Craig Petronella and Sanjeev Verma discuss Preveil - A highly secure, CMMC and ITAR compliant end to end encrypted email and file storage
Recorded February 2021. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.
What this episode covers
In this episode of Encrypted Ambition, Craig Petronella speaks with Sanjeev Verma, chairman and co-founder of Preveil, a zero-trust, end-to-end encrypted email and file-sharing system. Verma traces the company's origins to his earlier wireless venture and his return to MIT, where cybersecurity experts convinced him that attackers will eventually reach servers, so information must stay protected even then.
He explains Preveil's passwordless design, in which private decryption keys live on user devices, eliminating remote logins, and describes biometric protection on phones. Verma argues that encryption in transit and at rest is a myth because servers can decrypt email, and he contrasts Preveil with Microsoft's GCC High, which he says is not end-to-end encrypted and takes months to deploy. He covers ITAR rules that, at the time of recording, permitted cloud storage of ITAR data under Section 120.54 provided end-to-end encryption conditions were met, and he describes approval groups, trusted communities, and a product demonstration. The two discuss CMMC compliance, the defense industrial base, and Petronella Technology Group's bundled consulting approach.
Worth rememberingKey takeaways
- Verma explains that Preveil was not designed for compliance; its security-first approach to data protection makes CMMC and ITAR compliance an outcome.
“So, in a nutshell, we take a security-first approach to data protection, and compliance is an outcome of that.”
- Verma argues that passwords can be brute forced, guessed, or spoofed, so Preveil replaces them with device-based private keys and allows no remote login.
“Generally speaking, it can be either brute forced, or guessed, or fished and spoofed.”
- Verma argues that standard email servers can decrypt messages, so encryption in transit and at rest still exposes data to attackers, admins, and unpatched servers.
“And so, again, at the end of the day, if the server can see the information, so can the attacker.”
- With end-to-end encryption, Verma explains, servers hold no decryption keys, so attackers who breach them obtain only encrypted gibberish that cannot be read.
“If you have an end to an encrypted system, the server has no key whatsoever and can never decrypt it.”
- Verma says Microsoft's GCC High takes a taller walls approach rather than end-to-end encryption, and he describes it as complex, expensive, and slow to deploy.
“It's not an end-to-end encrypted system. It is a system that takes the taller walls approach to protection of your information seriously.”
- To limit damage from compromised admins, Verma describes approval groups that split private keys into fragments, requiring permission from multiple approvers before privileged access.
“Think of it like the nuclear launch codes. I need approval from a certain minimum number of approvers before I get access.”
- Verma notes that, at the time of recording, ITAR rules allowed cloud storage of ITAR data if it is end-to-end encrypted and the provider cannot decrypt it.
“But if, under Section 120.54, which became the law last March, a company wants to store and share ITAR data and share it with foreign, you know, subsidiaries, etc., they can do so provided the following conditions are met.”
The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.
From the show notesAbout this episode
Craig Petronella of Petronella Technology Group, Inc. and compliancearmor.com and Sanjeev Verma discuss a highly secure, CMMC and ITAR compliant, end to end encrypted email and file storage solution called Preveil that helps vastly accelerate compliance mandates with regulations such as CMMC, DFARS, NIST, ITAR, HIPAA, GDPR, and more. Be sure to contact Petronella for special discounted pricing on an exclusive compliance bundle that we've created and customized for our audience that combines the power of Preveil with Petronella's policies, procedures and security controls to greatly enhance the cybersecurity maturity level and SPRS score of your firm! Get your system security plan (SSP), plan of actions and milestones (POAMs), required policies, procedures, DFARS/NIST SPRS self assessment score as high as possible in record time, with most of the mappings already done for you!
Episode transcript
Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.
This is Encrypted Ambition, a podcast about the builders rewriting the rules. Join Petronella Technology Group as we decode the ideas, challenges, and momentum behind tomorrow's business, technology, and leadership breakthroughs. You're listening to Cybersecurity and Compliance with Craig Petronella. Visit us online at petronellatech.com.
Hello and welcome, Sanjeev. If you could please introduce yourself. Hi, I'm Sanjeev Verma. I'm chairman and co-founder of PreVeil. It's a company that builds a zero-trust, end-to-end encrypted email and file-sharing system, and it's heavily used for by defense companies for storing, sharing, CMMC.
And ITAR data, but it's a general-purpose system that is used by you know any industry for communication within the company, with suppliers, partners, etc. So that's a little bit about me. Awesome. Well, welcome. Thank you so much for that intro.
So, PreVeil. What made you think about creating something like this? I mean, obviously, Microsoft has solutions and is pretty popular in the compliance and cyberspace. But oftentimes, their solutions are expensive, and they they raise their prices. And but but where? How did PreVeil come about? What what was your methodology on that? Well, PreVeil came about from.
A very purist attitude. I'm a serial entrepreneur. Before I started PreVeil, I started a wireless communications company, and that company was started with a very simple premise that it was the year 2000, and we said, "Well, if Wi-Fi is such a great idea for."
