Guardrails in the Wild West - Ronak Patel - Guardians of the Data - Episode # 60
GOTD - Ronak Patel
===
Speaker 2: [00:00:00] Welcome to Guardians of the Data. I'm your host, ward Balza. Each episode will explore the passions, expertise, and real world experiences of security leaders who are helping the future of data security and governance. Guardians of the data is made possible by support from Centro. To learn more about our AI powered data security platform, please visit sentra.io.
Let's dive in.
Ward: Welcome back to another episode of Guardians of the Data. My guest today has over 25 years of experience in the industry. He's a cybersecurity expert, data protection strategist, and enterprise security consultant. Ronak Patel, welcome to the show
Ronak Patel: Thanks for having me, Ward. How are you?
Ward: Doing good, doing good. Ronak, I gotta say, I think back, you know, for the audience, you and I used to work together once upon a time solving all the world's issues at, uh, at a Fortune 500 financial and, uh, I miss those days,
Ronak Patel: Yeah
Ward: for sure
Ronak Patel: It was a simpler time actually. Now it's gotten a lot more complex, uh, the way the [00:01:00] industry has moved. AI, uh, security in general is, uh, it's a great place to be because it's a never-ending strategy, a never-ending approach, um, and job security like there's no other, to be honest with you.
Ward: Oh, totally. So perfect segue. I actually did not plan it, funny enough. But, uh, so that being said, right, it was a simpler time, and now it isn't. In, in your professional opinion, what is the biggest data security challenge organizations are facing?
Ronak Patel: I honestly, it's, uh, it's now multiple fords, folds now I look at it. You're, you're now dealing with AI. Uh, the is gonna be that Wild West again, of what we kind of had probably about 20 some odd years ago. It is the Wild West. Nobody knows what's gonna happen. Nobody knows the destination. Uh, we know that we came from a time when it came to cybersecurity or security in general, data security, all those things that, you know, organizations from a, you know, security or CISO level have been dealing with internal to [00:02:00] IT was, you know, well thought out and there was an approach that was kind of, you know, pretty good if you had the right strategies probably about five years ago. But now with the advent of AI, it is now taking a multiple level fold of, again, how do we tackle this? Because there are now agents and things that are out there that can do just about anything you ask, and you've got to have a counter to it, and that's the hardest part, that how do you counter that ask that you can pretty much plug and play and do something relatively quickly, you have to have a counter to that.
And that's the hardest thing I think that there is, is that can think up, anybody can utilize AI to devise a malicious approach on just about anything. countering that is gonna take a massive effort. Um, but I think it's gonna be this tr- uh, really, uh, troubling time probably [00:03:00] over the next three to five years I think organizations, software organizations, uh, are gonna have to have this very reactive approach to patching things.
I mean, you hear about things that are like AIs figure out how to hack OSs very
Yep
finding these things without, you know, necessarily having the white hat do it, but it's taking more of a black hat approach. We've got to figure the counter, and I think it's gonna, I think it'll honestly make things more secure in the long run, but it's gonna be a bumpy ride till we get there, and then we may have a more hopefully efficient counter approach. We'll see what that looks like. I don't know.
Ward: I mean, we've been hoping for that for years, right? So if I think back and, and I mean, you, you've been in the industry a little bit longer than myself, but, you know, s- similar story, right? We, we both got into data security back when we had the castle, i.e. the data center, you know, and it was relatively easy, although you had your own [00:04:00] difficulties there, right?
Where do I put the sniffer? Where do I do this? How do I route the things? And then cloud came, and it was very bumpy. Um, you know, transformation, which wasn't really transformation. It was lift and shift and still inheriting sins. Um, a- and now certainly for the last couple years, feels like this year even more so, right?
I think it's just the overall adoption, new things coming, um, just AI proliferation, which, man, I've, I've said it a few times in episodes, I'll say it here again to you, like, in my opinion, it's just hi- i- in, in hyper speed identifying the same stuff that we failed to do over and over again
Ronak Patel: Yeah, and I, I 100% agree. It's-- I would almost make it that similar transformation like you talked about when it was cloud, is that you've got this very, very fast-paced reorganization of protections, all those things that [00:05:00] were there, and now we're doing it all over again and at, at a hyperspeed like you mentioned. It is, the adoption of AI is ridiculously fast. proliferation of how it can be used, the, the limitations of control mechanisms right now in place don't exist. So it's a little like we're, you know, flying off the seat of our pants trying to figure out how to put guardrails on this once again. Um, and it's, it's incredibly difficult to do at this point in time AI is literally, there's a new iteration coming out, you know, on a weekly basis, biweekly basis, you've got to adapt.
