Empowering Innovation with RAD Security’s Brooke Motta
Brooke Motta, CEO & co-founder of RAD Security, explores how the company empowers teams to zero in on what matters most: Pushing boundaries, building technology and driving innovation, so they may focus on growth and success, not security problems.
Transcript
This is Textron tv. Hey everyone, it's a Shimmel. Welcome to another Textron TV interview.
You know, we've been continuing our look as we get ready for RSA at the, uh, innovation Sandbox finalist, right? This, as you know, if you've been watching this show for a while, this is I think the 18th or 19th year for the RSA Innovation Sandbox. Our friend, Cecilia Marne, she comes on every year and she talks about, it tells us who the finalists are, and we try to bring you these finalists before they're actually up on stage at RSA, so that if you're going to RSA, you could go there and check 'em out for yourself and see, and you know, when you look over the course of the 18, 19 years, not only the ones who won on any given year, but if you take the whole finalist class for the 18 or 19 years, it's a who's who of of successful security companies.
So, when you go to RSA and you're there, and you get a chance to go to the Innovation Sandbox kind of area where they, you know, they do the, the, uh, judging and and so forth, you're looking at tomorrow's security success stories. I'm happy to bring you one of those, hopefully today. Let me introduce you to Brooke Mata.
And Brooke, I hope I said your last name right? You did, yes. Thank you.
Yes, that's right. Thank You. It's Brooke Mata.
Brooke is the CEO and Co-founder of a company called rad, RAD, security. I don't know how many of you have heard of rad, but they were formerly known as KSOC, and Brooke is gonna explain that to us as well. And we're gonna talk about RAD and Cloud Native Security and Sandbox some more.
Hey, Brooke, welcome to Text Drug tv. It's great to have you on. Thank you so much, and thanks for having me.
It's a pleasure. So, Brooke, before we get into RAD and Ks o and and, and Sandbox, let's talk about Brooke, if you don't mind. Sure.
We were talking a little bit before we came on camera, but tell, if you wouldn't mind share kind of your journey, how you came to be CEO and, and co-founder here, and Sure. Then we'll go from there. So I've been in security for almost 20 years now and started my journey at Rapid seven in Boston, um, Massachusetts.
And so I worked there for about 10 years, and that's where I first went to RSA. Uh, I actually found an old picture of myself, uh, from about 15 years ago, attending RSA the other day. Uh, I've largely been leading Go-to market teams, uh, for organizations like Rapid seven, then Bug Crowd, and most recently was Bono type before, uh, joining forces with my co-founder, Jimmy Musta to start now RAD Security, then koc.
Yep. So I know Jimmy well for years. Did you say Sonatype was the last one before?
Yeah, yeah, I worked at Sonatype. So Wayne Jackson, of course, is a friend as well. He's, and, um, I'll tell you a secret, when I, you know, I didn't do this forever.
I, I had started several security companies. One of the ones was still secure and we had a vulnerability management solution, and I remember, I think it was, is it Alan Williams? Allen, somebody from Matthews, Matthews, Alan Matthews started Rapids and Around That's right.
The same time I started Still Secure. And actually Alan was a friend for a while. I haven't spoken to him in a bunch, but, um, I knew the Rapid folks.
Well, I have His number if he wanted. He's great. Well, I'm, I'm connected with him.
I just, you know, he's, he's a great guy, Alan, he's, you know, obviously hasn't been as involved day to day in Rapid seven for a long time. I know Corey, and of course HD Moore and, and all of the HD's all gone from there too. A lot of the people I knew at Rapid seven moved on to bigger and better things in their careers.
Um, so it's interest, you have a real security, you know, you, you've lived that security life now for 15 plus years. We've seen a lot of changes come over it. Jimmy's also a security, you know, rockstar has been around a long time.
Tell us, like, what was the deal with KSOC and the move to rad? Sure. So when we started the company, um, we were very focused on Kubernetes security, and that's how we started.
Um, Jimmy has historically been training, uh, fortune 500 organizations on cloud security best practices, and often starts with Kubernetes security training. Uh, we, when we joined forces and started the company, started with a Kubernetes security offering, um, but then started to really expand out into runtime and workload protection, um, and, uh, software supply chain security as well. And so once we started to expand, we felt the name was a little bit limiting, and that's why we changed it to Rad Security this year.
Very cool. Does Rad, is it RAD stands for something or rad? Is it radical?
It Doesn't just rad. Like, like for It's rad it's rad For the cool kids, Yeah. For the cool kids out there.
Very cool. Now, as I said earlier on, we, we have been following this year's class of the 10 finalists for the Innovation Sandbox. Um, at RSA give our audience a sense of look what goes into becoming a finalist.
Kinda what, what, what hurdles, what hoops did you have to jump through? So Cecilia's great. You mentioned Cecilia earlier.
Um, she's been wonderful to work with. So, um, we had to submit a pitch first, um, and then a video. We met with Cecilia a couple times just to make sure that, um, we were trending in the right direction.
