Stairwell CEO Emmy Linder on the Need for Continuous Malware Analysis
Newly appointed Stairwell CEO Emmy Linder dives into how continuous malware analysis is now a requirement in an era where cybersecurity threats are increasing in both volume and sophistication.
Transcript
Hey guys, thanks for the draw. We're here with Emmy Linder, who's the newly appointed CEO for stairwell, and they specialize in analyzing data for cybersecurity purposes, hopefully using something that feels familiar to folks like a search tool. But, uh, there are new challenges and new issues, and we're maybe on the cusp of the age of ai, so who knows what's gonna happen next.
But Emmy, welcome to the show. Thank you. Happy to be here.
Right. So you are taking on this role, the current CEO and founder is moving over to be, uh, the CTO, I believe his name is Mike Wyche. But what attracted you to Stairwell and and what are you gonna try to achieve?
Yeah, so Stairwell, um, you know, when I first, uh, started talking with Mike a few months ago, um, the things that I really found compelling about Stairwell is that there's a lot of really strong components within the company. First and foremost, Mike himself is an amazing founder, huge, uh, incredible cybersecurity background. And I say Google, uh, Chronicle, but that was one of it.
The others that I really was excited for him to stay on and wanted to be, remain very relevant and very involved in how the company continues on its technical vision. Um, top tier investors, solid runway, obviously security is always a good space to be in. And with ai it's even worse depending on your perspective, right?
But from the CSO perspective, defending and protecting companies has become that much harder. So they need more innovation and more technology. And, um, and I think where the company is and where what I can bring to the table is a really good fit in terms of Mike staying on with technical vision, and I'm coming in with operational excellence strategy and the ability to kind of match the product and the company to what the market needs and the pain that we're trying to solve to.
For CISOs, A lot of people have long said that security is really a data management problem in that sense that we're looking for anomalies, AKA needles and haystacks and, but we don't really have the tools to go after it. And, um, is that changing and, and where does stairwell fit in that conversation? So what Stairwell does, which no one really does, is it retains, um, files, executable files forever.
And, um, it's not, that is normally no one can actually do it. Sims or EDRs or other security tools kind of have moment in time windows, and then they kind of vanish and they move on further into the future. What Stairwell does is once you've, once you have it, it will forever look back and will continue to collect forward so that you can actually search and see whether you have, um, anything bad or were ever impacted by something bad.
Moreover, it can, it can find variances variance, which is really, um, that is something that is very unique because you can have a known bad or a known hash or a known, you know, some sort of indicator signature, et cetera. But to be able to say, okay, based on these parameters, this is going to be, you know, the difference between, uh, what is coming and going. Um, that variant analysis is something that no one does.
So those two things combined are actually one of stairwells, um, key differentiators, data forever and ability to, to look and understand variants across the board. And that's critical because in my mind we always have these moments where somebody says, you, we've discovered a breach. And then the next question is, well, how long has this been going on for?
Are you attacked? Are you, do you have it on your environment? Exactly.
And if you, even if you, if you had it, great. So that's an answer. And you, you kind of know, but you really wanna be sure.
And many times, if you, if you go to your environment, if you go to your sins, if you go and search your a DR tools, you might get it not right now. And the not right now is not helpful because depending on what it is that you're protecting and defending, sometimes you need a definitive answer and then you need to go back and fix it. And many tools don't have that ability because they don't look so far in the past.
And variants and, and executables, they know how to linger, right? They know how to kind of simmer and pop up when needed. And so no one does that.
And it's, uh, it's, it's a really key differentiator. And has the tenure of the conversation changed among the regulators? 'cause it seems to me increasingly they want a definitive answer.
So it depends. I think it depends on the, on the industry, it depends on the appetite, both budget and, uh, and security know-how and sophistication. But for the most part, um, those that have, uh, critical infrastructure, critical data that they need to protect, always wanna know the answer.
Regulators come in and it depends on their answer. It's not necessarily the case, but if you really wanna know a hundred percent, there's no other way. Mm-hmm.
So as you look into the future, you know, what's on the agenda for you guys? Where do you go from here? What's top of mind?
