State of Application Security Posture Management with Cycode’s Ronen Slavin
Ronen Slavin, co-founder and CTO of Cycode, shares key findings from Cycode’s State of Application Security Posture Management 2024 report, which it published in November 2023.
Transcript
This is Text Strong tv. Hey everyone, welcome back here to Techstrong tv and happy New Year to you. I guess it's still not too late to continue saying Happy New Year for at least another week.
But anyway, happy New Year. I am happy to be joined by starting off the new year with a new company and a new, uh, first time guest here on Text Drug tv. I want to introduce you to Ronan Slavin.
Ronan is the Co-founder and CTO for S Code. Ronan, welcome to Text Drunk tv. Hey, it's great, uh, great to be here.
Thanks for, for having us. It's nice to have you here. Um, Ronan, you know what, what we might as well, it's your first time on our audience is not familiar with you unless maybe you have friends and relatives watching it for today, which they know who you are.
But for the rest of us, tell them a little bit about Ronan Slavin. Yeah, so, uh, I'm, I'm Ronan. I'm the CTO and, uh, one of the founders at Site.
Basically, I've been a developer since I remember myself. I started programming, um, when I was, uh, you know, at high school. Um, I then, uh, served, uh, five and a half years at come the intelligence forces, uh, in Israeli army doing, uh, software development and, and kind of, uh, development of, uh, of tools.
Um, then I moved, uh, and I worked in the cybersecurity industry. Uh, I had a, another startup before Site Code, uh, that also, uh, focused on securing, um, that time. It was more like securing data, uh, from compromised devices.
Uh, and about, uh, four and a half years ago, um, we opened site code, um, kind of when we identified this, uh, gap in, in securing source code and, and treating source code as a, as the corporate asset and giving it, you know, the respect that it, uh, deserved. So we saw this gap, we saw it in the companies that we worked at, and we, um, you know, started this journey of, uh, of cycle. Excellent.
Um, so as you mentioned, site code is about securing source code. And of course, when we talk about securing source code today, you know, probably one of the biggest issues is so much of our source code is actually open source components, right? That's put into the apps maybe more than half, maybe more than three quarters of the actual code in the app.
And the source code of the app is, is, you know, pulled down from re repos and open source stuff. So is is that part of the site code mission is to secure the open source as well? Yeah, so, so kind of like what we see in the recent years is, is we see a major shift in, in the way that software is developed and the ways that organization develops software.
And we see it in, in first of all, the rapid adoption of new technologies. Like we're all developing in the CICD environments, embracing this devs trends that allow us to shift fast and, and build faster. And part of that is also open source tools, right?
Like if someone already wrote like, really good code, I wanna use it, I wanna, I wanna benefit from it as well. So we started using obviously open source component more and more and rely on that. And we, and we developed microservices and we begin to consume services.
So really a lot has changed in software development over the, the recent years. The barrier to become a software development developer is actually lower now, right? It's easier, easier to become a developer, especially in the, in this area of generative ai.
But the risks are, are actually, are, are bigger right now. It's harder to write secure code. It's harder to know, am I doing everything in a secure way?
Um, and in parallel to kind of this, uh, increasing challenge, we also see, uh, an increasing kind of expectations from regulators and from consumers, from from companies to take responsibility for the software that they produce. And that's where we come in. Like we want to make, we wanna help organization, you know, take this responsibility for the security of the code.
And, and in order to do that, they need kind of this full suite that, that we're developing. So there's a lot that goes, uh, into it. Um, kind of our way to phrase it is, is what we call a complete A SPM platform.
Um, but that's kind of the, the vision that we have in mind to, to, to enable this, uh, to organizations. And A SPM stands for application security, posture management, correct? Exactly, exactly.
Yeah. com. com.
com, a lot of people didn't believe in DevOps. They thought it was marketing. It's not really any different.
And to me, DevOps was never about the tools, though. That's part of it. But really the heart of DevOps is about the automation.
It's about using CICD pipeline to develop software. I don't care whether you use Jenkins or, or, or harness or, or whatever your CICD GitHubs, you know, whatever you are using is great GitLab GitHub, but it's really about the ci, it's about that whole philosophy, that whole framework, dev and ops working together. Now we're starting to see people say, oh, DevOps is old already.
It's passed it's prime. We're, we're moving on to platform engineering and we're moving on to this, that, and the other thing. Now I've been in, I've been in technology a long time, 30 plus years, technology doesn't necessarily die.
It becomes matured into the very fabric of what we do. Yeah, It evolves. Yes.
So when we talk about things like microservices and cloud native, N-C-I-C-D and GI Ops, you can't do those without having sort of that DevOps mindset. I think DevOps is probably more ingrained, you know, into the way we do things than ever before it continues to be. So I think the other piece of it though is, is the, so-called, you know, is what we call DevSecOps, right?
