Transcript
here at Okta, and joining me today is Stephen Manley, the CTO of Druva. Welcome Stephen. Great to be here. Thanks, we're excited to have you. So one of the best parts about my job is that I get to sit down with customers like you and talk about what's top of mind. We've actually identified a handful of topics and one of them, or the one we're going to talk about today, is the future of data resilience. And so can you tell us a little bit about your role at Druva, what it's like being the CTO, and just introduce folks to who you are. Sure. So let's start, I'll start with what Druva is. So Druva, we're a data security company, we're fully SaaS. So very similar to Okta, our focus is customers have data that they need protected. That might be endpoints, it might be Microsoft 365 and Salesforce, might be in the cloud, it might be on-premises, remote offices, wherever. You've got data everywhere, it's sprawled, and everybody wants it. And bad things will happen. Bad people are trying to get at that data, bad things can happen. And so Druva's job is to say, we protect that data for you so that on the worst day of your life, you're able to get that data back and you're able to get your business up and running again. So that's who Druva is. For me, I'm CTO. So that really means that Druva, I'm in charge of everything from the security team, and then of course, sort of the future architecture of the company. So it's a great job. And I mean, the best part for me is, again, I am meeting 100, 200, 300 plus customers a year. So when you're talking about what they're afraid of, there's a lot of fear out there right now. Yeah. Well, you know, we live in a little bit of an unknown time, it can be a little bit scary. We have, you know, cyber threats, natural disasters, just attacks and things happening all the time. What would you say are some of the fundamental pillars for a truly resilient data strategy? So the first thing that you need to look at when you're building a data resilient strategy is, do you have a protected copy? Because as Allison just pointed out, something bad's going to happen to you. And no matter how much you prepare, no matter how hard you work, no matter how good you are, someone will make a mistake or, you know, given where we live, an earthquake will happen or a bad person will be able to get in, you know, through a mistake or some sort of gap. And so to have data resilience, you need to be able to have a plan that says, when you get compromised, you are going to be able to recover. And so that's the first pillar is, do you have a protected copy that you're confident that you can recover? The second is, and this is increasingly important, it's not always just about having the technology, it's about having your people connected. And so to have a really good data resilient strategy, you need your IT team to be connected to your security team to be connected with your lines of business. Because it's all well and good to say, I have a copy of your data, I'm able to recover. If you don't know what it means to the business, then you're not really recovering them. And given the number of threats that are now security oriented, if you're not tight at the hip with your security team, then you're not really sure what you're recovering from. And then I'd say the third pillar that's absolutely critical is to have, I think, a workforce that understands, you know, that we do live in a dangerous world. So I'm not saying everybody needs to come to work afraid every day, but everybody does have to have a healthy respect for this is why we have securities. So those are really the three pillars. Have a data resiliency solution, data protection solution, make sure that you're tied together across your organization, and make sure you bring your employees along so they know why you're doing what you're doing. Yeah, that's really helpful. You know, at Okta, we say identity is security. And again, it's like, we want to make sure that the right person has the right information at the right time, so they can make the right decision. So it's really helpful to hear that, how you're thinking of it at Druva as well. So if we look back at the evolution of data protection, we have two questions. One, what has been, what would you say have been some of the most significant shifts that have shaped your approach to data resiliency? And then what do you think some of the key drivers were behind, or behind those changes? I'd say probably the two biggest shifts, if you look at it in the market right now, one is the importance of security, and then the other is the importance of cloud. So if you look back five years ago, those of us in the data protection space, security was not top of mind. And if you look at most security teams, they never thought about their data protection infrastructure. But because of the rise in ransomware attacks, and the fact that backups are targeted by ransomware so that you can't recover, and that in fact, backups are the only way you're going to recover from a ransomware attack without paying, all of a sudden security became really, really important. And it changed the way we designed, implemented everything that we focused on. And then cloud is the second, right? The fact is, most data no longer sits in a data center. It sits up in a cloud, whether it's a SaaS application or a cloud-native application. And again, that changes the rules. So those are probably the two biggest changes. And in terms of then the second part of the question, why? So again, security, what we find, and I'm sure you see this at Okta, too, I'd be curious. Early on, we saw a lot of organizations say, well, it's the big companies that are going to get targeted, right? The attackers want to go after the big name New York financial institutions. The reality is, in the last couple of years, we see it's educational institutions, it's hospitals, it's manufacturing companies, because that's an easier target, because they don't have the huge budget and the huge IT staff. So I'm guessing you see kind of a similar thing on the identity side, right? Well, it's interesting to see how companies have vulnerabilities. And so you have to really be thinking about your posture management at all times to make sure that you're as safe as you can be across all different parts of your business, and who you touch, and accounts, and partners, and things like that, as well. Absolutely. Right. And so to me, that's probably the biggest driver in the shift, is that a lot of these concerns, which maybe we used to think were sort of Fortune 50 problems, are now everybody's problems. Yeah. And that's just changed our market completely. Yeah. So it's interesting, because you sit down with your customers a lot, or your team does, or the remit handles that. So we know that organizations, they want to be more proactive, of course. They want to be able to see the future, and anticipate these disruptions, and really minimize their impact. At Okta, we have threat intelligence, and we're trying to be more proactive in getting this information out to our customers and our community, so they can prepare. Now, you probably hear this from your customers, as well, but how do they become more proactive? How do they get there? What are you seeing across your customer base, and what are you guys doing at Druva to get ahead of it, if possible? So there's two things we always tell our customers. The first one is, any solution you have in place for dealing with, say, again, recovering from a ransomware attack, if you haven't tested it, it's not a solution. Yeah, a terrible story, but we met a customer who, when they got hit with ransomware, really struggled to recover, and the CISO was just infuriated, and he said, I cannot understand why this has gone so poorly. We had this entire thing fully documented. It was a 186-page document, and you don't want to be mean, but you say, how many people do you think read that? And so we see that either people are overly rigid, or they don't have a plan at all. And so, get a simple plan that's flexible, and then test it, test it, test it. That's the first thing. The second, in terms of being proactive, and this really ties back to the identity piece, is, assume you're going to get hit, because it'll happen. Something bad will happen. Understanding that mapping between identity and data is critical, because if you get compromised, and the only thing that gets affected is some of your home videos, and maybe some marketing material, your heart's not broken, right? Thank goodness, someone looked at our marketing material. And so understanding who's got access to what is really important, because then you can put a lot more stringent controls on those employees that have access to, let's say, more of the crown jewels in the company. And so, understanding that relationship between identity, information, and application really helps you be proactive in terms of preparing for what's going to hit you. Yeah, having that strategy, and a much shorter documentation process as well. Thank you so much for joining us. Thank you guys so much, and we'll catch you next time.