Security for Unmanageable Applications – Bel Lepe, Cerby
Cerby officially launched the world’s first security platform for unmanageable applications, an approach that empowers both employees and security teams. Cerby has also secured $12 million in seed funding, bringing its total funding raised to $15.5 million.
Transcript
This is texturung TV. Hey everyone, welcome to another text drug TV interview. I am really happy to introduce a first-time company here on techstrong TV, and and we also have their co-founder CEO on let me introduce you to Bel Lepe.
Bell's over out in San Francisco area Bell, welcome to text strong TV. On thank you so much. I really appreciate the opportunity to be here.
It's a pleasure to have you on so Belle. I I will tell you of all the different kinds of interviews we do here at Tech strong, you know doing that new company. Was announcements coming out with the co-founder CEOs, probably my favorite.
So first of all, congratulations on on the company the name of the company you should we get this right to serve you. Correct, right, correct, and what you spell that for our audience, so just so we're clear. Absolutely, so it's serbi cerby.
It's actually a play on Cerberus which happy to go into but the company name is serbi. And the and the website just so we get that out of the way. com, excellent targeting those kind of four letter domain.
We were we were fortunate it was available. Yes. Yes.
All right. So let's start there. They'll give let's tell the audience a little bit about survey.
It's Herbie and a little bit about your background. Absolutely. So a little bit about us.
We're a company that recently stepped out of stealth a couple weeks ago as part of our stepping out of stealth. There were a couple of notable announcements first is the launch of our platform, which is a first of its kind platform that helps business users select any application for them to be using within their workspace today. We work with companies like Televisa dance to me Salud to name a couple of the customers at working with we're all so announcing research that we conducted with the austerman research team that talks a little bit about the situation in which, you know, our product exists and happy to talk a little bit about that and last but not least also now and our 12 million in funding from Founders fund Ridge Ventures Salesforce Ventures and knock Adventures.
So that's a little bit about the company again. We're cyber security company and some of the announcements now, My own background. I'm a second time founder most recently working in the media and entertainment space and one of the actually motivators for my founding Serbia's we worked with companies as part of my last company.
We worked with folks like ehp, HBO and ESPN and one of the things that I realized is part of working in that space is that well, there are all sorts of really important IP that get generated right? We were working with folks like HBO and they were spending 30 million dollars on Game of Thrones episodes the liability that we assumed in managing those episodes. The part of the production process was significant and that really was one of the major motivators for founding survey realizing that the domain the the surface area that companies need protected is growing and there are some cybersecurities focused on protecting the most obvious elements, but not everything gets covered.
So survey really helps with a lot of what I felt was not being properly protected properly monitored properly handled from an end user perspective. Okay, you got me. So what what do you think isn't being properly handled and protected?
So today one of the types of applications that exist are what we call unmanageable applications and these are applications that end users on board often outside the purview of it. So imagine someone goes to a website they put in their credit card and they start using the application right away. Now over the last few years.
It's become easier for end users to be able to do this because we're all we were all working from home, right? We were all accessing maybe our our work documents on personal devices personal networks. So it became easier than ever before for us to start leveraging our own technology.
Now, the issue is one out of every two applications that are now used fall into this bucket of unmanageable applications and these applications cause one out of every three cybersecurity breaches that occur out there. So it's not only the case that there are more of these applications. They're also generating more risk than ever before and so That's an example of a type of application.
That just is not getting the attention that that it needs. So let's talk about that a little bit about so and we've all probably been guilty at this at some point, you know you doing something hopefully work-related and man I I need this. You know, I I need some secret decoder.
I need something that's gonna make my job easier. I need this to access that that's great. I just go up.
I I register I put in my under not gonna put in my work email. I don't want them spamming me. I'll use my personal Gmail Hotmail.
Whatever Yahoo! And it's 99 cents a month. No big deal, dude.
Yeah Apple pay it or whatever and I'm boom. I'm on it's happening to me right every every six months. So I got to go through all of my like charge and and apples and all of these things to see what's on subscription that I used once and never used to get Those are the AppSec were talking about.
Correct. Correct. It could be email marketing platform could be corporate bank accounts corporate credit card accounts social media.
The average user has anywhere between 100 to 150 of these applications that they use over the course of a year. And sometimes you're you may be uploading sensitive company data into those applications. So you're exactly right.
Everyone is guilty. You know, I say an error quotes of this and at least in some capacity. Yeah, and so So is your job to make people aware of what they have?
May God the it administrators aware of what other people are doing, or is it just a block these sort of unmanageable applications? Great great questions. So historically the approach has been to block access and what we found is that's not an approach that works holistically or comprehensively and the reason for that is for some applications.
You might be able to get away with it. But the reality is blocking access to an application actually encourages a user to go around your infrastructure and use it anyway right away people kind of stuff, right? Yeah.
