Fast and Fearless: Secure Innovation at Cloud Speed at Cloud Native Now 2024
Enterprises increasingly embrace cloud-native technologies to significantly improve speed, cost efficiency, scalability and innovation. The rapid adoption of cloud technologies—from containers to generative AI—alongside the proliferation and sophistication of modern cyber threats introduces intricate security and compliance challenges.
While tools designed for cloud-native environments offer support, more is required. In this evolving landscape, there needs to be a tolerance for visibility gaps or delays in response. It is imperative to cultivate new mindsets and acquire new skills to manage these challenges effectively.
Join Sysdig and AWS for an insightful discussion on crafting a robust cloud security detection and response plan. Gain valuable insights into navigating the dynamic security environment, adhering to emerging secure operational standards such as the CIS 555 cloud security benchmark, and empowering your organization to accelerate its cloud security initiatives.
Transcript
Hello everyone. Thank you for joining us today with Techstrong for our keynote discussion, fast and Fearless Secure Innovation at Cloud Speed. I'd like to introduce myself.
My name is Crystal Morin. I'm a cybersecurity strategist at Cystic and former military linguist and Intelligence Analyst. And I'd like my partner Matt, here to introduce himself before we get started.
Sure thing. Hi Crystal. Thanks for, uh, for having me on.
Uh, my name is Backer Daria. I've been with AWS for about six years, and I've been heavily invested in the cybersecurity and observability, uh, community, uh, specifically with partners. Thank you for joining us, Matt.
Alright, so here's our agenda. Today we're going to talk about modern cloud technologies, some of the aspects that we're seeing in the current threat landscape in the cloud, and then cloud detection and response. So without further ado, let's dig in.
Well, let's make, um, just a couple opening remarks here, crystal, before we dig in. Right. So I think it's, it's a pretty monumental state.
It's, it's July 19th, 2024. And we were just talking about this before we got on the entire CrowdStrike windows, uh, sort of fiasco that's happening out in the world. It's bringing down tons of applications, mission critical applications for airports, healthcare systems, and so on and so forth.
You know, the name of our talk is, is Fast and Fearless. Um, and, you know, I think we had a situation where there was a fast and fearless sort of development cycle, um, uh, that hit upon something that probably needed some more controls around it, right? And I think part of the theme of what we wanna talk about today is we want, uh, developers, uh, to be able to move at, uh, very, very quickly, right?
Uh, especially within, um, you know, distributed architectures or, or with access to distributed architectures and sort of benefits that that brings, um, getting code quickly through your CICD pipeline out of your id, through your CICD pipeline in production and so on and so forth. But there's also a very good security compliance story that we need to wrap around that, which is, well, a, allow folks to be fast and fearless on that, let's call it the left hand side of the equation. But let's also put some parameters controls in place to make sure that they're not moving too, too fast, uh, maybe faster than the speed of light, maybe let them move at the speed of light.
Yeah. Thank you, Matt. Absolutely.
Um, so with that, I have a question for you to start. Um, what are some of the primary benefits that organizations are achieving and are seeing right now through the adoption of cloud native technologies? Yeah, so cloud native technologies obviously have been around for a very long time.
So all the hyperscalers that are, that are on the planet, uh, I'm obviously with AWS so I have a special, uh, relationship there. And, uh, very, very special knowledge about how AWS works. And so to give you kind of the AWS story, um, you know, we typically, we talk a lot about, uh, the customer adoption journey or the cloud adoption journey for our customers.
And it essentially happens in two ways, right? It's customers that are building natively on the cloud, um, and we call them, you know, digital first cloud first types of companies. And, and a lot of those are ones you'll see on your phone, quite frankly, right?
That you develop that have developed apps specifically for, for usage. Um, and then you have sort of, um, older incumbent companies who have built some on-prem stuff, and, you know, these could be dozens and dozens of years old, uh, and that are looking to figure out how do I modernize my applications to take advantage of this thing that I've heard? Uh, that's the cloud, right?
And so the reason that the cloud works is let's, let's take it from a developer perspective first. Um, and then I'll bring it up to why companies like it, why board of directors like it, why, uh, uh, CEOs and so on and so forth. CFOs really love the cloud, but developers have, and and I sort mentioned this in the, uh, in the prologue here, um, they have access to, um, you know, almost unfettered ability to do what they love to do, uh, which is produce code that meaningfully impacts some end user, right?
And that's what they wanna do. They wanna be able to get that impactful code out, whether it's a feature release, whether it's an entirely new app, that's, that's what they're built to do. That's what, that's what they're purpose driven to do.
Um, with the cloud, developers don't have to worry about all the sort of constituent underlying lateral pieces that are necessary for dev when you're in an on-prem environment, right? You have to set up your own infrastructure, you have to worry about storage, you have to worry about databases and so on and so forth. Um, when you're in the cloud, those things are almost preset for you, right?
Um, in lots of ways. And then developers, what they have to worry about is writing code. And then they have the understanding that I have the infrastructure pieces in place that then allow me to slide that code through my C-C-I-C-D, right?
