The Evolution of Application Security Integration with Veracode’s Jens Wessling and Chris Wysopal
Veracode recently announced the appointments of Jens Wessling as Chief Technology Officer (CTO). Jens succeeds Veracode co-founder Chris Wysopal in the role, while Chris assumes the position of Chief Security Evangelist.
In this joint interview with Jens and Chris, the two discuss the biggest change in application security over the past 20 years, which is how much it’s now integrated with the software development lifecycle.
Transcript
This is Textron tv. Hey everyone, welcome back to techron tv. Here.
I've got a two for a twofer for you. Uh, CTOs of Barcode, former and present. Actually, all kidding aside, you know, I've been in security for a pretty long time, probably longer than a lot of you folks have been in, in your jobs.
Um, one of the constants in security during my entire career at security, which probably 30 years, has been this gentleman here, well, they both have glasses. Chris WaPo, raise your hand, um, has been this gentleman here, uh, for those who aren't familiar with Chris, you know, Chris. Chris is one of the original hackers.
Back on Hacking, was really cool as heck. And you know, he, and he, and he was cool as Hack. And if you look at Chris's career, they originally was a company called at, well, eventually was a company called At Stake and became part of Symantec.
And that spun out. And then Chris, is it about 18 years ago now? Yeah, we actually, Veracode was founded 18 years ago, and we did, we did spin out a Symantec.
So, you know, there was a few people that came along from the at stake days to become part of the founding team here, um, at, at at Veracode. So since it's been 18 years, it's, it's hard to think back that far ago. But, you know, that first year it felt a lot like it did back then.
Yeah, I mean, it was, I mean, there was no AppSec, so to speak, industry 18 years ago. Veracode helped define the, the whole AppSec industry in many, many ways. And, and it's been quite a ride.
But we're here, you know, 18 years is a long time. It's about about half the light, the half the coer of the average congressman. Right.
And the go The company can vote and drive and all of those things. Yeah, I think it can in Canada. Yeah.
But there comes a time where, you know, bringing fresh blood and fresh faces, or at least moving people in, you know, to new roles. And that's part of the, the constant change that makes the tech world so vibrant. And so I want to introduce you to Jenz Wessling.
Thanks. Nice to meet You. Nice to meet you.
Jens Ys is now the Chief Technology officer, CTO at, at, uh, Veracode succeeding. Chris, so first of all, yes, congratulations. Thank you.
That's fantastic And a great opportunity. So, I, I gave Chris's background, I'm not gonna ask him to regurgitate it, but if you don't mind, I'm gonna ask you to share your background, your history with our audience. Oh, I've, uh, I came up through the ranks starting as a developer and then worked my into architecture.
And I've spent the last dozen or so years as a, in various chief architect roles for some, uh, interesting companies. And I've dealt with all the, the, the pain and heartache of a lot of the security things that, uh, people have to deal with. And, uh, when the opportunity came to work for, you know, a tight knit the industry that it really helped define the field, it, I just couldn't say no.
So she came on board as chief architect earlier in the year, and then things worked out as Cruz is ready to move into sort of a new role for me to sort of step in and carry on the really great work he's been doing. Well, those are, as, as they say, those are some big shoes to fill. Indeed.
Yeah. We're not gonna ask you to pick your leg up and show us the size of the shoes or the feet, but we'll just go with that. Um, before we jump into the whole chief technology role, CTO role, Chris, so you're no longer CTO, you're still the founder of Barcode, but you're not retiring?
I mean, I'm retiring. No, what are you doing? Yeah, so, uh, my new role is Chief Security Evangelist.
And what I found myself doing was more and more externally focused work. Um, you know, it was great that I had a great team that was pretty autonomous and I was able to do that, um, because I, I found myself needing to speak at more developer conferences and starting to speak at AI conferences. And a lot of development teams have internal conferences that are customers, and they want to have a security track now, which is really good news.
And so I, I found myself being more externally focused and I, and I thought, you know, this is really what the company needs now is someone who can at, you know, at a se at a senior level, right? So just not, you know, a solution architect or you know, a a a a, uh, an individual contributor that's, that's new to the business, but someone who's SE senior and has seen a lot, um, to go out and, uh, be able to do these keynotes, whether it's a developer conference or an internal conference. And, um, that's what I've been doing for the last few months.
