Your Cloud Network is the New Front Line
For years, the security industry has obsessed over locking the front door, building massive perimeters while ignoring the fact that our critical data has already moved into a building with no walls. Aviatrix GM and SVP Willie Tejada joins Alan Shimel on Techstrong TV to tear down the illusion of endpoint security, arguing that the largest, unguarded attack surface isn’t at the perimeter—it’s in the chaotic, ephemeral space between cloud workloads. As the White House rolls out its new National Cybersecurity Strategy, Tejada explains why the lack of cloud network security standards is a ticking time bomb, especially as autonomous AI agents begin operating at machine speed across our most critical infrastructure.
Transcript
Hey, everyone. Welcome back here to Techstrong TV. My next guest, I want to introduce you to him, I'm really happy to have him here.
His name is Willie Tejeda. T- T- Tejeda? It's good enough, Alan.
Willie, I apologize. It's good enough. Uh, W- Willie is the GM and SVP of Aviatrix.
Willie, pronounce your name right, first of all. Let's get- Tejeda ... let's correct- Tejeda.
Tejeda. Tejeda. It's three syllables.
Yeah, Tejeda. There you go. Much easier.
Tejeda. Just the way it's spelled. Willie, you're GM, SVP here, but you weren't born that way, right?
You, you- No ... you had a- No, no ... a, a life.
I took... Like, like most folks, I had, a journey to actually get here that puts me in front of this, this conversation, Alan. Thanks for actually having me.
The, you know, my career in technology has spanned, I'm old, so it spans over, you know, 25, 30 years. And, it, it, in security, I was fortunate enough to have one of my startups bought by Akamai Technologies. Mm.
And then, that kind of, one of the things that we did back then is that, that we, we saw that many of the features were being used for security. And what we ended up doing is standing up the first security products for Akamai, and that was, like, in web application firewall, their, DDoS type of product, basically- Really? were the first kind of entry points.
You know, now, I think the security products are the largest revenue producer for Akamai. Yeah. No, they are.
So we- were you there when Andy, Andy Ellis was CSO, or...? Oh, yeah. Absolutely.
I know Andy very well. Know Andy very well. Yeah, me too.
Spent lots of time actually an- with him. Andy's a friend. And then, you know, my, my, my latest, my latest stint before coming to Aviatrix was with Zscaler and working for Jay.
And, um- Sure, I know Jay too ... heading up, yeah, heading up their, what they called their Takeoff Team products. So you can kind of think of them, Alan, as kind of their emerging products.
And so I, I knew very well kind of like the, I'll call it workload protection, the digital experience monitoring area, as well as the data protection area. And then what was really interesting about how I, I crossed paths with Aviatrix is I owned the workload protection business at Zscaler, and, a colleague of mine introduced me to Doug Merritt, who's now our, our CEO, and Doug was in the midst, basically, of pivoting Aviatrix from a multi-cloud networking company to a security company. And what I realized was, you know, back at Zscaler, if we had been able to use the network as an enforcement point, the workload protection business, well, number one, it would've been much easier, but it would also actually been able to s- future-proof a lot of things.
'Cause today, you know, I, we posit at Aviatrix that the largest, unguarded attack surface area is at, isn't at the perimeter, it's actually in between the cloud workloads. Yeah. And so every app, every data- Well, there is no perimeter anymore- Ex- exactly ...
is, is the idea. Exactly. Exactly.
And so when- You know, and it's funny, I remember being at an America's Growth Capital cloud security panel that I moderated. Jay Chaudhry had just- Yeah ... started Zscaler, and he got up there and said that, that the perimeter's gone.
The perimeter's- Yeah ... gone. It's all about what's in the cloud.
And, you know, a lot of people in the audience were, were clutching their pearls. You know what I mean? And, but he, you know, Jay's not a dumb person.
No, not at all. Not at all. Yeah.
And so, you know, and there you go. You know what? I think for the most part, most folks really, really oftentimes is trying to guard that front door, when the reality actually is, is once attackers actually get in, they move laterally inside the clouds to get to high-value assets, and so that's where Aviatrix spends, its time.
That's where we deliver value, protecting those high-value workloads and applications, by utilizing the network as an enforcement layer. So is it, like, microsegmentation kind of stuff, or...? It, it is microsegmentation, but again, you know, if you think about dissolving your constructs of how you built a security stack on-prem, so you know, typically, oh, I got a firewall, I have a NAT device, I have all these other pieces, and you built it from the ground up and, and, and said, "Great, I'm gonna focus on cloud workloads," not, not user-centric zero trust, but let's call it workload-centric zero trust.
If you're doing it from that standpoint, then you'll do these principles. Like, great, you need to be in line to traffic. Great, your enforcement point needs to be close to the workload of the VPC or the VNet.
