Inside the Containment Era — Doug Merritt on Why Cloud Security Has to Get Back to First Principles
In this episode of Techstrong TV, Alan Shimel sits down with Doug Merritt — Chairman, CEO and President of Aviatrix and former CEO of Splunk — for a wide-ranging conversation about the shift from the detect-and-respond era he helped define at Splunk to what he’s now calling the containment era. They cover why 15 years into public cloud the network has become the most overlooked runtime cyber control, why default-deny and micro-segmentation finally become practical thanks to AI and intent-based policy, and how Aviatrix is bringing first-principles network security back to AWS, Azure, GCP and OCI to shrink the blast radius of inevitable breaches.
Learn more at Aviatrix: https://aviatrix.ai
Transcript
Hey everyone, welcome back to Techstrong TV. When I saw this gentleman on my calendar a couple of weeks ago, he got booked, I was so happy. I haven't spoken to him, actually, since he left Splunk years ago.
For those of you in the security space, you may know him, you may certainly know his name, it's Doug Merritt. I'm introducing Doug today, though, as the CEO of Aviatrix. Doug, welcome back to Techstrong TV.
It's been more than a minute. It's been more than a minute, and I'm very appreciative to be back, and to get a chance to catch up, Alan. Thank you for having me.
My pleasure. So Doug, look, I'm assuming everyone is a security insider, but there are people out here who aren't. Give people a sense.
I mentioned you were CEO of Splunk, but give them a sense of your journey. Sure. Yeah.
I'm guessing most of you know Splunk. It's been around for a while. But we did, during my tenure, pivot Splunk much more aggressively to address the needs of cyber teams and SOCs.
And the whole orientation around Splunk, but I got there, just for context, 2015, we were roughly $200 million in ARR. 2 billion. So it was a really successful run, which was nice.
I'm really proud of the company and what we did. But why that explosion happened is because we tapped into a really, really important narrative across the cyber industry, and then other complementary groups. But cyber really led that growth, which was the first era of cybersecurity, which was very focused on prevention and perimeter defense, which is still important.
But that era was no longer going to be a spotlight. The spotlight was going to be how do you do a much better job of detecting anomalous patterns and responding more quickly than those attackers were executing their attacks? And a data layer, my postulate, and the pitch was a data layer was absolutely critical to that, and the best source of truth was machine data.
Logs, metrics, traces, the ground truth of what's happening across your cyber estate. And that really was the fuel for Aviatrix, and it was for Splunk, and it really was one of the key anchors, I think, of that detect and respond era, that we're still principally focused on right now, I think, in the cyber world. Agreed.
So now that's happened. You're with Aviatrix. How long have you been over at Aviatrix then, Doug?
It's crazy to say, but almost three years. Two months shy of three years. It feels like it was yesterday.
I remember when it was the announcement. Yeah, it feels like it was yesterday, and it feels like 30 years all at the same time. Well, that's always the case, right?
You settle in quickly. Look, I'm going to bet less people out here know Aviatrix than knew Splunk. For sure.
So I think, if you don't mind, let's just quickly... Let's not rush it, actually. Not quickly.
Give people a sense of who is Aviatrix? What's the problem you guys solve? Absolutely.
So the problem that we are addressing is how do you invoke what we're calling the containment era successfully around blast radius, around the reachability of a contaminated area of your environment to a broader level of your estate, which that orientation tends to happen at network level. But if I go back to who is Aviatrix, for any of you out there that may have heard the name, you're probably going to associate much more strongly with multi-cloud networking. We were founded, and I didn't know this before I got here, but an aviatrix is a female pilot, an aviator.
And we were founded by a really, really talented and insightful female engineer from Cisco, in 2014, '15, who looked at the clouds, and at that point in time, they had no enterprise networking services at all. They assumed that you'd bring your Cisco to the cloud, the software portion of your Cisco to the cloud. " That was built for a very different era.
It's tightly coupled to the ASICs. We need to do it properly. And so she focused on building a software-defined, integrated, very thoughtful, and very comprehensive software-defined networking layer for cloud utilization.
