Managing Application Developer Access – Shashwat Sehgal, P0 Security
Following the raising of $5 million in seed funding, P0 Security CEO Shashwat Sehgal explains why managing application developer access in the cloud-native era has become a bigger cybersecurity challenge.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Shawa Segal, who's CEO for P zero security, and we're talking about developer entitlements and cloud access and how to make all that a lot more secure than it is today.
For sure. Sasha, welcome to the show. Good to be here.
You guys just raised, I think, $5 million in seed funding, so you're new to the whole space. What did you look at and say, here's a problem that needs to be solved in a way that hasn't been solved already? Uh, yeah, it's a good question.
So a lot of it was born out of our experiences. So, um, I, before starting P zero, I was at Splunk, uh, where I met my, uh, co-founder, Greg. Uh, and, um, Splunk has been acquiring a lot of companies over the last few years, um, trying to build, um, you know, the, the, and a platform for observability.
And all of those companies that came in were very, um, cloud native. And what I mean by that is that they were running very modern applications on, on, uh, Kubernetes in, uh, with lots of microservices in AWS and GCP. And what we learned was that to secure them is very challenging because there is always a tension between security and, and engineering teams.
Uh, in particular, security teams wanna be more conservative, be, um, and they want to set guardrails in place. But all of these cloud native applications are extremely, they have a very wide attack surface area when it comes to entitlements. The number of entitlements in a cloud native environment is astronomically large.
So, uh, what we observed was that, um, trying to put controls over them caused a lot of developer friction. And having experienced this problem firsthand, we realized that there has to be a better way to solve this, and that's why we started building the company. So what is the way to solve this?
Because a lot of the issues we have are developers have varying skill levels, get into services, and they may misconfigure them and they may not should be there in the first place. And sometimes we see issues with, um, privileges where they get escalated and everybody has the same level of privileges, and of course, everybody's after the credentials of these developers. So, sort this out for me.
How do we solve this thing? It's a great, great question. So I think it is probably worth stepping back and just diving deeper into the problem before I talk about the solution, right?
So why does this problem manifest itself, or rather, how does it manifest itself, um, whenever a company starts off or, you know, or it could be a small company starting off, or it could be a large company, uh, that's kicking off a new project, right? Typically in the first few months, the focus, rightly so, by the way, the focus is usually on speed or anything else. The focus is always on getting a product to the market and, and finding that quote unquote product market fit, right?
So in these early days, again, it doesn't matter if you're at a small company or a large company, uh, but in the early days of any kind of project, uh, the focus is almost always on making sure developers have no friction in front of them in place to, to iterate and build as fast as possible to find a group of people for whom the product works, right? What this means usually is that security takes, uh, uh, becomes an afterthought. Uh, again, I'm talking about only the early days.
Mm-hmm. Right? Um, let's call it around until a project or an organization or whatever approaches a critical mass of engineers, uh, for, let's call it around 50 engineers, right?
In the early days, it's almost always the case that, uh, people will move fast, break things as they should, and, and security is an afterthought. Uh, until suddenly there's a point where, you know, a few things might happen. Either, uh, a security team comes in and says, and gets freaked out about all the, the stuff that's happening within their cloud and says, okay, we need to put some controls in place because things can get out of hand.
Or the organization matures and starts selling to really large customers who say that, Hey, our data might be at risk, so put, please put some controls. Or the organization might want some kind of a compliance certification like SOC two or ISO 27 0 0 1, right? So many of these triggers, um, could be, could, could mean that, uh, any of these triggers could mean that the organization says, okay, we need to put some controls to, to cloud access in place.
And once the organization decides to put these controls, they'll realize one of two things, or maybe even both. The first thing is that, um, they'll realize that many engineers and many machine users or service accounts may have very loose levels of access, right? Everyone has very high levels of access all over the place.
Um, the second thing, which is obviously security risk. The second thing is more of an operational burden In order to tamp down that access, they relies that there are, they have to put some kind of a process, which usually involves going through a ticketing system and ticketing systems. They've been around for, you know, decades, and they're notoriously slow, especially in a far for, uh, for the needs of fast-paced engineering org, right?
So the second problem, the first problem is that of security. The second problem is usually one of an operational overhead that trying to go through ticketing systems takes away a lot of overhead or puts a lot of overhead on platform teams because they continuously have to process tickets, right? So, to come back to your question, which is what does a solution look like, right?
