Identity Protection Beyond Borders –Disrupting Shadow Access Across the Cloud - Shinesa Cambric
Transcript
hi everyone thank you for joining me in the CTO advisor seminar today in this session identity protection Beyond borders disrupting Shadow access across the cloud we'll talk about the changing landscape of identity and the processes and protections you need to put in place to build an identity and Dev strategy that goes beyond looking at employee identities but assesses your entire identity ecosystem for what may be lurking in the shadows so before we jump into it just to introduce myself my name is shanisa cambrick and I'm
a principal product manager with Microsoft I've been in the I.T industry for over 18 years and held positions from application development application security governance risk and compliance and now lead a product management team that's focused on building features to protect organizations from emerging digital identity threats so today's conversation is near and dear to my heart and we'll go ahead and jump into it so as I think about identity Beyond borders and thinking about identity ecosystem for me this really speaks to a digital identity supply chain
and as leaders in technology I think we all recognize that identity is the Cornerstone to a strong Tech program but understanding and securing digital identity is really more relevant than ever if you think about migrations to Cloud environments and digital transformation projects and it's not only relevant from a protection standpoint but also from an enablement standpoint you necessarily need digital identity to adopt cloud services right and when I think about what goes into an identity supply chain it includes a few different things one being your
infrastructure and what I mean here is your identity providers for example are where are the where's the employee identity information housed for your organization and how is that correlated and how does how is that integrated and then speaking of integration thinking about things like apis so apis themselves as an identity but then where do those apis connect out to or who's using those apis to connect in those are all sources of identities that belong within your digital identity supply chain mapping in addition to that thinking
about social sign-ins your business to business relationships things like partners and suppliers and then even your devices devices themselves have some type of identity Associated to them so all of these make up your digital identity supply chain um Everything You Spin up within a cloud environment has some sort of identity Associated to it and those should be part of the architecture and blueprint that you keep of digital identities for your organization there was an identity defined the security Alliance survey in 2022 that said that 98
of organizations saw an increase in identities within their organizations and if you think about the adoption of cloud services and migration to cloud services and you know adoptions of things like SAS necessarily there's going to be an increase of those identities going along with thinking about cloud is primarily API based so they're alone you're going to see some increase of new types of identities for an organization in addition to those new types of identities you're going to see a growth of permissions and access and this
is going to vary by cloud provider and cloud service there's uniqueness across all of these and if those are not well understood then they can lead to some levels of hidden access and permissions within an organization which leads us to the concept of some evolving risks within an organization and as we talk about evolving risk taking a step back of thinking about identities themselves as evolving in the past we thought of identity as a name or a number or a badge that was Associated to an
employee identity but now going to New Concepts such as Biometrics devices Behavior heuristics identity of things all of these make up the identities that can be within an organization and as the types of identities are evolving and increasing companies really are struggling to keep Pace with how do you protect those types of identities going back to Identity defined security Alliance they had a survey that said that only 26 percent of organizations felt that they were that they could detect risks or that they were comfortable protecting
contractor and supplier accounts and around 30 percent of those um the same way when it came to machine and iot devices so there's this mismatch right of these identities and identity types that are growing within an organization but the way that we're handling and protecting those identities is not keeping pace and so that's leaving a risk gap for organizations foreign and going beyond that if we take a step back of looking at that identity supply chain and looking at beyond our own organizations but our connected
Partners we have to think about how are they connecting these new types of identities and where could there be gaps that lead attackers to leverage those gaps to get into our organizations and vice versa so you really need to consider how you protect from the inside out from the outside end and then Connections in between organizations with these new types of evolving identities when we think about the attacks that are happening it's not just to the organization in many cases but it could be through the
organization so attackers have begun to leverage what we call Trust relationships so those partner relationships with other companies that you trust other service providers that you may trust that are integrated within your organization and they're leveraging those connectivity points to hop between organizations to get to their intended target okay um and then looking Beyond uh just thinking about you know large organizations thinking about small organizations and how they may be dealing with some of this we're seeing that there's some stats that say that 78 70
of small businesses are completely unprepared for a Cyber attack and if you think about small businesses being the foundation of society right there's these connectivity points of maybe hopping from a small business into a large business or increasing attacks on small and medium-sized businesses to get to a large business then we have to take a step back and look at those identities and how we're protecting those across that that digital footprint right um Additionally you know seeing new types of attacks that are attacking identity infrastructure
um you know all of us are pretty much aware about the lapsis attacks that have happened um where there were high profile breaches that attacked the identity infrastructure themselves um you know platforms that may have been servicing employee or service provider information provisioning that information and attackers attacking that platform itself to get into an ecosystem and so then we have to really take a step back and talk about how do we prevent or detect these types of evolving risks and also protect evolving identities as well