Which is you gotta develop more secure, you gotta try at least to develop more secure software, you know, higher quality software. And I, that's gonna be a big theme for us here, tech strong in 2024, right? Yeah.
DevOps isn't dead, of course not. Security is as important as ever doing things automated faster, AI helps for sure, it's gonna have a bigger influence going forward. But these are all important, important things for every, whether you're a big organization or a small organization.
Yeah, I agree. It's a, about evolution. And, and, and if we, if we used to, to kind of, uh, do security in a certain way, you know, before we had DevOps, now we do it d and then kind of DevOps introduced to do it, do things in a new way, faster, more times a day.
So this kind of triggered this shifting and thinking of, okay, how do we use the, use this tool, uh, to integrate security in better locations, in in more appropriate times that will eventually enable developers to act on them earlier on? Kind of, to me, like that was the, uh, the trigger for, for DevSecOps and eventually, uh, help us produce more secure products, right? Like that's the, that's the goal.
Absolutely. Let's talk about security posture, application security, posture management. How would you define that?
Yeah, so, so, um, A SPM to us, like is, um, is a chairman, is a, is a phrase that we begin to hear more and more, uh, you know, in the last couple of, uh, of months. Um, and when we started thinking about it in cycle and kind of like what is the way that, that, um, and the two wanna find it? A SPM is about solving the problem of building a secure software, right?
Like, it's not about just aggregating different tools. Um, it's about, first of all, uh, having this understanding of how software is being developed. So we call it call to cloud visibility.
Basically connecting to all the, all the tools that, uh, that make the, um, the company software and really understanding that this report ties to this build tools and, and to this artifactory and to this production, really gaining this visibility. Once you have that, you can start scanning from vulnerabilities. So you can do that with your own scanner, or you can ingest what we call like expert scanning tools.
Then because we have this protocol visibility, we can actually, uh, add context to the specific findings. We can actually understand what the spec, the specific issues that we're finding and how they affect things. This allows us to prioritize and actually help organizations solve the, the more critical issues.
Uh, first help with remediation and mitigation, right? Because that's the whole purpose. The whole purpose is to fix vulnerabilities, make sure that software is not released with vulnerabilities from the get go.
So to us, that all falls, uh, under that. Uh, and eventually, like, once we have all this suit of, of capabilities that enable companies to, uh, to build and shift software, uh, securely without compromising on speed, we wanna make sure that we know to communicate it to the executive management or to the, the executive board as we also see, uh, kind of the recent trends in the last couple of months is that they're expected to take responsibility for that. So they need to understand what's, what are they doing?
Is it enough and actually, uh, feel, feel good with taking their responsibility? We call it peace of mind, right? But that's what we wanna give them, and that's how we define SPM at site code.
Love it. Great stuff. Alright, so, uh, site code recently published a, uh, state of application security posture management 2024 report.
If you don't mind, share with the audience kind of an overview, like why, why the report? What would, what was the idea behind it? What were you trying to get at?
And then if you don't mind, let's hear some of the key highlights that you think the audience might be interested in. Yeah, sure. Um, so, so first of all, you know, as we, as we saw this, uh, trend growing of, of companies talking about SPM, so we, we really wanted to, uh, to hear from the market itself, from, from industry leaders, like what do they mean?
What are the pains that they're feeling regarding to, uh, to SPM? So we, we started this survey, uh, this survey, um, surveyed about, uh, uh, 500, uh, uh, people from different companies mainly. Um, we had the CISOs application security directors and dev ecop, uh, directors as well, uh, have the companies who organizations that have 5,000 employees or more, and the other has with, uh, 1000 to 5,000 employees.
And we articulated kind of the main challenges that we feel that are part of, you know, the, the emerging space of SPM and what A SPM uh, needs to cover. And we took it to this organization, uh, to understand like whether the, uh, the things that we, uh, feel that are kind of market pains, are actually the market pains that they're experiencing. So that was the kind of the, the initial idea, uh, for, for the, for the conference, uh, for the, sorry, for the, um, for the survey.
Um, so obviously out of that we released our, our state of A SPN, which included and incorporates all the insights that we got from this, um, this very large survey, uh, that we conducted. Um, to me personally, I like, like all the, all the insights that we got, but, but, um, like if I try to, to summarize them, uh, so it all ties back to, to kind of what we, what we talked about before. Um, but what, what we, what we, uh, see in, in a, in a clear, uh, way from the, from the report is that first of all, like many organization experience, what we call the K, and this is something that happened over the, over the years where organization adopted different application security tools across their stack, um, for the larger the organization is, they adopted more tools in, in more platforms.
And basically they have, um, I think not, not less than 20 tools for the smallest organizations that they need to manage. They need to understand, they need to, um, they need to orchestrate. And basically it, it, it created a, a huge, a huge, uh, uh, challenge for them.
