John Tonello, Tenable | KubeCon + CloudNativeCon North America 2023
Ermetic is now Tenable Cloud Security! In this conversation, John Tonello explores what Tenable Cloud Security has to offer to developers and cloud security professionals.
Transcript
This is Textron tv. Hey, we're back here live on wrapping up our last day of coverage of CubeCon. Hope you've enjoyed the last two days.
You know, Mitchell, Ashley and I have probably interviewed 30, 35 people in the last two days, and, uh, it's a lot of people, but I think, I think it, it was some great stuff, some great content, and we hope you, we've given you a flavor of what's going on here on the show floor this year. Um, my next guest is John Ello, 10 Ello. John is with Tenable.
Is it still called Tenable Network Security? It's, You know, that's, no, it's, we're just tenable. Just tenable.
Um, but that's in our roots, you know. Okay. So there's a lot of people that still say that.
I still do. Yeah. But, um, it's tenable.
And look, full disclosure, I, I've been working with Tenable for 20, Yeah. Since I think Ron er and, and, uh, Reno started Tenable, the founders. So that'd be around 2001 maybe.
I'm going to guess. 'cause that's when I had started my security company. But of course, today's Tenable is very different, John.
It's than just the Nessus company of 25 years ago. Tenable has kind of a soup to nuts type of security offering, right. Um, that a lot of people may not be familiar with out here.
Right? They may still think of Tenable as scanning or whatever, but there's a huge cloud security component. There's, there's a full range of Tenable, right?
So, not to put you on the spot, right, but tell 'em, You know, we get a lot of people that come up to us, you know, conferences like this in Q Con, they're like, oh, we've, I use Nessus in college and I use Nessus in my first job, and now I'm doing, you know, things that are a lot different and have a lot different longer titles, uh, and all that jazz. But yeah, technicals started over 20 years ago and, you know, became a defacto standard. And it's, it's nice to see folks coming in like, oh, I know Tenable.
But a lot of people, um, you know, it used to be an Oldsmobile commercial. It's not your father's Oldsmobile. It's not your Father's Tenable.
Um, moved well beyond just vulnerability management because the world has moved beyond vulnerability management. You know, I used to work for a regional optical network in New York State, eer, ethernet Uhhuh, um, and, you know, big part of internet too, uh, that infrastructure. And we had wide open networks.
And as an IT director at that time, you plug something into any one of our ethernet ports in the office, and it was on the raw internet. And you, you quickly learn that, wow. Um, the internet is a very dirty place.
Um, and then as people evolve from a data center to, okay, now we have devices on our factory floors, we're using the cloud, of course, we're not using one cloud, we're using multiple clouds. We have web apps that are, you know, primarily Tenable has evolved to, you know, not just chase that, but lead it. And having 20 years of data that we've gathered from what has happened, you know, that flows now up into Tenable one and gives customers really not just an isolated view of their risks, but across everything that they're doing.
'cause like you were saying before, al like no one's Greenfield. Uh, you know, like what a beautiful thing to be able to say, Hey, we're a brand new company. What's put up a Kubernetes effect?
Right. Let's start with a blank slate here. Give me my dream.
Right. You know, that's a, that's equivalent to candy and no beets and spinach. Yep.
Um, you know, so there's an aspect of that. Um, but, you know, security is hard and, uh, not getting any easier. A lot of the folks here at Q Con are developers who've been tasked or told, Hey, you have to worry about security.
Um, you have operations guys and gals that are having their roles shift and they are looking for ways to consolidate the tools, simplify the tools, um, just have a, a faster, easier way to solve the problems. Get rid of the noise, not have to write scripts to, you know, or queries to get there. Um, and that's what's exciting about our acquisition of Reeds, which, Well, okay, let's mention that.
So the acquisition was announced, what's about a month and a half? Uh, yeah, October 2nd, I want to say less so a month and a week, something like that. So let, let's start with this.
You know, our audience is somewhat diverse. We might have DevOps people, security people, cloud native, but we also have people who are into, you know, digital transformation and at a higher level. And of course, everything's AI today, right?
Um, but they're not, may not be familiar with her. Medic is the point Or medic, uh, Tel Aviv based, uh, company in the security space with some real great expertise, particularly in CCAP. So, you know, you're looking at the cloud native application protection and all the acronyms that, that fall under CAP.
But the, uh, I think what or Medic really nailed, not only from an understanding of, you know, the security challenges, but how people want to interact with that, which is in an easy interface that gives you a lot of power, um, that, you know, focuses on identity. And because we know that entitlements and identity are where bad people get into your systems. Sure.
So looking at that, um, and the Kim offering, uh, that's, that's part of what immed brings to the table. Um, it's really great. It enhances what we already have, not just our, our vulnerability management, but our working with infrastructures.
Code Tenable acquired Acura a couple years ago. Sure. Did.
Infrastructures code, actually the Acura, CEO was here. Yes. Former the founder.
Yes. He was here yesterday. And we still have the, the open source project of Terra Scan.
Yeah. Which, um, here at CubeCon is very popular, right. 'cause you can scan helm charts, uh, Terraform code, docker code.
