Video: Ransomware, Identity Threats, and the AI Boom: Resilience for M365 | Duration: 1812s | Summary: Ransomware, Identity Threats, and the AI Boom: Resilience for M365 | Chapters: Welcome and Introduction (34.91s), Identity as Perimeter (275.61502s), Cloud Backup Importance (452.405s), Security and Recovery (538.99005s), Data Recovery Challenges (793.79s), AI Risks and Challenges (986.72003s)
Transcript for "Ransomware, Identity Threats, and the AI Boom: Resilience for M365":
Hi. Welcome, everyone. My name is Eddie Waslowski, field CTO for Rubrik joined by, Andy Malone, Microsoft MVP and industry expert. And welcome to our session, where we're gonna be talking about ransomware, identity threats, and the AI boom, all around the resilience of, m three sixty five. Andy, thanks so much for, for joining us. Maybe we can start out if you could just maybe tell us a little bit about yourself and, and and get right into it. Absolutely. Nice to meet you, Eddie. Andy Malone, Microsoft MVP, as Eddie said. I'm based in The UK in Scotland. I've been an MVP now for twenty years and a Microsoft trainer for thirty years. I run a YouTube channel. I write novels and I speak a lot at conferences. And my MVP area of expertise is an identity and security, so great for this. Fantastic. Thanks so much. So we're gonna have some fun. We're gonna talk. This isn't gonna be kind of a product pitch, right? We're gonna get and talk a little bit about just kind of the reality of things that we're seeing at, at the Microsoft three sixty five level. For those of you who who don't know, Rubrik, has been supporting Microsoft three sixty five with our, technology stack for a number of years now, and have seen a number of trends. And speaking with folks like Andy gives us a kind of a good reality check to kinda make sure, okay, you know, what what are we talking about? How relevant is that? And and what is Andy really seeing as it relates to the kind of the threat landscape as it relates to, to three sixty five? So, you know, Andy, I guess I'll start off, you know, we've got into Microsoft when organizations initially kind of deployed Microsoft and not March, right? SharePoint servers on prem and file share servers and exchange servers and all these kinds of things. What we saw in the on prem world was a lot of kind of a data encryption types of types of attacks and seeing ways in which they can hold organizations hostage. But it's just not the case anymore really for for March. We've seen this kind of massive increase in attacks as it relates to, identity based attacks and and organizations more going towards this identity weaponization. Maybe you could talk a little bit about what you're seeing because our end, we see and and learn from Microsoft, these attacks are up 275% year over year, 600,000,000 identity based attacks per year. But kind of what are you seeing on on your end as it relates to the threat the threat landscape of March? Yeah. Absolutely. I totally agree with you. It's very interesting because the big selling point of moving to the cloud was that, hey, we don't need to do backups. Your data's safe, your data's secure, your data's protected. And it's interesting how, time has evolved on. But as you say, identity is the first port of call. And Microsoft Identity Solutions, I think one of the weaknesses is on premises and the fact that we still have active directory on premises and it's that link, if you will, that hackers are using. So if we can get on premises, find the weaknesses, and we can traverse that to the cloud. And of course, when you talk about ransomware, the cruel attack at the moment is not just simply ransomware ing target's active directory or their system, but also their backups as well, and that's particularly cruel. But also with identity, one of the big things that we're seeing at the moment is the token theft attacks. Yes? So token theft is becoming a real issue, and Microsoft did a pretty good job showing that and demonstrating that. But with the likes of phishing resistant credentials, they've just released token phishing resistant credentials for mobile devices that will sync with Apple, and we're hoping that that will hopefully improve security a little bit. Yeah. I mean, identity is so interesting these days. Right? Because, you know, you talk about, you know, building taller walls and wider moats and and trying to figure out ways in which to keep the the bad guys out. But identity really is kind of the the new perimeter. Right? So if you've got this idea that identity is collapsing or the provider itself is compromised, you're kind of locked out of your own estate or your own house. Right? Totally. Microsoft are rolling out conditional access policies. Everyone has to use phishing resistant credentials. And of course, one of the issues that we have with that is that we need some kind of a get out of jail free card for admins. So basically, have the idea is that you have these FIDO keys and it's a phishing resistant credential. So worst case scenario things go horribly wrong, you can store one of these in a safe somewhere and at least you can get back into your system. But the big recommendation right now is don't do security for all users, because if you do security for all users, it could encompass all admins and you could lock yourself out. So, in that respect, what Microsoft suggests is KISS keep it small, keep it simple, roll it out in waves, and that will give you more control. Yeah. You know, it's funny you talk about