And then into a production environment. So that's, that's the first ones. It's, it's basically speed and not having to worry about the, the supporting pieces.
Um, the second part is it's easy to incorporate cloudy tools right into that development workflow. Um, and developers have, again, lots and lots of options from testing tools to security tools, um, to all kinds of databases that they can play around with data repositories and so on and so forth. And that's just the nature of the cloud.
We have cloud marketplaces that allow access to literally thousands of types of, uh, products. SIG is part of the AWS, uh, marketplace, right? Our cloud marketplace, which then allows a developer who's thinking or already invested in Kubernetes development, for instance, to then take, uh, assisting instance, attach it to that Kubernetes environment, and then have, uh, not only, uh, security, right, for, um, for their containers, but then also the observability of how those, uh, containerized, um, uh, that the containerized applications are performing, right?
So that's a good, that's a good instance of like how we, we have that agility. And then, um, I just mentioned this, but allows you to take more advantage of distributed architectures of modern environments, microservices that are embedded into containers. And this allows for faster updates to your apps, right?
And so what businesses are interested in are not necessarily, am I running on Kubernetes? Am I doing serverless? Am I doing microservices on top of containers?
What they wanna understand is, am I getting features out to keep me competitive in an environment with my competitors? And what the cloud is really, really great at doing is allowing developers to send those, those feature enhancements, um, you know, to very small pieces of the application at very rapid speeds, um, rather than the old school way of doing things where there was a yearly or bi-yearly big update of an application that sat in a virtual machine. So lots of, lots of agility and speed that are, uh, that are included in that.
Now, going up to kind of the, the, the executive level piece of this right here are the things that we typically talk about. Agility. Uh, teams can experiment and innovate more quickly and frequently.
And boards of directors and CEOs love that, right? Cost savings. Um, developers are not so much worried about cost savings, but guess who is, right?
CFOs are very cognizant of this. Board of directors are very cognizant of this. And when, especially when you're looking at margins, you are looking at operating margins and, uh, gross margins, very, very important that the cloud allows you to spit up resources when you need them, spin down resources when you need them.
And then again, being, uh, an AWS employee, um, and an Amazon employee, our philosophy is always to lower prices over time. And we have a history of doing that on behalf of our customers. Um, elasticity is a big piece as well.
Um, you know, again, scaling up and scaling down, as I just mentioned, that's, um, sort of tied to this notion of cost savings. Um, and then what all this leads to is basically the ability to just innovate faster, right? When you have all of these things in place, you don't have cost prohibitions, you have increased performance because of things like distributed architectures and being able to orchestrate on Kubernetes.
Um, you just tend to be able to innovate faster on behalf of your customers and then build what I like to call a durable competitive advantage for that particular business. Thanks, Matt. Yeah.
So you, the last one you hit on innovation is my favorite part of this. And I think the greatest benefit of cloud native technologies, it's that innovation. So the industrial revolution lasted 60 to 80 years.
We're amidst the technological revolution right now, the equivalent of the industrial Revolution. We're only 40 years past the birth of the internet in the, say early eighties. Um, so we're at the heart of this right now.
Um, and we don't wanna see any organizations fall behind or not embrace it. Uh, we're all in this together with innovation. I think cloud was that next greatest step after the creation of the internet.
Um, and right now we're seeing gen, AI and large language models, I think is the next big step in our, um, revolution. Yeah. And so riffing off of that, uh, crystal, let me ask you a question.
Um, can, can you provide, um, any sort of like, specific examples of how generative ai, um, is being rapidly adopted in the industry? Yeah, Absolutely. That's obviously the big, it's a big touch point.
It, it's, um, you know, you mentioned the industrial revolution, and I love the context that you provided. Generative AI almost provides like another leap right on top of that sort of tech technological, uh, industrialization, if you will. Um, so generative AI is a wonderful innovation.
It really has the potential to allow people to automate menial tasks and prioritize more creative efforts. Um, this is hugely important and incredibly piti pivotal in that technological revolution that we were just talking about. Um, we're really going to see a lot of different business sectors start changing.
We're going to see the creation of a new job market for AI analysts, AI security, um, and the like. And that's gonna be all in the next couple of years. And so closely attached to that.
Um, and I think this is fairly obvious for you and I, uh, being in the security field. What do you, what do you think? Okay, so there's lots of benefits obviously to this that people have overt rotated on.
It's the automation, it's the simplification. It's allowing me to do less manual stuff like I do. I do document ization.
Um, and so I'll throw a six page, Amazon's famous for six pagers. I can now throw that into our own internal generative AI system, and then it will help me summarize what is included within that document. So I love it, right?
Rather than taking me an hour to do it, it's a five minute exercise, and then I fact check and so on and so forth. Now, that being said, with all of the productive capacity, um, and simplification and automation, the generative AI brings, what do you think are the security compliance, um, uh, risks or concerns that are attached to, to generative ai? So, just like generative ai, like any other security concern, you don't know what you don't know, and human error still exists.
Um, those are tough pills to swallow when you work in cybersecurity as a defender. Um, but you need to learn from your mistakes and mistakes of others. It's really one of the only ways that we can improve as attacks or errors happen.
