Cyware CPO Sachin Jade on Operationalizing Threat Intelligence and AI-Powered Cyber Defense
Cyware CPO Sachin Jade discusses his journey from cybersecurity entrepreneur to leading product innovation at Cyware. He explains how Cyware is transforming threat intelligence from raw data into actionable, contextual insights that help enterprises detect, correlate, and respond to modern cyber threats. Jade also highlights Cyware’s recent partnership with Microsoft, enabling bidirectional integration for real-time, AI-driven collective defense across hybrid environments.
Transcript
Hey everyone. Welcome back here to Textron tv. I'm really happy to introduce you to our next guest.
His name is Sasha Jade. Sasha is the CPO Chief Product Officer over at Sideware. And let's welcome him to Tech Drunk tv.
Sasha, great to have you on. Thanks for joining us. Awesome, Alan.
Great to be here. Thank you for having me. My pleasure.
So, Sasha, before we jump into Sideware and what we want to talk about today, let's talk a, a little bit, give our listen as a sense of who they're listening to here. I mentioned you're the chief product Officer at Cy, but how did you get to this role? Oh yeah, thank you.
Uh, first of all, again, thanks for having me here. So, always been a, you know, tech guy in one way, shape or form in long, you know, about 15, 18 years ago or so, I started looking at cybersecurity in a different lens, which is in the risk space, which is, you know, enterprises typically used to have, especially the Francis services work space, you have eight or nine different constituents coming from all the asset all the way to the investors. And in between these eight or nine players, you have so many things going around, and so your risk exposure just increases significantly.
So 2006, 2007, I started building my first firm, which was in the risk in cybersecurity space. And the whole notion of that was this concept called security value at risk, which is, you know, when certain things happen in a security event, what is your value at risk? It could be because of your brand getting, you know, unfortunately hit your credentials, getting compromised and that getting hit, uh, you know, you're getting ransomwares and all of those things.
So we built the product, uh, bid data, the traditional ai, not the gen AI part, et cetera. So we actually built the product. Uh, I love building, uh, and I also love customers.
I just love customers because if I am building something, I wanna make sure that it is getting used by somebody. If nobody's using it, why am I building it? So that's how I started building.
That's my foray into, you know, just the product side of things. The whole nine yards customers built that firm, exited out of that firm. And then for about a couple years was with a larger enterprise, uh, Deloitte in this case, uh, who were, you know, acquired.
And then, uh, I went to another larger com, uh, corporate and Horizon, uh, who was looking at, you know, different security and network products, so to speak, and saying, you know, what, how do we actually make certain money out of here? And so on. So I joined, I led a portfolio of products in there as well.
And what we built around that was how do we make and reve security into the core of Verizon's backbone itself, as opposed to having network just for the network. Uh, built that portfolio pretty nicely from a p and l standpoint and the products as well. And then, uh, you know, started getting the bug for my, uh, startup again and, uh, met with the folks at cyber.
And lo and behold, I am the chief product officer here taking that, uh, and all the things that I've learned over the years with customers, cybersecurity, threat management, et cetera, which excite me. And so that's who I am. Fantastic.
It's hard to get that startup thing outta your blood. It totally is. Know, I I've tried myself.
It, it totally is. And uh, I, I, I love soccer as a player, so I love, and I, so anytime when I'm driving across and I see kids playing, I'm like, let me just go play. It's that same mentality.
You know what? I hear you. So I, I, I satisfied that by coaching.
I coached kids in, in football and basketball for years. And uh, you know, when they got to the point where they were like, bigger than faster than me and, and everything else, I realized I was glad I was coaching 'cause I couldn't play with those kids anymore. But I think there's, there's, there's some of that in all of us that, you know, want to go back and do it.
So how long have you been with SWE now? So I've been with SWE for about 14 months now. Uh, a a little over a year, a little over a year.
Um, in my charter kind of, uh, is kind of bucketed into three areas, if you will. The first area is strategically thinking about what the product landscape should look like. What does that six month, eight month, 12 month, 24 month trajectory of the products to look like.
Second is how do we build our thought leadership around all the assets that we have in the cybersecurity as well, saying, you know, what, how do we actually help our customers? And the third, but uh, last but not least is working directly with the customers to see what are their pain points specifically that needs to be addressed so that, you know, unfortunately sometimes the cliche of like, yeah, you know what, everybody in the AI case, everybody wants to do ai. For me, it's very deliberate in terms of like, okay, that's great.
I can build ai, but what use case does it solve for you? Why am I building certain things with AI and not the traditional way because it's going to help you with X, Y, and Z? So these are the three quote unquote charter areas for me.
Excellent. And, uh, Sasha, if you don't mind, there might be people out here who have not heard of sware or maybe more likely even people who have heard of sware that may not be sure exactly what eyewear does or what, you know, it is, but we've heard it. Let's clear that up if we can right now, give people a sense maybe of who and what SWE is and what it's about.