And I have to say I'm traveling a lot more, uh, speaking to a lot more developers, which is, which is really, really exciting. Um, and the change from sort of trying to shoehorn into and force developers to listen to you versus them wanting to have you speak is, is, is very welcome. So, I, I feel good about it now.
Absolutely. Well, I'll tell you something. And you know, from where I sit, right?
com and Security Boulevard Cloud native now, tech strong, ai, tech strong, ITSM, like strong tv, digital, CXO. It's good to see someone like you in this role, because all too often, and I'm not, I'm not trying to be a crabby old man, go play in front of your own house kind of thing. But all too often that chief evangelist role today in a lot of security companies and even a lot of tech companies, DevOps companies, is some dude or gal who wears a funny hat, or they got blue hair, or they get something that kind of, and again, I don't take it the wrong way, but they, you know, they're, they're, look at me, look at me, look at me.
Right? And they're looking for that attention. Look at me.
I got a funny hat. I got crazy colored hair. I'm doing something because I'm, I want you to look at me.
Are, are you Saying they're not serious practitioners? Um, no. You wanna know the truth.
Some, most of them are okay. Most of them are, but they don't have the gravitas to command, not respect, but command attention. And so they gotta do, they have to do other things for attention.
Is that fair? I thought that was pretty, or Sure. I don't, I think So.
I, I think I got attention and I don't have blue hair, so maybe you're onto something. Well, at least you got hair Chris. Go easy.
Uh, I like that. You know, it could be me. Uh, with that being said, seriously, you know, all kidding aside, to have someone of your stature, of your experience available to talk at these things, because frankly, most of the people, as eds as I'm sure soon gonna find out, you're so consumed with our role as a CTO or as a Chief research officer or as a, you know, whatever your role is, it's very hard to carve out taring to go do that external piece.
Well, absolutely. Hard, hard to do. So, fantastic role.
Chris. I've got a bunch of stuff I'm ready to invite you to, we'll talk offline, but let's, let's, let's pivot a little bit. So the chief technology officer role has become a chameleon sort of role.
It differs so much company to company org to org sometimes it is very forward facing and almost is sort of like a Chris's role. You are. It's a, I call those the marketing CTOs, right?
They do analyst relations, customer meetings, a lot of customer meetings and, and you know, appearances at conferences and stuff. Then you have an internal facing CTO where they're almost like a pseudo VP of engineering running a development team or a support team. And you have another kind of CTO who's headed CTO slash CPO, chief Product Officer, really responsible for the vision of the products and the implementation and building that product.
What's it gonna be at Veracode going forward? What, what is that role as CTO? That's a, a great question.
And I think what's really come up is, as Chris has started shifting his attention more externally, the demands on the research side of things have really accelerated as AI is transforming our industry, as the whole security marketplace is changing towards application risk management, as all these things are coming to a head, I think we need to sort of reinvigorate and like invest even more into our research and development efforts to figure out where things are going. 'cause that's not an easy question, is people might think, so my focus is CTO is going to be, um, making sure that we're pointed in the right direction, that we're technologically sound, and that we're investing in the things that are really gonna reshape the industry for years to come. So would that research be more product focus here?
Because look, traditionally Veracode, right? You guys do one of the, I mean, it's kind of the granddad of the AppSec surveys and reports every year. Mm-Hmm, right?
That, that shows a lot of trends in the industry and a lot of trends in the market. Is it kind of that market based research? Or is it research on how do we use AI to make a, make us more secure?
Oh, I, I think after our conversations, it's very much not an either or question. We have to do both. Mm-Hmm.
If you leave the one of 'em aside, then I think you either aren't staying current on what the state of the art and what the industry is saying, or you're not keeping on top of the new developments and the significant changes that are happening in the industry. So the answer is both. I mean, I think we need to continue to invest in our applied research functionality, which has always been a core strength of the organization, and reinvest even more in things like Veracode fix AI based issues, and then figuring out how AI is shaping the industry as a whole.
'cause it really is changing the way we work and the way security fits into the, the, the whole landscape. Excellent. So let me, let me dive in a little further to ai and this question is for both of you.
You know, one, we AI sucks, sucks the air out of every conversation we have around here, right? We do our tech strong gang show every morning. We do three blocks in the morning, and usually two of the three are AI related and the third AI sneaks into anyway.
