Why AI Security is Actually a Data Security Problem

View Show Notes and Transcript

When an AI coding agent hallucinates a software package name, attackers can simply create malicious packages with that exact name, tricking the AI into downloading malware directly into your environment.  In this episode, Ashish sits down with David Gibson, SVP of Strategic Programs at Varonis, to explain why the rapid adoption of AI copilots and autonomous agents is fundamentally a data security crisis. We spoke about how connecting AI to your corporate environment before locking down your data creates massive, unintentional insider threats, allowing employees to instantly discover sensitive information they shouldn't see. We explore the Varonis Atlas framework, which provides a unified control plane to inventory AI systems, implement runtime guardrails, and execute automated red teaming. David also breaks down emerging threats like "hallucination squatting," untrusted agent inputs, and why managing identity groups without understanding data access is like holding a keyring without knowing what doors the keys unlock.  Questions asked:00:00 Introduction to AI Agents and Data Security02:00 David Gibson's Background in IT and Joining Varonis in 200603:30 The "State of Cybercrime" Podcast and the "AI of A" Segment05:00 The Through Line: How Legacy Data Auditing Gaps Amplify AI Risks07:30 Unintentional Insider Threats: Employees Finding Sensitive Data via AI10:00 Emerging Agentic Threats: Untrusted Inputs and SQL Injection on Steroids11:00 The Threat of "Hallucination Squatting" by Malicious Actors12:30 Copilot Enablement, Claude Cowork, and the Sprawl of Corporate AI Agents14:30 Shrinking Exposure: Inventorying AI and Enforcing Runtime Guardrails16:30 Why AI Agents Are Like "Well-Meaning Interns That Never Sleep"19:30 The Varonis Atlas Framework: Inventory, Red Teaming, and Runtime Controls24:00 Integrating Email Security to Stop Upstream IT Help Desk Impersonation29:30 The "Inside Out" Security Strategy: Starting at the Data Layer32:30 The Identity Gap: Holding a Keyring Without Knowing Which Doors They Unlock34:30 Moving Out of the "Denial Stage" of Shadow AI Adoption38:00 The "You Laugh, You Lose" Cybersecurity Joke Challenge

David Gibson: [00:00:00] You got a front row seat to dozens of breaches a day.

Ashish Rajan: What's the reality of the scale of agentic threats that are really happening versus which are just basically being amplified?

David Gibson: Let's create that package that's malicious, load it up, and then the AI coding agents are gonna download that. They're gonna download our malware.

David Gibson: I asked this query for my job, and I found this data. I shouldn't have seen this. And I worry about all the stuff that isn't reported. An agent is like a well-meaning intern that just never sleep. And if you've got thousands of these new well-meaning interns that never sleep, it's a different problem set to control them.

David Gibson: The attackers will send you a whole bunch of spam messages, and then they'll impersonate your IT help desk. Oh. Call you up and say, "Hey, you know what? We, we know you're getting all these horrible emails. We're really sorry. We're working on it. Can you just install this to help us diagnose it?" And then they're off to the races.

David Gibson: We don't know where the attackers are coming from, but we know where they're going, and it's the data. Train's left the station. Either you're gonna keep up or you're gonna get run over.

Ashish Rajan: If you [00:01:00] have been using Copilots or any other form of AI agents, you've probably tried addressing data security as a first way to do it, and perhaps you got it wrong.

Ashish Rajan: I had a great conversation with David Gipson, who is the SVP of Strategic Programs at Varonis, and we spoke about why AI security is fundamentally a data security problem, and how many Fortune 500 companies and enterprises are addressing that, and what's a good place to start specifically. We also spoke about the emerging risk of AI agents, and if you are a Copilot user, what are some of the things you...

Ashish Rajan: are obvious to many, but may not be obvious to you as things that are not default when you go for Microsoft Security. All that and a lot more in this episode with David Gibson from Varonis. As always, if you have been enjoying the episodes of the podcast for some time and have been coming back and sharing them with all your friends and colleagues, I really appreciate if you take a quick second to drop a follow subscribe button, whichever podcast platform you listen or watch our episodes on.

Ashish Rajan: We are on YouTube, LinkedIn, Apple, Spotify, and wherever you consume your podcast from. I hope you [00:02:00] enjoy this episode with David, and I'll talk to you soon. Peace. Hello, welcome to another episode of the podcast. I have David with me. Hey man, thanks for coming on the show.

David Gibson: Thank you for having me.

Ashish Rajan: I'm excited for this conversation, but just to set things off, could you share a bit about yourself and your professional background?

David Gibson: Sure. So my name's David Gibson. I, uh, am SVP of strategic programs at Varonis. Mm-hmm. I've been with Varonis since 2006. Before that I was at a company called Tripwire. Before that I was at a company called International Integrated Solutions, uh, where I was a security practitioner, network management practitioner and, uh, found my way into Tripwire on the kinda sales engineer side, which is how I entered Varonis, and I've had a lot of different roles at Varonis- Mm-hmm

David Gibson: over the years. But, uh, background in IT, I grew up with IT and, uh, data security. Well, you know, really network management- Mm ... then that led me into data security. Well, network security first, and then- Yeah ... data security. Um, so and then I've worn a lot of hats at Varonis, [00:03:00] uh, you know, since I started, and, uh, mostly I go and visit our, our enterprise customers, our strategic customers.

David Gibson: Um, I fly and I say things- Mm-hmm ... is the way I describe my role.

Ashish Rajan: And you have a podcast as well.

