Developer-Led Landscape: Secure Software Supply Chain (Part 2) – Tyler Jewell, Dell Technologies Capital
Dell Technologies Capital managing director Tyler Jewell released his latest in-depth report on the developer market, “Developer-Led Landscape: Secure Software Supply Chain.” The report includes observations and industry insights from a curated database of 1,500 companies whose products are sold to, purchase-influenced by or consumed by software developers.
Transcript
This is Text Drunk tv. Hey everyone, welcome back here to Tech Drunk tv. You know, my next guest was, he was just on a few weeks ago, but that was actually last month.
This is now this month. And, uh, well, I'd have him on every week if you would come in every week to talk with us, but it's a pleasure to have that. Welcome back, Tyler Jewel.
Tyler, of course, is managing director at Dell Technologies Capital. And we, you know, beyond doing his thing at Dell Technologies Capital, Tyler has been doing a developer led sort of report analysis survey, really becoming like a fountain, a fountain head of information. Um, Tyler, how long now?
That's like your shirt. That Shirt. Much like my shirt filled.
There's actually a Greek Theology on that. This is a Greek design. I I bought it in, I think in the island of Paros.
And, um, yeah, well, we'll, we could talk about that off. It matches that shirt matches your personality, Alan, Kind of. Yeah, well I try to, I try to.
We're gonna just, we can't stay on topic. All right, Tyler, welcome back to Tech Drunk tv. How are you man?
Good morning. I'm good to be back. Thank you.
So, Tyler, before we jump into software supply chain, secure software supply chain, in this latest iteration of the developer led landscape, a little background on the whole developer led landscape series that you, you know, it's been kind of your baby now for a while. Why don't, why don't you just kind of bring our audience up to speed? Yeah.
The developer led landscape is a database of, uh, companies and products, um, that were either purchased by or influenced, uh, influenced purchased by developers. And it was a database that I started in 2009. Uh, the original version of it had maybe a hundred, a hundred companies in it.
And, uh, I maintained it over the years. Uh, did my first online public publishing of it in 2020, uh, and had been updating it a couple times a year with, uh, commentary about what are the trends in that database, uh, since then and there's now 1500 companies in that database covering a very wide spectrum of everything in and around DevOps. And it, it has really become quite a resource.
Before we go any further, for people who maybe want to dig in there where, how did they get to it? They can look at my sub stack and just do a search on developer led landscape, or I'm an investor at Dell Technologies Capital, they can find it there as well. Fantastic.
Thanks Tyler. Alright, let, let's jump right in though. So this latest sort of slice of, of the, of the landscape talks about secure software supply chain.
You know, it's funny, my interview right before you was with, uh, folks at OX Security, I dunno if you're familiar with them, but they very Familiar. Yes. Yeah.
Um, you know, SBOs and kind of that kind of thing is, is where they're at. And of course that's tied into this whole software supply chain, uh, issue. Tyler, give us, if you can, the three big highlights of this most recent, uh, report, this most recent slice of, you know, if I'm watching this, what do I need to take outta this?
What do I Yeah, what do, what are the must haves? I have to know. Yeah, okay.
Th three things out of this report. Um, the first is, is that, uh, business continuity is software continuity now, right? They are now inherently coupled with one another.
And so anything that can threaten the construction, maintenance or operation of a software system, no matter how minor, um, is a security threat because a disruption to, uh, the software system is a disruption to business continuity. That that is a fundamental thing that if, if your organization hasn't grabbed, come to grips with it, you have to grapple with that over the coming years. That's the first thing.
The second is that by the end of this decade, software supply chain security, meaning all the practices and products and disciplines that you have to do in order to secure the software supply chain, uh, will be a top three CISO concern. And it's probably gonna be well north of a $15 billion a r r market. Wow.
By the end of this decade, it's going to be, you know, right now it is not a top three CSO concern. There's probably more like a number seven or number number eight issue. Um, and it's going to be, uh, a top three C concern.
And as evidenced by, uh, the growth of this marketplace, it grew 30 perc 32%. Uh, we discovered 145 vendors who make up, uh, various solutions as part of how you secure the software supply chain. And, and that 32% growth is really driven by this urgency of purchase that has come from a number of government mandates that are declaring, uh, many software producing companies as having to meet new standards around secure development, uh, going forward.
Excellent. You know, one of the questions, and, and it came up in this, this security interview I referenced with you earlier is ultimately, right, soft software companies develop software, right? And they sh they have to be responsible to securing their software supply chain, but then that's software gets used, consumed, whatever you want to call it, by, by end users.
