From Military Intelligence to Cybersecurity Innovation: Ian Riopel’s Journey with root.io
Ian Riopel, CEO of root.io, shares his evolution from a tech enthusiast to a leader in cybersecurity. With a background in military intelligence, he founded root.io to address software supply chain vulnerabilities using AI for automated patching. He highlights success stories, including securing NATO’s software, and discusses the importance of transparency in open source. Ian also explains the integration of root.io’s agents and the differences between their commercial and open source offerings.
Transcript
Hey, everyone. Welcome back here to Techstrong tv. Let me introduce you to our next guest.
io. His name is Ian Riopel. Ian, welcome to Tech Drunk tv.
It's great to have you on. Great being here. Thanks.
Alrighty. So, Ian, we're gonna talk all about rude and what you guys do and, and, you know, and this how in some way you're making the world better. But before we get to that, let's talk a little bit about you.
Sure. If you don't mind, share, share your story a bit. Yeah, of course.
So, um, I started off, I've always been kind of a geek. Uh, I've always enjoyed, uh, it, um, and, uh, have played with it throughout my whole, uh, growing up. And then later into my career, uh, while I was studying college, uh, MISI ended up joining the Army and, uh, did, uh, ended up joining the military intelligence, um, organization and spent some time there working in Counterintel.
Just really, uh, it was, it was a lot of really great learnings on kind of how to interface with people, how the world operates, how adversaries operate, how to think outside the box, um, when it comes to, uh, all different types of security. Um, and then I, uh, found a passion for startups. And, uh, so I worked at a number of different companies.
Uh, spent some time at Rapid seven. Uh, I was at a company called Cloud Lock. Uh, that, uh, ultimately what there was A-C-A-S-B security vendor was acquired by Cisco, um, for about $300 million.
Um, and where we merged with the, uh, cloud security business unit, where reform the cloud security business unit as part of their also acquisition of open DNS. Yep, sure. And, uh, I remember, yeah.
And so, um, I was there, uh, along with my co-founder, uh, one of my co-founders, um, who ultimately he ran the cloud security business, the product team at Cloud Security there. Um, and, um, we decided it was time for another startup. So he, uh, he went out and started, uh, started the initial kind of roots of this company, um, called Slim ai, and then ultimately, uh, moved into this new journey that is Root and I came over as a CEO, and, uh, we brought in a couple of other co-founders.
And, um, yeah, that's, it's been a, an amazing journey so far, and excited to see where it goes. Very cool. Um, when were you at Rapid seven?
Oof. Was, uh, 2007, 2008. Oh, Yeah, those were my years, so, oh, really?
So I, I, I, I was the co-founder of a company called Still Secure. Okay. And we had a product called, well, we had a product called VM that was more like a Rapid seven competitor qualis and that whole space, but we were more well known for our NAC network access control.
Yep. And, um, but I knew, I knew that, you know, I knew Alan Okay. The founder of Rapid seven pretty well, and then I knew Corey well as well.
Yeah. Knew the whole team. Yeah, sure.
Just That's funny. Before, before we were, before I was there, I was actually, uh, at Inter Networks for a short stint, and that was their whole thing was nac. Oh, really?
Oh, yeah, yeah, yeah, yeah. Sure. That's right.
In Terrace they had a nack and Yep. Yeah, That was, it was a brief moment in time, right around 2007. Yeah.
2006. Five to seven by eight. Yeah, exactly.
Um, anyway, but it brings back memories, Ian, and it, and it's always good to have, I, I enjoy having, you know, cyber, we call 'em cyber. I used to call 'em security people that on the show with me. Um, so look, no one wakes up in the morning and says, ah, let's start a company today.
Right. You gotta, you've gotta kind of have a little fire in your belly and really believe in what you're doing. Mm-hmm.
What is it that Roots doing that really made you just give up a, a nice job in a successful company to, to dive back into this insanity? And I say, with all due respect, I founded four co-founded four companies. I, I, No, no, no offense at all.
