Shadow AI Security: Protecting the New Builders
Shadow AI security is the new frontline for enterprise security teams. Gil Geron, CEO and co-founder of Orca Security, returns to Techstrong TV. Furthermore, he joins Alan Shimel to explain what changes when every employee in the company is suddenly a builder shipping code with AI tools.
About Gil Geron
Gil leads Orca as CEO and co-founder. In addition, he is a long time cloud security leader. Consequently, he has watched shadow IT become shadow AI. Vibe coding tools now spread beyond engineering into marketing, operations and finance.
Inside shadow AI security
Cloud security once focused on developers who spin up AWS or GCP accounts. As a result, most controls assumed a small group of technical builders. Meanwhile, tools like Lovable, Replit, Bolt, Supabase and Snowflake turned analysts and operators into builders. Therefore, the new perimeter has to cover a much wider surface than before.
Gil also unpacks Orca’s new AI red team and code security auditor. In addition, Orca’s remediation agents open pull requests to fix issues before deployment. Consequently, teams offload repetitive scan and triage work. As a result, humans focus on real judgment calls that need context.
Why this matters now
Meanwhile, the SaaSpocalypse debate reshapes pricing. Furthermore, Gil argues that pricing should track cost and compute, not seats. Consequently, seat based licensing breaks when everyone is a builder. Shadow AI security has to keep up with that shift across every public cloud.
Explore more artificial intelligence coverage and the latest Techstrong TV interviews. In addition, Gil shares where AI native app building will and will not replace traditional software categories like databases and hosting. He also explains why reinventing the wheel with a Claude subscription rarely pays off once maintenance, scale and long term security land squarely on the internal team that shipped the prototype in the first place.
For more information please visit orca.security
Transcript
Hey everyone, welcome back here to Techstrong TV. My next guest, I haven't had him on Techstrong TV, I'm going to say in two, three years maybe. My friend Gil Geron.
Gil is the co-founder, CEO at Orca Security. I remember, man, when Orca was first out there and the times we had with Avi and Gil and so forth like that, it was a different time. I look back on it now, and it was as bad as I thought it was then in security.
It was almost an innocent time compared to what we're living in now. Gil, how are you? Welcome back.
I'm doing well. Still kicking. And, so I'm Gil, I'm the CEO and co-founder of Orca.
For those of you who don't remember much about Orca, what we do is we provide cloud and AI security. We protect public clouds, everything that is in your AWS, Azure, GCP, AliCloud, Tencent, Oracle Cloud. Anything in those realms we are able to protect, and throughout the recent years, we've also started to do a lot of AppSec and runtime security, and so we've expanded so much since we've last spoken.
Well, the world has changed since we last spoke too. I think when we last spoke, I don't think you said you did AI security. It was just cloud security.
But now, of course, everything is AI. I know Orca was out in Vegas last week at Black Hat where we were. It was certainly the Black Hat of agentic AI.
And so that's where the world is today. Now, Gil, obviously you guys have now, not pivoted, but in looking at the world around you, you keep relevant and brought the product to today. You recently announced some even new functionality, though, and some new features.
If you don't mind, share with the audience a little bit. What exactly have you got new? So I think over the last year or so, basically we've witnessed a huge transition in the IT and security world, and the biggest transition that occurred was around how do you build software, which is a lot of it is leveraging AI, and the second is who is building software.
And around how you build software, how do you deploy software, we felt that security needs the velocity and speed, and so we've released a lot of capability like agentic security, red teaming, code security, similar like a mythos buster approach. But we felt that there is a big segment of the market that is completely neglected, which is the non-developers builders. And here we are talking about basically anyone in our company that builds using Claude or OpEx.
Yeah. Look, we're all builders now. And that I think is the key thing, whether you work in marketing or I don't care what you work in, we're all building with this AI.
And the thing about it is even if you just want to narrow that focus down and say, okay, the people who are generating code with AI, well, me, I haven't generated code in 30 years. But I'm generating scripts and codes and things that I never thought I'd be doing again. So it's a huge change in the scope of who you-- First of all, you got to protect me from myself, right?
And then you got to protect the rest of the world from me. So I think that, I absolutely agree, and while it is not a huge segment of your environment for companies, meaning that these builders are building a lot of internal apps, are doing a lot of things for themselves, but sometimes they create something they want to share with the world. And when that happens, the gap in knowledge, even policies like how to secure data, whether it should be encrypted or not, whether there should be external access to that or not.
So these fundamentals do not exist in the way that these tools are operating. And what we are helping is the security leaders, first of all, to find that new shadow IT, and- Yeah ... second, to secure that shadow IT, to ensure that if it's being used, it's being used securely.
We've been using the term shadow AI. Because it either they're using AI tools and AI agents that you don't know exist, or they're building with it. And so, we've got either one of those.
It may wind up being bigger than the shadow IT was in the height of when cloud adoption was going on. Because this is just developers were behind shadow IT. Everyone is behind shadow AI.
No, I absolutely agree, and where there is a lot of similarities to the early days of cloud in the sense that people would just go and log into AWS or GCP and just ... pop-up environment, and we pretty much got a handle on that. io, Supabase, Snowflake, MongoDB, CockroachDB, and I can go on and on and on to 50 to 100 services that people are using and being recommended to use.
And the reality is that we just felt compelled to protect these environments and to ensure that your organization is secure. And so we want to be in a position where you can adopt AI, accelerate your company securely. Agreed.
Another big thing though, Gil, is for lack of Mythos, right? I know there's more than Mythos. Yeah.
