API Security and WAF with Imperva’s Nanhi Singh at RSA Conference 2024
Mitch Ashley sits down with Nanhi Singh, chief customer officer and GM of application security at Imperva. They discuss the accelerated digital transformation during the pandemic, emphasizing Imperva’s customer-centric approach and focus on API security. Nani highlights Imperva’s upcoming containerized WAF solution, addressing evolving security challenges while leveraging AI and maintaining operational efficiency.
Transcript
This is Techron tv. Hey everybody. Mitch Ashley here at RSAC 2024 in San Francisco.
It's Wednesday, whatever day number that is for you. It all depends on, I guess, when you start. We've, I've been here since Saturday, so what, a few days into it.
You know, I have, I have a great pleasure of talking to so many companies who are doing fantastic things with their customer, for their customers and in our industry. And per is one of those companies that I often get to talk with, uh, with Pam Murphy and many of the folks, um, at the company. Today, I'm talking with someone new I've not chatted with before.
Uh, Nani Singh, who is Chief Customer Officer, as well as application security gm. Right. Fantastic.
Welcome. Thank you so much, Mitch. Yes.
I took on an expanded role after the acquisition of Imperva by Tallis. I was Chief customer officer of Imperva and continue to perform that role. And now I'm also responsible for the application security business and all of our products and the roadmap.
Very nice. Should get, have now that product, G, m, P and L responsibility as well as the bigger, the broader role. Right?
Absolutely. Yeah. And, and you know, I've spent my career in cybersecurity and in, uh, customer facing roles.
Hmm. And I think that, um, what I bring to this role is a customer first mindset. And, you know, we are, we are not doing science experiments with our products.
We are looking to solve real customer problems. Mm-Hmm. That's one.
And the second thing is that I've always believed in taking the feedback from the customer and working it into our processes that serve the customer. And we've done that in terms of taking the feedback and tactically working in that feedback into our roadmaps. But now what we are really focused on is design partnership with our customers and taking their input in the vision of our application product portfolio and our strategy.
Uh, and I've had a lot of those discussions here this week. And I have to say, I am energized by the conversations and by the level of engagement. Um, so it's, it's exciting.
It's exciting to be here at RSA. Fantastic. We, we can talk about all kinds of security things.
One of my favorite topics is application security. And, you know, I've been coming to RSA too for, for a while and a number of years actually. And it was really kinda last year, maybe the last two years, where application security kind of came above the fray.
People in the security world were talking about AppSec and APIs and, you know, kind of waiting is, when is that gonna happen? It seems like, uh, we kind of arrived. Of course there's more we can do.
What's, what, what are you hearing from customers? What are some of the challenges people are moving to cloud native and microservices and API first and maybe things that security people didn't talk about a couple years ago, but now it's all part of the conversation. Absolutely.
So I think what, you know, over the last decade, you've probably heard about digital transformation, the migration to the cloud, right? But when the pandemic hit, the digital transformation got expedited. Right.
Uh, I always use this example of how our experience as consumers changed. A very easy example is one of us going into a restaurant to order food. Um, we don't really touch paper menus anymore.
We pull out our phones and we scan a QR code. And what is that doing? That's using an API from your mobile device to pull up a menu, right?
And then you're making a selection and you are hitting pay. And now that's another API call from that application over to, um, maybe a backend, um, that is processing that transaction. So I think that digital transformation just got accelerated during the pandemic.
And then what I see with our customers is that they have applications pretty much everywhere. They're all in different stages of their, uh, migration to the cloud. And some have lifted and shifted and now realize that they weren't really taking advantage of everything that the cloud infrastructure gave them.
So there's a lot more discussion about cloud native. So the way that I see this, uh, is that we have to be where our customers are and we have to secure applications where our customers choose to deploy them. And that is, uh, what we are focused on at Imperva is providing the best in class security that we've provided for decades.
