Application Security Progress Check – George Prichici, OPSWAT
George Prichici, vice president of product for OPSWAT, dives into a survey that shows where progress on application security is and is not being made at a time when cybercriminals are increasingly focused on exploiting vulnerabilities.
Transcript
This is Textron tv. Hey guys, thanks for the thrill. We're here with George Preachy who's from Ops swat, where he's vice president of product and we're talking about this new survey that they put together on the state of application security, which we all know we've been throwing a lot of money at lately, but I'm not quite sure.
We're making a lot of progress. We'll dive into it and see where we go. George, welcome to the show.
Thanks much for having you, Mike. Appreciate it. So from your perspective, what are the highlights of the survey that you guys put together and most importantly, I mean you've been around the block a couple of times, what surprised you?
Um, sure. So there were quite a few things that um, were very interesting for us as like key finance. I would say that uh, there's a huge uh, amount of people actually got a significant increase in their budget.
Like over 60%, I think 62 have like a significant increase in security budget, but in total was uh, uh, 78% actually seen an increase. So it's not just about like, hey, with inflation they got like five, 10 points. There was a even more increase so that expect that they're actually gonna go and spend on a lot more tour.
And that was the part I was a bit surprised that some of the security me that had in place were not really there. And we can discuss a bit more on that one. But I want to bring up a few more key points as well that we've seen in the uh, report.
One is there's the cloud adoption. So there's a huge movement comparing even with the report that we ran two years ago as well, for them to move to our, to cloud infrastructure or even to SaaS products. 97% of responders claim they're using already a cloud or they're looking to use a cloud and container environments uh, in the next uh, six months.
So I think that's a huge uh, increase in adoption for let's say new technologies that comes with the risk as well. And one of the things I was very unhappy to see is that there, and this is back to ops and now some of our solutions is that there's still 33% of the responders, they're not even scanning the files this with one av, the files that accepted with their portal applications. And um, that I think is uh, very unfortunate when you're looking at the majority of people that are like very concerned about file apples coming in their organization.
We're talking like 98% are concerned um, about that one. And most of the concerns are coming from um, pretty much the concerned are gonna end up with the data breach and that's kinda like 80% of the uh, responders And we settled on who's in charge of application security. Cuz I've always felt like the application side said it was the cybersecurity people and the cybersecurity people always said it was the developers.
And then, you know, as is always the case when either everybody is in responsible for something, nothing ever happens. So are we getting better at figuring out who's in charge of this thing? Um, I feel like more and more in the industry there's the shared responsibility model that's being applied and it's being used as a wild card just to like, uh, get rid of responsibility I guess.
Right? Um, so I'll, I'll put it this way, right? I think nowadays uh, most companies are product companies, right?
People that actually work even like I know oil and gas and so on, everyone has uh, web application nowadays everyone exposed support working with partners, they're exchanging files and so on and so forth. So that's the digital world we live in, right? So when it comes to like application security, we kinda like have this new department, there's like a product team and they're building products that doesn't necessarily report within it or they're not necessarily attached.
So like security teams come in and try to mandate certain things, but at the same time when it comes to like the secure S D L C, if you want for them to secure the development life cycle, not necessarily operational there, it's something they expect for the application teams to take care of it, but it's still security that comes in and mandates a couple of things. But they are more of like influencers if you want, right? Like the security architects are coming and it's like well you have this risk, identify this risk, you guys know to go need to go and patch that one or you need to go and fix that problem.
But in general it's the product saying that, well I have this limited budget that was not in my budget. Now you're telling me I need to go and spend more. I need to do it this and this and that and so on.
I need to put it on my roadmap. And then kinda like that discussion starts happening because security team is not able to be the one that is fully in charge of this. Neither is the uh, application team.
So I think each organization has a different way of structuring or even like org chart wise on how roles and possibilities are being divided. And I think that's a big of a challenge, right? Because if the single, I dunno the first point of contact between those two teams are is the ceo.
