Tackling Secrets Management with Entro Security’s Itzik Alvas
Entro Security CEO Itzik Alvas explains why the proliferation of cloud services is creating a secrets management issue that most IT organizations are unprepared to handle.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Itsy Alvis, the CEO for intro, and we're talking about identities and secrets and the fact that they're all over the place, and well, if they're not managed, are they really secrets?
Hey, itsy, welcome the show. Thank you. Thanks for letting me back.
So it seems like we have these secrets that are everywhere. They're created by developers, they're created for SaaS applications, and it's kind of a bit of a mess. How did we get here and what's to be done about it?
But, um, so we are talking today about non identity than, uh, and secrets, um, which are essentially problematic. Access keys and our organization are managing them, um, today and avoiding, uh, avoiding marriage. So what happens with these keys and why are they more secure than they should be?
And are the bad guys kind of discovering all these things? Yeah, so I think, uh, non identity like service accounts, API, keys, connections, things, um, cloud access tokens and so forth, you know, that's a, that's an ancient problem. Um, basically those are programmatic access skills that applications workloads use in order to access and authenticate against, uh, resources or solutions they need.
Uh, so those have been around with us, uh, for, for a long time now. But did you mention correctly, uh, with the, with the cloud adoption, um, and more tools that we're using and each one of them needs at least one secret, a nonhuman identity in order to connect the two. So yeah, those, uh, non-human identities are spinning out control, and there's at least 45 non one human in each company.
So the number, um, of non identities are actually, it's insane, uh, trying to, trying to manage and secure them. Who's in charge of managing all of that? Because it was the business side that typically contracted the SaaS application and the security people involved.
Do they know about it or, you know, who's stepping up here? Right. Um, so I don't think it was the side.
Um, and it's not only SA application, it can be SA application, but it, its also can be, you know, cloud, cloud provider, uh, services like, um, RBS, which are the databases that are and so forth. Um, but yeah, currently was seeing that, um, known from security side is actually in charge on their security. Currently, those non identity like service accounts, A PIP connections, things are being created, permission ended, um, by, you know, the r and d side, the developers dev syringe, those are the ones who are creating them, permissioning them, and then using them.
Um, and then I'm doing that without, without proper security website. Um, terms of your question, it seems like, um, all the security teams, application security teams and, uh, IEM teams are the one while, um, responsible to secure those. But, um, actually in reality, developers are the one who are creating them and, you know, using them.
So we have developers creating those things usually at the behest of the business. Um, how do we wrap our arms around all of that? Because it seems like, you know, to your earlier point, they're proliferating at an incredibly rapid number, Right?
Yes. Uh, so developers are connect them and they can install them within vault solutions like AWS Tickets manager and so forth. Uh, those are stored solutions that you can install your tickets, your keys over there.
The application will FET from that storage solution and use it in order to dedicate to whatever source they need, uh, from those can store within different roles. Uh, today organization have at least five different world. Uh, so if you're using, you know, Kubernetes, you're probably using Kubernetes Secret, which are, which is the vault of Kubernetes.
Uh, if you're using Git guitar, you are probably using, uh, GitHub Secret, which is the vault of ttab. So organization have today at least five different worlds, uh, types. So those secrets are non scatter with between vaults, and then they also, you know, exposing them, like committing them into codes.
And the mobile slack channels, teams, channels are within Confluence pages. And the main problem we think today that, uh, security teams don't really know how many non nominate ident they have. Um, and where, and then if, if you ever seen a cigarette, an API key, for example, it's a long randomized thing.
So even if you find one, if it, even if it's security professional will find, uh, a cigarette anate identity, it's is no context, uh, uh, that he, he don't know who's the human owner, who is the creator, uh, which application is he using it to access, what resource. And when you combine that, when you combine the, uh, security teams don't know our ate that there where or what they're able to do, uh, that's why they are struggling to, to protect them. We're supposed to be engaged in the Whole Zero Trust initiative, but how can we do that if we don't have all the handle on all these different identity things that are floating around?
That's, uh, that's correct. So it's impossible to do without, uh, even understanding, you know, how many aware, um, or how, how they being used. Um, so yeah, that's, uh, that's people work.
Um, by the way, usually those non identities and secrets have no expression date. Some of them can, um, but usually they don't. Uh, so they are, they can live forever.
Anybody can use them. Uh, you have no monitoring on if someone, you know, misuse them, abuse them. And currently by boat, the eyes on and IBM, which are the leading reports, cyber of security for the past four years in a row, um, not even identities that second targeted detect of second most frequent attack on organization every other week.
We can see an example of that, uh, just last week, New York Times. Um, and it's the most crucial, costly, destructive attack on organization. Uh, so the most costly one.
Why don't we hear more about breaches involving this? I mean, is it just happening in ways that we don't see? So, um, the bad guys are just kind of manipulating those identities, and we just think everything's fine because they look like they're trusted when in fact they're not.
We, we are doing weak about the breach and the non that them, um, as you mentioned, just last week, new times, uh, prior to that, there, there, the, the Dropbox breach. Uh, prior to that, Microsoft, every, every other week, uh, we're hearing about a breach in the non that in tickets, uh, security. Um, so yeah, we've been hearing a lot about that, uh, for sure.
And, and again, it's the second most frequent, the second most frequent attack vector out there. It is, okay. Um, wants to be done about defending that then, Right?
