The Evolution of Vulnerability Management with Nucleus Security’s Steve Carter
Steve discusses the evolution of the vulnerability management market, as well as an overview of Nucleus’ latest product launch, Cloud Native Vulnerability Exposure Management Solution.
Transcript
This is Textron tv. Hey everyone. Welcome back here to techron tv.
Hi, I've got a CEO co-founder I haven't interviewed before to put on in front of you today. Let, let me introduce you to Steve Carter. Steve is the CEO and co-founder of Nucleus Security.
And um, Steve, welcome to Techstrong tv. It's great to have you on here. It's great to be here, Alan.
Thanks for, thanks for having me today. My pleasure. So Steve, we're gonna talk about nucleus security and we're gonna talk about cloud managed, uh, vulnerability management, et cetera.
But before we get in that, let's talk about Steve a little bit. You know, I don't want to put you on the spot or embarrass you, but give us, give us a little of the Steve Carter story. Yeah, yeah, yeah.
Happy to do it. So, so yeah, Steve Carter, CO and co-founder of, of Nucleus Security. A little bit of background on me.
Let's see. I spent, uh, I've been in the cybersecurity space for about 25 years now, so that's my entire career since college. Um, mm-hmm.
I spent about the first 20 or so years in the federal space working primarily for the DOD and the Intel community, uh, developing security solutions and, and vulnerability management solutions, uh, in particular for different federal agencies and different vulner management programs. Uh, so I worked for a lot of different defense contractors. In 2015, I started my own defense contracting business.
It's essentially a, a, uh, MSSP, but for, uh, you know, federal clients is the best way to think about it. And, um, and then it was in that business that, that actually had the idea for Nucleus and started to develop the Nucleus software. And then eventually in, in 2019, we, you, we spun the software out into its own company and I left the services industry to, um, uh, to focus on Nucleus.
And I've been doing that ever since. Very cool. Very cool.
I, um, as I mentioned, I've been in security a long time myself, actually, one of the companies I co-founded was still secure, and we did a lot of vulnerability management and what they call nac, network access control for DODA lot, army NMCI, which I'm sure you're familiar with. I worked on NMCI actually on a, uh, That was a bear, wasn't it? Yeah, I was working for Raytheon, actually.
Uh, and I was part of the information assurance, uh, team that supported NMCI. So Very cool. Really?
Yeah. No, we were there. So when, so our NAC product, um, who, it was EDS and then EDS got bought by, was it hp, I think.
Right, right. And HP was kinda running the, the network there. And, um, yeah, we, we were, we were the NAC solution embedded into NMCI.
And, you know, and people don't realize and you're not allowed, you know, we didn't talk a lot about it back then. Right, right. But that was probably one of the largest networks in terms of notes in the world.
Right. And it was, and it was a high target, right. It was a high profile target for, you know, nation states and hackers and so forth.
Yeah. What they used to, so it was, I Was gonna say, what they used to say back then was NMCI, uh, it was, it was the second largest network in the world, second only to the internet itself. That was what Ali Yeah.
You know, Raytheon used to say, No, it is. And, and for those who don't know, NMCI stood for Navy Marine Corps intranet, and it was just, you know, it was, it was con continental US only. Right.
But, you know, the Navy and Marines. The Marines, though, they never wanna admit it or part of the Navy. And, um, you know, it's one network that, that runs all that.
So, oh, yeah. That, those were interesting times. Certainly Steve.
Um, so what, you know, every co-founder I've ever met Steve, there's like, you know, it's almost like Richard Dreyfus and Encounters of the Third Kind, if you remember that old movie where he just had like this vision, he had a, you know, everything he saw was that Devil's Mountain, where the extraterrestrial are, you know, founders are driven. They like, this is, this is a solution that needs to be solved. This somehow this is gonna make the world better.
Right, right. What, what was that vision for you with Nucleus? Yeah, no, absolutely.
Uh, it's a, it's a great question. So, you know, throughout my career, um, building vulnerability management teams and software and programs, uh, you know, I saw the same problems on every project I worked at, every agency I worked for, right? And a lot of those problems were related, related to the fact that so much of vulnerability management was manual processes and, and manual processes were the bottleneck and were what prevented these programs from actually scaling and being effective.
And so when, when I started, um, the defense contracting company, the services company, the main reason I started that company was just to be able to fund the development of a platform that could automate all of these processes and actually enable a vulnerability management program to scale. Because I saw that there was more and more tools, there are more and more tools coming to market that could find vulnerabilities, discover vulnerabilities. And so organizations had more and more data to, to, to manually analyze and then then try to operationalize.
And there was just nothing in the market to help automate those processes. You've got Sims and source for security events, but you had nothing for vulnerabilities and misconfigurations and that type of data. So that was really why I started the services business.
So I could just make enough money to fund the r and d of this, of this platform and, and kind of bootstrap it in that way. And so that's, that's what really, um, you know, got me excited about Nucleus in the first place. And that's how I, how, how the whole process got started.
That's great. Great story, man. So you, you, you actually started Nucleus Security 20, 19, 5, 6 years ago now.
Yep. Um, bring us up to speed over, you know, give us the, the condensed version of those six years of your life. Yeah.
Well, what's interesting about, uh, about those six years, you know, that was when I started Nucleus. That was essentially me leaving the public sector, right? 'cause I'd always been, uh, in, in the public sector.
And when we started Nucleus, we made a, um, really a strategic decision not to try to sell, uh, or build anything for the public sector. Uh, 'cause we had some great advisors at the time that told us, Hey, focus on the private sector, focus on product market fit and traction. You can sell to the government later, that's a long road.
Um, and so, so that's what we did. And, um, so yeah, from 2019 to now, uh, just the, the highlights we're, well, we're now a 95 person company, right? It got started just, uh, just the three of us, myself, uh, Scott Kupfer and Nick Fleming.
Uh, we've raised three rounds of funding now about 37, 30 $8 million. We have over 500 organizations now using the Nucleus software, which is really exciting for me. And, and, um, uh, we're the market leader from everything we can tell in, in our space of unified vulnerability and exposure management, which there aren't really many companies that that do what we do.
We have just kind of a small handful of of competitors. Um, so, so yeah, that's where we're at today. I love it.
Great story, Steve. So, unified vulnerability management, you know, peel the onion back three more layers. Now what, what exactly do we mean there?
Yeah, so probably the best way to to, to talk about is to kind of just explain, you know, what Nucleus does, right? Because again, a lot of people aren't familiar with this category of tools, and there aren't many of us that do what we do. Um, so, you know, the elevator kind of pitch I always use is that nucleus is the single source of truth for vulnerabilities and exposures in an enterprise.
And it automates all of the, the workflows there need to get remediation done in minutes or hours instead of weeks or months, right? Because we know that when companies get breached, a large percentage of the time, it's because vulnerabilities were exploited, and that was the initial tack vector. And when they go and they do instant response, they'll say, Hey, we knew about this vulnerability for six months, for nine months, sometimes a year and a half.
It just never got, it never got prioritized correctly. It never got to the right people that are responsible for fixing it. And so, and so, a breach occurred.
And, and so anyway, in order to do all of that, uh, al kind of describe Nucleus and, and and also describe, uh, unified vulnerability management in the process. And so we, we basically start by consolidating every source of vulnerability, vulnerability data and exposure data in the enterprise. And so you think about, of course, scanning tools, your Quas 10 bull Rapid seven, right?
Those were the, what everyone, you know, back in the nineties, early two thousands, the N-N-M-C-I days, when you thought of vulnerability management, you thought of one of those guys generally. Uh, but, but it's become a lot more tools than that now as well. Obviously we've got, uh, vulnerabilities being discovered by endpoint tools, by A SPM tools now, cloud security tools, bug bounty platforms, penetration tests, whatever it might be.
We wanna consolidate all of that into a single source of truth, uh, kind of like a sim consolidates and aggregate security events. We're consolidating, aggregating any source of vulnerabilities and exposures. And then, um, once we do that, we basically enrich it with threat intel.
We contextualize it with, uh, with asset and business context so that we can prioritize and really help organization organizations focus on fixing what matters. Um, and then, like I mentioned, the, the, the main reason why we developed the platform in the first place was to automate all of those manual and repetitive time consuming processes that are required from the time you discover a vulnerability to the time that the vulnerability is actually fixed. There's a whole lot of process and workflow in the middle that is the bottleneck and is the reason why it can take organizations so many months to get vulnerabilities remediated.
And so we automate, uh, we automate those workflows. And so to me, everything I just described that is, uh, unified vulnerability management, or today you might call it, um, EAP, which stands for Exposure Assessment Platforms, uh, which, um, help organizations implement a CT Im approach, which is con continuous threat and exposure management. So lots of acronyms thanks to Gartner, uh, thanks to the analyst.
It's not me, but that's, that's UVM and Nucleus in a nutshell. I got it. Hey man, that was a great, great, uh, explanation as well.
Yeah. I'm, Gartner's loves coming up with those things, that, that was the whole reason we called our product nac. 'cause we actually had a really distinct name for it, which was something like, uh, uh, endpoint of vulnerability, threat detection, quarantine system blows right off your tongue.
And, and then, and then, uh, Gartner, Gartner, you know, came up with the term knack for that whole category. And, and thereafter we always just called it a nack product. But, um, it, it, it, that's the way things work.
So, you know, I I, I feel like obligated to let people know, look, this is a, a bit of a holy grail. We've been chasing in the vulnerability management space since I was in it in the early two thousands. This was now 2000 3, 5 7.
And, you know, it's one thing to find a vulnerability, do a scan, Qualys tenable, uh, it used to be found Stone McAfee bought them, but all, all Rapid seven, all those guys, they would scan until the cows come home and you'd get a telephone book ortho of vulnerabilities. And now, okay, now what do you do? Well, it, well, some level it was job security 'cause it would take you at least till the next scant That's To, to fix all of those.
Right? And then, I don't know if you remember, you remember Citadel Hercules back in the day with Darfa, and I Haven't heard that in a long time, but yes, I did. Yeah, You, that, that's, that's a blast from the past, right?
Right. And so that was gonna just automate patching basically, right. You know, remediation and, and that sounds great, but the devil's in the details, of course, right?
Not everything could be patched. Not everything need should be patched immediately. You gotta, you know, there's a process involved.
And so capturing that process w was difficult to begin with. Automating it back then was pipe dream. Right?
Right. But I, I guess today, Steve, with with AI and, and some of the other technologies at your fingertips, we, we can automate that whole process. I, I guess, Yeah, correct.
Yeah, yeah, yeah. Absolutely. And, and, you know, AI is certainly a part of it.
Uh, you know, I think the biggest challenge that, that folks have had, and, and I'll, I'll back up actually. You know, for years, I would say since the, you know, I dunno, 2005, 2010 timeframe, when, when we started to see virtualization and clouds starting to come online, a lot of or large organizations tried to build something to something that does what Nucleus does today. And, and even today, when we're competing in, in opportunities, probably half the time, we're competing against a homegrown solution that, that the enterprise has developed over the years and has grown into, you know, some, some big monstrosity that has become very difficult to maintain and and scale.
But, but really what we found is, is the, the biggest challenge of, of building a, a solution like Nucleus is really in how you, how you manage the data and, and scale the, the, uh, the data architecture, for lack of a better term. Because we're dealing now with so much data from so many different tools. I mean, you think about the CSPM tools and A SPM, and DSPM and ot, you know, it goes on and on now.
And so a large enterprise now has something like 20 different tools that they're using to detect vulnerabilities. So the biggest challenge is just integrating with those tools, pulling in the data fast enough, and then being able to actually do something with this massive amount of data that you now have in a, in a single place, uh, being ac you know, being able to, to, to report on it and do analytics on it, and do all these things really, really quickly and then be able to, to automate process on it. Um, it really becomes just a big data problem.
That's, that's been the, the biggest challenge I think, at Nucleus is just the scale and the amount of data that we process. Um, and, and so we've, you know, we've had to basically become data scientists to, to be able to manage all this. Yeah.
Yeah. Well, that, that today's world, right? I mean, that's, that, that's the, the, the, i I man, you, you're like transporting me back through my still secure days with this.
I, I remember all the problem all around with it. Um, Steve, I, we didn't mention nucleus security. What's your website?
com. com. Okay.
Just wanna make sure we get, because I'll forget it and, and we won't show up. com. All right, let's fast forward to the instant here.
You guys have a new, uh, product launch coming out, a new version, what's going on? Yes. So we recently launched our, uh, vulnerability and exposure management for cloud.
