Navigating Cybersecurity with Koi’s Idan Dardikman
Transcript
Hey everyone, it's Alan Shimmel. Welcome back here to Techstrong tv. Our next guest is Edon Ekman.
Uh, first of all, we gotta give Edon to a Mazel. Tuffy just, just had his first child, a boy last weekend, so we are thrilled to have him join the, uh, the parents club. So you Thank you so much.
Thank you. Thank you for joining us. So very exciting times for you having a baby, your company coming outta stealth.
You know, savor my, my advice to you, having been there, done that, right on both counts. Savor every second of this time because one day, 20 years from now, you're gonna look back and say, wow, those were the best days of my life. Um, so good for you.
Good for you, ed. Thank you so much. Yeah.
We're not gonna talk a lot about the baby right now. We'll save that for when you're working in the family, but we're gonna talk about COI security, but even before we talk about COI security, let's talk a little bit about you. You're a co-founder there and CTOI believe, correct?
Yeah. Give people a little bit of a sense of your journey, how you got to here. So I started my journey in the, uh, intelligence force of the IDF.
I did, uh, uh, cybersecurity there for about six years. And I was in charge of case security training for, uh, for the intelligence community. And then most of, after I was released from the military service, I dealt with incident response.
Almost my entire career. I was a consultant, one of the first employees in Signia. And after that I had my old firm.
And I really, really loved the human aspect of it. Like working with security practitioners many times it was in a very, in very hard times for the organizations. 'cause incident is a difficult time, uh, but also other times, uh, preparing for the incident, trying to prevent it.
And I think, uh, it was fascinating to see how different organizations think about security. What are the priorities of, uh, different security teams and so on. And then, uh, a few years ago I started working in a startup called, uh, Canon Security that was acquired by Zscaler.
I worked as the head of SA security research in Zscaler for a while. And almost two years ago I founded, uh, co security with, uh, my two co-founders. Excellent.
So, so you guys have been working at Koi Fruit, working at Koi for two years already to get to this point. Um, you know, even founding a company is not something one does lightly. Right.
Talk to us a little bit about kinda what, what was the mode of, you know, what, what drove you, what was the passion in finding in founding coi? What, you know, every, I speak to a lot of founders, um, multiple serial founder myself. Right.
What, what drove you, what was, in what way were you trying to kind of make the world better solve problems? So I think for me it's, uh, mainly two things. Uh, one of them is creating, uh, a great security product because, uh, during my career as a security consultant, I worked with a lots and lots of security products.
And many of them feel like they're not, you're not even supposed to use them 'cause they're really how to use. And the interface is, is low and it doesn't look so well. And it was really frustrating both for me and for the petitioners I was working with.
And I really had a, a passion of creating a security product that is almost like a B2C app. 'cause it should look good. It should be comfortable, it should solve a, a real problem.
And we knew there was a problem with, uh, software on, uh, endpoints that, uh, we were really passionate in solving, and we wanted to, to create a product that is loved by its users. And the second thing is that I really wanted to create a, a place that is a good place to work because I knew that in my career when I worked in good companies, it was a tremendous experience. The people you meet and the experiences you make together.
Sure. Absolutely. I, uh, you know, as, as I co-founded several companies and text Strum being the, the last one here, uh, I agree with you, right.
Having a sense of we're all in it together. You know, as you grow, it's hard to keep that feeling of family, if you will. Yeah.
Right. But you want to make it and, and you want to make it a fun place. You wanna make it a place where people want to come to the office, they don't feel like they're coming to a prison cell, you know?
And Absolutely. So yeah, I I try really hard with that too. So when we talk about software on the endpoint, right?
As a potential security mm-hmm. What, what exactly. I mean, there's a lot of facets to endpoint security, right?
There's, there's looking at traffic coming in and making sure no malware gets through. There's exfiltration, there's locking down the data, locking down identity, what, you know, what aspects of endpoint security is COI involved in. I think think that when, when we think about software for the endpoint, like the third thing that comes to mind, uh, for anybody that's been in the industry for a decade or or more, is probably, uh, executables, uh, DLLs binary files.
Like those are the classics. No, uh, like the, the, the classic attack is that somebody sent you a malicious file over email. And I think that many of the current, uh, solutions for endpoint security are still solving that problem.
