Cybersecurity Requirements of Cloud Computing with RAD Security’s Brooke Motta
RAD Security CEO Brooke Motta dives into the unique cybersecurity requirements of cloud computing environments in the wake of the company picking up an additional $14 million in funding.
Transcript
This is Techron tv. Hey guys, thanks for the throw. We're here with Brooke Mata, who's the CEO for RAD Security, and they just picked up $14 million in additional funding.
And we're gonna talk about with, well, first, how is that funding gonna be applied? And b well, how is security changing in the age of ai? Brooke, welcome the show.
Thank you for having me. It's great to be here. Well, congratulations on the funding, but um, after, you know, you bought everybody involved a beer, what's the priority here?
What's, what are you guys thinking about? Funny enough, we're in New York with one of our series A investors having a beer. Uh, not right at this moment, but, uh, we did last night.
Anyhow, uh, so good question. Um, we, uh, are working with a couple of new investors as part of the round as well as a few of the old ones came in as well. Um, and so the new investors are political, uh, ventures, which is the investor here in New York that we, um, spent some time with this week as well as, uh, Cheyenne Ventures, um, which is a West coast based vc.
Um, they are our lead in the round. And then we also have an investment from Akamai as well, uh, in terms of answering the question that you brought up earlier, and what are we gonna do with the money that's, um, what our investors would like to know as well. Um, and so we've had, uh, some success in the early days of Rapid seven, post our series, uh, seed funding.
And, um, and we want to really start to ramp up the sales and marketing organization, um, as well as hire some additional engineers to help us tackle the problems. Um, with AI that we're tackling today. It seems like cybersecurity is changing in, in a lot of different facets, but the one that seems to keep coming up is this sense of the need to build a platform and the need to centralize more functions inside of a platform.
Is that kind of where we're headed long term, or are we still gonna be wrapped around individual little tool sets that we're trying to stitch together? Yeah, I think for a lot of founders, especially in the past few years, it including, uh, you know, at moments in rad security, there are temptations to chase shiny objects and expand. And so we've been working really hard to stay focused, focused on our area of, um, of cybersecurity and, uh, and to not become too comprehensive as a startup of a platform where we're, uh, you know, a hundred miles wide and not very deep at all.
Um, so we have deeply connected to solving problems with infrastructure security, um, and that now extends into ai. So what specifically is, is infrastructure security in your mind then? What am I, what kinds of tools?
'cause I mean, it's just an alphabet soup of stuff out there and people get confused. So what exactly do I need to secure infrastructure these days? Well, you need, um, great people.
Uh, uh, you don't always need products, uh, first of all, but as a product vendor, I will tell you that our approach has been to think about in, in the early days, just a trip down memory lane. We started off as a Kubernetes security company. Um, and so Kubernetes is a widely adopted technology.
Um, we then expanded into cloud detection response. Um, and now what we've discovered is the ability to understand not only what's happening, uh, in your workloads, but also what's happening in AI workloads. And so we started to really think about runtime security, workload protection, and AI security, all sort of under the same, um, uh, delivery mechanism, which for us is looking at behavior and first fingerprinting to identify known good behavior.
And then, uh, looking at drift from that known good behavior to identify anomalies. We've been kind of stumbling our way towards this integrated approach around DevSecOps and we're trying to secure the platforms and their workloads and the runtimes. From your perspective, what's been the challenge?
'cause I feel like we're keep making fits and starts in that direction. Well, I mean, the world's changing. It's completely different now in terms of infrastructure than it was a year ago.
The dependency on AI for high velocity is, um, is there, and it also introduces new risks to most organizations, and so becomes really hard for, uh, security teams to wrap their brain around what's happening when the world's just changed so fast in a year. From my perspective, And as part of the infrastructure, we're seeing new animals in the proverbial zoo. There are GPUs and different types of platforms that need to be secured.
Are they fundamentally different in terms of the challenges or are they the same, but they're just kind of a different thing I need, they're a different type of artifact that I need to secure? Or what's the challenge when I think about AI security and infrastructure? So for the, for, from a rad perspective, we were able to use the existing telemetry.
We had to extend our capabilities, uh, in order to detect issues and workloads. And that includes data exfiltration, um, uh, insider threat. Um, and, and so for us it's sort of a similar approach, but for others it's different.
You know, there are tools out there that are doing, uh, pen testing using ai, um, and, uh, lots of other cybersecurity. There's probably one a day, maybe more cybersecurity companies that are, uh, created to help solve problems with this new modern infrastructure. But for us, it's largely a similar approach.
Are there workloads that are gonna be deployed on this AI infrastructure richer targets, and what are we gonna need to kind of double down on how we protect those more aggressively than anything else we do? Because, well, there might be an AI model running on that thing that is critical to the organization. Yeah, that's right.
Um, and it starts with knowing what you have. Um, been talking to a Texas based insurance company a lot lately, and, uh, and it all starts the same way that we approached vulnerability assessment back in the day where you have to first know what you have and do discovery and, uh, know what's out there. And the same thing applies to understanding what your, uh, engineering team is using in terms of, um, ai, uh, not just the engineering team, but especially the engineering team.
And then what's happening on those workloads, uh, for, from the case of rad security. So, um, it is, it is a big problem. And, uh, yeah, and so we're trying to be there at the intersection of, uh, AI and security to help.
