Asset Management for Cybersecurity with Firemon’s Justin Stouder
Justin Stouder discusses asset management in the cybersecurity space. He highlights Firemon’s role, tracing back to Bell Labs’ internet traversal software and Lumeta acquisition. They emphasize the importance of active discovery without agents or credentials, enabling comprehensive asset visibility.
Transcript
This is Textron tv. Hi everyone. Welcome back here to techron tv.
My next guest is my friend Justin Stouter. Justin is GM Firemont asset manager from Firemont. Um, so that was kinda self-explanatory.
Justin, welcome back to Tech Drunk tv. How are you? I'm doing well.
It's great to be back. Thank you, Justin. Did I, I'm just thinking, did I mess up your last name?
No, you nailed it. Stouter. Okay.
That's what I remembered. And I just, I'm just sitting here thinking, oh, you know a lot. You'd be surprised how many people are polite and they don't want to correct you when you mispronounce their name.
And I, I'm like, look, it's your name. It does, you know, it should be pronounced correctly. Don't, I don't take it personally if I got it wrong, tell me.
But anyway, Justin, regardless of what your last name is, tell us, tell us a little bit about tell you and your role in Fireman, if you don't mind. Yeah, absolutely. So most people remember Fireman or know Fireman as, you know, the leader of the NSPM space, working with firewalls, you know, inventing actually the NSPM space.
And we're still doing that. We're seeing great success in that space. Um, you know, growing the business internationally with some of the largest companies in the world.
Um, but the asset management business is just, um, it's really interesting. It's part of what FireMon acquired when they bought Lou Meta back in 2018, and of the solution set at FireMon, one of three products, obviously, you know, the flagship NSPM solution in which we're based, and then through Acquisition Asset Manager, which we get a chance to talk about. And then cloud defense via disrupt ops of which I know you're very familiar with.
Sure. So finance evolved and, and morphed into a, a solution suite in the cybersecurity space that, uh, is really distinct candidly. Absolutely.
And now, fireman itself, and I was there for this, you know, became a standalone company, spun out of, I think it was fishnet at the time, uh, fishnet security. And that had a, I'm going to guess that had to be around 2004 two. That's right.
Something like that. That's Accurate, yes. But the asset manager piece of it, which came from lume eda Right.
Predates that even. Right. It's even older, if I'm not mistaken.
That is correct. It's such a fascinating story, Alan. I love telling it.
Um, and I have multiple times, but, but what's really interesting is when I took the role, I did some research and found that at Bell Labs in 1998, of course everyone's familiar with Bell Labs, they were writing software to traverse the internet. And I'm, I'm dramatically pausing for folks to remember, like back then the internet was not that big. So they're writing the software Exploring it.
I, I had already sold my first internet company in 98. I want you to know, I started a web hosting, we didn't even call it hosting when I started, like in 96. Netscape is in better.
So, so one of the guys that wrote the first code for EDTA was actually the guy that coined the phrase firewall. Really? Yeah.
Yeah. Internet and firewall security was an O'Reilly book written in 1994 by a guy named Cheswick. It's his last name.
They called him Cheez. He was the author of the original lines of code for edta. Very cool.
So, so very cool. They've got this software, the United States government hears about it and speaks into Bell Labs and says, you quite literally, quote unquote, this internet thing is getting out of hand. We need your help keeping tabs on it.
So they commercialized the solution, and that time traversed the entire internet, which was 400,000 node. Um, the end of this year. The projections are 46 billion.
So it's changed a lot since then, but they just the productized it, yeah, commercialized it. And then, um, fire mom purchased the lu meta business in 2018 and we've been growing ever since. Mm-Hmm, Sure.
So, you know, there's certainly billions and billions to, to, to use Carl Sagan. I'll paraphrase Carl Sagan, but you know, also Justin, we've seen a tremendous emphasis on asset management, I would say in the last four or five years or so, because for a couple of reasons. Number one is the explosion of assets out there that are connected, right?
You can't protect what you don't know. Number two, again, going to protection is every one of those assets is a potential attack surface. That's right.
