In today’s cloud-centric world, data no longer lives behind traditional perimeters. Instead, it moves fluidly across SaaS platforms, IaaS environments, and hybrid infrastructures — making identity the new control plane. As organizations confront modern threats, the intersection of identity and data protection is where cyber resilience must begin.
Modern enterprises can no longer treat Identity and Access Management (IAM) and Data Security Posture Management (DSPM) as separate disciplines. Integrating identity context into DSPM and DLP strategies enhances visibility, limits blast radius, and makes prevention and response more intelligent and dynamic. This webinar will explore how this integrated approach reshapes proactive defense
John Tolbert, Director of Research and a Lead Analyst at KuppingerCole, will outline the latest research on identity-first security. They will explore how IAM and DSPM together address emerging threats, highlight real-world identity attack vectors, and explain why identity posture must be part of any data-centric security architecture.
Matt Lock, Field CTO at Varonis, will provide a deep dive into how Varonis’ Data Security Platform applies AI-driven automation to discover critical data, enforce least-privilege access, and stop insider and external threats. He’ll showcase practical examples of integrating identity fabric with DSPM and illustrate how to quantify risk and reduce blast radius across cloud environments.
Well, hello, good morning, good afternoon, wherever you are in the world. I'm John Tolbert, Director of Cybersecurity Research here at KuppingerCole.
And today, our webinar topic is Securing the Digital Fabric, How IAM and DSPM Data Security Posture Management Shape Data Protection Strategies. And today, I'm joined by Matt Lock, who's the Field CISO at Varonis.
Welcome, Matt. Hi, John. Thanks for having me. Looking forward to this.
Yep, I've been looking forward to it. Thank you.
So, just a little bit of logistics info before we begin. Everybody's muted centrally. There's no need to mute or unmute yourself. We're going to do a couple of polls during the webinar, and we'll take a look at the end. You can submit questions in the Livestorm Control Panel at any time. We certainly encourage you to do that. We'll take questions at the end. And then lastly, we're recording this, so both the recording and our slides will be available in just a couple of days.
So, I'm going to start off and talk about the challenges, the cyber threat landscape, and history of data protection technologies. And then I'll turn it over to Matt to talk about what modern data security platforms should look like. And then we'll do that Q&A at the end.
So, a little bit of background on the threat landscape and the business concerns that people have. So, I think we've all heard for at least 15 years now, identity is the new perimeter.
Well, maybe it's not new anymore. I think we've known this for a while. But really, it is a perimeter. And why is that the case?
Well, think about account takeovers. They're happening both on the consumer side, on the enterprise side, in greater and greater quantities, unfortunately. And we all too probably know through various reports like the Verizon Data Breach Report, almost every cyber attack, data breaches are using compromised credentials. And attackers can simply go out and buy these compromised credentials on the dark web. This might be from, you know, credential dumps, even disgruntled employees selling access.
Or in some cases, there are long live session tokens that the attackers capture and then sell those and they can be used for however long the cookie or token is valid for. So, now we say attackers don't break in, they log in. And it's because they can go out and get those credentials. Sometimes attackers don't even bother with using malware. But to sum up here, you know, identity is a perimeter, but data too needs a perimeter.
So, identity itself is an attack surface because, you know, our old school perimeters are porous. Identity, when you think about SaaS applications, it's the only real control plane that we have for SaaS applications.
You know, as SaaS customers, we don't control the infrastructure. Yes, we can control the configuration within the cloud sometimes, you know, for infrastructure as a service. But for SaaS, it's really all about the identity. That's the basis for access controls. And as you may know, shadow identity is a problem that continues to increase as well. How many different identity providers is your organization using that you know about? Probably not surprising here, but we've got, you know, three biggest security concerns that keep CISOs up at night. Compliance failures.
When sensitive data is lost, subject regulations like GDPR, the fines can be enormous. Data breaches themselves. We've heard a lot about Scattered Spider in the last year or two. Unfortunately, they've been very successful. It's led to big disruptions in business operations.
You know, a few prominent examples out there where people have been able to get back up and running in a few hours or a few days, but there have been a lot of organizations that have been down for weeks and even months. And a lot of organizations can't survive that. So let's take our first poll question. What is your biggest concern about data breaches? Is it that interruption of business continuity, cost to clean up, reputation damage, worried about the fines that might come from violating regulations, or is it just keeping your job?
So we'll open that up and feel free to vote on that at any time. I encourage you to vote. Be interested to look at the results later. So now I want to segue into the Information Protection Lifecycle. This is a concept we developed quite a few years ago, but it's still valid today. And this is really looking at the entire lifecycle from beginning to the end where, you know, data objects are created. Once they're created, they need to be discovered, identified, classified. What kind of data is it? What's the provenance? And that information can then be used to control access to it.