And, and this is basically our latest expansion of the platform that includes a lot of features and functionality bundled up that are really purpose built for, for cloud native environments. And, and this is really important because most, as you know, right? Most vulnerability and exposure management tools struggle a lot in cloud environments because they're designed to manage vulnerabilities from static infrastructure, right?
I mean, that was, that was when a lot of these vendors were, were, you know, coming online back in the, in the early two thousands. And so they don't handle the, the dynamic nature and ephemeral nature of cloud, cloud services and containers and serverless assets and things like that. And so this launched that we, uh, that we just did, I believe it was about, I don't know, three weeks ago or something like that.
Um, it bridges, it bridges those gaps, uh, in a lot of ways. Absolutely. Um, you know, I, I happen to be heading out to London next week for, um, CubeCon, you know, cloud native con Yep.
And they're expecting, I think they're expecting it to be the biggest cube con, cloud native con that they've done so far. So obviously this is a, a growing industry. What, I mean, the whole cloud native stack and the way, you know, things are stored in containers and distributed and, you know, all of the different issues.
How, how big a deal is that doing this right in a cloud native environment versus, you know, your traditional either on-prem or on a hypervisor kind of thing? Yeah, I can, I can tell you it's very important to our customers, right? And, and this is a set of functionality that, um, you know, we, we kind of accelerated the timeline on because there was such a strong demand for it.
And I think a lot of that was probably driven by the explosion of companies like Wizz, right? That, um, you know, it's like everyone, obviously everyone, you know, pretty much every large enterprise is using the cloud. And, and by now most of them have, uh, either a wiz or an orca or some kind of cloud native scanning tool that's discovering misconfigurations and vulnerabilities and exposed services in the cloud.
And so that to our customers is just another source of exposures that they want to ingest and bring into, you know, the single source of truth so that then all of the automation can be triggered, you know, to to, to basically get those things remediate quickly. So I can tell you it was, it was something that our customers were, were screaming for and, and banging their fists on the desk for for sure. Um, just because, and, and again, I attribute that to, to the explosion of the, you know, the CSPM tools, the CNA tools of the world Sure.
Is hey, 45 times revenue. It was 42 times, something like that, right? That's, that speaks for itself, right?
I didn't get your attention. Yeah, that is, that was crazy. It's crazy.
And cash. Um, anyway, Steve, we're about outta time, but I want to thank you for coming on here and, and educating us a little bit about nuclear security. Your background about what's going on in, in the, uh, vulnerability management market is just, you know, sometimes it just freaks me out that this was a problem i, we were trying to solve in 2003, and here we are 22 years later, right.
Still trying to solve it. Yeah. So hopefully agree, hopefully we'll get, we're making progress though, right?
Absolutely. Absolutely. We're making progress.
It's a, it's a really hard problem on its surface. It's, it conceptually, it, it's a simple problem. Uh, but it's a deceptively difficult problem to solve, which is I think why, you know, and even now, today, we still have a lot to build.
Uh, we're not, we're not even close to done. Um, there's a lot, a lot of work that we still have to do. So, so it's an exciting space.
Yep. Hey, you guys are gonna be at RSA, We are gonna be at RSA, so yeah, please come out to see us. I'm not sure exactly if we, uh, I know we have a booth number.
I'm not sure that I have it. Uh, well, It's a very small show floor. I'm sure they won't mention easy to find.
They'll find you right away. Yeah, right, right. Yeah, actually we're gonna be there live all week as well, so maybe we'll, we'll catch you out there.
Yeah, that'd Be fantastic. And you can look up nuclear security in your RSA guides. Most people, I think they have the app now for 'em too.
Anyway, hey Steve, thank you for coming on here. Don't be a stranger. Maybe we can't hook up an RSA.
Yeah. But keep up the great work. It's, it's a worthy course, right.
And we will, we will solve this riled. Maybe you're the guy to do it. We're, We're gonna solve it for sure.
And, uh, thank you Alan, it's a pleasure to be on the show here and, uh, yeah, look forward to, to future conversations. Maybe we can sit down and, uh, you know, reminisce about NMCI sometimes. That would be fun.
All right. Steve Carter is CEO co-founding nuclear Security here on Tech Drunk tv. We're gonna take a break.
We'll be back.