Techstrong TV – December 8, 2022
Catch discussions on shifting left, networking, cloud security and more on today’s episode of Techstrong TV.
Watch our live stream on Monday, Tuesday and Thursday weekly, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, Cybersecurity, Cloud-Native, Containers and deep-dives into specific technologies and best practices.
You can watch the free live stream on the web, or on YouTube at DevOpsTV Channel, Facebook Live, Linkedin Live, Twitter or on Roku, Apple TV and Amazon Fire
VTV via the DevOps.com TV app. Also on Android and iOS devices via the DevOps.com mobile app.
Transcript
Hello everyone and welcome to Tech strong TV. Today is Thursday December 8th, and I hope you all have a wonderful day so far. I'm your host William Willis and in today's show.
We're gonna bring you some fantastic interviews with Incredible guests from around the world. So stay tuned. As always I'm going to start off with our text strong news recap feeling you win on the biggest Tech headlines that are making waves.
Then we'll head over to Allen where he will speak to. Yeshi novel Chief strategist and CMO at kaito networks to talk about how it became the fastest growing Enterprise Network Security startup with annual recurring Revenue growing from 1 million to a hundred million in just five years. Then we go to kubecon Cloud nativecon North America where Alan met with Jim Douglas CEO and Armory and Fernando frere principal engineer and engineering manager at Armory to talk about the evolution of delivery platforms of the past decade how to fit in the environments people are using and how to leverage infrastructure that is already present.
Also coupon Cloud nativecon Allen spoke with Asaf Cohen CTO and co-founder of permit IO to give a deep dive into permit IO the only full stack permission Solution on the market. We're then joined Barbarian Cota J Brown who will hop on to tell us more about some of our upcoming webinars. Next up we are in episode three of our series engineering the change.
This series will follow the three winners of the engineering the change scholarship program as they tackle a 10 week intensive coding boot camp and prepare themselves for careers and software engineering. Then we will be airing episode 20 of the lab with Brandon O'Leary where Brendan tells us about this month's gitlab release. Then Mike Rothman will speak with teleport CMO Michael ferranti as Michael fills us in on their recent report highlighting access and security challenges as infrastructure becomes more complex.
Then we go to koala security conference 2022 where Alan met with quality. So Jonathan troll to discuss the priorities of security teams leading into the 2023. Also equals security conference Alan spoke with the lane Miley senior Cloud security engineer at Mercury Financial about methods that drive compliance and Remediation efficiency.
We will then wrap up this broadcast with two episodes of view with vizard in the first episode of Mike fizard interviews at Maps CEO Elizabeth Lawler as Elizabeth explains why observability needs to shift to left to ensure the best application developer experience possible? Then Mike Will interview Tom Gillis senior vice president and general manager of the network and advanced Security Group at VMware as Tom explains how project North Star will finally unify the management of networking and cyber security in the multi-cloud age. And that's what we have coming up for you here on this episode of texturing TV.
So that further Ado. Let's get the show started. Enjoy.
Do you know what you want? We afford this place. I'm thinking a thousand piece kubernetes Cloud workload protection and xdr combo.
Oh, yeah. I actually don't see any prices. I don't have to order off that thing.
We don't how did you get in here? Check this out? optic secret dollar menu Order today and you can secure any combo of cloud and endpoint assets through the end of next year all for one dollar.
What if I want to secure 100 Mac laptops and 900 Linux servers one dollar. What if I want 500 laptops and 500 kubernetes nodes just a buck. Yep.
Mix and match to create the combo that works for you. What about customer support? Yep everything for just a buck?
We're gonna order off the Optics secret dollar menu. And seriously, how did you get in here? Seriously, seriously?
Try the Optics combo of cnap and xdr delivered in a single UI and data model just one dollar just to secure your Cloud containers and laptops through the end of next year offer ends, December 31st. Hi again, everyone here the headlines for December 8th. First up the top Hospital in India is moving its way back to normalcy after a Cyber attack has hampered its operations for nearly two weeks.
Online registration of patients only resume two days ago at the all India Institute of Medical Sciences. It is currently unknown who conducted the attack but it was followed by several failed attempts to hack into India's top medical research organization raising concerns of the security of India's Health Systems. India launched initiative to digitize health records of patients last September with over 173,000 hospitals registering for the program since this being said experts fear that the hospitals might not have the ability to keep these records safe and further action might be needed.
Next the newly founded Japanese Semiconductor Company rapidus signing agreement to collaborate with the Belgian researcher organization to develop the next generation of semiconductors for production. Rapidus which only launched last month has already signed an agreement to team up with iMac a research organization known for nanoelectronics. the two planned to develop and mass produce a two nanometer chip by 2027 rapidus said it will send Engineers to iMac and Forge other ties with research Labs outside of Japan as well.
Japan was once the leader in the semiconductor development and production industry and with this new deal rapidus plans to bring Japan back up to the top. In other news in the move towards clean energy sources the US auction its first ever leases to develop commercial scale floating wind farms off the West Coast. What's more is that the five leases Drew strong interest from over 43 companies from around the world?
Well offshore wind is established in other countries such as the UK the United States is just beginning to jump into this energy sector. While the diversification of energy is impartially need for clean energy developing offshore wind farms has become significantly cheaper approximately 60% since 20 times. Currently there is only 123 megawatts of floating offshore wind operating but it's expected to increase to 19 gigawatts by the end of 2030.
The US is currently planning two other sites for auction in the next two years. Next amidst regulatory scrutiny and delayed adoption of autonomous vehicles Uber has partnered with the driverless technology company emotional to launch a public robotaxi service in Las Vegas. This launch is part of a 10-year agreement between the companies for driverless vehicles that will drive both passengers and delivery items.
Riders are currently not being charged but will be when this program will launch is commercially. Zooming out write your platforms are pushing towards Robo taxis with both Uber and Lyft making deals with driverless technology companies. Uber plans to make a fully driverless experience available to the public by 2023 On Security Boulevard, we have an article looking at a survey showing the shift towards passwordless access.
In a survey of over 500 professionals 87% says that they are moving towards some sort of passwordless approach. com. com.
We've an article looking at the cultural and Technical challenges of devsecops. From a global survey of over 600 it professionals 71% sided culture as the biggest barrier to the adoption of devsecops. Additionally 57% of the respondents stated that security threats were the biggest technology challenge to driving the adoption.
com. Finally on container Journal we've an article looking at our five predictions for kubernetes in 2023. Kubernetes will only continue to grow throughout next year yet.
We need to ask ourselves what we need to know as kubernetes adoption spreads. This article looks at five things. We believe you should pay attention to if kubernetes is important to your organization.
com. And that's today's texturing news recap. com is the number one online destination for devops education and Community Building.
com covers all aspects of devops including devops best practices and tools devops culture devsecops business impact continuous testing continuous delivery and more. com has the largest collection of original devops content featuring breaking news blog post podcasts and more. com where the world meets devops.
Hi everyone. Welcome back to techstrunk TV. Our next guest here on techstrong TV is you shiao Bell yishai is with Cato.
Okay, no networks and look I've been around I've been aware of Kato for a while. Now in the in the security space. I assume many of you out here have heard of Cato and probably more than a few of you are very familiar with Kato, but just in case not to worry we're gonna First of all, welcome you shy you shy welcome to techstrong TV.
Why don't we start with that with Kato? Give us a little background on Cato and maybe a little of your own background. Okay, so first great to be here so get on networks is an 8 year old company.
It's a network security startup that his innovated the convergence of networking and security into the cloud. So when we sat down back in 2015, and we looked at the clients World, which are founders came from flomo Cramer is the co-founder of checkpoint a software. The idea was to take networking and security and deliver them as a cloud service.
It sounds relatively simple and straightforward but technology. Needs a huge Challenge and what we've done over the past eight years is actually build out a platform a cloud service with almost 80 points of presence worldwide. The deliverer a wide range of networking network security capabilities power warnings your web Gateway caspi antimalware IPS quite a few of those and deliver it to over 1500 customers worldwide 23,000 locations half a million more users.
So I think what we have done is prove the last eight years, but it's possible to deliver these kind of capabilities at scale on the cloud and I think it's a it's actually a great news for a lot of our audience in the Tech Community. Love it. So you say you know our audiences I mentioned off camera is very technical, but about I don't know maybe 40% of it comes from a cyber background.
The rest come from devops cloud native, you know that that software development testing. the gamut Some of the developers. I mean when we talk security, they think in terms of deaf secops testing code making sure code is more secure but I don't know if they fully understand the challenges of trying to do, you know, what was traditional network security putting big appliances right at the entrance to the castle and having a moat right?
And you had a choke point with a firewall or what have you? And what you know saying I'm gonna do that from the cloud sounds very easy as you said but it's really very hard because you don't have that choke point necessarily. You don't have that big box sitting in front of the land there may not even be a land.
It's a win. It's work from anywhere. Why don't we first talk about really some of the challenges?
That Cato, you know tackles here in when we you know, we talk about moving it to the cloud. Right, and I think you made it very good point about the choke point, right? So if you think about this big Appliance or appliances they are present in certain locations where traffic must go to in order to be processed inspected cure and then go to the Internet or to the cloud.
And it it had worked in a world where everything was centralized. We had applications in a data center where we would put this firewall to all the traffic we go to the data center. And from there.
It will go either to applications on Prem or to the few applications that were on the Internet or in the cloud. And we moved to a world where it's everywhere to everywhere users can be everywhere an applications can be everywhere right these Cloud maybe folks. They are part of these movement moving on premise application to the cloud delivering applications from the cloud doing it in a global staff.
You may have multiple applications running a different regions. So ultimately, what do you put security here? Where is the job?
There is no choke point and the killing Ovation is these this cloud service with 80 points of presence is in the middle of everything? Okay. So it is basically this house which board we're all traffic go through and then comes out and we're ever and whatever fashion session you have use Earth to an application device application iot to the cloud.
It doesn't matter what the edges what the source it is what the destination is. There's always Security layer that sits in the middle of everything and that's a very big change from the traditional model where Appliance were sitting by themselves in some age and all the traffic has to be artificial in awkwardly get to them just to be inspecting we take away this trombone effect if you like which is rocking traffic in an inefficient way just to have it inspected by devices that were built for a centralized World, which doesn't exist anymore. Absolutely, excellent.
And look this is not new obviously, right this we we've You know been exposed to Cloud now for 15 plus years. I think people are understanding, you know, you have identity and access management to Cloud resources. There is no more centralized.
You know land type of thing. But so, you know, it's all in there now. But to take that as a business model.
And and recently Cato reached a kind of Milestone here of a hundred million dollars ARR, is that correct? That's correct. I mean that's that's you know a million here a million there before, you know, it's a lot of money, you know that that's a significant amount of money.
On that business model right of delivering this security via the clown. What does that mean? What do you think it means to our audience?
Why you know beyond it's a lot of money shy right? No you everyone knows that but what does it mean? So I think the first thing is that keto has been working hard to prove that we can operate at the scale the resiliency at the capability level that Enterprise spit.
It's not trivial you're used to do something for 20 years in certain way somebody comes in and say we're gonna do it completely differently and we're gonna do it in the most Mission critical part of your business, which is your network that connects everybody and the security that protects everyone. So when you reach a hundred million with the number of customers, we have the locations the clouds the all these different users. I think customers first of all have a confidence.
This is not a novel idea. It's not a concept. It's not the startup that is trying to you know, prove something but there is in fact has been proven.
So I think that's the first thing is customers of all sizes can feel confident to consider Cloud migration of the networking and security infesture. And as you said almost everything is gone to the cloud. It's some shady form and networking security the network security.
These are clients elimination replacement is something that is very new or is the last healer of it infrastructure to really move to the cloud. I think that's the first thing is there's confidence in the ability to take this idea this Vision or conversions in the cloud for healers and adapt it because so many organizations have in Mission critical environments in retail in manufacturing in legal in finance. It works.
The second is obviously that we are now over 700 people. We have a massive roadmap to deliver in a very large amount of new capabilities continuously. That's a benefit of the cloud model.
If you're familiar with the clients and the audience is you know, that the plants vendors release a new version every six months every nine months. There's a new build for the applies. It has these new features.
We release new features every two weeks so we can run 26 upgrades of the cloud every year. So there is this way of new capabilities that customer basically can access can utilize without Grace without patches without all this hard work of just bringing all these physical infrastructure. So they're gonna get more capabilities.
They're gonna get them faster. They can adopt them faster. And what's nice about convergence is that their TCO?
The total cost of ownership is not going to change meaning if you need to consume 20 features of security and you want to go to 30 today. It means more Point Solutions more people to maintain then you need expert just for these functions here. Everything comes through the same model same platform.
You're actually gonna be able to keep the same team or less and adopt so much more capabilities so many more capabilities, which is the value of the cloud. So production scale more features delivered faster that you can consume with a smaller team. I think that's that's where networking and security is going I agree.
I agree with you, you know, we friends when we got it too faster. We got to be more inclusive. Right Securities, everyone's responsibility.
And we and we we also need to deliver results. You know, we were kidding before coming on. I was added Vegas last week for the AWS reinvent show and besides a lot of our people getting sick there.
security was so like right in your face security was job one right for everything and and reinvent this developers that security people there's operations people. It's everything but I think never before have we seen security become so front and center. Right, as you know, everyone really focuses in on it.
Look that's got to mean something for Cato networks going forward too. What do you think you shine later? Where does you know this emphasis on security?
It's obviously got to help but how does Kato use that to help our audience? So when we think about clouds or cloud data centers Cloud applications, they are edges to our Cloud Network meaning we are inspecting all the traffic going in and out of these cloud data centers and in and out of the SAS applications that the organization is using obviously 65 Drive books all these guys so you actually get the same engine the same layers of security basically dealing with the production traffic. Okay, meaning that basically we can look for threats trying to Target the cloud data centers or if something got the horrible data center.
