JC Najera, Syntax | Qualys QSC22
JC Najera, the subject matter expert for vulnerability management at Syntax, joins Alan Shimel at Qualys Security Conference 2022 to discuss app security and what customers expect from Syntax services, as well as prioritization of vulnerabilities.
Transcript
This is texturong TV. Hey everyone. We're back here live in Vegas for the quality QSC event a 2022.
I'm really happy that you know, one of the nice things as we we've had a good mix of koalas people speakers customers. I'm gonna introduce you now to a gentleman who's from a company there there. Maybe I could call us Channel partner, I guess right.
Yes way to describe it. His name is Juan Carlos. JC naharan, but he's gonna say better than me.
Yeah, it's just Jose Carlos nakara. So Jaycee for for friends, right? And so we're good.
We got JC here. So JC, first of all before we get into your company a little bit about your background, right? So I've been using Flawless for almost 10 years now.
So I like koalas a lot. I am the subject matter expert for vulnerability management for syntax syntax is a large Erp hosting company. We do SAP, we do our cold business and we have our Advanced Security Services as well.
So that's that's pretty much it. Yeah, you know what attracted when you told me about this JC is it in the com days 1990 late 90s then into 2000. I actually helped put together a company that we back then we called in in ASP application service provider.
Right? But we would be hosting Oracle applications and people. Off and load his notes and bunch of you know, Enterprise kind of apps like that.
So and then that's actually how I got into security as we started hosting managed firewalls checkpoint firewalls. Wow, and that was how I started security. So it's a generation before you but very similar kind of yeah, so, you know the interest interesting thing.
I I know from my own story as well as talking to you is look when you're hosting people's Mission critical applications like that you take on the role of sort of a trusted advisor? Right? Right, and they they want to make sure their apps are running.
And security is part of that. It's not just the app itself. It's the delivery.
It's the availability, you know, all of the things you want in an Erp provider. So let's talk. Now you mentioned you in the for vulnerability you as a subject SME.
Yes, sir. What are your customers expecting from you? Well, I mean they they normally want to know how can they measure risk on their end?
Right? It's very important. It's how we can we can translate the security conversational language into the business language.
So then people can understand that by people. I mean Executives there's levels right? So they trust us on telling them where are the risks at?
So we're using Wallace to do that. So what we're doing is with this new tourist thing, which is very interesting because we can assign criticality to their assets. And then with that and the cute the quality detection scores we can see and we exactly what the risks are based on that acid.
So the crown jewels, for example, they're they're super important, you know internet facing devices are important they get this criticality score assigned and then quality tells us what is really important, you know, volume-based is something that it's it's already passed right? It's old-fashioned now. Yeah, so it's all about risk basically well.
You think about it? It's always been all about risk. Just didn't know how to measure and manage it.
Well, right and we're getting better at it when? When you use koalas, so you mentioned some scores and stuff and then kind of translating the security talk to the business talk. You know, I I've been in that I've been in your chair, right?
And what is the customer? What does that sea level customer want to know? Am I at risk?
Am I safe? It's my stuff safe. Right?
And you know, I don't care how good You are you're never totally safe, right especially if you connected to the internet, it's the nature of the Beast. And I think people have to understand that when we say manage risk. We don't say you're safe.
We don't say you're never going to be attacked. We don't say you're never gonna have an incident. What we say is look for the amount of resources.
We're putting in. We're lowering the chance of that happening exactly significantly if you want to lower it to zero. You're gonna have to put in a lot more resource.
Oh, yeah, probably, right. Yeah, maybe disconnect from the internet. Yeah, I mean having zero vulnerabilities.
I mean it Technically could be possible. You will need to patch every single day and reboot every single day. But that's only in a point in time tomorrow.
You're liable to Define your ability. Exactly. So you got to be very very wet to what your targeting and that's why you know risk is all about like we have a lot of vulnerabilities being released every single day.
You cannot keep up with that. So you got to focus on what's really important, right? Absolutely so that gets into the whole prior to prioritization of vulnerabilities.
Exactly. Yeah, the prioritization module. I was joking with with Matt Barnes my Tam and I told him when I saw first the prioritization module that I was I was worried.
I would I would go out like no job at all because that thing is it's it's a good thing. It's a good tool you can put in or craft the special recipe and then click one button and then you will get your priorities over there. And now with the true risk part, you don't even need to think about the recipe anymore because it's already in the right you so it's super you know, what I've been at this a little longer than you.
Security people never become obsolete not to worry Jesse. You'll always have a job man. Oh, yeah, but you're right.
It has gotten has got much simpler to you but to you know to zero in on these things. Yep. so now you're in a maybe a little different position than some of the other customers we because your servicing a wide amount of customers.
So the amount of environments the amount of different vulnerabilities the amount of variables that you're dealing with. Right in many ways. You probably see.
You know 10x 100x more than just a person works for one company. Yeah, and you know, so you're using quality across the board here with that. You find it scales out and fits the bill.
Yeah, absolutely. So that's one of my favorite Parts about my job at syntax. Where since we are in Erp company, we have the chance to meet a lot of customers with different needs different perspectives different problems different challenges.
But in essence, I mean if you can standardize them in in a single platform such as quality, right and that's that's what this job is like why this is fun, right? Yeah. We got this new perspective everything.
It's always new. It's always new and you gotta be Super Creative to find those things and then expose to the sea levels and the executives your ideas. So they understand what's really the risk because their businesses are different, right?
So you got to be very creative on that. Absolutely. Have you had an exposure to the total Cloud Flex scan?
I haven't I I just saw the presentation. Yeah, and it's fantastic. I really really want to go I yeah, I got to imagine you're you know, and syntax is lying to business.
This is gonna be something you guys probably got to get. Absolutely. Yeah, you'll quick.
Yeah, we rely a lot on the Erp Cloud part. So we're doing sap over AWS or as you're for example, or oh, sorry, I even yeah, so it's it's gonna be a game changer for sure because we do want to do what we're doing currently on the let's say the traditional way of doing sap or Oracle or whatever. To the cloud as well.
So this is just going to make our lives easier to be honest. I agree actually so you know what I didn't ask you for people who want to maybe get more information on syntax. What's the website?
com. Did you spell that for us? com.
Check it out JC. Thanks for being I guess thank you very much. Right the good fight man.
Well do sir excellent very much. All right. Hey, we're live in Vegas here at koalas QSC.
We're gonna be back in a minute.





