Free CSPM and Introducing SkyHawk Security – Chen Burshan, SkyHawk Security
Chen Burshan, CEO of Skyhawk Security joins Mike Rothman to discuss the state of cloud security, SkyHawk’s spinout from Radware, and why it’s important to look at more than cloud logs to understand cloud security posture. They also talk about SkyHawk’s free CSPM offering.
Transcript
This is Textron TV. Hi everybody, Mike Rothman here techstrong research for another episode of tech strong TV. Today.
We're interviewing Ken Burson from Skyhawk security new company, you know that actually spin out for my group, but I don't want to you know, kind of steal his thunder right? So so then welcome to the show, how are you doing today? Very good.
Thank you. My how are you bad? I'm doing great.
So what are you kind of run everybody through Skyhawk and the story that's fun out from from Broadway and generally, you know kind of what what area of the security space you really targeting. Right. So thank you Mike.
So Skype security is a spinoff from radward company was operating as a unit within radware for the last four years. I've been very successful in addressing basically runtime protection for customers in the cloud basically the CBR space the cloud protection and response space and with this the division hand within Rod. We're a company decided to make a boat move.
And this is me making spinoff of her company so that we can give it more focus and attention and grow it. I was brought in CEO based on my background. I was GM and site manager for note 9 in Israel, which state about acquired by checkpoint So I've been in this space before it was even called see I know you're just playing around with firewall rules to open it up before it was even cspm and I remember you bet correct, correct, and and basically created this Market category that now involved into a sinner and we are on target to revisionalize this Market again with our CDR.
No, that's great. That's great. So, you know cspn is something that everybody kind of thinks they have and and some use it some, you know, again Microsoft and and AWS and you know Google and these guys are increasingly, you know kind of bundling it in so it's perceived to be a bit of a commodity at this point, right and absolutely critical because misconfigurations are really what will kill you, you know kind of when you get into scale Cloud off so, you know having somebody look at that and applying those policies are absolutely critical but what's different about what you guys are doing.
It's not just one of the mill like Hey, we're gonna connect to your Cloud account tell you you know, kind of what's misconfigured and have you fix that. You know, you're going Beyond just that General set of analysis. Is that right?
Correct. And and the statement is spot on I really think that ESPN is commoditized that's part of the reason we actually announced our cspm as a out of the premium version of the product. You actually give it for free up to 1000 assets because we really think it's a big time capability.
Let's stay in Africa. I'll let you talk about CDR and the Machine learning stuff and in a second. So let's talk a little bit about the freemium, you know kind of cspm so supports variety of cloud platforms.
There's just AWS support. That's right Cloud platforms. We are in an extending all the time and we basically give it really free.
It's not if we try free with no it's really free functionality basically covering compliance reporting the learning on misconfigurations and posture management. So restrictions not, you know, you know great our reports, you know, you see those where A two reports in 20 or there and you're you can't touch them and it's kind of like, ah, yeah, so it's a really free. Okay, that's interesting.
It's really free. And and the reason it's free is exactly the reason you mentioned. We think that it's commodity and it's time to basically go beyond cspm and Beyond posture management and innocence even Beyond risk management around and protection.
Our customers are telling us that even which risk management in place and even with the best risk management in place. They still have to prioritize they cannot fix everything they have to accept some of us and with that level of friends getting runtime protection that allows them to actually make sure you close this Gap still enjoy agility. Enjoy the speed of you know, the speed that the cloud enables here developing their core business or go to market that way with us.
Basically Bridging the Gap. Between risk and actual actual trust. Yep.
Yep. So let's dig into that a little bit more. So you get Telemetry via apis from the cloud platforms.
All right you analyze that or you aggregated first, right, you know kind of do your policy checking on, you know, kind of the configurations that's you know, kind of the typical cspn stuff and and then you're doing some math on it, right? Is that right? So you're doing some math to kind of identify what could be malicious types of activities based upon your own research team is that you know, so you've got your own folks that are looking, you know for those patterns and and building that into the system.
Right. So we do basically do things. Obviously we take the configuration data, which is context for us to know what we're analyzing the second thing which is kids basically taking all the data all the logs data whether it's a network logs low logs access logs or the blogs.
The DNS logs, right? There's all sorts of indicators were taking from the cloud all over in our platform is really a data Hub. So we're getting all the data and then we're employing two levels of machine learning on it.
The first one is obviously the basic anomaly detections. Okay capability. The second skin is basically another layer of machine learning that allows us to build our sequences.
They can be mapped into them with your framework. They can be so that we can relate them to a real I will techniques there are being employed or just, you know, dealing with unknowns but the moment we see correlated set of events. There are forming what might be perceived as an attack.
We then we show another right and that's why we are able to give our customers and extremely accurate speed of alerts, which we call them real alerts, by the way. Yeah, in order to make sure that there's no other fatigue and there's no false positives and what they get is really accurate and explainable. I want with a visual presentation along them to actually see how they attacked involved how the attack to remove the lateral movement in their environment what they did before they get to the Congress.
Yeah, so, you know kind of the customers you're working with. Yeah, how much of their issues are those misconfiguration stuff versus real attacks? You guys see in real attacks on the planet?
I don't mean, you know somebody going in and you know busting in and then spinning up some, you know crypto mining stuff. I mean, yeah that's important. But our duty should catch that or elsewhere, you know, kind of screw yourself up but but like real Attack where people are, you know, kind of doing pivoting and and you know kind of really trying to borrow into you know, kind of a cloud environment.
Did you see a bunch of that? So we say a bunch of it. Obviously.
