Cloud Security Early Warning System – Sudarsan Kannan, Uptycs
Uptycs recently introduced the industry’s first “Cloud Security Early Warning System.” Uptycs customers can track and analyze malicious activity across multiple attack surfaces from a single user interface (UI), including endpoints, cloud, containers, control plane for cloud and Kubernetes, and with this announcement, repositories like GitHub and identity providers like Okta and Azure AD.Uptycs customers don’t have to choose between shifting left or right. They can shift up for unified security visibility and control over their modern attack surface—from laptop to cloud.
Transcript
This is Techstrong tv. Hey everyone. Welcome back to Techstrong tv.
My guest for this segment on Techstrong TV is Mr. Sudhan Kaan. Sudar Su Shian is with Uptick.
And if I mispronounce your name, sk I apologize. Why don't you say it correctly for everyone? No worries.
Uh, I'm Sudar sh Kaan, uh, I'm part of the product team here at Uptakes. Excellent. So, Suha, before we jump into uptick and, and what we want to talk about today, why don't we maybe just take a moment to kind of, you're part of the product team, but what's your background?
Sure. Um, I come from the breeds of strong security, uh, industry, uh, kind of, uh, different companies. I've been in security for the last 18 years now.
Um, I started off in I Am space. Uh, I moved to endpoint security, uh, MDMs, and now I'm working in uptakes on the cloud security side. Excellent.
Um, so I mean, cloud security has been something that of course has been, uh, I remember when cloud, it was an RSA conference back in 2005 or so, 2006. The whole cloud and cloud security thing kind of burst on the scene, and we've come a long way since then. Right.
And, and there wasn't a cloud native kind of movement back then, but Cloud native has certainly helped us with, with cloud security as well. Um, but it, it, here we are, 2023, halfway through 2023, right? It's June now.
And, you know, cloud security is still not a settled thing in a lot of places. I think a lot of people would find that hard to believe. But for all of the great progress we've made, there's still so much more that needs to be done.
Um, but Sudan, let's talk a little bit about Upticks, right? It's company that we've featured a few times here on Text Strong tv, but not everyone in the audience is gonna be familiar. Why don't you give us sort of the upticks background?
Yeah, absolutely. Upticks, our co-founders started back in 2016, right? Uh, they strongly believe that the power of telemetry is very important, and the power of data is very important in terms of solving the security problems, that they always believe that security is actually a big data problem.
So they took the learnings of, uh, they, our founders come from, uh, Akamai, from the apps influence from Google, influence from Salesforce. So they took all the learnings from those big companies and then tried to build a capability for the industry security industry where we look at the security telemetry at scale and try to solve security problems across all our attack surfaces, starting with endpoint and all the way to the cloud. Um, we do not, our founders did not wanna stop just at the end points.
They believe that the attack actually progresses from endpoint and all the way goes to any surface, whether it's cloud, whether it's Kubernetes control plane or whatever that is. So that's how the, the company has evolved the last seven years. And lo and behold, here we are talking about, uh, the, how we are trying to protect the entire spectrum, uh, starting from the laptops to the cloud.
Absolutely. Absolutely. And before we jump in, one other thing for people who want to get more information on upticks, I know it's spelled a little non-conventional, right?
Let's just make sure we get it out there for them. com? io?
What? What's the website? com.
Excellent. So U P T YC s. All right.
Now that we've got all that out of the way, let's talk about what we want to talk about today, and that is the, the industry's first cloud security early warning system. Yeah, Sounds, sounds Darson. What are we talking about here?
Yeah. Um, so if you think about the, the recent breaches, let's start with the industry problem, right? Forget about what uptakes has to offer, but let's start with the industry problem, right?
The industry, if you look at the last six months to an year, all the major breaches have always started with endpoints. Uh, a developer laptop, for example, if you look at the Circle CI incident, if you look at the last past breach that happened twice, um, within a span of six to seven months, right? All of that started with the laptop.
Why? Because humans are the weakest factor in the security space or the weakest link in the security space. Every, behind, every laptop is a human behind it.
So if, if I'm using my laptop or you're using your laptop, right? We are always using that endpoint computing devices. That is where the attackers know that that is a weakest link.
And then they go after that laptop from there. They don't stop at the laptop, right? At the end of the day, they're after your ip, they're after your data, they're after your, uh, compute instances to do ransomware, or sorry, um, coin mining or whatever that may be, right?
They're after the critical assets or, or, or the crown jewels of a company. Once they start from a laptop, they try to move into different environments, whether it's cloud, whether it's your, um, uh, orchestration, uh, uh, platform like Kubernetes. They try to move across and try to eventually get to the data.
So what we recognize is, um, detecting an attack in one place. The other is not enough, right? You can think of all the industries acting in silos today.
You have a laptop, you have a specific, uh, uh, e d R component that looking at laptop alone, all right? Then you have the cloud security piece that's looking at cloud alone. Then you have the Kubernetes or containers that looking at that layer alone, right?
These are all individual silos when it comes to security operations. Um, bringing all this together is very challenging from a security ops person, right? They have to look at multiple screens, disjointed data experiences, disjointed, pla UI experiences.
Now their effectiveness goes on significantly or meantime to detect or meantime to respond goes on significantly. So what our founders believed is let's try to solve this holistically, uh, across all attacks our faces. So you have to detect across all different attacks, our faces and bring that all together and correlate that in a single data model, single ui.
That is where this whole earlier banning warning system that we talked about earlier, that's what it's all about. Absolutely. Now, look, this all sounds wonderful, but productizing that, and you know, I've, I haven't always sat here doing interviews.
