Privilege Control and Threat Protection with Delinea’s Phil Calvin
Delinea, a pioneer in securing identities through centralized authorization, announced the introduction of Delinea Privilege Control for Cloud Entitlements and Delinea Identity Threat Protection into its cloud-native, unified identity security platform. Phil Calvin, chief product officer of Delinea, discusses how these additions allow enterprises to adopt an intelligent, risk-based approach to identity threat and further position Delinea to lead the $13 billion identity management market.
Transcript
This is Textron tv. Hey everyone. Welcome back here to Techstrong tv.
I got a, a first time guest here to, uh, introduce you to, his name is Phil Calvin. Phil is the Chief Product Officer with a company called delania. Hey, Phil, welcome to Techstrong Tech, strong tv.
It's great to have you on. Thanks, Alan. Glad to be here.
My pleasure. So, Phil, I guess we should start with Phil, you know Sure. Obviously I said your chief product officer at Deline, but, you know, give people a little bit of the sense of the path you've taken.
Sure, absolutely. So, uh, yeah, so as, as, uh, as Alan said, my name's Phil Calvin. I'm the, uh, chief Product Officer at Deline.
So I've been here for about three years. Um, I've been building software since I was 10 years old. I, I started by deconstructing a Commodore Vic 20, which should give you an idea of how old I am.
Uh, I'm dad ilk of that age. Yeah, yeah. And I started, started really, uh, building, getting into the world of, of computer science when I was in high school and, and started my professional career.
Got a job at Microsoft as an intern, working in their languages department and Wow. And then moved on to, uh, some, some really interesting work with, um, Rockwell software and building some manufacturing control systems. And so I've, I started in an early age building software that is, that is extremely mission critical.
Um, took a few swings at being an entrepreneur in the, in the tech nineties, um, crashed a couple of companies into the ground, um, managed to steps. I Mean, we all that's the best way to learn. Yeah, totally.
Is managed to sell one to, uh, to Citrix, which in 2004, which was, uh, one of the first versions of S-S-L-V-P-N, um, yeah, some early security architecture, security enterprise world. Um, spent some time in Citrix as a principal architect and then went, took some time off and started another company and managed to sell that one to Salesforce in 2010. It's sort of grown into become Salesforce communities, if you know Salesforce.
Sure. My path at Salesforce, I ended up leading the Lightning platform, uh, re-architecture of Salesforce, and ultimately the platform engineering team. So I got to again, kinda build on the, on the model of building large scale platforms that, that run forever.
Um, and that's kind of our, that's kind of the DNA and got brought into delineate about coming up to three years ago, um, to, to help, help the journey that we're on. So, very excited about that. What a great, what a great story.
A great career, man. Congratulations to you. Two, two exits.
There's something to be said for that, right There. There is. Yeah.
It's, you know, it's, there's a lot of hard work. I, uh, I, um, I'm very fortunate in that I love building software and I love working with people and teams that build software. There's technical components to it, there's organizational components to it, and then there's, there's the right product and what you're trying to build component of it.
And it, it's, uh, it's all super challenging and, and, you know, you wake up every day, the day is different and, and it's, it's, it's a new challenge and I enjoy that. I always have. That's what keeps me going too.
I, uh, you know, have a similar so note story, so, you know, just keep, keep banging away at it. But if there's other thing, there's harder ways of making a living is what I always tell people. If you're doing something that gets you, keeps you excited every day, it's great.
Yeah. Um, so Phil Deline company may not be familiar, familiar to our audience. Why don't you, it, June, you did such a great job on your story.
Let's hear the deline story. Sure, absolutely. So Delineate is the product of two, um, two companies that got, got bought and merged together.
One of them is psychotic, uh, which started off in the privilege access management space. Yep. Being, uh, uh, secrets and vaulting and, and really providing that side of the, that side of the access and then Centrify, um, which provided, uh, just in time and just enough privilege on and ad bridging for some of the, the technologies.
And so those two companies were bought, um, and put together, um, and, uh, and with the idea of let's turn this into one thing, um, and, and make, and that that product, that company is called Deline. And so when I joined, we had about, uh, eight or nine different standalone products. All had some really great technology to them, but they were very different, different animals.
They had different software development life cycles, they had different consoles you would use. They had different sort of ways of operating. And so we, we started on this journey to build, um, what we, what we now call the delineate platform.
Um, and this was taking a lot of the great technology that Dichotic and Centrify had, um, but modernizing the infrastructure around it. Uh, so building a cloud native foundation for deployment. Uh, all the nor normal buzzwords that you, you would hear in terms of running things at scale in the, in the modern era.
Uh, built all that up. We launched the platform about a year and a half ago, um, bringing initially the, uh, the vaulting use case onto the platform and, and, uh, and scaling that up with a privileged remote access solution. It's near and dear to my heart.
It's like the next few generations of my S-S-L-V-P-N from 2004. So it's, it's very exciting. We just recently launched what we're calling privilege control for servers, and this is another module on the platform.
Um, the, the really the important part about building something that is a platform, and you think about that, there's a couple of parts and pieces you have to think about. Um, one is, uh, they have to run forever. You just have to, you know, it has to be, have this DNA that the system doesn't go down and, uh, you know, it's an aspirational goal.