They may be commercial entities, they may be individuals or what have you. It almost seems like we're putting the onus on the consumer, on the user to, to make sure that the products they're using were in fact done with a secure, you know, with a secure software supply chain. Yeah, right.
Rather, and to me that's a little best wards, right? I I shouldn't, yeah. I mean, I should have confidence.
To what degree is the consumer responsible for validating you, you know, the safety, security, authenticity, um, yeah. You know, and, you know, and hey, how, what, what are the liabilities that I assume as a consumer by engaging with this particular type of software system? Um, I, I think that, you know, my, my engagement with CIOs and co CSOs, I don't come across anybody who feels consciously, like as a vendor.
They're trying to pass along liability to their end users. I just don't know of any businesses that do that. But I think that the breaches that we've seen have been so frequent, so, uh, uh, uh, damaging, uh, and, and that those breaches have caused consequences that have flown up to consumers.
Consumers feel like, Hey, where is my safety net? I don't feel like vendors are probably doing enough for me. And so it's creating a sense among consumers that, hey, I have to, I have to also be involved with the supply chain and validating it to protect myself.
And I, I think that the industry, um, has made some progress on this front. Like if you're a cloud vendor, there ares, you know, there is SOC two compliance, there is ISO 27 0 0 1, but these are, these are compliance mechanisms that B two B organizations will understand and appreciate, but the broad market consumer doesn't unders or is not, may not understand what they are, and they're certainly not gonna go and seek them out, um, as a way to gain confidence in around that. So there's, there's probably a need for a broader, a broader consumer friendly standard that can be a stamp of approval on software as a service systems or software that you download.
Absolutely. Here's another big complicator in this, you know, the flying the ointment for this for me, and that is, you know, with the advent of like APIs and third party dependencies being more and more prevalent, right? It's like that commercial and he told this one and so on and so on and so on.
It exponentially blows up that that supply chain chain that you have to, that you have to track. Yep. Right?
So I'm using this component, but really this component is just an a p I call The transit is of a component are oftentimes in the thousand measured in the thousands, right? Yeah. So each and every component you pull in, you've basically sucked in a, a couple thousand additional additional suppliers that maybe you haven't, you don't know about How the, how are you supposed to wrap your head around that?
Well, you know, I think, I think that, um, all all sorts of things that you need to do to get your heads around it. I mean, the first is, is that this is where the software supply chain is materially different than the hardware supply chain. If you are a car manufacturer, you, you do source not just all the pieces that come in to build the car, but all the pieces that tho you know, uh, that that was made to use the engine as well.
Yes. Uh, because that supplier has to source it and give you a stamp of approval around that. Um, in the software space, because you're changing the software so frequently, um, and, and the pieces that you're using are also getting updated so frequently, there's uh, uh, you can't do a static stamp of approval on an object that shift.
It's gonna be a dyna, it's a dynamically changing chain. And so that it requires new techniques that, uh, the industry hasn't had to grapple with. And, um, uh, and so it's no longer just sufficient for you to study the software that you're about to ship, but you also have to, as part of your secure practices, have software that interrogates the thousands or millions of transitive as well.
And there are, there are some really interesting and compelling vendors that have come out, um, to help you with assessing your external supply chain along with protecting your internal supply chain. I love it. I I got you off track though.
So we, we hit two of the big things in the report. What was the third one? The third one was, Hey, you know, um, uh, this is, this third component is that there's 145 vendors who are now producing solutions in and around this space.
Uh, uh, they're, they're already in billions of dollars of revenue. Um, and it's 32% growth. So the third big component here is, hey, this is already an active ecosystem.
Uh, there's a bunch of vendors that you need to do, you know, to a certain investigating that can help solve for this. Um, and, and we even provide some guidance in the report on if I'm a ciso, uh, and I really wanna get comprehension coverage, there's kind of four, you know, we kind of point you in four categories, four subcategories of the space. If you buy those four things, you know, you're in pretty good shape overall.
I I, I realize you may not have it on the tip of your finger, but what are the four subcategories? Well, you gotta read the report for that. Of Course you're gonna do that.
Yeah, Well, you brought it up. Well, the very first thing you, you gotta do is, um, uh, you, you need to start with a developer providence. Um, and we call it developer, uh, uh, software Posture management.
And, and what a, what a Providence system will do is it's going to help you, uh, uh, monitor the behavior of all your developers. Meaning you understand all the code that has been generated by ai, all the code that was copy pasted, and that you can drive, uh, uh, authentic signatures on all the code that you ship. It's not necessarily clear that because code was generated by AI and it works that you have copyright protections on that.
