Cohesive App Security – Guy Flechter, Cider Security
How do security and software engineers get on the same page about app security? We at least need to speak the same language, and establish some common group. DevOps workflows provide many entry points throughout the software creation process. Guy Flechter, Co-Founder and CEO of Cider Systems, shares his experience as a CISO and how understanding context helps dev and security create a cohesive app security strategy.
Transcript
This is Textron TV. At the great pleasure today. I'm joined by Guy Fletcher guy is co-founder and CEO of cider security.
Welcome guy. Hey, welcome. Thank you for having me.
It's good to be there. Absolutely always love to talk security actually app security. So we're gonna get into that.
Well first tell us about yourself a little bit of an introduction your background a little bit about cider security. Awesome. So guy.
I see you at co-founder of scientist security before that almost 20 years in the security trenches. You can say grew up and these are the Air Force so many years in the Cyber domain then move to private Consulting to private and public companies and then after a few years move to life person to the security team There are I walked in several positions and then after a few years that life person moved to apps flyer one of the biggest mobile attribution analytics company. There are Services their first season.
Basically I established the security team there was scratch And after three years that apps flyer decided to move to my next adventure together with a friend of my that we got to know each other at live person. We work together at the security team. So we decided to establish cider basically.
To try to fix the pains that we felt in our previous positions when we tried to walk together with the engineering ecosystem. I think every day every feature. We always say that every feature in the in the product.
It's like a scar that we have that we try to to recover with the picture. So yeah, so a little bit about cider we are. Here and eight months into the journey.
we are trying or at the bid this place that will allow security and depth and devops them to work on on security and all the different layers inside the cicd which is as you as you know, it's very you know, you can look at it very chaotic area of with a lot of opportunities for the different companies, but on the other and close a lot of challenges for the security team and also not only in by trying to follow and support the engineering needs but also in a way that and we saw just in the last year in many different in the last year and a half in many air in many bridges that happened that the advers targeted the cicd ecosystem because the security team yeah, I struggling to to protect it and to implement security controls part of it because of you know The the fact that it's moving fast and you know constant changes and and so on. Right. I'm not actually I want to get into the little better National Saw by the way that Michael coats former c yeah see so at Twitter and investor to have on board.
So congrats. He's a great guy. So, you know, I think a lot of security teams are trying to figure out how do we help?
How do we become part of the software process but not become software Engineers, right? That's that's not their gig but their security specialist so no a ton about it, which you know shift left can't mean the developers are just going to do it because they got plenty to do and they're not experts at it. So yeah, I think see ICD is a great place to start right?
That's kind of an excess where it comes together codes can check in Bill tested Etc go moves on from there. Your experience as a seesaw. I'm curious about curious about what that liar.
What if you could have done it the way you would have liked to have done it? What would you have changed in a situation like that? So I think that the most important thought is the fact that we need to understand this.
We need to speak the same language that the fact that If you go and this is also something that I felt in as a seesaw and also before that the Institute of limits and then you know for me. that when we try me and the team try to speak with the devils and the Destin we were in completely different understanding of what is happening. We always like to illustrate that you know.
Security teams are like walking with the map of Berlin in the middle of Manhattan. No any other did that you like? They don't know what is happening don't know where to go.
They don't know. What is the connection? They don't know.
What is the relations that you know, if you're gonna ask many security teams. What do you know about your cicd ecosystem? Most of them will will not have a good answer to give you and from that moment.
That's the problem start and and grow to the places that we have today. And and if I would be able to change it and and and much easier way to understand and understand what is happening that I think that is the critical part. No, I used to say recommend your security person go learn about software architecture go learn about Cloud native and containers and microservices and not everything's being done that way, but actually that might be helpful.
You want to become the software expert but actually now I tell people to learn about devops go learn about the process of our house software is getting created because if you want to get engaged that's where it's happening. That's where you can be part of it. So it sounds like a similar lesson from your experience.
Yeah. Well, tell me a little bit about so you're in the app security space. A lot of companies a lot of Technologies, you know rolling into Market or early in Market.
What approach did you take with cider security and why is that different or better than what other folks are doing? So I think that it's going back to the original what we speak about about going from the bottom of the approach. The fact that first of all we try to understand the terrain we start we try to understand what is happening.
What is the the common ground of the stuff that need to be done and and you know providing the security team the ability to First understand what is happening? What is actually happening there with the context with understanding of the flow what is connected to what what for example what repo is connected to what pipeline to what image is being put as part of the build process and all the way to their to the Pod inside the the production and what the third parties are involved whether it's a part of third party libraries that are part of the code or whether it's a apps and web books that are part of the CM or Jenkins plugins or stuff that is running as part of the pipeline, but it's not just giving you lists of stuff just giving you a lot of information. That's that's the problem with many security to by the way that I walked in the past, you know, they're giving you You know all the languages that you have here are all the containers that you have.
