Abhishek Singh on AI, Security Collaboration, and Governance in Cloud-Native Environments | ROCon 2025
Abhishek Singh discusses the challenges AI presents to security practices, highlighting the need for collaboration between security teams and developers. The role of AI in code development is explored, along with governance issues related to AI and data access. Resources for more information on Qualys and cloud native security are also shared.
Transcript
Hey, everyone. Good morning, good afternoon. Depending, I guess, where you are in the world.
Good evening even. I'm Alan Shimmel of Techstrong, and you're watching us live here at Rock on Qualys Security Conference. I guess it's the conference formally known as QSC.
Yeah, like Prince and, uh, it's been rebranded this year. It really emphasized the, the, the point that Qualys has really, you know, pivoted on around risk, managing risk. And of course, last year, if you watched our coverage from last year, Qualis introduced something called the Risk Operation Center Rock.
And growing out of that from last year to this year, the, the, the theme and the message coming in loud and clear is, look, security's hard. It's always been hard, but it's about managing risk to so that we don't waste a lot of money, a lot of cycles, a lot of manpower or people power or AI power as the case may be on, on security work that doesn't really do anything towards lowering or managing our risk. I want to introduce you to Abha Singh.
Did I get that right? Yes. Perfect.
Of Qualys. If, if you've watched our Qualys coverage in the past, EK's been nice enough to be here a few times, um, ek, first of all, welcome. It's good to see you again.
Thank you Adam. Glad to be here. For most people in our audience probably didn't watch last year, or they don't remember from last year.
So why don't you give 'em a little background At co I'm the Vice President of Product Management for Kubernetes and Container Security. That's my background. I'm cloud native by, by design.
Yes. Prior to co I had a startup called Rally Networks. Yes.
We were top 10 at RSA 2022. Uh, and we used to do zero trust for cloud native workloads. So now I'm here trying to do risk management and operationalizing risk for cloud native, You know, so we'll be in Atlanta next month for the cube con cloud native con.
Obviously, I don't know if you'll be there, but we're already starting to see, uh, a lot of, there's a lot of noise around cloud native security. The bottom line is I've been reading a lot of articles, traditional AppSec, you know, the kind we've had for 20 odd years now is not really, it's just, it's being changed. It's being changed by ai.
Right. And, and not for the better necessarily. It's made the job harder.
It's being changed as we are moving more to, not, not just containerized, but the, the whole micro architect microservices architecture. And whether you're going on VMware on top of a hypervisor, a hypervisor on bare metal or on the cloud Kubernetes on the, on the edge, you know, it, it just seems abha that we're in a, like a state of flux. Like for a while things were stable.
You know what I mean? It was, and we, and it was, okay, we know what the mission is and we're going to get better and better and better at it. This year, it seems like things are more in flux.
I'm wondering, do you see that? Absolutely. So with Gen AI and AI in general, containers have gone mainstream.
Yeah. So if you are doing ai, you must be using python. Python is a dependency problem.
You make a change works for you, doesn't work in production. The way to fix it is to use containers. You freeze your dependencies.
So Python has made containers very relevant for ai. And the new gene I stuff also uses APIs to connect to each other, right? So all these worker protection has become very interesting.
If you look at what call is saying, right? They're saying your attack path attack surface is humongous. It's volumes.
And even more so for containers because every microservice has put out its own vulnerability. Its own attack. Yeah.
Attack surface. Right? If you, if you try to keep up with that, you'll go nowhere.
It's a losing game because that, that's what I was trying to get at. The amount of vulnerabilities has exploded. How Do you operationalize risk?
And that happens when you can keep up with the incoming arrival rate, right? So first thing is you manage your arrival rate. And how do you do that?
By focusing on the most relevant ones. And how do you do that? By getting 25 plus threat feeds, that we have a threat research unit that, that continuously tries to enhance and, uh, embed these threat findings into these arrival things.
So now you can focus on the 10% that actually matter. You have a chance to keep up. So that's the first order of business, right?
Second is remediation is harder for containers. When you had legacy workloads, there was one IT team, you could go talk to them, life was good. Containers were different with developers, many developers, how do you make sure you go to the right team?
And finding that out is very difficult. So people talk about code to cloud, how can you trace back cloud findings back to developers so they can, remediation can keep up with arrival rate? And finally, because it's an ephemeral surface, how do you operationalize risk for a surface that continuously changes on you?
