Exploring Security Innovations with Alex Kreilein at at QSC24
At QSC24, Alex Kreilein talks about his journey from customer to product security leader. He discusses the launch of Enterprise TruRisk Management, emphasizing a security by design approach. Key topics include vulnerability management, customer experience security, and the importance of trust in security products. Alex highlights the role of the Qualys security operations team in advocating for customer needs.
Transcript
This is Textron tv. Hey, everyone. Back right here in San Diego for Qualys security conference coverage.
It's, they're coming fast and furious right about now. People wanting to get in, I guess before lunch, but, um, my next guest is Alex Kry line. Alex, you were with us, I don't wanna say two years ago, maybe three years ago.
It was actually, we met when I was a prospective customer of VMDR before it came out. Uh, I used to be Just had to be like 2017. I was gonna say before.
Before Covid. Yeah. Yeah.
Way before covid. Yeah. So look at you now.
I know. I feel great. So what have you been doing since 2017?
I've been running a lot and, uh, you know, traveling, uh, Alsot. Don't we All? Yeah, I've, um, I've had a really, actually very much amazing stretch in part thanks to great cybersecurity products.
Uh, I was a CISO at a cloud native SaaS company for oh, about three years. We were in the emergency communications space, so stuff that's gotta work. Yep.
And, uh, then I had the opportunity to go to Microsoft and worked in the Azure platform and, uh, followed a wonderful colleague and friend, uh, who's my, my boss, Jonathan Troll. I came over to Qualys and I've been running product security here for just over two years. I love it.
Yeah. That's quite a journey, man. It's been cool.
Good for you. Thank you. Uh, when we say product security, you are responsible to make sure that the Qualys product itself is secure.
Yeah. Like from a software supply chain perspective, That's definitely one of the avenues. So like Absolutely.
My responsibility is to make sure that what we ship to the market is safe and secure and of, uh, high quality. Mm-Hmm. Um, there's a lot of people who are part of that process.
I'm a person who does that. Uh, I built the strategy and process and framework to get that done. And I did it in part using Quas products, and I did it in part, using lots of other products.
It's a complex problem. Uh, yes, it is. Um, so when you say you did it using Quas products, let, let's jump into, I know you're speaking here today about something.
Yeah, it's, we're gonna get into that. It's cool, but now you, now you've ped my curiosity. Sure, sure.
Well, one of the things that we are enthusiastic about with the release of Enterprise Truist Management, which is really like a solid aggregation and decision making framework, uh, we get to bring Qualys products like web application security for dynamic application security testing, policy compliance, uh, and you know, probably like four or five other products in our ecosystem, like infrastructure as code analysis, um, the things that developers need to build products that are secure and safe. Uh, we get to now bring that into the ETM platform, which will be dogfooding with our own teams. Sure.
Um, but the outcome that we're trying to achieve is security, but also flow. I need to give a high degree of velocity to my developers, or they won't wanna do the work that I'm asking. You just become the anchor on the, on the, yeah.
The ball and chain on this. There's, There's, there's healthy friction, then there's unhealthy friction, and too much of that turns into fire. Um, and so what we try and do through our discern design, excuse me, security by design approach is to, um, loop in technology, um, that both we build and then buy in the open market, along with process like threat modeling, architecture reviews, um, and then, uh, kind of different controls around automation to help developers get the outcome that they want.
We are on a maturity model of this. It doesn't work perfectly today like anybody else, but you start small and effectively and then you build fast. You know, I'll, I've been in security 30 years.
Yeah. Have anyone ever told me they were done? Yeah.
Yeah. I'd say they're full of beans anyway. Sure.
So you're never done. Sure. Um, that's, that's fantastic.
It's really good stuff. And, you know, in many ways this mirrors Qualys customer's own journey. Yeah, it does.
Especially for ones who, you know, today every company's a software company. We all build apps and so forth, and it's mirroring that. So, you know, that's what we're dealing with.
Alex, you're presenting here. Yeah. Let's hear about what you're presenting on.
Awesome. So a lot of the market is super focused in vulnerability management. It's obviously we're here to talk about, but there are a lot of vulnerabilities that are not easy to detect with any kind of automation.
And those vulnerabilities are about design. Um, sometimes bad and effective ineffective design principles, like two applications communicating inside of the same trust boundary with wildly different security models. Um, or sometimes they're, uh, around like the supply chain that you brought into your application.
And today that's more, you know, more prevalent than ever. Yeah. So, um, part of what I'm talking about is our decision making process for how we identify those architectural weaknesses.
Uh, work to make them specific problems for developers to work with us on addressing, give them feedback, um, and then ship improvements. The other side of that though is a customer facing feature roadmap. So it's not just about the non-functional stuff, like, Hey, use these cryptographic ciphers or these libraries, or like, adopt this policy framework or, you know, ingest it this way.
It's also about making sure that the product that we ship is safe for the customer experience. Here's what I mean by that. There's the security of the platform.
Cool. Then there's the security on the platform, the customer's use of it. So like the identity and authentication management, how we report CVEs when we make a defect or a mistake in our product.
Um, it's also things like making sure that we can kind of automagically update customer's passwords if we find them exposed in the dark web. So what this is about is the practices about delivering security for the customer's experience while using our products, not just keeping the platform safe and secure. Got it.
So, yeah, I, I had a bunch of questions here as you were going. Were just running through my mind. Um, so one, one of the things I, I wanna talk about SBOs.
Yeah. Right. Our audience is very familiar.
Totally. Quas products come with SBOs. Now, Qualys products can come with SBOs.
