Cybersecurity Funding and Cost Sensitivity with Aqua Security’s Dror Davidoff
Aqua Security CEO Dror Davidoff, in the wake of the company picking up an additional $60 million in funding, explains how spending on cybersecurity is evolving as organizations become more sensitive to costs.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We are here with Draw Davidov, who is CEO for Aqua Security.
They're fresh off of picking up an additional 60 million in funding, and that brings their valuation north of a billion. And I guess the first question is draw, after all this time, what are you gonna do with that kind of money? What's the goal?
What's the strategy? What, what, what needs $60 million in funding? Uh, well, first and foremost, to keep a fueler growth, uh, you know, the company, um, have been growing quite rapidly for the last seven years, and we keep growing and, uh, we need, uh, to fuel the engine.
So, uh, we need, uh, we need additional funding to practically take the company to the next level in our, uh, growth. Uh, and we're going to invest it. Um, we will keep investing in the product and the platform.
I think, uh, even after seven year, we have very ambitious, uh, roadmap. We want to keep investing in building our platform, our solution for our customer, for cloud security. And we also want to keep investing in expanding our Go-to market additional geographies, additional verticals.
Uh, we made a huge investment in federal, so we want to keep making this investment, uh, over there. Uh, so that was the main motivation. It seems like to us that there's been a shift towards a more platform centric approach to cybersecurity.
Folks are trying to consolidate tools both to save money and make it easier to kind of maintain some context while fighting the big fight. What's your sense? So what is the current state of the cybersecurity market?
Right? So no surprise, of course, there is a, there is very much needed consolidation, but the, we, we need to understand what does it mean It's not a plain vanilla, uh, consolidation. So if we just look at cloud security, um, you know, and, and I think there is bigger consolidation that should happen in cyber, but just look at cloud security in the evolution of cloud security for the last practically decade, there are dozens of point solutions, literally dozens of point solution that, uh, you know, were very much a, a, a reaction to an immediate need.
So a, you know, Aqua's example, when we started eight years ago, 8, 7, 8 years ago, a Dockers container were coming to the market and people said, ah, wow, great technology, but we need to secure it. So when they looked for Docker security, right? And then came Kubernetes, and then came serverless, and then came, um, you know, many, many, many other components, API security and the, and the, the supply chain and the vulnerability scanning and the, a long set of specific network segmentation and, um, and, um, I identities and the permission and provisioning, there was a very long list of things that emerged as a specific requirement, and then there was a point solution emerging coming out to solve that problem.
And what companies find themselves is now looking at cloud security and understanding that, uh, they have too many tools and they that create a lot of a noise in the system because those tools, you know, do not always, uh, exchange information in a, in a, in a good way, right? So when we think about consolidation, our view here is that there will be consolidation around three main domains, if I may. Uh, uh, think about it.
One domain that aqua is not a player there is, when you think about the networking, the traffic that is going in and out and southwest in the cloud, right? So, so there's a whole set of solutions that will consolidate. This is the, the SE and the API and the network segmentation, all those different solution to solve the traffic issues in the cloud, right?
Network traffic issues in the cloud. The second big area, which where AQUA is playing, is to think about your cloud native application in the cloud and everything that you need to do in order to secure your application. And that's where AQUA is, is a very, uh, uh, important player and we have a very good solution for that.
But now it's, it's a very specific use case. It's your application security in cloud native environment and everything that you need to do from code to cloud. And I will elaborate about that, but I, we believe strongly that there will be consolidation in that specific, uh, I won't even call it vertical, but that cluster right of, of them.
And then there is the issue of, um, cloud infrastructure or configuration and visibility tools. And, and there some of the consolidation already happen and will keep happening. And this is, when you think about the CSPM and the KSPN and the Kim and DSPM, these are all tools that are about your security posture.
They're not solving the problem, but they're just giving you good visibility to understand what is your security posture, what are the areas that you now need to go and fix? What is your compliance, um, uh, status, et cetera, et cetera. And this is another set of things that we will see a lot of consolidation happening.
Now, some of the mega players like Palo Alto will claim, well, we will do it all for you, Mr. Customer. We have all the tools that you need to, to save your cloud or solve your cloud security problem.
