Advancing ASPM – Jacob Garrison, Bionic
Alan Shimel talks with Jacob Garrison, security researcher at Bionic, about how Bionic advances its ASPM platform with Bionic Signals and Business Risk Scoring.
Transcript
This is Textron tv. Hey everyone, welcome back to Textron tv. I've got a company, well, I've been aware of this company for a while.
I don't know if you have, they, uh, they emerged outta stealth back. I, I, it was during C V I D I guess, but, um, or maybe right before, but let me introduce you to Jacob. He'll tell us Jacob Garrison.
Jacob is with a company called Bionic. He's a security researcher there. Hey Jacob, welcome to Techstrong tv.
Hey Alan, thanks for having me today. It's a pleasure to have you on. So, Jacob, um, you know, before we jump into Bionic and everything, let's find out a little bit about you, if you wouldn't mind share with our audience, kind of a little bit of your own life journey.
Sure, absolutely. So, my name's Jacob, and like Alan mentioned, I'm currently working at Bionic, but prior to becoming a re or a security researcher at Bionic, I was working as a software engineer. And so I spent a lot of time building software and then that got me inspired to learn, you know, how do you protect that software?
And that has brought me to where I am today. Very cool. Very cool.
Uh, and so you're with Bionic. Well, you know what, let's hear a little bit about the bionic story and then maybe how you came to join Bionic. Sure, absolutely.
So to talk about Bionic as a company, um, we emerged from stealth in December of 2020. And the whole idea was to help these security teams understand what's going on in their applications and how they can best secure them. And so the entire platform is built on understanding application architecture and then leveraging those insights to make an actionable items and, and the most efficient items to improve the overall security posture.
And so as a company, they were working to define a category application security, posture management, which is A S P M. And that got recognized by Gartner earlier this year. So it's been a long journey to establish that as a category, and we've seen a lot of traction major companies like J L l Transamerica Inspire Brands, uh, Freddie Mac and amis.
So it's, it's been a really cool journey. And then the reason I joined specifically was I had been architecting this application in my past role and I was trying to explain to these new developers how it worked. And I was feeling frustrated of, of how complicated it was to explain the architecture and help everybody understand.
And then I saw Bionics technology and I saw how easily they were able to demonstrate the architecture of these applications, show all of the dependencies, and show all of the impact. And once I saw that, I, I gave 'em a call and asked if I could join because it seemed like a really relevant problem. Really.
What a great story. So you didn't respond to like the, we're hiring or anything like that? You said, you know what?
This company is solving the problem that I, myself see, and I want to be part of it. Exactly. Yeah.
It, you know, they were pretty young when I joined and I wanted to be a part of the journey. I wanted to watch it grow. And, and I've been fortunate enough to watch it grow a lot during my time.
Excellent. You know, Jacob, I, I've done my share of startups over the years, and it's a very interesting play when you are defining a new category, right? There's, there's been books written about this, right?
Do you want to be the missionary who kind of defines the category, but then recognize that sometimes, you know, someone can come in behind you and kinda, you know, you gotta hack your way through the jungle and then someone walks pretty easily down through the path you've cut for them, right? And, and has an easier go of it. But there's still nothing like being the, the company, you know, that defined the category.
What, you know, in terms of this category defining role, you know, what is by, how is bionic getting the word out there? I mean, is it just kinda word of mouth is when you're speaking to developers and cyber people, they're saying, yeah, no, this, this is exactly what I'm looking for. We have it, you know, much like your own personal experience.
Yeah. So I think one of the things that has really helped make Bionic gain traction is our unique approach to how we do our analysis and then how we provide insights. So our technology, the foundation of it is built on analyzing and recreating the architecture of applications.
So anything that's possible in the code, any possible execution shows up in the map. And then from that map, we're able to layer on insights to help people understand what's going on. Whereas for a lot of other companies, the maps that they have, the architecture diagrams, the data flows, they have to be generated manually.