And it's, you're literally moving pieces. It's like, I think I have control here, and then literally somebody's moved your chair three days later, and you have no way of getting it.
Ward: I mean, so super applicable to your role, right? You, you, you've been a consultant for many, many years, so you've ... I mean, it is literally your job, right? To advise folks on what to do. So how are you advising folks [00:06:00] today to try, emphasis on try, to solve for some of these problems?
Ronak Patel: Well, I think it kind of goes back to the foundation of what we kind of worked with, and that we've both done before, is you need to understand the organization. You need to have some sort of a overarching steering committee mechanism, you know, uh, in group of individuals that have to understand the business, have to understand the data, have to understand the ownership of that data, where it's located.
All of those things need to exist before you could really now tackle the guardrails. Because you look at AI right now, and it is being rolled out, in some cases company-wide, in some cases siloed approach. If it is a siloed approach, I think it's a better way to, do that same let's understand this business that may be less complex or more complex, put the right strategy around it, and then deploy that to the rest of the [00:07:00] organization. Uh, but again, it's moving so fast, and I think that foundation doesn't exist in a lot of organizations. So again, they're flying off the seat of their pants trying to figure that out. Um, but you know, moving forward with what we do have and the technology that we have right now you need to Try to slowly roll this out.
People are now adopting AI, whether it's Claude, ChatGPT, you know, Gemini, all of them are out there, and it's literally like, yep, if you're, uh, you know, if you're G Suite, they've already rolled it out. If you're, uh, Office 365, they've already rolled it out in Copilot. So you're chasing your tail, and again, I think it's one of those to where you need to understand how your employees are using these things, and I think that's another problem that we have to where the, uh, the utilization of tokens is off the charts, and I think you've probably seen that with organizations.
If they actually do an accounting, [00:08:00] everybody is using their AI agents in some cases, the simplest tasks, which cost money, and then the cost, the really intensive ones, which be more efficient, but they're also very cost, uh, you know, high, high cost value to do the AI. so I think we're going back to basics to a certain extent of shadow IT, um, of what we did, you know, decade ago of let's understand what people are doing on my network, what SaaS applications are they using, where is the kind of those things, and then putting the guardrails on. you're now doing the exact same thing with AI is a shadow IT approach to understanding what are people doing, what AI platforms are they using, an understanding of that, and then start putting guardrails around data. again, it's that same foundation we started with is understanding what the business is doing. Now let's understand what data they're utilizing those AI components. [00:09:00] And again, putting those same guardrails that we had around data security proxies, same approach, and that's why that foundation of understanding your data, understanding how to manage it, who's supposed to use it, who's supposed to escalate it, deal with those issues, that framework comes back into place. So I think it still is that foundation, understanding needs to be there, then putting those same guardrails that go then with AI
Ward: you don't mean just bring in a co-pilot and connect it to everything right off the, right off the bat and, you know, what could go wrong?
Ronak Patel: Uh, what can go wrong is, uh, I mean, we all have, we've all have read all the things that are going on with AI. If you give access to AI and they, they, you let 'em do whatever it is, the AI is gonna figure out its way to use malicious things, exfiltrate data, whatever else it might be, the guardrail needs to be there.
And it's almost to where you talk about when we had our own [00:10:00] infrastructure, we had our around, you know, our data center. Um, I would almost wanna go back to that in these kind of mentalities, is bring back that guardrail of bring everything back into your AI, your, your data center. You own it, and then an AI agent or some sort of AI component in your infrastructure that has no connectivity outside of it.
But again, seen that AI will break through these things because of the vulnerabilities that we don't know about.
Ward: Yeah
Ronak Patel: so this is the Wild West that I think we both reference, is that don't know where things are gonna go, and if there are not guardrails on these things at least some sort of a checks and balance, we are going to be in trouble.
And I think, uh, people don't, people don't have the idea of slow adoption or at least adoption with checks and balances and guardrails, can be a lot of trouble.
Ward: Yes. Uh, I mean, I, I'm [00:11:00] laughing because I think, you know, kinda like yourself, I'm sure, uh, on a weekly basis I have these conversations with, with folks out there, advisory conversations, and I always mention slow roll and everybody laughs. And we're, we're not laughing 'cause it's humorous, we're all laughing 'cause we'd cry otherwise because the business isn't slow rolling.