David Gibson: Yes, and thank you for reminding me. Yeah. Uh, we do a podcast called State of Cyber Crime- Mm-hmm ... which runs about every month or so, uh, and you can get information on that at varonis.com.

Ashish Rajan: I'm just curious as to, uh, how do you pick a story for State of Cyber Crime?

Ashish Rajan: 'Cause almost like every month there's a new story. We just had two just floated us like in a matter of weeks.

David Gibson: Yeah.

Ashish Rajan: What makes it to the State of Cyber Crime?

David Gibson: It... we really have way more than we can fit in a show. Mm-hmm. We try to keep the show to about 30 minutes or so, just because that seems to be a nice bite-sized chunk- Yeah

David Gibson: to get a CPE credit, right? And, uh, and it really, it's about, okay, what doesn't make the cut this week? And, y- you know, it's sometimes it's really hard to choose because there is so much going on out there. [00:04:00] Uh, we added a section probably about a year ago, which, uh, we have kind of fun sections of the show.

David Gibson: Yeah. Like, we have vulnerable vulnerabilities, right? We also start off every show with, "Is there any good news?" Mm. And, uh, 'cause it's it, you know, we, we wanna highlight where it's not just the doom and gloom.

Ashish Rajan: Yeah,

David Gibson: of course. Um, but we have a new section called AI of A, and that section just keeps getting longer and longer.

David Gibson: It's almost like we almost need a whole spin-off show just for the AI security stuff.

Ashish Rajan: Wow. So maybe just to bring it to the AI security piece, 'cause you've done IT, network security, data security. You've been with them for a while as well, specifically honing on talking to enterprise customers. How...

Ashish Rajan: What's the through line here for data security, AI security, and now going into agent security and stuff? Like, what's the through line here that you see has been ever-evolving? Mm-hmm. What, what stays the same and what has changed?

David Gibson: Yeah. Uh, it's actually a great question and, and a good lens to look at [00:05:00] today's problems through.

David Gibson: So w- really, the... what drew me to Varonis was its, uh, its frankly, its audit trail on the data. Um, it before Varonis, I, uh, working in security I knew how little people knew about what was happening with their data.

Ashish Rajan: Mm-hmm.

David Gibson: Um, you know, if, if it... just even on file shares, right? So who, who accessed what files, right?

David Gibson: Yeah. Who accessed this folder? Most people didn't have that level of auditing, and when you think about that from a, a security perspective... By the way, the, it was there with NetWare, but NT4 kinda broke it, you know? And so as soon as, uh, you know, Window- uh, you know, Microsoft and NT4 came out, auditing was like, yeah, you can kind of enable it, you know?

David Gibson: Yeah. But it's not... nobody really does. Yeah. And nobody knows what it means if you do. And, uh, n- not only did you have this lack of detective capability or really even, auditing capability, [00:06:00] but the permissions model was so complex. Again, NetWare, you'd be able to see all the data anybody could access.

David Gibson: Mm. But with NT4, that was gone. All you could see is all the groups that had access to a folder, and, "Oh, you wanna know who's in the groups? Well, here's AD. Good luck." Yeah. You know? And it's, and there's no way to go the reverse. So those were some of the things when I saw the Varonis demo, really what got me was the fact that there was an audit trail there that didn't require native auditing on Windows.

David Gibson: It was like, how are you getting that? And that, that's, uh, Jim O'Boyle who's, uh, who's our chairman now. He, he actually showed me the demo, and he, when he told me that you didn't need Windows auditing, this was, again, 2006. Wow. So, um, that was like, okay. I and I, I... that's what I spotted, from a technology perspective which made me wanna go work at Varonis.

David Gibson: Um, I didn't know to appreciate how well-run the company is, and, you know, there's so much. You know, we, we had... it was a very small company then, like 20 people. Yeah. You know, so there's a [00:07:00] lot that goes into it besides a great product- Yeah, yeah ... to actually grow a company. So I've been, I was very fortunate that way.

David Gibson: So the through line with data, it's similar because those basic controls have, and the lack of those controls, have come back to haunt us with AI. So most organizations, wherever they have data, these same problems exist. Mm. People have access to too much data. They're not necessarily sure what data's there.

Ashish Rajan: Yeah.

David Gibson: And they don't always have a good way to see what happened. And if you don't have a good audit trail, by the way, you don't have great detective controls either, right? If you don't know what normal access looks like- Yeah ... it's hard to see what unusual access looks like, uh, and hard to detect that. So I think one of the big things that people realize with AI is, hey, we gotta connect it to data.

David Gibson: And if we don't lock the data down, the chances that people will see something that they shouldn't see just grow i- in an unacceptable way, right? So [00:08:00] where before, without AI, somebody might have to go hunt for something-

Ashish Rajan: Mm ...

David Gibson: or search for something, now they fall over it. And I hear a lot of stories from customers where they're having, really good u- users like following process saying, "Hey, I asked this query for my job, and I found this data.

David Gibson: I shouldn't have seen this." And I worry about all the stuff that, isn't reported, right? Yeah. You've kind of got some unintentional insider threats. People are pulling the string, "Oh, tell me more." Yeah. "I didn't know. How much are they making? What was the..." You know, it's a, it's a I think that being able to lock down data or CISOs and the sec- security people that I'm, I talk to are really worried about connecting AI to data before they can lock the data down.

Ashish Rajan: Yeah.

