Cloud Security Evolution and AI Integration with Tenable’s Shai Morag at RSA Conference 2024
Shai Morag, SVP and GM of cloud security at Tenable, discusses the company’s integration of Ermetic and the rapid evolution of cloud security at RSAC 2024. Emphasizing a holistic approach, Shai highlights the importance of addressing multi-cloud and hybrid cloud setups while covering the entire software lifecycle, from development to runtime environments. He also hints at the future role of AI in cloud security, suggesting its potential to enhance measures like generative AI and secure AI applications.
Transcript
This is Textron tv. Hey everybody. Mitch Ashley here at RSAC 2024.
It is hopping. We've got some big, big, big crowds. We have some big, big, big, uh, people to talk to, some important folks.
We want to share some good information with you. So I'm joined by Shai Morak, who is SVP, general Manager of Cloud Security with Tenable. Welcome.
Thank you. Good to be Here. Good to be chatting with you.
Um, you know, I'd love for you to tell a little bit of your story. 'cause you've recently, fairly recently joined Tenable through an acquisition. So talk, maybe talk a little bit about that and kind of what's happened since you've come on board and part of the family.
Sure. Uh, so I used to be, uh, the CEO and one of the founders of a company called Matic. Matic was founded in 2019, and we focused right from the start on helping our customers protect their cloud infrastructure.
Mm-Hmm. Uh, we got acquired by Tenable, uh, in October last year. So it's been like seven months, uh, since the acquisition.
And it's been like, uh, really intense from One whirlwind to another whirlwind in some ways. Yeah, I imagine. Yeah.
Uh, so things are happening quickly with Inten. Again, big company, a lot of, uh, opportunities right now in the cloud security space. So we bringing a lot of our DNA and knowledge and great product, and we are leveraging the platform of Tenable, the platform of the sellers and the partners and everything that we can do together.
Uh, and also with the vision of the Tenable one, vision of the exposure management that we are also part of that. Um, so it's fantastic. Great, great time.
What, what, what has being part of Tenable kind of enabled you to expand and do that you weren't doing or able to do on your own? So, a lot of course is on the go to market motion. So if you think about it as a startup, you have limited resources, mostly in the marketing and sales, of course, also in the product development.
Sometimes, uh, when you're part of a bigger company, you can leverage a lot of the momentum of a bigger company. Again, you have the brand of a bigger company, you have a lot of more sellers and ses and go to market motion. You have more partners.
Um, uh, so Tenable has more than 40,000 customers and thousands of partners. So we can leverage and meet all of them, which is of course, one, one part. And also the join forces of the broader vision of the Tenable one, which is also, uh, great meaning sharing the full consolidation of the how we do exposure management in, in the organization, which includes cloud, which includes it, which includes ot, other identity capabilities, and others.
Again, bringing everything together. Um, You know, it is interesting, that's the motion we see a lot in the industry is going from kind of individual products. Maybe some people think of 'em as siloed, even in some cases, not yours necessarily, but being part of Tenable one sort of a platform play, right?
Which is one of, of course, you know, the big trends, customers are looking for that, right? Maybe they don't just want one customer. You don't want to depend on one only, but it's, you also don't wanna be in the integration business and the data transformation business across Right.
A company's own product, right? So it's a big advantage being part of that, Right? So we're seeing a lot of customers that of course want to leverage more than one product together.
Again, with the platform, of course, a total cost of ownership is cheaper. And of course, we have a lot of customers that are interested in our cloud security offering. Again, SNA approach and SNA product that we have, which comes with a lot of unique capabilities, uh, as part of that and a lot of differentiations and unique approach to the market, which is great.
Mm-Hmm. I'm glad you mentioned CNAP, because just in the last year or two couple of years, we've really started talking about AppSec API security, kinda the topics we would talk about in the software world, right? In a clouds, uh, security context.
How is that, um, what, what's your kind of assessment on the state of, of DevSecOps AppSec in the cloud security space? Right. So I, I think the trend that we are seeing in the cloud infrastructure security space, as again, part of synap, the cloud native application protection platform is, of course consolidation.