And control access, of authentication and authorization. These data objects also need to be secured. Probably one of the best choices here in this list is encryption, but encryption itself can be difficult to manage. We also need to monitor and detect threats to data throughout its lifecycle from all kinds of actors, whether they're insiders or APT actors. And there are other kinds of technologies that can be used here, like deception technology, where you can create fake accounts, fake user admin accounts, domain admin accounts, even, you know, VMs, machines, credentials.
And the idea there is if you see any activity on any of those assets, you know that it's an attacker because nobody else should have access to that. So it's one potential way to help catch nefarious activity in your organization. Then we have contain and recover, things like segmentation, micro-segmentation, good backup procedures, restore procedures that are tested. And lastly, disposition. Can't forget the end of the cycle. So acquire and assess.
You know, at the very beginning, when data objects are created, that's a great time to get an inventory, apply that metadata. This works for unstructured data, files that might live on file system, shares, collaboration apps.
And again, they're often widely distributed. Controls can be difficult to combine and enforce consistently. And then we also have data in databases, which is kind of a different animal, really, when you think about it. There are certain situations where, you know, individual tables within databases or even certain row-column-cell combinations might add up to a different sensitivity. So how do you protect data in a database? That requires, you know, a very sophisticated data security platform that can also apply the same kinds of policies to that data as unstructured data.
Here I thought I'd show, you know, the old exact architectural model. It still applies. Things like the PEP policy enforcement point that sort of lives next to the application. It controls access to the application. The policy decision point where the policy decisions are made. This can be in a distributed fashion. You have the policy administration point where business people or admins can put in the rules and policies that should govern access. And the policy enforcement point or information point would be things like your user data store.
So even if you're not necessarily using the exact language, most of us are still using this reference architecture because it still applies. And we typically call this attribute-based access control. And it's also the basis for policy-based access control, too. Moving on to monitoring and detection. So we've got a lot of acronyms, a lot of different kinds of tools. You've got all your DRs up top, the detection and response tools, things from your old school architecture, firewalls, web application firewalls, of course, SIEM and SOAR.
Then you've got the identity layer, IAM, identity governance, and now ITDR, identity threat detection and response. And then the data layer, DLP, a great tool from the olden days. Data leakage prevention, still very valid and viable today. Data security posture management and full data security platforms down there in the bottom right.
So lastly, disposition. Data minimization is a great thing to live by. Get rid of data that you don't need. Why?
Well, it saves you money. You don't have to pay to keep it. You don't have to pay to back it up. It reduces your regulatory noncompliance risks. And it also reduces your tax surplus. So don't forget about the last stage of the information protection life cycle, getting rid of the data. And that can be archive or delete, depending on what your jurisdiction requires. So let's look at a couple of old style and current data protection tools that we have. So you all may remember things like ACLs, access control lists, role-based access control. RBAC's been around for at least 40 years now.
And it's not without its problems. I mean, a lot of organizations have, in some cases, more roles than they have users.
So then, of course, you get entitlement creep. DLP. DLP was really designed in the days where on-prem was king, but certainly works in many situations yet today. Cloud access security brokers was kind of extending DLP to the cloud.
You know, being able to control access, again, based on an identity. And then encryption. So what were the problems with using ACLs?
You know, it could be very complex. I mean, the example I've chosen here is a budget spreadsheet. So you've got a whole lot of line items. And you can see how even in a small organization, this can get very complicated very quickly. You've got, you know, users, groups, maybe service accounts that need access. And then you want maybe a default deny rule. But then there's various permissions. What can they do, even if they have access? And then you might want to put conditions on that.
You know, what time of day or from which IP address ranges can these users log in and get access? So this gets very cumbersome. DLP and CASB, again, I think they serve a similar function, maybe architected a little bit differently.
But DLP, think of a tool that will allow you to prevent your users from, say, uploading sensitive data to their web mail or sending it, you know, trying to download a file onto a USB drive. DLP is good for that. And it does a lot of those other things within the IPLC, like acquire and assess, discovery, and classification, as well as being able to put the access controls on it. Same thing for CASB. CASB can do very similar things for the cloud. It can also help with shadow IT discovery.
But, you know, these tools, too, have some challenges. They're really designed for unstructured data.
They, too, can be quite complex. It can be hard to scale, I mean, simply because think about how many SaaS applications your organization has.
Yes, it can help with discovering those, but, you know, designing rules that make sense and apply across many different SaaS applications, you know, can be very difficult in and of itself. And then in many cases, this doesn't really work well with structured data and databases. I wanted to take just a minute and kind of do a little deeper dive on ABAC, Attributes-Based Access Control. We talk about it a lot. We talk about Policy-Based Access Control, too.
Well, Policy-Based Access Control is based on ABAC, largely. So, you think, how do you want to write rules or policies that, you know, strictly govern access to specific resources?
So, we can look at subject attributes, which can include things like the subject ID, the user ID, a role, what organization they're a part of, but also things like for export control authorization, would you need to know, you know, what's the nationality? Is there an agreement ID in place?
