Ben Herzberg

Ben Herzberg

Ben is an experienced tech leader and book author with a background in endpoint security, analytics, and application & data security. Ben filled roles such as the CTO of Cynet, and Director of Threat Research at Imperva. Ben is the Chief Scientist for Satori, the DataSecOps platform.

Articles by Ben Herzberg

  1. Database Activity Monitoring on AWS Redshift
    Leverage Redshift’s native capabilities and the broader AWS ecosystem to effectively track user activity, investigate...

  2. Modern Data Access in Snowflake
    Satori's native integration with Snowflake uses Satori to enforce security policies directly onto Snowflake, leveraging...

  3. Self-Service Data Access on Snowflake Data
    Satori enables self-service data access on Snowflake, empowering users to immediately access and use data...

  4. Access Control: The Dementor of Data Security
    Data access control is often described as the Dementor of data engineers due to its...

  5. 4 Levels of an Effective Customer Data Protection Program
    In our experience working with security and data teams, we’ve consistently found that there are...

  6. Satori is a Fast-Mover in the Data Security Platform Radar Report by GigaOm
    Satori has been reviewed in GigaOm’s Data Security Platform Radar Report, with ratings of 'Superior'...

  7. The Challenges of Protecting Customer Data in a Growing Organization
    We all know customer data is growing in use in this AI-dominated technology era. But...

  8. Level Up Your Data Security Game: It’s Time to Go Beyond Visibility
    CSPMs and DSPMs alone aren't enough - for modern data security, you need both visibility...

  9. Using Temporary Credentials for Production Database Security
    How do you give engineers access to production databases in a secure way? Learn how...

  10. Data Catalog vs. Data Security Platform: Navigating the Complexities of Data Governance
    What are the key differences between data catalogs and data security platforms, and how they...

  11. The Moment We Understood We Help Companies Win With Data
    Satori changed its tagline to Win With Data. Never Lose Control to better reflect the...

  12. Strengthening Ties: Satori Joins Snowflake’s Premier Data Access Tier
    Satori levels up in Snowflake’s Partner Network tier by enabling instant, self-service data access that...

  13. Satori joins Microsoft Security Copilot Early Access Program
    Satori today announced its participation in the Microsoft Security Copilot Partner Private Preview.

  14. Satori’s Data Security Platform Sweeps 33 Badges in G2 Fall 2023 Reports
    Satori sweeps 33 badges in the G2 Fall 2023 reports and is recognized as a...

  15. Privilege Creep: The Silent Killer in Information Security
    Explore the hidden privilege creep threat, where the accumulation of access rights puts your data...

  16. Introducing Satori’s Posture Management Capability
    Satori's Posture Management provides comprehensive visibility and control over data authorizations to proactively protect sensitive...

  17. Announcing Satori’s Inclusion in the Microsoft Pegasus Program
    Satori has been included in the exclusive Microsoft Pegasus Program and is now available on...

  18. Streamlining HIPAA Technical Safeguard Compliance with Satori
    Discusses HIPAA's technical safeguards and the benefits covered organizations can accrue from using Satori to...

  19. Still Giving Constant Data Access? Consider Using Temporary Authentication
    Satori provides temporary authentication and secures access to sensitive data on a need-to-know basis at...

  20. Can You Have Your Cake and Eat It Too: Does Data Security Have to Reduce Productivity?
    Sharing data is vital to increase organizational productivity, but this raises questions about security risk...

  21. Why Security Management Can be Challenging in Postgres
    Postgres provides many benefits and has a wide range of useful native security measures, however...

  22. 6 Effective SQL Server User Management Strategies
    We explore effective Microsoft SQL user management strategies to keep your users organized, authorized, and...

  23. Why Native Database Audit Logs May Have Limits
    Native database auditing capabilities, while necessary, in some cases could increase the complexity of an...

  24. Native Dynamic Masking and When It’s Not Enough
    Some data store platforms have their own native dynamic masking capabilities. While it may be...

