Cloud Security Turbocharged: A Wild Ride of Innovation, Threats and Staying Ahead | Cloud Native Now 2023
Buckle up for a thrilling journey through the fast-paced world of cloud security! As innovation and threats zoom ahead at breakneck speeds, old-fashioned approaches are left eating the dust. Organizations are struggling to prioritize the most critical risks in their environments while maintaining a strong security posture. While the notion of shifting left is noble, it must be turbocharged with context and runtime insights for maximum effectiveness. Teams need environment-specific security technology that fortifies applications and infrastructure and blitzes security issues at cloud speed. Prepare your cloud security for an adrenaline-fueled adventure where you beat the odds and win the race.
Transcript
All right. Hello everybody. Thank you for, uh, coming to our keynote, uh, here at, uh, the, uh, event for Cloud Native Con.
And, uh, today we're gonna be talking about a lot about cloud security issues. Uh, we're gonna move through this pretty fast, right? Cause it's kinda the world of cloud, right?
Cloud, the speed of cloud, right? And, uh, security issues happen quite, quite quickly in cloud. So, uh, today you're gonna be, uh, hearing from myself.
Mike is Bisky, director of Cybersecurity Strategy here at Cystic, and I am joined by my colleague, uh, crystal. Warren. Crystal, do you wanna introduce yourselves to the audience?
Yeah. Hi, my name is Crystal, and I am a cybersecurity strategist, formerly a threat research engineer here at sig. All right, awesome.
So let's get into it. Uh, if you have questions, please do put them in the chat. Uh, all, all of in the events are much better.
Uh, you know, if we can kind of personalize this for, for your, your set of problems, right? Everybody's, uh, world is a little unique, uh, whether it's people, process, or technology. Uh, so with that being said, let's, let's kind of dive in.
Uh, so security incidents occur at cloud speed. And actually we see this, uh, in a lot of, uh, different industry research. Uh, this particular statistic comes from I, IBM security, uh, and their cost of, uh, data breach report from 2022.
Uh, and that's that 45% of breaches were actually cloud-based, uh, in 2022. So, um, sometimes organizations will think, eh, I'm not really using cloud. But, uh, the reality is, your, your teams often are consuming, uh, cloud resources.
Hopefully it's, you know, sanctioned stuff, but, uh, most organizations are, are working in cloud, right? Uh, mo most organizations have also undergone digital transformation, uh, for some time now. Uh, cloud is, uh, very integral, uh, to those kinds of, uh, initiatives.
Uh, we also have seen very large scale breaches or incidents and breaches. Uh, we've seen Uber get hit multiple times, and sometimes I hate, uh, picking on Uber, right? Cause Uber actually did a lot of things, right?
They have very, uh, mature security program, uh, but they weren't safe from cyber attacks, right? Uh, this ha can happen to any organization. Uh, Uber did a lot of things, right?
Uh, but it's a, it's a very good example of how, uh, quickly, uh, even a, uh, leading security organization can get attacked and compromised. So, uh, they were kind of owned within minutes, uh, where the, uh, attacker got access to privileged credentials, uh, very quickly, and were able to move laterally within the network. Uh, we're gonna touch a little bit more on that too as we get through the session.
Uh, and as IBM reported, uh, 277 days was the average time to identify and contain, uh, the data breach, which is, uh, very, very long, right? Cuz we're talking about minutes for an attacker to compromise an entire network, steal data, uh, own the accounts, own systems, right? Uh, that they're, they're kind of, they have their, uh, it's full playground for them, right?
And then it takes us that much longer to even know that something happened, right? Cause there's, there's an enormous amount of data that, uh, organizations have to sift through. Uh, so th this is kind of reality, right?
Incidents occur within minutes, uh, but we're still measuring response time in months, which is, uh, very poor, right? And it, it's, it's, everybody kind of suffers from this, right? Because we, we don't always have the right, uh, tooling or process, uh, to deal with, uh, kind of, uh, the scale of the problem, right?
Or the speed of the problem. All right? With that being said, there's kind of four areas of, um, security challenges that occur for organizations in cloud.
Uh, one of them is that, uh, we're regularly working with vulnerable resources to start, right? And if you are on a container journey or, uh, deploying Kubernetes, not everybody is, right. We acknowledge that.
Uh, many organizations are kind of purely in cloud and using virtual machines. But, uh, you know, this, this particular statistics come, comes from, uh, cystics Cloud Security and Usage Report, uh, uh, issued earlier this year. Uh, what we saw that 87% of container images actually have high or critical vulnerabilities.