So what is the relationship between the security folks and the engineers these days? 'cause a lot of the times it's the engineers who are provisioning all this stuff and then the security people are trying to figure out what happened and they don't have visibility into this conversation, and then they are surprised when they wake up one day and find out that everything's misconfigured. I think that that's still the case in some organizations, um, are, uh, ICP tends to be organizations where the security team makes a focused effort to be close with the engineering team.
And so nothing's happening in a, a silo. Um, but we do talk to lots of different, uh, CISOs and organizations and, um, there are still a lot of siloed organizations out there where, um, the velocity of the engineering team is so fast that security is a serious afterthought. And so, um, uh, yeah, I guess it's very cultural, uh, and, uh, a lot of Uber here in New York meeting with a lot of modern companies that tend to, from the start build with, uh, security and engineering pretty closely aligned.
I think you put your finger on. Part of the problem is the velocity at which we are deploying applications and updating them is a major challenge for the security folks. And near, as I can tell, um, with the rise of AI coding tools, that's only gonna get worse.
So, um, how do we make it all better? How can we help the security people stay current with the pace of change that is just gonna exponentially increase in, I think for some organizations, uh, while security and compliance are definitely not the same thing, um, sometimes compliance as a driver is helping push security initiatives for CISOs. Um, now nothing or most things are not mandated for security leaders as related to ai, but, um, we do, we are starting to see, um, uh, compliance regulations like ISO 42 0 1 and the EU AI Act coming down, and a lot of security teams are actually choosing to become compliant, not because they have to, but it gives their customers a sense of confidence that they're handling AI in a secure way.
Um, and there are organizations out there who are helping to, uh, helping those companies to become compliant. So, um, that's one thing that we are seeing to address the problem. Uh, I think that the alignment that you brought up earlier between security and engineering is critical in order to make sure that, um, we're solving problems, uh, as, as one team, um, but also not slowing down the engineering organization because, uh, even if the company is huge, they still need to get out and ship quickly and, um, develop new, um, technology.
And so, um, security is trying to find a way, uh, with the help of lots of different vendors, and we hope RAD is one of them, uh, to make sure that we don't slow down velocity of engineering, but also, um, help security gain confidence that what, um, is happening with AI is done in a secure way. So we've seen, uh, more AI workloads as of late, and we're aware that the bad guys are using AI to attack us with greater sophistication and volume. Um, can AI help the good guys and what might that look like?
Yeah, for sure. Uh, so I only talked about one part of what RADS doing. Um, RAD has the ability to do, um, workload detection, uh, and um, identify issues, uh, in runtime, but also we have an agentic approach to our platform that allows for you to make really efficient decisions as well.
And so, um, our customers are able to, uh, especially GRC teams, uh, are able to quickly understand their highest level of risk to prioritize accordingly and, uh, remediate as well. And so the telemetry and the RAD cloud detection and response platform has allowed for them to, uh, be able to do that pretty well. Um, but it's not just rad.
Uh, there's lots of organizations out there and people who are forward thinking, who are trying to stay ahead of the, um, the bad guys, uh, for lack of a better word, um, uh, in order to keep up with the innovation that doesn't just exist with the, the security teams that the companies that we're talking to. But it also exists in, you know, uh, large organizations who, who are, have huge incentives to, um, exploit these workloads. So as we think this through for a little bit, will agen AI make security more accessible to a broader number of people and help close that skills gap that we've been wrestling with for the last as long as anybody can remember?
That's right. Yeah. Um, and you know, for us it's, uh, we just talked to a company in New York who said that the time it took before using RAD to get to the data that they needed, um, for, uh, governance risk and compliance was 30 days, and now it's three minutes with the RAD platform.
And so, um, you know, the amount of manual work that people were doing historically, um, doesn't, uh, lend to efficiency in a modern organization. And so, uh, we're doing everything we can to help, uh, create time to value and, uh, remove, uh, manual efforts so that security teams can focus on prioritization of real risk and, uh, not, you know, redundant or, um, low level tasks that can be replaced with, um, ai. Rook.
You've been around the cybersecurity block a couple of times now. What's that one thing you see organizations doing that just makes you shake your head and say, folks, we could be better than this? Well, I think you actually made me think of it with the, uh, the security teams being aligned with engineering teams today.
Um, I, I remember 15 years ago walking into, uh, WeWork when WeWork was in its heyday, maybe it was 10 years ago. Um, but uh, the, there was a person there, his name is Raj at the time, he's no longer there. Um, but I remember talking to him about how closely he was aligned with engineering and he was doing some really novel things.
And since then, you know, a lot of organizations have adopted that practice, but you still see some legacy c CISOs who, uh, operate in silos. And, um, and the other thing, I'll just have a bonus number two is the legacy approach of managing with a stick. Um, I just don't think that works in 2025 anymore, um, uh, with managing security teams.
And so I still see that in pockets and have talked to a few people who do that this week. So, uh, that's the other thing that sort of makes me ugh, a little uncomfortable. All right, folks, you heard it here.
The game has definitely changed and the only way to win it is to well lock arms because otherwise the bad guys are gonna find ways around anything we do, no matter how advanced technology gets. Hey, Brooke, thanks for being on the chair. Thank you for having me.
I appreciate it. All right. And back to you guys in the studio.