Prioritizing Application Security – Matias Madou, Secure Code Warrior
Organizations don’t need to be reminded to ‘start’ building a more positive culture and better lines of communication between their security and developer teams. That work needs to be done now, or better yet, yesterday, according to Secure Code Warrior CTO and Co-Founder, Matias Madou. When 86% of developers his company surveyed said that they do not view application security as a top priority when writing code, it not only demonstrated that a positive culture is lacking, but also that the level of communication and collaboration between developer and security teams have significant room for improvement. Madou believes cultivating the right culture continues to experience major roadblocks
Transcript
This is Textron TV. Hey everyone. Thanks for joining us here on another tech strung TV segment.
I'm really happy to have my friend Mateus Medusa CTO co-founder of secure code Warrior here on Tech strong with us. You know, usually I see Mateus whether it's at RSA or Maybe a cubecon or some conference in person. We don't get a chance to get them on here on text on TV often enough Mateus.
It's good to see you. I hope all is well. All is well.
And thanks so much for having me Allen. It's a pleasure. You know me Taylor said you and I know each other.
I know the secure code Warriors story, but there are people out here who don't I'm sure you know before we jump into what we want to talk about today. Would you mind giving them maybe a quick background on secure code Warrior? Oh, absolutely.
So what we're trying to achieve is secure code Warrior is we want to be there for the developer when he or she writes code we want to be there so that he or she can actually write secure code and the way we do that is by making sure that the developers get actionable results in the language and the framework of what they're using on the day-to-day basis. So if they're using Java e we make sure they can code securely in Java and we do that through training and through various other Solutions. Excellent and you know look death sentences someone invoked today and the idea of creating security tools that are Developer friendly and security and developer teams working together, but really secure code Warrior was out here doing this.
Item before it was cool. Certainly Mateus. How long how long have you been at secured code Warrior?
Seven years and you're exactly right back in the day seven years ago. There was video training and kind of boring stuff where you didn't learn much and the way we try to differentiate is really be language and framework specific. That's that's key in here and it's Hands-On training.
So it's not clicking through a slide show or a video, but it's really looking at code looking at code that you're hopefully familiar with and hopefully we're able to guide you inviting more secure code in the language and framework of your choice. Absolutely, and I remember those days. I remember interviewing you backed out about it.
So thing about seven years ago and eight years ago Mateus was that it wasn't just a question of what the the technology or the tools were there was a fundamentally a question of Whose security whose job? Is it Anyway? Right?
How much security did the developer really have to worry about or what should be their responsibility was developing secure code is important is just developing quantities of code, right or in other features and you know in that regard And you want to call that cultural maybe in that regard? We really say we really seen things change over the last seven years, correct? And I so I'll be honest maybe it was maybe part of the problem seven years ago because seven years ago.
I worked a lot on on static analysis Solutions and the people that were operating static analysis solutions back in the day seven ten years ago. They were really good at finding problems. They ran those scans and they threw them over the wall to developers and they ran us fast as they could because they knew there was plenty of problems and it was going to be hard to resolve them.
But I think we've came we yeah, we came a long way since since that day. Absolutely, but you know, you've heard this up I was involved in a conversation with Andy Ellis. You see Chief security officer Arkham.
I for so long and you know, Today when you're developer, you're not only worried about the static analysis, but you have Dynamic analysis and IAS and software composition analysis. And and it seems like every vendor is coming out with their own new analysis and all of this is being pitched back now to developers saying hey, you gotta you got to fix this so, you know, there's not secure and it be it's You know, they barely gotten their head around. Doing security and we seem to be overwhelming them with all of these alphabets soup kind of analysis code and scanning and so forth.
What do you think about that? Well, I have a little secret here. Well, we still need the people so we cannot throw as many tools as possible to the problem and hope it's gonna resolve itself because oh my God, it's still people that need to operate these tools, but more importantly it's people that need to look at those results and actually fix the code.
That is the most important problem. It does not matter how many acronyms we throw at the problem if we find a thousand problems and we're fixing zero. We you know, we didn't do anything essentially.
So it's it's all up to, you know, we need to developers. Let's let's be real here security can point out the problem these days. I see more and more apps that people that know how to code which is a really good start because now they can actually help the developer but it's still the developer that owns the code that can make changes to the code.
So we really really Need to get the developers on board with security and back to what I you know, initially said we cannot do that the way we did that 10 years ago. We cannot throw the problem over the wall and you know, and then run as fast as we can as security people we need to do it differently and the way I think we can do this differently is a couple things abstick. First of all, they do need to understand coding if if they do not understand coding.
It's gonna be really really hard. They need to bring the developers on the journey. And and by the way, it's not only security that needs to change the developers need to understand that the world has changed as well, you know management teams.
The organization itself requires developers to write security code. We're in this new world where you know, sub-par code is no longer acceptable in cars and all the things that we use on a day-to-day basis. So we really need to bring the developers on board and make sure that they are able to write secure codes and you know, we need to do that in the scalable way because right now there's roughly two applications security people per 100 developers that does not scale.
So we really need to empower the developers. We need to make sure they have the knowledge the skill to write secure code from the start or also, you know, if problems are thrown over the wall to the developers that they understand why this is a problem and they're able to fix that particular problem. agreed, you know that that's that statistic of two security folks abstract whatever folks per 100 Developers I mean it really is it hits?
All right. I mean it gives you an idea of the scale of the issue and and why unless we're gonna make these developers security champions. Correct it when we're just never gonna we're never gonna get anywhere right?
