Antonio Anderson on Transforming Security From Cost Center to Strategic Asset in Cloud-Native Environments | ROCon 2025
Antonio Anderson, a dual CIO and CISO, shares insights from his extensive telecom experience. He discusses the complexities of securing cloud native environments and highlights the need for visibility and prioritization in security management. The role of security is evolving from a cost center to a strategic asset, emphasizing collaboration and effective use of security tools to enhance business decision-making.
Transcript
Hey everyone. We're back here at Qualys Rock on in, uh, Houston. We, we've got one or two more to wrap up day one here.
So, uh, bear with us. We're glad we'd be live. For those of you watching, if this is the first one you caught and you wanna see any of the other, uh, videos that we've done today, the interviews, the, the, uh, on demand versions, we'll be ready in a day or two and you'll be able to get them on Textron tv and we'll probably see 'em on LinkedIn and everywhere else.
Anyway, let me introduce you to our next guest. He's an international man of mystery. I'm only kidding.
His name is Antonio Anderson. But, uh, an Antonio works for a very large managed service provider or or service provider, service provider here in North America. And, um, you know, in order to protect the innocent, we're going to just leave it at that right now.
But Antonio has a, a, a very interesting dual role, and I've seen it before with friends of mine, sort of a, both as a CIO and CISO type of thing, where they're responsible for it and information security or cyber as, as we call it. And it's an interesting trend. You're not a unicorn on that.
I, I've seen a lot of people doing this. A lot of organizations move into this. What I always find this interesting, Antonio, is did you come from the security side of the house and take over it, or did you come from it and take over security?
Well, that's, that's a trick question. 'cause I grew up in telecom. Okay.
Right. May not remember this little company called MCI three letters, WorldCom, MCI spent a lot of money with them in the dotcom era. Absolutely.
So I was there. So MCI, WorldCom acquired MCI. Yep.
MCI, WorldCom was acquired by Verizon. Yeah. I lived through all of that.
Right. And my role there was it mm-hmm. Telecon IT infrastructure, consulting, building, driving technology.
And then around 2007, I've always touched security, but security wasn't my primary. Okay. Around 2007, we made an acquisition of this little company called CyberTrust.
Sure. And then I went to work for CyberTrust, that side of the house. So I was one of 12 engineers in the country.
And, uh, I had a big territory, so I started blending it, telecom and cyber. And that's how I got into it. What a great story, man.
Good for you. I, I, I re I know all those companies. I'm old.
Um, anyway, I wanted to talk to you today, Antonio, about, you know, I call it Cloud Native security. And, and that covers a lot of things, but you know, a lot of people today are running containerized infrastructure, Kubernetes, managing it. Maybe they got a service smash on there, and they may be using GI Ops to upload stuff.
And they might be running bare metal. They might be running on top of a hypervisor. They could be at the edge and or all of the above are Absolutely right.
And it's a challenge because like, you know, I've been in it a long time in tech, a long time. Every new wave brings its own complexities and challenges. Talk to me a little bit about the ch and you, you've seen this firsthand.
You lived, talk to me about the challenges you've encountered in trying to secure this, you know, cloud native type of environment. Absolutely. Well, first of all, there are not a lot of tools available readily or vain, especially for some of the things that are coming out in the newer models.
Like AWS Fargate. Yeah. Right.
It's a very limited tool set that can actually get out there and give you the security or give you the information that you see. Right. And for me, before working with Qualys to deploy cloud container security through Qualys, I had very limited visibility.
The day I deployed it, my visibility went up nearly a hundred percent. So for me, container security, to your point, it has a lot of nuance. It's serverless, it has these little things called lambdas.
It's, it's, it's, it's not new, but it's the wave of where everyone is born. You very, you very seldom hear people talk about VMs anymore. Right.
Everything is containerized. Absolutely. It, it is the default.