Um, you then have to, uh, follow a template that they give you, uh, for the onstage presentation. Um, we have a window of three minutes to present once we do get up on stage and it's, and then there's three minute q and a section session afterwards. Prior to that, the judges are also going to be meeting with all of the finalists at their booths to do a demo and a q and a session at the booth as well.
So that gives the judges a little bit more time to do a deep dive. And I think that that's a new thing that they haven't done at RSA in the past. So we're excited about the opportunity to shelf the product as well.
Absolutely. And you know, they have a, a ma I our interview with Cecilia, we went over the judges what a, what an Allstar Hall of Fame line up for judges. Oh, it's crazy.
Um, yeah, Two really amazing accomplished women. Um, yes. Yeah.
Well, you know what? A lot of people don't real, so I've been going to RSA for 20, since 2001, so I, I guess 23, 24 years. Um, and I've been friends with the folks who run RSA conference for most of those years, Linda Britta, Michelle Adams, Dixon, and Cecilia, all of them.
It used to pain me, especially over the last couple years, like three COVID and then a little post when people were kind of dinging them for not enough diversity and stuff. Yeah. Because the fact of the matter is, it's all women who run this show, right?
There's maybe one guy or two people, you know, two men who are at that level. Um, but it's a, it's a, for the most part, a woman run show. What are you giving them a hard time about diversity here?
They're more diverse than any other organization that we deal with. Yeah. RSA is definitely doing, putting in the work to make sure that they're, um, recognizing the hard work and hardworking women in our industry who are really taking the lead.
Absolutely. Coming founders. And, and, um, there's a blog about to come out, uh, and will be on the rad security website that features women, um, like Michelle, the founder of CloudFlare and Dana Wolf, uh, also a founder X Rapid seven two, um, yep.
Dere Diamond. Uh, so there's a, a blog about to come out that talks about, uh, female founders, but RSA, you're right, it's doing a fantastic job. What's the address for that rad security blog?
You know, Um, well, you can go to Rad Security and, uh, it will take you Right. Just quick to blog. Yeah, very cool.
Send it to you. Uh, also, um, I'll give you the preview. It's already written.
Uh, very Cool. We, we like that. You know, we, we do, uh, we tried to do, we Can, we have a one video show, we do Techstrong women where we feature prominent women.
Then we have another one CSO talk where we, Jen, I don't know if you know Jennifer Manila, but, uh, she's the co-host of it as well. And, and we, again, we try to, we try to be as diverse as we can. Right.
And it's not just women, it's, it's a lot of underrepresented communities. Um, but we, you know, it, it's funny, I was actually just ordering t-shirts. 'cause Monday we put on our DevSecOps event every year at RSA in partnership with RSA in the Moscone Center.
And the last couple years I realized that women don't like to wear men's t-shirts. Actually. That's true.
Yeah. You know, so I try to order a certain amount of T-shirts that are cut, you know, for women or anyone who wants to wear a women's shirt. Like there's some guys who like to wear, it fits on your sleeves and everything too, but, um, and I don't really care what you wear.
I mean, it's not, but you know, in trying to allocate how many of that cut versus the regular cut, I'm still only getting 20% and I'm looking forward to the day where it's a 50 50 split or something like that. You know, I, a hundred years ago I went to law school, and in the law school I went to, I was the first class where it was 53% women. Wow.
It was more women than men. Wow. Which is the norm now in law school, actually, for the most part.
Little a time. Yeah. But it wasn't back then.
So we're making progress slowly but surely. Anyway, Brooke, I wanna jump in and talk a little cloud native security. We'll, we'll come back to RSA before we wrap up, but let's talk about cloud native security.
I'm just back from Paris. I was at Q Con and obviously security was a huge topic. Uh, at the event.
There were, what would they, almost 13,000 people in Paris this year for cube c**t. And, um, it's evolving, I'll say that, right. It, we haven't quite solved this puzzle.
Uh, Kubernetes overall isn't easy. Kubernetes security isn't easy. Uh, and, you know, and the problem is the cloud Native trade isn't stopping to allow security to catch up and hop on.
It's very much a case. You gotta hop on the moving train here and that train continues to accelerate. That's right.
Talk to us. Yeah. Talk to us about the challenges and maybe what you guys are are doing about it at rad.
Yeah. So, um, cloud native development is one of the largest threats that are, is facing security teams today. And so in order for those teams to develop resilience against those threats, uh, you have to bring in detection and response teams, detection and response solutions that are evolved beyond signature based, uh, solutions.
And so, um, many organizations are hiring these sorts of people today and really starting to figure out ways to address these sort of issues. And we just saw it recently with the XD backdoor that came out then that's, in our opinion, just the tip of the iceberg when it comes to software supply to chain attacks that are targeting cloud native environments. I, you know, Brooke, I think back to when like, cloud first kind of burst on the scene, I guess around 2005, 2006.
And at the time a lot of people just took their on-prem security stuff, you know, pushed it up to the cloud and said, voila, we have cloud security. Right, right. My friend Rich Mogul at the time used to call it cloud washing.
