Post-McAfee Cybersecurity – Gee Rittenhouse, Skyhigh Security
Continuing on from their previous conversation, Gee updates TechStrongTV on what Skyhigh Security has in store post-McAfee and speak to a variety of trends and issues. From ZTNA and CASB strategies to mental health and the democratization cybersecurity, Gee’s perspective runs the gamut, as he brings expertise from Cisco and Bell Labs to Skyhigh Security.
Transcript
This is texturing TV. Hey everyone, welcome back to Tech strong TV, you know, we had an interview last week aired last week with G writtenhouse. Who's the CEO of sky high security some of you I'm hoping many of you know already a little bit of the sky high security story who they are.
This is not your average security startup and but if you haven't I I do recommend especially if you're watching this on text from dot TV, you can scroll down to pass the interviews and you can catch the first interview with G on there and that might give you a little bit of the background for those of you who choose not to do so long. I'm gonna add G to kind of start off with a little bit of a foundational background on Sky High and himself, but it'll be shorter than the previous interview. Anyway, all that out of the way.
Gee welcome back. Thanks for coming back on technology TV. Thank you.
And thanks for the opportunity. It's always a pleasure to meet with you and the team. It's fantastic and it's good to have you on so G as I mentioned for those for those who maybe you're a little too busy today to go back and look at the last interview.
Give him a you know, a quick synopsis of the sky high story, maybe a little bit of your own background. Yeah. Sure.
So Sky High started by really focusing on data the data layer kind of security at it's hard security is a data problem and protecting that data and so as data really went from the data center into SAS and cloud and applications Sky High was formed to solve that problem whether it's on the web in the cloud or in SAS. We launched the company formally this year previously. It was acquired by McAfee and we started out I joined as the CEO.
At launch I come from a very long background in technology and security and Cloud software. So I really did look for the opportunity to take the company out into the environment by itself and serve our customers better. Absolutely.
Yeah, just in way back. I actually knew the original founding team from Sky High that was acquired by McAfee smart smart people. I thought that great product and they kind of got acquired by McAfee and and you know, it's hard navigating currents.
Yeah. I think this was Mac if he might have still been owned by Intel. I'm not even sure anymore, but it was a big.
Caution and and I'm glad to see it emerged now as and then really back to its Mission, you know, which was at its roots. Yeah. And in addition to that what what ends up happening is as you well know security and the security industry is all about Innovation and in particular focused Innovation around data and how to protect that and so when you're in a broader environment some of that gets deluded over time and so by bringing it out where we're able to focus continue to focus on the roadmap and and bring that Innovation into the marketplace which the customers really appreciate absolutely large large conglomerates like that or not.
Usually Innovation centers enough said, let's focus so, you know as we September, I can't believe how quick this year is flying by it's Already and as we look at kind of the horizon. You know, we continue to see digital transformation whether it's driven by covid or not. It's a whole other story, but we see digital transformation driving so much to the cloud.
Right from the data center. It's really accelerated by years, you know the amount of data moving to the cloud at the same time. I think we've seen a a reemphasis on The importance of data right?
It's about the data, right? We focus on the applications and the infrastructure and the identity and Mac access controls and all of these things but really as you mentioned so much of Securities about data. I'm interested.
She where do you see the market? Where do you see, you know where we've come from and again not long term because Who can see that far? But you know, where do you see us now?
And in the next six to twelve months? Yeah, it's interesting because as you said the cloud is changing everything for the most part, but in many cases our security approach as an industry, really remain the same it's still getting packets to the right place making sure they're the right packets and we've simply moved those functions from on-prem appliances into cloud and Cloud native functions and and called it something new but but the basic construct is still the same what we see now and and continue. I think we're still pretty much in the early stages is that this becomes really problematic you start to focus on individual Technologies, whether it's the end point Gateway or a firewall or any number of different things when to your earlier point?
It's all about the data. And so what ends up happening is you have all of these disparate Technologies each with their own policies and events and logs and whatnot. And you try to stitch them together to provide a coherent view of what you're trying to protect the data and what we find and what we we see resonating with our customers is to just flip this on its head if you want to protect the data, but the policy and enforcement and events around that data regardless of the underlying technology and so by focusing on that you can really simplify what you're trying to do.
And so whether it's in the cloud on-prem on a device mobile all these things really are secondary. When you focus and have that data first kind of view of security. Agree with you and you know quite frankly.
Look I Certainly unique place I get to talk to a lot of people and I I do I see us focusing on data and it's good that we we focus on the data. You know, there's so many aspects. of securing data Right, there's the obvious data at rest and data in motion and encryptions and all of that but there's also who has access to what data who has the ability to extract data who you know.
from a whole compliance perspective which is like a whole nother thing right how How do we keep what data and and all of these things I think to a lot of people out here, especially our non-security folks. I would developers and devops folks and Cloud native folks. data and security seem like such big domains How did they you know, how do you eat an elephant one bite at a time?
