Snyk and ServiceNow Integration – Manoj Nair, Snyk
Manoj Nair, Snyk Chief Product Officer, discusses ServiceNow‘s strategic investment in Snyk and their integration with the ServiceNow Vulnerability Response solution. Currently available to joint customers, this new offering unites Snyk Open Source, advanced software and composition analysis with the ServiceNow Platform.
Transcript
This is Textron TV. But the great pleasure of being joined Again by manotionair manosius Chief product officer was sneak welcome. Hey mates, good to talk to you again.
I'm just yeah Vegas right now. We're back to the virtual conversations. Right?
Exactly. Yeah, really enjoy talking with you there. By the way that interview that conversation is on Tech strung TV.
I'll put a link to it in the description when we are this one. Well folks it may not know you would you introduce yourself just about your role and a little bit about sneak. I know we're gonna jump into that further.
Yeah. No, so I've I'm Chief product officer. You're at sneak.
We're a company focused on out for security really, you know companies Origins are really focused on Flipping that equation. You know, Finding issues is really what a lot of the security minded tools we're doing I spent a lot of time in the security space, you know and gone through, you know, the the pluses and the minuses of all those approach and it's kind of one of the things about sneak. Are empowering developers to fix issues before they actually end up, you know becoming an issue and that's one of the big missions that were very focused on here.
In in the era of devops and SecOps, right? So let's have the developers do security. Well.
There's a big part. Of course, they play in all of that. Love to have you talked about that we've chatted before about.
When at least for me, the differentiators around sneak is developers know. It's a product. It's a tool set of technologies that were created for developers that can tell that it's not another security product for men for security people.
They want developers to use and I think that's that's extremely important because developers know when it's not something that's gonna it's gonna impede or help. What they what they're doing and that makes a big difference when you're developer. Yeah, you know as a former operation probably have a shirt that said I used to code, you know, I don't anymore, you know, I think the rest of the team thanks me for that.
But yeah, I I remember not liking the static analysis tools and others. They're just noisy. They're you know, we're looking took too long and there weren't really providing accuracy.
One of the fundamental things we have really focused on from the origin is developer's don't should not have to change how they work. You know, they have enough complexity in the deficit cops as DLC tool chain, and they have you know, the tools that they live in so how do you provide value in that context and part of it is a culture change too. It's you know, it's almost like product management you provide the developers the why and they'll go build the right stuff and here we're providing the why and the context of what you know, what is the security issue?
Right where they live in the IDE when they do the pr checks, you know providing education awareness and then automation so productive it is the other thing devs care about so one is empowering them and then making the life easy. So here's an automatic ability to fix it and you know the fixed PRS integrated into their workflow the tests are built into their build system. You don't have to change your build system.
So these are you know, some of the very important original Innovations and and you know, we have this developer lab and that continues to be something that we very very importantly focused on but then provide the best security intelligence and so you know that combination is really kind of created this, you know, we believe we're empowering to have sex off right the devops change has happened over the last four or five six years, but deaf psychops adoption is still early stages and and that bridge is really what we're empowering and you talk a little bit about so the IDE integration and other things that I've actually scanning can happen either local or when you check in code. And I see ICD processor into a repository. What are the other things that you know sneak is doing sort of at that developer experience that's part of their workflow.
Yeah today the dog board workflow, you know, if you think about the the original stack and you kind of packaged applications and after that, you know an IT team and a security team took over so longer the case, right? So when you look at it, you know, we have modern software's composed. It's not coded.
There's a lot of open source and all those dependencies and understanding what vulnerabilities they could bring and putting it in a risk context. So, you know, it's at the time of packaging and using those the right open source libraries and continuously making sure that there are new issues found there the first party code and you know, we created a hundred X speed differentiation in how do you do first party code analysis that makes it possible to do real time recognition in the IDE, but then it Stop there. They're responsible for the packaging in containers and microservices and you know, their potential vulnerabilities that can come there just in terms of choosing the right base image or should this container join that cluster and you know admission control.
So there's everything about you know, the containerized environment kubernetes is you know, how a lot of modern microservices applications developed. So we have you know solution around that and then you think about the final deployment and also the deaf Persona now through these processes change you got the developer building the code the platform engineer who might be responsible for packaging and the creating the terraform templates and you know, just within there. You know, how can we give the same context on the IAC templates says they've been created and we we further extended it to the cloud.