Right? You would cloud wash your existing security to make it cloud security. I think a lot of people look at cloud native security as maybe not much different than cloud security, but it is, you know, there, there's definitely some, and it's beyond just nuances.
It's not, it's not subtle, it's, it's subtle as a, you know, a shot to your jaw. There are some things that are very different and specific about cloud native. Do you want to talk maybe about that and what the challenges are?
Yeah, sure. So one of them is, you talked about Kubernetes. Kubernetes is overly permissive by default, and that introduces opportunities for bad actors to, um, to use that as an attack path.
The other thing that we're seeing is, in the case of the Z vulnerability, lots of organizations are scrambling to identify signatures, um, and CVEs in order to quickly patch, however, missing an opportunity to catch these threats ahead of time. And so it puts security teams in a really tough position to have to be reactive. And so, um, it's been, it's been a tough year for security and it's been super stressful in trying to figure out how to solve the problems of cloud native environments, not just cloud, uh, environments, as you said.
Mm-Hmm. Um, and especially with the introduction of, uh, Kubernetes into many environments as organizations start to expand their Kubernetes footprint, it's just become more of a challenge for them. Yeah, yeah.
Um, you know, an interesting trend that I saw at, at Cube Con Cloud Native Con Brook was Kubernetes not just in the cloud, but Kubernetes on the edge, Kubernetes, like on bare metal at at on-prem, right? So this whole kind of whole hybrid multi crack cloud run coob anywhere, and not just Cobe. Another big trend that I saw at, at the show was Wasm, I don't know if you've been running into this yet, but it, it, it's another part of this cloud native, uh, architecture that, that is like permeating, you know, into everything.
Have, have you run into ZO security issues yet? Or is it still too far behind, you know, too far down? Uh, you know, it's, it's, it hasn't crossed the chasm quite yet.
Maybe, uh, wondering on that, Um, I was just trying to find co uh, wasm based Co Yeah. Wasm Como is my friend. Liam Randall's.
Yeah, I was just thinking Cosmo. Uh, they're, yes. I think they're, they're doing really well.
Um, Their wasm and there's another one, um, Matt, uh, ferryman is the other big wasm, but the Wasm thing itself is part of the cloud native computing CNCF, and it's, it's going un and it runs on that cloud native stack, but it allows you, it, it kind of reminds me when Java first came out, right? Your right once run everywhere, it gives you the ability to run in, in much smaller, more nimble, lighter weight environments. So it's perfect for the edge, it's perfect for IOT.
It's, but it's taking cloud native off of that cloud, you know, AWS Google Microsoft thing and pushing it everywhere, which is a good thing. Right. I'm not saying it's not a bad thing, but we gotta figure out how to secure it everywhere too.
That's Right. And that might be the next, the next frontier. So that, yeah.
Well, you Hear investors, uh, with Cosmo and they're doing great work. Oh, do you? Yeah.
Yeah. And there's a really good better together story for RAD Security and Cosmo together. Um, very cool.
Yeah. Vertex is also an investor in them. Yeah.
Very good. Um, hey Brooke, we're about outta time. I want to quickly return to the RSA sandbox thing, if you don't mind.
Sure, sure. So Monday is sandbox day, and that's, um, so most of the day if, you know, a lot of people say, oh, well the keynote start Monday night, Monday afternoon, and you know, I'll get in there Monday, I'll roll in Tuesday. You're not there Monday at RSA, you're missing a ton of great stuff.
There's the whole sandbox thing's, there's the DevSecOps thing that we put on this year with ai, and we've got an amazing lineup. And that's all Day Cloud Security Alliance has an amazing AI thing going on Monday as well. Then there's a ton of good stuff, um, you are gonna be presenting.
Is there a specific time specific or it kind of, kind of flows How, uh, we have a really large window, sort of like what Comcast give you, gives you when they Talk. Yeah. One of those where they're servicing within four hours.
Now, Cecilia's, uh, gives us a little bit more than what Comcast gives you, but it's, uh, it's a decent size window. So we'll know a little bit more as we get closer, but I will be on stage and I'm really excited to talk about RAD Security and what we're doing and, and present there. Excellent.
All right. Um, you know what we did, we say RAD Security was the website, right? That's right.
R that'd security. That's right. So you can find out more about Rad Security there.
Uh, if you're going to RSA, check 'em out on Monday. If you are want, go to RSA but don't have the money for a full boat ticket, which you can get pricey. We do have free Expo passes, which I think get you into the Monday events.
com, there's uh, a code there for a free pass if people want to go. Rook, I wish you a lot of luck in the, in the Sandbox. It would be great to see you guys win, but you were already a winner if you made the finalist.
So congratulations to you and thanks, and thanks for being on Tech Truck tv. Thanks for having me. Pleasure.
Say hello to Jimmy for us, Brooke Mata, CEO Co-founder at Rad Security, a 2024 RSA Innovation Sandbox finalist here on Tech Trunk tv. We're gonna take a break. We got a lot more coming up today.
Stay tuned.