Q1. Varonis recently introduced DatAdvantage Cloud. What exactly is it, and what issue is it designed to help organizations address?
The adoption of cloud and SaaS skyrocketed during COVID and accelerated the digital transformation in ways we haven't seen before.
This adoption led companies to move their most critical assets into cloud repositories and applications, opening a massive new attack surface for external threats and insiders. One of the biggest challenges that organizations face, is identifying sensitive data and visualizing who can access it across their cloud and SaaS repositories. Cloud applications add another dimension of risk for security teams, mainly due to CI/CD and the fact that DevOps and engineers have more power and many privileges. We see security teams struggling to track when SaaS applications, APIs, and services are used in an abnormal way.
Our security teams are seeing a new trend—threat actors exploiting cloud apps to gain initial access to unleash devastating ransomware attacks. Monitoring the interconnectivity between cloud applications and identifying when users are moving laterally from one application to another is critical to detect threats and malicious behaviors.
With DatAdvantage Cloud, our approach to protecting your critical data and fighting sophisticated insiders and APTs now extends into cloud repositories and SaaS apps. DatAdvantage Cloud addresses blind spots with data-centric security for your most important SaaS and cloud repositories like Salesforce, G-Drive, S3, and more.
DatAdvantage Cloud provides key capabilities to identify where your sensitive data is located, analyze cross-cloud permissions, and visualize who has access to what – making it possible to conduct fast cross-cloud investigations around user activities, admins, applications, and APIs covered by our detections on suspicious activities and policy violations.
DatAdvantage cloud allows our customers to know exactly how sensitive data is shared cross-cloud to reduce their cloud blast radius. You can also leverage DatAdvantage Cloud to uncover shadow identities, risky SaaS privileges, enforce cross-cloud policies, and monitor risky admin activities.
Q2. Varonis has noted how threat actors have increasingly begun sidestepping endpoints in carrying out attacks. What are the implications of the trend for enterprise defenders? What should they be doing to address the threat?
I've met with many security executives who were completely blindsided by solely trusting their perimeter security. Those solutions are indeed an important part of the organization's ecosystem. However, most of the APTs we encountered this year, including the Darkside and REvil groups, sidestepped endpoints by simply targeting servers, VDIs, gateways, or by just using compromised contractor's credentials without executing code. Those attacks went undetected by many organizations that based their detection strategy on endpoint security.
Today, where supply-chain attacks, insiders, and sophisticated APTs are so common, we see organizations re-thinking their strategy. They are monitoring their crown jewels – their critical data. Threat actors are always after your data and will look for data to tamper, exfiltrate, or encrypt. Those facts call defenders to change their mindset. They need to monitor data activity and focus more on high-value data. The main challenge here is when an APT begins to act like a sophisticated insider. In those cases, IOC-based detection provides no value. To shorten the time to respond to threats, organizations should not rely on known indicators but on behavior-based profiles that can automatically detect abnormal activities that signal a possible attack.
Q3. What events has Varonis planned for Black Hat USA 2021? What can your customers and other security professionals expect to hear from you at the event?
Varonis has several in-person and virtual events planned at Black Hat this year. We will have presentations, demos, trivia, games, and some swag at our in-person booth. DatAdvantage Cloud, which was just launched in May, will be available to demo for all who stop by our booth. Throughout the week, we'll be discussing some of the most important topics our customers are facing today.
Our lunch & learn on Wednesday, August 4 from 12:05 - 1:30 PM PT, hosted by Bob Kryzsik (Field CTO) and Kilian Englert (Technical Marketing Manager), will focus on Big Game Ransomware. On the virtual side, you can request meetings with security experts, schedule 1:1 demos, and stay tuned for some other fun activities we'll be announcing closer to the conference. Also, make sure to stop by our on-demand zone within our virtual booth to watch Varonis' Security Researcher Kody Kinzie as he demonstrates how hackers breach Wi-Fi networks and unleash ransomware from miles away.