Veracode’s Brian Roche on Driving Innovation with AI
The safe adoption of AI technologies to fuel rapid innovation and business value is exactly the mission the talented and passionate Veracode team is committed to solving for its customers. Newly appointed CEO of Veracode, Brian Roche, discusses how the company will deliver on this mission.
Transcript
This is Textron tv. Hey everyone, welcome back here to Textron tv. I am really happy in his first interview here as CEO of Veracode.
He's been not here before. Before that though, let me introduce you or reintroduce you to Brian Roche. Brian, welcome and congratulations.
Thank you very much. I was the chief product officer the last time we talked, which I can't believe it's been two years. So thanks for having me back, Alan.
Absolutely. Well, I told him I won't have Brian back here until he gets some kind of promotion. And look, they went and made you CEO Yeah, Yeah, Yeah.
Go Figure. Until he helps customers with the problems they have today and, and yeah, I love it. Uhhuh.
Good stuff. So, Brian, look, well, let's start here. Brian Roche, CEO of Veracode, has a nice ring to it.
You were formerly CPO for a number of years, as you mentioned. Uh, give people a little bit more background, a little bit more of your journey, if you don't mind, Brian. Sure.
So listen, the first thing I would say to you is, um, it, it's a privilege and an honor to be the CEO of of, of Veracode. We were just talking before we got started, Veracode kicked off this market, this this market segment that we call application security testing. And we did that 17, 18 years ago.
And the position we find ourselves in today is a position of strength. And that's largely because of the, the position that Sam left us in. And I feel, feel very, very grateful.
And as I said, privileged to be in this position. But, uh, the world has changed and Veracode has had to reinvent ourselves numerous times now, and, and certainly over that, that 17, 18 year period that one of those reinventions more recently has been our developer experience changing how we show up and how we build our services. But if we take it to a macro level and we look at, at, at what is happening in the market today, uh, customers are, are, are facing, obviously AI is, is, is prevalent in, in top of mind to them.
They're leveraging large language models and code generators. And what that does is, at a macro level, customers are saying, listen, I, I have all this risk and, and I need to figure out how to secure all of it. Uh, but first I've gotta find it.
And once I find it, I've then gotta prioritize it. And, oh, and by the way, I expect to be in a position that's worse than where I am today, which is I have too much risk and I need your help to burn it down. And so if I were to articulate to you what our mission is, it remains the same.
It is to secure the world software. These are board level discussions. This is, this is board level risk that we're talking about.
But the way that we do that is building the application risk management platform that is the most comprehensive solution to enable customers to get after all of that risk and fix it. Whether it's running in production or it is, as we often talk about shift left on a developer's desktop, and we'll dive in more into what we're doing, the area of AI and the advancements we've made. But at a macro level, I mean, this is where we're at, right?
We're, we're solving the biggest problems, the biggest security problems in the world today for our customers. Absolutely. I wanna dive more into ai, but before we do, Brian, I I want to just, you know, go 50,000 feet for a second.
You mentioned Veracode in many ways help define what we now call AppDev, or not AppDev, that's another one. That's application security. AppSec, right?
Yeah. And you know, and, and, and frankly, some of the research reports and stuff that I, I talk to Chris Eng about all the time, you know, they reflect the years of, of really looking at this market, understanding this market, understanding what the state of technology is, understanding the adversaries, right? As best we can, um, understanding what corporate goals are.
And as you mentioned, AppSec has evolved, right? It used to be pen testing. It used to be, you know, I remember it, it was, it's very different than it is today.
You in many ways, the people using your product have really evolved. It used to be only the security team. Now we're having the testers use it.
The, the developers themselves. It's built into the IDs, right? And the IDs themselves may be built into Git or some other repos and stuff like that.
The whole 17 years ago, we didn't, we might have given lip service to it, but we didn't have a software factory that we, today software for the most part, or a large part, is developed almost on an assembly line. And we have pipelines, right? We have software supply chains, and, and you know, the whole way CI/CD and the way we do these things, and with every one of these innovations and advancements, if you wanna call 'em in advancements, there's new, there's more attack surface.