David Gibson: But then also to really have the controls, uh, around not just understanding the AI systems that are out there, but what are they doing? [00:09:00] Mm-hmm. You know, if I do lock everything down, I'm still gonna need to understand what is happening- Yeah ... uh, at the prompt, at the agentic level. So, there are some basic controls deficiencies that are being focused on now with AI-

Ashish Rajan: Yeah

David Gibson: uh, that, uh, haven't been, uh, a- as much. So hope- hopefully that- Yeah, it,

Ashish Rajan: it does ...

David Gibson: and there, there's more.

Ashish Rajan: Go ahead. It, no, I, I think it definitely is a good segway into the next question that I had was about the whole AI security as a as a trade ecosystem. You guys have- Mm ... a research lab, uh, which Varonis security lab is there.

Ashish Rajan: What are, what, what's the reality of the, the scale of AI agentic, let's just say agentic threats that are really happening versus which are just basically being amplified? If you were to give a few examples of maybe perhaps what the lab has seen or what you've seen with customers to get some sense of how real is this today in terms of, you know, the, the gaps that exist between the, "Hey, [00:10:00] who can do what with the data?"

Ashish Rajan: versus the agent itself. What are you finding as, like, some things that have stood out for you as an example in the threats that came out?

David Gibson: So I think one of the, the big things, one of the, the big themes, uh, is the untrusted input. Mm-hmm. Um, w- when you've got, uh, you know, you want an, you want an agent to read your email.

David Gibson: You want, you know... You, you, it-- We want automation for some of these things, you know, to go read websites and things like that. Uh, what has struck me is the vulnerability that exists when you've got that untrusted input that's connected to an agent that has access to stuff. Uh, that, that is one of the themes that I think, you know, has come up a few times, right?

David Gibson: So it, uh, it's a little bit like a SQL injection- Mm ... but on steroids. Right. Right? So that, that is one theme that has struck for me. There are several of them. Another thing that I think has been really [00:11:00] interesting is some of the... You're familiar with, like, the typosquatting?

Ashish Rajan: Yeah.

David Gibson: Right. Some of what the attackers d- are doing with the hallucinationsquatting. Apparently- Oh ... a lot of the agentic coding agents will hallucinate package names. Like, reliably they're, they hallucinate ones that are similar to other package names, so, great, okay, let's create that package that's malicious, load it up, and then the AI coding agents are gonna download that.

David Gibson: They're gonna download our malware. Yeah. Right?

Ashish Rajan: Yeah.

David Gibson: And, um, I think one of the big frontiers that we have to worry about is how are we gonna have effective human in the loop? I, uh, I could talk about that for quite a bit, um- Yeah ... 'cause a, a lot of the AI coding agents get nerfed, and you have to do a lot of approvals as well.

David Gibson: Yeah. And then there's a balance there that I think we're facing.

Ashish Rajan: Yeah. Joe I'm happy to kinda double-click on that a little bit more as well, 'cause what are the kinds of agents that you see customers using? A good common example or a good starting point for a lot of people seem to be the Copilots.

Ashish Rajan: Mm-hmm. "Hey, let's [00:12:00] enable Copilot and see what the organization can do." I guess the engineering and business side looks at this Copilot enablement as a different thing.

David Gibson: Mm-hmm.

Ashish Rajan: Security looks at the same thing as like, "Oh, I don't know how, how I approach this." So in the example that you gave about the coding piece, how...

Ashish Rajan: Is that similar when it comes to Copilots when it's enabled in an organization? What do you end up seeing in the conversations you have?

David Gibson: Yeah, I think the, um, m- it's interesting because everybody started with Copilot, just the conversational.

Ashish Rajan: Yeah.

David Gibson: Uh, and then you've got the ability in Copilot now to create agents.

David Gibson: But as that's been happening, I think n- people have started to explore... I- it's rare that I see an organization only using Copilot now. Claude Cowork is certainly becoming popular. There are, y- a lot of folks are using Gemini, you know. Like, there's a there's a big push from a l- a, a lot of different vendors, obviously, and AI systems, and that there's a, there's kind of a distribution [00:13:00] in what are we gonna use.

David Gibson: And it's happening similarly from an agentic side. Mm-hmm. So I see that people are starting to create... A, a lot of companies have a lot of employees creating a whole lot of agents. Mm-hmm. And I guess I feel like n- in the Copilot world- People are starting to kind of say, "Okay, do-- There are a lot of these, do we need them all?"

David Gibson: I think that also, you know, you've got a lot of kind of employee develop-- like non-de-non-developer, uh, developers. There's kind of a need, I think, maybe for an applied AI team- Mm-hmm ... in many organizations coming up because people are creating the same agents. There's not necessarily a lot of grounding.

David Gibson: Mm. You know, people aren't necessarily-- A lot of people are learning about AI and what it really is good at and what maybe it isn't so good at-

Ashish Rajan: Yeah ...

David Gibson: or good at, more than 90% of the time. Mm. Like, what do we do with the other 10%?

Ashish Rajan: Yeah.

David Gibson: Um, so there's, there's, uh... I see w- just blanket statement, there's a [00:14:00] really big variance in the capabilities that people have.

David Gibson: Some shops are really way out there and, you know, like leading the way, and then a lot of folks are, you know, adverse. You know, "Hey, we can't connect this to data." Yeah. And then there are many people in between as well. '

Ashish Rajan: Cause I think, um, it ties back to what you were talking about, the coding example, where it's hallucinating the packages, and now we're also talking about Copilot.