Sure. Uh, in 30 seconds, SWE is about operationalizing threat intelligence. And what that means is when you look at, you know, the history of threat intelligence, one of the core pain points was you would get all the indicators from so many different places, whether it's the external attack surface indicators that might be coming in, whether it's the internal assets that you have, internal data points from your c from your logs, from your assets, c MDBs, all of those places, most SOC analysts, CTI teams, et cetera, have a challenge of operationalizing it.
And what I mean by that is what is the signal here? What is the noise when it comes to threat data? Second is what is relevant for me?
Yeah, there could be threat vectors, but what is relevant for me, and the last but not the least, is once you've given me the actionable threat and the relevancy, what do I do with it? Do I block certain things? Do I patch certain things?
Do I take certain other elements to it? So that in a nutshell, that end to end, based on the threat and diligence and operationalizing it is who we are. My power portfolio is kind of based on four products.
We have the Intel Exchange, which does everything related to intel analysis. Second is collaboration, which allows you to disseminate all the right information to the right parties and the recipient groups on the other side underneath the uh, covers, we have what we call the orchestrate platform that allows you to connect to anything and everything with the AI driven playbooks, et cetera. And last but not the least, is a threat context driven case management system so that you can connect the entire dot of certain things that might be happening.
So that's who side that is and that's my power portfolio. That's excellent. A great great description of, of Sware assassin.
Um, so, you know, threat intelligence is a bit of a big boys game, right? You don't see a lot of mom and pop shops kind of subscribing to a threat intel feed or something like that. It's, you know, it's for enterprise, it's for public sector.
But here's an interesting thing. I've been in security myself 25 plus years. When I first saw threat intel kind of explode on the, on the scene, I think we always had threat in intelligence.
We just didn't call it threat intel. Maybe it wasn't a a product line, but we were always, always trying to be wise as to what was happening out there, right? But I think most people thought that an enterprise would, would subscribe to a threat, to a threat intel feed.
But I, I think in the real world we're seeing, especially with AI now and, and everything else, companies, large orgs, you know, the more, the merrier almost when it comes to thread intel and sources. I wonder if that's something Sasha you saw maybe at Verizon or, or now, you know, talking to many customers as part of sideware. Is, is thread intel sort of a, a one-horse or a one dog kind of house?
Or, or do most organizations now kind of have multiple thread intel sources? Yeah, great question. I think depending on the maturity of the organization, you do see a spectrum.
You do see larger enterprises that do have multiple threat intel data sources, feeds that they can do certain things with it and so on. You've got the middle, uh, middle tier, mid tier companies, et cetera, that kind of focuses on specifically one or two areas that they might want to see. And then you've got the, you know, the lower end of the enterprise segment that typically just have just one data feed or one, one intel and try to do whatever they can with it.
You see that spectrum. And so from our standpoint, the way we look at it is, if you want to start a CTI quote unquote program, you don't, you do want to use a CMM framework, if you will, because that allows you to put it in action. Uh, you can leverage, you know, products from us to set it up.
You get the, you know, cyber intelligence suite, for example, that bundles a lot of those things. So that your time to value in setting it up becomes very easy, uh, number one and number two. But that allows you to grow as you scale in from a smaller enterprise to a medium to a large enterprise.
Got it. Excellent. Now of course that begs the question of, okay, now I got multiple sources, right?
And I've got, and in addition to that, I have my own telemetry that I'm gathering, right? From my, from my own source, my own networks and stuff. You know, how do I wrap my head all around this now?
Yeah, we got ai, I'm sure AI is part of the solution. Perhaps, perhaps maybe it, maybe it adds more to the problem than the solution at first, but hopefully eventually it, it helps. But like everything else we're doing in technology today, AI is having, its, its say in there, its impact in there, right?
A lot of times we use the word modernization and it covers up a lot of sins. But you know, we are certainly modernizing how we take in multiple data sources like this, validate them, share them across the organization, and, and then translate that to response, right? And I would gotta imagine that this is a big part of ware's business today.
Yeah. Uh, one, one of ware's strength is understanding these multiple different sources that do come in understanding the correlation between it, so the entire whole nine yards of a threat event, data life cycle, which leads to normalization, deduplication understanding what is the element to you from a risk scoring standpoint, what is the high priority that you as an analyst should be working with, et cetera. That is a huge strength around it.
And then when you have capabilities from our partners, such as Microsoft, et cetera, where you can now not only leverage our data, but in a biodex level capacity, leverage certain things that might be happening in their product as well and get it back to us so that our product can take the effective decision around it. Case in point being, let's say there is an alert that happened and it has been shown in the, you know, Microsoft synchronal system, et cetera. Now that can be now contextualized and correlated leveraging external threat data that our platform might be seeing.