You know, no offense at all. So, uh, yeah. So my, my co-founder and I, and, uh, I have two other co-founders, um, also with, uh, some military heritage, um, on the Israeli side.
So we have Oh, very co Yeah. So there's, there's four of us, which is also unusual for, for co-founding team. Um, but, uh, two in Israel, two here.
Um, uh, and, uh, we were walking around at Black Hat a couple years ago, and we basically said, everyone's talking about this. There was this big whole shift left movement, right? Everyone was talking about, how do I reduce vulnerabilities?
This is this. Mm-hmm. And, um, every vendor there is trying to apply an, uh, this approach of how do I reduce that vulnerability account to an acceptable level that hopefully everyone can work on, and everyone feels like they're winning.
Um, it's this perpetual pursuit. But the problem that we had seen in kind of an early iteration of our company was we were, we were realizing that there was just no way to actually keep up in the way in the loop that we have today, the, the traditional mindset. Um, because the number of new vulnerabilities being generated within our software supply chain was increasing, uh, exponentially.
And there was just no way to keep up. We actually, uh, we, we had a speaking slot at, uh, CubeCon, uh, and, uh, we're on the main stage talking about this specific issue, and it was just, there was just, it, it was, we're like, everyone's trying their best, but there's no way we're gonna ever win. Uh, which is kind of a little, not the best message, but it is.
Well, but it's the reality. Well, it's the security. It's, but it's the security person's dilemma, right?
Yeah. And so, yeah. So we, so we walked around and said, well, what if we took a fresh approach to this?
And just completely went back to the start into a first principal's approach and said, what if we could just fix everything? Nevermind the aspect of triage. Um, and nevermind this aspect of golden imaging for your developers to build on, uh, which is not a, something that most organizations can do.
There's literally not enough humans in the world that have that capability and, and skillset. Um, and, uh, we went on a, we started on a mission to figure out how to, how can we patch all of open source? Um, and, uh, that was when it was the very early days of, I don't know that even people were talking about genic ai.
It was just ai. Um, and we started doing so leveraging our deep expertise around containerization and around cybersecurity. Um, and we're, we are, we're also born out of an open source project that we've since donated to the CNCF as 21,000 GitHub stars, really focused on container modification.
So to kind of speak to our, our expertise and chops in that space and our commitment to open source. Uh, yeah. And so that kind of all folded together, and it's been, uh, uh, a, we're at, we've been at the tip of the spear of figuring out what is the art of the possible for AI and agents, and the types of outputs and the speed in which that we've been able to deliver these outcomes, uh, for patching away vulnerabilities has been, uh, far exceeds what we expected.
Um, and now we have customers today that are, they don't think about triage. They're the, we like to say that developers, uh, no longer are chasing tickets to patch vulnerabilities. There's, there's no more of this concept of, I need to break my applica, make the decision.
Do I ship this feature or do I break, uh, uh, dedicate more of my sprint, uh, to rebuilding the app? Because if I upgrade, it's gonna cause a breaking, uh, change. Um, we eliminate that entire thought process.
Uh, we just secure everything that's upstream that you're pulling down and we deliver with an SLA with provenance and following all the SLSA standards. And all of a sudden SLAs become easy to achieve. Very, very, very cool.
Let me, uh, give you a little of my own history here. So, when I, when I started co-founded, still secure, our first product was actually an IPS. So at a time when the world was on IDS mm-hmm.
We said, come on, 85, 90% of this stuff is garden variety me, you know, not worms back then. Right. You know, you had code red and, and stupid I love you and nonsense stuff.
Oh, yeah. But, um, why wouldn't we just block it automatically? Right.
We, we could, you didn't have UTMs then You had an I-D-S-I-P-S, but you could like, work with a checkpoint firewall using like OPSEC or something. Oh, yeah. You know, just, just block it at the, it was every, there was no cloud.