all of this speaks to the need for organizations to evolve their risk assessment models to look at identity Supply chains and in addition to include extended types of identities along with that so not just your organization's employees but again looking at those partner identities looking at those apis looking at devices and other types of identities that exist within an organization so looking at the proliferation of identities which is almost a necessity with Cloud identities and talking about the your digital identity footprint this risk goes beyond
compromised employee accounts to include contractors suppliers guest accounts and even identity of things so devices Bots and apis and all of this is coming together to bring about this concept of Shadow access where there could be this level of unauthorized unregulated and invisible access that's putting an organization at risk because if you think about the sprawl of all of these identities and especially if you're in a multi-cloud environment how different those are how different the permissions could be across all of those Cloud providers unless you
have some type of tooling it's almost impossible to see end to end where some of these risks exist for example an AWS alone there's 13 000 permissions that provide access to over 12 000 cloud services that developers then combine to create data applications and then from there these developers take these services that along with automated identities get Pathways into your organization or your organization's data and then Thinking Beyond that as developers maybe putting credentials within a development repository how are those things being secured so um
so the problem gets complex if there's not a single way to think about or to assess where access lives what identities live within your organization um and what's the the hidden nature of things that they could be able to access so it's really important for us to understand the value of protecting your identity supply chain because attackers are going to go for the method of least resistance right so leveraging and weaponizing access essentially especially all of the you know going back to the thousands of permissions
that they exists within a cloud environment attackers are going to take that as the easiest way to exfiltrate data we see data breaches happening on a pretty regular basis and it's to the point where I think most of us don't even lift our heads when we start to hear about this in in the news right and some of this could likely be stopped if we take a step back and think about how do we protect these different types of identities from attackers in these scenarios and
I believe there's some common pitfalls that actually work in the attacker's favors when we look at cloud services and how those are being used one of the things that I think could be a pitfall for some organizations is not clearly understanding the cloud shared responsibility so what are the protections that your organization is responsible for when it comes to Identity and that identity landscape and footprint and what are the protections that the cloud provider is responsible for and delineating between those and making sure that you
have good mitigations in place where there may not be coverage from your cloud provider is really important what I've seen in the past is that there's some assumptions that because you're using a cloud service that means your identities are automatically protected but you really have to take that a step further to think about what what's the access that's being granted to these different identities and who's governing that right because that's in most cases that's not going to be the cloud service provider's responsibility that's going to
be the organization's responsibility and looking even beyond that some of the if you have a hybrid environment or a multi-cloud environment then it gets even more complex about who's managing what and where right there's particular nuances of hybrid environments and multi-cloud environments they have to be thoroughly assessed and vetted when you're thinking about protecting identities in your organization and failing to understand how all of this is integrated and architect architected is a good way for there to be hidden gaps that attackers can take advantage of
to get into your organization so how do we get in front of all of these risks that are being presented as a result of the proliferation of identities in Access across environments when I when I think about the solution here or a path forward there's two sayings that come to mind that my grandma used to say and one is that you are The Company You Keep which to me speaks to visibility and behavior and knowing your partner systems and then the other is don't accept wooden
nickels which speaks to verification and knowing which identities actually exist within your environment so thinking about the you are The Company You Keep in the visibility portion of this uh knowing your connected Partners it may be a bit difficult but understanding you may be connected to one partner who's connected to another partner and essentially your security posture is only as good as their security posture because in reality what we've seen is attackers taking advantage of those trust relationship relationships to migrate into another organization and then
get to their ultimate attack Target right so if your partners have very poor secure security posture then there's a likelihood that attackers are going to use that as an angle to get in okay so again knowing who your connected partners are knowing their stance on security knowing their stance on protecting identities knowing which of their identities are connected into your organization is very important right and then The Next Step Beyond that is verifying the identities within your environment which identities exist do they need to be
there do they need to have the access that's assigned and not only looking at a single point for those identities but looking end to end across your entire organization and create across your entire digital footprint of what that identity has access to to make sure that there's not toxic combinations that could be leveraged against your organization so both of these things are important both the visibility aspect and the verification aspect when it comes to Identity so going a bit further in addressing identity risk for me
there's two major categories of what you want to do one is identity threat modeling and then the second is visibility or creating some visibility and governance within your organization and if we take a step back to the identity threat modeling for me there's a saying that I I like to mention a lot is that attackers sometimes go to you they go or they may be going through you right so they may be trying to get to your organization itself and you know take advantage of data