The business is, uh, I'm not even gonna call it adopting, I'm gonna say using these things at hyper speed because, like, I feel like the term adopting has a connotation that you are putting guardrails in, you are doing the right things, you're truly bringing in and using it as an enterprise. It's, it's kind of unreal, for sure
Ronak Patel: You, you hope they are doing that enterprise-level adoption because, I mean, uh, I, I, I know for a fact prior to, you know, outs- on my own, you know, infor- information, my own, uh, tasks that I have, I am using AI on a regular basis, on a daily basis because it's very efficient. [00:12:00] So if you don't have those to either getting an enterprise license for whatever AI component you're using, um, and then don't have the guardrails or at least the, the checks and balances, the data checking and so forth, your employees or whoever it is, is going to be using it no matter what. then you have no guardrail whatsoever, and we've seen it to where AI has gotten, you know, upload of GitHub, um, and upload of source code that somebody was trying to say, "Hey, you know, ChatGPT or whatever it was, check my, you know, Java s- that I wrote and make sure that it is gonna be checked out." And somebody doesn't realize you just sent up the, the, the keys to the kingdom to just a public AI,
um, which we've all seen.
So it is this chase, uh, that I think the C- the security organization is gonna have to be to make sure the guardrails are in place and go, "Hold on, roll it out, but let me buy this really quickly." And I think that's another problem, [00:13:00] that people are buying things fast without the products, the platforms, et cetera, to plug a hole. then we're gonna come back later to realize how do we make this a unified platform or some sort of, uh, you know, multiple tools in the shed that actually provide all the things that I, coverage that I need.
Ward: Oh, absolutely. Absolutely. So you've used the term and, and so have I actually. We've both used the term now guardrails a few times. So for folks that are listening that might, well, are likely in the, uh, i- in the seat of what the heck should I be doing, what are, are some of the guardrails that you'd recommend folks do ASAP?
Ronak Patel: Just for, I mean, if we're talking about AI or are we talking about security in general?
Ward: I would say data security, but obviously, as you know, that's super broad, so I'm just gonna say yes.
Ronak Patel: So I think from a data security perspective, you need to have, I would say, at least three or [00:14:00] four foundational components. One is your email inspection, whether that is some sort of an email gateway, E- MTA, whatever it might be, have a really good, possible, best of breed. I know that we talk about, uh, Office 365 licensing, et cetera.
Those things are kinda cookie-cutter, cost-effective, et cetera, what it might be. You need to have a CASB component. You need to have, uh, a proxy component if it's not incorporated within your CASB. Those three or four things are foundational. On top of that, then you need to then have your content inspection, whether that's DLP, again, going to CASB, going to whatever else it might be, need to have those things in place to inspect that data, and then the right policies to inspect specific types of data on destination, on senders, et cetera. Foundationally have that regardless, and at least have an overarching team of people writing [00:15:00] those strategies or approving those strategies for different departments, data, et cetera. the foundation. with AI, you can now plug in those components of AI, uh, detection that can tie into your CASBs, tie into your proxies, tie into your MTAs, et cetera. And I think the AI aspect of it is even more so because now you're utilizing it and every employee is utilizing it on a daily basis. Um, and you can then plug in those same policies, those same data protection strategies right into that over, not-- new, new touch point of AI detection. Now, whether that's on the endpoint, a-and again, we can talk about an endpoint agent of some sort, and then again, you have, you know, proxies that can go on the endpoint as well. Again, you wanna be able to look at content that is happening on that level, at least at a minimum. And the AI can plug into those things. I look at things. Now, if you get [00:16:00] that coverage from the exfil of data, that is a good foundational coverage guardrail, as we talk about. the next level is once you've got a good handle on it, I would start looking then at, you know, UEBA, looking what the users are doing necessarily. think that's a light touch. I don't think it's a necessity. As long as you know what people are doing with the data as it leaves the organization, I think that's a good level. Um, so that's kind of where I would start and end to a certain extent. Um,
Very good
of course, on top of that, you need to have right, you know, configurations, GPO-level configurations, you know, lock down the endpoints, lock down, uh, y-your access to the data within the organization, within SaaS and environments, all of those things from identity management Need to be there as well.
Ward: Good tips. Good tips. Something I'm curious about. So for years, I would always beat the [00:17:00] drum as I was building a data security program that, you know, loss prevention, right, DLP or just data leaving, like that's what we need to stop, right? And, and it makes sense, right? Because again, if we think prior to we'll say five years ago, that was the biggest remit of a data security program, was essentially prevent the data from going out.
Now, my talk track, and I'm curious your thoughts here, that's what I'm getting to, my talk track has changed from, from data loss, data leaving, to just data exposure in general, which obviously could include data leaving. And the reason my talk track has changed is really those copilots, right? Like, if those copilots are in the environment, technically speaking, your data's not leaving, it's just potentially getting inappropriately exposed to whomever, right?