And, and so, you know, same manage, you can't protect what you don't know and how do you protect all these assets? You gotta know them, categorize them, and, and be able to see, you know, profiles and what you got in place for it. So, you know, I think we've seen a lot of asset management type of, of plays get bought by bigger security companies over the last, let's say five, six years.
I think directly because of that. What's interesting is how they go about doing asset management. Some people, some solutions, you know, I I I call them internally, they, they look internally at your address space.
You can tell them what your, your cloud, uh, you know, space is and they, they kind of see what's there. Then there's sort of the hacker's eye view of asset management, let's call it. Right?
Where, where they go out on the internet and see what they turn up. If you know, if, if it belongs to you, you probably need a little of both. I'm thinking at some point you, you do, let's talk about Fireman's specific read of asset manager.
Absolutely. So, you know, for, for true active discovery to work at the enterprise level, and I say that specifically because we have customers with millions upon millions of IP addresses, um, it, it needs two key things. And the first is agentless.
Uh, you wanna really fire up your IT team, talk about agents, installing agents, and, and even the concept of installing an agent means you're aware of where to place it so that it can do discovery, which is completely incongruent with an active discovery that is pervasive and just traverses your network. And then the second thing is credentials, right? The thought of having credentials is indicative of you knowing how to authenticate to a certain area of your network.
So you need the opposite of that. You need software that traverse your network without agents and without credentials. And that's the key, the two of the main differentiators of the LU Meta solution or FireMon Asset Manager.
We don't have agents and we don't require credentials. Um, and we've been building, you know, when you think about technology and, and the duration of building a software application, uh, there is truth in the benefit of having a longer duration. You know, you, you figure more things out.
You learn how to traverse networks without tripping over, you know, firewalls or endpoints, et cetera. And we've been doing this for a really long time. I've ground truth IT with customers who say, our IT teams never complain about your software.
And traditionally, uh, from a percentage wise, Alan, 30 to 40% more assets than what a CISO will attest to at onset, we find. So it's not just me being proud of our product, of course I am, but it's demonstrable success that IT teams and CISOs say, your solution's different. Absolutely.
Yeah. You know what else I, I just wanna make sure our audience is aware. Asset discovery is a subset of asset management, correct.
But it's, but it's not the whole enchilada, right? There's much more to managing assets than just discovering them, though. Discovering them as they say in, in Vegas.
It's a fine beginning, right? Um, but, but you can only go from there. Let's talk about that aspect of it, Justin.
Okay. So now agent list and, and password lists. We, we, we do our discovery.
Now what comes out? Now, what's next? That's A great question.
And so, and this is a point of contention probably with some of our competitors and the space at large, uh, there is not, this is gonna be potentially, uh, inflammatory, but there really is no one solution fits all in asset management space. There are some big players, of course, but those big players do a better job of managing assets than they do of discovery. And so if you've got that kind of ecosystem, what you need is interoperability or the ability to integrate and take what you find and extend that out via data lake, via integration, et cetera.
And so what you'll have, and you've seen it in the marketplace, is this integration race. Like how if we do discover really well, which we do, we do it best on the world, right? In the world, how do we take that data and then within the enterprise extend it out to you name it, uh, vulnerability scanner, data lakes, et cetera.
Um, it's really about exposing that data in a meaningful way. 0 release of asset manager called Extensible Web Services, where we take that code or that, uh, that data and make it available to anything and everything, not through a discreet one-to-one integration, which you're very familiar with. Where you go, you code up to an API, you build it, the moment it's built, it starts aging.
You have to persist it. And then once you build that library, it becomes cumbersome or you hire a third party to go do that for you. We're taking that completely off the table and just saying, this is a service that you can connect to with any level of API with any type of credentials, et cetera, to take that data that we discover, to your point, and manage it.
We have asset asset management tools within our solution, but most organizations, as you know, have multiple tools that need to get at that information. So it's really playing to the enterprise to what our customers are saying and saying, you guys, you discovery, great. We'll use some of your management capabilities, but we wanna take that and dump it into our data lake as the tip of the spear from our management perspective so that all these other tools that we have can overlay.