They're trying to come out we actually going to intercept it and so here provides this and a leveling of the playing field right? It's not one solution for one friend and one other solution for the cloud. It's also clouded nostick because we are the switch Hub then we treat Microsoft.
Traffic like we would treat AWS practical which is Google traffic. So all of these capabilities are consistently enforced across all clouds and all applications. So that's another dimension where we do and in fact, if you look at our customer base, there are probably over 500 cloud data centers connected to the cattle infrastructure as yet another age, meaning or within an organization.
Some of our customers have seven or eight cloud data centers globally and there are part of the same policy the same governance the same control and also gives the customers and the IT audience the freedom to migrate applications on Prem to the cloud and back. It doesn't matter where the application is that going to be controls applied to it regardless where it is. So customers can gradually mind with and this is something that I'm like startups that tend to focus on the future.
Okay, we're gonna develop just Cloud security. We actually with our solution. We are backward and forward compatible.
We would protect your applications in on-prem and in the cloud in the same way. Got it makes perfect sense. You shy where we're almost out of time, but for people who want to get more information about Cato check it out.
Maybe be contacted. What what do you suggest? com.
We have a contact task form where you can indicate if you want a demo or you just want to be a cool back. I will be very happy to have this conversation. I think that for the vast majority people organizations getokin dramatically reduce your costs your complexity and empower the team to focus on what's important, which is securing the business instead of maintaining the infrastructure.
I think that's that's a big value for all of our customers. Absolutely. Hey, I want to thank you for coming out here on techstrong TV.
It's been a while since we had an update and it's good to hear what's happening and continued success in Cato. Thank you very much. Ellen.
Great being here and looking forward to our next time. Okay, we're gonna take a break here on Tech Strunk TV. We'll be right back.
This is Tech strong TV. Hey everyone back here in Detroit for kubecon continuing our second day of coverage from the show floor. io.
A they really were the company that took Spinnaker commercial if you will right speed for those of you who don't know Spinnaker. Who's a amazing CD. See I see program came out of that Netflix right Google.
It was donated to the CDF Foundation probably but three four years ago now. And but Spinnaker is the company that really kind of. If you want to do Spinnaker in a commercial setting they they were you know, not just the rural open source.
They they were the experts kind of pioneered that I'm really happy to have him back on the show. I don't think we've had anyone from Armory guys on Tech strung TV. In a while spent too long.
We're happy you are and I'm really happy you're back. Maybe you took us coming back in person. Right?
Let me introduce you to write two friends friends here from Armory to my immediate ride is Jim Douglas Jim. Welcome. Thank you and to Jim's right is and we're gonna do our best.
We practice this off camera Fernando free day free day now, I don't do that rolling or I don't matter how much I drive but that New York. But anyway for Nando welcome. We should start off with what do you guys do in Armory?
Absolutely. I'm president and CEO or Armory been here about a year. Now.
You're excited to be with the company Fernando. I'm an engineering manager here at Armory. primarily developing Spinnaker and innovating the Spinnaker platform fantastic, welcome guys So, you know, I hope I didn't embarrassed you talking about the history here in Spinnaker and stuff.
But you know Spinnaker remains today an amazing amazing tool specially, you know, it used to be well, you're not Netflix who is yeah, but it's an amazing. Tool is it just an Enterprise tools out is it you know, how far how low does it go now? It's not.
I mean a couple things to think about just think about this show. It's called kubecon, right? Innovators 10 years ago that started Cloud native.
There was no tooling. So Google had to invent things like kubernetes that apply containers Netflix has got an outrageous deployment profile right 400 apps a day. There's nothing out there that could do that.
So they had to build the platform that could handle that Spinnaker a key to it is the power to do the multi problems. I call it multi environment and multi-target multi-cloud. How do you do that at scale?
And I think what was really attractive early is a lot of the early teams the platform teams wanted to be able to build curated deployment solutions for their developers and Spencer gives you that flexibility to do that. I think what we're seeing and one of the big highlights here is like every software industry. I cut my teeth in the kind of Eda or Electronics on automation world you see abstraction over time where you take away complexity and we're seeing that today right a lot of companies here talking about what's next on top of kubernetes and same things gonna happen in continuous deployment as kind of next gen that weren't the kind of innovators early adopters come along.
They're just looking for automation, you know, so for us, Spinnaker is a key part of our story. But our core competency. Our focus is really on continuous deployment at scale and one of the difficult things for the folks that are new to Cloud native is that got this thing called Legacy portfolio, right, you know as with a major bank on Monday and half of their applications are still running bare metal VMS, some of them they've refactored they've containerized and new apps.
They're trying to get into best practices around Cloud natives. Like how do you do that? That's the problem.
We're trying to solve and it said Spinnaker's one tool for that. We've got some new SAS tools as well. Really that take the best practices that some of the best teams on the planet have you Spinnaker to actually build deployment strategies around and fully automated that for the folks that I want to spell deployment.
They want to use Canary they want to use blue green they want to use Progressive rollouts, but they don't want to understand them. So we're trying to address that gamut but the end in mind is how do you reliably deploy software at scale as had scale is a world's not just kubernetes kubernetes is important but it's a lot of different container technology. This is non-container Technologies.
And how do you do that multi-environments and hybrid cloud is where everybody's going. So absolutely that's what we're trying to nail, you know. I mean look, it would be great.
If we all only worked in greenfields. Absolutely. I start with a blank piece of paper every time and say my dream my dream config my dream process my Jeep world's not that way.
I wish right but it don't in the world's not that way. The other thing that's interesting though. com right?
com 2013-2014. He was it was all ready. No one ever said your CI.
Yeah was always like cicd. See ICD, you couldn't say CI without saying CD CD and you definitely couldn't say CD. Yeah without preferencing it.
With CI. Yeah, right. They just went together peanut butter and jelly and see ICD.
But an interesting happened no interesting things happen over the eight years a lot of the tools. That were you know, the powerhouses the the standards eight years ago like a Jenkins for instance. Yeah.
com damn it. You know our audience knows Jenkins a little old in the tooth. If you're using Cloud native Technologies with kubernetes.
I mean those Jenkins X, I think I would change the name or whatever but it's not really the Jenkins itself. It was not really a cloud native design. You know that for good reason he came way before you're ready to jump.
I'm ready. I can tell that's an excellent point. Yeah, so Jenkins has been really the mature platform here for a long time.
And now you've got newer generations of tools things like GitHub actions things like get off CI all these different tools that are encapsulating a lot of those hard one lessons over the governors with Jenkins. They're gent two Gentry. Yeah, exactly and exactly what we're doing with the platforms that we're building.
So with our continuous service product, we really take in those Decades of experience with continues delivery and we're encapsulating them in the product. So the you as an organization or you as a devops engineer don't have to think about this stuff anymore. You can really focus on the things that you're client teams are trying to build right trying to deploy is really at the end of the day.
They don't want to think about whether you're using a hammer or screwdriver, right? They want to think about running get it done. They right.
I mean, that's that's I agree with you. When you're starting that cloud native Journey, you know, you're not ready just to change out of your tooling. So Engineers can do anything take Jenkins you write scripts.
You can do a basic deployment at kubernetes the first word done that before in past companies. That was our kind of training wheels if you would but at some point you got a scale we get back to the problems I talked about and so well one of the things we're looking at is how do you fit hand and glove in the environment people ran like Fernando talk about GitHub actions great tool once again back to extraction really abstracting way a lot of complexity for developers. Let them live in that environment, but give them a world-class deployment experience.
That's really what we're trying to do. something Alan's secret to life I didn't find this out. Yeah, it's not that profane Butner profoundly you are from New York after yeah.
Yeah, you're right, but no, seriously. I I didn't discover the size about 45 like that. It is about using the right tool for the job because using the wrong tool for the job.
You may brute force it. Yeah, eventually get that square peg rounded but you're gonna Bang Your Head on a lot of walls till he get you use the right tool things go easier. And and so to me and today's environments Cloud native.
You know, I'm not lift and shift but you know updating existing infrastructure having a tool designed for the mission. It's critical. Yeah, it's it's a must critical right?
We otherwise you just gonna make yourself a lot of work. And at the end of the day it may or may not really work where you wanted to yeah. And by the way, there's a lot of great technology available.
A lot of it's here. Like I said a lot of the book. Oh, yeah is about deployment Cloud native deployment, which is great.
It is it's all about that. You know, the other thing is so we went through this whole kind of I call it, you know, the shift left syndrums security testing. Yeah moving CD in to get.
Yep, right so you could get Ops and all of this stuff. But we we need a little focus on shift right too. How do I take the Lessons Learned whether it's Canary or future Flags?
Yeah, they be testing. Let's get that and put you know, make this kind of circular Circle or virtue kind of thing where I'm taking that and read the right today's tools. We need need to incorporate that kind of thing.
Right? I agree. The thing that I would say, I don't know if disagreement is developers shouldn't have to think about that though.
It should as you said move left into that development Zone where those capabilities are just there for them. Those are the best practices that they're platform teams their devop teams provide them as this beautiful experience. Yep, but they definitely have to move farther up in that flow.
Right? We don't want is we don't have want them to have to learn that right that's back to abstraction. Well, so I would say that that's a major thing to we we deal with Is the going to an existing team and say hey, let's change your CD tool.
Yeah, right. That sounds great. Yeah.
Well wait, let me clear the decks here for the next two months. I'll talk to you in January exactly. How do you deal with that when you you know, you go into organizations that aren't?
Using Spinnaker aren't using a modern. Yeah the platform and how do how do you convince them to? Hey, man, we should yeah, let me tear it up and have a good examples.
First of all, we don't we don't try to convince them. It's like I said, they've got those Investments for a reason and they're they're bolted in as you said every one of our customers just about I'm exaggerating a little uses Jenkins. There's something interest DLC trying to get them to rip that out full Sarah.
So it's how do you Leverage What infrastructure you already have that once again fit that into a world-class deployment scenario. So I'll do you Spinnaker as an example Spinnaker can do a lot more than just deployment. It can do some delivery aspects.
It could do some orchestration, but if you've got capabilities to do that, they're working for you now. You can weave that into that environment and just take advantage of the deployment capability same thing with our SAS solution over time as you evolve right? We're going to help you on a journey to get next gen and those capabilities but the discussions never about what you're going to take out.
It's gonna be how you can extend that. So maybe take that thread and pull it and to add on to that. I mean really what we try and do when we talk with our customers is is encourage them to crawl walk and run right?
You're not going to go from Day Zero start deploying 100 times a day, right? That's never gonna happen for an organization. That's just starting down that Journey.
So really what we try and do is partner with these customers and make sure that they understand this is the journey that you're gonna go on and this is how our products help you get to that point. Right? So day one is maybe just gonna be taking that script that you are already running on your Jenkins machine or Heaven forbade your local laptop, right and moving that into either continues to deployment as a service or continue, right and either way, right?
That's the first step and then just build on top of that and get more and successfully more. Made it until you get to the point where you can do those deployments. Once you're at that point, you can then take that and start thinking about well, what does it mean for my service to be highly available?
What kind of strategies do I need to implement? And those are all things that we help you and guide you through both through the product and the coaching that we provide. Very cool, you know, we're doing a we do it every year virtual event called devops experience.
It's coming up November 16th this year and we try to kind of highlight. Well, what's kind of the New Frontiers? What's what's the new things?
So this year we call it devops everywhere distributed devops. Yeah devops at the edge and Beyond devops of things iot and stuff. I got to imagine you guys are running into this because that that's where that's where.
The action lives today. Yep, right. It's not your side that Cloud Core anymore.
It's it's everywhere where a software software is eating the world already and wherever software goes devops goes with it. And see I C D is an intimate part of that, right? What do you guys what are you seeing on that end?
Like the nontraditional? Yeah, I'd say two-fold one is you've seen compute Cycles right centralized decentralized. Clouds here to stay because it's very good anywhere but to your point computes got to move where the data originates in a lot of cases and a lot of that you think about the iot trend right?
A lot of the devices that you have the edge of networks, very low latency devices that have to operate in real time. You can't wait for information to come down from the cloud. So you're gonna have to be able to prosecute workloads at the edge.
So from a deployment standpoint for folks that are building Cloud native, you know, they're the world has been everything to the cloud now. It's got to be about how do you deploy to multiple points in that topology? I think one of the things you're seeing and this is kind of my past life.
I used to be CEO at Win River. So okay, you know your question that is those people trying to abstract a lot of that embedded software higher level and start to virtualize. It's they can use cloud-native practices and thank you.
They can update it. It's part of the whole thing. Exactly.
So to your points. Yeah CD is gonna have to evolve where your targets are going to be different. So we talk kids your Is down there, right?
It's gonna be a different service. So we're gonna have to look at things like that over time and I see that as a big Trend too. These are so what's Armory doing around that I don't need to put you down the spot.
But hey, man, you're the engineer. Yeah. Well, we're really excited about what we're building or what we're gonna be building over the next year really where we're gonna be focusing is on bringing a lot, you know in You sign in 2019 everything that you saw at the at the conference was how do I run kubernetes now everything that you're seeing here a couple years later is what do I run?
On top of kubernetes? That's the same thing that we're doing. We want to make continuous deployment melt into the background and let engineers get back to what they're doing and what they do best.
So we're really excited to to make a lot of the tools easier and make them more approachable for engineers that are focused on that data science application or they're focus on that iot application right anything where they're a domain expert we want to give them the tools to get back to their work and be productive. I think he's in there. I'm a broken record but it's that multi-service or multi-target.
So your point you're gonna have different services at different layers and that compute biology. They shouldn't have to worry about that use the same strategies you talked about the system should have the knowledge to be able to do that to plan it for them. That's gonna be really key.
Absolutely guys. We're probably over time. It's okay want to get more information on Armory.
io. Correct. AR m o r y dot IO, right fantastic.
It's easier than his last name. There's none of those ours people in from New York have problems. It's the brother.
