Patchwork or Powerhouse? The Cloud-Native Debate with Loris Degioanni
The cloud-native landscape is intensifying as companies face a key decision: build custom solutions from scratch or buy top-of-the-line tools. Many are retrofitting outdated security products to stay relevant, but according to Loris Degioanni, founder and CTO of Sysdig, this approach falls short. Cloud-native security requires platforms designed with the cloud in mind from the beginning, not tacked onto legacy systems. Degioanni highlights the limitations of retrofitted tools, the need for agility in combating modern threats and his predictions for what will become the industry standard across nearly all sectors in the future.
Transcript
This is Textron tv. Hey everyone. Welcome back here to techron tv.
I'm really happy to have this next gentleman on as our next guest. His name is Laura Deani Deani. Laura Lawrence.
Say it for me. Could you say it better than me? Hey, Johanni, Say, Johanni Lo is the founder and CTO, chief Technology Officer over at Sig uh, lo.
Welcome back to Text on tv. It's great to have you on. I hope all has been well in your world.
Everything is great, and thank you so much for having me. It's always a pleasure. Absolutely.
So, you know, Loris, before we jump into our topic of discussion today, I always like to give our audience a flavor of who it is that they're listening to. So I mentioned you're the founder, you're the CTO at SY is a, of course, a major player in cloud native security, cloud security. But you know, you weren't always the founder and CPO at Cystic.
Give us a sense of, you know, your journey. Yeah. Sig actually is my second company.
My first company was called Case Technologies and was the commercial entity behind the Wire Shark Network, uh, analyzer. So, uh, in my career, I actually started working on Wire Shark when I was in school. Uh, started a company behind the, behind the, the project.
And so the first part of my career was, uh, you know, a mix of, uh, open source and networking and security. Uh, and then the company was acquired in 2010. And in 2014, I started working on focusing essentially on the, initially on the problem of visibility and security for cloud and cloud native infrastructures.
So, for the last 10 years of my career, I've been focusing, you know, on everything that is related to cloud, in particular, cloud native, trying to, you know, build a platform that can be, you know, like the great way to secure cloud native environments. You know, for those of us in security, you know, more than 10 years, 15, 20, 25 years more wire shark. I mean, so when I first got into security, there was a toolbox.
Um, a lot of them were open source tools, right. That every security, and it was mostly network security back then, right? That's where the action was.
Yeah. And, and there was, you know, you had end map, right? Yeah.
Wire shark. Yeah. Little snort, no heart.
That's this. Yeah. You know, and they, they were all great.
And every security person I knew knew all that. Those four we knew on for, and they were like in your toolbox. Like, you know, the plumber wears the belt with the, with the tools.
Those were your tools, and they were ubiquitous. Absolutely. You know, security was simpler back.
I, it was simpler to be a security person. I don't know if it was simpler or if we were as effective, but it was certainly a different time. Right.
And, and, uh, you know, there, those were your tools and every single security person, you know, knew how to use them. Funny. And it's been on one hand, uh, a great fun and honor, you know, to be part of the generation and to influence, especially, you know, like with Washer, with Snor with, and met all built by, you know, people that, uh, uh, I know well in their respect, we sort of define, you know, like sort of the security and visibility stack.
Mm-Hmm. But it's also interesting how, uh, many of the things, uh, that yes, the world is more complex nowadays and, uh, uh, you know, more dynamic, uh, and, and faster. Mm-Hmm.
But at the same time, what we are building for this generation is very much inspired, you know, like, uh, uh, even just the CD even just the c the way we, we collect data for cloud and cloud Native security, especially for the detection response side, is very heavily influenced by the stack that we built for Wire Shark, for Cpda, for North in the past. And even Falco Falco is an open source project. It's A-C-N-C-F graduated open source project that I worked on since the beginning.
I am, you know, the original creator of the tool. And Falco is heavily inspired by North, you know, the way it works, but it's, it's sort of north for cloud and cloud natives and, and and containerized environments. So yeah.
Nothing is reinvented, you know, or at least No. Everything is built on top of Exactly. And you learn from the prior generation and you try to get inspired and you try to apply it, you know, to the new challenges of the next generation.
Absolutely. Absolutely. It's what, you know, somewhere when something nothing's new in the world, right?
We, we just read the combinations are different and the way we build things are, you know, kind of, but you have everything you need and you go from there. But you know what, at least Tell people like, like, like me, you know, with, uh, you know, gray hair and gray and gray Hair, or at least you have hair. At least you have hair.
Be lucky, be proud. Um, so Laura still, you know, there are people out here who maybe don't know Cystic. Yeah.
Right? They may have heard of 'em, but they're not really, you mentioned Falco is a huge open size CNCF graduated project sponsored by Cystic, or they're founded over at Cystic, but the people if maybe who are not familiar with Cis Digg a little background. Yeah.
CIG is, uh, one of the leaders in cloud security. We offer a comprehensive platform that, uh, covers, you know, like the life cycle of, uh, cloud and cloud native applications. Our platform includes, uh, vulnerability management, uh, functionality detection and response functionality, compliance, risk and posture and so on.