There's new security vectors that companies like Veracode have had to, uh, you know, respond to software supply chain. I, we both, you know, back from RSA just two weeks ago or a week, I don't even remember a week or two ago, my, my Brain. It's a blur.
Yeah, it is. Um, but software supply chain is man on everyone's lips. So you're the CEO, now you're responsible for charting the course.
How do you balance all this stuff? AI software, supply chain, security, um, shift left, you know, the, all, all of these and, and yet more. The other thing is tough economic times.
We're moving to, people want less vendors. We want platforms for some of this stuff. Everything has an API attached to it.
How do you, man, it's chaos, right? At, at some level, that's a whole nother thing. Yeah.
Chaos engineering. But how do you, how do you put it all together and chart, chart a course here, We, we can talk about chaos and, uh, chaos slimer and, and chaos testing later on. Uh, look, I, I would answer, I would answer that to you in a very simple way, is a way that you navigate what you described, and I would agree with a very complicated market, landscape and tool, and technology landscape is simple.
You focus relentlessly on your customers and you listen to their challenges. And you and I both just got back from RSA conference and, uh, there wasn't a single customer that didn't, didn't say to me, I need to reduce my security spend, and I love Veracode, but I'd like you to do more for us. And by the way, you're already doing more.
You're already building a better developer experience. That's point number one. Point number two, you're already recognizing that the tool landscape is collapsing.
It's coming together. We're no longer looking, we're distinguishing between what is a rebo versus an IDE versus a pipeline. They don't care.
They just want security to be pervasive, but delivered in a way that doesn't get in the way and is not invasive to developers, but still enables that speed because they can't afford to trade off speed with security. So you gotta make it easy. And then the third one, which we talked about is you gotta help them on errors, all of that risk because you're, you're, you're essentially increasing the creation of vulnerable code by leveraging auto code generators and artificial intelligence.
And we know this to be true, right? We, we know large language models aren't, aren't particularly good at a general level and creating code. And we know they're not.
When you ask them for a suggestion, thinking, well, does this code need to be, uh, secure and, uh, performant and of high quality? And, you know, and all of the, all of the ilities, I guess that goes into software engineering. Um, so today they're not there, but everybody's leveraging AI is a competitive advantage and, and going faster.
And so what we do, and how I navigate it is you get up close and personal with your customers and you talk to them about the challenges that they face, and they're only too willing to partner with you because they need to solve them. And we have been that trusted partner for 17 years, and the differentiation that we've provided in our low false positives with SCA when we went on, uh, to, to provide supply chain visibility and to, quite frankly, turn all the lights on and illuminate. So there's no hidden risk in the room, uh, the supply chain.
And then we've continued to invest there in helping them import, export, redact information, better manage, uh, supply chain, uh, issues, and, and create visibility with their vendors because we recognize that, that there was an executive order that dictated how they needed to respond and to act. And so, I mean, I can keep going down the list, but the other thing I would mention is we're now helping them in the area of long BO Security and in Veracode Fix. And they said, you know, part of the, part of what informed our vision and strategy was we want to be the application risk management platform that both leverages artificial intelligence, but enables security in an artificial, in an AI era.
Because that, that's the place they find themselves in. 90 plus percent of developers are using some form of code generation or large language model. And that is increasing the risk for, for organizations today, 35 to 40% of the code that comes out of copilot is known to be vulnerable.
And you mentioned Chris saying as a, as a regular on the show, and Chris at Veracode leads our sauce report. And we know from our sauce report, I'll pull out two key areas of data to underscore this point. We know that organizations, if you look at the totality of their applications, at least 70% of them have some form of vulnerability.
But listen to this, Alan, and for everyone that's, that's tuning in 45, almost 50% of those applications have a critical exploitable vulnerability. So at the top of the show, when I say we help customers with board level discussions around risk, and we help them with, with, with the biggest security risks they have, that's what we do with the long boas security. We now find all of that risk wherever it may reside across multi-cloud environments, Google, uh, you know, AWS, it doesn't matter.
We identify all of that, and our core differentiation is taking, you know, what is apple's, oranges, and chainsaws? You know, it's, it's all this disparate risk. It is containers source risk and prioritizing that in context so that they're not staring down that risk of almost 50% of applications are vulnerable.
