Cybersecurity Trends and Innovations with Shai Morag at AWS re:Invent 2024
Shai Morag, Tenable’s new CPO, shares insights on the company’s evolution from vulnerability management to comprehensive security solutions. The focus is on exposure management, risk assessment, and the integration of AI technologies. The discussion emphasizes the importance of a platform approach to security, aiming to reduce risks effectively and adapt to the rapidly changing cybersecurity landscape.
Transcript
This is Textron tv. Hey everyone, it's Alan Shimmel. We're back here at techron tv cover, continuing our coverage of AWS reinvent here on Tuesday.
Uh, this is the first day real day, though. They, they kicked over the keynote last night, but today's the first real day where there's a lot of stuff going on, and there was a lot of announcements this morning. It's amazing how many companies are in this ecosystem that they said there's about 60,000 people, which is, I think, in line to what it was last year.
Mm-hmm. Um, so, you know, it's reinvent and it's a good time to meet with people, though, and catch up and hear what's new, not just from AWS but from the industry. In that note, let me introduce you to Shai Moran.
Shai is with Tenable. He is newly minted as their Chief product Officer, CPO. And congratulations to you on that Shy.
But before being CPO, you had joined Tenable as a result of an acquisition or a company that you had helped co-found. Yeah. Yes.
Um, why don't we start with your background and how you co-founded that company and came to be part of Tenable, and then we'll talk about as your CPO, what you see and what, where we can expect to see from Tenable. Sure. Uh, so thank you.
First, thank you for having me. Um, so I, I've been around the cyber industry for the last 25 years. Um, I joined Tenable a little more than a year ago through the acquisition of Matic, where I was the CEO and one of the, one of the founders, aromatic was a cybersecurity cloud security startup.
Again, we are focusing on what is, what is today called Synap. Yes. Uh, which today we sell it as part of the Tenable Cloud security offering.
Um, and before that, I would say, um, uh, I'm in the cybersecurity, uh, space. I would say mostly founding startups, leading startups, and for the last, uh, four or five months, um, the CPO of Tenable. Congratulations again on that.
You know, I'm also in cybersecurity about 25, 30 years. Matter of fact, I remember when Tenable started, right? Yep.
Um, who knew back then it was NEIS, basically. Right? Right.
And that we'd be talking about things like cdap and cloud security and ai, and all of these things that are out there now. But, you know, tenable has done an amazing job of staying current with the state of technology, with the state of security, and, and making offerings that, that make sense for today's environment. Um, and today's environment, make no mistake, it's very different, right.
It, it, it, this show is kinda proof of that. Right. Um, for those maybe who aren't familiar with Tenable, 'cause we take it for granted, we're in the security, we know Tenable, and most of our audience is in security too.
But there might be people here for our EWS reinvent audience who will say, tenable. I, I've heard of 'em. I'm not sure.
Mm-hmm. How would, I mean, they have, I mean, tenable has a full breath Right. Of, of solutions.
Now, why don't you, you right. Mind shy. Sure.
Oh, you are the chief product. It is what you do. Tell us.
Sure, of course. Uh, so Tenable, as you mentioned, again, started as the one of the leaders in the vulnerability management, the leader in the vulnerability management space, been around the block for more than 20 years now. Uh, and as you, as you said, turnable, um, evolved to being a leader in the exposure management space.
Yes. Uh, and if you are thinking, what is exposure management? Uh, I would say it's everything around the pre bridge ward when you're thinking about the value proposition for our customers.
Again, for enterprises, for companies trying to assess all the risks that they have and to quantify the risk that they have in their environment, trying to understand exposures, potential exposures and weaknesses and security gaps in their environment. Environment means everything. We cover everything from, I would say, uh, the on-prem to cloud, ot, iot identities, everything.
And at the end, it's assessing the risk, prioritizing the risk, and helping our customers remediating and responding to this risk and reducing it as much as possible, again, to lower the risk of being breach or potentially being breach. Uh, and as you mentioned, the breadth of the, of the coverage of Tenable and the offering that Tenable offers today, it's much, much, much wider than just the vulnerability management. Of course, we'll still deliver in vulnerability management, and it's still very important for a lot of our customers.
Sure. But we also offer, uh, OT security and cloud security, uh, again, as part of AWS conference. We'll talk more about that.
Uh, identity exposures, web application security, and, uh, attack surface management. Everything around, uh, that is needed, again, for organization, again, to understand more their exposures in their environment. We offer today, uh, as part, of course as a standalone product, but also as part of the platform Platform.
And that really is the key. It's a platform today. Dread Intel's in there too.
Yes. 'cause I remember something with that. Um, you know, you mentioned risk a lot.
So to me, this is in many ways the security industry coming full circle mm-hmm. For a long time, like when I first got into security, security wasn't part of it. Security generally was part like of the CFO and the risk management function, and it was about risk.