And it's very, very challenging then to layer on insights in a, in an accurate and actionable way. Especially as, as these applications are updated over time. And so the, the very nature of the foundation of the technology is what has been really the, the selling point for the company because people can immediately understand, hey, that's visibility I don't have, and the power of that visibility is immense.
So it, you know, certainly it's been interesting watching the market get educated on this new approach cuz it is a, uh, you know, a fundamentally new approach to solving this problem. But once people understand what we're doing, they tend to be pretty excited about the capabilities. Interesting.
Very cool. Um, and, you know, your role is, let's talk a little bit about you as security researcher. Explain a little bit about what you're doing there, Jacob.
Sure. Yeah. So I, my role is sort of divided into two functions.
Um, one is to look at how applications are being attacked today and then go in and recreate, uh, recreate hacks, look for new ways to exploit existing applications and be, you know, hands-on in the code, uh, or, or in these security tools, trying to figure out how to break things. But then it goes on to the second point, which is I also try to create educational content to help application security teams and developers understand what's trending and how their applications are being hacked and how they can better defend them. And so I get to leverage the, you know, my practitioner experience and my hands-on research to then go and create, uh, educational material to help companies be better prepared to avoid these attacks, um, and to architect things more safely in the first place.
Got it. Excellent. Um, let I, if you don't mind, you know, for our audience out here, let's talk a little bit about the on-ramp to Bionic.
If for a typical user cus you know, potential customer, how, how do, how do folks engage here? What do they, how? Like what's the path look like?
Yeah, so typically what happens is, you know, we'll, we'll come into contact with a company that's interested in looking at the technology, and what they need to do is decide which application they want to be analyzed as, as an initial proof of concept or, or proof of, uh, proof of value for the application. So they say, Hey, I want you to analyze this business application and these are the insights or the, the concerns that I have with it. So typically they pick something that either they know really, really well and they want to validate the technology works, or they don't really know what's going on and they want insight into what application they're trying to secure.
And so once that's decided, it's a really quick collection process that we have. We have an agent list collection process, and so typically it'll be, you know, a cloud-based application. Um, we'll, we'll run the analysis.
It doesn't take very long to set up, you know, um, it's one, typically we set a one hour schedule, and then once that collection runs, they'll get the map of their application and they can see, uh, pretty quickly all of their architecture as well as the threats to that architecture layered on top. So it's a pretty short engagement. You know, once all the paperwork is signed, companies are able to be up and running pretty quickly, and then they can go through, we'll give them actionable insights, we'll help them prioritize risks to that application.
And if they like what they see and they wanna spread it across the rest of their software, um, you know, then that's typically when they become a customer. But the p the whole process is, is pretty painless, um, and pretty easy for all the people that I've seen so far. Love it.
Excellent. You know, I don't think we mentioned the website though, did we? Uh, I don't think so.
ai. com, it'll take you somewhere else. Maybe Lindsey Wagner's homepage or something.
Right. Um, so Jacob, let, let's turn now though to some recent news. A as you mentioned, Ana came outta stealth December, 2020, so about two and a half years ago now.
And, um, you guys recently did kind of a major upgrade, huh? Yeah. So what I'm really excited to announce is our new feature launches.
So there's bionic signals and bionic business risk scoring. Well to tell. Okay, perfect.
So bionic signals to start there, it's importing signals from other popular security tools. So what we have available today, uh, generally available is importing from Sonotype and from Wiz. So we're able to import signals from other popular security tools that manage different parts of the security lifecycle or security development, and we can import those tools, findings into our platform to give more insights across the architecture.
And then for business risk scoring, where, because we're looking at the architecture, we understand the attack vectors where there's room for lateral movement, which parts of the application are accessible, and then exploitable from the outside and the business impact should, should a threat actually execute, should someone be able to cause a data breach. Um, we're able to show, you know, the, the blast radius or the business impact, um, you and we create our risk score based on the potential impact of that attack. Love it.
