Expanding Multicloud Security – Tim Chase, Lacework
Tim Chase, Lacework Field CISO, discusses expanding attack path analysis to Google (GCP) and Azure clouds (in addition to AWS) and adding Oracle Cloud (OCI) support. Lacework also adds integrations with Service Now and Jira Security for improved operational efficiencies.
Transcript
This is Textron tv. I had the great pleasure of being joined by Tim Chase. Tim is Global Field CSO with Lacework.
Welcome, Tim. Thanks. Glad to be here.
Hey, we, and you've got some exciting news. I want to get to that. But first, you know, tell us a little bit about kinda what Lacework is doing, particularly in the enterprise space.
I mean, all of us can go to the cloud, but the, uh, complexities, the things you have to deal with and prepare for and be able to handle as a, as a technology provider like yourselves, uh, that, that lace gets pretty long fast. It, it does, uh, when, you know, cloud is hard enough. Uh, when, when enterprises and when companies in general decide to go to the cloud, um, cloud can be difficult.
And securing the cloud can be difficult because, um, you know, in the cloud things happen faster. Uh, typically it involves some sort of a DevOps sort of, um, uh, arrangement where things, you know, are being pushed to production and, and close to real time. And so securing the cloud is difficult no matter, uh, the size of your company.
Enterprises tend to even have, uh, a more difficult time securing the cloud because what they do is, uh, uh, on alar, they do it on a larger scale, right? So, um, enterprises deal with, uh, large amounts of data, right? If you think about, um, all of the, the cloud logs, all of the different cloud accounts, all of the workloads that they're running in the cloud, um, having to manage all that, understand it all and secure it, and that's just a lot of data to deal with.
And, and on top of that, typically, uh, the, the decision to go to the cloud is usually a business decision. And so, uh, the business looks at the different clouds and they decide which one best fits their needs, which at an enterprise level usually means that they end up in, um, a multi-cloud scenario. They're not in just a w s or they're not just in, uh, G C P, but, uh, usually they're in at least two, if not three or four different clouds.
So the security teams are left trying to deal with an environment and secure an environment where things are happening very fast. There's a lot of data. Um, and they have multiple accounts and multiple cloud providers.
And then when you add on top of the fact that, um, security teams usually have some sort of an established, um, way that they like to see their vulnerabilities, track their vulnerabilities, they have, they have a workflow that's already in place, and they don't wanna have to redo that just for the cloud, right? So they then they have to take all of this data from the cloud, and they have to make it work, um, inside of these existing, uh, workflows, right? And so, uh, all of that just makes, um, securing the cloud, um, something that can be challenging.
So that's where companies like Lacework comes in, where they have the ability like data, the amount of data, uh, that is generated is not, uh, does not bother us. We have the ability to read through it. We have the ability to, um, understand it, process it, um, and we can do that, uh, at a multi account, multi-cloud level.
So you can see all of, um, you know, the security of your cloud from, from one place, uh, not having to go to different tools, not having to go to different cloud providers to see what's going on from a security perspective. You know, Lacework allows you to see, um, manage your cloud security in one platform, no matter how many cloud accounts or, uh, cloud service providers you use. Very good.
And oftentimes it's not by choice. You end up in multi-cloud acquisitions and et cetera. You buy a certain product that works there.
Good. I think that's a kind of a great, great job in hitting the high points, um, about enterprises in the cloud. And, and like I said, we could do, you know, three hours of the complexities of that.
Um, I'd love to hear about the new announcements about what's, what's happening, at least work and what you're talking about now. Absolutely. We're really excited for this, this new announcement, uh, for our October, for our, our October release.
Um, you know, we're always doing, uh, new things, uh, that we're excited about, but this particular release we're really excited about because it takes our existing, um, enterprise grade cloud security platform, and it really just expands upon it and makes it, um, even use easier, um, and adds some features, uh, that, uh, our enterprises will really value. And so, uh, one of the things that we're doing is we're adding attack path analysis for Google Cloud and, and Azure. And so we have that capability for a w s and we're expanding it, uh, to, to those two other cloud providers.
And what that allows you to do basically is, is when you have a vulnerability and you have a, a host, you can see the path to that vulnerability and then what that, uh, host actually talks you. So you kind of get this entire attack path that helps you better, um, understand, um, more context, uh, around that vulnerability, which will help you prioritize, right? Because that's one of the, uh, that's one of the things that's important to a security team is not to get overwhelmed.