And then over the years it became about compliance. It, you know, it became about it AppSec. There was no AppSec when I started, but, you know, there was an AppSec and all of these things.
But recently, I have seen many of the cybersecurity companies out here returning to talk about risk and risk management. I think part of the reason is, is that, look, the fact of the matter is, the last year or two has been hard for many of the startups. Tenable's a public company, you mean, you know, I don't follow the stock.
I'm not here touting stock. Speak to your stockbrokers, but Tenable's a public company. Your stock is public out there.
But you know, there's been layoffs in the industry. There's been hand wringing about what, what to do going forward, what's AI gonna bring. But through it all, people are saying, wait a second, it's still about risk.
Mm-hmm. And we need, risk is a language that board members speak about, that C level talk about, you go to a C level and say, we have 5,000 high severity vulnerabilities of which 4,300 are patchable. They don't, they don't care what you say.
They don't grip that. But if you tell them, you know, we have this billion dollar line of business that there's a 20% chance, you know, a risk that something catastrophic can happen, they could, the math, they know how to do. Right.
20% billion dollars, that's a big risk. And put the money towards reducing that risk as best they can. Mm-hmm.
And so this is, I think as a security person, I welcome that. Mm-hmm. Right.
I think we do need to talk about risk. The other thing is ai, you mentioned mm-hmm. Shy, you could bury your head in the sand and make believe, you know, it's gonna go away, or it's not real, or it's not gonna be as real as big as they think it is, but it's here and it's changing everything.
Mm-hmm. How are these two kind of trends manifesting themselves in what Tenable is doing and products you've released? Yes.
So I completely agree. At the end, we're seeing several trends in the industry. One is, uh, we understand today, or enterprises, executives, board members understand that at the end, a major or potential major business risk is cyber.
Again, cyber is being considered as one of the business risk that we need to manage. We need to understand, we need to quantify, we need to assess, and we need to understand at the end how we reduce it in a, I would say, risk management way. Meaning if it's something that is high risk, of course we want to invest more in order to reduce the risk.
If it's less, again, it's less, uh, potentially, uh, the risk is more on the things that are less critical to the business. Again, maybe we can manage with this risk. So at the end, cyber is one of the, one of the main businesses or potential business risk to the, to a business.
So this is one trend that we're seeing. Another trend that we're seeing in the industry is, uh, consolidation. Again, if you're thinking about it, um, of course, everyone wants to reduce, uh, to reduce the, the cost.
So it's also on consolidating and reducing the cost of ownership. Yeah. A part of that beside the consolidation is also how we can leverage ai or how we can leverage everything around the AI that we are seeing are seeing in the evolution of the AI to also get more value and reduce the cost, uh, in everything that we do.
So at the end, these are the two trends that we are seeing. If you're taking a look at what Tenable does, of course, we are focusing on exposure management, which it's the, in, in the end. It's also helping organization quantify the risk.
We also consolidating a lot of the, a lot of the, uh, solution that they have and reducing the total cost of ownership. And we today also leverage AI as part of the platform in order to help our customers leverage the platform more than, than I would say without the Ai. Sure.
Yeah. Sure. So, you know, when we look at ai, to me, it's sort of a double-edged sword.
Mm-hmm. On one hand, you as tenable, and you, if you are my security vendor, I'm looking to you to help me protect from AI aided threats mm-hmm. Attacks, because these attacks are better than ever, right.
Be because that's the nature of, this is the nature of the internet and cyber. Mm-hmm. The bad guys are very well armed.
They're very well financed. They're not dumb. They're using ai.
We need to combat that. We need to do that. Secondly, we then also need to lev, or we should be leveraging AI to make us better faster at security.
Mm-hmm. Better and faster. Again, two jobs for Tenable.
How, how, what are you doing on those? So, so I completely agree. Again, if you're thinking of security and a, and ai, again, you have both, you have security for ai, right?
How I, uh, make sure that my AI usage is more secure, and you have AI for security. I leverage more AI against to make my security solutions better. So we do both, and we invest heavily on both.
Uh, recently again, we announced that we offer AI SPM AI security poster management as part of a CNA offering with the DSPM offering that we have. So it's a full comprehensive cloud security solution. Let's dive into that.
Okay. What, What exactly do we mean by That? So, um, the Tenable Cloud security is what is called a synapse solution.
Yes. A ative application protection platform, which means that it's a full comprehensive solution that covers everything in security in your cloud. Meaning combining understanding of misconfigurations, understanding of vulnerabilities, potentially understanding of entitlements and risky entitlements and identities in your environment, understanding where you have sensitive data that you wanna protect and the critical assets that you have.