Good. What are what is the context? What is the relations between specific language the specific pipeline to a specific container?
Start with that and then based on that build all the layers of the different security controls that you need to have inside your security as part of your security practices for cicd one layer is of course the the ability to protect your cicd and understand risks inside your different systems and the guitar in the Jenkins artifactory and so on and so forth, but those also in the relations between the system because the systems are highly connected between themself. This is one layer the second layer is the ability to Implement and Taylor, the relevant engines are relevant to your environment how many how many times you know security teams brought in some very fancy scanner and they a lot of money and take out a lot of its Budget on specific scanner, but eventually the scanner is like good for very certain portion of your technologies that because any engineering teams using multiple languages multiple Frameworks, we see on average like around 15 different languages and Frameworks that are being used as part of the development processes and no and there is no single solution out there from scanning perspective that can support all those flavors. In a good way.
So we provide the ability to tailor from a Marketplace what you need whether by the way whether it's a commercial solution or open source solution. We are not tie ourselves to any type of solution. And and this is why we took a decision also not to try to develop a scanner by yourself.
There are good scanner. The problem is not the scanners. The problem is not to find something.
That is good for pythons something that is good for Ruby something that is good for no JS. The problem is that you need to be able to easy to implement it and also match it to the right technology and and stuff that you have inside your environment. You know guy, I think I agree where you said, I think another aspect of it is.
Oftentimes security people think of like pen testing or scanning as a point in time activity. This is a continuous process right software is being checked in Bill going into test at whatever and that the tool chain and the Technologies evolving at the same time. So you have to think you wouldn't put an intrusion detection system and and only turn it once a week right here, whatever technology it's got to be in line part of the process built into it upgrading to be compatible with the other Technologies.
So it's a context Sport and I think that's a mindset change for security people too. This thing continuous. Everything's got to be continuous.
You got to be in the workflow the pipeline. Mm-hmm. Absolutely.
Absolutely and and going back to the the first step. You need to be able always to understand what is happening. We the right context.
it's not only to know that you have for example python is need to know exactly which repo is located and which repo is going all the way to the production environment and which is not so you need to know and so on and on other aspects of the cic the only by understanding doing doing good asset inventory for your CISD. This is why we call it the technical DNA but giving you like in any other aspect that you need to do in your as a security practitioner, whether it's your corporate environment your production environment and development environment and environment. Before deciding what to do before deciding on the security measure you need to understand what you have.
You need to have a clear understanding with the right context. of the different elements and then that's let's make sure that we are giving the right security controls to what we have. I'm curious.
I don't know if this question will ever be resolved with the right answer is but do you sell the security people security Engineers if you sell the developers because I know the developer World else if you are immediately if you're not a development at all, right, that's a security too don't active security. Yeah, right that doesn't fit easily into my development environment. My my workflow my path my pipeline whatever it's got to be sort of.
Low friction right for them in add value not more work. Not that the security people want more work. They don't either.
So how do you approach that problem who to sell to? so I we eventually said to the security team eventually at the end of the day security team by security products and will invest in security tools. It's not like the budget right then the Bible it's not like developers will not invest or will try to find a solution if by the way they are small many small companies that they don't have security teams that that those stages but once you have a security team at the end of the day they are the ones that are being measured on security risks and gaps and stuff like that.
Of course more and more engineering teams are adopting more. proactive approach and try to be more good with security and Implement security as part of their day to day but at the end of the day, it's the security team that will will invest On those two. However, I must say it's not like we are completely focused only on security teams will also working very close with the devops teams.
Because they are strong champions of what we're doing. We are giving them the understanding that first of all a lot of elements of what we are providing is very necessary for devops day today the visibility that we are giving in the day to day of the cicd. not even for devops in many cases don't have this capability.
So we are working very closely with the devops team to to be champion of the platform of of. Cider, by the way. This is why we are.
For example, one of the main sponsors for devops days and these are one of the biggest conferences devops. But yet but the bottom line. Yeah, the budget comes from security at the end of the day.
Go where the money is not a bad answer. Well guy great to talk with you. I appreciate you stopping by you actually learned a lot both in your previous experience.
And now applying this to The Cider we're working folks find out more. io there. You have a lot of materials one of the pages.
We have the top 10 cicd risks something that we published just months ago something very interesting that we shared with the community, but we walked with the community before that such as Michael codes Adrian Ludwig from atlassian and many other amazing people from the industry. And this is something that related to the protection of the cicd and understanding the gaps and how you saw it. So also something very interesting to see and yeah, and also we have on guitar we have this cicd goat which is a deliverable cicd with Issues related to the top 10 cicd and you can do learning together with the devops team to learn about how to understand gaps inside the cicd and also try to protect them.
Joint project or work together with job and security. So. Alright guys, I appreciate it very much guy Fletcher who's co-founder CEO besider security.
Hope you come back again soon. Thank you. Thank you for that's Fidelity.
Thank you.