Your Supply Chain Is Your New Attack Surface episode artwork

EPISODE · Feb 29, 2024

Your Supply Chain Is Your New Attack Surface

from Info Risk Today Podcast · host InfoRiskToday.com

Your supply chain is your new attack surface, according to Galit Lubetzky Sharon, the co-founder and CEO of Wing Security. She discusses Wing's solution - Secure SaaS Posture Management, or SSPM - that helps organizations ensure that all of their SaaS apps are safe and compliant.

Episode metadata supplied by the publisher feed · Published Feb 29, 2024

Embed this episode

NOW PLAYING

Your Supply Chain Is Your New Attack Surface

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Welcome to Cybersecurity Insights, the podcast with the CyberEd.io learning community. Our goal is to have been Cybersecurity practitioners, the latest and most relevant education and training to up seal and dive deeper into topics that matter in today's modern cybersecurity world. Good day, everyone. This is Steve King.

I'm the managing director here at CyberEd. And today we have the amazing pleasure of having Galit Lovesky-Sharon, who is the CEO at Wing Security back with us again for another podcast. We talked with Galit about, I don't know, six months ago or so. She's also the co-founder and chief technical officer for Wing Security and a retired colonel in the IDEA, and was part of the 8,200 unit there, which is the equivalent of our NSA.

Although I like to think they're doing more good than harm. After 20 years or so leading IDEA Cybersecurity team, she co-founded Wing Security with Noem Shah, who is IDEA's former CISO, to answer a growing need and that was securing the SaaS layer. So today we know that SaaS is in use everywhere and by everyone, which means it's completely decentralized and mostly ungoverned. And not only does it introduce, you know, one of the huge shadow IT problems that we've ever seen, but it also creates a brand new attack surface and opens everything up to organizational sensitive data.

And when you lay gender-to-day eye on top of that, you know, it's like all bets are off. So just as a data point, I read or report the other data, so only 6% of 1,600 companies internationally had implemented a use protocol for policy, for CHAT-CHAPT. So you've got 94% of companies around the world, according to this survey anyway, that are happily doing whatever they feel like doing on CHAT-CHAPT, and it's called LLM Poisoning. So a great to have you with us again, Billy.

Thank you so much. Thank you for having me. I'm very excited to be here again. Great.

Let's jump right into it. Why don't you, you know, why don't you give us an overview of the kind of state of the world in terms of current compliance processes and what some of the challenges and gaps are? Okay. So when we talk about compliance regulations, and I will focus about security regulations because this is a security podcast and we are a security company.

So security compliance has defined the baseline of procedures and checks and best practices that need to be done in order to protect sensitive information of the company. And this is, you know, the very basic bar that you need to fulfill in order to be responsible, in order to assure that you do the things that you are aware of the sensitivity of the information, and you do practical measures to protect it. And with modern organizations today, it's becoming more and more demanding to control the domain because, as you mentioned, the use of SAS applications is booming. Everyone is using SAS.

Data is stored on many different SAS applications. And to control and to know which applications are part of your attack surface, which applications are being used, what data is stored on these applications. That very basic step became very complicated, because it's not something that you can do manually easily. We see that companies, even small companies with, you know, hundreds of employees, even small number of hundreds of employees, they use hundreds of applications, six hundred applications, seven hundred applications.

So it is something that is almost impossible to do manually, not to mention the fact that these applications are changed on a weekly basis or on a monthly basis. We see from our statistics that medium-sized organizations with 500, 600 employees are using seven new applications each month. So we understand that it is data-based. And those applications tend to be SAS applications, right?

Yes, exactly. It is crazy. You're in the, you guys could be considering the category of SSPM, which stands for SAS Security Posture Management. Can you tell our audience the difference in your mind between SAS Security Posture Management and Data Security Posture Management, which is another category that I think kind of got here earlier than SAS Security.

And I think there's some confusion in the space about that. Sure. So when we talk about SSPM or SAS Security Posture Management, we talk about all the applications that are being used as a service by the employees or just as an app to app by the company. So all the access that these applications got to assets of the organization.

When we talk about data, the SPM, data can be stored from the infrastructure to the SAS. So you look at all the layers of the cloud. When we talk about SSPM, we talk about discovering all the applications that are being used, understanding the permissions and the access that they have, defining the risk that you have that you take by using these applications. Of course, on top of that, there is the data that is stored on these applications.

But we are focused on the higher level of the applications of the cloud usage. Yeah. So data Security Posture Management tends to be cloud-centric because everything kind of is these days. And SAS Security Posture Management is going to be application-centric.