They're now saying, I got it. Thank you Veracode, for producing that, that, uh, visibility for me. And by the way, thank you for delivering all the capabilities you provided have provided to date, but now this AI recommendation tool called Veracode Fix that now remediates and offers suggestions for the most common vulnerabilities.
And at the end of the day, right, if, if you stopped, if you took them down halfway through my answer, the bottom line is it's the easy button for what is and what you just described as an an incredibly complicated tool landscape, technology landscape, and, and now AI landscape, which is going to impact the software development lifecycle and how we build software. So look, we, we couldn't be more excited to be at that intersection of board level risk. And the biggest challenges they face in a time when they, they, they can't afford to be increasing their security backlogs.
We are delighted to be there with a solution that we brought out last year. We were the, at the R State conference, we were the top five most exciting technologies. And this year we brought long boas security for that visibility, and then we brought it all together.
And that's what they're looking for. Help me to reduce my spend, reduce the number of security tools I have, bring down what feels like a marathon of alert fatigue, and by the way, provide me what is the, the, the, the water, uh, purifier for, um, code risk. So Veracode fix, if you, if you think about the water that comes out of your town or your, or your cities, um, uh, faucet, we are the water purifier.
We have the, with that middle layer strategy to secure all of the code that's coming into your IDE and all of the code that developers are producing and putting into, into their code bases. So, listen, it's a good time to listen to your customers, and it's a good time to be in a, in a very lean state where you can pivot to what they need and answer, uh, and and meet them where they are today. Absolutely.
Yeah. I, I just wanna mention, um, our crackerjack team of off camera editors. I just saw the comments Yes.
Yeah. Brought it out that, um, long longbow, well, you, you mentioned long, you referenced Longbow a few times in there. Longbow is a security company that Veracode acquired, I guess it was around the beginning of April.
That's right. So listen, we were on this, um, the last time I was on the, on the, the show. I talked a lot about thank you, Ted, for putting that in the chat.
I talked a lot about the need to provide visibility. And in, in many respects, we worked with Gartner and Forrester and all of the analyst community to, uh, identify what we knew was happening was markets were colliding. So what was formerly known as A-S-P-M-C-S-P-M and risk-based vulnerability management, these are all coming together.
And by the way, if you take a customer centric approach, a customer doesn't care about the market segment. They, they, they just care that you're solving their problems. And so, when I go back to listening to our customers and acquiring an asset that is best in class to be able to solve the problems they have, that was long BO security, long BO security, if you haven't checked it out, is this gorgeous UI that takes all of this risk, all of this disparate risk I talked about, and it prioritize it, it prioritizes it in context.
And then we took all of our AI in the form of Veracode Fix, and now we're starting to remediate that risk. And, you know, that's not all it does in terms of risk visibility and risk prioritization. It also has connectors into all of the tools and technologies in the ecosystem that, that our customers and our partners use today.
And so it acts as this phenomenal hub and or this single pane of glass view for you to get your arms and your mind around what, what is the risk within my organization? So, uh, yes, we acquired it in April. We, we looked at for Alan for quite some time for a solution that would provide us with, you know, both a gorgeous u UI and experience that appealed to our core constituents of security teams, but also something that developers would, would want and would use because we've gotta make our tools and technology and services, uh, appealing and available to all of the constituents that we serve.
Uh, you know, when we focused on reinventing our developer experience last year and we've delivered it, I happen to have a CISO round table in Europe, and they said, uh, one of them said to me, I love all the chairman windows, I love the IDE. I love that you brought static into the IDE and SCA and now Veracode Fix. But don't forget us, forget about us.
We're, we're the CISO community. We, we, you've gotta cater to the security teams as well, so that you, that's who we serve, and we've heard them loud and clear and long Bos our answer to that. Very cool.
Absolutely. Ryan, you, there was a lot packed in there to what you said. I wanna just, uh, peel out a few things.
Number one, this isn't a Veracode issue. This is a security industry issue. And I've been in security myself for 25, 30 years.