Hey, but anyway, hey Fernandez. Thank you very much. Thanks for coming on Tech stroke TV.
io here on techstruck TV. We're live in Detroit. We'll be back in just a minute with our next guest.
Thanks. This is texturing TV. All right.
Hey everyone. We're back. We're back in Detroit live on the show floor.
I hope you've been watching our day two coverage. Of course Mitchell Ashley our CTO and principal analyst has been doing some of our interviews today. Lessening the load on me.
I appreciate it. But I'm back here for this one and I'm happy to introduce you to a soft Cohen a sofas with a company called permit. io.
And we are gonna find out about them right now Airsoft. How are you? Hi, I'm great to be here great for to have you here.
So it's off. Well before we even get into permit. Let's hear a little bit about your story.
How do you come here? So my background is in cyber security. I used to be in the idea of intelligence forces Shmoney my time if anyone knows what it is 8200 and from there, I worked at a few cool companies in the industry.
I was a software engineer at Microsoft. I worked on the Xbox product. After that.
I was one of the first engineers in a company called Clarity in cyber security and finally I was a software engineer at Facebook where I did developer tools for engineers within the company. Very good. Yeah.
No now I'm I'm the co-founder of permit good for you. Yeah, so I've got 25 years in cyber. Pretty familiar with cyber.
We didn't call it cyber. Yeah, we called it security. Yeah, but anyway.
talk to me about Permit, what does it do? Yeah, so permit is actually the only full stock permission solution in the market. So first of all, we need to understand what why permissions are such a big problem so companies when they build a software products they have to do things like authentication understanding who the users are and there are plenty Solutions in the market like of zero in octane being identity, but after they understand who the user is so your Ln what are you allowed to do within my app what features can you access?
What resources can you touch what database objects whatever and in order to build that it's a big it's a big challenge. So you have to model your system developers need to understand what role-based access control is how to do audit logs. There's a lot of challenges here.
So what for me is trying to do is basically give you an SDK an API that you can use to just do it within hours. Instead of months. Okay just have it ready plug into your app and you have access control you have permissions.
You have everything actually. Yeah. So look, you know the big change.
I I've seen big changes during my career, you know, and originally when I was in security it was it was very much the perimeter. molten Castle, you know around the thing and You know, it was about Ingress and egress into the land. Yeah with the Advent of cloud cloud native and you know.
Distributed networks distributed applications. I am identity and access management has become. the Holy Grail right because that's how we control who has access to what in the clouds so forth and You know, it was a real problem.
It is frankly. It is a real problem. No problem, but it was a bigger problem.
Early on in Cloud. We've come up with a lot of You know, there's now Cloud directories and the the whole concept of zero trust. Yeah, right.
I'm not giving you access to anything because before was you had access to nothing or everything now, it's you don't need access to everything and you don't need access to everything every time at all times. So it's become much more sophisticated definitely, but from what you're saying. Permit allows you all of these things and more a very fine granularity.
Yeah, but almost like you said it once and then it's portable into different. Infrastructure, I'm on Google today. I'm on AWS.
I'm on Microsoft whatever. Yeah, and I could move it so that the thing is permit can be used for infrastructure permissions. So Primitives like I am that you can actually embed within your application within your writing in the apps.
Yeah, you can just plug it in but typically you would use it for end user access and not for infrastructure access. You can use it for infrastructure access. But our main goal is to make it easier for applications because for that you have nothing so you you do have today.
I am solutions for infra and you can configure I am through stuff like terraform and polymy and whatever and whatnot and for applications you have nothing so permitt is really and you application. Yeah and you think in the market that you didn't have before yeah, so give me an idea of what is the What's the end user user experience like with permit? Yeah, so first there's the developer that starts implementing permit.
So he gets apis and sdks and he can integrate into his application and we give him a low code policy editor that he can use to create a policy that says these are the users that allow this and these are the user of that. So for example, role-based access control, it can create roles and permissions and whatnot the end user and that's actually the special thing about permit can get and bearable access components. There are meant for him for end user.
So if a company is a client of permit, they can embed and user experiences within their front end so they don't have to build that as well. So think about user management screen think about API Key Management think about impersonation features share sheets everything you need to delegate access to your end users and let them control them that themself and not bug you for that. That's what we're trying to do.
All right, I get it. That's a beautiful thing. So how is this offer?
You know, it's not a hosted service or anything? Yeah, how's it offered? That's it sold.
So that's a good question. So for me is a SAS solution that manages policy agents on your end. So okay.
Yeah the way it works. There's a lot of company in the in the markets that give you an API and say okay now ping my cloud every time you need to enforce access and say is this allowed or not? This is not good for your app for a few reasons first latency.
So even if they reduce the latency within their Network to one millisecond, it's still their Network latency. You are not in their Cloud so add to that and it cripples your up and the second reason is resiliency. What if they're cloudy is down.
What if AWS itself is down. And they cannot control your app. Your app is crippled.
So what we do we give you an edge container that you put in your network that is controlled from the central cloud and can completely work offline and is independent of the central Cloud. So we just download updates every time there is a change. Yeah, but we we are not going to whole thing is completely dependent.
Yeah working. Yeah the container so it's essentially a microservice within your app in your yeah that we give you the code and we manage it for you, but it's completely independent. Yeah, beautiful and and How do you price it?
Yeah, it's a good question. So first of all permit is a free up to 1,000 users that you are enforcing access on every month. Okay, but we actually look at usage based tears where the amount of users you enforce access to reflecting the price.
So 2000 users. If you have them, that's great. If you have 1 million users you get a different value from us, so it costs more and that's how it works.
Excellent, and I love it. It's permit that IO yes for me that I owe. Okay, Cloud agnostic really doesn't lives within the app itself.
Yeah. Beautiful. Yeah.
Yeah because that it's it's a different thing that authentication people are mixing them up, but fourth indication you can live in the Gateway if a company like off zero which I love by the way, it's a great company of zero is down you're good because most of your users have a Json web token and a session and they will continue accessing the app and they will recover in a few minutes and you'll be fine. But if if you don't do authorization authorization or permissions within your app locally if somebody else a service is down, your entire application is crippled. So it's a different ball game.
Very big thing. It's it's a big thing. It's a huge difference.
Yeah, because the traditional Not just authentication. But yeah, the traditional model has been you go out. Whether it's a Sandbox or something, but you're dependent having it back.
Here is is a great thing. Yeah, um It's interesting. How are you finding the show?
Oh, I love the show. We are seeing great engagement here at cubecon. So at the booth people are coming.
I see questions. We tell them about the product. We show them the new features we ask how are they solving permissions and access control?
What is looks like in their organization. They're great conversations Happening Here. I also saw great engagement in security cons.
I had a talk at securitycon about opal or open source offering sure and people were really interested. Oh, so I I do have this control playing for policy agents that is open source, and I can use and people really engage and we're really curious how this can solve their problems if they're building on their own. So there is a solution for that as well.
So want to make clear is permit using oppa. so under under the hood permit uses policy agents and specifically Opa open policy agent as well and you can actually plug into that with your git and you can have pull requests that affect policy and you can review them and everything but we will support more policy agents in the future because we want to everything that the community uses we want to support because we don't want to force and use case on you want to be part of the solution. So it's important to support more policies.
Yeah, actually a soft. That's a great that was a great description. So it is permit that IO yeah check it out.
I think it's it sounds fantastic good new way to think about, you know application access here. We're gonna take a break. We'll be back in a moment.
com covers all aspects of cybersecurity including data security deaf secops Cloud Security application security network security security threats and more. com to learn more. com home of security bloggers Network Hey everyone.
Happy Thursday Cody J Brown here with some programs happening next week at techstrong Learning. We're starting our first program Monday at 1pm Eastern with a round table discussion on digital transformation. Led by our very own Mike bazard.
We'll have devops experts joining us to break down the essentials for bringing digital transformation the scales from small business to the Enterprise level, we'll cover what steps should be taken to increase the speed and reliability of your systems and how to provide up-to-date application experiences. Following at 3pm Eastern. We have Security Experts from threat X and cyberway us to present their 2023 economic forecasts and how organizations should consider resources in the instance of a downturn.
They'll highlight security Trends to keep an eye on as we move into the new year and how to co-manage both risk and cost. Join us on Security Boulevard for winter is coming 2023 security predictions and strategies to weather the storm. Now join us back Tuesday morning at 11AM Eastern for our final insights Forum of 2022 brought to you by Sumo logic and AWS.
We've got a stacked panel discussion on devops Trends predictions and New Year's resolutions this year in review will touch on the devops Innovations and challenges the driving factors behind devops and what will drive devops moving forward into the new year. com/webinars and be sure to look in the on-demand section. Have a great Friday and a better weekend everyone.
previously on engineering the change the program that was amazing. My career is completely changed from barely being able to you know, hold down a job to now being sought after by some of the biggest tech companies in the world. Boca code has billed me up if you grant me the scholarship.
like I said I will share my knowledge. people with women or immigrants dreamed of having an opportunity to show the world. You know how great you know, I can be I feel that anything I do I do my best in so what wherever I end up I'm going to do the best I can to make sure I'm making a positive impact.
So this scholarship would definitely assist me in changing the trajectory of my life. I'm really excited to tell Carly about winning. So fun to to Really embark on her careers and software engineer.
All right, probably we got the whole camera crew with. All right. Come on in guys are coming in Harley.
So your name good hurry up. Yes, so we're making this treasonation of 10,000 dollars today. Hope you get some puppies disco radiant.
This is sure what You don't know we're here. Hey, man, how are you? I want to present you with this we We had a tough time.
We couldn't pick up the finally. You guys are all great years, so you're right. Thank you so much.
This is a very awesome opportunity and I look forward to Starting from the best. Awesome. Thank you to be a great engineer man.
Thank you so much, Donald. You know, this was our this was my father's strongest class of people we had who applied for the scholarship. We were able to get it down to three finalists, but then in meeting with the judges we couldn't Couldn't pick a winner.
So what we decided to do is just pick all three finalists this winners. And and so we want to make this kind of contribution to your life. And we're gonna reward Stephanie Sanchez is one of our three spring 2022 winners of the engineering the change scholarship.
Stephanie congratulations Hey everyone. I'm Alan shiml CEO of tech strong group. We are a tech Media company based here in Boca Raton, Florida, and we have been for eight years.
I've been a resident of Boca Raton for 20 years now, and it's always been one of my Hopes aspirations is that South Florida would become a tech cup so we opened this program. It's called engineering the change. To underserved communities communities including women people of color but any underserved community in the tech space right when I look back and we have some of the past winners here with us and I look at the difference.
It's made in the community in their lives. Something to be really proud of so, you know, one of the things that Boca code really takes is Partnerships with companies like Tech strong and other local companies because we need them to you know to help support the school and we need them to you know to hire and interview our students as well. I'm gonna introduce some of our past winners and just have them briefly talk a little bit about your how their life has gone since taking this class.
When I received a scholarship, I had a lot of mixed emotions. I was a scared but excited for this new chapter on I had worked in the tech industry, but I never been in an engineering. Role, you know the people that Boca code Todd who I affectionately called coach because I kind of think of him as the coach in a game.
They guiding guide me step by step the whole process. Um, when I graduated from the cohort, I had over 10 offers from tier two and tier one tech companies and I had my my pick which was the first time in my life. I really had to make a choice where it was completely my decision the scholarship changed my life really from zero to a hundred as I said before.
I was in a state that I was really lost in terms of my career. I had a neuroscience degree from FAU but I couldn't get a job once I got this scholarship and I did the ten weeks at Boca code. A completely changed my life to better because now I have found actually my passion which is not just Tech but being able to help women.
Get into this field within the scholarship. It was once in a lifetime opportunity to change my career. The program at Boca Court was amazing.
I started a lot of fundamentals of software engineering and I approved myself that I'm capable of being successful developer that at that time I couldn't even imagine how I would need this job in three months when the war hit my homeland Ukraine and this salary of software developer gave me opportunity to help Ukrainian people in this hard time. So this year We wound up with three finalists for the scholarship and we brought them into our panel of judges. And each of these finalists were interviewed.
And then the judges got together and we had a picture sword. We thought we tried to pick just one and we really couldn't pick just one and they were three outstanding candidates. And so what we've decided is to give all three of them scholarships.
first person Is Carly doorless? Thank you. Thank you.
Thank you. Thank you for the opportunity. So I'll hold the check for you.
I will do my best to be successful and to help other women in other people. Our next winner of the engineering to change scholarship for 2022. Is the gentleman named Donald Vizio and Donald will tell you his story Donald?
Come on up? First of all, I want to think take strong Todd for introducing me to the scholarship. And you know, this is an amazing opportunity coming from Haiti and I hope with this opportunity that text strong and tired introduced me to I hope to like, you know, introduce it to others just like myself and get back to my community and show them that you know, Software engineering is cool.
It's not just for nerds. I started winner. For this year's engineering the change scholarship is Stephanie Sanchez.
First of all, thank you both for this opportunity and congratulations to my fellow recipients. I know we're gonna make a significant change in the world. I come from a background of Social Work.
And so I hope to be able to continue to put the people aspect in technology as we help others around us. I'm so grateful to be able to be a part of this. Yeah.
Thank you. here Hello friends and welcome to the lab a monthly show where we look at the latest and greatest developments in software development devops and the cloud I'm your host Brendan O'Leary and coming today from a seasonally cool Annapolis, Maryland on the east coast of the United States. And for those of you don't know me.
I'm a Staff developer Evangelista gitlab. Which means that I get to talk to amazing folks throughout the software engineering space about what it means to get code shipped to production. 6 releases out and brings Cutting Edge new capabilities to get Labs devsecops platform.
We have exciting new product updates that are going to help developers and other folks collaborate and deliver software more securely. 6 updates and also discuss gitlab's latest enhancements to security and governance and the solutions around that and I have with me here today get my director of product management Hillary Benson in front of the program who will join us later in the show to discuss some exciting new security features. 6 update.