Any solution to solve the problem of secure, uh, securing access has to solve two problems. The first problem is it's got to Provide a measure of security for the security teams. And by providing security, what I mean is they need to give a visibility into which identities have poor levels of access, right?
Um, and, and second, uh, they have to make operational overhead a thing of the past. And what that means is they have to be designed in a way that, uh, engineers find it very easy to adopt them. The, these tools they have to be in, in, in, it doesn't, it should not replace an existing process with yet another onerous process, right?
The, the, the, the, the system should automatically fit into the way engineers are used to doing their work so that it's a net positive operationally for the organization, right? So in other words, the solution that we have designed, uh, is, is something that price to find the right middle ground between security and operational overhead, You talked about friction, and if I put these controls in place, the friction that pops up is everything from I gotta type in my username and password multiple times over to sometimes it's multifactor authentication or whatever it may be. How do we take the friction out of that workflow?
Uh, great question. Um, so you, you touched on a very couple of very important points around MFA and around username, password and, and everything, right? So, um, our view of the world is that if you, if you think of it from first principles, securing any piece of infrastructure or securing any piece of, of data usually involves three steps, right?
Um, if you are an engineer, and if you're trying to access, let's say, an S three bucket, or if you're trying to access something in AWS or something in Kubernetes, you usually have to do three things. First thing is you have to connect to your system, right? Uh, second, you have to authenticate into your system, and third, you have to get the right levels of access.
Historically, uh, when we were in a quote unquote world where a network perimeter used to be a thing, right? Uh, connecting and authenticating were the, the biggest challenges for companies as they secured, uh, their, you know, access to their critical infrastructure to solve these problems. As you rightly pointed out, technologies like MFA, uh, you know, uh, hardware based authentication, username, password, strong usernames, and uh, uh, strong passwords, keys, key based authentication, et cetera, all of these things came out, right?
And securing access wasn't really a thing. Uh, 10, 15 years ago. It was all about securing connectivity and securing authentication to a system, right?
And again, this was because we were talking about a world in which security worked via securing a network perimeter where you define a ring or a network around your sensitive assets, and, uh, any, the critical problem is getting to that ring or getting to that network perimeter. And once you are inside the network perimeter, you know, you can do whatever you want. But increasingly in a cloud native world, uh, what we are seeing and what we are hearing from customers is that the first two steps, which is connecting and authenticating, are more or less commoditized, right?
Um, technologies such as, um, single sign-on MFA, uh, hardware based, um, MFA, et cetera, they've, they've mostly solved, uh, uh, these challenges. And now as a result, what organizations are struggling with is how do you get people the right levels of access once they're already in the system, right? And that's the problem that we are looking to solve.
How do we make sure that, uh, you know, um, assuming a person is already in the system, how do we make sure they have just the right roles, policies, permissions, et cetera, that they need to, to accomplish the task that they want to do? So there may be a guard at the front door, but I gotta make sure that all the folks that are getting on the elevator are only allowed to go to the floors that they're allowed to go to, right? Absolutely.
Absolutely. And, and, and, and the analogy here, um, that I would make is, in, in the past, um, sensitive infrastructure was like a castle with a moat, right? Um, you get past the moat and then you have access to whatever you want, but now modes have disappeared.
Instead, the castles have become very complex with lots of tunnels and lots of doors, and it's not immediately obvious what door or what tunnel inside the castle any, uh, person should have access to. Who's leading the charge on implementing this? Is it the security team, or is it more like the security team is yelling at the DevOps team to go fix this?
Yeah, it's, um, security teams historically have been more, uh, focused on operations and compliance. Um, and we've also, what we are finding is that, you know, that that, uh, operational security mindset doesn't really work in, um, trying to secure a cloud native environment. The, the reason being, um, the cloud is so complex, you need to have a lot of context into what is going on.
You just cannot expect to scan a cloud, find a whole bunch of risks, and, uh, fix them without any knowledge of the system, right? And, and what we are seeing increasingly is that, um, in cloud native organizations, security teams are increasingly hiring security engineers, not just operational folks, but increasingly they're hiring actual engineers who've had experience in the past working with cloud native systems. So most of the time, these are the people who are responsible for setting and implementing those policies, those guardrails in any system, right?
Uh, and often they work hand in hand with the platform teams, with the DevOps teams, uh, and between the platform teams and the security engineering teams, you know, those are the people in, in most modern organizations who are being tasked with, uh, defining and implementing those policies. So it's easier to teach a DevOps engineer security than it is to teach a security person how to become a programmer. A hundred percent.
