Empowering AppSec Teams with Snyk’s Sarit Kozokin
Snyk recently announced AppRisk Essentials, a new industry-first ASPM solution – designed to give power back to AppSec teams to govern and scale security programs – to keep pace with the nature of today’s applications, plus emergence of new cyber concerns.
Transcript
This is Textron tv. Hi everyone. Welcome back here to Techstrong tv.
Our guest, or our next guest for today is a first time guest here on Techstrong. It's re Kin. And re is the VP of Product at ny.
Um, Reed joins us today, uh, from Israel and it, I appreciate her staying up and coming on with us. Reed, welcome to Text Drug tv. How are you?
I'm good. Um, thank you for having me, Ellen. Uh, I'm really happy to be here for the first time, but I'm sure it'll be great.
And hopefully not the last time we'll have you on more. So, Reed, I, I mentioned you were VP of product, but you know that that can cover a lot of ground. Why don't, if you don't mind, uh, you know, share with our audience a little bit of your background, a little bit of your journey?
Sure, sure. So I started my journey more than 20 years ago, um, being a, you know, a developer, uh, getting, you know, developer experience, literally. Um, mm-Hmm.
And then I, um, evolved into becoming a product manager, uh, which I've been doing for more than 15 years now, focusing on cybersecurity domains, um, both in startups and big companies. Even like IBM like big enterprises. Mm-Hmm.
Uh, in a few products there, uh, under IBM, Metro Steer Trust tier Security, and also startups like, um, threat intelligence, cyber and startup. So I've been doing both. Um, and in ssn, it's somewhere in between.
It's still, uh, you know, I'm, I'm still, uh, you know, experiencing, um, mm-Hmm. At sny here I am, uh, leading, as you said, I'm a VP of product and I'm leading, uh, the, specifically the security experience division r and D division. And we're all focusing in, um, A-S-P-M-S-P-M vision for SNY in general, but specifically apris that you just mentioned.
And of course, we'll talk about it more, uh, soon. Uh, I'm here. My journey at SNIC started like a year ago almost on.
Okay. So a year. Yeah.
I've been there for year. Wonderful. So, you know, I, I always try to translate the alphabet jungle for people.
When we say A SPM, if people aren't familiar, what does A SPM stand for? Okay, so, um, application security, posture management, that's the, the term, uh, which is really, uh, focusing in, um, taking the developer experience and putting more on the security experience. So the idea is, and this is what we also hear from our customers and from also as, uh, c-level stakeholders and executives that they're challenged with, um, handling the issues that they have.
So they have a very good security program running developer tools, but they know they wanna know more about what they found and they wanna handle it better. They wanna be able to prioritize, they wanna be able to understand the application risk out of it. They wanna have visibility.
So for that, we have SPM that will either, like, you know, the, the basic things that, uh, SPM cover is really, um, looking at being able to collaborate, like, uh, um, empower security and developers to collaborate in order to handle those issues and make sense out of them and prioritize and drive effective remediation, but also have visibility into the application risk. Uh, you know, top of mind for, uh, for executives, you know, software, supply chain security risks through the application, uh, security posture. So it's both how to manage and how to collaborate in order to manage better, but also to, um, um, have visibility and have the understanding of the risk in order to monitor and to, to get better understanding.
Sure. com 10 years ago. Right.
But before that, my background is security and I always, to me, the reason I was attracted to DevOps was because I thought it was a great opportunity to do security better. And, you know, quite frankly, I've always, uh, admired snyk because they, to me, were one of the first companies that Right, right from the get-go, were about out security for developers securing our code better, you know, what, what we call now DevSecOps, right? With, and, and we've been, you know, for the, this year at RSA conference for instance, so I think it'll be the eighth year we put on the DevSecOps event for RSA on Monday of RSA week at the Moscone Center.
Though this year it's DevSecOps and ai. 'cause everything's ai. But, um, you know, it's always been DevSecOps for, for me and, and you know, and for sny, quite frankly, and I, I think I've seen this, uh, evolution where at first a lot of security people said, you know, developers don't care about security.
You'll never get them to care about security. And developers said, those security people, all they do is say no. Right?
They just say, no, they don't. They get in the way. They slow me down.
And then from that though, we, we've seen this evolution where no security is quality and everybody wants quality software. And we've, we've shifted more security to developers. But I think we also saw a little bit of a pushback saying, Hey, yes, developers want to develop secure code, but they're not security people.
Maybe they could be security champions, they're security aware. But there, there are certain things that we still need the security people to do. We can't just put it on the backs of the developers.
And I think what we've come to now is, what we're trying to come to is an equilibrium where the developers and the security people each recognize it takes a village, right? It takes a village to develop secure software. And, and how do we work together with that?
And to me, when we look at A SPM as a, you know, and, and SNY isn't the only a SPM solution out there, when we look at a SPM as a market, and we look specifically, let's say at App Risk Essentials, which we're gonna talk about, it is about finding that balance Exactly. Between the developer and the security professional. So We wanna help them come together, work together in order to really make the security program effective.
As they said, the security program may be owned by the security people, but they need to govern and be able to work well with developers and, and make it work together. Exactly. And vice versa, the developers need to dev.
Yeah. Which is exactly, this govern this dev governance and developer security platform. Exactly.
Absolutely. And the developers, they need to develop secure software. They need the security people as much as the security people Need that need developers to fix.