You know, for national security, you might want to know clearance. What clearance do they have? Are they secret, top secret? And then that would map, you know, over here to the resource attribute side, things like the classification, the national security classification. You also have export control classifications. This can be used for, like, sharing intellectual property, too. You may an agreement that says, you know, you're in, let's say, a big B2B supply chain, and you want to limit access to specific partners in that supply chain.
So, you want to know who the IP owner is. Is there a license there? What type of agreement?
So, there's lots of different attributes that can be placed on the resource, and this would be during the, you know, the classification phase. That way, you're able to write policies that take into account subject and resource, and then you see environmental attributes here, too. This can be about where the device is, what kind of device it is, you know, what operating system does it have on it? Does it have, you know, anti-malware? What's its overall health or posture?
So, all these things can be codified into policies for access control. So, let's talk about some of the new tools out there. ITDR.
Again, this is identity-based, but we need to know all about the identity events going on across your entire enterprise, and the idea is to be able to do real-time threat detection, to be able to understand what constitutes anomalous behavior, to be able to take in intel, to understand if, again, in a B2B situation, maybe there are partners who have had their credentials compromised.
So, taking in information from the partner, maybe from third-party sources, you know, have I been pwned by a cloud, something like that, and be able to make, you know, run-time decisions as to whether or not somebody should be able to get access. ITDR can also help you with attack path visualization and investigations, and the R part is, you know, response.
So, what can you do there? Next slide here. Actions. What can an ITDR solution do?
Well, it could potentially do things like force, you know, conditional access, step-up authentication, you know, just terminate the session, temporarily revoke access to a user if you think that particular account is under attack, maybe disable accounts, and, of course, log it. But then, you know, if you have a mature architecture and you've got multiple DR kinds of products, which system do you want to do that?
ITDR often works in conjunction not only with IAM solutions, but it may be routed through SOAR, or you may choose to use your CDR, cloud detection and response, or XDR solution to do that. So, these are architectural decisions that need to be made within every organization about which system, you know, has priority.
I like to say identity security has a data problem because it does, you have to think about the sources, again, B2B supply chain scenarios, quality of the attributes about a given subject user, for example, timeliness, you know, we've seen surveys that show some organizations take days, weeks, and, unfortunately, sometimes even months to remove access from employees or contractors who, you know, have been terminated.
So, if you're doing username password authentication on a business collaboration site, it's a potential that, you know, users who shouldn't get access may still have access days, weeks, or even months later. And then on the flip side, data security has an identity problem. Weekly protected IDs, you know, even in B2B scenarios, many organizations are still only using username passwords. The employees can be socially engineered. There's insider threat, disgruntled employees.
RBAC, like I said, you know, many organizations have more roles than users. So, RBAC doesn't really give you the granularity that you need. And then there's the overall identity attribute quality that has to be a concern. Are you getting good information about your internal users as well as partners, customers, contractors, temp workers? There's lots of different scenarios in use in the world today.
So, DSPM. DSPM is kind of a step up, a different way of looking at data security.
It, too, covers many aspects of the information protection lifecycle, all the way from data discovery and classification, understanding the data provenance. But also, many of them can give you really different views that you don't get from other tools, like looking at, you know, the user ID. What does that actually give you, that user, in terms of which files can they see? What other kinds of resources can they see? It can help with entitlement analysis to eliminate over-permissioning, which happens all too often, and identify orphan accounts.
DSPM can help with configuration and then compliance reporting. Many of them will have frameworks that support CIS, NIST2, NIST, CSF, things like that. It should also include data access governance capabilities, like helping you enforce least privilege, doing risk scoring, and then, like any other part of your security architecture integrations, it should be able to integrate with your ticketing systems, maybe your consent and privacy management systems, or, you know, some organizations have other data tools that they use as well.
So, DSP, Data Security Platform, what does it do? Well, it does pretty much everything a data security posture management solution does, plus, you know, it can have vulnerability assessment capabilities, it can have data protection, encryption management, again, encryption management is very difficult in itself. It can help you sort of bridge the gap between structured and unstructured data. It is sort of the pinnacle here of the type of solution that you would want for full spectrum data security.
So, in the interest of time, I won't go through this in detail, but I tried to put together a little chart that shows what ITDR, DSPM, and Data Security Platforms actually do. And you can see ITDR, of course, is very identity-centric. It handles the things like user behavioral analysis, attack path analysis, things that, you know, your data perspective tools may not do as well. But on the other side, you know, you've got things that ITDR doesn't do, which is look at the data level, you know, supporting both structured and unstructured data during the data discovery classification.
And you can see, in general, data security platforms are more comprehensive than just DSPM solutions. So, here, I'm wrapping up. Let's take another poll question.
So, and this is a multiple choice, you should be able to select all that apply, but which of these tools does your organization have in place today? Do you have DLP or CASB? Do you have a DSPM? Are you using ITDR yet? Or do you have a full data security platform? Or none of the above?