Yeah. I mean, and in fact, that is what we are increasingly seeing, right? There's, there's, um, uh, in many co companies before they hire a, um, you know, a fully, they, before they build out a fully fleshed out security team, they'll maybe start off by hiring one or two people as security leads on the platform side reporting event to the eventual CTO, right?
So that's, that's more and more a trend that we are, uh, seeing across, across the industry. We've been talking about DevSecOps for a while. Um, how do those security engineers meld with the DevOps engineers to create something that is easy to manage and is cohesive?
This is literally the problem that most companies are dealing with, uh, you know, all over the place right now. Uh, one of our big find founding thesis was that, hey, they, you know, both the security engineers and the DevOps teams need tools so that they, you know, tools that can bridge the gap and bring the two teams together, tools that are talking the same language, and not just operational security tools that are used by SOC teams or security operations teams that will give alerts and alerts and alerts that will drown them in, in, in alert fatigue and, um, but actual engineering tools that will help give deep context into a system and also help operationalize some of the policies that they come up with, right? That is precisely what we want to do.
Um, yeah, and I won't, I won't say that this is a solved problem. This is still very much top of mind for most security leaders. How do you not just building policies is the hard part, uh, is the easy part, right?
The hard part is once those policies are built, how do you actually operationalize them in a way that, you know, drives ROI in a way that does not kill adoption and does not impose any kind of frictions onto the, the, the, the engineering teams, right? That's still very much an unsolved problem. And that's, you know, something that in which we are hoping to make a dent.
Of course, these days everybody's talking about ai, can AI get applied to this? Can it help us figure out maybe where controls are missing or just explain to us what's going on? 'cause I think the environments are kind of confusing as they are.
Yeah, I mean, uh, fantastic question. So AI is, um, top of mind for literally everyone that I speak to, right? And at least in our space, in, in this particular space, there are at least two ways in which AI can be utilized.
Uh, the first is, I, I I, I go back to what are the two problems that we are looking to solve. The first problem is one of how do you provide security? And the second is, how do you, uh, reduce the operational overhead, right?
One way to use ai, for example, is to reduce operational overhead further by creating a very natural language type, um, interface for developers to request the right permissions that they need, right? Uh, instead of, uh, for example, um, building some kind of a web app where they go in and, and find the right resource that they want access to. Maybe what you could be doing is, is using AI to create some kind of a chat like experience, which makes it truly easy for them to request the right level of access.
That's something that we are, you know, uh, I'm sure lots of people in the industry are thinking about. I don't think that that has been solved yet. Uh, the second way, uh, to use AI for is, is for the second use case, which is how do you improve access security?
Uh, and again, I go back to the fact that access security is difficult because there are so many different roles, permissions, policies in a cloud native environment. How do you even start making sense out of all of those, right? Guess what?
AI can definitely help, right? Um, again, this is probably one of the many use cases that people are thinking about how to use AI to make sense of all of this data around us. So I, you know, definitely lots of areas to, to explore applications of ai.
I don't think it this is a solved problem either. So I definitely expect many companies to be, to be taking a crack at it. What's your best advice for folks about how to get started?
Because there's multiple clouds, there's lots of services, the whole thing can be intimidating, and in a lot of places it's a thankless task. So how do I get, how do I get after this in a way that won't drive me crazy? Uh, great question.
So this is, uh, I guess the age old question in, in, in cybersecurity, right? Uh, it's a very complex, intractable problem. How do you, you, you know where you want to get to as an organization, but how do you take baby steps towards it in a way that makes sure, ensures that you are making progress?
And the ROI is visible to everyone on the team, right? Uh, for us, at least, the way we are solving this is we will, uh, give organizations an easy way to scan their system, um, where we'll prepare a report of all the, the, the, the access and identity risks in their environment, and then we'll provide action, you know, tangible and actionable remediations for each one of them. And once you do, um, once you take any one of those steps, then our product is automatically embedded into their environment, right?
So we are taking more of an observability first, um, you know, uh, approach to, to, to solving the problem of monitoring and securing access. Well, folks, we didn't dig this hole overnight, so I don't think we're gonna dig our way out of it overnight either, but we gotta start somewhere. And first place is with some new tools that kind of help you manage the whole thing.
And from there you can figure out who should actually be accessing what. 'cause today it's kind of crazy. Everybody's just doing whatever they kind of feel like, and there's probably an auditor somewhere who's gonna have an issue with that any day soon.
Hey, Joshua, thanks for being on the show. Uh, great chatting with you. Take care, And back to you guys in the studio.