First we introduced get abuse rate limiting. This is really helpful feature that notifies administrators want a user downloads or clones more than a specified number of repositories in a group or subgroup within a given time frame and you can also automatically ban users who exceed that rate limit so that those users won't be able to access, you know, the the group or it's non-public subgroups. Now, of course that won't affect unrelated groups to that but it will help you kind of curb if someone's trying to download a lot of data from from your group and these bands are permanent by default but a group of administrator can unban and affected user if it was kind of an erroneous band and they were doing that for some legitimate purpose.
Also have new group and subgroup level scan result policies. So now you can manage those scan result policies at the group level or at the subgroup level and these policies then automatically flow down and applied all the projects inside of a group which makes it a lot easier to kind of enforce those policies uniformly for a large organization that might have a large number of projects or groups within gitlab. And so to get started just in your group or subgroup if you're the owner of it, you can link the associated security policy on the security compliance policies page.
To kind of go along with that comes a scan execution policy support for dependency scanning. So you can now require dependency scanning to run on, you know, a regular schedule or as part of the Project's cicd pipelines independent of what is inside of the gitlab ciml. This will allow security teams teams to manage those scan requirements separately.
And universally without allowing developers to then, you know forget or change those configurations. It's also very easy to get started by creating a scan execution policy under security and compliance again and in the policies page. One that is near and dear to my hardest support for special characters in ci/cd variables.
So previously it was very difficult to use, you know, like the dollar sign character and available variable because that normally signifies the start of another, you know environmental variable. And so gitlab would interpret it and try to expand it. But in in this release, we added an expand keyword which will allow you to say, you know, this is a raw variable that we don't want expanded it it has, you know a dollar sign in it and this raw variable can contain, you know, any special characters and isn't you know that we don't try to expand it more passing that on to the runner.
We also have an increase in support in the rules exist configuration for ci/cd variables. So once you get to more complex, you know gitlab CI configuration. It can be very difficult to kind of maintain and scale that at a large scale.
But by adding support for ci/cd variables within the rules exists keyword, you can now use variables for things like paths or file names and that allows you to easily have a single source of Truth by storing, you know, those frequently used variables somewhere and then ensure consistent Behavior across all of your pipelines and make that configuration a lot easier to manage. So that's really exciting update. And then finally really big update and maybe the large one.
It's hard to pick a favorite. But as a dashed API analyzer for on-demand dashed API scans, so Now we can use this Dash API analyzer for any on-demand dashed API scan and in previous version the analyzer used in these on-demand scans was the Legacy version of our Das to analyzer but our internal benchmarking shows that our - API analyzer finds more vulnerabilities. Has a lower false positive rate than our Legacy analyzer.
So we're really excited to bring this to the on demand scans. It also introduces new functionalities such as graphql scans support for authentication tokens that might expire scans using a collection from Postman or har files. So this is really, you know, a fantastic update and while we're you know switching with the switch to the dashed API analyzer some of that functionality is already available in the on-demand site profile in addition to using an open API specification inside profile to define the API test you can now also use a postman collection or hard file to make sure that your test gets, you know, all of the API coverage that you expect and and manage that a lot easier.
And also added basic authentication as another option for on-demand API scans, you know previously we were using token based only and authorized in the authorization header, but now you can use basic off as well. And next up will be work on adding graphql support to those on-demand API scans. And so look for a lot more improvements in the next few releases as we incorporate more of this Advanced functionality of the dashed API analyzer into the on-demand task ends.
6 fantastic improvements both to managing complex CI CD pipelines as well. As you know, this huge step forward with dashed Dynamic application scanning. 6 and read about all of the Fantastic improvements and you've course go to the GitHub blog and look for the blog post that has every one of the improvements and changes listed right there.
And now I'm really excited to dive into gitlabs newly announced, you know, security and governance features, but not under the Hillary Benson who has previously joined the lab as a guest a few times and has a lot to tell us about this new product announcement Hillary. Welcome back. Thanks for having me Brandon.
I'm happy to be back. Yeah, always glad to have you on. Now hurry, could you tell our listeners a little bit about you know security and governance?
What is it? And why does it matter and and how's gitlab looking at this the space? Yeah, of course.
Um, so inherently there's usually quite a lot of complexity involved and making sure that you have the right approach the right processes and the right Tooling in place to build secure software that can continuously meet requirements both for your organizations internal security policies as well as any regulatory requirements that you might need to comply with. So The concepts of security and governance within gitlab are all about reducing that complexity. So we're very laser focused on enabling our users with a platform that's outfitted to help you implement a comprehensive devsecops program that not only lets you enable or lets you find and fix security issues early in the development process, but also provide the native capabilities to help you manage your Global Security risk with built-in security policies and compliance Frameworks and system of checks across the entire development lifecycle to ensure that you're your software supply chain is as secure as possible.
So our recent product announcement highlights number of features, most most of which are are available now in the product today that can provide, you know, Concrete Solutions for users in each of those areas. Yeah, that's that's really exciting. And and I I know I've been looking at this announcement.
There's a lot of different exciting updates that are part of it. But you know, what are some of the specific changes or updates and and what are you most excited about when it comes to you know this kind of broad category? Yeah, there's really a lot of great stuff that's available today.
So I think from from our most recent announcement that features, you know, broadleaf fall into three buckets. There's software supply chain security finding and fixing vulnerabilities and compliance. So in the first bucket software supply chain security, I think often the first thing that comes to mind for most people when they think of supply chain security is managing dependencies and building that basic, you know software bill of materials.
So earlier this year we made it easier for gitlab users to generate and Export software bill of until materials or s-bomb for their projects using native data from gitlab. And so as we continue to evolve our s-bomb capabilities, we're looking to provide users with a way to leverage third-party tools that they might be using to do the same thing. And I think another big aspect of supply chain security is in, you know, being able to prove the authenticity of any software artifacts that you're building.
So today get lab Runner can produce a salsa to compliant attestation for any artifacts that it produces and then going forward we'll look to have the runner automatically generate those attestations for every build. So it's a real seamless process. So those are sort of the big things going on in this pie change security bucket.
We have a lot of other stuff going on there as well. But these are the kind of highlights. In that second category of finding and fixing vulnerabilities, we've delivered a number of really important improvements recently.
There's really too many high to highlight individually, but generally speaking we've been very focused on reducing exposure to false positives improving our rule sets streamlining user experience. So there's a lot going on there. There's one feature.
I want to highlight specifically earlier this year. We introduced what we're calling Integrated Security Training into our developer workflow a very common problem organizations face is actually enabling their development teams to take action to resolve security findings. There's a number of challenges that are sort of baked into that.
But part of the challenge comes down to very pointed security education for developers. So the idea behind Integrated Security Training is to provide developers with the information that they need to understand the risk behind of vulnerability. What causes it and how to fix it at exactly the moment that it's most relevant which is when they've actually introduced some bit of insecure code into an MRI that they're working on.
So this pulls security education that is often kind of high level and sort of esoteric for folks and makes it very actionable and relevant for developers by putting it in the context of their day-to-day work. And then finally the last bucket of updates I want to touch on are around our compliance offerings. So this is another major area of ongoing Focus for us and there's really a laundry list of features to touch on here from streaming audit events to you know, enabling folks to require two person approvals in merge requests based on certain criteria the ability to set specific password requirements for your users.
We also recently completed our fips 140-2 compliance effort. So there's been a lot going on here and then going forward we're very focused on making it easier to manage compliance at scale. So you see a lot of that coming.
So for example, we have some work coming up on customizable roles and permissions. That'll make it easier to scope who has access to what So that's quite a lot that we've had going on. But those are those are the major highlights.
Yeah. No, that's a lot and and you know, it's a large area security compliance and it's one where I think I'm really excited to see us taking all these, you know, big steps forward and kind of looking at the full breath of you know, security and compliance and that security education you touched on is really key. I know back when I was trying to develop software for the federal government, you know, you have a lot of times where you get to the end of a cycle and have all of these, you know security findings and it's like none of the context is there right?
And so putting that in context really enables developers to learn and make a smarter to assessment of you know, maybe something is a false positive or maybe we haven't thought through how Something's Gonna work having that happen. When you're in that context of the merge request that's making the changes. It's just so critical, you know our deaf sack up survey the sheer showed that you know developers and lots of folks throughout the deaf stuck off space or feeling more and more responsibility for security.
And so hopefully this is a way we can help enable that And then you also started with something. There's been a lot of discourse about you know in the past year and a half two years supply chain security, you know, is that discourse? What's what's driving these changes or what do you think about that when you when you look at the market?
Yeah, that's definitely a big part of it. So I think with kind of the wide scale supply chain attacks over the last couple years and you know, the additional standards that folks are working on tonight try and get a grasp on how to address those attacks. I think you know organizations are very aware of their security postures and our prioritizing that and at the same time, you know, we're seeing broader organizational ownership of security then was the case in the past, right, you know these days development operation team operations teams, or you know, owning significant pieces of the security puzzle as much as the security team is and so for most people's security is already kind of right at the center of their software development lifecycle and their product strategy and if it's not it probably should be So forget lab, I think that means making devops look more and more like devsecops every day.
Right? And so one of the one of the benefits I think of our single platform approach is that it really directly facilitates a lot of that evolution in a very natural way because it's where these different groups are already working and we're fighting that's driving a lot of value for for our users our customers and partners. And in fact in our our annual the secopsurvey this year we found that you know, as you were touching on actually that security was the highest priority investment area for organizations and you know nearly 57% of Security Professionals stated that their organizations have kind of already shifted security left or they plan to this year.
And so the devsecops philosophy is definitely, you know going into practice and folks are always looking for ways to make it easier. Yeah, that's interesting. You mentioned shifting left something.
We've heard a lot as well. Is that still something that you know folks that may have a devops practice or or working on there is that's shifting left still something that's key to like the bigger picture of devops. Do you think?
Definitely, I think so. Yeah 15 shifting left is a critical part of it as as organizations try to move to more of a devsecops model of developing software, you know bringing security testing earlier in the development life cycle is always going to be a critical critical part of that process. And so that's why I get lab, you know, we're continually focused on reducing the friction associated with that process and trying to make it as easy as possible to test as early as possible.
Makes sense. Well great. Well, Hillary your insights are always so appreciated.
It's been great having you on the lab again, and and we can't wait to have you back. Thanks so much Brandon. Yeah.
Thank you. com or check out our latest blogs and press releases. And thanks so much again for watching me watching today and joining us.
You can find me on the internet at O'Leary crew most places. If you have an idea for a future episode or want to discuss anything from today's episode more detail. Feel free to reach out.
Again, the lab is produced monthly. So thanks again for joining us and I'll see you next month in the lab. Happy holidays and stay safe.
This is Tech strong TV. Hi, this is Mike Rothman. I'm back with another tech strong TV interview this time.
We are pleased to welcome Michael Ferrante who is the chief marketing officer of teleport here to talk to us a little bit about a recent study that they did. Asking folks about access and and you know kind of how they're protecting access and really making sure that the right folks get to the right stuff internally, especially as things continue to get a lot more complicated as we've got, you know devops and Cloud native infrastructure and and all sorts of and multiple devices and and multiple locations and all this remote work. So, you know, it's it's a pretty complicated world out there and and you know, getting folks to the right stuff continues to be a major priority for organizations, or at least it should be if it's not gosh we should but yeah, we're trying a little bit before the before we started, you know kind of the interview and I don't want to say disturbing but you know, there was some stuff that was clearly surprising from the standpoint of the data that you guys kind of came up with.
So first of all, welcome to the show welcome. Thanks for having me. I'm excited to be on Good to tell us a little bit about you know, kind of the study and and maybe you know it start with one of the top line, you know kind of results that you got there.
Yeah. Well, I think you know it is um It these security surveys are always, you know, they're always eye-opening. If you if you don't want, you know your children asleep at night.
You can either like let them watch a scary movie or read a security survey. It's it is it is kind of disturbing. In fact, one of the headlines of the report which is called the state of infrastructure access and security of folks want to look it up.
I'm just Google it on. This is the second year that we've done the report. Um, and so we we actually asked many of the same questions as we did last year so that we can see how things have changed over time.
I'm sure we'll get into that one of the questions that we asked last year and this year as well as how confident are you that X employees can no longer access your infrastructure and what I mean by infrastructure well infrastructure is it's servers. It's databases. It's internal applications like cicd systems monitoring dashboards.
I'm Cloud accounts, right your your AWS account. These are all writ large infrastructure resources. Kubernetes clusters is another one is very popular with our customers.
And so, you know, when an ex-employee leaves your organization can they no longer access that kubernetes cluster that SSH server that Windows box that that cloud account. Um, and Not surprisingly because it's very consistently with last year. But but concerningly only a quarter of respondents said that they were fully confident that X employees could no longer access company infrastructure.
Um, so, you know Michael gets fired on as Chief marketing officer at teleport and you know, Ken Michael no longer access teleport infrastructure, um, in my case the answer is yes. Hopefully, I don't get fired but we we actually have a unified way of removing all access but many companies don't on folks work from home. And so you can imagine a situation in which you know, Michael devops engineer gets laid off during the fall of his own through, you know, I'm just kind of the that seems to be what's happening these days and his companies that you know, Michael just keep your laptop.
Great. Okay. So Michael no longer works at the company.
His OCTA is the provisioned but on that laptop, Michael still has an SSH key, right that was registered on in a production environment. And so though Michael no longer works at the company. Michael is still able to access those production systems on it's the siled nature of how access is managed for infrastructure that creates a big problem.
Yeah people and you know, I think that really highlights a lot of the challenge of a lot of this new modern infrastructure that we have, you know, you kind of mentioned. Yeah, you know your deposition from OCTA. But again, if you don't lock down the Federation part of it and Salesforce of workday, right, you know, you really locked out so you just you just have a lot of different moving pieces relative to you again modern infrastructure that makes you know access and really restricting access on that front complicated.
