SSE Platform – Gil Azrielant, Axis Security
Alan speaks with Gil Azrielant and learns about Axis Security and what they bring to the market.
Transcript
This is Textron TV. Hey everyone, welcome to another techstrong TV segment. I really happen to be joining us from Tel Aviv today.
Jill asrelent Gillis with access security and he's going to tell us all about it. Hey Gil, welcome to text truck TV. Thank you Alan.
It's great to be here. It's great to have you so Gill. Well, let's start with let's let's start a little bit about who's Gill.
How did you come to access and and then from there talk to us about access. Absolutely. So my name is Gil.
I'm co-founder and CTO at access and and I've been a developer and a hacker for as long as I can remember. Mostly mischievous stuff growing up, but then I you know in Israel you have mandatory military service and what was my time to serve I was picked up by 8200 which is the Israeli equivalent of the NSA with the offensive and defensive cyber security task forces for Israel's intelligence. So then you know, that was when I got into the pros and I was part of one of the biggest and most sophisticated offensive cyber security organizations in the world.
Um, that's where I met my co-founder and many of the team that helped us build this project this company and later on. I founded my own consumer company that didn't go as well as I expected while my co-founder and many of my co-workers here joined fire glass which is which was the early web isolation technology. That was later sold to semantic.
Many great lessons on what to do and what not to do when building an Enterprise grade security product. We then all got together to think about how we can use our knowledge use our expertise and experience from both offensive and defensive cybersecurity to make a dance to do something great in the world, and it was very clear to us that access remote access but access in general Is very flawed and it is oftentimes the weakest link of the attack kill chain where many attackers and Intruders go in through and that's how we kind of got around to set ourselves to solve this problem in a way that was not solved before in the world. Absolutely.
It's a great story. You know, first of all listen. A Serial entrepreneur myself.
I've been starting companies for 30 years. and someone much smarter than me a mentor of my told me very early on you learn more from your failures than you do from your successes. Right.
So the fact that your first, you know Venture didn't work out as well as you wanted it to work out in the long run you and I'm sure you're already realizing it now at access the lessons you learn there will serve you very well, right it access to wherever you go going forward. You. Don't forget those lessons.
I I do so look not everything. I've done been great crazy successfully either but Anyway, but that's the light of the life of an entrepreneur right? That's that's how we learn and how we grow.
Absolutely, keep us working. That's what's not never make the same mistake twice and that's how it goes. If you're gonna fail fail fast get to know fast and move on.
But anyway, hey that but that's a great story and I we appreciate it very much. So now with access security right, you want to tackle a big problem as you said but I'm gonna ask you if you could frame it for our audience. Like that's you.
What was the mission? So we saw that the modern Enterprise uses between four and eight different solutions to provide access to their systems. So different ones if it's managed devices or if it's unmanaged devices different ones, if you're going to the public internet or maybe a private applications everyone if it's a solution or the World Wide Web So this created a huge fragmentation that stemmed from the fact that this really wasn't iterative process.
Every time something new is introduced to the workspace and a patch was applied to to tackle it but no one ever looked at it from a holistic point of view now many modern vendors and players kind of took. They took their own product. It could be a casbit could be a swig and they kind of Spawn it off to to solve more problems, but it was always centered around their core product which made it flawed in many ways.
Maybe it's not supporting a wide enough variety of applications. Maybe the visibility you're getting is limited to web access only. Maybe there are a few separate clouds depending on the use case and this one unified solution that has one unified policy and one unified visibility across all the different deployments and all the different types of endpoints and all the different types of resources.
That was never made. No, nothing was ever made from the ground up to tackle this generic problem. Now, the cloud technology was really ripe at this point to become the shoulders of giants on which we stand And use this Global Network of a very elastic very fast responding competing services.
To provide this unified decentralized also redundant and you know world-class. Access platform across the private applications the private networks the cloud the SAS and the internet so it was an accumulation of all these things that ripe to be leveraged in order for this problem of resource access within the Enterprise and the modern Workforce to be so like never before in the most elegant way and the most easy and unified way if that makes sense. Yep, I get it.
Look, we we've seen this. You know there was a time where everyone used active directory basically right for their and before that I'm old before active directory there was ldap and and the Novell directory stuff and right and but the world was simpler then as you said right today, we we have so many different means of English and you guys are under the network. so we want to talk a little bit about sassy and stuff today.
I'm gonna ask you yo if you could frame that. Absolutely. So sassy secure access Services Edge, that's the the notion that access and routing should come closer to the edge that everything should be decentralized in cloud-centric and it no longer makes sense to backhaul into a central location just in order to go out to the internet or go out to an application.
Think about the Absurd I could be in Texas. The application could be in California. But if the VPN concentrators in London, we're gonna go all the way across the Atlantic just to go even farther west and when we started and the internet is the centralized by Nature when I go to Facebook from Tel Aviv, and you go to Facebook from Florida, we go to entirely different servers Because the Internet is built such that everyone has access close to where they are.