Imperva has been around for a couple of decades now, has been a WAF leader for a very long time. And one of the things that has put us on top is our focus on security. And we take great pride in that, and we lead with a focus on efficacy.
Excellent. You know, that that transformation, the digital part of it seems like we've gone through an organizational transformation too. When we talk about security.
Um, are most of those conversations around AppSec API security happening still in the development teams? Or you see more of it happening in the security teams? Are they working together more on those in that area?
They're happening everywhere. Hmm. Because I'm increasingly seeing roles like Chief Digital Officer Mm-Hmm.
Chief e-Commerce Officer. Because what has happened is that the business has shifted to being digital first. And what that requires is it's not just about, you know, the security people securing the applications, the developers developing the applications.
It's, it's about enabling a customer experience and how do you do that while minimizing the risk to your business. So it's, it's a conversation that everyone is involved in. Now, One of the things I'm really excited about your combination of roles is it's easy to get locked into the technology of it, the security of it, the application development of it, and securing APIs, ultimately that's all in service to something else, right?
I think you mentioned mobile. Think about how much more, many more mobile apps are part of our digital experience. Now, what mobile app doesn't use APIs, very few mobile apps just live on your phone.
All the rest is through APIs. It wouldn't be enabled that way. And we live in a world where that communication has gotta be just as secure, if not more so than the overall experience.
Right? Absolutely. I think that the one conversation that all of our customers and even prospects want to have with us right now is about API security.
And, uh, I think that, uh, you know, we are now talking about WAF and API security together. Uh, the other thing that we, um, also see is that a lot of the attacks on the APIs are actually bots because almost 50% of the internet traffic is bots. So our API security product ties in really well with the offering we have on advanced spot protection.
And, um, we see that, you know, we are actually solving real business problems with those offerings. It's interesting, even the, the CDN the network providers, you know, say numbers of 70, 80 plus percent of our traffic is API traffic. Yes.
Not just HTP, right. Web web traffic. So it is the commerce, it is the communication mechanism.
We talk about. How do you, um, a a as chief customer officer, how do you think about helping your customers, uh, deliver better security but not lose the customer in the process? That's, that's a really good question.
So I think that the very first thing is you have to eliminate as far as possible false positives, right? Because security has to enable the business. And that is really one of the things that I am most proud about with our, uh, especially our cloud WAF solution.
Um, more than 90% of our customers use us in blocking mode with, um, almost no exceptions to policy. What percent was that? How many?
It's actually 92%. That's amazing. Precise.
Because, You know, being around a security while, you know, that's a big to flip that switch into auto response is a big, big commitment. Absolutely. And, uh, in fact, that's amazing.
Uh, we've been meeting with customers here and, uh, every time they, you know, we ask them, we say, are you using, when you onboard a new application, do you onboard it in blocking mode? And they go, oh, yes. And we are like, can we record you?
Because when we talk to customers who haven't experienced Imperva's solution, they find that hard to believe. And, uh, and it is actually the truth. And we have obviously many customers who are happy to be references as well, uh, and talk about their experience.
Uh, but that's really what it is about, is how do you enable business and how do you not get in the way of business because you never want to be, well, the app was down because, you know, a security policy, uh, triggered something that it shouldn't have. And the other thing that we find now is that our CISOs are often asking us to help them explain what our solutions did for them. Mm-Hmm.
Right. How many attacks did you block so that they can really explain the value that, uh, the security products are bringing to the company. Yeah.
It doesn't, we don't, uh, report metrics some how many good things happen that we didn't have to invoke those that blocking. Right. Yeah.
You know, it's interesting, I, I, uh, quite a while ago I interviewed a former CSO from Twitter. And one of the things, uh, that they said to me was, when I look at security technology solutions, I always evaluated on what's gonna decrease work, what's gonna increase work? 'cause I can't, I can't hire more people.
I don't either have staff or money or ability to find those people. Is that something you see us still, you see today still with cil? I can't imagine we always talking about how do we find all these security people?
