Fueling the Future of AI Data Security – Sentra’s $50M Series B and What’s Next with Sentra’s Yoav Regev
Yoav Regev, Co-Founder and CEO of Sentra, joins TechStrong TV following the company’s $50 million Series B funding announcement. In this interview, Yoav will discuss how the new investment will accelerate Sentra’s mission to secure sensitive data in the AI era.
Transcript
Hey guys, thanks for the throw. We're here with Sentra, CEO, Yoav, Regev, and they fresh off raising $50 million in additional funding and they're in the data security space, which is getting a lot more attention 'cause people are realizing, well, that may be the last line of defense. You have welcome to show.
Pleasure to be here. And thank you for having me. There's a lot of folks in the data security space.
So why don't you describe a little bit about the company and what makes it a little bit different from everybody else in the problems you're trying to solve? So, uh, we are in the, we can say data security, but at the end we deal with the data itself. And what we have started to solve a few years ago.
And we think more and more it's about how to help organization to understand the basic questions, to understand the basic thing about the data. And in the past it was very hard to do it, but uh, with the movement to the cloud, we can see that, uh, organization have more and more data and they kind of lost control about what they have. And when we speak about large enterprise, that they even more important for them.
And what centra do, what what, what we do, it's, we help organization, first of all to know the data. Second, uh, uh, to, uh, understand and to classify the data. And they, of course to secure the data.
So we are very different, uh, in few aspects. We have a very different approach about to do everything in the customer environment. We don't take any piece of data outside.
Secondly, we do in a very efficient way, discovery, highly accurate classification. And the context, when you combine that together, you cannot find such kind of solution at scale. So how do I actually secure the data once I discover it?
'cause I think to your point, a lot of people struggle with trying to figure out, well, what data matters? There's so much of it. But once I get past that, what do I gotta do to actually secure this?
Of course. So at the end, there's a few different approach, depends on the organization, depends if it's a compliant, depends if it's a specific, uh, uh, data, intellectual property, uh, PII. But the main, uh, uh, things to do, the main action to do is to make sure it's part of your policy.
So what you do, you can, uh, when you find duplicate data, you can delete their irrelevant data. So you can reduce the risk when you find your most sensitive data, like PII or PCI or PHI, outside of the production of the relevant data, you can understand and find the root cause analysis whenever you have, uh, and you understand that, uh, you have data that is not in the right position. So after you understand the data, you take the action that's relevant to the data itself, to the context of the data.
And of course, as part of your specific policy, uh, that it's a bit different from one organization to another. Have we over invested in the perimeter security, which doesn't seem to be all that effective anymore, or even endpoint security for that matter. So do we just need to retrench at the data level?
Absolutely, uh, totally. Uh, uh, it's totally right. Data has its own life.
Um, you know, when we started, uh, uh, uh, to think about Sentra, uh, we came with a few, uh, uh, different aspects, different, uh, understanding. And one of them was that of course data is the most valuable asset, but most of the other solution deal with the wrong uh, uh, uh, approach. They deal with the endpoint, they deal with the infrastructure.
At the end, you need to deal with the data. And in the past it was good enough to deal with the infrastructure and with the other product, it's very important, by the way, you want to reduce the risk. But the data itself, it's everywhere.
Uh, uh, you move more data, you share data, of course, with the AI models that you push the data to a place that you cannot control the next steps of the data that people use it. So for sure, you need to think and understand the data level, the data layer, to understand the data, to track the data, and to make sure the data is well protected, protected. We're also living in the age of ai.
You can't walk down the street without somebody leaping out to tell you about their great new AI thing. Is the volume of data getting to a point where it's just gonna overwhelm us? Absolutely.
And you know, we can, when we speak about AI at the end, it's a data problem. It's a data issue. It's not, uh, it's not ai.
It's only one way to deal about state-of-the-art technology, that organization want to leverage the data they have. And if we take a look for a moment, not about ai, about the business side, about the data, they have the best organization in the world. The organizations that want to be the leaders, uh, they know how to be a data-driven organization.
They know how to leverage the data. They know how to adopt new technologies exactly as ai. And you cannot move to to, to that approach.
You cannot make it without, uh, controlling the data. You don't want to slow down the business. You want to push the business.
So from one hand, you want more and more data. As more data you have as better decision and better understanding you can make. However, as more data you have, you need to know how to deal with that.
And this is exactly, uh, our approach. And this is exactly what we can bring to the board because we help organization, and I like to say, move fast and secure. You want to move fast, you want to use the data, you want to get more data, but you know, but you want to do it with a a a a in a responsible way.
And this is exactly what I believe is the future, more and more data. But in responsible way, Will we use AI to secure the data that we're generating using ai? Yeah, so ai and again, uh, you can replace AI with technology, but let's focus, uh, ai, ai, you can use it, uh, to, uh, uh, to be much more sophisticated as, uh, from the attacker perspective.