Ashish Rajan: The common theme there seems to be increasing the exposure that an organization has. What do you see as, Obviously, we are at BlackHat, people are trying to rebuild or at least uplift an existing security program for what that would look like for AI security. And what's something that you have found is a good approach to shrink some of that exposure that people may be exposing themselves to with coding agents and Copilots of the world suddenly being available to everyone- Yeah

Ashish Rajan: everyone's building agents? To kind of the examples you said, what are some of the things you're seeing that customers are doing or how they're approaching that?

David Gibson: So in general, I-- when I'm talking to customers, usually they're [00:15:00] trying to, uh, understand what they can do from an inventory perspective to understand what they have, uh, and they're trying to not only look for issues with what they have, or vulnerabilities, or problems, or misconfigs but really it goes quickly to guardrails.

David Gibson: Mm-hmm. How do we monitor s- the coding agents, the runtime, the tool calls? Uh, how do we get some control there- Mm-hmm ... around what goes into and out of the models and, you know, the inputs and the outputs at the prompt or the agent and the tool calls and, uh, and how do we get a little bit more proactive for, you know, r- red teaming or testing you know, some of the systems together?

David Gibson: So these are some of the common themes that I see people, you know, trying to grapple with. Uh, you know, Claude Code is, is exploded, so how are we gonna monitor that? Mm. You know, and, uh, luckily Claude has, some really good hook capability that you can instrument.

Ashish Rajan: Yeah.

David Gibson: Um, they now for Claude Cowork have an, an API, right?

David Gibson: So you can get some visibility there and auditing. But, [00:16:00] um, the one gap that I, I don't see universally solved yet is that connection to the data that feels safe. So this is still kind of a source of friction. A lot of people, by the way I should add in, you know, monitoring the MCP servers, um, you know, controlling the MCP tool calls and the capabilities there, kind of hairpinning or bottlenecking or, you know, doing an API gateway or an MCP gateway as well.

Ashish Rajan: Yeah. Yeah.

David Gibson: Um, this is, uh, this is a big component of that. A lot of people are kind of like, "How do I get my arms around this? How do I see when there's a rogue MCP server tool call?" You know, the there's the, um- I guess o-o-one, one analogy, you know, is, is, uh, it's, it, i-i-an agent is like a, a well-meaning intern that just never sleeps, and if you've got thousands of these new well-meaning interns that never sleep it's like, it's a different problem set to control them.

Ashish Rajan: Do you find that do-- And I, I [00:17:00] appreciate the example as well on the the growing ecosystem as well of these highly motivated non maybe on Red Bull as well, I guess- ... uh, AI on agents, uh, right? I think do you find 'cause I guess you guys have an Atlas framework that you guys have released. What's that about, and how do you try to find people using it, and especially to what you said, it's a widespread of how the, how it's being used.

David Gibson: Mm-hmm.

Ashish Rajan: And I'm curious also, maybe before we talk about the Atlas thing, does data security play a role in every AI use case, most AI use cases, or is there a place where data security is not perhaps the main concern? Like, uh, is there any use case? I, I'm almost feeling because to what you said- Mm-hmm

Ashish Rajan: we started the conversation by saying, "Hey, dude, there was a clear line between data security and how AI can start consuming it." I'm also curious in terms of is there an anti-pattern here in terms of the data security is perhaps not-- could be an application which [00:18:00] is not using sensitive information.

Ashish Rajan: It's just public information- Mm-hmm ... public chat, whatever, right? I think obviously I'm giving an example here, but anything that comes to mind where data security is probably it's okay, I won't say not to use it. I guess what I'm trying to get to with this, with this is that, um, does a data security have to be considered for every AI adoption capability?

David Gibson: I would say that data security needs to be considered for every AI system that connects to a data source that you care about. And it's hard to think of an AI system that you'd care about or that would be worthwhile using if it didn't connect to a data store that you cared about too, right?

Ashish Rajan: Like- Yeah, like a help desk- Yeah

Ashish Rajan: would still require to access, "Hey, what is Ashish asking for? What's his- Mm-hmm ... Social Security number?" Or anything else that you'd have to verify, so it's just still connecting to a data

David Gibson: source. Yeah. It's very hard to imagine a, an AI system that did anything useful if it didn't [00:19:00] connect to some data store that mattered.

Ashish Rajan: Yeah. So- Unless it's just doing mathematic- I mean, I guess, I'm sure we could-

David Gibson: Well, if the data's all public and you're just kinda using it like a public search engine- Yeah ... then, uh, then it would be more like, okay, well, what else can it connect to, right? Mm-hmm. Like, is it, is it a read-only? You know, does it have any power, right?

David Gibson: 'Cause as soon as it has a computer-

Ashish Rajan: Yeah ...

David Gibson: right, then it's a different thing, right,

Ashish Rajan: as well. Yeah, then you're talking to identity and everything else as well.

David Gibson: Yeah.

Ashish Rajan: Which kinda leads me to the Atlas, uh, framework that you guys- Mm-hmm ... have as well. A, what is it, and how do you see customers using it as well?

David Gibson: Sure. Um, so w- you, I guess the story of how we got here is, uh, we, you know, we, we've had a data security platform for a long time. We focused on making sure we understand what the data is. We lock it down, and we monitor the heck out of it. Mm-hmm. Now, that's, that's what Varonis has been doing.

David Gibson: W- you know, a few years ago, there was a new way to get to data Copilot, right? We started, so we added support for Copilot to kinda map where do we have [00:20:00] permissions gaps or, you know, links, like overshared data that, you know, Copilot's likely to, to get to now, you know? Yeah. And so people can unintentionally get to data, uh, or intentionally for that matter.

