Customer Experience in Cybersecurity – Arvind Nithrakashyap, Rubrik
Natan Solomon chats with Arvind Nithrakashyap, CTO of Rubrik, about the impact customer experience (CX) can have on the efficacy of cybersecurity. Natan and Arvind also discuss how organizations can improve CX with continuous feedback loops and increased visibility, as well as the ways security and engineering teams can benefit from becoming more customer-oriented.
Transcript
This is Textron TV. So hi everyone today, we're here with Arvin Nick nithraca shop. Goes by Nitro.
Did I pronounce that right? Yeah, that's that's pretty good. Great.
So Nitro is the CTO of rubric. How are you doing today Arvin? I'm doing good.
And thank you so much for having me on this program, of course. So, um for people that might not know who you are. Could you maybe provide some background on your experience in this industry and how you gotten to where you are now?
Absolutely. I actually started my career at Oracle as a software engineer there working on the core database product. In fact people lose my co-found and CEO and I used to work together at Oracle.
That's up. So we know each other for more than 20 years did a bunch of stuff there as well as launched X8 products and storage platform specifically focused on the database use case. So I have the three of us who started that project and was there until mid Lisa first version and then after that I mostly worked in small startups and most recently before rubric was at a advertising online advertising startup for Rocket Fuel, which is really about doing real time ads real-time ad buying for display ads through ways exchanges spend about four years here there and that's when people and I reconnected and then we started exploring this space and the more we look at it.
Well, like there was that means much destruction in a long time and that the world had changed but a lot of people to start with very old Technologies. And so we felt it was an opportunity to come and do something very different and change the game there and that's how we got started pulled in a couple of other co-founders and started rubric in 24 14, that's amazing. And so for people that might not know exactly what you guys have going on at rubric.
Could you like dive into that and your role with the company? Absolutely. So at rubric we are 100% focused on providing data security to our to our customers.
Right? So today we have 4,500 plus customers that we partner with we have been the company has been around now. We're actually eight plus years we started in 2014 and we're about 2,500 plus employees the what we mean by data security is really about as as you as you probably know in the last few years the number of attacks that have been happening in to across Enterprise as only reason right and and very often when you think of security companies are mostly looked at walking infrastructure security.
How do you secure the firewall? How do you make sure that the security posture within in terms of credentials accounts? All of that I managed.
Well, right, but and all that is great. I mean it protects you from the perimeter make sure that none of the malicious actors get into your into your assets, but then When that one in 10,000, you know. You know breakage happens.
The core asset that all of them are after is your data and today for every Enterprise. You their businesses business runs on the ability to be able to access the data, but it's customer information or internal information IP. Whatever it is and what the what that attack is a targeting is can I get to those critical assets?
And either make them inaccessible or Worse even exfiltrate them and threaten to release them into the public domain and and extractor Ransom in exchange. Right? And and this is something that has only escalated and the interesting thing about this is that it has become almost it's it's become the you know, almost like a business model where these these malicious actors are able to go and You know sit in something maybe even in a foreign country and attack or Enterprises and actually extract or Ransom and it's almost a safer way to do crime than doing anything in the physical world today.
Yeah. So this has been in the on the increase and you know, even through the pandemic we've seen today I would say that there are you know, in any given week that I wanted to customers that are going through a ransomware mediation process and we are helping them through the process. So this is happening every week.
There's one some customer we're helping through this process. So it's it's all over it's happening very very frequently. Right and like as cybersecurity advances, so it has ransomware and the the way that people are conducting attacks.
So it just seems like you guys would like to stay one step ahead always right and that's I think and especially but you know, but the pandemic there's explosion and in Virtual work people. It is a distribute much more of a distribute Workforce today than it was even two years ago. Right?
So people are taking the laptops everywhere, you know, they're walking remotely and and what happens is just increase the surface area of attack right and and very often a very common way in which the malicious actors get and it's through credential stealing right could be a fishing attack. It could be. Oh you're on a network.
That's not as secure because you're working remotely. That it it's no longer while in the past because everybody comes in the office and I really secure my office. It's no longer the office.