  25. What’s Stopping Your Organization’s Data Sharing Culture?
    Many organizations are hesitant about data sharing. We explore the problems that prevent and the...

  26. State of Data Security Operations Report 2022
    In this report, we analyze and report the results from our survey of 300 industry...

  27. Why Data Ownership is Hard!
    Data ownership is a critical yet often avoided task within organizations. While, individuals shy away...

  28. Why Don’t All Companies Apply Attribute-Based Access Control on Data Access?
    ABAC is often implemented to overcome the limitations of RBAC, however, ABAC is not without...

  29. Data Access Challenges for Healthcare Companies
    The tremendous amount of Healthcare data can generate financial benefits as well as save lives...

  30. Zero Trust For Data Access: Why Is It So Important?
    The zero trust model requires continuously authenticated, authorized, and validated access to applications and data...

  31. Agile Data Governance with Satori
    Agile data governance is crucial for organizations using cloud data stores with constantly changing data,...

  32. When Does RBAC for Data Access Stop Making Sense?
    RBAC is a useful model for access control, however, there are some instances where it...

  33. Why Data Engineers Should Take a Step Back from Cloud Data Security
    Data engineering teams can spend a significant portion of their valuable time on cloud data...

  34. Why Cloud Data Governance is Complicated
    Data governance by itself is a complicated procedure that is further compounded when performed in...

  35. Why Data Classification Projects Are So Hard
    Data classification projects are a dark cloud for data teams, often appearing randomly and redirecting...

  36. Data Security Projects Keep Data Teams Away From Their Core Responsibilities
    Data security is critical, however, this task often defaults to already overwhelmed data engineering teams...

  37. 9 Common Struggles Data Teams Face With Data Masking Projects
    Data masking is essential when working with sensitive data. However, there are a number of...

  38. How To Piss Off Your Data Consumers With Data Access Bureaucracy
    Stakeholders including data consumers are ultimately people. Having an annoying work environment reduces productivity and...

  39. Enabling Employee Access To Production Data
    Uncontrolled employee access to production environments is an operational challenge, because while access is necessary...

  40. Implementing “Need To Know”
    Classifying data as "need-to-know" is important for securing sensitive data. In this post we discuss...

  41. Benefits of a Consolidated Data Access Platform
    Managing security and access policies from a consolidated platform simplifies processes and increases visibility and...

  42. Role Explosion in Data Access
    One of the common pain points data teams experience in authorizing users to access data...

  43. Satori Is Now Available On AWS Marketplace To Simplify Secure AWS Data Access
    Making life more simple for our customers not only means striving to deliver the best...

  44. Satori Announces #Slack Integration To Simplify Data Access Workflows
    One of the most commonly used productivity tools is Slack, and the ability to control...

  45. Satori Introduces Automated Data Portals
    For years, we have been following our mission of enabling companies to deliver quicker data-driven...

  46. Simplifying Data Localization Requirements With Satori
    Meeting data localization requirements can be challenging; this post explains how to simplify them with...

  47. Satori and Cockroach Labs Partner to Provide Secure, Simple, & Resilient Data Access
    Satori and CockroachDB are announcing a partnership that will enable existing and new Satori and...

  48. Satori Announces MySQL Support For Secure Data Access
    We’re announcing MySQL support in Satori to help companies secure their data access for MySQL...

  49. Database Reverse Proxy 101
    A proxy server can be a forward proxy where the client directs traffic through a...

  50. Asking the Right Question: RBAC vs. ABAC or RBAC AND ABAC?
    Before they can access data, users must get authenticated and authorized. In this regard, access...

  51. Data Access Orchestration and Its Limitations
    In this article, I will give an overview of data access orchestration (not to be...

  52. Satori Across Various Deployment Options
    Some of the most common questions we, Satorians, encounter are about the many Satori deployment...

  53. The Dangers Lurking in Data Swamps
    The more data a company collects and stores, the more likely that data can turn...

