Payton O’Neal, Apiiro | KubeCon + CloudNativeCon North America 2023
Payton O’Neal and Alan Shimel talk about supply chain security and why it’s so important in cloud-native environments.
Transcript
This is Techstrong tv. Hey everyone, it's Alan Shimmel, tech Strong tv, and we're back here live at CubeCon in the windy city of Chicago. Wasn't that windy out?
It was actually pretty warm this morning. I thought it was gonna be worse. So we're really happy about that.
I am joined by Peyton O'Neill, director Marketing at Aro. Peyton, first of all, thank you for coming. Thank you.
Um, Peyton has been, we've been working with Peyton well long time, even before you were at aro. Yeah. A long time.
And, you know, coming here to CubeCon it, it is about seeing a lot of old friends. Um, API is a company we've been working with for a while too, but I realize, realize not everyone is gonna be familiar with App Piro. So why don't we start there, if it's okay, Peyton?
Sure. Give us a little bit of aro background. Sure.
Um, so api, this is our second cube con, um, north America, um, application security space. Uh, we definitely are, uh, sort of bridging the gap between developers and application security teams, but really trying to solve two core problems. One is that traditional AppSec tools suck.
They create a lot of noise. This is a known problem in the space. Everyone this year is talking about noise, reducing noise, cutting through the noise.
Um, but two, which is a problem we don't talk about as much is all of the processes that AppSec teams rely on. Two, understand their application attack surfaces, uh, and ultimately prevent attacks, breaches, et cetera. Um, so we take, we sort of flip that model on its head.
We're taking a very risk-based approach. Of course, everyone's saying risk-based approach. What does that mean?
It means understanding context of your application and your business to define what really is a risk, and then use that to take action, whether it's, uh, shifting left. So giving that feedback to developers earlier in the development lifecycle or alerting your application security team, or even using, you know, a a, a design flaw, uh, that we determine is high risk to trigger a threat model or even add to your pen test scope. So those are, those are the two main spaces.
And, um, it's kind of an emer emerging market application security, posture management, uh, really just kind of well-defined this year. Um, we're excited to see where it goes next year. There's a lot of vendors in this space already.
If there's one thing AppSec is good at, it's uh, Attracting vendors. Attracting vendors. Well, you know, the argue, so I've been in the security space a long time, as you know.
So from a VC point of view or, or the glass half full point of view is because no one's doing it. Right. Right.
If someone was doing it right, you would have the traditional three vendors and that's it. Totally. Um, so that's the mark of an emerging market Yeah.
With vendors who have not quite solved. And it's a Trickle effect, effect of, you know, you had to the Veracodes and your traditional SA Tool, the old app. So as you said, AppSec was noisy, you know, when we talk about noisy, it, it's more than noisy.
The problem is it generates so much data that it, it's not just the noise, it's the signal to noise ratio. Totally. Right.
So if you have a lot of noise, but there's a lot of no nuggets there, great. But when you have to like, you know, look for that needle in the haystack. Exactly.
It doesn't work. Now some people will tell you, oh, we have AI or we have ml or whatever that finds the needles in the haystacks for you. Again, no one's really, they talk that game.
Yeah. But we don't really see the answer to that. Yeah.
So that, that's an Issue. It's not a silver bullet. Yeah.
So it's both about bringing all of those signals together. So you do have like a unified control plane to see everything in one place. Yeah.
And then our approach, uh, that's a little bit different from some other vendors is going really, really deep on the context. So both in code, so understanding where PII exists, um, being able to extrapolate every type of application component language framework technology, um, and then also connecting to your running Kubernetes clusters or API gateways to get that runtime context. Is it deployed?
Is it internet facing? You need all of these factors to be able to say, this is a risk that I need to address right now, or that I'm gonna block a build or block a pull request for. Got it.
Unfortunately, DevSecOps tried to, to shift security left, but it really just shifted the same problem left. So Well, it it shift. Right.
And well, what it did is it put security on the back of the developer who was probably already overworked. Exactly. I I think what we've seen, Peyton is a lot of, even the AppSec vendors, I, I did a, uh, I did a tech strong tv.
We do this video series called DevOps Unbound. Yep. And we had one on AppSec recently, and I saw a different tune.