Right? How do you make how do you get your arms wrapped around that your head wrapped around it? yeah, so I think when when we look at it through that lens you one of the kind of modern approaches to security is something called a zero trust framework which basically means that as a user.
I'm not gonna have access to everything just because I'm associated with network or group or a device or whatnot. I'm gonna just have access to what's required of me to be successful in my job. So I'm gonna start with zero trust and kind of build from there.
We normally think about that through the lens of access and access to Applications. But as a developer, you can also think about it as you only have access to the part of the code base that you're responsible for that you don't have access to the entire code base because if you were Owned by some fishing or whatnot that would give the perpetrator access to the entire thing instead of a very narrow one. We extend that to the Enterprise and we extended to users as well.
But one of the key elements that where we've extended this principle is not just having access to that code or that data or that information, but how it's actually used. So where most people restrict just the access we go further and say what are you allowed to do with it? Once you have access to that and we call that data aware.
But basically it's extending the zero trust formalism into usage as well. And so yes, I can what developers see this all the time. You can't just publish code.
It has to get reviewed and and approve before you publish it. You can't just download the code because you know, the whole repository you can only take Cases that you're allowed to do and so these kind of things even if you're not a security professional you can recognize some of the good processes and approaches that we use insecurity as just good hygiene even for code and development. Excellent.
I I agree with you and you know, I think zero trust is if you went to RSA this past year there was the you know, that was the main theme of RSA conference and so zero trusted something. I I think people are starting to Understand the necessity of you know, it's funny sometimes security people get a bad rap G right because yes developers. No, we do though developers understand that just as you said, but when it's the security people telling the developer, they can't do it then it's like, oh those yeah those, you know, rotten security people.
They're always saying no, they're always slowing me down. Right? And so there is I mean, it's gotten better with the whole Advent of defect Ops and everything.
There's more cooperation, but there's still some of that that goes on there. From where you sit how do you see this playing out? Over the next you know, short-term little longer-term thing is is it building on that?
Is there anything else on your the horizons that you guys are already starting new? You know, yeah, so I I think you summarize the problem really well by saying look developers want to just push features and bring their Innovation to Market as quickly as possible, by the way. Prizes want to bring their goods and services to the market as quickly as possible and historically security has been viewed as a blocker because we want to put some control into that and so the kind of next step of all of this and one area that we've spent a lot of time and attention on is to make it as simple as possible that people can produce features and functions in a secure way without even really trying because it's built into the pipeline.
It's built into the methodology. And so as you get trained up in your particular Pipeline with compliance and everything else, it's just just part of it so you can post a feature functionality quickly but still do it in a way that is secure we can look at those. Loads and make sure that they're not vulnerable and if they are show you or make sure that the posture is correct or any number of different things in a way that if it's done easily and in an integrated way does not slow down the innovation of an Enterprise or of a developer.
a great Great. Sorry an interesting article the other day about. So they called it super cloud.
But what they were really talking about is this the amalgamation of all the different Cloud providers into one amorphous Cloud the cloud right kind of yeah. So I mean, you know, my wife's sister for instance thinks of the cloud is just a single place up there the clap. Where did but it's almost true.
That's kind of where we're heading. What is that? What are the implications of that for Sky High right people don't care Amazon Google Microsoft.
It's the cloud. So we see we see this happening because of companies wanting to execute in different regions with different Niche clouds large clouds Etc. And so there is this thought around the super cloud of abstracting out all of this to have one orchestration layer or one load balancer or whatever and and that's pretty tough to do because these clouds are built purpose built for compute memory and networking.
So they have a lot of feature functionality but one of the kind of common topics across all of this is security because from a security perspective each one of these large Cloud providers. Well, they have a lot of depth they're different between the two and Attackers can exploit the fact that there is these differences and gaps in your security profile. So if you're able to abstract out your security profile to cover all of them, then you have an advantage and so this is exactly why we built a platform and why we integrate in with not just clouds but as I said before and points and SAS and everything else because that is the model so that you have one view of what you're what your date is doing and where it is in regardless.
What particular Cloud it's in or what infrastructure it's on and so by being able to security is one of the really powerful use cases of this abstraction provided by the super cloud. Rather than just a compute and and memory and and networking pieces of it. A great a great Chief.
We're almost out of time. But what else do you have to share any you know, and I don't say anything that's gonna get us all in trouble. But what what is Sky High have up their sleeve maybe in the before the end of the year or right after the year?
Yeah. So as we we execute this year, it's all been around some of our key products in the portfolio a casby or a web Gateway. We see more and more customers though as we start to go on that maturity curve start to expand across the platform and really start to take advantage of some of the things that we were talking about so that they can have a holistic view of their security and really start to reduce the attack surface around the cloud and whatnot by applying these zero trust Frameworks.
Yep. Zero trust. All right G writtenhouse.
Thanks so much for coming back on. I appreciate your your time. You know what we didn't mention people who want to go check out more about sky high security the website.
com. Excellent. Hey be well best of luck.
Hope to see we're gonna take a break here on text drunk TV. We'll be right back.