The ability to see what's going on, and I know you talk a lot about compliance. And I assume that's one of your go-to markets here. This really has, in my mind, at least should be a necessity for any company that is trying to improve their ability to both detect and prevent threat from inbound server attacks, so that you can essentially observe all that's going on on your attack services. And that would be everything that says applications are touching, isn't that true?

It is absolutely true. And I like the word necessity. Since every company is using SAS applications today, it actually became a necessity to have a protection layer to that domain. So that layer must consist of detection, a pillar.

You have to discover, otherwise, how can you protect things that you don't know of. Then you have to assess, and you have to prioritize what is the risk that you take by using these applications. And then you have to control the access, you have to control the permissions that these applications have, the permissions that your users, your employees have to go to this application. And since this is something that is ongoing, and by the way, it is also something that is defined in the regulations, we refer to that as the essential security layer.

First of all, you have to discover, assess the risk and prioritize, and then control the access permissions of your employees to your major business applications. If you do that, later, we can move on to higher levels of security protection, such as alerting or abnormal behaviors and remediation and automation of those risks, but the very basic thing that you must make sure that you have, and it is also stated in the compliance regulations, is discovered. So you have to, these are all the vendors, this is actually your supply chain, right? All the applications that you use, this is your new attack surface.

And then you have to assess the vendor's assessment. And then you have to control the access, and these are the user access reviews that according to compliance regulations like Stock 2 and ISO 27001, you have to do frequently, at least four times a year, but if you can do it on a continuous basis, then you get a better security protection. Yeah, that's why I'm not a big fan of compliance driven initiatives, although it's easier to reach your audience, and I understand that. But at the end of the day, four times a year, you're going to cut it, you know, I mean, the market changes, I mean, the threat landscape changes so frequently, and bad guys, again, now enhanced with generative AIers, it's so easy to figure out how to get around most of the solutions that were created, you know, a year ago, that we have new threats all the time.

And, but they, in my mind, that most of them go to human errors, you know, and over permissive policies on access or, or configuration errors on containers and, and, and cloud access, those are human errors. And when I talk to companies and say, well, you know, you guys got to address that, and so well, we have no visibility into that, but, but your, your product and company provides that visibility is the first step. That's what we say discovery. That's what you're talking about, right?

You're identifying all the configuration errors or vulnerabilities that exist along that whole system chain, right, and you identify all of the over permission access to those containers or to the cloud or to identity access management systems or what have you, isn't that right? I mean, first I must agree that this is such a dynamic domain and ever changing. So just checking four times a year, what is the access that employees have to the different applications is a very limited visibility, I totally agree. And that's why you need a tool to help you discover and control, and that's exactly what we do.

So as you mentioned, we discover all the applications that are being used by, by the employees of the company. We discover not only the name, we will then let you know what this app is all about because otherwise, imagine a long list of applications, hundreds of them, we don't expect you to know everything, every app, and without the insight about what this app is all about, what is the threat history of the vendor, what are the permissions that this application asks for, how can you make a decision? So the discovery alone, without the information, the insight, the prioritization is not enough. So we discover the attack surface, we discover your list of the applications and vendors, and then we help you prioritize by providing risk scoring to each app.

So you don't have to manually go and check for the background of the vendor. You can easily just get the attributes of the vendor, what compliances they have, what is the size of the company, this is all calculated into risk scoring, then according to your policy, you can make a decision whether you allow using it or not. On top of that, now you can see who are the employees that are using this application, what permissions they provided to that application. If that application is connected to your sensitive assets, such as, I don't know, maybe your CRM, maybe your email account.

So now you can actually understand what is the risk, and you can take measures, you can decide if you want to remove those permissions, if you want to disconnect, if there's data that is stored on these applications, then you can see who that data is shared with and so on and so on. So it's too bad you can't take that an extra step and just shut down the application when you find that there are level 10 vulnerabilities, but of course we can, we can. You can if they give you permission to, yeah. Right, we have asked for the right permissions, the security team they need to customize it, but if they want to automate the process, they can do it easily and by that we have them save hundreds of hours because as you can see, this is a domain that is changing all the time.

So instead of on a daily basis going through lists of tasks, you should look for a solution that can automate the process and we do that. Yeah, that's interesting. When you tell me what percentage would you say that companies give you the authority to do that when you discover a critical vulnerable? Okay, so many of the tasks are the continuous ongoing minimizing the attack surface.

That's not right now a risk that is emerging, but a continuous control of the domain. So when you see applications that are overprivileged or applications that you provided access to and you're not using, we can automatically, according to policy, remove those permissions and I must tell you that almost 100% are automating these workshops because otherwise it's very tedious. Yeah. Yeah.

We'll get to an event. Something happened. Listen Steve, you're using an app that was breached today. These are the users that are using it.