Context is king. You want to have a holistic approach. You want to have a platform that can zoom out and see the bigger picture.
That includes everything. You don't want many tools. Again.
So this is the, the approach that we are taking in the last several years is of course, as part of Tenable right now, we have recovering a lot of use cases that used to be handled by different tools like CSPM and CWP, again, with a strong vulnerability management capabilities that we are bringing for the vo, tenable, and Kim and infrastructure is code security and more and more and more capabilities that we're, and use cases that we are bringing into one platform. And I would say if you mentioned a lot around API and how our approach is a little bit different than what's going on in the cloud infrastructure, that at the end, when you think about the cloud infrastructure, because everything is global, there is no real perimeter. So identity becomes much more important and permission is much, but becomes much more important.
So it's not just users, it's also all the API calls and everything. If you wanna get access to something, you need to leverage your, I would say, machine identities or service roles. So at the end, at the end, the identity and the entitlements are important for, for two reasons.
One, because you have a lot around identity risk. Again, you can leverage identities that you still, but also when you think about blast produc in the cloud, it's mostly around access. When you think about a vulnerable machine, again, that leverages, again, ask yourself if this vulnerable machine is critical, I would say vulnerability for the company, or I would say less severe.
And it depends a lot around what this vulnerable machine can do in your environment, which API can leverage again to reach, uh, other elements and other resources in your cloud environments. And it all depends on identities, on the machine identity that it's assumed. So at the end, uh, leveraging the identity analysis and understanding risk and entitlement in the cloud is so important in all aspects.
Also, in terms of the actual risk, which is important of course, but also in terms of the context, in terms of the under understanding the blast values. Mm-Hmm. Very good.
Um, when you say cloud security, or you're also talking about in a multi-cloud sense, 'cause a lot of folks are sometimes by choice, sometimes by acquisition or, you know, requirements of customers geolocation, lots of reasons to be in multiple clouds. That adds a whole nother layer of complexity to it. Yes, Of course.
So if you think about cloud security, every customer that you'll talk with probably has, uh, uh, a multi-cloud strategy. So leveraging more than one clouds is a big, again, a bigger part of their strategy. Sometimes they're leveraging 90% in one cloud and 10% in other cloud, but it's still, they need to be able to protect older clouds.
So it can be AWS and Azure and GCPF got the bigger ones, and Oracle and Ali and others. So at the end, you need to add the layer of the multi-cloud. On top of that, sometimes they have some kind of private cloud capability, so it's also hybrid cloud.
So that this is one, and this is only one dimension. When you think about cloud security, you have, as we said, different layers, different models, different use cases. Everything need to go broader and deeper, uh, in order to give the value for our customers.
Um, and Part of that broader, deeper is, um, personas or users that are across the organization, right? Maybe the, the op, the SecOps group, but maybe application security and developers and anybody across that, that chain, if you will, that supply chain. Exactly.
So when you're going broader to a platform, and you are dealing with more use cases, of course, you need to support more personas in the organization. So of course, you have your security teams and SecOps and others, again, cloud security teams, but you also have, uh, sometimes developers and DevOps and think of the gap between security teams, the security teams and developers. And DevOps Can be, it can be massive in some cases, right?
It Can be very challenging, again, in a bigger enterprise, sometimes, again, it's very far away in terms of the organizational structure. So also closing the gap between security teams and developers and DevOps. It's a key value, again, of your platform.
Again, you need a platform like ours that helps organizations close the gap between security teams and developers and DevOps, and also close the gap between dev, different personas in the security teams and the developer organization. All of that, again, as you said, creates more complexity, but it's also part of why it's so important, again, to get, uh, the right synap approach, uh, to your organization to make sure that you're, you're secure as a, as It's the world we live in. Right?
Right. Whether you, you said or not, sometimes you don't have a choice. So talk a little bit about CAP and, um, sort of the lifecycle of software and how, how far upstream do we think about CAP when we get talking to the developers and the architecture and the infrastructure software, you know, Kubernetes and caterers and everything else that might be involved in, right.
