Netskope’s Cyber Threat Report – Ray Canzanese, Netskope
Alan speaks with Ray Canzanese, Director of Netskope’s Threat Labs. Netskope released its latest Cyber Threat Report, which analyzes the latest cloud threats affecting enterprises based on anonymized usage data (between January 1 through May 31, 2022) relating to a subset of Netskope customers.
Transcript
This is texturing TV. Hey everyone, welcome to another text drug TV segment my guests for this segment is Ray Canzanese. Ray kenzini seed depends where you are, I guess raise with net scope and he's joining us today.
Hey, Ray welcome. Hey Alan. Thanks for having me.
It's our pleasure to have you on Ray. You're I mentioned you're with that scope. I didn't give your title and Being you know, I'm gonna assume not everyone in the audience knows who you are.
Except for Ray's family and friends have been told when he's gonna be on it or tuning in and welcome, but right give people a little bit of your background and maybe while you're at it something about Nets sure so my background is in threat protection. I am the director of netscope threat labs and we are netscopes research arm. So we focus on all sorts of cybersecurity challenges with a focus on cloud netscope is a secure access service edge platform.
So we sell a secure web Gateway a firewall a private access product and entire platform of protecting people when they're going direct to cloud in their corporate environments. and of course You know, it amazes me. There's still organizations who don't go direct to Cloud that are kind of backhoeing back in, you know to the to the land from the land to go back out to come back in to go back out.
It just seems so damn wasteful but it is what it is. Anyway, Ray, I'll be honest with you. This is about the fifth interview.
I've done this morning. I think three or four of them have been with research. Yeah James various vendors Stuffs for the stuff is flying and I don't know if it's a result of black hat is this week?
And so they're geared up for that or we're just going through a bit of a rough patch in terms of the bad guys. It seems like the bad guys are always. you know living one step ahead of the law so to speak but let's go recently released a big report.
I don't want to take words out of your mouth. Why don't you share with our audience? Sure.
So we write one of these reports every quarter on a different topic every time and this last one we focused on cloud data sprawl. So in other words, we were we were focused not on attackers and what attackers are doing, but more on what your employees are doing at your company with Cloud AppSec and really the thing that's most surprising in this report is the numbers meaning everybody understands. Hey, I use a lot of cloud AppSec, right?
I don't know do I use maybe 20? I mean that's a big number right? And so we start looking at you know, an organization of up to 2,000 users has if you some all those Cloud AppSec up more than 1500 Cloud AppSec getting used there.
And so you start looking at that and you say well I don't upload data all at all those AppSec, right? So who cares? Yeah.
So but you look at even the AppSec that people are uploading data to and it's still more than a hundred AppSec even in an organiz. And of under 2,000 users where users are uploading and sending data to and when you look at that from an organization's perspective, what do you manage centrally in your organization 20 AppSec 25 AppSec 30 AppSec maybe you do 50 AppSec right? It's not even close to the total number of AppSec that people are sending data to and this just creates a really big mess.
If one of your goals is to control where all that data that you are working with ends up. You know look a lesson that we've had to relearn I think it's during covid times is it's all about the data. It was always all about the data but we got so focused on AppSec and laughs and and apis and all of these things that what we forgot is that the crown jewels of the data the data, there's so much information and we do we live in an age of data sprawl forget 2000 people.
We're 30 people here texture. Our new Mitchell my CTO and a long time friend. We recently did our own little audit.
If not what it's a really big word. We didn't do a formal order but we did a little research study to see hey how many AppSec are we using? Where is our data?
Because we're like many companies out there where it's at company. We don't develop software. We're using third party satsapps.
you know the usual suspects and It's scary. It's scary everything from our Google email Google accounts where each user gets eight terabytes. Think about that someone my age.
I was buying a 30 megabit hard drive. It was this big 30 Megs was a hard card and I was like, what am I ever gonna do with that? Everyone on our team has a terabytes on Google to play with but forget that you've got the Hub spots and the slacks and and the word presses and the canvas and the Adobe stuff.
And you know, first of all, we we found that our average user here is using probably very thirty six three dozen AppSec. Yep, which is not crazy from what I know understand. No, and that example that you shared of Google is a really interesting one, right?
Because what you're saying is like you went and bought a corporate Google license and you gave everybody a Google account, but they all already probably had their own Google accounts too Gmail account. Yeah exactly that right. Yeah.
so, you know from a from our point of view How do we really know? I mean look the total amount of day that is staggering in terms of you know, terabytes or whatever. What's even scarier is let's say it's five terabytes.
