Shifting Application Security Left and Right – Sandeep Johri, Checkmarx
Newly appointed Checkmarx CEO Sandeep Johri explains why application security needs to ultimately shift left and right as organizations focus more on securing software.
Transcript
This is Textron TV. Hey guys. Thanks the throw we're here with Sandy jewelry who's newly appointed CEO for check marks and we're talking about application security and how the world may be finally changing for the better Sandy.
Welcome the show. Thank you, Mike. I think if I look back in time application security never really got the respected deserves because I think the security guys thought the development team was handling and then development team thought the security team was handling it.
Nobody actually handled anything. So is that changing finally or were you reaching some sort of level of maturity around application security that we haven't seen in a while. I think so.
I mean it's the story is not very dissimilar for from testing. Right which is where devops comes in play and security is the same thing where there's a lot of pointing fingers and and people that you know developers don't always like to deal with security but security is an important thing and AppSec are becoming fundamentally, you know to running everything in your business and and application security. I think the whole idea around devsecopsis the same concept of devops Canada by and including security into it.
So yeah, I see it changing. I see a huge opportunity in application security and as the vulnerabilities are getting, you know as the deployed as the applications are getting more complex. The deployment is getting more complex with the cloud and the criticality of applications and a number of applications that enterprises have all of those expanding.
Those are kind of getting more complex and and that creates a need for for a lot more application security and I think it's not it's one of those things which you can take care of your applications just from network security, you know, you have to build it in as they say to build it build the security into your AppSec and that's why I'm super excited about the opportunity. So what exactly brought you to check marks? Because you've been at HP in a few startups before you've been around the block a few times.
So what is it about this particular opportunity that caught your eye? Well one is that I am a huge believer in application security my previous company. I was at HP a few years ago for the last eight years.
I was at at tricentes which I Grew From, you know, five five million and ARR and today they're doing about I don't know month many orders of magnitude more than that. They're one of the largest vendors in in functional testing and I see check marks as a similar opportunity it the space has a huge time for all the reasons. I talked about earlier is still growing security is only becoming more important every day and check marks is known as a Innovative leader and has been recognized by Gartner five years in a row as the top right corner of the doctor and Q.
So it's a great company with a great history great lineage from Israel, which produces some of the best security companies so just everything. About the company got me really fired up. So.
We hear a lot about shifting left of but who's in charge of application security these days it seems to span the gamut but is Shifting left enough or do we need it to be more like a team sport? It is really a team sport, you know every everything. At Enterprise, you know.
It's not very distantly the devops, you know, where you really to to deliver agility. You need to have Deb and Ops working together with testing. Integrated into into a ship left type Paradigm and security the same thing you have CISO that are ultimately responsible for the security but that is after the fact and you know security like I mentioned earlier has to be built into the app and the only ones who can fix issues are the developers.
So ship left makes sense, but it's not just developers. You need to think about shift right as well. So check marks is talking about shift everywhere because it's not just you ship left and throw the responsibility at the developers and everything will be okay.
You have supply chain. You have the cloud environments. You have the whole the whole life cycle of the app.
There has to be security throughout that whole process you have apis which are third party API sometimes so it really is multi-paceted. And and that's why we we use the term shift everywhere, which is it, which almost means that security needs to be thought about and factored into every stage of the lifecycle of the software development life cycle. If you would say that way so as part of that we've seen a lot of interest over the years in SecOps, but do you think that that is accelerating because we are seeing more regulations.
There are more edicts from the Biden Administration and do you think Enterprises are kind of gonna follow suit Yeah, absolutely. I mean Enterprises that the cost of the economic impact Of having an app out there because every Enterprise is exposing itself to the to engaging with its customers and therefore exposing itself in all its interactions through online online AppSec if you may and therefore the you know, the the need for making sure that they're that they're secure is only increasing. The number of attacks is not going down.
The number of failure points is not going down which is why you know people talk about the threat surface, right the they what is your threat posture. It's not just in debt. It's not just in the deployment.
It's really all around. So yes, I see. I don't see any letter in the need for more security.
I don't see any let up in the need for applications and there's no Silver Bullet here. You have to secure the app at every stage of its life. And and regulations only further.
Accelerate the need but regulations are not the only driver being compliant is important and regulations force you to be compliant and you do meet those needs but there's an economic need for most businesses and most Enterprises to to be secure because the losses are Monument. Do we need to make this simpler? Because you mentioned developers earlier.
