Shantanu Gattani, Tenable | KubeCon + CloudNativeCon Europe 2023
Tenable’s senior director of product management Shantanu Gattani talks cloud security and the evolution of Cloud Native Exposure Management. He also dives into Tenable’s open source project, Terrascan, and how Tenable Cloud Security is bridging the gap between security teams and developer teams and enabling DevSecOps through comprehensive CSPM and KSPM capabilities.
Transcript
This is texturing TV. All right. Hey, it's Alan shibble.
And we're back again many thanks to our chief content officer. Mike pizzard for doing a double duty with me here at kubecon. It takes the load off, but I'm happy to be on it on in on this next one.
I want to introduce you to shonta new katani. Katani and I hope I got that right. Yeah, it was good.
All right, Sean do is with tenable and and I I know think tenable network security needs an introduction to our audience, but it's always a company. I enjoy interacting with I Friends with Ron gouler who wanted the co-founders? Absolutely.
The Renault and and Jack but of course the tenable I worked with 23 years ago. It's not the tenable of today though. There's still that base.
but We should start with you shot didn't give the people a little bit your background. And what do you do with tenable? Absolutely, so I'm with terrible.
I do product management for our Cloud native security solution and it's been a long journey. I've been in tech for I've been in security for almost 20 years now been a developer which is why I love being at a place like this, you know, it's a fantastic place so much good energy around everything cloud and Cloud native and I've been in product for the last oh God 10 odd years now, so it's been amazing to see the journey, you know on both sides absolutely and you know, look I assume everyone knows about tenable, but maybe they don't or they're not sure. Yeah, we should get a little absolutely absolutely so tenable has been you know, we we did our bread and butter and we build our base in vulnerability management and that's the four day.
That's what animal has been known for but the last two years or a little over tannibal's been on an acquisition. Spree and what we've done really well is acquired different sensors that look at all different categories of assets. So we have a cloud native solution.
We have a solution that does active directory security. We have solutions that do web application and we are now able to look at vulnerabilities and security posture issues across all of these things under one umbrella, and that's what tenable's new exposure management platform is that's what number one is. excellent And so the platform is called tenable one cannibal one.
Yeah, so make sure we get that out there absolutely attainable one so You know, it's interesting you you as a developer get excited being here at Cloud native. I get excited because this particular Cloud nativecon seems to be aimed not just exclusively at Developers. For that sres and platform engineers and security obstacle and all the folks who are you know, kind of pulling the levers pushing the buttons and checking the metrics.
On making sure stuff's running. It's it's the Ops. Yeah piece of it if you will.
But you know, we're in day two here. What what has been like some of the stories that kind of grabbed you or some of the topics that you found interesting. Yeah.
That's that's great question. And you're absolutely right the diversity of people at this show is fantastic. Yeah, and you have everyone from people who are hands on keyboard writing code creating applications to people who are running them and scaling them.
I think something that struck me this morning during the keynote and the Keynotes were fantastic. I'm sure you were you were attending as well. What struck me though is this is a very rich open source Community that's over here and open source, as we know is always on the bleeding edge and some of the things that they were talking about are the same message that we are talking about attainable, right?
So kind of when you find yourself in that place, you're like you're not we're we're saying the right thing right you're doing something right? Exactly. So if you interesting stats that we talked about this morning at the keynote one was 80% 80% of organizations out there today are looking to make sure that they have full stack security right?
We're talking security at at kubecon, which is fantastic and the second stat. Was that more than 60% of the organizations. Our insecurity limbo because they are getting way too many findings.
They don't know what to prioritize right? So you put those two things together and you kind of get to understand what exposure management really is all about. You have to have full stack visibility all the way from top to down from your application to the infrastructure to the code that went into making that infrastructure.
You have to have that across the board for applications for for it Dr. For external attack exposure and you have to be able to prioritize and in order to prioritize you need context across the board. So now when we're looking at a vulnerability, is that a vulnerability on an instance is that a vulnerability with an application that can be used to exploit the vulnerability on the instance?
What are the permissions that are associated with that instance? You have to understand all of these things to then be able to say oh, yes. This is the most important thing that I need to get to first.
Right? And that's what exposure management that's what tenable one is all about helping you understand all of your assets all of the problems that are associated with those assets and which are the ones to go after first. Yep.
You know listening to you talk. You're not look I've been in security a long time myself what I find really interesting is that when we talk about managing vulnerabilities these days it used to be look just scan it and tell me what I got right and then I'll try to prioritize my remediation. Yeah.
And that was an uphill battle for a time, right? Yeah now in this day and age we of course scan and we don't even necessarily scan. We monitor, you know, we we have a better picture.
of what we have than we certainly ever did before but the other piece of it hasn't changed and that is sensory overload if you will, right? Yeah, he sensitization. I used to tell people when I was selling vulnerability management that it was like it was job security for so many.
Oh, yeah security folks because you would run a scan even if you ran a scan once a year, you would deliver a phone book size. List of vulnerabilities and yeah, I'm trying I was living in New York that I used to say. It's like painting the Verrazano Bridge.
That's a lifetime job. Yeah, because they usually start painting that bridge right after New Year's. And they finish right before Christmas.
They take Christmas to New Years off and it's time again. That's what vulnerability management was for a long time, too. now we have so many more tools available to us to help us prioritize really a what should we fix be?
When should we fix it and see we have the ability to automate so much more of it. Yeah, right and to me when we talk about exposure management, I want those three. Kind of dials that I could dial in.
Yeah. To make my life easier. Yeah tenable one help with that.