It's no longer a constrained area. It's it's distributed globally, right? So because of that that the odds that you there is some kind of a, you know, breach just increases and while absolutely should focus on infrastructure infrastructure security and do everything to secure that You also have to always think about what happens if there is a breach.
How do I protect my other core assets on which which are critical for my business and how do I make sure that If God covered or something like this happens how like quickly remediate and get my business backup company and that's what we are focused on. So it's complementary to everything else you see in the in the in the security landscape, but we are I think this is a missing Dimension that that we are focused on and really want to you know, help our customers right? It's it's integral also, because the more people that are online the more potential targets there are so these cybercriminals are just casting a wide net and some things they're gonna catch something right and so speaking on cybersecurity and especially Hot Topic is the impact customer experiences can have on the efficacy of cybersecurity.
So any thoughts and the importance of this within this industry Yeah, I think what's happening is again. If you go back over the last 10 years, right? We talked about data being the critical asset for your business.
The problem is that that critical asset is not, you know, safely guarded in a locker it exploded. Because businesses have you know today businesses are many of them are the Enterprise but they're moving to the cloud. They're using SAS applications some organization use hundreds of SAS applications on a daily basis.
And this is how they make their their book was productive make sure their customers are getting the the right kind of experience that they should so what's happening is a proliferation of data in multiple forms and factor form factors across across your organization. So what so when there's so it's it's beyond kind of like human comprehension is just one, you know diligently go and safety guard all of these right? So so what happens is you have to really focus on making this simple for the for the for the practitioners for the for the whether it's the sea salt the security organization or the it organization.
They can't there's a giving bombarded by information from different sources. However, they kind of separate the signal from the noise and focus on the true threats and make sure they mitigating that so customer experience is becoming even more important per day because of the so when I say customer experience I'm saying In in the normal runtime, can you can you make sure that your data is resilient, right if something happens, how do I make sure that all my critical applications or my critical databases are protected. So that's one piece.
Then there's a lot of activity that's going on within the organization one one key observation that you know be important from many Security Experts is that it's not that doesn't that actor comes in and there's a breach and the immediately goes and does something very often these these malicious piece of software light dormant for a long period of time and then they look for the right moment to attack but the right ask that to attack. So so what you have to do is you have to constantly keep scanning your your internal ecosystem to detect such things and see you. There's some action to be taken.
But again, you can get if I give you thousand alerts every day. You can't you can't human it's not humanly possible to right be so visibility has to be ability has to be it. You have to really call out the five things that you should look at and and make sure that you're separating the signals in the noise.
And again that's part of the customer experience right in the sense that you got to make sure that it's simple and easy for people to Target the key things they should do and then the last piece is God forbid it doesn't attack. It's probably the most stressful day for any of the operators trying to remediate that right at that point you you don't have the mental bandwidth to go and You know think on the Fly what do you want is a very easy. Time-tested way that you can remediate recover the data.
And and you need to be able to hopefully have done some practice runs before that that you know how how this operates and it has me very it has a few clicks human error can is another big factor when you do the recovery process human error can actually cause it long make it longer for you to recover. Because you miss something and all you have to go back and do the same process again. So as much as you can automate as much as you can make it a few clicks, and I can restore and and do it as quickly as I can.
Again, that's that's very critical because you don't have you you're trying to get the business back up under you don't have the time to check hundred boxes and make sure it's working. So so it's become a very critical component of all of these three. Pillars we see from overall, you know data security perspective and that's what we're focus on.
How can you make it some easy to make it resilient? How can you provide you the right kind of observability as you go through your normal operations and if there's any kind of an attack, how can we help you recover as quickly as simply as possible. So it's definitely a multifasted approach, you know, it's not just having visibility.
It's having the right visibility and having it be efficiently and and that ties into the response. Right? So like if there is an attack if if the visibility isn't efficient, what are you gonna do?
Right? So so how can security and Engineering teams become more customer oriented and like what would that mean for cyber security organizations? Yeah, I think the obviously customer feedback is important right?
So If you're trying to just this example, if you're trying to help customers remediate any kind of an attack, you obviously need to understand the process. They give to the you need to understand what are their pain points. So obviously you can do this through conversations with them.