They have to be able to prioritize and understand, um, uh, the risk that vulnerabilities, uh, present. And so that's what attack path, uh, allows you to do. And so we're expanding that to Google Cloud, uh, and Azure.
Um, in addition to that, uh, we're adding a fourth cloud. So we, you know, mentioned a w s, uh, Google Cloud and Azure. We're also now supporting, um, Oracle Cloud.
And so that just adds another cloud for our enterprise customers. There are a lot of, um, enterprises out there that have started to use, uh, O C I for some of their cloud workloads for various reasons. Uh, and so now we have the ability to, to support that as well and really enhance our support to our, uh, enterprise customers.
Um, and that's, that's kind of what, go ahead. Thank you. And that's kinda what we're doing to, uh, expand our multi-cloud capabilities.
We're also adding some features on some on the operational efficiency side. So when we are talking about some of the, um, the complexities of, of cloud security in an enterprise environment, I mentioned that they kind of have their existing processes, right? They don't wanna rip out and create new ones for the cloud.
And so we have, uh, a couple of announcements, uh, related to operational efficiency that our enterprise customers will really benefit from. So, uh, one is, uh, our integration with ServiceNow vulnerability response. And so we have the ability to take the vulnera, we have the ability to take the vulnerabilities that we find inside of our platform, um, and push those to ServiceNow's vulnerability response.
And you can see that, um, in the ServiceNow marketplace. And that's, that's just helpful for a lot of our enterprise customers. I, I think, uh, a majority of enterprises out there use ServiceNow in, in some capability, right?
It's, it's, it's one of the most, you know, popular C MDBs and, uh, that's out there. And a lot of them also use it for, um, tracking vulnerabilities inside of their, um, operations team. And so we have the ability to integrate with, with that.
Uh, and the other thing that we can do, um, is, uh, we're announcing that, uh, we have a security in Jira integration. So, uh, JIRA made an announcement where, uh, they have this, this product called security in Jira where they can manage, uh, these vulnerabilities. And so we have, we're one of the five security partners, uh, that, uh, are gonna integrate with, with security in Jira.
So we're, we're very excited. They're, they're already a, a good partner and we already have the ability to push, um, you know, any, uh, of our alerts and vulnerabilities into Jira, um, as a task. And now we're adding the ability to do that, um, in the, in the security in Jira product.
And so that just really helps, um, it really helps give our enterprise customers that visibility that they need inside of the processes that they already use, right? Visibility isn't enough. You have to have that list of vulnerabilities, uh, in a place where you can go and, and fix 'em.
Um, so just kind of touch on a couple of those things. One is, so in Oracle Cloud, same capabilities that you're offering in the other three cloud providers, kind of pretty much parity, or are you rolling It Out in parts? We'll roll it out in parts.
So for O C I, where we're at today is, uh, we have the, the C S P M, uh, ability, right? So, uh, you have the ability to kind of go and understand your, your cloud security, posture management for, um, O C I, right? So that allows you to kind of get that whole picture of, um, if you're in, you know, multiple clouds and O c I is one of them, you can kind of see what your cloud security posture looks like in one place.
Talk about why that's important, important of integrating what you're in ServiceNow. Yeah, I mean, I think it's very important because that's, we have to meet the customers where they're at. We have to meet the teams where they are at, right?
And, um, a lot of our customers, uh, we don't want them to have to come necessarily to Lacework to do all of the work, right? The, the best way to get, uh, customer buy-in the best way to get adoption with, um, the teams that we have to work with, right? Is to meet them where they're at because they're likely not gonna adopt an entirely new, um, uh, kind of, uh, uh, process just, just for you.
And so that's why security in Jira and ServiceNow, that's, that's why it's very important because you have these teams, uh, that you have to work with. And they say, look, we work day in and day out in ServiceNow. That's where we, we have all of these workflows where when a defect comes in, when the vulnerability comes in, it's gonna automatically be assigned over here for triage.
We can take it to the defect or to the, to developer teams. We can do all of this work. We don't wanna have to redo that in another platform.
And so that's why, uh, that's why both of those integrations are super important because we wanna meet the DevOps teams, the operational teams where they are, so that, um, you know, we can kind of, uh, our security teams can still use the product, but the other, the other, uh, teams that may need to, to see the findings from the product can work, um, inside of their tools. Well, It's, you don't wanna under underestimate the value of that. Like bring the work where people already work in what will they already work in, whether that's email or ticketing system or service, uh, service type system.