Uh, and this is specifically cystic customers, right? So these are organizations that already acknowledged they, they have a problem, uh, and they're still seeing these, uh, issues, right? So what happens is you are sourcing, uh, images and components from other, other public registries and repositories.
Uh, those, those resources have latent vulnerabilities or cve IIDs. Uh, we're gonna dive a little bit deeper into each of these as well. But that's kind of the current state of affairs, right?
Uh, what we're starting from is known vulnerable, um, configuration management or posture management. Um, 90, 90% of cloud breaches actually start with misconfigurations. Uh, this, this particular stat comes from, uh, Gartner specifically.
Um, another cystic stat from the usage report is that we saw that, uh, 90% of granted cloud permissions aren't even used, right? So they're granted to, uh, accounts and then never used again, right? So that's a potential attack vector.
Uh, kind of like the Uber example, uh, and threat detection and response. Uh, really the thing that is highly impacting to TDR efforts or SecOps efforts is that, uh, containers are very short lived, right? We, we talk a lot about how cloud is highly ephemeral.
Uh, cloud or, uh, container technology is really what is powering a lot of, uh, cloud or cloud native environments. And, uh, those containers are very short lived by design, uh, but then also to satisfy business functionality, right? It becomes, um, usually more efficient, uh, cost efficient and, uh, operationally efficient to run things as containers, but it creates new security challenges, uh, particularly for your, uh, threat detection and response.
All right? So what's happening in reality, right? There's kind of, uh, this split, right?
We hear this a lot in industry with, uh, shift left and shield, right? Um, it's kind of where you're putting your areas of focus in your security program. Uh, some of this is a little marketing heavy, the terms, the terminology, but it's a nice way of kind of thinking about where are you focusing your efforts.
And, uh, it is kind of fundamental to security strategy. A lot of organizations are shifting left in their security because they want to identify known vulnerabilities and configuration problems, uh, prior to those things being to deploy, to running environments or production, right? Because that's, uh, it's eliminating your potential incident, right?
That never, that thing never got to, uh, the running environment. Uh, the problem is that the more you test, the more you start to unearth a lot of issues, right? And, um, most organizations are still doing a fix, uh, a mix of manual and automated approaches, right?
You might be automating your security testing, uh, but you're not always automating the response to that or your release decision, right? Uh, what is an acceptable threshold for vulnerabilities to allow that thing to, to release to production? Again, if you run any kind of security test, you're going to find CV IDs.
It's, it's inevitable, right? And if you think about the entire, uh, application portfolio and all the systems, uh, you're talking about thousands or tens of thousands of vulnerabilities in most cases, right? Depends on the size of your application portfolio.
But, uh, it's not uncommon to see a thousand findings for just even one application, right? And then if you think about the broader, uh, view of the organization, there's different teams focusing on different, uh, areas of problems. Uh, the, the teams handling shield, right?
Might be your network security function or a cloud security function, where shift left might be more, uh, DevOps, uh, personas. So, uh, there's, there's very much the, uh, people kind of complexity to this, right? And then how do you structure your processes to identify all these issues, but then triage them in the right way?
That kind of introduces the whole concept of time, right? And as we've been saying, like, things in cloud happen very quickly as do attacks, right? And if you, uh, are trying to coordinate response internally across all these different personas, uh, gaps arise, right?
So, uh, every organization kind of struggles with this. I've seen it, uh, hundreds and if not thousands of hours of advisory work. Uh, it's a very common problem, right?
It's, it's not hard to find issues. It's hard to, uh, find them quickly and then address them quickly, right? And then how do you prioritize the work?
Because you only, And that's where, uh, this whole concept of runtime insights comes into play, right? This is kind of the, the missing link, right? Because, uh, thinking back to that slide about shift left, we can run scanners, we can find all these issues.
We can potentially automate them in our build pipelines. But then what do you do? Right?
You have to correlate all that information. You have to make risk and determinations to know what are the things that I'm actually going to work to remediate or mitigate? Uh, that's a lot of manual, uh, thought process, but also the work to fix all that.
Um, so you have to have automated ways to, um, kind of analyze that, right? He help me to understand what, what is actually being used, right? Because if I have, uh, uh, a package within an application that's never being used, uh, that's probably not something I'm going to prioritize to remediate quickly.
I might push that in the backlog or deal with it a week from now, or two weeks from now, right? It's, it's gonna depend on criticality of that application or the exposure, right? There's a lot of, uh, variables there.