And also, as part of that, also understanding the AI resources and the AI models that you are building, and making sure that we have all the context to secure the infrastructure of the AI that you are leveraging in order, in order to build your AI applications. So if you're thinking, uh, about ISPM, it's a big, it's a part of the bigger solution of the cloud native application protection that we offer to our customers today, which gives you, as a cloud security platform all the information in one place. So you have all the context, you have better visibility, but also better prioritization because you have all the context.
And at the end, you can easily focus on the things that are more critical for your business, again, are higher risk, again, for your business, highest risk, and, uh, remediate them. So that's one of one area that we invest on. The ai, again, I would say, uh, securing the ai.
So that's one. Another announcement that we announced several months ago is what we call AI Aware. As part of our vulnerability management solution, we also offer, uh, uh, models that find AI usage in your environment and making sure that it's secure and you gives you visibility to make sure that you are also meeting your compliance needs.
Because at the end, it's also very important Sure. Is that your AI usage in your org meets your compliance needs. And, and, and, and that's a big part of that.
So that's another offer. Uh, and we'll continue to invest in security for ai, again, making your AI usage and investment in your organization more secure. So that's one area.
And the second, as we mentioned, is AI for security, of course, you, we want to leverage as much as we can the gen, uh, the gen ai, um, uh, evolution that we are seeing in a lot of, uh, a lot of great application great, uh, potential usage in order to make our security solutions better. So, of course, as part of our platform today, we also offer, uh, AI as part of that to make the platform smarter and to play, to make the usage of the platform easier. So that's a big part of also where we are investing heavily.
Uh, so we, we continue to invest in both, in both areas, uh, because it makes sense. Again, this is one of the biggest innovations in our generation, and of course we want to continue to, to leverage that As much as possible. I Agree.
So another thing I, you know, I have a great seat where I sit. I don't have to worry about making products, selling products, satisfying customers. I just let you talk about Brad and I just ask questions, but I get a good view.
One of the things we're seeing is agentic ai. So we're almost generative AI gen, ai, last year's news, next year's news, ag agentic ai. We're making these agents, smart agents, AI agents that are gonna do these things for us.
So we don't even have to type it or talk it into a chat bot. We, we set our agents loose. We're gonna, all of us will have an army of agents doing four kinds of things.
Mm-hmm. We'll need an agent to manage our agents. Is that something you, you'd see tenable utilizing, leveraging soon?
So at the end, every innovation that we'll see in the industry, tenable will leverage in order to make our products better, to make the life of our customer easier, to help them leverage, uh, and to be more secure. So, of course, this is something that is still under again, uh, we're still in the process of developing and seeing again where, where it goes, if it's a promise or something that we'll see more and more and more. But at the end, tenable will leverage everything around AI to make the life of our customers better and easier.
Agreed. And more secure, of course. Now managing those agents securely and making sure agents, again, that's part of Secure support, Securing your a Yeah.
Curating for your ai, not using your ai. Yeah. And that'll be, I imagine part, a part of the mission as well.
Mm-hmm. If you don't mind shy, I want to turn to reinvent here. Mm-hmm.
So it's only been a day. I know, and you've been in meetings most of the day. But what's your take?
So first I would say it's, uh, it's an amazing conference. Probably one of the biggest out there. Uh, um, I'm not sure if this year is bigger than last year.
Again, it's about the same me, to me, uh, it, uh, takes me back to the pre covid ward, I would say. Yeah. In terms of the numbers, which is, it is, is great.
Yeah. A lot of, uh, um, announcement. A lot of vendors here, a lot of partners, a lot of customers, which of course gives you, uh, the ability to meet everyone in the same place, which is great.
Uh, and for us, of course, for Tenable, it's also a, a great place that, uh, to, to make sure that we are meeting our partners and meeting our customers and working with them, uh, and making sure that we can do it in person. I would say, especially in a world that a lot of the people are still working globally and remotely, it's, uh, it's an opportunity for us, uh, to meet everyone. Okay.
Good stuff. Um, We spoke before we got online, we were talking about RSA Tenable, of course, already will be there again this year. Uh, as, as we look at, you know, RSA is, uh, the end of April.
Mm-hmm. Beginning of May. Um, as we look into the second half of the year, it's hard.
No one has a crystal ball. I get it. But do you see anything beyond ai?
'cause we all, you know, we all have like, AI in front of our face and we can't see beyond it. But beyond the ai, what else do you see as, not game changers, but things you need to be watching, political, uh, nation state kind of activity or, or something else that, that you think might, you know, we need to be aware of? So, I, I would say in, in general, if you're thinking about, uh, the ward, of course there are some instabilities, of course, uh, in the ward today, Say the least.
Uh, to say the least. I agree. Uh, and we are not sure how the future will look like.
Yeah. I would say. Uh, so of course you need to, to watch that and to see, again, what's the implications also on the technology side and on the cyber side, of course, instability also creates a potentially cyber risk, of course.
