The Future of Workload Isolation with Edera’s Emily Long
Edera CEO Emily Long, in the wake of the company picking up an additional $15 million in funding, explains why a new approach to isolating workloads is needed to better secure IT environments in the age of the cloud.
Transcript
This is Textron tv. Hey guys, thanks with Row, we're here with Emily Long, who's CEO for Adera startup that just raised $15 million in additional funding for workload isolation technology. And I'm gonna let her explain what that is.
But Emily, welcome the show. Thanks for Robb, me, Mike. Appreciate it.
We've been trying to isolate workloads since somebody invented the virtual machine. So my question to you is, um, what's different about your approach here and what is the problem we're trying to solve? Exactly.
Yeah, so if you kind of take a step back, if you're looking at, like you said, virtual machine technology back in the day, um, what we're really focusing on at Adera and why we just closed our 15 million, uh, series A round, um, with Microsoft as one of our backers, M 12 as well as a couple others. But, um, the reason why we really are focusing on isolation at the container level is because in virtual machine world, there are a lot of isolation technologies that are fairly effective. But when containers came onto the market and people started using them, you know, over a decade or so ago, uh, containers actually have a false, uh, word to describe them.
Containers actually don't contain, which is quite funny in their name convention. Uh, and it, I think it's taken some time for us to really appreciate how much they don't contain. And so a lot of, um, the, the industry has kind of started to move on and really realize the risks.
Here you see a lot of people talking about vulnerability, exploitation, and people's secrets getting exposed. And really a lot of that has to do with the lack of container isolation that's present today. Now Adera really focuses on the premise that you should be able to trust your workloads and trust your containers and have them be isolated as you really did with VMs back in the day.
And so we really came forward with a isolation technology that really uses, um, a lot of older primitives using some older technology blended with some new technology to make it really able to be used anywhere at any time. And so we really focus on making sure that you can't get exploited for lateral movement, living off the land attacks, those types of things. And so we care a lot about this, um, particularly in the age of AI because people are now using GPUs and even the attack surface on GPUs is exponentially greater and scarier.
And so we ca really came forward to try to solve that problem at a really fundamental, simple way. 'cause there are actually some technologies out there that exist, but they're really complicated to use or have performance degradation and those types of things. So it's been kind of this fight between how much do we lean into security and how much can we actually run our infrastructure, um, simply and and meet our customer's needs.
Didn't this need to isolate kind of, uh, lead to some, for lack of a better phrase, I'll call it unnatural acts, where people were putting containers and Kubernetes on top of virtual machines to guarantee the isolation, but in so doing, adding overhead or maybe not being able to move off of a virtual machine altogether, which increased cost if it was a commercial one. Yep. So, um, has this been something, I feel like it's a long time incoming, but is this something that's a little on the overdue side?
Uh, we, we believe so, yes. I think the hard thing with computing, when you kind of look at it from a a holistic perspective, you know, we, we end up with a lot of technical debt, right? We're kind of like layering upon layer upon layering over time.
You end up with top-down solutions that are kind of plugging certain holes here and there, and we end up with this really complex ecosystem of layered tooling. It is overdue, um, mostly because I don't think there's been anyone focused on really trying to solve it at the lowest levels. And very simply, like you hear the premise of like secure by design or secure by default making things just run securely naturally, which is really where we come in that's a little bit different.
Um, there's people, you know, trying to look at kind of the isolation or, uh, I wouldn't even say isolation as much as inhibiting vulnerability exploitation to be a problem by alerting you. And you look at your dashboard and you can see if something's going on. That's really been the industry's response to the need for isolation because the problem itself had not been solved yet.
And what we came in to do is really this overdue need is to solve it simply at the lowest lever levels and being able to plug it in really simply because we, we recognize most of our team here at Adera has worked with enterprises for years and years, and you can't tell an enterprise to start over and rebuild, and you can't tell an enterprise to slow down their production environments because customers, you know, that they're serving have certain expectations. And so how do we evolve with the, you know, increased threat landscape, but also create a simplistic solution to do so? And that's really where we came in on the isolation side specifically.
And if I don't do that, it comes really hard to limit the blast radius of a breach, right? Because otherwise this malware starts moving around laterally and it's too easy to do. So is that part of the thinking here?
Yeah, I'm really, that that is the, the premise is that, um, because containers don't contain, if you get an exploit in one container and you're running containers alongside each other, they all have what you call a shared kernel state. So in any environment, you're kind of setting up, there's a shared kernel running your, your workloads. If you get a container exploited, they can pop over to other containers and the shared kernel, which in the current day and age means you burn your infrastructure down.
You don't know where they've gone, you don't know what's been taken, you don't know where they're lurking. And so you have a really, um, unfortunate situation as a, you know, person who's running infrastructure to have to start over. It's not, um, we, we wanna try to avoid that altogether and, and we really should be able to trust the infrastructure that we're on.
And, and that's really where we, we come in, is to make sure that when you're running your containers, if you have a isolation boundary around each workload, and the way we see it is that you should not have a shared kernel state. So we also isolate the kernel, um, that allows you to then not worry about the blast radius at all. And so it really gives the power back to people running a secure infrastructure, um, themselves.
So it's, it's pretty powerful technology. And again, like you said earlier, overdue. So you raised the 15 million, um, I'm assuming you bought everybody at least one beer and but what, what on from here?
Yeah. I mean, yeah, the virtual beer, but we'll, we'll come together and celebrate soon. Yeah.