That's a problem, right? So it's hard for you if you don't have like the same goals and you're not aligned and so on. It's very hard to get even budget approval, go and spend more time on new things and so on to improve security because that is being seen as like a separate layer that comes in and tries to like pretty much I know disrupt your roadmap if you want.
And frankly I'm, again, since I'm leader of the product, I know that we have application security team that's taking care of the security D L C that is part of our team and then there's the security team that's looking at like at and so on in production, like how fast we patch that one and the push for that and so on. So I'm very familiar with the model of fortunately and unfortunately that's how you wanna put it. So one of the things that left out in me in this survey was despite our progress, which you know, we are making some progress, something like only 2% of respondents were confident in their ability to secure this or be successful.
So what's behind all that? And you know, how do we make folks a little more confident in this space? I think they're like too many horse to plug, right?
And I think that's kind of like has a security ion practitioner you're gonna look at to like okay, what are all the risks, right? And at the end day you have a huge amount of different areas you have to focus on. And even though you have an increased budget, you're gonna have to figure out how to prioritize to like take care of all that.
And most of the budget is going out of the security on different important, let's say component out of their stack. But at the same time they're trying to like start plugging some of additional holes. So I want to believe that 2% was more of like a concern on the overall uh, status or whatever you wanna call it, like the posture, security posture of the uh, application.
Not just on like hey I have uh, we didn't deploy a web application firewall, right? Because in the past was like, well our application is secure cause we have a web in front of it, therefore we take the box and so on, right? So I think that there's a lot more, I know people understand a bit more like all the risks they're seeing all the supply chain ties, they're seeing all the replication ties are happening nowadays and so on.
And they're more concerned that what they currently have in place is not good enough and they need to actually go and invest with more in that direction as well. Are expectations realistic or should we really just be focusing on how are we gonna contain the blast radius for an inevitable breach versus trying to figure out whether we're gonna defend against everything? Because as a famous emperor once said, if you're gonna defend everything, you defend nothing.
Right? And I think this is pretty much where it gets back to, right? And the, the model now in the industry is not when you're gonna uh, be hit.
It's like, uh, like if you're gonna uh, be hit is when, right? Like at the end day you need to accept that you're not gonna be able to, maybe there are the risks, you're not even aware right now depending on the organization. And again, the pace we're seeing for some organization are rushing to like go to market with uh, products and so on or like are are building new functionalities that are not fully vetted from security perspective and so on.
Those are new risks that are kind of like added uh, in without getting full buy-in probably from some of the security teams, right? And again, there's still things where security is an afterthought. So from that perspective, I think it is a matter for these teams to understand better like what they have and if there's something gonna happen, how they can contain that part.
And I think the efforts are uh, going in that direction as well because nobody has unlimit budget and go and buy let's say eight points solutions to fix each of the problems, right? And I think the second part that was definitely a movement in the industry as well is consolidation, right? People are looking more of a platform play to like have a solution that does a fairly well uh, fairly good job to cover all uh, most cases but it's not doing an excellent job on each particular problem and so on, right?
So then you to accept a couple of risks, sorry as well. I think at the end day this is kinda like what gets back to like higher ups including like ciso, it's risk management, right? Like at the end day there are certain risks you're identifying you're gonna have to prioritize based on like which are the highest ones.
And so those ones and whatever you have, if you have budget left for the smaller ones, that's what gonna go and plug those ones in as well or you've scheduled them for some other time and so on. I feel like there's also a disconnect between the folks in charge of discovering vulnerabilities and that's the security side and the developers cuz you know, across comes this list of vulnerabilities, it's usually still in a spreadsheet unfortunately, but developers look at it and then they go investigate it and then they figure out that, you know, 80% of the time at least that you know the issue at hand, that particular module code was never made into production environment in the first place. It got downloaded at some point but it's not actually running and we waste a lot of time and effort on this stuff.
