Transcript
Hey everybody, welcome back to another episode of Into the Breach and today's topic, we're going to talk about how you can get faster remediation if you have a data centric security approach. No better person to talk on this topic than Mike. Mike, welcome back to the show. Hey James. Yep. Good to be back. Looking forward to it. Awesome, Mike. Well, let's, let's dive right in. So, you know, alerts like there's a lot of noise as customers have hundreds of security tools. You got these SOC teams that are super overwhelmed by the millions of alerts that are occurring on a daily basis. To kick us off, like, you know, how are customers traditionally approaching this overwhelming challenge of all these alerts? Like where do they even start? Yeah, so it's actually a pretty tough problem as customers have moved, especially more into the cloud and SAS arenas. There's so much more data, especially in the internet age, there's tons of data being generated every year, which adds to the amount of alerts being generated. There's a lot of different technologies in the mix, which adds to the number of sensors that are generating these alerts. And then those all come to a central place, maybe like your SOC. And the real issue is that, you know, where it might've been thousands, if not a million alerts, any given time period now that's probably closer to a hundred million, a billion alerts. And obviously this is something that a single human cannot handle. So a lot of this drives into anomaly detection or other methods for sifting through the noise. But a lot of that leads to false positives and red herrings. And it's at the same time, very data centric or excuse me, I should say very network centric in that we still don't have a true basis of what we're getting after from an end goal and an end perspective of, you know, how does this help the business by fixing this issue? And it leads to frankly fatigue by your IT operators and SOC personnel that are just completely overwhelmed by the amount of alerts that are being generated. Yeah, no, for sure. So, all right, there's got to be a better way then. What do customers, what can they do to like prioritize all these alerts that are coming in so they know where to actually take action and what, how would they just prioritize this whole thing? Yeah, so what we are seeing in the wild and now the industry is that we just have to change the approach of what we're actually focused on as our crown asset. You know, previously that was looking at networking and data from a kind of a lock and key and moat and castle type perspective. You know, let's protect everything with an outside perimeter. That really doesn't apply as strictly to cloud environments anymore because there's so many different ways we can access this data. The attack service is much broader. And so what we really have to focus on is a data centric approach to security. You know, think of data as your core asset and then create security policy around that. And what that's going to allow your SOC teams and other groups to be able to do is when we see alerts that are focused on our most sensitive data, you know, we can take real action and everything else that's generated is frankly noise that can be left for another day. But, you know, our core assets, our core applications, our core data that belongs to our customers or third parties or other businesses, you know, that's our top priority. And so anything related to that, we can then take very focused, immediate action. Yeah, it makes sense. So, you know, the outside in approach isn't working as well. A lot of the TIG, all these alerts, you got to take a more of an inside out approach, kind of what you're describing here. So, you know, DSPM's out there. How does DSPM solve this in a better way? Yep, so what DSPM allows customers to do is first off, provide visibility as to where all their data lies, as well as what of that data is sensitive. Through classification process to start separating maybe our most restricted or confidential data from benign internal, even public data. And now that we have that intelligence, we also can understand how users are able to access that data to help drive least privilege. And with that, we can start building, you know, bringing back the concept of anomaly detection. We now have a more focused view of what anomalies we're looking for. And that relates to how users are accessing sensitive data or entities in a cloud environment. And that allows us to get much more focused on where we need to drive attention from a SOC perspective, as well as as we think about things like ransomware, encryption attack, social engineering, we can more easily determine when user or device entities have potentially been compromised based on looking at how those users access, again, the sensitive data as that core piece we're trying to protect. And this allows those security teams and SOC teams have a much, much more focused goal of sifting through, again, those millions, if not billions of alerts and driving action to the data that's most important to the business with the goal of, you know, continued uptime and security of corporations, more sensitive assets. Now, this is awesome, Mike. So there you have it, folks. If you want faster remediation and you know and want to know how to prioritize all of these alerts coming in, you've got to take a data centric approach to it and DSPM can help. Mike, thanks for joining the show and we'll catch you next time. Sounds good. Thank you.