Security is Job One | Predict 2023
At Predict 2023, the group will discuss the practicality of the shift left philosophy, addressing the skills gap with managed services and automation, the foundational importance of identity, the challenges of visibility across the extended enterprise and how to make the most out of the scads of aggregated security data.
Transcript
Hi everybody. This is Mike Rothman. Welcome to predict 2023.
This is the keynote session for the security track. And as you may have realized it's a little different this year. So what we're doing is presenting our Trends so text on Research.
Has presented as produced Trends in each of our coverage areas. This one will be security. So what we'll do for the beginning of the keynote session is to go through our Trends real quickly.
I'll read them to you kind of hit some highlights over the next 13 minutes or so, and then we'll bring in a panel of just fantastic experts that will help illuminate that will really kind of dig in a couple of different topics. It's gonna be a great panel. It's gonna be a great session to be a great day.
I'm really glad everybody's here. But without further Ado let's jump in. So the theme for security in 2023 is that security is job one, right?
And that's really kind of what we've been trying to do for a long time. So this shouldn't be a surprise. I just went through a number of that in the conference keynote.
So we're not gonna spend a lot of time on Securities job one but suffice it to say now is the time especially in a economy of uncertainty where security is increasingly important as we do applic. Development and where data is stored making sure that everybody understands the security is their job is going to be job one in 2023. So let's jump right into the first Trend.
It's about application security and we're calling it shift right question mark the backlash against ship left forces security to question, whether it's two onerous to expect developers to take primary responsibility for building security into the application. It's time we rethink the ship left philosophy and find something that works for everyone and that's something that we're hearing again. Remember we sit in the middle of devops and Cloud native and security and digital transformation.
So we hear a lot of the griping in terms of security folks just deciding. Hey, it's the developers problem. We're going to give them some tools.
But at the end of the day, they're responsible for the security the application we've got developer fatigue. We've got to make more progress on security Champions focus on API security and then the two main topics that will focus in the panel is cloud configuration security and software bill of materials. So suffice it to say application security and not just based upon the fact that that's where we live.
Right? But application security is going to be one of the key issues that you have to deal with in 2023. Now let's go into the second Trend which is about Management Services.
Our managed Services just have them do it. So with ever-present security skills Gap resource allocation remains one of the biggest challenges for security leadership. Thus there continues to be great interest in all sorts of services and service providers to help bridge the skills Gap in addition Automation and orchestration also have a role to play in scaling up security capabilities efficiently and effectively in providing a continuous response to attacks.
We'll talk about continuous a little bit later in one of the later Trends but suffice to say we're gonna look to manage services whether it's sassy for a managed Network as managed secure network service MDR to really help to supplement your internal detection capabilities security as a service types of offerings. We don't have the people in a lot of cases. We don't have the skills.
We need to depend on service providers to bridge that Gap. The third trend is on identity and access management everything is entitled and not entitled like, you know, kind of half of those kids that you know entitled like they have entitlement. So as organizations move to Cloud platforms and new software architectures the most significant changes that identity and access management entitlements can provide access to every cloud resource.
Thus organizations will Embrace Federation to manage the identities and focus on using access rules to minimize the attack service identity and access management emerges as a critical success factor for securing cloud-based resources. This is already kind of happened. So we're a little bit sandbag in on this trend but what we want to highlight is how intrinsic and how important I am is to your entire cloud-based infrastructure your entire modern infrastructure.
We've got to have one authoritative Source that's where Federation is going to come in because we All sorts of user repositories user repositories we may start to have seen so that's one of the first topics that we have here, which is really about managing your customers dealing with machines, right? That's another thing. We've got apis.
We've got all sorts of other identities that are not necessarily humans. We are certainly seeing some backlash in terms of MFA. Especially SMS based MFA not being good enough and ultimately with all of the different combinations permutations Alternatives that you have having some measure of analytics to help you understand what you are privileged environment.
Looks like it's gonna be critical, right? So again, everything is entitled. Fourth Trend visibility surveying the sprawl it seems the industry has finally realized that it's impossible to protect an organizations a tax service and security posture without a clear understanding of its attack service and security posture.
However, the rapid movement to SAS and Cloud hosted application Stacks that lack knowledge about the providers security posture stresses the system making it harder to evaluate risk as a result. There will be a continued focus on maintaining the visibility of cloud-based resources and assessing providers security posture in mostly real time. So basically this is about visibility And the reality is is our data goes in all places seemingly at all times.