So you can, you know, deploy it to secure, uh, cloud applications, uh, essentially from build, from code to, to production run. Um, what makes this the unique is, uh, uh, our focus on speed of detection. So I sometimes, you know, describe what we do as we're able to tell, uh, our users what, what other players in the space are able, we're able to tell today what our other players, players in the space are able to tell them tomorrow.
And the other thing is we focus on a platform that is based on as much as possible on open source components and on, uh, pieces and co and components that are developed, uh, by a community and for a community Fair. Absolutely. com is the, is the what main way.
com. That's right. Yeah, Yeah.
Right. With that out of the way, Laura, let's jump into what we want to discuss today. You mentioned 10 years, 10 plus years you've been working on Cystic Cloud Cloud Native Cloud Native's been around, right?
Yeah. But here we are 10 years in and we're getting ready. Uh, uh, juke Corn is in a couple of weeks, less than a month out, I think now.
And, uh, here we are, patchwork powerhouse. Has it reached critical mass? Has it reached its potential?
If not, will it ever, you know, is, is, did you think it would take this long? How much longer gimme your views? Has it been su success?
Well, uh, I must first of all, uh, admit that I probably have a, a little bit of a bias view here, because by, by definition, since you know, the company that I founded, uh, and that I still work for, uh, operates in the cloud security space, and in particular, our solution was, you know, very much born as a container security solution. So, you know, the, the inception, the, the beginning of SD was, was specifically for container security. And, uh, the company was essentially born together.
I remember, you know, few months, uh, before we started our company, you know, a little Mm, platform as a service provider, basically, San Francisco Code Cloud was renamed into Docker To Docker. So It was the very beginning. And then Kubernetes, you know, released by Google and the, and the Orchestrated war Orchestrator Wars, I dunno, who remembers, you know, like Mezo and, and Dockers war And, and rancher and, and, you know, everybody we're gonna be an orchestrator.
Yeah, exactly. So, um, definitely I, I've seen this evolve and mature, uh, a lot. And, uh, I am involved in like, uh, you know, like Kubernetes projects and cloud native projects essentially on a daily basis.
Uh, I would say, um, first of all, I always believed, and I still believe that, uh, cloud native, and in particular the Kubernetes stack to me is the operating system, uh, of the cloud. And more and more, you know, similarly to the way Linux is an operating system that runs on a single machine and orchestrates processes and applications on a single host, Kubernetes, you know, uh, sits on a cluster and orchestrates, uh, applications that run on this cluster, and in particularly the di the different services that, uh, compose, uh, an application. Um, so I think that for anything of a certain scale and of a certain, uh, complexity in the cloud, there's no escape to the fact that, uh, in the long term they will be run by Kubernetes.
It's just the right, you know, stack for, for this kinda stuff. At the same time, uh, this stack is, uh, um, relatively complex and in my opinion shines, uh, particularly when you run applications of a certain scale, uh, in, in production. So, for example, one thing that, uh, surprised me when I started being part of this ecosystem is that, uh, I was expecting, uh, originally the adoption to be a little bit like the adoption of the cloud, you know, where small startups may be, and, and smaller entities took advantage of the cloud first, and, and the enterprise came only few years later, right?
Uh, AWS started in 2006, 2007, and you know, it, after like five or six years, we started seeing actually, you know, real enterprises and, and, and corporations u using it while with, uh, with containers. I think it's been the opposite. You know, uh, I've, I've seen adoption that, or at least I'm witnessing even today.
Adoption typically comes from bigger companies, uh, especially you united spaces like, uh, uh, finance, like media, like internet companies and so on. You know, companies that need, let's say the scale, the automation, the functionality that comes from, uh, from, you know, being, uh, container native. So, uh, I think that he, despite, you know, this really being the stack for the cloud, it's especially useful and especially adopted by companies that actually have required the scale, uh, to actually make this useful.
Well, and they could, that could handle the complexities of it. Because look, I remember the first darker con I went to, we were thinking about launching what became cloud native now, and I was gonna use Docker in the word because I thought Docker would be the be all, end all for cloud native, but we couldn't because we would've got sued, right? Docker, I'm glad we did it in retrospect, right?
We, it was bad enough. But, uh, but I came back and I told the team here, I said, you know, there's this other stuff. 8.
8 or so. I wasn't, you know, the one oh, release. I said, everyone's talking about that, but I don't see how it's ever gonna succeed.
It's so hard. I, I don't know how people would do it. Well, that's why I'm still doing this.
But, you know, it, it is hard. But here's, here's the, you know, one of the things I've learned as I've grown is it's about using the right tool for the job, right? You use the wrong tool and the job gets a lot harder.
If you have a greenfield situation, there is no doubt that doing it on a cloud native stack, on a cloud native infrastructure is the way to go, right? You, 'cause you've got a nice clean sheet of paper. You can, you can do it really well.
You can do your microservices and your, you know, the whole, the whole thing. And you can design it securely from the outset too. You can assist, dig and other tools.
If you have a brownfield situation, let's say you have, uh, an application that you want to transform, migrate, it's still not easy. It's still way too hard, right? Taking a, a monolithic application and trying to convert it to microservices and, you know, yeah, you could just take a whole monolithic application, rapid container around it, put it up there, and have, you know, Kubernetes manage that container and tell yourself you're cloud native.