Thet Future of AI in Cloud Security | KubeCon SLC 2024
KubeCon highlights significant growth in attendance post-COVID. Liat from Tenable shares insights on the company’s evolution, including the acquisition of Eureka Security, which strengthens data security management. The discussion focuses on the importance of contextual data in cloud security amid rising AI risks. Predictions for 2025 emphasize AI’s role in cloud infrastructure and security, alongside Tenable’s investments in comprehensive security solutions and Kubernetes Security Posture Management.
Transcript
This is Textron tv. Hey everyone, good morning from Bridged, well, maybe not frigid, but certainly cold Salt Lake City. We're here with our Day two Cube card coverage.
We're right on the show floor. I hope you guys can appreciate this on lot of people walking around. I think there's, uh, the, uh, CNCF folks said there's nine or 10,000 people here for the Salt Lake City Cube Con.
It's the biggest cube con, uh, since, uh, in North America anyway, since COVID. I believe the ones in Paris and Amsterdam before that were, uh, bigger. So it's interesting that Q Con is actually bigger in Europe than it is in in North America.
Um, speaking of Europe Q Con, they've also announced obviously that next year's, next Springs Q Con Europe will be in London, and, uh, there will be one in Japan in 2025. And then, uh, Atlanta this time next year. So stuff to look forward to.
We're gonna do something a little different on our show here this morning on our live feed. Um, our next guest couldn't make it here in person, but nevertheless, they are a player in the cloud security and cloud native scene, and I wanted to bring them in for their view on things. I'd like to introduce you to.
T lia is, lemme put on my glasses so I don't mess this up. Lia is the VP product management and research for cloud security over at Tenable. First of all, Leon, thank you so much.
I know it's evening in Tel Aviv, so thanks for joining us. I appreciate it. Um, always wonderful to have our friends from Tenable on.
You know, I, my my relationship with Tenable goes back to when Ron and, and Rene originally founded Tenable. I guess that was around 2001, 2000, something like that. I had founded a security company and also vulnerability management, and I know Ron ever since.
I'm, I'm actually still good friends with Ron and Cindy, so it's always good to hear from Tenable and what's going on. Um, Leon, before we get into news from Tenable, and we're gonna talk about some things, let's hear a little bit about you. If you wouldn't mind sharing, I gave them your title, but give us a little bit of your background, a little of your story.
Of course. Uh, so I'm actually quite new at Tenable myself. I've only been at Tenable for five months now.
Uh, I joined Tenable through its recent acquisition of Eureka Security. Sure. Um, I was a CEO, one of the co-founders for Eureka Security, where we focused on data security, posture management, and data security platforms as a whole.
Um, and then, uh, before founding Eureka and, and, uh, joining forces with Tenable, which was a, a three year journey that we can cover, you know, we can spend a whole hour talking just about that. I spent about six years at Peloton Networks, uh, also leading product management teams. Uh, so I've, I've had my, uh, my time in the cybersecurity industry, seeing it from all directions.
And then, uh, before that, uh, being from Israel, I spent about a decade in the Israeli, uh, cyber cyber command in the IDF. Got it. Uh, so that's a bit of Excellent.
Excellent, excellent. So, look, tenable is much more than Nessus or vulnerability scanning today, right? It's really become a soup to nuts type of, of, of security operation.
We'll get into it, but Eureka Security, which is a company you co-founded, acquired by Tenable, may be new to our audience. Why don't we, if you don't mind, tell us a little bit about what Eureka did and how that has made its way into the Tenable product line. Um, so Eureka Security, uh, was, was a data security posture management platform.
Uh, what we like to refer to as DSPM, uh, DSPM, um, actually means two different things in the industry these days. Um, we acted as the first one, which is a standalone data security platform that allows organizations to see, classify and protect their data across SaaS, applications, cloud environments, data warehouses, and so on. Um, but it also ties very strongly into the cloud because a lot of the feature requests and the, and the integrations, uh, that we received as Eureka back then is to help organization not just see the, the, the data security posture, but to get that within the context of the applications and, and security tools they're already working with.
So it's not surprising that synap solutions, like the cloud security platform we have now at Tenable want to have the data context when, when we, when figuring out issues and exposures that you have in the cloud, right? If you have a vulnerability in a, in a compute instance, like an EC2 instance in AWS knowing whether or not that compute instance has a self-managed database on it with sensitive data changes significantly the prioritization or how fast you are, you're going to, to handle that vulnerability. Um, so that context became quite significant and that's exactly how we fit into the c napp solution here at Tenable.