To include third parties. So kind of curious your thoughts, number one, but [00:18:00] also your thoughts around like starting to solve for that problem, because I think a lot of companies are really struggling with the copilots these days.
Ronak Patel: So that, that ties in then the prior to this AI, you know, floodgate that opened up, we were looking at DSPM, data security posture management. You know, there's a lot of different acronyms for it is looking at right permissions, the right exposure, e- whether it's external or internal of your cloud data, that might be, whether it's Office 365, whether that is Salesforce, your SaaS, wherever else it might be.
Everybody is sharing this data a regular beta basis. people are allocating, uh, you know, those shares very, very quickly. People are spinning up things and spinning do- down things on a regular basis, whether in AWS or G Suite, whatever it might be. You need to have some sort of a accounting of that. that's another area where prior to this, [00:19:00] like I said, before this AI floodgate opened up, that's what we should be looking at. But I think I agree with you that that is a priority, from a whack-a-mole perspective. Um, that's what I would focus on first, but the AI has popped up and it's like, okay, I've gotta cover this. And I would almost say that the AI kinda goes back to a little bit of the DLP component because you're looking at the data as it's now being exfilled or utilized by some other individual, I call the AI agent. but the d- the data, the DSPM aspect of it is still a important point, especially 'cause the fact you can't expose that internally as well as externally malicious individuals or people that shouldn't have access to it. it is another component of security that, again, we have not gotten [00:20:00] a good understanding or and I keep going back to that word, um, to, to, to have a good understanding of what it is, where it is, you know, what level of control is on it, um, and, you know, making sure that it's been protected.
Ward: it's those sins, right? It's those sins that, and I've, I've certainly been there in organizations, that organizations have, like, committed over and over. Um, maybe not 'cause it's not easy, 'cause it's not easy, right? Doing, doing all that. But also, um, it was deprioritized for, "Hey, we need to upgrade our firewalls," or, "Hey, we need to do this thing or that thing.
We need a new EDR solution," because of, of reasons, right? And, uh, it's unfortunate because at least what I'm seeing The things that we ignored or deprioritized, data security and identity are really coming to the forefront now in most solution conversations. "Hey, we've got [00:21:00] this problem." "Okay, what are you doing from data security perspective?
What are you doing from identity perspective?" "Oh, yes." And, right, 'cause everyone understands like, shoot, we d- we didn't do our rights cleanup. Um, yes, we never got a good handle on our service accounts, now they're non-human identities. Yes, we never got a good handle on our CMDB, but a CMDB from a data perspective.
It just, all of those things we haven't done for, for years at this point
Ronak Patel: And, you know, it, it goes back to this foundational approach of a security committee is talking to all these different departments. And I, and I think it's one of these things to where, again, there is no, you know, board that goes through and goes, "What are we doing with this today?" And they go, "Oh, well, we're just allocating some new, you know, stores in AWS or in this location," wherever it might be.
Okay, what is the security posture we have around this? What are the control mechanisms? Who's allowed to look at it? What [00:22:00] are we doing? So it is this framework that needs to be developed to go as we provision this or provision that, we need to go through some checks to make sure the right controls are in place.
And I know it's very hard to do from an organizational perspective 'cause everyone wants to run at the speed of light to get things done without checking. And that's the problem with security, is nobody's saying, "Hold on a second. What are we doing?
Do we--
Yeah
this correctly so we don't have to come back and chase our tail?"
Which is what we're now doing with those things, that we're chasing our tail going back, "Oh, wait a minute. We didn't do this at the beginning," which is now we have to go back and now do all of this identity management and do all this, uh, data s- audits to understand what's going in. So, and I, I, I can go into so many other directions of we don't have enough personnel, people aren't throwing enough, you know, obviously resources at this thing. which I, you know, going back to what we talked about at the very beginning, [00:23:00] cybersecurity is a great place to be, or security in general, because it is a never-ending problem solve. I mean, we, if, if we can solve this problem in this conversation today, we would be a home run. But every single organization takes a different approach, and it, it's, uh, yeah, it, it's a problem that's gonna continue happening, and I don't know when, uh, until s- every organization realizes that this is, uh, you're proliferating the problem by running at the speed of light, is what it is.
Ward: So what are your thoughts on, I mean, there, there's a lot of, there's a lot of folks, and rightfully so, talk about, you know, AI for business. Um, there's talk tracks around like AI for bad, right? Pen, uh, so the good part of bad would be like, you know, red teaming and, you know, pen testing, and there's like the bad, bad, right?
