Stream Security’s Or Shoshani on Merging DevOps and SecOps
Stream Security CEO Or Shoshani dives into why the time to meld DevOps and security operations (SecOps) teams to improve the overall state of cybersecurity has arrived.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We are here with Orris Hanani, who's CEO for stream security, and we're talking about what is it gonna take to meld DevOps and security operations.
We've been talking about DevSecOps for a while, but it seems like we're still struggling with some of these issues and we'll dive in. Warren, welcome to the show. Thank you very much for having me.
Uh, it's great opportunity for me to discuss about, you know, the practices for the SecOps and the DevOps and how they have been challenging in order to blend up together. So thank you for having me and I'm looking forward to have, uh, the conversation with you today. I think a lot of this conversation revolves around the fact that there's a general shortage of people who have cybersecurity skills, so we're trying to quote unquote deputize more folks and the IT operations people are taking over some tasks, the developers are taking over some tasks.
What's your assessment of where are we on this journey right now? So, this is a a great question though. You know, so in in general, you know, from having conversation with think hundreds of, of organizations from SMBs up to the leading Fortune 500, uh, companies, so I think the, from what we have seen is that in, in most organizations, the ratio, um, between the security versus the dev and the DevOps should be like for one security engineer.
There are 20, 25 engineers and DevOps guys. And you know, as we keep running and keep our presence in the cloud and also, uh, increasing, uh, deployments in the clouds and all of the moving parts there, it requires for the SecOps to be, to keep up with the pace. And I think for the only way for, for the security to keep up with, you know, with the, um, with the pace of the DevOps and the Dell would be for the security guys to be able to Democrat democratize the ownership or some of the ownership of the security and to democratize them, um, throughout the entire organization.
It mean by that is that the DevOps and the dev would take some ownership over the security state of mind and also to be able to fix and remediate in order to help for the entire organization to be, um, to be secure. Because this is like failure remission for a tiny group, like the security group that owns not just the cloud, also the, it also the physical security and on top of that, the on-prem as well. So the organizations have to understand the, the, you know, the state of mind of the democratize, the security among the, the, the devs as well and the, uh, DevOps as well.
And this is pretty challenging for everyone, you know, so how devs that would like, you know, to shift fast to be able to take into account security, um, in incidents as well. And same for the DevOps as well. So this is a challenging task.
What is your sense of how much of that is a technical challenge versus a cultural challenge? It seems like all these groups grew up with different processes, so where's the, where, where's that clash? Is it on the cultural side or is it just simply a matter of getting the technology?
Right. So, so I think I can split it into two. Alright.
From what I've seen in the industry, so with small organizations, everything is very close to each other. So the security and the DevOps and the dev, they are working closely and in most cases the security owned by the DevOps as well. So where there, I've seen that there is culture and state of mind of taking security consideration into account.
And I think they're starting, you know, the mentality and the philosophy of owning security is much better in comparison into more, you know, structured and more regulative and more process driven organizations where there is a huge silo between the groups and each one is just laser focused on its stacks and not trying to think like out of the box. So that's why the co uh, the components are being separated have been siloed and have been owned by different groups and each group has different KPIs or OKRs and opposed to different personas. So it creates friction.
So that's one of the things that we need to work on, how to bridge that gap when there is a security team, DevOps team dev team, how we can bridge that gap when they're working in silo mode. Do you think AI will play a role in helping the, to democratize these processes? 'cause I think part of the problem is also nobody's looking at the same thing at the same time.
Yeah, so, so this is, you know, this is great question and, and I think in general the AI has been, is prettier, uh, revolutionized and we are in early days of where AI would impact. So I think we are now, it's, it's, it's pretty hard to predict what would be the outcome, but I think it gives a fresh, um, innovation and fresh open mindset into getting new culture and getting new capabilities in line because everybody's seeing that AI is coming over and they're expecting something to be changed. So it helps with the changing their mindset.
So even though that may AI may not be, you know, the candidate may not be the, the technology that will do, um, the magic, but it just triggers, um, innovativeness into people because they're inspired by the revolution and they're now being more open to new technologies. So I think it's, it's, it's a great, um, time to be like as an entrepreneur and great time to be a, a technology guy to run in parallel to the AI evolution because it just bring refreshness into the industry and people are me are more open to new technology because they're feeling that the a a is so exciting. And so let's see and let explore what is now the market has to offer.
I don't think there's a lot of love loss between developers and security, and I don't think that that is, uh, much of a secret. The issue primarily is that too often the security people come up with a list of vulnerabilities, throw it over the wall, and developers go chase their tails only to discover that the vulnerability's not relevant to, for a variety of reasons. And they only have a few, maybe 10% of their time to throw at fixing these issues anyway.
So they generally ignore a lot of the things the security folks say. What's your advice to security f folks about how to be more relevant to those developers and have a more meaningful conversation? Yeah, so that's what we are veering a lot and it's not a lie, as you mentioned.
So I think the key factor for having, uh, a meaningful relationship between the EC and dev and, and the, and the DevOps would be around PO prioritization in case organization that has large scale and opening up tons of tickets would be able to prioritize better and opening up only tickets that, you know, are high severity alerts that the operational guys would need to fix right now think it would help dramatically reduce most of the noise. And that's what is challenging how we prioritize all of our alerts and take into consideration, you know, configuration state, um, behavioral state and also business aspect. And if we can take all of those elements into account, I think it would reduce most of the noise.