Uh, and this is kind of the, the information that most, um, practitioners and leaders and CISOs are looking for is that, um, there, there's only so many resources to go around. Yes, gimme the telemetry. So I know everything that's going on.
Uh, but I need to know, like, really what's the most important, right? Because what am I gonna do right now? What do I do tomorrow?
What do I do a week from now? So, uh, that risk prioritization is, is absolutely fundamental. Uh, and that's run well.
We assisted, uh, call runtime insights. Uh, current state of vulnerability management is unfortunately kind of a, a car wreck or a train wreck. Um, we're talking about the speed, right?
If you think about, uh, delivery of, uh, applications and infrastructure, it's happening very rapidly. If you're doing any kind of deployment in, uh, say aws, for instance, you're working with cloud formation, maybe terraform, uh, you can spin up assets and tear them down extremely quickly. And then if you are in the world of Kubernetes, uh, that's happening by design, right?
That's container orchestration. So, uh, it's moving very fast. And, uh, if you think about a build pipeline or C I C D, right?
You can inject these scans to find things, but, uh, again, you're, if you just found a thousand, uh, C v e IDs and if a, uh, collection of app code with the infrastructures code, what do you do? Right? And, uh, not all of those are going to be first party issues, right?
Uh, oftentimes it's open source dependencies you're working with, or a commercial vendor that's providing some piece of code or a system, uh, who's accountable for that, right? That's fundamental to security programs is, uh, who's the owner to, uh, mitigate or remediate an issue, uh, that's going to slow down release, right? Or delivery, uh, which really creates friction in digital transformation.
And, uh, you know, most organizations are looking for very, very quick release velocity. Even if you're not trying to deploy 10 times in a day, um, you still need to be able to deploy efficiently, right? You don't want these kind of bottlenecks where you're finding things and now you have to engage teams.
It just, uh, creates too much, um, extra work or toil. Um, and, you know, we have to remember that engineers are focusing on business requirements first and foremost, right? They need to deliver functionality, they have to maintain availability and uptime.
Um, security is, is kind of always gonna be secondary to that, right? It's not their primary mission. So we need to be providing, uh, tooling and process that kind of, uh, provides the right context, uh, and that security, uh, expertise where it, it doesn't necessarily exist, right?
Uh, Gartner started to call this, uh, cyber judgment, but it's really about, uh, it's kind of, I've also heard it term self-service, uh, but it's really equipping people with the right information, but also, uh, technology that they can, uh, very quickly and officially, uh, uh, fix something, right? So, uh, ideally that might be fully automated, uh, you know, if you are kind of a leading class organization, but you need that information real time or as close to it as possible because of speed of attacks. Now, crystal, do you wanna jump in here?
I know this was kind of your baby for a while. The, uh, the threat research Yes. Report, yes.
Yeah. So this information you're looking at right here, it's a lot. I'm gonna talk you through it right now.
This came from the usage report as well. We got that 87% of images have critical or high vulnerabilities. And if you're running hundreds or thousands of images, that's pretty overwhelming, and your security teams aren't going to be able to effectively manage those vulnerabilities.
So, which vulnerabilities actually matter? Which ones do you focus on and prioritize first? That a hundred percent you're looking at right there, that's the 87%, right?
So we're looking at all of these critical and high vulnerable images. What can we do to reduce that number? First, we looked at the number of vulnerabilities that had a fixed available.
So there's some kind of patch or something. Um, the third party vendor that you're obtaining this image from knows that they're an issue. They send out a patch or a code correction, and you're able to apply that, no problem.
That's still 71% of your vulnerabilities. That's still a lot to work on. If you can consider the runtime insights, now you're looking at only 15% of your images are in use and have a vulnerability.
That's probably the sweet spot where, um, most organizations are going to sit. Um, you are using these images, they have a vulnerability, you wanna correct them. You should focus on that.
Uh, this 2% exploitable, these are images with critical or high vulnerabilities. Um, they have a C V E assigned to them, and there is an active P O C. So, you know, we always see those on Twitter or something like that.
There's log four J, the SolarWinds breach. We know that bad guys are using these vulnerabilities, and they are compromising organizations. Um, so that would be the most critical to fix.
That means there, it's exploitable, it's active, and your organization has it in use. That's what you wanna prioritize first. But ideally, prioritizing that 15% of your images that are in use and have vulnerabilities is what you should be working to correct.