So you need a developer posture management system to, uh, observe what the developers are doing and put the stamp of approval on that. And then to also enforce lease privilege access for those developers across all the different systems where the code is being touched. So that's one.
The second is a pipeline security system, um, that really tracks, uh, uh, the, the, the movement of the software assets from, uh, code creation all the way through shipment, um, helps develop the SBO m creates the SS OMM archive, validates the SBO m aga against a bunch of different standards. You need, uh, a software composition analysis tool, which is how you interrogate, analyze, and track your external supply chain. Um, uh, that, that's going to be super, super essential.
And then an application security strategy as well. So, uh, static testing, dynamic testing, penetration testing, there's a whole range of things you need to do to validate that the code, you know, the operation of the code is gonna be sufficient. Excellent.
Um, last question for you, 'cause I we're running out time. What was the big surprise for you in this report? Anything?
Just Go ahead. Yeah, well, I mean, you know, the, the, there was a couple of big surprises for me. I mean, one, you know, application security testing has been around for 30 years and, and it's really dominated by, uh, a few very, fairly large vendors within the two to $400 million range.
And, and they had, you know, uh, over the past decade growing at kind of a sleepy pace. It had been a sleepy market, sleepy pace growth. And, and so to see the inflection point from, um, kind of slow growth to now 32% growth that happened over the past 36 months, uh, is pretty remarkable.
Now, some of that growth came from the large vendors like a Veracode, um, that that's out there. Uh, but, but it's also augmented by what is effectively a hundred startups, um, that have materialized over the past five years, uh, that are really providing disruption on software composition analysis, the developer posture management and the pipeline security. These are really kind of, you know, new emerging, uh, disciplines.
But, you know, and while there's a lot of startups there, their revenue is, is not, is material and it's material enough that causes the whole segment to get this nice uplift in growth in the inflection point. Yeah. I mean, you know, look, I've been covering security a long time.
I've been in security a long time. My experiences is what generally happens is a few of those big guys are gonna gobble up some of the more successful smaller startups and, and kinda cooperate. Well, there be consolidation.
Is there gonna be consolidation on that? Oh, There has to be. That's the way of the world.
We'll, we'll see. You know, it, um, it, it, it, it, it could happen. Uh, but all the early acquisitions that have happened in this segment have been to vendors who are not in application security, right?
So, cider cider security got gobbled up on Palo Alto Networks. Um, uh, but there's a rumor, there's a, there's a rumor that started by TechCrunch that CrowdStrike is thinking about buying a purchasing bionic, which is an A S P M solution. I heard that rumor, Again, not in the AppSec players.
Um, you know, Microsoft has some AppSec technologies, but I think that, you know, they're, they're hinting around, but, and also sneak bought inso, uh, yeah. You know, I think it was like $50 million they bought inso, right? And, you know, and SNY is a S C A player, but, you know, I know that they want fancy themselves as an application security vendor, but I think they have work to do before they're fully in that space.
So I, I Think they, they have aspirations of doing that. You're right. I think they've changed their, their marketing.
I look, I, I think some of the earlier AppSec players, you mentioned Veracode, but, and they're, they're all in on this, but, you know, some of the earlier apps say, I don't wanna speculate, but the white hats and the check Marxs and the, even the contrast and the synopsis and, and all of these, the, the question is, can they innovate fast enough to jump to secure software supply chain tool race, or are they making a make versus buy decision? Well, you know, they're, they're, that's probably what they're doing at the corporate level. But if any one of them were to give me a call, the CEOs or the strategy officers, or any one of them would give me a call, what I tell them is that, hey, they're, they're long history.
Uh, what it, what it, what it's given them is a set of customer relationships, um, that are unparalleled. And, and those customers in the process of adopting their tools have, um, uh, taught their development organizations a certain type of developer experience. And so, so they are, they are the harbinger, if you will, of understanding how developers work with security issues.
And so they're in a prime position, um, to expand upon that existing security, uh, developer experience and just, and just make it more encompassing and lock down the entire supply chain on that. So I think, I think they're well positioned. Um, uh, I think the biggest mistake they could make is just not acting fast enough.
Uh, which, which is probably the, the, the, the tendency of large companies that have a lot of revenue to protect, they, they should be moving and moving fast. Agreed. Tyler, thank you for coming back on.
We'll see you next month. Absolutely. All right, man.
Tyler Jewel, managing director Dell Technologies Capital with his developer led landscape. Check it out, his developer led landscape, check it out on, on his sub stack or on the Dell Technologies capital site. Always great stuff there, Tyler.
Thank you. We'll see you soon. We're gonna take a break on Textron.
We'll be right back.