This is not extremely prevalent, right? It's not happening every day, but we see it and we simply put customers and we hear from customers that we are able to block and events in their environment and they are able to actually understand what they should do in order to prevent future events. So this is actually another key point.
It's a feed into the cspn right once we see events we can see into the priorities ESPN to allow them to actually deal with the real risk and not with us. Yeah. Yeah, and that's because that's always been the case just you know, and and typically when you do see that type of attack or activity it tends to start because you've got an overprivolution environment are you didn't lock down a network or something all that stuff you did in the old shop, right, you know kind of went for networks.
I am to all those you because that tends to be where you know when it's what's hard, right? You know, especially doing it at scale that that stuff is really hard to operationalize awkward. So correct then and you really touched on another key point, which is our ability to correctly different things right the network.
They didn't the only different layers combined the single story because it's never about just itdr or Identity or just Network. It's it's been over and that's why why we are so unique in our ability to correlate these events in multiplayers or singles unified story. Yes.
What do you call that? I was having an argument with somebody the other day and I grew up as a networking guy. Right?
So, you know 35 years ago. I was just, you know, kind of plug in and statement trying to figure out how to do, you know all that stuff again. I know most of the audience is like what is this old guy talking about?
Um, you know, but but we were talking about, you know, kind of what are you call this and and they used the term attack right an attack path to me. That's a network. And again, that's just the way Think right because that's kind of how I grew up.
I think about oh, I'm gonna break into this and then I'm gonna do that and I'm gonna if I can block the the network side of that but then I kind of took a big step back and I said, well it kind of is an attack pattern is that the vernacular you guys users? There are other you know, kind of ways you describe what that that, you know kind of series of events, you know turns out to be so we call them a sequence the sequence of advanced with the sequence of the effect, right? Yeah, but but many of the industry veterans it's still calling here that and we're trying to find our customers where they are.
And and then get them closer to us. So we will use these terms interchangeable. Yeah, and and to me that's the hard thing right, you know building that timeline because when when you're really trying to do an a response, it's really all about, you know, understanding the timeline figuring out, you know, kind of what was breached and you know was anything exfiltrated and and all of those, you know things so so sequence or timeline that made more sense to me than bath.
But again, I'm an old guy and I I think you know when something breaks, I'm like, did you check the wire right there? No liarsity anymore, right? So that's you know, those are the conversations.
I have that with my offsprings. Now this there's no way there's actually no perimeter right? There's no period that's right, you know, it's all up there and somebody else's environment so Discovery and and data management and all that.
That's another Rat's Nest that I don't know. We want to go towards on this run but that's exciting with the freemium stuff. And so many people in the company now, okay, we're 50 people in the company people.
Okay? Yeah, it's incorporation and You cutting edge technology could you know we have here a research team the data science team obviously engineering team. A lot of interesting pieces of technology that are actually enabling us to provide capability that really my perspective is the next step.
We we talked about it earlier that I've been in this industry for a very very long time when I saw this technology was very easy to see The Innovation here and how this is like creating the Next Generation and the next advancement in this View. So, how do you I mean so so are you focused only on kind of the cloud infrastructure side of things you dig into containers, you know, they're obviously a lot of past services that are available in kind of fused into the clouds, whether it's you know manage Decay, you know manage kubernetes or you know, kind of CNS and laughs and all that are you digging into into that pieces of it, too? So we're looking into kubernetes as well obviously and it's almost even though you know, we're talking about Cloud.
It's eventually containers. Are there everywhere, right? So we will see double down there looking on Our Roots right coming from where it only makes sense for us to also take Network perimeter and all the amazing product that was producing around love and he doesn't take these delivery in as well.
which is which is also a key and I want to emphasize again. We look on ourself as a hub of telemetries from all sort of some of these are things were working on right now and will probably talk about them in our next Engineers on how we're taking more fields to make the story more complete and with a even better view into application layers and some of the other videos that are required to really provide decent to install. So it's more more coming stay tuned is that that's the message plan stay tuned.
Thank you. This will come work always more, right? Yeah.
I always got to keep push from the bar forward. That's that's the whole thing. And you know, I started a company do cspn like a thousand years ago at this point.
So, you know, that's that's a market that's near and dear to my heart too. But also, you know, I'm pragmatic about the fact that it is, you know, pretty commoditizing good to see you moving in Direction both deeper right in terms of you know, These managed services but you know also, you know multi-cloud and being able to you know, kind of start down as some of the activity to find a tax because that's really what it's about at the end of the day. Correct, and we know that most of the customers are going to do to be multiplied.
Right? I mean, it's like today will be cloudy with it's not just, you know, one cloud with another cloud in the lab. It's really move the cloud.
So It is speaking of which you know where we're gonna release a new survey that we have man. We just did a pulse meter as well, which is one of our other, you know, kind of infographic research projects products and it shows that you know kind of a bulk, you know over 50% now have multiple clouds and that's just gonna grow from here. So that's definitely something that we're gonna continue.
Well, it's great. How do folks get in touch with with Skyhawk. So basically to our website there is a form to request a few cspn version go there link on it where excited very very looking forward to have customers subscribing to our free cspm and then going forward with us in the journeys.
We use our runtime protection, which is really where we shine compared to everything else out there. Okay, that's great. Well, listen, thank I really appreciate the time.
Thanks for being on Tech strong TV. We'll look forward go check it out cspn for free. Oh my goodness cspn for free.
So go do that. And again, I'm I may hold you to it right eluded to a new another interview at some point in the future. So we'd love to have you back on the show just, you know reach out and let us know when we can when we can chat some more.
Looking forward to it. Thank you very much for having me you bet. Well, we'll send it back to the studio now for our next interview.