Cloud Security and AI with Checkmarx’s Sandeep Johri at RSA Conference 2024
Sandeep Johri, CEO of Checkmarx, highlights the company’s successful growth amid challenges faced by other startups, attributing it to their cloud-native platform and focus on consolidating AppSec benefits. Sandeep underscores the criticality of cloud security and the integration of AI into cybersecurity practices, while also emphasizing the importance of DevSecOps in seamlessly embedding security into the development process.
Transcript
This is Textron tv. Hi everyone. Welcome back.
We're here live on the last day of RSA conference. We hope you've enjoyed our last three days of coverage. We've saved some of the best for last, though sitting here to my left is a friend of mine.
I've had the pleasure of knowing now probably five or six years. I bet. Uh, Sandeep Johari Sandeep is the CEO of check marks.
Sandeep has a long history in, in, in the cybersecurity market, as well as in DevOps and DevOps testing. He used to be the CEO at Tricentis as well. Um, just a very intelligent guy.
Not as nice as his wife, quite frankly, but still a very nice guy. Um, Sandeep, welcome to Tech Drunk tv. It's great to have you here.
Let's first start off with check marks. You guys, you know, it's been a tough year for a lot of venture backed companies, a lot of the startups, but check marks has seen seem to thrive over the last year. Yeah.
At least from my, where I sit. But why don't you give us sort of an inside look there, if you don't mind. Yeah, Sure.
What's so, so check marks, uh, we were lucky in that, uh, four years ago that the team, uh, realized what's going on in the market, which is that the, that customers are looking for two things. One, a cloud native platform and a consolidated platform that can offer all the benefits of AppSec. So we started that journey last year, uh, four years ago, and last year was our, uh, kind of maturation of the platform.
So, uh, we grew checkbox one is the cloud native platform. We grew that 200 plus percent last year. A doubled our customer base last year.
So we had a great year. Now you talked about startups having a tough time. Yes.
Most startups and especially ones in security are not making money. We all nonprofit orgs check marks actually is one of the few ones that in security is profitable and has, you know, so we reached profitability for the full year last year. We are gonna expand that this year.
So we have the sustainable sustainability power that many of the other vendors are gonna have some trouble this year as, uh, people start running outta money. Uh, We're seeing it, I mean, valuations and, and and so forth, you know, and when there's no money to have you gotta, you gotta do what you have to do. Obvious.
That's right. Obviously. That's right.
So being profitable and having a little dry powder uhhuh, you know, gives, gives one all kinds of possibilities. Might we see some check mark acquisitions? Yeah, we are definitely, uh, looking at acquisitions as well.
Like I said, you know, we, I I've, I've done a lot of acquisitions at tricentis, at hp, so I'm not averse to acquiring companies for that matter, in technology, in security especially. There are so many, uh, really innovative, um, uh, strong companies. So I'm very open to it.
We are considering, we, we have had conversations with many, uh, I just wanted to settle in, uh, and get our, uh, house in order and, and, you know, wanted to make sure that we are profitable and our on solid footing and our check marks one platform is, is, uh, is table and scalable. And now that it is, I think this year we'll see a lot more of that happening, I think, across the industry, but also for check marks Itself. Absolutely.
I, I think we're gonna see a lot of consolidation this year. Uh, Sandeep you mentioned Cloud native. I, I was just in Paris, I guess it was almost two months ago now for the, uh, CubeCon event.
It was their biggest cloud native Uhhuh endeavor. I 12,500 some odd people. Fantastic event.
Great energy. I'm wondering, so I'm bullish on the cloud native, you know, as, as the new stack as we call it, right? It's the new way we, we do stuff.
I'm wondering what you guys are, I mean, obviously you had phenomenal growth, so there's gotta be something there, but what do you see in the cloud native ecosystem that gets you excited? You, You mean cloud native for security Securing cloud native? Yeah, and, and, you know, cloud native in general even.
Yeah. So, so, you know, enterprises, and I'm talking about the very, very large enterprises are actually accelerating their cloud journey. So I've had, I've had the pleasure of meeting four or five CISOs from large large banks, US banks, uh, here at RSA, and every one of them is accelerating their cloud journey.
As they do that, obviously cloud security becomes very critical, which is why you see the phenomenal growth that Wiz and some of the, uh, cloud protection vendors have. But that's almost a little too late in that yes, you can protect at the cloud level. We see AppSec as being a critical component.
The, the holy grail in security now as people are moving to the cloud is code to cloud. Yeah. And the cloud protection vendors are doing a great job of protecting and figuring out posture in the cloud.
But to really go fix it, you have to have AppSec. That's how you get go to cloud. So we have customers very aggressively moving to the cloud.
Now, from our product perspective, we integrate with the cloud native, with the cloud runtime protection vendors. We have integrations with, uh, with Wiz, with tic with Cisco. We have partnerships underway with most of the other major players.
So that's how we deliver code to cloud. We've not had any resistance in our customers adopting our cloud native product. One because they're going to the cloud themselves.