And because of that, we can send an enriched data back to Centen level for an alert system, et cetera. And when their AI or our AI now enhances it based on the con context that they see as well, now downstream from there, most of the other players can take advantage of that. So now not only have you leveraged the data that's coming from multiple different sources, but you have enhanced it, enriched it, and allowed the contextualization for somebody else to take a particular decision around it.
I, I kind of put the analogy that I was talking to on another part, the Microsoft team, it's that whole team of teams, our process, which is you need to have the data to be shared across, but contextually the decisions that a particular team takes might be very different than the other team, but they need to know the data that everybody else is also aware of. That's how we also operate. Excellent.
Very cool. You know, not quite as big as ai, not anywhere near as big as ai, but a term Sasha that we hear a lot kicked around is observability. Right?
And you know, I almost, I still remember when I first started hearing it, little did I know it was gonna replace like everything I knew about, uh, a uh, a PM, right? Or I mean so much, you know, all these companies are now observability companies. Um, do you think cyber at some level is an observability company or an observability enabler?
Great question. Um, so there are advantage points and two lens around it. Uh, in particular areas we observe what might be happening within the actual asset.
And I'll give a use case for example. Uh, let's say there's a Compromise credential that's been happening and unfortunately we heard that, you know, earlier this week as well with respect to the number of passwords that got leaked and so on. And when Compromise credentials happen, you not only need to observe, but then you need to enable actioning on that observability.
So in this particular case, we kind of do both because we actually take a look at, you know, certain compromise credentials that might be happening. We actually get the information appropriately around it, and then we enable the identity access management systems to take action against it, which is maybe quarantining the Compromise Credential or changing or resetting the password and so on. And then the other areas we, what we typically do is we will be enabling the, you know, observability platforms themselves saying, Hey, have you looked gone and looked at, like say for example, you know, Microsoft team systems or have you gone and looked at the asset database C and DBS to see what applications are there that needs to be monitored as well?
So we kinda look, uh, you know, we kinda play both roles depending on where the context lies. The essence is still to make sure that the context and the data for the actioning is relevant in the Compromise Credential example, sometimes when you are buying certain things off of Telegram channels and so on, on the Compromise credentials packet, 60% of them are not even your users. It's a mechanism for the telegram folks to make money.
Uh, they make release actors to make money off on the Telegram channels, but 60% of them are not even new users. So validating that, making sure that the signal is really cusp for you as an enterprise to actually take action against it is what our sweet spot becomes. So it's the observability and then enabling the action around it.
I love it. So Sian, uh, Cy where recently had some news releases, some noteworthy, uh, information, if you wouldn't mind while we got you here, I don't want to turn you into a PR news person, but you know, you gotta do what you gotta do. Tell, share with us maybe some, some, uh, news coming outta sware.
Sure, yeah. Um, we just announced we were part of, uh, the Microsoft Intelligence Security Association, uh, which is a really good honor for us. But then expanding on that, what the Microsoft team and ourselves as well, what we started kept looking was this need for a bidirectionality in how the threat intelligence is used, evolved, enriched, and then shared.
And so, you know, typically Microsoft has this amazing strategy as well, which is, you know, to break down silos, which is very much in line with our thought process, more collaboration, more collective defense. And our product gets used as a significant component of the automatic collective defense within, uh, you know, federal government as well as ISACs and enterprises. And in that capacity, because that plays a key role in their seeing the sentiment defender system, et cetera.
And our pla our platform now allows the bidirectionality in terms of integration with them. And so we announced that partnership, which is available as an offering directly from Microsoft as well. Uh, so we are extremely excited.
It allows the enterprises to, to make use of their investments that they have done in the Microsoft ecosystem and ours as well, and make that by ity and leverage that for what I was kind of alluding before, which is how do you take those correlations and actions pretty much in real time. Love it. Where can people get more information on that, Sasha?
Yeah, so it is on our website as well. com/tech alliances slash partnership slash Microsoft, I believe. Uh, but yeah, that's on our, might Be, might be easier to Google.
That Might be easier to Google. It's on the web, it's on our, uh, website as well. And, but they absolutely take a look.
We also have a blog populist. Microsoft has the appropriate corresponding block published as well. We have, we're extremely excited on that.
Fantastic. Hey, I'm looking at my watch here. It seems we're kind of just about outta time.
I, I appreciate you coming on. I appreciate you giving us the scoop here on the latest with Sideware and talking a little bit with us about threat intel and, you know, in, in, in like everything else through the lens of AI today. So continued success, come back and keep us posted.
Ware is an exciting company. Absolutely. Once again, thank you for having me and I'm absolutely in the portfolio coming back.
Thank you, Sasha Jade, chief Product Officer at sideware here on Tech Drunk tv. We're gonna take a break and we'll be back in just a moment with more stay tuned.