Arabella Hallawell, Mend.io | RSA Conference 2023
Security was once an afterthought in software design, but today it’s an increasingly critical aspect of application development, from design through deployment and beyond. The volume of applications developed, distributed, used and updated over networks is rapidly expanding.
As a result, application security practices must address an increasing variety of threats. It’s even more complicated when cloud-native applications built using microservices and containers are thrown into the mix. It is not enough for application security programs to operate by focusing only on compliance. Modern AppSec programs must go deeper and answer much more complicated questions about the integrity of each software component.
Transcript
This is texturung TV. Hey there, welcome everybody. We are at rsac 2023 San Francisco.
It's so good to be back in person again. A lot different this year from last year. This is kind of got the I want to say old RSA buy but the true RSA by back.
There's a lot of people a lot of energy we're talking about absec that application security a lot of which I have a great guest to talk about that Arabella Halloween. How are you doing? CMO with men IO yeah.
Thank you. Thank you for having me and excited to be here for another RSA and excited to talk about application security. So this time sort of last year men.
I renamed itself the company used to be called white sauce. And in many ways to have founded open Soul security decade ago and we rename the company for a number of different reasons, but we've brought down Beyond open souls and really we've been very much focused on using all animations to souls and really tough application security problems, and we see even more tough ones coming down. and we've been very fortunate we have about 25% in growing of the Fortune 100 as our customers and yeah, things are changing all the time in the space and I'm glad to see application Security in many ways has got a very solid fitting here at the conversation with RSA today.
I see a difference even from last year to this year. Yeah, it is it is a topic of conversation many people are having I don't know if it's not xdr, which is you know in the security world is kind of popular last year same as this year. I think it's the it is the new topic that's on everybody's with their tongue.
At least. That's how I said. Yeah, I think a lot of it is because in many ways the threat has jumped to the application land and this has been an ongoing Mark over the past three years, but we can continue to see it accelerate and I think both Forester and the Verizon Business Report data both show just skyrocketing skyrocketing data, the you know, the number one source of organizations breach is now through the application layer and I think a lot of the challenges in fact go about to HDR if you look at traditional five is security and I've been in this space.
Now and you know many many ways. I still see the Cyber threat organizations the security operations organizations endpoint and network-centric and I don't think anyone's really figured out how to really bring in the upset world into process technology, you know even people and so I think there's gonna be a real explosion in the threats and then organizations playing catch up to figure out how do they stop it in a more effective way. Yes interesting too.
So two things happening the attack vectors are just wide open. Yeah a lot of it kind of laying there for so long it haven't been taking advantage now are At the same time, you know I've struggled with how do we get this conversation going between you know, kind of peanut butter and chocolate, right? How do you get the Reese's Peanut Butter Cup between security and software Dev?
It one of the things that I think is really relatable to both is the idea of the chain of trust and the security world, you know that about for that from pki a lot of things very much fits the software supply chain absec. Idea right of what's the sources of the software? We were using what we're creating.
Right? All the elements go into creating apps and infrastructure and all of that. So maybe that's helping a little bit I think so.
If you see one area that we've been increasingly helping our customers with is and I guess I'm making it better term, but I'll call it supply chain malwest. So we've seen an absolutely explosion in I'll just call it malicious packages malware within food itself. And if you look at the the vectors the vectors is a fairly traditional for most cyber threat team salt teams, you know chasing iuc.
So excelsioration. We see protests where we see some different alcoholic develop attack tactics to fishing but more very much for the develop the world and so a lot of those types of technique all the same but done against developers and particular developers using packages where they Might not understand the origins of those packages. And so I think that's really the challenge which is you know, how do you figure out within code that you're developers are building.
In fact typically composing from lots of different sources, you know, what's you know, is that could poison or not? And I think that's a big challenge for the ciso the Cyber threat organizations as well as obviously engineering leaders don't want to be you know shipping poison code. It was a popular terms had gotten a lot of tensions as s-bombs.
Yeah bill of materials. And while I think that's a great thing. It's a great start right?
It's not it's not the end product. Right? You've you knowing what you have.
It's kind of the traditional security people. Think about for the security anything after know what I have and it sort of solves that question early answers. Yeah provided.
It's automated. It's always up today. Yeah, and that but you have to move far beyond I think just the S bombing you talk about automation.
Can't keep up with this. Yeah with manual process. Yeah, so I think this there's a number of different issues there.
So in terms of s-bombs, that's obviously being a big fixture from a I'll just go a executive order a spotlight. Obviously, there's been more pressure put on their area. It's very much just starting point sort of understand what you have is it's definitely a good start but it's in many ways in sufficient and is not back to what we were saying about is your code poisoned doesn't really to know the trustworthyness of the code that you're supplying to other people.