Um, there's only so much that we can do to be preventative. Attackers only need to be right one time to be able to get into an environment and wreak havoc. Um, we need to be right every time to be able to protect our environments and defend against that.
Um, in regards to gen AI specifically, there's a lot of security concerns right now because of the types of sensitive data and information that might be fed into 'em. Yeah. Um, but really from our security perspective, it's not as scary as it seems in the news.
Um, a large language model workload is the same as any other cloud workload. It just stores a different kind of data. Uh, so in essence, it requires the same kind of security that we're using, uh, to secure the rest of our workloads in the cloud.
Um, but in light of the security concerns with generative ai, uh, SIG did recently create security for AI in our platform. Um, and this is allowing our customers to prioritize the security of cloud infrastructure where AI workloads may be hosted. Uh, what it does is it brings those issues or those vulnerabilities to the forefront since some of your most data exists there.
Um, you can choose whether or not you want to look at workloads that are in production, that have ai, that have a vulnerability within them. Um, and you might wanna consider fixing those first, if you are feeding sensitive data into, uh, your AI workloads. Um, with this new capability that SIG has, we also partnered with AWS to protect some specific AI services that they offer as well.
Um, uh, AWS Bedrock Q and SageMaker. Uh, and maybe you can speak to what each of those services are a little bit and why there's, why it's so important that we protect those services in particular. Sure thing.
Yeah. Um, so the, the, um, the services that you mentioned really comprise what we call our machine learning ai, generative ai, uh, capabilities. And so starting with, um, let's start with, uh, SageMaker, that's probably the, the most fundamental SageMaker is, is our managed service around machine learning, right?
And so there are various models that are available through the SageMaker service that allow customers to easily get up and running with machine learning algorithms and, um, utilizing that in order to improve, again, their business outcomes. There's, there's, you know, literally hundreds of difference of u uh, use cases that you can, uh, go through with that. And of course, machine learning is the underpinning when you go all the way up the ladder, I guess you can call it two generative ai, right?
It really starts with machine learning. So again, there's a, there's an entire library managed service of, of algorithms that you, uh, that customers can take advantage of there. Um, I'll go down to Amazon, q and Q is another, um, uh, set of services that, uh, that AWS has or Amazon has.
Um, and then you can think of Q services, um, as sort of like copilots, um, or assistance, right? And these are really productivity enhancers. These are ones that Amazon has built with underlying LLM technology.
And a good example of this is, uh, Q for developer, right? So we're sort of have a developer theme going on here, and Q for developer is basically a way of automatically generating code, right? And it's code that a developer might otherwise, otherwise be doing that's really not very sophisticated.
Um, it's really just a lot of manual labor. And think about, um, if you're familiar with this, or if the audience is familiar with this GitHub co-pilot, essentially what GitHub co-pilot is doing, but from an Amazon perspective and within an Amazon operating or an AWS operating environment. And then that gets us to, um, our bedrock services, right?
And so Bedrock is basically, uh, it's an Amazon service that you can think of as an API call to a bunch of pre-trained LLM models from companies like anthropic. So we have all of the cloud models that are available, um, through Bedrock that customers can take advantage of. Um, we have, uh, the, the llama models that are included in there, and stability, AI and so on and so forth.
There are, you know, dozens of, um, LLMs that are involved in there. And of course, um, and it may not be evident to everyone, but, um, LLMs are not homo homogenous, right? Like, you're not utilizing one LLM in your operating environment in order to do every single thing.
Some LM LLMs are very, very good at doing certain things. Some are good, very good at code generation, some are very, very good at image generation. Some are very, very good at synthesizing information and so on and so forth.
And so customers will use multiple types of LLMs, and then they'll look for pre-trained models. They'll look to then train them with their own data, right? To bring them into a more close knit, personalized version of what they need to have happen, and then go ahead and try to use that while within their, uh, the production environments.
Awesome. I just wanna highlight again. So q for example, like you said, it's used by developers, it kind of expedites the development process, right?
Um, so one of the reasons, And then that's, that's specific, that's specifically Q for developer. We have Q for business, and we actually have Q for contact center. And so you can think about these as if you're a business analyst, you can use Q for, uh, business in order to do analogous things to what a developer would do with an assistant for coding, uh, business analyst for all of their spreadsheet related work.
And number crunching would use an assistant in order to automate and help simplify those particular tasks. And then obviously, we open this up with sort of contact center, uh, piece. Uh, we all know we've all been on contact center calls, right?
In order to help to automate, simplify, and speed up and make more, uh, precise and accurate that entire, uh, you know, sort of system. Um, we, we do have, uh, you know, Amazon queue for contact center that helps do that stuff. Awesome.
Yeah, that's like what I was saying about the call centers, right? Kind of getting some of those simpler questions out of the way to be able to free up real people for the more difficult responses. Um, That's exactly it Too.
I think one of the important parts of keeping workloads or services like that secure, uh, a majority, I believe it's more than 60% of developers and businesses are often pulling their containers or their images to develop their own code from public resources like Docker hub. Um, obviously you hope that these are being checked beforehand, before they're being brought into your environment and being pushed into production. Um, but that's not necessarily always the case, or if there's an update where some kind of vulnerability was pushed.