So now in the platform Engineers, let's say making a change in an S3 bucket policy may maybe that is okay because there's some other mitigating control in the cloud dep. Meant they don't have false positives and not only do we give them context on their policies and their deployment templates. We're telling them.
Hey years of cloud deployment and continuously assessing that or there things like click Ops where you might have a deployment template, but somebody goes to the cloud console changes that what we call it is a connected code to cloud and back to code. So this context we're able to take all the way through in where all these different types of living and in a connected way. It will allowing them to bring risk down before it actually manifests in a production environment.
So really good point I'm glad you brought platform engineering into it obviously relatively new or an evolved role. Increasing role in this but from the developer standpoint part of this complexity is I might be in deploying code in my code into different environments because there could be multi-cloud but also could be different configurations. Right?
I'm running this cluster, you know kubernetes configuration for this Market these customers whatever it is, but that same code microservice whatever might be running in something different and that's a lot of cognitive load for anyone developer anyone else to kind of keep know that we're doing that but also keep Pace with the change because they don't all of the same parity and and configuration changes and all of that. Yeah in the modern application is very complex, you know, it's got hundreds of thousands of data points and a single app and how it's composed in the end. So just getting that context in the end if I'm writing code here, maybe do your point.
It is manifesting itself and maybe a few different app context and the risk might be different in different ones right the other issue. Prioritization, you know the doubt having that context. All you could have is tools that create a lot of noise along the way this kind of become a big, you know deal in the community like one of the reasons why things don't get fixed is just so noisy and people get overwhelmed.
So connecting it really helps you to also kind of really focus on prioritization which probably brings, you know, kind of in some of the news that we are going to talk about here too. Well, let's let's shift to that because you do have some some great news that you announced recently about your collaboration with service now tell us about that. Yeah service.
Now, you know we're very pleased that service now joint snake as a strategic partner and an investor. So we just announced yesterday the 25 million dollar investment and that extended our series G which was about 200 million coming into the company. So, you know that it's you know, it's a good customer value thing to but it also shows they see this Beyond just a partnership.
They see this as a Strategic investment and partner that benefits our joint customers and you think about the customer benefit here service now obviously well known for being a category Creator and leader in IT service management and we talked a lot about deaf security and how the world is changing to microservices Applications with digital transformation. Every company is becoming you know technology company in that sense when you look at their workflows a lot of the Workflows in the Enterprises and all live in this it service management tools. We talked about the prioritization problem.
So great. We have devs fixing things. But how does the it and security organization get visibility to it?
How did they, you know with an asset management system like service now where they might have the business value of an application that's a nice context to be able to use to do prioritization of risk. So that's really in a service now vulnerability management and our open source product sneak open source is the first integration here we're announced and that's really about that, you know increased value Bridging the dev world and the deaf Tech Ops World with the it and security world and different people able to continue to live in their context the devs able to live in their context the it teams you're able to use their workflow but feeding their information. Context across that bridge and that kind of application risk view of workflows for it.
These are some of the benefits and it's really about Bridging the SecOps world and you know pulling existing organizations forward with the abilities that the joint solution can offer. Interested to is this related to any of the Acquisitions that serve as nothing that that your relationships not an acquisition. It's an investment, but you know, they acquired light staff.
They acquired what era software kind of people in observability instant management space, you know some real some real fantastic Talent from from that world. Are you gonna be working with any of those companies are required companies or you're kind of working with core light step product. Where do you fit into there ecosystem?
Yeah, you know where we fit in this what service now called the service now vulnerability management capabilities, and that's now some of again the power of you know, we're a platform company, they're connecting observability and some of these, you know signals into their platform capabilities. So, you know, there's obviously, you know connections and better context that over time can improve Integration, for example an observerability signal, you know could tell you what's in runtime, right? And that's these are all the possibilities but you know right now yeah, the focus is where we're starting is you think about supply chain security.
How do you manage that? You know, if you have I think last time we talked much about as bombs and what do you do with that? Where are these assets?