Sharing information between computers. People want to get access to the internet on cell phones, and believe it or not, at that time people were saying, "Well, that's the craziest thing. Cell phones are for voice." Right. And we said, "No. Not only should they be about data, they should be about high-speed data." And so I started the company with the crazy notion that data ought to be available on high-speed networks.
And we became the world's second-largest supplier of what is now known as 3G and 4G. So about 40% of the U.S. cellular data network on Verizon and Sprint ran on us. So you ask why? Where did PreVeil come about? So I ran the company for about 14 years. It was a publicly traded company, and I went back to MIT, my alma mater, and was intrigued by cybersecurity.
And I there, I met two of the world's top, you know, cybersecurity experts. My co-founder now, Lukas Popa, and Nikolay Zeldovich, both were professors at MIT. Lukas now at at UC Berkeley. And in essence, they educated me that the what we now recognize, but was not that obvious at that time.
Was that the traditional approach that virtually everybody, Microsoft, Google, and everybody takes, is the approach of building walls around information, and those walls are of software, obviously, to prevent the bad guys from getting to the information. And while those are essential, you obviously want to prevent bad guys from getting to the information.
It was clear in the research community and the intelligence community, even at that time, that despite your best efforts, the attackers and the adversaries will eventually get to the information. So, what they were saying is that the right security systems ought to be those that protect information even when the attacker gets to the servers where it's stored.
Even if the attacker breaches your password, even if the attacker breaches the admin who has access to to your information on the server or in the user account, and those were what were the core principles that sort of guided us and said that's what the world needs, and we were ahead of the time both in the wireless systems and in in PreVeil.
But ultimately, that's really how the system was created, and we decided to go and make it simple because security was complex. So we said, "Well, nothing complex is going to be used." So we're not going to compromise the key principles of protecting information, even when the adversary kind of gets to it - a zero trust principle.
But also to make it simple for people to use it with everyday communications in files, emails, etc. And that's really how we came about PreVeil. It wasn't our goal to build a system for compliance. It turns out that because PreVeil is a really highly secure system, and it is easy to use.
It turns out it's an excellent system for CMMC and ITAR compliance, but we never really went about and saying, "Ah, let's go build something that will be in compliance with regulations." So, in a nutshell, we take a security-first approach to data protection, and compliance is an outcome of that.
And that's how we were born out of MIT. We were looking to build something great that would transform security, and hopefully, PreVeil plays a part in in doing so. And certainly, when we look at the environment today, I think there's every reason to believe that systems like ours are sorely needed.
Absolutely, and and one of my favorite things about your system is the passwordless technology. Not having to deal with passwords. I mean, we're humans; we are terrible with passwords. Yeah. Well, it's again back to the core principles of PreVeil. The two core principles were number one that no matter how well protected the system, the attacker is going to get to it.
They'll get to the the servers. They'll break the passwords. You can come up with complex passwords, and I'll speak more to that. And they'll break the admins who also are accessing systems through passwords. So passwords are particularly deadly because no matter how complex a password you you create.
Generally speaking, it can be either brute forced, or guessed, or fished and spoofed. And if the attacker compromises your password or your credentials, you get access to the information. And the second aspect of passwords is that we all live in a world where we want anytime access to information.
And so, consequence of these password-based systems was that you could log in remotely. In fact, that's exactly what you're seeing with the attack through SolarWinds on the U.S. government. The attackers aren't in the Pentagon or in the Department of Justice. They're in because they have user credentials, infiltrated the networks.
So, from a passwordless system, here's how PreVeil addresses it, and we'll come to the rest of the elements of it. But first of all, any access credential should not be brute force guessable. And so, with PreVeil, your password access is actually replaced by an access through your private decryption key.
So, for each user, there's their email address that serves as their identity, just like your phone number could. But in PreVeil, we use email address, and attached to it is a set of public-private keys. So it's your private key that serves as the authentication mechanism and the decryption mechanism for you. So why is that good? So number one.
the the decryption key, the private key, is equivalent to the number of atoms in the universe, not just in our solar system, not on Earth, but the entire universe, which has a hundred billion galaxies, each with a hundred billion stars, and we're one of them. So, no amount of compute power can guess that right now. So, you can't brute force it. The second important aspect is that the key.
Is tied to your device, so your private key is stored on your device. So, let's say you're accessing PreVeil, and your user, you have PreVeil on your computer and on your phones and your iPads. Your private key will be on all of them, and you don't need to know anything about it. It's automatically there. In addition, there's a device key, one for the phone, one for the computer, one for, say, the iPad, which are different.
So first, you can't guess these keys, and it's a combination of these keys that gets you access. The user doesn't have to type anything, so you don't have to remember any password. And the third and most important thing is, since these keys are on your devices, it's only your devices that can access your information. There's no remote login, so you don't have adversaries that are halfway around the world.
They are remotely logging in because they have brute forced, or stolen, or fished, or spoofed your password. And from the user's perspective, it's one less headache that you don't have to remember anything. You've just got a secure key on your system. And I'm sure viewers will probably be looking for, well, how is that key protected? Quite well. So if it's on the phone, it's in the app.
And it's got biometric authentication, so even if your phone's available to the adversary, and remember, it has to be physically available to them, and they've gotten into the phone, still they can't get at your private information because the app has biometric authentication. On the computers, it's under you know encrypted storage on an admin privilege you know account. So again, while it's not impossible.