Do you think it's possible we're putting too many eggs in that basket or we're, we're kinda wishing hoping that it, it its a lot more functional, a lot more, uh, doable than it will be? Like, you know, are we making a new Apple vc, uh, you know, virtual reality sad thing that's $3,500 and the market doesn't want Right. By putting all our eggs in AI basket, Someone take the, I'll let you take the first pass at this.
Yeah, I'll, I'll, I'll, I'll I'll start with this. I, I think that, um, yeah, we're definitely turning the, the dial up to 11. Um, you know, AI is super important and super valuable, but I, I do think we're, we're over amping it.
Um, and so one way we're doing that is we are rolling ahead quickly with an AI solution without thinking about the problems that it's causing. And you know, one of the ones that's close to me is, is AI code generation, right? It's like, hey, you get 40% productivity, um, you know, every, every developer's writing 40% more code, uh, per day, and isn't that great?
And then you're like, well, wait a minute. How is that impacting my testing requirements? How is that impacting my, uh, d to remediate vulnerabilities that are being generated faster, right?
So we're, we're, we're in that point where we're, you know, we're, we're learning that the engine can go very fast and we're real. We're realizing we need really good brake too to, to control the car. Uh, so it can go fast, but we can slow down before the curve.
And, uh, I think we're kind of in that phase now and we're just learning about some of the downsides of, of, of going quickly, quickly ahead. Uh, but of course the solution to that is more ai, right? Of course it is.
It's more ai, right? So that's, that's where Veracode fix comes in. We've made a solution that, you know, we originally made it so that people could fix the vulnerabilities they weren't getting to, right?
Their security debt, the things that have been sitting around for a year and they couldn't get to, but now we're seeing this, there's an even more important need for it because each developer is creating more code. That would mean each developer needs to fix more code, right? Um, so, so having an automated remediation is, is super important to, to be the breaks on the, uh, on the, on the, on the, on the AI hot rod, right?
Uh, but I think the other, the other area we're seeing it overamped is everything just has to have AI in it no matter what. Right? You need a chat interface, right?
You, you just see modern if you have, if you have this, right? So it's sort of like the infinitely scrollable, you know, websites, right? Yeah.
It's just like you have to have it. Does it add a benefit? I don't know.
But it's what modern things look like and it makes us cool. So I think we're seeing AI in places it doesn't need to be because it's the fashionable thing. It looks cool, it look makes, it looks modern, and we're seeing it where it's really necessary.
But in both those cases, there's some downsides to the AI that we're sort of just learning about. So yes, more AI begets more AI and we're, we're kind of stuck with it. I would agree with that.
I mean, I sort of view technological innovation on the spectrum of, you know, from VR goggles to cloud hosting and SaaS, right? And I think this falls somewhere comfortably in the middle. I don't think it's gonna be as transformative as cloud hosting, but I also don't think it's going anywhere.
I think it's the new reality and we have to learn to function with it as a core part of our experience in the software industry. And our, our job is to figure out how to use it effectively and where it actually provides value and where it just provides noise. And I think we're still all trying to figure that out, right?
Oh, yeah. I, I, you know, to me it's kind of like, remember the story when you were a kid? Well, we had a problem with mice, so we're gonna get cats to get rid of the mice.
Well, now we got a problem with cats. Well, we gotta get some dogs to chase the cats. Well, now we got a problem with dogs and okay, we gotta get something, you know, something that takes chase.
Eventually we get to the elephants and the only thing we could do to get rid of the elephants is to bring the vice back. And, you know, that's kind of the, the AI thing. But you know, again, we talk about this a lot here.
We have about, you know, they estimate the 27 million developers going to 35 million, 20, 30, whatever. But with AI generating code by 2030 or 2035, we're liable to have hundreds of million develop of developers. There may not be developers in the sense you sake of right now, but people who are generating code, most of it via ai and that code, you know, what is there?
They, they asked me, I'm just pulling numbers, but they asked me this, what is it, 2 trillion lines of code or something out there now? Well, that's going to quadruple really easily when we start having, you know, 500 million people developing apps and code. Someone's gotta test all that code.
Someone's gotta secure all these apps we've gotta store, you know, to run these apps. Infrastructure. We gotta store the data these apps generate.
It is, you know, AI begets more ai, AI also begets more, uh, pressure on all of these pressure points in our world, in our tech, Kind of, and the same thing with like physical factory automation Yeah. Where the jobs shifted from doing the line work to supporting the machines and building the machines and logistics. Yeah.
And qa. And I think we're gonna see a lot of the same thing. I think there's areas where you still need to make sure that the right thing is happening.
