Enhancing Cybersecurity with AI and Advanced Tools with Rapid7 ‘s Craig Adams
Craig Adams, Chief Product Officer at Rapid7, shares insights on the evolution of vulnerability scanning and the company’s focus on understanding attack surfaces and prioritizing risks. He discusses the impact of AI on improving detection and response capabilities. Adams introduces Vector Command Advanced, a service that merges traditional pen testing with continuous red teaming, and addresses the challenges CISOs face in integrating new tools and managing risk effectively.
Transcript
Hey, everyone. We're back here on Tech Drunk tv. I'm really happy to have my next guest, Tanya.
You know, sometimes ships crossing in the night could be in the same industry for, I don't know, 20 years, 25 years. And somehow or another, you just never got a chance to catch, catch up or meet each other. So, in, in setting this interview up today, I had a chance to meet a new friend in the security space who's been here as long as I have, and that's always a good thing.
Let me introduce you to Craig Adams. He's the Chief Product Officer over at Rapid seven. Hey Craig, welcome to Tech Strum tv.
Uh, Alan, the pleasure is all mine. Big fan of the show and thrilled to be on it for the first time. Uh, it's a pleasure to have you on there.
So I gotta just ask 'cause people are looking, that's a really nice background. Is that, that's real, I'm assuming. Yes, this Is real.
This is the home in beautiful Waltham, Massachusetts. Well be that. It's a good, it's a nice time of year to be in Waltham.
It's the, uh, this is the tricky thing about New England is while we have four seasons, the winter one is six months long, so you're in that sweet spot, uh, before it's not too hot. And then, or That's at the end. That months starts.
Exactly. I in Florida it's a very different dynamic though. So, uh, this is not something we have in common.
No, well, I'm, I'm from the north. If you couldn't tell from my funny French accent, accent, accent, I am from the Northeast and grew up out in the wilds of Long Island. But, um, yes, we are in Florida now, and if I undid my window back there out to the balcony, yeah, we are, I'm on the intercoastal in it.
It's beautiful here today, but hot is hot. Hot is hot. Hot, hot, hot.
Anyway, Craig, I don't know how long you've been at CP over at Rapid seven, but as I mentioned earlier, you have a distinguished history in the cyber InfoSec space. Share with our audience a little bit about your journey. Uh, very kind.
Uh, so I spent two decades at Akamai Technologies building out their security business. Really the thesis was that while organizations were investing a lot of things on-prem, there was a, a fundamental different layered security when you add on top. Um, after a few decades there, I realized the world was moving to not just the magic application, but the intelligence and data we put in the application.
So became Chief Product Officer, uh, recorded future, uh mm-hmm. And then I recognized that a lot of your viewers recognize, which is yes, uh, data is key, but fragmented data from all of the 35 different security tools, or 45 or 55 different security tools we use. And so I moved over to come, uh, as Chief Product Officer, rapid seven, approximately a year and a half ago, helping customers better leverage their security investment and reduce some of the fragmentation of their environments.
Excellent, excellent. You know, as we were talking off, off camera, I, I've, I I've literally been following Rapid seven since the day Alan Wallace launched Rapid seven. And that was, that had to be, what, about 22 years ago?
I'm going to guess 20, 21 years ago in that range. Yeah. And, um, it's come a long way, right?
What, what started as sort of a very basic vulnerability scanner, and this was back in the days when you did vulnerability scanning. Once a year you delivered a phone book Right. To the security admin and he worked through that phone book, basically you scanned around Christmas, right?
You gave it to him and you came back and gave him another Christmas present next year. That's how long it took him to work through the book. Yeah.
Dude, interesting definition of present. I've never seen a vulnerability list referred to as their present. Well, I I'll that one, I'll be, it's funny you bring it up.
'cause the, you know, the company I had co-founded still secure. We, we had a product similar to Rapid seven called Van, and we used to call it the Bad News generator because that's what it was. It was the bad news generator.
That's Right. That's right. But to be fair, Craig, and it's a, you know, it's a view into our industry, other people called the job security.
Sure, sure. Because I had plenty of vulnerabilities to work on. They needed me.
That's right. Of course. The, the, the, the game has changed a little bit, right?
Absolutely. We've shifted scanning left, we shift more often. We, we remediation processes are better than they were.
Um, n not just patching and the whole, the whole AppSec thing came into being, right. Yeah. And testing and yeah.
And SecOps, which is, you know, something I obviously got very involved in, um, talk, you know, for our people out there who still think Rapid seven is a quick vulnerability scan, you do once a year, Craig, your chief product officer, give him the vision of the Rapid seven product line. Yeah. So, so absolutely.
So still, we, we honor our heritage by of course identifying exposures in your environment, but that's actually the minority of what the company is today. So, mm-hmm. To be clear, there's three things that Rapid seven does for our customers.
Uh, the first is we help them understand their attack surface, um, which is the first mistake most organizations make. Gartner will say 17% of organizations identify 95% of their tax surface. We're not even looking at the things we're trying to protect at the end.