It is extremely hard because now the attacker has to physically get to the machine or fully get into it, which is a really difficult thing. And again, you have to do it user by user by user, and that's why the passwordless systems are are important. And I'll say more about this when the passwords are the passwords that belong to the admins. And so we'll speak more about how we protect admins.
Because if you compromise a password of an individual user, you just get one user's account. But if you compromise an admin, you got the entire organization. So that's how we sort of help with a passwordless system, and that's really where modern security is headed right now. Absolutely, yeah, and.
I think the recent headline: the DHS is now adopting CMMC compliance. Now, so I think that there's going to be bleed over into that. You know, with the CMMC, I think it's so complicated. I think it's it's a great methodology. I think it's awesome that they now require that third party audit of systems and things like that.
And I love what you've done with Preval, especially with all of the scoring with SPRS. You're able to really elevate by purchasing Preval and implementing Preval properly. You can get your score from a negative to a positive 65 in pretty much record time, and then with some more configurations, bring it up to 85. One of the the questions I had is.
One of the challenges in the CMMC space is, while you've done a fantastic job in securing the data with passwordless technology and zero trust, as well as the email, a lot of folks have data all over the place. You know, like in their financial systems and things like that.
Is there? Do you think, with with your awesome passwordless technology, that there would ever be in the future some type of API or way to extract data out of other systems and put them into the PreVeil Secure system? Well, this short answer of it is that we do offer APIs right now, and you know.
While it's true that, you know, certainly for very large organizations, there are complex, you know, systems that are holding financial data, etc., one has to simplify it. CUI is going to be, you know, largely design information, you know, special defense contract information, presumably also starting with the DoD originating it.
And so, when the DoD transmits it to you, you are in good stead by putting all that document design data, etc., in Prevel Drive, and use it with whatever application, and and then sharing it on on email if that's what you want to do, but.
Using APIs, it has always been our ambition, and our vision, and our hope that the security principles that underlie Perio, which we've developed into a very simple email and file sharing system, aren't limited to those. But the same security principles are applied to the way you store data in the cloud for whatever application that you're using.
And therefore, we have always made available APIs. And so, you know, as time goes by, whether it's other applications that you're using, or it is financial systems that you're using, you can always call those APIs, and you don't have to even invent the wheel. You know, you call an API and say, you know, store my data encrypted.
In simple terms, and it'll do so, and it'll do all the generation of the encryption keys, store it, share it. All of that is done with a single command, as opposed to, you know, creating a system that can, you know, create the keys, find the right places to store, change those keys, make them available to admins, and so forth. So, absolutely, you know, PreVeil does make that available.
But we'll take baby steps, and again, CMMC should also be looked at, saying, "Let's consolidate and secure our CY and ITAR data first, and then we've got the majority of sensitive information protected, and then we go and get better at it, and we now look at other applications and other pieces of information, and slowly."
Make our way towards, you know, more and more of our information, protected with modern principles that make it really hard for the adversary to get at it. Yeah, well said. I I think that that's absolutely true. I I think that you know a lot of people with the CMMC they're confused, they don't know where to start. So I think PreVeil is awesome to start with securing the email and the data storage because, like you said, it's where most of the.
The CUI and FCI is living, so let's secure that first. And then, you know, I call them puzzle pieces or onion layers. You know, there's several layers to this. And you know, starting off with with secure storage and secure email, and then moving off into the other pieces of the enterprise. Where you know, where else does CUI live? Where is the spillage? What you know, policies, procedures, security control layers, etc.
And then kind of expand from there. Obviously, defars and the interim rule compliance has been, you know, a big thing. At November 30th of 2020 was the deadline for that, and you know, we're still consulting with a lot of folks and recommending PreVeil as a starting point for them to accelerate their.
There work to be done because, you know, quite frankly, a lot of them have a lot of work to do because they haven't done very much in their organization. So there's a lot of structure and workflows that need to be built. But I'm also noticing that there's other industries. I know when you built PreVeil, it really wasn't, you know, focused on CMMC. But I'm noticing that.
Auto dealerships that deal with, you know, sensitive public information could benefit from PreVeil. Also, HIPAA and you know HIPAA compliance and healthcare compliance, you know, could also benefit. What do you think about those compliance regulations? Well, we think that you know.
What you're saying is absolutely correct. That you know, Proweal is a general-purpose email and file-sharing system. In fact, we've designed it such that it's a free system for anybody to use. So, if you are an individual, it's simple enough. Just like you, if you want to send a secure message, you choose Signal or WhatsApp.
You can choose Prevel for all your email and files, and it's simple enough that you know any user basically can get and use Prevel with any email address, whether it's from Google or Yahoo or whatever. So, our goal and ambition has always been, and our guiding principles have always been that Prevel is a general system that any.
Industry ought to be using. It's a rather unfortunate reality that most people gravitate towards systems like ours through the compliance mandate, rather than approaching them from the fact that they ought to be securing their information.
For the sake of securing it, because it's their information and the client's information, and so forth, part of it is just understandable. It's human nature, you know. We are, as a human race, evolved such that if I see somebody with a weapon in front of me, I perceive the threat instantly. I said, "Oh, there's somebody who's going to attack me," and I am going into a defensive mode.