So, with that, I would invite you to feel free at this time, if you've got questions, go ahead and submit them. We'll take them at the end. And now I'd like to turn it over to Matt. All right. Thank you very much, John. That was really insightful. I want to follow on from that and talk a little bit about the scenarios that we see with identity and data and the issues of being able to bridge those two initiatives. And then talk a little bit about how we as a company help companies tackle and deal with these threats. But let's start at the beginning.
The identity crisis really has, I think, been thrust into the limelight over the past maybe 12 months or so. The number of very public compromises that have been happening, it's all come back to one thing, which is really a compromised identity. I think the irony in a lot of these cases, all of these organizations that we hear about had, you know, a lot of investment in layers of very, very capable, very clever security technologies.
You know, it may be next gen files and DLPs and SIMs and EDRs, etc. But unfortunately, we're still in a situation where data is being taken. And it's being taken because, as John already pointed out, it's the identity that's been compromised. Every breach typically starts with a compromised account, certainly the external ones, and ends with data being taken.
You know, there are all sorts of reports that came out. The Verizon data breach talks about 57% of all cyber attacks start with a compromised account.
You know, over 80% of all security breaches involve a stolen or weak credentials. And the last point on this slide really is you know, just very recently, a healthcare organization in the US had a compromise. It was on one account. It didn't have MFA turned on. And they were able to get access to that data store. It was done by a threat tactical ransom hub. And they stole half of the US population's records, so about 190 million records, all for one compromised account.
So really, I mean, what is happening? Nothing that we don't already know. An account gets compromised. And as John has already pointed out, there's a number of different ways that this can happen. Once they have access, they can move laterally. They can start to collect data with little friction. And the reason why is because they can get their hands on very sensitive data because we're not really managing what we call the blast radius, you know, and everything is interconnected.
Once an attacker has a foothold, they're elevating their privileges by reading chat messages or finding credentials in plain text. And then obviously, AI, I will mention AI, then makes the attacker's job that much easier.
You know, what they need to do now is ask their chatbot for the data, and it will compile it for them, and it will give them for them. So, you know, this is off the back of the Statista report that came out at the end of last year. 194 days is the average dwell time. What do we mean by dwell time? It's the time to identify and contain a data breach globally. A number of examples.
This is, you know, this is just unforgivable, I suppose. But nonetheless, this is a recruitment arm of a well-known global fast food chain. I'll let you use your own imagination to work out who that is. They were utilizing an AI tool, as a lot of companies do now, to do, you know, the hiring and the investigations and to look through the CVs and look through some really sensitive information. And unfortunately, one of the admin accounts had one, two, three, four, five sets in both the username and password fields.
So obviously, it didn't take very long for, you know, the access to be compromised. A research group was able to get access to the admin interface, and then they then subsequently downloaded and got access to, I think, 64, it says there on the screen, 64 million records of all the applicants that applied for jobs.
So again, you know, it's a simple compromise of an account. That's all it takes now. And the integrations that we have between all of these data stores and these SaaS applications mean that they make it very easy to find and exfiltrate very valuable information. So this really is fresh. Unfortunately, Sales Loft was compromised very recently. It began with a compromised GitHub account, again, publicly accessible, contained information within the GitHub repository. The OAuth token was stolen.
The integrations that were then in place in Sales Loft, particularly with things like Salesforce, meant that they were able to then move laterally from one SaaS application to another SaaS application. And there were a number of very high-profile organizations that then had information stolen, exfiltrated. So we really do need to think about this concept that if an account is compromised, the ability to land and expand and move laterally between interconnected data stores, SaaS applications, IaaS repositories, is really much easier than it's ever been.
And with storing, as I've just alluded to, you know, more data in more places than ever before. And with that drives more risk. We now need to understand how, you know, how access is provisioned in a multitude of different user repositories. John talked about IIM, but the Azure and the Oktas and the Single Cell, they all have their own way of doing it. They all have their own way of being configured. And so we are seeing data being exposed, sometimes nefariously, sometimes through negligence. And the blast radius is growing. It's growing relentlessly.
And it really does fall on that shared responsibility model that we as consumers have to ensure that these things are configured properly and we're not exposing information that we shouldn't. And of course, AI, chatbots, agentic AI will utilize that identity fundamentally to be able to provide answers to questions that are then given to it. We know the level of exposure that organizations are suffering from because we see it day in, day out.
We produced a report earlier in the year, as we do every year, the state of data security, and it highlighted a number of different really eye-watering issues that a lot of companies are having. This is actually a report that was pulled off the back of a thousand organizations of assessments that were done on their SaaS environments, on their on-prem environments, on their database environments. And this is obviously AI focused, but really every organization had had information exposed to AI tools unnecessarily. A lot of organizations have unverified apps.