this whole idea of we're talking about like identity, and I think it's important to provide a distinction between recovery and resilience. Right? Because recovering is just, hey, you know, Andy and Eddie are users, and we wanna be able to get those back up and running. But if you think about, like, the resilience and, the trust fabric and all of the things that exist within something like Entra, And how that relates to active directory on prem, which most organizations have deployed some kind of hybrid type of scenario and situation between the communication. But thinking about like all of those things of, okay, I I've got conditional access policies. I have app registrations. I have enterprise applications. All of these things that are critical, not just restoring those, but understanding how they relate and being able to recover those in minutes as opposed to, you know, hours and weeks where we've seen this kind of process within Microsoft, like a 150 serial steps. And we've seen organizations take, you know, several weeks to be able to to kind of recover these. So we see these kind of organizations that are kind of thinking about their their blast radius and kind of what's happening. And, you know, within March, it's it's this kind of hybrid idea. Even though things are it's a SaaS application, we still have this kind of scenario of of being able to to kind of recover both. And I think that's a critical distinction when you talk about identity. It's not just recovery, but it's the resilience and all the critical applications and things that exist within identity. Oh, I mean, totally. Somebody was talking to me the other day, and they said to me, Andy, is there a way that I can back up my configuration, my Entra ID structure, and things like that? And, you know, there isn't. There's there's no way that you can do it natively with Microsoft. There are third party products, but that's the problem. We're starting to see gaps. Microsoft said you never needed to do backups, but now we do need to do backups. We need to back up our data. I mean the whole cloud flare I was in The US just in November there and we had a massive outage. There was a massive outage of so many different sites and it's a little embarrassing when you're up on stage. And if that was a mission critical environment, you are really in trouble. So you really do need a backup. A) Because if you are hit with ransomware, you would hope that an organization like Microsoft trusts. You trust them to get back up and running, but the fact is it is looking like we need to have these extra safeguards in place because the cloud vendors just don't have them. So things like extra backups or some third party identity backup solution or third party tool is going to be more and more important, I think. Yeah. I mean, you think about the concept of of like a minimally viable business and what do you need to to execute operations? It's not just, you know, within the Microsoft stack. All of the things that these apps are touching, you have in terms of Entra. Right? How do you log into specific applications? Right? How do you deal with, you know, time off requests? How do you deal with accounting? I mean, all of the things that that touch Entra or just all of these these applications is is quite robust and organizations, I think, need to be thinking about this broader approach and saying, well, I don't necessarily need to back up, you know, this three sixty five. I don't necessarily need to back up identity. Well, what's what's the strategy? Right. And we've seen organizations go through these attacks and unfortunately have to figure out ways in which to communicate, collaborate, be productive without these, which is, which is really, really crazy. I'm sorry to interrupt you. You're talking about identity there. Of course, we had Entra, and the big thing, of course, was, Hey, let's connect to a directory sync server on premises to active directory. And the big selling feature in the early days was convenience. The fact that you could have single sign on and that would give you single sign on not just to your on premises infrastructure, but all these other SaaS application platforms that are out there. And now suddenly Microsoft and many kind of third party watchers are looking at that going, Now hold on a minute. Do you want convenience or do you want security? And we now realize that that single sign on solution is potentially an Achilles' heel. So, you know, it's not necessarily a recommendation anymore. Well, Andy, you're making all of our product managers very happy hearing all of these things, because it helps validate what we're doing is actually is relevant and is helping customers from a broader perspective. So, so let's talk a little bit about kind of recovery, right, in kind of the traditional backup strategies and and these kinds of things. And, you know, if these attacks happened, if the playbook has been kind of restore from backup. And think we're kind of highlighting why that really doesn't, that doesn't work. Because, you know, thinking about a recovery process, trying to like make the distinction of what to recover and how long it's going to take. It's a pretty big challenge these days. Would you agree? Totally, totally. And one thing that has definitely emerged is the need for immutable backups, or air gapped backups as the trendy name is now. So, and in fact, I'm here in Norway this week and we were talking about the famous Maersk attack, the ransomware that hit