Navigating Zero-Trust IT with Cayosoft’s Bob Bobel
Transcript
This is Techron tv. Hey guys, thanks for the thrill. 5 million to drive a solution that helps you kind of manage and monitor and protect active directory environments, which even today are still pervasive.
Hey, Bob, welcome to the show, Mike. Thank you. Appreciate the time.
When is the challenge with Active Directory? I think everybody kinda has it. Um, it's not clear to me they even remember that they have it, but they still have it.
And I, I think some people have forgotten they have it. Yeah. And it, and it's always been something of a challenge to manage, and it feels like there's a lot more concern about the security of it these days.
So what's going on? So what people, um, uh, I think are living with is a directory service that was first released in 20 or in 1999. And that service, uh, gained wild popularity.
It basically dominates, uh, corporate America and large enterprises. It is the key identity store for most enterprises, probably 80 to 90% of them. And that technology was built, you know, for the previous generation of it, it was built for client server environments where the networks were the perimeter for security.
Um, and now identity has become the perimeter for security. And there's a number of reasons for that. Uh, primarily because we're now a remote society and everybody is, you know, turning to, uh, software as a service in the cloud, Microsoft is one of the biggest leaders in that space.
Um, but connecting the older active directory, uh, to users who are coming in from external, uh, sources, uh, introduces a lot of security challenges. And as you correctly pointed out, um, people have seen Active Directory for so, so long as plumbing that they're now just rationalizing, Hey, wait a minute, this thing is critical to every piece of our operation, right? So if Active directory goes down, our business stops.
And there's a number of really clear examples where ransomware attacks or malware attacks have, have stopped an organization from functioning. So the, the big casino hacks that happened several months ago, um, Lincoln College in Business for a hundred and some years went out of business because their active directory got taken out. And then most recently on the East Coast Healthcare Company got hit, and, uh, they had to redirect traffic, uh, going to their emergency rooms to other hospitals.
So people don't really understand that fundamentally that piece of infrastructure is critical. And if a workstation is compromised, then that sets up a attack path into the directory. Once the directory is compromised, the attacker can sit there.
They own the keys to the Kingdom at that point. And what a lot of people don't understand is that because access is also granted across the enterprise on an ongoing basis through active directory, suddenly they have access to all your AppSec and all your other type of critical infrastructure, your files and folders and SharePoint and whatever. And now that things have been expanded to the cloud, it just, it just exacerbates the problem because now they have access to other resources that, that, uh, are now maybe supplanting the on-premise email.
You're now using cloud email. So it's just, it's just one of those things that people thought it was just there to work and it just works. And so it kind of got ignored.
It reminds me of back in the day, you'd hear about, you know, people that would stand up a, like a Novell server and then there'd be construction and that Novell server would be in a closet and it would be walled off, and it still continued to function for years until they discovered it, right? Or until something happened. A power, you know, glitch happened, or a mouse to the cable, and then they'd have to open the wall.
Active directories like that, it just works for so many people that they've kind of let it fall to the wayside a little bit. It almost seems like though the folks who have not forgotten about it are the bad guys. And so are they actively targeting active directory?
'cause they see it as kind of a relatively easy exploit. That's as absolutely the case. Um, and, you know, they're, they're interested in anything that gets them to a point where they can get leverage over you, right?
Especially in ransomware attacks. Um, and so they're not just looking at Active directory, they're looking at, you know, um, suing, uh, people that are working on a day-to-Day basis by calling their telephone numbers and trying to get their passwords. So this is nothing new they're, they're looking for, for different attack vectors.
Active Directory is, uh, particularly critical because of that nature of, uh, providing both authentication and authorization for pretty much most resources in, in the organization. Are people gonna replace Active Directory, or do I just need to kinda shore it up a little bit? I mean, what's the thinking here as we kind of look at this new level of threats for something that's been around for more decades than any of US care to admit?