Yeah, it's interesting too, cuz it's, uh, a lot of organizations will think, uh, critical, right? That's, uh, if you think of like, CVSs scoring critical is always gonna be the most critical. But this gives you another, uh, way of kind of slicing that, um, information, right?
And, um, you know, if you're thinking kind of tactically, well, I really want to address those things that are known to be exploitable and or actually being used, right? I, I do wanna get all criticals obviously, um, but I still have to take time to do that, right? I've seen, uh, plenty of, uh, SLAs or service level agreements on critical vulnerabilities that you get a week to fix that, right?
We just talked about how organizations can get breached within minutes, right? So it's, it's kind of an unacceptable s l a. So, um, while it seems weird to say, well, why would you only focus on that 2%?
Uh, you have to kind of think in terms of time, right? And again, that speed of cloud, that becomes the way that, um, you can kind of organize your resources and tackle those, uh, really the most truly critical issues, not just what C V S S tells you, is a, uh, uh, critical finding. Okay?
So next step we have cloud permissions. Um, this pertains to the entitlement management that we talked about earlier on. Uh, 90% of permissions are not used, um, are granted to employees and not used.
So they're sitting out there as just more risk and opportunity for an attacker. Um, the way that I like to frame this, that helps it make a little bit more sense to me is, um, downloading mobile apps on your cell phone. You know how when you first download an app, it always asks you to grant all of these permissions.
I actually looked this one up last night. Candy Crush, we all know, right? Just a game that we all like to waste time on.
You've got five minutes between meetings, you're gonna go play Candy Crush. Um, candy Crush actually asks for your location and also for a list of all the other apps on your phone, which they wanna give you ads that pertain to what you're interested in, right? Um, but this is just unnecessary due risk.
You don't need to grant those permissions to go and play Candy Crush. It's the same thing with cloud accounts and the permissions granted to your employees. They may come and ask you for certain permissions so that they can work on a particular project.
Um, there's groups like say DevOps personnel. They're creating a new app or something like that. And they need administrator permissions to be able to, um, ensure that they're building an app correctly, that they can span the environment.
Um, once they're done with that project, those permissions should be removed. Um, so just making sure that you're keeping up on your granted permissions, taking away permissions that are no longer actively used by your employees is going to greatly reduce your risk. An attacker is always looking for, obviously, first a means in once they're in your network, they wanna move laterally.
The best way that they can do that is picking an account and moving through that account, looking for administrator permissions and things like that. If you reduce the number of permissions that your accounts have to only what's required, you're going to reduce the attack surface as well. Yeah.
And one, one thing I like to stress here too, crystal, is like, uh, uh, oftentimes when we think in terms of identities, we're just thinking, uh, people or humans, right? And when you're, when you're talking about cloud and cloud native, uh, applications or systems, uh, there's a lot more machine identities usually, or service services as well, right? And those things need to be, uh, assigned some kind of credential.
Um, and it be, it could take a lot of forms, right? It might be an api, API based, uh, access. It might be something that's certificate based, um, a mutual s for instance.
But there's a lot of different types of credentials in play. It's not just employees and, uh, customers, which are distinctly different as well, right? So there's a, a really massive landscape of permissions that very quickly erupt in cloud, uh, and it becomes almost unmanageable.
Most organizations without, um, tooling to kind of give them the right information of how is this thing used? Where is it used, uh, has it been used recently? Uh, and, um, a lot of attacks actually happen with, um, attackers targeting identities, uh, if not initially that might be part of the attack chain.
Uh, and it, you know, sometimes as security practitioners, we might dismiss an incident as like, oh, they just kind of fished that person or social engineered them. But, um, that is a very critical aspect of your security, right? It's not just ensuring that you're using, uh, vulner vulnerability free code or as close to that as possible.
Uh, it's also making sure that you've, um, defined access controls properly and set up permissions, uh, as part of zero trust architecture. All right, crystal configuration management. Exciting topic.
Yeah. Um, so regarding initial access, right? Like you said, Gardner found that 99% of cloud breaches start with a misconfiguration.
Um, this is mostly human error, right? We all make mistakes, and that's a really scary burden to hold. I know I wouldn't wanna have to be in charge of configuration management and knowing that there's such a high possibility that there's gonna be a compromise due to an error that myself or my team made.
Um, permission management relates to this as well. The less permissions there are, the tighter that this configuration access is going to be. You don't want a lot of your employees to be able to make configurations and be able to make those misca mistakes.