David Gibson: Then also monitor what data they were touching through Copilot.

David Gibson: And we then added that functionality for ChatGPT Enterprise, because that started coming up, and Salesforce Agentforce. And meanwhile, AI exploded.

Ashish Rajan: Mm-hmm.

David Gibson: And people were developing their own RAG systems, you know, a lot of different, uh, purpose-built AI systems.

David Gibson: Agentic started to happen. People started using Claude, people started using Cursor, people, you know, y- you name it, it just exploded. And so we announced Atlas, which gives us r- really support for all of the AI systems. And I, and I say all because it's a cat and mouse thing. You know, it- if I... There's new stuff coming out every day.

David Gibson: Yeah. And, but we're also agentically racing to keep up with all the new stuff. Yeah. And when I say support it, what that means to, to us is to inventory each of these [00:21:00] systems, map the risks, both through scanning as well as automated red teaming. Put runtime guardrails in place for the tool calls, for the, you know, the prompts.

David Gibson: Multimodal, right? So not just text, but images. Mm-hmm. Being able to, to quarantine the MCP servers, control the tool calls there. But really anything at runtime, controlling the ins and the outs. Uh, and then also, uh, automating a lot of the compliance requirements that are starting to become burdensome, as well as third-party risk.

David Gibson: And I guess one of the, one of the cool things about Atlas is if anybody has looked at any of these of the AI solutions that are out there, usually, like there's, you know, there are a lot of AI gateways, right? Uh, there's some red teaming components. There's a lot of posture stuff. But having a solution that has all of these components together, really, people's eyes light up when- Mm

David Gibson: we show it to them. Because it's like, "Hey, I hadn't thought about that." You know, if I, if I can make [00:22:00] pen testing as part of my CID, CICD pipeline, right? Yeah. You know, it's like, okay, let's have a GitHub action, call the pen test whenever we make a change to the, the AI system that's being inventoried, and we know when it's changed.

David Gibson: Yeah. Okay, then let's apply a guardrail if we find a vulnerability, and then rete- rerun the pen test. And okay, let's also observe the activity, you know, 'cause we're monitoring runtime, and design a, a pen test specific for that AI system, right? Let's see if we can, you know, do something that's more surgical- Yeah

David Gibson: rather than kind of the sledgehammer, all the OWASP and the, the, the different MITRE, um, kind of tactics. So there's a lot to having all of those components in one solution. But really the, the, the other side of the coin is the data. And having one master control plane for both the data and the AI side, that's something that people are r- really when we s- [00:23:00] start to talk through that, they're like, "Yeah, I need that because I need...

David Gibson: With the AI security stuff, I'm gonna be able to see everything down to the MCP calls and the, and the tool calls from the MCP. But if I connect an MCP server to a database, Proness is also gonna see the database activity."

Ashish Rajan: Hmm.

David Gibson: Right? And you know, so it's like n- it, like there's this threshold once it passes a tool, once it passes an MCP, where you gotta see what happened on the data-

Ashish Rajan: Yeah

David Gibson: and also know what the potential exposure there is, right? Yeah. And so being able to have one solution that can kind of do end-to-end traceability there, that's really exciting.

Ashish Rajan: Do you find that and I, I'm pretty sure you're sharing the entire end-to-end as well because It, it is to- today, a lot of CISOs are being given a lot of information about AI security, how to approach it.

David Gibson: Mm-hmm.

Ashish Rajan: Some people are saying, "Hey, email is the right way to start." Some people are saying, "Browser is the right way to start." And I think what to... what you're almost asking people is to, hey, this is actually... all of them are important, [00:24:00] but maybe they all just need to talk to each other as well.

Ashish Rajan: What's the value of the email, the browser?

Ashish Rajan: Let's just say the email security to begin with. Yeah,

David Gibson: yeah.

Ashish Rajan: What, what role is that playing now in this AI world ecosystem that we're kind of moving into?

David Gibson: Yeah. So I, I... it's funny, you know, we got into email security because of, uh, the data security that we're doing. Oh. You know, we... Well, honestly, when I started at Varonis- Mm

David Gibson: we had one alert, and I called it our early resignation detection system. And the way that alert functioned is it would take, you know, your file utilization, how many files did you touch in a day or access in a day? We'd create your daily average, and if on a given day you exceeded your daily average by three times your standard deviation, that was an alert.

Ashish Rajan: Yeah.

David Gibson: And it really worked. And the, Uh, uh, uh, this was bef- in 2006 or so, so it was kind of before security was a thing. Yeah. It didn't really become a thing until Target.

Ashish Rajan: Yeah,

David Gibson: yeah. Um, and, really w- we started adding around 2013, [00:25:00] 2014, some more, uh, detailed alerting, some threshold-based, but then quickly got into machine learning.

David Gibson: And this, uh, you know, we, we now have hundreds of behavior-based threat models, right? Yeah. And when we went to SaaS, we became... we added a service where... what we call managed data detection response, where we can be responsible for looking at the alerts, tuning the alerts, and calling you if we think there's something that, that we need to know.

David Gibson: And so now we've got a front row seat to dozens of breaches a day.

Ashish Rajan: Yeah.

David Gibson: And I don't know, a couple years ago, m- m- you know, we looked at all the alerts, about seven out of 10 of the, the things that we caught were at the identity layer, two out of 10 at the network layer, and one out of 10 would make it to the data.

