kind of skis exactly.
So Adam. So you I can't tell you. Look I'm an entrepreneur myself serial entrepreneur.
I've done several more than several Venture backed ones that fetch your back startups and but I've also over the years met interviewed dealt with as business development Corp development literally hundreds of entrepreneurs and founders. and you know the most common fact pattern I see with Founders is hey, I see a problem. I saw a problem.
I saw a problem not just at the company I was at before but I saw this come this problem at the company before it's been a problem. I spoke in a friend who have the same problem and and it's a problem that needs to get fixed and that it became a passion it moved from being a problem to a passion. Right, I'm gonna fix this problem.
And and it's in that maybe small way big way. I'm Gonna Make the World better for people like me who are living this and and people who deal with it. So, you know, I would say that's exactly the the kind of story the fact pattern that we see, you know behind so many startups today behind so many successful businesses.
That's what it often takes to get started. So, you know, we live in a world of SAS. We were talking off off camera.
and so many especially midsize but even larger companies so much of their infrastructure today is based on third-party SAS. A good reason it's convenient. Right.
It's there. They someone else went through the trouble of building it for you. It's usually more affordable rather than buying the whole Farm.
I can pay for it monthly. Right or maybe annually an annual contract based on a month, but it's cheaper. It's Opex versus capex right from a financial point of view.
And I think a lot of people say, you know what let it be someone else's problem. I just want the damn thing to work. I don't care how they make it work.
Right as long as it works, it's their problem. I don't have to worry about the infrastructure. I don't have to worry sometimes about the security event which you know in today's world.
The hairs on my what hair I have left stands up, you know when I hear that I'm not worried about the security. But let's talk about that. What do you what do you see you know with this and and how do you solve the problem?
So I see that. I have a different way of looking at it. Okay.
Anyway, like I think that you know people don't Milk The Cow anymore. They go ahead and buy milk. Right, they have two type of milk expensive meat and ship.
That's how fast is today. It's standard default. You know other choice, you know, I'm like on-prem.
It's like you don't know luxury to have an appointment. It's a big pain and so right now when your defaulted fast the question is What kind of tools those SAS application give you to first of all understand the exposure that you may have ongoing? Not because of your fault, but because of the general consumption of that right that exposure is very diverse.
Right. The question is what tool those ass up give you even if you have to pay for it in many cases you do have to pay for it, which is a shame but there's a shame that you you have to pay for SFO that will be very different basic but that's a different topic. So you have on one hand the tool the fast app give you on the other hand you have security team.
Who we don't have many of those the talent shortage right and theft it's just a fraction of everything they have to deal with. Endpoints identity Network inside of it infrastructure everything in between. But the biggest difference between those categories and fast.
Is that it's too obstructed? overly accepted in a way that you don't really have a lot of choices in order to protect it because if you enjoy to a cloud infrastructure like AWS, or either or gcp you have hundreds of security features. 100 for every single feature you have something you could put into in prosecurity whether it's if an encryption key or different network management, it doesn't matter you have it.
It not the case for fast. Why do we do about it? Right, I think at this point.
Security Executives have relied that whoa. We have to take control over that. And never wait for fast ecosystem to do that for us because that is not a revenue driver for them.
just not right now so we got to a point where it is a huge awareness about. Okay SAS security is a thing that we need to take care of. So that's good.
Then the question is. What approaches are there in the market right different? Then don't have different approaches and they deal with different threat mode of and those need to be matched with your security strategy as a whole.
right And so I think that secure the leaders need to take a look and be honest. With the fastest State and try to answer this simple question. How much data do you have in staff?
Who owns it? Of course what business department? How is it exposed internally and externally and sometimes even publicly?
What data sensitivity are we talking about for how long don't have failed simple questions? You can enter today in AWS? within a couple of queries You cannot answer them across several sat application.
You absolutely cannot even if you pay for all the features. so Before you even think about a solution. You don't even understand.
What are you solving for? And that's the fundamental where you start of security program. What am I filming for?
Does it make sense so far? You're not to me. It makes perfect sense.
I live this. I want to make sure it makes sense out for our people too. I think.
When I look at the SAS security problem Adam. Part of the issue is look if I only had one SAS application no big deal. I deal with that application provider and I I make sure I got it straight but I don't have one SAS application provided.
I have 30 or 50. I mean we interviewed a company a while ago. They called sasops.
Right that you need a whole team forgets just security you need a whole team to manage the average stats, you know the amount of stats that we're dealing. So now I'm dealing with 30 to 50 different SAS providers. And all of them only care about themselves, right?
They don't care how it works with their next sets provider. But I do. I need a comprehensive security strategy.
That doesn't just deal with these five. But it deals with all of them. right and You know, we're talking about access and access control identity and access control.
What what what's the posture of the SAS provider how it you know, how do I normalize that? to my own risk policies right because in some ways when you use SAS, I'm assuming their risk posture and that's not necessarily mine and and that May not work for me. Right if I'm in finance or some heavily regulated industry.
So these are the issues as I see that? Yeah, I am assuming that's what you working with. I agree.
We see the same issue about the stall on staff application. And I think it's been tackled. First of all from a financial perspective.
How do you perform cost optimization removing active licensed consolidate features? I do that myself for the control, right? I don't approve more app than usual if you don't need them because they're trying to build a sustainable business and from a security perspective.