You can use AI to build your solutions. Like as we do at Centra, we help AI a lot internally to make sure we can bring the best, uh, uh, classification as an example. And of course, you need to protect and secure or to use responsible AI for the customers.
So many different aspects about how AI can be part of your life. From, uh, our perspective, the most important part or parts, uh, are first of all to use AI organizations that will not use ai And Central is part of them, uh, will not be there and will not, uh, uh, uh, uh, uh, be the best ones. So we use a lot in a very different approach.
And the most important part for us is to secure the ai, uh, uh, uh, processes, the ai, uh, uh, uh, um, uh, for our customers. Do you think we need to look at the data that we're creating and, um, manage it better? Because most of it's not particularly classified and, uh, or well, and most of it is duplicate and all that data seems to just expand the attack surface we're trying to defend.
So are we in some level our own worst enemies? Totally agree. Totally agree.
And this is exactly the way I believe we need to handle that problem. And I mean, you don't want to tell people, don't create data. Don't share data.
No, you do a, a wrong, a, a, a wrong process when you try to move fast and duplicate data. No, that's very good for business. However, it makes exactly what you just mentioned.
The problem that we have so much data that sometimes irrelevant, sometimes are duplicate. We duplicate the data, sometimes it's not sensitive. And the right way to do it is to find the very specific data that's relevant to manage, that's relevant to deal with.
So the first step is to discover and to understand what is important and what is not, what is sensitive and what is not. And that's exactly the first step. You cannot protect it all.
You cannot deliver it all. So when you understand what is the most important part, where are the crown jewels, then you can act. And now I connect it to your, uh, uh, uh, previous question, then you can act in a very, very efficient way because you understand here is my most sensitive data.
And for different organization, there are different types of sensitive data. Sometimes it's API I, sometimes it's the intellectual property, sometimes it's very different aspect of what is important to me. So yes, we create a problem, but we need the right approach to solve it.
I think historically, part of the problem is a lot of it, people didn't really know what the data was. They were charged with collecting and storing it, but the business side created the data and knows how important it is or not important it is. So, um, how do we kind of bridge that conversation In one word?
The context in the minute you can connect the data to the right context. Who is the owner who create, who, who, who just did like created the data? Who is the user?
Why do I need that data? Is it in production? Is it sensitive?
So our mission is exactly to un to find and understand the data by the way we tag the data. So when the data move from one place to another, the customer or the systems or the flows can understand the context. It's very different if the data came from production or non-production environment.
And it's all about the context. So the context is the, uh, uh, specific point, the meeting point between the it, the security, the governance, and of course the business. Will there someday be AI agents to manage data security?
I mean, is that the next logical conclusion? Because we're seeing AI agents everywhere, and I'm sure one of them must know something about data security. Why not?
Why not for sure. Like, and, and you, you ask about the the actions. Yes.
At the end it's about to, whenever you understand and you have the knowledge what you have and you have the knowledge, what you need to do, there is no other reason not to do exactly as, uh, the AI agents that can help you to solve that specific problem. Yeah. So, so we are think more and more, uh, uh, uh, correlation between how to solve the problem with ai for sure.
So I think that a lot of people look at this issue and they immediately are overwhelmed. What is the best advice for getting started? Is there some place that you've seen customers who do this well, um, approach this in a way that others can copy?
So yes, first of all, just make sure you are aware about the problem. Many organizations think, no, we don't have the problem. We know, uh, uh, everything about the data or enough.
And, you know, it's, I like to, to to, to say that it's like glasses. You know, when you understand that you don't see, uh, like good enough, you go to the doctor and then you ask, uh, to check yourself, right? And then you understand what is the problem?
Do you need, do you need gases? Do you, don't you need it? Or something else?
So please just be aware and understand that this is huge. Uh, this is a huge problem for many organization. And go to the doctor and please check yourself.
And in the minute you understand and know the problem, then you can know how to solve it. So as you think forward from here, um, is responsibility for data security changing? Is it really the cybersecurity folks who are in charge of this?
Or is the business team stepping up here to take more responsibility? That is amazing question. You know, because when we, like a few years ago, 5, 6, 7 years ago, when you asked the security, what do you think about the data security said, no, no, no, I'm the infrastructure guy.
Data is someone else. When you went to the, uh, uh, uh, the CDO, and by the way, most of the organization didn't have CDO during the those times. And you ask them, what about data security?
No, no, no security, it's the security guys. And now we are exactly in the, let's say the moment that data is everything. It's for security and for the business.
So if you ask me the short answer, yes, the business is responsible about the data because it's all about the data. You can, you cannot run your business, your business continuity. However, the ones that responsible to solve and to make sure that someone really solve it is the security, uh, uh, uh, organization.
And this is the reason you can see more and more, uh, C level and executives and board members ask about the data because this is exactly the meeting point between the security and the business Folks, you heard it here. Data is both the first and last line of defense when you think about it. Hey, Yohan, thanks for being on the track.
Thank you very much. It was great to be here And back to you guys in the studio.