Transforming Zero-Trust Access with Craig Davies
Gathid CISO Craig Davies explains how artificial intelligence (AI) will be applied to make it easier to use identity to ensure zero-trust access to applications and IT infrastructure.
Transcript
This is Textron tv. Hey guys, thanks for the thrill. We're here with Craig Davies, who's CSO for cat, and we're talking about identity as an attack surface because it seems like, well, we've spent a lot of time securing everything from the network firewall all the way through to the database, but maybe we're overlooking this whole thing about identities and credentials and all that other stuff that the bad guys are really after.
Hey, Craig, welcome to the show. Hey, good morning Michael. Good to be here with you.
On the plus side, we hear more about identity and identity management and things like zero trust as of late. But it seems like we're having a hard time figuring out what exactly is an identity. 'cause maybe people have identities, machines have identities, software components have identities, and it seems like they're all under attack.
So what's your assessment of where we are in our level of maturity at the moment? Well, I think it's interesting that, uh, identities for since the beginning of technology have been the key element that, uh, have driven so many systems, but we've forgotten about them a little bit. You're right, we've developed, you know, firewalls and patching methodologies and UpToDate, you know, insert random piece of wonderful technology here.
Yet the most common attack that an enterprise will suffer when you think about it, is related to an identity issue. Be it a forgotten credential, be it, uh, someone with too many rights in the environment or even down to our current, uh, flavor of the month is the reuse of credentials and the reuse of identities being seen as an attack method against many, many organizations. I think it's really important to note that when you look back at the, a lot of the breaches over the past period, that so many of 'em seem to relate back to a people issue rather than a weakness in a piece of technology.
Why do we have so many zombie identities and credentials running around that people are no longer using that have these full sets of privileges that were granted at some time and then forgotten? Is it nobody's job to kind of pay attention to all that stuff? 'cause on the face of it, it seems pretty fundamental.
It does seem fundamental, doesn't it? But the fact is, nowadays with the world being so distributed, and also it is so easy for an organization to implement new tech, particularly cloud-based environment, or as I sometimes call it, credit card architecture. So if someone sees a really great tool, they flop out the credit card, they buy it, they share it with a few people in the organization, it goes growth.
The people who may see themselves as accountable for identity never actually know about it or perhaps don't see it as in their remit. So we're not really clear as to who should do it. The other thing that happens is, whilst we have regulatory frameworks that expect us to do user access reviews, they're only expected to be done at best quarterly.
Whereas these attacks can happen in the blink of an eye. Many organizations don't have robust offboarding or onboarding procedures. So this leads to this exposure of these little identities around this is just the people identities, let alone systems and, and, uh, processes around it.
And we see this continually that this lack of visibility creates this unexpected weakness in your architecture or in your environment that no one's a hundred percent certain it should do it. I think they're really important to think about when you look at some of these great tools that get used for cloud, um, that, you know, I'm not sure if it needs to be owned by an IT function, but you do need to have something that can provide that governance. And if you, depending on compliance to get it done.
So many organizations, their number one way of doing a user access review, which I think is a nightmare, is you spend weeks creating a wonderful Excel spreadsheet. You send it around the organization, you get some of them back eventually, but, you know, time passes from from there. So people don't have that scene, don't see it as such a critical aspect of their environment, and it kind of just floats along until it goes bad.
Do we need just more adult supervision here? To your point about the credit card architecture, it seems like we let developers provision infrastructure with these lovely tools they have, whether it's Terraform or whatever it is, but we never look for the misconfigurations. And a lot of that seems to be around how, um, authentication and access is grant.
Yeah, but you know, in a modern organization, do you want a central point of control, you know, doing that? Wouldn't you rather prefer to have, you know, it's the whole thing we talk about is security, you know, trust but verify. We feel that it's better to have an oversight capability that can see this thing, these things happening automatically and then build that environment as visibility and then let you manage that rather than creating bottlenecks in environments where people, uh, need to go and ask, you know, need to lodge a service ticket to spin up a new instance of something.
Or someone might wanna trial some, uh, you know, a piece of tech they've found. You know, I've worked in organizations, you know, my background, uh, I'm Atlassian, I'm ex medical device company. I'm ex banking, uh, I work in the startup space, our own company gathered.
We use a range of different technologies. We don't have any in-house systems. So we've gotta have a view of all those things.
And then all those companies that I've worked with over the years, particularly smart, fast moving companies, the oversight and the audit or visibility layer is far more important than the control aspect. I feel you've got robust procedures and you've got that visibility. You just want people, be it developers, whatever team to get on with solving the problems they've been charged to solve, rather than worrying about filling in form 57 B to provision a new vm.