You have to do all those types of things. So yes, we do microsegmentation. Yes, we do firewalling.
Yes, we do NAT-ing. You know, you do g- all these types of things with the sole idea that I'm protecting workloads. So, you know, we get a lot of telemetry from partners like Wiz, and allows us roughly actually to deal with security in the runtime, the cloud runtime as we call it, so that when we look at it from that standpoint, the network is an ideal enforcement layer, especially when...
You know, Alan, what I would say is, think about the entity we're trying to protect, modern cloud workloads. When, you know, when you went from a VM, you lifted and shifted basically to a VM, you know, a traditional next generation firewall, probably fine, probably north-south traffic basically is gonna be okay. But when you think about the progression of that, it's moved to Kubernetes, it moves to serverless, it moves to autonomous agents, right?
Like, if you have an agent-based architecture for protection, how do you do that basically with a serverless? Just, you know, when you think about the ephemeral aspects of workloads, they disappear and they come back, and IPs are different. So looking at it from that standpoint, the ideal scenario to get pervasive workload protection is actually the network.
So- Right ... you know, we utilized 10 years of building an asset of cloud, multi-cloud networking and orchestration, and now we're purposing it for protecting workloads. When you think of it, it's the one constant, right?
You know- In a world, in a world where we're all working from home or, or you know, from anywhere, there is no perimeter, there is no moat, there is no... The, the only constant is we're all connected, right? You know, it, it- And, and, and that's how you gotta look at it.
You know, you got it so fast, Alan. It's so- I alm- I almost had to skip a beat 'cause you got it so fast. You know, again, thinking about it from this idea of, like, some of the things that we deal with is, is enterprises almost always believe that the cloud network is implicitly trusted, right?
And like, that, that's one of the things that, that, that comes about. And, and then the rest of the security industry has been primarily focused on locking the front door. But, you know- Yeah ...
in the cloud and workloads, it's as if, you know, you locked the front door and moved everything inside of a building that has no walls, right? Yeah. It's like that's, that's basically, like, where the gap really lies.
So, you know, we find roughly that the last five years of security has been really focused on end user-centric zero trust, and we think be- and being accelerated by agents, that the next five years will... a lot of the focus will be on essentially what we refer to as workload-centric zero trust. And so that's, that's how...
what we refer to as our cloud native security fabric. Love it. Willie, before we jump into what we're gonna...
t-topic of discussion today, for people who wanna get more infor-in-information about A- Aviatrix, where do they go? ai. Um, the other thing that I think pr- practitioners would find high value is we provide some, threat research resources, like a threat research center.
Um, so you can come to find out about Aviatrix, but probably more importantly, come to find out about threats and other, things that you should know as a security practitioner, actually come to Aviatrix, and won't be product-based, but can help you do your job. Excellent. I love it.
Um, let's pivot a little bit. So I, I guess it was earlier this week, 'cause today's already Friday when we record it, the White House released their cyber strategy for America. And I'm warning you, I've got some opinions on this.
But I'm gonna let you go first. What was your take? Yeah, you know, um...
All right, so let's do this, Alan. Let's give credit where credit's due first, right? Okay.
So on one side, on one side I'd say this is the strongest presidential cybersecurity kind of posture statement that I've seen in my career, right? It, it is one side. But, but I think what's left up is the execution actually of it.
So they should get credit basically for putting this posture actually out. But, the other side of it is, you almost have to hold the applause because one of the things that I think is gonna be important is about how the execution happens around roughly kind of like the posture statement itself. And, and look, I, I think a lot of this actually has to do with, you know, how the public and the private sector actually work together.
W-one of the, I'll call criticalness is that, of course, Aviatrix likely has i-i-in this scenario, is a lot of the definitions of it, we think because of the threat landscape being in the cloud, is built on protecting end users, like we've mentioned before, when the real threat in front of us isn't the perimeter, it's actually in the cloud itself. And so we think that there's, while they define pillars, I think that there's, still a lot of specificity that they can actually make to have, this position actually translate to hardened execution. Yeah.
I, um... Look, I, I wrote an article on this. My views are out there.
You can check it out on Security Boulevard. Grab it on LinkedIn. Um, you know, to me, this is akin to what we've been hearing about the health clap- healthcare plan we're gonna get for the last 10 years.
It's gonna be huge. It's gonna be great. You're gonna have less money for drugs.
You're gonna have taking the insurance companies out. Well, we, we took that same analogy and said, "We're gonna have a great cyber plan. We're gonna be offensive.
We're gonna be offensive cyber warriors, and we're gonna work public and private," but make no mention of CISA, the agency that's supposed to be in charge of that public and private, you know? Uh, that they've cut the budgets and there's probably less than 1,000 people, and everyone I know who worked there left. I mean, it, it's kind of crazy.
