The Importance of Data Security Posture Management with Normalyze’s Amer Deeba
Normalyze CEO Amer Deeba explains why the only practical way forward for organizations to approach cybersecurity is to rely more on data security posture management (DSPM) platforms to reduce risks.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Ammar Deepa, who's CEO for Normalize, and we're talking about how we're really evolving into a data-centric approach to cloud security these days because, well, I think everything else we tried just isn't working as well.
Amer, welcome to the show. Uh, it's so, so well said, Mike. Thank you.
So it's, uh, well, it's not like it didn't work. It just, it, it proved it, it showed us that we are still missing a very important element, which is how to really zero in on the data. And, and despite, because, you know, as, as we moved into the cloud, digital transformations reformation cause a lot of data sprawl everywhere and understanding where the data is, what's the value of it, how important is it to me and to my organization is, is a big factor for securing it.
Uh, and that's sort of what our approach is all about, is to help you really understand where your crown jewels are and how they, how they fit into the overall picture in your cloud and cybersecurity programs, and how to really have that kind of ongoing visibility to secure it. So we hear the buzz phrase, data security, posture management. What does that mean exactly What's involved in that?
I think a lot of folks are, you know, they know about firewalls and everything else, but what exactly is different about what we're calling data security, posture management Data. It's, it's really the, the approach or set of processes that you can combine together that's gonna help you build and understand the security posture around your data on a continuous basis. So you can discover it first and, uh, know where it is in your environment across your cloud, uh, cloud or hybrid cloud, hybrid environments, of course, cloud SaaS and on-premise, um, discover it first, understand really what's in it and what's the value of it to your organization, where the sensitive data is, what type of sensitive data you're holding is a PII data, is it, uh, customer data, consumer data that you really need to know about and, and, and secure properly.
And then understand also the level of access around that data. It's, it's a very important element in order to secure the data you really know who has access to it, what type of access they have, when they've lost access, that should they have that access on an ongoing basis or not. And then the big, the big component I think that the SBM gives you is kinda understanding the context where that data sets in within your environment, either in cloud or on premise.
And then be able to understand really that level of risk around the data. Are there any attack paths around that sensitive data that can lead to compromises or lead to data proliferation or to lead to, to unused, uh, unauthorized access of that data. And the last piece is really managing compliance.
So, so the end result, having a full understanding of the security posture of your data on an ongoing basis, being able to answer questions around your data with confidence, answer to your teams, to your board, to the SCC. Now considering the, the SEC uh, uh, kind of change data are coming on December 18. And finally be able to manage compliance in a much easier way where you can get answers quickly, you can see where the gaps are.
You can associate it with different teams within the organization so they can help you do it better and faster and quicker and with more confidence. What makes achieving end? So, So that the whole, the whole program we, we call it, or what the industry now is starting to refer to beginning to end that whole process, data security, posture management or the SPM, which, which I think is a very good term.
And it's really hones in on really what needs to, what needs, what needs to happen. So what exactly is different about securing data in the cloud versus say in an on-premises environment? I know historically we relied heavily on firewalls in an on-premise environment and tried that in the cloud, but what makes it more challenging to secure that data in a cloud environment?
Very good question. Uh, so on premise, I think, you know, we had more control with the data. We put it like maybe in structured or unstructured data stores, but we had much better 'cause kinda, we built these castles and we put the data in it.
So we, we had a much better understanding first of all, of access around the data who has access. And we kind of knew where, where the data is in a more kinda, in, in, in a more controlled manner. The move to the cloud made that problem much harder because first of all, now everyone is a multi cloud environments.
Um, the changes that are happening as you are building applications in the cloud and the, the fact of the, of these, the, the, the fact how fast these changes are happening are really causing kind of the sprawl of data to happen everywhere. So data are used in certain environments and forgotten, which is how contain sensitive data, um, the changes that happens, the frequent changes that happens within the CICB cycle also sometimes causes more challenges misconfigurations to happen in the environment around the data that can, that can cause a attack factor around the data or compromise, compromise, make that data more compromisable. So it just, it's the, the the and the sheer, the sheer amount of data that's moving into the cloud also now because of AI and modern data modeling and LLMs and all of that, there's just so much out there and I think the security teams and and compliance teams are having a hard time controlling it in a systematic way where you can really have that continuous visibility around the data and so you can secure it properly and it, it's just, it's, we are at the cusp.