For example, we have partnered with, you know, even instant respond response organizations to understand the process they follow to understand better the bottle next that we can go and you know help alleviate. But also I think in today's world as we move more to a kind of a sas-oriented application model we actually can get a lot of information metrics from customers as they go to this process. For example, if there's a workflow they're going through and they they basically they click on something or they spend too much time on the screen that's an indication to you that maybe there's some complexity in that process, right?
So then it gives you the right kind of questions. You can ask to the customer saying hey, I saw you're going through this workflow. I saw that this took a lot of time and not average just takes much longer than the other pieces.
Is there some complexity there. What is your pain point if you don't do if you don't get these very specific pointed questions, it's hard for customers. Just think back and say hey I need you to do this this and this because they are going to many such workflows during the day.
So I think today and as we and you know recently announced our rubric security Cloud product and ideas to really provide a central SAS control plane for everything for all of these different pieces that are amazing amazing. So from that perspect now, what we do is if every piece of interaction that our customer does goes towards aspect but we can actually get a lot more detail metrics and really hone in on what are the what are the points in the in the workflows that maybe are not providing the best user experience and where we can how can you make it faster and easier and simpler for our customers? So I think I mean historically when we think about security we think of like firewall, they think of back and we think of things we don't think of customer experience but even it's a human work humans are involved in all these processes and we have to make it easy for those people to step through these and and make sure they can do this quickly and efficiently.
So I think customer experience is becoming very important partly because of just the scale and size of the data that's that they have to deal with and also the complexity and the workflows that they have to go through. So the more we can do here and more we can make it simpler for our customers, you know, the more security they will be because if it's simple for you to make do a few things and be secure then it's easy, but if Our schedule 100 things. It's easy for you to miss right that explains.
It needs to be seamless for both sides. It's just excited issue because you're providing efficient visibility for them. But at the same time you need to have insight as to how to improve your processes, right?
And and so that's probably some of the challenge there. Um, but on the flip side of that what would a poor customer experience mean for cybersecurity organization like what sort of an impact can that have on utilization or efficacy? I think the number the way I see the number one problem is so let's say there's that there's an attack right and you're trying to recover from that.
If now if it's going to take you hours and hours to figure out how to do it. Yeah your business. I mean, it's your business effectively is down for that period of time, right?
So the number one point is if you're if you have four years experience your action recovery time, and the ability to recover will be seriously impacted which means your business will actually be Down or non-operation for a longer period of time so that's the number one problem. Right? But then the other piece is that while you know, obviously hopefully attacks cannot happen every day, but then it's really the what you do on a daily basis that ensures that you're better protected for these.
So then again if you don't have visibility into okay are all my critical applications and assets protected are all am I looking at the key metrics that I need to look at to ensure that there are no looking cyber attacks. If you don't have the visibility again, it's got up. It's going to boil down that you just miss certain things and you're just more, you know more prone to such attacks.
Right. So so poor user experience implies that it's just in very simply just makes you less secure. Because you're not able to use the tools effectively, you're not able to use the tools efficiently and every idea organization is is you know has hundreds of things that they're asked to do, you know, they get constantly juggling things, right?
So the easier we're making for the more effective they can be Right and the process needs to be refined before the attack happens because once the attack happens, it's a matter of response. You're not changing. It's just visibility and all of that.
Um, and one point is that we for example if some of your data are sensitive data is actually in the hands of of the Bad actors then I mean, there's not so much. I mean they can do a lot of damaging releasing personal information of the customers and so on so it's it's not just about Okay, impact the business you could actually have impact outside of your business to your customers as well. So it becomes even more critical right and and how does the damage control go for that when they get at like access to that critical data like Secrets, how what how do you backtrack and make sure that you're controlling the amount of damage that happens?
point Yes, so I think the key thing there is can you? Before an attack happens. Can you proactively monitor for example, there might be sensitive information that is sitting in a particular database.
And now you see that one States financial information. Why is somebody from the HR department accessing that commission and they've never looked at its before but suddenly they are accessing and querying all these records. So that's a trigger to say something is out of the ordinary here.