Exactly. Alright, so let's jump into App Risk Essentials. What is it?
So app risk is really, uh, ssn. A SPM, uh, it is developer first, A SPM workbench. You can call it, uh, we call it a workbench, like set of tool, set of, of functionality that would help the security persona implement a govern and scale the security program.
Okay. That what we just discussed, you know, the ability to do this collaboration and this governance through those tools, through the Workbench. Um, and it is something that is still, you know, we, we want security to empower developers.
So we're still around developer first developer, uh, experience focused, which is what sny, you know, this is what sny, uh, you know, does and is, is, uh, that's, that's our vision. But we build this on top of that. So it's like a new chapter that comes into developer security.
Uh, in general, this, the developer security world. Now, specifically for up risk, we have two versions. The one that we announced now is, is called Up Risk Essentials, and it is focused on, um, security programs that are more SNCC based.
So it's mainly the SNCC dev tools, the best of breed, uh, uh, SNCC tools. And, um, on top of that you have this upper risk essentials. And this is where I talked a little bit about SPM, but the main functionality there is, um, around the ability, and, and this is, you know, the, the thing, the, the main name, uh, or unique thing that we have is what we call asset first.
So we first discover the assets and map the assets. So we start with the assets, the application assets. This is what will help us understand the application.
And then we met, uh, the controls, the security controls that cover those application assets for compliance, for security, we wanna know that we are covered, right? Those black, those blind spots that we have, we wanna know that we are covered, like the customer wants to know that they're covered. And this is something that is really hard to do today.
And on top of that, we also bring the, uh, we leverage the prioritization, uh, what we call risk-based prioritization. That is, is based on indicators that we provide more context to the issues, more context to the issues that relate to those assets in order to prioritize and drive more effective remediation. So context can be, is this like, you know, looking at the assets and, and saying, is this asset open to the internet?
Is it configured to be open to the internet? What we call is public, uh, is it relevant to my operating system? So bringing and some business context as well.
So bringing those indicators would help the security people to prioritize, okay, what do I need to fix first? Where do I need to focus based on the risk that is, uh, this, those issues posed to the, to the business? Um, so it's like three, three steps.
You map the application assets, you look at the security controls and where you have gaps, and then you prioritize the issues with the assets in order to prioritize better. Got it sounds, it sounds pretty comprehensive rit. How, how would a company or an organization get started in this?
What, what, what? Like what's the on ramp? How would it start?
You mean like how we decide? So they, So someone out here says, this sounds like a great program for us. Yeah.
How do they start? So, yeah, so first of, they start with the dev tools, right? Like they start generating those issues, right?
They start generating those issues, looking at what they have, building a backlog, trying to handle this and understand, you know, their, their security posture. And then once you, you get to that point, you put up risk on top of that in order to, to manage this better, to govern, to write the right policies, right? Like once you, you wanna scale it, and once you wanna understand this, the situation, the security posture better based on that, then uh, up risk comes into play.
Usually it comes, you know, it can come hand in hand. Like when you understand you are a security program, you understand how you wanna build it, then you get to, to, uh, to this becomes relevant at risk, becomes relevant. Got it Very much about, you mentioned that, but it very much about the effectiveness of your program as well.
Like you build this program with those, those dev tools, but you also want to understand you're doing the right things. You have the right policies in place. You, you have the right security controls in place, and this is where operas can help you understanding the effectiveness of your program.
Got it. Do you, do you have to already have sort of the sneak, uh, products installed to use this? Yeah.
So, so it builds on That Essentials? Yeah. Operas essentials is BA Upper in general is based on, uh, SNCC tools.
Uh, I talked about two versions, upper risk essentials. And the next one that is gonna be launched early in 2024 is called Up Risk Pro. That's the next version we're working on, and we'll be launched soon.
You heard it here? Yeah. Yeah.
Um, mm-Hmm. And it, uh, it's also based on additional, like, if, if you wanna scale your security program, like you, you wanna scale in a way that you have more security tools that you want to include in this coverage of aris, then a PRO does that. So you can scale your program with more solutions, uh, on top, do more.
Okay. And, um, for, so snyk, DO IO is the main, uh, website for snyk. Yes.
Can people go there to get information on this? Is there another site they should be looking at or another page? Yeah, so if you go to sncc, do io, the landing page, you have a link straight to the, uh, relevant materials for operas.
But you can also go straight to the product, uh, page using the SNY IO product, SNCC Up Risk as the URL, uh, to get straight to the product. Fantastic. Siri, thank you so much for coming on today and, and telling us a little bit about App Risk, both App Risk Essentials and the app forthcoming App Risk Pro, which should be soon.
Uh, we'll be excited to see when that comes out, what additional functionality's in there. In the meantime though, you know, thank you to all of our friends at Snyk for what you guys are doing. I, as I mentioned earlier, one of the leading companies kind of bringing security and developers together.
I, I know it's very fashionable now in DevOps. Everyone wants to be a DevSecOps company and lead with security, but you know, Snyk was one of the originals doing it. So keep up the great work.
Thank you. And come back and keep us posted. Thank you for having me, Ellen.
Thank you. A Pleasure. Sarit Kin, VP of Product here at, uh, at sny here on Tech Drunk tv.
We're gonna take a break. We'll be back in a moment.