The State of Application Security 2023 – Renny Shen, Checkmarx
Renny Shen of Checkmarx joins Mike Rothman to discuss their Global Pulse of AppSec survey. They discuss the push to “Shift Everywhere,” how infrastructure needs to be under the purview of security testing, and some organizational challenges to making AppSec work across the enterprise.
Transcript
This is texturing TV. Hi everybody, Mike Rothman here general manager of textual research and she's strategy officer of tech strong group with another tech strong TV interview. I am pleased to be joined today by ready Chen who is and I just found out this is a thing right senior director of portfolio marketing.
So that's the thing. Welcome to the show. Rainy.
Why don't you tell us a little bit about one yourself a little bit on your background. I also a little bit about check marks right? Because we don't like to assume that that anybody knows anything about anything when they show up.
So let's get a sense of what you guys are doing, especially on the application security for. All right. Thanks Mike.
That's a pleasure to be here. And for those of you who are watching who didn't get the joke because it was done prior to starting recording. I was explaining what portfolio marketing men, which is simply that I've been doing product marketing for like 15 and 20 years.
And when I came here at Google what portfolio marketing meant apparently basically means that most need to have more than one. You have a portfolio. So you must be you must be in portfolio marketing but that aside we're all talking about products.
We're talking about capabilities. We're talking about Technologies and how it impacts obviously us as vendors and all of you in terms of your daily lives. So in terms of check marks, what we do is application security testing what that means is really if you think about application security think about digital transformation and all of the applications that are constantly changing.
We all know that we live and breathe that as consumers as people as well as people working in the industry. All of that has to be secured. So how do you do that?
And how do you do that? While applications are being developed as opposed to finding out about breaches after they've gone live so that's what that's how we help that's what check marks does we help you more securely develop applications. Oh that that's fantastic.
Obviously. That's something that's near and dear to our heart at Tech strong. Right?
Because you know, we focus on devops, we focus on cloud native infrastructure and obviously security there. So that is kind of the intersection there, but it's not about you know, whether we're not here to talk about portfolio marketing or even you know, kind of you know, the the auspices of the intersection of devops cloud native and security right? We're gonna talk about a study that you folks are releasing a recently released about, you know, really the state of application security out there specifically around, you know, kind of application security and and vulnerabilities and issues relating to application code.
Sorry. Why don't you just give us a little bit of an overview in terms of you know what the study was about and maybe some of the high level findings. Yeah.
Absolutely. So we run a global survey. It's called or Global reports called the pulsive application security part of the reason we run it is because we're like everybody else we say the same thing so many times we drink our own cool way.
Sometimes we have to go back and find out what everybody else thinks. I think for all of you. That's more interesting.
Anyways, right? What do your peers think how are they reacting? What are they seeing?
That's how you better understand like what you want to do next. So this is a cool report because we go out there and we combine both data from our platform as well as with former survey of 1500 survey respondents and that's cool because of the number but also because it takes an interesting cross-section of cisos and abstick managers and developers, right? So if we think about application development and application security, it's just one of those areas where you have this convergence of different people with different job responsibilities, and now like nobody really knows or everybody everybody knows because They disagrees whose job.
Application security is right. So that's what's cool as you get the perspectives of seesaws from their perch and then abstick managers who live and breathe it every day and developers who have to come in and fix things and sometimes they are responsible for it at the same time. So, yeah, well great.
So so 15 minutes. So what kind of data are you finding actually out of your platform, right? That's interesting to me.
Obviously, you're kind of scanning a whole mess of different, you know, kind of code on any given day probably, you know, millions and billions of things. So what are some of the conclusions that you drug just based upon seeing what's actually happening, you know, what's what's one of the the most interesting statistics from our platform is the number of customers that are running essentially we call them engines right multi-engine. So you can think of them as like static application security testing is an engine on our platform, right?
So is that so as sea or software composition analysis, right? And it really the reason why it's interesting Is not because customers have our products but because they're reinforces some of the findings from the reports, right which really highlights how complicated and how complex applications are right used to be you could just scan your code and you're good to go now applications have gone really complex, right? You have your code that you're writing.
You've got open source, you've got second party code, you know moving to the cloud right? One thing that people are realizing again is break things up into microservices and you have apis everywhere and you know whole Cloud deployment means infrastructures code. So it's it's all really complicated which means that application security has gotten more complicated, right?