Um, so sing brings those kinds of concerns to light for something like AWS's Q Service. That's right. Absolutely.
All right, let's move on. Navigating the threat landscape. All right.
This is, uh, super interesting stuff since we've gotten beyond sort of the value prop of the cloud and sort of, uh, development on the cloud. And we've gotten a little bit into the gen AI story and sort of the tech, I can't remember the exact term you used Crystal, but it was a great analogy to the industrial revolution. I'm gonna, I'm gonna actually use that one in my own talks now, but now that we're moving on to modern threat landscape, um, a question for you, especially as, uh, you know, an employee of a company like Cystic that, um, in our minds at AWS is sort of leading in this newish field, right?
Of cloud native application, uh, protection platforms, CNAP for short, C-N-A-P-P. Um, how have modern cyber threats evolved in the context of these dynamic cloud environments that we just opened up our conversation with? Yeah, so, um, I work very closely with SIGs threat research team.
So we're constantly looking and trying to find what attackers are doing in the cloud so that we can share these concerns and these findings with the broader community. Uh, one of the things that we've seen pretty consistently in cloud attacks is that attackers are using the same innovative tools and capabilities that we are on the detection side of the house. Uh, so this makes it very difficult to find them and separate, say, an attacker from one of your typical users.
Uh, a lot of cloud infrastructure is open source, right? It's known. We know what API calls there are.
We know what services exist and what they all do. Uh, so any attacker can go and look up and evaluate, say, an AWS environment before they decide to go attack a victim. Um, this kind of takes away some of that reconnaissance and the extended timeline that would happen in an on-prem environment where when you enter an on-premise environment, um, it takes you some time to get the lay of the land.
Um, now in the cloud, they already know when they get there. Um, like I said, it makes them harder to find when they're using some of the same tools and capabilities as we are. Um, for example, a recent discovery we just made, we just called Crystal Ray, um, this threat actor is using a pen testing tool that was built and developed for defenders to be able to map out their network environment and find where credentials and secrets might be, uh, so that they can secure this environment, remove those credentials.
This attacker decided to use the tool to do exactly the same thing. That is, wow, that's rotten. That is rotten, Plus several other open source tools.
I wanna say there were probably five or six tools, if not more, uh, that this attacker was able to group together and use to improve their reconnaissance efforts and expedite it. Ssh. All right, crystal, I I, I, I have to ask, is this a metas exploit based, uh, pen test tool that was being used?
I'm not sure. I'd have to go. Okay.
Okay. So though, Very interesting. Yeah.
So, uh, very, that's the struggle that we have right now with the modern threat environment. Fortunately, we know that that's the case. Um, so it does allow us to be a little bit more proactive in defending against these attacks.
Um, but attackers are just as innovative as we are. So when they see a new tool, I guess s sh snake pop up, they're gonna try to take advantage of it too. Yeah.
And then, you know, crystal, the thing that we've been talking about a lot with our customers and various other partners is the fact that, um, it's not just a human being behind the keyboards now that is taking control of a pen testing platform in order to disguise themselves as a good guy, pen tester, but actually creating some malicious activity to exfiltrate data credentials and so on and so forth. It's now generative ai, right? That's being used to do that at scale, at volume, and then repeatedly and repeatedly, human beings are limited by the amount of keyboard clicks they can do, and they have to sleep, and they have to eat, and they have to do other activities.
But guess what? Machines do not have to do that, right? So far as we know, they do not have to do that.
So, um, it's become, uh, entirely, again, I don't know that we've started to see the, um, the impacts of what have been predicted as possible attack, uh, attack vectors multiplied by this different sort of attacker, if you will. Um, but it's something that we're obviously keeping our eyes on, and I know that you and I have talked about this, that we feel like, look, it, it may come, we, we have the inklings or provisional notions of what it could look like. Um, and I think that the more that we talk to, uh, you know, partners and customers, they're cognizant of that as well, right?
Because they don't wanna be caught, um, sort of with their guard down, so to speak, and then have a massive scale attack happening where, you know, literally all the data is being exfiltrated out of a company, right? Yep. That's something, and I mean, if you look at just password cracking via generative ai, right?
I don't know if you saw the, the narrative around that, but it takes generative ai Yes. Very, very few seconds, right? To crack the code on your, on your iPhone or your, or your email, right?
Um, and now the recommendations are based on the trajectory of how good generative AI is getting at tasks like this. And it's just a, it's a task amongst others that AI does, right? That's what we have to understand.
Whereas for a human being, it's, you know, that's a, an entire career is that that's all you're doing, but, you know, password protection is going to be something that we have to think about more phishing attacks, something we have, but thinking about in a more sophisticated manner and so on and so forth. Absolutely. Very interesting stuff that's coming up.
It's Okay. So I kind of already give a teaser of some of the challenges, uh, but what do you think are the key challenges that organizations are facing right now, uh, particularly in regards to vulnerability gaps or say response delays? Yeah, so look at, at AWS we, um, we meet with a lot of CISOs.