Maybe there's a valid reason. But most more likely this is there's something strange going on. So what that does is it it lets you proactively go and look at this and if you see that, oh, yeah, these people should not have access to information.
This is this is a mistake in the way. We configure our permissions and you fix that then what you've done is you have sealed that one one potential area of attack and prevented that from from being compromised. So it's a lot of this is around.
Figure out first of all, can you figure out by your sensitive information is in this huge amount of data that you would deal with on a daily basis? And then can you make sure that only the right people have access certain data. So the more you can reduce that surface area of attack the more secure you are.
Right. And so that ties back into ultimately your your how prepared you are for an attack tells you how your damage control will go because ultimately like if you know who has access you're just tracking that but I don't know that before you're in trouble, right and and most of it is because most of this happens not because they're malicious actor with an organization. It's because more people have access to this information.
They should and one of them is going to get compromised, right exactly and that ties into like the holistic understanding of user perception like how that can like, can you elaborate on how that can build the customer success in the long term opposed to short-term attacks just longevity was how having that that understanding effect customers. yeah, I think the the key thing here is you have to have a very good view in in terms of what are the critical sensitive made? It could be critical IP of the company.
It could be critical financial information. It could be critical personal information. What customers are employees so those and and there are new applications being created every day.
There are new copies of the data being created every day because there are new use cases coming up. So but as soon as a new You're such use cases come here can actually go and very quickly understand that. Oh, it's not just sitting in this database.
There's another copy of this data sitting in this database. It might be a valid use case, but then it's now I need to make sure that I'm also keeping an eye on that. So what you need is you can't go manually look for these you need to kind of have the system kind of tell you there's be some kind of tool that wants you that's saying Here here's some sensitive information that I've now found in this database that wasn't there yesterday.
So that's precise the kind of stuff we do which is As we protect applications day in day out we say oh yesterday. There was no sensitive information here. But today this database has some sense of information, right?
How does rubric like productize like the this increased visibility and customer experience? Like how is this offered to people? So what we do so so when we take VTEC VTEC, we protect the applications every so every day.
We take a copy of the data and storing it in a system. Don't you and once a new new version of the data comes in? We we actually scan through it to look for sensitive information.
So we can say that oh, this files are didn't have any sensor information yesterday. But today there was a new file that was created that contains some credit card numbers. So then we flag that and we send a notification to our customer to our customers saying we just found a new new hit where there's a file that sends information sitting in this place and there are thousand users of access to this file.
Wow, that immediately triggers the the either the security office person to go and say, okay. Why is that is this is a valid use case. Maybe it's a valid user but let me double check and they'll say oh no somebody made a copy and just put it in the wrong place.
Okay, so then let me take it out of there. So you guys are basically in a watchtower over these applications. Right?
And and so you are the visibility in a way but yeah, so what we're the the reason we're able to do this is we are taking you know copies of your data every day for from a data protection perspective you're doing this every day, right? And so we are able to use machine learning techniques to detect both an analyst changes. Hey, wow, why did 30% of the file this server?
And is this an attack? Right so we can warm customers? Why is Well, you besan here's a new fire a new file or database with sensitive information wasn't there yesterday.
Is this a valid use case? And if so, then maybe you should make sure that the the right permission the right people have the system and not everybody has access to it. So it's it's basically because that's and all of this.
This could be your sensitive information is probably one percent of your data, but there's you can't manually sift through it. But if a system is constantly watching and bringing and looking at the new changes and is able to analyze this and you know, really again separate the signals on the noise right point out the ones that you should pay attention to then you can go and take action on. Well, that's my question is do you guys treat all attacks the same or do you see a major critical breach and and treat that differently than you would something mind or like do you just flag a minor attack?
And like how does that work? How's that process so beer? So we are 100% focused on the data, right?
So so what we're trying to do is we are looking at patterns in the data that might indicate either the potential for an attack. Or maybe just the an exposure that you should not have. So this is say even before an attack is actually I'm talking about before an attack happens.