We're not that good in actually responding to an enemy or a threat that is unseen, and cybersecurity is just that. You know, it's not that it occurs to you on a daily basis. The adversaries are sitting ten thousand miles away.
You don't see them. You don't see their face. Well, also because most people don't have any type of monitoring to see those threats, right? Absolutely. And so you're not cognizant that there's an organization of you know twenty thousand people out there snooping at your network and trying to get in. And so therefore.
We postpone that, you know, to the next day. Okay, yeah, I understand conceptually security is important, but let's go go forward. And I think that the CMMC and HIPAA and personal information compliance mandates sort of are addressing that very natural human frailty. Before this, we all knew, as part of the day, that you know we're working on sensitive, you know, information that we ought to be taking extraordinary steps.
To safeguard it, but not very many companies actually had the know-how or actually took the steps to. Well, I think that they don't. I don't think they intentionally mean to do something bad, but but I think it's an educational concept around people have a false sense of security, especially with email. They think that if I'm just going to email you something.
That it's just going to be secure and get to you, but the reality is they don't understand all the hops that it goes through and how it's like a postcard. Absolutely. Well, I think as I mentioned, that's why I was saying that part of it is you're not cognizant of the magnitude of the threat, and most organizations weren't trained to recognize what you were saying that whether it's files or emails, you know.
They've heard things like, "Well, email encrypts in transit and at rest," and they kind of think, "Oh, it's some kind of encryption going on, so it's secure." But the bottom line is that, and we'll go into it more detail, why encryption in transit and rest is is the biggest myth of all security. But people aren't ready to do it. So compliance mandates, by putting some consequences and putting some requirements.
Force companies to do what they ought to be doing, and I'm absolutely reiterating what you are saying. It's not that they didn't have; they were maliciously ignoring security. It's just that it's a combination of the threat's not apparent and the knowledge is not apparent to the the company on what constitutes good security.
So, just as CMMC is doing, it's driving a sense of urgency in the defense industry. HIPAA and other compliance objectives do so for other industries, and PreVeil happens to be an excellent system for whether you're a law firm or a financial firm, or a hedge fund or a medical company. But I also submit, just as an individual.
If you've got information, use the free version and protect it, because there are a ton of people interested in taking advantage of of what you know folks are doing as a business and as an individual. So it's a broad system with use across multiple segments, defense being one of them. Well said.
Talk a little bit more about the the you mentioned the encryption of email. You know, a lot of people think that oh, well, it's TLS or SSL encrypted, I'm safe, right? Yeah. So I think, if I may, I will speak to it, but I might even actually show you. Yeah, absolutely. An animation. An animation that. Could you enable screen sharing, please? Absolutely. One second.
There you go. So, I'm going to, with your permission, share my screen and show you, you know, the fundamentals of security. So, when you have information on a traditional email.
That email absolutely does get encrypted in transit. It gets encrypted on your device, and it gets to be sent to the server where it's stored, which could be a cloud server or your Exchange server on premise. And it is also correct that that email may very well be encrypted at rest. So you've heard terms encryption in transit.
In encryption at rest. So, take a look at this little animation. Your email goes encrypted in transit, stored encrypted at rest. Then it gets hopped over to the receiving company's mail servers. But what is not understood is that these servers, whether they be for O three hundred and sixty five or G Suite or any of the services.
Essentially, have the ability to decrypt that email. So when it goes encrypted in transit, the server receives it and can open it. It does processing on it. Oftentimes, they render the emails, particularly on Gmail. They're looking at it for keywords. Often, in certainly the Gmail of yonder used to, you know, sell advertising based on your email.
And that's the issue because if the email can be seen on the server, then the attacker can get at this email, and therein lies the second conundrum. So you physically think that, oh, the attacker's got to get to the server, and that's a really hard thing to do. And it's not as challenging as that. If the email is seen on the server, whether yours or the receiving company's.
Suppose the server didn't have the appropriate security patches that were up to date. A new security patch is released. The attackers look at it. They get into the server, and now suddenly, since the email is visible there, they can read it. Second, that email is a user's email. If you compromise the user's password,
Again, you can read the email. Third, if you're an admin who is managing that company's servers, so you've got an IT admin, that admin can read all those emails. And if I breach that admin, I can read those emails. And then finally, suppose that there was a bug in the firewall that was protecting the server.
You can breach that and get to it, and that's exactly how the big breaches occurred. So, when the breach occurred with Amazon's storing of Capital One's data, it was not Amazon's fault, but an admin found a vulnerability in a firewall, got to the servers, and they could read all of Capital One's information.
Same things happening in the DoD, not the DoD, the the the United States government. I want to clarify: the DoD wasn't breached; the U.S. government agencies were breached, including, you know, Justice Department, Treasury, etc. With the Solar Winds attack, the information is visible on the server, and so can so the attacker can get to it, and that's the big myth.
Of encryption in transit and encryption at rest. The final thing to also remember is, even if you say that I have taken great measures to protect my server, when the email goes from your server to the receiving company server, which is exactly what's happening when a prime, for example, communicates with suppliers, those servers at the suppliers aren't as well protected.