It's five terabytes of dark matter as far as we know right? How did that five terabytes? I maybe know one terabyte of what what really that data holds rights shared drives and stuff like that.
But for terabytes is dark. I mean, it's just who the hell knows, you know, we don't really have a handle on it and we're a little nothing of a company right think about a real company. You know and what what this means for them, it's scary stuff.
Right and well, I mean, we're not a big company either right? We're we're only about 1,500 employees now, I think when I started we were only four we were only 400 right when we started but we have the same problem. Right every individual at the company is making their own choices about what AppSec to use for what reasons right and you have people accidentally sending things up to their personal Google Drive instead of the work Google Drive, you have people accidentally sinking things to where they shouldn't be synced to and then you have people that you know, I need to convert this sensitive PDF to a different format.
I don't know how to do that. Let me just Google and see what it says and you get this result for some random PDF conversion service and there you go. You have somebody who's just uploading sensitive docs to some service that they found by searching on Google right?
I mean you just start adding this up and this this, you know, if you have no controls around it, right data is just going everywhere unchecked on the In of every single individual who works at the company. So you talk about controls? Yeah.
So again, this is another pet peeve of my forgive me for going off. But you know, we we live in this work from anywhere do anything from anywhere environment? When I tell my people we can't you can't use that or you're not We're not gonna do it that way anymore because it's a risk because we don't know.
You know what? No, I'm not gonna buy you the full Adobe Acrobat but you can't use the upload to convert it send it into someone who has full Adobe here. Welcome, you know in in company.
People have the attitude that hey man, I do it, you know, I work from anywhere do anything from anywhere and I'll do anything I want and if it's not a company tool, but it's a tool. I want to use I'm gonna use it. It's my own equipment in many cases and even if it's not my own equipment, I use it like it's my equipment right and and it's getting harder and harder the police that stuff.
Yeah, it is and so what's interesting when we started looking at this we're looking at different industry verticals to see what the differences are across the industry verticals and I think unsurprisingly we found that in the banking vertical and financial services those companies seem to have the best handle on controlling this, you know, obviously there are yeah, they're in regulated Industries, right? They they have maybe an extra incentive there. But you know, we looked at some of the the policies we've talked to some of those companies to see what is it that they're really doing differently and it's usually around these these personal AppSec, you know that you're using with your private email address and and personal instances of those AppSec that they are controlling what can be uploaded there.
So they let you upload things there, right? The company's not trying to prevent you from uploading pictures of your kids to your Picasa right or or Personal documents to your Google Drive, they're trying to prevent the company's data from going to those places, right? So they they're setting up the policies that control the movement of that data specifically so that people don't feel like you're cramping their style and telling them what they can and can't do you're letting them do whatever they want.
Unless you see that it's sensitive data that's being moved. And then you say well hold on you shouldn't be moving this data to that location and for us we give you know, our clients the ability to either directly block that Or to coach that and so meaning like we can just you get a message that says blocked. You can't go here versus a message that says hey you probably shouldn't be doing this but if you'd like to do it anyway, please hit proceed and we'll let you do it anyway, and we found that even that where you just sort of leave it up to the the user to decide they still usually say no, right they they realize that point.
Oh, you're right I shouldn't be doing this. This is right, but they decision. Yeah.
Yeah. That's that's a good thing. So, right, you know, I've been in security really long time.
We used to call what you're describing sort of DLP. Right, right. is it still called DLP here is that It's it's still called DLP.
So we we definitely call it DLP. We talk about DLP when we talk to our customers. It's just that we're not talking about it.
Maybe in the same sense. We were 20 years ago where DLP was preventing you from printing a document or moving a file to a USB drive. Well it never it never really works so good.
That was a problem with it too back that you know, I'm sure it's gotten a lot better. Right, and when it's Cloud delivered you have you know, lots of machine learning and AI systems and exact data matching and signatures and hashes, right? There's so many Technologies we have now for being able to recognize, you know, this is a potentially sensitive data and we don't want to move it.
Absolutely. Great. We went down the rabbits hole here a little bit.
Let's come back to the report. So what what do you think some of the other key findings are that you want to share with the audience? Sure.
Yeah. So one of the big ones is when we're looking at data being uploaded to let's call them personal AppSec and personal instances. We see more than 20% of all users doing that regularly, right?