We have to get our arms around that more effectively. So there's a new category of tools. Although they're not that new call the tax service management.
We've got I'm calling them X SPM because there's X for everything but really what that is is a combination of cloud security posture management SAS security posture management now data security posture management at some point we'll have identity security posture management. So that would be I SPM or maybe I am SPM, you know, depending if you are excited about going forward and pushing on the on the acronyms there and ultimately what this is about is prioritizing our efforts. So again, we've got to get on top of all the resources that are in our environment and make sure that we are tracking them and finally the fifth security trend for 2023 is about security monitoring and security monitoring continuously Dev.
software delivery microservices serverless orchestration Infrastructure as service and gitops all put software into continuous motion presenting a continuous opportunity for misuse and attacks security can no longer maintain a fixed mindset as the code apis Cloud configurations and software components exist in near continuous state of change security monitoring approaches. No longer have the luxury of waiting for logs to appear and analytics to generate alerts. So what we're going to be doing in Flushing out this research agenda is talking about fast path versus low path.
Wish I had time to get into that now you'll have to stay tuned to text wrong to learn more about that in the future things like sore, you know security orchestration and Automation and response are going to be key aspects of making sure that we can continuously track what's happening in our environment and ensure that we are protected and that our detection mechanisms having chance to perform and finally were built observability say that 10 times fast observability overlap in that we're starting to see as devops becomes more prevalent as we more effectively isolate specific applications within the environment. Security monitoring can happen in some cases within the observability platform. So we'll start to see aspects of that.
So these are our trends for 2023 when it comes to security what you'll see throughout the year is text wrong research fleshing out each one of these Trends digging into it providing some quantitative research to support what it is that we are positioning and where we think things are going and ultimately this is going to drive the research agenda for the company in 2023. So enough about that. Let's get to the real show here.
Let's bring in our panelists. And you know, you've heard a lot from me about where we think things are going in 2023, but I'll be the first to tell you I certainly don't know everything and a lot of people would tell you. I don't know much from that perspective.
So we've assembled really a great panel today to kind of dig into each of our release at least a handful of our trends that we published today at predict. So first, let's kind of introduce the panel Caroline long. Why don't you introduce yourself?
Let us know what you're about great. Thanks so much Mike. I'm delighted to be here today.
My name is Caroline Wong. I'm the chief strategy officer at Cobalt. We're a pen test as a service company.
com at digital and then Joined Cobalt about six years ago. I wrote a book called security metrics a beginner's guide with McGraw-Hill gosh more than a decade ago. I host a podcast called humans of infosec and I teach cybersecurity courses on LinkedIn learning.
Wow. All right. So Caroline's been there done that has the road rash and and probably a whole bunch of free fall as well.
Great Neil Carpenter, welcome to predict. Thank you again for thank you introduce yourself, too. Yeah.
I feel like we should have had Carolyn go last instead of first, but I don't know. Yeah. Yeah, but Neil Carpenter, I'm a principal technical evangelist at Orca security.
We're a cloud security company my background. I spent a long time at Microsoft most of it in the instant response space as an analyst and a lead did early work on Azure and Office 365 and how we responded how customers would respond to incidents there. So, you know, I had something good if I had something compromised in Office 365.
What does that mean? How do I figure it out? Help build.
What is now Dart the Consulting team around incident response there? And it was time to move on. I spent a long time at number of cloud native companies twist lock stack rocks torque and now Orkin and so really post instant response trying to help customers get get ahead of that and instead of seeing how things go bad help them.
Go right and get ahead of security incidents a little prevention go figure, right, you know kind of we spend some functional detection. Yeah. Exactly.
Great. Thank you Neil great to see you man. Jason Jason Leigh.
Why don't you introduce yourself? Yeah. Thanks Mike.
It's great being on this panel. I mean, I'm among the elite here. Probably the the one that doesn't fit quite in here.
But anyways, I am the product marketing director over at sneak and sneak is a developer security platform. We help customers find and fix and prioritize their security vulnerabilities and their applications. So I've actually only been in and out security for a couple of years.
Worked at varicode before this but I spent 20 plus years in my career working as a product manager a product marketer and in all sorts of various Industries and companies from large to small a lot of startup work working in the trenches with with the developers the the marketing teams helping to try to grow and build applications. So I get to sort of take all the stuff that I've done over the years and now bring a security-centric sort of view to that to that world and help advocate for for all us developer and products and managers out there and and we will get to that Jason since obviously application security is right in the Wheelhouse of what we do at Tech strong and text wrong research. So we'll want to really kind of excavate into exactly what that means from a developer security standpoint a lot of those Trends.
