Shantanu Gattani, Tenable | KubeCon + CloudNativeCon NA 2022
Shantanu Gattani, Senior Director of Product Management at Tenable, joins Mitch Ashley to talk about how Tenable shifted from IT vulnerability management to exposure management with its new Tenable One offering. They also talk about how Tenable formed the Tenable Research Alliance to help customers understand vulnerabilities right as they are announced.
Transcript
This is texturing TV. Hey, welcome Mitch Ashley. We are here at kubecon North America in Detroit Detroit City Motor City.
So we're having a great we're on our second day of live streaming interviews. And with have some more fantastic guests line up. My next guest is from tannibal.
I shot to new guitar. Welcome. Good morning.
How are you? Good good your product man. Director product management.
That's right. Yeah been with Hannibal a little over a year. Now.
It's exciting times of the company. Absolutely it is we're just chatting. I know tenable from the original open source days, and it became a company and absolutron and you know all the history that has So I'd love to talk about you know, we have to go back to the origin story but love to talk about the shift to tenables made into the world of software because yeah, I grew up with tenable.
Yeah as a vulnerability on devices and the software on devices and servers and employ. Yeah, but you know, that's a different world for tenable. Totally The Way Way Back In grad school.
I used to be, you know, red teaming and blue teaming that kind of good stuff. Right and I used to use nessus and you know, all of the tools that came along with that. But yeah, if you think about it right tenable decade ago sort of pioneered the way in you know, it vulnerability management, right and that's what tenable has been known for and that's where we've made our muscle.
But now I mean if you if you're looking at the more recent attack management, you know security organizations now absolutely pioneering our way into exposure management, right? So, you know candles made some very strategic moves in the last couple years. And the new leadership really has brought in all of the right pieces to be able to take a look at the the entire modern attack surface and then be able to manage the exposure in that.
Yeah, so it's very very exciting times table is really evolved into you know, you know a large platform a security platform absolutely part of that is the evolution of tenable one was that announced. Yeah about a year ago or no Temple ones very new very new October is just this October we launch yeah just happened, right? Thank you.
Yeah, I for saw that it was gonna happen a year ago. That's how I knew. Yeah on the announcement.
Yeah. Well tell us about it. So terrible one is all about exposure management and before talking about you know, what the product does I'd love to establish what exposure management really kind of looks like right, you know, not just for cloud not just for kubernetes, but across the board you're attack surface now includes everything.
From operational technology, right, you know Control Systems all the way to Identity all the way to Cloud all the way to you know devices right the the hybrid attack surface, right if you will so as part of that, you know, instead of being reactive, right and security is always been reactive. Right? We want to move to a more proactive world.
We want to we want to be in a place where we're anticipating threats and blocking them before they happen, right? You're putting up the right Shields. So that's that's one major part of it.
Right? The other big part of it is sort of breaking down these silos right over over all of my career, right? You know security is always been right.
Somebody takes a look at one piece. Somebody take a look at another piece. Right?
We all have a lot of the data we all have all the information but have we been able to effectively contextualize that have we been able to effectively correlate that right? That's always been a challenge. So you bring that in into, you know, one single pain in class you're able to take a look at all of the different sensors.
Of the different aspects of security and correlate that data. So we kind of help break down silos and you help establish better communication, right? And I kind of think of this in trees you talk about visualization right find everything, you know, you can't protect what you don't know you can't protect against what you don't know right so visualize everything contextualize everything.
So, you know, what are the pieces that you need to hit on first? What are the pieces that you need to protect against first and then democratize right? So visualize contextualize democratized democratizes, you know, make better decisions faster through better communication, right understanding everything and making sure people know providing them the right tools to solve problems.
Talk a little bit about the iuc tenable fitting into this or flow of how we create software now, right because yeah, you know security has happened. He's happened at all levels whether it's a microservice to container. Yeah, you know operating system virtual image, whatever it might be have so many things so many places where you know, they're vulnerabilities can either come in from an outside Source like a Docker Hub that somebody yeah.
It's the might have a four configuration that didn't get, you know caught or our own code. You know, how do we how do we how do we insert tenable and nessus and all the tools? Yeah.
Absolutely after that. It's a great question. So let's let's take a look at the life cycle.
If you will write. I mean you you always have things that are running that you need to protect right where your crown jewels are where your data is, very infrastructure is right. You always have your runtime, but how did things get there?
Right if we you know, just put that in perspective or in context of cloud things start now in a very different fashion that they use to write. Anybody can put push code to production they can change infrastructure they can change application. So there's there's an entire sort of life cycle here that needs to be managed and it can't just be at the end of the day.
