Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Rubrik: Data-Centric Security for Faster Alert Remediation

Rubrik
10/09/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Hey everybody, welcome back to another episode of Into the Breach and today's topic, we're going to talk about how you can get faster remediation if you have a data centric security approach. No better person to talk on this topic than Mike. Mike, welcome back to the show. Hey James. Yep. Good to be back. Looking forward to it. Awesome, Mike. Well, let's, let's dive right in. So, you know, alerts like there's a lot of noise as customers have hundreds of security tools. You got these SOC teams that are super overwhelmed by the millions of alerts that are occurring on a daily basis. To kick us off, like, you know, how are customers traditionally approaching this overwhelming challenge of all these alerts? Like where do they even start? Yeah, so it's actually a pretty tough problem as customers have moved, especially more into the cloud and SAS arenas. There's so much more data, especially in the internet age, there's tons of data being generated every year, which adds to the amount of alerts being generated. There's a lot of different technologies in the mix, which adds to the number of sensors that are generating these alerts. And then those all come to a central place, maybe like your SOC. And the real issue is that, you know, where it might've been thousands, if not a million alerts, any given time period now that's probably closer to a hundred million, a billion alerts. And obviously this is something that a single human cannot handle. So a lot of this drives into anomaly detection or other methods for sifting through the noise. But a lot of that leads to false positives and red herrings. And it's at the same time, very data centric or excuse me, I should say very network centric in that we still don't have a true basis of what we're getting after from an end goal and an end perspective of, you know, how does this help the business by fixing this issue? And it leads to frankly fatigue by your IT operators and SOC personnel that are just completely overwhelmed by the amount of alerts that are being generated. Yeah, no, for sure. So, all right, there's got to be a better way then. What do customers, what can they do to like prioritize all these alerts that are coming in so they know where to actually take action and what, how would they just prioritize this whole thing? Yeah, so what we are seeing in the wild and now the industry is that we just have to change the approach of what we're actually focused on as our crown asset. You know, previously that was looking at networking and data from a kind of a lock and key and moat and castle type perspective. You know, let's protect everything with an outside perimeter. That really doesn't apply as strictly to cloud environments anymore because there's so many different ways we can access this data. The attack service is much broader. And so what we really have to focus on is a data centric approach to security. You know, think of data as your core asset and then create security policy around that. And what that's going to allow your SOC teams and other groups to be able to do is when we see alerts that are focused on our most sensitive data, you know, we can take real action and everything else that's generated is frankly noise that can be left for another day. But, you know, our core assets, our core applications, our core data that belongs to our customers or third parties or other businesses, you know, that's our top priority. And so anything related to that, we can then take very focused, immediate action. Yeah, it makes sense. So, you know, the outside in approach isn't working as well. A lot of the TIG, all these alerts, you got to take a more of an inside out approach, kind of what you're describing here. So, you know, DSPM's out there. How does DSPM solve this in a better way? Yep, so what DSPM allows customers to do is first off, provide visibility as to where all their data lies, as well as what of that data is sensitive. Through classification process to start separating maybe our most restricted or confidential data from benign internal, even public data. And now that we have that intelligence, we also can understand how users are able to access that data to help drive least privilege. And with that, we can start building, you know, bringing back the concept of anomaly detection. We now have a more focused view of what anomalies we're looking for. And that relates to how users are accessing sensitive data or entities in a cloud environment. And that allows us to get much more focused on where we need to drive attention from a SOC perspective, as well as as we think about things like ransomware, encryption attack, social engineering, we can more easily determine when user or device entities have potentially been compromised based on looking at how those users access, again, the sensitive data as that core piece we're trying to protect. And this allows those security teams and SOC teams have a much, much more focused goal of sifting through, again, those millions, if not billions of alerts and driving action to the data that's most important to the business with the goal of, you know, continued uptime and security of corporations, more sensitive assets. Now, this is awesome, Mike. So there you have it, folks. If you want faster remediation and you know and want to know how to prioritize all of these alerts coming in, you've got to take a data centric approach to it and DSPM can help. Mike, thanks for joining the show and we'll catch you next time. Sounds good. Thank you.

TL;DR

  • SOC teams face overwhelming alert volumes—from millions to billions—as organizations adopt more cloud and SaaS technologies, leading to analyst fatigue and missed threats buried in noise.
  • Traditional network-centric security approaches focused on perimeter defense no longer work effectively in cloud environments where attack surfaces are broader and data access patterns are more distributed.
  • Data-centric security shifts focus to identifying and protecting sensitive data as the core asset, allowing teams to prioritize alerts based on actual business risk rather than treating all alerts equally.

Summary

This episode of Into the Breach addresses the overwhelming challenge facing Security Operations Centers (SOCs) as they manage millions to billions of security alerts generated across modern cloud and SaaS environments. James Purvis and Mike Schmidt explore how traditional network-centric security approaches—focused on perimeter defense—have become inadequate in cloud environments where attack surfaces are broader and data access patterns are more complex. They advocate for a fundamental shift to data-centric security, where organizations identify and prioritize their most sensitive data assets first, then build security policies and alert prioritization around protecting those crown jewels. The discussion demonstrates how Data Security Posture Management (DSPM) provides the visibility, classification, and anomaly detection capabilities needed to cut through alert noise and focus remediation efforts on what truly matters: protecting business-critical and sensitive data from compromise, ransomware, and unauthorized access.

