BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS...

41
BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Transcript of BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS...

Page 1: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

BRING YOUR OWN SERVICETHE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 2: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

ABOUT VARONIS

Founded in 2004, started operations in 2005

Over 1800 Customers

Over 4500 installations

Offices on 6 continents

Based on patented technology and a highly accurate

analytics engine, Varonis solutions give organizations

total visibility and control over their unstructured data,

ensuring that only the right users have access to the

right data at all times from all devices, all use is

monitored, and abuse is flagged.

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 3: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

BRING YOUR OWN DEVICE

Page 4: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

BRING YOUR OWN SERVICE

Page 5: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

EXAMPLE: CLOUD FILE SHARING EXPLOSION

Public cloud file sharing has exploded

As of November 2012, Dropbox claimed

to have 100,000,000 customers

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 6: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

WHY DO PEOPLE LOVE DROPBOX?

It’s easy!

You have a folder

You put stuff in it

It syncs

With all your devices

With the people you want to share with

Services like this make BYOD work

…but does BYOS work for business?

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 7: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 8: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Hey boss, can I use Dropbox?

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 9: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

No.

=(

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 10: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

VARONIS BYOS SURVEY RESULTS

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

of companies currently do not allow cloud-based file synchronization

of companies are satisfied with the controls that cloud-based file sync services have in place

of companies are not satisfied but are going ahead anyway

Page 11: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

ACCESS RIGHTS AND AUTHORIZATION

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Why not?

worried about maintaining correct access rights and authorization

Page 12: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

AUTHENTICATION

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Why not?

worried about authentication

Page 13: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

AUDITING & DATA LOSS

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Why not?

worried about data loss or auditing access activity

Page 14: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

FEARED CONSEQUENCES

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Downtime Loss of productivity

Compliance violations

Data theft

Page 15: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

SO, WILL YOU EVER ALLOW DROPBOX?

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

No

Yes

IT plans to allow cloud-based file sync

Page 16: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

TOO BAD! WE’RE USING THEM ANYWAY

1 in 5 employees

already use

Dropbox for work!

Source: Nasuni http://www6.nasuni.com/shadow-it-2012.html

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 17: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Doing nothing means we’ll lose control

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 18: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

WHAT IF…

…you could manage them in the same way you can manage internal resources?

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Yes

No

Page 19: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

LET’S HAVE OUR CAKE AND EAT IT, TOO

Give users what they want:

Simplicity

Accessibility

Mobile support

Give organizations what they need:

Control

Compliance

Security

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 20: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

How do we do this?

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 21: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

WHAT ARE THE OPTIONS?

Cloud

Internal

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 22: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

To the cloud!

Cloud

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 23: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

DO YOU HAVE AN EXISTING INFRASTRUCTURE?

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Existing infrastructure?

Easy!

No Yes

No Yes

Page 24: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

CONTROLS IN THE CLOUD

Data stored in the cloud is still subject to

the same risks as internal data

According to the Information

Commissioner’s Office (ICO), you’re still

responsible for your data even if it’s

stored in the cloud

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 25: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

DON’T FORGET TO PACK…

Backup & recovery processes (BCP/DR)

Authorization processes (entitlement

reviews, authorization workflows)

Retention & Disposition

Content inspection

Access auditing

Change management

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 26: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Extend your existing infrastructure

Internal

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 27: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

DO YOU HAVE AN EXISTING INFRASTRUCTURE?

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Existing infrastructure?

This is a whole different presentation

No Yes

Page 28: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

WHAT DO WE NEED?

We need to provide client for mobile devices and laptops

We need to provide file sync

We need to authenticate with Active Directory

We need to enforce existing permissions

We need to coexist with all the internal controls we

mentioned before (backup, classification, etc.)

Would be ideal to be able to have everything contained in

our own infrastructure

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 29: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

VARONIS DATANYWHERE

Provide cloud usability using only existing

infrastructure:

There’s a folder

You put stuff in it

It syncs…

With your existing storage (NAS, file

servers)

Using Active Directory credentials

Using your existing file system permissions

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 30: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

STEP 1: LOGIN

Login with your domain credentials (Active

Directory) and/or multi-factor authentication

Page 31: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

STEP 2: COLLABORATE

Your sync’d folders appear in explorer

Changes sync to your CIFS serversVARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 32: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

SEE SYNC SPEEDS AND NOTIFICATIONS

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 33: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

MOBILE APPS

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 34: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

RIGHT CLICK FOR INSTANT EXTRA-NET

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 35: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

SECURE COLLABORATION WITH 3RD PARTIES

Set permissions and expiration dates.

Share with partners, customers, vendors, and clients.VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 36: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Windows

Mac

Smart

Phone

Tablet

DatAnywhere Client

DN Edge server

Sync Manager

Sync Worker

Sync Worker

DN Edge server

Client authorization

DATANYWHERE ARCHITECTURE

Varonis Systems. Proprietary and confidential.

Windows File

Systems

NAS

MS Active Directory

Sync Manager

CIFSHTTPS

Page 37: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

One more thing…

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 38: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

INTEGRATES WITH DATA GOVERNANCE SUITE

Use DatAdvantage to manage permissions

Use DataPrivilege to automate authorization

DatAnywhere activity is recorded by DatAdvantage

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 39: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

SUMMARY

Cloud-style sharing and BYOD may be inevitable

Organizations must choose a direction before

the employees choose one for them

Organizations have a choice between moving

data to the cloud, or extending their existing

infrastructure to provide cloud-style capabilities

in-house

Whichever direction your organization chooses,

governance will be instrumental for secure

collaboration

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Page 40: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

VARONIS SOLUTIONS

GOVERNANCE

ACCESS

RETENTION

Ensure that only the right people has access to the right data at all times, access is monitored and abuse is flagged.

Use your existing file shares, on your own servers, to provide file synchronization, mobile access, and secure 3rd party sharing.

Intelligently automate data disposition, archiving and migration process using the intelligence of the Varonis Metadata Framework

Page 41: BRING YOUR OWN SERVICE THE EFFECTS OF CLOUD SERVICES ON COMPLIANCE AND DATA PROTECTION VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.

Thank you

VARONIS SYSTEMS. PROPRIETARY AND CONFIDENTIAL.