#149 - Why is Data Security so Hard? w/ Yoav Cohen
Nov 1, 2023
auto_awesome
Yoav Cohen, co-founder & CTO at Satori, discusses the challenges of data security, strategies for dealing with analytics over sensitive data, compliance requirements for data teams, and the importance of data engineers as security engineers. They also dive into the concept of the death of big data, the process of data masking, and the importance of adaptability in the data domain.
Advancements like Databricks' Unity Catalog simplify data security by focusing on securing tables and views, removing the need for separate security models for each data manifestation.
Organizational approaches to data security have shifted towards distributing ownership of data stewardship, empowering teams to approve data access based on their knowledge and fostering a sense of responsibility.
Deep dives
The challenge of securing data in the data lake or lake house
Securing data in a data lake or lake house presents challenges due to the different manifestations of data. Historically, organizations had to manage security for each manifestation, such as raw files and tables in the query tool, which required different security models. However, advancements like Databricks' Unity Catalog are simplifying this by focusing on securing tables and views, removing the need to provision access to the underlying files separately. This convergence around a SQL-like model is beneficial for standardization and simplification.
The evolving role of security in organizations
Organizational approaches to security have shifted from security teams taking ownership across various domains to distributing ownership of data stewardship and ownership to different business units. This allows the relevant teams to approve data access based on their knowledge of the data and specific business requirements. The goal is to empower teams and foster a sense of responsibility for data security, making security more of a leadership and orchestration role rather than a gatekeeper role.
The importance of monitoring and user-friendly security processes
It is crucial to make users aware of robust monitoring systems that can detect potential security breaches. This awareness can deter users from attempting unauthorized actions. Additionally, security processes should be designed to be user-friendly and easy to navigate. If the process is overly complex or cumbersome, users may resort to insecure workarounds. Emphasizing accessibility and ease of use can foster a culture of responsible data handling and minimize security risks.
Preparing for technological change in data stacks
As technology evolves rapidly, it is essential not to become too locked into specific features or vendors. Instead, organizations should focus on ensuring their security posture can adapt to new technologies that may emerge in their data stack in the future. This forward-thinking approach allows for seamless integration of new tools and maintains a strong security foundation.
Yoav Cohen (co-founder & CTO at Satori) joins the show to chat about why data security is hard, strategies companies use to deal with analytics over sensitive data, security and compliance requirements that data teams need to meet, and much more.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode