Sweet Security’s Eyal Fisher on Cloud Security Innovation
Eyal Fisher talks about Sweet Security closing Series A funding to capitalize on the interest in its holistic, runtime-based approach to cloud security.
Transcript
This is Textron tv. Hey everyone. Welcome back here to techron tv.
You know, I've got a, a new company to introduce you to today, and I, we, we, we've got one of their co-founders and Chief Product Officer. I want to introduce you to a Al Fisher. Al is the, uh, CPO and co-founder of a company called Sweet Security.
Al, welcome to Tech Drunk tv. It's nice to have you on. Great to be here.
Thank you. You're welcome. So Al you know, be we're going to, we're gonna jump into what we want to talk about a little bit later, but I wanted to start off with a little bit about you.
You're the co-founder of Suite Security of Suite. Um, give us, give us the story here. Give us your background and how you came to Co-founder and why you came to Co-Founder Suite.
Okay, great. So I have, uh, vast experience in cybersecurity. I, I was like 20 years in, uh, uh, the famous, uh, unit A 200 in, in the IDF, the Israeli defense.
20 years. 20 years. Yeah.
20. I Think that might be a record for us here. I don't think we've ever had any, most people put in there four years and they're going to start companies, you know.
Exactly. 20 Years, a long time. Most of those were actually, uh, I was their commander actually.
Really? So, yeah, so, so I was 20 years in that unit. I retired as a colonel.
My last position was, uh, yeah, my last position was heading the largest fiber, um, center fiber operation center in the unit. 1000 people doing fiber operations. Uh, probably one of the largest, um, um, uh, such organizations in the world, uh, doing research development and the operations themselves.
Uh, quite unique position. Interesting. Absolutely challenging, uh, and important for, for, for, yeah.
No, actually That is, that's impressive. Congratulations. Thank you.
So after doing that, um, I, uh, I retired and, uh, from the unit, uh, and from the Army, you, you retire young actually, and you have like, time for your next chapter in, in your career. I did some other few other things. Uh, and actually I met, uh, my old friend, drew Kti, who, who is like, uh, he, he's, uh, uh, my co-founder and CEO we were, we have like a very long, uh, uh, relationship in the unit.
Like we know each other for 15, 20 years. And, uh, and I know that, uh, in his last position, he was the fifth of the IDF. So, yeah.
So we cover like, you know, uh, defense and offense. I mean, I did offense stuff. He was defending, trying to defend the sensitive networks of the IDF.
And the one thing that we talked about is that, uh, uh, you know, when, when the government of Israel, uh, decided to go out and, uh, migrate to public cloud in, in, in few further, uh, networks and, and, and, uh, and applications, we found out that there is no good, uh, runtime, uh, protection tool, the equivalent to the EDR for the on-prem environment. Right. We suddenly understood that there is no such an equivalent.
So going out to the public cloud leaves, leaves you actually quite unprotected. And we understood that that's the issue of most of organizations going, doing their digital transformation, going out to the public cloud. And we looked into it a little bit more, and we understood that the problem is even bigger, meaning that, uh, security teams are doing their jobs amazingly for on-prem environment.
But when it, when it gets like to, uh, you, you go to like your cloud environment and try to understand how you are going to protect it, suddenly you find out that your team is not an expert in cloud environments. The tools are not the right tools. So, and the CSO is responsible for the cloud environment, but he's not in charge of it.
Right? Exactly. So, Yes.
And That's always been the problem, right? I mean, look, I've been in security a long time, right? And I remember when cloud first came out, right?
Security w was holding it back. The problem I think y is, it's not our cloud. It's whether you're in AWS or Google, Michael, wherever, whatever cloud you're in, it's their cloud.
And inherently in cloud security is the idea of a partnership between the cloud, the cloud provider, and the, and the cloud user, right? The, the tenant, if you will. And, and so the cloud user's ability to secure the runtime, to secure the assets in the cloud is at the, at the mercy, for lack of a better word, at the mercy for what the cloud provider is doing and giving you access to, they give you access to a lot more than they used to, but even still, it's not their access, right?
They, they give you a subset. So let's take it one step forward. Now, let's imagine that you are the CSO of, uh, of a, of a company, uh, building a SaaS, you know, application for their, for their customers.
Now, what happens is that the CSO is responsible for, uh, the, the, uh, the of the security of the environment, but he's not the one to develop, you know, the application. It's the r and d guys. So the CISO is not, you know, he has AWS on one hand, he has developed developers, uh, uh, uh, on the other hand.
And what's happening at the end is that the cso, he or she is actually has, you know, there to, to take the blame in case, you know, something really bad happens. Sure. Uh, uh, uh, he or she can't decide on which tools to, uh, to implement because that's r and d to decide, uh, he has limited resources or tools because A-W-S-W-S is like, uh, is dealing with the other side.
So he's in the middle and we called it the miserable cso, and that's when we decided to call ourselves security. We try to Sweden a little bit the life of the miserable cso. How you nudge.
That's Exactly, and we decided to bring in a runtime security, a tool that will enable the CSO to be really, you know, in charge of the environment to understand everything that's happening in the environment, and to be able to protect, to really protect the environment and gives like, and, and, and do what he or she is in charge of, uh, protecting the, the, the company's, uh, super, uh, essential, uh, uh, asset, the cloud environment. That's the most important asset that the company has. So that's where, that's where I get it, how we started.
Excellent, excellent story. You know, timing is everything. You talk about the miserable ciso, how about the CISO is criminal, right?
Because here in the US now we have the SEC charging CISOs, right? I'm sure you're familiar. Yes.
With, with criminal, the, the Uber ciso Wow. Was also, was actually tried criminally, thank God he didn't go to jail. Right.
But it, it, it's, it's ludicrous to think that a CISO can get in such trouble and, and ruin his career over something that he doesn't really have control over. He just has responsibility for. Exactly.
Here's another thing I that I, I, uh, I always have a problem with too, which is a lot of the cloud providers, and I'm not picking on AWS or any particular one. A lot of the cloud providers, they offer up cloud security tools over and above what they give you for free, let's say, right? Over and above.
They offer up some of their own cloud security tools and say, this way, you don't have to go buy some expensive tool or some, uh, third party tool. We, we give it to you. All right?
And those tools generally, while they're, it's nice 'cause they're billed under your Amazon bill or they're built on, you know, with your Google bill or they're, they're tightly integrated into your Azure or what have you, they're generally not as good as a best of breed or a standalone tool that comes from a, an independent vendor. There are exceptions, but generally this is true. But I feel like a lot of companies compromise their level, especially of runtime, security and cloud, by, by taking the, the provider's suite, suite, the providers tools.
Ah, it's free or it's cheap, and I could just, and it's integrated and it's easy. I pay them on one bill. And again, security responsibility without control of your security.
So it, exactly. And, and let me add one more thing. Uh, uh, adding models, native tools that generate, you know, tons of alerts and findings that you in your organization has no one to analyze, to understand, and to, uh, to, to, to handle, you know, is like, uh, actually wasting your money.
It's like, uh, so you turn on All, it's a double waste of your money. You're wasting your money doing it, but you're also now wasting whatever resources you do have trying to figure out where to deploy them. Exactly.
Right? And you get tons of alerts, and now your team has to go after all those alerts trying to understand what's happening. And just bear in mind, we just, we just, you know, talked about the, the, the fact that they are not cloud experts.
That's usually what happens. So now those non-cloud experts have, they have tons of alert. They try to understand what happened in order to, to understand what happened, they need to go to the r and d team.
Now, the r and d team has no patience and time explaining again and again. No, that's not relevant. No, that's not important.
No. You know, at the end, they, they won't call you back. Yeah, no, it's desensitizing, right?
It's like they're, they're, you're not, you, you're not making best use of them either. Al I want to talk, we didn't even jump in yet to this series A or new product, so we gotta move along. But before we do, what's the URL for people who wanna go get more information about Sweet, Sweet Security, S-W-E-E-T security.
Perfect. Now, I, uh, you guys recently, uh, came outta stealth and launched a, a series A. Can you tell us a little about it?
Yeah. So, uh, we just, uh, closed, uh, the a round, uh, uh, being able to like, uh, accelerate, uh, our offering. Uh, we raised, um, quite, uh, quite, uh, large amount of money and team now it was like almost $40 million that, uh, was raised by the company, uh, by, uh, a tier A, uh, VCs, uh, evolution, uh, MRV, uh, and ot, uh, cyber CVC, uh, sold.
Oh, really? Uh, really good, uh, um, uh, uh, VC that, uh, backed us. And, uh, now that we have like, uh, we have the funding, we can accelerate even more, uh, what we, what we have, uh, until now, we, uh, concentrated, uh, in like a, having a very good, uh, product market fit, understanding the need, understanding what we can bring in.
Uh, and we found out at the end that it's like, uh, that the, the market there is a, you know, large need. So yeah, we are, we, we implemented, uh, in like 10th, uh, uh, I have like, uh, 30 or 40, uh, implementations already with, uh, uh, paying customers, beautiful. That they understood the value of what we bring in.
Um, and, uh, now with new funding, we can even like, accelerate even more, uh, build our, uh, uh, US-based, uh, uh, team. Uh, and, uh, and, um, and that's, uh, the nice thing now is that, uh, part of the, uh, acceleration is, uh, building more and more, uh, um, solutions that are based on runtime. We call it the runtime suite.