Everyone was, it was, you know, the, the, they called Mote and Castle. Funny thing happened on the way to market. Everyone, not everyone, but most people didn't want to turn on automatic blocking.
They were afraid they were gonna break something. Yep. So we kept banging our head on that wall and looked for a new wall, and we started a vulnerability management.
Yeah. Based on nessus, like everyone was using back then. Mm-hmm.
And, um, I remember as we were talking, you know, rapid seven came out, a couple of others, Qualys was there, found, so anyway, we said, but wait, that's not enough finding vulnerabilities. Why can't we just give you the patch, give you the remediation? Not everything's a patch.
Give you the remediation. Same problem. I'm a we're afraid to do that until we take about 90 days, the qa, all the peer mutations of this patch, because God forbid something else should break, especially if it's the CEO's desktop or something.
Yes. And, and we got outta the automated remediation space as a result. There was a company back then, I don't know if you remember it, Citadel, their product was Hercules dis uh, you know, they became the defense department thing.
They worked real close with Tenable. Yep. Um, then we did network access controller.
We said, okay, this time we found a fresh soft wall. Right. We're not even gonna let you on the network if you don't meet our, you know, golden, uh, yeah.
You're gonna go to the practice ticket, if you will. Yep, yep. And, and that caught on a little bit because we weren't doing anything to your endpoint.
We were just quarantining it basically. Mm-hmm. But this idea of applying remediation patches in an automated fashion, I don't understand why in 2025 it hasn't, it's not an old problem that was fixed a long time ago, but it obviously isn't.
So I could, yeah. So let me answer that. Um, so go ahead.
Uh, so our open source project and, and kind of the first iteration of our company was called Slim ai. Uh, what we're trying to do was take this open source project and sify it in a way that, and the concept, right? It was, which is where most of the industry is right now.
There's a lot of vendors out there that are saying, build on our base image or build on our golden image. We'll give you some sort of SLA around it, and we'll guarantee there's no vulnerabilities in it. But it's, uh, but we, what we were trying to do was leverage our open source project, which minimized all the compo, removed all the components in your software that didn't need to actually be there for your application to run.
The problem with that approach is that the, uh, that's very dependent on developers having great test suites, and many of them do. Uh, many, many do not. And even the ones that do, what about those one-off cases where you might accidentally remove something or there's something that's minimized and, you know, the once a year it causes a breaking change.
And what we discovered was even if you cause a breaking change, like 1% of the time, developers will not trust it. Um, and yeah, that's then, and the whole thing fails. So the trick here, and what root focuses on is we are experts and we've created a fleet of genic ai, uh, uh, of various agents that operate as a swarm, um, that are constantly inspecting the software supply chain for all of the most ular open source projects and for any, uh, uh, packages and PA and, uh, oss that our customers want supported.
And it's interrogating the pa potential patches that can be applied to remediate the vulnerabilities that exist in your code without causing a breaking change. And if there isn't a patch that matches that criteria, our agents will go find a version that can be, uh, reconfigured in a way to be deployed within your version of your open source. And, uh, and then our agents will not push it back to you until it's successfully passed the entire test harness.
And if there isn't a sufficient one, the agents will create test harness to verify that that, uh, new patch that's applied will not cause a breaking change. But, and then we push that back to you, and this entire process takes minutes. Um, and we love it.
Yeah. And, and so the, I think what's, uh, one of the things that we discovered on this journey was how much we needed to do this. Uh, or not just us, but everyone.
Um, and so, uh, there was, I'll give a real life use case. Uh, we just rolled out the third generation of our agents, and the, there was a recent, uh, vulnerability that came out that impacted both the entire Debian and Ubuntu ecosystems, you know, very popular links or operating systems that everyone builds on. And, uh, that critical vulnerability, uh, the upgrade path was you needed to move to that basically caused a breaking change.
You had to move to the latest gen. So if you were building on a, if you were not building on Debbie and Bookworm, or if you weren't building on Ubuntu 20, uh, uh, or sorry, if you were building on Debbie and Trixie, you were fine, but behind you weren't. Okay.