But before we get there, right, I just, you know kind of the theme right the theme for security in 23 at least according to us is His job one right in and again from my standpoint. I've been doing this. So I feel like kind of the you know old guy in the group right?
Although you know that some of your rivaling mean gray hair. Not you Caroline, thankfully, you know, but you know, I've been doing this for a long time right for a long time. We've been trying to get folks to pay attention to security but now with application security and really as part of devops or devsecops right now that we've got kind of ransomware as such a high profile type of fish type of issue, we've got all sorts of of kind of cloud-based things where our sensitive data is going there and you know what I really want to get at here is are we just kind of drinking our own bath water?
We just in our own Echo Chamber from the standpoint of saying security is is important and security is job one or as you kind of get in especially like Jason, you know, you're sitting there dealing with developers right now. You're out there. You know kind of with a bunch of cloud practitioners Caroline, you know kind of on the you know, yes, you are see so piece of it but you know, you're working with companies that are you know, trying to test their systems in an automated fashion, right?
Are you here in the same kind of stuff or again? Are we just kind of kind of smoking our own at this point? I think that you know, basically we are not smoking our own right?
We're we are at the Forefront of it. We've been we've been you know, we've been saying it for years like hey security is important security is important and I think over the last couple of years. I I got the pleasure of starting it's sneak the same month that log for Jay decided to reach head and and go everywhere and that was a lot of fun and that actually that wasn't the only thing that led to the government getting involved.
But you know when the government gets involved the next thing, you know, the whole world pays attention and starts to follow and so I think there's a there's definitely a big Trend that's following the log for Jay events the solar Event some of these those breaches that have happened over the last few years and we see that magnifying we see like the number of attacks the number of breaches going up and up and I think every company now is not just a company. They're all software companies. Every company has some form of application and hundreds if not tens of thousands of repos out there could repos that they're building and you know, everybody from like bio agricultural companies to high tech they all have some mobile application or website or logistic application that all needs to be protected and I think the word is getting to those Executives to actually take it serious Exactly.
Yeah. No, I I agree. I think there's some movement though.
So if I go back sort of seven eight years to like the target breach in that time period we were all very scared and security orgs were like the top of the stack everything security said went all the budget went there and there was a lot of Being a roadblock. If you will very much. The the older stereotypical Security Org gonna block things until it's right gonna keep things from being deployed.
And I think what's happened in the intervening years is the business The Business Leaders have realized everything is software. Whether I'm actually running a website or I'm delivering things to stores or I'm teaching people whatever it is everything now runs as software. So delivering software in a timely fashion has become a core business.
Value if you will and so what I've seen happen is security teams have become. More balanced if you will less sort of the the sole Desiring of the biggest budget the biggest and it's had to be it's had to be balanced and we've had to become more complementary and more. More integrated and and better better able to deliver security without interrupting the business.
So I think you mentioned that SEC Ops I think the terms over use but I love the concept of integrating security and having security be part of the pipeline part of how we're delivering. I think that that's where I'm seeing. The best people I work with the best companies and works I work with that's where they're going is a much more Integrated Security world where security is not a blocker security is a partner that helps deliver things right Caroline.
Is that what you're seeing? so I think that. Security is a very funny industry fundamentally security is about protecting value and everyone wants to protect value.
Everyone would say that they wanted to protect value. You know, as Neil is saying all of the value in the world so much of the value in the world. It's shifting from the physical to the digital Realm.
And I think in the Physical Realm, we're pretty good at security. You know, we know how to use locks on doors and you know seat belts for our car seats for our children. I think that one of the things that I've noticed in cybersecurity is that Sometimes it seems more complex than it actually is.
I think that sometimes you know, I look at something like nist 853 that is like nearly a 500 page document, you know, even if I look at something like Beeson a descriptive model for software security. That's now, you know more than a decade old research project. Take more than 120 or something controls.
And that can get intimidating. It can get overwhelming, you know, we use terms in this industry like s bomb right? If you don't know that s-bomb stands for software bill of materials and is actually a really boring term for a software components ingredients like The sound of the word.
