Ben Herzberg
Ben Herzberg
Ben is an experienced tech leader and book author with a background in endpoint security, analytics, and application & data security. Ben filled roles such as the CTO of Cynet, and Director of Threat Research at Imperva. Ben is the Chief Scientist for Satori, the DataSecOps platform.
Articles by Ben Herzberg
Database Activity Monitoring on AWS Redshift
Leverage Redshift’s native capabilities and the broader AWS ecosystem to effectively track user activity, investigate...Modern Data Access in Snowflake
Satori's native integration with Snowflake uses Satori to enforce security policies directly onto Snowflake, leveraging...Self-Service Data Access on Snowflake Data
Satori enables self-service data access on Snowflake, empowering users to immediately access and use data...Access Control: The Dementor of Data Security
Data access control is often described as the Dementor of data engineers due to its...4 Levels of an Effective Customer Data Protection Program
In our experience working with security and data teams, we’ve consistently found that there are...Satori is a Fast-Mover in the Data Security Platform Radar Report by GigaOm
Satori has been reviewed in GigaOm’s Data Security Platform Radar Report, with ratings of 'Superior'...The Challenges of Protecting Customer Data in a Growing Organization
We all know customer data is growing in use in this AI-dominated technology era. But...Level Up Your Data Security Game: It’s Time to Go Beyond Visibility
CSPMs and DSPMs alone aren't enough - for modern data security, you need both visibility...Using Temporary Credentials for Production Database Security
How do you give engineers access to production databases in a secure way? Learn how...Data Catalog vs. Data Security Platform: Navigating the Complexities of Data Governance
What are the key differences between data catalogs and data security platforms, and how they...The Moment We Understood We Help Companies Win With Data
Satori changed its tagline to Win With Data. Never Lose Control to better reflect the...Strengthening Ties: Satori Joins Snowflake’s Premier Data Access Tier
Satori levels up in Snowflake’s Partner Network tier by enabling instant, self-service data access that...Satori joins Microsoft Security Copilot Early Access Program
Satori today announced its participation in the Microsoft Security Copilot Partner Private Preview.Satori’s Data Security Platform Sweeps 33 Badges in G2 Fall 2023 Reports
Satori sweeps 33 badges in the G2 Fall 2023 reports and is recognized as a...Privilege Creep: The Silent Killer in Information Security
Explore the hidden privilege creep threat, where the accumulation of access rights puts your data...Introducing Satori’s Posture Management Capability
Satori's Posture Management provides comprehensive visibility and control over data authorizations to proactively protect sensitive...Announcing Satori’s Inclusion in the Microsoft Pegasus Program
Satori has been included in the exclusive Microsoft Pegasus Program and is now available on...Streamlining HIPAA Technical Safeguard Compliance with Satori
Discusses HIPAA's technical safeguards and the benefits covered organizations can accrue from using Satori to...Still Giving Constant Data Access? Consider Using Temporary Authentication
Satori provides temporary authentication and secures access to sensitive data on a need-to-know basis at...Can You Have Your Cake and Eat It Too: Does Data Security Have to Reduce Productivity?
Sharing data is vital to increase organizational productivity, but this raises questions about security risk...Why Security Management Can be Challenging in Postgres
Postgres provides many benefits and has a wide range of useful native security measures, however...6 Effective SQL Server User Management Strategies
We explore effective Microsoft SQL user management strategies to keep your users organized, authorized, and...Why Native Database Audit Logs May Have Limits
Native database auditing capabilities, while necessary, in some cases could increase the complexity of an...Native Dynamic Masking and When It’s Not Enough
Some data store platforms have their own native dynamic masking capabilities. While it may be...What’s Stopping Your Organization’s Data Sharing Culture?
Many organizations are hesitant about data sharing. We explore the problems that prevent and the...State of Data Security Operations Report 2022
In this report, we analyze and report the results from our survey of 300 industry...Why Data Ownership is Hard!
Data ownership is a critical yet often avoided task within organizations. While, individuals shy away...Why Don’t All Companies Apply Attribute-Based Access Control on Data Access?
ABAC is often implemented to overcome the limitations of RBAC, however, ABAC is not without...Data Access Challenges for Healthcare Companies
The tremendous amount of Healthcare data can generate financial benefits as well as save lives...Zero Trust For Data Access: Why Is It So Important?
The zero trust model requires continuously authenticated, authorized, and validated access to applications and data...Agile Data Governance with Satori
Agile data governance is crucial for organizations using cloud data stores with constantly changing data,...When Does RBAC for Data Access Stop Making Sense?