I think that you need to ask yourself. Where is the critical data is being stored and consumed? Because some SAS AppSec.
Are not so sensitive to be honest something. That's fantastic. I mean currently.
You know what can be the title with like an email, but of course, I'm not undervaluing the important but like that's that app. Do not pose such a significant track. And right the whole game is they don't have access to critical data.
That's they unless you could use them to access other. exactly that that my point my point is that a good strategy would be hey, why won't we map? The South Africa we have in terms of you know, whether or not they have access to our core.
that story so if people log in to I don't know Trello with the Google Drive. credential that Grant Federal programmatic access to our Google Drive tenant And in that case, I want to know what are the actors is legit. with a trailer there Legit, you know app certified by the Google marketplace whether they kind of permission.
They require make sense to for the business use case, whether they have access permissions and if they even use those right that is super important because that can clarify and help you come up more ready for the tough conversation with your business stakeholders because at the end of the day, you have to go back to the head of X department and present them some confirming finding and come into an agreement Right because we don't work alone in security. We collaborate right I call it security business partners. Yeah, and so You know while the spirit of such active concerning it's important to nailed on the scope to truly solve the issue at first achieve a better Baseline if you like, right?
Yeah, so it could be the programmatic act that it could be the actual data. It could be the users that they have accurate. It could be who has added me and why they have admin all these kind of stuff should be taken into consideration and that lead me to my next point where We don't quite see a platform in the market offering all of that.
We don't right. No, I was living here thinking the same thing and we would say you would you would think that way where's Palo Alto? Where is craft like this killer of the world?
Well, they've been doing what are they doing? And so they are still having invested in very profitable businesses, you know zero trust and take access and point detection infrastructure security. Those are all very legit solution that you and I use in a day today.
The next one would probably be staff security time. Yeah. Well, sorry, I spoke to a lot of hundreds of entrepreneurs another Common Thread.
I heard what your biggest competitor spreadsheet. Do you know what I mean? That's this is a classic example people may be keeping spreadsheet.
You could see a security guy. I ever spreadsheet of all the SAS. AppSec that we're using here and I'm trying to track them right with their individual postures and you know different different differences.
And look if you can get into a market where your biggest competitor is a spreadsheet you're doing good because you should kill that right you should you got to be better than just a spreadsheet and and so it would seem to me. you know you this is the right to have a platform that does this is the right move you mentioned crowds to crowdstrike and maybe I got it wrong, but Strut who was the Strategic events or yet? It's strategic investor in due control.
Yeah, that would be cost. Like okay, so obviously God strikes saw this As a as a need in the market and made a bet here. Yet a hundred percent.
We are a hundred percent aligned with them on the strategy in the future of these specific domain. They do feel that an immersion threat and that's why they decided to invest and we very much happy about the relationship with them. Absolutely.
Yeah. It available and adopted by some of the best tech information institution in the world. Yeah, it's fully available.
um, and you know I put my hand down and being very humble about it. I'm not gonna brag about the solution. It's good.
It's working but I I'm leveraging this opportunity to speak with you not to do self. You know, I don't know. I understand like for people around there and say yeah, this is a problem.
I'd like to go check this out right now. My my goal here is to raise awareness about the need for a Sasuke you to platform 2023 to truly consolidate those Solutions and cover many Mission critical threat model to help the community again understand how we get the problem because multiple statically they know quantify it go back to business partner Katherine mediation plan thick reduce the attack surface and then hopefully automate ongoing that's the whole Grail. Are we there?
In some cases. Yeah in some case but no substitute event or to the qualify for such category as of yet, but they will be including us and that's the point right we have to continue to innovate and we have customers to go ahead and solve those and Problem because nobody gonna buy five different stuff through security solution. In the regulatory climate that we find ourselves in now and they're talking about new.
Control software supply chain, that's problems. All these things are hearing about new regulations in Europe here in the US. I think it's going to be important that we have.
A SAS compliance and I assume this is gonna be something if it's not into control you're gonna have to right for someone who needs to run a report about hey, am I handling my sass applications in a reasonable manner in a compliant manner, right and here's my report to show that we are. Yes, I do have it. So here's the thing though.
Here's what the tricky part, right? And we've been going through a bunch of compliance artists and whatever especially as a security vendor. It's much harder to achieve compliant on.
cloud service provider when you infrastructure because you have more to To enforce security. There's so much more to audit right versus staff with way more abstracted and yet you do have a lot of control in that especially across multiple ecosystem, but they don't go deep or nearly dip. As your Cloud infrastructure were the majority of the compliant geosteen effort in into bringing the evidence on the cloud infrastructure, right?
And while there is an effort on staff. it's not comparable in my opinion to if guys It's not there's a well but to be fair IAS now it's been around outside 2006 15 16 years, right that's dominance like this. You know, it's got some time to catch up.
We're way over time. I promised your 15 minutes. I think we're over 20.
I want to thank you for coming on though and telling us about Duke control. We wish you the best of luck. I think this is a really important area.
We're going to see more of this coming year. So congratulations. Keep up the great work come back on and keep us posted.
Thank you so much. And I really appreciate it and I like your Vibe. I'll have to show keep it up.
I appreciate it Adam gavish from duke control here on Tech strung TV. We'll take a break. We'll be right back.