So there are another, you know, kind of Top Line, you know conclusion that you guys found yes prepare to last year right was that, you know our changes from you to years always interesting to me. Yeah, one of the one of the things that we looked into this year was kind of the just the the increasing complexity around infrastructure and we talk about access often we think about you know, the example that I just gave it's it's Michael that's accessing and infrastructure resource, but in the data center the vast majority of communication between various systems. Is what we call machine communication machine the machine it's not, you know a developer logging into a system.
It's it's a microservice that I've written or a, you know, a cicd pipeline that that I've deployed that is speaking on to other resources on and because of supply chain attacks and and various security vulnerabilities. That's actually a huge problem. And we ask people you know, how many how many machines infrastructure resources Etc.
You typically have in your environment compared to people on in machines out number humans a hundred to one in the average organization and I think folks are not thinking about access policy. For their services that are being written the way that they're thinking about it for people now clearly when only 25% of organizations are fully confident and ex employees can no longer access infrastructure. We have some ways to go when it comes to managing policy for humans, but I don't even think we're there yet when it comes to the policy that's attached to these machine users.
And I can tell you we're not right. I can tell you we're not because you know again I've spent you know more time than I care to admit in the trenches of you know, kind of cloud type stuff and and it's incredibly complicated, right so so locking down a lot of those resources. It's not just oh, hey, you know kind of This Server gets access these, you know specific resources, right?
You have to really think about it from an entitlement standpoint and and again not just who can access it right? But what can it do right? What can it what can that specific resource do within the environment a little bit more grammatically, correct on that front?
Yeah. I spent some time as this DMO too. So so, you know kind of the words I try to get the words as precise as I can on a given time, but you again and we start thinking about you know, kind of how do we lock down?
A lot of the apis that are being used to access a lot of these services and you talk about cloud and Cloud accounts is really kind of a new version of this infrastructure that we have. Well everything we can do, you know and one of these cloud councils Can be accessed via apis, right API keys. So so how we you know kind of doing all that so not surprising at all to me that again.
We're we're pretty crappy at locking down the users but we're just awful at you know, kind of a lot of the resources because we don't think about it that way right, you know kind of the IM team within any specific Enterprise tends to focus on provisioning the users and federating their identities to where it is. They need to be they don't think about you know, kind of what components are within these specific Tech Stacks that you know, kind of comprise a lot of new modern applications now go off a little menu here, right but, you know, the marketing Machinery of the security industry, you know continues to strike again, right and and you know, hear a lot of these problems Michael and you know, the first thing that comes to a lot of folks mind is you know, hey, I read somewhere I saw something somebody said zero trust is the answer to that right? So we just Embrace zero trust right, you know on that front, you know, all these problems go away now.
I'm gonna try to reserve my my initial biases about that before I give you a chance, you know to react to that specific statement, but I mean, you know again a lot of folks will just kind of throw out a term, you know a marketing term when you're trying to you know deal with specific, you know, kind of very tangible issues. So so how do you kind of deal with this mismatch of you know, somebody who's been conditioned to think that you know, hey, I just buy a zero trusting and all these problems go away and the reality of those different issues that you kind of decompose in the report. Yeah.
Yeah great question. I mean it's it's interesting that you know, if you want to buy a zero trust solution, you know, you just Google it and who shows up it's all over the networking vendors. What is your zero trust zero trust as the network no longer matters.
Do you really think that your networking provider is the one who's going to bring you to the promised land of zero trust? I don't think so. And I think that's where some of the marketing message.
It just clouds it. What do we actually mean by zero trust? Teleport what we mean by zero trust is simply that you know it, you know Michael it doesn't matter that he works at teleport when he's trying to log into any system a server a database an application.
He's gonna be authenticated and authorized based on policy. That's what zero trust is every single connection gets authenticated and authorize regardless of the network the machine or human which or human that's right unified policy for every single connection. That's what zero trust is.
The problem with zero trust is I mean, I think folks get that you need what's typically called an identity aware access proxies you need to do that. I see funnel all of your traffic through a system that provides the authentication and authorization mechanism. That makes sense.
So it's like, okay. Well, how do I do that? There's some technical challenges around building your your identity native proxy on that's one of Major components of the teleport platform which is why people come to us, but you know, there are other ways to do it and we and we encourage that as well because we'd rather have a secure internet than a then a less secure internet, right the other piece though is how do you attest to Identity?
Right? So if if I'm saying this is an identity aware proxy, how is identity instantiated? We're proven rather one of the things that the survey reports on and this is like truly I believe in today 2022 truly catastrophic the vast majority of organizations are still using passwords and other secret.
Um, in other Secrets like SSH keys for instance on to authorize people to access infrastructure resources and These things can be stolen right? So if I steal your username and password, then I can log into that database and drop tables as if I were you am I you know, but because I have these credentials that are static in nature I can log in We believe that zero trust requires a move away from static credentials and to embrace identity based on phishing proof on forms of authentication such as Biometrics and multi-factor authentication. When you combine what we call a secret list approach with a true zero trust identity native access proxy magic starts to happen because the all of the sudden the happy path is the secure path.
I'm an engineer I come in in the morning. I you know open my MacBook Pro and I you know, I tap my finger now, it knows that it's Michael there's proof or presence there's proof of identity. I have access policy that defines what Michael should be able to access in every time I try to go to a server a database an application.
My identity is being on is being verified. Um, it's it's it becomes seamless another marketing term, right it becomes transparent, but there's a complete audit log of it. On and I don't have to continue to log into all of these different servers using using passwords and keys.
I can simply use my identity. So let's talk a little bit about coverage right because you know, when when you map out a vision like that, it's like that sounds great. How do I go and do that?
And then you realize oh I have about 200 different, you know Legacy applications that I have to deal with right. I've got, you know a whole mess of sass, you know kind of platforms and application to deal with some of which I don't even know about right because you know, we all know this business it stuff happens and they go around, you know, kind of central it because they're not, you know relevant enough. So, you know, I guess and one of the constraints and this is an excuse, right but one of the you know, kind of responses I always hear from us.
Well, you know until we get to everything we're really get to nothing and there's still the weak link. So I mean, how do we kind of start to Stage out and really migrate towards this idea of seamless, you know transparent secure and and verified access to a lot of these cool resources knowing that it's going to be a bit of a journey, right but not, you know kind of wanting to continue to sacrifice Security on the stuff that you know would plug into So what's the general, you know approach and recommendation for for how we start to get there? yeah, typically the way we see with our customers is We we kind of started out as we're very engineering heavy organization on the engineers and the founders of teleport worked at large-scale cloud computing providers and kind of their their job was building the systems that we all rely on every day and they took those lessons they said, okay, how can we create a generalizable solution to big problems that we face as engineers at these at these hyperscalers and that's where teleport came from so our customers tend to be very very technical teams within organizations that are pushing the envelope for what it can provide.
So, you know, when you are running massive scale kubernetes clusters, right and your it has what's called Pam solution privilege access management solution. Everything has to go through a pound. Well, these teams are like Okay, I I hear what you're saying and I understand the implication of that you want audit you want to be able to explicitly authorize you want to be to implement zero standing privilege.
Like I get all of that but these Solutions do not do that for kubernetes. And here's a solution teleport on that allows us to Define who can access our our kubernetes clusters provides real-time audit provides zero outstanding privilege privilege escalation just in time access, you know, is this sufficient in it look at it'll be like Yeah, absolutely. And so they'll start there and then our experience for managing access to Linux and windows servers tends to be more Dev friendly than traditional Pam Solutions.
So they'll accrue those use cases and then it's database access and it's in it is application access teleport is a class of service that we're seeing a lot more of where developer experience is really the part of the core value of the platform. We provide the security here lawyers would say not guarantees. We provide the security that you would expect from a traditional security vendor, but with an experience that developers love again, so the happy path is the secure path.
And it's just it's it's a Groundswell people hear about it. And this is why this is just the you know, the the nature of Technology Innovation and you have you have a market leader and then they become stated and then people, you know start to get frustrated by and then income comes and workers in that phase right now on and so I would say look You always need a match these business priority these business expenses with business value. And because all companies now are software companies.
You really need to keep your engineers happy and productive. And so rather than trying to solve, you know, 1000 different use cases across your entire organization for potentially limited results focus on where you're spinning the most money on Talent which typically is in your engineering organization and also the highest value of business applications that you're developing. So, you know, who's gonna be building your AI system, right?
That's gonna be enable you to compete over the next decade. Well, it's probably some very highly paid Engineers writing some highly specialized micro services to manage it Focus there on and then spread out. Yeah that I think that's a good and you know, I guess my Council to most folks is don't try to boil the ocean, right, you know again whether you're starting developers and I think that's a great place to start.
I think there's a lot of pretty important information and SAS environments that you know, kind of would be another, you know, kind of decent place to you know, kind of start restricting access and and managing access along the those lines along, you know, kind of the collaboration environment that you know, kind of we see day in and and day out, you know our officers 65 and our teams and our you know, kind of slacks and a variety of those so so they're just a ton of applications that you can get going where you've got very sensitive information flowing in and out and I think it does warrant, you know taking a look at what can I do to ensure that we're not impacting and making complicated more complicated than we need to right the user experience yet. We're you know kind of ensuring that we protect that I like that concept that you know kind of when when the easy path is the secure path that tends to be You know when good things happen. So Michael really appreciate your time on the show today.
How do we get how do we get in touch with with teleport? If our folks want to you know, learn a little bit more about the survey or more about the company you want to tell us how we can get touch with you guys. com and we can happy to answer any questions you have you can you can find the survey there on you can learn more about teleport solution talk to one of our solution Architects figure out how we can help you would love to talk to folks.
Well, that's fantastic. So Michael Franti, thank you so much for your time and appearing here with us on Tech strong TV and we'll head back to the studio for our next film. Thank you, Mike.
com covers all aspects of software containers from container management data management for containers container security networking for containers to the entire container ecosystem kubernetes microservices serverless and more. com has the largest selection of container-related news featuring breaking news blog posts podcasts and more. com to learn more This is texturing TV.
Hey everyone. We're back here at the koalas QSC conference 2022. We're at the Venetian in Las Vegas.
And our next guest. I'm really happy to it's first time every interviewer interviewed him. Jonathan told Jonathan is the ciso of koalas and hey Jonathan, welcome to text John TV.
Yeah. Thanks for having me excited to be here. Absolutely.
So Jonathan you've been see so about a year over. Koalas. That's right.
If you know my share with the audience a little bit of your background sure. Yeah. I am, you know, I've been in I guess information technology and intelligence for quite a long time.
I was a lieutenant commander in the Navy did Intel work there. So there's a lot of application from like physical, you know National Intelligence to cyber security from there. I was with the state of Colorado is the ciso and worked in the security department for 12 years spend a good run at Microsoft where I ran the Global incident response team, so 300 incidents around the globe, you know visited 18 countries with with teams of reverse malware reverse Engineers incident responders infrastructure Specialists.
A lot of ransomware attacks that we would go and and help large Enterprises recover from and then I've landed at qualis as as cisa. This is my actual second stance as see so it quality so I had a brief stint about six years ago. funny as I told you I was in the security space a long time, but security company, I co-founded called still secure which based out of Boulder and we had state of Colorado as a customer back then at the time.
It's going back 20 2005 to 2007 time frame. Yeah, they were winning a lot of awards there because they really stated the state of Colorado had a great. Yeah, but we called it infosec not yet, right.
Yeah the great info sec. Department and program there. Yeah.
Yeah. I ran a program there called secure Colorado really to Centralized security ended up working a lot at the time with the gentleman named John strufert who was there with the Department of Homeland Security around the continuous Diagnostic and monitoring program, and we really wanted to take what was really what I thought of best practice at the federal level and adopts kind of our state version. And then also I mean at the time we were Maybe even before I guess all of the election kind of issues popped up.
We were very focused even back then on, you know, helping our secretary of state and our counties secure our election systems, you know before it was I guess fashionable and I I really is we're here the day after election day, right? So we didn't. Well we have in heard yet of any kind of craziness, but it you know it farther for another conversation.
Yeah, well text drug TV, but unfortunately the drop off a lot of times from the federal level. Of like vulnerability management and cyber in general to State and local sometimes can be drastic. Right?
It's very choppy state to state. But I wanted to talk to you more about going on here at the QSC, you know our audience sitting at home saying well, it sounds like a quality user conference. I know it is it is not going to say it's not But I've been going to qsc's I think since Philippe started them years and years ago.
And I've always found them a great industry event a great a great Forum to speak with peers to talk about. Relevant topics. It's not just all quality product all the time.
No interested in your take on that. Yeah, I would agree. I mean I think well it is, you know, obviously branded as a quality conference.
I mean, there's cisos here from you know, government agencies Health Care manufacturing Financial Services, you know, there's security Engineers that are actually implementing and working in different programs. And you know, if you look at the the new products that that we've introduced over the last couple of years, it's not just vulnerable management anymore. Right?
It's web app security web app pin testing. It's patching and Patch management. It's cyber asset inventory.
And so, you know, all of these the industry's been struggling with, you know for forever right since the beginning and so, you know, I think it's a lot more about the dialogue and and learning best practices from peers. And you know, how do we do this? Well, how do we move more efficiently certain extent, you know?
All constrained with budgets and the macroeconomic conditions. So there's a lot of talk about, you know Automation and how do we optimize the resources and help us focus on the most important things and I think that's where a lot of the value comes from this conference. Yep, and you know, well obviously over the last well last year was in person but it was hybrid, you know virtual end in person.
I believe the year before was virtual lonely this year. It's not virtual at all. It's all in person and one of the nice things I don't know if our audience can see because when we have it's not a big backdrop that's real right.
