Navigating Application Security with Palo Alto Networks’ Sarit Tager
Transcript
Hey everyone, it's Alan Shimel back here on Techstrong tv. I'm thrilled to have our next guest on. Let me introduce you to Sarit Tager.
Sarit is VP of Product Management at Palo Alto Networks. Uh, well, I I don't wanna steal her thunder. I'm gonna let you, I'm gonna let her tell her story.
Reed, welcome to Text Drunk tv. It's great to have you on today. Thank you.
Great to be here. Thanks, Ellen. Um, you know, So I always, I, let me, let me, let me start.
I always like to let our audience know a little bit about who they're talking to. Tell 'em a little bit about Ed. Uh, so I always say you cannot get out of being developer 'cause this is how I started.
Uh, I was a developer. I, uh, kind of did a lot of applications, school applications, and then I moved to be a team leader and a VP engineering and kind of did a lot of walk around, uh, software and kind of experienced the application security tools from the other side of things. You know, I spent a lot of time, a lot of nights trying to figure out what I need to fix and how to fix it.
And usually it comes in the worst cases when you have to go to production and stuff like this. And then I thought, okay, my journey will, will go trying to be, uh, the product of such solutions. And I started in different cybersecurity companies for, uh, cloud security and application security.
Super exciting. I think that the one I'm always telling as a joke is that I speak a lot of languages, which is not, uh, just generous languages like English, but more about programming languages, which is super cool. And it's, I really like this space of being, uh, an application security, um, expert and trying to solve a problem, which is super, uh, you know, super critical for developers.
And they spend a lot of time doing it. Even with all these new AI agents, they still have security problems. Look, some people say, with all these AI agents, we may have more security problems, but Correct.
We'll see how that plays off. You know, he takes with one hand and gives with the other. Right?
And so this is what you're dealing with. Siri, Palo Alto Networks is certainly no stranger to most of our audience. It's no stranger to people involved in cybersecurity, the world over, you know, I remember when near, near and, and, and the team first came out, next Generation firewall and all that that entailed.
Wow. It was big stuff. Of course, you know, the cloud came out, uh, the cloud native, there's been so much ai, so much has happened, but Palo Alto hasn't stood, stood still either, right?
Uh, they've been a leader in cloud native security almost since there's been a cloud native security. The cloud security jumped on it. Um, recently there's been, well not recently, it's probably close to a year already, where maybe Cortex Cloud, which is now sort of the cloud unit within IMP Palo, um, has, you know, quickly established itself as a force in, in cloud security.
Um, I don't know, did I tell a good story about where Palo Alto's today, you think? Did I leave anything out? Yeah, so it's super exciting really, that we have like the Cortex platform and the Cortex Cloud, which combines the Cortex Platform Pro combine our, combine our XXAM solution and XDR and the Cortex Cloud, which is our solution for the cloud security and even our application security.
Like things cool, things like A SPM. And we are kind of, uh, always chasing innovation, whether it's our S-P-D-S-P-M solution or our ISPM solution. We are al always cha chasing innovation, and PM is one of them, and I think we'll spur some time talking about it.
And we absolutely are. Before we do, I wanna go back. Your VP product management for Palo Palo Alto, is that across the entire portfolio or just a specific, uh, section?
So I'm focusing on application security as part of Cortex Cloud. Uh, everything that is from the developer first line of code till it goes to production. Uh, try to save, you know, trying to save the production, uh, environment before they actually become vulnerable.
And my mission will be to make sure we all have a very, uh, safe production environment, but the developers, I wouldn't say love security, but at least don't hate security. And they kind of hate kind of try to, uh, meet them at their processes and make sure they then don't be, uh, uh, blocked by things that aren't, they are not aware of. So I wouldn't go into live in security, but at least not a security in a way that they can, um, see it as part of their processes.
So kind of have this ick security guys practitioners, which are super keen, just to make sure that they have a safer environment. And the developers, as we all know, really want to kind of push things to production, make sure that they have a cool things and cool business value bringing into production. So trying to balance between the two, uh, different, uh, personas.