We give them an aggregate view, looking at everything across the environment. The second, of course, is we help them prioritize exposures based on risk in their environment. It doesn't matter if it's on-prem cloud in an application, uh, a mis uh, identity or mis inconsistent control, but we're gonna help them risk prioritize exposures.
But then finally, and where we spent the most of both our time as well as most of the company's revenue today comes from detection response. So how do you provide an AI driven both sim MDR service intelligence with the critical validation wrapper around it that allows organizations to be helpful? You know, what makes us unique in this space is, uh, I believe religiously that environmental context matters.
So when you're doing detection response, when you're investigating a threat, as much information as you can have about that environment, AKA, does that machine have an exposure that's currently being exploited in the wild? Is that cloud account perhaps misconfigured? Or does that application have a vulnerability attached to it as much environmental context that you could integrate into a detection response that allows you to prioritize faster, respond faster, and of course understand quicker the path to remediation.
That's where we're spending a lot of time focused today with our customers. I, I would imagine what a time for something like AI to come out and help you with that. Oh, the, the, and, and first, you know, we, because we hit AI in the first five minutes, you and I also need to be intellectually honest that there's a lot of AI washing of things.
Uh, ML models have been around a long time at the same time with all the ML models. Even if you just flip 'em and call 'em ai, we knew that in detection response, what was doing in the past wasn't working today. It wasn't working just to do predictive analytics.
We actually had to go to Angen world where truthfully, when a threat's identified, it's instigating a series of actions that each, depending on the previous data sources or calling out other actions, that ag agentic AI workflow is one of the things that we believe is gonna drive detection response across our horizon. Um, I disagree, I'm convinced it's finally gonna give us the best path to the cyber skill shortage that everyone know is so pronounced these days. Abso, I I agree with you a hundred percent, Craig.
Of course, getting from here to there isn't always easy, right? I mean, one, one of the lessons I learned the hard way in security over the years was, you know, we, we've had the ability to automate things for a long time. Sure.
I remember, you know, the company I helped start, we went IDS to IPS and people were freaking out. You can't block stuff automatically. I gotta see.
Sure, sure, sure. I would've blocked the CEO's porn or something. Who knows.
Right. But, um, I Was gonna say important memo, but still Yeah, Well, something like that, you know, the ability to, to remediate vulnerabilities for so long has been something we all give lip service to. And, and yet we're just now really starting to see as part of detection and response automated remediation.
Right. You know, and it's, it, it's, it is what it is. We've seen it in the whole shift left thing and movingly from, from, you know, once upon a time scanning to continuous testing.
Yeah. You, you're, you're, you're so accurate at first, and this is the always the grand debate of what do you want clippy to do? Uh, yeah.
Use clippy. 'cause you and I are of a certain age. We remember Clippy, we Remember Clippy, we remember he's co-pilot the next clippy.
But that's a whole nother ending. That's a separate episode. We'll, that's not for Today.
But, but I think the, there is something that I believe we're now at the point, and this is what we've been working so hard, and we recently announced, as you know, around how do you take something that was being done like it was 30 years ago, which is this validation assessment or pen testing environment, a continuous red teaming, um, the mythical environment that most people wanted that no one can afford. But how do you actually use AI as well as environmental context to bring together a validation view of an environment? Because if we actually look at problems that exist, every, the number one question every CISO is asked by the board is, are we protected?
Uh, they want that clarity that fundamentally is a validation question. They're asking our traditional way of doing that, of one pen test a year or two, only for the largest organizations with the largest budget, a continuous red team service that's not sufficient. And that's what we've been working hard at recently.
Rat seven. We're gonna dive more into that here. You know, one of the reasons I had left still secure and gone outta that whole thing is I came to the conclusion that security was too hard except for the very largest and not even the Fortune 500, maybe the Fortune 100.
That's right. The Fortune 50 have the ability to do continuous red teaming, inhouse, have the resources for true 24 7, no sock layered differences. I, I felt like for the, for the average guy for the medium, small, medium enterprise, let's call it, they didn't have the budget.
The don't Have the budget. They probably didn't have the end of the day, Craig, they didn't have the stomach for it either, because it's a huge undertake. You know, we throw around things like, oh, continuous red testing and, and this, and tell the board what your risk is.
You, you, what's the CSO to do? Just stick his finger up in the air and say, I think my risk is 30% about today. That's Right.
You, you need sophisticated tools in addition to people That's right. Assesses right. And, and so it, it, and, and I'm not alone, right?
This is every security not at all dilemma. Right? We, we get frustrated because we know we, for the most part, the overwhelming majority of organizations don't have the wherewithal to do what they need to do to really protect themselves.
So instead they become zebras in a herd and hope the lion eats a different zebra today. And, and I think even worse, the limited budget, I shouldn't say worse, and the limited budget they have is often forced on things that are regulatory compliant. So, so take, right?
So, so take, um, take even if I'm a zebra in a herd, but I'm in a regulated industry, I have to do a pen test w which is, but, but I, I get the budget to do essentially that, that, right? And it's the lowest common denominator Once a year. Right?
