Exploring AI Innovations in Application Security with ArmorCode’s Mark Lambert
Mark Lambert, Chief Product Officer at ArmorCode, discusses the company’s mission to filter security signals and its growth in application security. The conversation highlights advancements in AI, particularly Anya, an AI tool aimed at improving security processes. Challenges in AI initiatives and the evolving roles of security teams are addressed, along with the future of application security and the importance of visibility amidst rising vulnerabilities.
Transcript
Hey everyone. Welcome back here to Techstrong tv. You know, the thing about Black Hat, it's, it's really two days of the show, right?
Like, uh, uh, Wednesday and Thursday are the actual show. There's trainings the weekend before, and that Monday and Tuesday, and in two days it's just hard to fit everyone in. So, unfortunately, I didn't get a chance to meet up with our next guest while we were out in Vegas.
Or maybe it was, fortunately. 'cause this is a lot more relaxed. It's not like you're in the convection oven of 110 degrees out there unless you're in the air conditioning.
Um, but let me introduce you to Mark Lambert. He's the Chief Product Officer over at Armor Code. Hey Mark, welcome back to Text Drunk tv.
It's great to see you. Great To see you too, Alan. Thanks for getting me on.
And yeah, it's so shame we didn't get a help co up in, uh, Vegas this year, but I know both of us were running around like crazy. Yeah, yeah. As we were talking off camera, it was, it was a lot of stuff.
Even my nights were filled up with stuff and I, I'll be honest with you, I try not to like, do the late night things and, you know, go to a gazillion parties, but a lot of vendors do business over dinner out in Vegas now, right. They have all these kind of round tables and it's, it's not just, it used to be when I was younger, go out for drinks. You actually have, there's good business being done.
Good discussions, good people. So anyway, enough about Black Hat 'cause it's r a's early this year. We gotta get ready for that.
But Mark, let's talk about you, right? You're, as I mentioned, your CPO over at Armor Code. Let, before we get into Armor Code and we're gonna talk some agent ai 'cause what else is there to talk about?
Um, let's talk about you, mark. How did you get to become CPO over here? What's your journey been?
Well, I, I mean, I've, I've been in the application security space for over two decades now. Um, originally, uh, working for an organization where we were one of the early, uh, SaaS tool vendors. Um, you know, we also had a broader portfolio of DAST and ISS and API security as well.
Um, and, you know, the thing that I saw during that, that time is that that tool landscape is very diverse and there's just a lot of, you know, frankly, a lot of competition, a lot of time spent trying to figure out who's got the best scanning capabilities. And what I realized is it was just generating a whole bunch of, you know, I don't wanna say noise, but just like people being overwhelmed by, uh, findings, vulnerabilities and alerts and not being able to make sense of it all. So that was actually where, around about the time that I met, uh, Nikhil Ktar, our, our CEO and founder here at Armor Code.
And, uh, he'd just come outta stealth with Armor Code at that time. And the thing that we do here at Armor Code is we bring all of those signals together to filter out the noise so you can actually figure out what to do and how to do it. Um, and that was kinda like what got me over here, um, and, uh, yeah, in, in the chief product officer role hit.
So how long have you been in Armor Code then? I'm knocking on for, well, well over three and a half years now. So, yeah.
Getting on towards my foot. You Were, yeah, you were really early. 'cause I remember, I, you know, I remember when Nickel Neil launched the Armor code and the whole, you know, verbal books and, and everything that goes with it.
And, you know, we followed along. I was gonna say it had to be during COVID or thereabouts. Yeah.
We were still in the throes of COVID, uh mm-hmm. Uh, you know, log four J had like, just come out. Yeah.
It was, all of those things were kind like bringing kinda like that critical mass of, of things together. So, you know, we were going through cloud and digital transformation. We were seeing open source security attacks becoming real, uh, software supply chain, uh, chain attacks being real.
Um, and that's really driven the, the industry's focus on how do we kinda solve this problem of, you know what, like I don't, I, I need another scanner to find the thing, but how do I bring that into a workflow where I can actually consolidate the data from across all these different sources? Um, but yeah, it's been a, a phenomenal journey. We we're really blessed to have some great, um, organizations that we work with, um, name brands within the Fortune, uh, 500 and Global 1000.
Um, really leveraging the platform at scale. So, you know, we've got, um, over 320 different integrations now with different scanners of different sources. Everything from threat modeling through the AppSec stack cloud infrastructure.
