Enso Security Acquisition – Manoj Nair, Snyk
Manoj Nair, chief product officer for Snyk, explains how the acquisition of Enso Security coupled with some additional new DevSecOps tools will lead to better software supply chain security.
Transcript
This is Techstrong tv. Hey guys, thanks for the throw. We're here at Manoj near who's Chief product Officer for Sneak, and we're talking about some additions to their portfolio and an acquisition.
So stay tuned. We got a lot of big news coming here. Manoj, how you doing?
Good, good. Mike, good to talk to you. Right?
Welcome the show. Walk us through first, you know, some of the product updates and what's coming down the pike from Sneak, and then we'll jump into the acquisition. Excellent.
So, uh, we, we have been doing these, uh, quarterly sneak launches, uh, for the last, I think, six to nine months. This was the third in the series. Um, a lot of our focus, you know, sneaks focus on, um, category that, you know, we pioneered Cal Dell per security, and so it's really about enabling the devs, um, to fix issues faster, whether it's in their open source or in first party code, uh, containers, infrastructures, code.
So everything from code to cloud. And that's, you know, been the trajectory of the company over the last seven years, really driving empowerment of devs and driving a fixed culture automation. Um, on, and, you know, a lot of our growth, you know, uh, or LA in 2022 was in the enterprise.
And one of the things we started hearing from our enterprise customers, you know, chief security officers and heads of AppSec, uh, software, supply chain security, big concern, top of the mind, and obviously, you know, by driving fixes earlier in development, that brings the risk down. Um, but, but part of it is despite the best context and automation and enablement, the complexity and the speed of DevOps and innovation means that things escape. And so one of the things that, you know, we started hearing a lot about is prioritization.
And especially when you're scanning the same application at different parts, you end up with a lot of, you know, um, potential noise. And the more noise is there. Devs, they're focused on creating new things, not fixing security issues.
That's one of the first things we announced in terms of, you know, how do you help with, you got all these tens of thousands of issues. If you go to any reasonable size company that's open, um, what really matters? What should we drive fixes on?
We create, we were doing an, uh, innovation around something we called insights. So we launched that, uh, yesterday, and that was really around driving contextual prioritization in the context of an app. And what does the modern cloud native app even look, you got these repositories, you got open source containers, let's, let's show what is all the components of the app and then filter it down based on what of the risks that showed up on the extreme left actually made it all the way into the package, into the container, and finally got deployed.
And is it deployed? And, you know, is it a sensitive app? Is it a higher risk app?
This really helps, you know, our, our, uh, security, um, teams out there driving much more prioritized fixes. So that was one of the big things that we announced yesterday. Uh, the other big thing, uh, was, was really connected to, again, our concept of driving fixes faster.
So one of the, our original innovations was, uh, fixes in, uh, in, in open source that are automated fixed prs is what we call it. Uh, we brought that same concept, um, to first party code, and we believe we're the first to be able to do that around security oriented fixes. Um, there's a lot of, you know, noise around ai.
Uh, we actually use, uh, hybrid AI is what we call it to, you know, do powere code. The, our actual engine is much faster than any static analysis engine out there because of all that AI tech. So we took that next leap forward there.
Uh, we also, we also came up with a name for our engine, deep code ai, uh, and deep code AI fix was introduced that automates creating fixes. As the developers are coding, it'll say, here's an issue, here's a recommended fix. It could also be you're using a AI generated code generator and the same thing, you know, um, recommending security fixes for that real time.
Uh, those are a couple of big highlights. There are a few other things we announced in terms of expanding our software, supply chain security capabilities and strengths and learning and all that. But it was a packed, uh, announcement and, uh, obviously then expanded that with the acquisition, which we'll talk about.
Yeah, so the acquisition involves, uh, Enzo security and they've been at the forefront of a notion of, uh, application security, posture management. So I guess my question to you is, where does that fit in the spectrum of things that you just discussed? Yep.
That fits squarely in that whole, you know, reducing the software supply chain risk and, um, where, you know, where this complexity, I talked about prioritizing issues even within one app, right? We, we, you know, some of our beta customers showed a single app as a hundred thousand issues. You know, imagine now that's not what you have in your enterprise.
You have tens of apps, depending on your size, you might have hundreds. Um, some of what happens is you don't even, you know, know, you know, what's, uh, you kind of know that you have a coverage gap. Not all your applications are being covered with all the, uh, things that can be done before they get deployed, whether it is open source analysis, container analysis, static analysis, some sensitive apps have dynamic analysis.