I check the box Because we know our environments aren't constantly changing. We know the front landscape isn't constantly, it's not, yeah, it's static. Once a year is ample, But I'm writing one does 95.
And so the question we heard from our customers was, how do we change that? Like how do we actually take the thing that was a checkbox to actually create a posture validation service? And I do believe this is one of the areas that without ai, we would not have been able to do it in a cost effective way for our customers.
But the ability to do continuous red teaming with the penetration testing included, which is critical for, um, compliance authorities combined with the attack surface visibility, exposure visibility, that's what makes it unique. So if I can go there for, say, like, one of the things I get excited about is, um, being able to look at the external world. Just EASM is, is just such a minimal step in an operation.
Everyone knows its movement inside of an organization. Attack path navigation, this is where the unique technology we already had and the ability of service command, the ability to see across your environment how those things connect combined with the exposures inside of it, with our continuous testing services, allow organizations on a regular basis to get validation of the controls they have in place if they're working, what are the newest identified hotspots in their environment, and of course the deep penetration testing that whatever their industry requires. But, but that's unique and is gonna be a significant disruptor, in my opinion, to the traditional pen test market.
I agree with you Craig. We, we keep biting at the edges of this thing. Yeah, let's go.
Does it have a name? Oh, of course. It has a name.
Uh, vector Command Advanced. Uh, the intent of vector command is as you're looking across your environment, you need to be able to see if all of your attack vectors do you have command to control what's happening across the advanced recognizes that in addition to continuous red teaming, you need that deep penetration test as well. If you're regulatory compliance, vector command advance is the main Absolutely.
VCA vector command advance. Now is it, it tradi, it combines traditional pen testing. What about like a, is there an AppSec element to it as well?
Like to the left of the event horizon of deployment or, Yeah, absolutely. Yeah, absolutely. So, so there's a few key things that separate.
So first of course it has pen testing, but pen testing is Table Stake since I'm gonna put that to the side for a second, right? Uh, the, the critical things that does this. First it was organized and built to be compliant supportive.
So we recognize that many organizations, one of the things they're trying to figure out is how do they get the materials go back to them away that directly supports whatever audit readiness they're going through. The second is a need to integrate into your exposure management visibility. So that means what exposures exist inside of my environment, whether it's application on-prem or cloud, it can also critically include the attack pathing information that Rapid seven has.
So again, just being able to see that I was able to access this machine, I wanna be able to see that inside out view based on, uh, what we enable from attack pathing, which then allows organizations to understand just the significance behind it. But critically, it's not a once a year thing. That's one of the things we constantly heard from our customers is I need regular validation if my security controls are actually protected.
Because we know with the way modern compromises work, we're seeing a significant rise in the spray and prey. We're seeing a significant rise of when a exposure or compromise happens, it's broad, uh, or threat actors are able to go broad fast. So the adversary is constantly validating your defense.
Um, how, how are you? Uh, and I don't believe it's just enough to have the controls. I think you need to actually do the work and do the test to be able to see yourself.
Agreed. Agreed. Is it available right now?
Craig? Available now we have over 40 customers already using it, and we have not had a customer yet. That said it didn't fundamentally change their view and approach the security posture.
I love that. How could we, how could people that watching this right now go grab more information on this? Oh, so first, uh, if you're already a Rapid seven customer, contact your account team.
If you're not, come on the website, you'll find a clippy ish thing to chat into. Reach out to us, let us know more, and we're happy to engage, to talk to you more about Vector Command Advanced as well as what's new at Rapid seven. Because if you're still viewing us as a vulnerability management company, oh my goodness, quite a bit has changed.
We'd love to talk to you about our SIM MDR service and all of the capabilities to keep you protected. Gotta ask a stupid question. For those of you out there who don't know, rapid seven is R-A-P-I-D number seven, if I correct, that's Correct.
Dot com. Dot com. I just wanna make sure we get that out there.
Hey, Craig, unfortunately, this is too short a format for us to really dive deep, but I, I'd like to continue the conversation 'cause I, I, we spoke about it off camera, we didn't get to it, which is what's the CISO's dilemma here, right? They have, okay, now I've got another tool to use here. How do I integrate this?
How do I, how do I pick and choose, right, the right lineup to, to deliver, bang for the buck, measure my risk, convey that risk exposure and everything. You're a hundred percent right. Um, uh, every ciso, and I'm using the word every, um, if they're trying to figure out how they better consolidate to use both the time and treasurer of their teams effectively, that's the most frequent conversations we're having with our new customers coming on board today is like, wait, I can consolidate my vmem MDR validation, threat intelligence, CAP chasm, all in one place.
Or by the way, uh, you operate an open platform to find one of these three things of yours, three things of someone else's, Not how, how do I locked and choose? Yeah. And that's A big contrast to other, Uh, platform organizations with their closed is the ability for people to choose how they wanna work with us and engage.
We'll continue the conversation. Alan, I love this. Thank you so much again for having me on.
You're welcome. Craig Adams, chief product Officer, rapid seven, enjoying the season up and welcome. Alright, Thanks all Back here in a second on text tv.