Does that mean that I should take security people and put 'em on a DevOps team or is there some way to kind of structure this because there's clearly not enough security people to go around. So how do I kinda break that ratio dilemma that you talked about earlier where it's 10 to one in favor of DevOps versus security people? Yeah, so, so that's one of the things that we are trying to solve here at Sprint is how to better democratize, and thank you very much for having that question is how we can try democratize the security among the DevOps.
So, and one of the things that we have learned is that there are a couple of things that we have learned. Uh, one is that if you build a platform that the DevOps can trust and it's easy for use, not for the security, also for the DevOps, this is something that they can adopt to their workflow. That's one.
And second of which is that by building a technology or building a solution that would by using Stream, will be able to reduce most of the noise and neglect most of the unrelevant alerts and only focus on things that matters to the organization. This is something that we have seen and we have experienced that is loved by, not by the sec, also by the dev and the DevOps. I also think it's not much of a secret that developers don't know a whole lot about security.
Most of them were exposed to it as an elective that they chose not to take. Um, do we need to retrain the developers or is there some way to, um, approach this? Because a lot of the developers would say, you know, I already have too much to deal, I don't need to deal with security stuff and I'm, and I don't have the training so somebody else should take this lift.
Yeah, so you hundred percent right when there is a bridge, because one of the bugs that one of the developers deployed into the production, so none of them would want to be in that situation. And second of which none of them would be, would want to be in a situation where they're trying to fix something and they're breaking the production as well. So once you give them the confidence that with having a, a solution that is truly frictionless and want need for them to be security experts or infrastructure experts and for them to sort of communicate and interact with our platform will be in the same language that they are using on daily basis.
You find them more engaged into our platforms. As you kind of look over the horizon a little bit, do you think that we're gonna see a lot of new regulations in the coming year? They seem like they're more stringent and I feel like most of the conversation we've been having thus far around DevSecOps has been somewhat aspirational, but do you think that those regulations are gonna force this conversation?
So from what I've seen is that I think as you mentioned, uh, a DevSecOps is more of a culture not yet regulated yet. And I think we're still on our early days on how to articulate the DevSecOps culture and to be, you know, take that culture and translate it into like a walk a regulation that would be enforced it. So I think we're a bit early on in our, in in our days, but what I do see is that organization right now, they understand that they have friction, they understand that they have challenges, so they don't know how to articulate DevSecOps yet and what would be the best approach for them to bridge that gap, but the starting understanding that they need to bridge the gap.
So with that understanding, I think we are now in much better position to start thinking about how regulation would look like, but I don't think we are yet to be, um, enforce that regulation because we're still early on. So you've been at this a while, what do you see people doing that just makes you shake your head a little bit and go, folks we're better than this. I mean, what's that kind of one thing that you is more or less a pet peeve that you see your customers doing or other organizations doing that we could all collectively be better at?
Yeah, so we are trying to maintain, you know, um, very straight to the point and very product driven value. So we are trying to show how we stream security, how the day is going to look like, the day after they deploy in using us from more of operational manner. For example, when we find a threat, when we find a vulnerability, when we find a misconfiguration our platform in real time, building up all of the impact analysis around that.
And on top of that, we also provide all of the remediation steps combined together. So once the DevOps and the dev are starting to working on that ticket, they have all of the context and what caused that situation to be happened, how to fix it. And later on when the before even they deploy, they evaluate the new fix with our platform and get the feedback on how it going to look like when they deploy.
Because in most of the cases, one prevent most of the data to deploy more capabilities, the fear of creating more security vulnerabilities or more downtime to the environment. So when you, when they see that we are able to provide them this type of capabilities without trying, um, you know, let, let, let me pronounce that differently. One of the things that is pretty challenging is to, to have a statement that you are going to change the way the work until now.
This is, uh, that creates like an infinite level of friction. So when they see and witness it that our platform is play with the kind existing solutions without strengthening their client workflow and provide them at additional level of understanding and will be able, that will help them move faster. That's the ha moment for, for them to start adopting our platform.
Last Question. Do you think we're obsessed with building applications too fast? Are we proceeding at, uh, a pace that doesn't give enough regard for security because we're trying to get things out the door and in so doing, just throwing vulnerabilities after vulnerabilities into production environments?
So, so I think that in general, you know, eventually you are trying to build a business to be sustainable and the dev and the DevOps are trying to help the business to be sustainable by deploying new capabilities that would be help the business to generate more revenue or for the platform to be more meaningful and provide more value to, to our customer, to their customers. And in 2024 that every, everything move very fast, every organization need to keep up the pace by adding more and more capabilities to keep up with the end customer needs. So basically that's more of like a global leads for, for us to run faster and faster and faster.
Uh, so that's one thing. So that I think in general we are, we will be, as we grow, we'll need to shift more and more capabilities faster and faster. So that's one hand.
On second hand, I think CISOs and security leaders understand that you won't be able to secure the entire organization from A to Z. It's all comes down into what matters for them to secure and what matters for organization to secure and what's not. Because from working with a lot of organizations, what we have seen is that, for example, we are working with Fortune 500 company that runs 300 different apps in the cloud, but two of them generating 99% of their revenue.
So from them, the top one priority would be to secure those two apps, and the second priority would be to secure the rest of the environment. So eventually it is a story of how to prioritize and how to be more flexible because we won't be able to secure everything. All right folks.
Well, you're heard it here. DevOps and SecOps are coming together. It's inevitable.
The only question is, well, how much pain is gonna be experienced in the process because it will be required. Hey, Ora, thanks for being on the show. Thank you very much for your time.
All right. And thank you for watching our latest episode and back to you guys in the studio.