Two, we have multiple deployment models. So we do multi-tenant, cloud native. We also do a single tenant cloud native.
So really large organizations that don't want to do multi-tenant can do a single tenant in their tenancy with them being the only one, and we can encrypt it. So they're, they're quite comfortable with that, so. Excellent, excellent.
I, I think again, we're, we're gonna see that as long as we're talking trends. Let me continue along that ai, a lot of people are saying we should have called this year's conference, RS ai. Um, Sure.
Every conference, Not just conference. Everything we do, it's extra. I, you know, we started our whole site just for ai.
Yeah, makes sense. But it's still, but it's still on every other site we have. Yeah.
Wondering its effect. What are you seeing at Check Mark? How is it changing things at check marks?
So there, there's, uh, there's three things that we think about it in three, uh, kind of code buckets. One is how can we use gen AI and AI in general to improve our product? And we are doing a whole bunch of things on that front.
What can we do to improve our product, build it in. And we announced, we had a major announcement, uh, earlier this week, um, or late last week on Gen ai, a number of initiatives. So that's one bucket.
Second is, what can we do with Gen AI to enable more value realization in AppSec? So for example, we have added capability where, uh, you know, developers hate security. They don't want to become security experts.
We tell them, here's all your problems, and now they need to go become security experts. Well, with Gen ai, we actually tell them, you don't need to become security experts. We will not only identify the vulnerability for you, we'll even tell you how to fix it.
Mm-Hmm. Here's sample code on how to fix it. So we are using ai, gen AI to actually help our end customer become more efficient, become, uh, you know, deal with the real value that they want, which is make my security problems go away.
Right. The third area is actually the most interesting area, which is for a security company, which is gen AI actually brings in now yet another vector of vulnerabilities. So for example, there's a lot of, uh, use of open source.
Well, there are examples, and our research team identified some of these and published them where genai is cranking out open source packages that are not real. They're hallucinations. Yeah.
If you ask Genai enough times, it'll go create a package for you. You think it's an open source package. So, uh, supported by the community, it's a made up thing.
Yeah. Now, those packages are the ideal for malicious code. So AI kinda new threat vectors that are AI specific becomes really interesting.
That's what, uh, you know, that's what CISOs are worried about. Sure. Is what kinds of new threat vectors we are gonna get.
And if we are auto generating more code, is that code clean? So we are spending a lot of time on that. We've added a number of capabilities there as well.
So It's interesting, I had a conversation with some folks yesterday is ai, should we use AI to generate code or to edit code? Is it a better editor than it is a generator? But you shouldn't use it for both at the same time.
Right. Don't use your AI to generate your code and edit your code, because that's probably a recipe for, for bad stuff. Um, I Would say put it, uh, slightly differently.
Go ahead. Do it for both, but make sure you don't, um, delegate all your responsibility to Gen ai. For example, auto generation of code on, on a chat GPD or a Azure AI plugin.
Awesome. However, that code, you cannot assume just because it was machine generated that it's vulnerability free. So it's great to have a generate code, but make sure you still have AppSec so that you can scan it.
We have a plugin for chat GPD, and now for Azure ai, what the plugin does is it lets you generate code, but before you accept it, we scan it to make sure there are no vulnerabilities. So as an enterprise, you want to encourage your people to generate code using gen ai, but also put in, put oversight mechanisms. In our case, what we have done, what we have enabled is a, a, a scanner that checks to make sure the code is good before you bring it into your enterprise.
So Absolutely. And that is, I, so that's the kind of the, the nuts and bolts, practicality uhhuh that we're going to need to make AI real. Correct.
There's a lot of hype out here, but to make it real and, and you know, and this is great. It's some, call it DevSecOps. mm-hmm.
It's part of this DevSecOps. And that comes to the next thing I want to discuss with you. So we were talking earlier on Textron Gang and we're talking about AppSec DevSecOps.
Is, is AppSec equal to DevOps? In other words, is are they synonymous now? Is it the same thing or is there more to AppSec than just pure DevSecOps or, or vice versa?
Checkmark lives in that world. You've been in this world. Uh, the kind of thing you just described with AI in my mind is DevSecOps when we're shifting security left Mm-Hmm.
Into where we're writing code. Yeah. That's devs sec.
To me that is Uhhuh. Is that AppSec? So I guess what do you think?
So, so check Marks has been a leader in AppSec for a long, if you go Yeah, for a long time. If you go back a few years, pre DevOps security was an, in the waterfall mode. Security was one of the waterfalls.
Right? You get, you do your build and then before deploying, you ch run security checks. Hopefully.
Hopefully if you do, yeah. So AppSec was used in that mode, which is the security team would run the scan, the security team would identify what, what the problems are, and then go beg the dev team, or if they had the authority, stop the dev team from shipping till they go fix those things. So that's what AppSec was called.
Now that mode is no longer the case. Everyone is doing it in a continuous mode with a dev, with a DevOps methodology, which is what, and you have to have security built into your DevOps practices. So our customers, for example, most of them have it fully integrated and have our tools fully integrated into the CICD tool chain for that matter.