Um, we actually build that into our DNA of the company comes from my early, early roots in software that you're building, mission critical systems. Um, and so you have to build that into your entire life cycle. Quality isn't something you sort of beat into the product at the end of the day.
It's something that you have to build right from the beginning and into your SDLC. Then the second part of it is you have to make a console, an actual unified console. You know, in my Salesforce days, we had a, a whole bunch of Scrum teams building the Lightning platform, but it looked like one team built it.
And so we have that same mental model at, at, uh, at Dely with our, with our platform. We've got about 35 scrum teams that are contributing to the, to our platform on an ongoing basis. Um, and they use a common user interface language.
They use common user interface components and flows and navigation so that as you move around the platform, it's very familiar. It becomes something that is easy for you to, to add onto, um, and easy for as a user to adopt, uh, to learn. The patterns are simple and, and, and, you know, that's sort of the core out to what we're building.
I love it. Just a quick little, uh, extra on, so Dichotic and Fire they brought together, was this like a PE sort of deal? That's correct.
That's correct. So, um, TPG, uh, bought the, bought the two companies. Um, who is it?
Uh, our CEO in charge named gentle, named Arg, Gilland, uh, art. Art. And I have actually had actually known each other for about 10 or 15 years, uh, beforehand.
And so when there was an opportunity for me to come and, and work with the art and the rest of the Dilan leadership team, uh, it was, uh, it was really exciting. Uh, the company's growing really well. We've got, uh, uh, you know, all the incredible financial metrics and all that kinda good stuff that we're very excited about it.
We're about coming up to about a thousand people, um, as an organization. And wow, just a little over, little over 300 million a rrr. Um, you know, our, that's fantastic in our books and, uh, you know, congratulations.
Our, our financial, uh, leadership keeps us up running as a sort of rule of 40 company. So all those kind of good things. So we're, we're, uh, we're enjoying ourselves.
It's, it's a great company. Good stuff. Um, Deline is D-E-L-I-N-E-A.
com? That's Correct. Yeah.
Got it. Yeah. Alright, so Phil, we did, I think all of the foundational kind of background here for our audience feeling, you know, like they're empowered.
Um, let's talk about some recent launches from deline, some new organ, uh, some new capabilities, if you wouldn't mind sharing. Yeah, absolutely. So, um, uh, as I said, we, uh, we, we launched the platform about 18 months ago, and that is sort of the core what was dichotic and ified use case, and that was sort of the core privilege access management.
But you know, because we've built this foundational platform, we have this, we have this ability to add to it very quickly, whether that's by our teams building new technology on top of it or, or by or by acquiring other companies. And so we've, uh, this year we've actually acquired two companies. One was a company called Optimize out of Tel Aviv, um, mm-Hmm.
And Optimize brings CIM and uh, ITTR, uh, capabilities. I'll talk a little bit about how we're integrating that. And then in April, we, uh, acquired a company called fastpath, which brings sort of a lightweight IGA technology as well as, uh, SOD technology, which for me, I think of SOD as Pam for line of business.
It's not the, that's not marketing, but that's kind of how it is. It's just in time access to your NetSuite and all that kind it's stuff. But so the, the, as we looked at, at expanding beyond just pure privilege access management on the platform, the key part for us was how can we bring these new capabilities into the platform and, and satisfy the, the core tenants that I talked about.
The user interface has to marry up the, the, the reliability and quality needs to be there. And so when we brought in optimize onto the, onto the platform, um, it, it now, uh, this is about six months after we closed the acquisition and, uh, optimize is actually just going generally available in the next week or so on our platform. And it doesn't look like some bolt on, it doesn't feel like some bolt on the team has done an incredible job, looks, looks building like as if we built it ourselves.
And, and what that allows our customers to do beyond the technology is, you know, cloud entitlements management basically gives you the idea to find, find all your admins, find all your shadow admins, all as you sprawl, every company customer is on their, some journey to the cloud, whether they're lifting and shifting their, their, their, their workloads up to the cloud from their own infrastructure or whether they're, you know, building net new Kubernetes deployments and all that kinda stuff. And so you have this identity proliferation that's going on. Um, and, uh, optimize allows us to, in the platform, find all your admins, find all your, um, shadow admins, see what's going on with those accounts, what kind of privileges do they actually have, and what do they actually need, and then reduce those so they have just enough privilege.
And, you know, tying it into the, the broader delineate story, if I finding an identity that actually does need a, a huge amount of privilege, I can then bring that into the vault and I can vault that, that particular credential. And I can find that very easily. And that's the, the really exciting part about the CIM side of, of optimize on the identity threat side.
It will, it will provide the ability to deck detect things like brute force attacks or MFA bombs and all those things in a very, very manageable console. So we're very excited about that, uh, bringing that on as just a, uh, uh, as a way to sort of continue proliferating the identity security story and, and with authorization as the core, as the core part, what are you actually allow authorized to do and at what point. So we're very excited about that.