And same with Ubuntu. You had, you had to be above 20. Um, when we tried to create a backboard of patch, we thought this would be a great opportunity that would be stable and also patch that vulnerability.
We thought this would be a great opportunity to actually test and bake off, uh, if you will, uh, against our human researchers. So we took one of our best researchers, and we had them work on trying to create this fixing change. 1% of companies out there have the capability do, right.
This is, this is, uh, You Gotcha. Yeah. Um, that took this researcher eight days, and the reason was the, in order to back port this patch successfully, it required updating 17 different snippets of code over three different commits.
So a very complex patch to ensure you do not cause a braking change. Um, our agent did it in sub 15 minutes. And so when you, when you think about that delta, right?
The, everyone likes to talk about 10 xing. It's not 10 xing, it's thousand X-ing. It's Not even, it's exponential stuff.
And so when you put the, if you take a, take this to the next logical step, right? And thought it's okay, well, if we're, if that's the rate that we're able to patch these vulnerabilities, and then obviously adversaries are going to figure out how to weaponize this at that speed. And then on top of that, we're completely thinking incorrectly about SLAs and compliance requirements as they exist today.
This thought process of, oh, I'll fix things in 30, 60, 90, or once I detect something, even a critical seven days. Right. That's anchored in a reality.
Uh, that is, that just doesn't exist today. I know it may not be known to most, but yet, um, but the, the, that, that is a human-centric timeframe and time span that ceases to exist. It's Not today's speed of business.
Exactly. That's that. Right.
There's the issue, the speed of business today is not on that human mind kind of, you know, clock if you will, of days or weekly. Exactly. And, and, and our, our, our, our, the industry's guidance thus far has been, well, don't trust open source, go into these gated ecosystems and build on some sort of proprietary vendor locked source.
Um, and, But they're not necessarily any more, not only are they locked, but they're not necessarily any more secure, quite frankly. E Exactly. Right.
And, and the transition is not easy. So we have customers, um, so we, we, we have customers of all size. We're, we are very excited and, and, and proud of the fact that we have customers that are small few person shops.
And then we have customers that are publicly traded companies, and they are, we, we literally have containers, uh, are, that are secured using our, uh, solution deployed on in NATO missions. Um, and so the, what's when you, when we baked off, uh, in against some of these other versions of, of our other golden imaging approaches compared to ours, um, we were able to secure the entire software supply chain, uh, of that. This customer, for example, I'm thinking of, uh, was able to secure all of their containers.
It was 37 different core containers that they were building on for this large Kubernetes deployment. Um, and, uh, the, it took them three weeks to move just one of those containers to this new base os because again, when you move to any of these minimal base images, everything breaks, and also that's just a tax on your engineering team. It's a tax on innovation that, that, that's a giant business decision and a huge sacrifice.
And again, not how the world should be or kind of the forefront of the, the world is, is operating. Um, we, we secured that entire supply chain in under four hours. We were fully integrated into their CI/CD.
Um, and, uh, it, it's not a one-time fix again. Uh, what the way we deploy is it's ongoing. It's con it's inspired by FedRAMP's conman process, right?
So, uh, mm-hmm. Hey, basically every time someone does a poll, or at the worst case every 24 hours, the system is going through and re re interrogating the entire supply chain looking for any new vulnerabilities, and then immediately deploying the fleet to figure out how to patch that for you and push it back to you. And we do this all very transparently.
So all the patches we generate, uh, we we're hyper transparent about what's in there. We publish what's actually in the code. You can see it within the container.
We give an SBO and a VX statement. So again, true to open source, this is, uh, something we're, we, we think transparency is key to the future here. Not, um, these gated ecosystems or, you know, security through obscurity.
You have more questions, Ian? We're low on time, but I want to get this stuff Out. I'm sorry.
