Benefits of a Unified CNAPP and XDR Platform episode artwork

EPISODE · Apr 22, 2024

Benefits of a Unified CNAPP and XDR Platform

from Info Risk Today Podcast · host InfoRiskToday.com

In this episode of the "Cybersecurity Insights" podcast, Uptycs CEO Ganesh Pai discusses unifying XDR and CNAPP to improve visibility and explains the coming shift from behavioral detection to outlier or anomaly detection, which uses sophisticated ML and AI.

Episode metadata supplied by the publisher feed · Published Apr 22, 2024

Embed this episode

NOW PLAYING

Benefits of a Unified CNAPP and XDR Platform

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Welcome to Cybersecurity Insights, the podcast with a cyber ed.io learning community. Our goal is to have been cyber security practitioners, the latest and most relevant education and training to upsell and dive deeper into topics that matter in today's modern cyber security world. Good day, everyone. This is Steve King.

I'm the managing director here at cyber ed.io. And on today's podcast, we have Ganesh Pai, who is the founder and CEO of upticks. Ganesh was previously the chief architect and carrier products and strategy for Akamai Technologies. And then before that, he was a founder and vice president of systems architecture to bear a few, which is a provider of content delivery solutions to service providers that was acquired by Akamai.

And prior to that, he was principal architect for net devices, which was acquired by Alcatel Lucent, and then served as the engineering manager and software architect for Sonos Networks. He's a Boston based entrepreneur and technologist, has been awarded multiple US patents, received his bachelor's degree in electronics and communications engineering from Mangalore University and a master's degree in computer science from Temple University. So welcome, Ganesh. It's a real pleasure to have you on our show.

Steve, thank you. And I appreciate the opportunity to be here on your podcast. Yeah, sure. So you guys promote yourselves as the first unified CNAF and XDR platform.

Can you explain to our audience what that means? Yes, big question. Thank you for that. Of course, the terms XDR and CNAF are very industry analyst-centric.

As in the likes of Gartmoor, Forrester and IDC, they've coined these terms for the evolution of N.3 detection technology, which has now gotten broader and become extended because you can do a lot more. And then on the cloud infrastructure site, there is the need for securing misconfigurations of cloud infrastructure, whether it's your workload or services that you might procure from a cloud service provider, in addition to your own workload. Where our customer engagement has been, and to a data extent, where our vision has been, is that either as a result of our digital transformation or the emergence of cloud native organizations who tend to plan everything on cloud and deliver it as a SaaS service. These are the organizations which seek for observability model across their productivity and points as a Mac and Windows laptop and Linux and container nodes where their workloads are in the cloud in conjunction with the services they might procure from these cloud service providers.

And if you're an organization which is growing using these elements as a basis, as a cloud native organization, or your traditional enterprise as a result of digital transformation, we're also on a similar journey to use SaaS services and leverage cloud infrastructure. You will inevitably need that visibility to go from your productivity and point to your workload and endpoint in the cloud. And that's what we specialize in, and that's the heart of the updates unification of XDR and CNAAP, which is nothing but cloud infrastructure security, which got not otherwise called as cloud native application protection platform. Yeah, I see.

What is your opinion of the ability of the CSO community at large to embrace hybrid and native cloud applications these days? I mean, we're in a modern environment. We're most of the business units who want to push toward digitalization or by definition pushing us toward hybrid cloud and toward the edge and SaaS and so forth. Do you think that there's a gap that's developed between what folks should know about this stuff and what they don't know about it?

Yes, there are two drivers which are bringing our approach to the front. Some is the good fortune of timing. Here's how I'd characterize it. One is, especially in the world of software where software is used as a differentiator to provide an offering.

The emergent need for supply chain visibility from the conceptualization of software, the way it is built, the way it is packaged, the pipelines that it undergoes for the continuous integration, continuous delivery and being operationalized in the cloud. That has that approach of getting that visibility into that software built and software supply chain as to how it's built and how it's operationalized is a big driver, which is putting a little bit more emphasis on how upticks approach is its solution and how it provides accessibility. The second driver, which is causing a lot of people to have more meaningful conversations with us, is in the past, it used to be the case. And usually this is how I think the pendulum swings.

It used to be best of read for every security control, as you can imagine, in the context of something like a NIST framework. There was a specific vendor, people did not rationalize well, and they bought tools for each of the individual controls. And what we are seeing as a pattern in conversations with Sysos and others is the need for rationalization of software tooling. Be it triggered by the macroeconomic conditions due to the expense incurred in multiple tools, which are trying to do a piecemeal approach or be due to resource challenges.

