CNAPP with End-to-End Detection and Response – Pawan Shankar, Sysdig
As organizations build out their cloud environments, they face sprawl, with hundreds of unchecked and potentially vulnerable applications, services, and identities. Most cloud security tools are slow to identify suspicious behavior, and once alerted organizations can spend hours, if not days, combing through snapshots trying to piecemeal together what happened. Sysdig recently announced the first CNAPP with end-to-end detection and response. Join Pawan as he explains why cloud security is consolidating and the power of an end-to-end threat detection tool.
Transcript
This is techstrong tv. Hey everyone, it's Alan Shimmel and welcome back to Techstrong tv. My next guest, he's been with us before, his name is, uh, uh, Pavin.
Shankar Pavin is the Director of Product Marketing at Cig Sig. Well, I'm gonna have him tell you who Sig is, but if you watch techstrong TV or any our techstrong sort of, uh, events, webinars, learning events, articles, SIGs a company we cover a lot, they're a leader in, in, uh, cloud and DevSecOps, cloud security. So, Pavin, welcome back to Techstrong tv.
I hope you're well. Thanks for having me, Alan. Happy to be here.
It's a pleasure. You know, we got a lot to cover today. So I mentioned your director of product marketing, but I probably didn't do as good as job as you will in describing Sustain Pavin.
So let, let's start with that. Maybe give people a quick, for those who maybe you've heard not familiar have heard it, but not sure Ctig, what's the story? Yeah, sure thing.
So you actually covered it pretty well. Uh, at the highest level, you know, CSIG is a cloud security company and really defining its moment in the C app, uh, category. Uh, what, you know, our, our mission is really to secure and accelerate cloud innovation.
And how we do that is using our, uh, runtime insights and really our strength of the knowledge of what's happening at Runtime, uh, to make every aspect of cloud security better. Uh, we've also created telco, which if you have heard of the open source tool, uh, is really a open source solution for CloudFlare detection. So really leaning in on those open source routes to power cloud security, uh, as our mission.
Absolutely. Now, look, we throw a lot of acronyms around here, right? C A C N A, PPP Double P help get, if you could, maybe a little bit poppin, get our, uh, audience smart around c a, what's it stand for?
What's it mean? Yeah, it's a great question, and I think if we just step back, right? Capp, cloud native Application protection PLA platform, it is a mouthful, but, uh, it is, it is an acronym that real, what, what it really means is that, uh, there's an, there's a sense of consolidation, Alan, that's happening in the market where Cloud Security's consolidating.
Uh, and, you know, the reasons for that are multitude, right? There is the current macro environment that's forcing, uh, CISOs and CIOs to really think about tool consolidation. How can I get more with less?
So that's one forcing function. The other is security teams and DevOps, uh, teams are really overloaded, right? They're trying to address multiple use cases, and what they really are looking for is simplified workflows that are streamlined and are looking to manage those different use cases with a single platform.
Um, and that's another key forcing function, uh, and I think the, the market is really telling us, right? And I think Gartner is a great example of this where, uh, you know, they, they've been talking about, uh, CNA for a while. There's a market guide that just came out, uh, and, uh, it's really starting to take hold in in the industry.
As I talk to customers, that overall theme of cloud security consolidation is really, uh, resonating with them. Uh, and we're really excited because this is an opportunity that teases us up well for the leadership in this category. Absolutely.
Absolutely. And, and, um, and you mentioned it, right? CAPP isn't some name that CSIS thing came up with this, this is now a whole gardener quadrant.
No. Is it actually a quadrant at this point, a magic quadrant or a, I forgot what they call the one under it? Not yet.
It's a market guide. Market Guide, right? It, it's really, but it also represents a maturation of the whole cloud, na, cloud security, and then specifically cloud native, uh, security space, right?
Because it, it was, look, you know, cloud came in 2005, 2006, and the first thing everyone started talking about was, Hey, this is gonna demand a different kind of security. You can't just take the security you were doing on-prem and, and, you know, cloud wash it, you know, lift it up to the cloud and think it's gonna work. You had to have kind of native, native cloud security tools, processes, training, et cetera.
Then of course, the whole, you know, cloud native movement with Kubernetes and containers, and, you know, it represents kind of a whole new stack compared to what we were doing 15, 18, 20 years ago. And, and this has also caused its own kind of revolution in, in security, right? It it gives us a lot of capabilities we may not have had before, but it also gives us a lot of challenges we, we didn't have before either.