There are people here and they're talking to each other right and we don't get that in the virtual space. So to me, this is Plus why you want to come down meet with people and really talk some of these topics, okay? Jonathan 2022 like most years in security has had its challenges.
Yep. It asks, right we have had. We've had some duties ransomware is crazy.
Everyone talks about software supply chain, and that's bomb that's bomb this and that. For you, what are the big stories for this year around cyber? Yeah, and I I think obviously open source software has has gotten a harder look right.
We've had some vulnerabilities that have come out and it doesn't mean anyone's not using open source software. It just means we're now having to really consider. How is it supported?
How do we keep track of it? You know, it goes back to inventory but again inventory spent hard, you know for a lot of companies and I I think you know with the presidential executive order and you know s-bomb and a bill of materials is a big topic it's in it's hard to get into it, but it is a very critical aspect for our industry and for me as a Cecil of a software supply chain company, you know, there is a there's a lot of emphasis from our customers that I do have full control over my supply chain, and that's a very Allocated task and we're working very hard on it. I know a lot of my other peers are working very diligently on what does it mean to truly Implement, you know a supply chain security program and to deliver an s-bomb that people can rely on it, right that makes sense to them.
So that's been a really big topic and unfortunately like you said from the internet response standpoint, you know still eighty ninety percent of the attacks and I see your ransomware related, you know, unfortunately, it's causing a lot of pain. I'm not sure I have anything more to share. I mean, it's the same tradition.
Oh, I I don't think it's you know good. I think yeah what we're seeing out there is it's become almost just common. Meat and potatoes kind of things quickly on the issue of the open source.
I think there's certain extent open sources almost been a victim of its own success. You know, I remember and I'm sure you do too. I really say mac was so much more secure than Windows, right?
Well when Windows had 95% of the market and Mac had five percent. It wasn't as big at Target now. I don't know what it is now 75 25 or whatever Max certainly is more market share than he used to and you see attacks on Max now, maybe not.
Windows isn't what it was either. They're both I think much more secure than they were in the 90s. Yeah, really 2000.
Yeah. Um, but open source is everywhere something like I forget if it's 98 or 99% of Enterprises are using open source software within their bullying I'd be shocked. If anyone in the world of any size didn't have some component of Open Source, you know, either a small Library that's a dependency of some code, you know, some Docker instance, it was pulled down because it seemed easy to use it was, you know, put up in some repo and share it out.
And I think that's why the the challenge of securing the supply chain is so difficult, right? Yes code that's openly shared and a lot of developers share openly right and freely and and even whether they license it is open source or not. I mean, they're sharing their code and sometimes the attackers know that and they have time squatting, you know, that will trick developers into downloading the malicious about the wrong containers.
Yeah. You know what, I think that goes to fundamentally. com in 2013-2014.
And one of the trends I was seeing then was the change in the way software was built. It wasn't just an engineering and writing code from scratch right in many ways. They were assembling.
like a supply okay exactly, right, you know building an application and and so when you have that all of a sudden that software supply chain becomes a big deal. So that's certainly a huge Vector you mentioned the ransomware. you know as much as I hated and I Marvel at the Organization of the bad guys, you know, I don't know how you solve that.
Right? Right. Yeah.
I mean, I don't think we're gonna solve that like policy related or through criminal sanctions. I mean it it's just too complicated. I mean, I think you know, we're I I like applaud the people that are trying to bring you know, those actors to justice but it there's a lot of political complications and people that are Out Of Reach depending on what country they're operating from and I think what we have to do is we have to and a lot of companies are doing this now saying I'm gonna have a ransomware threat Reduction Program, right?
You know, I think if you don't Focus your energy right controls can slip and and so if we know ransomware is, you know, probably the leading risk factor for a lot of us we have to have a ransomware response program. We have to evaluate all of our controls against what ransomware would normally get in. Environment move laterally and I think we just really have to focus on it and you're starting to see a lot of programs that say listen.
I'm going to have a ransomware Reduction Program and that we're going to focus on all of the ransomware families how they get in how they spread we're gonna design controls around that and I think it just takes that level of emphasis now Enterprises can do it. I think it's much harder for a small business. Right and that's where a lot of the attacks are happening.
Yeah, and they're hitting right they make your money go. I realize you're to see so equal. It's not the product guy.
But what what you know you haven't xdr and and you know, what is quality is doing anything to help maybe the mid Market with rent somewhere. Yeah, absolutely. So, you know, we've released our new EDR products and xcr I think are the top of really helping prevent ransomware attacks executing on an end point or detecting them quickly and then on the vmdr side, which is I mean been a Mainstay, but I think the thing is now using threat intelligence, you know, we say these are the ransomware families.
These are the specific vulnerabilities that they're leveraging patch those first and foremost, right? Let's make it easier. Don't try to I mean most failures of vulnerability programs in my opinion are treating everything equal, you know, and you get 500,000 vulnerab.
And you send a report over to the IT team and they're like, oh my gosh. I hate you guys in security right like stop sending me this. When in reality like let's focus, right?
There's five vulnerabilities that if we fix those it'll reduce our risk of ransomware. So I think it's you know, helping people prioritize and so I think that's too and that's always been yeah Pig just one more area. I want to cover with you if it's okay 2020 for you Siri with two months out from the new year.
I'm sure rent as we said ransomware is not going away software supply chain. it's gonna continue being a big thing, but security is As big a priority as it's ever been and everyone I speak to. What do you think for 2023 are other areas that we maybe haven't mentioned yet that we should be looking into or be cognizant enough.
Yeah. I'll be honest with you. I don't think the industry has fully matured with the Automation and the automated responses as much as we had hoped.
You know, I think there was great promise and sore and yeah, this is gonna limit the need and you know, we won't have to hire as many people and honestly, I just don't see that that's played out for the industry. So I think we are experiencing some macroeconomic conditions. Maybe not in cyber, but there's some pressure to say, how do we do more with fewer resources?
Yeah, and usually that leads to Innovations and automation. I would I would hope and then I I think on the attack side. Well, we have the continue to tax that we have.
You know, I I am nervous about the just enormous growth of non-traditional Computing devices and and how we handle those and and I think you know, luckily we haven't seen Mendes we've had a few Colonial pipeline a few others where we've had like OT system impacts, but you know, the more that we have embedded Computing and like very physic physical oriented devices that have true life safety risk. I think there's going to be an emphasis, you know, there's gonna be some issue that's going to transpire that's going to really call attention to a need to better regulate, you know, look for some Solutions in that space. Other than what we have right now, which is unfortunately kind of isolate and let's hope nothing happens is well right as an industry.
You know, we talked about iot devices and there's gonna be 55 billion of the next couple years. It's funny. We have a virtual event next week called devops experience and one of the areas.
One of the tracks is called devops of things. Okay, because I think from a security point of view. We were in stage one of well, what the heck's out there, right?
Yeah, right that's discover. What's connected? Oh those devices.
They don't have a lot of Headroom. They can't be patch, you know, they're they're simple on off but the nature of those devices are changing as you mentioned their pacemakers rights Hearts. They're other medical devices that are implanted.
They're they're sensitive manufacturing but they're sophisticated devices. They're not the old skater on off on off switch. Yeah, exactly and and they have real software on there and they're upgradable.
Yeah, they've got to be secure too. And I I think that's a challenge. And it's not just the security industry's challenge the maker of those the right factors right now another putting a lot of work into it.
I mean listen, I applaud, you know, like the honeywells and many of these yeah corporations and well let's yeah, they're putting a lot of effort and I think that's absolutely you know, kind of the right direction, you know, and unfortunately so easy to get into software development and manufacture devices and and you know, Microsoft and AWS provide sdks right get easy for developers to create these smart devices. But with that ubiquitous nature, you know are you know, my concern is are we back to the point where oh my gosh, like every sea code has buffer overflows all over right? They thank goodness.
You know, we've moved to some more secure languages. Yeah garbage collection and do a better job on that. But watch out there man.
There's so much out there. So right like exactly exactly November 16th devops experience. We actually the few tracks right on that point well, and we're gonna predict in January.
Anyway. Hey, first of all, thank you, you know, the first time we've interviewed you is see so here Carlos. I hopefully it's not the last Yeah by John we do take strong TV three days a week, right we have you on here.
Thank you for talking with us. It's a great show here at QSC 2022 and good luck. Thank you.
All right time. Thank you. Hey, we're gonna take a break here in Vegas and we'll be back with QSC and just a minute just a minute.
This is Textron TV. Hey everyone. We're back here live at the Venetian for koalas's QSC 2022.
It's always one of my favorite events to do because you get to meet real security people and not just people who I'm interviewing. But even if you look behind us, there are people standing around, you know, what we miss this where we were all working from home. You can't do this for truly.
So it's nice. It's nice to be back. It's nice here security people talking.
Security let me introduce you to my next guest. I'm gonna put on my glasses so I don't mess that's this up. It's delaying Miley.
That's correct. Okay, and Delaine is with Mercury financial and Before we get into the great presentation. She's doing in her case study.
I'm gonna ask Elaine to tell us a little bit about herself and Mercury Financial. Sure. So, my name is Elaine Miley.
I'm a senior Cloud security engineer with Mercury. I've been in the security industry. I guess just a little over five years now, and I've been at Mercury for about three.
So Mercury Financial is a Fintech company, we really focused on being an inclusive fintech company. That is our goal. So we were founded in 2013 and our whole goal is about helping everyday Americans build better credit so they can have a better life.
It's fantastic and you know what in case anyone's interested website for mercury. com. We are based out of Austin, Texas.
We also have an office in Delaware as well. Beautiful. Austin's a great town.
Love it. so that's interesting and you know, what fintechs are such a Hotbed of innovation absolutely. It does great stuff coming out of here.
You mind if I ask you a couple personal questions too personal? So senior Cloud security engineer. How did you get into this?
Kind of by accident. I mean I grew up in generation that you know, we were just kind of around Tech forever. It never really was something I kind of thought I could make a career until I kind of stumbled upon it in college and found out that security was a thing, you know something that I can make a career and it was it was a way that I found that I could make a hobby into an actual profession, which was very exciting and it's it's very much worked out because you know, when you're passionate about something it just makes it easier to do your job every day and I love that.
It's such a an ever-changing industry. There's there's always something new to learn. There's always something new to discover and it's just I love it you're preaching to the course.
I've been insecurity. I'm ashamed to tell you how old I am but I've been in security about more than 25 years and like you got into it quite by accident. And they didn't have it in college when I went College.
But we did get into security one of the most common questions I get more from my kids. They're friends. So my kids but their friends they've taken security classes in college.
They're interested in a career in cyber. Where do you start? How do you you can't get that first job?
Because every first job once you have experience. Well, I have no experience, but I did take some classes. Advice for everyone out here.
How how would you get how would you get it? I it's tough. I will say I was just having a conversation with a friend about this the other day and it is hard because it's you know, there's so many jobs that I could get on a whole soapbox about this because I think it is kind of a problem with the industry of expecting too much experience from entry level folks right now, especially when so much of it is not in a formal setting, you know, they're My degree was management information systems with a focus and security but it wasn't.
You know a bachelor's in cybersecurity. That's right. There's more of those now, but it's still not super common.
And so really it's just a matter of Poking around and everything you can find something you enjoy. I mean for me it was a building a home media server on a Raspberry Pi because I was bored and it looked like a fun tool, you know, and and from that I realized I was learning more about command line stuff and from you know, then you can apply that to all different kinds of tools. And so I think it's really Just find something you're interested in and just start poking around in it, really and and just find something that you can have fun with whether that's you know, some of the websites was like hack this box or things like that that are just out there for people to use.
Yeah, and from there. I think it's a matter of playing everywhere you can and and find Find a culture that you work with that was I got lucky with that at Mercury that you know, our a lot of our hiring is as much more about can you work with our team, you know, as long as you are an intelligent individual we can teach you what you need to know, but do you work well enough with us that we can teach you that so be teachable. That's the key right there too.
No coachable. Yeah, and that that's true true and security to attack. It's true in life.
Right being coachable is is a huge thing. You know, the nice thing about working in a food Tech like like Mercury Financial is you don't have a lot of legacy. old stuff there's a lot that you know, they're kind of born in the cloud.
So it's certain degree. So you get to work not in a green field, but in a newer environment where you could take advantage of, you know, some of the Newer technologies that you have available to you. You're speaking here at USC and I want to get this right.
So I'm putting up harnessing self-service and risk prioritization to drive compliance and Remediation efficiency. So look, I founded a company that came out with a vulnerability manager in 2003. Okay.
We've been fighting this fight. Oh, yeah. Philippe corteau the founder of koalas was a contemporary of my he was fighting this fight.
We've been fighting it as an industry. right the ability not only to find a vulnerability but to patch it. The ability to automate patching I keep thinking this is the year right where we're really gonna automate it.
You know compliance kind of really came on and like maybe 2005 2007 where we started doing. Clients instead of security in many cases now it it's kind of found its equilibrium. I think but talk to me.
What do you know in your talk? What are you gonna talk about? Maybe some best practices some some good things share it with our audience.
No see yeah sure. So, well, you talk about, you know us being a fintech and so we were we were found in 2013, you know, we're just now coming up on the 10 year mark, but but even so it's weird to say that a company that's less than 10 years old could have Legacy systems. But we you know, we everyone has started like 10 years of tech is a lifetime compared to most Industries.
But even with that our entire Focus has been AWS, you know, so we're Cloud native and that has been a huge huge win for us, you know in so many ways and a lot of that is with looking at things like vulnerabilities and risk and I think you make a good point of, you know going from patching to compliance to like and how they work together. So my background I started my career as a consultant at PWC. So I have a little bit more of that kind of, you know, grc-esque mindset when looking at this and so that's kind of what I want to Really hit on that's kind of the plan with with really the talk is really looking at.