We're talking about shadow AI, shadow IT, to be able to get access to this information. And the other interesting thing is this concept of ghost accounts. So ghost accounts are those accounts that are still active, still have the ability to authenticate, but are no longer needed, no longer used. And it may be contractors, it may be third parties, it may be guest accounts, it may be accounts that were created for testing purposes that are never removed. The problem is we're not doing very well at our joiners, leavers, movers process. We're not identifying those ghost accounts.
And if those accounts belong to a non-human, then it's very unlikely that someone's going to flag that my account is doing things that they shouldn't. So you can read the numbers for yourself, but you know, a lot of stale accounts, a lot of stale permissions, a lot of unnecessary risk and exposure that really is low hanging fruit that we should be cleaning up and doing a much better job of. Data security platforms typically, and John alluded to this really nicely earlier, the integration with identity.
So if you think about what data security is looking at, it's looking at the data, of course, but it sort of lacks the visibility of identity, risk, and of course, posture, how they're configured, the MFAs, the password changes, all of those things. And that then leads to a lack of understanding and being able to respond to identity-based threats. That is your early warning sign. The last thing any organization wants is an alert to say that data's been taken or exfiltrated or encrypted, heaven forbid.
We want to be told early on that there is a risk or there's been a compromise and it's on the identity. And DSP platforms typically lack that integration. So they make it very, they can be quite ineffective in being able to disrupt that attack chain from that compromised account all the way through to, you know, the actual identifying and exfiltrating of valuable information.
And in the flip, when we look at things like identity, you know, threat solutions, ITDR solutions that John explained earlier on, they really have very little visibility or understanding of the data sets that those identities have actually been given access to. So being able to make a determination about whether an account needs access to a certain, you know, application or not really is a very much a difficult job and somewhat reliant on the business to help make those decisions because they don't have that context of the data that those accounts have access to.
And so therefore being able to reduce the blast radius of really valuable information is really a bit of a non-starter. They don't really have concept of what we call user and entity behavioral analytics, the types of data that identities typically work with, their peer relationships, all these different attributes that we can actually make a determination of this identity processes and creates and shares and collaborates on these data sets. Without that visibility, we're somewhat in the dark, there's certainly a certain amount of disconnect.
So we really see ourselves and, you know, just bringing it back to us as being able to bridge that, bridge that gap between identity and data to make it much, much easier to ensure that, you know, the accounts that have been provisioned are getting access to the right data. John talked with authority on what DSPM is. I like to talk about DSPM, so passive DSPM and active DSPM. DSPM is a really, really fundamental part of the cybersecurity stack that every company should have.
It helps you identify where your valuable assets are, what's important, and it goes some way of being able to identify, you know, access and provisions, but certainly misconfigurations. But really, I sort of see that as the easy stuff. The hard stuff is what do I then do about it? It's all very well being presented with, you have a lot of data, it's very overexposed, you have misconfigurations in your IaaS platforms, in your Azure platforms, or wherever they may be, but not really having any way of being able to mitigate it or remediate it.
We certainly don't have the time or the staff to be able to tackle this stuff. So the hard stuff is analyzing the findings, automatically remediating and fixing and locking down, you know, that overexposure, making sure that those identities are mapped properly and being able to respond to alerts. Because at the end of the day, why are we investing in a data security posture management platform? It's to stop data being taken.
And if we sort of go half a distance and we're told we've got problems that we can't really tackle, you know, the challenge of ensuring that data isn't leaving our business, then we really do need to think about how we perhaps change the approach. And of course, that leads me nicely on to what we do and our approach. So on the identity piece, three core pieces of information that we feel really helps, you know, visualize the risk that you may have.
The first thing is resolution, and I'll go into details in a minute, being able to understand who an individual is and all the subsequent access they have. The posture of an identity is, you know, really clear to understand. How are they configured? Do we have the MFAs? Do we have password changes? And of course, identity threat detection and response really is the early warning sign. So how do we do it?
Well, really, we map every single account that an individual has. We think it's some clever magic, and I work out who Cameron is, and I work out all the subsequent identities, and then I then correlate it down to an individual. So I can then see very quickly what is the blast radius of Cameron? What is the risk associated with Cameron being compromised? What accounts does he have? Think about the joiners, leavers, movers process. John talked about people leaving and not having their accounts removed.
This is a great way of ensuring that I know who Cameron is, and if he leaves my business, I know all the individuals, all the identities that I need to go and remove. So identity resolution really is the first step, but then you need to understand how is that identity configured? And this is the whole posture piece, and again, this is bridging that ISPM, that Identity Security Posture Management, and the DSPM piece.
So continuously track all the changes to that account, you know, all the access that it's been given, all the roles that it's been given, making sure that they tally up, that they're in line with peers and group expectations, making sure that you can reduce the exposure that that account has. Being able to understand what's important and then know whether an account has access to it really is a huge challenge, but you know, being able to then mitigate that really needs to be part and parcel of it.
So being able to determine and identify risks, misconfigurations, and then automatically remediating them to ensure that this attack layer, your identity layer, is in as good a place as it possibly can be. And then all of that information then allows us to then respond to identity-based threats. We run a managed data detection and response service.