That's pretty cool. Now, you know, one thing we have plenty of insecurity is, uh, I'm looking for the right word, schemas, if you will, to, to measure risk, right? We, we have, you know, vulnerabilities, we, we, we obviously have the nist, uh, you know, critical major minor kind of stuff.
Um, how does the bionic sort of risk measurement or criticality measurement work with, or maybe it doesn't, some of these industry-wide kind of standards? Yeah, great question. And, and to your point, there's a lot of ways to measure risk and a lot of them result in a lot of noise where there's a ton of alerts that can't possibly be handled by development teams and, and they struggle to work through their backlog of threats.
And so bionic's risk scoring really relies on the architecture. And, and to give an example, we work with a financial industry's customer and, and in scanning their architecture and scanning their applications, they had, I think it was 900 individual services in their apps, 2000 APIs, a lot of databases containing sensitive data, and there were 120,000 security alerts, things to potentially be investigated. But using bionics risk scoring, it was narrowed down to 14 things that were business critical.
And so the way they were defined as business critical is there is a path, there's an access path to this service. So an attacker could get in, you know, whether it's internet facing or through some other means, and then it's accessing sensitive data. So for this particular customer, it would be data that falls within P C I DSS scope, you know, a lot of credit information, payment information, and we are able to look at that access path, the sensitive data, and these known security threats.
So because we're looking at industry standard things like CVEs or vulnerabilities, and then especially with bionic signals importing these risks from other tools, we can figure out where there are, there are these, uh, risks that are accessible. And then the blast radius and combining all of those things together allows us to really reduce the amount of noise and allow these security teams to focus on the threats that are most critical to their business, the ones that are gonna have the largest impact, and when they resolve them, the greatest overall reduction in risk. Excellent.
Right. Excellent. All right.
There were two major things in the release. Yes, I did. What was the next one?
Yeah, so the risk scoring and the bionic signals. Um, and so we've, we've talked about our risk scoring capabilities and, and the way that that gets defined is on a scale from zero to a hundred, and it's relative to the other risks in the platform. And so we're importing a lot of the industry standard data.
And then, like I had mentioned, we're using this architecture of the applications to go and, and define which things need to be prioritized. And then we'll also give you an actionable playbook of which things present the most risk, where you should start, and then show you how your overall risk posture will reduce as you work through the highest priority items. And then for bionic, for the bionic signal side, we're able to, you know, when, when a, when a, a customer has a security tool they use, so for today we're announcing Sonotype and Wiz, if they use one of those tools, we can import those tools findings.
So they're able to then look exactly where those findings exist in their architecture. And that allows bionic to both provide an even more tailored risk score, and it allows the customer to then go through and understand which alerts from those tools they want to manage first are most important. And so the whole idea is to give them this comprehensive view of what their risk posture is, as well as automatically prioritizing where they should spend their efforts, where they're going to have the most impact on the system.
Got it. Excellent, man. Um, the, the new, the, the updates to the platform are out and available today, Jacob.
So they will be available on Tuesday, June 27th. By the time that people see this, they should be out today. I was just gonna say yes.
So we, we, we, we recorded this Monday, the 26th, but it probably won't be until maybe Thursday. I bet. So by the time people see this, it's out.
Perfect. Well then, yes, they're available today. All right.
ai and, and they're all part of that in there as well. Absolutely. Yeah.
And so there's a, uh, they'll be available on the website if you wanna look further, and then if you want to contact us, you can also do that through the website as well. All right. Hey, Jacob, I want to thank you for coming on Text on TV today and getting us a little bit smart about Bionic and what it does and, and some of the new features and the, the update to the platform, continued success on making it a great company.
Matt, thank you. I really appreciate the time today, Alan, it was great speaking with you. I appreciate it.
ai, check it out, including the new updated platform. Lots of good stuff going on there. We're gonna take a break here on Techstrong tv.
We'll be back in a moment.