Mm-hmm. So that's also something that we're seeing, uh, if you're thinking of more on the technology side, the cyber industry is evolving all the time. You're seeing so many new startups.
You're seeing so many new technologies leveraging all the potential evolution and revolution in what we're seeing in technology, like the ai, uh, and the new AI agents and the gen ai and everything that we're seeing in the last few years. I would say in our space, exposure management is still something that, there are a lot, there is a lot of innovation happening there. How to make sure that we consolidate everything.
How to make sure that it's so, so easy to use and understand and prioritize risk based on everything that you have in your org. Yeah. This is still an, I would say, uh, a market that is happening right now and is with a Evolving as It's evolving all the time with a lot of innovation.
I imagine in the next four or five months, we'll have so many announcement until then to share more about our exposure management, to share more about a cloud security solution. A cloud security solution is evolving with a lot of innovation all the time. Cloud, because also the cloud infrastructure is, uh, is evolving all the time and very quickly and very rapidly.
So one of the things that we saw maybe at the last RSA and after that over the summer, was that, Well, number one, a lot of companies were saying we could do more with less. We leverage ai, we'll do more with less. Secondly was, you know what, for the last five years, seven years, eight years, our security, our cyber budgets keep going up, up, up.
Mm-hmm. But we don't necessarily see the ROI, we don't, we don't feel any less. Risk is a good way of looking at it.
And we're getting tired of increasing cyber budgets and no decrease in risk. When, at what point do you think that's changed, number one. Number two, what can we do to really give not the security people, because I think if you ask security people, they'll tell you, we're probably more secure now than we were mm-hmm.
Three years ago, four years ago, seven years ago. But the board level, the C level, the non-security folks, what can we show them that says, Hey, it's worth putting more money into cyber because you ha you don't have a choice, really. You have to, and we are lowering the risk.
That's gotta be a big part of your job. Right? Right.
So I, I would, uh, take us maybe to the beginning of our conversation at the end, I agree with you. There is some kind, maybe of trend or feeling that maybe we're not more secured, but we actually are, of course, we're way more agree, we're way more secured. Uh, and we are also seeing the consolidation as part of the reducing the cost.
Again, at the end, people want more ROI. So we're seeing a lot of pressure to consolidate to make sure that we're giving more, uh, ROI from everything that we do. Mm-hmm.
Of course, we we're doing it more. But at the end, what we need to do is, do we need to make sure that we understand that cyber risk is part of how you manage your business? It's business risk.
And the things that I feel like there is a lot of evolution right now is how we communicate this risk, again, to the board, to the executives. We're seeing a lot of this happening more in the last few years, and it's a big part of our task as security vendors to make sure that the CISO or the security team can communicate the right way. Again, their the risk, communicate the risk to the management, to the executive, to the board.
And at the end make, um, being able to have a good discussion and, uh, that at the end you can prioritize based on risk and based on, uh, things that will help you manage your business to better. To me, that is the most important part of being a CISOs job, is translating security talk to risk in a business level talk that these people understand. Mm-hmm.
And that's the only way you're going to get budget. That's the only way you're going to get the go ahead for new programs and new ways of looking at things, unless you wait till you get hacked and then all of a sudden it's an open checkbook. Right.
Yeah. We gotta fix it. Uh, but it, it, it's interesting times we live in.
Right. Um, talk to our audience. Chian, we'll close out.
I want you to explain to, if they wanna stay on top of their risk, stay on top of security. I mean, it's easy to say buy all the tenable products, but beyond that, what El what advice would you give them? So, so at the end, um, security is a platform play.
You want to understand that the siloed, I would say view that we used to have, which, uh, with every small niche, getting a second product will never solve the, or reduce the risk as much as, as much as we need at the end. There are security gaps, there are gaps between, uh, the standalone products, the siloed views that we used to have. And we're seeing the evolution of the, of the industry to focus more on the exposure management platform.
So at the end, this is what we believe in Tenable. This is what I believe That is, this is the, the way to reduce your risk as much as possible, to understand and to quantify your risk as much as possible, to, to leverage the platforms to make sure that everything is integrated. And you see everything in, in one place with all the context and prioritized based on that.
Fantastic. Shai, we kept you longer than we think we were going to, but it was a good discussion, so it was worth it. I apologize.
We will, hopefully we'll see you before RSA, if not in person, maybe on text, on tv. Keep up the great work. Congratulations again on the CPO role.
Thank you very much. I'm sure you'll do great there. They need you.
Thank you. com. com.
Right. com. I'm old.
But anyway, we hope you enjoyed this discussion. We'll be, we have more AWS reinvent coming at you today, tomorrow, Thursday, all the way through. So stay tuned here watching us on Drunk tv.
We have more content that's gonna come on right now. But until then, this is Alan Shimel. We're live here in Las Vegas.
Thanks for joining.