  54. From “Default To Know” to “Need To Know” to “Need To Share”
    We all like having our cake and eating it too. In this article, we will...

  55. 5 Ways to Apply Decryption & De-Tokenization in Snowflake
    This article will discuss the distinction between tokenization and encryption and their inverses: decryption and...

  56. Metadata Repositories: Data Dictionary vs. Data Inventory vs. Data Catalog
    Data dictionaries, inventories, and catalogs are terms often used interchangeably. While they are all critical...

  57. Taking Satori for a Test Drive
    A lot of thought goes into how to help potential customers try out your product....

  58. Writing The Snowflake Security Book
    For the last few years, we at Satori have been a bit obsessed with Snowflake....

  59. ABAC: An Introduction to Attribute-Based Access Control
    Access management has evolved to incorporate need-to-share authorizations in addition to need-to-know information. The authorization...

  60. How To Accelerate Data Democratization
    The future of data democratization lies in the hands of your end-users. They are already...

  61. Simplifying Multiple Snowflake Accounts Management, Security & Governance
    One account is not enough. In many cases, organizations using Snowflake use multiple accounts rather...

  62. You Have Data, But Is It Accessible?
    As the saying goes, “data is the new oil,” as it is quickly becoming an...

  63. Satori Joins Snowflake’s Accelerated Data Governance Program
    Today, as part of Snowflake’s global Snowday event, we are excited to announce our participation...

  64. The Datamasters: Data Owners vs. Data Stewards vs. Data Custodians
    There is no such thing as a one-size-fits-all data governance framework that works for all...

  65. Using Satori & Collibra to Boost Data Governance and Security
    Satori augments your Collibra data governance capabilities and creates a synergy for better DataSecOps across...

  66. The Redshift-Tableau-Satori stack for DataSecOps in Data Analytics
    Many organizations are using Tableau to empower their BI activities for reporting and analytics. These...

  67. Custom Classification: Common Use-Cases
    In a previous post, we introduced you to our data classification capabilities. As a recap,...

  68. Applying DataSecOps Principles on MLOps
    Machine learning has been commoditized in the last decade or so, and I love it....

  69. Introducing Custom Data Classification in Satori
    When data engineers and other professionals experience Satori for the first time, one aspect they...

  70. The Tableau-Snowflake-Satori Stack for Secure Data Democratization
    Tableau is one of the most widely used BI tools which provides a wealth of...

  71. Amazon Data Lake Security with Athena and Satori
    A few years ago, when I first began using Athena, it was a magical and...

  72. 5 Indicators You’re Doing DataSecOps Wrong
    I love hiking as well as outdoor navigation. What I find especially useful for these...

  73. Redshift, Looker and Satori: Advanced Data Access
    I’m guessing there is no need to introduce you to Amazon Redshift or Google Looker,...

  74. Data Classification With Satori
    In this article, I will discuss how people perform data classification using Satori and explain...

  75. Data Classification Best Practices – Part 2
    In the first part of this article, we discussed the many reasons why you should...

  76. Snowflake & Looker DataSecOps with Satori
    In this post, we will discuss the DataSecOps advantages that Looker users over Snowflake enjoy...

  77. Data Classification Best Practices – Part 1
    Note: this is part 1 of the guide, in part 2 we discuss the questions...

  78. Limiting Snowflake Access to Specific Clients
    Before we drill down to the “why” and “how” of limiting client tool access in...

  79. Democratize Data in AWS Redshift With Self-Service Data Access Workflows
    Amazon Redshift allows companies to analyze large amounts of data, whether the data is stored...

  80. Zero to Self-Service Snowflake Data Access Management
    Let’s start with good news – if you are using Snowflake and want a simple...

  81. Snowflake Security: Best Practices for Stages
    This article is also published as a chapter in our Snowflake Security guide, covering many...

  82. What is DataSecOps?
    History repeats itself. The transition of applications to the cloud and the development of software...

