Data Protection Companies are Security Companies?

13:22 · Watch on YouTube ↗

Transcript 2,212 words · about 15 min to read

Auto-generated captions from YouTube, not hand-corrected, so names and technical terms may be imperfect. The video is authoritative.

(click with echo) (electronic whoosh) >> So Vic and Jon, thanks for joining me for this sponsored conversation. But before we sit down, I got to ask you guys this question around this idea of data protection companies becoming security companies. Like I've, I've seen this trend happen where, you know where we just happened to meet at AWS Reinvented. I'm seeing this trend more and more on the show floor. What's the deal? Like, what you two worked for Cohesity, what, what's the what's the high level story?

>> Vic? Yeah, absolutely. So I think just the transition to this is that given today's attack, you know the cyber threat landscape that exists today, it just makes sense to bridge the gap, right? I think a lot of organizations, a lot of vendors are seeing that that bringing IT ops and SecOps a little closer together. Together for collaboration, just makes sense. You know, these teams typically have their own systems and they don't work well together, most of the times. They have their data, they have their data and then what ends up happening is that they have this like, like, like data but they don't know what to do with it or they're working on solving it apart from each other.

And that can cause a disconnect, right? And so this is an attempt to try to solve a problem that's going on today. Really is just to help with that business continuity, trying to bring those things together so that they can help fight things like ransomware, things like bad actors in the environment a little bit more efficiently, a little bit more seamlessly. >> So Jon, you've been out talking to customers constantly about the idea of data protection being and specifically, Cohesity products. We'll get into that in a little bit.

Cohesity products being kind of at the forefront of thinking about analytics and data and, and, and, and data protection. Vic hit on a point that kind of made me pause a bit. When we talk about data, we're not just talking about the actual data assets themselves, the the things we run our analytics against, we're also talking about the metadata around that. Are CISOs kind of in tune with the importance of metadata in, as well as the data assets themselves? >> Well, and I think what you're seeing now is that they're starting to be, and it's becoming more apparent that whether it's the regular data.

if you want to call it that, versus the metadata, that at the end of the day, security teams need to pay attention to it. And that's what we're definitely seeing. We're seeing even in the data protection stories and conversations that we're having with customers, CISOs are being brought into the conversation at the same time. While they may not necessarily be the primary target, upfront for some of these conversations, they're definitely being brought in to be a, just a, a another voice at the table, when it comes to these particular discussions.

Knowing full well what Vic mentioned that at the end of the day, these responses that we have to these attacks come from the data protection side of the equation. So knowing full well soup to nuts, so to speak, using bad cliches, that we need to pay attention to not only the network side of the equation but also down to whether or not we have good data to respond to these particular attacks. Just because we all know it is another cliche, it's not a question of if but it's a question of when your organization has to deal with one of these particular attacks.

>> So let's have a seat and we'll talk through Data Hawk. Sanjay Poonen, about a week or so, sent me a message like, see Keith, see how great Data Hawk is? And I'm like, ah, Sanjay, I don't know if I'm buying it. And I said, you know what, I'll be at Reinvent. How, how about I'll talk to a couple of your folks and they can kind of run down the Data Hawk story to, to me. So let's, let's have a seat and, and, and and give that a, give that a go.

And while you two are sitting down, I'll go ahead and introduce the program. Hi, you're watching the CT Advisor, on location here in Las Vegas. We just happened to be recording, doing AWS Reinvent. Not sponsored or anything by Reinvent, but you know, two of my industry friends wanted to talk about their product. Jon Hillebrand, technologist? >> Principal Technologist. That's the, that's the title du jour for this week. >> It is the title du jour, the goals from field CTOs, to Principal Technologist to, and Vic, Vic, what's your last name?

>> Last name is Camacho. Vic Camacho, also Principal Technologist. Same team as Jon, so pretty much a glorified storyteller. (men laughing) >> All right, so let's talk about storytelling. We, you know, we kind of, in the, in the pre-discussion we talked about the need of both the data protection team and the CISO team to collaborate, same set of challenges, same direction, same data. At the end of the day, if they suffer a ransomware attack, both teams are going to get called into the same room and they'll have to collaborate.

Data Hawk, first off, what is it? It's cool name... (Vic laughs) but what is it? >> Well, in a nutshell, Data Hawk is bringing a couple of things together, right? So there is the data classification part, piece of it to allow our customers and, and organizations out there to not just help understand where the data is at but also to tag the data so that you can move it and understand where your sensitive data is, right? This could be highly regulated data, things that fall under HIPAA or GDPR, right?

As they say, you really can't protect what you don't know you have, right? And there have been times where you walk in and you ask the, a simple question, do you know where all your sensitive data is at? I think 99% of the time is, yes, they do, but we when we run something against the environment, they find what I typically call breadcrumbs. Because over time things change. And so this helps you to understand where your data is at so that you can actually protect it in the right means.