Ashish Rajan: Mm.

David Gibson: And, you know, or an insider threat, right? And we just asked ourselves, "Okay, where, where are all the attacks coming from?" Most of them were coming from compromised identity. Most of them through phishing.

Ashish Rajan: Yeah.

David Gibson: And we started looking, okay, well, what could help keep the attackers further from the data?

David Gibson: And we found a solution that we liked so much, it was like head and [00:26:00] shoulders above the others in terms of efficacy- Right ... that we bought the company, and- Oh, my ... you know, it's called Interceptor now. And that is, it You know, with some of the attacks that we're seeing today where, like, I mean, the one that's happening all the time is, uh, the attackers will send you a whole bunch of, like, spam messages, and then they'll impersonate your IT help desk through Teams.

David Gibson: Oh. Call you up and say, "Hey, you know what? We know you're getting all these horrible emails. We're really sorry. Um, we're working on it. Can you just install this to help us diagnose it?" And then they're off to the races.

Ashish Rajan: Oh.

David Gibson: Right? Um, so it, you ask how email, you know, is connected to AI security.

Ashish Rajan: Yeah.

David Gibson: It's certainly connected to data security, right?

David Gibson: Yeah, yeah. 'Cause this is one of the ways that attackers are getting in. I think email security also has a big role in AI security because of that untrusted input that I mentioned.

David Gibson: Right? So, we've seen a, a couple of vulnerabilities in Copilot, right? Like, you know, you, you ... If you can fool an AI-

David Gibson: You know, an LLM that's reading [00:27:00] your email into doing something or triggering an action, that's a big vulnerability surface. With all the stuff you have access to through that, you know, your, your, y- your Azure account, right? Or your, if you're in 365, right? If you've got access to Graph, you can do a lot of exfiltration there, for example.

David Gibson: So I think watching the inbound email for not just the traditional phishing but, you know, some of the AI phishing that's starting to, to be a thing.

Ashish Rajan: Yeah.

David Gibson: You know, I think that's a big role. And then also monitoring the email going out, right? Yeah. Because one of the vectors will be, well then, email it out, so the there's a bunch of different, I mean, email's a big data set, right?

Ashish Rajan: Yeah. And I, I'm glad you mentioned this, but a sidebar, and I'm sure- Yeah ... um, are there any Nigerian prince emails coming in this?

David Gibson: I got one earlier I was supposed to- Oh, did you? You know, yeah. He needed some more money, and so.

Ashish Rajan: Yeah. 'Cause I'm like I've... I almost miss them, if that makes s- I know it's a sidebar, but I'm just like-

David Gibson: Oh, the good old days.

Ashish Rajan: Yeah. I feel like that, that was, like, really interesting times when you used to get emails from a Nigerian prince asking for [00:28:00] money. Yeah. I have not seen that for a long time.

Ashish Rajan: Yeah. So when you say that now people are being spammed and going, as in IT help desk, I'm like, wow, that's more sophisticated than just a Nigerian prince trying to... Like, uh, to the point that everyone in our generation kinda knows about that, but somehow it doesn't exist anymore.

David Gibson: Yeah.

Ashish Rajan: Like, I mean, no, no offense to any Nigerian princes want to send us money.

Ashish Rajan: Please do. But for so, for the moment, um-

David Gibson: Maybe they cashed out. I don't know. You know?

Ashish Rajan: Yeah. Or maybe Bitcoins maybe these days. Now we have that option, too. To, that email security thing is an interesting one 'cause, Many people already have the Microsoft license. Mm-hmm. They have the Defenders, the E5, E7, whichever the license is.

David Gibson: Yep.

Ashish Rajan: What's the... I guess, what's the balance or what's the challenge to them using a Microsoft-provided Defender or DLP or any of that data security ecosystem that they have been creating versus using a third party? Like, where, where is the gap or the delta-

David Gibson: Mm-hmm ...

Ashish Rajan: that they don't get to see if they were to just go with the Microsoft option?

David Gibson: So I- most of the companies I talk to have multiple email solutions, right? So most of them [00:29:00] have a SEG, Security Email- Yeah ... Gateway, uh, and that does a lot of that upstream filtering. But then there's also kind of an on-delivery system as well. It's kind of a second layer. Right. Okay, let's do a deep analysis of, you know, the emails as they're coming in, and then remove anything that looks like it's harmful.

Ashish Rajan: Mm-hmm.

David Gibson: Um, so it it plays nicely with the Security Email Gateway solutions.

Ashish Rajan: Oh, right, and what about people who already have your EDR, MDM- Mm-hmm, mm-hmm ... the list goes on. 'Cause to your point about we were talking about AI security. We spoke about Atlas. We spoke about the inventory. We spoke about the end-to-end as to how it kind of travels through, traverses through.

Ashish Rajan: We have the email security component in there as well.

David Gibson: Mm-hmm. How does it all relate?

Ashish Rajan: Yeah, how does it all relate? Yeah. And what, what are people prioritizing, 'cause they already have... enterprises have that solution already.

David Gibson: O- well, the, the... almost everybody has a, uh, an endpoint security solution, right?

David Gibson: Yeah. Um, and almost everybody has a Security Email Gateway. U- unless you have Varonis, generally you don't have a, a data security [00:30:00] solution- Mm-hmm ... you know, something that's monitoring the data. Some pe- a lot of people have identity monitoring. I put our models up against, any identity monitoring solution, um, that we've just...

David Gibson: Because we started with the thing that ev- all the attackers are after, the data-

Ashish Rajan: Yeah ...