I'm just you know getting ready to push my button to get everything into into prod and oh, hey Mr. Security or Miss security. Please take a look make sure that we're good to go.
Right so it can't just be that you have to absolutely be involved at runtime. Make sure that everything that you have across let's say hybrid Cloud right? I'm cloud guys.
So hybrid Cloud right make sure that you have a good solid view of everything there. But then, you know remediate that fix the problems that you find contextualize intermediate, right? So you have to protect that but then you kind of start looking at how do I scale?
Right? How do I get to a place where I find flaws before they become false and eventually exploit it because they're vulnerabilities, right? So that's part of the whole democratization process and eventually, you know, Street term around that is shift left, right?
You you move things you move your detections earlier and earlier and earlier you find a common language in which in which your Ops folks and your developers and your security folks can talk. And you know, I like to say that that common language is policy you make sure that the people who really understand security can author, you know, those policies that they can establish. Hey here are the things that you need to make sure you do or you don't do right, but then others who I mean I was a developer right part of part of my life was making sure that all of my stuff is conforming and that was the part that I like the least about being a developer right?
I'm sure somebody yeah, maybe somebody's stopping me somebody stopping me from getting my stuff out working. Right? So but now, you know, I as a developer or thankfully, I'm not a developer anymore, but developers need to be able to just know that hey what I'm writing here may not be Best defaults, right?
I mean we heard so much about just in the keynote yesterday number of vulnerabilities is in containers are rising there are up 60% you know, 300 vulnerabilities 30% of them are critical, you know per containers. It's staggering numbers, right? How do you prevent against that just at runtime?
I mean you're going to be doing whack-a-mole forever. So you got eventually be able to help the developer figure that out quickly easily and fast and you know help solve that problem. That's where we come in.
Obviously, we have a full tool set for cloud security at runtime, you know both looking at vulnerabilities as well as misconfigurations in one single place so you can then better prioritize and figure out again, right? What's my exploitability? What's my impact for any given single resource and solve for that first right reduce that mean time to remediation so you can solve your problems fast, that's runtime, but then you take all of that same expertise and start saying right.
Hey, you know engineering Team. This is these are the these are the core principles that you need to sort of adhere to and oh by the way, we are able to plug in into your IDE. So that as you're writing your IAC, you see the little squiggly lines.
I tell you may not be wanting to open everything up to the public Cloud, right? So that's kind of how you get into that whole life cycle and help solve problems before they become problems like real problem. Well, I think that's a big picture for entire security industry.
Just having to make some of made it already is going from kind of point in time scanning. Yeah or filtering things to being part of a workflow. It's automated and security can Define or help put in with the policies are what they yeah, but what Conformity we need to have around certain security aspects But the flow is the flow and it happens without impeding the flow.
That's right, or at least Services an issue at the right time. So somebody can do something about it as opposed to way out the end when you know, by the time you report the the vulnerability it may have been replaced already exactly reporting something that's not even there or serverless. Absolutely that matters absolutely tell us about so the open source world and kind of things that tenable to doing.
Yeah. Yeah, absolutely. So for example has been known for our sort of vulnerability research right and you know being first and you know the best in understanding vulnerabilities publishing them getting the community know about them to solve them, right?
So now tannibals again taking that leadership role. We've formed formed an alliance with you know, private other inaugural members. It's really exciting than research Alliance.
And as part of that our agenda really is to be able to help customers understand vulnerabilities right at the same time as they're being Pounds so vendors working together making sure that we understand and you know provide plugins and provides trips for for solving for that. That's that's a really cool initiative that tenables recently launched and on the cloud side, you know tenable when when they acquired the cloud security company, that's now part of attainable that came with Terror scan, right? So we're the original creators authors of Terror scan.
It's one of the most one of the most engaged communities around infrastructure as code scanning political polyglot code scanning. We provide out of the box policies and it's pretty Vibrant Community is actually training on GitHub. Just just yesterday when I checked so it's pretty pretty cool tool really really amazing Community.
That's that's around it. We absolutely intend to nurture it and continue growing that community and keep that space of thought leadership when it comes to infrastructure as code scanning. Yeah.
I absolutely encourage everybody to check it out. Contribute, you know come find us. It's really really good stuff.
com. Absolutely. Absolutely.
Yeah for a while. It's good to see yeah LeBron and respect all the things that he did with the company. It's good to see, you know, with the changing management accountable continuing to flourish and yeah, absolutely the best thanks for coming by thank you.
It's been a pleasure great and fun talking about tannibal go. Check it out. Wow nessa's Days.
We're talking here. Sorry good time. Hey, we're having a great time here at kubecon talking with some fantastic folks and we've got some more people lined up.
So stay tuned. Don't go away. We'll be right back.