We're never going to fix this problem. And that of course. You know again as you mentioned it gets us a way necessarily from that tools discussion.
What tools do you want to use and stuff like that and you realize it but you really becomes a cultural? discussion right and and that's something I know secure code Warrior, you know spends a lot of their training and time and educating You know the the base with that talk to us. How do you how do you affect that culture Matthias?
Yeah, so actually there are a lot of different ways to influence that culture. First of all, every organization is different. They're all they're not all special snowflakes.
There's there's groups of organizations where sometimes it is a board member that asks like hey, what do you do for security for all your developers? So sometimes it is really top down. Sometimes it's bottom up.
Sometimes it's it's developers that want to write do the right thing and they see security as a subset of quality, which I think is correct, you know, if you write qualitative code, it should also be secure. I think both need to be in land in line with each other. It's a it's not a top-down approach.
It's not a bottom-up approach. It's a holistic approach where the management the executives the Board needs to be on board. But also where the developers hold the responsibility of hay we really want to do the right thing and not say you know, what today time is up.
I need to ship code. I know it has a problem but I'm still gonna do it. We still see today that that you know over 60% of of the developers that we asked they say, well, you know what sometimes I still ship code which has a problem which has a security problem.
So to me, how do we influence that first of all the developer we make them where is that? Well as security knowledgeable developer is to me a really good developer and there's a good reason why I think if you start coding you make syntactical mistakes, once you're over that oh Java lines end with Me call them. Once you are over that particular hurdler, you know how code interacts with each other there are functions and files then you go to architecture and at the end of The Journey you start to realize oh my God, there's like hidden functionality in my code, which has security implications.
So to me, it's important that a developer understands that a security Savvy developer is equal to me as a good developer. So if they want to be seen as a top much developer well for sure they need to know about security. So in education part on the developer side at the same time, there's an education part on managers on Executives if they are not given time if the deadline is always yesterday.
It's not gonna happen. They will not be able to write secure code. They will not be able to upskill themself so you can work both ways sprinkle on top of that a couple of prizes a little bit of gamification to make it interesting for both parties, and I think that's a really good mix to move forward and get the entire organization on the journey.
A great a great let's talk about you know where we're coming in this September. It's almost the end of September. You may test it.
Look I'm not gonna sit here and sugarcoat things and say everything's wonderful, but we've made a lot of progress. I I think in some ways working remotely as has made people maybe it's between that and all the security incidents we've had but it's made people more security conscious, right, correct? And not just the security people.
They will always security conscious but the developers the QA folks. They yes, I read everyone, you know up and down the stack. Well, what do you see a secure code Warriors kind of mission now?
You know to in that capitalize but to there's a good time to bring the you know spread the word. So first of all, I agree 100% I think we've made a couple good steps forward. Unfortunately or fortunately, I'm not sure what to say here the market also requires this huge step forward because more and more solutions came online and because of the homework because of people were the whole look down issue people had to work from home.
They they were required to rely more on tools and new Solutions came out. So also the softer has made drastic steps forward in everything that we do on a day to day basis. So it's you know, we made progress but also there's more code that needs to be secured.
So I'm not sure how much progress we've made in the end. To answer your question our mission or vision is we really want to be there for the developer. You know, we estimate that there's roughly 20 million developers on planet Earth where a long way from from that particular number we have over a good 300,000 of developers on our platform, but not the 20 million that people predict.
So what we really want to do is is go after really huge organizations because we offer our solution in a lot of different languages and Frameworks. So with scales very well. So we really want to go after organizations huge organizations so we can help them so we can actually make a dent in this market and we can also push this forward in radical steps.
So we prefer not to go after the 10 or 20 developers. We prefer to go after the 10,000 a hundred thousand developers because then we can help, you know, at scale. We can help these organizations at scale rolling a solution out at scale and help 10,000 100,000 developers at once instead of trying to do like in person training 10 people at the time.
Absolutely. Well, that's the real beauty of online right? Because think about it.
You can't You're Gonna Fill A Stadium up with people, you know to to do this. It's not that doesn't work. No, it's if it's gonna be scalable.
It has to be online for people want to get more information. Where can they go? com.
They can always reach out to me or Peter violington. We have a Twitter handle as well. Sick code Warrior.
That's I think the easiest way to get in touch with us. Absolutely. Also look people are starting to go back to in-person events again and meaning are you guys gonna be anywhere coming up?
Maybe keep quiet kubecon or something like that. And we have people attending pretty much all these events. We're lucky that we're we're growing fairly rapidly, which means we have more and more people all around the world.
So we're able to to go to a lot of events these days. I'll be honest. Our focus is still the RSA conference and and the black hat guy friends, of course, but yes, so you can actually find us at these various conferences.
There's always somebody from security code look for the shirt look for it. Look for the shirt and always be sure. He's actually logo RSA.
I think call for speakers is next week. I I saw some communication of floating by that. Yeah.
Yeah, I we of course. We're always there doing our devsecops event. So hopefully we'll be there this year as well.
Anyway, thanks. It's great seeing you. All right.
Thank you so much for having stranger because RSA is not so like what is it next April? I think it's fast it always comes up really fast. Well, yeah, it's probably it's been moving on us, but come back on here and talk to us more.
Yeah, absolutely. Appreciate it. Appreciate the invite.
I'll definitely do. Alrighty Mateus with you co-founder CTO secure code Warrior here on texture on TV. We're going to take a break.
We'll be right back.