Enhancing Cloud Security with Tenable’s Lior Zatlavi at KubeCon Paris 2024
Hear from Lior Zatlavi, senior cloud security architect at Tenable, to learn how Tenable is extending its leading CNAPP capabilities to Kubernetes environments to scale visibility and preventive controls across public and on-premises K8s deployments. He’ll also chat about how Tenable Cloud Security is helping to eliminate the barrier to entry for developers, security professionals and security leaders alike by dramatically simplifying technical risk data into plain, easy to understand language.
Transcript
This is Textron tv. Hi everyone. We're back here live at Paris for Cube Con.
It's, it's a roaring cube con. You don't hear it 'cause our microphones are good, but there's like a din in the place of, you know, all these conversations and things going on. I wanna introduce you to my next guest.
His name is Lyor. Let me make sure I get this right. Za Right.
That, that's pretty good. Thank you. Lyor Za Lior is with Tenable.
Is it still Tenable? It's not Tenable Network security. It's just Tenable now.
Right. The company's name is Tenable, right? I'm old, But Lyor Act, when did you join?
10, you came with an acquisition, what, about a year, a year and a half ago? Yeah, That's right. So I'm a technical evangelist for a product called Tenable Cloud Security.
Okay. Um, which used to be ed. So we came to Tenable with the Hormetic acquisition back in October, um, just a few months ago.
Um, and now we're tenable cloud security and very, very excited to be part of this really amazing, large company. Um, such a great opportunity to bring our mission and what we do in cloud security is so many companies and bring this advancement to, to the cloud security world. Sure.
So let, let's talk about that, right? I mean, we're here at Cloud Native and you know, I remember when the cloud first came out, my friend Rich Mogul, who at the time was at Gartner, said a lot of security companies were cloud washing their security companies, their security offerings. What he meant was they were taking what they had before cloud and just pushing it up to the cloud.
But it really wasn't cloud security. Well, it's the same thing I think when we talk about cloud security that was designed to work, let's say, on hypervisors and that whole infrastructure as a service type of environment. Now all of a sudden you got cloud native Kubernetes containers, microservices, it's there, you know, there, there it is cloud, but it's probably closer to like pass platform as a service than it is to infrastructure and, and what worked necessarily for cloud security doesn't necessarily work for cloud native.
Mm-Hmm. Security thoughts on that. And, and why is what you're doing Tenable Cloud security.
Cloud native. Exactly. So I think you're, uh, I think you're right on at making this distinction because the cloud is really amazing new technology.
Um, not that new, but still fairly new. Fairly New. It's maybe 10 years old, 12 years old.
Yeah. Something like that. So it hasn't been around forever.
So there's not like abundant overabundant experience of people actually 15 years old. Yeah. Something like, but it's not like 40 50 in the making that, you know, it really has penetrated, uh, into like the amount of talent that you have out there in the market, right?
Yep. And expertise really is the name of the game. And that really changes, by the way, just what you, uh, just what you mentioned.
Um, because securing cloud native technologies, or even companies that are now migrating their technologies into the cloud, is not just a matter of taking your security tools that you have, and you've been traditionally using them on-prem and then just shifting them, just, you know, moving them to the cloud and that's it. Right? That puts you in not, I would say not a great position because to have really effective, uh, cutting edge technology to secure cloud, you need to be designing it for the cloud.
And it needs to be designed from day one. And I think that was the mission of companies like URM Medic, uh, who started as companies for security of cloud native solutions, right? Because it has to be designed to the client, the new game.
It has to be, the technology has to be there, it has to be fit. Because what it needs to bring to the client eventually is out of the box expertise, right? They need to be getting simplification of really complex concepts, processed very well, very professionally, very, I would say aptly into what cloud technology is.
And for that, it has to be designed for that specific purpose and then bring them like the insights and the direction that they need in order to secure their environments, right? Because that's the thing, it's a very dynamic new environment, very complicated, changed all the time. And you need someone or need a product that was designed specifically for that.
And this of course also applies for Kubernetes, right? This is why it's, it's by the way, it's great to be here in Paris. Always, always a good, always.
It's not a bad place to Be, not a bad place to be, and not just because of, you know, the beautiful architecture that we have around, you know, in, in more than one way. Food, food, good food, good architecture. Good, Good, good.
It's a very pleasant view. Amazing. But also the, uh, I think the company, I mean, the people that we have here, the professionals that come to the booth and we talk to them and we meet them and go, uh, in the different sessions is really amazing.
The kind of energy. And by the way, I, I'm, I'm I I have some trouble hearing you, so, okay. I I hope it's, uh, because of all the conversation around No, no.
Luckily the mic's are good. They hear us. That's what counts.
That's, that's exactly it. Um, so amazing. We get to talk to so many people who live and breathe, uh, cloud leave and breathe Kubernetes, which is an amazing technology and really, really significant to be securing it.
Um, and that is, that's why it's so exciting to be here, you know, for people who do that. It's really exciting to be here, and it's really exciting to talk about the new things that we bring out and how they help us accomplish that mission of se, of helping our CLI customers, securing their environment. So any news from Tenable here at this show?
