Cloud-Native Application Protection Platforms – Rani Osnat, AquaSec
Rani and Alan speak on where the security market is headed, why CNAPP is an emerging category and why Aqua Security was named the Best Cloud Native Security Solution/Service in Techstrong Group’s DevOps Dozen Awards.
Transcript
This is texturing TV. Hey everyone, welcome back to Tech strong TV for my next guest today on Tech strong is my good friend Ronnie osnot from Aqua security. I haven't had Ronnie on the show in way too long.
So it's a pleasure to see him Ronnie. How are you welcome. I'm great.
Thank you. Allen. Great to be here.
It's great to have you as always my friend, so. Rodney so we want to talk about aqua and the devops doesn't award. But before we do, I think most of our audiences They've heard of our clock was like Aqua security, but that maybe some people have it.
Why don't we start there? Give them a little bit about who Aqua is. sure, so we are a cloud-native security company we focus on You know this call it second generation of cloud applications that are based on Technologies like containers serverless.
Kubernetes, we've been added for a while. So more than seven years now. And we serve some of the largest organizations and deployments of cloud native technology out there, you know, including major Banks.
major media and the kind of web companies manufacturing energy. You name it? We're there.
Understood and thank you. And Ronnie York. I don't even know your title these days with awkward security.
Well, that's these days. I'm still SVP strategy. And this is development You've Won you've warned many hats over the years at our several hats.
Yes starting marketing move here. Yeah. And you've seen it, you know, we were talking off camera.
I was saying you know that the very first time I heard the term Cloud native security. Was was from you right and and at a time where everyone was still talking darker darker darker and kubernetes kubernetes kubernetes and container container container. you really?
for the vision of cloud native security security for the entire Cloud native stack and it was it was more than a marketing term in a word. It really made you think about stuff And we're going to jump into that. But look we shouldn't dance right awkward security was this year's winner of our devops doesn't Award for best cloud native security solution.
And when you think about it, why shouldn't the team that coined the term Cloud native security one win that's Cloud native security solution. So I think it was well deserved and congratulations. Thank you.
Very honored to receive that. Yeah. good reason So Ronnie, if you don't mind if I'm gonna put you on the spot.
So I think it was around 2017-2018. Your first came out with the term Cloud native security. Yep.
Tell us a little bit about aqua's Journey from then till today. Right. So, you know in 2015 when we were just starting out we had this notion we heard about we know about containers and what Docker was doing at the time and we felt that this could be a game changer in how applications are developed and deployed.
And we recognize that this would require the significant change in security. Because not only are you now packaging applications differently and running them, you know in places where you don't necessarily know in advance where they would run because that's the whole idea with containers that they're affordable but now all of a sudden developers that much more impact on the outcome in terms of security For Better or Worse, right? And so we recognize that early stage.
This will have to be kind of what we call a full life cycle. approach to security starting in development going all the way to production whereas before these were typically Very isolated processes you had appsec which focused on. testing and development and so forth and the majority of the security Market dealt with applications and infrastructure in production, right?
Nobody was looking at development. So this was the first kind of Step change in what we saw. And we made a gamble in the sense that it wasn't clear at the time again talking late 2015 early 2016 that this will even catch on in a big way.
You know, it could have remained the Silicon Valley fad because that's where most of the hype was around Docker and but very early on, you know, we the kind of data customers. We had or Enterprise customers of the traditional kind not like, you know, not people like Twitter, but people like Lockheed Martin right or or Banks, so we felt that pretty safe. In our assumption that this will become an Enterprise play and that's when the journey started and then as you pointed out around 2017.
The orchestrator wars that have what were happening at the time because kubernetes had emerged it was it was donated? To the cncf at or open source with the cncf by Google as early as 2013 but it was you know incubating. It was pretty small.
But around 2017 what happened was that the massive adoption of Docker made? A lot of organizations realize that this is going into production on a massive scale. And that they need something to run it.
And all of a sudden it all happened pretty quickly people. Like hey there you asked the Microsoft and a red hat put their weight in VMware. Put their weight behind kubernetes as an open source project.
And it was at that point that we realized that the balance of power is shifting. And that this will become a much broader. Ecosystem and play and we were talking about earlier about how you know dockercon used to be the trade show of the industry and then kubecon.
Start taking over around 2018. And so with that came the realization that we're actually talking about a much broader set of Technologies. The containers themselves also the orchestration tools that run the things like serverless functions cicd tools that are used to automate the you know, the delivery of these.
Capabilities and so on and so forth and we start account branching out into those areas. Absolutely and call the cloud native security. Yeah, yeah.
You know, I I will tell you I was one of the judges this year as I usually have for the devops doesn't. What amazes me? Well, first of all.
I think we had almost 600 different companies people. stuff nominated this year and in the public voting section for the first time we had over 10,000 people. Vote we never got over 4,000 before it was crazy.
But specifically Cloud native all of the though. It's called the devops doesn't Awards is several Cloud native related categories. What struck home to me was the continuing maturity of this Market?
Yeah, right, even in the cloud native security where you guys want there was some very Worthy. companies mainstream security companies that aren't You know because they in my mind that's two flavors here one is represented best by you and aqua right? These are dedicated Cloud native companies that were Would conceived and and came up as Cloud native specialist.
Then the other side of the coin are these, you know, big security conglomerates who see the cloud native. Market and and want a piece of it and it coming in there because they recognize there's a problem and and quite frankly they usually buy companies like what right or these things and they because they buy that innovation. and we saw that we we saw some of those in here, but native in and of itself is such a a force such a for it it is the way everybody's doing.