Chapters

0:00 - Introduction to Data-Centric Security
0:32 - The Alert Overload Challenge
2:43 - Shifting to Data-Centric Approach
4:17 - How DSPM Improves Security Operations
6:03 - Summary and Key Takeaways

Key Quotes

2:56 "What we really have to focus on is a data centric approach to security. You know, think of data as your core asset and then create security policy around that."
3:37 "When we see alerts that are focused on our most sensitive data, you know, we can take real action and everything else that's generated is frankly noise that can be left for another day."
4:33 "What DSPM allows customers to do is first off, provide visibility as to where all their data lies, as well as what of that data is sensitive."

FAQ

How does DSPM help reduce alert fatigue in SOC teams?

DSPM provides visibility into where sensitive data resides and classifies it by sensitivity level. By focusing anomaly detection and alerting on access patterns to this sensitive data rather than all network activity, DSPM dramatically reduces noise and allows SOC teams to prioritize alerts based on actual business risk. This means teams can focus on threats to crown jewel assets rather than sifting through millions of low-priority alerts.

Why doesn't traditional perimeter security work well in cloud environments?

Cloud and SaaS environments have much broader attack surfaces with multiple access points, making the traditional 'moat and castle' perimeter defense approach less effective. Data is distributed across multiple cloud services and accessed through various channels, so protecting the perimeter alone doesn't adequately protect the data itself. A data-centric approach that focuses on protecting sensitive data wherever it resides is more appropriate for modern cloud architectures.


Categories:
  • » Webinar Library » Rubrik
  • » Cybersecurity » Data Security
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Cloud Security
  • Security Operations
  • Data Privacy
  • Technical Deep Dive
  • Best Practices
  • Data Security Posture Management
  • SOC Operations
  • Alert Prioritization
  • Data-Centric Security
  • Sensitive Data Protection
  • Anomaly Detection
  • Security Operations Efficiency
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Rubrik: Data-Centric Security for Faster Alert Remediation

              XStreaminars (watch here)

              • Oct
                28

                EnvZero: Near-Zero Time to Resolution--Live Agentic Remediation for Failed and Drifted Infrastructure

                10/28/202601:00 PM ET
                More events

                Industry Events (Sponsor Hosted)

                • Oct
                  13

                  Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                  10/13/202601:00 PM ET
                  • Oct
                    15

                    Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                    10/15/202611:00 AM ET
                    • Oct
                      20

                      Harnessing Data Governance for AI with Cyera and Snowflake

                      10/20/202611:00 AM ET
                      • Oct
                        27

                        Maximize Security, Value, and Returns on Your Microsoft Investment

                        10/27/202611:00 AM ET
                        • Oct
                          27

                          The HUMAN Experience: Real-Time Insights into Page Intelligence

                          10/27/202601:00 PM ET
                          More events

                          Upcoming Webinar Calendar

                          • 10/13/2026
                            01:00 PM
                            10/13/2026
                            Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                            https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                          • 10/15/2026
                            11:00 AM
                            10/15/2026
                            Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                            https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                          • 10/20/2026
                            11:00 AM
                            10/20/2026
                            Harnessing Data Governance for AI with Cyera and Snowflake
                            https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                          • 10/27/2026
                            11:00 AM
                            10/27/2026
                            Maximize Security, Value, and Returns on Your Microsoft Investment
                            https://www.truthinit.com/index.php/channel/2178/maximize-security-value-and-returns-on-your-microsoft-investment/
                          • 10/27/2026
                            01:00 PM
                            10/27/2026
                            The HUMAN Experience: Real-Time Insights into Page Intelligence
                            https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                          • 10/28/2026
                            01:00 AM
                            10/28/2026
                            [APAC:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                            https://www.truthinit.com/index.php/channel/2125/apac-ensuring-comprehensive-security-for-ai-applications/
                          • 10/28/2026
                            06:00 AM
                            10/28/2026
                            [EMEA:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                            https://www.truthinit.com/index.php/channel/2127/emea-ensuring-ai-security-across-all-platforms/
                          • 10/28/2026
                            01:00 PM
                            10/28/2026
                            [AMERICAS:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                            https://www.truthinit.com/index.php/channel/2126/securing-ai-across-the-americas-strategies-and-insights/
                          • 10/28/2026
                            01:00 PM
                            10/28/2026
                            EnvZero: Near-Zero Time to Resolution--Live Agentic Remediation for Failed and Drifted Infrastructure
                            https://www.truthinit.com/index.php/channel/2179/envzero-near-zero-time-to-resolution-live-agentic-remediation-for-failed-and-drifted-infrastructure/
                          • 11/04/2026
                            11:00 AM
                            11/04/2026
                            Leveraging CISA’s Zero Trust Maturity Model in an AI-Driven Landscape
                            https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-in-an-ai-driven-landscape/
                          • 11/04/2026
                            11:00 AM
                            11/04/2026
                            Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                            https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                          • 11/05/2026
                            02:00 PM
                            11/05/2026
                            HUMAN Dialogue: Embracing the Rise of the Agentic Consumer in AI
                            https://www.truthinit.com/index.php/channel/2160/human-dialogue-embracing-the-rise-of-the-agentic-consumer-in-ai/
                          • 11/05/2026
                            02:00 PM
                            11/05/2026
                            Reclaim Your Evenings: Leverage Data Intelligence to Minimize Risk and Boost AI Adoption
                            https://www.truthinit.com/index.php/channel/2172/reclaim-your-evenings-leverage-data-intelligence-to-minimize-risk-and-boost-ai-adoption/
                          • 11/19/2026
                            01:00 PM
                            11/19/2026
                            360View: Govern, Secure & Recover Your Microsoft 365 Environment
                            https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                          Truth in IT
                          • Sponsor
                          • About Us
                          • Terms of Service
                          • Privacy Policy
                          • Contact Us
                          • Preference Management
                          Desktop version
                          Standard version