David Gibson: we got really good at e- I think, going outwards. If we had to do security over again and detection over again, we'd go inside out, not outside in. Oh. There's just too much signal at the perimeter that isn't meaningful.

David Gibson: Right? But if you're starting... we don't know where the attackers are coming from, but we know where they're going, and it's the data.

Ashish Rajan: Oh.

David Gibson: So because we started at the data, we had a little bit of an advantage there. We got... We re- really learned where clean signal could come from. Mm. So that's why our uh, you know, all the other mo- our data models are great, but our identity models are great.

David Gibson: Our, our, you know, we've got, uh, really we look at some key signal from the network and the, the email solution just fits right alongside that, right? Really if, if a cu- a customer has our email solution we [00:31:00] honestly it saves us some time because we're defending, you know, whereas, like without our email solution, they'd get to an, you know, they'd get an account, you know, and we'd stop them when they were Kerberoasting- Mm

David Gibson: or they were doing internal brute force, or they were starting to snoop around the data using machines that they didn't normally touch. That's when we'd stop them. Now, with Interceptor, we stop them before that happens- Mm-hmm ... so that's good. And then the AI activity is being folded into that service as well.

David Gibson: So really, having AI detection and response along with your data detection and response is, it just makes a lot of sense, right? Mm. Because it doesn't... If you're trying to protect data, if that's your job as a security practitioner, um, which really kind of is now- Yeah ... right? It doesn't matter whether the data is being accessed through AI or through, a, a web browser, like- Yeah

David Gibson: by a human. You have to protect the data, right? So being able to have a, a system that's monitoring the data regardless of the [00:32:00] channel that's being used to access the data seems to make sense to me.

Ashish Rajan: With the identity piece that you mentioned-

David Gibson: Mm-hmm ...

Ashish Rajan: a lot of people go down the path of baselining identity.

Ashish Rajan: A lot of people go down the path of, hey, I'm gonna look after the credentials, the permissioning, and everything else. Like- ... what, what's your approach towards identity security, and does it cater for the AI security identity challenges that people have been facing as well?

David Gibson: Yeah. It's, uh, it's an, it's a, it, it goes hand in hand.

David Gibson: I think- M- the, the way people unfortunately have kinda looked at identity is kind of a, a panacea- Mm-hmm ... in some cases. It's, okay, we'll manage the groups that the user's in, right? Whether that's an Okta group, right, or an AD group or an Entra group, and, you know, the- we'll have a group owner and they're gonna manage who's in their groups.

Ashish Rajan: Yeah.

David Gibson: But they don't tie the group back to the data. So what data does being in that group give you access to? You know, what, what do, what do you get access to by [00:33:00] being added to that group?

Ashish Rajan: Yeah.

David Gibson: And if you don't know that question, it's like reviewing the keys on a key ring without knowing what doors the keys unlock.

Ashish Rajan: Yeah.

David Gibson: And so we bridge that gap from the identity to the data.

David Gibson: And so we make those identity reviews a lot more meaningful, and we can flag when, hey, y- this person doesn't need to be in this group. Or this group, uh, has a lot of access.

Ashish Rajan: Yeah.

David Gibson: Right? So, really it's, um, I think it's, it's a level deeper than some of the privileged account management.

David Gibson: You know, privileged account management's like, hey, are you a DBA or not, right? Oh, yeah. Yeah. It's, I mean, it's certainly a little bit more granular but the, when you're talking about data authorization, it needs a level of granularity that doesn't exist if you're just looking at the identities alone.

Ashish Rajan: I'm glad you mentioned this also because, um, perhaps a lot of CISOs may be over-indexing on one part of AI security versus the other. I'm curious in terms of people who have not kind of [00:34:00] looked at that end-to-end thing and you mentioned the At- Atlas framework as well. Where should people start the AI security conversation of the uplifting of a security program?

Ashish Rajan: And let's just assume they may not, may or may not be aware of this customer. Mm-hmm. Um, so what is the right place to start, and what some of the stages of maturity that they can get through? Like, what, what makes sense? 'Cause we've spoke about so many things. We spoke about identity, email, data security as a whole, AI agent, coding agent, and we've already covered, like, such a breadth of topic.

Ashish Rajan: And I imagine CISOs out there are still going overwhelmed by a lot of the information that are being shared 'cause everyone would share that, hey, theirs is the best way path forward. That is the only thing to care about. I'm curious in terms of, uh, based on the frameworks that you guys have found and the s- research that you guys have done, what is a good place to start?

Ashish Rajan: And what is probably over-indexing that you're seeing a lot of people do at the moment, which should, should be almost like a difficult path to start? Is there like a easy that [00:35:00] come to mind?

David Gibson: Well, I guess it, um... I think most folks start with denial. Yeah. Um, and I'm seeing more and more people move out of that denial stage.

David Gibson: Right. Right? So the denial stage is, it's kind of a, a double entendre because they're denying access to AI, and they're denying that AI already exists- Mm ... in their organization, right? Like all the shadow AI and things like that, when really the train's left the station. Yeah. Either, either you're gonna keep up or you're gonna get run over, right?

David Gibson: It's, uh, you're gonna get on the train. It's, uh, the... And the alternatives aren't great, really. Mm. So I think the- Kind of common sense, but okay, if we're gonna get out of the denial stage, we're gonna need to m- get a handle on what we have and what we're adding- Yeah ... and and be a little bit more deliberate about adding.

