Kaus Phaltankar, Caveonix | RSA Conference 2023
Kaus Phaltankar, CEO of Caveonix, joins Mitch at RSA to discuss how the company helps people manage their cloud infrastructures.
Transcript
This is texturung TV. Welcome back to rsac here in San Francisco 2023. It's great to be in person again second time in a row since 22 23 being here in person.
I think you're here last year as well. Yes. Okay, great.
Great what we have we have great people on great discussions conversation. Kausis is of course, one of them call cow spot Hangar who is a CEO with the cavionics? Yes.
Thank you. Thank you very much. Thanks to nice to be talking tom.
Yes exactly over Electronics Zoom stuff. Yes, what did tell folks a little bit about yourself until about quibianics. Thank you for first of all.
Thanks for the opportunity. So my name is Cape house fulltanker. I'm co-founder of CEO of cavionics and cavionics really focuses on providing a solution for Mid large and extra large Enterprise customers who are really looking to have their hybrid and multi-cloud environment.
Being monitored from just the visibility security posture management and compliance partial management and then ultimately governing for any risk elements. And as you know cloud is a key component of a lot of Enterprises digital transformation Journey. They can quickly test validate and roll out new products Services respond to competitive pressures and so on.
So for them to be able to do this quickly is what caveonics I love them to do is manage this posture very well because Cloud essentially exponentially increases your attack surface so hands managing that surface is very important to them. And so so that's what caveonics does and what makes this very different in in this space is is that most of our customers the one that we just describe to serve a large extra large businesses or midsize. They're still operating parts of their infrastructure on the data centers, and they're also adopting public cloud.
So it's a it's a world of hybrid cloud. and we early on recognize that and and have put a very good and equal emphasis on on-prem as well as on the public Cloud side. So anytime customers have hybrid requirements and hybrid multicloud requirements.
And they need all the three elements of visibility security compliance and and aspects of governance along with compliance. They look at cavionics. It gets very complex very quickly.
We talk about not just migrating the cloud or moving part of the workload to the cloud oftentimes. It's multi-cloud. Yes, sometimes that comes through Acquisitions and you're handed.
Here you go. Well now it's a security posture. How do we manage it?
I would imagine to the governance requirements get fairly complex because what day do you have available? What are the servers providers give you then you've got to pull that together in one-to-one coaches. Yes analysis.
There's where we are here. So we're compliant. Yeah, absolutely, especially in the public Cloud space.
It's a shared risk model right public Cloud providers will tell you that anything you spend up in our environment through our service offering is secure. Now how you set up and configure it is your requirements of the shared risk model? And so a lot of times customers who are adopting cloud.
Tend to think of it as it operates in a very similar way as their on-prem infrastructure. So simple example when customers say well, you know, why do I need to protect the the storage because on-prem a VM or a physical machine the story is attached to it. So I'm good to go if it's secure on the VM.
It's secure on the storage. Well when you still started dealing with object storage in a public Cloud environments. By default a lot of them can spin up as open public access.
And today the Bots are looking for such spin-ups. And can compromise that spin up in under 30 seconds. So the information can leak out of that that public open storage bucket.
Hence part of the shared risk model you have to be very careful as an Enterprise is that you just don't take the default configuration. You you look at it and set it up correctly. So a lot of those challenges are there as you adopt cloud and of course.
Each one of the public Cloud providers continue to offer new sets of services, right just literally two years ago. There are roughly about a hundred Cloud native Services. Let's say on Amazon AWS.
Oh the days of only yeah, and and now it's about 300 services and then if you are multi-cloud, That's a lot more services out there. And you know the the expertise and managing and configuring them correctly just doesn't exist in the marketplace. Nobody can actually catch up to the rate of these new Services being deployed.
All the developers would love to start using the latest and the greatest it's usually where it's injected into the organization, right the developers exactly. Exactly. And so, you know, our job in the market is is to take on that hard work of making sure everything that's spun up is right.
It's been a directly configured correctly. Including the latest and the graded Services offering that are out there and and ideally not only detect that in the runtime environment, but ideally protected even before it gets deployed. So there's this huge emphasis on shift left strategy.
So shift left of security. But also shift left of compliance because compliance drives a lot of the spending as well in addition to the security aspects because again it have made large and extra large businesses need to be compliant with local National and Global regulations multiple of those multiples exactly. Right?
Exactly. Right? Well tell us a little bit here.
You have some interesting news some great things that are coming out caveats. Yes. Thank you.
So at RSA, we are announcing availability of a fifth generation product, which is fine art over release off cavionics now in the world where everything is SAS only One of the things that a differentiates us from a lot of Justice SAS only providers or cloud-native only providers is we have a lot of customers in finance sector Health Care sector utility sector public sector in the federal side or state side of it where everybody being in that hybrid state that we talked about earlier. A lot of their security requirements or their compliance requirements or just the level of comfort they have in going all in on the public Cloud just doesn't exist. So for a lot of those reasons, they would love to be able to deploy a solution like ours for cloud security posture management or workload protection or for the compliance and governance on Prem or combination thereof.
And so this is makes us very unique in the market. What also goes back to that earlier point that we were talking about is that the native expertise on new Services just is catching up and it will always playing a catch-up game. That means that if there are issues they need to be addressed and identified.
First of all, very quickly and address very quickly. So there is and the example we talked about where a public bucket can be compromised on a 30 seconds. That means there's no time to triage this create a ticket send it to the appropriate infrastructure team.