So yeah, and I have to say even though we see this huge momentum and we've definitely crossed over, you know, a couple years ago we crossed over from Kind of, you know the tip of the spear or oven guard the earlier dollar to to yet to much more mainstream mainstream adoption. There's still quite a long way to go. Oh, yeah, and and we are and you know, one of the things our driving this is also open source, right the fact that all these projects we've mentioned a few, you know Docker and we know these are both open source projects, but but also things like Prometheus and other tools that are in this set are all open source projects with huge with huge communities, right?
He's communities and driving a lot of innovation a lot of adoption and this is actually something where we also made a conscious decision a few years back to make an investment, right? So we ourselves have open source. Projects for security like trivi and Tracy that that we that are some of the biggest, you know, the most most likely used open source tools certainly in security anywhere and they've gotten huge adoption and this, you know drives recognition for aqua, but it also drives this change in security mindset.
To allow, you know developers devops and security people to start. Understanding how they can incorporate these tools. And yes, you know when they get to certain size or they have needs that require better support or reporting or things like that.
They will come to Aqua for the Enterprise solution or to one of our competitors, but but in itself this drives Innovation right and that we couldn't have We couldn't have done some of the things we've done at that Speed without the community around open source. I agree with you. I in so many ways the whole Cloud native Market represents such a different way of doing things because it's not just the opens the open source underlies it all in Powers it all.
But what the open source also enables is what I call co-opetition. Right that in in previous Computing scenarios, you know Microsoft didn't share with Google Google didn't share with Amazon Amazon didn't share with IBM everybody, you know went to their own corners. But would because of Open Source and cncf and these things everybody everybody chips in sort of for the same.
purpose and and that is it's a good thing. It's a good thing. for sure and again, I mean we We see it within Aqua the level of innovation the speed of innovation within open source is tremendous.
I mean it needs to be managed, of course Etc because not everyone is of equal quality Etc. But the rewards are vastly superior to to doing things on your own. And and like I said, it also drives a change in mindset and understanding it makes it more accessible to people.
And and this is something that is, you know part of our strategy overall. Absolutely, very good, man. Ronnie what about what's coming down the pike.
I assume you guys will be at cubecon and Amsterdam in April. Yes. We'll be there as well.
I think we have some speakers thoughts there as well. We you know one of our areas of investment this past year and also this year is around the software supply chain, which we see again in the cloud native context of being Inextricably linked to everything we do just like we started with the lifecycle security interesting left and all that. This is in a way an extended shift left up the of the chain, but also it has its own set of challenges.
And we're also seeing it on the research side looking at exposures and threats. In this area is still you know, frighteningly easy. To attack the software supply chain, especially when it comes to open source and Cloud native because of the breadth of what's available the openness and the speed at which it flows through Pipelines.
So this is something that requires a lot more attention from us and from the market in general. And and this will be one of our areas of emphasis for this year. Um, we acquire the company of 15 months ago or so argon security that you integrated it into our platform.
And and this is you know part of now what we're we're doing is to see how we can kind of connect the dots that are for customers to be able to detect things very early. Even before even before developer actually builds anything to to ensure that they don't ingest anything harmful from their third party providers or from open source projects. And that everything is tracked.
And we make sure of the Integrity of code the Integrity of the tool set itself, right? I mean people use for example open source CI CD tools right to build things people use tools like terraform or or other tools to deploy. A lot of these tools are not properly configured in these environments.
Absolutely, right. I tell you know, we're doing the RSA show again in also in April the week after Cube card and we'll putting on the depth set cops day on Monday of the week there and our theme this year is devops is now devsecops. You know Ronnie you've been with me when we first started that years and years ago, right?
It was a hard sell a lot of security people didn't believe in this whole devops kind of mindset that devops way of doing things but now more than ever with things like software Supply chains and the s-bombs and all of this. You can't do devops without security devops is devsecops today. I've heard it from gitlab and we've heard it from Jay frog and we are hearing it from cloudbees.
Devops is devsecops and and that's kind of and again. You were out way out in front of this preaching this kind of. You know Mantra about that and it's it's coming true and we're seeing it play out right in our lives every day here.
Yeah, I think the big change in the market and you're right. I mean we in the market started talking about this a long time ago. I think it was Gardner who coined the Secaucus back in 2013, but basically I think what happened the big change in the last few years.
is on the security side not on the debt off side devops have always owned up to Having some sort of security or elements of security being implemented as part of their automation. They understood that even before they were told to do so. And you know a lot of our early customers the buyers were actually devops teams and not security teams security teams.
Didn't know what a container looked like or how to spell kubernetes right but at the time but this has shifted, I think the big change in mindset is happening now. in security organizations where they understand they can't even from an organizational perspective on how they're you know how their teams are structured. They can't just keep it the same way.
They can't have the silos. Of you know absec people doing abstract Cloud SEC people doing Cloud sex infosec people doing infosy Etc and you know response teams and they understand that they have to have some sort of Unified. visibility after work off the same, you know music the score right they have to to all Not think of themselves as kind of doing their own thing passing it passing it on to the next guy, but actually collaborating to understand priorities to understand for example, if there's an issue.
Should it be remediated or mitigated? Can it be fixed or not? Does it actually impact?
Workloads in production or is it purely? you know something that will stay in development and so on and so forth, so I think there's a whole wave of efficiencies waiting to happen. Once that change is complete.
Actually time because it's people it's people in processes. I go. You pop it.
com or our sector. Yes. All right.
Hey my friend. Hopefully I'll see you in April in Amsterdam. And if not in San Francisco, we'll see what's up.
Alrighty, congratulations again to you in the whole team on the devops doesn't award well deserved. Keep it up. Keep leading the way Ronnie and thank you very much.
Thanks. Be well. We'll be back here on Tech strong in just a minute.
Thank you.