Um, and that's one of the, one of the things that SPM is trying to solve, right? Like taking this chaos of vulnerabilities that are surfaced everywhere, um, and giving them context, giving them, uh, automatic remediation workflows, enabling companies to actually act on them. Um, so that's like the, uh, the first thing, um, in the reports we have like 10 insights.
So I won't, I won't go, uh, go over all of them. Um, but also, like, you know, two, two more that I think that are super, uh, interesting and probably relevant to every company is this whole notion of, um, of shifting left and, and kind of like understanding that what we did so far wasn't the most efficient, right? So when we, when we talk about shifting security left, what we did was to take the vulnerabilities and, you know, kind of like, uh, throw them on the developers, right?
Like, tell them you need to fix all of this and this is, this is not effective. And, and, and it actually, it backfired because when the security teams actually like, took many issues to the developers, it it slows them down. In many cases, they might not be like the most interesting vulnerabilities to fix or maybe, you know, maybe they're not actually being called or things like that.
So the, the missing context was actually hurting us because it created these frictions between developers and application security teams where the application security teams are tasked with, like taking the vulnerabilities to zeros, but they're missing the context. They're missing the understanding of what these vulnerabilities actually means. And then it kind of, uh, created this, um, problem in translating it to the developers and, and again, created conflict between, between the teams.
Um, and eventually it slow it slow development down, right? Because now I have developers that need to fix vulnerabilities maybe that are not as critical as other ones that we would've prioritized to fix before. Maybe there's a discussion between application security and developers on whether something should be fixed or not, and then they're investing a lot of time in it instead of in other things.
So we had a, a good intention of taking the issues as early as we can to developers, but maybe we, we, we, we did it too much. We did it, um, we did it, uh, let's say in a uncontrolled way. And the result is long development down where kind of the, the way to address it in A SPM is to have what we call control shift left, where you do it responsibility responsibly and, and, and in fashion and incorporating prioritization, remediation and, and enabling developers to act first on that.
So that's, um, that's another one. Um, and it also kind of, um, uh, echoes like this, this issue. Who is, who is responsible for the security itself, right?
Is it the development teams? Is it the application security teams? It's a very unique, uh, challenge.
I think when we, when we talk about security, because we see the security team responsible for, for these issues and, and they're expected to take responsibility, but they're not the one that can actually fix them. They, they need the developers to, to apply the fixers. They need developers to do the fix.
And it's, and it's actually a unique equation that exists only in application, in application development and software development, right? Like if I need to, I know to, um, to update an AV on the server, usually the security, they can do it themselves, right? They, they don't necessarily need to involve other teams, but in this case, you have to, you have to cooperate with developers.
You can't go and make this decision on your own. If you do, you might break something which would, you know, um, won't be good and eventually like, cause more, more harm than good. Um, so just like even defining this responsibility is challenging for organizations, uh, to do.
Um, and I think it's also like kind of a core piece of the problem where SPM is also trying to be, uh, the bridge between, between everyone. Like we, we want to, um, we want to be able to, um, see all the issues and, and, and, and vulnerabilities that exist, you know, within the, the development process. We wanna know to prioritize them.
We wanna know to take them to the developers and we wanna know to explain it to the management of a company, right? So we wanna do all this translation between these, these different entities that has a shared goal. But when we try to think like who is actually responsible for it, the answer is not always, uh, clear.
Got it. Ronan, we, we could talk more about this, but we're running outta time for people who maybe want to get a look at the whole report on, on, uh, on this state of application security, posture management. Just go to the site code website.
What, what's the website? com and you should see a banner where with their reports. And if the, if the report is, uh, is interesting and, you know, we kind of, we kind of pick your money and you wanna see how we are addressing these challenges.
So, um, so integrating the platform is super easy. Um, we usually, uh, we usually offer, um, a POV of, of a few weeks, and you immediately see the value when you, when you connect the platform to, to the tools that an organization is using. You can start with some of the tools.
You don't have to connect every single at once, but if that's, if you agree with the kind of the, the aspects that we talked about in the report and you're interested in seeing how we're solving the issue. So we're always, uh, we're always welcome that and happy to, to work with companies that experience similar challenges. com.
Exactly. Yeah. Excellent.
Hey, Ronan, I want to thank you for coming on and, and giving us a little bit of the highlights of, of this state of application security, posture management report, as well as telling us a little, you know, talking a little bit about the state of software development and security today. Um, it's gonna of course be, I think a theme for the rest is always a theme, but this year especially will be harping on it. Best of luck to you with S Code.
We hope to see you. We'll have you back on soon, and we'll talk more. Thanks for having me.
I, I really enjoyed and yeah, hopefully I talk soon. Alright, Ronan Slavin, co-founder CTO at sco, talking about the state of application security, posture Management 2024 report, as well as SCO solution for Security Posture Management or A SPM. We're gonna take a break here on Textron.
We'll be back in a moment. Stay tuned.