We help organizations understand threats on their data, but nine times out of ten, the breaches that we stop almost daily at the minute are on the identity, because we have that concept of understanding who an individual is, how they typically behave, their role, their privilege. We have complete forensic view, all the activities that they perform, so we're able to respond very quickly if an account looks to be compromised. And it may be, you know, an account that's been sold and coming to a sense application, or it may be an insider that is looking to leave the business.
Every single one of them have their own behavioral patterns, and we're in a very good place to be able to determine that and respond to it. So visualizing the identity risk is one of the obviously really important part. The middle piece, automatically remediating and sustaining that low level of risk has to be part and parcel of what we regard as acceptable configuration for an identity, and any deviation, any changes, the ability to alert and of course respond, as John already talked about, being able to, you know, log out accounts and disable them whenever we feel fit.
So we really are in a position where we have a data security platform that bridges the identity risk and then overlays it over all of the data sets, all of the repositories of information that we then look at. So just to touch on the identity piece, we automate and we help organizations implement guardrails, acceptable usage of how data should be provisioned and processed. We find everything that's important, we fix everything that needs fixing automatically, and then of course we alert as when we need to.
So real-time visibility for us basically pulls on obviously the importance and the sensitivity of the data, and we do that for everything, wherever the data may sit, unstructured, structured, semi-structured, it makes no difference. We understand all the effective permissions and of course the configurations. We capture all the and how data is flowing in and between cloud repositories and of course we understand identity. Once we have that information, then we can add some context into what we're finding.
We understand where you have exposure, we understand lineage and business context, we make sure that this is a current view, always up to date. When we see documents being amended or changed or created, we automatically inspect them, scan them, protect them, so at any point in time you can see what the data estate looks like, and of course there must never be a situation where you have blind spots.
Huge amounts of databases, they all need to be scanned top to bottom and unstructured data always has that hidden nugget sensitive information on page 22, so we have to make sure that we scan everything. And then when we find those risks, then we then allow companies to automate the protection, automate and remediate without any intervention, by removing excessive access to data sets that they don't need.
Maybe they had a role that they've since changed, or maybe it was a project that was fired up and then has since disbanded, or maybe it's all wide exposure through negligence or an accident, but automatically revoking excessive access without impacting the business really is the game that we play. Again, fixing misconfigurations, whether it be buckets that expose or identities that get compromised, helping companies automatically label and apply protections to data sets, so downstream DLP policies can be turned on without any involvement from the business whatsoever.
Removing third-party applications, disabling, you know, stale users, those ghost accounts that I talked about at the top, even removing redundant, obsolete and trivial information, and I won't repeat what John went through, but you know, it's a massive problem. There are risks, there are costs, there are fines, we shouldn't be protecting information that we shouldn't be holding, but again, you need the visibility.
So whilst we find it, and whilst we're automatically protecting it, we're monitoring everything, and we build up an understanding, a profile of every account, human, non-human, we know what they do, we know the data they work with, we know their level of privilege, we know all the applications and the SaaS apps that they have access to, and we know what we expect to see, so we monitor everything, and you know, we're very fortunate to be able to provide a service around this where, you know, we respond in minutes, almost instantaneously, to be able to lock down and isolate that risk without further damage to the environment.
I put this on here because everyone always asks me, well, how do we start? Well, this is typically how every company starts.
I've left it on, I've put a QR code, so if you wanted to take a picture it will take you to a site, they'll give you a bit more information, but really, the best way of articulating what this is, is it's an assessment that's completely free of your environment, wherever your data may be, in whatever format it sits, and yes, it will highlight risks, and it will highlight exposures, and it will help you cement and visualize in your mind what risk you're holding, but fundamentally you have something tangible in your hands that you can then build on.
So as you start to go on your journey to start to mitigate and reduce the risk, and dispose of information, and lock down those identities, you have that baseline to then, you know, demonstrate that there has been increases, and there has been reductions where there need to be reductions and increases.
So I urge you, if nothing else, you know, turn the lights on, you know, get an understanding of what your risk looks like on your data environment, wherever it be, in the cloud, in a data center, makes no difference, and then you can then make a determination about where you prioritize and focus your efforts to ensure that your data and your identity, of course, is protected. So that's me, I think there's a thank you slide at the end, but I'll stop sharing and come back to you, John.
Well, thanks, Matt. Yeah, that was very informative.
You know, some of the things that you had there, you know, the staggering numbers of ghost accounts that are out there, that just really confirms some other figures I've seen in the field too, you know, it's kind of amazing that organizations have this problem today, you know, that there are so many accounts out there from, let's say, partners or customers that are no longer active, and they do represent a real risk. Absolutely, absolutely.
Yeah, we run that report every year, and it's always eye watering, and I always hope somewhat that it gets better, but it doesn't. There is this concept of the shared responsibility model, and I think people tend to forget about that. When you think, I'm putting my data in the cloud, I'm now going to be using the Azure, the blogs, and the AWS, whatever it may be, and it's going to be in a much better state.