Well, they're never gonna be enough. It's Like, there, there's already a shortage has been for a really long time. So when we think about our roadmap, um, you know, I talked about security efficacy as one of the pillars for our roadmap, because we are a security company first.
You know, yes, there are, you know, we have CDN capabilities, but we don't lead with that. Um, but the second, uh, big category is operational efficiency. So we look at ways in which that we can minimize the work that a security team has to do.
Uh, and a lot of, um, the discussions more recently have been around. I, can you explain to me what happened? And can you perhaps, you know, and I have to throw this in there 'cause it wouldn't be an RSA discussion without saying Gen ai.
I was waiting, I was waiting. If you didn't bring it up, I would. So how do we use, uh, gen AI to take all of that data, that wonderful data we have from our threat research and all of the customers we protect and explain what is going on and how we prevented those attacks?
Mm-Hmm. Um, so it's, it's an exciting time. We're, we're, we're definitely in that evolutionary state, really kind of figuring out all the things we might do, can do, will do with ni I Right.
Now today, um, you mentioned something about combination of web application, firewall and application security, or API security. Sorry. W why are those two things in combination a powerful thing to do?
Uh, I think that, um, all applications are now basically API enabled, and you cannot talk about securing the application without talking about securing the APIs. Mm. And I think one of the biggest problems today is that, um, APIs are everywhere.
And the first thing that people often need to do is to discover what's out there. Very true. And then get into, well, where are the, the risks in, you know, and, and actually detect where the problems are in those APIs, and then the next step is remediate them.
Mm-Hmm. Right. Very good.
What are, what are some other conversations you're having with customers, not naming names, uh, you know, that are really kind of peaking your interest about either current or maybe some emerging challenges that they're having in AppSec? So, uh, we are, um, actually about to very soon release a, uh, uh, a containerized RAF solution. And, uh, that solution is right now in, uh, beta with many, many customers around the world.
And, uh, as we talk about that solution with more customers, it is really resonating and it's almost like they are relieved that we can offer them the same level of security that they have been used to with our SaaS delivered cloud WAF in a Kubernetes environment. Oh, interesting. So, um, I, I think that is the, the one that I would call out.
Um, and bots, anyone who's in the travel industry or hospitality industry in particular, any e-commerce, they have a bot problem. So they wanna talk about that. 0, um, uh, we've gotta get compliant private, The ever evolving landscape too.
Yeah. I'm curious about, so the containerized, um, a container security that you're delivering, so this is not part of the, uh, SaaS services, this, this is something that they can operate within their environment, correct, Correct. Customer managed.
Is that, is that tied to moving to a microservices Kubernetes architecture, or is it, can you use containerized with, without going down that path? Well, right now the focus is the Kubernetes architecture. Okay.
And it's really the, uh, our solution that allows our customers who want to go that route to get the best of what Imperva has had, uh, in the past several years. So what we've done is really taken the engine of our cloud WAF and enabled that in, uh, in a Kubernetes cluster. Mm-Hmm.
Well, it's gotta be an advantage too, of they're already operating your WAF in other environments. Now they can do it within Exactly. Bernet also, and we're familiar.
We know how it works. We know how to manage it, tune it, you know, monitor It, and it's the same console. It's the same console.
So wherever you've deployed our different, you know, WAF options, you still get to manage it off the same console. Mm-Hmm. Very good.
Um, are there any things happening in the, you know, you mentioned ai, gen ai, there's also the regulatory front to that, which is probably a little more active on the European side maybe than the US though. There've been, you know, presidential orders and things like that. Yes.
But you can't turn on the news without, you know, this person said, you know, the dangers of ai, this person said they extolled the benefits of ai. It seems like it could be a, a solution to our skills and, and resourcing challenges, but it also seems like a big part of it is the bad guys are gonna use it. We need to use it too.
Right? It has to be part of our arsenal to use that metaphor for what we do. Bad guys are using it.