This is what you have to do. This situation is usually taken care of manually, but we have automatic workflows to alert, to push an alert and we suggest we tell you what are the steps that you need to take in order to mitigate them. So the situation, so things that are ongoing and are very heavy on the security team are easily automated, things that are more, I would say rare and they usually need custom fit mitigation are usually taken care of manually. Right.

There is an emerging category that is known as automated security validation and it feels to me like you easily fit in that space. They've been that you can automate all of those responses as you just described and I'm pretty sure that that category will subsume both SAS and data security posture management at some point here going forward. It makes it easier for, I believe, this is just my view, makes it easier for your market prospects to understand what it is that you do and what the expected outcome is going to be. Those three words, automated security validation, to me, mean exactly what we've been talking about, that you validate that and this is on the basis of a lot of knowledge in your case about SAS applications and where the vulnerabilities are and all the rest of that.

So if you do that discovery and correction in an automated fashion, I don't know why any company on the planet wouldn't want your solution in place in their environment. Actually, I think that modern organizations can't afford to invest time in solutions that are not automated. There are so many tests, so much responsibility on the security team. They have to look after so many aspects without a solution that can actually remove the load of their day-to-day chores, I think it's almost impossible to integrate with solutions that will not prove value, not only in terms of security, but also in terms of the ongoing management that the security does demand.

And that's why from day one, we made sure that you can define and customize the automatic workflow that will help you as a team to solve your – to cover the remediation according to your policies. I must tell you that the last time that we talked, it was exactly after we published our free discovery capability. And since then, we were exposed to hundreds of companies, hundreds. So we now have data that is based on a very wide visibility.

And this is actually exciting because we can now provide insights that are based on crowd wisdom. You can see applications that I can tell you from someone's team, you're the only one using this app. I'm all hundreds of companies similar to your own. Or the way you use this app is not the regular or the common way to use this app and so on.

So there are more insights that are now embedded in a solution that I think that, looking forward, you need to see to look for solutions that will help you, you know, help you in the automatic way of removing load, but also will provide you insights and benchmarks where do you stand relative to other companies that are like your organization, your company, and what are the priorities that you should take to make sure that your status usage is secured and safe. Yeah, sure. Well, I'm glad you were exposed to hundreds of companies since the last time we talked. That means you're growing and doing well as well.

You should. I'm conscious of the time here. If can you give our audience a little flavor for what you plan to do next from a product point of view? Or is that too really for, you know, to reveal a product roadmap here in terms of future capabilities?

I think that the interesting thing that was investigating is the new pillar that we launched lately, which is a very lean security solution that should be available to everyone. We believe that SaaS is so common that there is a need for a security protection that should be available to every company and that essential layer consists of discovery, vendor assessment and user controlling of the user permissions or user access reviews. You can also use those procedures and generate evidence for the compliances there. But the major thing is that you get the essential security that keeps you responsible in working with many such applications.

So at least you know you can assess the risk and you can control the access of your employees to your major security and to do your major applications. And that's easy to one board. Everyone can use it. Try yourself.

But it is also affordable because we truly believe that especially in this type of economics is something that is something that should be adopted by everyone. So it is also very appealing. We provide it for $1,500 a year, so it's supposed to be next. Yeah, well that's truly amazing and you're absolutely right.

I mean nothing like easy to use and affordability is to the key selling components. And so how do you go to market? How do you get to a message app? Digital marketing, I think that the need is doing the job.

Companies need security, they want their employees to use applications because it pushes the business forward. Actually nowadays you cannot block or prevent your employees from using such applications because if you're an organization with business needs, then SAS is very helpful, it pushes the business forward. You just need to make sure that you have the right protection layer. Since this is also part of the task that you need to do as part of the compliance, we help customers save hundreds of hours by automating the process.

So I think that's the way. Yeah, well, it's great that you do. This is a great product that's one that everybody needs and at high time that people stop resisting the ability to detect the kinds of human errors that we see everywhere all the time. And I don't know what the resistance to that could possibly be.

You've made price, you've eliminated prices and objections. Oh, no, it's yours. Pardon me? No, no, there was no excuse.

There's no excuse. So I hope you sell millions of product here between now and the next time we talk. So congratulations. And thank you for taking time out today, go to revisit here.

And again, I'm very happy you guys are succeeding. You deserve every ounce of it. So thanks for being on the show again. Thank you for having me.

I enjoyed it very much. Great. I always enjoy talking with you. Our audience did too.

And until next time, this is Steve King signing up. Thank you for joining us for another episode of Cybersecurity Insights. You can connect with us on LinkedIn or Facebook or send us an email at social at cyberair.io. For more information about the podcast, visit cyberair.io or with slash podcast.

Until next week, stay safe and secure. And we'll see you on the next episode of Cybersecurity Insights.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on February 29, 2024.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!