You cannot walk down the street these days without somebody leaping out to tell you about their great new AI thing. And can AI save us from ourselves here when it comes to identity? I think the early days for ai, and I'd love to know where it lives on those, uh, graphs.
You know, is it at the peak of expectations or, you know, inflated expectations? I'm not really sure right now. And I think one of the challenges is depends On what hour of the day it is actually.
It's right. Well, look, you know, you, the AI that you, I've been everyone I think's been playing with, be it, you know, chat GPT or copilot. But you know, let's talk about copilot for a second.
Really great piece of technology. We're seeing it being used as a tool we need to build into our platform so people can ensure before they release the AI of copilot into their environment, they haven't inadvertently opened up material in their SharePoint folders, which has been documented cases about before. And then, you know, you think about the tools, you know, the image creation tools, photo editing, whatever, even your phone now allegedly has AI in it.
You know, you can highlight something and remove something out of the photo, you know, perfect for removing that pesky friend who does the bunny ears behind everyone all the time out of the photographs. Mm-hmm. But where the promise of it lives is being able to help you to see those extra patterns that perhaps you haven't been able to see before.
Now people are really good at seeing patterns. So we, you know, in our platform we produce a a spider graph, we've got a patent around how we describe it, and it helps people to map those relationships visually rather than a flat, you know, excel type spreadsheet. So the promise of AI is to help you, particularly in identity, to start to see these outlying aspects or you know, what we call a poison combination.
You know, someone has got an incredibly high right in an application, but everybody else who has a similar role doesn't have that. Or someone who perhaps lives in New York City has physical access to a building in Austin, Texas. You know, what's happened there?
You know, all these little things that get missed, you know, be it building access systems, be it operational tech, you know, uh, I've worked in manufacturing environments where you have lots of this little systems running, you're never really sure who has access to it, your know, air gap systems, they never get really audited 'cause they're very hard to do. Um, what we've worked on is to ensure that we can get the information outta those systems, even if it's traditional sneaker net, you know, grab a file of a system, walk it across the room, plug it into ours. And the more that we can do that, then the AI and machine learning algorithms can get a better handle on what a typical enterprise or your enterprise should look like.
Like. So then you're starting to see anomalies in the environment. So if we take a bank, you know, we've got a client who's a bank, uh, clients who are banks, and, uh, they're very keen to look at, you know, role-based access control.
So what level of access should a typical customer service officer have? What level should a lending officer have? So AI will help us to map those anomalies and also validate that those people have the right level of access across their entire environment, not just that particular ERP lending banking system, whatever they have.
I always think that many organizations have probably one or two systems where they've got a really, really great handle on their access control, but they don't necessarily know if who's got physical access to the system. Particularly nowadays in the world of remote work where you might only see a person once a month, once a quarter, Has this all become a bigger issue post covid? Because very few of us are in the same location where the central physical office we're all over the place and some people are going back to the office.
But even then we're all pretty much working hybrid anyway. So it's kind of hard to know when who's using what machine based on what privileges when. So is this getting just too hard?
Well, it's getting challenging or you know, for us, we've worked in technology for a while. I think it's a really great adventure. You know, how do you figure this out?
We've got, uh, we client who's mapping, uh, expected IP addresses for a person against their normal profile in the platform and they're flagging anomalies if they should go somewhere else. Now, if you think, if you work for that company, I think that's a really great idea, except you wouldn't probably wanna take your laptop down to the local cafe, you know, because perhaps you're gonna flag an alarm. But, you know, I think of our own example gathered.
You know, we're based on, uh, on the Gold Coast in Queensland. Yeah, really great place to live, beaches, all those things. I live in Sydney, so I only go to the office at best once a month.
We've got team members in Melbourne, we've got team members based in the United States. We've got team members based in the Philippines. Uh, usually one of us is at least traveling at the moment.
We've got some staff traveling in the United States at the moment. So we're a fully distributed organization. In fact, we don't officially, you know, in terms of technology, have an office.
You know, our office is set up. I describe the network, it's set up like a cafe. You know, you come in, you authenticate and you work if that's where you choose to work that day, we are still figuring out if we should buy a printer.
We don't even own a printer yet because people, uh, you know, their work is where they happen to be at the time. So that's what organizations are facing. So, uh, one of the challenges for many people, the number one challenge we see for a lot, which gets forgotten about, is things like building access management.
You know, unless you're one of the big players, you don't run your own building access system. You just kind of, you know, you're in a building from there. Um, distributed technology, you know, someone uses a cloud platform for marketing or for technology or for finance and you may not see it.