But this is something that happens less and less as time moves on, because we do make some progress, and now we have great tools that prevent this kind of scenario. Um, but in recent years, we found that most software that actually runs on the endpoint is actually not, not what we imagined at all. It's not the binary software.
It's a high level language software. Many times the JavaScript, for example, Chrome extensions, people think, oh, it's just extensions. It's just, it's sandboxed.
It's not something serious, but it's, it's software, software nonetheless. And extensions for the IDE for developer environments, those stuff, they can, they have high privileges. They can touch any file on the computer.
So the security world doesn't treat those kinds of software as serious threats because they're not binary, they're not executable, but they still are little pieces of code, or not so little, but run some logic, some business logic on the endpoint. And we found this to be a huge gap in the current, uh, security model for the endpoints. Absolutely.
Absolutely. And, and, you know, so a lot of it is browser-based security, right? So that's what we're talking about.
Mm-hmm. Because the browser, more and more, the browser is the interface that users use on the endpoint, and it, it's, it interfaces with the software on the machine. It interfaces with software, you know, up in the cloud everywhere now.
So is that where COI plays, then? You're locking down sort of the browser, uh, browser extensions, browser interactions, monitoring web traffic there? So we do provide, uh, security for browser extensions.
Mm-hmm. Uh, our main focus is to secure the actual software that is installed on the endpoint. Got it.
Which can include browser expansions, but it can be, uh, NPN packages. And right now we have a huge incident in NPM Today. Did you see this?
Like 140 packages or something? I saw. It's crazy.
And we have an, uh, updating incident page in our website to help practitioners monitor, because new packages are discovered to be, uh, compromised, uh, by the minute. Uh, so this is, uh, uh, a great example of how those type, the new type of software, NPM can be marvel for the endpoint, not only endangering the, uh, CITB or the production, You know, I was reading this morning before we got on here, um, evidently I think CrowdStrike is rolling back some of the packages to previous versions that didn't contain the malware. Mm-hmm.
But if, if you're watching this and you're not aware of it, you should get on top of this immediately. Absolutely. Right.
Make sure you don't have any of these packages in there, or maybe go use COI software for this. Right? I mean, this is, this is exactly, you know, the poster shop for what you guys are, are trying to prevent, right?
Yeah. And unfortunately, uh, we couldn't have asked for a better demonstration. Um, and even people that are not, uh, using coil coil customers who can reach out to us and we'd be happy to help, uh, understanding this threat and mitigating Yeah.
This is a serious thing. And, and, and I'm not picking on CrowdStrike, right? I I know George for many years.
I CrowdStrike's a great company, but when it happens to a security company, it's like a double, double whammy, you know? A double double. Yeah, Absolutely.
I don't think it's, it's definitely not CrowdStrike's fault. There are no, uh, secu not many security tools, uh, today that can stop this kind of threat because it's a new type of form. Uh, but it just shows that if it happened to the people that know security best, then it can really happen to anyone.
And it's a threat. And, and it also brings up a whole software supply chain. And, and, you know, you've gotta know what, what's going into the software you're using, right?
What packages and so forth. And I, I think a lot of people, a lot of end users are shielded from that, right? Whether you use Windows or Mac, you don't think a package is, or Yeah, we don't even think much.
I mean, we think of applications maybe, but you know, it, it, it's not like, it's not like you're installing Linux on a desktop and you're picking what packages I want in my in store, right? Where you're very, you could be very deliberate about what you want and don't want on the machine. Uh, most of us, you know, we, we click the button and we download and we get what we get with it.
And, and it, it's, it's scary. Um, it, and we'd be, you know, negligent If we didn't mention that Coy came out of stealth just recently now, and, you know, with a very, very big, a round seed round. Why don't you tell us about that a little bit?
So the way we started COI is we built the risk engine first, and then we started working with, uh, paying customers. And we got the Fortune 500 companies, uh, contacting us because we had this type of risk engine that nobody else in the industry had. So it really helped us raise, uh, significant sums of money because the value was already proven when we, uh, stopped our seed round and then promptly after we moved on to raising the RA round, uh, uh, $38 million.
Uh, that's the, a total funding is, uh, 48 million. And this is great for us because we really see there is a huge gap here and a big opportunity, and we're very determined in, uh, building a product that mitigates this opportunity. But, uh, you need firepower to do that.