And so, again, at the end of the day, if the server can see the information, so can the attacker. And we can now have the basis to see how to address this using, again, end-to-end encryption. So let me show you that. So when you recognize that no matter how hard you try, the attacker can get to the server.
You are now forced to reckon with a system which says, "Look, since the server can be breached, let me encrypt my email or file on the sender's device, and it shall remain encrypted at all times on the server and directly only delivered to the recipient." The big difference here is, unlike encryption and transit, and.
Encryption at rest. If you have an end to an encrypted system, the server has no key whatsoever and can never decrypt it. So, even when the attacker gets to the server, all they get is encrypted gibberish, which no known technology can decrypt because the keys to decrypt it are on the sender's device and on the recipient's device.
And that's why the NSA, when it was counseling, you know, agencies in the government and outside, on what's the best way to protect information, in the wake of the pandemic, they said, you know, use end-to-end encryption. So that's the first point to understand on why that end-to-end encryption achieves the goal of, you know.
An attacker, even if they get to the information, not really getting anything, versus encryption in transit and encryption at rest, really saying, "I got to be right 100% of the time." And if you are wrong, even 0.1% of the time, and you always are, either through admin breaches, server breaches, password breaches, the attacker gets in, and once they get in, they see the stuff.
Right. No, that that's awesome. Thanks for showing that too. That was a great overview and and demonstration. So thank you for that. Yeah. So where do we where do we go from here? Like, obviously, this is solving a bulk of the problems. You know, like you said, NSA recommends end end encryption.
Obviously, Microsoft has the the GCC suite, right? Which is the really hard to get. There's only like six or seven, I think, resellers in the United States where you can buy the GCC High version for DoD. That's manned by U.S. citizens, background checked, et cetera, to accommodate for CMMC and NIST compliance. But isn't it true that that solution's still not end-to-end encrypted?
It's not an end-to-end encrypted system. It is a system that takes the taller walls approach to protection of your information seriously. So it's saying, "Okay, I am going to guard the servers with better technology."
And then limit access to those servers to U.S. citizens. Put those servers on U.S. soil, etc. PreVeil's approach is similar to them in the sense that you know our default servers for government clients are Amazon Web Services GovCloud, also made U.S. personnel.
Also on U.S. soil, also on sovereign land, also having state-of-the-art protection, but the PreVeil system, unlike GCC, doesn't rely on the notion that oh, I've done all these good things, and so the attacker will never get to the information. They will always get to the information, but when they get to the information in the PreVeil system.
Then they get nothing. And in such systems, when you're thinking about security, you've always got to assume the worst. So we assume that even PreVeil employees could be untrustworthy. There is a possibility that a PreVeil employee tries to get access to the information.
There's a possibility that there is a U.S. citizen who is at AWS GovCloud or at GCC High who, for whatever reason, decides to go and try to get access to the information. These things have happened in the past. Absolutely. The difference is that with PreVeil, the system, since it's designed to trust nobody, not even PreVeil.
And the information is encrypted at all times. Therefore, the information is secure. So, again, I want to make sure that the viewers understand that your information on PreVeil is also on a government cloud, manned and accessible by U.S. personnel on on the GovCloud part of it. And GCC does a great job with it. It's a capable system, one that we respect.
But at the end of the day, you know, we feel we take security to the point where even if that is breached, your information is safeguarded. So that's where you know we we bring an approach, and we make it simple for small to medium businesses to adopt it very quickly. Because GCC, because of the complexity of the system, is hard to deploy.
It takes months to deploy. It's an expensive system, and I think Microsoft, to be fair to them, acknowledge that. They have said in their latest communiqué yesterday, "Yeah, it's not going to be simple. It's not going to be inexpensive." And what PreVeil says is, "It is inexpensive. It is simple. Deploy it in a day. Just overlay it over your O three sixty five or G Suite or whatever you've got."
And you get best of both the worlds. You get obviously the protections of you know a very well protected cloud on where the information is stored, but the system, because it's end-to-end encrypted, doesn't rely on that. You know, even if it's breached, and we believe that at some point all these systems will be breached somehow because the adversary is very, very capable.
Then all they get basically is gibberish, you know. So that's the difference in approach. And I like that approach too, because you know a lot of the threats are insider threats too. You've got rogue employees. You've got you know system administrators that have a lot of knowledge in their head, and you know maybe their their latest salary negotiation doesn't go so well, and they you know they they want to never know. Yeah.
That's the thing that you know. You just saw what happened at Twitter twice. First, Saudi Arabian intelligence, we believe, got access to the records of communication and tweets in response to the Khashoggi, you know, murders. Now, the folks that provided the information were admins within Twitter.
Similarly, there was another breach recently where the Twitter accounts of former President Obama and others were compromised. They were Twitter admins, and there's every reason to believe that Twitter takes security seriously. They have put processes, technologies, countless people to go and protect that information. It's not that Twitter is at all a lax organization.
They are doing their best, but it is a fundamental vulnerability that they are relying on admins to protect and safeguard information, and the servers can see the information. So, therefore, you got a hole. Whereas in a PreVeil system, no single admin can access the information, and if you get to the server, you get nothing.
