Introducing Hush Security: A New Era in Cybersecurity with Micha Rave
Hush Security emerges as a promising startup in cybersecurity, Co-founded by Micha Rave. With a rich background in technology, Micha discusses the challenges of operating in stealth mode and the company’s mission to manage secrets effectively. Hush Security adopts a policy-based access management approach, offering a free assessment for onboarding. Backed by notable investors, Micha expresses optimism about the future and the role of passion in their journey.
Transcript
Hey, everyone. Welcome back here to Tech Drunk tv. You know, I don't know, there might be something in the water, but it seems it's, it's coming outta stealth season.
Uh, we've covered a few companies this week, of course, that have come outta stuff. I've got another one here for you. And it's an exciting security startup.
It's called Hush Security. And to tell us about it, I want to introduce you to Mika Rave. Mika, welcome to Tech Drunk tv.
Thank you for being here. Thanks for having me, Alan. Nice.
Hi everyone. Yep. So, look, first of all, congratulations, right?
Malow tough. And so coming outta stealth is a big, uh, a big accomplishment in my career. I've done four or five venture backed companies and, you know, launching them out of the stealth mode is telling the world the secret you've been working on.
And, you know, no pun intended, 'cause you guys work secrets a lot. But, uh, congratulations. But before we get into Hush meher, tell, give people a sense.
How did you come, you know, what, what's your journey been like? Yeah, thanks, Alan. So I've been, you know, working with computers since, uh, the third grade or so.
Uh, been very enthusiastic about it. I liked it, you know, ever since the first, uh, um, irat, CPC that I had, uh, like in 84, I've been using that, uh, been working through that, you know, through school, college, and through all my, uh, career basically. I started with, uh, you know, the, the electrical engineering worked my way, managing teams of, um, of developers and engineers.
Uh, eventually ended up, uh, as a product manager, uh, responsible for a very big virtualization, uh, project, uh, with one of the companies I worked for. Uh, moving there from there to cyber. And then eventually kind of, uh, in late 2016, I was, uh, tapped on the shoulder by a friend of mine from way back when they were starting a company called Meta Networks, which was doing, uh, zero trust, network access very, very early on.
And so the technology was amazing. Uh, the people were great, and I, I kind of, uh, jumped on that wagon. The company was acquired, uh, three years after by Proofpoint, a very big, uh, you know, security enterprise.
Uh, and then, uh, we decided, you know, the entire core team and the rest of the, of the engineering team and, and the product team just came with us. We decided to move out and, and, you know, solve another big problem that was waiting to be addressed. And this is basically the exponential growth of, of non-human identities, secrets, uh, machine to machine access and so on.
Absolutely. Absolutely. And, you know, people think a company emerges outta stealth that all of a sudden it was born Today we just started.
But no, often I, look, I have friends who've had companies in stealth for two, three years sometimes. Yes. How long has the, let's call it the incubation of hasin until a, Uh, yes, that's very true.
We've been in sales for a year, right? Uh, we've been, uh, developing very rapidly the solution in various, uh, dimensions of it, right? And because we are, uh, a seasoned team that has been working, you know, together for past decade, but separately for, you know, more than two decades.
Uh, so we know, you know, we had a very good, uh, clear idea of what the, the solution would be like and what would be the infra for that, right? The, the, the ability to scale, the ability for design with security in mind, the ability to sell to the enterprises and the Fortune five hundredths of the world, all of those things, you know, you kind of acquire them as you go along. And, uh, we've put all of our experience into this and pour it into the solution we had one year to kind of, uh, hone it, and then now we are feeding that it's the right time to announce that to the world and start, uh, start getting some, uh, demand.
Yeah, Absolutely. And one last thing, Mika, what, what's your position? I'm the C-E-O-C-E-O and co-founder.
And co-founder. That's true. Congratulations.
Thank you. Uh, Let's talk about Hush a little bit Now. Hush, now that you're out of stealth, we, we, yeah.
Um, so obviously you're deal with tackling the secrets problem, which is a, look, it's, it's a thorny issue. We've seen several companies, especially I'd say over the last year to two several companies really, uh, you know, going after this problem because it's, it, it's, it's a problem we've built up. I mean, the whole idea around doing secrets was, was in itself a good security.
And, and this is typical. I've been in security 30 years, you see this stuff. So we came up with the idea of having secrets and vault, and, and of course, HashiCorp, you know, kinda led the way there a little bit.
And, and it sounded great. You know, another a, a good way of, of securing stuff. But it's a case where the solution became the problem a little bit, right?
Where we built up this whole infrastructure of secrets that then became a, a new attack surface, if you will, Right? That. And, and now, you know, it's like the old story.
We, we, we had elephants, so we got mice in to take care of the, Got mice. Now we got a mice problem. Uh, now we got to get cats, and then we get the cats.
We'll have to get the dogs to get rid of the cats and to get rid of the dog. You know, it goes round and round. But what, what about H'S solution is, is unique, is, you know, why, why is this the right solution to manage our secrets and secure secrets and vaults and so forth?
It's an excellent question, Alan. And I think the, the, it all started, you know, for us, right? The journey started like a, a year and a half ago when we looked at, at the, this problem, which was troubling us.
And we, this was part of, uh, what we wanted to solve. We looked at what was, uh, available at the market back then. And as you said, there were several companies, several very good teams backed by very good venture capital.
You know, we're, we're kind of doing, uh, uh, a thorough way of educating the market about this problem that is locking within their data centers and, and clouds and so forth. And the exponential growth of secret. They did a phenomenal job in the education part.
But in my opinion, when we started to look at what we, they were developing, and we talked to a security practitioner, we found out that there wasn't really a solution. So it's one thing to talk about and to scan, you know, and find and try to find those and open geo tickets for them. But this is just a, you know, increasing your technical debt.