So customers running multiple engines are increasing which is no surprise given that the number of risks that customers are finding across their applications or focused on our prioritizing is also very myriad. Yeah, you bet and and let's kind of dig in on that complexity thing a little bit right because that's one of the biggest challenges that that organizations face right is that you know with all of these different components having to work together right on a variety of different platforms. You've got all these, you know different teams and you know, get your typical even mid-sized Enterprise is gonna have dozens of different application teams messing with, you know, kind of different stuff.
How do you keep track of all of these things? Right is is it all right. We want to plug into our pipeline.
That's where we want to get to but having I mean our folks breaking bills are you, you know, kind of detecting, you know, those kind of things with within, you know, your tools that what are some of the more common attacks that you know, you're seeing and how much of that is is really driven just by complexity and how much is because you know, the developers still don't know what they're doing from the standpoint of of building secure code. Yeah, you know, it's funny as I wouldn't you know this I wouldn't go out there to say that developers don't know. Doing it's really that there's a wide garage spectrum of expertise in any field.
Right? So you have developers who know exactly what they're doing from a security perspective than the others that are new but if we up level it to an organization, what's really interesting is, you know digital transformation is a topic that in marketing. We kind of feel this old hat.
right, we've been saying it for so long that you know, we think it's boring but then Customers companies are viewers are actually living and breathing it in real life today every day. Right? So it's even funny like recently when you think about people going through financial and financial services, you know at the Forefront of digital transformation recently spoke to a CSO in a paint manufacturing company, right just starting to think about it today.
They're all going through this and when you think about what that means it's just a lot of applications that are starting to change whether they're existing applications and you're re-architecting it or you're business processes require new functionality or you know, you're consumers are demanding new features applications are changing right? And so when you think about that and every organization having hundreds or thousands of applications, you know, how do you even keep up with that? Right?
So that's what I think about when I when you say devops or devsecops, I got yelled at one time for basically simplifying dead setups as automation. Oh, yeah, I just automation after all of that, which is all great. But ultimately it's like how do people get their hands around all these applications that are changing.
Right? So you have to start with how they're big developed how they're being deployed built all of that and that's the sdlc and that's where you have to apply your security controls to automate all the otherwise. You just can't keep up.
Yeah is that you kind of been perceiving, you know pushback from any of the development side of stuff, you know, we went through the whole thing that you mentioned up right this whole shift left initiative where we wanted to, you know, kind of move security testing earlier in the process. So you find the defects earlier you fix the defects. It's a lot cheaper blah blah, right.
The numbers are the numbers and then you know, you have a group of developers that sit there and kind of say so, let me get this straight. I got to develop the code and then I'm entirely responsible for the security the code and you folks just sit there and tell us all the things that we've screwed up. That's how this is.
The work. Yeah, I don't think so. Right.
So we started to see this pushback of folks going. No. No, this has got to be more of a partnership here and we got to figure out a way to get better more contextual information about the security issues that are found in the code so that we know what to do for again largely development community that are not Security Experts intentionally.
So were there any data points in in the survey that you guys did they really talked about what the developers responsibilities are and and kind of what the expectations are around, you know their ability to secure the code. That's built. Yeah, absolutely.
So there's a few really interesting statistics in the report about you know, what the perceive what first of all what the top three causes of breaches are right and what's really interesting so from an athic manager perspective as well as from a developer perspective and what's really interesting is it doesn't overlap right? So it doesn't overlap because not because it doesn't have a lot because there's just so many ways and application can get breached, right? I think the abstract managers talk about.
Open source software. They talk about stolen potentials and secrets. They talk about proprietary vulnerabilities and proprietary code right developers talk about when you deploy the application on the cloud or via infrastructures code.
They talk about apis they talk about malicious packages. And those are all different ways that that applications can get breached, right? So they're all thinking about it.
They're all thinking about what's interesting is thinking about different parts of that software development life cycle that ultimately it's a joint responsibility for right so, we're not talking about shift left as much anymore shift left still applies. If you think about your own code that you write it's all about. How do you shift left and get closer developers make it easier to fix but when you think about software development life cycle when you think about from starting from your own code all the way out to how it's deploy now, it's more shift everywhere because it's not just that code right you can think of it as test everywhere protect everywhere.
You got all these tools and where how do you automate that everywhere in yourself develop? Cycle so you catch those different risks at the most appropriate Point. Yeah secure everywhere, right and that's really kind of a mindset as opposed to you know, kind of anything else and yeah, let's not do this for a long time.
Right? I keep you know kind of chasing the windmills and hopefully, you know, Don Quixote, you know, kind of finds the you know, kind of the the prize it's at some point out there for everybody. That's that's been trying to do this for a long time.