Um, we are then actually ingesting now over 200 million findings a day in the platform. We've processed over 40 billion and we're processing, sorry, we're supporting over 4,300 security practitioners supporting, um, wow. An estimated 200,000 developers.
So you, we've got phenomenal, um, you know, community and you referenced the Purple Book community as well, which is, um, you know, a, a non-A code, um, you know, o organization that we support from the point of view of orchestrating it. But really it's, it's a group of security leaders meeting on a regular basis to talk about things like the impact of AI or the Cyber Resilience Act, which are the two things that we did as, as Purple Book community panels, um, at the, uh, at the blackout event. Absolutely.
You know, mark, it strikes me as I'm sitting here listening to you, you and I have both been around the block. We've been in security, as you mentioned, you're in AppSec two decades. I'm three decades into security, you know, and we think of, oh yeah, that was during COVID mm-hmm.
And during COVID we saw lock four J and software supply chains and S bombs. And, and that was kind of, you know, when I was a little kid, I used to watch happy days and you know, what the kid, what they wore then versus what I was wearing as a teenager then. And, you know, we, we think of, okay, those were the COVID days, but of course now everything is ai, right?
And it's like, that stuff is almost back in the drawer, so to speak, though. It's still real problems that we real need real solutions to. But now we think in terms of, okay, well how can AI do that?
And what is else is AI bringing to us and what new problems do we have maybe as a result of this? And, you know, it seems like it's AI all the time. Um, and, and of course it's no different, right?
Armor Code recently announced significant advancements, and it's a agentic ai, I dunno if you called it tool or service or product on my notes. It's called Champion, Yeah. Called Anya.
Tell us about Anya, mark. Yeah. So, so you, you touched upon the right thing there.
It's like we, we go through these waves of disruption. Yeah. Right?
So we had open source as a wave wave of disruption, software composition analysis came in to help put guardrails around that. Uh, we then had Cloud CSPs and Synapse kind of helping there. Now we have this explosion of ai.
Um, and, and you really have to ask yourselves two questions is like, first of all, how can you know, uh, you know, an organization benefit from the use of AI for their internal processes, from the point of view of internal, of improving their developer productivity, for example. But then also how can the mechanisms that we leverage to defend and help, um, do things like prioritization like we do at, um, how can we leverage AI there to basically scale and go faster? Um, so at ALMA Code, we've been introducing AI powered capabilities now for a little over actually getting on for two years now.
Um, and, um, you know, that started with Correlation, trying to identify kind of patterns in the findings that we're ingesting to really understand what are the unique issues. Uh, we then brought in a remediation LLM that started providing remediation guidance. We leveraging AI for ingesting pen test results from PDF files.
But that was kinda like the first wave of like, okay, how can we leverage AI to move things faster? The thing that we're now seeing, which has driven like the next generation of functionality within AL Code is as organizations are adopting AI themselves, the development teams are becoming a lot more productive. They're generating a lot more code.
How can we build a workflow and a process that really enables the security teams to scale and keep up with that pace of innovation that the development team now have? They've got 40%, uh, 40% more productive. Or if you read some things like four to five times more productive, you know, that just means it's downstream of, of work that needs to be handled from the point of view of the security teams.
Um, now I will say that there's a, there there's an e uh, evolution of that work, which we'll talk about in a, in a minute, hopefully. But what we're doing in Armor code to meet that challenge is we're introducing, um, a whole suite of Ag age agentic driven functionality within the platform that started with the launch of Anya at RSA this year. So Anya is a natural language interface.
You're right, we call it our, your virtual security champion. You can ask natural language questions, you can ask natural language, um, um, actions for it to take. And we're connecting it in to the ecosystem that already exists with Anya, uh, sorry, with Armco.
So Anya being this native AI capability and, um, agent interface that sits on top of all of that data that we're already ingesting for problems that are real and still there. But how can we supercharge that with an agent AI like Kanye? So Mark, guests development seems to be moving ahead, right?
Security can't afford, security can't jump be the man who jumps out in front of the railroad tracks and says, stop, stop, stop. 'cause that trade's just gonna run you right over, right? We've learned that the hard way.
Um, so we, we need to, to, you know, kind of fight fire with fire or to be on par, right? Uh, it's kind of cold war. It's mutually assured destruction.
We gotta make sure we're doing what they're doing. But we're also seeing Mark, you know, a couple of studies have come out, some of these AI initiatives are not being successful, are not delivering what we thought they, what people thought they might deliver. And some of it may be because the expectations were so ridiculous, right?
