EN
Red Team Tales and SaaS Strategies for Immutable Cloud Recovery
Immutability is just the beginning of achieving resilience by design. Securing static data isn't enough to actively retain control before, during, and after an incident. As organizations increasingly rely on SaaS and multi-cloud platforms, understanding who truly has control of your data—and how that control can be asserted, audited, and reclaimed—is vital to long-term resilience.
This session explores the following viewpoints:
- Strategic view – our SVP of Product will lay out emerging SaaS-backup architectures and policy controls.
- Adversarial view – Red Team Manager, will reconstruct a recent cloud-breach scenario to show exactly how attackers erase or encrypt backups and how immutable protection can break the kill-chain.
Speakers
Bart Binder | Red Team Manager and Cybersecurity Analyst, Keepit
Niels van Ingen | Senior VP of Business Development and Strategy, Keepit
View transcript
Hello everybody, thanks for attending. My name is Niels van Ingen with Keepit, which is a company focused on SaaS backup. I'm not spending my time all day long in the security space with 25,000 other vendors. Backup is a little bit more specific. One of the things we're seeing is we're building the walls higher and higher from a security perspective, the moats deeper, but things still happen. This is ultimately your ability to get to data, recover, is a key part of ultimately your security posture. So with me I have Bart. Bart, if you want to introduce yourself. Yes, hi, I'm Bart. I'm a Red Team Manager in Keepit. I started solo as a pentester. And I'm trying to involve offensive security in the wider fields and more departments in Keepit. And I'm also trying to... convert or translate deep technical data into executive strategies. So yeah, let's get into it. We have 20 minutes, so this will go pretty fast. So why we're here, so a couple of things that we want to accomplish, and again, it's not going to be a lot of diagrams. Some bigger trends we're seeing around this from a recovery perspective, what a customer is struggling with. But we'll start a little bit, you know, what is it from a vendor perspective, when we talk about hardening and making sure that the security is good, that we deliver a solution that's secure for our customers, what does it actually take? And so Bart is doing that on a daily basis, and so that's where we'll start. Yes, so first of all, like probably everybody knows here what the Red Team is and what the Blue Team is. But I would say that we as a Red Team, we are the bad guys working for good guys to protect the good guys from the bad guys. And so the Red Team, Blue Team is monitoring all the surroundings and the infrastructure and trying to catch us, the Red Team. So that's just how it is. Now, what's our job as a Red Team? Usually it's pretty boring because time testing is boring. It's just repeating the same stuff all over again. But what we are trying to achieve is to go wider and to bring the offensive security in every and each aspect of our products. And why we want to do that? We want to do that to protect our clients. That's the most important thing that why we are doing it. So there's a couple of things around this as well. So obviously, I think every vendor obviously does this internal, has this approach, internal pen testing. But the other thing we do, certainly from a Keepit perspective in our approach to making sure that the data is available, is also work with partners and also customers actually to take their approach to pen testing and making sure that, again, we pass their needs ultimately and making sure that continuously we bring that into our product. We bring that into our program in everything that we do. In the world we live in, with data going to lots of places that we don't intend it to be, and AI is actually making that worse right now, this is becoming more and more important. So getting the customer involved as part of your security posture becomes a really important thing. Yes, but also to collaborate between the departments inside the company, not only with the clients, but inside the company. And this is super important. Super important for offensive and defensive security to work with close collaboration with operations, engineers, internal IT and so on. We want to be or we are involved in very early stages of designing the product because we can catch more at the very beginning of the production process. Yes, so your core architecture is obviously key in all this. And there's just so many stories around this, right? If you get it wrong early, it feeds all the way through. But this is also where the threats are going, right? So it's not about the immediate impact. Sometimes it's really about seeding and then using the opportunities down the line for different purposes. And so as security teams and red teams, we have to, and as vendors, we have to think about this completely different ongoing, based on how just the market is coming, and very much focusing on the problems that are evolving rather than just the now. And I think that's a big challenge in the security space because, as you can see here, and we see the same thing at RSA, there's 25,000 vendors and there's so much noise, but it's all very much focused on the now. Well, what are we solving for two, three years from now? We need to know that if we get the architecture right for our customers, you know, building that today. Yes, so let's move to... Yeah. You want to tell a little bit story here about... How some of this stuff is being used. Yes, I would like to move to Italy for a moment. Probably our CISO would be very happy to... For our company to be there. But this is going to be only a virtual tour. So we are in Italy in the house of Giorgio Sarmani, the guy who makes suits, basically. You're not wearing one? I'm not. You have to imagine that. It's February this year. And his assistant receives a call from chief of staff from the Italian Ministry of Defense. And so what's happening is that the Minister of Defense, this guy in the picture there, he would like to speak to Giorgio about a wire transfer, about actually a ransom. It's a very delicate thing. So the assistants, they connect them through the phone. And Giorgio talks to actually... I forgot his name. I'm sorry. This guy there. The Ministry of Defense talks personally to Giorgio. And he asked him to wire transfer a ransom for two journalists that are in Italy. So they are being captivated in the Middle East. And