Transcript
Senior Director of Product Management at Rubrik. Malika, thanks for joining. I'm Nawaz. I'm thrilled to be here. Thank you for having me. Why has identity become such a critical part of cyber resilience? Nawaz, that's a really a great question. So today we're seeing a changing landscape. We've seen the surge in identity-based attacks. Actually, 62% of breaches today exploit identity. The way attackers are coming in is now through the front door. There's actually a great report recently from CrowdStrike where if we're looking at big breaches that have happened recently, 82% of detections are now malware-free. And majority of now are based on identity. Attackers are walking in through the front door with valid credentials. Today, the way attacks are happening, it's phishing, stolen logins, forged Kerberos tickets. And what's really interesting is once they're in, on average, it takes less than 30 minutes between initial compromise and lateral movements. So once your attackers are in, they are spreading through your system with the goal being staying hidden, blending in, and waiting for the moment. So when you think about resiliency and recovery, now it's a question about when the attack does happen and when your identity does get targeted, how are you actually going to be able to recover? That's a great way of looking at it. What are organizations usually missing when they think about their identity environment is already protected? Yeah, most organizations think about, hey, I've invested in my MFA providers, I've invested in ITDR solutions, so I'm very much covered from an identity standpoint. But as I mentioned today, when you think about how modern attacks unfold, attacks are now unfolding in a very different way. Attackers usually start with something most companies already know is a weak spot. They're looking at reused credentials, missing MFA, over-permissioned accounts. And from there, it's escalating. It's privileged escalation, forged certs, hidden backdoor accounts. And by the time the attack is actually detected, the attacker isn't just sitting in a foothold anymore. They are effectively part of your environment because if you think about the IDPs that a customer has, AD, Entre, and Okta, they are all wired together. So your attacker now is widespread. And so this is the piece actually most teams don't appreciate. Spotting the attacker now is actually becoming the easy part. Cleanly removing the persistence from your systems is what breaks people. So the question I always ask is, if someone took control of your identity environment tomorrow, what would recovery actually look like? How could you actually go recover clean and confidently say that you have removed the attacker away from your system, out of your system? That's a great way of looking at it. So if identity is compromised, what does recovery actually need to include? Yeah. So when we think about what does recovery need to include, let me talk about a little bit about how recovery is done today so that you have context on what are our customers doing today, right? When a recovery happens today, the options that customers do is A, a lot of times if customers are using elements like AD backup, they're backing up your domain controllers. And when you're recovering back your domain controls, a lot of times when you're recovering back, you're recovering back an environment where your attacker is already in. So you're recovering back all your backdoors, your forged tickets, and you bring your attacker back in. So you're not able to really recover clean, and recovery clean is a very critical component. The second option, which a lot of our customers do, is a full forest active directory forest recovery. Now, Microsoft themselves document how do you do a full active directory forest recovery? This is 150 pages, it's 20 plus manual steps, and there's a high failure rate. I think when we looked at data, it said around there's an 80% failure rate if you do an active directory forest recovery manually. And so this is why Rubrik really got into this space. We wanted to build a solution which talked about one, how do you recover clean and ensure you're able to recover clean confidently. And then second, we are thinking about this manual cumbersome operational process and making it as simple as possible and making this a five-step process. So Rubrik, really that is the Rubrik vision today. It is kind of an end-to-end solution that solves for customers' hybrid identity environments. We go from attack to recovery at machine speed, and we really think about four things. How do we go detect and resolve disruptions? So we integrate with your identity solutions already in the market, like CrowdStrike, Defender, even things like your IGA tools, SailPoint, Workday. We defend with your identity provider, your existing identity systems to kind of ingest their signals, be able to detect what an attacker comes in, be able to pinpoint what is that clean recovery point, so that when you recover, you recover clean, you're eliminating your attacker persistence, and you're minimizing this business disruption. So that is really how we recommend customers looking at recovery, which is thinking about how do you make sure you recover not only fast, but you're recovering clean and removing that attacker from your system. What opportunities does identity resilience create for MSPs? Honestly, there's huge opportunities when we think about identity resilience for MSPs. When we talk to our customers today, let's think about the big IDPs out there, AD, Ontra, Okta. 10 out of 10 Okta customers are not thinking about resiliency and thinking about protecting their Okta environment. 7 out of 10 on the Ontra side, 6 out of 10 on the AD side. So the opportunity here for MSPs is huge because this is top of mind now for customers, because as I mentioned, with the surge in identity- based attacks, it's not about when an attacker comes into the front door, it's about when they come in, what do you do? How can you ensure you minimize business disruption, and how you're able to get your business back up and running with confidence that your attacker is no longer in the building. So this is a huge opportunity for MSPs to really go talk to customers about this on this very relevant top of mind issues. And now as we think about the changing environment, especially with agents coming in, the attack vectors are now only increasing with agents now also coming in. So the boundaries, so we call it, is really removed. You need to think about external threat actors, but you also need to think internally, are there agents now with over-permissive access who can go in and kind of create havoc in your system? So recovery becomes even more of an integral opportunity here. Malika, thank you. This is, I mean, this is great information. Until next time, I'm Nawaz Ali. Thanks for joining MSP Inscript.