That way they're not jetting out to a third party application and trying to cross reference ticket ticket numbers or whatever it might be, right? And yes, of course, then there's data differences. And one of the things about, uh, I, I happen to know Jira a little bit better than ServiceNow, but they do that very well.
They're very good about integrating all that data, whether it's, you know, information from development or vulnerabilities, et cetera. It's great. And they have teams that, they have teams that love to use it, right?
Like Jira has a lot of, uh, teams that have used it for years. They like it, they like the workflows. And so, you know, the quickest way from, uh, that I've seen in my experience for, uh, security to succeed is to, is to meet teams where they are.
And JIRA's a good example of that Definitely is, well, congrats on the announcement. I look forward to, um, that hitting the street or hitting the cloud per se, and, uh, have folks getting additional chance to work with it. Um, anything coming up as the, is the year we kind of close on 2023, look forward to 2024.
And I think multi-cloud is clearly gonna continue to grow. Of course, it's like 93, 90 4%, some different numbers, but it's in the very high range of companies that are multi-cloud, especially enterprises. It's just kind of a fact of life.
Mm-hmm. Yeah. I, I agree.
Multi-cloud, uh, is, is here to stay. I think, um, uh, cloud adoptions is gonna keep growing. I think that we're gonna see, um, uh, more and more people figure out how they're gonna integrate, um, some sort of L L M or Gen ai, um, inside of their processes.
I think that's something, uh, to keep an eye on. Uh, so a lot of, a lot of really good stuff happening in the, in the security world. I think, you know, one of the challenges that people will, uh, keep trying to address, uh, this year probably into next, what I talk with customers about is how, how do I take this data?
How do I take, you know, the number of vulnerabilities that I'm dealing with? Like, how do I make sense of it? How do I prioritize and know what I need to work on right now?
'cause I'm just being overwhelmed with data. So, you know, that's why, you know, I talked to a lot of customers about, about how they can do that in the clogs. I think that's gonna be a continuing conversation point, uh, for the, for the remainder of the year into The next.
Very much so. Well, great. Um, we look forward to, uh, more from you and the Lacework team and, and, uh, 2024.
Gotta get used to saying that almost there you, I don't like it. I know, I think things go so fast. net, correct?
Yes, that's correct. Yes. Come check it out and see all the, um, the announcement and, um, all of the, uh, other stuff that, that Lacework can provide, um, For Very Cool for You.
I meant to ask you in the beginning too, field ciso. Mm-hmm. Does that mean you're working with customers a lot, engaging with them about the challenges and solving some of these problems?
I'd love to hear a little bit more about what do you do as a field ciso? Sure. Absolutely.
Uh, I, I love, uh, that aspect of my job. So my aspect, uh, one of the, one of my favorite things to do is I get to talk to customers. And that could be, um, um, prospects, people who are considering purchasing lacework existing customers, um, meeting at all the, the major conferences, just having customer meetings.
And I, and I talk to them about the security problems that they have. You know, it's, it's, uh, I want to hear kind of what, what, what are your challenges? Like what are your top five things or top three things that you're working on this year?
And let's, let's talk through them. Like, you know, my background, you know, I've been a security practitioner for 20 years, uh, been in, uh, leadership and CISO roles for, um, I think about 12 years, something like that. So I've, I've done cloud migrations and AppSec rollouts and building of security programs.
So I just like to talk to customers to just say, you know, is there anything I can do to help you? Right? I like to use just my experience to just talk to other practitioners and that maybe are going through some problems that I've already solved.
Right? And that's, that's what I do. I have, uh, I do it and I have a team of people, uh, that do it as well.
Like, we're former, uh, security practitioners that have just done it right? And, and then have the opportunity to take what they say and maybe, um, tell, you know, give that back to product and say, here are some things that I'm really seeing when I talk to customers and kind of help shape, um, you know, some of the, some of the ideas of, of where the product goes. And then just being able to do, um, speaking engagements as well.
So, you know, the opportunity to talk to, to you Mitch. And, um, I'm, I'm speaking at the I S C Squared Security Congress, um, uh, this, this week a couple times. So that's kind of what, uh, field CISO's job entails.
So I, I love it. Just the opportunity to speak to a lot of people and, and meet a lot of people is, is great. Fantastic.
I have a, I have a good sense that you're very good at it. So Congrat, you, congrats, congrats on the release. And, uh, good luck as that rolls out and, you know, keep us informed.
net. Sure. And check it out.
Thank you.