And so there's been a whole market, right, of companies like ctig, though cigs one of the leaders who have arisen into this so-called cnap space to kind of fill, fill this void. Now, Pavin, as we said, as I said, cigs been a leader in it for as long as I remember now, you know, around capp, but you guys have recently released a kind of a, a, well, it's a major release, right? And it's around c a but it's also end to end.
It's, it's a more holistic full feature, but I, I don't, again, you are the product marketing guy, man. Let's hear you tell us about it. Yeah, no, you're absolutely spot on.
And a lot of the themes that you, that you mentioned, uh, are really resonating with our customers, the maturity in the capp, uh, market. And, you know, we've been talking about CAPP for, uh, quite some time now, Alan, and, uh, and I think Gartner actually called out CIG as a representative vendor in that market guide. Uh, and you know, one of the key highlights, if you think about what Gartner is saying, is really that detection and response is a first class citizen.
It, it actually, in the market guide itself, it actually highlighted runtime protection as, you know, cloud detection response, uh, as a key component and criteria of, uh, for customers to, to consider when evaluating C A P. And with this launch, we're really strengthening our C A P with a laser focus on detection response, right? That highlights our unique approach of being end-to-end in real time.
Um, so, you know, to, to your, to your question, you know, if I think about why, why are we even doing this today? You know, uh, as you think about the problem we're trying to solve for our customers, and as I, as I speak to many of them, what I'm starting to realize is that a lot of times these organizations are building out their cloud environments. They're facing what's called clouds for all right?
It's really hard for these security teams and DevOps teams to know, number one, what resources are deployed in the cloud, you know, how are they configured and who has access to them, right? And this is exacerbated with the scale of workloads in the cloud today, like containers and serverless functions and hundreds of cloud services, you know, to be honest, that are being adopted, uh, at the, at the speed of cloud. Uh, on top of that, if you layer on identities that are being leveraged, both human and non-human, you know, the problem is really complex to solve.
Um, and the, the reality is today, Alan, a lot of times these cloud security tools that teams have in in place are slow, you know, to identify suspicious behavior. And once alerted, you know, teams can be spending hours if not days, trying to figure out what happened. And that's just not the right approach because, you know, DevOps teams and, and application teams are moving at cloud speed to innovate, but, but cloud security's not keeping up, right?
And this is the best case scenario for attackers because they're leveraging this arbitrage and get, taking that advantage of, of the time that they have, uh, to really steal your crown jewels, right? And the organizations oftentimes don't even realize this until it's too late. Uh, so that's really why, uh, you know, this launch, uh, you know, we're really pa proud of this launch and passionate about solving the customer problem of end-to-end, being able to detect across a broad, uh, breadth end, you know, of, of, of the tax surface as well as being able to do this in real time.
Um, so those are the, the key, uh, areas that we can get into today. Sure. Well let, let's get into 'em.
I mean, look, I, I think what you mentioned before was an important piece of it. First is, hey, just detecting that you're under attack in a somewhat real time or as close to real time as you can, right? I mean, cuz for many years, you know, whether it was Verizon or any of the breach data reports, you know, a common theme was, Hey, a lot of breaches don't get discovered until six months, eight months, 90 days.
It's great, right? You only, you only, you know, but to be able to discover that in real time is a game changer, right? But discovering a breach and then reacting to it in an appropriate way, those, those are two very different kind of things.
And they actually usually involve different teams, different protocols and, and everything else. So, you know, when we talk about sort of an end-to-end detection and response, you know, it, it's kind of the same thing like dev and ops, right? It, it's pulling in your, your threat detection and your attack detection and now instituting your responses as well.
And response has to be, well, let's mitigate ongoing damages. Let's make sure what in fact was compromised, and then what do we gotta do as a result of that, right? Um, it, it let you know, tell us how, how do, how you doing all these things.
Yeah. I love how you set that up, you know, giving, you know, the emphasis on both detection and response. And that's a good way to tee this up, you know, on the detection side, it's really, you know, what we're offering is unparalleled end-to-end coverage for cloud detection response that goes beyond what people knows for, for, for us today, which is containers and hosts, uh, to also address broader attack surfaces in the cloud that span across containers hosts Kubernetes cloud identity and supply chain, right?
So it's a really massive attack surface that expands our, our, our breadth of coverage beyond, uh, the workloads in the cut environments to also address new categories like identity and supply chain. Uh, and we do that, uh, specifically w for identity with Okta detections that are, that is new for us that we're adding as a key detection that allows us to protect against identity attacks like M f a spamming or account takeover. Uh, and also for supply chain, we have newly released our detections for GitHub logs.