Um, no amount of training can fix this problem. It's just something that we, we need to keep an eye on. Um, environments are mixed.
You have multi clouds, it's distributed. It's that difficult thing to get a grasp on. Yeah, and a couple things to add, you know, um, control planes, right?
If you're not familiar with that concept, sometimes that pops up more in like network engineering language or network security. But as you're working with different environment types, um, each tech stack kind of has their own, uh, control plane or management layer, right? And you have to define all these access controls there and configurations.
Um, if you think about, uh, like a complete enterprise architecture, you're contending with multiple layers of those control plants, right? So, misconfigurations, it, it's kind of the, uh, one of those things that's very simple, right? It's like, why is this number so high?
Why don't people actually disable, you know, uh, a port 80, which is another point I'll get to in a second. But why these things happen? Well, it's partially because we have so many, uh, different spots.
We have to configure and manage things. Uh, that's kind of unavoidable, right? This isn't necessarily, uh, vendor, uh, product selection.
This is just kind of the nature of the beasts in how you, um, create all of your infrastructure or the compute that powers it. Uh, and you know, even if you're just purely an aws, uh, if you're also using Kubernetes and, uh, virtualization services, you're using multiple, uh, pieces of technology in aws, each has their own control plan, right? So you have to make sure your VPCs are configured correctly.
That's one component. Uh, and then Kubernetes itself becomes, uh, a layer within that. So you have to make sure all those things are configured correctly or, um, uh, access control as, as, uh, crystal alluded to, right?
These, they are very tightly intertwined. Sometimes people won't say misconfiguration, they're actually meaning mis permission, uh, or something related to access controls. Uh, but the other point it was bringing out about like ports, right?
Cause like particularly in the network security space, um, the, the, uh, if you think in terms of firewalls, there was kind of that tendency, like, let's lock everything down, right? Cuz that's going to, uh, make it secure, right? And we should seek to do that, right?
That is kind of lease privilege and zero trust. Uh, but the reality is most applications, uh, or services or microservices, uh, they need to be open or in some state of openness, right? And for network connectivity, that's typically 80 and 4 43.
Uh, but they also need open access controls to, uh, to talk to one another, right? And then we kind of get back to that entitlements discussion is, well, what's the appropriate access for that user or machine to that, uh, piece of code, right? So it, it's very hard to kind of define, uh, those access access controls at scale and know what, what is the proper, uh, configuration for the infrastructure Onto Right?
Threat detection. Yes. Um, so the stat from the usage report, 72% of containers that we saw lived less than five minutes.
Um, this environment is very ephemeral. Things move very quickly. And this makes it very difficult for threat response teams to be able to capture the appropriate logs to be able to see what's going on.
This only gives you five minutes to witness the container spinning up and spinning back down, capture that activity that's going on. It also only gives five minutes for an attacker to be able to get into that container. But if they're already watching you, they've done their reconnaissance, they know maybe how often this container spins up and down when it goes live, they're ready to attack.
Um, like we said, cloud attacks are really fast. So, um, this makes it very hard for threat detection teams. Um, attackers use AI to make things faster so that they can get into your environment within that five minutes.
Uh, threat detection needs to be able to use AI as well to be able to capture what's going on in that short timeframe. Um, what else do you have to add to that, Mike? Yeah, uh, I mean, a bit.
I just wanna be mindful of time too. So it's, uh, there's a few things in play here, right? Like the ephemerality, it is definitely important for threat detection and response.
It's also really critical for auditing and governance, right? So there's, uh, there's many p pieces to this, right? And that container status, it's really kind of mind blowing when you're really think about that amount of time just like it is with, uh, the time to, uh, uh, time to breach, right?
Uh, or boom, right? So it's like we need to get ahead of that and, uh, it's very short, right? And like, we need to retain all this data to support our auditing and governance.
Uh, so yeah, the AI piece is, is newer. I mean, technology-wise, not terribly new, but, um, we're seeing more attackers use AI as a tool themselves, right? Just like how the world has woken up to LLMs like, uh, chat G P T and seeing how they can incorporate that into their work.
Uh, attackers are also using, um, things like LLMs to, um, accelerate their reconnaissance and, uh, attacking and exploiting. So it's, uh, the time could really accelerate, right? I guess it's the, the short way of saying, uh, it, it seems really pressing, but it, it could actually accelerate even more.
So it, it really emphasizes that need for systems that can automate the detection and response. Cuz there's just no way you're gonna get ahead of it annually. There's just too much data to sift through.