And because you don't see these people, your endpoints become the perimeter of the enterprise. So you don't necessarily have a great handle as to, you know, who's accessing that endpoint? Is it supposed to be in our environment?
What does its positioning look like? Does it meet our compliance requirements? Do we actually know what our compliance requirements should be for a remote worker?
And I think many companies still a couple years post covid are still trying to figure out what it is. They're still living in this command and control environment where we thought, oh, we'll put everyone behind the firewall and it'll be nice and safe there. Whereas now people work anywhere.
So that's why our systems, our identity systems need to reflect the reality of modern work. And that's what we've been working on to ensure that our modeling tooling allows you to still see your environment, still create that provisioning and still see where the threats could be in your environment from there. So who wakes up in the morning and says, I gotta go solve this issue, or says, I gotta go get on the zero trust bus and figure out what's going on with all this identity management stuff.
I mean, 'cause sometimes I feel like, um, it's the IT people who provision access and they do what the business tells 'em, and then the security people come in behind it and say, my God, this is chaos. But, but who's in charge? Um, well, you know, who wakes up in the morning and wants to solve this problems is like, hi, I am Craig.
I'm from Gathered. You know, and the, and the, you know, the rest of the gathered team, you know, we, our legacy is 20 plus years of doing, you know, this physical identity systems for large organizations, very large organizations, you know, name, you know, household name organizations. And we saw this problem brewing.
And I think in organizations, um, I think the really key point that you've kind of talked about there is the business, right? IT people and security people go, lemme just remind you all, you are the business. You know, it's your responsibility to be thinking through how the company wants to work and how you're going to solve it.
So the person who wants to solve it, I don't really care whereabouts you live in the organization, but someone needs to have that epiphany around this could be a problem for us. And then it needs to be balanced against the reality of the business problem you're trying to solve. If you're trying to solve this purely from a technology value point of view, you're just gonna look like the sad person in the corner going, this is a problem, this is a problem.
You have to bring it back to the business challenge that you need to solve. And the business challenge could be, we've got people, you know, constantly remote, we don't know who has physical access to our buildings or, um, our entry procedures or our off-boarding procedures are really bad. So if someone leaves the organization now, it's not like they could before where someone leaves the organization and they can turn up at their desk and go, yep, we'll have that, thank you.
And, you know, give their belongings in a, in a bin liner and, you know, they get escorted off the premises. Now it could be the other end of a Zoom call. And the other one I think about, and uh, I've written some articles about this recently, is the onboarding process.
Nowadays, because people are so distributed, you've gotta get this onboarding process really robust because you think about yourself, mate, you know, you've been in a few organizations by this stage. We've all been in a few organizations. Everyone remembers how bad it was for the first couple of weeks when they joined a new company.
You know, they didn't have access to this system, they didn't have the rights, and they couldn't see this thing and they were asked to do that. So, you know, people get all excited to join an organization. We give them all the big thing, we give them the little pack on the first day, we welcome them aboard.
Perhaps they get the T-shirt and the coffee mug and all those things. And then we're kind of like, and good luck with that. Um, so the principles behind managing identity programs really well allows you to create an incredible onboarding experience as well.
You know, where people don't have to chase this stuff where they just get the access. But the other thing it lets you do is ensure that that's optimal. So you don't necessarily assign all the rights that Barry has.
'cause Barry's been in the organization for 15 years and he's got access to everything which he shouldn't have. You don't wanna mimic that. And then conversely, with people off board, um, I talk about this a lot with, you know, insider threat and you know, people leaving.
When someone leaves an organization, you have an obligation and you want it to be a wonderful experience as well. 'cause maybe you're gonna rehire 'em down the road. Maybe they're in a career growth that's important for them to move on.
But so many organizations either get breached because a credential gets left behind, particularly in the cloud platform, or they think they've been breached. Because when Sally left Sally hack us, you know, afterwards, and there's been court cases on this stuff, but what you want to have is that visibility. So when Sally leaves, you can exit them with dignity.
And more importantly, you can honor the fact that they did work for your enterprise for a period, and you don't see them as an ongoing threat to the company by going, oh, well that's because, you know, Sally still had access to the environment. Oh, trust me guys, that's a, like an epic fail on you, not on Sally's behalf. All right folks, well, you heard you here.
I think it's fair to say that when it comes to identity, we're, shall we say, little schizophrenic, but hey, once we start admitting we have a problem, we're halfway there to solving it. So there you go. Hey, great.
Thanks for being on the show. Thanks, Mike. It was great to spend some time with you.
All right. And back to you guys in the.