Maersk, one of the biggest companies in the world. And thank goodness they had an off-site, active directory server on a boat somewhere in Africa, that they managed to restore their entire network. And so you need to have some kind of off-site air gap backup. It's an absolute necessity these days. Yeah. And you think about, you know, you want things to live outside of the trust boundary, right? Because if you have these kinds of attacks where social engineering is working and you're and you're gaining access at a at a credential level, you know, there's just there's no way to really prevent that. So we have to do that in order to to kind of bring these these things back. The thing is, humans are really super smart, you know, when you look at the actual technology, the technology is sound. And the whole thing about social engineering is that the bad guys lure you away from it or pull you aside from it so that their attack can go through. Know, things like token based attacks and SSL stripping attacks and things like that. The whole point is to divert you away, make a noise over here while you do the damage over here. It's a classic attack, you know. I often talk about in my sessions with with customers, I talk about how three sixty five is kind of this virtual attic or or virtual basement because you you have an aggregation of data that has been accumulated over decades. Right? And when you think about undergoing a task or or a process where you're saying, I want to back up all of this data is great. But then you think about like a recovery process and kind of what is the the minimally viable company? It's very difficult to make the distinction of what is the most critical thing from a business level process that we need to be up and running. Right? So this game now that we play is, well, how fast, how long does it take? How quickly can you get up and running? Right? And if you think about going from an attic that you've got all this stuff up there, I have to use attic because I'm in Texas. We don't get we unfortunately don't get basement. But, you know, think about this, this kind of strategy where, okay, well, I've gotta be able to bring the data back and we can't wait so long. So, you know, without this kind of without utilizing things like AI or other data classification technologies, figuring out a way in which to prioritize recovery becomes quite a big challenge too as well. Oh, totally. I think, and this is where, you know, companies need to do a risk analysis of what data they've got, where is it stored, what compliance requirements are required for that data as well. Things like retention policies absolutely critical. How long do they have to keep it? That's all got to come into it as well, interwoven into that backup strategy as well. Yeah, I mean, you think about if you have something where you have an outage or an instance of you know, compromising event, I think probably the I don't know what you see from from your perspective, but a lot of what I see is trying to figure out, well, what what it was impacted? Do we do we need to recover? How quickly is that gonna take? Do we need to consider a ransomware payment or do we have information that can help us prevent us from having to do that, that we have enough information around what was been impacted? I think a lot of what we're seeing is that the time that it takes to discover. Sure, sure. I mean, you definitely need some kind of EDR solution. I mean, the world has evolved and we've moved on so much that traditional security just doesn't cut it anymore. And this is what worries me about hybrid solutions. If you're still on premises, some of your data is still on premises, which is great, and you've got backup solutions there. But again, you need the off-site backup, you need that air gap to backup. And to be honest, this is one of the benefits of the cloud. Having a provider that you can work with, I think is a real win win. And so you see it in one side as being a potential nightmare, but again, on the flip side, if it's done right, it can be a great solution. Yeah. Alright. Let's pivot to the thing that everybody wants to talk about. AI AI Copilot this. We wanna be able to leverage leverage the technology, which is which is great. I know you've got a significant amount of expertise in in the Copilot arena and and AI. So let's talk a little bit about that. We're seeing a lot of organizations that are are rushing to do this. And we wanna we wanna get to to, you know, to this point. But where we're seeing this kind of issue with, at least on our side, from a Copilot deployment in in mass at an enterprise level, is we see we've got overexposed data. We've got permissions that are are broken. We don't necessarily know what data lives or what what the classification is of that data. So, like, what do you see around kind of the biggest risk of of an organization turning on Copilot very broadly within a within a Microsoft three sixty five environment? Well, I think, I mean, it's huge. I mean, Microsoft really pushed CoPilot and they spent $13,000,000,000 on it. So obviously they want a return on it. And many companies came in with CoPilot and there were a few test cases. Yeah, this is great. Let's go and switch it on. And then as you said, as soon as you switch it on, you realize, Woah, hold on a minute. CoPilot agents, they can literally see everything and anything. So for so many companies that didn't have data loss prevention policies, information protection, classification, labeling, all