Um, we have regional CISO council bowls at all of our events, at our summits, at reinvent, at reinforce, and various other events that we have. We are always careful to meet with, uh, with CISOs, um, and gather data from them on what's keeping them up at night. Security is, uh, job one at aws, that's our motto, right?
We take it very, very seriously. And there are basically three things that, um, CISOs talk to us about or, or that have emerged as themes. And, and you, me, one of the, and you already mentioned is visibility, um, with the, uh, you know, we always used to joke around about this, um, that look, there's the promise of all of these distributed architectures and this vast amount of space in the cloud that you can start to build your dream applications on and do all kinds of really, really cool things, right?
And we love that. But what keeps the CISO up is, well, we've just traded, um, all of that, uh, that potential, right? Um, or the, or the ability to be creative within the cloud for just increased complexity from my point of view, right?
I now have, I used to have a single VM that I had to be concerned about OnPrem, and now I have all these HTTP calls between all these microservices, you know, thousands and thousands of microservices that have to be worried about, and I've never even heard of a microservices firewall, right? I don't even know what that isity of the cloud, right? That we Said at the very, that's exactly it, which is, that's exactly, it exactly is all.
Yeah. And so, so and so, it is this, this key concept of visibility having, uh, because you can't protect what you, what you can't see, or what you can't, what you don't know exists, right? In your operating environment, that is still the number one concern of all CISOs, is I do not understand my IT landscape the way that I should, right?
I do not understand how many, uh, applications are running, uh, in my, my corporations, uh, IT landscape. I don't know how well protected those things are. I don't know how much rogue it is going on and so on and so forth.
And I need control and governance and visibility around that stuff just so that I can see it mapped out accurately and dynamically updated at the speed of the cloud, right? So again, as you're scaling up workloads, as you're scaling them down, as you're, uh, uh, you know, opening or, or, um, producing apps in new regions and so on and so forth, CISOs need see that. So one of the things that we do at AWS is we talk to CISOs about, we have, uh, a lots of capabilities around helping you do that.
And if you want to utilize a third party like cystic, there's an API that CYSTIC can use, they can take all of our telemetry, dump it into your platform, and then you can go and say, well, here's a multi-cloud, uh, customer, and they also do some hybrid, and you can also collapse that information into a single point of view for the CIO, the ciso and any other stakeholder that needs to have that sort of information. So that's the, that's the visibility piece, right? The other pieces are, they're very, very worried about two things, active attacks, and we sort of talked about that especially, you know, generative AI stuff that's on the horizon.
They can't even think about that because they're dealing with what's happening today. Um, and so their detection and response capabilities need to be really, really good. And again, as we're talking about cloud, the cloud operating model and cloud instances with the, uh, the dynamism and the ability to scale up and scale down the networking pieces along with the endpoint pieces and so on and so forth, um, tooling and services have to be available to these CISOs to allow them to basically run detection work on that stuff.
Let's say they already have visibility, now they gotta make sure that they have a tool that can at attach, be attached to all those VMs, containers, serverless instances, and, uh, microservices, architectures on containers, and so on and so forth. The networking pieces, the database pieces and storage pieces to make sure that all of those points of, of entry or potential malicious activity can be accounted for detected. And then, and this is where the third piece is dorm, what I call dormant vulnerabilities.
Let's say that after the detection has happened, it's a real-time detection. It's happening really, really great. Now, these CISOs and security analysts are faced with hundreds of vulnerabilities, sometimes thousands of vulnerabilities in the operating environment, and they're like, look, we know these things are there.
We just don't know how to fix them. Or we're afraid to fix them because we're thinking we're gonna bring down the business. And so, CISOs know by and large that they have lots of vulnerabilities that are running in their operating environments.
'cause the detection work's already been done. What they really need help with is how do I surface the vulnerabilities that really matter? How do I understand the dependencies associated with those vulnerabilities?
And then how can I patch that with confidence, keep the bill, the business resilient and performance while security kind of is the, the underlying hero, right? Of, of that whole process. Awesome.
Thank you. Yeah. Um, on that note, I think let's talk about threat detection response, which you mentioned in the cloud.
Yeah. Yeah. So, so, so that's, yeah, that's what I was gonna, I was actually gonna try to dovetail into that Crystal.
I'm glad you brought that up. Um, you know that it's incredibly important for our customers. I just gave you the sort of the CISO data in a way it's more of an anecdote, but we do have the data that supports it.
Why do you think that, um, or how do you feel about real time detection response for cloud security? Um, and I would love, I would love assisted sort of like flavor around this as well, right? Yeah, sure.
Uh, so in the cloud, uh, your threat detection and response has to be real time. Um, again, our threat research team is trying to stay on top of this. We found an attack last year that went from initial access to stealing proprietary data, not crypto miners or DDoS or anything like that.
They stole data from the victim in under five minutes. So you don't have time to run log queries. If you think something is happening, you need to be alerted right away.
Um, with that attack. And some of our other findings, SIG came up with a benchmark for threat detection in response in the cloud, it's called 5 5 5, it's five seconds to detect, five minutes to investigate or correlate data and five minutes to respond. Um, Scarlet, I, like I said, under five minutes, we're trying to give you a 10 minute timeline, but attackers are fast in the cloud.