So this allows us to, you know, extend our threat detection into the software supply chain, which has a lot of buzz right now, and helping devs and security teams be alerted in real time, uh, for events that are happening in their GitHub repos, for example, when a secret is pushed, uh, things like that that we can detect quickly. Uh, and all of this, uh, Alan is based on, uh, Falco, right? This is really leveraging the power of Falco, the open source, uh, tool for threat detection.
And this gives teams a single policy language and a consistent experience in the cloud for threat detection. Uh, and they're, they're, they can be confident, uh, and assured that these are all based on open source. Uh, and that's really adding a lot of value for, uh, for DevOps and security teams.
Uh, and this is really unique because none of our competitors in this market ha can have this breadth of coverage, uh, and this end-to-end detection, um, that's truly multi-layered. Got it. So let me, uh, let me hit a couple of things there that you said.
So Pavin, number one, it sounds like the identity piece of this is, is Vera partnership with Okta, which, you know, is a market leader, and, um, you know, if you're gonna market, if you're gonna partner with someone, market with, you know, partner with a leader, so, and, and so that brings a lot to the table, but then there's also, like for instance, the GitHub integration, right? This starts taking on the characteristics now of a platform where today it's GitHub, tomorrow it's GitLab, you know, and then, and whatever else you're using for your GI ops and, and, and so forth. I mean, software supply chain is beyond buzz.
It, there's a reason why there's so much buzz. It's a huge potential, uh, security poll. And, you know, look, you got the federal government involved and the whole s bombs and all these things.
Um, you know, this is, it's kind of where the action is when we look at the cloud native applications these days, right? There was a time when, and I remember this right, where we, you know, oh, cloud native applications in the cloud, no problem. Instead of using the firewall we use here, we'll set up a wap, right?
A web application firewall, very, you know, that similar kind of thing to a next gen firewall that you'd have OnPrem. But this stuff is just, there's a total different, there's a gift different game, right? There's a whole playing at a whole different level.
Yeah, exactly. And I think that's, that's the key here, right? Because sec security is evolving, right?
And the cloud is just so dynamic and so interconnected that your, your tools really have to speak the language and understand this broad context that, that not only just looks at a particular workload in a silo, but how is that workload interacting with the cloud resources, the identity elements of it, you know, and, and the other things that we talked about like supply chain. And that's really our, our, our, our focus here because as we talked about consolidation as a theme, right? Realtime detection response is a part of C A P.
And you know, with this launch, we're giving teams a single platform that understands the entire application lifecycle, puts that workload at the center, and then consolidates security around it. Agreed, man, I love it. Hey, we only have a minute or two left.
So is this available right now? Yes, it is available, uh, right now. Uh, customers, uh, and prospects can, uh, check out our content, uh, in all the information that we have and get access to a, a free trial that allows them to play with, uh, and experience these features, uh, firsthand.
How, how, what's the on-ramp for that? How do they do that? So, uh, it's actually pretty, uh, you know, we give them a, a, a nice onboarding experience, uh, makes it really easy for them to understand and adopt the platform, uh, and really leverage us and integrate what their existing tools that they're already using.
Uh, so, you know, a lot of, uh, handholding and, and, and walkthroughs that help them experience the power of the platform. com, you can just sign up right from there? Correct.
com, you can sign up for a free trial. Uh, and if you're interested in a more, uh, white glove service, you can also get a demo and our sales team can, uh, partner with you to explain the, the details of the product and help you onboard seamlessly. Great.
And is this like sold as a SAS kind of offering, or is it Yeah. Yes, that's right. This is a SaaS first, uh, offering here, so makes it really easy.
Uh, it gives them a frictionless onboarding experience, uh, from a deployment and onboarding standpoint to adopt the product. Very cool, man. Hey, Pavin, I want to thank you for coming on and telling us about this, you know, new offering from sig.
Look, there's a reason why you guys are a leader in the market, right? It's this kind of coverage. Congratulations to the whole SIG team.
I should also mention we have, I, I want to say it's the beginning of July, our cloud native, now virtual event, of which I think TIG is one of the, uh, major sponsors. And we thank you for that, and we're looking forward, maybe we'll hear more about it at that event as well. Yes, definitely, definitely.
Feel free to check us out and, uh, really thank you for the partnership here, Alan. It was great, uh, having this conversation Always is, man. All right.
com here on techstrong tv. We're gonna take a break. We'll be right back.