We think that there is a lot of a know one, know-how and expertise in each one of those cluster that I just described. And there will be a big enough problem for organization to have consolidation around those clusters of problem and not say, okay, I need my cloud security for one vendor. And by the way, it doesn't really ha uh, work for a Palo because it's, it's too broad and there are big gaps.
And, uh, you know, a good size enterprise will always look to have the best of breed to say, okay, around each one of those strategic problem, the application, the infrastructure and the network, I want the best solution there. That's the kind of consolidation that I predict will happen in cloud security. What is your sense of, um, the complexity of the environment?
Initially, we had a lot of talk about monolithic apps, and then we had a lot of, um, cloud native applications, containers. Now we have serverless computing frameworks. It seems like the whole attack surface is more complicated than ever.
Um, how do we approach that in a more holistic fashion? Absolutely true. The, the, the challenge of the perimeter, the challenge of, you know, your application is now broken to hundreds of microservices that are very portable and moving from one environment to the other environment.
I think we, we think that's one of the major challenges in cloud security. Aqua solution is focused exactly around that. We think about the workload itself and what do we need to do to protect it.
But we also think about it in a very, um, holistic way. What do I mean by that? We think about, on the one hand, how do I set the policy in the way that it'll be, um, relevant in all my different type of workloads, wherever they run.
And then there is the enforcement mechanism, the agent that is the, uh, the, the workload itself. And then for the different types of workload, we have different types of agent, whether it's container, whether it's serverless, whether it's, um, a zu, whether it's a Windows container. There are multiple types, probably seven or eight different types of workloads at the end.
And, um, and the aqua, you know, biggest strength is the ability to have, you know, the, this range of different enforcers for any type of workloads and the ability to set the policy once no matter where the workload we run, whether it's on-prem in the cloud, multi-cloud, or whether it moves, you know, from being, you know, bun packaged in one way to another way, maybe today it's packaged as a container, and then the following day it's still packaged a container, but now it's running on Fargate, which is a managed container, uh, environment. We will still have the same policy. We will just use a different hook or technology at the agent level to do the enforcement to the different types of workloads.
So for us, what we call, we, we we're saying we're platform agnostic. We don't care what type of workload and where is it, where does it run? We know how to protect it.
Of course, you cannot walk down the street these days without somebody talking about AI and cybersecurity these days. So what's your take on what's going on with AI and has it helped the bad guys more or the good guys more? From what I can tell right now, it's still, you know, helping more the bad guys than it is for the good guys because, uh, it just made it so much easier to replicate attacks and, um, you know, the level of knowledge now that the attacker needs in order to be very effective is much lower.
So, you know, it, it's lowered the bar for the bad guys. On the good side, I'm sure that we will see great things and great help for the, you know, the, the, the, the defenders in helping us improve the security posture and the security level for organization. But the, and where would it, uh, happen for aqua?
So we think about multiple areas where we can do two things. Number one, reduce the noise. So how can I take a very large set of vulnerabilities or a very large set of alerts and use AI in order to reduce it and identify the, the music for the noise, right?
To separate the music from the noise to really help organization to focus on the, excuse me, on the most critical vulnerabilities or the most critical alerts. Okay. Because, you know, that's one, I think that's one of the biggest challenges of security nowadays.
We have plenty of detection tools, there is a lot of alerts, but then, you know, separating that, and I think AI can play a major role there. Another area is in the remediation. So can I, now, now that I have identified and I narrow down, what are the most important thing, can I use AI to identify what is the best way to remediate it?
And this is a, today, a lot of this work is done manually. People have to go and research and identify the code and what is the problem in the code and what is the recommendation on how to rewrite it or to replace the library or what, whatever are the instructions to remediate a problem. And this is manual work that, you know, requires heavy investment.
So if I can now do this with AI and reduce a three day into a three minute effort, I think that will be a huge, uh, productivity gain for the security practitioners. So these are the two areas that we right now working on, things that they are coming out. Some early, early capabilities are already embedded in the product that is, uh, publicly available and there is more coming in the, in the next few months.
So these are the first waves on how AI will help us and, and help our customers. There are other things that are a little, you know, more futuristic and are still in early stage that are thinking about a, you know, can I use AI to do generative security, right? Can I predict where are the problems and now create policies to prevent those problems?