that you have or perform malicious activities against your organization or they could be using your organization as a stepping stone to get into another organization and so you have to take both of these scenarios into account and there's actually a third scenario that you really need to take into account as well which is Insider threats so all of these need to be part of identity threat modeling scenarios where you look at different types of identities what those identities have access to if they were used in
a malicious way what would be exposed where are their their gaps in your understanding of what those identities have access to and then with visibility and governance what you're trying to answer here is the end-to-end understanding of those identities and why they have certain types of access who can access what making sure that you have a comprehensive view of the different types of identities within your environment so going back to those apis those Bots and devices and non-traditional identities because those as well will be used
by attackers to get into your environment or to get into your partner's environment you want to make sure that from a visibility and governance standpoint that you're also reducing the footprint of what an identity has access to at a particular point in time so trying to leverage things like just in time and just enough access and abiding by zero trust methodologies you know for example segmenting parts of your environment so that when and if an attacker does get in that you've limited what's exposed to that
particular identity and a lot of this is is really hard on the surface it sounds simple like give visibility and governance to these identities and you know everything's going to be great but in reality if you think about how complex an environment can be having a single pane of glass is is extremely difficult in some cases close to Impossible without some level of tooling that's going to aggregate all of that together right you don't want to be trying to build those type of things from scratch
and you don't want to look at environments in isolation because you're going to miss things if you do that if you're just looking at one solution versus another versus another or one Cloud environment versus your on-prem you need to look at those things in totality and so you're going to need some type of solution um I have a little diagram up here that comes from a solution that's called stack identity and I really like this because it calls out the need to understand your data and
identity posture what would happen if that identity was compromised and what would it have access to what remediation Solutions exist or opportunities exist and what's a predictive score of a breach getting ready to occur to occur when it comes to your data there may be other solutions that are out there but I do really like this this diagram to show how visibility and governance can come together along with some of the threat modeling that needs to happen for your organization so now let's talk about the
components that go into building and identity and depth strategy we've talked about a few of these in the previous slides but to kind of tie these up together the first is knowing your environment and here talking about Partners plan and posture right so knowing your integrated partners because again the security posture of their environment really impacts the posture of your environment especially if going back to scenarios of trust abuse right and then having a plan to understand what's the organizational footprint what's the architecture and how
do you keep that updated as your environment changes and evolves and grows and keeping in mind that you don't want to just look at those human identities but you want to assess all identities or understand the footprint of all identities when it comes to that architecture and footprint the next piece of an identity in-depth strategy would be to as much as possible align with zero trust methodology here this is about segmentation separation and finding ways to minimize the impact when and if an attacker does get
into your environment right and so not just looking at this from the lens of your individual environment again you need to take a step back to knowing your your partners and how are they integrated within your environment and what are the ways that attackers could use that relationship things like apis and devices to get into your environment for example and then finally you want to think about setting controls so having policies and a regular Cadence to review those policies about what access can and can't be
assigned and how do you accomplish least privilege how do you understand new permissions that exist within your environment both those that come out of the box from a cloud service provider and even those that your organization may be creating from a custom standpoint and what does what do combinations of those types of access do and look like when it comes to risk and threat modeling for your organization right and a big portion of this is also making sure that again you're looking at those different types
of identities I know in my past experience when you think about service accounts and workload identities that it's really common to give carte blanche access to those types of identities and it's something that we need to try to avoid we need to get to least privilege and I know how painful that can be but I also know the ramifications of not doing that I'm you know seeing firsthand about companies and organizations being compromised because they allowed a service account or workload identity to have such broad
access which was then compromised because a developer may have put the credentials in a code repo that an attacker stand and use to get into your environment right so you want to try to cut off those angles or those avenues for attackers to get in by doing things such as least privilege across all identities so on the previous slide we talked about the importance of having a plan and I think most people have seen this quote by Mike Tyson that says everyone has a plan until
they get punched in the face and why I want to call this out here is having a plan is important but testing that plan is even more important right so having something on paper having policies on paper but not going through the actual exercise of testing and validating those policies and any controls that you have in place will certainly lead to some hidden scenarios or hidden gaps that an attacker is going to take advantage of right part of this is within your plan is making sure
that people know what they're responsible for people understand the end-to-end architecture of your environment and the the plan is a living document and that it adapts as your Cloud footprint changes and adapts right right so starting to bring some of this home here not only should we have a plan not only should we test that plan but we need to have some continuous risk evaluation so I've mentioned in a couple of slides that Azure environment changes as your as you adopt new Services as your organization