Malicious actors using it. Um, what are your thoughts on AI for good, though? I mean, certainly there's, there's a lot of things coming out, right? [00:24:00] Both homegrown and, and vended. I'm just, fr- from a data security perspective, do you think that can help close some of these gaps we're talking about? Or, or 'cause you also mentioned people, and I agree with you by the way, or do we still think a lot of this is, you know, a people problem that we need to solve?
Ronak Patel: I would probably say it's the first. We probably should solve for AI 'cause I think AI has a higher threat potential than individuals. Um, AI for good, and, and I think it's, you're paying with the y- the and y- yin and the yang of these two sides is the AI for good and the AI for bad. And this is why I talk about we're gonna go through this, y- you know, rollercoaster ride over the next probably five to 10 years maybe, um, is you're gonna have a lot of the AI for bad that are going to open up these holes and find these holes that, you know, we can't [00:25:00] figure out as individuals, even pen testing, we didn't think about these things. Um, and then we're gonna then find a way to utilize AI for good. So there's gonna be this kind of a yin and yang that I think bad is first, AI for good will come into play somehow. But, it's gonna be the malicious ones that are gonna try this first, as opposed to the white hats trying to go, "Let's get this ahead of the game first."
Because I- I've always said this before is I'm a good thief. I think like a thief, but I'm a good thief. I know how to figure out how to exfil data, and that's why I put protections in place to go, "What are the ways I would think about doing this in a forward dir- if I knew you had proxies, firewalls, these things in place, what can I do to get around them?" That's, you know, thinking like a good thief on what can I plug them? So AI is gonna do the exact same thing from a good perspective, but I think it's gonna be the malicious that's gonna try it first.
Ward: A- and I like where you went with that 'cause I, I, again, I [00:26:00] think back to the good old days when, when you and I were working together, you were helping me build out the program. And y- you, you'll probably remember, I used to challenge the team, think like bad guys, right? It's cool that we're implementing this DLP tool or we're implementing, you know, DAG or whatever, right?
We're implementing these things. But if we're just doing out-of-the-box configurations and saying, "Ah, we're good," like that's a problem. Think like a bad guy. So I, I do really like the idea of, I've talked to a few folks that, that are doing this today, like literally putting their security configurations, their network topology into hopefully an internal solution 'cause oh my God, hopefully not putting that out.
Um, but then saying, "Hey, like think like a bad guy. If you're gonna take PII, whatever data out, how would you do it?" And then letting it expose your, your gaps at that point
Ronak Patel: And I think that's gonna be the hardest plug [00:27:00] because AI, and I, I think I might-- I'm not sure if I talked to you about this, but I literally, I, I've spoken to a few people of, uh, there is the simplest way of exfilling data, and AI would be able to do it, and even an individual would be able to do this. It takes a little bit of effort, but if you literally took an Enigma-based level encryption that did character swapping, whatever it might be, and I would then specify AI, use some sort of algorithm, encrypt this data, scramble this data, whether it's PII, whatever it might be, scramble it up, send it out the door, then wherever it's received, reverse that and unscramble Easily done. Even today, it's a lot of work, but how do you stop that? And the only way, and, and I don't know if there's any easy way of doing that even now, because you would need to know the [00:28:00] origination and the destination of that data. And the origination would be, again, looking at your DSPM controls, looking at your identity controls, looking at UEBA or, or,
Yeah
know, threat risk. That would be the only way to connect the dots
to was gonna, I was gonna say the only way is behavior analytics for sure, like period
That would be the only way. again, it's one of these things, if you don't have those foundational controls in place, you're not going to know that this is actually happening. and it will go right out the door, and you will never know it happened without those kind of things in place
Ward: And that's, it's funny, you and I, we know that. That's second nature. We've been doing it long enough. But I, I don't know, man. When I, when I mention things like that to people, it's like brains exploding. They're like, "Oh my God, really?" Like, yeah.
Ronak Patel: Yeah
Ward: Like, again, a data protection [00:29:00] program is not a tool at all. It is a program that, yes, has tools, but it also has processes and people, and all of this living in harmony to actually be able to protect.
Hope- yes, hopefully. Hopefully living in harmony
Ronak Patel: Not a siloed approach, which a lot of people love to do to this day,
Ward: Yeah. Oh, those data security guys, right? Separate from the SOC, separate from, you know, IT governance, like literally its own island sitting out there doing whatever, essentially
Ronak Patel: Uh, you know, e- teams being managed by themselves that don't have communications with the data security or the, the, the, the audit team, the DSPM team. It, it's everybody get in the same room, get a good foundational understanding, a good approach, a good strategy that comes together, um, and then comes together with your other tool sets of data aggregation, mining, et cetera. All of that needs to come into play. Um, and I think there are [00:30:00] good set of companies out there trying to do it. Um, when we get there, I think it's a matter of, you know, the right Legos in place, the right bricks in place to get it to done. And again, it goes back to gonna be a rollercoaster, um, of people trying to get this to work.
