The Importance of Email Authentication with Hornetsecurity’s Andy Syrewicze
Andy Syrewicze, security evangelist at Hornetsecurity, shares why email authentication is now a must-have for a brand’s reputation, as well as the benefits and challenges of implementing DMARC.
Transcript
This is Textron tv. Hey everyone. Welcome back here to Textron tv.
Our next guest, first time he's been on the show. His name is Andy Sic. I hope I got it right.
Hey Andy, how are you Doing? Good. Doing good.
Good. Thanks for having us. Welcome.
Andy is a security evangelist with Hornet Security. We're gonna find out more about Hornet in a second, but before we find out about Hornet, let's find out about Andy. So Andy, you know, security evangelists can mean a lot of things and come from a lot of places, but where'd you come from, right?
What's your background? How did you get to be here today? Definitely, definitely.
Good question. So I've been in this IT world for, I've lost track now, I dunno, 22, 23 years. And of course, like so many people in our industry, I started more on the infrastructure side of the world.
You know, servers, virtualization, network, uh, storage networks, you know, all the guts and the pipes that all of our software runs on, right? And so I think it was about six, seven years ago now, I decided to make the pivot into security because, you know, the writing had long been on the wall, that okay, security is a big thing and becoming a bigger thing. Um, especially with, um, the way things like ransomware was panning out and, and things of that nature.
So I made the switch into cybersecurity. Um, and more specifically, the last several years I've had, uh, very much a focus on, um, security in the Microsoft Cloud, specifically 365. And of course everything that, everything that underpins that, right?
That includes, uh, um, I still say Azure ad I should say the artist formerly known as Azure ad. Of course it's called Microsoft Intra now, right? Um, so, um, if I slip up there and say, uh, Azure AD a couple of times in this interview, uh, that's not surprising, but anyway, But at least I'll know what you're talking about, right?
Right. So, yep. Exactly.
To me, that made just a lot more sense than the fancy card name. Um, but be that as it may, it's great stuff. Andy.
Um, porn security. I was gonna say one other Other thing. I That, yeah, one other thing I would add really quick as well too is, um, I'm, uh, also part of the Microsoft MVP program.
Um, and I'm a Microsoft security MVP. Mm-hmm. So, um, you know, I kind of got hung up on the M 365 Microsoft Cloud portion of that conversation, but, um, I spent a lot of time talking with the Microsoft community about security as well too.
So, and then coming back to your question, uh, tell us about Hornet security. So, Hornet Security, we are a, uh, security vendor that focuses specifically on Microsoft 365. So, surprise, there's my correlation with my 365 security background, right?
Um, and so Hornet Security, we've been around since 2007, um, you know, have historically focused on the European market, but we've, the last, well, it's been several years now, uh, we've been in the US market as well too. And so when we talk about what we do in terms of 365 security, that's a number of different things, right? We do your traditional, uh, email, um, security, so spam, malware protection, DMAC, which we're gonna be talking about later in this interview.
Um, you know, advanced threat protection, encryption, signatures and disclaimers. Everything around email security and 365, right? We also do, um, uh, data protection so we can back up 365.
Um, basically everything from all the major services we have, security awareness training. Uh, we also have a product that helps manage share permissions for SharePoint online and OneDrive per OneDrive for per, uh, OneDrive for business. That particular, uh, solution is called Permission Manager Surprise, right?
Um, and then we also have, uh, a number of other things in the, in the stack as well too. So, um, our newest solution is, um, what it's called, multi-tenant manager for MSPs. So MSPs have to, you know, work with and deal with a lot of disparate 365 environments, multiple tenants, and it provides a one nice single pane of glass for MSPs to manage and, uh, ensure compliance with certain settings, um, across multiple M 365 tenants, right?
So, um, it helps with rollout management, but it also helps remove that human element from security as well, right? You know, I, those cases where, um, you know, the human forgot to do this one security setting over here, and now it's different than all the other tenants that they, they manage, right? So we, we help provide that automation and that, uh, that, you know, compliance with, um, whatever blueprint the MSP comes up with in terms of terms of security.
So we do a lot of different things around the, the 365 space. com for all the nitty gritty details about us. So, Andy, I've been in security 25 years, right?
And, and when I started in security, yeah, most of our security, most of me and my friends came from network, right? And well, he, he came from two places. He either came from the network side of the house and you worked on, you know, the Moton Castle kind of defense firewalls and you know, big boxes right?
At the perimeter or, or you were an endpoint server guide, you know, working on natural machines and you did a lot of host space stuff and stuff like that. Um, ads to the cloud came to be, and you know, we started moving it. Network security isn't what it was.
Obviously pre-cloud. 'cause the network's not what it was. We don't have perimeters, we don't have that, right?
Microsoft moving from hosted office or, or desktop application office to off 65, you know, cloud-based was another huge piece of it. But part of that move was supposed to be, Hey, let us worry about the security. We host it, right?