Can we proactively? Keep keep giving the customer information. So for example, we have this what we call a data security dashboard which gives you kind of a score and what that's saying is, how is your posture regarding sensitive mission?
Do you have sensitive a lot of sensitive information? Distribute across organization with lots of people access to so that indicates to you that okay. That's that's a problem.
That should go and look at or are there an analyst kind of changes that are happening that usually usually don't happen? So every Sunday, let's say there's a there are a bunch of files that are cleaned up in a particular server. Suddenly on a Wednesday.
I see that 30% of files are cleaned up. Maybe it's a legitimate use case but likely it's potentially attacked as well. So what we're doing is we're we're separating we are using machine learning technically separate a normal activities that happen.
And and point out the abnormal activities that could put a point to an attack then the customer can go and evaluate and see is a valid use case or is an actual attack that right. So so this is the kind of what we are constantly monitoring the data because we are bringing all the data into our platform as part of the data Protection Services provide. And then we are building these services on top of that to provide insights back in question.
Right? And as you as we were saying earlier the rise of cyber attacks, it's exponential. It must be like trying to find a needle in a haystack considering how many attacks or things that may appear to be an attack happened on a daily basis.
How do you sift through the noise? You know if there's so much traffic happening. How do you identify like this might develop into something that you know something that might be small now, it may be develop into something.
That's a huge issue. How do you sift through that? Yeah, it's again that it's that's where we employ some machine learning technique.
So kind of learn so once we start once Our system gets operational in a particular organization. We are monitoring the normal activities that happen so over call it a period of one to two weeks the system learns that okay. This is these are usually normal active.
So we don't want anything the first couple of weeks, but after the first couple weeks we kind of get a sense of the normal ways in which data data patterns change and then if something abnormal happens Essentially our our measuring models are indicated. Okay. This looks like a potential abnormal operation.
You should take a look at it in some cases. They might be legitimate things. Right?
I mean there was some one-off activities that are legitimate activities, but what that lets you do is if there are five such activities and four of them are okay, but there's one that is not then let you go probe and understand what's happening then maybe that is actually an indication of some kind of a Cyber attack or presence of you know, some kind of malicious software in the organization and I'm sure as she's more attacks it gets smarter and it's it's understanding what how things develop exactly but join another note. Could you dive into continuous feedback loops and how this is important to teams in this industry. Yeah, so the one of the things that we should realize I mean we talked about ransomware like it's a specific kind of attack but ransomware itself is constantly evolved right?
There are different kinds of techniques that people use at different kinds of organizations that that have very different ways in which they attack. So the the key thing is you there's you can't be static in this industry and part of it is yes, you can learn from what's Happening elsewhere, but you also constantly get feedback on customers on things that are working or or there might be changes in the processes within the organization that's only triggering false alerts and that's almost as bad as as real as missing a real attack because that is a noise that you have deal with so you constantly have to keep talking to customers to understand the systems working as you expect. Do we need to tweak it we need to tweak the models that we need to be.
We need to customize certain things for customers. So so the more you learn from your customers and the other piece here is certain things might happen organization. It might also be happening in hundred of the organizations, you know within your customer base again, if you can take all of the synthesizes and share that with the larger Community it also helps.
Spread the knowledge within the community and you know people proactively can learn from this and take more, you know protective actions. So so again, it's we are at this unique advantage point where we have as I said, both of our plus customers we can actually get learning from from all of them synthesize that and feed that back to our custom basing. These are the kinds of attacks we're seeing and you know, there's a new kind of attack.
We have discovered a particular customer. So you should you should watch out for what these kinds of things. So those are also very useful for the community to to kind of, you know, protect themselves against this the thing is we are I mean, this is not going away.
We think cybercrime is only going to keep increasing especially as I mean, there are even National actors who are doing malicious things. So as we as we kind of if this is going to continue to scale our we have to constantly learn and we have to be constantly willing to adapt to the changing that landscape and and so this is where getting candy is feedback understanding whether The workflows at work yesterday do they work today? Do we need to change them and you have to constant dynamically keep changing them and also feeding back the best practices to the larger community so that everybody learns from it and can improve their best practices.