why they ask? It's because they don't want the world to see that the ROM is actually sponsoring terrorism. So they have to do it very, very... It has to be hidden. Then Giorgio is promised to get his money back in 48 hours. And he gets his money back in 48 hours from the Italian national bank. What really happened... I'm sorry. It's just more than six people received the tycoons, received those calls this day. Those day. That day. Sorry. My English is not perfect. And what really happened is the bad actors, probably from Eastern Europe, they deepfaked the voice of the Prime Minister... Oh, sorry. The Minister of Defense. And that was not him calling. It was the hackers, basically the scammers. And out of the six persons, the six tycoons, which involves Pirelli, Prada, Giorgio Armani, one paid the ransom. He was the ex-owner of Intermanazion. remaining migrants. It fé all controls. kommen. and why we're saying, hey, from a recovery, you know, we're doing a better and better job in security. There's lots of budget spent, but are we actually getting more secure is the real question. And the way to think about it, obviously, again, it's not if it's going to happen, it's when it's going to happen. And then what are your abilities to reconcile and actually get back up and running? And that's really where we're focused from a recovery perspective. You know, and those numbers are pretty staggering, right? So if you look at ultimately from a GDP and how much we're actually spending on cybercrime, you know, it's a really, really massive number. In the range of, you know, what some of the biggest countries in the world are dealing with. And you see other stats, right? So all the numbers are going up ultimately. If you look at the number of ransomware which is going up, the number of ransomware attacks, and that will only increase over the coming years because of obviously with AI, the scale of it. Today, you know, some stats say out there that if, you know, if it's human generated, you can sort of do 2,500 attacks, you know, by human and one will be successful. But if this all is getting more intelligent, impersonation, all these types of things, then the conversion rate, so one becomes three, becomes five, becomes maybe 25. But also the 2,500 attacks because of scale and how AI is being used, you know, goes up and became our hundredth fault. And that's what we're dealing with on an all the time basis. And the key attack factor is clearly identity. And again, just to give you an idea, right? So if you look at Microsoft Entry ID, per day there's 600 million attacks on Entry ID. Every day. And again, those numbers are going up. So. Yeah, let's go back there for a moment. Like what do you say? Like every company that has been breached has one thing in common. They all have firewalls. That's the thing. And also we can divide the organizations that has been, I mean, all the organizations in the world on those who has been breached and know about it and has been breached and doesn't know about it. Right. One other thing, right? So the, so one is obviously the volume. I think the other piece is very much, and you, and we test this obviously internally when we look at the product as well. It's just the speed of things, right? So often we think it takes a long time, but really, we're literally in most of the time now we're talking about minutes, right? Yeah. It's like 71% as far as I remember. Yes. So 75, 1% ransomware in the groups. Now script the backup, the, the, the ledge, the lead gen, the, the leeching in the first five minutes. So from the first point of, of compromise, let's say for, from a fishing link to the bulk delete, the backup is just five minutes. It's super, super fast. Yeah, exactly. All right. Yeah. So let's get back to Italy for a moment. So you would, you would actually think that, okay, this doesn't forget me. It's like this tycoons, the 1%. So why should I care? The thing is that this is not true. We are now talking about Florida last month, but this is just one example. Mother receives a call from her daughter and the daughter says that she's crying. And he, she says that she hit a pregnant woman. It was a car accident. So, and then she, she passed away. She passed the phone to, to the lawyer or attorney and attorney, uh, keeps the mother on the phone while she's going to the bank to pick up the cash to pay the, um, sorry. Sorry. Not really the ransom, the bailout. No. How do I do call when you go out from the jail? I lost the word. Bail. Bail. Thank you. Thank you very much. Sorry. Um, and of course, and of course it was a fake. Uh, um, she, she, uh, she gives $15 ,000 to the, um, to the scammers and, um, the methodology behind it was very, very simple. The, uh, the scammers, they scanned, uh, the daughter TikTok and social media, basically Instagram. They only needed 30 seconds of, of her voice, of the voice of the daughter to replicate. Uh, the, the personality. Yeah. So this is in private. And obviously we see a lot of elderly dealing with this on a daily basis, but this is also happening in companies all the time. And again, it's getting more and more sophisticated. Uh, you know, if you look at, you know, how did you have TPT and I want to have a profile of you, you know, I can do that very, very quickly and then start social engineering and get to where you need to be. And again, where it's important from a vendor perspective is we need to think about those things as we build our controls, uh, around those particular pieces. I think another piece. And we, we've talked about for years about ransomware and ransomware sort of, yeah, ransomware. Here we go again. Tired of talking about it. It's a term, but ransomware is also changing very quickly. Right. But if you think about this from a data perspective, because ultimately a business is not there for security. It's ultimately get to business outcomes. Then ultimately one, one of the things we need to think about is comes really back to data availability. That's what you're trying to provide to the business. Ultimately such that can, they can, can achieve their outcomes. And so ransomware is real inside. A threat is real as far as why people cannot get to do that. Data data loss, certainly lots of people make mistakes and that's a reason to, to backup and protect your data. But the other one is very much, and we start to see this more and more is unintentional of, you know, so for example, we see adoption of AI, uh, you see a genetic approaches and all of a sudden it's doing something