How to Leverage a Unified Cloud with Raj Rajamani
CrowdStrike is the only unified cloud-native application platform that extends security to applications, providing organizations with a blueprint that bridges the gap between their security & development teams. Raj Rajamani, Head of Products – CrowdStrike will discuss the state of the cloud market, how CrowdStrike prevents breaches, and CrowdStrike’s cloud momentum.
Transcript
This is Techstrong tv. Hey everyone. Welcome back here to Techstrong tv.
You know, I, I didn't even realize that my friend was gonna be on this episode until he actually came on and I saw him. He's been with us before. Let me introduce you to Raj.
Raj Raja. Uh, Raj is the CPO Chief Product Officer over at CrowdStrike. Raj, a pleasure to have you back on.
How have you been? I've been great, Alan. Thanks for having me today.
Thank you. So, Raj, you know, well, I've had you out here before we've had a chance to talk, but not everyone out here watching has had the pleasure of meeting you before. Why don't you give people a little bit of your background, a little bit of how you came to be the CPO over at CrowdStrike?
Sure. Um, I joined CrowdStrike about 18 months ago. I've spent most of my career in cybersecurity at some, you know, notable names like McAfee in the past, more recently, uh, silence and a few other competitors.
Um, eventually I made my way to CrowdStrike, uh, George, uh, was the CTO at McAfee, if you remember, from back in the day. Sure. And I used to know him.
So recently I reached out to him and I'm here working for him in a products capacity and loving it every single day. Excellent. Yes, I do remember those days.
I actually remember when McAfee acquired, what was George's company, the vulnerability management, Excuse Mestone down stone. And not only the, one of the like progenitors of the whole vulnerability management space, but also education and, and books on the subject. I mean, Foundstone was kind of the, literally the foundstone of, of vulnerability management.
Um, so it's, you know, it's it, looking back over my time in security and how things have evolved. It's funny to see how it all plays out. So, Raj, your, your CPO at CrowdStrike and, and CrowdStrike, I gotta assume almost everyone in our audience is sort of CrowdStrike, but maybe some haven't, maybe some aren't sure.
How would you explain to them? I mean, CrowdStrike's grown from a, you know, into a soup to nuts security company, but how would you describe it? I would describe cybersecurity, uh, CrowdStrike as a cybersecurity leader focused on stopping breaches.
Um, we very recently made it, uh, to the s and p 500. So you can also think of us as a constituent of s and p 500, which are the, you know, largest 500 companies that compose the standard in post index. Um, that just shows how crucial we have become as part of the infrastructure and security narrative of the whole country.
Well, not only, well, you, you mentioned the country. Look, CrowdStrike is always, seems to be in the, in the mix whenever we talk about kind of nation state cyber act and, and, you know, critical infrastructure kind of stuff. Um, but, but CrowdStrike, we, I don't want to give the impression, it's just a us, uh, type of operation crowd, one of the most fundamental cyber companies worldwide.
Worldwide. Absolutely. Thank you.
Yeah, we have customers and over a hundred countries. We have employees and almost 15 or more. So, uh, yeah, we are present in all the continents, all the geographies, and we are doing a lot of good work keeping customers safe.
Absolutely. Absolutely. You know, to that regard, you guys recently published a report.
Why don't you tell us a little bit about it, Raj? Yes. Uh, so this is the Global Threat report, Alan, uh, which is something we publish every year based on the activities as well as the threat intel that we have, you know, connected or collected over the last few months and quarters in the most recent threat report, Alan, and we mentioned that we have seen a dramatic increase in cloud conscious actors, and these are actors or adversaries who are now very familiar with how customers are using their public cloud infrastructure and sometimes even private cloud.
Uh, they know how to move laterally, how to exploit weaknesses in your cloud security posture. And it's become a very big thing. We are also noticing commensurate a 75% increase in cloud exploits by these A actors, right?
So clearly the number of actors is larger, and each of these actors is targeting and exploiting vulnerabilities, misconfigurations exposures, or other weaknesses in your cloud security. Absolutely. com/global-tourette report.
Right. com/global-tourette report. You could download the report anyway, Raj, interesting.