And that was what the company was still doing when I arrived in July, August of 2023. The pivot that we've gone through is, when I looked at it, I was like, "That's a really hard and interesting problem to solve," and we do it very well for a number of Global 2000 companies that really depend on us to deliver packets to them from their edge to the cloud and across the multi-cloud estate. But the bigger problem I saw, looking network up inside these companies, was the basic fundamentals that were part and parcel of how every data center was built that we all controlled, which is ensuring that you've got three legs of the cyber stool all invested in simultaneously at runtime, at the identity layer.
If you want to stop something bad from happening, one way to do that is you can cancel or restrict the identity of someone attacking badly or an agent that's attacking badly. Endpoint, the other area is you've got some infection happening at the compute layer or one of the critical supporting layers, and how you contain and shut down something at the compute layer, which is what Endpoint does. And then network.
What I saw within clouds is people had completely forgotten about and completely overlooked network as a meaningful cyber runtime control. And so that pivot that we've been making, the evangelists I'm driving, around this containment era isGetting back to first principles that were pretty prevalent within the data centers that we all controlled and built, but invoking those into the cloud landscape where they generally do not live at all right now. The wheel goes round and round.
They- Yeah. It's old news again. Yeah.
Crazy. com where people can go get more information? Yep.
com. ai, excuse me. Yep.
com will reference you there. And there's really, really interesting info there. I mean, there's a bunch of stuff on Aviatrix, which is fine.
But if users will navigate to our Threat Research Center, I think most people will be fascinated. I'm so proud of our team. Our CISO, John Chen, was the head of product security at Zoom during the go-go years.
He's very hands-on, very technical. He's got an incredible team, and the depth and insightfulness on the Threat Research Center of what is happening five to 10 times a day since the beginning of this year, and how insidious attacks are. Everyone go in just for that.
It's really important to understand the patterns that the attackers are invoking and what it means for each one of you. Absolutely. Go check that out.
All right, Doug, let's talk containment error. Yes. What does it mean?
So, as we started talking about a few minutes ago, there's two basic modalities for cybersecurity. One is how do you try and prevent things from happening, and the other's how do you stop things that are in flight. Containment is really focused.
It can certainly help with prevention, but it's more of a runtime control. And again, there's some really interesting containment capability on things like identity and endpoint. If you look at the cloud services, the one area where they invoked default deny was identity.
I cannot do anything with a cloud workload until I present a valid set of credentials that are tied to me so they can start to bill me, which is also then a great control. As long as I understand every actor and what they're doing and what they're allowed to do, that's one important leg of the cybersecurity stool. The area that we're focused on is network containment.
Ultimately, most organizations today have got thousands to tens of thousands to hundreds of thousands of workloads. Think all the pods in a Kubernetes container. Think all the serverless functions that you have if you're using Google Cloud Run, Azure Functions, Cloud Functions, or AWS Lambda.
And then all the traditional workloads, and then all the PaaS calls and SaaS calls. All those are either workloads you control or workloads that can impact your environment that you should have very clear visibility around. And what we're arguing for, ultimately, much like a submarine has got a whole series of compartments so that if you happen to have an accident, the whole sub doesn't implode.
It's localized to one compartment that hopefully, if you get breached, it happens, you get breached. We're arguing for the same thing within the cloud estate, is you should have an effective ingress and egress filter around every single workload in the cloud if you eventually do this right. And eventually where people should get to is a default deny posture on every one of those workloads.
That you should know exactly if I am invoking an MCP server, because I'm very AI forward, you should know exactly how many communication paths are legitimate for that MCP server. Is it 18? Is it 26?
Is it 42? But there's a very finite and relatively deterministic set of paths for most of the workloads to go down. And my belief, looking at cloud estates and with a cyber background, is if we can just focus on blast radius, understanding what is the reachability between every workload and every other workload, and then do a much more effective job of at least ingress and egress inspection and macro segmentation, the cyber landscape will dramatically improve.
Like dramatically improve. So that's the containment area, is that we're moving from a primary focus on how quickly can you detect and respond to the primary focus that I believe every board should be staring at is what is my blast radius, and how cataclysmic is a breach if I get breached? Because I think breaches could become the new norm.
I can't disagree with anything you say. Doug, we spoke extensively off camera. We both have a history in the security world.
Sometimes I sit here though, and I'm amazed that, I mean, this ain't rocket science. You know what I'm saying? I know what you're saying.