RBAC is a useful model for access control, however, there are some instances where it...Why Data Engineers Should Take a Step Back from Cloud Data Security
Data engineering teams can spend a significant portion of their valuable time on cloud data...Why Cloud Data Governance is Complicated
Data governance by itself is a complicated procedure that is further compounded when performed in...Why Data Classification Projects Are So Hard
Data classification projects are a dark cloud for data teams, often appearing randomly and redirecting...Data Security Projects Keep Data Teams Away From Their Core Responsibilities
Data security is critical, however, this task often defaults to already overwhelmed data engineering teams...9 Common Struggles Data Teams Face With Data Masking Projects
Data masking is essential when working with sensitive data. However, there are a number of...How To Piss Off Your Data Consumers With Data Access Bureaucracy
Stakeholders including data consumers are ultimately people. Having an annoying work environment reduces productivity and...Enabling Employee Access To Production Data
Uncontrolled employee access to production environments is an operational challenge, because while access is necessary...Implementing “Need To Know”
Classifying data as "need-to-know" is important for securing sensitive data. In this post we discuss...Benefits of a Consolidated Data Access Platform
Managing security and access policies from a consolidated platform simplifies processes and increases visibility and...Role Explosion in Data Access
One of the common pain points data teams experience in authorizing users to access data...Satori Is Now Available On AWS Marketplace To Simplify Secure AWS Data Access
Making life more simple for our customers not only means striving to deliver the best...Satori Announces #Slack Integration To Simplify Data Access Workflows
One of the most commonly used productivity tools is Slack, and the ability to control...Satori Introduces Automated Data Portals
For years, we have been following our mission of enabling companies to deliver quicker data-driven...Simplifying Data Localization Requirements With Satori
Meeting data localization requirements can be challenging; this post explains how to simplify them with...Satori and Cockroach Labs Partner to Provide Secure, Simple, & Resilient Data Access
Satori and CockroachDB are announcing a partnership that will enable existing and new Satori and...Satori Announces MySQL Support For Secure Data Access
We’re announcing MySQL support in Satori to help companies secure their data access for MySQL...Database Reverse Proxy 101
A proxy server can be a forward proxy where the client directs traffic through a...Asking the Right Question: RBAC vs. ABAC or RBAC AND ABAC?
Before they can access data, users must get authenticated and authorized. In this regard, access...Data Access Orchestration and Its Limitations
In this article, I will give an overview of data access orchestration (not to be...Satori Across Various Deployment Options
Some of the most common questions we, Satorians, encounter are about the many Satori deployment...The Dangers Lurking in Data Swamps
The more data a company collects and stores, the more likely that data can turn...From “Default To Know” to “Need To Know” to “Need To Share”
We all like having our cake and eating it too. In this article, we will...5 Ways to Apply Decryption & De-Tokenization in Snowflake
This article will discuss the distinction between tokenization and encryption and their inverses: decryption and...Metadata Repositories: Data Dictionary vs. Data Inventory vs. Data Catalog
Data dictionaries, inventories, and catalogs are terms often used interchangeably. While they are all critical...Taking Satori for a Test Drive
A lot of thought goes into how to help potential customers try out your product....Writing The Snowflake Security Book
For the last few years, we at Satori have been a bit obsessed with Snowflake....ABAC: An Introduction to Attribute-Based Access Control
Access management has evolved to incorporate need-to-share authorizations in addition to need-to-know information. The authorization...How To Accelerate Data Democratization
The future of data democratization lies in the hands of your end-users. They are already...Simplifying Multiple Snowflake Accounts Management, Security & Governance
One account is not enough. In many cases, organizations using Snowflake use multiple accounts rather...You Have Data, But Is It Accessible?
As the saying goes, “data is the new oil,” as it is quickly becoming an...Satori Joins Snowflake’s Accelerated Data Governance Program
Today, as part of Snowflake’s global Snowday event, we are excited to announce our participation...The Datamasters: Data Owners vs. Data Stewards vs. Data Custodians
There is no such thing as a one-size-fits-all data governance framework that works for all...Using Satori & Collibra to Boost Data Governance and Security
Satori augments your Collibra data governance capabilities and creates a synergy for better DataSecOps across...The Redshift-Tableau-Satori stack for DataSecOps in Data Analytics
Many organizations are using Tableau to empower their BI activities for reporting and analytics. These...Custom Classification: Common Use-Cases
In a previous post, we introduced you to our data classification capabilities. As a recap,...Applying DataSecOps Principles on MLOps
Machine learning has been commoditized in the last decade or so, and I love it....Introducing Custom Data Classification in Satori
When data engineers and other professionals experience Satori for the first time, one aspect they...The Tableau-Snowflake-Satori Stack for Secure Data Democratization
Tableau is one of the most widely used BI tools which provides a wealth of...Amazon Data Lake Security with Athena and Satori
A few years ago, when I first began using Athena, it was a magical and...5 Indicators You’re Doing DataSecOps Wrong
I love hiking as well as outdoor navigation. What I find especially useful for these...Redshift, Looker and Satori: Advanced Data Access
I’m guessing there is no need to introduce you to Amazon Redshift or Google Looker,...Data Classification With Satori
In this article, I will discuss how people perform data classification using Satori and explain...Data Classification Best Practices – Part 2
In the first part of this article, we discussed the many reasons why you should...Snowflake & Looker DataSecOps with Satori
In this post, we will discuss the DataSecOps advantages that Looker users over Snowflake enjoy...Data Classification Best Practices – Part 1
Note: this is part 1 of the guide, in part 2 we discuss the questions...Limiting Snowflake Access to Specific Clients
Before we drill down to the “why” and “how” of limiting client tool access in...Democratize Data in AWS Redshift With Self-Service Data Access Workflows
Amazon Redshift allows companies to analyze large amounts of data, whether the data is stored...Zero to Self-Service Snowflake Data Access Management
Let’s start with good news – if you are using Snowflake and want a simple...Snowflake Security: Best Practices for Stages
This article is also published as a chapter in our Snowflake Security guide, covering many...What is DataSecOps?