You know, some interesting, uh, stats came out of the report, uh, intrusions into cloud infrastructure. I don't think people are surprised to hear they're up 75% and the number of attacks cloud-based attacks, so these may be successful or not, is up over 110%. So, so it's doubled over the last year.
You know, I've been in security 20 something years, 25, almost 30 years. It always used to freak me out, uh, back then how many attacks we have. But what really a lesson I learned, and it was actually when I left still secure, one of the companies I founded, was that would the amount of attacks increasing doubling every year.
Most organizations, even if you were a Fortune 500 or an s and p 500, you didn't have the resources necessary defend yourself without outsourcing, without third parties, without MSPs, without, I mean, it was a, it would, you know, in my mind there was a handful, maybe 50 or a hundred companies that really had that kind of juice where they could, you know, adequately defend themselves. They had the resources. I don't think that's changed, has it?
No, it hasn't changed. And the complexity has only increased. Got, yes.
Suppose there are more cybersecurity analysts, um, in the workforce today than say, 10, 15, 20 years ago. And the skillset has also improved over, but your thesis that most companies or very few companies have, the financial wherewithal to have enough security analysts reviewing and looking at all the threats in their environment doing threat hunting, keeping themselves safe, is absolutely spot on. There are very few companies who are able to do that.
Yep. And, and, and again, I, you know, RSA was what, maybe a month and a half ago. So we, you were out, you know, we were all out there at RSA and W.
What was interesting is, you know, we're hearing about this pushback from large organizations that, hey, we've spent a ton of money over the last couple of years on cyber technology, and we are not, we're not seeing the return, we're not seeing, we don't feel any safer or more secure. And for the most part, I think one of the problems is, is that we've, we've put our money into SAS products and technology, but we kinda left out the people and the skill gap in that, right? So what we've tried to do is make up for a lack of, 'cause people are, some are probably the most expensive part of the equation.
So rather than putting in more people, we bought more product, and it hasn't necessarily worked out. I wonder what you, what you think about that. Um, again, agree with that statement wholeheartedly, and, and it kind of touches some of the, you know, core principles of CrowdStrike, as the name itself implies.
CrowdStrike is all about bringing products and people together, the experts together to solve some of these really complex problems. Now, initially, as you said, customers were just buying products and was the onus was on the customers to install, configure, manage, as well as take care of all the threats and alerts that were popping up in their console. And we know numerous instances where that didn't quite work the way it was expected to, or it was designed to.
So when we, uh, started CrowdStrike, or George started CrowdStrike, well over a decade ago, he had this idea that we need to bring in the human intelligence, the human expertise to bear in order to truly prevent and stop the breaches. And that's exactly how it's playing out in all the realms that we are in all the different market segments we are in Alan, including EDR, right? Which is a, a whole category that we pioneered.
And the way we thought about it is none of the EPP solutions, these are the preventative solutions, are able to prevent all the different types of attacks because the adversaries were using various different approaches, whether it is living off the land attacks or, you know, just harvesting, um, credentials from the dark web and using that to enter your organization. So we introduced the concept of Falcon Complete, which is a service which over 70% of our customers subscribe to. And what this service does, Alan, is monitors as well as helps customers manage their entire environment, everything from the installation of the software, configure, configuring it properly, managing the alerts, doing threat hunting to see if there are any threats, unknown unknowns in your environment that you need to take care of.
And that's one of the reasons why we've been able to fulfill the brand promise of stopping breaches because combining the product with the people, we've been able to keep most of our customers safe, right? And, and we are clearly one of the most trusted cybersecurity brands out there today, mainly because this approach is resonating. This is one of the few approaches that has worked at scale.
Absolutely. So, Raj, one of the things I grapple with is how do you allocate prevention and response resources? Because they're, they're intrinsically linked on the, in terms of budget, manpower focus.
What, what's the right few loyal mixture here, right? How, because you don't want, you don't wanna go too far either way, frankly, right? You, you want to balance how, what's a company to do?
What's an organization to do today? How do they balance that kind of bringing balance to the force? I always pitch to my prospects that the way to approach this or think about it is not in terms of projects, but in terms of the outcome that you're after.
Now, most businesses will agree that the real outcome they care about is accelerating their business, keeping their customers happy, delivering value for their customers, and at the same time, protecting the data of customers. No matter where you, what type of business you are, you are collecting a lot of customer data today than you were a few years ago. So there is a lot of customer data, which means adversaries come after you, either to steal your proprietary intellectual property or to steal your customer information.