And I think there are a few organizations or a few companies out there that I think can crack it, but it's gonna take some time
Ward: Completely agree. Well, Ronak, you've been doing this for a while, you know, over 25 years. So tell us, how did you get to where you are today? What was your journey?
Ronak Patel: Well, um, start that I-- My, my, my journey was I thought I was a programmer, and I re-learned really quickly out of college that I am not a programmer. Um, I, I think my first job, I didn't last more than probably about six months, then I realized, yep, I'm not a programmer. I'm not a developer at all. and I started off working at a Air Force base in Los Angeles as, um, desktop [00:31:00] support. Mind you, I'm a lot older, and networking didn't exist back then or, or did, um, and that was with coax if you, if you know anything about that. But to the, uh, IP dates, uh, Ethernet those days, I was desktop support. So, know, teaching people how to use Windows, um, when Windows w- didn't exist, uh, the first iteration of it at least. Um, so I'm, know, I'm an old D-DOS guy. Uh, I'm an old keyboard guy, so I still know everything to do on the keyboard level, still, you know, do configs, all that stuff, uh, know my Linux. So I've kinda come and I was lucky, I'd probably have to say, as I came up as part of the information age did come about. Um, and I was very, you know, on hands keyboard, computers, building things, all of that stuff that was there. So, over the years, I just, uh... From there, I actually ran IT organizations for PlayStation One. It was brand new. Um, so I was building out their infrastructure, you know, networking, switchings, [00:32:00] firewalls, uh, SGI machines, if you remember Silicon
Ward: Ooh, yeah
Ronak Patel: a lot of hardware technical stuff. And then slowly over the decades, I got into, uh, you know, because I was able to implement all these things and, uh, had the right approaches to them, I knew exactly how to consult around these things. So, went into consulting. I actually worked for one of the, the, the big four, big five, whatever you wanna call it. Uh, did that for a little bit, and then during the dot-com days, I started building some of the largest websites with, uh, some consulting companies. so we were rolling out, again, at the speed of light, figuring out how to roll out, um, you know, Linux machines left and right when we didn't have AWS or didn't have cloud to spin up things with a click of a button. It was, how do we script the spinning up of a Linux machine? Okay, let's script the crap out of it and spin up three or four m-machines, you know, instances of [00:33:00] every single platform that was out there on top of these machines. So it was a lot of, you know, flying off the seat of our pants, figuring out how to write process, write scripting, you know, being able to say, "Okay, let's run this script."
We now got my instance of whatever ATG or whatever my prox-- my web front end was, my application back end, my database, doing all of that, you know, as quickly as we could, uh, and then understanding, I think at that point, the security ramifications of spinning these things up. because back then it was like, okay, we were in our own data center.
We were behind our own firewalls, um, but we had to have the right configurations, right VLANs, all of that stuff. So it was a very hands-on approach, understanding the problems, how to plug them. then after that, I just slowly got into security organizations, became a sales engineer on, um, CMDBs, a sales engineer around, um, at that point, a-after the, the CMDB was to [00:34:00] spin up drag and drop networks, um, so you didn't have to necessarily do the programming anymore.
You can spin up a VLAN by dragging, um, some connect to the dots on, you know, a picture of a firewall, a picture of your switch, and spinning up machines and making those VLAN connectivities done by UI as opposed to scripting them. Uh, and then after that, I got into data security. I worked at a company called Vontu, which was the kind of the foundation
Ward: The grandfather
Ronak Patel: Yeah.
The, the origination of it. And I think there is where I got my chops really around data security because had to figure it out. Um, there was no DLP, there was no data security, component of content inspection, understanding your p- y-your data from that level, uh, on how it was being utilized across all of the different vectors, whether it was email, proxy, uh, endpoint, uh, you know, I was leaving out the network.
[00:35:00] All of those things were the foundation on data security. then that, you know, because of all the regulatory requirements that happened around that, PCI, HIPAA, you know, and that still is happening on a yearly basis now to where we've got GDPR out in Europe, and now we have the California ones on scraping that data. all of that has been based on the origination of understanding that data around the data type detections, et cetera, now been ever-changing. And so after I actually, uh, built my own security practice, and that's where we started working together to where I was consulting for a lot of large organizations on how to strategize the data security, know, process, how to deal with writing the policies, the, uh, the components around building that foundation, and then making it a, a process or a business within every organization to be proactive on understanding how that data is being used so I can put the right policies, [00:36:00] guardrails, et cetera, in place. did that for roughly about 15 plus years, and now I'm going back into the, uh, software realm of now looking at this new generation of DSPN, this new generation of AI security, um, because there is a ton of tools that have been spun up over the past, about two years, that were in its infantile and now are coming out to where they might be able to put the right protection in place.