I think this kind of emphasis emphasizes it as well. Crystal? Yes.
Okay. So here I wanna give you some examples of the complexity that we see in cloud attacks. Um, what attackers are using for automation, what vulnerabilities they're taking advantage of.
Our threat research team has done a lot of work answering all of these questions over the last year or so. Um, first I wanna start off with that complexity aspect of how challenging it is to look at and analyze an attack chain. Um, we reported this with our Scarlet Eel operation earlier end of last year.
Um, our attacker there used an infrastructure as code service called Terraform. Um, they were able to initial access into Terraform. They used that to pivot from the Kubernetes container into an a w s account.
So they're going across multiple environments, which makes it difficult to follow them. And they were able to steal proprietary data, um, from the customer that was attacked. So they know what they're doing, they're moving across environments.
It makes it very difficult for threat detection to be able to track them as they're moving as well. Um, that next one, free jacking. We coined that term in our purple urchin report.
Um, in that blog we found a threat actor who was, who built this massive crypto mining operation. Um, they took advantage of three free trials leveraged by, um, GitHub and things like that, C I C D service providers. Um, and they use those free trials to build, run, and scale their operation.
Uh, this threat actor actually automated the account creation process. Um, so, uh, you're only limited a certain amount of hours, a certain allowed amount of compute with these free trials, of course. And as they burn through that allotted time, um, they would automatically build a new account on say, GitHub, and use that to continue their operation.
We actually watched as the threat research team, this happened in near real time. We were watching accounts be created and all of the code for their operation being added to these accounts and implemented, um, so that they could continue scaling their crypto mining operations. The other, um, attack that we kind of coined this year as well was proxy jacking.
Um, and this case, the attacker used, um, proxy provider services to make profit. Um, they used a log for j vulnerability for initial access into the victim's account. They were able to take the IP address from the victim and they sold it to the proxy service provider.
Um, and then collected the passive income from the service provider, um, by selling the victim's IP address to unknowing users looking to obfuscate their source ip. Um, so there's lots of examples of attackers learning. They're becoming faster, they're becoming more evasive.
Um, they're really taking full advantage of the cloud environment. They're using the same tools and applications that we are to protect ourselves and they're finding their way in as well. Yeah, it's, um, I guess something to stress here too, cause I, I mean I saw it a lot in advisory, right?
It's, um, if you, if you're still kind of doing that vulnerability scanning from outside your network and, um, uh, that's kind of it, like that's the gist of your approach to security, uh, most would just label that as vulnerability management. Uh, ho hopefully it's clear. Like it, it's just not gonna cut it, right?
Uh, cuz as crystal's pointing out, right, CVE IDs, uh, get chained. Uh, but some of those things might not be obvious, uh, externally, right? Or attackers are gonna use, uh, applications and services and pieces of infrastructure in novel ways that, uh, wouldn't even make sense, right?
So it doesn't look like, uh, a typical exploit of a, uh, a known vulnerability. So when something like, uh, issues like, uh, log four shell came out, or the open SSL vulnerabilities, uh, it, it's kind of, well, there's that initial wave of how somebody might compromise that, but then there's all the other ways they might kinda chain that together or, uh, attack business logic, right? So it, uh, becomes, uh, pretty nightmarish.
Uh, and then the other big thing to remember, um, is that, you know, we don't exist in a vacuum, right? Most organizations are partnering with other partners and suppliers. So everybody needs to be doing this and thinking about this, right?
Cuz that's kind of that complete software supply chain. So if there's weakness in one of the aspects of that complete system, right? Cause you have to remember it is your partners and suppliers also, um, that that becomes another way you can, um, kind of be attacked.
All right? So a little bit of how Sig addresses this, but I'll, you know, I'll, I'll say that this is kind of what you should be seeking, uh, in your cloud security platform also. Uh, but as I mentioned, you know, cystic is, uh, uh, going very heavy on this runtime insights, uh, uh, aspect because it is so critical to cybersecurity, right?
And we talked about these concepts throughout, but hopefully this kind of ties it together for you. Uh, we talked about that concept of posture management, uh, right? Your security posture is critical.
It's kind of ha have you hardened everything, uh, pre-deployment as it's being built. And then as it's being delivered, you wanna make sure it's appropriately hardened. Hardening comes from, uh, analyzing all the infrastructure is code and your configurations and all of those control planes to know, well, are my assets appropriately hardened from the get-go?