So how do you keep customers safe? And that's the main idea or goal behind most of the products and services that we offer, which is let's focus on the outcome and less so about each of the products, each of the, you know, point products that security is so good at, you know, uh, introducing just in the cloud space, Alan, for instance, it's an alphabet soup of, uh, various different points solutions. And there is A-C-S-P-M for just cloud, uh, configuration management and vulnerabilities, identifying vulnerabilities.
There is DSPM for data related configurations and exposures. There is an A SPM for applications, and you start scratching your head and wonder like, can one product not just cover all of this? And, and that's exactly, uh, you know, what brings us to C nab, which is a unified, consolidated attempt to deliver a service or a set of product capabilities that keeps the customer safe.
But what we are also saying to your earlier question, Alan, is that just the product by itself is not good enough. You need to combine that with people expertise. So at RSA, we in introduced a number of cloud data, uh, detection and response innovations.
And one of this includes managed threat hunting across cloud identity and endpoints with 24 cross seven cross domain threat hunting from Microsoft Azure environments. So this is something that is very unique. Most of our competitors just sell you a product and walk away and expect that, you know, that will keep customers safe.
And we know, sadly, that is never the case. We are also one of the preeminent incident response solution providers. So we go into many incidents and we have the, uh, opportunity to clean up and observe what's happening.
And most of the time, you know, adversaries exploit the weaknesses or lack of expertise. They love to live in the blind spots and uh, and in the shadows. And that's pro precisely what our cloud detection and response is, you know, tailored to fix, to make sure that you have the experts looking at the console and keeping customers safe.
Yep. So I think, Raj, one of the things I, and again, talking to people like at RSA and on here all the days is specific to cloud, right? We've got multi-cloud and hybrid cloud and serverless versus cloud and cloud native, and then Kubernetes and containers.
And there, there's so many flavors and types of clouds and like every organization has sort of a unique cloud footprint, let's call it. How do you normalize protection and response when it, it's almost like a bespoke industry, if you will, right? It, it versus having, you know, a standardized kind of solution.
Um, it is to a certain extent bespoke, but there are some common functions and services that almost everyone uses, whether it is in the form of virtual machines or as you mentioned, Kubernetes and as well as serverless functions and certain other services like, uh, app Engine and so on. Right? Now, if you look at the, you know, 80 20 rule, which is what is it that 80% of customers are using very consistently and commonly, um, it covers these services like EC2 RDS, um, you know, the functions, which is Lambda and a few others.
And we have optimized, obviously, for having better telemetry and visibility across these, you know, highly common popular services. But we also get the information about all the different services that a customer may be using. The average customer uses well over 20 different server, uh, if they're only in the public cloud.
And one of the beauties or interesting things that has also happened in this, you know, shift to public cloud infrastructure, Alan, is that almost everything is now API driven. There is much better logging and visibility and telemetry about these services than in the past. Back in the day when we were running our own colos or data centers, we didn't have this much, these many APIs, this much visibility into what was happening in the infrastructure because we were largely relying on operating system vendors.
But what Amazon, uh, Microsoft, Google, as well as various others like Oracle have done, is they provided a very standard and clean set of interfaces, APIs, as well as logs and telemetry that are now available for cybersecurity vendors to understand what's happening. So even though there is an element of uniqueness and, you know, uh, in the way customers use cloud, there are enough commonality and there is enough API support and visibility that we are able to work and pinpoint anything that may be off. Got it.
Raj, we're over time. It all, it happens. I, I gave out the, uh, URLI just wanna give it again for people who wanna grab this report.
com/global or threat or dash report. Check it out, Raj, my friend. It's great seeing you.
Keep up the great work. You know, sometimes as it is in security, the best job, the best way, you know, the best things we do, we don't hear about it, right? It's when we hear about these things that something went wrong.
But, um, say hello to everyone and keep up the great work. Thanks for being on Text Trunk tv. Thank you for having me, Alan.
Have a good day. A pleasure. Raj Raja, man.
Raj Raja, man, I messed that up. I apologize, Raj. Thank you.
We're gonna take a break here on Text Trunk. We'll be back in a moment.