Securing the Cloud-Native Edge
Techstrong Group’s Alan Shimel sits down with Veeam’s Kevin Keller and Matt Slotten live from SUSECON in Prague to explore how the rules of data protection are entirely changing in the agentic era. The trio discusses how Veeam Kasten has pivoted far beyond simple Kubernetes backup to become a critical AI resilience engine, explicitly engineered to secure massive RAG databases, LLM models, and the delicate software supply chain against highly sophisticated, AI-driven threats. Highlighting their deep integration with SUSE Rancher, Keller and Slotten explain why deploying robust, cloud-native security controls is the only way to protect mission-critical environments as organizations navigate the complex great virtualization migration.
Transcript
Hey everyone, we're back here at SUSECON in Prague. It's been a great couple of days. Let me introduce you to our next guest.
I've got on my far right, Kevin Keller, and next to me on my closer right, Matt Slotten. Mm-hmm. Yes.
We got it. We're here, yeah. Both of these guys are with Veeam.
I used to say Kasten by Veeam, but it's Veeam Kastan. Yeah. They're long-time SUSE partners, and we're going to get into it.
But first, let's find out who these guys are. Kevin? Yeah.
Go ahead. So, yeah. So Kevin Keller, I run our business development for our partner organization at Veeam's.
I'm the director of business development, manage the relationship for SUSE and our cloud native partnerships. Very cool. Matt?
Yep. Matt Slotten, principal solutions architect, cloud native partnerships. So I work very closely with my buddy Kevin over here, and then work, of course, closely with our partners like SUSE.
All right. Before we get into the SUSE partnership, and we will, I think we got to lay the foundation of, well, not everyone out here knows Veeam, not everyone out here knows Kastan. I think they know cloud native.
I hope, otherwise, what are they watching this for? Yeah. But how would you describe Kastan and Veeam to the audience?
For sure, yeah. So Kastan itself is a cloud native data protection solution. Veeam, as an organization, is a little bit larger than that.
We are the AI data and trust company. That's our new tagline. But essentially, if you need something protected, whether it's from backup, disaster recovery, data security, posture management, Veeam's kind of that one-stop shop for all of- Very cool ...
those different data and technologies. And obviously you're a SUSE partner, but in terms of go to market, what kind of companies do you partner with? So SUSE is one of our top partners.
So obviously in the cloud native space there's a lot of players. Mm-hmm. But certainly storage providers as well.
Yeah. So I know, for this conference, we work closely with Lenovo and SUSE for- Yes ... reference architecture.
We also have an AI resilience reference architecture with Lenovo, but also partners like Portworx and Dell and- Sure ... some of the other sponsors here we definitely work with as well. Yeah, I would say pretty much a lot of the others from a partnership standpoint in the ecosystem here that are represented at SUSECON are also key partners of Veeam as well.
So it really helps us as far as developing a go to market with SUSE, because we can really triangulate and really provide the best of all of our offerings from a company standpoint and a vendor standpoint to our customers. So that's what the real benefit is. Very cool.
No robot? The robot dog? Were you referring to our robot dogs?
Yeah. Well, you had the dog here yesterday, but at RSA you guys had a real robot. Yeah.
I heard about that. RSAC, yeah. Yeah.
He was about this tall. Green. He was outside.
Yeah. He was white and black. Oh, okay.
All right. He was outside Moscone shaking hands, taking pictures, and smiling. Yeah, no robot today, unfortunately.
Yeah, we had to leave him at home. It's just us. Yeah.
So we'll have to do. We're not replaced yet. No.
Well, look. You ain't the only one. So, I got that we're partnered with SUSE, and I got what it is you do, but let's peel that back another layer and really get into it, right?
Because the cloud native means a lot of things to a lot of people. At some point it was all Kubernetes, but it's not. Yeah.
Now there's observability, there is a lot of cloud native security. There's 200 and something projects in the CNCF. Yeah.
How exactly, where do you work in this whole stack? Because it is the de facto compute stack. Yeah.
Right? Even with AI and everything now, it's becoming the AI stack. Yes, exactly.