So there's just like an awful lot of data going there. So obviously that's going to be a mix of personal data and Company data, right depending on who's doing what but then when somebody's leaving the organization is is typically when things get much worse and we found that in that last 30 days before somebody leaves the amount of data, they start moving into those personal AppSec just starts increasing and increasing because they're basically packing their bags to go and the way they're doing it is usually by throwing everything into their own, you know Gmail account. Or their own OneDrive account so that they can keep everything on the way out.
And obviously that's a big concern for security teams. Right who you know in the last stage of somebody's employment are trying to make sure that nobody's taking anything. They shouldn't be taking great.
Great, what else you got for us from the report? You think the people would want to know about? So I think the when we talk about controls and what's working, I think that the by volume the personal data the data that's going places.
It shouldn't go it's mostly the one drives the Google Drives the Dropbox is the boxes. I think people assume that it's things that can easily block. Oh, it's just some bad app that people shouldn't be using it's it's not like that.
It's much more nuanced. It's the same AppSec that everybody's using all the time. com email address unless you have a technology that can do that.
This is really hard really hard stuff to Police from just the technical point of view. It really is. Yeah look, I tell you another scenario.
I think that makes it you want if I had hair I'd pull it out is You know for someone like me, so I have a lot of Apple devices right? I have my MacBooks my iMacs my watches my phones my iPads and and obviously with my Apple devices I have iCloud. Yeah and like everyone else the extra 99 cents a month quickly ran out and now I'm up to 299 a month and I forget how many gigabytes I got there right and that I try to make that personal.
Right not put my work stuff there. My Apple like these are personal ID. Not a work ID.
Then I have my Microsoft Office. Right kind of stuff and I have a OneDrive account with that and I for whatever reason years ago. That's where I made my work versus private personal stuff.
Right? So I have the one Jive also not under a work address. Then of course, I mentioned the Google the a terabyte Google drive under a work address.
I don't know. I I think the Google Drive integration for me was never as good on the app on the Apple devices as OneDrive in iCloud were so I tend to you know, what obviously goes in there goes in there. But if there's a question usually winds up in one drive.
I have found my one drive ready to be polluted right between personal and and work stuff and If it's happens to me, it can happen to you out there. Right and this that's where I think you really start running into stuff. Right because you you kind of faster and looser with your personal and maybe you would be with your work accounts.
and and if you've got your work stuff up there. You get ransoms you get whatever you're in trouble. Right?
Right, and I think that's a really nice way of putting it right like the the pollution of of your personal with all your work stuff because I mean most people watching this right are reacting saying well, I'm not I'm not a bad person right? I'm not trying to steal things from my employer. I would never knowingly move work data to somewhere where it shouldn't go right but that's I mean what's happening is not typically knowingly moving the data to where it shouldn't go right?
It's sort of accidentally ending up especially this iCloud thing is a thorn in the side of so many organizations who's users are using Max and they just go in there and tell everybody just disable it stop music that I called back up because we don't want all of your work data and you open your Cloud backups because they have you have you know, as the organization you lose all control over that and now as the individual what you're going to make sure for the rest of your life you safe. Guard that data as if it were as if you were still working at that job you left years ago. I mean, it's just no way to protect data that way.
Absolutely. Absolutely. Hey Ray for people who want to get more information.
About the report maybe you know. Figure out some ways they can help themselves. What what's the best place to go to for that?
com/threatlabs website that will give you this report our monthly reports and all of our blog posts as we put them out all on that one page. com/thread Labs. It's beautiful.
So that's this court is report. You want to give us a preview at least of what next quarters reports on you're not allowed to say yeah. Next next quarters report is going to be interesting because we're gonna talk a lot about the risks that come within the AppSec and the app ecosystems themselves.
So we're gonna talk a little bit about fishing attacks that go directly after you are one Drive account and we're just gonna talk about how often people go and they click on that button. Would you like to allow this app access to OneDrive right? Everybody knows what the answer to that question is.
It's yes because if I say, no, you're not gonna let me do what I'm trying to do. Actually, exactly alright, hey Greg. Thanks for coming on and and giving us a little insight into the into this and great work on the report.
Come back next quarter. Let's talk about the next one. Thanks a lot Alan.
Alrighty, we're gonna take a break here on Tech strong t V crazy morning we've got more. Stay tuned.