Transcript
data security is more critical than ever. Today, we will show you how to reduce your data attack surface using Sierras Data Security Posture Management technology. We'll break it down into three actionable steps. Understanding your unique data attack surface, removing overexposed data, and improving the precision of your purview data classification and labeling. Now, let's take a look at Sierras AI-powered classification and how it works. Unlike traditional systems that would rely on manual programmed regexes or static scripts, Sierras uses advanced large language models, or LLMs, and natural language processing, NLPs, to automatically detect the context of your data. This allows it to classify not just PII and PCI data, but also recognize the different levels of risk based on the subject role and the specific data category. For example, Sierras can quickly distinguish between a customer's financial information and an employee's financial information, giving you an added layer of insights into how your data is classified and what risks might be associated to your business. But what happens when your organization creates unique data that doesn't fit into any predefined categories? Let's take an example of a superhero talent agency, very unique type of business. Here inside of their Microsoft SharePoint, they have a structured database. It's filled with superhero names, secret identities, and superhero ID numbers. There's no regexes for this type of data. So Sierras AI is going to go beyond those built-in templates, but it will automatically detect and generate new data classes like superhero names and secret identities, which are entirely unique to this organization. It's also able to look at the subject role and create a brand new subject role for superheroes. By scanning every structured and unstructured file in your Microsoft 365 account, Sierra ensures that nothing falls through the cracks. This very powerful classification capability gives you the starting point of a complete picture of your data and allows you to uncover previously unknown risks, and therefore start to reduce your data attack surface. Now that we've mapped out your unique data attack surface, it's time to address any instances where your data is overexposed, increasing the risk of breach or misuse. Sierra allows you to easily search within your Microsoft 365 data stores to find any overexposed data. For example, that's filtered by the custom data class superhero name, and that's just what we've identified. By applying this filter, we can quickly locate all files that contain superhero names across SharePoint, OneDrive, and Teams. With this information, we can now focus on reducing exposure by identifying where these sensitive files might reside, and if they're in the wrong locations. One of the most common forms of overexposure is external sharing of sensitive data. Let's take a look at the issues page and filter by superhero data again. Here we can see that we have a policy violation which has triggered an issue. One of them is personal e-mail addresses have access to sensitive Microsoft 365 files. If we expand this, we can see the data store that has had this particular issue, and we can see some of the data classes that have been detected. If I go into that data store, I get a detailed description of what this policy means. It's been shared with a Gmail or Hotmail account, any personal unmanaged e-mail domains. We can see the risk type is access. We can see the data classes, audit report, welcoming letter, and those superhero names and secret identities. If I click at the data at risk tab, we can see there are two files that have this particular violation. If I click on one of these files, let's go with the welcome letter, welcome to the superhero talent agency, and I can drill down, I can start to see some of those data classes with the sample data. We can see the full names, the superhero names, the secret identity that has been masked, as well as that superhero ID number. What we can also do is jump into the permissions tab, and I can see that, yes, indeed there has been a share of this file to a Gmail account. In this case, the notorious supervillain, Victor Von Doom. What I do is I can close this down and then open up an action ticket, and if we're integrated with ServiceNow or JIRA or any ticketing tool, we can then start the process, the workflow of removing those permissions of that particular file. Finally, let's talk about improving the precision of your Microsoft Purview data classification by integrating Cera's AI-powered classification to provide deeper insights and precision. Cera integrates directly with Microsoft Azure, allowing administrators to view any issues associated with labeling. Let's apply a filter to look for superhero data and maybe filter by the labels. Here, we can now see that there is a data dispersion issue where files are missing confidential sensitivity label. There are three issues open, and if I jump into, again, the superhero talent agency, I can start to see what those data classes might be and the various context to them. If I click on the data at risk, let's have a look at the superhero information database. Inside of this, we can then look at not just the overview information, but also the data available with that sample data. We can see the secret identities are available, superhero names, and superhero ID numbers that are listed in this document. We can go up and we can see that the sensitivity label for this document is public, which absolutely should not be the case. If we close this, we can click on actions, apply sensitivity label, and that will allow us to apply this label to this particular file, and any of those files that have been deemed sensitive. Very quickly, what we've been able to do is use this integration to ensure that administrators can make sure that data labels that haven't been automatically applied, can be applied and enriched with the contextual insights to provide the proper levels of protection. In summary, Sierra's data security posture management technology allows you to reduce your Microsoft 365 data attack service in three ways. Understand your data landscape with high precision using the AI-powered classification, remove overexposed data, and improve the precision of your data classification through direct integrations with Microsoft Purview. Take control of your Microsoft 365 data security with Sierra and visit our website today to learn more and start your journey towards a safer Cloud environment. Thank you.