And that idea of shifting left it's tired term almost for a lot of folks. But it's really the idea that the earlier you fix stuff, the earlier you have visibility in your problems, the better off you are. And for developers, folks that, you know, it's a big chunk of the audience here.
It's not everybody certainly, but they want tools that match their IDE, you know, it could be done in their IDD that doesn't add a whole new workflow to them. Um, both the medic and and Tenable understand that, that the ability to give many different people within a company access to not only the tooling, but the reporting. Yeah.
Without having to be, you know, what I would consider, you know, guru experts to do that stuff. You know, John, it, it, I've been, as I mentioned, I've been at security many years, did a lot of federal government work. And the federal government, when you go talk, especially DOD people, it's about the mission.
And when I hear you describe what Tenable's doing, what Tenable today is about, to me, it's, it's really clear, look, the mission has changed. It's not, it's not enough to just scan your applications and fix vulnerabilities. The people who are carrying out the mission have changed.
They're not necessarily security professionals, right. Who live, breathe, and die CBEs and, and GDPR compliance, you know, these kinds of things. Security's everyone's responsibility.
Starting not even with the developers starting before the developers. Yes. Yeah.
We call 'em platform engineers, but we've always had them before there was a thing called platform engineers. We always had people, architects and systems people that were setting it up, security's their issue, developers, it's their issues. It's the ops, it's the DevOps.
Right. It's the, it's the SREs. It's, it's really, it's everyone's, yeah.
And I think a lesson though that I've seen, you know, we're from where I sit and I, I have a good seat. I don't, you know, I don't have to do sales or sell a certain amount of security products. Right.
But from where I sit, I, I think, think the biggest thing we've seen is that people are, They, they recognize that everybody needs security. I'm trying to think of the right way to say this. Everyone needs the security that they're comfortable with.
So in other words, the security professionals tool doesn't suit me as the developer. It doesn't Exactly. Doesn't suit him as the ops person.
Right. Doesn't mean I shouldn't be involved in security. Doesn't mean I shouldn't have a tool that helps me with security, but not that tool.
Right. And I think today's successful security companies recognize this. And whether it's the same nugget under the covers, just with different interfaces or it's truly separate things, but they work together, that's what we need.
Yeah. And the inverse is true too, that the security guy, uh, and team doesn't necessarily know the cloud. No.
You know, like, uh, and, and if you know, one cloud doesn't mean you know, all the clouds. Um, and they're all different. Yeah.
And then, uh, they all have their own nomenclature and who can afford, you know, experts for every single task. You, you can't, Well, that's something that hasn't changed. Its security is we can't, generally, most organizations, maybe the Fortune 50 can Yeah.
But most organizations cannot afford the security expertise across the whole spectrum. Right. That they would need.
Which is why look at, you know, my last company we pivoted to become an MSSP. 'cause I, I recognize that just selling them product half of it never got installed or got installed and never used. Yeah.
Because they didn't have it. They didn't have the ability to run it. Even That's the thing where Tenable, you know, has made a commitment long term to its customers to be on that journey with them.
Yep. To say, you know, Hey, you're benefiting from what we've learned from all of our 40,000 plus customers in this space. So that when we are giving you best practices or tooling, it's with that bigger picture in mind.
We know where your, your challenges are. Um, we know what threat actors are, are trying to do, and you know, we're giving you tooling that, you know, simplifies it. But, you know, I always hesitate to say simplify.
'cause it can be misconstrued with, um, being a broad but not deep solution. But I used to back, you know, back in the early web days, I used to say, it's easy to create a website that's hard to use, hard to, yeah. Build a website that's easy to use.
Well when, when those things come together that, that ease of use, but power, um, you know, across a lot of domains that like you're describing and for a lot of different users, um, that, you know, becomes where the rubber hits the road. Agreed. I agree with you, Matt.
Alright, so we, we covered a bunch of stuff here. I want to do a little bit of a recap and, and give some people some homework. Okay.
So we, we mentioned the recent, uh, acquisition and, and what that means for cloud native application, uh, security and so forth. C that it also brings a really great ui Yeah. Right.
To the whole tenable thing. Where do people go to kind of see that in action and maybe kick it a little bit? com is our main, uh, URL and under there are the products.
com/terra scan. There's a sandbox Great that's freely downloadable and it's a very popular, uh, tool and you know, the number of forks and downloads that Terra scan gets because you can integrate it into your CICD platform on your work stage and do all those things. Um, that, um, run Terra Scan io is its own site.
And you know, we're always looking for contributors as well for that, uh, project. com. You'll also see some, uh, content on Hermetic, uh, which is now branded obviously as a tenable company.
Uh, there's, there's a lot of resources out there. Fantastic. John, thank you for coming on.
I know this is your first time on text on tv, but you know, come back and visit us. It doesn't have to be at one of these shows, Pete, be happy to. Yeah, we do it via zooms and remotes every day of the week, so.
Right. Pleasure, pleasure. com here at CubeCon.
Hey, we still have a few more interviews left to finish out the day. We'll see you, uh, back here in just a moment. Wrapping up day three, coverage.
Stay tuned.