So for Greenfield, right? New, new, you know, uh, applications, infrastructure, something like 80 plus percent is, is containers. Containers, boob, brownfield.
So modernization, call it modernization transformation, it's still upwards of 50%. Right. If people are gonna modernize, they move from a data center to the cloud one cloud to another or what have you, they're moving to containers.
They're, a lot of them are also transforming those applications from monolithic like waterfall mono to, uh, to microservice architecture. Correct. Which is a whole different ball there.
Yeah, it is. I mean, it, it, it's, and from a security point of view, you said there's not a lot of tools, right? It's not, it, it's a, it's a different animal.
Yes. Different animal. Let's talk a little bit about the Qualys solution for these kinds of environments.
Well, one, for one, it gives me the visibility. And that's the biggest thing. Because if you can't see it, you can't protect it.
Absolutely. If you don't know about it, you can't protect it. So for me, visibility is number one.
Now that I have visibility, I have insight. Now, some of the other things that are more structural and more fundamental to Qualys is this whole QID thing and how they're able to stack rank or prioritize the information that they're seeing, right. To help my team be more available, to deal with risk that are what I would call all high value risk.
Okay. Meaning if I can go and pinpoint what I need to work on immediately and take that information and act on that information and reduce the high value vulnerabilities. 'cause all about, all vulnerabilities are not built to sectors.
Right. And to get rid of the noise, to get to the signal. 'cause that signal to noise ratio before deploying Qualys was very off.
And now that I have it, I'm able to pinpoint exactly what I need to do, where the high value is, and then make it seamless to my team. Because that, that was another thing. My team, whether it was dev, engineering operations, they were not seeing the same stuff.
Nah. And now with Qualys, we have the seamless set of dashboards that allows us to see the same information, which makes the, the remediation effort a lot easier. We are talking the same language.
I'll tell you what makes it a lot easier in my opinion, is having one guy who's it and security, because otherwise there's a lot of this that goes on, you know, and a lot of, a lot of territorial matches. Right. I, I think, you know, as a lot of people out here say, ah, he's crazy.
But no, I'm telling you, when you have a single head that is security, NIT, right? Uh, summed the CEO of Qualys used the term in his, I don't know if you support his, uh, keynote here. I did, I did.
Dashboard tourist. Right. Did you catch that one?
Yeah. So, and I've lived that my, and not just in security, I get it with Salesforce. I get it with a lot of our products, you know, that we, we've been so busy making individualized, customized dashboard views for every role in the organization.
But your dashboard is, is so different than my dash. It's like the tower Babel and none of us talk the same language. Exactly.
And, and to me that, and so these tourists go from dashboard to dashboard. You know, they visit, but they don't live there. And so what you are describing, where you all talking the same language, that's key.
That, that's, that's invaluable right there. Now I would tell you this, we didn't get there overnight. Oh, I'm sure you did.
It. This is a process. It's a process.
And why I have great influence over securing in it. I don't control my dev team. No.
And I don't control my engineering teams. So that rolls up to the CTO 'cause that's all customer faces. So you got a CTO who's like a CPO as well, kind of.
Right. So that's, that's the model. Now, the CTO's, the CPO and the CSOs, the CIO.
So, and, and I don't report to the CT. Oh, I get get it. I report to general counsel.
Yeah, well you're coming. Okay. So I You're under risk.
Yeah, I'm under risk. But they get it and my CTO gets it, but the friction is still there. Oh yeah.
You know, I, I, I said it Well, their profit motive motivated. Yes. Not necessarily the case.
They still view you guys as a cost center. I've been working to change that. God bless you.
That's how it's worked. I just, I just had that conversation right now. And this is the right time to have the conversation.
Right now, security no longer is in the back office. Yeah. That's why it's in the boardroom.
It's not in the boardroom. Because they want to hear about it. It's in the boardroom because it can cost serious dollars.