So you have to be able to quantify risk at stable levels, right? You can't, you can't keep, uh, managing risk at a container level. At a cluster level.
Things are more stable than a ephemeral workload itself. So how do you quantify risk at a more stable level and how do you operationalize risk? That's really the theme of what we are doing right now.
So I think you've done a great job of outlining the issue. Yes. Talk about the solution.
So the solution also I outlined, right? So how do you make sure you focus on your risk surface attack surface? And that is a simple exercise by not looking at CVS and CVSS.
But what call gives you is very different. We don't split vulnerabilities. We tell you missing patches of a hundred vulnerabilities is one patch noise free.
So less noise, less work. And that's what allows you to keep up. And then we rank these based on the threatening tell 25 plus threat fits informing you how to make risk-based decisions.
You want you to work with less noise, do less work, and be more secure. And in a way that is in harmony with devs. So you can take the same tooling how security is looking at risk, and enable developers to have the same experience and work less and do more productive work and still be more secure.
So you brought up a very important part, and to me it goes kind of to the heart of cloud native security, is that it's a shared model. It's not just the security person who's gonna make cloud native secure or the security team. You've gotta work with Dev, you gotta work with your DevOps engineers, you've gotta work with your platform engineers, your SREs.
All of these people are in the, the mix of, of managing risk, of managing security. How do you, I don't mean to insult you, but Qualys is a security tool made for security people. How do you take this security tool for security people and get the devs, the DevOps engineers, the platform engineers to understand what it is it's doing, why we gotta do it, how we gotta do it, right?
I mean, because to get their buy-in, they need to kind of wrap their head around their arms, around it. Yeah. So again, there's couple of concepts here.
One is code to cloud. So you're talking to the right person, you waste a lot of trying, figuring out who to communicate, right? So first, first thing is finding the right owner, and then there is a concept of devs, sec harmony.
So how do we make sure we, when we communicate to dev, we are not trying to push work on them, we are trying to align them so they can work less. And that is very interesting. And the third part is how do we create gates that are consistent and shifted, left?
So at runtime, we can control what a process can do, take it left, we can fail risky deployments, and the same evaluation criteria can be shifted left. We can fail bills if they're risky. Again, we're not failing every bill.
We are taking a very risk conscious, business aware decision to fail bills we can even fail commits if they're not safe. Again, the the main theme is harmony. How do we make the same criteria across the board and help developers do more with less?
Again, security often comes in the way we are trying to remove that obstacle and be in tune with them. So we are helping them, helping them be more secure with less work. And devs would love that, right?
Consistent tooling, working in harmony with sec, having the right owners, having the right context. So now I'm telling them why this is relevant. This is relevant because it runs in production.
It's relevant because there's 20 other toxic combinations that make it important to fix. Right now it's being exploited in the vial. All that context and consistency creates that dev ssec harmony.
I love it. Let me, uh, you mentioned ai, but you only mentioned it in passing. It's the single biggest thing.
Would, it sucks the air out of all of our conversations. Uh, it's going to play a role here. It already is playing a role.
90% of developers here's, and it some interesting stats. 90% of developers are using AI to help develop their code. Almost 40% of 'em don't trust it.
66% of them say it introduces instability, securities risk into the equation, but yet 90% are still using it. How does that factor into your mission to Qualys mission about managing the risk? So there are a couple of aspects, right?
It's not all that bad. There's a school of thought that thinks that when AI generates code, it'll be secure by design. So there's a ray of hope there, right?
So there is, it's all not all negative. Uh, there's a school of thought that thingss that SCA will be rendered not that effective or needed because AI would be able to generate secure code. But we are agnostic to that.
We will do assessments of your code no matter who generates it. So that way we are neutral. We, we don't care who, where this code comes from.
Yeah. But if it comes to your security operations, you're responsible for it. The source doesn't matter, AI or not, we will assess that code, we'll give you recommendations.
So you focus on your risk surface, not your attacks of it. It's huge. But how do you focus to the relevant bits of it, regardless of how the code came from?
And that is where we think this will come together. Right? And again, uh, there's more to that than just that aspect of it, right?
Lot of AI code runs on containers. So how do you do a discovery who is using ai? And this, that discovery can also come from us with that discovery, how do you find the findings that are most relevant to fix?