Uh, one of the things that we've seen is that there's been a proliferation of simple bots because it's now very easy without having to really know how to code very well. Uh, you can actually use AI to create a simple bot. So, um, bad guys are using it.
We are definitely seeing that. Um, I think that there is obviously a lot of hype right now. Everybody is talking about ai.
Uh, but I like to think that I'm an AI optimist. Mm-Hmm. Uh, and I like to think that, uh, we will do good things with, with AI as humanity.
Um, and, um, I think in cybersecurity, we all aim to do good things. We aim to secure, um, users and secure our customers and our employees. Um, so I am hopeful for what AI will do for, um, security.
I think security was already in that realm. So much of, uh, you know, machine language was already, ML was already being used. Right.
Of course. Now we talk about gen ai, which is obviously different. Uh, but we've, we've been leading the way in the security industry.
So I think that we will continue to lead the way there as well. Well, we learned a lot managing, um, all the data that it takes to power and use, uh, machine language algorithms on and models for artificial intelligence and Yes. LLMs and all the acronyms that are part of, you know, gen ai Yeah.
Bring some new things to it, but it's not totally unfamiliar with this. Right. We've been, you've been going down this road for quite some time.
Yes. Um, in fact, a lot of the secret sauce in our, uh, WAF is all ml mm-Hmm. It's all machine learning.
And, uh, we will continue to, um, develop that as we Great. Very good. So the, the future question, right, which means you can't be wrong 'cause nobody could say what the future's gonna be.
What do, what do you think, what kind of things might we be talking about a year from now at RSA that are either continuations of current, uh, themes or maybe some new ones? Any thoughts on that? That's not a trick question.
It's, there's no wrong Answer. Yeah. Well, you know, um, I think this from a, from a risk standpoint, I think the whole deep fake thing, it's, it's going to be something we, we think about.
So, uh, I had a very interesting conversation just earlier today with a customer, uh, from, um, from the APAC region. And, uh, you know, they were saying that one of the things they're concerned about, uh, is their bank and is that when people use their banking mobile application, um, they open it with the, the face id. Right.
And, um, you know, they're, they're wondering whether, you know, we should be worrying about deep fakes because they've started to hear about it. Um, I, I haven't personally heard of a specific, you know, breach or something that happened because of it, but, um, I think we'll be talking about that. What if we can kind of connect the dots, you know, the, the adversaries are already doing that too, right?
But how you, I've kind of thought about could somebody take a deepfake and create a 3D model of it and use that to get onto your phone? You, there's gonna be some way Yeah, yeah. Help Figure Out how to leverage that.
Right. I mean, there's so much in the news these days of, uh, people using, uh, CFO's voice Mm-Hmm. And, you know, and basically faking it to call employee, where are this money here?
Right. The money. Exactly.
So I don't think we, we might be talking about it more next year. Mm-Hmm. I, I, I think you're right.
I wouldn't be surprised to put you. Well, well it's great. Been talking to you and thanks for coming by and sharing with us both the customer perspective as well as application security and the kind of things you're hearing and working on with your customer.
We look forward to, um, the, uh, containerized wap kind of continue to evolve and eventually coming out. Uh, congratulations on being part of the Thais organization. Thank you very much.
Boy, I remember when that was like, that was certificates for my server right? Long days ago. Many more things that tha yesterday, so including and purpose.
So it's been a pleasure talking with you. Look forward to likewise our next conversation. Hope you be back.
Thank you very much. Thank you for having me. All right.
So application security. You know, that's one of my favorite topics of course, as well as customer experience. That's a big one too.
So we don't often make that part of our conversation. I think we should more and, uh, some great insights from Nina because she's talking with customers so much. It's part her role.
Also general manager over AppSec. So thanks Tonita and the Imperva team for being here. We'll be back with another great interview.
Can't promise it would be quite as good as this one, but it will be fantastic. Either way. We'll be back in just a moment.