But more importantly, it's in the boardroom because it's high risk. It's this little thing called supply chain management or third party risk management, however you wanna look at it. That brings the conversation of reveling to the table.
Because right now you can't close a sales deal if your security house is not in order. You got your s bombs and everything. They Yeah, absolutely.
So now you have this thing, like I, I told my board last week, I just presented to my board and we have this little thing, you know, because we deal with phone numbers, phone numbers are not really considered PS PII, not as a standalone. And they're not considered high risk targets. So that means our risk tolerance is very high.
Right. Right. And if your risk tolerance is high, typically your security controls are low.
Yeah. Right? So you don't spend a lot of money on security.
That was the case prior to my arriving. Now they understand we're not selling to ourselves, we're selling to customers. And some of our customers happen to be financial institutions.
And that risk tolerance is very low. Right Now, my security controls have to go very high. Yeah.
If I wanna win business. Absolutely. So security is no longer, um, cost center in my humble opinion.
I, I don't, in my opinion I agree with you a hundred percent. I think that is the old way of looking at it though. Because here's the deal.
I, and I think you hit it on the head, you cannot have products going out the door that are not security tested, that are not secure to the, to the best of reasonable degree. Right. Now you sell to the government, the government's starting to put in what they were talking about putting in, you know, then it had to be free of any known vulnerability if you're gonna sell to the government.
Absolutely. That's a pretty high bar. Right.
Because a lot of software goes out that door with vulnerabilities in there. Right. That's the nature of this.
It is, it is funny that you mentioned the government because my biggest sponsor is the FCC, the Federal Communications Commission. Uhhuh. I meet with them once a month.
We have a hard requirement to be FSMA compliant. Yeah. Now, because of that hard requirement and because of that, that no known vulnerabilities.
They're exceptions to this. Yes. But they wanna know how well are you managing those vulnerabilities.
Yes. And it's, it's not called vulnerability elimination. You never eliminate the vulnerabilities, but it's, it's management.
It was always vulnerability the same way. It was always about risk management. I agree with you.
So what do you think so far about the conference? The conference has been great. Um, some of the things I'm learning, I deploy almost 95% of Quas products.
One thing that I realized is I'm under utilizing the capabilities. So some of the things that the product team and I have been talking about is how do our teams get together? We already meet rag group, but now we wanna get together so that we can figure out how to maximize utilization.
Perfect. You're not alone in that, by the way. I, you know, I think on the whole, ha, so I've been at security 30 years.
I started a few security companies on the whole, I think customers use 30% of the, of the buttons and dials in an interface. And you asked me about that other stuff, and it's like, yeah, we don't use that. We don't use that.
And, you know, and, and yet I've been on the product side of the house where, you know, every piece of real estate on that screen is valuable. And yeah. Getting people to use it is what it is.
Right. I don't, I don't know if God bless you for trying, but I don't know if that ever changes. Well, that's where the influence come in.
I, I think that's why I have some leverage of playing a dual role and having both teams, because my teams are interested. You know, and if you let your teams explore, right. Because I empower my teams to go out and learn the technology.
I don't make technology decisions. My team do. I I'm not managing the stuff.
They are agree. Now my job is to make sure that we, we have the right stewardship in place, right. And the right financial model.
But outside of that, they're the technologists. They're living in this stuff every day. And I always tell them, if we have less than 70% utilization, we need to get that up.
Otherwise we need to get it outta here. Agreed. Man.
Adrian, we're about outta time. Okay. I appreciate you coming on here and tech from TV and talking to our audience.
Keep up the great work. Enjoy the rest of the show. Let me ask you one more question actually, while are we here, did you come in early for any of the training?
Uh, no. I, I, I arrived yesterday. Alright.
Only because I wanted to actually talk to someone who's sat through the training, but we'll find someone. Thank you. Antonio Anderson here at the Qualys Rock on.
We got one more interview coming at you on a long day today. And we'll be back. You're watching Tex Strong TV.