There's a lot of great AI-based vulnerability scanning tools or bug-finding tools, vulnerability-finding tools. ChatGPT, the new Chinese open-weight models are good at it, too. Grok is probably the new one, who's supposed to be very good at it.
But for everyone says Mythos, and we know what you mean. Look, as someone like me who's been in security 30 years, this is such a game-changing thing because, for most of my career, the challenge was finding these vulnerabilities before the bad guys did. And in some ways, we still have to find them, but the bad guys are using these tools too, right?
Yeah. But now we're finding so many vulnerabilities that the challenge is what do we do about it, right? It's not enough to just find vulnerabilities today.
So I know you guys recently came out with an AI code security auditor that helps with the what do I do next? Yeah. What we've released, we've decided to release whole teams of security that will try to automate as much of your function as possible.
Now, I'm not talking about the things that require a human to actually put his thought on, but there's plenty of things that security teams are doing today that could be automated and are just waste of time of repeating behavior of that team. Clicking again and again and again on the same button. It's something that we can definitely automate.
And so what we've released, we've released a red team that try to take care of everything that you do and release, and it contains the AI code security, which tries to find vulnerabilities in your code, but also contains an agent that does external exposure management to try to find, after the code is deployed, whether there are new and more vulnerabilities. And when you think about the velocity that you're required to release application and services, that function needs to be continuous as well. Yes.
Absolutely. As for remediation and taking action, so we've released agents that automatically generate PRs, automatically try to fix and remediate the code. And it's the same mindset of saying, okay, let's say the red team found something.
Who's going to fix it? Should it be a human? Can we automate most of it?
And the answer is yes. So let's do that. And so imagine a world where you're building an app, you found the vulnerabilities, it's going through the release cycle, it's being deployed, issues found, fixed, you arrive in the morning, your service is up and running and secure and went through pen testing.
It's a beautiful thing, no? It's a great thing. Gil, I'm going to ask a question.
We didn't rehearse this or anything, so it's going to be your honest take. Part of this whole AI thing is looking at the whole, what they call the SaaS apocalypse, right? That, look, people are rolling their own apps with AI, for good or bad.
And one of the reasons that they're doing it is that the SaaS pricing models don't make sense, right, to some people, in some circumstances, depending on what the SaaS model is. Now, when you marry that, Gil, to this world of how we're all builders, we're all AI builders today. These SaaS models, a lot of them charge per seat.
So maybe I used to have 100 developers, and so I would buy a license for 100 developers, 100 seats. Well, now I got everybody and their mom building apps on Lovable and Replit and all these places and uploading them. And all of a sudden, I might have 1,000 people who are contributing code somewhere along the line here, whether it's an internal application or not.
Yeah. I got to worry about it. As Orca, how do you approach that?
How do you change your model? And I don't know what the Orca model was, so feel free to talk about it, but to encompass this much larger corpus of builders versus, let's say, developers. So I'm a strong believer that pricing should be as closely related to your cost as possible.
Meaning- Mm-hmm ... I am a strong believer that pricing should be fair. And it should be related to amount of cost that you have around providing the service.
And so if it's around the amount of people using your software, then okay, so maybe that's your model. And by the way, Anthropic and Claude and these guys have subscription models that are user-based. Yes.
And I think that's why so many people are using the open weight models frankly, right? Right. On the other hand, for us, for example, we charge based on compute, based on your workloads, because that's the- That's the real number ...
yeah, that's the real number. That's what I later pay to all of the good cloud providers that supply me with service. And so, we build the software on top of it, but there is the cogs, and I want the price to be coherent with the cogs.
And when I take the cogs down, I can take my prices down and similarly. And so, I think that when you talk about SaaSpocalypse in a more broader scope, look, there's plenty of software that is built around building a different interface to your data or creating for UBI and stuff like that. And unfortunately for those companies, that portion has became really easy.
You just dump it to Claude or Opex and they can give you the answer. Agreed. There's plenty of elements that will not die and shouldn't die, right?
There's so many services, like for example, web hosting. There's absolutely no reason it will grow out of the service. Databases, please don't try to build with Claude a database because it won't be scalable.
Well, why reinvent the wheel? And that's part of it too. Just because you can, doesn't mean you should.
Yeah. Right? And reinventing the wheel in the long term is not going to save you money because you could build an application today, but who's responsible for updating it, securing it, making sure the vulnerabilities aren't there?
Where a database, you got a company that they build databases for a living, right? It's like trying to say, "Hey Gil, we don't need Orca Security. " Yeah.
Right? Have at it, right? Let me know, because we've invested millions of dollars in this.
What are you investing in? In a $20 a month ChatGPT subscription? It's not the same.
And it's not only the building, it's also are you going to maintain it? Maintain it. Are you going to- Sure ...
behind the scenes, there is plenty of software and subscriptions that we have in order to bring to our customers the latest intel, the latest services. We have research teams that are consistently obsessed with giving you the value, and making sure that you're secure. And so that aspect, I feel that if you are producing valuable data to your customers, you're safe.
If you are producing a service that is scalable and requires complex engineering and architecture, I think you're safe. Agreed. Gil, we're over time already, but for people who want to get more information about Orca, what's the best place?
security. We would more than be happy to show you a demo of what we've got. I love it.
Gil, don't stay away so long. Come back and talk to us again soon. Yeah, absolutely.
All right. Gil Geron, CEO, co-founder Orca Security here on Techstrong TV. We're going to take a break.
We're coming back with a lot more. Stay tuned. Thank you.