That's, that's one piece of it. And Jon, you want to take the the other piece of it is just the other part of it, if you want to weigh on that. >> Yeah, sure. We get into a lot of like threat detection capabilities. And this is where you and I have had a discussion in the past about the extensibility of our platform. This is where we start working with a lot of platform partners. You've probably seen some of the announcements of things like using Big ID, using CrowdStrike, some of the big bigger names in the security side of the equation, to allow us to scan the data that we're residing on our particular platform.

So this allows us to determine what, you, as Vic was mentioning with classification, the idea of the blast radius of what the impact is going to be, if you get an attack. So understanding what you're being attacked by. What understanding then what the radius is and then ultimately the response with the Cohesity platform being the recovery engine for what sort of issues you end up getting, based off of either a ransomware attack or I'll even go one step further, the bad, the, you talk about bad actors, but there's also you know, data loss that happens innocuously, that you have in the environment.

How many times when we used to work as technologists did we have to worry about recovering, say an Excel document for somebody in accounting because they either lost the data or misplaced it or accidentally deleted it? >> Yeah, I have a copy of that same data, that data that's on my local drive. I have a, a copy of that on my OneDrive, as well. I don't need both copies, so I'll delete one copy. Modern technology is the same thing as deleting it on your G drive.

It's, it's the same data, duplicate data. And I bring up the duplicate data example for a very good reason. I, I'll talk about the parts of the Data Hawk story that I like and we'll get into, kind of challenging the messaging after that. So Jon, help me out here. In my mind, if I'm a CISO, I'm worried about active data protection on my, let's call 'em primary storage array. Cohesity has used cases where it can be secondary or primary storage.

Let's forget those definitions. >> Okay. >> And talk about, I have my three part storage array and I have my active scanning against that, isn't that where I want to catch it versus in backup? >> Well, I, we bring up an example of which when you're talking about say, active, active arrays, when you're trying to make a copy of that bit to another location so that you can use it in either a DR fashion or in a recovery fashion. Well, everybody talks about writing the data to that particular secondary source.

But what happens when a delete is issued? What happens when ransomware hits that active location? Well, it's going to write that same subset of data to that other copy. So you're going to effectively lose that particular copy to to a ransomware attack, or as we mentioned earlier, just an innocuous delete, issued by somebody who may or may not have needed the right to do so. >> So Vic, I think I'm starting to get this, this isn't about data protecting companies becoming the only security company that you're going to engage.

This is about security in depth. So you, you mentioned it earlier, kind of CIS the, the not working with the data protection team. >> Yeah, absolutely. It's really not about data protection or data management, taking over the space, right? In many cases, it's just not in the wheelhouse of any data management protection company. So it'd be better to have those integration pieces with folks, with organizations that already do that as part of their wheelhouse. And so it's really about bringing those systems together in collaboration so that somebody, somebody in the SecOps team can actually, kick off recoveries with, in our particular case, with through Cohesity, right?

And so that integration there is what is allowing a more seamless way of recovering, right? Getting back to business continuity SLAs. >> Yeah. And, and, and effectively closing the loop. You, you know, we talked, we used to talk a lot about DevOps and how it used to be a big loop, essentially, to make things happen. Well, in this particular case, not only do you have the active scanning going on, you can determine where the sources are coming from. You can determine what the particular blast radius of that particular attack may end up being.

Is it attacking sensitive data from a from a Data Hawk perspective, yes or no? Then you can determine ultimately what is the cleanest copy that I can put out here that may not, that may not not necessarily be impacted by ransomware but still be able to allow the business to continue to operate. >> Yeah, I wish I, I wish we had the light board here because if I, we had the light board, I draw kind of deck op, DevOps, dev, dev SecOps and this is starting to fall underneath that DevSecOps part of the discipline where we're looking at the entire landscape.

Because before when I just had my knock I could only do real time. There was no in, interaction or engagement with the data protection folks. >> And that doesn't necessarily mean that you don't do that part of it as well, right? This is just another layer for more protection, right? We're giving you the option to add some roadblocks or obstacles to threat actors, to bad code like ransomware. >> So guys, you have really helped me kind of crystallize what Sanjay pitched to me last week.

You know, it's Sanjay. You know, he's, he's, he's great on NB, he's, he's great on, you know Squawk Box and all of that. But I'm a technologist, I want to know how the technology works, how it's going to integrate into the operations. And I, and I now better understand that I appreciate you two coming on. com. com. Until the next CTO Advisor, follow me on the web @ctoadvisor or Twitter to DM me any questions I did not ask Vic or Jon.