Inference, anyway. Well, you've set me up perfectly, Alan. So yeah, I think to dive in a little bit more, we obviously as a cloud native data protection solution, we inherently can protect things that are on Kubernetes.
But to your point, cloud native, it's now more than just containers. So Kastan, we've been around for about what, I guess, almost eight years now. Coming on it.
Yeah. Maybe aging us a little bit, but we'll say it. Yeah.
I like to... Got to aim higher, so. But yeah, so essentially, we've been protecting these Kubernetes workloads for a long time, developing a lot more maturity in terms of what we can do in terms of data protection, logical backup and whatnot.
And then really in the last year and a half, or really two years, we've somewhat pivoted to now include things like SUSE virtualization, virtual machines in a cloud native environment, because that's very different than kind of traditional Veeam backup. Yeah. Just because the architecture is fundamentally different.
Yeah. But then to your point as well, a lot of these AI applications are inherently built. You can see it at SUSE at the keynote today, are built on SUSE Rancher.
Yeah. So quickly we are becoming also an AI data resilience organization as well. Yeah.
So protecting things like models, even training data, RAG databases. Yeah, I think it's really to focus not only on the application and protecting the data in the application, but really get into that data layer to get deep into that and understanding how we can catalog and identify all the metadata that's associated with the data that's related to all these agentic models and these agentic... To use as far as with its enterprises and really trying to drive a business within the new AI world.
But this is where Veeam now, within our portfolio, are really bringing this all together to have this one control plane to really manage this environment across the applications, the data, and to drive the agentic enterprise. Yeah, look, I get it, right? It isIt's more and more about the stack.
You mentioned AI, and the AI stack is not going to be exactly the cloud-native stack. It may have Kubernetes, it may have containers, there may be a lot of elements, but it's going to bring more to that table, too. Absolutely.
And so that's more of a challenge. When we talk about partnering with SUSE, though, you mentioned virtualization, right? But I don't know how many people are just trading one hypervisor for another.
Mm-hmm. Right? Because when we make that swap, if you want to call it that, people are saying, "Well, wait.
I don't want to just do that. " Yep. Right?
And now, maybe as long as I'm swapping hypervisors, maybe now's a good time to move to microservices. Maybe now's a good time to move to real cloud native. Right?
Absolutely. And I might as well do it. So I went from just hypervisor on bare metal to OS, to Kubernetes kind of stack.
That's a job. Yes. It's not something to be done lightly, even with AI.
Right. And then if we add AI to it, well, what does AI bring to this now, too? Exactly.
So how has that changed your world? Yeah. I guess in a number of ways.
From a product perspective, we had our start focusing on containers, and then there was the fun exercise of KubeVirt. I say fun because there wasn't really a forcing function for a lot of organizations to adopt it. Obviously, that forcing function did come into effect a couple of years ago with a large acquisition.
So the good news is, again, because we can already protect Kubernetes resources, it wasn't a huge lift for us to then also support SUSE Virtualization. What's underneath it. And the good news about that as well is that we can help organizations as they transition.
So, yes, they might need to hop maybe from a other backup vendor, or even Veeam's kind of more legacy product to Kasten. But once they're on the Kasten product, we can protect initially VMs, but as they modernize those into containers, we can inherently use the same tooling to protect that as well. Yeah, and I think, you look at how Veeam's been around for a couple of decades.
Yes. And basically grew up on the back of VMware, right? Yeah.
So we understand that market. We understand that environment. We have lots of customers, obviously, that use Veeam and are protecting Veeam workloads.
And so, we're definitely set in the right position to help them as they make these decisions to go to SUSE Virtualization, as an example, and we have the portfolio and the products to enable them to make that happen. And so, I think from a company standpoint, we really bring this all together, where we can protect any different type of workload the customer may have and help them with this movement and the mobility piece. Obviously, mobility is very key and important for customers in the enterprise, as we were hearing this whole conference so far.
It's about resiliency. Who's been number one in data resiliency for many decades? It's Veeam.
