The Gap in SaaS Security – Glenn Chisholm, Obsidian
Glenn Chisholm, CPO of SaaS security company Obsidian, joins TSTV to discuss SaaS Security Posture Management “week” and highlight the importance of managing misconfigurations, threats, and entitlements for the hundreds of SaaS apps a typical company uses. They also delve into the compliance issues presented by SaaS.
Transcript
This is texturing TV. Hi everybody. Welcome back to techstrong TV a Mike Rothman general manager text on research and I'm joined by Glen Chisholm who is Chief product officer of obsidian.
They are a SAS security company. I really should accept I'm not going for a long time and and you know kind of it's been interesting just to see that the city it's Rises and kind of started out from a handful of folks looking at some identity management issues. See, I mean anything I remember that my doing management issues around SAS and now they've built out a full staff security offering Glen.
Welcome to text strong TV. How are you today? Well, thank you.
Thank you having me appreciate it great. So what I introduce yourself and tell us a little bit about what obsidian does as opposed to, you know, how I just butchered, you know, both the history and and the positioning of the company. Not a problem.
Sorry Glen. She's a mom one of the co-founders of obsidian and you know obsidian is a security company. We think about SAS security from A very fundamental level, you know, we've now had SAS for 20 years.
We initially as a security Community for against SAS. We then decided that no, it actually made a lot of sense. You know, ultimately Microsoft is going to be better at depending, you know exchange then, you know security team.
I have security team Bay. But when we did that what we did really think of is how to look after our responsibility. And so what if city is trying to do is to give the tooling to the security teams to understand?
Whether it's a Salesforce, whether it's a doctor whether it's a 365 or a g Suite or service now or work day, whatever it happens to be how do you secure that? Infrastructure, how do you think about that and more importantly? How do you get the most value for the business while doing that because sasses amazing?
It's agile. It's versatile. People can use it in many different ways and the Speed and Agility is something that security should enable and help drive forward and I'm seeing is there to think about the pieces of that?
So how do we can figure that application that well that platform these things are really platform. Don't really application. How do we can figure that platform and make sure that it's secure and all the rapid changes that happen to it.
This isn't this isn't 2,000 where it's it's you know, 12 months to do a software upgrade and half a million dollars to to add in your knob to a thing to it to a screen. This is something that changes all the time changes occur changes constant. So we have the posture management piece of the product to help security.
Live in that life cycle of Rapid change with information moving everywhere. Then the second piece is these applications are not Islands. They're all connected to other applications you go.
Look at something like a a g Suite or 365. You know, we might see say, you know a thousand applications on average connected to you know, a g Suite or a 365 and may maybe a couple of hundred connected to a sales force at a large Enterprise that can be 10 12 15,000 applications of 365 and 100s connected to a Salesforce and hundreds connected to a service now. That's a measurement into connection that you have to think of much more like a network in itself of all your information flowing.
And then the last piece is how do we think about threat for a really long time with SAS? We really just sort of thought. Well, it's all about the employee connected to the South application, but it's not because that's applications have employees.
They have vendors. They have contractors. They have customers connecting to them.
But also all those additional connections, so how do you think about threat? How do you think about compromise? How do you think about threat detection?
So we bring those three pieces together to provide a product that actually helps enable security teams to protects ass. Yeah. I understand what they want to clarify a little bit because you know, some sass environments or platforms some are not right, you know, you have them, you know all over the board, right?
And there's some that are you know, very slim very discreet from a functionality standpoint, but have incredibly sensitive content in there, you know, it's in the organization I and it's really the impetus and and the responsibility of the security folks to really understand again where the data is what they're doing with it, you know kind of what is the security environment that the SAS provider, you know deals with so there's a lot of diligence involved. There's you know, and it's not just hey, let's make sure they have the right entitlements and you know, we've got the thinking correctly. Also a decent amount of you know, kind of third party risk that's integral to you know, this process so really and and as that's become the first choice, right?
So we joke about Cloud first, right? But I would say almost every organization now is SAS first. Well, why would you roll out an application on a bunch of servers in Iraq and a data center that you probably want to get rid of anyway, right when somebody else can deal with it?
So you have all these things generating together. I mean, I agree 20 years in it's still abysmal in terms of you know, kind of what folks can do to both understand where their data is how you know, those environments are configured and ultimately to track, you know, the threats against that data again just abysmal. So you guys kind of wanted to bring a little bit of focus on that.
So you came up with you know sass what's it SAS security posture management week, so we were joking a little bit and you know before we start up the interview, that's like a Hallmark holiday right like National Siblings Day, but we have set as SPM week you all got to get cards and t-shirts and all that kind of stuff which is, you know, a little bit of a tongue and cheek way of really kind of saying this is a pretty important issue and something that you know, folks really have to start being more serious and and focused on Look, absolutely. I mean, you know sspm week is about sign. Think about how you're using this think about where your information is think about who has access to it and think about whether or not you have any control over that and you have any understanding of that.
