Cloud-Native App Protection – Vladi Sandler, Lightspin
Cloud-native early stage SaaS companies looking to secure their data and workloads in the cloud have been left with two choices: purchase a cloud solution or software focused only on the enterprise market. To close this gap, Lightspin has launched free access to its Cloud Native Application Protection Platform (CNAPP).
Transcript
This is Textron TV. That's a great pleasure being joined by Gladys Sandler and Gladius CEO and founder of lightspin welcome. Hey I doing thank you for inviting.
You bet, of course glad to be talking with you today. Well, there's a little bit about yourself and also tell us a little bit about light spin. So bloody Sandler, I'm the only co-founded lights being I'm 34 years old.
Just located to New York from Israel. It's a huge exciting for the company to myself. Like we are next Generation Cloud security technology platform in place where growth based technology under the category called synap Cloud native application protection platform.
What is special about Life Technologies main unique value proposition which are the ability to prioritize and remediate any kind of read that you have to do in your Cloud environment from your infrastructure service to your kubernetes from Casey this you Toronto in one holistic platform. Fantastic. Well, you know as we both move applications and build new applications in the cloud native architecture move into the cloud.
There's obviously it hasn't yet. There's a tendency to bring things that we know Technologies tools approaches. We know from a non-cloud native environment into the cloud and into Cloud native applications.
I imagine there's some scenarios where that makes sense, but imagine there's some some different ways. You have to think about application Security in a cloud native world. Tell me your thoughts on that.
Yeah, I think in general when you look on the digital transformation process happen nowadays. Maybe accelerated things to the covid, right? We see more and more companies moving to the cloud and when you look on the cloud himself, you need to split the relationship to two levels.
The one layers are the infrastructure themself, which is there. And our Amazon kubernetes and the second one is the application Level the signification of the application Level themself. And it's running on those infrastructures.
Life means uniqueness is coming. Also, of course to take care of your infestation because the scale and the change is much higher and the chance for mistakes because of misconfigurations in improper permissions same which leads to most of the data brushes. And that come to the understanding the customers now, they are more looking for scale and more care about the time to Market than before now that's important point because if you care about time to Market you care about money security is a big influence on time to Market.
So every time I completed Sprint in do deployment security coming inventions, we have a problem. It's a big issue right? It's some conflict with final second relationship between the devops and the security of people What we need to understand in our perspective is the shifting left is to take care problems before the deployment happened or during the deployment happened so you can get better context.
That's what's actually the posture management about. So essential more about how this fits into a devops process. I mean, I think one things have been kind of pondering about is probably if you're doing cloud-natives you need to do have lots visitor.
Is it a requirement? Maybe you could try it without it, but I think you're much better off course to be using a process. Like how does that change and influence, you know act an application application security and application security platform approach like you're talking about So it's a good point.
I think that it's really depends on the organization and on the design of your Cloud environment. We see a lot of times. Implement different kind of implementation of your sacd processes.
I think that's from one perspective like in serverless a lot of time the developer who writing the application he is the owner of the deployment themselves not only of the application but also of the infrastructure and other cases is to separate processes in which we consider deployment with pool we perform PR or requests or Gita boss for infrastructures and for the code and the code requires some kind of resource in place and those processes those infrastructure because or code building through path through the same ACD process, but in both case scenarios, that's why we call secops or security Engineers you see more and more needed organization. To be in Security in general positive more than a traditional security because deployment have a lot of effect. So one of the angles that light can come with is the ability to analyze full requests.
So they see so or the depth of security and organization can get quickly by every time they developer to pull request get the full map of the reef. This pull request is going to do which allow them much earlier on the CCD process to start a discussion with the developer or the devops for fix the problem even before the build or deployment process that It's an interesting idea kind of the pull request which of course starts everything and the software development side. We're pushing to production.
That kind of defines at least part of what the environment that you're trying to protect in seems like also infrastructure software right structures code or terraform or whatever using that sort of a declarative environment that you're pulling into that potentially can be pulled from the repository as well, right? Yes, right so light pins main goal in focus is the infrastructure the service layer and the kubernetes layer which we can basically Define platform of the service layer and on those layers as I mentioned before everything done by configuration analysis and configuration and deployment which required to configuration analysis during which you can online for permission configuration issues over risky permissions or configuration. So we're exponentials in place, but also from the Application level one thing that we know to provide customer with the ability for agent class vulnerability management.