History repeats itself. The transition of applications to the cloud and the development of software...The Future of DataSecOps, As Reflected in RSA Innovation Sandbox
Every year, the cybersecurity industry has its biggest conference, the RSA conference in San Francisco...Snowflake Role Hierarchy
Snowflake’s data access modeling is different from many other databases and data warehouses. It’s funny...How to Automate a Data Inventory for AWS Redshift
Creating and maintaining a data inventory is an important part of a comprehensive data management...Redshift Data Masking – Getting It Right
Data masking is the act of transforming parts of data to maintain its anonymity. There...How to Monitor Access to Sensitive Data In Snowflake with Satori
Being optimally focused is the key that helps you spend your resources better. When your...Implementing Row-Level Security with Satori
There are moments when architecting data where you need to make decisions that will have...Data Inventory for Snowflake: Manual vs Automated
The Snowflake Data Cloud helps organizations quickly transition from having a lot of data to...Snowflake Data Masking: Static vs Dynamic
In today’s ever-evolving digital age, data masking is one of the most essential features of...Snowflake Data Access Journey
Let’s understand the chain of events that leads to data access. For example, imagine you...Simplifying Snowflake Roles Management using Satori
A few days ago, I wrote about some of the complexities of managing Snowflake roles...How to Scale Snowflake Roles Management
RBAC, or Role-Based Access Controls, are foundational tenets of good data governance and key to...Benchmarking Snowflake Performance Using TPC-H
Benchmarking Snowflake DB with TPC-H, including full queries and source code.How to Complete a Safe and Simple Migration to Snowflake
Data migration is not fun. I’ve been there, done that, and I did not like...Satori Universal Data Access Control for AWS Athena
How to get better access control & security for your data lake using Satori along...Setting up Column-Level Security in Snowflake
Column-level security in Satori for Snowflake, simplifies data and security teams life so they can...Snowflake Row-Level Security
How to implement Snowflake row-level access control, a step-by-step guide, with secure views or by...Analyzing Data Access Logs? Here is What You’re Missing
Native DB access logs are useful, but using Satori to analyze data access logs helps...Data Engineers: Stuck in the Middle?
Data engineers are often conflicted between engineering teams, security and privacy.Turn over-privilege risk into a healthy Snowflake DB permission fit
I recently published a lengthy diatribe about the problem of over-permissive access to data, the...Effective GDPR DPIA on cloud data warehouses
Meeting GDPR requirements is important, not only for EU companies but also for any companies...7 Quick Ways to Improve your Snowflake Security
Update – January 12th 2021: Following Snowflake’s preview addition of self-service account creation using the...Hardening GCP BigQuery security: access controls explained
In the spirit of our Snowflake DB security and AWS Redshift security guides, we’ve created...Sensitive Data Isn’t The Crown Jewels
I need to get something off my chest. It’s time for our beloved infosec community...AWS Redshift security: access controls explained
This is part of our complete Amazon Redshift Guide.Snowflake security: access controls explained
If you’d like to read this guide, along with additional guides to specific topics in...Enterprise data protection implementation: why so tough?
Implementing security products, services and solutions in enterprises is intrinsically difficult, especially when coordinating several...How Satori uses Apache Drill to conquer data exploration & preparation
“Laying out data infrastructure for a new product and big-data research is no small task....Washington Privacy Act Passes State Senate: Another Step for Privacy
This week, the Washington senate approved the Washington Privacy Act (WPA) to advance data privacy...Why today’s data access controls don’t work for data-driven organizations
As the world undergoes a data revolution, the ways we generate, store, access, use and...