Right? And a lot of, uh, that, that is essentially shift left, right, or secure by design. Uh, and then vulnerability management is kind of in there also, right?
You're, you're testing to make sure, uh, things are relatively vulnerability free or as close to that as possible. And then, uh, it has to be continuous, right? Just like we just talked about.
Because new vulnerabilities are discovered, uh, pieces of functionality change, uh, aspects of the system change. Uh, entitlements are gonna be a moving target, right? Because, uh, those accesses for all types of identities, humans as well as, um, machines.
Um, and then what are you doing for your security monitoring to inform threat detection and response, right? And it's not enough to just uncover an issue. Well, now you actually have to, um, queue up the appropriate response, right?
And maybe that includes your third parties, but do you have all the right data to, to inform that? So it's quite a bit, right? And it's, it is kind of full life cycle.
Um, all all of these things are really, uh, critical for compliance, right? We have to remember there is kind of that, uh, regulatory oversight piece, which, uh, is increasingly or is increasing. Um, that's kind of a separate discussion, but the security industry is, is probably gonna be undergoing some change where this becomes, uh, increasingly required, right?
So we know these things to be true. We really need to be doing it a as, uh, any organization in any industry because, uh, very quickly things can be compromised, right? And can impact safety.
Um, usually what happens as part of these discussions is that, uh, again, organizations wanna do this quickly, right? We're talking about the speed of cloud, the speed of security incidents. Uh, we need to be able to, uh, find these issues and, uh, correct them quickly.
So you need to be able to detect configuration drift quickly, right? In seconds, uh, because it can change, right? Maybe a DevOps engineer, uh, modified some code, or your software engineering team changed something in the infrastructure as code that's gonna have, uh, implications to your security posture, right?
Uh, or maybe platform ops, um, mis misconfigured something in the code. Uh, we talked a lot about the vulnerability noise, right? Uh, there is this very large spectrum of CVE IDs.
They're always going to be there. Uh, there's never gonna be a problem finding them. Uh, the issue is what's actually in use, and then how can we reduce that noise so we can actually prioritize the things that are worth fixing, uh, permissions not to be the dead horse, but, uh, they're often bad, right?
Particularly if you include scope of machine identities, but it becomes another big attack vector for threat actors. Uh, and then you'd be able to detect the threats, uh, very quickly and in all types of environments, right? That's, uh, as we've said, there's, there's very mixed, uh, technology in in most organizations.
Um, so SIG is a, uh, cloud native application protection platform provider. Uh, we, we've kind of talked about this at length, but, uh, runtime insights are key. We need to prioritize, uh, what is most critical so organizations can, uh, and practitioners within the organizations can work quickly and effectively to, uh, harden, right?
Prevent that code, uh, prevent instantiations of that code from occurring again in delivery. And that happens at, uh, the application source code or infrastructure as code. Uh, you have to stop the attacks, uh, in motion with real time detection, right?
We need to be able to see these things very quickly. We can't, uh, have that kind of old world of, well, we ran all the scans, we found these 10,000 issues, and we're gonna take three months to address it all. It's just not gonna work, right?
It's kind of a huge security gap and a huge, uh, window of exposure. So you need very, very quick, uh, um, uh, threat detection or, uh, security gap detection, uh, in industry. There's concept of snapshots.
I'm not, not gonna really dive into this too much, but there's latency in doing snapshotting. And, uh, it, it can really greatly impact to respond quickly to threats. Um, and then end-to-end becomes, uh, super critical, right?
Because no tech stack is super simple, right? It's often used in different types of compute. It might be connected to different environments, right?
So an application is not this small, tightly contained thing, even if it is containerized, right? It's, uh, it's a collection of containers and resources and networks and, uh, suppliers and partners all working, uh, together. Um, so you really need that, uh, complete coverage or end-to-end protection.
All right, with that, crystal, I'm gonna hand it back over to you. Yes. And close this out, and then maybe we'll hit some questions.
Uh, so obviously you guys see that we had a Formula One theme here with races going on this summer. Um, just wanted to throw this cart in here. This is actually my personal vehicle and would like to say that I see cystic and our C a P capabilities more like a rally racer than an F1 car.
F one s are fast, they're agile, but they're not quite as rugged. Um, rally racers go a little hard, so I just needed to put my car in there with our race theme. Um, and with that, I would like to share with you all, um, just another, a few more options that you have while you're in, um, tech Strong's Cloud Native Days today.
