Paul Stamp, Cado Security | KubeCon + CloudNativeCon NA 2022
Paul Stamp, Vice President of Products at Cado Security, joins Alan Shimel at KubeCon to discuss the company, an automated security incident response provider for cloud workloads.
Transcript
This is texturing TV. Hey everyone. We're back live in Detroit for kubecon.
This is our day three coverage. I'm happy to be joined. So this gentleman here.
I know from my security days. We probably know each other longer than we both want to admit at least 15 maybe more years. His name's Paul Stamp Paul.
Welcome. Hi. Howie's good to see you my friend.
Yes. So look, you're with Cato right? We're gonna talk about that.
But before we do I already said How do we know each other so you got to talk a little bit about your background? Sure. Yeah, so I've been insecurity for about 25 years.
Yeah every bit. Yeah, I started off as a security consultant and then one dad I answered an ad in the Boston Globe to be an analyst Forester. So, you know, I was allowance Forester for a couple of years then kind of spent some time on RSA and there's a little bit of time AWS.
And then since then I've just kind of been doing smaller companies kind of doing security thing security product management. That's at smaller companies. It's been a it's been a great ride.
I've really enjoyed it. I certainly has and I think I don't know if you were at Forest or when I originally met you. I think I was I think I was yeah, I got to meet a lot of people in that job.
It was it's great. But we've stayed in touch all through the years and now lo and behold were both here at Cuba good native indeed. It was the company it's called Cato.
That's right. That's right. So sure do share so Cato.
We do automated incident Response Security incident response for cloud workloads. So, you know, you've got your xdr or you've got your intrusion detections or your sins that will trigger off on alert. What we do is we automatically fire off the process of going acquiring the workload whether it be a VM a container a serverless function.
We'll do you know, we'll get whatever data we can whether we belongs with a full disc acquisition memory. What do ultimate the entire process of what an analyst would do of going through that and then presenting back to the customers think to the Of what we think went wrong was this a false positive if it wasn't a false positive, you know, when did we start to see this activity? You know, what do we think is that is actually going on here.
Excellent, and then we and then for the people that really want to dive in and do more of that we get kind of forensic level detail about why actually went on my system. So how do people engage Sure, so, you know, we've got to cut a couple of times people, you know, we've got the folks that you the traditional security traditional incident responders that it should all you know, folks that don't want to use the desktop tools anymore because we run, you know in the cloud ourselves, then we're able to take advantage of all the parallel processing and all that stuff and then you've got the other folks who are really imagining how they do security operations, right? They, you know, they're not going out and hiring your traditional analysts.
They're going out and they're they're hiring engineers. To instruments every step of the process and ruthlessly automate every step of the process. So that's really where that that that's where Cloud native in the whole debug thing.
You know things is about so that's great. What about the show here? What's your impression?
Sure? Yeah. I mean, it's it's interesting that that this is this is very much a developer show.
Yes. It is very much a developer show. But you know the days of the security team kind of been in their Ivory Tower and out there are gone, you know every developer Is really responsible for security.
I mean because as well if they don't do that then then you know Something's gonna happen where they're taking away from developing new features to go and fix security bugs or deal with security incidents and they have a responsibility to do that and they want to make sure that they're maximizing their time. So they're doing it right first time right from the beginning which is you know, really interesting for folks like you and me that have been in the security actually a long time. This is what attracted me did the whole that's why I started devops that guy make years ago.
Whoa was short on time for people want to get information about Cato. Where did they go? com.
That's right. Hey, man, are you gonna be at RSA? Of course?
I'll see you there in April. Thanks a lot. Cheers.
Bye for stamp Cato security. If he's with this company. It's a good deal.
Go check it out. We're gonna be we're gonna take a really quick break. We've got a lot of people waiting.
Got a lot to bring to you today here from UConn Detroit back in a moment.