Esbomb is terrifying so there are the ways in which Sometimes it seems like it's so complicated and fundamentally. I think it can actually be simple not necessarily easy, but simple, you know fundamentally, maybe it's really just about figuring out what we have to protect in the first place trying to get a handle on that and then finding fixing and preventing security vulnerabilities. Maybe that's all there is to it.
And I think that you know there there's a lot of language and a lot of acronyms and a lot of complexity. I think that sometimes gets in the way of something that in one way can actually be simple and I love this idea. Security's job one know what you've got to secure fine fix and prevent problems.
So I think that's an awesome thing. Awesome, so, you know and and I want to Echo and and highlight, you know, what each one of you pointed out right which is we're kind of at this I don't call it an inflection point but kind of a period where we as security folks have the ears of a lot of the people making decisions right? Whether it's about software as folks are evolving to a modern development structure, right, you know devops right?
Whether it's you know, folks or migrating there infrastructure to a cloud-based platform again, whether it's really just trying to get your arms around what a security program is, I think that we have an opportunity in 2023 to really start to press that Advantage right to really start to show value in terms of how we can do better things for the business. One of the things you'll see on text from TV is an interview, you know, we recently did with the CEO of attack. IQ right, but that was really not about you know, that's specific company.
It was about aligning security controls with business outcomes. And I think that's something again as a theme perspective. We really should start thinking about how we tell a better story to the rest of the organization.
But all that being said, right, you know highfalutin, you know kind of motherhood and apple pie stuff. We still got to get stuff done right? We're still developing software and and count on you you brought up the s bomb word, right, you know kind of software building materials and and obviously that's that's very popular now, but one and our first train that we really hitting on this year is this idea of how do we more effectively integrate security into this development process, right?
The last five years we've talked about shifting left that we want developers to be more involved in this the cybersecurity guidance from the US federal government mandated that folks do that ingredient list right that you have to start, you know kind of divulging what it is that you have in your application. Right is your hosting these environments in Cloud platforms. You have to get a sense of again.
What's vulnerable what's misconfigured? What is actually, you know kind of good to be there. So again, you know as we kind of move into the next point of discussion, right?
How do we make progress? I'm gonna pick up what Carolyn said which is this is not this is probably not as complicated as it has as it as it seems to be right we want to identify problems early solve problems early and a lot of that is Automation and it's it's, you know, figuring out what the right process and the right Integrations look like to put those things in front of developers where they're already working. They've already got other automation finding bugs finding integration issues finding finding other things, you know, it's it's a matter of how do we take this?
How do we take the security stuff and do the same stuff? Same thing with it? How do we work in a way that's familiar to developers surface things in the same place.
I'll tell you the truth. I worked with a customer a few years ago now. Who did this really really?
Well, they had a fantastic security leader. They were in the middle of a huge move from on-prem monolithic apps to moving everything into microservices into the cloud. They identified what their goals were.
They set up automation to catch those things early. And it was sort of interesting. I was working for one of the products that was part of their part of that.
They did this so well that they that the developers the Ops folks really didn't even know what the products were. They just knew that if they built a container and it had vulnerabilities in it and they were over a certain threshold their bill was gonna fail they were gonna have to go fix those things and deliver it right and it was so well integrated. I talked to him a year later.
None of the folks doing this. They just knew that this was the process and these things if they built something wrong, you got flagged they got failed they had to fix it and deliver it and so now 18 months later. This is just part of DNA of how these how they build and ship software now, they are by far the best example, I've seen of that, you know, it is not you do need clear leadership.
You do need really strong technical people doing it. But once you get it, right it becomes just Just the same as I found a performance bug because when we test it and it scales to 100 instances everything falls over. Yeah, when you have when you have you know, a 500 to 1 in some cases ratio between security and developers, you kind of are forced to you know, help, you know, take ownership as a developer take ownership as an engineering organization of not just creating value from a new feature.
But making sure you're building in a secure way and I think that's that's one of the things that we advocate for and we're trying to kind of we since we've been founded we've been pushing this notion of developer security as a as almost a segment and some of the analysts that we work with are like we don't understand it because it's new it's different. We're trying to sort of bring that that understanding to the world and and I think my opinion in in I think we've seen this we hear this from the end you but like that whole term of shifting. Left it sort of.
It's a good term like it means something but to the people that you're shifting stuff onto it feels like more work. And so we have to make it super simple super easy. It's not about shifting left.