You are not actually solving the problem. You're still using, I would say, a broken, uh, architecture for, for the modern and complex environment that we, that we develop software in. And so we thought, you know, that's nice, but there must be a better way to doing that.
And when we looked around, we actually saw kind, kind of parallel domains in which it was, uh, it was very well done. The, the first one is, is the human identity side of thing, right? And, you know, think about what has been done in the past decade, like single sign on and MFA and, uh, IGA and Pam and so forth.
So the lab, great solution, you know, to help, uh, uh, maturity, the identity, uh, and, and solve the risk around that. Second place, it has been solved, uh, quite nicely is cloud native environment, right? So when you go to AWS and you wanna access one machine, you don't necessarily take a key and store it in a vault.
You just write it policy, allowing that machine to access another machine. And so we thought, we know how to do this. We need just to bring those principles and those methodologies into everywhere, cross cloud, on-prem, federated, uh, and done.
Nice. And a very, very important, uh, part of it is that we wanna do it in a way that is kind of transparent or retrofitting to what customers are doing, because we don't want to go in and do like a multi-year project that costs hundreds of thousands of dollars and, and years of, uh, implementation. And so we actually found a way to do that, and we wrote a patent, uh, on it.
And, uh, we have built a platform around the, around that. So, so first of all, comprehensive discovery, so you can actually see what you have and where the bodies are buried, so to speak. And then on top of that, we can actually transform you into policy-based access management rather than chasing secret.
So in a way, we are going to obsolete the vaults and, and, and, and maybe the secrets as well. Excellent, excellent. Um, so the, so I just wanna make sure we get this here for the audience, right?
So that one of the real advantages of Hush is you don't have to be all in on the public cloud, on the hyperscaler, and you don't have to, whether you're a multi-cloud, hybrid cloud, what, whatever it is, right? You, it's one solution across the infrastructure, Correct. For your, Yes.
And by the way, we are using, you know, trusted framework and standards when we do that, right? We don't wanna invent, uh, anything from the beginning. So for example, the base of our, uh, attestation is, is a spiffy, right?
If you're familiar with that, it's a kind of an up and coming, uh, standard, which was have a very hard time kind of getting momentum behind it because it's quite hard to implement that on your own. So we use that, we kind of bring that to the masses with a very, very easy onboarding team. And it's part, it's just one brick, you know, one component in our, uh, in our platform.
And, uh, so we tend to build on, on, tried into, uh, standards and frameworks. I got it. Let's talk, I wanna, Mika, I wanna turn a little bit to kind of the, the nuts and bolts of how people engage here.
Um, sounds like, you know, if I'm a, an organization, I want to use hush security. What, what, what, what's the process? What's it like to get started?
Excellent. So first of all, we need to connect, uh, to your infrastructure agentlessly, right? So you give us a, you know, an API key or an A or an A RN or whatever the case is, we connect to your code repository, to your infrastructure, to your SaaS.
We scan whatever we can, and we build the, the initial, you know, inventory of, uh, of what you have. And then on top of that, and this is where we kind of differ from anyone else, I think in this field, we map everything in runtime. So we have this set of runtime technologies, which we deploy very easily, and then we can see every machine to machine interaction and every authentication event that happens.
And we've got so much telemetry, we, we upload some of it, uh, the metadata of that to the cloud, and we do some deep analysis with some ai, and we bring back very nice, um, uh, findings and result and, and basically posture for every machine to machine interaction that you have. Excellent, excellent. Um, is there a free trial?
Uh, how, you know, what, what, how, how's it packaged, I guess is the word? Yeah, absolutely. So basically we allow a free assessment, right?
So you come to us, there is a landing page in, uh, hashtag security. Uh, you can go there and there is, uh, get a demo and get an assessment for free. So we can, you know, the onboarding is super easy.
We can, uh, take, take our customers through that. And, uh, and basically an hour or two, you've got all your environment, uh, mapped, uh, and, uh, and yeah, it's, it's, it's easy, as easy as that. Excellent.
Yeah, I mean, we're almost outta time, but you know, I, I feel like we didn't ask this question or at least touch on this subject. Usually companies come outta stealth. It's, there's a, a raise involved with it, right?
Because that of course helps us get out there, right? Um, talk to us about, uh, fundraising at Hush and some of the financial backers. Yeah, so, uh, financial backers are, are amazing.
Uh, we've got Battery ventures, which is a global, you know, uh, very well respected and known in the industry. And, uh, we also have as the cyber, uh, aspect of thing, which is wild ventures, and they're doing an amazing job. Uh, and so I couldn't ask for anything better, right?
It's, uh, it's a, well, uh, you know, known and back one, which is better. And then we've got, you know, the, the cyber, which are experts, and they have their networks of advisors and, and CISOs. And so I think it's a great mix, and I, I, I, you know, recommend that for any cyber, uh, uh, innovators out there.
It's, uh, come talk to me about it. Excellent. Mika, again, good luck and congratulations.
You know, I, I, I think I told this once to a founder. This is the end of the beginning. Mm-hmm.
True. And now you start on this next stage, and, and it, it's exhilarating. It's, you know, but as long as you have the passion, if you have the passion for what you're doing and believe in it, it, it's, it's great.
Um, keep us posted as you guys continue to expand here. Maybe we'll see you, I don't know, at some security conference in person. Oh, absolutely.
I'm gonna be everywhere, so, uh, I'll, I'll look out for you. Alrighty, good luck. Thank you very much.
Thank you. Hush Security and it's hush security. Go check it out.
Managing secrets a real problem is a real solution. We're gonna be back on text Drunk TV in a minute. We'll take a break.