And, you know, ai, at least LLMs can't be implicitly trusted. They're sort of best efforts. So we need to make sure that when they don't do what we need them to do, whether it's security or quality or functional, that there's somebody there making sure that they do.
And that's the role Veracode hopes to play. Yeah. I mean it, but it, it is a, you know, you think replacing Chris is a big job.
Being the AI watchdog is a big job that that's a big job, right? It, it's a, it's a huge job. And I think we're, we're investing in internal research to try and understand where it fits and what the trends are actually telling us.
I think if you look at the research into AI right now, you can find someone to tell you just about anything you want to hear. Is it making developers more productive? Yes.
Less productive? Yes. Like what's the, the truth of the matter.
And I think we have to come to terms with that and look at what's actually out there to determine where we're actually going to be able to provide the most value. And that's what we're actively doing. If you don't mind, guys, I wanna turn to the security industry at large.
Cyber, as they call it, wasn't cyber when it started, but now it's cyber. Um, it almost seems a little bit like the bloom's off the roads. There was, you know, it's not that anyone thinks cyber is not important, cyber is still a top priority and all that good stuff.
However, we're hearing from boardrooms that, hey, every year you want a shiny new tot and every year we increase your budget and you buy a shiny new tot. But we're not any more secure than we were last year. Where, where's the, where's the ROI here, where is the payback on this one is enough, enough spending.
The, the other thing we're hearing is I don't really care about how many vulnerabilities your scanner found and whether it was a ship left scan or post appointment scan, or how many intrusions you potentially block talk business to me, I wanna know about what, what is my risk? What's my risk in this line of business? And how much quantifiably can you reduce that risk?
Right? Business talk. So, you know, I I definitely, you're definitely right that, that the budgets don't keep just increasing, right?
It's not bad. Great. And it's more about, alright, your budget's the same.
Can you, can you optimize that? Can you, can you do something better? Can you be more secure within that budget?
So that's what drives consolidation, right? Um, how, how, how can I have less vendors and then squeeze that one vendor saying, Hey, I'm spending all this money from you, gimme a bigger discount. Um, so we definitely see, we see that that pressure, which is both good and bad for a software vendor, right?
Uh, we see people consolidating because you have a good suite, but then of course you see price pressure because they expect the spend less, right? Um, so, so I think that's happening. So, you know, the people who can put together the right suite for the particular problem, and it just keeps consolidating.
I mean, even in our space, it's like, it, it's consolidating all the way from, you know, writing the IDE where someone's writing a line of code to, uh, monitoring that coding production, right? With the whole environment being, being part of that and tying that all together. Um, and, uh, I'm sure it'll just keep getting all more and more consolidated so that that's simply, you know, 1, 1, 1 big factor.
Um, we, we see, but you, you also talk about like, you know, just remediating vulnerabilities or, you know, preventing blocking things. It's like, what is the meaning of all that, right? Like, what is, what is the meaning?
And can we just count these things? And if we're doing more, is that better? And, and so I, I think we're seeing a shift towards like that meaningful risk reduction, right?
And that's what, you know, Jens was alluding to, you know, uh, you know, risk management instead of testing and remediation, like first it was testing, now it's being good at remediation, but the next step is like, am I even wasting my time repeating things that don't matter? And especially if it takes a human to do that. Uh, 'cause we're always gonna need humans to fix business logic and design things, even if we get better and better at fixing more and more things with automatic remediation, you know, maybe we can fix configuration and if infrastructures code too and patch containers and all that.
But still, there's gotta be people. So I think we see moving to a more risk management lens that we look through all of our activities through, I get it. Yeah.
That's absolutely, we're hearing the same thing from our customers. Like finding 20,000 vulnerabilities doesn't actually help me remove the needle. Like it's more than just Yeah, yeah.
No, it's more than just your meantime to remediation either. Yeah. I've found 20,000 vulnerabilities in our meantime to remediation was five and a half days.
That's great. What does it mean to my business? What is it?
What, where's the risk here? I, what have you reduced the risk? How much have you reduced the risk?
Right? That's absolutely the heart of application risk management, which is where Eric was investing a lot now, is to help customers understand across this broad landscape of security, what's going to move the needle? What's the most bang for the buck?
Because ultimately, budgets are fixed and problems aren't boundless. So how do you most effectively use the dollars you have at your disposal to give you the best possible security you can? And so that's the problem we're answering.