I love it. So look, CCAP is obviously a, a pretty fast growing space. The, the data security platform management is a maturing thing, but I'd like, you know, look, we're here at CubeCon, right?
There's, I don't know, almost 150 sponsors. I said about 10,000 people security's on top of everyone's mind. But, you know, the cl when we look at cloud today, it's not just in the AWS data center or Google or a Microsoft data center, it's on the edge.
Some people are taking and building their cloud, private cloud, if you want to call it that. But they're, you know, putting stuff back in the data center and what people are looking for in security solutions today is not a separate solution for here and a separate solution for there. We want a solution, right?
That, that transcends my infrastructure wherever my data is. I, you know, talk to us about how data security, posture management helps with that as well. 'cause that's what people are asking for here, right?
This multi-cloud type of approach. Yeah. So there, there are few layers to what you, you just described because on one hand, and, and we, we are strong believers in that there's a huge benefit for, from having the platform, right?
When we talk about at Tenable, when we talk about exposure, we want to, to help organizations identify true exposure across the environment. So if you have compensating mechanisms or specific choke points where exposure can be mitigated, we wanna be able to identify the best, you know, the most effective, uh, ways to, to approach that. That being said, you can't really do that if you don't have best of breed products that tell you about the, the issues, the findings, the exposures within their specific perimeter.
Um, and when we talk about exposure, it's, it's what, uh, is, is, is the, it's the risk itself, but also what's at risk. It's the vulnerability, but what that vulnerability exposes behind it. So, uh, with, with our CNAP, you know, we're a best of read cloud security product on its own with the data security posture management capability within IT allow, allowing us to assess the risk to understand what the impact of an exposure might be.
And that fits as a piece of the puzzle within our Tenable one platform that allows us to provide, uh, organizations with the ability to, to see overall risk, prioritize that risk given everything that I just talked about, and be able to act upon remediating or addressing that risk. Love it. So Leon, we're, it's, it's the end of the year almost here, right?
We're coming into November, December. Where do you see, as we look ahead to 2025, where do you see the risk in cloud security? Where do you see the new battlefront in cloud security, if you will?
So, if, if, if, let maybe start by, by providing some, some of my, uh, my perspective on, on cybersecurity in general. Sure. Cybersecurity is an extension of it, right?
We, we do not protect things just because we love it, even though we do love it. We protect the things that our customers, that our organizations actually need. Uh, whether if it's, you know, new applications that are using new mechanisms, new use cases that they have.
So even the, the evolution into cloud, um, has, has been an extension of organizations moving to cloud and the need to, to protect that, uh, the need for providing data context as followed up cloud because we now have stronger motivations for organizations to store more data in higher volumes, higher levels of sensitivity within cloud infrastructure. So that's an extension of that. So the easiest way to answer your question directly is to ask ourselves, what are organizations going to do, uh, in, in 2025 that we need to be able to help protect against right to, that we need to help them do, but do securely.
Um, and I think, you know, the, the answer that probably is on everyone's minds as as I'm talking is ai, right? We are really now at the phase where AI is almost every organization we talk to, uh, when we ask them what do, what, what do they do with AI today, their answer is, we're testing it out, right? We're now trying to see what, what it will give us 2025.
2024 was the year of experimentation around ai. 2025 is going to to be the year where I believe most organizations are going to seriously adopt, um, AI mechanisms to create AI pipelines within their cloud infrastructure to generate AI and gen AI applications. Um, so this is, this is the next forefront, right?
This is what we, we wanna make, we wanna help organizations make that transition and make it securely. Um, and, and that's what we're, that's what we're focusing on too, to help, to help them do that. Got it.
Got it, got it, got it. Um, you mentioned ai, you can't do an interview without mentioning ai, right? Yeah.
That's what's in everyone mind. And There's, there's two side, right? There's, and AI is like a Gemini, right?
There's always two sides to ai. There's the good and the bad, but that's how life is, right? Uh, I always like to say God never gives everything to everyone.
There's always something, there's a price, but certainly the, the promise of how it could help us here is, is huge, right? Um, do you think in, in your perspective of, of, of security and, and, you know, for 2025, do you think you've given enough weight to what impact AI's gonna have here? Or I'm, I'm, I'm, go ahead.
Most certainly. We, we did not, right? I think, I think it's going to, the, the impact is going to have is somewhat unexpected.