You don't gotta worry about it anymore. Well, yeah, they said it with the best of intentions. I'm not accusing them of lying for me, but, um, that being said, isn, it is it what Microsoft doing around Office 365, good enough, or, or like most cloud-based security, what we found is that, uh, the, the cloud host goes to here, but you're responsible from here to there.
Yep. And that's a nice segue into, um, the shared responsibility model that Microsoft has. And you can do a Google search on that and, and find a webpage that describes that whole thing.
And the shared responsibility model for Microsoft basically says, uh, kind of what you just said, right? We handle this stuff and you the customer have to handle this stuff. And when we talk about SaaS, software as a service, which is what 365 is, the customer is ultimately responsible for data identity and things of that nature.
And when we say identity, that's, we're talking security, right? And so, right. That move, that movement to the cloud changed a lot of things.
And you were talking about how we used to do things right with Perimeter defense. Um, yeah. When, when Microsoft says we're handling security, there's, there's some level of truth to that because when it comes to things like securing the servers that are running that infrastructure, all of the stuff that they handle internally, yeah, they're handling the security for that.
But what we did as an industry is we created all of these different, uh, you know, points of contention in terms of security and different ways that attackers can get in. Um, we created an entirely new attack surface, right? And so, um, you know, we've had, as an industry, we've had to figure, figure out the best practices and how to secure that.
How do we, uh, you know, secure email that lives in the cloud, how do we, um, secure management portals that, that live in the cloud? Um, the other thing that I, I bring up quite frequently in this conversation is, um, file storage. Think about how we used to do file storage.
We used to have a file server on premises, right? And you could walk in the server room Used have Exchange Server too. Yeah.
But, Yep, exactly. Same thing. And so SharePoint online and OneDrive for Business has become the new file server for the enterprise, right?
And so, um, you know, I mentioned our permission manager solution. You think about how easy it is for, uh, people to share files in any office application, there's the share button in the top right corner, right? Um, very quickly businesses run into a situation where they're like, whoa, hey, we, we have 10,000 shared documents, um, 800 of them externally, you know, it's, um, permission manager.
Our solution allows you to help wrap your hands around that specific problem. So that just comes back to my point with this cloud thing. We've just created a whole new attack surface that's, you know, companies like Hornet Security, you know, we've, uh, sprung up to help, you know, customers and, and businesses and enterprises secure that infrastructure.
So Ported actually has that apps that built, uh, that help with these things such as Permission Manager. Yep. And those are like basically SaaS based apps.
They're correct. And it sounds like you might be offering them through MSPs and MSPs, Correct. Yep.
So, um, we'll go straight to end customers as well too, if, if customers want, we are channel focused, right? So, you know, if there's a channel partner in your geography, obviously we're gonna work through the channel partner, but we do cater to MSPs and MSPs as well. Definitely.
Excellent. Right? I think I got it.
I think they got it. More importantly. Nice.
com. Correct. Alright.
Alright. Let's turn our attention now to DAC, right? Sure.
We, we have it. As I told you earlier, we have a very technical audience. I think most folks out here know what we're talking about, D market.
It's not some new regulation from the EU or anything like that. But, um, you know, dmar is, is a setting on your mail servers, basically on your DNS and done, right? It helps ensure your mail gets delivered and not into spam boxes and junk boxes, uh, done wrong.
And you are a security risk like Typhoid Mary, and, uh, for sure, you know, someone can come in here and in essence hijack your mail infrastructure or your mail domain authentications and so forth, uh, to, to, to send malicious. And not only that, they can probably come into you, but you are the expert. Andy, how, how do you describe DAC For sure, it's DAC is often asso, I I shouldn't say often.
It's always associated with two other protocols in the email security space. And that is SPF and DI and the three protocols kind of work together, uh, and form what we call this email authentication, um, framework, right? And it serves a number of different purposes.
One, we wanna stop things like domain spoofing. com, um, you know, I don't want, uh, my next door neighbor to spin up a mail server in his basement and start sending email as my domain, right? And so, um, those three protocols, that's one problem that those three protocols look to solve.
The other one is in terms of email deliverability, right? And so when we look at the, yeah, a lot of the large email players in the industry, I'm thinking like Gmail, as strange as it sound, Yahoo's still a really big email player for private mailboxes. Um, they're starting to require things like DAC dec, Kim and SBF be configured properly in order for, you know, the mail, whatever piece of mail you're sending to not end up in their junk mail.
And so it kind of solves those two problems. And, um, I find that dmar, DIM and SPF are, they're those protocols that, like you said earlier, they're kind of the soft under Billy of, of email security and that a lot of people, they see those, you know, those, those acronyms, but they don't really understand what they do. And so, um, it really comes down very simply to this.
com, right? So I'm, I'm telling the world, this is where my email is coming from. com.