It's really important point because when you develop on some framework you always use some binaries or some packages just package is also can be vulnerable. from one aspect if you want to stand in Stock Tour PCR anything else you need to show that you have a very management process in place right another Part part of the story you want to know that you did write deployment to the cloud so lightly it goes to give you the context is the ability to take different fees that we know to provide, you know on your risk posture management and so providers the context that allow you to prioritize and give the focus of very should start and work on things to the attack pass our unique technology. So a little bit more about Cena Cloud native application protection platform platform can mean here's something that everything runs on or runs in and we're protecting it.
I mean it might also mean there's something you put in containers and libraries that applications use or perimeter kind of protections, but put some more definition around see now for us. It's a good point. So I think when we look historically on the cloud security Market the cloud security Market started from basically free categories, it was the Cosby And which was maybe the first category even before really was kind of clouds more perimeter level.
there was the cspm the cloud security posture Management Solutions like gridlock domain style and and Cloud workload protection cwp platform And what happened with the years that if in the traditional Enterprise security you buy a bunch of tools. In the cloud as I mentioned before everything is part of the same chain, right you have you need context you need the aggregation of different feeds. The customer service quickly start to come to situations that okay.
Awesome. I don't want to have a lot one cspn one work will protection in one I didn't management. I want to have one solution who can provide me all of those.
That's what actually generated this probability in vision of platforms called syrup. And their ability to provide you one platform. It will care all all your needs you need to do in your Cloud security portion.
So kind of a more of a fabric interconnected here's here's the common things that you can use a Crusher a crush your environment from, you know, identity management Access Control exactly. Whatever parts that may be. Yes.
Okay, good. So well tell me a little bit about sort of the state of this technology in the market. Where where are we with people adopting it and what things need to be created next?
increase adoption so I think it's it's really depends on the maturity of the customer and The mature customers who already have some Cloud security solution in place are looking for the Next Generation because they already suffer from Pain special of noise. And then synapse the right category for them. And other kind of customers which are in early stations.
They're joined to the cloud a lot of time looking to build fundamentals of the cloud security, which most of the time will compliance will be a team management and protection. In this case solution like life being would provide them the specific. Specific package of the platform or specific needs they needed this cfpm or the world of protection.
the specific in this case Okay, very good. Well still a little bit more about. Your approach and white spin, how do you have what you're offering look like?
Is it a SAS platform? Is it a series of you know environment to run in? You know, how do you deliver your products?
So first of all, we are And light skin we are a full multitenant multi-cloud platform. And lights being we in of course, we're success too. But more important than that.
We are self-importing. You come to my website we can start for free and you can start to use the platform with with split it and build some package which provided full free forever. capabilities and in the platform in other cases you it's classical and model of pay based on what you need And more than that, we really big you are in life's Vision really believe in community and we really believe that we should be the most adaptive Cloud security Solution by any engineer.
So we'll launched a free SAS tool called Recon Cloud. She allow you to do fully reconnaissance today all your Cloud off which exposed to the internet which is really popular tour in place. The reason time of it is because customer don't need to spend a lot of time on self calls and demo calls and you know to be bothered you have a problem.
You can go use my platform see the value and then discuss its value was pay for that or not. and is it usually developers as a platform Engineers Ops as a security teams who's usually the person you're selling to so most of the cases again. It depends on the stuff of the organization, but the budget owner will be deceased.
So CIO CTO repairing depends on the size. The end user probably will be from the security in general secops deaf secops or devops in the company. Okay, great.
So folks head to your side. It's light spin that I know correct. Yes, and it can they sign up for free account there or sandbox or something to test your product all free trial use it play with it.
And as I mentioned before we launch two weeks ago also free full version of the platform soon. Also, very interesting. Okay.
Well, thank you very much appreciate getting expensive time with you and planning to talking about light spinner. I hope folks will check it out. That light's been not.
Oh, I know. Thank you very much. Thank you very much.