So we started from detection response, uh, and we did that as I just, uh, explained a detection response solution that generate a very low ratio of false adults in order to keep everyone, you know, uh, calm understanding, just bringing in just the important stuff. So every, so, so the security team won't need to like, uh, run after all the alerts and everything, just the important stuff. So we did that, and now what we are doing is bringing, bringing more, uh, more value based on the and insights we bring.
Uh, and we call it actually, uh, uh, you know, uh, identifying risks that really are exist in the environment, not risks that can be be in your environment, risks that actually exist in the environment. And, uh, and, and examples are like vulnerabilities that are really in use by the application. So now you can prioritize better the cvs in your environment.
Uh, secrets that can, that, uh, that we actually, uh, we call it, uh, non-human identities, uh, that are in use by the application, can be analyzed by our, uh, solution. And again, we can identify risks that really happen with, uh, uh, secrets that are, uh, that, uh, uh, went rotated. Secrets that, uh, suddenly appear in, in, in, in the part of the application that didn't use that, uh, that, uh, that secret.
Uh, we have added now, um, uh, runtime, uh, posture management again, uh, giving insight, uh, on your environment that can't be thin in any other solution because we go down to the level of what is being called a layer seven, meaning that we see everything even before it was encrypted. So we see the access to your, uh, buckets. We see whether it was a read or right.
We see who accessed those buckets, not just that they were accessed, and more, and more and more. And what I'm saying at the end, that you get a full suite that covers you from reducing risks that really exist in your environment from one hand, and giving you like the, the, the best detection response solution out there to make sure that in case you get breached, you will know about it and you will know what to do, uh, the next steps. So that's what we do.
Excellent. Excellent. Now that's, 'cause I was gonna say before we could get into what's new, let's understand the baseline, right?
What, what do you guys have here? Um, so we've raised the money, you've got already follow on announcements with, uh, more, more even more functionality. What, what's the latest on that?
Uh, the more functionality that, that, I mean, the la the more functionalities that we added or when we started, can you Repeat it? Well, I think you laid out when we started, but now what are we adding a little? Okay.
So after, after we decided, uh, after we started the detection response solution, we have added the vulnerabilities, vulnerability management in runtime, adding now the non-human identities, again in runtime, adding it now, and the posture management in runtime. Again, adding all those together, you know, it becomes a, a suite of solution. Yeah.
A suite of solutions based on runtime that is like, uh, sec, the security switch pole. A cloud environment in runtime. Yep.
com, cloud native now text drunk ai, digital CXL or Techstrong, ITSM. Now, um, runtime doesn't exist in a vacuum, right? Good DevOps kind of hygiene is, you create feedback loops, take what you learned in runtime, feed it back in so we could correct it in the next reiterate, we keep iterating and reiterate and reiterate, is there plans to move?
You know, we talk about shift left shift, right? Yeah. Plans to move in to all of these areas, or just to maybe partner with some of the providers there.
Yeah. So of course we started, uh, in the area that we identified that the, you know, the missing piece of, of course, Mm-Hmm. So that's why we, we've started with the runtime.
Uh, the options now that we have in order to expand also for the shift left stuff is like partnering or expanding. So it is still too early, uh, for us to decide yet, but, you know, all the options are on the table. I must say that we have started with a difficult part.
So the random piece is a lot, you know, harder to achieve. Um, building like, uh, a, a, a best in class that will bring in the random insights is not like a, a super easy task. We have the best team in the world to accomplish such a task.
Uh, guys that knows their way in, uh, Colonel Linox and think that most, you know, uh, software engineers actually hate, uh mm-Hmm. We have guys who knows, uh, their way in those areas. So we built the best in breed, best in class, uh, sensor.
And on top of it, what we did is we built, uh, what we call, um, a behavioral baseline. Our system learns automatically the environment and the application, so we understand how your application behaves. It's not just, you know, detection, detecting malicious stuff like most other tools are doing.
That approach will generate at the end the large amount of, uh, uh, alerts that we talked about. Our approach is utilizing a baseline building very quick, quickly, a baseline, and then, you know, um, uh, follow the deviations, understand what happened, whether that's, uh, a misbehavior of the application or whether what we see is every breach. And, and that's, you know, the, uh, the thing that is unique in our solution, uh, that we are based on, on that baseline.
Got it. Hey, Al, we're, we're about outta time here. It's, it's probably over time actually.
Well, listen, I want to thank you for coming on and, and, uh, explaining to us about Sweden, your mission, and what a great story. I wish you nothing but a lot of success because your success will make us all a little bit more secure here. So that's a good thing too.
But do come back on and keep us posted about what's doing. Thank you very much. Thank you.
Ayel Fisher, co-founder, chief Product Officer Suite Security. It's pretty sweet. As or as they say, as sweet as it gets here on text Drug tv.
We're gonna take a break. We'll be back in a minute.