Some, you know, so part of what, um, CISOs, um, and AppSec leaders don't know is what's the coverage then? Then there's what apps exist out there that we don't know, and it's a cloud native environment, pretty easy to spin up a new app. And so there's that, you know, I called it the, you know, unknown unknowns and the unknown unknowns of, uh, application security.
And, um, that's really what this category called A S P M fits in, right? So we built the, uh, capability organically, uh, around prioritizing within an app what issues really matter based on a risk perspective. Enzo complements that with these other pieces, discovery of your SDLC environment holistically, what assets are there, what apps are being created and doing that continuously.
But then also this, you know, it's, uh, called control coverage is the ability to say what controls are now deployed for which apps. Okay, this app, I believe is more important. Let me make sure it has the coverage I be, it needs.
Um, but then there's also, you know, next steps in there capabilities. Like we are very focused and I talked about prioritization, about issues created by the sneak products, um, findings. Um, there are other products in an environment, in a complex enterprise, they use a lot of other things.
Uh, what this a p m platform that, you know, this category and Enzo was the pioneer of the category. What they do is bringing issues from all the other products. They also bring do integration.
There's like, they have about a hundred, uh, integrations into their marketplace. So they connect kind of that left, which is the sp re-deploy to the right, right? And so there are tools sitting on posty and it kind of brings all those signals together to help with a better prioritization, awareness, visibility, and risk management.
It feels like there's more focus on the software supply chain than ever. And yet things still seem to go wrong. We give developers tools, we have analysis going through the pipeline.
From your perspective, what is it that we're missing or what is it that seems to be holding us back? Cuz we seem to be still encountering these issues even though we've been talking about it more, uh, at least in the last two years. And somehow or other we're not quite there yet.
So where, when, when are we gonna get there? It's, uh, it's a great question. Uh, you know, we ask, uh, the same question, you know, and this is partly what drives us to do some of these new innovative capabilities.
Um, part part of it is just complexity. Um, part of it is adoption, part of it is visibility. And these are some of the challenges.
Um, I, you know, our, the sneak customers will, will tell you that, Hey, we've driven this culture change. You know, I, I get, uh, emails from CISOs and Fortune finders saying 60% of our backlog was fixed and we didn't even ask the devs to fix it. Well, that's great, but did you roll out, sneak in these other apps that if you didn't know about it, you probably didn't roll it out, right?
And so this is where the risks, when we study the risks, it's coming from a little bit of, uh, noise fatigue. So I got all these tools now I deployed to cash things, uh, yet when the noise gets so much, you're not just give up and you keep going and doing what you're good at, which is writing new code for new, new features and new innovation. And that's what's happening on the dev side.
And on the security side, they're challenge to say, okay, I can't go and tell the dev teams and engineering teams to just become people who sit and fix security issues all the time. So how do I prioritize? And the number one thing that when I talked to CISOs that came out, software supply chain, huge buzzword, big problem.
We have to go to the board, have to go to the audit committee, but the low hanging fruit's not getting done. The stuff we know is not getting prioritized and fixed. And so that's why we started with prioritization.
And we believe that these capabilities, the reason A S P M has kind of become this fast moving category, uh, it was nowhere in the last year. Gartner just wrote, you know, an innovation insights about it two weeks ago. Uh, and we are seeing it in our ecosystem and in our partners.
Uh, it's because of this. It's because they need, you know, uh, customers need help with prioritizing finding, and then kind of that continuous, once you get to a healthy state, you don't want to go back to a bad state. And so then it has to be a continuous process.
But I think it's like those three are the fundamental building blocks, I think, um, preventing, um, better utilization of good technology, uh, to prevent the issues. We hear a lot about various proposals for legislations. There's the national cybersecurity strategy.
There's stuff coming outta Europe. Seems like, um, we talk a lot about those things, but do you think that they're gonna have a material impact? And how long might it be before they actually become the law of the land?
Um, look, le legislation's definitely something that I think gets people's attention to the topic, if nothing else. Um, not that they shouldn't have been paying attention. So, uh, I do think that it helps but, uh, bring some pressure and focus, um, the nature of the detail in there.
You know, I would argue that, um, while it's great to focus on, on things like software, bill of materials, uh, sometimes what happens is people get, you know, they chase these, these objects rather than thinking through what are the outcome. Uh, and you know, sneak was a pioneer in, in, in, uh, we build our products with an sbam in mind. The standard formats then came for us, snapping into the standard formats was easy.