Well, only if you configure it properly, only if you ensure that your shared responsibility is actually looked at and gone through with a fine tooth comb, because any mistakes in those situations could be catastrophic, because obviously all of this is on the internet and exposed to anyone who wants to go and make, hey, well, the sun is shining, I guess, but yeah, it's always a bit eye watering when you get the numbers back from those reports. And I like the distinction you drew, too, between, you know, what I'm going to call it broadly security posture management solutions do.
I mean, we now see DSPM, CSPM, ISPM, you know, they're about, you know, they'll help you find problems, but they're not really designed to help you remediate them. So that's why, you know, most tools also require some sort of companion detection and response tool if you want to be able to actually do something about this security posture management issues that you find. Yes. Yeah. And I've also seen, you know, that we can help generate support tickets for you. So we And that's great.
But I mean, again, it comes down to manual intervention and having the resources and the time and making sure that that then is done, you know, properly and continuously. And it's just not sustainable. We really work very hard to try and automate as much as we can, because we know that organizations don't have army of individuals to go around making sure that these things are continuously locked down.
So yeah, it needs to be an end to end finding the problem, identifying the problem, but actually then using that information to proactively implement acceptable usage and guardrail policies. And I think a lot of companies really starting to embrace this now.
You know, and I like that you showed the integrations that you all have, because no security tool is an island. And being able, you mentioned ticketing, you know, that's, that's really key to be able to integrate with TSM and other parts of your security stack.
Yeah, yeah, absolutely. Yeah. Yeah. When we've opened the platform up, you know, we're very hopeful that APIs and MCPs and integrations with different tools, they all add, you know, more, more, more context to what we're doing. When we're running investigations, you know, we want to see, you know, the EDR logs, we want to see the firewall compromise logs, because we want to identify how it, how it happened and where we need to go back to patient zero or compromise zero to make sure that all that work we're doing isn't just going to happen again.
So yeah, the integrations are absolutely invaluable. Well, let's read over our poll results, because we've got some pretty interesting numbers here. The first question was, what is your biggest concern about data breaches? 55% said reputation damage. Interesting. Yeah. 27% said interruption of business continuity. 14% remediation costs. 5% regulatory non-compliance fines. And nobody's worried about losing their job. I guess that's a positive change in the work environment today. Yeah. The reputation damage is an interesting one.
I mean, I'm sure you're aware, we've had a spate of attacks in the UK, for example, retail companies. We had supermarkets that were ransomed, and, you know, Harrods, I think, were done. Big organization, Marks and Spencers, were compromised. And obviously, reputation was hindered, because it meant that their customers would go to other supermarkets, because, you know, that's, that's where they could get their weekly shop from. Just an example of how the reputation can be damaged without you really thinking about it, I guess.
So, yeah. Yeah, it can have a lasting effect for sure. Absolutely. The second question was, does your organization have any of these tools in place today? 40% say yes to DLP and CASB. Okay. 28% said data security platform.
So, a lot of room for growth there. ITDR at 24%. Interesting. And 8% said none of the above. And nobody said they had a data security platform amongst our respondents. That's interesting. Yeah. A lot of room for growth for DSPs and ITDR. Yeah. Absolutely. Absolutely. It seems to be top of mind at the minute.
So, some of the questions that we have received so far, if we decide to run a data risk assessment, can we do that on all of our data? And what happens to our data? You could potentially do it on all of your data. It depends on how much data you've got, and how disparate it is, of course.
I mean, we could spend, you know, a few weeks scanning it all. I would say a lot of organizations typically pick 100, 200 terabytes maybe. And they sort of say, you know, this is the wild west as well.
This is, we want to know about this data set. We want to know about these. This is where we store the most important information.
So, when we run these, we typically target those data sets. But go big. Go big. It's important you know that these things can scale. What happens to your data? It remains in your tenant, in your repository. The last thing I want is your data. The last thing my legal team want is your data.
So, it's really important that when we're looking for regulatory sensitive intellectual property, it's all done locally with inside your environment. So, no data leaves wherever it's hosted. It's really important.
Yeah, I guess my take on that would be, yeah, start with a manageable amount of data. But yes, try to point it at all the right places. Use tools to help identify where those right places are.
And then, yeah, try to select a tool that can understand data in the various locations, including structured data and databases. Another question is, if an identity gets compromised, what can Varonis do? Can you stop that identity from stealing data, running ransomware, et cetera? Absolutely. That's the short answer. Yes. We have a number of ways of being able to respond. If an account is compromised, you know, we can disable it. We can do all sorts of activities with it.
Yes, everything within the Varonis ecosystem, if something is alerted against, and we have hundreds and hundreds of what we call behavioral-based threat models, if any one of those are triggered, you have the ability to automate a response straight away. We can do that identity. We've been doing it for things like ransomware for years, you know, being able to stop an attack, isolate it, stop it in its tracks.