So can we get smarter about what we need to defend And the code itself and production, it feels like there's this uh, left and right hand don't seem to know what they're doing Right though trust me, I'm a lot in those conversations, right? Uh, that's why I'm laughing. Uh, but at the end day I like to see it this way, right?
Um, it's your responsibility as a developer to make sure what you're building works, right? Um, and I think part of the KPIs in the past for engineering teams were to make sure you're not bringing in I know new box or regressions and so on, right? You make sure you have quality code.
Um, security was again seen as an afterthought, was seen as a separate team, a separate responsibility than their responsibility and that needs to change. And yes, I totally agree on the idea that like way too many tools out there, they're providing way too much noise right At the end they maybe, I don't know you're using a library that or a node module cause this is quite frequently seen and that node module is gonna bring another 20 different modules next to it. But you're using a small functionality that you're not gonna even touch some other library that's like three uh, levels down that has a critical form p d right?
But the end day it is bundled in your application, right? So that gets reported even though it'll be like um, uh, no risk for you cuz you're not actually using that piece of code. It's still bundled within your application and I think this is the model where you like it or not, especially if you're shipping product to your customer or if you're running in your environments and those are getting flagged, these are even like compliance regulations where you not allowed to have like critical for bids and so on, then you need to go and like justify that one get an exception or just go and replace that module.
And again, I'm going back to, and I'm not trying to make excuse for developers, I used to be an engineer and so on, but um, we are all rushing to like build as fast as we can. We're trying to reduce as many open source components as we can and for us just to add a, a little bit of the logic on top of it and so on, right? And that's where you're kind of introducing PO potentially the Trojan horse as well.
And that has been seen quite frequently in more and more supply chain attacks and so on. And this part needs to be taken a lot more serious. I agree that nobody wants to spend time on pretty much noise on false positives and so on false alarms, but at the same time there's a more, a bigger concern in the market with the supply chain attacks and this needs to be the more taken seriously it needs to be part of the engineering team's KPIs and so on.
How smart are the bad guys getting? And I'm asking the question cuz sometimes I think that, you know, we focus on vulnerabilities that are like, you know, yes this code is vulnerable if it was 2:00 AM on the third Thursday of every month. And um, meanwhile the bad guys I think sometimes laugh at us cuz they're like, you know, this is kind of trivial stuff for us, so maybe we should just be focusing on some of the fundamentals and not worrying about so many cartwheels.
Yeah, definitely there are a lot more advanced attacks out there, right? They're like zero days, they're like state sponsored actors and so and so forth, right? But they're also like three field ones that are still successful, right?
They're, they're, I dunno, as dumb as my sound type of sporting is still working. Like I can actually go and even I know copy a known library on GitHub, I know rename it a little bit, make it look like it's the original one and so on. Still some, um, impression or like let's say some stars and some to feel like it's an important library and then for me to go and uh, run in a lot of environments and so on.
There were a lot of them. There were like, um, a few attacks recently where they took over like GitHub accounts and so on and in, in certain malicious code and that's an easy way to get your foot in the door and actually start ending up running in environments, right? So I feel like it's not about like let's figure out the super advanced zero day attack and let, I know for us, like spend months to like, uh, enter some critical infrastructure organization.
It can be a easy thing to do and someone's gonna walk you in, right? And I think there's a matter of like how we actually validate these things, right? How we validate it, how we're filtering the content is brought in, right?
The way we're spending a huge amount of budget out of the security files like email security and endpoint security for instance, right? We're trying to filter all the files that you're getting through email that you're dialing from the internet on file upload and so on and so forth. Kind of the same validation, the same filtering mechanism, the same approval process needs to be in place for all these third party libraries.
And all the, again, back to the application security one-on-one on like how you know, what you're building is secure. If you don't own that code, then you're just relying on that someone in a basement or someone in maybe even like in a, I dunno, threat, uh, actor state it's actually, or um, building that code on like committing things and so on, right? So you have no control over that, but you're still using as part of application.