It's very commonsensical to say, hey, segmentation, ingress, egress controls, understanding that the same kind of gotchas that exist in our LANS, that exist in our private data centers, exist in our clouds as well. Yep. And the fact that somehow we've buried our heads in the sand to ignore it, and it's not like, oh, this is just a new thing because cloud just started three years ago.
No, we're 10 years plus into this already. We're more than 10 years. More than 10 years.
Absolutely. We're 15 years into this. Yep.
It's almost mind-boggling. But here's the good news. At least now maybe we're starting to recognize it.
Unfortunately, you know how security is. We never seem to do things till there's a gun to our head. " So one, I'm in deep agreement on humans, we've gotten so distracted.
It's the entire environment around us, and it takes a little bit of patience and time to focus on fundamentals and first principles, and I'm amazed over and over, even with myself, and I'm very first principles driven with the domains I'm focused on, and then there's others right next to me where I don't have the time and energy for the first principles work there. But anyone in the cyber world, we've got to get back to first principles. It is relatively simple at the 10,000-foot level.
The OSI seven-layer model still works. It's a nice framework for where are the different control points. Runtime is still really important, but I'll urge everybody to get back to fundamentals.
What's interesting with cloud is where I think people got confused is the clouds have done a phenomenal job of building incredibly secure data centers that they operate. And they needed to evangelize to the world, like, why abandon your data center? Well, we've built something way more secure than you could've, and they have.
The investment in very complete and comprehensive and thoughtful cyber across the AWS, GCP, OCI, Azure landscape is phenomenal. But they came out with the shared responsibility model, which says our data centers are secure. Every workload that you put in there, it's up to you.
And people didn't listen enough to that. And then the default posture of the different workloads that they create is very different. The default posture on identity, as we talked about, is default deny, that you cannot do anything within your cloud services until you've fully vetted and authenticated yourself, which is that default deny policy.
No one can access it, and then we add them one at a time based on thoughtfulness. The other areas are default permissive, wide open, and as part of that shared responsibility model, it's up to you, Mr. Customer, to figure out what your network segmentation should be, what your filtering should be, what your egress policy should be, what your macro/micro-segmentation policy should be.
And somehow, many CISOs forgot about that. Or started maybe with the next-generation firewall and their stateful workloads, and then forgot about it or got run over by development, and just ran away from them. But ultimately, it is the job of the cyber teams to protect the estate.
And we've got to get back to fundamentals of if you assume continuous breach, and I think we could very quickly get to a landscape where an organization is being breached 100 times a day or 1,000 times a day, because the attackers are much more organized than they used to be. They have access to AI, and that's both for vulnerability discovery, but also for autonomous attacks. And the cloud is so wide open because of what we've been talking about, that if you attack, even if you just assume a successful breach in one part of your estate per day, what you have to focus on as a mitigating control is how compartmentalized is that?
How containerized is it? If it's just one workload in one service, it sucks, but the rest of the estate is still fine. I can still operate.
If it's lateral movement that's really easy, and you have to assume patience and credential harvesting and effective lateral movement without the right controls, it gets really bad. com's estates, and we can't transact until they pay the ransom, which could be days or weeks, as we saw with Jaguar or Tesco in the UK. So that's my passion, is can Aviatrix help solve this?
For sure. I think we've got a really elegant technology for it. But my passion is even more on the please pause and think.
Do something. Pause and think. Help yourself.
Yep. Help yourself. I feel like Jerry Maguire, help me, help you.
No, right, it's by Jerry Maguire moment. Use something else. Use a different tool, but take care of yourself.
Do something. Yeah. But Doug, let's focus in on the Aviatrix solution, though.
How do you guys tackle this? So because we're network roots, we've got a really interesting architecture that first of all combines many different elements that people would typically put into a firewalling, micro-segmentation, NATting, IDS, IPS arena. So it's very comprehensive in what it attacks and what it delivers.
But the more important part is these estates are really complex. Now you've got thousands to tens of thousands of workloads. And it's a very elegant and interesting distributed policy enforcement point framework because you want the policy as close to the workload, as close to the action as humanly possible.
And there's a couple of key tenets that we've been working on to make sure that we can solve this problem effectively. So one is it's got to be ubiquitous, that you've got a whole bunch of mixed types of workloads. You've got stateful, traditional VM-tethered workloads.