of that kind of stuff, It was just a complete nightmare. The problem is once you switch this stuff on, you've switched it on. You've opened Pandora's box. So you really need to do a full risk assessment. To be honest, I just don't feel that some of the tools that come with Microsoft are great. You need to be able to scan. You need to deploy this quickly. And the problem with it is we're treating this technology as if it was an on premises tool, and in that respect we're rolling it out like an on premises technology. We're going really, really slow department by department, and it's taking such a long time where we need a solution that we can roll this out fast because it's urgent. I think it's really urgent before AI does potential damage or you have the loss of critical information. Well, it's funny. This isn't the first time that Microsoft has talked about this or deployed this. Right? You and I have been around long enough to remember Delve. Right? And the strategy that Microsoft had around around Delve, is a similar kind of thing based on who you are, the information that you have access to, Dell would, excuse me, surface to you information that is relevant to you in your role. Yeah. But if you didn't have all of this figured out, organizations failed with Dell because they didn't have proper data governance set up and didn't have these kind of, you know, classifications. So, you know, we talked about AI being able to Copilot being able to access everything. Right? So are there compliance regulation challenges that you're seeing if if AI is accidentally modifying or moving sensitive data, financial records, and those kinds of things to actually, you know, inhibit or do damage to organizations from kind of an over permissive AI model? Oh, I mean, totally. I mean, I've heard in fact, I was in Denmark just recently, and I heard of a customer in Denmark, a medical provider, and people were just querying doing CoPilot queries, and they were basically pulling up records information that you really shouldn't be able to see at that particular level, you know. So that was a bit concerning. So problem was that there was no information protection in place. Now, is that a technical problem or is that a procedural problem? So again, you need to have a good security policy, good procedures, and the technical stuff will hopefully come and get it right later on. But it just goes to show that it can cause definite issues, you know? Yeah, it's one of the reasons we kind of looked at it from a product perspective to say, okay, need some AI resilience. We need to understand, we need to have a better strategy around how do we classify data within the platform, right? So how can I accelerate something like Purview to be able to not only tag the data, but be able to check against what users are doing? Because oftentimes we see organizations are enabling some manual or user based data classification that needs kind of a check and balance, as well as trying to extend this throughout the entire platform. Again, the attic analogy, you've got so much data. How do we go through this? But then also thinking about it from like an AI resilience perspective, if agents are doing something based on their access, have they done something that is not sanctioned by the organization? Is there a way to kind of undo and have a way in which to, you know, we have the term rewind. But I think all organizations would be thinking about this kind of undo button that exists within AI. I mean, the problem with agents, don't get me wrong, fantastic, but agents have just suddenly appeared from nowhere, and it's the buzzword of the week. And we have to kind of step back and look at these, you know, they're an Entra ID. So now not only do admins have to manage users, you now have to manage agents, and they need to know exactly what these agents are actually doing. And that is just there's nowhere in Microsoft three sixty five where you can get a definite report on that. Other things, you were talking about, you know, users, just simple things like permissions. You know, there's real weaknesses where as a user, I can't just go in and see a list of my files and get a list of who's accessed this file, who's this file shared with. There's no tool like that natively and it's just a weakness, and it's a weakness that needs to be addressed. Yeah. Yeah. I mean, that's, you know, again, that's kind of our unified approach of how we're thinking about things at an organizational level. So cyber resilience is identity, it's data, it's AI, it's all of the things that are within this ecosystem. And as a technology vendor, we have to be able to think about all of these trends and how organizations are deploying these because they're often relying on organizations like Rubrik and folks like yourself to be able to say, how how do I do this in a way that is responsible, that is scalable, and then I can actually realize, the the benefits of the of the technology. So it's it's definitely something that is more and more prevalent within our within our day to day. Okay. I think I've covered on a a bunch of stuff. We've gone through and and covered a lot of topics. Andy, I greatly appreciate your time, your perspective, your information. It helps validate things on our side that that we know that we're we're doing right, and and we enjoy partnering with folks like yourself to be able to help, kind of keep us keep us in line. So, Andy, I greatly appreciate, your time. Thanks so much.