And, but it, it goes on. We're gonna cut regulation. Now, normally, I'm not for government regulation.
I'll be honest with you. I'm not a big government regulator guy. But when it comes to cybersecurity, especially critical infrastructure that transcends public government-owned infrastructure, we're talking about utilities, healthcare, critical infrastructure.
This isn't a case of physician heal thyself. This isn't a case where, trust us, we'll, you know, we'll do... You, you need standards.
Like, we- Look, I've been in security for 30 years. I, I, you know, I've seen this, right? And for a long time, the security industry tried to implement some standards to sort of, veto...
not veto, but to negate the f- the government having to, right? The whole PCIIf you remember back- No, no, y- y- a hundred percent, hundred percent I mean, you- You know- You've been around, you know. Yeah, no.
You know what- We're, we're talking the same language here. We, we are. You know what?
I- you know, and if I build on what you say, there, there's one side of it basically, which is just as you said, the resources and, and, and you had agencies and departments doing good work actually in terms of standards like CISA. Um, you had an entire industry basically doing mappings to how does my solution map to NIST or CISA? So, you know- Yeah ...
those, those frameworks could continually be invested in. But I'll even take another angle actually at this in terms of that scenario of what they need to do in this area is, like, the, the people writing those national cyber security policies, they deeply understand endpoint identities, zero trust. They've been well briefed.
But the cloud network layer is new territory. And so, you know, from our vantage point, the, the industry hasn't been talking about this, and so that's where a lot of the focus actually is. But the, the largest threat, as I opened with, is this unguarded attack surface area that's actually in the cloud.
And then to your point about standards, Alan, it's like, where, where could we make some ground? Look, first, you could have cloud network security standards, right? Like, second, you could do what AI agent traffic visibility as a standard.
Would be nice. Right? Yeah.
Mm-hmm. Like those two things basically would be really fantastic in terms of really getting back to the substance that you're talking about. And then, you know, back down to the scenario of like organizations set up, you can have public and private, cloud security coalitions.
You know, the things that help us close the gap, between operational, you know, and taking a paper, but basically making it really enforceable in execution. The- these are, these are things, you know, like you said, they, they have to, they have to be more than just notions, right? They have to actually be grounded actually in, you know, either agencies putting forth very strong standards and like s- like I mentioned before, you know, it's, it's one thing to be rooted actually in what was the trailing architectures.
But, you know, today, how fast things are moving, I think we gotta look forward basically in terms of how are A- AI agents gonna impact these pieces and where are the areas that we actually see are being breached. And we, we think it's the cloud network is the- is that largest liability. Absolutely.
Um, you know, it, it, it's an interesting point you make there. I, I do think that the, the cybersecurity posture of this nation, and, and make no mistake, th- this nation, the US, is a hyper-connected society at the B2B level, the B2C level, and everything else. Uh, those are the kinds of situations that scream out for public-private partnership.
No private industry is gonna be able to do it themselves. Let, let's look at cloud, for instance. You mentioned cloud alliances.
Like, you have the CSA, Jim Reavis, the Cloud Security Alliance. Sure. They've been doing good, you know, yeoman's work now for, I don't know, twelve years, maybe more, right?
I'm trying to think. I was there at the first meeting at RSA when they formed the s- the, the CSA. My friend Rich Mogul's over there now as the analyst in residence or whatever.
They do a great job. They just came out with a whole bunch of new, of stuff. But the problem is this, where's the teeth?
Right? How do you get organizations to do more than shake their head and say, "That's nice"? How do you, you know, in f- and that's always been a problem in security, right?
Is because for each company, it's a risk management decision that they make. What I may consider too risky, you may not. Yeah.
And- Yeah ... you know. And, and so that's why when it comes to things like critical infrastructure, I do think you need some standard, some...
I, I always said to com- to people about security compliance, security compliance ninety-nine, nine hundred and ninety-nine out of a thousand times is lowest common denominator security. It's the bare minimum of what you need to do. You should aim higher.
Yeah, no- But if you know you're gonna have, you know... Makes no sense to me. You know, look, I think the, the, the things that you're actually saying, Alan, you know, when you think about when agencies won't show up, you know, the private sector has to be in the room, right?
Is, is basically what it comes down to. So, yeah, there's no doubt in my mind that, a- again, I wanted to give credit where it's due. It's great.
They put a position actually out. Um, it- and it's starting these conversations that you and I are actually having here. Yeah.
But, but to your point, you know, if there's no teeth in it, if there's, if there's not muscle actually behind the NIST and the, and the CSAs actually of the world, then, you know, the bottom line is, is much less identity and all these other areas that we actually know. You know, the cloud network is where American enterprise and government infrastructure actually lives now. You know, if we don't secure it, then, you know, what else really matters i- in, in my mind fro- from that standpoint?