But again, it is still the Wild West. Um, but again, I'm getting my hands dirty and understanding exactly how these things can work to put together probably another level of consultative around what's the right approach. Because you need to understand the, how AI works. I mean, that still is ever-changing. Um, a-and figuring out how can we hook into these things to then identify what are they doing with [00:37:00] this data? How are they getting hold of this data? Can I put the enterprise controls around this utilization of AI agents for, uh, you know, the employees within their corporate umbrella, if you will? That's where I am today.
Ward: Wow. Quite, quite the journey. So for those listeners, and there's a lot of people out there, I'm not saying they're all listeners, right? So I'll just say for the people out there, a lot of folks are without jobs trying to break in. Do you have any advice for either one of those groups? Because it is, at least in my opinion, it's crazy times.
You talked about the Wild West technology. I think it's a Wild West of just landing a job these days as well
Ronak Patel: I 100% agree, and I think it's very hard. I think we're probably in the same boat that we have a ton of colleagues that are really strong knowledge colleagues, and it is getting really tough. I think it's this, um, I hope it's this. And I'll say this, I hope it's this, is that this AI, [00:38:00] this AI approach that everybody was exploring "Oh, AI is going to solve all of my problems around resource availability or the, the personnel that I need. So I am going to reduce my hiring process or eliminate some of these positions that I think I don't need, because I think AI is going to solve this problem." Um, and I think a lot of organizations, and I think we've, you know, seen some of the big, uh, the big companies out there realize, "You know what? This is not going to reduce my headcount. Uh, it may make things a bit more efficient, but it is going to increase my headcount because I am now going to need stronger individuals that need to, at least from a security standpoint, manage this AI, my security, because it is going to be the Wild West."
Mm-hmm.
So I'm hoping that organizations and security organizations are gonna start leaning into this, going, "This is gonna be a bigger problem than I can handle, even the way it was [00:39:00] before." Because even, uh, both, you know, we, we both know this, security have not grown as fast as they should. It is always a, a line item on an accounting book,
Mm-hmm.
When it
Ward: Yep
Ronak Patel: a more security or insurance-based approach of, "We need this because it is going to proliferate even faster. And if we don't have these things, we're gonna be in serious trouble." so I think I'm hoping that it's gonna be similar to those organizations that realized, "I didn't have a da- or a data security program, and, I lost a bunch of data and I'm getting smacked with fines, and now my brand has, you know, been damaged."
I'm hoping people realize we don't want that to happen again.
Right
the latter of it's gonna happen and then people are now gonna the CYA after the fact, which I hope organizations learn not to do that, but who knows? but as, as far as [00:40:00] finding the jobs, And I, I know there's a lot of people out there that say utilize AI.
I would utilize AI 1000% on helping you write your resumes. Have a good foundational understanding of what your resume is, and then use AI to build your resume based on every single job req that you look at, to where, "AI, here's the job req I'm looking at. Here's the company profile. Here's my resume.
Rewrite it in such a way to where it is a good resume for this position." I think that's an important starting point. And then on top of that, whatever connect- connections you have at the organization. If you know anybody that's even a third step off of your relationship via, let's say, LinkedIn, reach out, get in there, because it is now so competitive that that internal network is gonna help you land that position better than anybody else, and that's what every-- all the people that are getting the positions are utilizing [00:41:00] to get there, 'cause it's very competitive. for those individuals that are starting off in cybersecurity, I would probably say, uh, do whatever coursework you can, build your labs, get your hand dirty, do a ton of research, go to Black Hat, go to whatever these, you know, things are. You need to go them, one, from a networking, two, from an understanding and seeing what is happening at the ground. because if you can't intellectually speak about these things, you are competing against those that can. And, um, it's-- and I would almost say there is no job that I would refuse if it gets your hands dirty. Even if you think you're ov- you're overqualified for it, take the job, you're gonna be able to prove yourself within that organization [00:42:00] and find available positions or responsibilities that you're gonna have pre- purview to that nobody else out- outside the organization is gonna have. That's unfortunately where we are
Ward: I think that's, I mean, lots of great tips. I think that's a really good tip though. I mean, some folks I've talked to or even just seen their posts on LinkedIn, like there's a lot of ego in there. And, um, I think that was fine back when you and I were getting into it, you know, 20 years ago or so. Um, that's, that's not gonna land you a job just saying, "Hey, I'm the smartest person in the room."