How do you approach that? You know, oftentimes traditional security groups by Tenable, right? And of course, you're, you're with Tenable thinking about it more broadly, Right?
So, uh, this is another dimension that you need to deal with. So of course you can go right. I would say more even sometimes to detection and response, uh, with a runtime, but you also need to go left, I would say, and cover, I would say left, middle, and right.
So it creates a lot of, also of complexity. And it's also important to support different lifecycle. I would say usually today what we see, we see organization leveraging application security platforms and solutions.
You'll have the, they'll have also their synap or cloud infrastructure security, and they will overlap again. Mm-Hmm. But it's better to overlap than having gaps between your solutions.
So, Well, and oftentimes they're doing development in the cloud, right? Yes. 'cause that's where they're deploying, right?
Exactly. Naturally, you've got a CN app for your runtime environment that can support Right. Earlier in the, the development.
So we also support as part of our approach, also container security in the runtime in the repositories again, and also in the CICD pipeline. We also scan there, we also cover the infrastructures code. Again, you deploy, deploy again, uh, cloud many aspects, again, is also being deployed using code.
So you also need to analyze the code and to make sure that it's secure. You need to find the problems right away. You don't want to wait until it's a part of the production environment.
And also when you find it in the production environment, you wanna make sure that you fix it in the root cause and not just, and just not just in the production environment. So kind of Built in security, not bolt on. Right.
Exactly. Exactly. So coverage, covering everything from, again, the beginning till the end, and also making sure that when you find problems also at the end, again, you fix it in the beginning again, it's, it's a big part again, of the value.
Great. Um, this is not an AI trick question, so don't, don't worry, there's no wrong answer. What do you think we need to be talking about in cloud security, um, that we're not talking enough about yet?
What's the thing we need to kind of elevate and talk some more about? So again, I think we're talking mostly on the, on the, on the right things. Again, covering more of holistic approach, covering, uh, I would say broader and deeper and covering life cycles, multi-cloud and hybrid cloud.
I think this is the most important piece. I'm not saying that today. If you think about the trends, if you think where we are going, of course AI is a big part of that.
Again, you mentioned ai, That was the trick part of the Question. Don't talk about ai, but let's talk about ai. Yeah.
Again, so generative ai, again, is also something that a lot of organization will leverage the cloud infrastructure forward. So going upper, more to the application part, but that's, I would say probably that's the next step, maybe in the next several years. Mm-Hmm.
In the mtil being shaped here, Do you think of the compute environment for AI or LLM security? You know, you can kind of slice a lot of different security out, data security for, um, ai. Is that part of a, a cloud security architecture, do you think of it that way?
So today it's not, but ask me, and I will say in the future, maybe again, I'm sure right now, of course, you need to make sure that your AI application and everything that you do there is secured. So, and we'll see more and more and more organizations go into that. So at the end, you need to support that also.
Uh, will it be part of the syn up approach or will it be part of the cloud security, or will it be separate again? It's still early. Still evolved, still.
Yes. Still Evolving. Yes.
Still evolved. There's so many tentacles that a AI touches and vice versa. Yes, yes.
Good. That's only one. That's Only one, right.
One part. Yeah. Great.
Any, any other thoughts you wanted to touch on while we're chatting today? No, just I would say in general, I feel like, uh, we are making a lot of progress, I would say, and, and cloud, uh, um, is evolving fast very quickly. I would say it's very dynamic and also evolving quickly.
So, uh, cloud security should evolve quickly again. So that's also part of our responsibility and we're trying to help our customers again, uh, be more secure and more protected. Always be moving forward.
If you're stationary, you're falling behind. Right, right. Okay.
Shai Moog, who is, uh, SVP and general manager of Cloud Security at Tenable, and congratulations on the acquisition and folding into the company. So we wish you the best. Thank you very much.
Thanks for being part Of our conversation here at SAC 2024. Thank you for inviting me. Great.
Thank you. Right on topic with what's happening at RSAC. So, uh, privilege to have Shai join us in talking about cloud security.
We will be back with another great interview in just a moment. So hang tight. Same bat station, same bat channel.
We'll be here at r say in just a bit.