So what we're, what we are focused on right now is making sure that we clarify what it is that stairwell does and what problem it solves for CISOs, especially in the AI world where attacks are, you know, we used to say attacks had, you know, they had to be low and slow taking months and weeks in order to be able to not spark any kind of alarm or alert for, for socks to find in the world of ai, you're in the fast and furious. They're very good, they're very frequent, they're very believable, and companies and enterprises are constantly under attack in that world, you need more defense, not less. And you need to be, um, you need to as usual, right?
There's always a resource problem with security. You wanna be able to get to the answer fast. You wanna know if you have to do anything, yes or no.
And if so, what is the best course of action? And that's what we wanna make sure that companies are aware of and what stairwell brings to the table because no one does what we do. Mm-hmm.
Um, you mentioned ai and it occurs to me, I mean, how could I not, how could I not? There you go. But we got all the way into about 10 minutes or so without mentioning it, we go, um, but there will be AI agents going forward and I think it'll work out this way.
Won't I, as an security analyst ask the AI agent to go find something and search for something and more than likely that AI agent's gonna call stairwell? Is that how that's gonna work in your mind? So if, if you have stairwell, the AI agent will be able to go into the data and understand whether or not you've ever been touched by that bad thing.
If you don't have sterile, you won't be able to have that answer. Even if you have a thousand AI agents there, and that's where the uniqueness of stairwell shows it. You, you first and foremost need the data, then you can do a bunch of different things.
We have the data, we store the data, and we supplement it with a lot of additional information, not only from your environment, but from other, other feeds, Right? Of course, when any, lemme try that again. Of course, whenever somebody says, we store something forever, everybody's mind immediately go to, well, how much does that cost?
'cause storing stuff for a long time is expensive, so how do we kind of store everything forever without breaking the bank? So this is where, this is why I love Mike, because the way that he, that they built it and that he and the team built it, I, I just walked in the door, right? But they built it in a very efficient way using a lot of kind of, you know, they're all Google background, right?
So everyone's got that search and the, and the billions of people that need to use it and access it type of mentality, um, they found a pretty efficient way of doing it. So once you get the data in, the way that we ingest it, the way that we store it, the way that we can call on it, is really efficient. And the storage costs the cogs.
And believe me, that was one of my first questions, pretty good. When you kinda engage with these customers and you talk to them, what are they telling you their number one pain point is? So the number one pain point is, has been and continues to be time, resources and, um, too much information that you, that you can't actually sift through.
And that, that's been the case for a while in the security world with, with, uh, defenders specifically. And that's still the case. And again, AI is making everything worse.
And so anything that makes it easier, less time intensive, uh, gets you to the bottom line, answer faster is a positive. And again, within the noisy space of security, you need to make sure that you provide an end-to-end type of value prop. So that is why partnerships is something that we are definitely looking into because it's a way for us to integrate into workflows that already exist.
Right? Of course. This is not your first cybersecurity rodeo, but what were you doing before stairwell?
Uh, so, uh, my previous role was COO of Cybereason, and, uh, last couple of years I've been doing a lot of advisory work for startups and uh, and operational coaching as I call it, for CEOs and CEOs. Right. Um, so what is that one thing that so far in your experience when you talk to customers that you see them doing over and over again, that just makes you shake your head a little bit and go, folks, maybe we should be a little bit smarter than that.
Yeah. Um, I think what, there's a couple of things of course, but generally speaking, um, some, some CISOs and some companies want to do the bare minimum just to basically kind of be in compliance and, and be, you know, do just check the box type of security. It's just not enough.
Not in the world that we live in and not in the amount and level of attacks that are out there. And so we need to be, you don't need to overdo it. You're not protecting necessarily, you know, government affairs, but you definitely need to be able to protect your business with tools that give you all the information that you can have in an easy way.
All right. Well folks, you're hearing it here. Anytime there's an attack, regardless of how successful is, there are five questions that get asked and they're generally who, what, when, where, and why.
I think you need some tools to go answer those questions, and that's not gonna happen if you can't actually search anything. Hey, Emmy, thanks for being on the show. All right, thanks a lot.
All right. And back to you guys in studio.