So I think the, the, there's no, there's no real way of saying yes, we assessed it correctly. Uh, we are seeing AI impacting our, our, our organizations and our customers' lives in three ways, right? So the first one is what, how can they best leverage ai or how can the tools they're using, like us best leverage AI to help them, right?
So being able to ask questions in a, in a, uh, natural language based way, uh, being able to provide remediation steps that are very contextual and very descriptive of what they need to do. So that's the first thing. The second thing is they are now starting to generate, oh, AI has become, it's almost like, you know, talking almost like just saying, we, we do code, right?
Everyone will be doing AI soon, so how can we make sure they do it securely? And then the third aspect, and, and this is what we know today, right? There probably are more, is we know hackers and attackers also leverage ai.
So how can we make our protections better to make sure that the, the techniques they're using, the speed of delivery, delivery of how fast they weaponize, uh, some of the, the, the, uh, exploits and, uh, and mechanisms they find using ai. How can we make sure though we protect against that? And that's only things we've seen in, in the last year or so, right?
It's, it's still pretty new. I'm sure if we have this conversation again in a year, there'll be number four and number five, and maybe even number six to that list. Excellent.
Let's talk a little, I just said what was about five months you with Tenable? Now I look, I'm gonna ask you to look into your crystal ball again, and, and, you know, the whole cmap kind of offering, uh, you know, uh, the, the, uh, platform security, platform manager, digital security, platform manager, DSPM, how do you see, like, how do you see that integrating into the Greater Tenable one, I think is the name of the platform, right? Do you think that that's where it's at now is adequate or what, what leverage and, and improvements do you think we can expect to see there?
See, yeah. So I definitely don't think we're, we're at the end of the journey. We're at the end of the road, right?
Uh, Tenable's investment in cloud is only, is only begun and is, is, is increasing, uh, with time. Uh, we very much believe this is a strategic area. So that's why you've seen on two, two acquisitions already in the last year or so, and a lot of investments also internally and organically.
Um, and then in parallel, we are seeing the same level of strategic focus and investments on the platform side on Tenable one side. And the reason you're seeing both of these advanced at the same time is because we believe the power and each of them is, is a great product on its own, but the power really, really relies in the combination of these two components along with the foundational core product that Tenable already has today. So in today's world, for organizations to really be able to understand their exposure, having a strong, uh, basis, a strong foundation of understanding their vulnerabilities across their environment and building the, the, the cloud, um, context on top of that is what we believe provides them the best understanding of exposure and, and, uh, and risk across the environment.
Good. Excellent. One last area I want to cover, if it's okay.
So we are here at CubeCon Cloud Native Kubernetes, and all the things that go with that. What's specific to the cloud native stack, Kubernetes microservices containers? Does DP, uh, DSPM, you know, specifically help or, you know, interact with?
Yeah, so maybe I'll start by saying that, uh, uh, Kubernetes Security Posture Management, KSPM, I know we love acronyms here, um, is, is a foundational part of any, any great CX solution, ours included. So being able to, to protect, uh, Kubernetes based deployments, by the way, both in the cloud and on-prem, because we do believe that, uh, the, that that is an extension of the cloud environment for many customers is a foundational aspect in, in our synap solution. The way to think about DSPM, the way that I like to think about the integration, how, how Eureka Plus Tenable, uh, is, is a better together story is that data exists everywhere, and having data context across the environment benefits any aspect of the cloud security solution.
So if you're looking at KSPM or if you're looking at runtime protection, if you're looking at configuration management and CSPM type of capabilities, each and every one of these capabilities gets better. If you know what data it has or what data it can access, that is also an important. So if you have a container that has access to an S3 bucket that has sensitive data in it, that is something you want, you might wanna manage a difference.
Um, so it's, it's really about the combination of those things together and the ability to identify what we call the toxic combinations around those things. So, so, and, and again, Kubernetes and KS DM is a foundational part of that. So it's really, it's really all about combining those things together.
Li I don't know if you could hear, they were making announcements. It's a little loud here, but listen, I want to thank you for joining us. I'm taking time outta your evening to join us here live in Salt Lake City.
Um, next time we'll do it in person, maybe RSA or something will be there or reinvent. But thank you so much and congratulations by the way, on the acquisition from Eureka, by Tenable. Keep up the great work and we'll talk to you soon.
So much. Have a great conference. Alrighty, li Hyun, uh, VP product Management and research Cloud security at Tenable.
We're live, we're a cube con. We'll be right back.