And that's the reason why these modern zero trust systems, you know, work. And in essence, I mean, you're seeing that with messaging as well. If you really want to send a secure message to somebody, you're not going to go and send it as well-intentioned as Apple is on an iMessage. If you want truly to have a secure communication, you encrypt end-to-end on a Signal.
Or on a WhatsApp, because similar to what we're saying, no passwords can breach that. The providers of the service can't access it, and that's really also why the State Department issued the regulations on storing and sharing ITR data. Very specifically, they said.
Till now, you're not allowed to store and share data on a cloud service. But if, under Section 120.54, which became the law last March, a company wants to store and share ITAR data and share it with foreign, you know, subsidiaries, etc., they can do so provided the following conditions are met.
Number one, the cloud service is end-to-end encrypted. They recognize it. Can they work with the NSA to come up with this guideline? So it's encrypted by the sender and can only be decrypted by the recipient. The cloud where it's stored cannot decrypt it. Second, they say the cloud provider must not have any access to either decryption keys.
Network access codes or passwords, and third, they say that they should use trusted algorithms like FIPS one hundred and forty two to to encrypt it, and that's exactly what PreVeil does. Again, we didn't come at it to design the system to comply with ITAR. We had designed these because those are fundamental security principles, and of course, ITAR.
Adopted them, and that's really the way to kind of think about it. Take a security-first approach. I also want to emphasize that you know, as an industry, we have a choice right now. Yes, the DoD is mandating that we comply with CMMC, and it's a good thing. I applaud Katie Arrington for.
Pushing this, we also have a choice where we can choose whether we approach CMMC security, CMMC compliance with the security-first principle, or through a check-the-box principle. And I would argue that ultimately.
We've got to take a security-first principle. And what we really like about PreVeil is that it makes the security-first approach also the easier and the less costly approach. It is a lot easier to go on a system that is a lot more secure and a lot less expensive. And so, in this case, we really are to be pursuing a security-first approach to compliance.
And it's the same with messaging as well. It turns out that the most secure messaging systems are also the easiest to use, which is WhatsApp. Anybody can start with it in minutes, or Signal, and same with Prevel. So you know we gotta see things clearly, and if we take the approach of a security first, DIB first.
We have a unique opportunity where the solution that you know we're fortunate enough to provide also is the easier and the less expensive, you know, path forward. So that's really what we we love about where we are today. Absolutely, yeah. And I've taken what you've done and mapped it to the system security plan and created policies and procedures around that.
To also further along and make it easier for the little guys to to comply with the CMMC mandates, and you're doing a great job with that, Craig. Because ultimately, when you look at CMMC, those that love and revel in complexity will obviously find a great deal of complexity. It's 17 domains, 130 controls, and so forth.
But life is not about boiling the ocean, and Einstein didn't figure out, you know, the secrets to the universe by making things complex. You got to simplify, and what you're doing is simplifying things. So the path to CMMC compliance is start with a foundation technology to store and share your CUI in a manner that is compliant with CMMC.
Or one of the ways to do it, GCC certainly is an option. You pick whatever is your favorite, and second, work with the consultant like yourself, who then addresses the remaining gaps that are not addressed by PreVeil or GCC, and then you provide policies and procedures, and in some cases, supplementary technologies, to your clients, and.
Through that simple combination of underlying technology like PreVeil, a basic system security plan, and augmented policies, procedures, and technologies from Petronella Inc., you've got yourself in in a shape to be ready for you know facing an audit, and that's the three-step process that almost any company.
Ought to be, you know, looking at. And here, I want to be again careful in saying, even if you go the GCC route, because it turns out it's a better solution for you for whatever reason. It's the same simplifying principle. It's the basic system, policies and procedures plus a consultant like yourself to guide them through what's remaining, and that's what puts.
The Dib Company in the best position to confidently address CMMC. Yeah, what we've done too to further that along is we actually launched a whole separate website called ComplianceArmor® dot com, where we've built out what I call these onion layers or these puzzle pieces, and we've packaged PreVeil with Petronella Services.
Policies, procedures, and you know, everybody's at different places with this, and they're at different budgets and timelines. So we try to make it easy for them to adopt, and we always recommend starting with something like the PreVeil bundle that we've created because we've secured that relationship with you guys and that partnership, and then we've bolted on our consulting services to just make it - it's the easy button for folks. We appreciate that, and I think that you know.
Again, when you look at the defense industrial base, we're looking at potentially fifty thousand companies that will be required to get level three compliance, and those companies are structured in a pyramid. They are the big primes at the very top, and arguably there is probably a thousand of them. For the most parts, the very biggest primes were already CMMC ready because they were sophisticated organizations with big budgets.
And sophisticated security personnel, so they're pretty much there. And I would submit probably exceed CMMC you know guidelines at level three already. But the remaining forty nine thousand organizations are organizations from five hundred people down to five people, and for them, especially the ones that are.
Twenty, fifty, hundred people - they don't have compliance people. They don't have sophisticated IT staff. They're in the business to do what they're doing, and not learn about even cyber security. Much as it's dear to my heart, it shouldn't be their primary focus. And so, what you're doing is for those forty-nine thousand companies, you're making it simple for them.