Oh, no, don't be, look, you're telling me you're sorry. I talk like you're, you're preaching to the choir. Um, where do these agents live?
Do they live in the CI/CD pipeline? Do they live in like a gi in GID and GitHubs? Do they, I mean, they don't live in the repos, right?
They're do they live in the IDE, all of the above? Yeah. Great question.
So our fleet of agents live, we host the agents. It's a SaaS service. Um, so those live on, um, various cloud providers, uh, like AWS for example.
Um, and then we integrate with, and we can integrate any number of ways. So we can integrate directly with your, uh, CI/CD, uh, we can GitHub GI actions, you know, however you want to set it up, uh, Jenkins, um, we can integrate directly with the various registries. So you can plug us directly into A-C-R-G-C-R, you know, you name it.
Uh, JFR Sky's the limit there, ECR. Uh, and, um, so we try to make it super easy. And then we just recently actually rolled out, uh, an MCP.
So you can, as part of Claude code or part of Cursor or whatever, you can literally just say to it, Hey, now patch all my patch, my os patch, my, uh, libraries, you know, and it'll just reach out and just at the developer level, now, you can even do all this before it even goes upstream. So it's, um, it's highly customized. It's not customized.
It's highly configurable to whatever you would like to do. We, we've built the platform API first behind everything. Excellent.
Um, I think you answered my second question, which is sort of what was the difference between the pure open source version versus the commercial model? You, you're hosting IT SaaS in commercial, and the open source people host it themselves. Is is that There or So, uh, so Well, the open source is a different product at this point.
The the, yeah. The open source is still fo is still out there. It's still popular for in, and that's called Slim Toolkit.
And that's that, right. Uh, that focuses on, uh, and we've actually since, um, uh, it's in the CNCF sandbox now, right? Um, so we, that is more focused on ification.
And again, there's a lot of challenges for most folks, and also a lot of organizations really just want this to be fixed, right? They just wanna pass their audit, they just want the compliance issue to go away. And so, uh, what we do is we, as part of our platform, you get an SLA, so a guarantee that we're not gonna cause a breaking change.
And that also you're gonna have these vulnerabilities patched within whatever timeframe is you need to meet. Um, and then also, uh, basically that guarantee how wide you want that guarantee to be spread across your organization. Does you need it to apply to five images or, uh, a library, or do you need to do a thousand, right?
Um, so those are kind of the dimensions that we license on. But people can try out the product today for free on our platform. Um, there's, we have this com, we have a com, this concept of a community version that you can try out, you can buy.
Mm-hmm. There's actual licenses that you can buy starting as cheap as under $10,000 a year, you know, seven, 800 bucks a month. Um, and then obviously we're, we have much more advanced versions that can do things like FIPs and so on, um, to help people really as part of their, uh, FedRAMP journey.
Yeah. We have a customer delete me, for example, that's in the, that's, uh, on their journey to FedRAMP and we're supporting that effort and we're, we're basically conman in a box for them. That's right.
You know what? So, uh, back in the N days we were in, we were in information assurance certified, uh, DOD solution. So yeah, I had good times.
I spent a lot of times in Fort Chuca, which was down there. That's where I went to school. Really Good old, good old Sierra Vista.
Yeah. That's where the Army Intel School is. Yeah.
Oh, yeah, Yeah, yeah. Yeah. I was there from, I ate a lot of, a lot of Mexican food there, waiting for them to finish their testing.
Anyway, small world. Hey, it is Ian. io, community version licensing, everything.
You gonna be a black cat this year? Of course. Always.
We'll be there. We're doing video on the show floor. If you see me come over and say hello, I'd love to meet you in person.
Beautiful. And come back and keep us posted here, man. Great story.
Absolutely. I love it. It's nice meeting you, Adam.
All right. Appreciate it. Take care.
Nice meeting you as well. Thanks. All righty.
Bye-bye. Excuse me. Ian Riopel, CEO root io here on Tech Drunk tv.
We'll be back in a moment.