I think of, you know, especially now with the hockey stick of the growth of AI and ML that's happening in the cloud, we are gonna see more and more data coming in and more, and we really have to put the controls in place so we can visualize it, understand what's in it, make sure we're using it properly, especially as it goes into LLMs and other modeling techniques within cloud environments. Uh, and all of that, you know, if you don't have an approach to do that properly and effectively and and understand it, uh, on an ongoing basis, I think it's just, it's gonna start become a, a big challenge to, to manage in a multi-cloud environment specifically. And we see that in every customer right now, they're all in multiple clouds.
They use different clouds for different functions where these clouds are better and providing additional capabilities and techniques that can help them. Um, so it's, uh, it's, um, 2024 I think is just gonna be a big year for that. Do we need to be smarter about what data we're protecting with what level of resources?
'cause our resources are limited and I don't think we can realistically protect everything and some things aren't worth protecting. So exactly smarter about figuring out what to protect. And that's where the very good, very good question.
And that's where understanding the data or call the, the technique and the SPM is a classification of the data so you really know what's in it and you understand not just only one in it, what type of sensitive information it has, but also what are, what are, what is the value of it to your organization? What is the value to the organization and what is, if it were to get hacked or compromise, what would be the cost of that hack to you? It normalized, we call it the monetary value of that data.
So knowing this information will give you very good intelligence to prioritize course, the risks around it, how to fix them faster and better. And second also allows you to take that information to your board so you can get budgets, you can, you can share, say, okay, well, you know, if this information is to get compromised by by a third party or an, or an, or an attacker, this can be the cost for our organ or our, to our organization. Um, and that CISOs find that very helpful, again, to prioritize remediation and drive it and also to get budgets to, to do more to, to secure this data.
Are there bad guys getting smarter at identifying the data that has the most value? Or are they just taking everything they can find and sorting it out later? Uh, the bad guys are always getting smarter and they always go for and for, they always look where, you know, it's, it's the least effort to get the most, the most out of it.
Um, at the end of the day when they go in, I think they, they grab everything, but then they, they're very good to immediately identify what's in it. And now, now they're actually calling, calling me, you know, calling on the SEC to say, Hey, you guys didn't do your job because you know, the breaches are happening and, and this data, like, it's not the, the the, the ability to disclose this information, it's not happening at the right time. So as you see, they're getting better and smarter every day and they're using, or even these recent regulations, they're using it to their advantage so they could put more pressure on the customers and get more money out of them.
But, you know, it's, uh, we always have to take that into consideration, uh, I think and assume the worst, and then build, build the programs in place so we could be more proactive and we get better and smarter. So when, when something, when we get hit, we can act quickly and we can immediately provide the information we need to now to disclose it at the right time, but also to answer questions to our customers and partners as quickly as possible. We've heard a lot about shared responsibility in the age of the cloud for security.
Um, is that really working or do we need to kind of rethink that approach? I mean, it seems like a lot of folks maybe think too much of what the cloud service providers are doing, and maybe we need some clarity. Yeah, I mean, look, the shared responsibility model is very, of course it's helped a lot.
Uh, and cloud providers are doing a lot to help. You need to own your data. Cloud riders don't know what's in your data and can't, can't, can't police that for you.
It's, it's, it's us as companies, as organizations, as security team, we need to take that ownership, understand what's in our data, how valuable it is to our business, and make sure that between the shared responsibility that we get from the cloud providers and the additional tools and programs that we have in place, that we can protect it properly and continuously and an ongoing basis. So it's, uh, it's uh, that shared responsibility. That's why it's called chair, it's between the cloud provider and us as an organization.
And, and I think the combined efforts and understanding that whole picture around our data is, is really what's gonna be, what's gonna be the appropriate or the fortify to really fortify the model around our data and the security to 45 security around our data. Of course, these days you can't go out the front door without somebody telling you about their new AI thing. How does AI get applied to data security, posture management?