As an example, operationalizing different tools implies every tool comes with resource utilization and that causes a challenge. So the confluence of software tooling rationalization due to cost and resource needs, plus the need for getting visibility across supply chain are the two factors, which have made it far more conducive for upticks to have a meaningful conversation with Sysos. Yeah, so how are we going to rationalize all of that? That is a great question, because if you were to look at why do organizations deploy security technologies, they do it for two reasons.

One, and foremost, which is important is to make sure that they have the necessary detection and protection cases for protection capabilities. And this is pretty standard if you were to look at frameworks such as NIST, which you might adopt, which tells you that you need to do identified, protect, or detect remediate, and potentially respond when there is something recovered as the last part. So that's one reason that you may want to operationalize various tools. And the rationalization comes into play is that what's the most efficient tooling, which not only allows me to do the parts where I'm doing prescriptive security for my GRC needs, which is to give assurance to my customers, which is so that they can establish trust that you've got good hygiene and good practice, but also to protect oneself, because when there is suspicious behavior and malicious intent, it goes beyond showing that you have good hygiene, because you might have good hygiene, they might be like insider behavior, which deserves a threat.

And you want to make sure that your threats are addressed. So the realization based on the combination that you have address trust-related needs, as well as your own cybersecurity needs, and potentially the ability to do both threat operations and GRC operations that are one tooling, is one of the big drivers that we are seeing in our conversations. Right. The tendency is to layer in additional solutions, be they point or platform and what it seems to me, we end up with this more complexity through that layering.

It would seem to me to be smart to kind of undo everything and start over, not at the brick and replace level, but down to at least let's look at the tool set that we're using and kind of set that aside for a minute and figure out what a better platform or solution might be to replace all that stuff. Doesn't that make sense? It does make sense. Especially in, I don't want to say necessarily modern or sophisticated organization, which tend to be digital knitters or organizations which are born in the cloud of software tech.

There is a desire to have broad-based visibility. Visibility is a very generic term. Everyone seeks it. But when it comes to actual security control, there's no such thing as visibility as a control because controls are very much aligned with ensuring that you have something which aligns to auditing framework and all this controls are essentially tools.

But visibility and more broadly visibility through a observability paradigm is probably going to be a foundational basis as we move forward. The approach of observability is very much there today for availability reasons. If you look at organizations today who have the notion of production operations and what's called a site reliability engineering. These are built on the fundamentals that if you have different tools, the tools emit telemetry and the telemetry results in observable paradigms which allows you to ensure reliability and uptime.

And into that, if you layer in that, you need to get security done in a similar way as in all the assets that you need to secure and the attack surfaces that you need to secure. How can you observe them at scale and draw conclusions whether there is something trending in the wrong direction or something is misconfigured. You need to introduce the notion of security observability atop the general platform of availability which is very prevalent for uptime and service availability. When you layer in security tooling in such a way, you now have the ability to incrementally look at what is your infrastructure, what is your laptop and everything else telling you about where things are trending and if they're trending in the wrong direction, how quickly can you remediate?

This approach of security observability which is very different from individual tooling mandates that you collect telemetry in a structured manner and act upon it because that's how it's been proven to be successful at large hyperscalers such as Google Amazon at the next year of large tech organizations. And now it's being assimilated down into smaller organizations so that they can reap the benefit of security observability and that's one of the tenets and upticks that we've had the good fortune of building a platform ready for that. So this getting into the observability paradigm and starting small and starting with a few assets and asset categories first and building up towards your entire limit is probably the approach which might make most sense for most organizations. And so what would your advice be to a CISO who's dealing with this today?

Yeah, so CISOs have a dual challenge. At the end of the day, they're mandators because they are a part of an organization. And in most organizations, there is either a CIO centric poll or a CTO centric poll which results in operationalizations of certain type of technology such that the business is able to provide the value to their customers. The CISOs mandate typically ends up being securing and reducing the risk for the technology choices made by the CTO or the CIO.

And based on our conversations with CISOs who are in both buckets where technology decisions which have been made which kind of mandate what kind of security they have to operationalize. Our conversations with them have been, okay, if you're more digital native organization, if your con jewels happen to be in the cloud, that's where you begin by having this new model of getting observability through the telemetry and using it both for your threat operations as well as using it for your trust and regulatory and regulatory class. And then you can incrementally add each different attack surface and start providing coverage. That approach of not necessarily risk-based approach but starting off with what matters to you the most and building up from there is where we've had some good fortune of engagement with CISOs.

You had mentioned multiple roles here. Do you think that the CIO role is just as important should be just as active in setting direction and making these decisions as the CISO role? In fact, if you think about it, right, the CIO is the person who's ultimately responsible for information security. CIO is ultimately responsible for security that information in the same way that person responsible for infrastructure, data center operations, or everyone characterizes you responsible for getting production systems through and all the rest of that.