Yeah. I, I don't care to admit how many decades I've been working with it. Um, but I started with Windows One, if you can imagine that.
That's, that's really a long time ago that I think Microsoft has a desire, and they've stated this in our meetings with them. Uh, they would like to move people to the cloud and to Entra id, which is their, it was named a, uh, Azure Active Directory. Now it's been renamed to entra.
Um, and their, I think their intention is to move people to that and they spend, um, a considerable amount of treasure, um, working on security and defending, you know, that piece of ground. Um, and they, uh, have provided a path for people to move to, to that application. But unfortunately, active Directory being launched, you know, in 90 19 99 has been so ingrained in environments.
It's really a victim of its own success, or Microsoft is a victim of its own success. Um, it's still being used by people to scan door badges, right? And then it talks to Active directory to make sure you're a current employee.
Um, we see patient information being tied to an active directory account. Um, and so it's so ingrained, it's just gonna take a, a while for people to, to figure out what's next. Of course, there are a lot of other vendors out there that are pressuring, uh, companies to move to their, their solution.
Uh, a lot of folks believe, um, the cloud is the answer. And so you'll see companies out there providing authentication services to large enterprises, and they, you know, don't make any kind of, uh, hidden or veiled, uh, inferences about moving off of active Direct. They just say it outright.
Uh, and I, you know, in our conversations with our partner at Micro Partners at Microsoft, they're aware of that. And, you know, they're, they're wanting to make sure that they continue to hold their dominant, uh, position here and they just continue to invest more in both the on-premise directory and in, in, uh, entra id. So I think a lot of companies are looking for a way to figure out what's next, but it's convenient now to be in this hybrid mode.
That's what our company does, is it enables people to be in that hybrid mode with an eye on moving to, uh, maybe a cloud solution in the near future. So What is it exactly that you guys are providing in terms of capabilities that I wouldn't get from Microsoft as part of the core platform? Sure.
So, so Microsoft is, you know, putting, putting the majority of their resources from what we can see and, and what we're being told into their cloud platform to their Azure platform. And so they're really concentrating on building, uh, the next generation. Now it's, it's copilot and, and artificial intelligence as being, you know, um, put through, uh, all aspects of, of their, their development cycles for us, um, our experience was in the identity management, identity security and active directory management space.
And so when we founded this company, we looked at what was going to happen to those companies that had invested in Microsoft, and how do we help them make that transition to a cloud version of, of IT management, right? And so that's exactly what we do. Um, we started off with a management tool to provide sort of a firewall, uh, type, uh, situation around active directory.
So all changes could be evaluated before they were made to active directory. So you couldn't change the security people didn't have too many permissions, et cetera. A lot of the things that, that didn't come with the original active directory, we kind layered all, um, that also provided, uh, roles, business roles and business rules so that, uh, people who were interacting with the directory didn't make mistakes or couldn't make changes that were inappropriate.
After that launch of our management tool, we moved into change auditing because visibility becomes a challenge as you're moving into these new cloud services, particularly if changes being made on premise are then, um, also replicated into the cloud. So we have what I believe is probably the best, uh, change auditing solution for managing high, uh, for monitoring and, and managing hybrid active directory and ENT id. And then if you're in the worst case scenario and you know, you've, you've kind of ignored maybe active directory for a while and your organization is the victim of a cyber attack, um, we have a solution that brings back your active directory instantly.
So if you've already moved your email to Office 365 and people are using Office, we can get the logins back for your on-premise directory that are gonna give access to those resources. So at least you can get the Microsoft stack back up as quickly as possible. And there's just no way to do it faster than, than what we're doing.
We actually create a whole fault tolerant standby version of your active directory, but we do it in the cloud where it's maybe a little bit better protected and isolated from your on-premise network. So what we like to say is, if the stuff hits the fan, we are there to recover you. But hopefully with our other tools, the management and the change monitoring, you never get to that.