Like we said earlier, they know the lay of the land already. Um, sometimes they don't even care to hide. They know what API calls they need to run so they can hit it and move laterally.
And now you have to try to go find where they went. Um, they can move from an EC2 cluster to Kubernetes and vice versa, just in a couple seconds. Um, so now you're trying to track them down.
Uh, realtime threat detection is imperative to the same. Yeah, And Go ahead. Yeah, and Crystal, what I would add onto that, and, and this is why I especially like, uh, Systa, is, um, companies are looking for ways to not only do realtime detection, but they don't want to then have to deal with 12, 15, 20 different tools and looking at, okay, well I have my, IM platform over here and I have my vulnerability detection platform over here, and so on and so forth, right?
What they're looking at is, can we simplify this into a single SaaS platform that then consolidates all of these various tools, right? Some of which speak to each other, some of which we need to take a, a control plane from another partner or potentially AWS in order to correlate all this information or maybe send it into a SIM platform. But as you said, SIM platform does not necessarily give you enough time.
We've had many, many companies try to lift and shift their SIM platforms, and they're just like, this doesn't work for cloud operating model at all. We've just taken what we did on-Prem for 20 years. That doesn't work what for what we're doing for the cloud.
And so they, they love the, the fact that we can, uh, you know, take all of these disparate, uh, tools and different security functions and actually have it consolidated into a single viewpoint, a single SaaS platform. So that's number one. The second thing is, and this, this goes along with sort of the distributed model and innovation, um, you know, high performing companies with, with apps that, that are really competitive.
They have small teams, right? That are doing, um, these small updates to, to the apps and so on and so forth. And for the small teams to actually have ownership of the security features.
Now, whether that's an app sec shift, left thing, or in the runtime environment for that, those particular components, um, having those developers have access, um, and have what I would consider to be human readable, uh, understanding, uh, of security and compliance issues from both the left and the right side is extremely important, right? It's a decentralized way. Um, we're, we're talking about centralizing or consolidating the security tooling, but the opposite is happening in terms of how the information is being able to be used very, very quickly by the teams that matter.
And so, cnet platforms like CYSTIC typically very much empower small teams that are, that are distributed to have the power to understand and take action when it comes to, uh, security and remediation. Yep. And so that's a, that's a really important thing, especially in a cloud operating environment where again, you might not be able to wait for centralized response to something that would be better suited by this person who built it and owns it, actually applying their knowledge to it.
Exactly. So, like we said, real time detection, initially, the data correlation needs to be automated. Trying to gather that information in the intel relating to a potential attack in regards to the users, if there were failed compliance or posture policies, um, and any of your detection alerts.
And then also, if you have the capacity, automating the response action as well. If you're confident, then you can do something like that as well to perhaps pause the vulnerable container. Um, you can stop the workload too if you want, although that can sometimes, that's right.
Unplanned downtime. Um, but there are options that you have. You can build out playbooks, um, and know exactly what your automated systems are capable of doing and can do in the event of an detection alert.
Absolutely. Right. Alright, I'm going to move us on.
Um, so next I want to ask you, um, visibility and response again. Uh, what strategies can organizations employ to improve visibility in their cloud environments? I think we kind of already touched on this, but if there's anything else that you wanna add on visibility, we can do that.
Um, look, here's the, here's the thing about visibility. I mean, vis, we could spend an entire, uh, 45 minutes plus probably entire series of webinars on just visibility, right? Yeah.
Network visibility, endpoint visibility, you name it. Visibility, everybody's perspective, absolutely everyone's perspective. Um, I, I am, uh, you know, I've been around the block, so to speak, right?
In, in the industry. And I remember when, you know, our first, or my first, uh, you know, introduction to CMDB was, you know, I was presented with a spreadsheet, static spreadsheet that was missing about 75 of percent of the information, um, over what the IT landscape actually looked like. And then the question was, well, how do we update this thing?
And everyone was scratching their heads and they're like, well, this is probably as good as it gets. Um, flash forward to today where, you know, we've gone through kind of thinking around, well, what could the next gen CMDB be, be like? And, and what it does is basically eliminates this concept of CMDB altogether.
And what it presents to us is a cloud-based dynamic representation of what's happening in your IT landscape, especially obviously when it comes to cloud, multi-cloud, and then attaching hybrid components onto that particular view. And so, um, you know, utilizing tools, uh, from your cloud providers like AWS that allow you to do that, um, and utilizing third party technologies that can help extend from a single cloud to multiple clouds into hybrid is extraordinarily important. Now, that is just the visibility around the big things, right?
You have databases, you have storage, you have networking, exactly. You have obviously your apps and so on and so forth. What's happening now, and Crystal, you may know a lot more about this given your history, but you know, this idea of, um, you know, a, uh, a bill of materials for software or software bill of materials is now going to be a mandate coming up that really says, well, yes, I'm glad that you identified this application and you, you identified this database, but now we want to double click on your application and figure out what the software supply chain looks like that actually constitutes that application.