Love it. You know. com though about 12 years ago.
I, I have a slightly different view. I, I don't think developers hate security. I think they don't understand security well, like why we do things that we do.
And, and they may not love the security admins. I'm not gonna hate's a strong word. com, I did it because I thought it was a great thing for security.
And for the last 10 plus years, every year at RSAI actually, well, we put on the DevSecOps event there on Monday in Moscone of jfr and all of the big DevOps, GitLab, all the DevOps companies have been there. And really the mission was to bring the, the DevOps tribe to the security community and vice versa. We've made a lot of progress.
We've made a lot of progress. I think we've learned a lot of lessons, right? I, I think we've learned that developers will never be security admins or security professionals.
They're developers, but they do care about quality code and that's what they want. And I think that's, with that in mind, security people need to approach it that way. Let's talk.
Look, not everyone out here is a security person. Some of them are DevOps cloud native platform. When we say A SPM, what does A SPM stand for?
The SPM stands for application security, posture management, you know, always say there are a lot of spms. Like you have the data security, the network, the infrastructure, the cloud one. Um, now we are talking about application.
I think that the most exciting thing about it's actually connect between the business and, um, and the security. If you think about it, you a developer know on which application you're working on. And it's not just about, okay, I have something on my infrastructure, or I have something on my data application is a core thing for you.
You know, you are working on application, you know, the valid application is bringing. So PM is about really connecting all the dots between security and application, given the business context. And the nice thing we do about it is that we have all the data from all the different signals, whether it's from the code, from the supply chain, from the cloud, and even from the actual attacks within the soc, combining one single place in which it can have all the different insights.
And this is how we create an application security which first has all the visibility. Second, can really point out to the developers what they need to fix. And the third one is about making sure they can, we can prevent as early as possible by giving them a very granular guards and not just yes, block everything, which is critical, which is not something that it's actually, uh, feasible if you are walking with a company in need of velocity and you want to make sure that the business value is being delivered to the customers.
Okay. Excellent. I love it.
Now you just introduced this Cortex Cloud, A SPM, um, is it available now? So it's available, uh, in beta in July and will be available for GA in October. Oh, okay.
So you have hard dates already. That's Course, That's brave. What do we put, what is putan, um, you know, point to achieve so you can actually meet them?
Yep. You put your flag in the ground and Yeah, we I've been there. I've been there.
Um, so you know, the tagline here is accelerate secure development with the definitive prevention first A SPM. So I'll, what do you Mean by that? I'll tell a story.
You know, the, most of the application security practitioners and most of the companies tend not to block things in the developer because usually it, from them it means they will, uh, uh, slow the developer, the development and they will not be able to accelerate the business value into the customers. So this is maybe correct for the things that are going on on developer side, but when you go to production and you find out the vulnerability or somebody that you have to fix, then this is a real, uh, now it'll become a real long process. Like first I need to figure out who is responsible, responsible for this, who is the one that need to fix it?
How do I know exactly where, who is the one that need to fix it? Probably the developer that already that did something is already on something else. You know, on the next version, on the next thing probably, uh, found another cool AI thing to, uh, work with.
And now I need to kind of convince him to fix things. And then when he fix them, then we need to test them and deploy back to production. So in the reality, I spend a lot of time trying to mitigate things on production.
This is one. The second one will be I'm vulnerable. My production environment, especially with all this new, uh, uh, possible attacks, uh, is vulnerable for a longer time and I don't really save developer time.
What we say is that because we have all the context and I know exactly how your repo looks in production, uh, whether it's open to the internet or whether it has an access to sensitive data, I can say, okay, this is more important than others, so let's prevent them first. And when you prevent for pr, for example, when you do a pull request, then this is the developer that sees this and knows, is, knows this code. You explain that this is the reason you blocked it, and then they will fix it.