Absolutely and actually let me let me Explode the complexity of this problem, right since we're at kubecon, I'd be remiss if I didn't talk about how this works with the cloud native and kubernetes, right? Yeah. So a couple more interesting stats for us, right 92% of web applications are now being deployed in cloud and 83% of those are Cloud native, which means it's all going on a containerized environment somewhere, right and in kubernetes gay or you know, K could be for kubernetes complexity.
And I think that that complexity is infinite because kubernetes by definition allows developers and teams Cloud teams to move as quickly as possible with a variety of control planes available to them, right? And that control plane stuff is completely out of control because everybody's just doing what they want to move as quickly as possible to deliver more value, but security teams are kind of getting left behind right? So you're talking about one phone book.
I mean, I don't even think you can finish painting that bridge in two years or three here security jobs here. So what does that do for us now? What that means is that Security teams have to get involved at every stage of the life cycle you have to do as many things preventatively as possible so that they don't go into your environment.
Don't don't get exposed and don't become problems that can be exploited. Right? That's how you start nipping at the bud some of these problems.
But how do you do that? Right and that's that's where you know, you know, the three things that you're talking about become interesting to understand right prioritization absolutely context that tenable one provides will help you understand. What are the what are the different things that are connected to your container to your node?
How do you make sure that you can understand multiple asset types in one finding so that you can prevent that exploit because attackers are not thinking in silos. They're not thinking vulnerability. They're not thinking misconfiguration.
They're not thinking exposure right? They're trying to figure out how they can utilize all of these things to combine into an attack path, right and with tenable one you understand attack pots you understand criticality of your assets. So you understand crown jewels, and you understand what are the most exploitable exposed assets, right?
So tenable want to help you with that, but let's go back into a containerize environment into Cloud native for a second, right? Security teams have to take a posture of governance across the board right when you're in devops, when you're developing an application when you are deploying that application when you're monitoring that application runtime security team has to be everywhere certainly apply the right security gates. And that's where I'll kind of go into my third thing on how right how do you actually do this?
So if effectively really the only good way of doing this in our opinion is having a single policy framework across the board. So you have a security team that is an expert in writing policies and writing controls understanding Cloud benchmarks codifying them in a fashion where these can be deployed when a developer is writing code, right you want to be able to tell them that all that subnet that you're putting in there is not gonna match your compliance policy not gonna match your security policy. When you're scanning when you're looking at repositories of your infrastructure.
When you're scanning your container Registries when you're scanning your pipelines when you're going through a pipeline, you can put preventative measures in place. So then when you're looking at your runtime environment, which are hundreds of thousands of containers, you're not worried about whack them all over there. Right?
And I think that's how you really kind of get to controlling this madness through some some well defined. Well done policies that are written by Security Experts, but applied by the cloud teams. so look I think one of the biggest positive changes.
in terms of vulnerability management is the concept of pre-deployment vulnerabilities management In my day, we had a beg people to scan their existing infrastructure once a year now. The last thing I saw was 80% of all applications are scanned for vulnerabilities prior to deployment. Look, I don't know who the other 20% are but we're gonna don't even worry about that.
They got bigger problems. Yeah, but the fact that 80% is it gives you the kind of stuff you're talking about? Absolutely.
Now you you know, you kind of don't have that gun to your head. So to speak where you've got stuff in the wild. Yeah.
This is still pretty deployment exactly and it gives you that kind of of you know a power. What about automation? So all of this is in some kind of automation, right?
It gives different teams autonomy to run at their own pace to automate out their deployments to automate out their infrastructure, but it gives security teams the the people who want to put some checks and balances in place the ability to do that right have one policy that gets deployed everywhere as you're automating as you're scaling out, you know that you're working off of clean code clean images, right? We scan our environment at this point twenty thousand times a day within tannibal right every single time. Somebody is making a small change tiny change anywhere, right?
So the whole process is completely automated everything gets deployed and scan in pipelines and anytime you say sorry. This is not gonna this doesn't meet you stop the pipeline you break the pipeline you get into preventative mode, but the most important thing here I think is being able to do all of this in one single place because again, you have to be able to take a look at what Vulnerabilities that are in an Ami image which is referenced in your infrastructure as code. So you are able to understand vulnerability and misconfiguration policy compliance all in one place.
You can't do that effectively in different tools, right? Otherwise, you go back to that siled, you know myopic vision of security and that's not what you want. Any other observations Cloud native?
So going back to the cloud native conversation, especially around security right a couple couple more interesting points that I noted in in our conversations over the last couple days. That applying policy as code is the number one problem that customers have and the numbers the second problem that customers have the most important thing is controlling admission controlling access to your clusters, right? So what I would what I would encourage everybody to do is take a look at tenables.
They're a scan open source project. It's 100 built for kspm for containerized environments. We have admission controller as part of that project.
And with that you can look at our policy engine. You can apply the policies at you know, container entry time and and block that right something that I think everybody needs and should definitely look at absolutely. We're we're just about done on time is the sun's coming back out, which is a good sign.
You know, what we didn't tell people you want to get out on tenable one. You want to check it out get started. Where did they go?
com. All the information is available. com.
Look up tenable one. We have a couple different ways to go with tenable one anybody out there. That is attendable.
I/O customer necess user highly highly recommend that they go check out tenable Cloud security how that ties into tenable one how that helps you out and eventually helps you understand your overall exposure and attack pause highly recommend people going to our website and checking that out. You heard it here. Alright, so thank you, sir.
Thank you. All right tenable one here talking cloud native vulnerabilities. We're going to take a break.
I think we're back on and just 30 seconds with Dan Garfield from code fresh. Awesome.