that was not really the plan. And you might not know, you might know about it. So we expect to see more and more use of data, but it also means more data. And then you need to manage that, but also again, things processing. And then are we getting to the right outcome? And so when you think about having data availability, again, as part of your security security posture, there's multiple reasons why you really need to make sure that as a business, you can get back up running some malicious, I think over time, more and more, uh, it will be around unintentional based on, you know, not fully understanding what we're doing or assuming something is one way. And it actually turns out to be slightly different now where that's really important and where we were born as keep it from a SAS perspective is actually. The proliferation of, and sort of the loss of control within the organization, right? So, and again, take this obviously with a grain of salt, but the analysts are talking about, you know, 75% of business outcomes are going to be achieved using SAS applications. Now add to that the AI, AI, uh, proliferation. And so we're talking much more about, you know, data living in multiple places, infrastructure living in multiple places, but as customers, you don't necessarily have control over that. What is it doing correctly? Where's the data going? How do we go about it? So what becomes really important as you adopt these things, and this is, again, I think the big challenge for it and certainly the security teams is what level of control do you actually have? Because what we're seeing right now, again, based on just the numbers we're seeing, you know, uh, with our customers is on average, you know, an average, you know, a good sized company, more than a hundred SAS apps, more and more tools adopted by users, but only 40% is actually approved by it. Right? when you look at your business outcomes, make sure you really are focused on the problems. And when you look at these adoption of types of tools, then make sure that you have a level of control around it that you're certainly from a security perspective are comfortable with. And I think that's one of the big sort of challenges if we look at overall adoption of more advanced technology and really deliver against the true promise of AI, which is not just about automation and augmentation. It's really like problems will fundamentally change, which leads to transformation ultimately. So this is not just solved by the security team, right? So I think another big part around the data problem, and again, I've been in this space for a long, long time, wasted my life on backup and data protection, really comes back to 20 years ago, we knew we had data, we kind of knew where it was, but we didn't know what it was. And that problem is still very much true today, right? We create more and more data, but what is it? And are we actually able to manage it? So boundaries in a SaaS AI ecosystem, again, the key thing in our conversations with customers is also what getting away from an adoption perspective is, you got to figure out where does the control live? And if you don't understand where your control is, or you really don't have a way to control it, then you're kind of already in trouble. And again, I think we're all facing it today. If you look at obviously the SaaS adoption, which is again, just happening, a lot of it is happening outside IT. But I think, the AI part is actually in some ways even worse, right? Because we do it ourselves as a company, like we adopt co-pilots, we adopt enterprise versions of various technologies, but are the users actually using it or are they just taking data from your company and putting that to the outside? And then what is the security risk associated with that? So that's the challenge we have today. And we as vendors, but also certainly as customers, we need to get ready for that. So control becomes a real thing. That's really getting in the way of adoption, because I think every company is sort of struggling with that. So when you talk about backup and data protection, you know, one other key thing that you have to think about, especially if you think about, again, SaaS and AI protection, is that when you look at your data in your SaaS production system, it's always just that point in time. So as you make changes, an M365, for example, today my mailbox looks like that, tomorrow it looks like this. And yes, if something gets deleted, it might be in a recycle bin, but it is very much a point in time. I think the power of things like data protection and what we do, for example, with Keepit, is actually, it's not just a point in time. It's your complete corpus over all these, you know, over as long as you've been backing up these SaaS applications. And that gives you multiple advantages. One, from a data governance perspective, there's more things you can do with the data because you've got the bigger picture. But two, we can also bring some of that data together then to actually get to additional outcomes, right? So this kind of speaks back to the data protection, this speaks back to the control part, where now you have a big corpus of data that is within control that you can set policies around and who has access, where does it live, how long does it need to live? And then again, use more advanced tools to actually, you know, get to better business outcomes. Versus, hey, we're going to go to every SaaS silo, trying to work with these vendors and we get what we get. So, you know, it's part of what you need to think about, again, not just in context of security, but also achieving better business outcomes ultimately. Go ahead. So one last thing is, and I say this now a couple times, what we see over and over again, and we're also guilty of that very much as vendors, is that we tend to just focus on the solution, the next thing, the next thing, the next thing, that we can solve for our customers. Again, I think a key part in all this is, again, certainly as security experts, stay very focused on the problem you're trying to solve and don't overreach, because I think we're overconfident and overcomplicating a lot of things right now. And sort of, you know, in some ways, AI is actually feeding that. Too much data, you know, problems becoming more complex versus, hey, this is all we need to solve the business outcome, which makes you more secure and gives you more control ultimately. So with that, thank you very much and have a great conference here. Thank you very much.