'cause it, this, this is really big challenge. Absolutely. Absolutely.
Um, so congratulations. Uh, you know, in today's world, it's not COVID times anymore. VCs have tightened up with the monies.
They, it, they don't write checks like they used to. So to raise that kind of CA round combination c and a round is quite an accomplishment. So congratulations to you and your co-founders and the whole, the whole company.
You know, it begs the question, well, what are you gonna do with this money? Right? A lot of people out here have never been a founder, have never done the startup thing.
They say, oh God, they raised $38 million. They must be rich. Well, no, it don't work like that, right?
We, I wish it did, but really, what did think of it as going to the gas station, right? And you now filled up the tank with fuel, and the question is, where do you drive? Where are you gonna drive?
Where are you going next week? Exactly. You got full tank of fuel.
Um, so where, where does COI go next here? So we, we started as a solution for, uh, visual Studio Code and Chrome Ideas and puzzles, uh, which, which was great. And we used the seed round funding to raise great l and d team, uh, founding engineers, really great guys.
And, uh, of course the research team. And, uh, now that we have the A round money, our main focus is, uh, two things. One of them is, uh, creating the, uh, GTM team.
Uh, that is really important for our company to scale because now we know that we have a, a great product that, uh, we need to get out there. And the second thing is to, uh, to hire more people for r and d and start tackling, uh, the harder, uh, problems. Uh, we already have support for NPM and ppe, uh, but those marketplaces are, uh, at different scale and we need to build, uh, we need to build for much, much, uh, larger scale because, uh, we are very ambitious in the, uh, problems that we want to solve.
We want to be a single platform for managing really anything on the endpoint, any type of software That's ambitious. Let's talk about, go to market a little bit to GTM. So is there, like, what's the model?
You're gonna hire salespeople to go sell this, you're just going to create market demand from sort of outbound marketing. Is there a geographic focus? Is there a particular verticals that you're aiming at?
Right. How, how are you going the market? Actually, something that is, uh, pretty unique, uh, at COI is that we get lots of, uh, inbound traction because, because of our risk engine, uh, we keep finding malware all the time in all of the marketplaces that we operate in, and we publish about it.
So the risk becomes very apparent for many, uh, security, uh, professionals, and then they reach out to us. So, uh, the marketing of all kind of create itself just by the research work that we are doing. And, And I assume it's responsible disclosure and all of those things, right?
Yeah, Yeah, absolutely. So we report anything that we find, but since many times it's just malicious items, like malicious packages, malicious, uh, extensions or modules, then we don't need to responsibly disclose to the threat actor. Many times we do communicate with the threat actor, but Yeah, I get it.
Um, that, that's fantastic. How can people, you know, stay on top of your research? How can they, is there like a website, a, a service?
How can they stay on top? Well, we have our blog at, uh, security slash blog, and we have a very active, uh, Twitter or x uh, page. We have active LinkedIn page, so we publish all the time on there, usually every week.
Very cool. So if I had to ask you, what's the one, I'm sorry, what? One last thing that I really want to mention is that we all also have something called Codex, which is our community project and Codex, it's like the index by coi.
And you can, it's like virus total, but for extensions and items, uh, you can search any extension on Codex and get a detailed risk report. Uh, even if you're not currently a customer of coi, you can use that. It's a research that we're giving away just, uh, to help people get, uh, safer.
How, how do people get to that? What's, is there a URL something? How, how do they look guide up?
co security. Got it. Excellent.
That's a cool, that's very cool. Um, we don't have a lot of time. One last question for you, Eden.
What's the, what's the biggest problem you're looking to solve in r and d now that you have this a round money, let's say, over the next six months to a year? Oh, that's a great question. So building, uh, a risk engine that can scan, uh, millions of, uh, binary software is something that we are aiming at and that we're actively working on.
And this is the challenge. Absolutely. Very good.
Edan again, congratulations on, on the baby. Congratulations on the raise. Congratulations on coi.
As I said, take a moment, maybe smell the roses, enjoy the moment and, uh, come back and talk to us here soon. More on Text Drunk tv. Okay.
Thank you so much, Adam. All right. Idan Dart.
Dart. Gonna make sure I get this right. Darter?
Kaman, yeah. Okay. Co-founder CTO at COI Security.
That's COI Security here on Tech Drunk tv. We're gonna take a break. We'll be back in a minute.