So yes, the answer is, if an identity is compromised, we will then ensure that that account is then stopped from authenticating. And of course, any existing authentication sessions that are in place, we can kill those as well. So there's no sort of subsequent access that's going to remain open for 24 hours. So all of that can be stopped. Another question is, bringing identity to data makes perfect sense, but how do you ensure employees aren't losing access to the data that they need?
Yeah, it's a great question. So there are two ways of looking at this. First of all, having the ability to automate and remove exposure is giving a lot of companies, particularly in the world of collaboration, where we've been productive individuals for years and years, and I can share information to whoever I want, and that's great, and we're never going back from that. But you can, as a company, enforce policies to say, if something is organizational wide exposed and it contains this level of information of sensitivity, it's removed. That's a quick policy that we can define as a business.
And if somebody loses access to a collaboration link, for example, then they can quite easily go back to the individual and say, can you share it just with me? So that's a quick way. The other thing in terms of implementing least privilege, this is where it really comes down to, again, profiling and understanding accounts and peer relationships. So from the day one, we are starting to understand who John is, for example, and John's role and John's privilege and the department that he's in and the projects that he's in, and we can very quickly work out peer relationships.
And then we're in a very, very unique position to be able to make determinations that this account doesn't need access to these data sets for all of the reasons above, and actually model the changes to ensure that if we were to remove that account, we haven't seen any activity that would suggest that it would need it. All the peers don't need it. And so we've got 20 years under our belt now, being able to implement these policies and remove that superfluous access without impacting the business.
Of course, a lot of this comes down to building confidence in companies. So typically the way we tackle that is that we can show you the model change that will happen.
So, you know, you can get approvals, maybe with the custodians or the owners or wherever you deem fit, to actually say, Varonis is making a suggestion that these 12 people lose access to your SharePoint site because they believe they don't need it anymore. And pretty much every time the business go, yeah, that's fine, they left, they left, they don't work for us, they're a different team, that's fine, make the decision, you know, go ahead and do it.
And after a while, typically what we found is that the confidence levels grow and then Varonis is just sort of looking after it in the background and removing access where it doesn't need to be. But there's a lot of analysis, there's a lot of modeling, there's a lot of context and information that we capture before we make a decision that an individual on account, I should say, doesn't need access to a certain data set.
Yeah, that's kind of a principle that certain access governance tools use, you know, you can put it in monitor mode or sometimes they call it audit mode, watch what, you know, users, groups are doing, and then it can make recommendations about what should be pared away from that to help you enforce at least privilege. Yeah, absolutely. Last question we have here is securing one piece of data is one thing, but what about millions of copies? What can be done? That's pretty good.
Yeah, well, when I say millions and millions of copies, I guess we're talking about duplications of data. I always give this example, I mean, obviously, we use things like Google and Microsoft and all these great collaboration platforms, absolutely rife with duplication.
I mean, John, you share a PowerPoint document with me and I click on the link and it opens it up in a browser and nobody likes using PowerPoint in the browser. So, I open it in my desktop version and then I save it to my OneDrive and then Tom wants a copy and within the space of 15, 20 minutes, that's three copies. It's a huge problem, the whole duplication piece. What can be done?
Discover, find, identify. We use a lot of AI techniques now to actually interrogate documents, so not looking at names of documents, not just, I don't think we can hash things anymore because things tweak and change.
So, we're continuously looking and identifying documents that meet duplication parameters and then you then have the ability to make a determination, either manual or automated, to say this is the definitive copy that we're going to keep and all these subsequent copies are going to be removed. Again, that can be automated.
But, yeah, you need to interrogate the content. You need to interrogate the usage and then to make a decision on which one do we keep.
Well, really, it comes down to activity. This is what we found. This is the one that's shared out the most. This is the one that's used. This is the one that's accessible to our customers. This is the one that we're going to keep.
Again, there can be an approval. There can be a whole workflow to make sure that we're doing this properly, but you need to interrogate and investigate every piece of content on every single document in an automated way and then make a determination that these are the duplications. Duplications is a massive problem.
Cost, especially with cloud repositories, it's getting more and more expensive to store this stuff. Obviously, the attack vectors are, of course, a big factor as well. I agree. I think back to the information protection lifecycle, the earliest phases when, let's say, a PowerPoint is created, tools that go in and can allow you to put that metadata, that labeling on in such a way as it's retained if it is copied or moved to a different location.
Those labels can help you then consistently enforce policy across different collaboration systems or different file systems as long as there's agents that can really act as the policy enforcement point then. Absolutely. Absolutely.
Well, great. Thanks for our audience for joining us today.
Thanks, Matt, for your contribution. I think it was very enlightening.
Thanks, Joe. So, yeah, as I said, the recording and the slides will be available in just a few days. And please join us for our next event. Thanks again, Matt. Great.
Thank you, Joe. Thank you.
See All Locations
See All Locations