Integrating Security Early in Software Development with Snyk’s Danny Allan
Danny Allen, CTO of Snyk, stresses embedding security early in development. By shifting left, Snyk enables early vulnerability detection and fixes. He highlights AI’s dual role—creating risks but also enhancing security. Snyk’s AI Trust Platform supports this with intelligent automation.
Transcript
Hey everyone. Welcome back here to Techstrong tv. You know, I'm really happy to have my next guest, uh, back with us.
His name is Danny Allen. Danny is the, uh, CTO over at Snyk, and I just found out Danny is an avid boater, in addition to being a crazy hockey player. He's an avid boater.
So we, we just spent way too much time probably talking about boating and, and all of that good stuff when we have work to do. But Danny, captain Danny, we should call you. Welcome back to Techstrong tv.
How are you? I am doing well, Alan. It's always great to talk with you and there's a lot of analogies here, right?
Because when you're out in the water, there's all kinds of chaos and big seas and similar to the tech industry, right? Yeah, it is. Say that again.
There's certainly waves in the tech tech industry that are crashing on here. Um, hey, Danny, for people who haven't caught you before on Techstrong tv, give them a kind of sense of, you know, how you wound up here as the CTO at Snyk. Sure.
Well, I've been in the security industry for 25 years and mostly focused on application security testing software, because of course most of the vulnerabilities and a lot of the threats that we face today come because of software. And so I started my career way back as a pen tester, but then found my way to a company called Watchfire that did dynamic application security testing. Essentially, we'd crawl web applications and look for vulnerabilities.
And ever since then, I've been very fascinated in the software security space. And I had the opportunity about 18 months ago to join a team that I'd worked with before here at snyk, really focused on the mission to secure all of the software that is coming through modern pipelines. And it was exciting and I joined up.
Very cool. And they're lucky to have you, Danny. Most of our audience is familiar with snyk, but there might be some folks who aren't, you know, there's a new folks watching this.
How would you describe Snyk to them? Sure. So Snyk is about a decade old, and the founders of snyk really came in with a mindset of let's shift security left.
Because security historically has been always the afterthought. You bolt it on after you build the infrastructure, right, the application, and you do the testing at the end, and then you're host faced with this Sophie's choice of, you know, do I release the insecure software or do I slow things down and go back and fix it? And so the founders of snyk came in and said, let's take all the security testing, let's build it in at the very beginning of the software as it's being created.
And they were really focused on, uh, open source software components and testing those for vulnerabilities. And over the last decade, what we have done is taken one type of specific security testing, which was, uh, open source security testing and expanded it into static application security testing, and IAC infrastructures code testing and container testing and all of these different things. But the, the real focus, Alan, has been on shift.
It left so you, that you find the vulnerabilities as early as possible and then focus on remediation. Don't focus on finding issues, focus on remediating the issues and eliminating them early, early on in the cycle. Fair enough.
I absolutely, and, and, and you know, look, NY has been a, uh, a pioneer in this whole shift, left DevSecOps, and of course that's led to software supply chain security and the SBOs and, and everything. And it's part of wrapped up now into platform engineering and, and all of these things. So it, it's a big piece of it.
Now, what I didn't mention, Danny, was AI can't have a tech conversation these days without mentioning ai. And you knew it was only a matter of time until someone said, Hey, let's take AI into this shift. Left DevSecOps world, um, May 28th, almost a month ago, by the time people see this, um, NY launched a whole new platform around it.
Tell us. Yeah, well, we were talking about boating, and so I liken this to the, the perfect storm in terms of a terms of ai because three things have been happening, three storms converging. One is that developers are using AI to write code more than ever.
In fact, recent studies have said that, you know, 75, 80% of developers are using these coding assistance, and the result of that is more code faster than ever before. The second thing that is happening, the second storm, if you will, is that there's a whole new type of software being written that is using ai. And so you have a whole new attack surface.
We saw just last month with copilot this echo leaks vulnerability or the, you know, there was the, the lang chain, uh, vulnerability that came just recently. And so all of these new AI applications also increase the attack surface. And then the third storm that is converging is that attackers are now starting to use AI to create even more sophisticated attacks.
And so AI is causing a huge amount of change in the industry at a very, very rapid pace. And of course, we have the opportunity to build security in from the very beginning. And so just like Snyk kind of flipped DevOps on its head and said, we're gonna do security early in DevOps, we believe at SNYK that we have the opportunity to embed security early on as we adopt all of these AI technologies within our organizations.
Sure. Absolutely. Um, now Danny, and don't take it the wrong way, but everybody's announcing an AI strategy, right?
What, so two things. First of all, how real is, is this s sneak AI trust platform? Not that it won't be real or that it's a figment of someone's imagination, but how much of it is aspirational versus available right now?
Right. Well, Yep. Well, let's start with that.
Well, I would say two things. You're absolutely right. A lot of the AI that I hear about is marketing, marketing, like everyone's talking about AI because they wanna make themselves relevant.