Uh, you know, uh, it's, again, it's, I think it can, uh, uh, we already using it like we use it in our backend and our scanners and uh, and uh, we use it in our remediation, uh, how we can recommend remediation to our cus to the customer in a more, kinda more, um, uh, uh, uh, uh, in a manner that that really can help 'em drive remediation factor and quicker. Um, we are gonna also, we are gonna see a lot of focus to use to help, to help make sure as data is going into AI mode and into AI and modeling, that that data that's going in is the right, the right data and it's being secured properly by these models. So, so it can be a AI is gonna be very helpful in operationalizing data, DSPM, data security, posture management, uh, solutions and workflows that come out of it.
But at the same time, we need to make sure as data is going into various LMS and different AI techniques and models that we are making sure that data is, we know what's going in, we know what's coming out and that data is being protected properly. So we're gonna see a lot of innovation also in that, in that arena moving forward. But, but in terms of the SPM, I think AI can really help or operationalize a lot of the d the, the SPM workflows specifically when it comes to remediation, because I think we can use it to really help customers do get better information about their data threats and to drive remediation in a more effective ways.
You've been at this for a little while now, and on the one hand it seems like protecting data feels a little on the intuitively obvious side of something we should be doing, but we don't. What is the hurdles that you're seeing folks in organizations as they kind of make this transition running into, and, you know, what should they be thinking about now to make it less painful later? Very good question.
You know, it's always about like, who owns the data and your company becomes the, the big fact, big question. Like who is owning it? Is it the security teams or are, is it the business?
Is it the, who are the various owners that, that have access to that data and own it and can, can help, can, you know, can help the security security also get control and get, not not not control maybe is not the right way, but get the visibility required in order to protect the data to, um, our main advice to customers as they start, don't try to boil the ocean. Focus on what's important first. Get, get the understanding and the visibility you need, uh, to see where everything is and then try to really start understanding really where is the value of that data to you within to the values business organizations and units within your company.
And then from there, start kind of when it start focusing on the, the kind of the, the quick wins that you can get for, uh, enforcing at least privileged access to the data. So if Mike has an access to a data store that contains all the sensitive information, but it's not using it anymore, why should Mike continue to have access to that data, for example? Um, so that's a quick win that you can get immediately and, and increases really your security posture around, uh, around that data.
Um, understanding where our shadow data stores that are within the environment that, for example, have all the sensitive information, but they're just, they're just like kind of sitting there with no more use for for them. And we see a lot of that phenomena a lot because that also that that, that, that gives you additional, uh, you know, additional cost savings if you get rid of, uh, these, these shadow data stores. And second, it eliminates a lot of risk around that data if it's no longer needed.
So these are the quick wins that we encourage every customers to get into and then expand into really understanding the risks around the data and remediating it and building the workflows to do that, and then taking that information to drive better compliance frameworks around it. So it's, um, um, it's a, you know, and, and start like, don't try to do everything at once. Focus on the clouds where you have the more data, um, and start try by prioritizing the data based on its value to your business.
So, so you you, you focus on what's important first and then you can, as you drive remediation and expand on that, then you could just create more that culture, more more of a data centric culture within your, within your cloud security and, uh, within your, within your overall security framework. So unfairly or not, it seems like the SEC and various other entities are going out of their way to hold security people more accountable for the data breaches themselves, regardless of whether they're at fault. Do you think that that shift is just gonna force this whole data security posture management issue because ultimately the security people are now responsible for the data itself?
Absolutely, and I'm hearing it, I was at multiple conferences in the last couple of weeks, and this was a main topic that was discussed in many panels and many sessions and all, it's on every cecil's mind. They're all building the playbooks around it. They're all trying to now saying, you know, if this happens, what do we need to do and how we're gonna be ready and prepared?
Um, and data is a big part of that and understanding the data within the environment. So again, you can answer these questions to internally first and to your customers and to the SEC on time, uh, you know, and with confidence when it comes to if, if a certain breaches happen. So I think it's definitely gonna be a big factor to bring more urge.
I think it's already happening, but this is gonna bring more urgency to the, to, to, to the, to the table. So, um, everyone now can, can have, have build programs that are data centric and can answer and respond to the SEC, uh, within, within the, the, the timeline required. All right folks, well you're hurting it here.
The answer is the data. Of course, what the question was doesn't really matter because the answer is the data. So that's what you need to figure out how to secure and that's what you're gonna be held responsible for.
Amer, thanks for being on the show. Thank you. Always a pleasure, Mike.
And, um, happy holidays to everybody. Thank you so much. And back to you guys in the.