From Surfboards to Cyber Shields: Cristian Rodriguez on Cloud Security and AI at CrowdStrike
Cristian Rodriguez, Field CTO at CrowdStrike, shares his passion for surfing alongside his career journey. He highlights the company’s growth from three to thirty security modules, stressing the significance of cloud security amid evolving threats. AI is pivotal in bolstering security and aiding analysts. CrowdStrike will present its latest innovations at the Black Hat conference, showcasing advancements in AI models and cloud security solutions.
Transcript
Hey everyone. Welcome back here to Techstrong tv. I'm really happy to have our next guest on.
Let me introduce you to Christian Rig Rodriguez. Christian is, uh, CTO over at CrowdStrike. When he is not surfing, it looks like, Hey, Christian, how are you man?
I'm doing, I'm doing great, Alan. You know, thanks for having me on. So I always like to find out a little bit about and share with our audience a little bit about, talk to us about the boards.
Oh, so, and I just got into surfing, uh, last year. My fiance's a big surfer. She's kind of surfed all over the globe.
And, um, I basically am at this point now where I'm learning to not drown, uh, and also look fancy during that process. And so I've had the, the, the pleasure of going, uh, through like Central America and a few parts in on the east coast, do some surfing, getting used to, you know, standing up and, um, you know, not embarrassing myself as I get better at it. But, uh, yeah, that's, That's, yeah, no style.
Style absolutely counts in surfing. It sure Does. It absolutely does.
Yeah. No, good for you, man. Enjoyed It's a great hobby.
Yeah. Um, so Christian, when you're not surfing and before you were CTO at CrowdStrike, talk to us a little bit about kinda your, you know, give us the Christian Rodriguez story. Oh, wow.
We may need another hour. Um, and so, um, you know, we got time not including all the, the, the, the inner child work and meditation, um, but, but, um, Haven't we all, We all exactly. Uh, I've been with CrowdStrike for almost 11 years.
I started here as a, um, sales engineer, probably part of the first 120 employees when we, we basically had like three offerings of the company from media art to intelligence and, and hunting. And you know, now we're, we're, we're, there's 30 plus modules, but, um, but my background even prior to coming to CrowdStrike is big in the solution architect slash systems engineer, sales engineer roles. I've worked for the likes of, of Websense and Fishnet and Zimperium.
Uh, so roughly 20, 21 or 22 years in the industry, you know, working for sure for cyber companies in some capacity. Yeah. Gary's an old friend of mine as well.
Oh yeah, I know Gary. Yeah, he's good people. Yeah.
Yeah, absolutely. One time we'd get a chance off camera, my first time to Kansas City to fishnet way earlier. This is early, early two thousands.
And the first time I met Gary Fish in Jody Perel was the CTO that is now CEO and Fire Mark. But yeah, all, all good people. Yeah, great People.
Um, so you, you've got some real, you know, cyber, cyber creds as they say. How long you been CTO over at CrowdStrike? So, uh, Field CTO of the Americas for roughly three years.
Um, where, um, I feel very fortunate this, this role is, I feel, um, I just love doing what I'm doing, right? I get to, to understand the way we think of problem solving, but then I also get to, uh, work with all of these enterprises on understanding their vision and how they plan on maturing different disciplines in their security practices and, you know, how they think of problem solving as well. And then figuring out how we align our strategy with their strategy and their vision with our vision.
And, um, it's just a really great opportunity to just speak with a very wide array of different customer types. Uh, and then also just evangelize what we're doing here at CrowdStrike and what we're seeing in terms of new threats and, you know, what, what, what thought leadership is based upon customer feedback and how we're building new things. So Very cool.
Yeah, very cool indeed. Um, you mentioned when you first came on to CrowdStrike, you know, they had three modules. Yeah.
Yeah. And they've got 30. Yeah.
Yeah. There's a little something for everyone, it seems That's right. When it comes to security and CrowdStrike, but you know, if we, if we, we don't have to go through all 30 modules 'cause we really will be here an hour, but, you know, Christian gimme like big garbage cans, if you will.
Yeah. You know, break it into big cans. Yeah.
The, the areas. Yeah, I think, I think they're, they're really, um, I, man, it's, there's some there I would say, uh, four to five kind of major pillars, if you will. Um, you know, naturally we, we, the flagship capability of the, of the company or the nucleus, if you will, of the company's success has been around the endpoint, right?