Um, so in order to, in order to, you know, completely secure and manage, um, the lifecycle of non identity, and in order to enable organizations to secure use them, the first, the very first step is to get the individual right to understand where are all of them, um, and how many you have. Um, and you should do it by discovering them when they are created. So if someone, you know, creates a new token at your MongoDB, you should be aware of it.
Uh, if someone stored a new cigarette at your board, you should know that at where, and also if someone expose it somewhere, like in a config file or send it over Slack, you should also be aware of it. Well, uh, and if you are able to discover them at creation location or educational or exposure location, you can have a full inventory, um, and answer questions like how many non-human, so that's the very, very, you should classify in reach and business context to each another, one of your non identity. Those are long randomized things.
Um, so you should add context to them and basically visualize the map of, or which workload are using water to access water resource and other, other vital data like the mono, what, uh, what are their permissions, um, enablement focus, uh, if they're even enabled or maybe they already expired and guess about them. Um, and we think basically you need to understand the number news. Um, so yeah, that's the, those are the very first steps to understand where they are, how many have, and what they're able to do.
And of course, the rest that are associated with them. Course these days, you can't walk down the street without somebody telling you about their great new AI thing. Can we apply AI to this in some way and maybe save us from ourselves?
Uh, so AI actually creates a lot and a lot non identity, new non identity, each organization. So AI contributes to that problem. Um, we can, we can for show you the AI in order to find some of our identity or make sure that are actually, you know, those long strings are actually two secrets and not, you know, long string of character that someone they download in keyboard.
Um, but, um, but the reality is that AI contributes to that problem and and belong severely in each organization. Um, yeah. But, uh, but what we, what we can do, and what we should do is after getting that inventory, after classifying, enriching each of the one of them, we should, you know, combine that, we should combine that inventory and classification and do risk, uh, portion money demand to understand, you know, how many of my, my stake actually wanted and securely stored.
How many of them have excessive privilege that they don made? How many of them have not been updated in time and bridging my compliance and and forth? Uh, so we should lose the inventory and clarification in order to conduct a push management around them, uh, and secure our environment.
What's, um, what percentage of those secrets are actually stored in a vault versus just kinda randomly stewing around the environment? Uh, that's, that's a great question. Um, so, and to the nominate management, uh, company, uh, we help organization to securely use non, uh, and, and part of what we're doing to understand how many of loge are actually voted, or also we are each we for that, uh, it depends on the organization building inside, but, uh, only overall at least 60% of protection, not vaulted, um, and exposed somewhere, which of course contributes, uh, to the, to the percentage of riches we are seeing.
So as you start thinking about all of this, um, is there gonna be, I mean, will there be some sort of crisis soon that was gonna get everybody to wake up about this? Because to your point, it is a common attack factor, but um, it doesn't seem like anybody's paying attention. Uh, the market is definitely up.
Um, everybody, they understand the problem nowadays, um, because it's the second most frequent attack. Uh, so a bit about myself, I'm, I'm, I'm the CEO of central security, ment security, the non-human identity, lifecycle management and secure security platform. Uh, I started cyber security, uh, journey, uh, in the IDF and then learned defense force, but one of the intelligence units over there.
I wasn't offensive side, uh, after that on, you know, moving to the public, uh, market. I, I, I've done defensive side of cybersecurity, um, and I, I managed large groups of fiber and, and several organization, uh, healthcare, Microsoft and support. Uh, so with Microsoft alone, I was great wise by nominated entity.
Um, and that 1, 4, 5 years ago, um, and today again, we're seeing every week a new, a new attack. So the market is definitely adopting, um, new solutions like, and or in order to protect against nonhuman identity, uh, and the, and the market directly understand the problem. Uh, Soto was the first, uh, company to able receive, um, the first another fault, but the first it was a gap.
Um, so analysts are underpinning the problem, seeing a lot of reports around on that. Uh, so yes, I think like the market is different gap. Um, and, you know, people are, are adopting solutions, them managing secure, like, uh, of not everything.
So what's your best advice to folks? Ultimately, do I just take all the developers in the security people and throw 'em in a room and lock the door until somebody comes up with a plan? Or how do I kind of get my arms around it?
Yeah, so again, when you, um, um, so again, GPA saying the 45 W one, our benchmark in 92, we are seeing a tele customer base, 92 times non-human identities per one, uh, human, human identity, of course, no one can manage that manually, right? Uh, so if you will take all, you know, the teams and security teams and belong in the room, uh, they still, it's unmanageable. Um, and then you should, you should be restored.
You should, you, you should use platforms like in order to automate, um, the discovery, the risk, the classification, uh, if you monitor any abnormal behavior else. Um, so we have non decorative infection response, pill, uh, image, IDR, uh, that basically helps you monitor any abnormal behavior. So let's say that someone from China is using your tokens and you don't do business with China, uh, we are gonna help you prevent, prevent that if someone missed downloading ticket from world, uh, that's another abnormal behavior.
We're gonna help you prevent that as well. Um, so yeah, you should use platform like control security in order to automate, um, that non identity security and, and five second management, because doing that manually, uh, some, Yeah, no one can do it actually too much, right? Folks, you're earned it here.
There's just too many identities we're having, uh, basically an identity crisis and we're all little schizophrenic from an IT perspective. And I guess we gotta figure out some way to manage all that. 'cause this whole zero trust thing isn't gonna happen unless we know what's going on with our identities.
Hey, insect, thanks for being on the chat. Thanks. Following me, Mike.
All right. And back to you guys in this studio.