How can we take these this raw data that's coming out of koalas. How can we take the numbers on the patches that we've got and the vulnerabilities and what we're doing with that and then how do you apply a risk lens to that to really decide? Okay, you know where do I focus here who is focusing on what that's really important with the self-service part of things.
You know, we have I believe I kind of six different teams that are in qualis for different purposes on you know, most of them a daily basis and so being able to really tailor, you know, the different parts of the tool and different, you know reports and such to those different teams is huge. But then it's a matter of you've got all this data. What do you do with it and being able to context you alive it?
Partially for a you know remediation plan. So, okay. What is what is more important to me?
What is you know, what should I patch first? But then also taking that to an executive level and saying, you know, this is what our This is what our raw Tech looks like and then this is how that translates to risk and to business decisions that need to be made. So that is that that's another thing you find it security right is I for instance an RSA conference one year I once was on a panel of what metrics do we show the exact team sea level and the board level, you know, and there was someone on the On the panel who flat out said well, you got a dumb it down and that kind of funny when you think about it, right but you don't have to dumb it down.
But how do we translate security speak to business speak? And and when should we do because I'm also the opinion that sometimes security people have to learn a little business speak, right? It goes both ways.
Absolutely two-way street. So what advice do you have for people? Oh gosh.
Okay. So I think this could go into another potential soapbox of data visualization, which is another love of mine. So and part of the reason I say that is is because I think visualizing your data and visualizing things like risk or you know, like a risk scores within vulnerability is for example is Kind of an easy way to translate information if someone you know, just seeing numbers on a page.
Okay, what does that mean? But then if you can, you know visualize it in a way that makes sense, you know, like all the koalas dashboards that are offered but and and the reason I say that shout out Dr. Trip from Baylor, I took of data visualization class and he started class by saying data visualization could have changed the outcome of the Challenger explosion and here is why and that has stuck with me.
And so I I it's amazing and so I I kind of take that approach to things when I'm trying to think of how can I translate something because translating things and words from business to Tech Sometimes even if you know sometimes even the same words mean different team different things depending on which teams you're talking to but if you can display it in a way that is easy to see and easy to understand that goes such a long way. Absolutely. Yeah, you know you mentioned and look I'm not an expert on the qualis product.
But I know my way around it pretty well from being in the industry. One of the things they have with their dashboards is different views for who you are exactly within an industry. You want to be a met.
You're a manager you're direct, you know a higher you're a practitioner, you know, they give you views that are relevant to you. how do you Now, of course, it's all about how you dial in the dials, right? In your position, right?
You're at you're at that border, right? Which would the translation happening? Struggle with it.
Is it something you kind of kind of got down at this point? I like to think I do but there's always room for improvement. And I I think it just it's something that kind of comes with practice and and understanding you're environment because it's also different kind of depending on who you're talking to.
I mean that was something I've worked within, you know, the Consulting space is you're dealing with a different clients sometimes every week and so you have to learn how to translate that. To the people that you're talking to for them to understand. I've been at Mercury long enough now it's a little easier because I know you know what our board and what our Executives can do it, you know expect so it's it's kind of a little easier to translate that and knowing their their understanding of the tech that we're you know describing but It's I don't think it's an easy task at all.
I think it's something that requires constant, you know or find men. Yeah, and then, you know your line of business you have another. Kid another constituency to please and that's auditors.
Yes, right and that's a whole whole different language talk about that a little bit. Yeah, that's audits are we're finishing up our PCI audit right now. So we are we are right in the middle of that.
I let our PCI audit for a couple years. So I'm very familiar with that realm and That's another it's another translation because it's you know, okay, you're you're taking something and showing it to Executives to explain, you know, how they can make business decisions on it. But then you have to take that same data set and show it to your auditor and explain to them.
You know, I mean, yes, of course your auditor should know the tool it should know, you know, the would you Basics yes should but you know with that you you need to still explain to them how it works within your environment. And that's another thing that we use qualis for every year is you know, it's for one hour the PCI scans, you know, that's huge for us having to you know, display that but then also, you know having the data to show will this is how we're actually using this in our vulnerability Management program actually. So look, we're not here to do a commercial necessarily for college.
But so it sounds like koalas is giving you the ability though to really pivot You know, no pivot tables. I'm staying away from that but you know to Pivot the views and and and slice the information to the audience that you need to to present to. Listen.
If you want to talk pivot tables, then we're in Excel and that's completely language so we can get there. Yeah. No.
No, it's like garlic to vampires to me. I can't do that. Then we won't go there.
But yeah, and it's you know, it's interesting. I think when I kind of first Really started getting into the industry. It was okay, you know vulnerability scanners or that just that they're just a scanner and so it's been interesting to see how yes.
Koalas, but also just the Technologies overall have kind of evolved to okay now, we're not just scanning now. 0 is continuous compliance, you know and and having an agent that's constantly keeping up with that and to things like automating patching, you know, so it's okay. We found the vulnerability we'll now what do we do with that and the fact that We're getting to a point.
We just had to talk this morning with Robert Herjavec. I'm sure I butchered that but I know who you yes, they do too. He made a point about the technology is becoming more commoditized and that it's gonna be more about context and I I think it's really true that you see that in just how many Technologies there are out there of either so much that you can automate but it's still a question of okay, but what do you do with that?
And how do you use that to improve your security posture? Absolutely, you know. a lesson I learned and it's as relevant today as it was then was just because she can do something doesn't mean you should absolutely and you know when it comes to automation, especially we really do we need to say can we yes should we?
I'm not sure. Yeah, and and you know, you got to be smart about that. But you're right, you know technology is ubiquitous.
That vulnerability scanning quite frankly. I mean I come from a world where we used to have to convince people to scan once a year. Okay guys, and it was only posts like already employed infrastructure not like the idea of scanning your apps before you do unheard of but you know, so we've come so so long but we still struggle with the Automation and look I started a I started devops not coming about eight years ago.
And that was one of the reasons, you know, I felt it would be great for security. But I also knew that devops brought this whole idea of continuous integration continues to delivery continuous everything and security had to get with that program. Absolutely.
We're gonna keep up with because things move too fast. You can't you can't have points in Time stuff. It just doesn't work.
Well the automation gets tough too because it's you don't want to break anything. You don't want to break this process. Absolutely and I think it's been nice to see and I kind of an approach we tend to take Things is okay if I can automate.
The actual work, but I am going to choose when to push that automation. So there still has to be kind of a person pushing the button. Much as in devops.
They had to be a person doing. Okay deploy. Now pushing a button to deploy was a lot easier than what we used to have to do.
Exactly. And that's where I think we need to be in security as well. Yeah, really?
Thank you so much for being with us today. com. Yes, the website good luck on your presentation.
We're gonna watching and keep up and you know what? Five years in the industry. She did it you can't too so probably you out there.
There's plenty of jobs and security. Thank you. Thank you.
All right. We'll be back in a moment here in Vegas. you this is texturung TV.
Hey guys. Thanks for the throw. We're here with Elizabeth Lawler whose CEO for atmap and we're gonna have a conversation about developer productivity and observability Elizabeth.
Welcome the show. Thank you very much for having me my Developer productivity has been an issue as long as anybody can remember but it seems like as of late. There's a lot more focus on it from your perspective.
What's driving that conversation? Well, you know, I think that this is a natural progression now that I think companies have finally gotten their arms around what they're trying to do with delivery, right? So if you think about the evolution of devops over the last decade A lot of focus has been on, you know, really the last the delivery of software into modern it infrastructure.
And so if you look at the theory of constraints, right and you say okay, what are we doing? Well, we can build our application we can test it. Essentially we can release it into protection really quickly high performance organizations can do this minutes.
Where's the new constraint and really it's around? What do we build? How do we build it and unleashing the creativity of the developer?
And I think that's really where it's shifting that all of that attention to the new constraint. That's the furthest left. It's the code editor.
In to that point, it seems like a lot of investments in observability to help drive that are in the cicd platform and at the you know, we're kind of leaning it a little bit left, but we're not providing the developer themselves with much Insight. So do we need to strike a balance between what the developer can observe and what the rest of the devops engineers can observe and how do we get there? Well, I think if you actually look at the types of performance and security issues, which are now becoming more prevalent and production environments.
They actually stem remove causes that are in code design. So if you look at for example at the oauth top 10 or the most recent leading cve they're designing nature, they're things that you can only see when the codes running but they stem from code quality issues so such as inversion of authentication and authorization for example as a bad a bad design pattern for for security. And so it's really I think it's really interesting how you know that being able to see runtime is not actually part of a typical's developer developer experience when you write code right?
It's like writing the novel and expecting the directors kind of the movie to come out the other side and be perfect. And so, you know, I think by bringing some of that information about code Behavior runtime performance Dynamic security analysis into the developers workflow where they're working. Side the code editor we can unleash a lot of creativity which is sucking developer, you know time away into hunting down issues across the later stage sdlc products that you just described earlier.
How smart can all this get because a lot of times the developer even when presented with something doesn't always know exactly what they're looking at and they may not even know what questions to ask. So how do we kind of surface that in a way that is you know, as some people say the idiot taxes as low as possible. I think that's really great point.
So right like it's giant amounts of information from from logging and tracing that you get to sift through to try and figure out things that how things are working by scoping information literally to the line of code. You can bring the kind of you know, we like to think about it kind of the Google Map problem, right? You don't want to map of every street and every city around the world.
You just want an app from here to the next destination which might be a seven eleven. So you really want to have just the information that's relevant to the code that's in progress the code that's being worked on and have all that observability scope down in a really nice way and link to those lines of code with you know, interactive dependency maps and Trace views and sequence diagrams and things that people can interact with and look at in the scope and localized way and I think that's really how the developer experience for observability is a shift from what you think about as typically like the It experience for absorbability which needs to be very broad spectrum and nature. And we do this across teams that developers because one of the things that we've encountered for example with security is everybody might scan their code for vulnerabilities, but then by the time you load everything up in the bill all kinds of issues start to emerge.
So how do we do that in a way that everybody can understand what their peace interacts with somebody else's peace and create some sort of suboptimal experience and can we get in front of that? Finally my code and you don't let yours then our code is not linted. Right?
So so it's definitely important to have basically, you know, the first line of defense is to fix errors when their cheapest to fix right when they're being introduced or when they're being written. The second line of defense is to catch it at the CIA, you know at the CIA level the when you're when you're basically running everyone's changes in in a common staging environment or in test. So, you know at map itself Works in both environments one of the backstop, but then you know shifted the furthest left because actually, you know, that's where people are most inclined to make the changes.
It's the pricing how many things that are flagged actually make it into into production based on we'll say like waited decision-making right, you know, you could have things that have been flagged with security issues or flag this potential, you know potential issues. You might want to have adjust but they'll still make it into production if you're under a deadline so you really want to catch it. Moment of creation and to your point There's an opportunity to use that data in the generative way to make more suggestions about how one might code better and I think that's really just improving the curve right bringing everybody up to having a natural method of coding that's more secure and more performant and helps them understand languages and Frameworks.
They work better. Hmm. Oh helpful can again in this regard.
Will it eventually surface and say hey we've noticed that this is the fifth time you've made the same mistake and perhaps you might want to take this training class to get product Yet it would probably pay extra for that. She makes suggestions about things like common, you know. Common mistakes people make when writing queries where they Loop or common mistakes people make in accidentally logging out secret information.
And where the information is actually, you know where the secret is created and where the information is logged out is two different places in the code. So, you know, you are it's a I'm not does servant strongly educational purpose around how your code is or how your code base? It's organized and how it works when it runs and how you should think about working within it.
So, I think that's really a really important key part of that. All right, and how automatic can all this get I mean eventually a lot of developers I know are kind of like well, thanks for telling me but could you just fix that warming? So can I close the loop on this and what might that look like?
Yeah, I think that's definitely well. We obviously provide pop-ups and show you exactly the line of code. You need to chase change but we haven't yet started writing for you.
I think that's where the power of this data can go though, which is if you look at things like co-pilot, right? They it's generative. It will tell you how to write, you know parts of code very well that's until you how to assemble it together and it doesn't tell you how to you know, how maybe your code will be interacting with it with it with an endpoint service for an API or necessarily the database.
There's missing piece of that data that that could be used to make those types of code recommendations help people stitch together the components of their application better. And that's something that we're certainly thinking about how we could use it to be more generative. And who leads to charge and kind of putting this kind of tool in place.
Is it the developer or is it the devops engineer who got a vested interest in maybe fixing all this stuff and they show up at the end of the holiday year and say, hey look what I got you. Yes, I think that's a great point. We actually have multimedal distribution of users everyone from new devs to Architects.
They're often leading a charge around. Um, maybe they're working on institutionalizing some of their own design philosophy through app map and the ability to enforce even Custom Custom Design patterns in in the coding environment as well as Security Professionals who are looking to communicate better with the recipients of their of their recommendation. And sorry who are looking to try and figure out that last mile connection between an existing observability tool or platform.
They might have like data dog or dinotrace and making the code recommendation to the actual development team for fix and so we kind of Play nicely with all of those tools. So I really think that any one of those individuals can could bring us in. I think we're most often adopted by developers because they're in the IDE and we distribute through the vs code and generates marketplaces.
So they're usually the first ones to see it. Alright, once you're best advice to folks then what's that one thing you see development teams doing over and over again. That just makes you shake your head and go can't believe we're still having this conversation.
oh my I would say that the the ability to preview how your software will behave for being changes. It is one of the most common things people spend their time around chasing down rabbit holes is unexpected behavioral changes. If you could if you run that app in advance of of even committing your coach will PR you can pre-play or certain types of breaking changes through behavioral differing and I think that is an incredibly powerful tool to be able to optimize your code before you submit it to the rest of the process of code quality like peer review and Central testing and stitching.
All right, cool. Hey Elizabeth. Thanks for being on the show and sharing your insects.
Thank you so much for having me. I appreciate it. All right guys back to you in the studio.