So we, we do endpoint security, uh, extremely well. Right? And that's, you know, the EDR, the next gen av, anything that we can see on the endpoint has been kind of the big, you know, thing for crash work for since our inception.
And then we got into identity as well, doing identity and authentication analysis and behavioral analysis on who's logging into what, why are they doing that, you know, what do we do to prevent something that could be bad? And then there's cloud kind of the third pillar, if you will, uh, where we can understand, um, ephemeral workloads or the configurations around your systems and the likes of any of the major CSPs, like AWS or, or Azure, uh, or GCP or OCI. Um, and then there's also even the, the, the SaaS side of the house, right?
Where we, we we plug into doing SaaS analysis and authorization of analysis across SaaS applications. Uh, and then even if you were to think about, you know, those kind of four pillars, then there's this AI model that sits on top of all that very high fidelity to telemetry that we're capturing where we can start to help our customers augment their stock efforts by having AI help them with decision making or hunting or, you know, just doing analysis and triage. Excellent.
I think that was a nice way of kind of compartmentalizing into some people wrap their heads around, man. Yeah, absolutely. Yeah.
All right. com if anybody wants to go to the website and explore all 30 modules and Yeah, sure. And jump into all that.
There's lot, There's lots of brows. The website. Yeah, there is.
It'll keep you busy while, yeah. Hey, look, it's job, it's job security for someone who does the website, right? Totally.
Um, well let's say AI replaces them soon. Who the heck knows? That's whole.
That's a podcast episode. Get into that if you want. Yeah, I was gonna say, Alan, I'd, that's A podcast episode where we, we will we'll, you know, we'll, we'll commiserate.
Exactly. I mean, like, it keeps me busy just talking and writing about that particular subject. But anyway, you know, well, I'm not going to get into it now, but I'm doing a thing right after this.
You know, S stands, what is it? No, the s in vibe coding stands for security. Oh, that's funny.
And there is no s But anyway, um, let, let's talk, let's talk cloud security, though. You're a big advocate, right? For how do we put this unwieldy monster to heal?
Yeah. Let, let's hear your thoughts on this. Christian.
Um, I, every, every enter enterprise, every organization we've met with has something in the cloud, right? I don't think, you know, cloud, cloud solutions are a novel per se. Um, people are moving applications into the cloud or moving infrastructure into the cloud, or they're, um, subscribing to cloud services to make their lives easier in terms of spinning something up.
Uh, and what we're seeing is that, uh, the more that enterprises move to cloud, right, the better adversaries acclimate themselves with, you know, what's in these cloud services. We, we, you know, Ellen, I'm sure you're familiar with the way that we track the bad guys, the adversaries that are out there responsible for the attacks. We're seeing, you know, ECR groups, nation state, hacktivist groups, for example.
Um, and what we're seeing is that these adversaries are becoming a very cloud conscious. So they understand how to navigate the control planes, and they understand the services that power, the fact that someone spun something up or a workload or a container. And so what we're seeing is that enterprises are having, you know, challenges defending against those attacks that are very cloud focused because they're also managing disparate tools.
Or they may have a tool that's very much focused on endpoint and a tool that's focused on, again, the authentication mechanism that is GI giving access to that cloud environment. And then they're managing all of these different da disparate tools that lack context, or there's a lack of cohesion. But adversaries are really using the cloud as a pivot point even to move back on premise.
And so, you know, what we're seeing is that, uh, adversaries are very proficient in understanding those cloud services and they're taking advantage of things like misconfigurations or they're taking advantage of systems that have been orphaned in these cloud services. And as a result, they're very successful with respect to how often they can actually successfully infiltrate an organization or enterprise because of those services that are misconfigured or, you know, IM policies that have been abandoned or have been excessive. And that's, that's essentially a major area for us investment wise, even just to give our customers better visibility and better protection and consistent protection, I should say.
Right? That analyst experience is extremely important in terms of consistency of dealing with a threat, whether it's on premise or if it's virtual, or if it's a hardware based box or if it's an informal system, it should be fairly consistent. So Christian, I, you know, I've been in security 30 something years.
30 years, right? When I, I founded a few companies and helped found a few companies. George Kurtz was at a company called Foundstone.
Yeah. When I first got into security, and I knew George, we had a vulnerability management tool as well. This has been a holy grail for a long time.