It's about educating helping they're fixing things and Building Things and it's it's really hard to sort of ramp down after building functionality and come back two weeks later and all the sudden you get hit with a bunch of fixes and bugs and security issues. And now you got to go rewrap back up. So why not just present that stuff in the middle of development while they're working on their mindset is there so just making those types of things easier but making sure the security team understands that angle as well.
So Say about it. As a security company, I think security people have an opportunity to learn about what it's like to be a developer what it's like to be a product person. I think shift left is fine shift right is fine.
Maybe there's an opportunity for us to try and shift everything everywhere all the time. I think there might be like a movie with something like that title because here's the thing and I think we've alluded to it. The bottom line is that software is built by people.
And it's built in different stages and phases no matter whatever you call it or how fast it goes. And so every single step of the software development life cycle is an opportunity to either introduce a security vulnerability or eliminate a security vulnerability and I think that what I've seen actually over the past several years. three is security people getting curious about what it's like to be a developer about what it's like to be a product manager.
How do these folks work? What tools do they use? What processes do they have in place, you know start there and then ask the question, how can I help?
I think that I've actually seen a shift from the relationship between security folks and development folks speaking broadly. I've seen a shift from a me versus you to an us against the problem and I and I do think that that's an opportunity and I look forward to to continuing to see an evolution there. Yeah, that that's that's fantastic.
Right? First of all shift everything everywhere all the time, right? I'm still trying to figure out what that movie actually, you know kind of what was going on with that.
But I do think that that's really an act metaphor and and one of the things that that, you know again Caroline, you mentioned your book, you know, early on I wrote God it was 2007, right but I wrote a book called pragmatic CSO and that was really about how do you practice Security in a business context? And nobody had really talked about that at the time right? And that was really about understanding it's about your business and it's about how do I you know couch and position protection within the context of that business.
So again, I guess if you're in this business long enough you see things, you know kind of circle back and then Circle back and Circle back again, so hopefully we're entering an age where you know folks start to understand that it's not about security for security sake that it's really about you know, security to enable or further the value of the business, right? But you know again we still get back to this whole thing of you know, tactically we can talk about how do we integrate in with the applications? And now if we go through and think about it from an infrastructure standpoint, there's still just a significant lack of visibility, right?
We just don't know where things are. And if anything it's getting a lot worse, right? Because we've got sass everywhere and you know Jason you certainly know this right, you know kind of a lot of the development motions that we have now are driven by SAS applications.
Our code is up in some of these repositories. We're doing testing, you know, folks are integrating and and connecting into our accounts on all that's the important and one of our other trends that I think will be relevant that we want to you know, kind of Discussion of around is really about getting your arms around your entire estate. Right?
We're calling it surveying the sprawl. But ultimately you're hearing a lot about things like posture management, right? So maybe it's Cloud security posture management.
Maybe those data security posture management or SAS security posture management, but everybody we used to call it configuration stuff. Right? I mean that's kind of old folks will remember it is, you know, just hey we gotta think about how things are configured now it's posture which you know again makes everybody feel better.
It's a great marketing term, but all the same it's one of the fundamental High genic requirements that we have in order to really build out and run an infrastructure in this kind of environment. So love to get everybody's opinion about what's real here. What's a feature right?
What he should be in in the platform. Do I need a visibility platform, right, you know kind of just stuff that I should be doing as part of, you know some other Tool or capability that I have within the environment because again, I thought you know people that are listening here are gonna get bombarded by folks talking about posture managers. How should they parse that what does that mean to them?
I think we can start with something that I believe we all know. Which is that there is not a silver bullet and we cannot expect software to do everything for us. No matter how fancy AIML blah blah, you know at the end of the day, you know surveying the sprawl.
Has got to do with growth. That we don't have good governance over. Sometimes good governance comes down to doing important and boring things like keeping a list up to date.
You can buy all the software you want that is supposed to do whatever you want. But at the end of the day if you don't have a manual process somewhere where the person updating the version buying a new thing making a connection is gonna put that information somewhere that other people know about and can rely upon. You're just not in a good situation.
I have the silliest of analogies. my daughter and her toys If I say to my daughter, she's seven years old. Hey.
Maybe we should go organize your toys make a list of them, you know characterize the state of each one because that will enable us to take care of your toys. You can you can take care of them and you can enjoy them for longer. She says, you know, I'd really just rather play with this toy right now, you know, and I've really got my eyes on that other toy that we saw the other day.
And so I think a hard question is how do we encourage boring and important work? Neil I'm sure you have something to say here yeah, I mean so You know and obviously governance is part of the problem. Right but we want to have defense and depth.