Quas products will come with more freely available SBOs in probably Q1 or Q2. One of the things that we're doing based off of, actually maybe let back up for a second. So, um, cisa, uh, probably about nine months ago, um, announced that they were doing a secure by design pledge.
Yes. We're one of the early companies to take that pledge because we know it's valuable to the customers and to the market. Um, it aligns with one of our goals, well actually aligns with three of our security by design goals, one of which is making it prohibitively expensive for attackers to exploit Qualys and its customers using our products.
Mm-Hmm. Software bill of materials are about obviously the supply chain and providence by which we received all of those artifacts. Um, what we are looking at doing is figuring out not just how to ship software bill of materials, but how to make the discussion about vulnerabilities more productive between the software producer and the user.
So we're looking at delivering SBOs and XPDX and cycle and dx, but also, um, having a VEX file or a vulnerability exploitability exchange file, riding along with that to tell the user if this CVE is indeed applicable or not. Right. It's not just about vulnerability, it's about exposure.
We need to help people understand if they are exposed by using a product that we built that has a defect. And so what we seek to do is build a more perfect method of communicating around that. Love It.
I love it. Um, wanted to talk about the next thing, which is, you know, this is all about risk and to a certain extent, risk is about trust. I've gotta trust when you tell me we've, this reduces my risk by 10%, 20%, I gotta trust there's a certain level of trust that's necessary for me to buy into that.
Yeah. That nowhere is that more important than in buying security products. I think that's probably Right.
Right. Recent events, not naming names CrowdStrike. Right.
And it's not their fault. It could happen. I'm Not, it happens.
It happens, but it that erodes trust. Yeah. And, and you know, and that's such an important Yeah.
Piece of it. Now, secure by design is, is made to instill trust in my customer. In your customers.
Sure. Customers in period. How do you, and without getting Cool, cool.
Too crazy, but how do you make sure we don't have a blue screen, a death incident? Yeah. So you're definitely gonna be coming to my talk at 3 45.
Okay. Uh, One of the, um, there are some real, so the problem statement that I heard you say is, how can I trust your SaaS? Right.
You built it, I bought it, I use it. I have no real ability to get visibility into it. So getting away from the first part, which is usually the identity and access management part, how do I get onto the platform?
Then the next question is, how can I get some sense of control? One of the things that we'll be releasing in Q1 or Q2 is the ability for customers to, um, lock a manifest to a specific version or to an N minus X policy, right? Mm-Hmm.
So in the CrowdStrike issue specifically, they shipped a content update, um, that led to a pretty significant technology exposure. Um, customers couldn't test for that, they just accepted the update. Right.
We think that a better approach to solving that problem is to give customers choice, allowing them the opportunity to test and evaluate deploy Before Applying it. Right. In the same way, we also believe that we should be giving customers their audit and security logs so that they can ingest that into their SIM and determine if they have an active exposure Sure.
On our product. Absolutely. And, and you know, the funny thing, uh, is that the way it used to be?
Yeah. You used to, you know, you would get your, your Microsoft patch Tuesday, no one applied the patches on Tuesday. Totally.
You know what I mean? We, we would test them. Some organizations would take a couple days, some would take a week, some would take months.
Yeah, yeah. Whatever, whatever floats, you know, whatever works for your particular risk profile. Yeah.
The, the challenge with the challenge with some of this though, is the customer is inherently accepting a different risk though, right? Yeah. When they choose to not install updates, that means that they're not getting the most current version of our detections, leaving them potentially exposed to certain, you know, risks.
Like a zero day or a, So I, I've had this conversations with Fortune 100 CIOs Yeah. And their attitude is yes, but it's about measuring risk and the risk of me being exposed to something for a few more days than I already was exposed to it. Yeah.
Versus the risk of me taking down a major portion of my network Totally. Or something. They're not equal.
I Mean, like, and I make my decision on that Between, I think I read, I'm gonna get it close, but I think I read certainly less than 10% of crowds tech's customers were exposed to the incident and it was a world event. Mm-Hmm. Right.
So obviously I think customers need to have risk informed choice making. It's their risk to accept. Right.
We also just need to make sure that they're informed about the other side of the coin when they make those choices. But yeah, I mean, people should be able to make the choices that they need. It's their business.
Someone should have told the Delta CEO that I will keep myself Quiet. Yeah, no. You know, I'm a, I'm me here, I'm allowed to say stuff like that.
You can't. Um, It's a hard business. It is.
And again, I, you know, I know George Kurtz a long time from down stuff Yeah. And, uh, that that could happen to anyone. Stuff like that happens.
But there was a time in our industry where we didn't just blindly Yeah. Apply patches and update stuff. Yeah.
We, we tested and, and Different trust models. It comes back to I'm our first customer at Qualys. My, are you the, the team?
Well, we, we are Customer zero, the qua security Team. Right. You are the customer.
Zero. We get the first ones and we have an amazing security operations team that test and evaluates all the things that we take in, um, that, that puts us in a real special place. I like to think that because of that, I have a little bit of the voice of the customer, uh, and I try and advocate for them through the work of Secure by Design.
Very cool. Alex, a pleasure seeing you, man. Thank you.
You look great. Thanks. It's good to have you here.
You too. Thank You. We don't talk about that enough.
You look great too. I talk about it all the time. What that?
Yep. Hey, we're live here in San Diego. We're gonna take, I think, a quick lunch break and we'll be back with a ton, a lot more Qualys interviews and content coming up for the rest of this afternoon.
You're watching Text On tv.