So, a, a lot of what we're actually rooting for is, is great. It's a great gesture in putting out a framework along those lines. But again, putting some of the things that, that I mentioned, especially around cloud, network attack surface area, putting some of those motions actually in place, I think go a long way of putting teeth into the system.
How do we get cloud network security standards? How do we impose, regulations on AI agent traffic visibility? Um, you know, y- y- y- when you're, when you're putting some of these things actually in place in, in other hardened analogies, you know, the bottom line is, is that, you know, you, you would, you would deploy cameras in somewhere and mandate that they have cameras to watch certain things that have high protection.
" Agreed. Hey, we got a little bit of time left, not much, but I, I wanna take a right turn here. You mentioned AI and agentic AI.
Y- y-- It's the elephant in every conversation, right? It, it-- These last two, three weeks, I think it's set AppSec on its head- Yeah ... right?
With, with some of the stuff going on. It's gotta be having a huge impact on, on what you guys are looking at at Aviatrix. Tell us- It, it does ...
a little bit about it. Yeah. You know what?
So, so we, we articulate this macro problem. We kinda refer to it as the architectural divide, and, let me try to explain it actually to Alan. So if you think about the two opposing forces that you typically...
that most enterprises are dealing with. You know, they, they adopted a cloud because they wanted faster innovation, right? So faster innovation, they changed the way they develop, they, you know, have CICD pipelines.
They've-- They've gone to essentially how fast can they actually build this innovation? And certainly agents and AI are playing a critical role actually in that. You know, that's one vector is what's actually going on basically is like, great, they've adopted cloud, and that cloud infrastructure has gotten quite complex.
" It could be Azure, it could be AWS, it could be GCP, whichever one was the first cloud that they went to. But then all it took was another developer saying, "I like this cloud better," or they acquired another company and now they have multiple clouds, and the complexity basically grew. Then kind of along the other vector, I would say, is this idea that the workloads are evolving at a pace and have different types.
I mentioned VMs, Kubernetes, serverless. And then think about like an AI agent is like one of these workloads on steroids, right? Because it's autonomous.
It makes its own decisions. It has skills to connect to all these other pieces of data. And so when you think about those two vectors continuing to grow, that space in between is the attack surface area that all of these bad guys are really trying to actually go get.
So as, as long as you continue to develop agents and as long as you continue to actually have, you know, greater cloud infrastructure, you incorporate Equinix or a Megaport, that complexity is exactly what gets exploited. And so, you know, our posit is that what you actually need, and you said this earlier, is a pervasive enforcement layer, and that's where the cloud network actually comes into play. The, the idea that you could put like, an agent to monitor all of your agents that you're deploying.
I think one of the stats that I saw was like machine identities are a hundred and forty-four to one to human identities. So one, you just got all these things. Think about it like you, you're trying to monitor all these laptops because that's where user identities are.
Now you're at a hundred and forty-four to one relative to basic cloud. And that doesn't count the agents. Wait till agents- It doesn't ...
really take off. Exactly. Exactly.
You could put another zero in front of that. You throw the... And then they operate at machine speed, right?
And so, you know, and they're in this kind of scenario. So this is what, what are we dealing with in this scenario? You know, in, in many of these cases, it-- we're still in education mode, Alan, where, you know, trying to explain to people, great, you know what?
You need to have your arms around securing your cloud agents, but utilizing that network as the enforcement layer is the thing that's gonna allow you to have common policy across all clouds, to have common enforcement, close to where the workloads live and where they, where, where, where the greatest vulnerability actually is. So yes, we're quite busy in that scenario. They're-- For the folks who get it, they're running actually to us.
" Um, but I think, you know, again, we're at-- entering into this next era where, what folks will actually think about is what, what, what can they do roughly actually to enable themselves to take advantage of the innovation that's coming with AI agents, you know, expansion of workforce, acceleration basically of a 10X knowledge worker. And to do all those types of things, they have to be confident that they can securely deploy those agents in the cloud, and that's where Aviatrix comes in. Got it.
Hey, Willie, I got... We're over time. I apologize.
I got people in the waiting room for our next interview. I'd love to continue the conversation, though. I'm gonna be at RSA.
Is it next week? Next week by the time people see this, if you're there. I will be too.
We're at, Broadcast Alley in Orwell. Fantastic. Stop by- Fantastic ...
and say hello. I'd love to meet you in person. I would too, Alan.
Thank you so much. All right. Willie Tejada, GM and SVP of Aviatrix, here talking about the cyber s- strategy for America, but more importantly, about securing our cloud networks.
Uh, we're gonna take a break on Techstrong TV. We'll be back in a moment.