Like, a lot of what I'm seeing, a lot of what I'm hearing comes down to everything you said with a super big emphasis on networking. Big emphasis. And a lot of ways to do it. I love that you mentioned go to Black Hat. I would s- offer like... So first, yes, right? I've done that for many years. But if not Black Hat, go to Bsides.
If not that, [00:43:00] like go to your local ISSA. Like, there's so much out there now. Um, the industry has gotten so big that go do something.
Ronak Patel: Don't, don't sit around because it's not gonna-- I, I-- This job market is tough. It reminds me of the dot-com days wh- uh, the bust where you-- every single job organization laid off a ton of people, and there was a flood of so many technical, capable individuals, and it was so hard to find a job for, you know, probably about a year and a half. we're kind of in that same realm again last year. There's a ton of RIF and a ton of talented individuals are out there, and they're all fighting for the same job. Um, I know for a fact, and you probably have the same thing, it's like, you know, I literally applied to the same job as probably about five other people I knew, um, because we all fit into that bucket.
It's like, oh, this is a great, you know, post that came out on LinkedIn or whatever job site [00:44:00] all fighting for. Um, and you've got to be really proactive to where single day I probably would've said is that, you know, you're, you're posting to five to 10, 20 jobs.
But every Single one of those has got a different resume. you've got to resonate these things. And I, I, I, you know, I hate to say it, AI is great for that. it made my life a lot easier to say, me a cover letter, write me a new resume for every single one of these positions to where it gets me to the top of the list, hopefully." And if not, get ahold of that network go, "Hey, I applied for this job."
Or, and I've learned this more recently, is if you see the job, go to your network first, ping them and say, "Here's the job, here's the job ID, here's my resume, here's my cover letter. Post it for me." Because you don't wanna do it-- You [00:45:00] don't wanna apply first and come around second. Go around that bucket first, and
No
say, "Hey, now go through the portal or whatever job," then go that direction.
Ward: lot of companies are doing referrals, right? A lot of companies do referrals
Ronak Patel: Yeah. And then, hey, you work at a company and somebody, you know, one of your friends is like, your colleague just goes, "Hey, I'm applying for this position," and I'm gonna get maybe 1,500, two grand, whatever it might be, gonna go fight for that two grand.
Ward: Yeah.
Ronak Patel: hurting.
We all need it.
Ward: Yeah,
Ronak Patel: it.
Ward: absolutely
Ronak Patel: fight for that and go, "You need to go talk to, you know, John Doe. He's an amazing guy at this, and he's gonna be a, a great technical lead or a, you know, technical resource. Bring him in. I've worked with him." Right? That kind of thing. That matters in, in our industry.
Ward: Totally
Ronak Patel: so that's kind of where we're at, unfortunately.
Ward: Well, Ronak, speaking of networking, folks want to network with you. What's the best way to do so?
Ronak Patel: Find me on LinkedIn. Uh, happy to answer some questions. Um, happy to point you in directions. I, we, I, we've got a couple Slack [00:46:00] channels that I'm on with some other colleagues we're always talking to say, "Hey, there's new jobs, there's new postings, there's this or that." But I would definitely, you know, obviously I think LinkedIn is great for a lot of these things.
I would look at, you know, Dice, Indeed, all of them are kind of okay for security. Um, but I, I know there's some other ones that are out there. Um, for example, there's a website that I used to work, do a little more stuff with MBO Partners. They are looking for consulting engagements for KPMG and a couple other ones.
Those are nice little resources if you wanna, you know, get a 1099 as opposed to It'll fill the gap, and again, it, it will add another network layer. You might get some connections that might get you in a position somewhere else. But it, it is tough. Um, utilize that network.
Ward: Love it. Love it. Well, Ronak, thank you so much for joining me. Finally got this in the, uh, in the books
Ronak Patel: Took a while and I'm glad it finally happened.
Ward: Well, thank you so much. [00:47:00] And big thank you to the audience. We really hope you enjoyed the episode and learned something today. Please tell others in your network to follow and listen. This has been another exciting episode of Guardians of the Data. See you next time
Speaker: That's a wrap on another episode of Guardians of the Data. Thanks for tuning in for show notes and more Visit Guardians. The data do show Guardians of the data is made possible by support from Centro to see how we help organizations discover and classify all of their data accurately and automatically while quickly achieving scale data protection without the fuss, please visit sentra.io.
Catch you next time.
Creators and Guests