Absolutely. Hey, Phil, you know, we live in a world of acronyms and for those of us in the industry, when you say things like CIEM or ITDR, we know just what you're talking about, but there may be some folks here who maybe aren't security folks, you know, come at it from a different site who would not familiar, if you wouldn't mind, just, would you mind, well, if you wouldn't mind is what I asked you, not if you wouldn't mind. Um, when we say CIEM and ITDR, what do we actually, what do those stand for?
What are we talking about? So I, I, I am actually also, uh, one that I, I actually despise acronyms, so I try to use them as little as possible. Um, uh, to me, so if I look at my cloud infrastructure entitlements management, so CIEM Yeah.
What, what does that actually mean? So, so every time I spin up a new service on AWS or Azure, I've got a, I have an identity that u that uses that, there's, that there's a machine account or there's a, there's a human account that's able to do that. What this does is it basically allows me to see my identity posture.
Where are my identities being used? What are they being used for? What are they allowed to, to do?
I don't under what circumstances? And so breaking it down very simply from the, from the acronym warfare that I think that we, uh, we in the industry often in Florida, implore on our customers, um, what that allows you to do is find all your, your admins and your identity risks. So if I all of a sudden look at an, look at a, an a, an account that's got admin access across all of AWS, well, that's a massive, that's a massive risk.
I may not know that. It may just, it may just have happened through na natural proliferation. And so rather than say you need CIM, what I'd rather say is like, let's look at where your identity risks are, um, and we can look at your cloud infrastructures as well as your on-prem infrastructure.
We can find those, find those risks of your identities where you have overprivileged and you have too much admin, um, uh, uh, privilege sitting around. And then, and then you can con control that and puts you in charge of it as opposed to this acronym or that acronym, um, ITDR on the other side of it is identity threat detection and response. And so this is the notion of what is actually happening in real time.
If I'm getting an, uh, you know, brute force attack on a particular account, uh, brute force password attack on a particular account or, or MFA bombing where somebody's could be susceptible to MFA fatigue in order to get on or, or other types of, uh, uh, types of identity based attacks. Um, that is, as, again, these are very specific things that customers see. Um, the, the, I try and stay away from the acronym warfare.
It, it, it, I think it confuses people more than it, uh, more than it helps personally. Absolutely. And I don't disagree with you.
Um, so we've got a few minutes left. I wanted, like for people out here listening saying, you know, it sounds good. We, we have a solution that does some of this, we're not happy with it, or I'd really like to check de linea out more.
com, but kind of a little bit more than that. What's the on-ramp here to, to get started? So, you know, one of the, one of our core values is, is ease of use and time to value.
Um, for, for a deployment for, um, a very, for, for a straightforward, say a say a commercial organization that's got, you know, relatively simple network and, and all that kind of stuff, um, you could go from, from concept to running in a matter of a few hours. Um, you'd be able to run discovery on your networks to find all your admin accounts. You could start to vault those, vault those away.
Um, we have a, a trial on our website for the, for what we call the de delineate platform. Um, once you register for that trial, it's a 30 day trial, what you'll do is you'll get a link and you'll set up your, your, your cloud tenant, which we spin up for you automatically through our, our, our systems architecture. And from there you can explore the, the parts and pieces of the delineate platform.
If you're looking to, um, to looking at your wanna of see what your cloud identities are doing, you simply provide a connection to your AWS or your, um, or your Azure or Ping or Okta or whatever you happen to be connecting to. Um, you can add your, uh, login. So you can log in using your ad users very quickly.
For more complicated, uh, customers, it can be anywhere from a month to two months to get set up if you've got, you know, multiple domains in multiple areas that you have to figure out. But the, uh, the onboarding is intent intentionally, um, and, and consciously very quick firm for what we're trying to do. Excellent.
Excellent. Uh, bill, I want to thank you for coming on and, and making us a little smarter here about the linear and, and some of the things that you're doing around identity security. You know, I've, I've always said, I I think identity and access management are the, the key, the killer apps for cloud security, right?
Yeah. Because I mean, I grew up in a security world where it was more land and you had your moten castles and your big boxes in front of your infrastructure. We don't have that in the cloud, right?
And we're, we work, we do anything from anywhere all at once, right. And, uh, you need, you need, I mean, identity and access control is, is the, the killer app for that. So, good Stuff.
I totally agree. Yeah. Mm-Hmm.
Totally agree. I think the, uh, the world's shifting from sort of an infrastructure focused security to an identity focused security, and yeah. You know, if you add the who, who you are and you, and you put that in with what context is what, what you're trying to do, then, then that's where, that's the new perimeter, uh, rather than the sort of castle and mode architecture that you had.
Absolutely. So who are, in a lot of cases, it's what you are too, because there's more non correct nonhuman identities than there are human identities, right. By a lot.
Correct, correct. So it's crazy we're out different than when we started, but Phil, continued success to you and all the folks at deline. Congratulations on the acquisitions and everything going on here.
It looks great. Come back and keep us posted. I will, Alan, thank you very much for having me.
Alrighty. Phil Calvin, chief Product Officer at Deline here on Tech Trunk tv. We're gonna take a break and we'll be back with even more.