The game is over in 30 seconds. So Auto remediation of these capabilities in a non-destructive way meaning you don't have to destroy that storage bucket, but you can isolate that storage bucket until somebody takes action on. You can quarantine and endpoint or isolate and endpoint so that somebody can take an action in correcting that configuration setup that needs to be corrected.
So those kinds of action prevent the Bad actors exploiting these capabilities and it needs to be done very quickly. So these ability to do auto remediate auto protect is becoming very very important. And these are the kind of elements that we are providing in find out.
Oh, especially, you know, we have endured with this new era of AI so to speak with the chat GP timing how far into all of our conversations. Yes, I come. There you go.
You might be the quickest. But yeah, which is good. Yeah, but again AI from AI is a very broad term, right?
So how do you get to this automation of understanding either anomalies or behavior modeling and everything that need to be done? Has also evolved over a period of time. So for example, you know, if you talk about AI, you know two years ago or even a year ago.
It was all about machine learning machine learning machine learning. In our case, you know a year ago. We were talking about machine learning.
We don't talk about machine learning anymore because to us machine learning is a it's not very scalable. Its ability to build the models. The training models takes a very very long time and a lot of data and a lot of data, right?
So at this point in time, we have shifted completely over the last year and a half now almost to a neural net deep learning technology for AI. Okay mainly because it's unsupervised and when we are dealing with a global scale of public clouds with multiple zones that currently exists nationally and globally for large customers National customers as well as Global customers. The ability for us to ingest all that information and then be able to run the anomaly detection and or modeling steps and all on a supervised model is just not possible.
It's not doable. It's not scalable. Whereas deep learning allows us to take an unsupervised approach and yet be able to feed it all kinds of data and and leverage some of the elements of the public cloud like gpus even on-prem.
By the way. There are lots of GPU elements Dell announced recently for your servers is a major GPU chips and you know modules that means now you can process information very quickly be able to build the models very quickly identify anomalies very quickly. And so our ar-driven component does the behavioral modeling training in matter of minutes with deep learning technology versus machine learning, which you take hours.
Secondly, it's unsupervised. That means it can operate on its own at scale versus machine learning coordinate. So that's the new AR component.
It's a we call it neural Insight Technology so neural because it's based on neural Net Technology inside is because what's the output of this exercise the output of this exercise is we are building the insights. For people who are operating these environments. Either from a security perspective Cloud infrastructure perspective or the application specific compliance and governance perspective giving them insights to where they should focus.
First second third. So prioritization becomes important and secondly, the minimal resources can create a Maximum Impact. And that's why the neural inside technology is a key underpinning of this fight auto offer.
A lot of very exciting things in five. Oh, yeah, one things that I picked up on earlier. It's kind of a subtle thing.
But you know, we used to live in a world of Set it and then it's all hands and feet right and their Data Center and the sort of managed Services were someone else to be your hands. Yes. It's a management.
Now. We live in a world where things are automated that creation of that S3 bucket is animated. Yeah, maybe the script had an area yes or could have been a person but that infrastructure the stack that we're running our applications on the environment.
The applications themselves are under constant change. Yes there there. They rarely stay in a static State themself, right?
So you've got to have an environment where it's not only where it has the context through things like machine learning and neural networks, but also automation to respond to it. Yes, because many things may happen all at the same time or a successive series of times. Yes with your neuron that analogy.
Yes, but it takes that kind of technology and not every organization is equipped to set that up create that know how to operating right? Yes, so, you know hands and feet or eyes and eyes of hands or whatever it might be from the old days. Yeah, we are so far from that.
Yes, it is and mostly also it's a it's a scaling issue right as you say, you know, only constant is a change. But that constant the change is happening not just in your local infrastructure. It could be in the global infrastructure right and depending on size of the organizations and so on.
and then you know, I always give this analogy that you know in especially in my new start again with Cloud native Services containerized deployments one click you can spin up like 10,000 containers another click you can spin down 5,000 containers, right and a lot of these could be having a being spun up based on as needed basis because they last a city that you build in your application now allows you to spin things up in as the demand grows you can spend more resources and as it goes down you spin down the resources So like you just said it's a highly Dynamic and very agile environment and automation has to be the key to deal with that at scale. So, you know, we basically had today according to many different analysts that are very familiar and I talked a lot of these larger Enterprise customers. We have one of the largest.
single Enterprise deployment in the industry with million plus Cloud Assets in the management and single Enterprise. So this Enterprise of Fortune 100 company that operates 68 countries and so on. And major footprints on all the public Cloud on-prem 37 data centers as well.
And so to do this at scale. And to prove it at scale was a challenge which we met over the last year and now it's in full production in the challenge is not just meeting the challenge of course super important, but it's the trust that comes with that. Yes.
I mean there now there they know you can operate at that scale. 0 and what's happening. I assume on the website or maybe visiting author here at RSA.
Yes. 0. But also we have done a significant improvements on the user interface and user experience and you know also from a sustainability perspective.
Now, we have introduced a dark mode within our dashboard because it does consume less amount of electricity creates a less carbon footprint. So we are being also making a small contribution from a sustainability perspective fantastic very much. Thank you very much coming by absolutely.
Thanks for conversation. Telling us the great news. I look forward to more good stuff.
Thank you very much. Have your next team. Yes.
Thanks another great conversation. Thanks for hanging in there with us. And we have another one coming up.
Great conversation, just like we did with gouts. Thanks for joining us. Thank you.