It's, it's a little too early to talk about it, but this is a direction that we're looking at Who's in charge of security these days. And I ask this question because there's always been this divide between the security team and the application development team, and the dev guys are provisioning cloud infrastructure and deploying the workloads, and the security guys don't always know what's going on. Has that gotten any better?
We've been talking about DevSecOps for a while now, but I'm wondering, you know, are we making any progress? Well, you know, it's, uh, it's always the darkest be before the light comes out, so it'll get a little worse before it will get better. We're in a, we're still in a transitional phase.
It's been for a couple of years. So historically there was this battle between engineering and security, right? Because security are responsible for security, but in order to really fix a problem, they need the help of engineering, right?
So, so there was always this tension, uh, uh, between the two. And many times security will identify an issue and engineer and say, well, actually it's not a real issue. Well, who, who, who are you to say, you know, who will decide if it's a real issue or not?
That's the history. When cloud emerge, the, the, the scene have become more complex because now you have the DevOps that are responsible for the cloud infrastructure. And now it's a, it's a three-way conversation.
It's not only between security and engineering. Now there is also the dev and I think a few conclusion. Number one, there was a realization that the, there is a dev sec.
There is someone that have the DevOp and the security understanding that will emerge, and he's the guy that will have the power of understanding and fixing many of the issues that historically were in the hands of engineering. If you look at organization, very few really have a dev ecop function, but they're all thriving. They're all aiming to have one.
And, uh, one of the conclusion at least that I heard from multiple customers is to actually take DevOp people, DevOp skillset and then train them in security. That's a better approach than to do the other way around, to take a security person and try to educate him with DevOp uh, skills, right? So, so at least the market now understand what is the career path?
So if there is a strong DevOps skillset, you can now train in the security, uh, uh, skills. And then now you have your dev sec. Organizationally, it's still not structure.
I mean, is it reporting into security? Is it reporting into DevOps? Is it reporting into engineering?
Talk to three different organizations. You see three different answers, but there is evolution of the market. Um, one thing for sure, when we started our journey in seven out of 10 cases, the budget for our solution were within the DevOps team.
It'll, it was always DevOps and security that had to make a decision. But who was the budget owner? Historically, it was much more the DevOps.
It had changed dramatically, probably eight out of 10 cases. The budget owner will be within the security team, under the cso. So that one thing that they've already, you know, the market have already shifted as far as the practice of DevSecOps.
There's still the way to go, but we see this, the market is, it's constantly moving and I think that's the direction it's moving in that direction. So what's your best advice to customers at this point? What's that one thing that kind of makes you shake your head and go, folks, I think we're better than this and if we could solve this issue, we could start moving forward and all this other stuff.
I think, and you know, what I'm saying here is probably not a, a not no, no secret to any, uh, um, experience cso, um, there, there was a period of what I call of a dissolution, right? There's all these acronyms and Gartner came and all these many, many new vendors coming out with, you know, very big promises, right? So I think to shift into what are the real important use cases that you, it's an enterprise need to accomplish in the next 12 to 24 months.
And then around those use cases, what you currently have, what are you missing and where can you consolidate whether with existing tools or bringing in new vendors to consolidate. And I think the focus around the use cases, there is a much better clarity because there is much more experience in the market to say, ah, what do I need for my cloud native application to secure my cloud native application? What is the set of control that I need to report back and to really harden in order to have the right security state?
I think there is much better clarity on that, and we will see more and more organization focus on that rather than trying to buy this point solution, whether it's DSPM or Kim or API or A-A-C-W-P-P or C-S-P-M-A-S-P-M, I can keep on and on with all those different acronym. I think there is now understanding that there is broader encompassing use cases. What are my priorities?
Which of the use cases are the top priorities for this coming year? And different organization will give you different answers. That's also a, um, uh, something that we, we see.
And, um, based on that, think about how can you now effectively consolidate consolidation is a good thing, but it's too much of a broad title right now. You know, to bring it down to earth is where where can you do this effectively and where you can really as an organization will gain from this consolidation. All right, folks.
William, you heard it here. Acronym bingo is no way to approach cybersecurity. So a little, a little focus will go a long way.
Gerra, thanks for being on the show, Micah, great to be here. Thank you so much. All right.
And back to you guys in the studio.