Advancing DevSecOps Adoption – Raj Datta, oak9
Oak9 CEO Raj Datta explains how $8M in additional funding will be used to advance DevSecOps adoption.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Raj's Dada whose CEO for Oak nine. They just raised eight million dollars to help address. All our security is code issues Raj.
Welcome the show. Thanks Mike. Appreciate you having me on.
We've been talking about Security's code and shift left and a lot of the issues that emerged with infrastructures code for a while. Why haven't we solved this problem yet? What makes your approach different?
Yeah. I mean that that's really what Oak nine is focused in on and just a little bit of background of what nine does is we're a cloud native security platform. Essentially.
What we do is we really hone in on Focus. We focusing on securing infrastructure as code and so, you know just for the audience members like I'm sure you're familiar with the scriptures code, but just from a very high level, you know, the easiest way I like to describe code is you know, if you go back about 10 years or so and you know, if developers wanted to create an application you have to put in an order you'd have to get a service stood up. You have to get networking.
You have to get storage Etc you fast forward to today what's happened is all of that has been codified. That's a lot of developers to crank out instructors code at lightning speed, you know. The likes of a hashic corpse terraform for example has been widely adopted.
It's not a 12 billion dollar market out there for them. And what we've seen is the rise of the developers having the ability to deploy instructor's code at lightning speed. Now what's happened is you know, and everyone's aware of this is there's a massive shortage of security Engineers.
I was just reading last night, but there's about 38% unfilled security engineering roles that are out there and you know security teams are unable to keep up with the speed of infrastructure's code. And that's really where Oak nine comes in and really our Focus has been to help organizations really instead of you know, the buzzword out there is shift left, but we believe in starting left. So if you really, you know bake in your security posture at the very beginning of your development process throughout the cicd pipeline, we're able to keep it secure throughout the process and then once you go and deploy the product you're already secure at that point and so that's what makes you know, okay.
I'm very very different than you know, many of the companies that are out there today. It seems like there's a bit of a debate about shifting left versus leaning left and shifting left is like we're gonna ask developers to take care of all this stuff and you know, they may or may not have the time or the skills and it will be uneven versus leaning left is we invent things into the ci/cd pipeline and devops Pipeline and we automate a lot of that stuff on behalf of developers. So which you know, how far left are we gonna go to you think that well, you know Oak nine starts at the very beginning right?
So we truly are starting left. So as you're designing the IAC, you know, whichever language you're using and then checking in the code. That's when Oak nine gets activated and our product.
We've kept it very very simple because we do, you know, we're aware that developers don't want to be Security Professionals and that's not what they signed up for. But what we do is we ask, you know, four or five simple questions with regards to the application what type of compliance needs they'll have. Where is the data gonna be focus is going external as an internal very very simple questions.
And once we do that when ends up happening is, you know, Our engine kicks off and the developers can go into their own workflow continue to develop in the platform that they see that they use today. And what we're doing is we're working in the background and so very few times will the developers actually come into our platform. It's also, you know a lot what we also allow is Security Professionals to actually tailor the security guardrails that are required within our platform and then it's Off to the Races.
So it's automated in the background. So people aren't thinking that they have to go in checking at Oak nine every single time the very first time actually check it in and the design phase that engine is running in the background. All right, what will be the role of Security Professionals in this Brave new shift left world because you know, we've had a divide between developers and security folks forever today.
Is that going to get any better as a result of all this? I I see the Divide every day my two other co-founders one developer by nature and want security by Nature so I can't see the Divide on it regular basis, but that's you know, that's really why we build this product the way we did is, you know, we're we're allowing security Engineers because we know like throughout the development process security needs are gonna change and what we allow Security Professionals to do is actually update that with what we call our studious code blueprints so you can make live updates to the development workflow without disrupting with the developers doing Do you think as we go along here that one of the issues that we're dealing with is we haven't abled developers in the name of productivity to use these tools to provision and configure infrastructure mainly in the cloud but by and large, there's just a raft of misconfiguration. So, um, you know have we reached a point where this is going to become a crisis?
Um, you know, there are some companies that are rapidly developed deploying IC and really checking a very small percentage of that and what's going to happen is, you know, the technical debt keeps building up and building up and that's where you know, we feel very strongly that if we're able to catch the security drift prior to deployment that's where you know, we I was reading as a stat that IBM had produced is like it's a hundred X more expensive to catch that security drip post deployment versus if you do it during the development process and so, you know by integrating into a product like nine, we're able to stop allow that additional exposure that's being created every single step of the development process. What's your best advice to organizations about how to go about doing this? Because frequently, you know senior managers will come down and they'll give the sermon but everybody kind of stands around after that and says, you know, well, that was nice but how do we go do that?