One could argue that the CIO role is more important than the CIO role. How do you feel about that in terms of your approach to doing this stuff? That's a great question. Thank you for bringing it up.

It really depends on the organization. There are two broader categories of organizations and I'll give some examples and anecdotes to the extent it helps. One is probably as an example in the almost manufacturing, whether it is consumer goods that they produce, their value is very specifically around the brand and the products which they manufacture and consumers buy it and consume. In an organization, as such, usually you don't tend to have a CTO because the CIO is the one who is at the center of making technology choices and a manufacturing company typically as an example, more often than not, procures technology from outside, whether it is a supply chain thing such as SAP technology, and then they might make a decision that in order to be more digitally aligned as a result of the digital transformation needs, they might take the supply chain technology such as SAP and operationalize it in various GOs in AWS and make sure that it's close to their suppliers so that they get proximity and other things.

That's one part where the CIO and their technology decisions which cloudboard technology they operationalize brings up the type of assets and the attack surfaces that the CISO has a charter to ensure that they have to secure it. On the other hand, if you look at more software-centric technology-centric organizations where the software which is being developed in-house is the crown jewel of the organization, whether it is a financial transactions processing company or it's in the business of CRM, the CTO and the engineering choices which dictate what kind of software tooling, how they build software in-house and the scale at which they operationalize it in which cloud. That's a different set of elements and the choices that are very dominated by a CTO. seldom would you have a CIO in that organization who is making the choices because it's really the CTO and its organizations who got the responsibility to ensure that technology is operationalized as typically a SaaS service and it's consumed and that's the source of revenue for them.

In those organization, the CTO choices dominate all else and the CISO's charter is to ensure that they secure the assets and the attack surfaces represented by those choices. So a short answer is it depends on the org and how they're structured. It's usually one or the other in tech-centric organizations. It very likely is the CTO and in other organizations like bank and financial institutions and manufacturing, it's mostly CIO-centric.

Yeah. You think we place more emphasis on the things we understand the least, like technology, and when we think about who we look to lead the information security part of the organization, as opposed to GRC or sort of a strategic leadership from a business point of aim? Yeah. That is a very important question that organizations have to answer because the root of it is really the risk and organization faces and as a part of mitigating the risk is the investment in the security tooling, the desire to have the right kind of CISO in place to ensure that the CISO is the main person who understands how to bridge the gap between what risk an organization faces versus what tooling people processes have to be implemented.

An organization like ours typically provides tooling and helps in the process, but what the CISO has to make sure, as an example, it's in the realm of syntax. If the payment processing infrastructure takes a hit or is a challenge, then it's almost existential in nature. And if that's the definition of risk that they have to model, then they'll have to ensure that that's the area where the risk is the most and how can they pick people processes and technology from vendors like us to operationalize it the right way such that they have the ability to reduce the risk for that organization. That's how the choice is tend to be made, so which is why the role of CISO is becoming more crucial than ever, because it's not only being tied to establishing trust to say that, yeah, I'm a good company, you can do business because all the real nice practices and security at the stations my CISO has helped us accomplish, but also have the second place is that if things go wrong, you know, your risk, which might be existential in nature to some organization is potentially reduced.

If you're being breached, you want to make sure that you reduce the dwell time and quickly know so that you can prepare a response. And a good CISO with good process people and tooling always has the edge or others. Yeah, there is a pretty good debate these days about whether or not the value of a undergraduate degree in cyber security or a master's degree in cyber security compares with multiple certifications from industry. What are your thoughts about?

I think if there's an opportunity presented to even not necessarily as a part of a job application, it is always good to have fundamentals whether it's through a college high school or whatever education to make sure you get your fundamentals right. Of course, the professional attestations and your work experience at the end of the day is probably going to be the most meaningful in terms of your ability to contribute towards securing someone's infrastructure or being a part of a security organization and providing value. But grounding in schooling and all of that gives you constructs in a way such that it allows you to be a better thinker and be better at your job. So work experience, while it might trump and dominate, I do feel that if there is a level of college education and things that you might have gone to, it adds as a bonus, but really your work experience probably is the most relevant part which dictates your applicability for that job at hand.

Yeah, if we're even semi-worth teaching critical thinking anywhere that I would agree with you. One thing that's obvious to me in our daily view of the landscape here is that the threat actors are much more adept adept at their craft than we are adept at defending and protecting and preventing. If you see that trend continuing and if so, what can we do to change that trajectory? Again, that's a good question because as long as the incentives are there, it's going to be a dominant problem of people trying to do things maliciously and whether it's new tool.