And so overhyped, um, I'm wondering what, you know, you guys are obviously, 'cause Anya has to, I'm imagining closely track with what developers and DevOps teams and platform engineers and these folks are doing. How are you seeing, you know, separating the hype from the reality of it? What are you seeing?
Uh, that's a, that's a great question. And, and you know, I think, you know, we're, as an industry, and I'm not just talking about security, I'm talking about just software in general. We're figuring out the ways to leverage AI to be the most effective.
And certainly, you know, we're, we're leveraging AI ourselves at Armor code. You know, we're using things like Claude Code cursor, windsurf interfaces that enable our engineering teams to move faster. What ends up happening though, the, the work changes, it doesn't go away.
You know, people concerned about, Hey, AI taking my job, kind of thing. No, it's actually changing the way you work. And you are, you are making yourself more productive.
You know, a good example of that is one of the things that we, we see a lot of people focusing on today from the point of view of the risk of AI is, and it's like, Hey, you're gonna be generating more code, but that code is gonna have more vulnerabilities and therefore it's gonna overwhelm you downstream. And while that's kind of true to a certain extent right now, that problem's gonna be relatively short-lived. The, the code generators are getting better.
The, the tools like Asem rep are getting embedded into the pipelines. You know, that feedback loop is tighter. So the code quality, I actually think ultimately the code will actually be generated, will be actually better than if a human had generated.
The problem that we're gonna start to see though, is this generates another problem. And that other problem is it now just takes you minutes to spin up an application and you can create almost disposable applications that potentially don't have the same level of governance in place that your traditional, um, uh, software development approach would be. So how can we evolve our security practices to not stand in front of the train tracks so that you get the visibility of what's going on, and so that you can actually focus your resources correctly?
And this is actually one of the things that we're very focused on within the category of application security, posture management, which is really the one thing that Amco does. But certainly the primary thing that we, that we talk to from a market category perspective is as part of A SPM, looking at the code repositories, identifying those that are leveraging ai, identifying those or, or, or just basically identifying applications that are deployed quicker. Because what's gonna happen is your volume of vulnerabilities from that generator code are gonna drop, but the number of applications are gonna increase, and those applications are going to be spun up and then potentially forgotten about, which means you've got a growing attack surface.
And you and I both know that vulnerable, you know, security is not a point in time. I mean, you know, log four J taughts that, um, you know, you'll have an application that spins up on a certain stack. There's a vulnera, you know, there's leveraging a, a framework or a library, and I need to track that.
I need to be able to be able to audit it. I need to, in essence capture its SBO so that I can know when a vulnerability appears that I have an asset out there that's vulnerable, that's maybe not being scanned anymore because that code repository has been archived because the team are no longer, uh, working on that. So this sprawling attack surface and having the controls and visibility in place is going to be the real problem that I think we're gonna start up, uh, seeing in the next 12 months once we've got over this ai a AI generated code concern.
Fair, fair. Mark. It's only a 15 minute interview.
We've used a lot of it. Let, let's talk, you know, practically speaking, now people say, this sounds good. I'd like to check out what Anya is.
We're all, you know, we're always looking for solutions. What's the best kind of on-ramp forum? Certainly.
So the, the best thing is the website as it is with, with almost everything these days. com, uh, you'll see the request, the demo button there. Um, you know, we're more than, you know, more than happy to share that with you guys.
Um, there are a whole bunch of other resources on the website as well, including little videos that'll give you kinda like quick tours, so to speak, of, of that capability as well. Um, and then, you know, we also run, uh, pilots and POCs like, uh, you know, like everybody else does in the industry as well. But we're gonna connect that to your real data.
We're gonna show you what Anya is able to do on your real data within a fully controlled sandbox environment. Love it. Excellent.
Well, mark, look next big one on the list. I, I don't know if you'll be at reinvent in December if you guys are there. I Won't personally be there, but we'll have a couple of folks there for sure.
Well, RSAI am sure you'll be at, and it's earlier this year. I, I think r a's in March. I'm not sure.
Yes. But let's make sure we don't miss that one. Okay, That sounds great.
Look forward to it. Alan Alrightyy, Mark Lambert, CCPO at Armor Code, uh, talking about Anya. Go check it out.
com Mark, take care. We'll see you soon. We're gonna take a break here on Techstrong tv.