Yeah, Yeah, Yeah. Right. com too, right?
com, a new site cover platform engineering. You, you, you look at all these other areas and the move to a platform is kind of the natural evolution, right? Instead of doing point solutions mm-hmm.
For developers, we, we develop an internal developer platform, an ITP, and we have platform engineers that lay this all out. And we have cloud native engineers that, you know, even there, like how we, 'cause I mean, Kubernetes is the hardest thing. One of the hardest things I've ever seen to use.
How the hell it caught on? I don't know, but, but it did, right? And everyone uses it, it seems so, but we have cloud native platforms.
We've been trying to do unified security platforms mm-hmm. For as long as I've been doing security. Why now?
Yeah. I think you're right. It's, it's not, uh, the concept isn't novel, right?
To say the least. Um, I think everyone has been trying to, uh, bring uniformity and consistency with, uh, a lot of disparate data sources. And I think what we're seeing is there have been, uh, it's less of a trend and I think it's more of a necessity now.
I think it's, you know, if you're asking why now, I think it's because it's very expensive to touch all of these disparate systems. Uh, and it's also very risky, right? There's so many things that can happen in between those seams of these tools that people are, and organizations trying to stitch together, right?
There's so many things that can fall through those little cracks and those, you know, an adversary only needs to be right one time, right. In order to be successful. And so I think it, it comes down to the concept of the appetite for risk has been reduced significantly because the cost of a breach is also skyrocketing.
And so, you know, companies can't afford to have these disparate systems that are, you know, poorly sits together, you know, act as their, their bedrock for security, right? I think platform and platformization and grand scheme of, you know, what platform truly is platform is, you know, native capabilities that can show first party data seamlessly connected to together, right? So that that opportunity for the adversary to live in those cracks of those disparate tools now is going away, right?
And we're be, we're making it harder for the adversary to become successful because everything is so well put together in a, in a true platform. So I think it's less about a trend and it's more of around how do I ensure the, the future of my enterprise and the safety of my enterprise? And it's ensuring that, um, in the consolidation story, if you will, is, is, is more tied to how do I do my job as a, as a defender more effectively and more efficiently, uh, versus dealing with these disjointed tools.
So Christian, I, I think all that true. Mm-hmm. But let me, let me put something else forth to you.
We need AI to make this work. 'cause the, this coordination, this tightening up of, you know, it's like, you know, the SR 71 Blackbird plane you've seen pictures of, that's a badass looking plane, isn't it? Beautiful.
You know, that used to leak fuel when it was first taking off or on the ground, it needed to go a certain height and speed and heat would build up that would fuse the, the metal there to make it airtight fuel tight so the fuel wouldn't leak out. AI is, it's the same kind of thing. We need AI to get that tightness, right?
So that we don't get the leaks out the little. 'cause it only takes, as you said, it only takes one time. Yeah.
Only one time. And it's only one crack. Absolutely.
Yeah. And that's all they need. But with ai, I feel like, you know, maybe we finally have the, the putty Yeah.
To, to, to seal all these things and bring it together and make it work in real time. 'cause that's another piece of it, right? Oh, absolutely.
We, we need this to work in real time. Absolutely. I, ai I think is so crucial to our success as defenders, right?
I think what we've seen is, and, you know, data, um, if you were to ask me even like, wait, what, what is CrowdStrike, you know, today versus what we were, when I started here, we were very much talking about endpoint security then, but we were very much focused on how do we do more with this telemetry right? On the endpoint? And then how do we expand and open up that aperture so we see more things.
And now again, right. 30 modules later, right? We're seeing everything on, again, cloud identities, endpoint SaaS, I could go on even third party ingestion.
Um, and so in order to get your arms around around the problem that's growing, right? Data is the problem. Your, your business.
So, so that's, that was CrowdStrike, right? Like we, we opened up the aperture. We're collecting all this telemetry as a business and as an enterprise, you're also growing and your problems are becoming bigger.
The more you start expanding on data, the more that you start to monetize even data, right? And as your business. And so what happens is AI helps you get your arms around the problem.
'cause you can use AI to reduce remedial tasks, right? You can augment your SOC analysts and your defenders. You can start to assess large, uh, you know, areas of data to start making more sense of it, right?