Mistakes are whatever other reasons because it can almost envision in my brain that the cyber security problem is probably nominally a next one in a year or more problem and the level of attacks and sophistication is going to continue to increase. I think then it comes down to the fact that it's not a question of if you're going to be breached or if there's going to be an incident, it's a question of when is it going to happen. And those who are astute practitioners do realize that you can put good elements in place to ensure that your hygiene is good and this is in some ways tied to the heart of upticks as a venture because we have a very fundamental premise in how we approach things which aligns with this topic at hand because good practitioners first need to have an understanding of what is it that they have to secure? Because the cliche is you can't secure what you're not aware of which means having excellent asset inventory and having an understanding of what your attack surface is and what your assets are super important.

And then the next step you want to do is make sure that your hygiene is good because it's only inevitable that something will go wrong because if your hygiene is good and you have the necessary detection things in place, you then have the ability to secure yourself better because if something goes wrong, you can reduce your dwell time or if you're seeing something going wrong in the wrong direction, you're able to remediate and block it. So the short answer to your first question is being prepared by one getting your basics right, by understanding what is it that you have and ensuring that your hygiene is good so that your probability due to a vulnerability or this contemplation is reduced. And finally having the tool to see if things are trending in the wrong direction are things which you can do to reduce the probability that something might go wrong. It's going to be bulletproof to answer is no.

So long winded way of admitting to the last part of your question, there's no easy way out because no matter what you do, there will be people who are sufficiently determined to find a way to break and breach because there's no such thing as bulletproof security. True, it seems, however, that we could get a little further forward in our ability to detect incoming during the reconnaissance phase of a threat factor and take some action before we get any further along the path. Do you see any kind of movement along those lines, including your own product? Yes, that's a big question because saying you have a good handle on your inventory and you have a good understanding of what your limit looks like and you've done the necessary prescriptive hygiene checks ensure that your systems have been patched and you've got the necessary auditing to ensure that, you know, silly things like password rotation encrypted desks all have been addressed.

It's only inevitable that things will go wrong to your point about threat vectors. There are two ways to start doing this better. One is based on, you know, there isn't a prescriptive standard, but the closest one which comes to it is what's called as the MITRE-based attack framework, which posits that, you know, across current known landscape of behavioral threats, threat actors go through a series of techniques and tactics. And if you have a good understanding of these tactics and techniques, when you start seeing patterns, you have the ability to discern that something is hitting a threshold based on the behavior model and potentially is a leading indicator of something bad.

And you want to address them. The other model is very interesting because it's mostly based on outlier activity detection to say that what I'm seeing is not a norm and it's a deviation from the norm. And so that you now start getting into statistical machine learning and advanced techniques to say what's normal and what's not. Now, the good news is that both in the evolution of the behavioral detection and the evolution of the outlier and anomalous activity detection, there is significant research and hopefully with the emergence of AI, when it's mostly being applied today to the realm of generative AI, applying it to outlier detection probably becomes a next key technology phase, which allows us to do further automation to detect the threats that you just outlined earlier about people trying to do things a certain way and, you know, how do you tear off the vectors and try to catch them?

I think learning techniques are going to be instrumental, but training these systems first and such that they can start detecting using sophisticated machine learning is where the future of security is going to be. The usual thing of antivirus and training based on malware samples, many organizations I don't want to say are perfected, but those are based on pattern matches and on that. But when it comes to behavioral modeling and outlier detection, there is a lot more training to be done, and that research will hopefully come to the front and make a difference overall. Certainly should, and that's a great way to end our session here, Ganesh.

We're all hopeful that there were continuing to move in the right direction here, and we want to change that relationship dynamic between the attacker and the defender so that it's in our favor for a change. I think we've just talked about some ways to do that. So I appreciate you taking the time and sharing your vision, and I wish you and your company the best of luck here, and I hope that we can revisit this in a few months and see what's happening in between. Thank you, Steve.

I most certainly appreciate the opportunity to be on your podcast. You're welcome, and it's up-ticks with why. UPTYC is. That's absolutely right.

It has started off with uptime, availability, and analytics as applied to the realm of security and hence the name, because that's the domain you could register. Alright, so we all know where to go. Thank you to your audience for spending time with us again today. Until next time, this is Steve King, you're host, signing off.

Thank you for joining us for another episode of Cybersecurity Insights. You can connect with us on LinkedIn or Facebook or send us an email at social at cybered.io. For more information about the podcast, visit cybered.io or slash podcast. Until next week, stay safe and secure, and we'll see you on the next episode of Cybersecurity Insights.

Thank you for joining us for Cybersecurity Insights.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on April 22, 2024.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!