Um, every year we spend more and more on security. Security's a top priority all the time and, and this year more than, and there's always a little pushback, right? No one ever raises, I've never seen a security person raise their hand who says, they gave me more budget than I knew what to do with.
Right? There's always, I need more. We're good.
We Yeah. Or we're good. We've gone the Risk, we're good, we're good.
Keep that money on account for next year. Yeah. You know, you never hear that.
But nevertheless, this year, more than in other years, we're really starting to hear, Hey man, this gravy train has gotta slow down. We are continually buying more and more security tools, continually amassing more security vendors and continuously we're not seeing our rift necessarily approved. In fact, there's more breaches and ransomwares and, and incidents than ever.
Yeah. And what's the sense, are we just throwing good money after bad? And I think, look, you're the CEO, so the buck stops there.
Mm-Hmm. As an industry though, we, we need to, you know, deal with this, your, your, your thoughts. We do.
I, look, I, I'll acknowledge this point, gets point well taken. When I first came to Veracode, you know, one of my assessments was, do we do a good job of, I won't call it promoting, uh, but, but articulating the value that we provide. And, uh, I, I'm, I'm fortunate enough to be CEO now of a company who is, um, very mission driven.
We, we are, we are driven to tackle the hardest security problems and deliver solutions for that. And the team is relentlessly focused. And it, it, it wasn't, what they weren't focused on was telling the world, uh, how great we were.
'cause they certainly looked at it as self-promotion. And we stepped back and said, but you know, CSOs and security teams need to be able to talk about at the board level where they are. They need to be able to come into the, to those meetings and essentially say, this is how I assess my risk across all of these attack surfaces in these different contexts.
Whether it's perimeter, whether it's the applications, whether it's the network. And I'm able to assert that we are good or not. And when we stepped back and sort of lifted our head, we started to implement in the platform capabilities like peer benchmarking, so our customers could look at how their peers were performing, how their industry segment was performing.
And, and that was the first aha moment for us, that there was this, this overwhelming desire to be able to communicate the value of the program that they had put in place. And we since then have moved on to providing dashboards and visibility so that you can answer that question of like, listen, this is, this is how Veracode has made us faster, but also more secure and enabled us to burn down our technical debt. And I would say that at no time is that more true now, where we're moving away from dashboards to just going ahead and fix it.
And that's in Veracode Fix. And we're now able to qualify that, you know, Veracode Fix is able to tackle 50 to 70%, uh, of all of the vulnerabilities in your backlog. And so Alan, like, think about this for a second.
net, go lang, we support, you know, so many languages, but we can take the languages that they are using, whether it's legacy or new languages, and put them side by side and say, would you like us to take Veracode Fix and provide you with fixed suggestions for 70% of that risk? Alan, this is a, this is a game changing conversation because we're going from alert fatigue to creating visibility to now offering solutions. And, and, and our customers are like, this is what we need.
This is the easy button, and, and can you deliver it in a way that our, our developers can get access to it quickly and easily? And the answer to that is yes. It's in the IDE, the fixed suggestions are there, whether they're typing code, pasting code in, whether they're auto generating code, or they're just opening an application, they have an open for the last three or 10 years, it doesn't matter.
We can attack that risk and, and understand that risk for them. And so your point is well taken. A lot of the vendors in this space that we used to call application security testing have missed the mark in articulating the value and showing them that, uh, where they're, where they're vulnerable.
And I'll pleased to say we're no longer there, so it's a good place to be. Excellent. Hey, Brian, I, I'm sorry, but I catch you much longer than the 15 minutes your people, uh, committed to.
No problem. To, I apologize, but it was a good discussion and I think it was a great way to kick off your first appearance here as CEO. I hope that you, obviously this is not gonna be your last appearance.
Yes, hope so. On Tech TV as CEO. So come back soon to us, let's continue this discussion.
Very good. Thanks Alec, for having me. And thank you to everyone for listening.
No problem. Brian. Congratulations.
I think, think Veracode's done a good thing here, picking you as CEO. Looking forward to where this ship goes next, say hello to all my friends at VER Code. Will do.
Thank you. All right, we're gonna take a break here on Tech Trunk tv. We'll be back in just a moment.