Teleport’s State of Infrastructure Access and Security Report – Michael Ferranti, Teleport
Teleport’s CMO, Michael Ferranti, fills us in on their recent report highlighting access and security challenges as infrastructure becomes more complex. As a bonus, Mike Rothman couldn’t resist poking fun at zero-trust marketing hype, so they had a good discussion regarding how zero-trust can help and what it’s good for (and what it’s not).
Transcript
This is Textron TV. Hi, this is Mike Rothman. I'm back with another text wrong TV interview this time.
We are pleased to welcome Michael Ferrante who is the chief marketing officer of teleport here to talk to us a little bit about a recent study that they did. Asking folks about access and and you know kind of how they're protecting access and really making sure that the right folks get to the right stuff internally especially is things continue to get a lot more complicated as we've got, you know, devops and Cloud native infrastructure and and all sorts of and multiple devices and and multiple locations and all this remote work. So, you know, it's it's a pretty complicated world out there and and, you know getting folks to the right stuff continues to be a major priority for organizations, or at least it should be if it's not gosh we should but yeah, we're trying a little bit before the before we started, you know kind of the interview, and I don't want to see disturbing, but, you know, there was some stuff that was clearly surprising from the standpoint of the data that you guys kind of came up with.
So first of all, welcome to the show welcome. Thanks. Good to tell us a little bit about you know, kind of the study and and maybe you know it start with one of the top line, you know kind of results that you got there.
Yeah. Well, I think you know it is um It these security surveys are always, you know, they're always eye-opening. If you if you don't want, you know your children asleep at night.
You can either like let them watch a scary movie or read a security survey. It's it is it is kind of disturbing. Um, in fact one of the headlines of the report which is called the state of infrastructure access and security of folks want to look it up.
I'm just Google it on. This is the second year that we've done the report. Um, and so we we actually asked many of the same questions as we did last year so that we can see how things have changed over time.
I'm sure we'll get into that one of the questions that we asked last year and this year as well as how confident are you that X employees can no longer access your infrastructure. Um and what I mean by infrastructure well infrastructure is it's servers. It's databases.
It's internal applications like CI/CD systems monitoring dashboards. Um Cloud accounts, right? You're you're AWS account.
These are all writ large infrastructure resources. Kubernetes clusters is another one that's very popular with our customers. And so, you know, when an ex-employee leaves your organization can they no longer access that kubernetes cluster that SSH server that Windows box that that cloud account.
Um, and Not surprisingly because it's very consistently with last year. But but concerningly only a quarter of respondents said that they were fully confident that X employees could no longer access company infrastructure. Um, so, you know Michael gets fired on as Chief marketing officer at teleport and you know, can Michael no longer access teleport and infrastructure, um, in my case the answer is yes.
Hopefully I'll get fired but we we actually have a unified way of removing all access but many companies don't on folks work from home. And so you can imagine a situation in which you know, Michael devops engineer gets laid off during the fall of his own through, you know, I'm just kind of the that seems to be what's happening these days and his companies that you know, Michael just keep your laptop. Great.
Okay. So Michael no longer works at the company. His OCTA is the provisioned but on that laptop, Michael still has an SSH key, right that was registered on in a production environment.
And so though Michael no longer works at the company. Michael is still able to access those production systems on it's the siled nature of how access is managed for infrastructure that creates a big problem. Yeah people and you know, I think that really highlights a lot of the challenge of a lot of this new modern infrastructure that we have, you know, you kind of mentioned.
Yeah, you know, you're depression from OCTA. But again, if you don't lock down the Federation part of it and Salesforce of workday, right, you know, you really locked out so you just you just have a lot of different moving pieces relative to you again modern infrastructure that makes you know access and really restricting access on that front, um complicated so there are another, you know, kind of Top Line, you know conclusion that you guys found. Yes here to last year right was that, you know our changes from year to years always interesting to me.
Yeah, one of the one of the things that we looked into this year was kind of the just the the increasing complexity around infrastructure and we talk about access often we think about you know, the example that I just gave it's it's Michael that's accessing and infrastructure resource, but in the data center the vast majority of communication between various systems. Is what we call machine communication machine and machine. It's not you know a developer logging into a system.
It's it's a microservice that I've written or a, you know, a CI/CD pipeline that that I've deployed that is speaking on to other resources and because of supply chain attacks and and various security vulnerabilities. That's actually a huge problem. And we ask people you know, how many how many machines infrastructure resources Etc.