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Tom Gillis who is senior vice president and general manager for with networking and advanced Security Group at VMware Tom. How you doing? I'm good.
How are you Michael? Well, you guys just launched this whole project North Star initiative. So I was hoping you would kind of explain what that's all about given the fact that we are seeing more convergence between networking and security these days but everybody's gonna North Star where's your email?
Yeah sure thing. So really our North Star is pointed around, you know, stitching together the multi-cloud universe and so what we see more and more is customers are saying I've got, you know, very large private cloud data centers with lots of workloads, but I've got, you know increasing number or public Cloud workloads. Maybe I've got it on two different public clouds, maybe even three public clouds.
And I want to pull this together in a single coherent system. And so project Northstar is designed to do exactly that project Northstar is the policy and the security analytics hub. That allows us to create one Global setup policies and then we can still customize them in localize them.
And you know your East Coast Data Center your West Coast Data Center. Your instances is running on Amazon or instances running out on say Google and pull all this together with a single pane of glass. So yeah, it's a pretty big it's a big project for us and it's one of the customers have been waiting for for quite a while actually.
How is the relationship between networking and security people evolving these days because it seems like to me at least that more of the security operational functions are moving towards the networking guys, and the security guys are focusing more on policy, but maybe it's not that neat. Well, let me put it this way. The the big Trend that we see in security is is you know with the principles of zero trust you have to assume the attackers are already in they've already penetrated your network.
So now the name of the game is how do you stop them from moving laterally throughout your infrastructure and stealing all your data or worse, you know sort of creating a ransomware situation that lateral movement is very difficult to detect if you don't have you know tight integration and cooperation between the network team and security team. So so, you know used to be you could deploy firewall and a firewall would live in one place at the perimeter. Okay?
And so the networking guys all they had to do is was provide routes that would allow you to to plug the firewall in and the security team could be completely separate and independent. But when we look at the distributed nature of these attacks, we really need to be able to put security not just that the perimeter you want to put security everywhere. So integrating security and networking together into one functional team, that's the future and this is even more relevant when we talk about public clouds where you don't have a physical box to put it in right?
So this is all distributed software that we need to work together to make sure that we're deploying in a sensible way. Do you think that the rise of multi-cloud computing therefore is forcing a lot of people are revisit these issues because we're not adding a lot of more security people heck we can't even find enough networking people. So do we need to find a smarter way of going about doing all this?
Yeah. So I think that's a tale, you know and a dog and I think that the the dog here is the, you know, sort of shocking and steady increase in both frequency and severity of ransomware. I mean ransomware is a giant giant problem.
The reason is giant giant problems. It's a really good business because most people pay their handsome so you can expect that Trend to only continue, you know, we expect ransomware to just get worse not better. And so so, you know as we think about how we're going to stop this ransomware, it comes back to identifying lateral movement of attackers, you know, the idea that you're going to keep all attackers out is naive.
So assume that they're already in your network. How do you stop them from moving around and that's where this distributed security becomes so important once you have deployed a distributed distributed security architecture you want that to work on every cloud so multi-cloud is kind of the second phase of this if you will, right? Like let's let's think about an advanced security solution.
And then let's put that everywhere our workloads are which is private Cloud public Cloud, you know Etc. We've been talking about micro segmentation for a while. Now.
What's the challenges that organizations have when it comes to implementing that and adopting it because you would think it might be a little more widespread than it is at the moment. So clearly there's work to be done. Yeah.
So microsegmentation is something we came up with, you know, almost almost a decade ago, like like eight years ago and micro segmentation stops what I call the obvious problem, right? So it's obvious that a web server in a development environment should not connect to a database and a production environment ever under any circumstances. So don't allow that to happen.
So microsegmentation is about shutting down application Pathways that shouldn't exist. And the challenge with it is is you would ask the question. Well what application Pathways should exist and you know one of things that's interesting is if you ask a developer tell me what ports and protocols you need to have open for this application.
You know what the answer is. All of them right because developers oftentimes don't know that's not the way they're thinking and frankly. It's not the way we want them to think we want developers to focus on business logic not worrying about what ports and Protocols are being used.
So we've we've spent you know, the better part of a decade building Ai and ml capability that can analyze your existing Brownfield applications and then automatically generate firewall rules to do the micro segmentation. So the tools are in place to do segmentation and do it and do it at scale and we do this for the largest customers in the world. Right?
So we're kind of way way past the point of credibility on this the so the good news is for those that haven't deployed micro segmentation. We can help you do that fast. That's a good news.
Here's the bad news. The bad news is that attackers are assuming you have segmentation in place. And so what we're seeing happen is there's a significant rise and what the security guys call living off the land attacks where an attacker will either steal a credential or they will compromise a protocol to move through legitimate application Pathways that micro segmentation won't stop so microsegmentation is a foundational capability.
If you don't have it in place, you're making it super easy for the attackers to do an Equifax type of Clean Sweep of your data center, which would not something anybody wants, but but it's not enough because we have to be able to stop these in line attacks that are that are using legitimate pathways. You talked about developers. What's your sense of the current state of devsecops?
We've been trying to get better at application security and sometimes I feel like application security winds up being a jump ball because the networking people think the app people are doing in the app people think the security people are doing it and then nobody does anything. So yeah. What do we need to do to kind of bridge that divide?
Yeah. Well, what's interesting is, you know, it's clearly the future, you know, you know the world we're moving into especially in a kubernetes space world. Security doesn't come in a box anymore security is going to be code.
Right and as is infrastructure as is the connectivity those Pathways that I was talking about. All of that stuff is going to be described in software. Redetermined pre-calculated and then when when you know, it's runtime you push a button and say go so that means no tickets to open no waiting a month for the fireball team to update those firewall rules.
Remember that no waiting, you know a month to get a DNS entry or VIP from a load balancer, right? You just push a button and and it works. That's the cloud operating model.
But what's interesting to me is that I think your point many customers say yeah, that's what we want. That's what I want. But but they struggled to get there and it's not the tools aren't in place, but they struggle with is what I call the layer 8 problem, right which is which is humans people.
And and probably the number one offender or the biggest challenge you have to overcome is the firewall team. Because fire walls have been working incredibly. Well like they're these are very very well engineered very high performance.
I used to build firewalls right these things run and run and run. They don't make mistakes. And so so we've been relying on these things for decades.
But the fundamental architecture and design of a traditional firewall, even if you pull it out of the box and make it a VM, it's a scale up system that's designed to run at a perimeter. It's not designed to run everywhere. And as I said like the name of the game these days you got to look everywhere.
You can't just look at the perimeter and hope you're gonna catch all the all the ransomware. So so changes in the wind changes in the air changes hard smart, you know administrator smart Architects are getting in front of this because this is clearly the future but we as an industry got a ways to go. Yes.
Are we seeing a flattening of cybersecurity in the sense that we used to have a lot of different silos? There'd be endpoint security. There'd be the network guys that they're with the firewalls app guys and Cloud networking security folks.
And if everything becomes code, can we just flatten that so it can all just be centrally managed? Well within security you see a similar, you know kind of you're moving from let's call it centers of excellence or you could call them silos, you know, and you flip at 90 degrees and say I need one cross-functional team that's gonna look about how I make security is code for this application and that's gonna have everything to do with code Integrity on the, you know, sort of very very upfront all the way to hardening and securing the runtime. None of that stuff should be figured out after the fact none of it, right?
You should be you know, when you're building a checking in code you're scanning it looking for vulnerabilities. That's all automated likewise when you're you know, turning it up a new cluster and putting in production. You should make sure that the crypto is in place that at the you know, malware detection is in place and that you're doing Advanced API security where we're looking at how apis reviews and making sure that they're not being abused with that legitimate application pathway that ransomware would take advantage of so, yes, the the world is changing but it's all moving in this direction that it has been for a while.
Right which is is software. And policy but that does entail across functional approach. You can't do that with the center of excellence model right The Silo model.
We hear a lot about all things AI these days. What's your sense of what's real about AI is it applies to security and network management versus what's in the more fanciful side of things. Yeah.
It's funny. I just gave a talk in another form on exactly this topic. So what is the role of ai ai is essential for any security solution?
And you know, if you think about that East-West problem that I talked about This is a great example. So You know, the the imperative of looking at lateral movement is not new. This is something security has known for you know, a decade or more and I would argue this is like one of the main value propositions of a Sim.
So a Sim will look at everything. It looks all your net flow records and your sislogs and your you know, sort of, you know web blogs and kind of munches them all together and says, let's see if we can identify the lateral movement of an attacker. And most of the customers I talked to were like, you know these Sim systems.
Like if I didn't have to buy this, you know because of regulatory requirements, I wouldn't because it really really expensive and they're really really noisy and they're really really hard to use and I'm not really sure I'm getting you know the value out of it that I should be and so so and it's not that the algorithms in a Sim are bad Sims relying on Sample data. So Sam is gonna rely on Netflix will tell you server a talk to server B. So good.
That bad should I worry about that? Right? It's not enough context to know.
Is that something we need to worry about? I feel a little bit like you ever watched Game of Thrones. Mm-hmm.
So when I watch Game of Thrones, I'll get to like season 3. Someone gets killed. I'm like that good guy bad guy my happy my sad what you know like, oh, it's too complicated.
So Netflix and Sample data are the equivalent of the Game of Thrones problem and that you need to have very very high fidelity data to figure out friend from Foe. And and you know, that's really where the industry is going is is you need to be able to ingest this huge quantity of data at the packet level and at the process level and then the anomaly stick out like a sore thumb thankfully, you know sort of advances in Big Data platforms industry why they're not security specific but just tools that allow us to ingest all this data and you know and process them on platforms like snowflake. This is pretty amazing.
Right and so so, you know, the tooling is in place to go do it now. We just got to put the systems in place to make it a reality. All right.
Well keeping on that theme winter is coming. So are the bad guys getting smarter or they're more of them or is it just that you know, they say complexity is the enemy of security and we maybe everyone worst enemies. Yeah complexity is definitely the enemy of security and so as we move to multi-cloud world the attack surface gets much much bigger much broader much more non-traditional, right?
So so here's a great example API security. So people think about hey apis that I have for an application. They're generally thinking about the north south or Internet facing apis, but what about all the internal facing apis the cloud native application can be made up of thousands of micro Services thousands of little tiny containerized Snippets of code each one of which has an API.
So if you really want to understand the inner workings of an application, you've got to look at the API. The API is the new endpoint in a kubernetes world what we see it as happening is attackers are taking advantage of apis that are don't necessarily have a vulnerability. But as you weren't coded with security in mind, for example, if I wrote an API that said if you give me a name, I'll give you a credit card number that same API.
If you gave me five names, I'll give you five credit card numbers. If you give me $50,000 names, I'll give you 50,000 credit card numbers. Right so attackers can take advantage of these apis and extract huge amounts of data without actually violating the terms of the API.
And so so the the next Frontier, I really believe in the industry is to understand and Baseline the behavior of these apis and then look for normal behavior. And then we can identify these attacks even though they're not exploiting a vulnerability. They're gonna be using an API either out of sequence or in a way that should never be used and we can stop that from within.
Tom has a lot of people who are pessimistic out there when it comes to security because every day they wake up and another issue. What's your sensor? We went in and are losing this battle right now.
And you know, do we have accomplished for optimism somewhere? Yeah. I mean look, I've been doing this for decades and I got this question all the time and and the fact of the matter is, you know, especially when you look at ransomware It's never gonna go away, right because it's a good business because most people pay their Ransom.
And so so what we see is what like any other business the attackers are investing in tools to be more and more crafty to look like legitimate application traffic and do that East West movement so they can Harvest your data. So so we'll never stop them coal. But what we can do is kind of like the vaccine right we can make the severity of the attack much lower and I think one of the other really interesting areas that we're focusing on is how can we automate the recovery of the attack?
So using technology to speed up the recovery from ransomware? We just recently introduced carbon black integrated into our VMware Cloud disaster recovery. And so what this means is when we take a snapshot we scan it and we tell you is this known to be clean or not.
So in the event that that ransomware of attack does get through we're gonna go through and say, oh here's the last known verified clean snapshot and you've now defined your recovery point. And I believe like over time we can actually start to drive that recovery Point down maybe even to zero. Which would effectively be an antidote to Grant somewhere.
It's like yeah, you get Ransom, but don't worry. I restored you right back to where you were before the attack happened, you know lose any data at all. So so I think it's one of these things we're going to continue to find ways to ameliorate and minimize and attenuate the threat but never eliminate it.
Yes. All right. So inoculations may not prevent you from getting sick, but they sure as hell can't help you recover faster Tom.
Thanks for being on the show. Always a pleasure. Thanks, Michael.
All right back to you guys in the studio. Do you know you want we afford this place? I'm thinking a thousand piece kubernetes Cloud workload protection and xdr combo.
Oh, yeah. I actually don't see any prices. I would have to order off that thing.
We don't how did you get in here? Check this out? optic secret dollar menu order today and you can secure any combo of cloud and endpoint assets through the end of next year all for one dollar.
What if I want to secure 100 Mac laptops and 900 Linux servers one dollar. What if I want 500 laptops and 500 kubernetes nodes just a buck. Yep.
Mix and match to create the combo that works for you. What about customer support? Yep everything for just a buck.
We're gonna order off the uptick secret dollar menu. And seriously, how did you get in here? Seriously, seriously?
Try the Optics combo of cnap and xdr delivered in a single UI and data model just one dollar just to secure your Cloud containers and laptops through the end of next year offer ends, December 31st. Hi again, everyone. I hope you all enjoyed today's episode of tech strong TV.
We had some amazing interviews with industry professionals to give you the latest in the tech world and alongside of airing of the lab with Brendan O'Leary and Engineering the change. We had plenty of great content. We'll be back again on Monday.
So we hope to see you then. But in the meantime, thank you so much for watching and hope you have a wonderful rest of your day as always stay strong. Text strong.