But you are the source of truth. You are the one that does discovery better. And so I really, I really think it's being honest in the marketplace and understanding there really isn't a one tool that solves the entire chasm space.
You gotta work together with other tools. Fair enough. I get it.
Um, interesting. So I I, I'm not gonna do it. It's tempting to say let's talk more about this may release, but we're not, we'll bring you back on in May.
Maybe that'll be RSA timer actually today. Yes. Maybe you could come in person.
We're gonna be on broadcast alley streaming all week and we could discuss it there. How's that sound? It sounds wonderful and I'd love it.
Alright, for now though, we have a few minutes left here, Justin, not a lot, but for people who maybe want to, you know, give this a whirl, take it for a drive, how would you, what would you recommend? What's the on path here? Absolutely.
So the easiest on path would be to go to our website and the header is request a demo, click that button, and then there's a notes field and just say, I'd like to see asset manager in action. And we have a team ready and willing to, to demonstrate the product. We're doing it multiple times a week.
Um, and real excited to show everything I've just spoken about. So go to our website, request a demo, that's the easiest way. And anything, uh, to get ready for the demo, should people have.
Absolutely. Yeah. Any, you know, preliminary kind of things, what Sure.
And so, you know, I'm a very transparent, candid person. I'd love to know the IP size, and if you don't know, that's fine. A guesstimate on the size of your network, because we are at best at the enterprise level with hundreds if, if not millions of IP addresses.
Um, we do that in a distinct and unique way, uh, against our competition. And so we'd like to flex a little bit on what we do really well. So the number of ips would be ideal.
Makes sense to me. Um, and, and again, I just wanna remind the audience. Asset managers one of the three legs of the stool over at Firemont.
You've got the, uh, the cloud product, and I, I'm drawing a blank. I speak to Rich on it all the time. Justin, what's the cloud?
Security product? Cloud defense. Cloud Defense.
Excuse me. Yes. And then of course the, the, uh, the fire, the firewall management, policy management, kinda flagship Firemont product.
Um, Justin, anything else before we sign off? One last thing, and it might be a little anecdotal, but, um, it's just an awareness of this space, the chasm space and the growth that's taking place there. And my encouragement to anyone that watches this, it's something that you need to spend some time on.
Uh, for whatever reason, it just seems, uh, like folks know that it's an issue. You know, you can't manage what you can't see. It rolls off the tongue really easily, but investigate and inspect that space in your enterprise, in your network, because it's worth it just to understand what am I really required to manage?
Um, so spend some time thinking about it for sure. That would be my last thing. I got a question for you, if you don't mind.
Where are APIs sit in this? Are APIs considered an asset or, or not? You would leave that question.
That is a I would not, I would say no. Oh, I think you should. That should be part of, if not the may release the release after.
Okay. Because, you know, I, I, interestingly, I had a guy from CloudFlare, uh, I forget his name now, grant, grant Bazookas, I think he's CSO at CloudFlare. They did a survey 50 something, like 51%, like a majority or not, maybe it wasn't 50, maybe it was 40.
A very high number of traffic on the internet. It's actually API to API traffic or API to a plugin kind of traffic. And I think one of the biggest, I mean the whole API security space is blowing up, right?
Right. There's, there's plenty of companies that are dedicated just to API security, but you know, I, I've been in security long enough to know that today's product becomes tomorrow's feature. And, um, I really think that eventually API security becomes part of asset.
You gotta discover these APIs and then manage them. Mm-Hmm. Securely.
And, uh, That's a really good point. And the natural transition from that is, is identity an asset? Right?
That, that's another thing, right? Is is it so is, and it's not just people identity, machine identity and, and code identity and stuff like that, right. So yeah, it's all there.
You, it sounds like job security to me, Justin, you got your work right out for you. That's right. All right, Ella, thank you so much.
Thank you. Thanks for coming on. Tech Drunk tv.
Say hi to all our friends at Fireman and we'll see you soon. Okay. Will do.
Take care. All right. Justin Stouter, GM Fireman Asset Manager for Fireman here on Tech Drunk tv.
We're gonna be back in a minute. Stay tuned.