And you're making it inexpensive for them, and that's wonderful because you get them on a platform that is deployed in a day versus months, which is what we offer with Preval. And the second is you offer policies and procedures that you've sort of pre-worked and built into a core system, such that the custom work that you've got to do on a client by client.
Basis is less and less, and so you can help a lot more companies. And from a company's perspective, it's also simple. Well, let me deploy Preval, Craig. I'll work with you, get the basic policies and procedures. I am pick your number, eighty, ninety percent there. You help them with the remaining twenty percent, and now let's go face the audit process. And now the goal of CMMC has been achieved because.
You've created fundamental security, and you have done so relatively quickly for the the client. And and and that's wonderful because as a nation, we are better protected. As a defense, you know, industrial base, we are better protected, and it wasn't.
Like boiling the ocean. It wasn't that it's taking you know years and you know oodles of dollars to kind of do that. So that's where innovation and you know sort of leadership come together. And again, I can't applaud Katie Arrington you know enough for setting the tone, for seeing the big picture, putting this you know framework together, and then.
As always happens in America, no matter how hard the challenge, the private sector rallies around to come up with solutions that are efficient, inexpensive, etc. And we saw the same with COVID. Yep. Nothing like you know we saw a big challenge. Naysayers would have said it can't be done, wouldn't be done, it'll take five years. Yep. And in nine months, there were vaccines from multiple companies.
And it wasn't that they were a trillion dollars. They were, you know, built with the right budget. And CMMC is the same thing. So we're in a good spot right now. A lot of work to be done, but we're doing the right things together. And I appreciate what you and your organization are doing to help the SMBs. Absolutely, absolutely.
Well, let's dive in. If you if you have a few minutes, if you don't mind, let's just do a quick overview of the solution. If you don't mind sharing your screen, and sure, I'd be happy to. So let me share my screen here. So as I mentioned, we take a security first approach. I already shared with you the basic principles of end-to-end encryption.
I also shared with you the prevailing system, having no passwords, and the fact that, as you see on the right, your private key on your devices is what allows you to get access to your information. So there can be no remote login.
The third principle that I'd like to share is how to prevent the worst attacks from occurring, which is if your admin is compromised. As you see in a traditional system on the left, there's an admin, super user privileges. The attacker goes after the admin and gets everything that the admin has. This is exactly what is happening with the current attacks. In Preveil.
As an enterprise system, you're absolutely allowed as an admin to get access to a particular user's emails or files, but also the organizations, for example, for e-discovery. But you cannot do so by yourself. So there's a notion of what's called an approval group. Think of it like the nuclear launch codes. I need approval from a certain minimum number of approvers before I get access.
To privileged or encrypted or confidential information. So, if you see this little animation, what happens with the approval group is that the user's private key is broken up and distributed amongst the group of admins or approvers. So, each admin now has only a little fragment. So, if they go rogue,
Or if they are compromised, they cannot access the information because the information needs to be decrypted with the full key, and the admin has only partial key. But when they get approval, as this little animation is showing, the key gets constructed. You can decrypt the information, and then system rekeys itself. It's important to recognize that this.
Keying and rekeying and breaking up is any n out of m. So you can set an approval group that has eight people, but you require permission from only three, so that if people are on vacation, etc., it doesn't bother. And then the final aspect of the system is what's called trusted communities. So you define your organization's domain and that of your suppliers and certain trusted partners.
And now your CUI and FCI and ITAR data just flows within this trusted community. Even if I'm an outsider who has a PreVeil account, I can't communicate in, and information can't be exfiltrated. And that's what makes you now ring fence your CUI and make it secure to attack on the servers, passwords, etc. Let me now quickly show you PreVeil.
In action, so as you're familiar with GCC, you're required to rip and replace O three sixty five or G Suite. With Preveil, you stay on those. So I'm going to show you email first. Here's your existing system, could be O three sixty five or Exchange. Here's a user, her name's Alice, and these are her regular emails. Obviously non-compliant.
You can see even Microsoft sending Valentine's Day greetings. So, can the attacker could be phishing and spoofing you? When you join Preval, it adds an encrypted inbox with the same email address. You don't need a new email address, and this is where all your CUI-compliant emails, etc., come. So, you deploy Preval to those users in your company that access CUI or ITR data.
And the email is accessed just as you are used to. You open it, no special site, no nothing. You say thanks. You'll notice that it says that it's encrypted, and you send it. What happens when you are sending an email? The system has auto-encrypt capability, so you create an email. Let's say you're sending it to somebody, Ed Murphy, who's on a Gmail system outside the company, but handles the UI.
The moment you type his email, notice what happens. It switches automatically to encrypted mode. And here's a demo for Petronella. And you can put CUI, you can put ITAR, you can put you know FCI in this.
And all the capabilities that you're used to in Outlook just work, and you just send this thing. So, at the other end, I said that Ed Murphy is on a Google account, also non-compliant. But Ed says I'll receive my emails. Emails.
And so, what Prowell does is adds a secure messages tab. Here's the regular inbox where non-compliant messages on Google. Here's the secure messages, and here's the email that I just sent, which has CUI and FCI. This email can't be compromised, even if your Google password's compromised. It can't be seen on any Google server.