However, what I'll say is that SNY has been using AI specifically in machine learning within our platform for well over five years now. It's, it's not something new for us. In fact, the way that we could do the analysis as quickly as we could do it was because we were using something known as symbolic regression analysis.
It's an ML technique. The second thing that we added a few years ago actually was also generative AI fixes, because we recognize that you're slowing down developers if you ask them to go figure out how to fix particular issues. So if they have a SQL injection vulnerability, you know, it slows them down to go read about it, figure out what they need to do and implement the fix.
And so we actually implemented generative AI fixes within our platform almost two years ago now. And as part of this AI trust platform, which I'll get to in a moment, we've expanded that. So it's not just doing it within the IDE, we're doing it within the workflows for the developers.
And so what I'll say, Alan, is it's not just marketing with us. We have been doing this for well over five years before AI was cool. Now, the interesting thing for me is not just AI for snyk, which is what I've been talking about, us using ai, but SNY for AI as organizations build these AI native applications.
Of course, I talked about this increased attack surface. And so one of the things that we're doing is, for example, giving organizations the ability to test for things like prompt injection. Again, that that is in our platform today.
We track source to sync is, is the data going to an LLM? Is it coming out of an LLM Or for example, we demoed, we've been doing SBOs for a while, you mentioned that earlier. But what about an AI bomb?
Give them the inventory of all the large language models that they're using and all the components used in conjunction. And so all of these things are very real. And ultimately the purpose is to give our customers confidence, trust in AI as they adopt it within their organization.
Absolutely. Danny, just going over the notes, five new AI powered innovations in this platform. Could we just hit, hit the five?
Sure. So really quickly, AI security, posture management, I just talked about that, that's sneak for ai. So testing for things like prompt injection, giving an inventory of all the AI components.
So very real, very tangible for, you know, the, the lead engineers who want to know what's being used where across the organization. Secondly, sneak assist. It's basically an AI powered chat bot.
So as your platform engineers or developers or security engineers have questions, it's powered by our learnings within the LLM so that they can say, what is secrets? How do I solve this particular issue? And so that is NY Assist, um, is what that is called.
The second, uh, or the third one I should say is NY Studio. Now, as developers are adopting copilot and Cursor and Windsurf and Code Assist and all these different coding assistance, what we've done is exposed our capabilities via an MCP server that stands for Model context protocol so that they can integrate with these coding assistance. So as it generates code, we will secure that code.
And that's called snyk Studio. That's the third capability. The fourth one is snyk agents.
So as I said before, we have been fixing issues using generative AI now for several years. And we were doing that within the integrated developer environment, the IDE for the developer. But we've expanded that to do it as part of a PR check.
So when you're, when you're checking code into GitHub or GitLab or Bitbucket or one of these scms, we will also not only test it, but generate the fix as part of that workflow. And so that is known as sneak agent. And then the, the fifth one is sneak guard.
And so we believe in the long run, Alan having policies and guardrails to prevent issues from being introduced is really the long-term objective. And so for a while we've had the ability, for example, to prevent critical vulnerabilities from being checked into your source control management. And so it's really taking the guardrails that are needed by the organization and putting them on steroids, powered by AI to make your business smarter about the code and software that you're writing.
Excellent. Very cool. com, but like what's the on-ramp to, to start using this platform?
What, you know, what's the path they should take? io. That is our, our website.
And you can sign up actually for a developer account for free. io. And so our content on how to secure AI powered software, this isn't just traditional software.
The content is all free. You can go learn about the top 10 LLM threats, you can learn about API AI security threats. io is the starting place for most organizations.
And like I say, the content to learn about it is free. Very cool. Danny, you know what, I, I would expect Snyk to be a leader in this field because you guys have been a leader, right?
For going on, as you said, almost a decade now. So it'll be interesting to see how this plays out was to a certain extent. The whole AI thing gives, it's like a little bit of throwing the cards up in the air and seeing where they land this time, right?
But, um, you know, leaders lead and, and that's, uh, something that I've learned the hard way over the years in, in, in my business career. So looking forward to continuing to hear more about Snyk and what they're doing here at this AI trust platform. Well, thank you Alan.
It's, it's definitely exciting to be out on the forefront on this. And we don't, uh, our focus is to enable organizations to use ai. It's a very exciting time.
We just want to do it in a way that gives them the trust in that AI as they, you know, increase the productivity and momentum of their respective businesses. Excellent. Hey, thanks for coming on.
Keep us posted. I hope to see you in person soon. Maybe on the boat down here.
We'll see how that goes. But for now, uh, captain Danny Allen, chief Technology Officer at Sneak here on Techstrong tv. Keep up the great work, Danny.
Glad see no black ice from hockey today. So that's all good. Uh, of course our Florida Panthers are one game away from the cup over here, so people down here in South Florida are excited.
But, um, we'll speak to you soon. Alright, Thanks Alan. Alright.
Danny Allen here on Text Drug tv. We're gonna take a break. We'll be back with more in a moment.