Do you typically have in your environment compared to people on in machines out number humans 100 to one in the average organization and I think folks are not thinking about access policy. For their services that are being written the way that they're thinking about it for people now clearly when only 25% of organizations are fully confident and ex employees can no longer access infrastructure. We have some ways to go when it comes to managing policy for humans, but I don't even think we're there yet when it comes to the policy that's attached to these machine users.
I'm I can tell you we're not right I can tell you we're not because you know again I've spent you know more time than I care to admit in the trenches of you know, kind of cloud type stuff and and it's incredibly complicated, right so so locking down a lot of those resources. It's not just oh, hey, you know kind of This Server gets access these, you know specific resources, right? You have to really think about it from an entitlement standpoint and and again not just who can access it right?
But what can it do right? What can it what can that specific resource do within the environment to be a little bit more grammatically, correct on that front? Yeah.
I spent some time as this DMO too. So, you know kind of the words I try to get the words as precise as I can on a given time, but you again and we start thinking about you know, kind of how do we lock down? A lot of the apis that are being used to access a lot of these services and you talk about cloud and Cloud accounts is really kind of a new version of this infrastructure that we have all everything we can do, you know and one of these cloud councils Can be accessed via apis, right API keys.
So so how we you know kind of doing all that so not surprising at all to me that again, we're pretty crappy at locking down the users but we're just awful at you know, kind of a lot of the resources because we don't think about it that way right, you know kind of the IM team within any specific Enterprise tends to focus on provisioning the users and federating their identities to where it is. They need to be they don't think about you know, kind of what components are within these specific Tech Stacks that you know, kind of comprise a lot of new modern applications now go off a little menu here, right but, you know, the marketing Machinery of the security industry, you know continues to strike again, right and and you know, hear a lot of these problems Michael and you know, the first thing that comes to a lot of folks mind is you know, hey, I read somewhere I saw something somebody said zero trust is the answer to that right? So we just embrace your trust right, you know on that front, you know, all these problems go away now.
I'm gonna try to reserve my my initial biases about that before I give you a chance, you know to react to that specific statement, but I mean, you know again a lot of folks will just kind of throw out a term, you know a marketing term when you're trying to you know deal with specific, you know, kind of very tangible issues. So so how do you kind of deal with this mismatch of you know, somebody who's been conditioned to think that you know, hey, I just buy a zero trusting and all these problems go away and the reality of those different issues that you kind of decompose in the report. Yeah.
Yeah great question. I mean it's it's interesting that you know, if you want to buy a zero trust solution, you know, you just Google it and who shows up it's all over the networking vendors. What is your zero trust zero trust as the network no longer matters.
Do you really think that your networking provider is the one who's going to bring you to the promised land of zero trust? I don't think so. And I think that's where some of the marketing message.
It just clouds it. What do we actually mean by zero trust? Teleport what we mean by zero trust is simply that you know it, you know Michael it doesn't matter that he works at teleport when he's trying to log into any system a server a database an application.
He's gonna be authenticated and authorized based on policy. That's what zero trust is every single connection gets authenticated and authorize regardless of the network the machine or human which more human that's right unified policy for every single connection. That's what zero trust is.
The problem with zero trust is I mean, I think folks get that you need what's typically called an identity aware access proxies you to do that basically funnel all of your traffic through a system that provides the authentication and authorization mechanism. That makes sense. So it's like, okay.
Well, how do I do that? There's some technical challenges around building your your identity to proxy on that's one of Major components of the teleport platform which is why people come to us, but you know, there are other ways to do it and we and we encourage that as well because we'd rather have a secure internet than a then a less secure internet, right the other piece though is how do you attest to Identity? Right?
So if if I'm saying this is an identity aware proxy how is Identity instantiated or proven rather one of the things that the survey reports on and this is like truly I believe in today 2022 truly catastrophic the vast majority of organizations are still using passwords and other secret. Um, in other Secrets like SSH keys for instance on to authorize people to access infrastructure resources and These things can be stolen right? So if I steal your username and password, then I can log into that database and drop tables as if I were you am I you know, but because I have these credentials that are static in nature I can log in We believe that zero trust requires a move away from static credentials and to embrace identity based on phishing proof on forms of authentication such as Biometrics and multi-factor authentication.
When you combine what we call a secret list approach with a true zero trust identity native access proxy magic starts to happen because the all of a sudden the happy path is the secure path. I'm an engineer I come in in the morning. I you know open my MacBook Pro and I you know, I tap my finger now, it knows that it's Michael there's proof of presence.
There's proof of identity. I have access policy that defines what Michael should be able to access in every time I try to go to a server a database an application. My identity is being on is being verified.