But in my experience most developers don't have a lot of security expertise. It was probably an elective somewhere that they skipped. And so the question then becomes how do we secure these environments in a way that doesn't require as much effort or expertise on the part of the developer?
Yeah, that's a very good point developers. Love to write code. They have creative Geniuses at the end of the day and they love writing code.
Testing that code testing for security is not the most thrilling thing for a developer having said that they need to worry about it because they're the only ones who can go fix those things. So the whole thing around ship left is about enabling developers to to be able to catch errors early in the dev cycle. So you're not doing it retroactively.
However, like you said they they are not experts in security. And therefore there's a lot of there's two aspects to that. We see one is you really need Solutions either.
There are a lot of points solutions that don't that don't integrate with each other and sometimes you cannot viewing the issue just from one perspective. So there's a couple of Trends one is around having a a more comprehensive platform so that It one end of the development cycle of one end of the app. Cycle is not doing something that is then leaving others and other ends to vulnerable.
Do you really need to be able to look at it for holistically, which is where check marks the new platform. The cx1 platform is an end to end application security platform. So the comprehensiveness addresses some of those concerns that you raise the other concern you raises the expertise, right?
What do they do the developers know how to deal with all the security issues and there again, we believe check marks as one of the most the most respected and advanced research organization. So we we bring out we research vulnerabilities. We bring out fixes on how to address them.
We build it in context in our application. So when we tell you what the issue is, we can also give you Solutions. We have also got another training almost like a training capability.
code bashing Which allows developers when they run into an issue we highlight the issue, but right in context it tells you how to address it. So. The the modern tools can't just raise issues and throw a bunch of bugs or you know tickets at the developers.
You really need to be able to enable them to go fix those because like you said, they're not experts in security. Sometimes it's the first time they realizing that there's a that this this kind of really so we try to one make it comprehensive and two enable them so that they have the right context to address the fix if you how automated can all this get of course, you can't walk down the street these days without somebody talking about AI but can we automate much more of this it feels like what we do today is very manually dependent. You know Ai and machine learning has a role in every aspect of technology and I'll give you an example.
For example, we have a correlation engine called Fusion. That takes our what we what we discover as issues from multiple aspects from from a static analysis from open source components from apis. We take all of those alerts if you may correlate them and and that's how we can make sense out of not just throwing 10,000.
That's an empty. In areas like that. There's a lot of room for improving the insights or really identifying minimizing false positives.
Right because false positives are wasted effort. So our Fusion correlation engine helps reduce that I think there's a lot of opportunity to use machine learning to use what we have what we have learned from other application developers bringing that knowledge back into another customer to say gives out the other one fixed it so there's a lot of opportunities to use AI but like anything else, you know chat gbt doesn't eliminate the need for reporters to put you know, it can and it can enhance their insights. It can enable them to become more efficient more broader in their research, but it doesn't eliminate that that you know that element of it and it's it I viewed it as similar machine learning AI all of these are capabilities that can further improve products, but it doesn't I think the days of saying well everything is just automatically going to be fixed.
That doesn't happen. It needs human intervention. The question is can you make that human intervention efficient, very, you know precise enable them with knowledge bases and things like that.
So there's a there's a lot of opportunity for AI in which machine learning that takes the collective knowledge and and makes individual small productive. So, where do you think you in the company are going to be a year from now? What are your goals and Visions?
What have you kind of outlined? I know it's still early, but Loosely speaking. You know, what are you hoping to accomplish?
Well, you know, I'm new to the company. It's week one. I'm an Israel right now Intel in the beautiful city of Tel Aviv meeting people and learning so I can't tell you all I can give you all the answers but a few things are very clear, you know checkpoint.
Has been in business for a while and was known to have the best static analysis. Solution on the market by by far more recently. We released CX one, which is a more comprehensive solution.
And in just one year we have had more than 250 Enterprises adopt that. For the reasons. I stated earlier its comprehensive.
It's end to end all of those benefits. So I see that cx1 footprint expanding very very rapidly. We are already recognized as the leader in application security.
I think application security is getting wider and what you were talking about where you need to ship left and shipped right and really take care of the whole life cycle. So, you know, we're gonna continue to focus on application security just make a solution more comprehensive and continue to maintain that leadership position that we have. I want us to not be just one of many leaders.
I want us to be Clearly the best solution on the market and that's where I see us going in the next few years. And hey, Cindy, thanks for being on the show and best of luck. All right.
Thank you, Mike. And back to you guys in the studio.