So what okay. Now so what are the most interesting, you know kind of data points was just you know, kind of thrown in front of me, right 88% of organizations experience at least one breach in the prior years of direct result of vulnerable application code. So one breach, you know, so let's kind of hone in on what that actually means data loss or what have you just to make sure to folks are clear about that.
But that's kind of a shocking number right that you know, kind of we all know about I'm just configurations or somebody clicks on the wrong thing or anything like that but vulnerable application code, right he percent of organizations, you know, kind of showing a reach due to that. Well, let's begin and out a little bit because that that's a number that should get folks attention. Yeah, it should get folks attention, but it's also striking because it's it's striking because of how common it is now, right?
It's almost the cost of doing business on the internet and as a cost of doing business, we all want to reduce costs, right? So it's to get your attention at the same time. It's something that you can focus on.
Is you know back in the early days? It's just about like reducing risk and it's hard to quantify that now. It's like, you know, the average cost of a breach is four million dollars.
Well, that's Quantified. But let's start to let's figure out how we can reduce that the cost of breaches, right? So, yeah, so so go earlier.
So what were some of the you know, interesting conclusions that came from the audience part of the service, right you talk about the data that comes out of the platform and that's great. But what we, you know, are there huge differences and perceptions from c c shows to application man abstract managers to the actual developers that have to do that stuff. Yeah.
So what's interesting is I mentioned earlier. So it's one of the most interesting figures in the city in the report is top three causes of breaches, right? So I'm looking at it right now, right?
So abstract managers the top three causes of breaches where 41% reported open source software supply chain attacks. That's cool. Because that's a that's a new frontier in application security right stolen credentials Secrets week authentication.
I think that will continue to be a problem that was 40% known or unknown vulnerability in code released a production was 39% So we've been talking about shift left. We've been talking about sash for 16 years. That's still a problem.
Right? We still have to do it. It's becoming more of a problem because of all these application changes on the developer side, right?
So 40% talked about like I said earlier Cloud resource infrastructures code or container misconfiguration, right? Those are the things that they get yelled at right what they happen or that they think they can fix through infrastructures code 38% said vulnerability or vulnerable or Shadow apis. That's a big thing.
So important to Wall Street Journal the other day, I think where I don't think people recognize that every time you introduce a new API, that's a new entry point to your application. Right and you in apis are introduced constantly and that 38% Said malicious third party packages or components. That's another you know, now forward thinking we're talking about supply chain security and not just like known vulnerabilities, but actual attackers injecting malicious code into these third parties that now you bring down to build into your applications, right?
So that's pretty cool top three causes of breaches. There's also interesting stats in their important terms of how do you prioritize risk? Right?
So when you talk about a c so apis are starting to get their attention, right? So 37% and I'll say they want to prioritize addressing apis first software supply chain security risks still high 37% containers 37% open source, 36% infrastrophers code is 36% right? So it's what striking is actually like how high the stats are across the board.
It's like there's no shortage of Dove to do what a prioritize or unacknowledgment of those issues. Right? So when you have you know, a full third of folks, you know kind of saying that something like infrastructure's code presents a risk that they don't mean that's kind of interesting right because one you know, I'm actually kind of surprised that 36% of anything knows what infrastructure is code is given that we're still pretty early in it's in its Evolution, but you know to really start to appreciate some of those risks there.
I think again indicates that we are kind of in in much more of an environment where there's awareness of the risks of a lot of these application environments awareness of the risks of some of these new development processes and whether it's agile or devops or whatever you want to call it. All right, and then to not make the same mistake in terms of calling everything automation but to give folks You know kind of feel that they're included right? That's why we call it devsecops, right?
So the devs, okay. I'm part of that right the answer, right? Hey, I'm part of that and then exactly later on we added the security folks so that the security folks didn't feel marginalized either and everybody realizes that we've all got to pull in the same direction in order to solve.
Yeah these problems so that's great. So it's already where where do we get touch should you know see the actual report is a matter we can just download it from from the check Mark's website or is there some other place to go see it and and that's probably a good example, you know, how do they get in touch with check marks if they want to learn more? Yeah.
Absolutely. So we're listening at Monday. Um, what month is it make sure April 24th at RSA?
So you can just get it. com. It's a Premiere report for us.
We do it every year and we're very excited to have it. com download it and see where get the pulse application security. Yeah, that's right.
And and you know, again, we certainly do a whole mess of research, you know about application security, but we love to see other folks, you know, just broaden the pie and really help to increase the awareness of some of the challenges that that folks have keeping things secure as the world gets more complicated right as our technology platforms get more complicated. So Russian. Thanks so much for your time.
com. And now we will send it back to the studio for our next. All right.
Thanks back. Nice to be here.