So we really know a lot about this space. And we just carry this over now with obviously what we can do in the cloud native space with the Veeam Kasten, and then now what we're also building across our portfolio with our AI support and data protection. Absolutely.
Here, when they use the word resiliency, they're talking about sovereignty a lot, too, though. Yep. How is that playing with you guys?
You've set us up perfectly, Alan. It plays very nicely. I think certainly SUSE and Veeam, Veeam Kasten, have a shared ethos, right?
So we support choice. We support public cloud. We're going to be in your data center.
In terms of a sovereignty and approach, though, we can fully support things like air gap. We can fully support whether you're a gov cloud or limited to a specific country or soil. We can essentially move with those requirements.
And we can also provide that assurance when it comes to government compliance, like data resilience requirements and backup requirements and whatnot. Sure. Yeah.
And so instead of having the additional securities built in, whether it's FIPS compliance, as an example, from a government standpoint. But yeah, just meeting again, all the business continuity, the regulatory, the governance, managing that data where it needs to be, whether it's within certain data centers, within certain countries. But again, and we have that mobility story, so we can also move the data as necessary too, but we can also help you control through policies of where that data needs to be and reside around to keep it protected to meet those requirements.
Absolutely. Last question. It's not anything to do here with SUSE- ...
per se, but ransomware. Oh, boy. I'm hearing conflicting news.
I've been in security about 25, 30 years. Mm-hmm. Long time security person, startups and stuff like that.
I heard ransomware was down because of solutions like Kasten by Veeam, right? Hey, no big deal. We'll just restore.
We've got a clean one that they can't get to. But again, AI seems to have upped the game in terms of making ransomware better. Better if you're a bad guy, I think, rather, right?
Yes. Worse if you're not. Harder.
Harder for us. Yeah. You're on the front line of this.
What are you seeing? Absolutely. Yeah.
So we're no stranger to Project Mythos. Yeah. So we have our submission.
We're hoping to get early access to that. As you said, AI is absolutely changing the game, right? So traditional SAST and CVE identification, while important, is quickly being outmoded by AI.
Yeah. So it's a bit of a cat and mouse game, ensuring- It always is. Yeah.
But to your point earlier, and from a ransomware perspective, we have a lot of the fundamental or foundational pieces already there. So things like immutable backup, building AI into our solutions as well to detect malicious behavior using things like entropy analysis so we can see ransomware injected. But really, I think from a Kasten side, we're really focusing on our software supply chain.
It's becoming more important now than ever. We're seeing some very sophisticated attacks on open source software. So we're definitely cognizant of it.
We're all ready, actually, as we speak, our PM and engineering team are looking specifically in preparation for Mythos and- Yeah ... preparing for that. Well- And I think even just to add to that, again, so Veeam made an acquisition the end of last year with security AI, and that, again, just ties into this story.
So it gets deeper into that data layer to really understand where the data is. It's all the governance piece, so which I was just talking about. But as we really want to control and understand how these agents are using this data and this information, this is what we can provide through a graphical representation of how this data is being managed and used, and how you can help control it to help reduce these types of incidences.
And then on top of that, we have these services to help manage if you do get attacked by an incident, to help do this resolution and incident response. So we have that from a services standpoint within the company. So it's really this holistic end-to-end offering around managing the applications, the data, having your backups, all the other security elements associated with that.
But also from a services standpoint, if you do get attacked, we can help do that remittance as well. I love it. Last thing.
Where can people go get more information about Veeam? Well, Veeam Kasten, as well as the larger Veeam. For sure.
Yeah. com, obviously at the SUSE conference. But yeah.
com. I'll do a self plug as well. It's an unofficial blog property.
I have to say that officially. dev. A lot of interactive demos, how-tos, talk about advanced AI applications and how we can protect those.
A great resource to get started there as well. Very cool. Kevin, Matt, thanks for coming on, man.
Thanks, Alan. I appreciate it. Appreciate it.
Hey, check it out. Veeam Kasten, big SUSE, long time SUSE partners here. But in the cloud native space, they're really one of the OG kind of folks there.
We'll take a break here at SUSEcon. We're going to come back with more. Stay tuned.