Um, we actually, so um, we, we closed the series A, um, recently, like I said, with Microsoft. We also had some other investors coming on, um, with Inq Tel as well as, um, mantis venture funds. And then we also had the, our existing events investors from our seed, um, in the Act six per five FPV come back in we act, we actually only raised our, our se our seed, um, three months prior to closing the series A.
Um, the reason I mention that is because I think that there's just a lot of, um, recognition that this is a huge area for opportunity and making things easier. So really what we're focusing on now is our AI products. Um, it's not AI in the way that it runs, it's secures AI workloads.
And so really what our focus is with this money is putting into the further and increased development or, or pace in which we're developing our G-P-U-T-P-U and DPU security offering. So when we're talking about kind of isolation of workloads and them being important holistically, um, over 65% of people are using Kubernetes and containers in their AI ML workloads already. And we already know that the isolation primitives that exist aren't there.
And so we're really here trying to push that forward as fast as we can to make sure that the amount of AI workloads that are being processed now have the same security guarantees with GPUs as, as we want to do with the holistic container environment. No, I love to get your opinion, but we talk a lot about DevSecOps over the years and we make, you know, some progress, but not as much as we would hope. And I have to wonder how much of that is just kinda something we're doing to make up for a lack of a capability in the core platform itself.
So, um, if we can isolate the workloads, can we just have better DevSecOps workflows based on how we deploy the software in the first place? Yeah, I would agree with that. You know, there's incredibly smart people out there trying to do things themselves, but it's with the, with the inability to do something at the base, like at the actual infrastructure level, we will always be in a reactive state.
You know, I think we've talked a lot about, um, or, or the industry has been talking a lot about the proactive measures of security versus the reactive measures of security. And we're putting a lot of DevSecOps teams in a reactive stance and we really need to do better for them so they could spend time doing more important thing. I not to say it's not important, but they're, if we can actually stop it at the source, then we'd be able to enable them to do a lot better work.
So yes, I think that, you know, we haven't really gone down deep to solve the hard problems that's really changing the way computing works, which is really our, our ultimate goal. Um, because we, you can't just keep stacking like the Jenga tower eventually will fall and you know, what we wanna do is be able to like put the foundation back together again so that we don't have that problem where I, I think there's a misconception that it's too far gone and it, we don't believe that that's the case at all. And yeah, if I look around, the bad guys seem to be just sitting around taking advantage of the way we built everything in the past and almost daring us to go fix it.
Right? I agree. I agree.
And we are taking that challenge over here. Uh, and, and it's a hard one. We know, we, we, you know, we recognize the, the depth at which you have to kind of change the way of thinking.
You know, in some ways the industry has gotten comfortable with this idea that, you know, well, we have this alert dashboard, at least I know what's going on, all these alerts, but you can't actually then stop them before they start. And so we're really working to shift kinda that mindset of we don't need to rely on this dashboard. It, it should still exist, but we should have context like what's important, why should we care, um, what's actually at day, you know, at risk.
And we don't need to give any sort of attackers any easier way to get in than we already do. And, and we do believe that we wanna empower the industry with the ability to keep their infrastructure safe from the start. So when you talk about this with customers, what's the part that's the most challenging to help them get their heads around?
I think the idea that this is possible, we, we call it kind of the, uh, 15 minute skeptic effect. And I think it's because we've been in this industry so long to assume that it's not something you can fix, uh, and not do it in, in a way that's not performance inhibitive. 'cause there have been other open source technologies who have tried to do this, but when you try to run it, there's the, you know, 30, 40, 50% performance impact and it's just not a viable solution to use.
Um, but most of what we get through is people being relay, I can run this anywhere, it's that simple. Um, because I think most people believe that to, to create something that really allows multi-tenancy, um, and to, to decrease costs in this way would somehow require some sort of major trade off. And that's been our big conversation starter here, is that we, we have intentionally architected it so that the trade off doesn't exist, um, because we don't believe that there should have to be one.
And thankfully, you know, I, I work with incredible technologists. We, you know, we've been really fortunate to be able to find a solution to this, this problem. And the other question we get is, how come nobody's thought of this before?
Uh, and I think it's, you know, again, you have to have a really deep knowledge of computer history meets the present day, need to be able to architect something like we've done Now inertia's a powerful thing, and yet we are seeing the rise of these platform engineering teams. So is it easier to have this conversation now because so many people are kinda rethinking the way the platform functions? Yes, I would say definitely.
So, and, and also, you know, the, the relationship between platform teams and security is a really important one too. And we found that, uh, for many years it's, they've been somewhat at odds with each other because you're really trying to, you know, a lot of times security tools require this just very heavy, um, large kind of lift. And so if things are slowing down and stuff like that, um, but when you're looking at platform teams, you know, they're really looking to simplify and they're really looking to do things optimally.
And, um, we've been really fortunate as we've come out. We've, we've only been around since April of last year, but we've had great conversations with large enterprises, mostly the platform teams too, because they're looking for this solve and platform teams too are also starting to get the lift of certain compliance measures, like specifically Kubernetes, container based things through FedRAMP and stuff like that. So they have even more interest in trying to make sure that the infrastructure they run is inherently in, in its own right.
Simplistic. Well, folks, you heard in here, Hey, if you keep doing the same thing the same way over and over again expecting a different result, I'd call you crazy. So that's alright.
Have to change the way we do this thing. Emily, thanks for being on the show. Thank you, Mike.
I appreciate it. All right. And back to you guys in the studio.