Finally, if you are in a situation, uh, where you're, um, looking at Active directory and looking at protecting it better, we have a free threat assessment capability that comes with the products we have, and that looks at active directory for indications that you may have some misconfiguration that might be putting you at risk or maybe an indication that somebody has already broken into the systems and maybe has changed security or been doing some nefarious tasks. The good news is if you do get compromised, you can also use that to figure out what happened as sort of a post forensics, um, a solution. So it doesn't happen in the future.
A lot of folks are getting out of bed and they're kind of going, we gotta get this whole Zero trust thing going. And it doesn't sound like to me that's something you buy as much as it is an adventure, but, um, how do I get to Zero trust if I'm working off of a active directory starting point? Yeah, so, so we don't, so we don't solve the entire Zero trust problem, but we definitely contribute to that solution.
Um, our role at koft is to provide better delegated administration and automation to remove the human element. And so as you're looking at your Zero trust strategy and you're trying to figure out how you're gonna implement that, maybe starting with mobile devices and moving all the way across the stack, we're gonna help you on the Microsoft side by providing a much better security model than you would get natively on the NA on the original. We now call it sort of legacy active directory, but let's say the client server version of Active Directory.
And the cool part is that that also integrates directly with, uh, office 365 and Azure AD or Intra ID so that you don't end up with three or four different interfaces, which makes the complexity, you know, much broader problem and, uh, chances of having issues, uh, expanded. So by giving a single pane of glass and better security around the whole thing, we actually are actually a pretty strong component of, of any, uh, I think comprehensive, um, zero trust solution that you're trying to put together. And like you said, it's not a product, it's a journey, uh, or a maybe a way of thinking, um, more than everything else.
I think the one fundamental thing I think I tell people is that, you know, you shouldn't operate from a, if we ever get attacked type scenario, it's when you get attacked, right? And then consider that you maybe already have been a, a victim, you just don't know it yet. And so these advanced persistent threats that governments are using to, to penetrate corporations, to, to steal intellectual property or to do other things, um, those are real people have them happening.
They don't know until oftentimes too late. So you really do need solutions in addition to, you know, a a new mentality around zero trust to look for those things, find 'em. And again, as I mentioned, we offer that as something that we do for free because we believe it's such a big problem that every vendor there should be contributing to that.
Of course, these days you can't walk down the street without somebody leaping out to tell you about their great new AI thing. Will we apply AI to active directory? And what might that look like?
So we've been looking at that obviously because, uh, nobody in their right mind would, would not be thinking about it if, you know your competitors are thinking about it. Um, for us, we believe that AI open some doors, uh, to do data analytics and also open some doors on natural language processing that didn't exist in a usable form before. So you can imagine being able to, to take very complex attack scenarios and apply AI to looking across not just one directory, but multiple customer directories to see how things are working and looking for specific attack vectors that might be very difficult to do, uh, without an intelligent, um, uh, process behind it.
Um, and I mentioned natural language processing. Um, it does that fantastically. I mean, it's a great solution.
And anybody who's sat down and tried copilot or chat GPT or any of the others out there, you know, you, you type a question, the thing understands you and, and replies back in a, in a meaningful way. Um, and so for us, you know, we're looking at different mechanisms to make our products simpler by allowing people to maybe, for example, make comments in a teams chat, uh, that would be recognized by our service, and then maybe perform some action or does some lookup. Um, other than that, we're gonna hold on that a little bit because obviously we, uh, don't wanna give away too much, uh, of the secret sauce that we're working on, but I think that's pretty near term for us.
All right, folks. Well, you heard it here. The one thing that is for certain is if you have not looked at your active directory implementation lately, the bad guys are.
So maybe you might wanna take a look at what's going on there and revisit the whole thing, because well can't trust anybody these days. Hey Bob, thanks for being on the show, Mike, it was a pleasure. Thanks so much.
Appreciate the time. All right, and back to you guys in the studio.