Exactly. That's one of the labels that is alternately used to refer to unmanageable applications. And you know, I think it's human nature when you tell someone not to do something that kind of even maybe increases their desire to go and do it.
Anyway, exactly and so Actually as part of recent research that we conducted what we found is that 92% of the hundreds of users that we spoke to want full control over the applications that they leverage so vast majority of users want to be able to have this control and so our approach is not to block access. Our approach instead is to allow that access to allow it securely so our aim is to be able to strike a good balance between autonomy or agency over the technologies that end users can use but do in a way where they're not putting themselves their company or their company data at risk and being able to strike that balance. That's something that's very novel because again historically most of the approach around this has been around blocking around enforcing a certain set of policies.
We instead take more of an enrollment approach and what we found is that is far more effective at ensuring that security policies are observed across across the board. It's a little bit more. More carrot versus stick if you will in terms of our approach.
Got it. You know. So I've been in security for 25 years.
Right and this is always a dilemma, right? You don't want to be the people who say no to everything but, you know quite frankly giving everybody. On tethered unhinged access to everything they want on the corporate Network.
You're running over a corporate Network or accessing corporate it? It's the kind of stuff that keeps you up at night. Right as you see so or security person and striking that balance is really hard.
You don't want to be big brother. You don't want to monitor everything that goes in and out or maybe you do. I don't know but it's it's a hard one.
So, how do you how do you guys Do this. Absolutely. So automation is a really big part of how we're able to achieve that balance.
So let's you know, let's look at why these applications generate anywhere between one out of every three or two out of every three cyber security breaches. The reality is when end users on board their own applications, they're focused on productivity. They're not focused on necessarily configuring a strong password enrolling two Factor authentication or let me give you a classic example, you know, maybe they get a a request to be added to HubSpot and the users give an administrative capabilities when they only really needed read only capabilities to pull this report, right so they get over permissioned and so this happens time and again with applications that are administered by you know, your average and user what our platform does is it takes that user out of the critical path for the security hygiene tasks.
We can automatically once the account we're given access to the account. We can automatically update. Words to make sure that they're always secure we can automatically enroll to a Fae.
We can automate automatically add and remove access. So you never have a situation where maybe a third party that you haven't been working with for months is still retains access. We can also monitor what are user is doing in the application and downgrade their permission to only be the permissions that they need.
So all of those reasons why you might have heartburn over user selecting their own applications serbes able to help the user nudge the user towards the right action. If not in some cases actually carry out that action altogether. And so this is how we're able to achieve that balance.
We can give users the freedom to use any application because underneath the hood we're taking care of all those actions that end users often forget to carry out themselves. I love it. How is this package meaning ballet cows?
How's it sold price? Is it that's you know, what? What's the story?
So it is that we are a SAS off. So we're able to work with any application. That's that's delivered over the wire so to speak and we price primarily on the number of applications.
So what we found is that you know, we don't want to price on the number of users number of devices number of clients instead. We we primarily price on only price on the number of applications that we detect and then we're automatically protecting for you. So we have some customers that started out with any applications and within three months our detection capability saw that they actually had 300 applications that were kind of being used in the shadows.
And so that's the primary Dimension that we operate along and since every user is likely to have a certain number of applications. We didn't want to add any friction by pricing by the number of users. So that's that's why our sole pricing Dimension is as number of applications managed.
actually What the heck I eat since you said it in the beginning. It's on my mind. So give us the background service.
To surveys again. Oh, yes service. Yeah, of course.
So when we were conducting early research on the company we met with a couple hundred cios and sissos and we were asking them about this problem, you know, do you see this and it was interesting as as the pandemic really went into full swing and more folks working from home. They kept saying Yeah, I know this is this is a problem and it's getting worse because we're not we're not there to control the network, you know, people are adding their own applications and we're not we're not aware of it and invariably one of those applications gets hacked and then all hell breaks loose and I kid you not 60 to 70% of the cios and systems that we met with independently all used that expression all hell breaks loose and that made us think of Cerberus which is the three-headed dog that keeps Health from right breaking out into the living world and we thought hey there's there's something here right? We're getting the universe is telling us that there's something to be done with this.
So obviously Risk, as a company name and domain was taken so we went with a kind of cuter version of service, which is where we're Serbia came from and the domain was available which is which is always a nice Plus. Doesn't suck if they say in Hollywood anyway, so you know what? This is a great story.
You guys have narrated money. You're public you're out of stealth. People want to get more information.
com anything else. We want to share. Just we're excited to be out of stealth again.
We're first of its kind platform that helps achieve that balance right as we're talking about being more of enrollment versus enforcement. com. We'd love to learn more about the applications you might have they're being used in the shadows and show you how we can help.
so we'll do we'll do things out. Appreciate it. All right, Doug Lupe from serbi.
Nuke nuke survey a new company Chuck them out. We're gonna take a break here on Tech strong. We'll be right back.