Yeah, so just, just right before, uh, CubeCon, we actually announced, uh, a bunch of features directed at Kubernetes security, um, that I think really showcase a lot of the power that we have in our mission. So, but before, I'm gonna talk about that, I just want to express one more thing. I think that, um, technology like the cloud, as we mentioned, they're very complex.
They have a lot of, they have a lot of potential to them, but they're very complex to manage. And complexity is an enemy for, for security because, you know, when something is complex, when it can go wrong, it will go wrong. It's hard enough to do when it's easy, it's impossible to do when it's hard.
A hundred percent agreed. So in order to have the ability to get the kind of control you need, as we mentioned, the kind of technology that was designed, uh, specifically for that. And that by the way, is specifically true about Kubernetes, right?
Because if you have cloud environments thinking about, you know, Kubernetes and the kind of complexities that there are there, they sort of get to a point where a lot of security professionals who aren't Kubernetes engineers, they don't live and breathe the yaml. Um, and the kind of configurations and, you know, it, it, it is very, very, uh, complicated technology. I know, uh, and it might put them a bit at, at a loss, right?
When you in, you're a security professional and you're not well versed in that and in a technology that you need to protect, you're really at a loss with, um, when you work with the infrastructure people in your organization that they have, of course a lot more experience there. And, you know, you come, you kinda wanna, if you think about it, put restrictions on what they can and cannot do. And of course, business always wins.
So that's a big challenge. Yeah. Um, for, for, for a lot of these, uh, for a lot of these security professionals, this is how we support them, um, by doing the analysis automatically, by connecting to the clusters, um, as we connect to cloud environments and doing the analysis and presenting it in very, very readable and consumable way, and also actionable that they can take the kind of output that we get and allow them to really use it.
Um, and also have like a common language because you don't have to be a Kubernetes expert, for example, to use our product and to understand the problems that it communicates and to understand how to, to, to support them. If you are a security professional, that's great because you understand the security context, you understand the problems, you understand it meaning and the context, and then you can use it in that aspect without being, uh, a Kubernetes expert. Of course, you always need to, uh, advance your skills, right?
So, um, but that get like a very, very good platform and benchmark to do that. I Love it. Yeah.
So that, so that's in general, and I, I think that the, the, so the new things that we released, uh, are really in evidence of that. Um, so first of all, we, uh, just released the ability, um, just announced the ability to, uh, connect to on-prem clusters. Uh, so not just clusters managed, um, by managed services, for example, like E-K-S-A-K-S-G-K, uh, or even clusters that are deployed in cloud environment.
Uh, but also clusters that are deployed on-prem, um, which allows us to bring our abilities, uh, our abilities to there. So, um, one thing that we provide is, for example, really deep, uh, visibility, which again, very easy to, uh, to consume, even if you're not that familiar with all the kinds of resources. And now they interact, you can get them in a very clear way, right?
Um, but not just that also analysis of the kind of security issues that there are, um, with the cluster and contextualize into the best practices that there are for, uh, for Kubernetes clusters as we do for like the entire cloud environment. Um, and in that aspect, I think it's also very significant to understand that the kind of insights that we give are not just for the cluster, but also for the cloud environment, which it is a part of or integrates with. Yep.
Which is also very important because we are able to tell the entire story, um, using that, right. Using that, that exact thing. It's a big thing.
It's the, it's the whole, the whole ease of use. Look, it's been, it's a long story in security, right? And, and it's also part of the reason why we look at DevSecOps, for instance.
You, you can't expect non-security people, you know, for non-security people to use security tools that are so hard that even the security people don't use. So that whole visibility ease thing is important. Where can people get information on this?
Um, so going on our website of course, and we just released a blog post about that feature. And yeah, also the other feature that we're gonna talk about, um, and if they're at Cube Con, they can they Come by? Your booth Can come by Booth this live, maybe they're watching.
Uh, I, I sure hope so. I mean, if they can grab me while we're here. I mean, once we're done with The interview, now run.
Yeah. Um, so one more thing that I wanted to talk about, um, is, um, something that a lot of people have been really excited about here at the booth when we met them, um, is there is a concept in a Kubernetes cluster called an admission controller. So that's a component that you can deploy that is basically part of the pipeline of the deployment of new resources.
So when you do coop control applied, it actually goes through, uh, that as a validation station. Um, so what we are able to do is allow, uh, customers to very easily deploy their own admission controller and configure policies. It's based on something called Gatekeeper.
Gatekeeper. Yeah. Um, which is, which is great technology.
However, it could be a little overwhelming for people to deploy and then manage, right? So instead of having to deploy it themselves, they can can configure it within the product. It is then deployed to the cluster and they can manage it in an intuitive, uh, interface that allows them to configure the kind of policy that they want, the admission control to, uh, to, to enforce.
Um, which is really great because again, a lot of people can make a lot of benefit from such a feature, but sometimes it could be a little hard to get started with. Right. So they can do it in Intuitive, uh, in the intuitive interface if they want.
Uh, they can also do it in the regular language by, by opa. Sure. Uh, which is how it usually is done, so they can do it in raw form.
Okay. And, and then they can deploy things and uh, track the logs of how it worked And done a lot with. Yeah.
Excellent man. Yeah. Good stuff.
Lior, thank you for being on our show. Thank you so much for having me. This camera right here, Lior Z from Tenable live with us in Paris.
We're gonna take a break. We'll be right back.