So that was part of what we announced yesterday too, is, you know, more support for things like Cyclone dx, s spdx, these are some formats. Well, great, now you have a bill of materials that you're supposed to exchange. How do you exchange that in a secure way between different consumers and producers of software that's only telling you what's in the software.
Now you need a really good security intelligence vulnerability data to light it up to know what's, is there an issue with any of the things in this package, right? And so those are some of the problems we're focused on kind of at the next stage. I think the industry government partnership is a great thing other than the industry always has to be much more ahead than government legislation.
Legislation probably brings kind of a standardization and focus and maturity, but our focus is work with an ecosystem of partners like ServiceNow. We announced a partnership and an investment later with ServiceNow late last year. Uh, and we're working with them on, we're focused on within the SD L c, we create ASBOs.
We have a world class vulnerability data base that is used by the likes of a w s, not just our own products. So that intelligence, how do we make it available for a wide variety of enterprise customers to know what to do with these kind of things? So we're trying to get ahead to the next thing beyond what's today mandated, uh, and then the workflows around it.
How do I work with you if you're my supplier and I know something is in your package that is vulnerable before you even inform me. So there needs to be a procurement workflow, there needs to be a GRC workflow, there needs to be a third party risk workflow. These workflows are built in products like ServiceNow.
So piggybacking on that and, and enabling that to, to kind of facilitate a better outcome in terms of, you know, kind of that shared, it's a shared responsibility, um, and, and it's within, but it's also within the ecosystem. It sounds like a lot of our challenges are directly related to how we operationalize things like SBOs and kind of do this at a level of scale. I guess my question to you is, you can't walk down the street these days without somebody talking about ai.
You talked about it a little bit earlier. Is AI gonna save us from ourselves? Yeah.
Or, or create more problems? You know, I think this has got an opportunity for, for, for both. Um, we are strong believers that anything that, uh, you know, history has taught us that anything that actually improves productivity will get, uh, adopted.
And you know, there's, you know, I talk to customers, they're either in, uh, you know, carefully studying it or one extreme we have blocked it and we don't want anything to do with ai. And at the other extreme, you know, awesome, it's a party, right? Like, so, um, the, and people are just, you know, trying to figure out, you know, what, what does all this mean, um, in our domain, uh, when you come back to software develop and then code, um, the topic has been around code generation, right?
And so, well, lots of companies are generating code now. Microsoft, aws, Google, all the big ones. Uh, they're like, Hey, we will use AI and G P t, uh, of different kinds to generate code.
Um, what we hear from our customers is, is this code secure? You know, there's lawsuits out there that challenge whether this code was even trained properly in terms of using, um, uh, you know, open source software that it should not have used. So is that going to cause an impact to us?
Um, there's stories out there like, you know, the Samsung story and their chip designs were dropped into chat G P T, and now they believe that that's been leaked. Um, because the model is training from its inputs. You know, obviously those policies were changed after the fact.
This is what customers are dealing with when it comes to like, you know, the dev teams, obviously engineering teams, very excited about the productivity, uh, boost and game. Uh, and security teams now have a, a, a much wider set of headaches that they're thinking about. Uh, we're focused on solving that bridge.
Uh, we want people to adopt AI code generation because again, as I said, there's no stopping these kind of moments. And so how do you do it in a safe way? And that's what we're very focused on.
You know, you you wanna help your customers adopt it with safety. Um, there's research by Stanford in December and NYU after AI generated code is actually less secure than human generated code. And Mike, you asked me why would that be?
Isn't this supposed to be super powerful? Well, it's trained on open source software. We have seven years of history and this gigantic vulnerability intelligence d db on all the issues with open source software.
So when you train on inherently, you know, broken, flawed in some ways from a security issue, things, the model is producing things that are, uh, flawed. Um, that's just one thing. And the other one, you know, it's a whole, all kinds of things about G P T and whatnot.
We can talk about. It's, you know, the same thing that writes the, the kid's drama script or a nice social media. Uh, post is not the best thing for generating code, and that's really where we are coming with this hybrid AI approach, um, focused only on securing code and finding issues in code.
All right, folks, I heard in here it's an age old proverb, garbage in, garbage out. So you need some humans in the middle of this conversation to kind of make sure that we don't wind up just making more garbage. Hey, Manoj, thanks for being on the show.
Thanks, Mike. All right, back to you guys in the studio.