Right? And so obviously you guys are providing the visibility into what the tax might be certainly like compromise or a difficulty to compromise when you when you tell someone like this is a risk and they need to commit resources to that. How does that exchange usually go is it usually they they take they take exactly what you're saying or is there some sort of a compromise with the ease of use for them versus what you're providing them information was?
It's it's often a dialogue. Right? I mean some some of these things are I mean, if suddenly we customers are discovered that they run this, you know, sensitive data classification product and suddenly they get 5,000 files and that have sensitive information.
So now there's going to take them like this a good amount of time to sift through this and actually figure out what is what is what is the what are the real issues here? So it's often a dialogue. What we're trying to do is is really Provide this information to our customers and then be constantly partner with our customers because we don't think this is a there's not a one shot thing.
Right? We you know, it's a journey of Discovery for the customers generated Discovery for us as we learn through them. So it's it's so what we do is We we provide this information if needed we'll be even you know, spend some time with our customers walking them through what this means and and how they can adopt some best practices.
One of the things we just recently announced we started the thing called zero labs to kind of just provide more more information about threat landscape to a larger community and this is really about can we learn from this and keep providing information, right? So so again as customers and I mean, let's be let's be honest, right? It's the customers are struggling to deal with a lot of things that are being thrown at them.
So the more information and best practice we can we can share with them the better, you know better with they are for all of this but in some cases these are simple resolve in some cases. It's gonna take an initiative that takes three months six months to get them into a better shape. Right?
But if you can provide information then organization can prioritize assess their risk and prioritize when they do it. Should they do it right now, so they you know, Them out. It gives them more information to be able to make such decisions.
And would you agree that acting preemptively is always the best thing here in terms of you say it can happen three months from now. How early do you need to be prepared for that in terms of being ready to deploy resources and stop whatever the attack may be. Yeah, the best thing you can do is.
You know put in the put in the right kind of, you know, observability and and metrics before anything happens right proactively look at it when when no attack has happened. That's that's the best time to go and SS is where there's are and then if you can do that then then you're better prepared for anything that happens. That's it.
But something happens got to reactor. But that time you don't have the luxury of time because you know business is down you're there are customers or maybe not able to access your products. You need to activate it.
You don't have the time to think through this and think about what long-term changes you would make so doing this preemptively doing this proactively when there hasn't been an attack let you plan this out. Let's you think about oh, you know what we need to rethink the way we are managing this kind of data. Let's put some of these controls in place so that three to six months from now, you know, we had a much more secure position as an organization.
So it's I mean, there's not easy and with the changing threat landscape you constantly adapt But again, if you get if you have this DNA productively monitoring, then you're better prepared for for anything that might happen and even different changes you need to make as you as you access the right. It's amazing. It seems to be ahead of the curve, right?
So before we wrap up where can people find more information on rubric so obviously we have you know, obviously the they can obviously start with our website but video, but we often do a lot of Webinars and just just to spend more information within the community. I talked about a zero Labs initiative which soon you'll start seeing a lot of information coming through about just what is the credit landscape? What are the best factors what you should do and and our hope is to really, you know, beyond, you know, obviously providing tools for our customers to to be able to handle this is to really be a source of Information and source of best practices that customers can learn from we also have a bunch of events.
We are obviously at the events like VMware explore and so on but we also have a user conference where we talk to talk about a lot of these things and do a bunch of introductions as well as best practices and things like that. Yeah, so and for our customers, I mean, you know, we are happy to they can reach out to us anytime we have. You know teams within our customer success organization our overall go to market organization who will jump on it and help our customers through it, right?
So there are we have everything of you know, different ways and channels in which we can help our customers, you know, navigate these landscape right? It's amazing. This is a great conversation Nitro.
Seriously you guys seem to have a lot going on there. I really appreciate you taking the time to talk with me about this Bank around me. It was a great job as conversation with you.
And yeah, it's a it's it's not an easy problem, but, you know one separate a time. Hopefully we can keep evolving. Am I right got it here.
Got you. All right. Thank you so much.
Thank you so much for having me. Have a great one.