So we do want to have some form of a visibility on top of that. And when I was in the instant response world, we used to I hesitate to call it a game given the situation we used to play a game with customers that we went to help them investigate an incident and it was real simple one. We would ask them.
How many endpoints do you have in your environment? How many workstations do you have? How many servers do you have?
And typically we would get three or four numbers. That were 20% or more different. Somebody would tell us.
Oh, we have a thousand workstations. Someone else would tell us we have 1200 workstations. And they would both look at each other and be totally confused about it.
Right? And and so we would as part of the as part of instant response. We would have to go out and light up the environment figure out that they were actually 1400 and 200 of them were running out was out of date that nobody knew about and all of these other sorts of things and that's it's a problem when you're buying each and every piece of Hardware it becomes a much more dramatic problem when I can hit a button and deploy stuff and I can write code and deploy stuff and then that code sort of lives on its own.
So, yeah, fundamentally, I think. You know, whatever whatever the approach is. You've got to have approaches and solutions to knowing what you have deployed knowing what you have running.
Knowing what the state of it is and and having having good. Good visibility and good controls around that so being able to find you know, okay, we've got a bunch of stuff running and In This Cloud In This Cloud these things are out of date. These things haven't been touched in a period of time.
And then having that available to you, you know. Jason mentioned log for J. Which I think for all of us was a was an absolute.
Killer of a December but you know it was it was very much. Like that was a great situation where people if they had a good inventory if they had good visibility to what was out there was not of it was not a tremendous problem. They could go look and see.
All right. What versions of log for Jade do we have what you know where they deployed? But I talked to a lot of people 13 months ago who had no idea and they were panicking around.
How do I go find these things that I have deployed? How do I dive into multiple layers of java jars inside of java jars and figure this out. And they had a really bad December and a really bad January for the lack of that capability.
Maybe we actually had a problem and we did a I think a testimonial of a Blog about this customer but this customer was actually not a customer at the time of log4j and they were faced with exactly that the like it happened and they're like, what do we do? Oh my god. Well, it turns out they had just kicked off their pilot like a week or two before like let's you sneak.
Okay great and then they dove in and they were able to find and and identify all of their repos. In fact, they're it. They found a bunch of repos that they didn't even know.
They had that had it because they were out searching for but anyways, yeah, I think identifying and being able to see everything that's in your ecosystem visibility is key. Right? If you can't you can't fix or you can't prevent you can't see so having the right tools across your entire environment.
And now the environment is being created On Demand right with I see developers are now using the infrastructure is the extension of the application. So Important to not only just sort of monitor at a fixed state but ongoing all the time every minute of every day like okay, here's an application has been deployed and it's changing this it's changing that and now there's a vulnerability here. How do we know where in the code that actually originated from?
So being able to track and not only see everything but then also be able to track like from code to cloud and then back to code again and making sure that you can find the root cause and and that you put in best practices and I think you guys both said, you know governance is really important having the right processes around. You know, when do you change? What do you change?
For example, if the developer is responsible for building an application and they're setting the I am rules in your Cloud environment, you know, if something's wrong don't go fix it in the cloud environment fix it in the code and then redeploy, you know, I think there's just process things like that that need to to be adopted a little bit more and then we're learning as an industry. The industry is starting to ad. those best practices but Yeah, that's right.
And and you know, first of all, I want to thank oh you guys really fantastic discussion. I wish we had three hours to go through because we probably still wouldn't be done with all the trends but it really was a great discussion a couple of takeaways that I get here and it's stuff. I've been talking about for a long time.
So there's some little but you know, but you know again it's it's the boring stuff right? It's the work and a lot of people got into security because it was sexy and they can go red team and break s***, you know, all that kind of stuff and that's not it right. It's the work and and what we're gonna do hopefully in 2023 and then moving forward is that work of integrating our security into how we're building out your products right in every company is a software company now, so that's critical.
We're gonna get you know, what do a lot of the work on figuring out what we can do to increase our visibility as our data is spreading to you know, the winds and all these different, you know, Cloud platforms. We're gonna focus on identity. We're gonna focus on networking.
Security services. So there's again a whole bunch of detail underneath the trends. I want to thank Caroline Wong Neil Carpenter and Jason Lane for joining us here on predict and that is what we have for our security keynote.
So thanks everybody head on we've got the next panel starting up shortly.