So this backhauling both in terms of private access if I'm going to the data center, but even more so within the internet, this is a huge burden. A huge cost and this is a huge productivity. Productivity night.
It hasn't made sense for 15 years, right? It was one thing when you looked all back hauling infrastructure and land right this whole thing. It was built when we had a motion Castle kind of mentality, right?
So you had to come over the mode back into the castle. I think you really didn't have to go out necessarily the application because the application lived in the castle. Right, once we started having to go out in the cloud the idea and then and then and that we weren't working in an office.
We could be remote we could be anywhere the idea of back hauling back in so I could go through my firewall and round or back out, you know over a VPN. Let's say it didn't make sense and then certainly with covid. And though everybody working from anywhere.
It really didn't make sense. I think at that point everyone realized the emperor had no clothes. Right.
This was just this was just wasteful as what it was and so You're saying. Sassy is not replaced this exactly this notion that you're either in or on your or out the castle mode. Um notion.
That's no longer relevant this am I yeah, you can access everything or am I out? No, I cannot access anything. That's no longer the case and core companies one the ability to give true least privilege.
So if I am a perfect user on a managed and point and all the posture checks are going great and maybe it's my working hours. We need to take all those things into account as well as what the Sim says what the UVA says what the ADR says we need to ingest all these things in order to give me the truly privilege and not the only nothing approach and like you said during covid that was even worse because businesses scramble to maintain business continuity, right and every Time if you have the choice between better security or business continuity. No CEO will tell you let's go better security.
So that created these many holes through which attackers could get in and Sassy again is the notion that it should be very flexible. It should be enforced on the edge and not in a central location and that all these different Services the cats be the swing the VPN the sd1 some vdi use cases. All of those should be Cloud delivered to the user as opposed to again backhaul into a central location and let's take it from there.
a great I mean, you know to us it makes perfect sense, of course, I think one of the problems that you run into is the inertia of organizations that have invested. Millions literally millions tens of millions of dollars into this whole out of date out of touch kind of Technology, right? You know the vpns of the world and so forth.
and I think you know, it's hard to get people to just say okay, I'm gonna walk away from that. Absolutely, and you know if you look at at security Trends in general some of them fail, but those who don't fail have the cycle where at first it's the techies. It's the people are crazy about new tech.
You always want to be on the bleeding edge and they're the very early very fast adopters and for zero trust that or for sassy that's pretty much gone. Um, a zero trust has been around since 2014 assassins here for a few years and these are all evolutions of adjacent terms describing similar things and then there's the point where many realize that in terms of managing their risks. It makes sense to move at this point because the technology is mature enough and because there's lots to be gained and that's when most ditch old technology that was purchased maybe for a lot of money, but they're doing it to remain up to date to not be left behind instance of security and then there are those who will be very stubborn and you know, my previous decision was right at the time so it must still be right or maybe they have fear that their teams will not be able to make the transition.
Many there are more excuses for for stagnation and I can count in such a short interview. But at the end of the day those will be left the most vulnerable because at some point they'll be there. It's an Ever shrinking fraction of the business ecosystem and the business landscape and the smaller you are the part of a smaller Target group you are because you're the easier Target.
And at some point you you need to swim faster than your friends and not faster than the shark because everyone gets caught. at the end of the day Yep, absolutely. But you know the story you don't have to outrun the bear.
You just have to outrun the guy who's also trying to outrun the bear. That's great. Let's talk.
If you don't mind get a little bit of bad access and stuff. How is the offering kind of offered? You know, how does how do people engage with access for this?
So like technically it's very easy, you go to the website you leave your details and we talk to you from there on it's pretty simple process. POC can be set up in just one day where you start getting visibility to all the things you're starting to limit access to a certain SAS applications and private applications. You can choose what can be accessed agentlessly and what with an agent it's very easy and the way most Enterprises do it they sign up they install it and they're setting up a policy that kind of resembles their VPN policy.
Now you might scratch your head and say so why do it at all it's the same policy. So first of all, you're getting visibility and and uniform policy right out the gate but then something interesting happens, you start accumulating data and seeing who accesses what and when and at this point our system will suggest ways to narrow down privileges. So maybe this application is only accessed by HR.
Maybe R&D is the exclusive accessor of this application and over time you're gonna see that the policy gets Tighter and Tighter and Tighter. so, you know getting to truly's privilege is a never-ending Journey, but if you have data and if you have one vantage point to look at all access across the organization all of a sudden the aspiration the the striving for truly is privilege becomes a much more actionable and much more manageable process and sooner rather than later you're gonna see that what started off as you know, Showing the the same policy that the VPN had evolved into a truly privilege and a very reactive very breathing type of policy management that you know, helps and offloads much of the burden of the security team and into the the platform. So we're we're overtime but for people want to get more information about access security.
Where do they go? com on the website. com.
We would all be very happy to answer any of your questions and hopefully support you in your journey to a more secure workplace. com Correct. Got it.
Hey, Gil. Thanks for being right. Yes, come back.
Keep us posted on this. Okay. Absolutely.
Thank you Alan. Alright take strong TV. We'll be back in just a minute.