The admin can't compromise it by themselves, and obviously, the server is only having an encrypted copy, and that server is on Gulf Cloud. And the second aspect of Prevel is file sharing. So we've got this thing called Prevel Drive. When you create your Prevel account, it'll create a folder. Here's my little demo folder here, and you basically go and create.
Subfolders in there, and this is where you basically go and put your CUI and FCI. I'll show you on the left my phone. So here's my phone. Here's the PreVeil app. Again, it's got biometric authentication, and here are all the emails that are sent for Alice. And at the bottom, you'll see PreVeil Drive.
So notice that if you create a folder on the computer, it's mirrored on your phone because it's got your key. If you, for example, have a new project, you open it. You've got the same files on both sides. And now, if you wanted to, for example, add a new file to it with CUI, you simply drag and drop it.
Notice what happens. It basically gets encrypted, uploaded, and you'll see it synced with your phone. Any changes you make to the document are synced, and then you can also share this. So, if you, for example, are on the phone and you say share, you can add the email address of the recipient, and if you want the recipient to further share.
You say edit and share, but if you want the recipient to only view the information in a browser and not even download it onto their computer or phone, you say view only, and that's really what happens. And you can do the same thing by simply right-clicking and saying share on the on the computer, and you can also do the same on a browser. So again, you can access Preview on a browser.
Here's the new Navy BAE project. You'll see the project has people on it. That means it's shared. When you say share, it shows you who it's been shared with. You can add people to it, and more importantly, you can set a recall date. So you can say, "I am sharing for say two days or six months." And think of the use case.
If you are communicating with a supplier, and you have a project for six months today, if you share something, the supplier has the information in perpetuity. You may not even be doing business with them, and if they get hacked, your information's gone. But with PreVeil, you set an expiration date, and when you set the date, say for example, for this case, February 26th, tomorrow.
After tomorrow, the information will be deleted from the shared person's computers and phones and recalled. And that's a quick view of PreVeil. It's simple from an admin perspective. You can see the users down to the devices. So in conventional systems, you don't know where people are logged in. Here, since a key-based access, you can see that Baker.
Is only able to access his account from his PC and these three phones. Everything is logged, obviously, for compliance perspective. These are tamper-proof logs. You can set up trusted communities by simply specifying the domains that you trust or email addresses, and now communication can only be be between the trusted community and.
As I had mentioned, if you've got compliance and you want to look at a compliance request, you want to look at emails for certain users or the entire organization. Say you've been sued for e-discovery; you say, "I want these emails and files." You don't have the keys to them, but it'll say, "Go get permission from the approval group."
Once you get the permission, you get the decrypted emails and files, and that's a very, very quick overview from both a usability perspective. As a O365 user, as a G Suite user, you saw PreVeil on mobile devices, on browsers, and you saw PreVeil drive on all these devices, and an admin view to it. So that's in a nutshell.
A very quick overview, and this system can be deployed as Craig you do all the time in a day for a typical organization. It takes an hour. You onboard people, and and off you go. That was fantastic. Thank you. Just one quick question on the the secure, PreVeil data drive storage. I'm assuming it's bit level and doesn't really care what the data is. Is that accurate?
That's correct. It's it doesn't care what application the data is. Any application data is encrypted and stored over there, and accessible. The only constraint is on the view-only privilege. When you are saying you cannot download and it's only rendered in a browser, then the browser will render. You know, Word, Excel, PowerPoint.
PDFs and the popular formats, but you can't obviously at this time, on a view-only basis, just look at, say, a CAD file. But if you wanted to look at a CAD file in any other format, like you know, edit and share, it's all encrypted and stored, and you'll have access to it on a local copy, and you can open it and access it. So.
We we provide you with the ability to use any file of any format. That's awesome. Well, thank you so much, Sanji. This has been fantastic. I appreciate Craig the work that you're doing. I appreciate the time that you have advocated and allocated for us. And I wish you well in in the efforts that you're.
Taking with great seriousness to to protect your clients, and we love working with you. Thank you. Yeah, absolutely. Same here. I think your solution's awesome, and it's become a part of our culture here. We use your technology as well, and we encourage others in our ecosystem to use it. Like you said before, it doesn't have to be CMMC or defense contractors. It could be other businesses that we help that are in regulations like HIPAA compliance or GDPR, other reg.
Absolutely. Well, thank you again. Love what you're doing, and look forward to doing more and more of it. Absolutely. Yes, us too. Well, thank you again. Have a great rest of your day, and we'll see you on the other side. Will do. Thanks for listening to yet another episode of Cyber Security and Compliance with Craig Petronella.
Listen to all of our podcasts on Apple, Google, and Spotify. Visit us online at petronellatech.com to book a meeting with Craig about your business. That's a wrap on this episode of Encrypted Ambition. Subscribe wherever you listen, and if today's guest inspired you, leave us a review or share the show with someone in your circle. To learn more about how we support innovators with AI, cybersecurity, and compliance.
Head to petronellatech.com. Thanks for listening, and remember, the future favors the bold.
Never miss an episode
New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.