Well these assets typically in most Enterprises are kept in an its management system service now is the leader there and they have the workflows around it. So, you know, there's a lot of other things that you know together we can actually help our joint customers with fantastic. Well, we look forward to being seeing what great things happen with that and You know sort of joint ventures and Investments and companies partnering it always seems to me comes down to where you have mutual shared interest, right you have customers with your both contributing to solving the problem for them as opposed to kind of lose couple relationships sort of evolved but move move a part over time, but within an investment in you, that's a strong signal.
This is more than just let's say a partner agreement, right? Yes. Absolutely.
It's you know, we're pleased to have service no join, you know a whole bunch of our investors that have committed to you know, sneak and just making us, you know, a generational company here helping, you know for the the entire customer context and applications get more and more secure and you know, most of the world today is, you know developers or coding and creating new new digital content. IP and that's kind of the shared Mission we have But an end just stepping back for a moment in this context of this time, but he said 200 million in your in your year round Rays. Is that correct in total?
5 was that round and then with this additional 25 on top of it is, you know, extending that series G. It's it's that's an accomplishment in and of itself, you know, a lot of folks have had to retrench their strategies on funding. Given times but you know when you when you've got momentum you got the product.
You've got the market. That's a great sign. You can continue that, you know to have folks invest in you.
Yeah, I know it's you know was something that in for us, it's really about continuing to expand the Strategic value. Our customers can get and you know, it's it's a really strong endorsement and what sneaks done so far. But also where we're going with the vision and our capabilities.
I'm gonna touch on you you mentioned in your in your description talk about developer productivity. That's the reason very high on the prominence of conversations. People are happy and having just you know, as we think about iosa tech companies and we where do we spend our money and of course developers are are an extremely valuable Resource as our you know, other folks that are part of integrating software and securing it.
But there is that emphasis of let's make sure we're both enabling developers with tools and technologies that help them and don't get in the way and also know that that they're doing the best work that they can do at least we're empowering and to do that. Yeah, I think that if you think about you know, like some of the productivity improvements and there's you know, good metrics in the devops community, you know, Dora metrics a lot of devops teams love to use that and you know the light nice competition between teams and like every Dora Elite and I see that, you know, even internally and and you think about those metrics they're really focused on speed and and you know comes back to how productive or your teams now think about what for, you know, I'm a former love on fan. So I like to think about you know, if I put you know speed bombs on the track for the developers, so trying to go fast and reproductive and to be more Innovative, then that's not really going to allow them to pick up their speed and that's partly What's Happening Here with you know, some of the older approaches where you know, I think about this like this is these are like checkpoints like after the fact you're scanning you're finding a bunch of issues.
There are always Moved on their context is no longer there. In fact, you know, one of one of the interesting things we've seen is, you know after six months, even if you wrote the code, it's like you found it. Somebody else's code where we're giving you the context right there and that itself is a huge productivity boost and developers, you know would rather not get interrupted while they're off to something else to come back to something that they may or may not remember anymore and it's all those little Innovations we talked about and and and and you know, you think about like these origin fire girls.
You have the next log for Shell to people who have to cancel vacations and get on Long teams calls most sneak customers like 95% loss of snake customers resolved that all of the issues and knew they were in a good place in less than 48 hours and you know for everyone else it's like 30 days and lots of you know painful. Activities that's productivity. That's the organ like the entire org has to go into these fire drills.
And you know, that's these are all examples where we are optimizing Dev productivity and the overall organizational productivity. It's I like the analogy the racing analogy kind of Formula One of where we've been and where we are you think about all the Telemetry data and all the information developer doesn't need all of that, right? They need what they need in the moment to you know, get the best performance out of the car understand conditions of the car and the track and how everything's are performing and what adjustments they need to make and can make but they they don't want to see everything they just not what they need to do the best job in the moment and where they're headed, you know where they're headed down the track now where they are at that second and they're empowered to make the decision then they're party, you know, we're giving them the ability to have speed and stay productive.
Wonderful big great talking with you. Congratulations on the investment and then the partnership. Look forward to seeing the outcomes of that and definitely come back and let's get together at the next kubecon or Vegas or whatever it is.
I'm sure we'll be in the same city soon because there's lots of stuff happened and look forward to Let's thank you and thank you to your listeners for the time. Absolutely. It's been fantastic having you manushnair who is Chief product officer with sneak and I'll put the link into our other interview.
Definitely check that out, and I'm sure we'll be talking again soon. Take care.