It’s an amazing time to build and grow a business. Good Health Company (GHC) is a rapidly expanding global health and wellness brand. At GHC, we have always wanted to grow, and grow fast - we have expanded quickly from India to multiple global markets including North America.
Using the cloud (AWS in our case) to get set up and scale up on demand has become commonplace, and we are no different. Growing successfully at this pace has required us to adapt fast with sound data-driven decisions. The data cloud has evolved to provide a host of data platforms that put powerful analytics at our fingertips. Our applications, our analytical infrastructure and our recommendation systems are all powered by these data cloud platforms such as S3, Mongo Atlas, Snowflake and others – allowing us to operate with tremendous speed and automation.
Data Cloud brings security challenges
Today, multiple teams across marketing, supply chain operations, finance, engineering and other stakeholders across GHC leverage various datasets for their business functions. In our early days, we were, like most start-ups, fairly laissez faire with our access to data - solely focused on moving fast. But as we expanded into the North American market, we faced new regulatory requirements. We introduced new growth strategies such as personalized assessments and consultations which meant we had more consumer health data. Almost 80% of our data lands up in Snowflake, and it started to get unwieldy.
Like most companies today, data is our competitive advantage. We know we have to do things differently to secure it before becoming an impediment to business growth. That’s when we partnered with Acante. There were three key business drivers that we wanted to achieve through our Acante deployment:
- Compliance & Privacy: every new market we enter introduces new compliance requirements. Foundationally, it became critical for us to have a firm handle on where we have PII data - in S3, Snowflake, RDS or some other data cloud platform. Right from the start, Acante put together a Proof of Value that fit our data security needs. Having a highly automated data discovery engine is critical, and they delivered on this quickly. Plus, for the prescription data we are collecting, we could be diligent about tracking that PHI data continuously in Acante.
- Managing Proliferation of Access to Data: Most IAM and identity-centric security solutions have no context of the data, its sensitivity or schemas. Acante emerged as the most effective option we saw that would allow us to maintain discipline in our access privileges to data. They integrate right into our access provisioning workflows via Slack and JIRA – providing the relevant data risk context so we can approve data access without much back and forth. Acante gives us a complete, accurate view of where our data lies, who has access to it and why. This really helps us ensure our PII data is always properly segregated and makes our data access reviews much less taxing. At the same time, our data engineers and other consumers are happy about getting faster access to data.
- Preventing Data Leakage: our data teams are running a variety of queries, dashboard, analytical pipelines and notebooks with customer behavior models on the data. These workloads are becoming the new APIs for data leakage. We wanted to make sure we monitored these pathways for data leakage before we have a serious incident – not after the fact.
A data-focused approach to security
Before onboarding with Acante, we looked at the plethora of cloud security tooling available. While useful, we realized most of the other solutions’ focus lies around protecting applications and their underlying infrastructure. Acante gave us the opportunity to rethink our security strategy and implement a data-centric model. Being a largely distributed workforce, overinvesting in perimeter and infrastructure-centric security makes less sense for our business model and makes it harder to protect our most valuable assets – our data.
As we move forward, we’ll look at integrating Acante’s least-privilege remediations into our data access review workflows so we can achieve and maintain a “just right” access posture while ensuring productivity of our data teams. We are excited about using advanced data sharing capabilities in Snowflake (Data Exchange), knowing that Acante will have the security visibility and compliance considerations covered. We believe in their vision to unlock the benefits of the data cloud without compromising on the security and privacy of our data.