I think that is the part that's currently missing right now because there's no proper approval process or like validation process in place. Anyone can go and like deliver faster with any library they want from the internet. And that's how we end up in these situations.
I'm not sure what the answer is, but I do know that SQL injection attacks have been on the top 10 list for attack vectors now for a better part of a decade. It's kind of like watching a Broadway play that's running on forever and ever and It's, they're successful, right? Like yeah.
And I think the cyber criminals are like, why would I do anything more complex? Um, we hear a lot about AI these days. Can, what's your sense of where are we with ai?
Will AI save us from ourselves? Uh, Yeah, I I feel like there's a lot of, um, expectations that AI is gonna solve all our problems, right? And especially in cybersecurity every other year there's this topic for ever since I joined, uh, the cybersecurity industry.
But yes, there, especially on the application security side, I think AI is gonna have a way more advanced capabilities of understanding a lot more the context. And I think this is the part that we were missing in the past on like trying to understand what we're building, how this is used, how is this gonna run and so on and so forth to like help prioritizing maybe some of those vulnerabilities. Help understanding more of the risk and I know plug some of those risks and so on and so forth.
So, uh, having that capacity of understanding better the context and run a larger scale is beneficial. I don't think we're fully there yet to be able to say that we're gonna put a, I know a chatbot in our products and problem solved, right? We're we're saved and so on.
But there's definitely a huge investment in that direction now. Um, I liked that I saw a couple of reports like for I know GitHub with copilot, what they did in the, uh, previous or like in the last year and so on, how much of that code was generated through copilot? So that is something I see very exciting, right?
Like that's something that's gonna change entire, the industry for good and for bad as well because the way I like to see that everything that's being billed can and will be used against you at some point as well, right? So even though there are functionalities that might are meant to make your life easier, can potentially be used, uh, to make your life a, I dunno living hell as well. So that's the part we need to be more careful.
Like how well, or like how these functionalities are gonna actually be used because they can be used by threat actors as well. Not just like, I dunno generate a simple safe to consume code and so on. All right, so what's that one thing you kind of wish everybody would focus on just a little bit that would move the needle a long way?
Cuz it seems like, you know, we are having a little trouble figuring out what to do first. I think if you're looking like, let's say cybersecurity as a whole, as an industry, it's a huge interest. There are way too many things going on and probably cybersecurity as an industry into like, you can split in like 50 different um, I dunno, smaller categories if you want or industries on their own and so on, right?
But at the end day there's too much noise and I think we're being very superficial in our approach of uh, um, securing our organizations to a certain level, right? We're like, we're in the industry of ticking boxes unfortunately, and that's the part that's caused us right at the end day. Yes you need to tick some boxes to make sure that you have the, I know whatever certification, whatever regulation you have to comply with, otherwise you're gonna lose the organization's license to, I know, I dunno, contain their business so on.
But at the same time, taking those boxes not gonna make us secure. So, um, there is some resistance in adopting new technologies on the security side. Cause um, you always gonna go, you cannot, uh, go wrong if you're selecting the top right corner kind of thing, right?
A vendor. But at the same time there's a lot more disruption in the market that's happening. And I think it's especially us is a bit slow and adopting new technologies to solve their, uh, more advanced problems.
So I think if there's one thing I would want from the security, I know industry as a whole is for us to be more careful when we're actually making these decisions, not just ticking boxes, right? And again, this applies like everything, not just application security at the end day. All right, you're in to here folks.
We need to think beyond the box. And maybe that starts with thinking like a bad guy. Cause if you start there, then you can start working your way back through.
Well what is the simplest thing to do? And thwart that and one thing after another. Eventually you might get somewhere.
George, thanks for being on the show. Enjoyed the chat. I appreciate the time.
It was a pleasure. Thank you. And back to you guys in the.