  83. The Future of DataSecOps, As Reflected in RSA Innovation Sandbox
    Every year, the cybersecurity industry has its biggest conference, the RSA conference in San Francisco...

  84. Snowflake Role Hierarchy
    Snowflake’s data access modeling is different from many other databases and data warehouses. It’s funny...

  85. How to Automate a Data Inventory for AWS Redshift
    Creating and maintaining a data inventory is an important part of a comprehensive data management...

  86. Redshift Data Masking – Getting It Right
    Data masking is the act of transforming parts of data to maintain its anonymity. There...

  87. How to Monitor Access to Sensitive Data In Snowflake with Satori
    Being optimally focused is the key that helps you spend your resources better. When your...

  88. Implementing Row-Level Security with Satori
    There are moments when architecting data where you need to make decisions that will have...

  89. Data Inventory for Snowflake: Manual vs Automated
    The Snowflake Data Cloud helps organizations quickly transition from having a lot of data to...

  90. Snowflake Data Masking: Static vs Dynamic
    In today’s ever-evolving digital age, data masking is one of the most essential features of...

  91. Snowflake Data Access Journey
    Let’s understand the chain of events that leads to data access. For example, imagine you...

  92. Simplifying Snowflake Roles Management using Satori
    A few days ago, I wrote about some of the complexities of managing Snowflake roles...

  93. How to Scale Snowflake Roles Management
    RBAC, or Role-Based Access Controls, are foundational tenets of good data governance and key to...

  94. Benchmarking Snowflake Performance Using TPC-H
    Benchmarking Snowflake DB with TPC-H, including full queries and source code.

  95. How to Complete a Safe and Simple Migration to Snowflake
    Data migration is not fun. I’ve been there, done that, and I did not like...

  96. Satori Universal Data Access Control for AWS Athena
    How to get better access control & security for your data lake using Satori along...

  97. Setting up Column-Level Security in Snowflake
    Column-level security in Satori for Snowflake, simplifies data and security teams life so they can...

  98. Snowflake Row-Level Security
    How to implement Snowflake row-level access control, a step-by-step guide, with secure views or by...

  99. Analyzing Data Access Logs? Here is What You’re Missing
    Native DB access logs are useful, but using Satori to analyze data access logs helps...

  100. Data Engineers: Stuck in the Middle?
    Data engineers are often conflicted between engineering teams, security and privacy.

  101. Turn over-privilege risk into a healthy Snowflake DB permission fit
    I recently published a lengthy diatribe about the problem of over-permissive access to data, the...

  102. Effective GDPR DPIA on cloud data warehouses
    Meeting GDPR requirements is important, not only for EU companies but also for any companies...

  103. 7 Quick Ways to Improve your Snowflake Security
    Update – January 12th 2021: Following Snowflake’s preview addition of self-service account creation using the...

  104. Hardening GCP BigQuery security: access controls explained
    In the spirit of our Snowflake DB security and AWS Redshift security guides, we’ve created...

  105. Sensitive Data Isn’t The Crown Jewels
    I need to get something off my chest. It’s time for our beloved infosec community...

  106. AWS Redshift security: access controls explained
    This is part of our complete Amazon Redshift Guide.

  107. Snowflake security: access controls explained
    If you’d like to read this guide, along with additional guides to specific topics in...

  108. Enterprise data protection implementation: why so tough?
    Implementing security products, services and solutions in enterprises is intrinsically difficult, especially when coordinating several...

  109. How Satori uses Apache Drill to conquer data exploration & preparation
    “Laying out data infrastructure for a new product and big-data research is no small task....

  110. Washington Privacy Act Passes State Senate: Another Step for Privacy
    This week, the Washington senate approved the Washington Privacy Act (WPA) to advance data privacy...

  111. Why today’s data access controls don’t work for data-driven organizations
    As the world undergoes a data revolution, the ways we generate, store, access, use and...