I founded a few venture back companies taking this concept and turning it into a more than a ui, but a real product that sits behind the UI empowers the ui. Um, is, you know, the devil's in the details. Let's talk a little bit about how upticks is doing that.
Yeah. So basically we normalize the telemetry of the source itself. When you say source, it's, uh, your laptop or your servers.
If your workload is running on your cloud environment, if your workload is running on-prem or if it's a laptop, it doesn't matter. We normalize the telemetry of the source. We beam the telemetry back to our cloud and from, and we do the same for endpoints.
We do the same for cloud. We do the same for, uh, the, the Kubernetes and containers. Once you bring that data back in, we put that in a single data store.
Eventually, when you put that in a single data store, it's much easy to correlate across all this, um, using a graph DB or using a sequel, whatever that may be, we are helping our customers make it simple to query that and build your own dashboards if need be, or provide out of the box visibility in terms of the detections itself. But as all these attacks interfaces, Excellent. Um, you know, we live in a world, especially when we talk about, let's say cloud native, right?
Where open source, uh, projects really form the backbone of so much. When we look at like, let's say, observability and, and stuff like this, I'm wondering if, you know, when we look at sources, they're not just destinations like a laptop or a cloud server or instance, but are you also able, able to gather data sources from some of the big kind of open source projects out there? Yeah.
So when you say open source project, I'm assuming you're, you're, are you talking about vulnerabilities specifically on the open source? Or are you talking about the tools using open source Vulnerabilities as well as telemetry? Yeah, but It's open telemetry or something like that.
Correct. So we recently integrated what we call Amazing Security Lake, uh, where there's ocss, ooc, SS Standard. We strongly believe in that open ecosystem, right?
That is something that our founders, especially our CEO es pa, is very, very particular about. Where we try to integrate with those kind of open framework like O C F is, is, is a, is a very big, uh, uh, open source where you can collect telemetry from different places that we recently announced it actually, which is to spot onto your point, we strongly believe in that, uh, ecosystem, and then we wanna play with that ecosystem really well for the benefit of our customers, by the way. Sure, sure.
And that, I mean, quite frankly, I, we've, I've referenced 2005 RSA cloud security stuff. We didn't have that back then, right? We didn't, we didn't have this Amazon Security Lake where you had, uh, you know, all of these data points that you can draw upon to help, to help be, be more effective.
Yeah. So, Daron, let, let's talk now about how, you know, so now we understand how it works from a product, let's say, point of view. But how is the offering, how, you know, how do people engage here?
Is there a free trial? Is it a a Yeah, A proof of concepts? How do we engage?
We can't do, uh, we allow our, um, target market to pick each. We can choose anything that they want to. Um, that is a, there is a trial that they can take a ride and, and play around them, play on to see how it looks like.
They can always engage with our sales team to go through a p o V point of proof of concept, of proof of validation. Um, we do have different venues when it comes to the go to market and reaching out to our customer base, right? There is always the flexibility to try out the new capability and, and touch and feel what we have to offer.
And of course, we have our own, uh, store in, in the amazing marketplace, AWS marketplace as well. So there are different venues that customers can engage with us and start that journey, uh, on that whole, uh, early warning system that we have built out. Excellent.
Um, and so what does that on-ramp look like though? com, you know, where do they go from there? com, they can try and sign off, uh, sign up for the free trial offer.
And from there we can help guide them through the process and, uh, touch and feel. In fact, we are offering a, a capability where it's, when I say touch and feel, it's just we provide a tenant for our prospects, and they can go around and play with the tenant itself and look at how this, how the data is all set up. So how the vulnerabilities work, how these detections work, and how the telemetry collected across all interfaces.
They can, they can get that visibility right away once they sign up for the trial. Of course, there is some witting process internally, but definitely customers and Prosper can take a advantage of that cap, uh, capability. Love it.
How long is, you know, what, what's been the feedback from, uh, from customers in the market on this? Yeah, It's, it's been, it's an, uh, terrific feedback for us. In fact, a couple of customers have already started engaging with us, and they're really keen to know about how we do this correlation across all our attack surfaces, starting from your laptop all the way to our source repository, like a GitHub.
And if you have any I d p, like an Okta and all the way to the cloud, they're really, they're really intrigued by, because that's a real attack that is happening. Those kind of attacks is what is happening in the environment. And now we are able to detect it, uh, across these different attacks, interfaces.
They're very, uh, one of the biggest, uh, um, streaming companies, for example. They're really interested in learning about this as well. As we start learning more from our prospects and customers, I'm sure, uh, there's gonna be a lot more value that we, uh, we can de deliver to our customers, and we can build the product as well beyond what we have delivered today.
Excellent. Um, you know what, I think we did a good job covering this. I'm gonna let you have the last word, though.
What, uh, so if I had to ask you, talk to your CU potential customers out there today, why is this a must have thing versus a nice to have? Yeah, I know one thing that we all should remember is attackers don't think in silos. Okay.
Why should we as defenders, right? So that is the one thing that I want to, uh, encourage every organization to think through. Don't think in silos.
Think about how you can connect all the dots together and make it operationally feasible for you to execute on those specific detections or vulnerability management, right? That's the most important question that you have to ask as an organization. And we are here to help, uh, address those challenges that, that, that, uh, that our, in our target modest market is having today around this specific problem set.
Understood. Sue Daron, I want to thank you for coming on Text Strong TV today. You've been great.
com. That's the industry's first cloud security early warning system. We're gonna take a break here on Text Strong tv.
We'll be right back. Thank you, Alan. Thank you.