And so this is gonna get even more complex because it's not, it's going to be, you're gonna have a level one, and then you're gonna have a level two and level three that you need to be responsible for. And this has obviously, uh, implications for security and compliance, right? You, you're gonna wanna understand that if there's a vulnerable component in your, um, uh, in your application and it's been identified right as the fall and out in the, out in the wild, um, you can easily determine like, okay, I know that, that, I know that that is something that's important because it's just part of my software bill of material.
It's literally in the list of ingredients that constitute my, my application. So it's gonna get even more, this, this idea of visibility is gonna get even more sophisticated, I think, um, in, in the relatively near future, right? Yeah.
Um, yeah. Um, just real quick, I know we're running out of, we're running close to time, so I can get through this quickly, but the visibility and response, in my opinion, all comes down to prioritization. Um, I've seen environments that have tens of thousands of vulnerabilities when you first open up the hood and look underneath.
Yeah. Um, but most of them don't matter. Either they're not in production or it's a low vulnerability, it's not being exploited.
Um, so there's various ways that you can prioritize what truly matters, what's actually running in production, and what could truly hurt, um, if you were, where, where the breach risks might actually lie. Um, so I think that runtime enhances that kind of visibility and prioritizes what you need to fix first and foremost. Um, and that's an incredibly important and powerful tool for your threat detection response capabilities.
Yeah. And Crystal, I mean, that echoes what I, I talked about earlier with the, with the CISO feedback that we get, it, it really is, you know, they know they have a bunch of vulnerabilities. I don't know if I did a good enough job explaining what you just explained, which is a lot of them are benign, right?
A lot of them can, uh, they can coexist in a onetime environment with the application and they're gonna be just fine. What they wanna figure out though is what are the non benign or malignant, malignant ones? How malignant is this?
How fast do I have to move on it? And then what are all the critical dependencies that are attached to that particular, let's call it an endpoint, a malignant endpoint that needs to be patched? All right, I'm gonna move that song now.
Okay. Do some more of this support role for people instead of just trying to scare them with what the cloud landscape looks like right now. Um, so I'm got a couple questions that I'm gonna throw at you back to back first.
Why is it essential for organizations to adopt a new mindset in cloud security? And then alongside that, what kind of practical steps can they take, um, to cultivate continuous learning and adoption culture for a cloud security? Yeah, you know, I think we, we started off this conversation talking about, um, innovation, right?
Um, whether it's just generally how you can use the cloud to be more innovative, you said that's your favorite term. I believe we talked about generative AI and how generative AI can help in some of those innovation tasks right now, uh, today, those use cases might be slightly limited, um, from a business context. Um, but they're certainly growing in, out, in, in artistic context in terms of producing movies and producing music.
Um, you know, there's music that I've seen that I did not know was pro, or I've heard that I did not know was produced by an AI engine. And I'm like, wow, wow. It is very eerie the type of creativity that's coming out of these things or innovation that's coming out of these particular engines.
So in terms of innovation, that's what businesses are around for, right? Um, businesses have to innovate, um, in order to grow, uh, they have to grow in order to provide returns and so on and so forth. And to delight their customers, we, we know that story backwards and forwards.
Um, security has to keep up with the level of innovation, right? In other words, um, they can't be a blocker to innovation. Uh, and so when you have this sort of natural tension between developers or what we'll call the creative class from a corporate perspective, and then you have sort of, Hey, I call them the Lamborghini or the Porsche crowd, or that's what we, the term that we use, you wanna go fast, you know, they wanna do that.
And then you have the Volvo crowd, right? You have all the compliance specialists, you have the procurement folks that worry about cost, right? And the CFO that's worried about cost.
How much does it cost to actually do all this cool stuff? Are the seat belts locking in place correctly? Um, are the tires pumped up to the, the right pressure that they're supposed to be pumped up to and so on and so forth.
There's this natural tension, right, that has to, has to exist between the folks to make sure that things are safe and secure. Then the folks that are innovating and delighting the crowd, if you'll, right? And so, um, the new mindset really has to be that security and compliance has to be able to move at the speed of the innovation.
They can't clip the innovation or they can't clip it too severely. Otherwise, the reason for being for that business essentially gets truncated or gets get, gets cut off, right? Mm-Hmm.
And so by utilizing not only cloud operating environments and cloud infrastructure, but the services that have been built around it, I know we, this was not an exercise to talk about, you know, the dozens of tools, security and compliance tools that AWS has, uh, available, or the vast ecosystem of partners that do incredible things, right? That literally thousands of partners, some of them hyper specialized into LLM, vulnerability detection, all the way to the statistics of the world that are doing, you know, cloud native application protection at large for, for enterprise customers. Um, you have to be able to introduce a, a tooling, uh, solution, a process piece, and a people and culture piece that supports your company's, uh, ability to innovate.
Um, I, I'm, I'm not gonna get into the process piece 'cause that's really a lot of stuff, but just on the culture piece really quickly, you know, at Amazon we have what we call culture of security. Um, and we bring in a lot of CISOs and a lot of board of directors of companies, and we actually talk to them about how Amazon runs security. Um, and as I mentioned, security is job one for not only Amazon, but on behalf of our customers, we wanna make sure that they're secure.