And if they are you don't have all the answers, that's fine. Like that's why we should think about this and go and do something about it because you know, one of the things that we've seen is we saw solarwinds happen a couple of years ago where SAS was the target, you know, the attackers were trying to get into 365. They were trying to sit there for a long period of time and they were trying to extract information in a very surreptitious way.
What we're seeing in the last 12 18 months is just a massive increase in SAS breaches. And you know, you can go to news you can go to you know, all the different, you know channels out there and see the metronomic increase in breaches and just to share a number of days some of these are about fishing the employee how to submit to factor by relying on human priority and this isn't a shot at any individual All humans are frail. We all have bad days.
things can happen or targeting another company that has one of those connections to your SAS applications. To get information out of your environment. So the short answer is the attackers are focused here because they know the data's here and they know that generally companies aren't looking and protecting this place.
So this is a place where they can get into where they can spend a lot of time, you know often I make the joke. It's like being, you know pride pride of city and I was the CTO of Silence, you know, we had you know, a few people ran into table until You know, it was a very large company and you know when when silence started out, you know, you would you would look at the dwell time stories statistics and the dwell time statistics were 400 500 600 days. And the whole focus of that next Generation endpoint was to get rid of that concept of dwell time being in the hundreds of days.
But if you're not looking in SAS, then you could end up back in that world. And I think that's where we are. Now where the dwell time is back up in those hundreds of days because no one's looking.
Yeah, and it's it's both right, you know kind of you do have to protect the end point. I think that is, you know, kind of the path of least resistance for a lot of folks, but the reality is and and this is a lot of the same tactics that we use in, you know, kind of infrastructure as a service architecture and and Cloud design and that you want to isolate things to the greatest degree possible. You want to manage the configurations.
You want to reduce the attack surface. You want to make sure that you're identity really lock down so that you know, even if Of an endpoint with attached to a specific identity is compromised. They have a limited, you know kind of access and and limited ability to you know, pivot and exfiltrate and and really steal and compromise, you know that data.
So it really is hitting both sides it right. It's not just endpoint. Yeah that but, you know, it is paying a lot more attention to the back end right paying a lot more attention to a lot of these environments and really the challenges.
There are as you mention right hundreds. If not thousands of these things. He even with a different.
Yeah, you know, all right. So so we kind of Federate to after right so that you know kind of you you don't have to deal with the this is Glen and this is Mike and the sound and this is you know the other person and that's fine. Right but each one has their own set of entitlements each one as their own set of permissions each one as their own, you know, aspect and access to the data that's there and who does that right?
Is that the The marketing person that's responsible for that Mark Tech thing. Is that the finance person that's responsible the fintech thing, right? So I mean when you're dealing with customers and how do they deal with just the the sheer amount of administrada that's required to get these things set up.
Well, I mean this is part of the critical issue is that ownership of SAS applications is distributed. You know often who acquires the HR app, it's the head of HR the head of legal. They acquire the HR app who acquires the the go to market apps.
It might be the cro. It might be the CMO or might be a combination. And so you end up with sales operations business owners HR operations owning these individual applications along with the traditional it ownership model where you may have it I need service now and 365.
So you have this real blend now, obviously you have to have quality endpoint infrastructure. You have to have quality Federation. You have to have wealthought out two Factor.
No SMS, none of those things like they should all be gone. but even with all of this You end up in a situation with this distributed ownership and and I said, you know one of the key functions here. Is this the rate of change in these things and this is where it's very different from infrastructure as a service infrastructure is a service.
I'm going to have a high rate of change managed for a high quality, you know devsecops type of approach. Okay, hopefully but I can I can put that into place here. I've got a much more distributed a larger pool of people a larger, you know environment.
I don't have necessarily those those clean processes. And what's important is? We used to have a situation.
We had Federated identity where your entire authorization was controlled by the federal debt identity player. Once you get into SAS application authorizations application of application as you as you know, so somehow Bob becomes an administrator, but if you don't know Bob's an administrator. There's no way for you to deal with that and you end up with a wealth of problems.
And and you know, if you work in a you know, any form of Industry that has compliance as a key aspect and these days it's almost rare to not be in an environment that has a compliance requirement that it is to be in one that is everyone has some degree of compliance. these things were all causing you real issues and compliance and compliance 10 years ago was a set of paperwork compliance now is Auditors that are asking for direct evidentiary proof, but also that comes with real penalty And those penalties are material. And so if you're not thinking about this compliance obligation inside the SAS applications that are fundamental level.