And you can start using that data to start getting answers faster. And I think that's really where on our side, AI plays a big role on augmenting your efforts as a SOC analyst, as someone that's looking into vulnerability management, someone, um, analyzing identities and authentication requests, and then guiding you into what is gonna be the next best step for our organization based upon trends that we've seen that mimic this type of behavior or trade craft. Or what is a true outlier look like in my business based upon poorly written applications versus an adversary that has his, his or her hands on a system and they're moving laterally or dumping credentials or, you know, being persistent.
And so I think AI allows you to start expanding your defensive measures in a similar fashion or a rate that is also matching what the adversaries are doing, and also keeping up with the way their business is growing. So you could probably spend another hour talking about AI use cases, but AI for us is expanding on allowing defenders to, to extend themselves. And, and there's a lot that, that, that we're, we're gonna announce soon around the AI capabilities in our platform.
But I, I think it's pretty, you know, it's pretty fun stuff. It's pretty geeky stuff. It is, it is.
Let me ask you a hard question about the AI though. 'cause you know, when you first started talking about, we, when we first started talking, you mentioned, you know, and isn't it great to have sort of a personal advisor, a analyst to talk to and explain this to you? Is AI going to be that analyst soon?
Or do you think it's a person who's augmented by ai? I'd say for right now, it's a person that's augmented by ai. Uh, and the reason is, you know, your business is growing and processes change and adversary tradecraft evolves.
And, um, the, the AI model is as good as the data that it has a access to. And you know, we, for example, at Crosscheck, we've trained our models based upon what human analysts are doing to triage systems and remediate systems. And so, you know, I think every, you know, you may have a business that has a, a SOC analyst that needs to come up with an answer faster, right?
And we don't necessarily plan on replacing that analyst, but if I can save that analyst five to 10 minutes for every detection right? Or event that they're analyzing, that adds up if we're talking about thousands of events, right? Right.
And so our goal is to have ai, uh, quite frankly, reduce things like alert fatigue, right? Or this platform in as a whole reduces alert fatigue because it's showing you contextually the anatomy of an attack from start to finish, from the identity side to the endpoint side, to the cloud side, to the SaaS side, for example. And then AI is basically guiding you on these are the things you may wanna hunt for, or this is how this event was triaged, or let's start automating some of those tasks for you and having that human analyst validate that the AI is doing its job properly.
So I think for right now it's augmenting, you know, there may be a future state where AI's doing a lot of the work on behalf of that person, but that person would still be involved in some, some capacity. All right, we'll, we'll see. Yeah, we'll see.
Um, we'll see. Hey, Christian, I, you know, we're coming up in the black hat season. I know CrowdStrike's out there totally random, but for folks watching this who maybe are going to Black Hat I'll, what can they expect from CrowdStrike?
Yeah. Uh, I'll be there at Black Hat with, with the team. Um, I think we're doubling down on showing some really great innovation coming out of, uh, our, our Charlotte AI models.
Uh, so really excited to showcase some of those capabilities like our detection, triage, and our, uh, uh, our, our, our hunting, uh, capabilities and our workflow capabilities. Um, you know, there's a lot that we're doing in cloud security as well, right? This ability to do, you know, runtime analysis and protection on of systems that are, again, or workflows that are spun up in these cloud services.
I think that's another big component, and I think we're, we're really doubling down on, uh, you know, what our customers are asking us for. And that's just to protect, you know, everything, right? In terms of, you know, runtime and the, the configuration settings that you have across those cloud services or, you know, those AI workloads.
A lot of our customers are asking us like, how do we get better, better visibility into, um, AI workloads within our CI ICD pipeline? Who's spinning up what instance and is that going to lend itself to some type of new risk or some type of data loss? Uh, and so we're doing a lot on the AI SPM front for security posture management, and we're, we're excited to showcase some of that at, at Black Hat as well.
Cool. If you go into Black Hat, go check out the CrowdStrike booth. Good stuff going on.
Hey Christian, I want to thank you for coming here on Techstrong TV and, and talk in a bit. Yeah. And you got it.
Come back, visit us soon. If we see out in Vegas, we'll we'll catch up there, but if not, yeah. Back here on tv.
Okay. You Gotta looking forward to it. Yeah.
All right, man. Ride good waves. Thanks So much.
Thanks Alan. Alright. Christian Rodriguez, CTO CrowdStrike here on Textron tv.
We're gonna take a break and we'll be back.