What D-M-A-R-C does is DMAC looks at both SPF and D Kim and it basically tells receiving email services, what do I do when one or both of those checks fail? So if SPF looks good and D failed, do I still deliver it? Do I reject it?
Do I put it in quarantine? Right? So D-M-A-R-C kind of tells, um, mail servers what to do when those checks either of those checks fail or both, right?
Um, hopefully both of those checks pass. And that's basically gives the receiving email server a high degree of reliability that, hey, this is a good email and we can deliver it through to the inbox and not the junk mailbox. Right?
So at a high level, that's kind of how dmar DM and S-P-M-S-P-F all work together. Very cool. Now, in figuring, DMAR is the bane of many an administrator Sure.
Is. Why, why can't, what can't we, can't we somehow AI this or something, right? What, what can we do to make it easier?
Well, the problem is, is there is DNS configuration in place. I mean, you look at your, your email configuration, right? I stand up a new mail server, or I switch to 365, whatever, I have to go in and configure my Amex record, right?
To tell the internet, here's where my mail server is. Well, you have to do the same thing for DA and de. Im, you have to, to configure DNS, uh, because DNS is a component of that, of that protocol.
It uses DNS for, for, for its checks. And that can be a problem for a number of different reasons. Um, I find that there's still administrators today that, um, they're not comfortable with DNS, you know, they're afraid they're gonna break something and, um, you know, so they're a little leery of it.
And so maybe they don't want to, to tinker with it. Uh, at the same time, I find that, um, a lot of administrators don't know where their DNS is hosted, or if you're a service provider or a large enterprise that you have multiple domains that you're sending mail from. Um, you know, maybe you don't have the credentials for the DNS provider for all of those, right?
So there's a lot of different reasons I think why people kind of, um, you know, get a little bit worried about configuring these services. And even all that aside, when you actually go to configure the record, there's a very specific syntax that has to be followed in order for the protocols, the function properly. So I guess, you know, when we talk about manual configuration, we as humans are prone to mistakes, right?
And, you know, the more complex something is to set up, the more chances there are for mistakes. And, um, a lot of business, I don't know many businesses that can tolerate any interruption in mail delivery, right? Um, at least not for any length of time.
So I think that's another, another factor as well too. So, yeah, I mean, hey, I, I've configured DNS I've configured Dmar. I don't consider myself an expert by any stretch of the imagination.
And I will tell you, I do, I get nervous. 'cause, you know, just setting your DNS service, your primary, your secondary, I always have three. And you know, I don't know if you ever knew Dan Kaminski, uh, who unfortunately we lost a year or two ago, but Dan, Dan is a, was a giant in the cyber industry.
He's the one who broke the internet or could have broken the internet one day with the big DNS. That kind led to the whole secure DNS uh, market. Um, but, you know, ever since then, I'm always real careful when it comes to playing with DNS and, and Dmar.
'cause it's part of it, uh, about, you know, and, and it just screams to me that this should be something that if not automated, some, some sort of service that makes it easier for people. We, I've always felt if, if, if it's something that people get queasy about, that's a solution that that's a problem in search of a solution. Right?
And it's funny you mentioned that because, uh, sorry, go ahead. Go ahead. No, I was gonna say, I was gonna say, I, I'm surprised we haven't seen it.
Go ahead. So We got, we do have a, uh, a DAC solution that we have put out as part of our, our stack now surprise called DAC manager. And it's designed to make the process as easy as it possibly can be.
So it gives you a nice centralized location where you can keep track of the records for the various domains that you're, you're managing DAC settings for. Um, we make it easy to, to manage the DNS records from that single pane of glass, um, depending on the provider that the DNS provider, you're using rights. Um, and the other thing is, is we make it really easy to view, uh, DAC reports as well too.
So I I didn't mention that earlier. There is a, uh, function of the DARC protocol that allows you to see a, a report. And basically what this report entails is, um, what's happening with DARC?
Uh, are, are males getting quarantined somewhere? Are they, are they being delivered? Um, you can basically find out, you know, a lot of information about your, your own domain's, email traffic, who, who is sending as your domain, you know, is anybody out there trying to spoof your domain, right?
And so we make it really easy to surface all that information in one nice, easy to use portal. Um, that's all of our other tools in our stack sit inside of as well too. So it's, uh, it's a one-stop shop, single pane of glass for DA manager and all of our other security tools that, uh, administrators might want to use to secure their 365 in infrastructure.
Very cool. com. Indeed.
All right. Hey Andy, we're about outta time. Thanks for coming on here and talking a little d mark with us.
Yeah, appreciate it. Thanks For having us. Let us know a little bit more about Hornet as well.
Well come back on. Keep up the great work. Keep it safe out there.
God knows we need it. Sounds good. We're gonna take a break on Tech Drunk tv.
We'll be back in a moment.