Um, and whenever an issue comes up, that is A-C-A-C-E-O level issue from a security perspective. So the security team at Amazon reports directly into the CEO. So Steve Schmidt, our, our, our CISO reports directly into Andy chassis.
And these are, um, conversations that they're having on a weekly basis on the security status of the entire company. Um, when issues come up, there is a very defined process with high level executive folks that are involved, and they literally are not shutting down until that issue is resolved. And then there is a correction of error document that we call a process that gets in place where we figure out, well, okay, it happened, but how does that not happen?
Again, it is an enormously disciplined and very, very conscientious approach to security that says security is here right alongside how the business performs. And unless you have security, right, your performance is, is always gonna be at risk. Um, and then that has issues obviously for things like resiliency.
You could have down massive downtime and so on and so forth. Yep. Um, one with teaching around culture of security, we have an an enormous amount of trainings and certifications.
You can go to the AWS website, you can go to our training and certification page, and you can actually look at all of the cloud related, uh, security training, uh, that you can get that really taps into a lot of the things that we talked about today. Some of which are free, right? Some of which are free.
Absolutely. That is correct. If You wanna learn more about cloud or generative AI or whatever you have there, then that's a great place to start.
Yeah, Correct, correct. And then, um, let me ask you potentially a final question. We'll see how much time we have left, but, um, how can organizations leverage cloud native tools like sig, um, and AWS combined for better security?
Uh, it's a beautiful partnership obviously, for cloud environments first, but that's regardless of whether or not it's a single cloud, multi-cloud or hybrid, you're in the process of moving over or part of your business requires remaining on-premise. Um, you need tools that can handle the breadth and the complexity, uh, the ephemerality of the cloud, things constantly moving, changing, and scaling up and down all the time. Um, so without proper visibility, there's unknown and unseen vulnerabilities, um, and attacker movement within these hybrid environments, and that's where SIG and our CNA can really come into play and support the security of your AWS plus environment that you're maintaining.
Um, our CNAP also encourages the democratization of security for all teams in your organization. Um, like you had just said, security culture is incredibly important. It doesn't matter what your job is within an organization.
Um, so being able to have a single platform that is available to more than just your security team is so incredibly important. Uh, your security team can use a C app, your developers can look and see what's going on. Your legal team could even go and review compliance posture and make sure that your compliance policies are all at a hundred percent and there's no failures.
Um, one thing I'd like to say though is obviously just make sure that all of these user accounts have the appropriate permissions and need to know access. That's right. You don't, you don't need your lawyers to have, you know, admin access where they could go and break one of your workloads.
Um, but having one single dashboard for several people across your organization to be able to log in and support a more secure business, I think is incredibly important. Excellent. All right, so real quick key takeaways.
Do you have anything else that you would like to add, Matt, before we say goodbye? I, I think I just gave my key takeaway by the way, um, which is that security needs to be able to move at the speed and pace of the business. Um, and you know, again, with, uh, unlimited opportunities for innovation, um, comes the need to make sure that all of those things remain safe, secure, compliant, um, and you don't want to do it using an old school way that you learn from your on-prem environment where you have the luxury of time.
That's really what it comes down to is time, right? Um, we no longer have the time that we had when we were dealing with just on-prem environments. Um, we want to scale things quickly, we wanna take advantage of dynamism.
Um, and those are fast paced things that are happening. And having a security practice and having security, a security platform that can keep up with, with the speed and the dynamism, um, really should be job number one for any security practice at any company that's, uh, that's in the business today that has any sort of digital assets. Um, whether, you know, you plan on being an AWS customer or you are an existing AWS customer, or you're a partial customer in utilizing multi-cloud, uh, environments.
Yeah, there are some too that are, I've heard people say that their companies are on-prem first, but there's no getting away from the cloud or digital assets these days. So they realize that there are still some parts of their business that touch the cloud. Um, I think, like I said, innovation is wonderful.
Um, and you need to move fast to keep up, but not too fast because you need to keep security at the forefront. You don't need an expensive or huge security stack. You just need a strong security to be able to reduce your risk and keep your business safe.
Um, and like I said at the beginning, we're in the middle of the tech revolution, so just embrace the innovation. We're all in this together. I know at SIG we're a bunch of security nerds.
We're all engineer based for the most part. Um, AWS probably is too. Um, but we love our Customers.
We have a lot of, we have, we have a, we have quite a few of those as well. Yes. But we love helping and sharing and that's what we're here for.
Um, it's all about a cybersecurity defense, uh, and we're all fighting the same fight and playing for the same team. Um, we all wanna keep ourselves safe and secure. Alright, With that.
Fantastic. Thanks. If you don't have anything else, Matt, thank you for joining me.
Um, thank you Textron for having us today for this keynote speech. Um, I appreciate you all in the audience for taking the time to listen. And if there's any additional questions or you'd like some resources or support from either SIG or AWS, please reach out and let us know.
And I hope you guys enjoy the rest of this conference.