Um, SIG has a booth, a wonderful booth that's been manned all day. Um, we actually have our own game going on over there. Um, but earlier this morning we had, um, a, a, a live demo session with our friend Nigel.
Um, he went through some cyber attacks and how to defend them. So you can go check out that session that was recorded this morning with him. Um, you can, I believe you can link back to that at our booth.
Um, there's also a link to our Runtime Insights paper. Um, we just published this a couple weeks ago, I believe, right, Mike? Um, so you can get a little, I don't, same month ago, Okay, a month.
Um, you can go and read this and get a little bit more detail on what we tried to briefly skim over here today for you. Um, and then, like I said, you can go to our booth here at the conference. Um, in addition to the scavenger hunt that text Strong's got going on today, we also have a crossword puzzle you can solve for some cool cystic swag.
I'm not sure if it'll be hats like ours today. Um, but we're also giving out Amazon gift cards and it's prime days, so those could come in handy for you. With that, I think that's all we have.
We've got a couple minutes left. We can address some questions. Um, but I'd also like to let you guys know real quick, um, that our threat research team is publishing their second annual threat report that's going to be out in less than a month.
Um, if you enjoyed today's discussion, there is a ton of information in that report that is very much so related to and backs up everything that we talked about today. Um, I'm super excited about that report. I'm sure you guys will see us, you'll probably see my face talking about it a whole bunch next month.
Um, so just wanna bring that little teaser out. Uh, we have a couple questions and I can tell you guys about the bike as well. Mike, do we wanna talk about the motorcycle picture there, or should we go with some questions?
Uh, maybe let's hit some questions and it's, uh, all right. Hopefully we hit on everything. It's impressive that Crystal didn't spill any of the beans, uh, uh, details in the threat report, but yeah, definitely ties into a lot of the concepts here or, or reinforces them.
Okay, so here's one. This one's kind of a tough one, but we'll start with this one. Why are response times so slow for organizations?
Yeah, it's, um, yeah, it's, it's like, uh, it's almost like my, I would defer to my analyst answer of it depends, but it's, uh, it's kind of a mix of a lot of things, right? It's that, uh, uh, heterogeneous environments, like all the different technology stacks, uh, and then coordinating your response across all that. And then do you have visibility into, do you even know it exists?
And then you have, do you have the visibility into it to know if something even happened? Uh, most organizations really struggle to, to answer that. Uh, un unfortunately, that is going to really bubble up.
Uh, that's some of what we're seeing with, uh, the s e c disclosure rules, right? You have to very quickly, uh, disclose when you've identified an issue. Uh, but if you're slow to identify, maybe a little wiggle room, but it's like, uh, you know, it can create problems for you as a, a publicly traded company or a company that aspires to be publicly traded.
And that's kind of the tip of the iceberg, right? That's, uh, almost the easiest thing for the US federal government to enforce. But we're, we're also seeing this in other, uh, countries as well, drawing a blank on, on the eus, um, e equivalent of the National Cybersecurity Strategy.
But, uh, it, it's going to become very critical, right? Uh, you need to secure everything, uh, upfront, right? Do that hardening, uh, they might call that shift left, but, uh, most of these things are kind of the basic security principles, right?
We start to label 'em different, differently as industry or, or marketers. But, um, it, it is very much security 1 0 1, right? Make sure that thing is deployed securely from the get-go, that's gonna reduce, uh, the exposure or the ability to attack and exploit it.
Uh, but you still have to monitor in runtime to know, uh, is somebody, uh, targeting you, exploiting it. Uh, but yeah, it's kind of lack of budget, right? Lack of manpower.
Uh, we didn't always have, it's hard to Look for what you don't know. Yeah, Yeah. And it's like the, you know, this ability to stitch together, uh, data, you know, some of that comes by virtue of cloud itself.
Right? Now we can scale better. We can actually, uh, analyze data much faster.
We can use AI to analyze the data to surface signals for AI and ml. So there's a lot of factors to that, right? It's not, it's not so much that organizations are just poor and, um, actively ignoring the problem.
It's just, uh, we didn't have, uh, all of the right tools at our disposal, or there wasn't enough awareness on it. Yep, exactly. And I think we are at time, so, Awesome.
Thank you all for tuning in. Um, I hope this was informative. I hope it helped.
Um, there was a lot of, a lot of stuff to cover in a short period of time. Um, but we've got a lot of resources about these, these four keynotes that we spoke on today. Yes.
Thank you everybody. Take care.