Um, it's it's it becomes seamless another marketing term, right it becomes transparent, but there's a complete audit log of it. On and I don't have to continue to log into all of these different servers using using passwords and keys. I can simply use my identity.
So let's talk a little bit about coverage right because you know, when when you map out a vision like that, it's like that sounds great. How do I go and do that? And then you realize oh I have about 200 different, you know Legacy applications that I have to deal with right.
I've got, you know a whole mess of of sass, you know kind of platforms and application to deal with some of which I don't even know about right because you know, we all know this business it stuff happens and they go around, you know, kind of central it because they're not, you know relevant enough. So, you know, I guess in one of the constraints and this is an excuse, right but one of the you know, kind of responses I always hear from us. Well, you know until we get to everything we're really get to nothing and they're still the weak link.
So I mean, how do we kind of start to Stage out and really my great towards this idea of seamless, you know transparent secure and and verified access to a lot of these cool resources knowing that it's going to be a bit of a journey, right but not, you know kind of wanting to continue to sacrifice Security on the stuff that you know would plug into So what's the general, you know approach and recommendation for for how we start to get there? yeah, typically the way we see with our customers is We we kind of started out as we're very engineering heavy organization on the engineers and the founders of teleport worked at large-scale cloud computing providers and kind of their their job was building the systems that we all rely on every day and they took those lessons they said, okay, how can we create a generalizable solution to big problems that we face as engineers at these at these hyperscalers and that's where teleport came from so our customers tend to be very very technical teams within organizations that are pushing the envelope for what it can provide. So, you know, when you are running massive scale kubernetes clusters, right and your it has what's called Pam solution privilege access management solution.
Everything has to go through a pound. Well, these teams are like Okay, I I hear what you're saying and I understand the implication of that you want audit you want to be able to explicitly authorize you want to be the Implement zero standing privilege. Like I get all of that but these Solutions do not do that for kubernetes.
And here's a solution teleport on that allows us to Define who can access our our kubernetes clusters provides real-time audit provides zero outstanding privilege privilege escalation just in time access, you know, is this sufficient in it look at it'll be like Yeah, absolutely. And so they'll start there and then our experience for managing access to Linux and windows servers tends to be more Dev friendly than traditional Pam Solutions. So they'll accrue those use cases and then it's database access and it's in it is application access teleport is a class of service that we're seeing a lot more of where developer experience is really the part of the core value of the platform.
We provide the security here lawyers would say not guarantees. We provide the security, um that you would expect from a traditional security vendor, but with an experience that developers love again, so the happy path is the secure path, And it's just it's it's a Groundswell people hear about it. And this is why this is just the you know, the the nature of Technology Innovation is you have you have a market leader and then they become stated and then people, you know start to get frustrated by and then an income comes and we're just in that phase right now on and so I would say look You always need a match these business priorities these business expenses with business value.
And because all companies now are software companies. You really need to keep your engineers happy and productive. And so rather than trying to solve, you know, 1000 different use cases across your entire organization for potentially limited results focus on where you're spending the most money on Talent which typically is in your engineering organization and also the highest value of business applications that you're developing.
So, you know, who's gonna be building your AI system, right? That's gonna happen enable you to compete over the next decade. Well, it's probably some very highly paid Engineers writing some highly specialized microservices to manage it Focus there on and then spread out.
Yeah that I think that's a good return. And you know, I guess my Council to most folks is don't try to boil the ocean, right, you know again whether you start in developers and I think that's a great place to start. I think there's a lot of pretty important information and SAS environments that you know, kind of would be another, you know, kind of decent place to you know, kind of start restricting access and and managing access along the those lines along, you know, kind of the collaboration environment that you know, kind of we see day in and and day out, you know our officers 65 and our teams and our you know, kind of slacks and a variety of those so so they're just a ton of applications that you can get going where you've got very sensitive information flowing in and out and I think it does warrant, you know taking a look at what can I do to ensure that we're not impacting and making complicated more complicated than we need to right the user experience yet.
We're you know kind of ensuring that we protect that I like that concept that you know kind of when when the easy path is the secure path that tends to be You know when good things happen. So Michael really appreciate your time on the show today. How do we get how do we get in touch with with teleport?
If our folks want to you know, learn a little bit more about the survey or more about the company want to tell us how we can get touch with you guys. com and we can happy to answer any questions you have you can you can find the survey there on you can learn more about teleport solution talk to one of our solution Architects figure out how we can help you would love to talk to folks. Well, that's fantastic.
So Michael Ferranti, thank you so much for your time and appearing here with us on Tech strong TV and we'll head back to the studio for our next film. Thank you, Mike.