You've got a bunch of containerized workloads. You've got a bunch of serverless workloads. You've got APIs you're calling, PaaS services you're invoking, and if you can't cover that entire estate, then you're in trouble from just a visibility and policy perspective.
So something like Istio or Cilium will do an interesting job inside of a container, but it doesn't do a great job container to container. It doesn't do a great job on other workloads. So you've got to be able to address the totality of workloads with one solution.
It's got to be multi-cloud. Very few organizations today are resident in just one cloud, and they're all very different, as most of you out in the audience know. It's got to be able to resolve policy very quickly.
Going back to what are we thinking we're facing? If it takes an hour to propagate a policy across that estate, you're dead in the water. It's got to take sub-seconds to seconds.
And then the framework for it has got to be both agent understandable and human understandable. The old policies, if you just go to a firewall construct, were IP-tethered, because of that they become very, very complex. You've got to have a way to address every single endpoint resolution framework.
And that doesn't work in this world for humans or for agents. So we're intent-based. We've got really elegant language where you can say simple things like dev should never talk to prod.
Because the magic that we do within the clouds, we're deeply embedded into the lower-level primitives within the clouds. We will very quickly determine, through the metadata and APIs and much better elements that we tap, which workloads are dev, which ones are prod. And if a brand new Lambda function springs up, we can identify it in milliseconds as a dev Lambda function and apply those policies directly to it so that you don't have those huge openings.
So our goal, why don't we have this? Why didn't micro-segmentation ever take off in on-prem data centers? Because it's really hard.
It's really, really hard to try and start with a default deny policy. And our core is to make the network invisible. We leverage the network for what we do, and to not make it super hard.
We need to be able to get to a default deny policy as the standard. And I think a lot of the core constructs we put in place are important, and I think, going back to AI, it being good and bad, AI can be super, super helpful on this. That I agree.
You know what? I agree. Micro-segmentation was not something you snapped your fingers and you were able to intelligently micro-segment, not just your cloud, your LAN, your servers, everything.
However, with AI- It's so hard because there's so many combinatorial effects. Yeah. And a human mind- And there's so many things, it was so dynamic.
It changes minute by minute. Yeah. But with AI, I'll be honest, with AI, there's no excuse.
I agree. No excuse. It's so good at synthesis.
That's our problem, is we hit a cognitive peak trying to understand the graph. And AI is actually really good at that. So we've seen incredible impact from deploying AI within our customers' environments on both the initiation of what you do, but then the day two operations, to make the day two operations workable.
Love it. Doug, we're about out of time. We got to wrap up.
io? Yes. Okay.
ai. Yep. What about Aviatrix on the road?
You guys are going to be at Black Hat, you're going to be anywhere, or looking for people- Yes. We were at RSA. We will absolutely be at Black Hat.
We're going to try and be visible. Where, like many vendors, we're less focused on booth and show floor than we are meaningful conversations with people that are there. Yep.
So if you guys are interested- Well, we'll be there doing video. Reach out. Doug, let's catch up in person.
Yeah. We'll continue this conversation. It'd be great.
It'd be great to do this in person. Yeah. It's 114 degrees there in August, but what the heck?
August 1 through 6 is always a perfect time in Vegas. Yeah. Yeah.
Just a couple of degrees cooler than hell. But Doug, man, it's hard to believe three years, but congratulations. Keep up the great work at Aviatrix.
Look, these are real problems that are becoming more real and more serious, and as we continue down this AI adventure we're all on. I completely agree. We're counting on you.
Okay. Thank you. All righty.
So I'll leave you all with the simple slogan that we're coming up with, which is, when prevention fails and detection is too slow, going back to those first two errors, containment is mission-critical because it decides whether the incident becomes a breach with catastrophic or material impact or not. So we just have got to add in blast radius as a key board and CEO metric, which is a lot why I'm doing work with folks like you, Alan, is I feel for the CISOs. They need air cover, and they need the right metric to go toward.
And getting to zero vulnerabilities is interesting, but I don't think it's the core. We're not going to get there. We're not going to get there.
I also think it's impossible. Stop. Yeah.
But anyway. Yeah. So thank you.
And what do I know? And thank you for having me on, and thanks for the great conversation. Thank you.
Doug Merritt, CEO of Aviatrix, here on Techstrong TV. We'll be right back.