Many of the, and, and we have plugins that go in that are inside the IDE for that matter. Many of the developers, the end users don't even know that they're using check marks because they see a plugin that helps them with the fixes. The build server is doing the at, at every pull request, it does a scan.
So it is fully integrated. So in that sense, DevSecOps and Dev and, and AppSec is one and the same for me. So I, I don't disagree.
I I think it's a question of, you know, wearing a comfortable pair of jeans or a brand new sip stiff suit. I think some people, especially people who have been in AppSec mm-Hmm. Before DevOps mm-Hmm.
You know, they think of top 10, they think of sort of that traditional AppSec pen test, you know, and or, and they're doing, you know, pen tests now as a shift left before deployment. Um, and when you say DevSecOps to them, they, they, they, they pull back a little bit because they don't fully accept. There are a lot of people that don't fully accept DevSecOps as a thing.
Right. It's, Uh, It's marketing to them. No.
Now, not every enterprise is mature enough in the DevOps. Sure, Yes. Methodologies and across all the applications to embed DevSecOps into, or embed agreed SEC into devs, into DevOps.
But, um, DevSecOps is not marketing. Uh, I mean, we have, I agree With you. You're preaching Yeah.
com. Yeah. We have customers that have, um, you know, that are doing, uh, penetration testing, that are doing, that are doing, scanning all their code before they used to do it, after the fact, after it's being built or after everything has come together today, they're doing incremental.
We have customers that have, with every pull request, they incrementally scan that piece of code. If you don't meet their guidelines on, uh, security vulnerabilities on that piece of code, you can't submit it. It doesn't get built.
Absolutely. So that's where everyone wants to do, uh, wants to get to. And at the end of the day, only developers can fix vulnerabilities.
So you have to shift it as much left as possible, which is why we have plugins inside the I-E-E-I-D-E now. Yeah. And that's, that's where the action is, whether it's in gi, gi, GI ops and so forth.
An interesting thing though, we see there is that with, with DevSecOps and, and, and this whole thing is the developers, we've seen these studies developers spend somewhere between 11 and 30% of their time coding. Mm-Hmm. Depending who you believe.
Certainly not more than that. And developers want to develop and security folks want more secure code. And if you could do that in a way that it increases the developer's ability to develop Mm-Hmm.
So it's 40%, 50%. I think that's great if we're putting it in the IDE, but it quote unquote makes more work for them, but gives them less time coding, we get pushback. Our, we, we recently did a, a research thing called DevOps Next Mm-Hmm.
And, and would Dev SecOps next is a subset of MM-Hmm. And, you know, we were surprised to find that 20% of enterprises are doing dev SecOps, uh, organizationally. You, you might have bubbles, a team here, a team, you know, dev team there and there, but organizationally Mm-Hmm.
They're not only about 20, 22%. They have it, they have multiple tools. There's a Yeah.
A lot of tools. Mm-Hmm. And that, that's, that's a whole nother story, right?
Mm-Hmm. How do we consolidate it to a manageable tool set? I really feel like even though we've been preaching it here for eight years, dev SecOps, the future is still in front of it.
I think the, the market opportunity is still in front of us. Yeah. Uh, I mean, I, I, I, you're absolutely right, not every large enterprise has fully adopted DevOps, which is why they can't fully integrate SEC into DevOps.
Sure. Having said that, I think security companies, especially AppSec companies, have, have done a little bit of a disservice in, in that developers today get too many vulnerabilities from five different tools. This duplication, there isn't enough prioritization.
So one of the main benefits of our platform check marks, one, is that we have all of these various static analysis, open source supply chain, API, all of these in a single platform. We can correlate across these and, and then pull in runtime data to narrow down the list of things that, to identify what are the most critical things that developers need to fix, and then prioritize them so that the developer doesn't get overwhelmed. And that's what drives the adoption.
That's what drives the effectiveness. Not everybody does that. If you throw a thousand vulnerabilities at a developer, they're not gonna do it.
Why? Because they'll never ship anything. Yeah.
And, uh, that's yet another issue. Right. But this is always, I remember when, uh, still secure, one of the companies I co-founded, we had a vulnerability scanner, a management product.
That was the problem. It was almost job security because you had so many vulnerabilities. That's right.
By the time you finished that, you had to scan again. But the truth of the matter is that if you prioritize them, right, uh, we for example, have a risk engine, right. And a risk assessment.
Uh, if you prioritize them right, then you can get the teams to focus on the right things. And without that, DevSecOps doesn't work. No, absolutely.
'cause if you're gonna dump a thousand vulnerabilities at each developer, they're gonna learn to ignore it. Right? Well, And that's exactly what happens.
Anyway. So if we're about outta time, you know what we didn't mention, let them know. They want more information on check Marks way to go.
com Easy. com. Dot com.
Yeah. We got a lot of content online. com.
Absolutely. That's a wrap here at RSA. We're live.
We'll be back. We still have some more coverage coming up. I think we have another hour maybe here at RSA Sandeep, say hello and congratulations.
This Alan Shimmel. We're out.