You will not have to, uh, suffer for any insecure, uh, environment or from, you know, trying to remem you know, one of the things the developer don't like, and I didn't like it as well, I always say, when you are a developer, when you come up in the morning, you, you ate your code that you wrote, uh, last night. 'cause I think it's not good enough. I think that in this case, if you let the developer fix things, when you see them and you explain why you fix them, why you need to fix them and why it's important, why it's a really, uh, uh, create a security program, then they don't need to get, go back to court like three months afterwards or something like that.
So really try to bring all these signals together to make sure that you have the information on how to prevent things. And we also enrich all the different signals we have from the system. We don't necessarily have to switch your entire, uh, if you are using different application security tools, then everything will go into the same place will be enrich and you will also be able to prioritize.
So this is about how we really accelerating instead of just, uh, um, just, uh, uh, you know, making into production and then fix it there. Siri, thank you for that. You know, as I said, I've been involved in DevSecOps since we started, before we called it DevSecOps.
Um, I, I think there's a couple of things that kind of make, make the, make the whole thing go round. Number one is this, you know, shift left, right? It, it's kind of a given where the further we shift left, the more efficient, less expensive it is to fix defects, bugs, vulnerabilities versus letting it go, right, right.
If it goes into, into, uh, reduction or just further down the CI/CD process. So certainly if A SPM can help us be more efficient in finding vulnerabilities, bugs, what have you further left it, it's gotta be a big thing. The second thing, and this has been a problem in security and I'm interested in your take on it for as long as I've been insecurity desensitive, desensitive desensitization, no words, people get, they're overwhelmed.
There's so many vulnerabilities, there's so many, uh, things that need to, you know, take our time that the, the backlog of of fixes rapidly, you know, goes past our ability to do it in a timely manner. What do you is, how does, how does the, uh, cortex Cloud, AP A SPN help us with that? They always say that we do prioritize, we give the context for the issues, and you will be able to see what is important and kind of, you know, narrow the, the backlog to be, uh, much more, uh, uh, smaller.
We also allow you to, for example, say I only only care about new things rather than, you know, just everything. Um, I think the most important part is that if you prevent first, if you make sure that you prevent at the source, then your funnel is, is getting less, uh, getting smaller instead of just, you know, priority as in at the end of the funnel. We want to make sure the funnel is, is kind of being, uh, created smaller and then you have less thing to remediate.
I mean, in the, in the, in the end, this is the reason we want, we bring all this context into the developers, we bring them the information on why they need to fix it and then say, fix it now. You will not see it again in the future and you will not have to fix it. What's going to production or as you mentioned, create such a huge backlog, then you said, well, I dunno what fix, like I have too many issues to actually handle.
Fix it once. Fix it once. Exactly.
I don't wanna say fix it and forget it because that, that has bad connotations. No, you don't want to forget it, but certainly fix it once. Re you mentioned it's in beta right now.
The Cortex Cloud, A SPM, is that an open beta for anyone who wants to use it or closed? No, it's closed beta for customers that I want to, to use it. So this is what we're doing now, but it'll be available for all in October, just In a couple months.
Yes. Excellent. For people who maybe want to get more information, where could they go?
Okay, so they can, uh, check our website for additional information for uh, A SPM, uh, with additional information to, uh, kind of create demo or do anything on the platform. com or, or is there a separate site for Cortex Cloud? You could probably get to Cortex Cloud off of Palo Alto Networks.
Yes. Yes, you can get from the, from the main, uh, From the main page and look for a SPM from there. Siri, thank you for coming on today on Techstrong TV and telling us about this exciting new offering coming out.
Uh, I think we'll be seeing a lot of a SPM type of products, news functionality, and, uh, looking forward to hearing more from you. We, you know what, at the very least, you'll come back on October when this is in will With all the great news. Absolute.
All right, thank you. Best of luck and we'll be in touch with you Sir. Tagger, VP of Product Management, Palo Alto Networks here on Dron tv.
We're gonna take a break. We'll be right back.