David Gibson: Uh, really I'd say that the mission, it, when you think about it, is what data are we gonna connect AI [00:36:00] systems to?

Ashish Rajan: Mm-hmm.

David Gibson: Because, it- it's, I, I've seen it in our company, right? So okay, great, we got Claude MCPs for every- everything, right? Yeah, yeah, yeah. You know, it's like, I, I need it in Salesforce. I ne- you know, it's like, it's like I need it in Outlook.

David Gibson: I, I don't wanna schedule, I don't wanna read my email anymore- Yeah, yeah ... just to get to do it for me. You know, it's, uh, it's, uh, y- it's... Once you start to get a taste and you get rolling, then, uh, it really, it kind of, it's very hard to resist the temptation- Mm ... to connect it to data, I think. And, you know, and people are resisting that temptation, but I think the answer is to do it deliberately in a controlled way.

David Gibson: Yeah. And the checklist is, okay, do we have the right preventive controls around the data? Yeah. Do we have the right instrumentation around the data? Are we able to see the AI systems that connect to data? Yeah. Do we have a way to look at the preventive controls, the configurations, the vulnerabilities there, and do we have a way to m- monitor what's happening at the AI [00:37:00] level?

Ashish Rajan: Yeah.

David Gibson: A- and so, I know it sounds really simple, but it's, you just can't manage what you can't see.

Ashish Rajan: Mm.

David Gibson: Right? So if you're gonna close your eyes to it and deny it exists, then you're not managing anything. So we have to open our eyes, we have to instrument, and then I think if we can safely, if we can pr- provide approved systems...

David Gibson: I mean, it, we saw this with, like, Dropbox, right? Soon as people got a taste of file sync and share, they're like, "Yeah, I'm not doing the file share stuff anymore," right? So, you know, we had to g- make an approved, file sync and sy- file sync and share solution a- or else, you know, people just weren't gonna use your, your corporate stuff anymore.

David Gibson: So it's the same with AI. We need approved systems that function, that work, that approach the superpowers that you can get at home, right? Yeah,

Ashish Rajan: yeah.

David Gibson: And, uh, but that are also controlled and not gonna kill your organization.

Ashish Rajan: Yeah. Wow. And I love the approach also because it simplifies an action plan almost for people to work forward, so thank you for sharing that.

Ashish Rajan: Sure. That's most of the technical questions I had. The last [00:38:00] section is the you laugh, you lose, and I have a joke for you.

David Gibson: All

Ashish Rajan: right. My, my hope is, uh- I'm gonna

David Gibson: lose.

Ashish Rajan: Yeah. My hope is I, I... Well, I'll say the joke and you have five seconds to react. Hopefully you don't s- laugh. If you d- if you'd laugh, you lose.

Ashish Rajan: So

David Gibson: I'm, I'm s- not supposed to laugh for five seconds?

Ashish Rajan: Yeah, you're not supposed to laugh. Okay. All right. You know what's funny about data owners?

David Gibson: What?

Ashish Rajan: Nobody owns the data until you suggest deleting it

David Gibson: I don't know whether that's a laugh, but it's totally true. It's totally true.

Ashish Rajan: Unfortunately, that is the reality of all cybersecurity jokes. It is...

David Gibson: Yeah. No, it's, uh, it's kinda funny. It's, uh, it- we, you know, we, we, we... it's funny, you know, sometimes we, we would talk to customers, it's like, "Yeah, w- you know, we're...

David Gibson: We, we don't really store anything that matters. You know, we don't, we don't need data security. Sorry," you know? And then ransomware happens and all of our data's critical.

Ashish Rajan: Yeah. Actually, funny enough, this is, this is related to another joke that I had, which is, uh, backups are like umbrellas. You find out if they're working or not when they, when it starts raining.

Ashish Rajan: It's, it's like that one. I'm like, [00:39:00] yep, it's literally the, the... To what you just said. Yeah. I'm like, "Yeah, we have the backup." Yeah. Then it's like, "Holy shit, it's ri- raining. I- there's a hole I did not know." Exactly. Um, but thank you so much for laughing to my joke as well. Yeah, of course. Um, where can people find out about Atlas and the work you guys are doing at Varonis and connect with you as well?

David Gibson: Certainly. So, uh, www.varonis.com. You can go to our website, you can learn about Atlas, uh, you can learn about State of Cybercrime, you can learn about Interceptor, our data security platform, any of the products that we have. Uh, and there are plenty of ways to get in touch. If you go to our website, we'll probably be calling whether you fill out a form or not.

Ashish Rajan: No, thank you so much for sharing that. I'll put the links in the show notes as well. But thanks everyone for tuning in as well. See you next

David Gibson: time.

Ashish Rajan: Thank you for listening or watching this episode of Cloud Security Podcast. This was brought to you by techriot.io. If you are enjoying episodes on cloud security, you can find more episodes like these on cloudsecuritypodcast.tv, our website, or on social media platforms like YouTube, LinkedIn, and Apple, Spotify.

Ashish Rajan: In case you are interested in learning [00:40:00] about AI security as well, do check out our sister podcast called AI Security Podcast, which is available on YouTube, LinkedIn, Spotify, Apple as well, where we talk to other CISOs and practitioners about what's the latest in the world of AI security. Finally, if you are after a newsletter, it just gives you top news and insight from all the experts we talk to at Cloud Security Podcast.

Ashish Rajan: You can check that out on cloudsecuritynewsletter.com. I'll see you next episode.

Peace.

No items found.
More Videos