evolves you want to have a continuous update of processes of documents of architectures of Assessments of risk right so understanding where access is granted and why especially as your organization May spin up new SAS services or things that maybe um Shadow I.T Services getting a good handle of what those are because all of those data points are accessed into your organization as a whole right having a governance strategy to do some Automation and enforcement of remediation to continually update documents that reflect the architecture of your
organization are important and then making sure that you have ways to prevent as much as possible uh risk that that may be likely to occur so here it's having baselines of identity activity of identities within your organization and then later being able to detect anomalies against those baselines and I think here it's really important to have some Automation and strategic tooling we talked a few slides back about how identities are expanding how there's this proliferation of identities and access and so without some type of tooling
I think most organizations are going to have a hard time with accomplishing this so as a technology leader for your organization I'm going to give a couple of calls to action as part of this presentation now understanding the identity goes beyond the human identities that we need to look at apis we need to look at Bots we need to look at our partner systems because all of these make up our identity supply chain all of these impact our organization's security posture and architecture so with that
in mind the first call to action is to make sure that you go back and review your environment having documents that explain those connectivity points having documents that are clear on what cloud services that you have having documents or an understanding that makes it clear about your your relationship with cloud service providers and who's responsible for what and where there may be unmitigated risk within your organization the next is to go back and re-certify those identities that are already existing within your organization again here don't
just focus on the human identities you need to look at the devices you need to look at apis and API usage who's connecting in who's connecting out where why what all of those need to be answered looking at your workload identities and system users and the Privileges and access that all of these identities have within your environment right and Performing that on some regular Cadence the next is to Baseline the identity and access Baseline identity access and behaviors within your organization so standardizing the access that
gets assigned throughout your organization is important but understanding how that access May combine with different cloud services different on-prem services and where you may have some types of toxic combinations coming together to open unintended doors for those identities right and then understanding where there may be deviations from that Norm or those templates that you develop as new identities enter your environment as new permissions are granted as new permissions are being built right so understanding what are the doors that are being open as a result of
that and then last but not least focusing on both detection and prevention so here visibility of what's Happening across your the footprint of your organization across the footprint of your Cloud environment and digital identity supply chain is really important being able to detect anomalies when they're occurring so maybe there's some behavior that this identity is normally performing and all of a sudden it's doing something different being able to detect changes within a partner security posture or identities that exist within a partner that are connected with
yours all of these are going to be critical to making sure you close those risk gaps for your organization and to be truthful some of this is going to require tooling right with thinking about you know 12 000 plus permissions within one cloud service and you may have multiple cloud services you may have a hybrid environment with multiple cloud services this is going to get unwieldy pretty quick and so you'll need some type of tooling that's going to help you there with understanding both the identities
and the access that exists within your organization right so as I wrap up I want to leave you with a few links to some resources for each of the cloud providers they have some really good documentation on permissions um and with that with default permissions and understanding how you may be able to create custom permissions so I think as technology leaders it's important for us to understand what exists out there and open have open understanding of how this may impact the risk posture of our organization
um not just for us alone but then also our connected Partners right and then there's some open source tools that can help with doing some assessments of the roles within your your organization that are in use where there may be some over privileges where there may be some uh controls that may need to be enabled or enforced in certain areas and then I would love for individuals to take a look at the the book that I've recently released on cloud auditing best practices here it's a
Hands-On technical walkthrough of the three major Cloud providers and a couple of the more non-traditional Cloud providers understanding security controls including identity and access management and risk and tying those back to risk Frameworks and then doing Hands-On walkthroughs of assessing those controls and knowing exactly where those things live within a cloud so I think you'll find that as a valuable resource and would be happy for you to check that out or to ask me any questions about it so that's the end of my presentation thank
you so much for for sitting in for listening in if there's questions feel free to reach out to me on Twitter I'm Global secure one or reach out to me on LinkedIn I'm shanisa cambrick there and happy to take questions thank you as promised wasn't that a great session if this is your first session of the day and you're wondering what's next well you have options you can hang out in the chat room now and you can see there's a conversation going on in the chat
room in the session that you're in this will be open until the end of this hour and the top of the next hour the next session will start if you want to go into the breakout room there's a general chat session you leave here go into the lobby and then enter General's chat you can chat with your regular attendees I'll be floating between the two chat environments love your feedback if you have any questions please you can DM me within the platform or on Twitter at
CTO advisor enjoy the rest of the conference