Right? So there's also the element of finding AI in use at, in production. And then most of it is running on containers.
So container has a central role to play in discovery, prioritization, and remediation. Got it. You know, IIK, I speak to a lot of security people too, and I, and I have to, I'll be honest with you, I've been hearing from my friends in security, it's the same old, same old, all of this AI innovation, all these new platforms that are AI powered, all the, we're generating more code than we ever did.
And it still feels like AI is a second. Uh, not ai, excuse me, security is a second class citizen security. Look, we're running as fast as we can with ai.
We're worry about the security later, right? Like we always have done for as long 30 years that I'm doing this. Do you see that?
That people are running really fast and not prioritizing security as they should? Security has always been an afterthought, right? I know.
And it, it is by design, it's by nature. And I'm not here to challenge that, right? You can't do QA before you write your code.
Yeah. So it's a, it's a by design thing, right? You have to have business to want to secure it.
And that's why it's a risk minded. It's a business aligned decision to secure. So some of it is by design, there's nothing wrong with it.
But when you do so, you make sure you're secure, you are trailing. But when you trail, do you have the right hooks in place so you can shift left, you can secure upfront, be proactive and catch up. It's a catch up game.
Security cannot lead the development, right? QA cannot happen before development. So security is by design, by nature where, where it is.
But we can be smarter about how do we do things? We cannot be a bolt-on with containers. You can't go after the fact and do security.
You have to build the hooks in upfront. You can't build the hooks without code. Right?
Code has to exist, but you can't build hooks in production. You have to build a shift left, fixed, left. So that's the change.
It's not that you can do security before you write code, right? But when you're doing security, it should sprinkle into every aspect of development. Not before the fact.
Even after the fact. It has to cover the whole development Contemporaneous. Yes.
That I, look, I think it's a very mature attitude. We gotta, we, I think we have to understand that. I also think there's so much pressure today to just go fast.
Go fest, you know, use this new stuff, use, you know, use AI wherever you can. Agents, we haven't discussed agentic ai. What do you see as the role of agentic ai, right?
Autonomously now writing code, testing code, deploying code, securing code. Is that something Qualys is already looking? Absolutely.
So when we talk about rock, rock is AI native, we have the benefit of starting in an age where gen AI is front and center. So the way people interact with their systems is no more with a dashboard and a ui. They want to chat, right?
And that is a, there's a whole new way of interacting with your system. It, it enables you to customize, to create workforce in a very novel way. So we are very a adoptive of that whole paradigm.
We are saying our rock will be AI first. It's the, it's the AI native. That's how we interact with rock through, through your chat.
And you see that in our demos, right? The other part is it does bring new risk. So we have had governance around who has access to data, but when you build these gene AI systems, it has a wealth of data and god knows where the leakage comes from.
So while we embrace this AI and it has a lot of powers, we want it in a safe way, including co. So when as colleagues you interact with our LLM models, we make sure that only the right role has the right data access. And LLM is only a way to make your interactions in English.
It's still calling APIs and those APIs have R back. So they have strong governance models behind them. What is AI is just the translation from English to APIs.
It makes it easier to create your workflows, but the governance model cannot be compromised. And that's where the risk is. If it is a LALA line free for all, the governance is lost.
Now the data is everywhere you go, scratching your head, how do I protect it? But if you do it in a disciplined way, which we are, it's, it's, it's okay. It's manageable.
It's Manageable, it's beneficial. It's, it's important to leverage it. Gotcha.
For people at home who wanna find out more about Cloud Native and Qualis Cloud Native Security and Qualys, where, where should they be looking? So we have a lot of, uh, events that we participate in. You can go to our website, find more about us.
com. Yes. And is there a section cloud native security?
Absolutely. So we are covered as part of Total Cloud cloud security comes under the Total Cloud umbrella. So if you go to Quas and look for Total Cloud, you'll not miss us.
Excellent. Abha, it looks like, I guess people are coming in and you probably can hear this at home, but I wa I was lucky we got you before it got too crowded, I guess. Yeah, it's a pleasure seeing you again, my friend.
Keep up the great work. Likewise, Alan. Great to be here.
Abha Sing vp, uh, container Security and more here at Qualys. We're gonna continue live from Rock on Rock on.