Low-Code Security Automation – James Brear – Swimlane
Swimlane CEO James Brear explains how $70M in additional funding will be used to advance security automation.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with James Brear CEO for swim Lane. They are provider of a sore platform in the land of security. They just raised 70 million dollars and we're gonna be talking about what is the state of Automation in the land of cybersecurity James.
Welcome the show. Thank you by the beer. 70 million sounds like quite a lot.
So what's the plan for that? I'm sure you maybe bought everybody a virtual beer, but at this point the top of the agenda for you guys, I think the reason for the fundraising is that we're on a pretty rapid growth trajectory. Currently we want to continue at that growth.
We hadn't spend a ton of money on sales and marketing most of our activity has been in development. We're now transitioning to go in going work aggressive on or go to market and us we want to raise capital and enough that to get us to a break even position that's effective. The reason we've been talking about sore for some time.
Now, there's a lot of choices out there. What do you think is the challenge organizations have with automating security in the first place? Well, believe it or not.
I don't even use the word store. I think sore kind of denotes a very small portion of the overall security landscape in a way clearly soar is important in terms of it basically denoting the security operations center the sock and that's generally we're sore Technologies begin to get adopted but for swim Lane, I think that's one of the things that separates us from the competition is we go beyond the sock or beyond what the classic definition of stories. And we really look to new applications outside of the sock for our growth.
What kinds of applications are those do you think? Oh, man, there's quite a few, you know, the traditional sock application of they're still the Bedrock that's kind of our entry point. But if you look outside of it, we're looking to our customers.
We're seeing a multitude of different places that we're getting interaction, whether it be in the fraud team compliance team the dev team multitude areas where we see an opportunity to get broader and help bring automation to the broader security contacts. We hear a lot about devsecopies days and it gets a little tough sometimes for the developers to wrap their heads around and a lot of people are wanting to what degree can we shift that left or should we be relying more on Automation and now less than the developers who are never going to understand cyber security in the first place. A very good question.
I mean initially. Sore and has been traditionally a technology. That's somewhat complex.
It does require a level of expertise. To implement these work these workflows or playbooks. And that is kind of help the the market back.
One thing that we did a long time ago is develop a low-code framework that allows if it's devops secops folks to begin to visualize and become builders in their own way where they can articulate a workflow or a Playbook on the own and execute it leveraging low code tools where in the past that was not able or available. What level of development expertise do I have to have if I'm a cybersecurity professional to use Loco tools? I mean, can I just be a mere mortal or are these more like powerful end users?
Where are they in that Spectrum? I would say historically we saw a lot of folks that had like python experience you have to do that level to really building Garner the value out of an automation platform. I think if you look today at least for swim Lane, you don't have to have programming experience.
It's more of a drag and drop kind of a very intuitive technology allows you the secops analyst to visualize and execute A playbook. That would not require a program. Do you think that the bad guys are automating maybe faster than the good guys?
And are we involved in a cybersecurity automation arms race essential? There's no question at the end of the day. The value automation provides is it you can't get enough work done with humans.
You're fighting Bots and the proliferation of bots or are so much that you have to automate there's not enough time the day there's not enough money you could spend with humans to protect against So why don't you think people automate is it just too hard at the moment and that's been the issue or are they reluctant to put their human knowledge inside of platform? I mean, what is is this a career threatening issue in people's minds or is it just that it's too hard. I don't think it's career threatening the folks that we talked to the customers I talk to.
All sees value and automation. They know they've got to do it. Um, it's just a matter of do they have the team and the Strategy to implement Automation in my mind if you're a C cell you have that's your first decision.
Automation is effectively kind of the data plane, you know the control plane or the the power grid for your your security strategy everything all your endpoints all your technology feed into automation. So if you don't have an automation strategies can be very hard to protect and defend so in my mind, it should be the most important. I think there is a sense though people understand the power of automation.
It's still we're very early in the cycle of automation. I would call it the third inning be honest. There's so much more if you look at the use cases that are being adopted.
You know just go back two three years ago was triage it was you know. Simple simple use cases now. It's very Advanced and it's going to expand even more broadly over the next 24 months.
What do you wish most organizations new or appreciated about automation going in when you first meet them. What's the one thing you kind of seeing folks doing over and over again that you wish they were a little further down the road. I think the recognition of the value automation provide in terms of protection and compliance, you know, there's every even small companies even swim Lane has 200 disparent security Technologies.
It's overwhelming and I know that as a seesaw or a manager of any kind of enterprise. If you only knew how valuable and automation strategy could be to ensuring protection. I think you'd want to investigate a lot more thoroughly.
And now where the direction of automation's headed. It can be deployed used from a broad set of folks within the entire security organization. It doesn't have to be that you know developer in the sock or in devops that takes a long time.
It's scary. It's hard to use. It's really matured a lot not only in the industry, but for swimming specifically we spent a ton of time on usability and simplicity to make it easy to use and deploy.
All right, so we have nothing to fear but automation itself as it were. Hey James. Thanks for being on the show.
You bet. Thanks for having. All right.
Thanks guys and back to you in the studio.