Mm. Actually it wasn't DevOps Unbound, it was our SecOps Okay. Virtual event.
And I did a panel on there about, it was called the Sock and the Knock. Okay. Little Dr.
Susie thing. Even the AppSec vendors were saying, uh, we gotta shift all over. Yeah.
You can't just shift left. Totally. You gotta shift everywhere.
And I think that's a theme that's up and coming of, look, we gotta go where the problems are in, in security software, supply chain security, the SBO stuff, the, the, uh, observability security issues. These are all things that Real, they're all interconnected, real, And Right. They all At risk is multi-dimensional.
Attackers don't think in CVE score, AC vs. What did they think about, oh, I want to exploit what this vendor does not what, what that vendor does. Right.
So you guys are here at the show. I know it's early on Tuesday. Here it is.
Just open The door. Do you, what do you think? It's great so far.
Um, Detroit was quieter last year Was, Detroit was the first after Covid one. I think Covid is, no one gives a crap about it anymore. Uh, so I was, I was in Amsterdam.
You didn't Do Amsterdam? No, we didn't do Amsterdam. It was more like this.
Yeah. Though European, yeah. Food was better.
Um, uh, not really. Amsterdam was okay, but Chicago's good food too. No, diss amazing Chicago.
It's, but it's great to see so many security vendors here over, It's a very strong security over past couple Years. Yeah. You've just seen such an influx first with, uh, more of like the infrastructure security, cloud security shifting left.
Yeah. Uh, my previous company, uh, created checkoff and open source tool. Yeah, sure.
Um, and now application security, joining the team, we have tons and tons of vendors. So I think it's hard to see what it is, is we've seen a shift from a really very dev centric cube con to op centric op. Yeah.
And I think that's security's part of that. Yep. Yep.
All the projects around open source security and supply chain security are huge. All of these are interconnected and the cloud native ecosystem relies on all of these components. So we need to be Here.
It's also the primacy of security Security's a priority. So now you guys didn't have necessarily an announcement here, but I know you guys got some stuff in the works we're working on Some Stuff. Don't get, I don't want to get you in trouble.
No trouble. But no, it's just you and I. No one else is here.
No one here. Nobody. What do you guys got working on?
If you, whatever you can tell us. And that's For progression of this market. Um, and a lot of vendors are already starting to combine more and more elements.
Uh, having native context is really important for the core components of cloud native applications. So APIs very, very important to have a strong understanding of your inventory. Uh, open source dependencies.
Obviously the percentage of usage in code bases is whatever, 90% whatever they're saying now. Yep. And pipelines and source control managers are the next part of that.
Yeah, absolutely. Um, completing our coverage there, having a really strong story about being able to connect all of those, uh, potential risks into what might be a toxic combination that an attacker, uh, could easily use to get in the front door, um, and some more. I'll stop there.
There not Go too far, but Yeah. Otherwise we won't have you on next year. Um, let's talk about this now.
So this is cube con. Where else if people want to maybe are planning on going to some conferences, will you guys be maybe at Reinvent or RSA or any of these shows? So Reinvent, um, is a tricky one in AppSec.
Yeah. There's really, if you look at the partners of AWS and AppSec, there's really not that many. Um, we are working on having a tighter alignment there more to come there.
Okay. Um, but of course, always the RSAs Sure. Always the black hats.
Um, we do a lot with oasp. They're, uh, a, a solid foundation that's been around for a long time. Absolutely.
Uh, There's some synergies of course with the CNCF and Linux and oasp. So, um, yeah. Regional events, love 'em.
CubeCon is always a favorite. And of course, if people can't get to see you in person, they go on the web. com.
Yep. And they could find out about all these things happening that you're hinting at. com.
Yep. Or look, you can catch it on, well, you guys are on Security Boulevard. Yep.
You hit all our bases. Of course. com Cloud native.
Now they're, they're on all of 'em. Of course. Peyton.
Enjoy. Thanks For having me. Enjoy this Show.
com. Check it out. We're live in Chicago.
I, you know, we we're shooting out so you can see some of the traffic here. It's a busy show floor. It Is.
Sure is. All right. Thank you.
Thanks for Having me. All right. We're gonna take a break.
We'll be back here in a second. Live at CubeCon Cloud Native Con, this is Alan Shimel. We're out.