Oh, I don't believe I made Bob an administrator Bob is an administrator when they go get proof of that. I've now got an issue all there's a breach and this causes a loss. This significant financial penalty associated with that.
Yeah, but I wanted to you know, kind of get into the compliance thing, right because you know, the checklists the folks with the checklist, right? They it was the the ink is still wet on on kind of their you know, AWS and Azure checklist. I mean are they in a position where they actually do start to screw something besides the IAM stuff and you know kind of the things that are pretty Universal across all SAS applications.
I mean for things that are, you know, customer Centric, you know, if you're if you're a regional bank, right, you know your bank systems abusing assessed with that your HR, obviously any of your your kind of you know, financial information. I have the Auditors, you know, kind of gotten to the point where they're starting to even know what questions to ask her. Is it still, you know, a bunch of blind folks, you know, kind of walking around bumping into stuff.
The audit has gotten into this space and they starting to ask questions. I started to ask the evidence reprove and and you've got to remember that one of the things that happened in the financial industry is that some of these Regulators aren't just sitting You know in some remote office somewhere. They're actually sitting in the offices of these companies asking questions during meetings.
The Regulators are sort of now getting more involved than our asking more complex questions. So these regulatory Frameworks are much much more impactful and because they see the breaches like everyone does because they then see the outcomes of these breaches then they go and start asking questions. Um, and so I think that what we've seen certainly in the last 18 months is a level of thoughtfulness and approach by the Auditors The Regulators to say it's not enough to tell me that you're doing this.
It's not enough to show me some data from your Federated identity provider. I want to see data from inside this application that shows me that you've taken these steps. I want to make sure that you have the appropriate configuration.
I want to make sure you know where your data is and where it's flowing to. This isn't just a configuration issue. This is all the pieces I touched on.
You can't just configure something and say that you're compliant. You have to be able to show what happens inside the application the activity the actions they're occurring. That's an important piece.
You have to be able to show that you're monitoring that application to make sure something doesn't go wrong to make sure you don't have a breach. It's much more than just the settings. It's everything around so.
No, no, exactly. And and I think that you know kind of the whole idea of really having to start to substantiate what you're doing is the huge change and also you're in an environment where it's not just the application that's changing all the time. It's who can do what we've got, you know provisioning deep provisioning issues.
We've got you know, folks changing groups changing entitlement, you know dealing with new capabilities. So this idea of you know, kind of going through the process, you know a week of hell before the assessor shows up, you know, and then forget it for another, you know, six months before they come back again things are changing too quickly. So you really have to be on top of it has to be one of these things that you're monitoring on an ongoing basis and and really looking for those misconfigurations and looking for those potential problems or else again bad things happen folks can do a lot of damage in a short amount of time now is look the beauty of SASS and it is a beauty over it, you know.
you and I are old enough to remember on premise software and the the Pains of just asking for minor chain. I mean you think of the the head of sales that when they started out, you know, 20 years ago and they had an on-premise CRM and they wanted to get data out of it. It took an Act of you know, and a blessing to get data out of it to be able to enrich that data.
Now that head of sales can go to sales operations and say connect up one of these marketing automation tools. I want you to enrich all of this data. I wanted back in my system.
I don't want to be able to take these actions with it. All those things can happen in a matter of hours. But every single one of those things have the compliance a regulatory and security impact and to see security team can't see those new connectings can't see those data flows kind of understand the threats.
the seaside is absolutely both responsible and accountable for this and they have to be fully aware. Yeah, they do. Well good Glenn, really appreciate you showing up talking a little bit about SAS security posture management week.
Oh weak. It's just not a day. You can't have to be awake.
It has to be the laws too much stay awake too much can't go down the Hallmark at the card and you know, just buy a T-shirt and be done with it. You gotta focus on it for a week. So we certainly appreciate that because again, it is a huge problem.
I think in under appreciated problem. So, you know beating the drum for it. I think, you know, I can I'll put fun at you because I can but I do think that it's I do think it's an important topic that we make sure that that folks continue to focus on so really appreciate you coming on Tech strong TV.
Tell everybody how we can you know, learn more about sspm week and also about City in general. Blaise I come look at obsidian security calm. We have some great lightboard videos that cover the material more importantly we have some fantastic blog posts to give you some places to think.
I understand where to go look and reach out to the team reach out to me. We're happily chat and spend the time of year. Yeah you bet and again, this is something that every company with employees with computers as this is a problem.
Everybody has everybody's using workspace everybody's using 365 and you know, a lot of people use it, please like HubSpot and work day and and all these other ones. So this is not just hey, I'll stick my head in the sand and the problem go away so lunches. I'm really appreciate you being on the show and that's why so send it back to the studio for our next interview.