Yeah. You know, it's interesting, Ella, it's, it's like going back to the roots. You know, we we're talking about at stake, and when it was humans doing this, the humans were doing threat modeling that humans understood the application, they understood the design, they knew where the, the crown jewels were.
And so when they were doing a code review and they found a SQL injection issue, they said, Hey, this one needs to be fixed. Why? It's exposed the internet.
Oh, and what can you do with it? You can get at the crown jewels data. Fix that one.
This one here is in like some, you know, nightly logging batch job. You know, it's not really exploitable. And even if it was, we don't really care that much when we had humans doing review.
We implicitly got this risk management. 'cause you're having a conversation with a person who understood things as we'd moved to like find it fast, fix it fast, fully automated to just keep up with DevOps. We had to get rid of the people, right?
We got rid of the people. And I think we lost a lot with that, right? We just started, you lost some Of the common sense and some of the mirror.
And then, so we're bringing in that common sense now we're bringing in, uh, reachability, we're bringing in what kind of assets are impacted. We're bringing in the complexity of where things are deployed to understand, yes, we're tracking that line of code from the developer. We know there's a vulnerability there, but do we even need to fix it?
Um, and I, I think we're, you know, we're kind of coming full circle and we're finally getting to what we used to do, but now we can do it at DevOps speed, right? Because we have to, especially with AI coach generation, there's no, there's no choice, Right? No, no one, they're not gonna stop the change for us and say, you know, catch up.
No Human review isn't gonna work. And common sense is one area where AI will not help you. I was just gonna say that.
How do you teach common sense to an AI anyway? You don't, And that, that's a tough one. But we can, we can, we can, we can build things that aren't reliant on the AI understanding it because we know what reachability is, right?
And, and we know what sensitive data looks like, so we don't need AI to tell us that. Um, and, and, and, but still use AI for say, remediation. But, but, but use it in places that it works.
And, you know, just use plain old algorithms and data gathering where, where we need it And use United where it provides value and use common sense where that's what you need. Very cool. Guys.
We only have a minute or two left, but we didn't really, Chris, you mentioned a new Veracode, uh, solution that has AI Ys, you might have mentioned that, I'm not sure, but can you give people I, beyond the personnel changes, quick update, what's happening in Veracode? What's exciting? Yeah, so maybe I'll do the ai, the Ys could do risk management.
Uh, we, we kicked off ai, uh, code remediation about four years ago because we saw that was the biggest problem that that, uh, we saw developers team having that meantime to repair was just getting longer and longer. So this doesn't help you necessarily decide what needs to be fixed, but it fixes its fast, right? So, um, we, we, we, we don't see an alternative as, as, as velocities of code generation and app deployments keep getting faster and faster.
We don't see a, an alternative to AI based code generation. Uh, whether it's fixing things that humans wrote or that the machine wrote. So Veracode Fix, I think, is supported by eight languages now.
Uh, there's a total of, I think over 25 different cws across those languages. You know, some languages have common weaknesses, some have unique ones. Uh, and, um, we're getting good customer traction with people using it in their AI and in their build pipeline to not check in code that has vulnerabilities, just fix it right then and there before check in.
Yeah. The time to do it. And on the, the risk management side, we had an acquisition earlier this year of Longbow Mm-Hmm.
And their, their goal is to try and pull together all of the different vulnerabilities and all the different security information findings to one place. Use them to create a composite picture of all the vulnerabilities and the relationships between them. Understand the impact that they have, whether or not they're accessible, and tie all that information together to actually provide an impact score that lets us know where the, the greatest value for investment is.
And to present that in a very easily accessible way so people can get a high level survey of their whole security landscape and decide where they want to invest and where they don't wanna invest. Very cool. Very cool.
Guys, we're, we're over time. I apologize. I know we ran late, but I haven't caught up.
Well, again, of first time we've spoken, Chris, I haven't caught up with you in a while. Um, to both of you, congratulations and best of luck in your new role. You know, keep that Veracode ball rolling forward.
Right? You gotta keep the, the ball rolling forward one foot in front of the other. And, uh, we'll stay in touch with us, right?
Keep us posted, Syd. Thanks for having us. It was a pleasure.
Yeah. Yes. Thanks A lot, Alan.
My pleasure. All right, we'll talk ya. We'll be talking as well.
Look forward. Check him out. com.
We're on Techstrong tv. We'll be back in a minute.