So is there some best practices or some success here that you've seen people implement we have you know, our goal has been to make us very frictionless and very easy to use. And you know, that's what we've really spent the past two and a half years doing is just honing in on a product that is very easy to use. So, you know, like I mentioned our goal is not to have you know developers to become Security Experts by any means and so, you know advice to organizations is you know, as you're starting to look at the adoption of IAC, which you know, most companies are it's just, you know, some companies are adopting a lot faster than other companies.
It's just, you know, the whole digital transformation story that you're very aware of and so, you know, some companies have made a decision that all their new applications will be developed in the cloud using IAC, you know, my advice to any of those companies is, you know, take a look at you know, a product like Oak nine because you can really bake in security at the very beginning of your development process versus thinking about it building up all the security debt and then having to worry about it posted. Do you think that the Biden administration's executive order is helping this whole situation. It seems like it's very focused on federal agencies, but will Enterprises kind of follow suit?
I do believe Enterprises will follow suit, you know, as larger government agencies continue to bake insecurity make that a, you know, a high priority for them other organizations are also realizing that you know with all the security threats that have happened over the past couple years, especially, you know during covid we saw a huge Spike during that time is you know now is the time for Enterprises to take a harder look at at security and what we're seeing is we're talking to companies is you know, even though you know, the Market's a little bit Rocky right now security budgets are still holding very strong just because of the need to make sure that you know, their environment is fully secure. How did we get to this situation? I mean back in the day there was always a cybersecurity review of stuff deployed on premise and then we decided to like Chuck that essentially when we moved to the cloud.
Are we developing applications too fast right now or is this unsafe in any speed or can we keep it this pace and make things more secure? Yeah, I mean, that's a great Point whether you bring up is you know, what we've seen is, you know throughout you know, the adoption of the cloud developers have been given all the all the different products and tools in the world to go as fast as possible. Unfortunately what's happened is during this time Security Professionals have not gotten the same type of same type of love out there, right?
They haven't gotten the same type of Technologies to help them support this fast adoption. Now, I don't think you know, if you're to talk to any developer, I don't think anyone would say, you know slow down my development process or we're developing, you know, we're not we're developing to slow. I mean everyone wants to you know develop as fast as possible a couple reasons behind that.
I mean you look at the market today with invention of of SAS products out there. It's a very it's become very very competitive. You get the right developers in place you start building out the right Technologies and you can go, you know develop at the speed of light and so and it's a very competitive situation.
So it's how much technical debt do you want to take on is really the question and we talk to a lot of one on Out companies that they're so focuses to get their product out to Market and security is more of a secondary notion, but once you know cut their customers are beginning to ask them for security guardrails and things like that. That's when we're having, you know, pretty healthy discussions amongst our companies because they're realizing that there's a there's a definite need to bake in the security at the very beginning and that's where we're seeing a lot more adoption. Do you think at some point I mean you mentioned that we have this chronic shortage of Security Professionals that can't keep Pace with the app Dev projects.
But do you think that AI May someday save us from ourselves and how smart can we get with all this stuff? Yeah. I mean, you know Products, you know such as ours that have intelligent learning built into it, right?
So we understand that. Okay, the developer accepted this code change but decided not to do this one. So it's slowly picking up.
Right and I think AI will definitely help but you know, there's also always going to be a manual need. I mean you won't be able to automate the security engineer professional by any means because they're always being new security phenomenons that come out there. There's gonna be different types of hacks that occur out there.
So you're gonna need still some manual processes at the same time though, you lay around the AI and get you that much more secure. All right. We have been talking about devsecops for a while.
Do you think that over time we'll just go back to devops and we won't necessarily put the word second in the middle of that. It's a little cumbersome as they say and Security will just be part and parcel of everything we do. Yeah, I mean, yeah, you know devops that's multiple different buzzwords that keep floating around in the industry.
But you know the way I you know, one thing that we're seeing is actually with larger companies is they're starting to actually have in their development team security champions. Right. So these folks are really tasked with making sure that things are secure but they're more from a developer standpoint.
So it really is that devsecops Persona will we go away from that? I mean, you know at the other day if it's devops or devsecops, I think the goal for you know, all companies. It should be, you know to develop securely throughout the development process.
So you're not dealing with it at later stages of your development lifecycle. All right. Well as they say, you know from your lips to God's your hopefully this will all work out.
Hey Rush. Thanks being on the show. Appreciate it.
Thank you. All right back to you guys in the studio.