So we still have a really really long way to go particularly. If you just look at the number of days of that month. In fact years it takes just to fix critical vulnerabilities and then if you just look at the explosion of the number of critical vulnerabilities, the developers are struggling in the same way the many of the analysts and the soccer World are struggling which is huge.
Amounts of noise and for developers is absolutely overwhelming and the stories are true. In fact, I was speaking with a very large organization that said actually they're developers are struggling so much with keeping up to date with all the vulnerabilities. They really cannot ship the applications to the business need and that amount of noise and just basic fixing that develops have to do we believe in men and why we renamed ourselves amenders you can solve that very effectively through Automation and there's probably sort of three pillars of that one is I'll call it dependency updating and it's used in the development World quite frequently.
Oh, I want to go from package X to why for an upgrade but it hasn't really caught on from a security perspective, even though it's incredibly effective over. I think it's 85% of all in basically vulnerabilities already have a fix available. So if you just update and proactive you've you know, you traumatically reduce your attack surface.
So we've Incorporated that into everything we do. We're very fortunate with the We own renovate which is the leading open source. Dependency Health sort of updating updating community.
And so we see all that intelligence and are able to infuse that into our solution but beyond You know our own capability the practice of dependency health is very very important for automation. But there's many things that you can or to me and then things you can't automate there are some effective ways of being more efficient and I think the there's been a lot of talk around automation, but still there's a lack of trust developers don't necessarily trust application security tools and not you know mess things up and I think the trust is still a big part of why we haven't seen a lot of the adoption that we really need to to improve application security. I think that's a lot of the human element of this equation, which is the developer world, you know, the pressure on them is faster producing more absolutely getting code out.
Yeah, you're out into prevention and and there's also a big cognitive load when you're software developer. Just keeping your mind in the problem space. So anything that interrupts, oh, that's right.
When I when I push in to get I've got to do these two extra steps that adds 15 minutes even 10 or whatever it that can be now. I've got to spend another 20 30 minutes to get myself back when I can start working in that flow. So understanding that process.
Yeah and how to fit into it. So maybe you're transparent or at least is transparent as you can be to developer except when they need that information. No, absolutely.
So we've we've done a lot of what without repoing to gracious and that's what we see some very dramatic improvements and we've got a lot of customer testimonials to that fact that if you To gray at the repo level you can. Again, just from a fixing things for set perspective. We see organizations be able to fix things in hours minutes when before it's at the months or even years and that's really just integrating into workflows.
There's not even about being developer friendly is actually just being very very integrated into the workflows. And that's what we a very focus on doing making sure that from a developer perspective whereas as least intrusive as as possible and that has both efficiency benefits, but also to your point doesn't distract from you know, a lot of the focus and what they want to do. I think that's where a lot of security companies struggle.
There's not understanding. Yeah the developer life cycle the workflow of the developer. Yeah.
It sounds it sounds pretty straightforward to you start to do it. Yeah. It's like watching, you know Game of Thrones and then stopping in the middle of it and waiting six weeks to finish it.
You forget what happened you've got back and kind of I'm A Game of Thrones fan. Sorry have to throw in the allergy, but you got into three. And how's the dragons everything else?
But it is it we go back and watch a couple of episodes to get ourselves. Yeah, and it's very much that process and it's pretty companies understand that then you can design products. Like you said you spent a lot of time.
Yeah, how do you make that as effective and the friction low? Yeah for that process. Yeah.
So I think that in some ways it's a you know, it's a it's a focus which is you know application security teams, obviously, once you make sure that the code is fixed before it hits production or if they do find things in production. There's a really good feedback loop to figure out how does it get fixed? And you know, I think that visibility and control has been a struggle and then from the perspects about the developer they want to make sure that the the alerts they getting high fidelity.
They're not full of false false positives and it's very clear. Not just that there's a problem What is the path to most effective resolution and again, that's kind of where we focus we've really tried to focus on making sure that all steps along the way and today at the RSA conference. We call it autopilot, but we try and figure out all across those workflows.
How do we enable develop a generally be able to like press autopilot? And then when they realize they have to put their hands on the wheel they know exactly where they need to get involved to fix things and it's been a very effective for our customers. And so you want to get out there and spread the word the automation isn't scary.
It's safe and it works and you know, like a self-driving car it takes getting used to and then you get more and more comfortable with actually like technology Works maybe stuff driving isn't a great example. This has been yeah, but the concept is is that Which is and we believe very very strongly. It's pretty much the only way to solve some of these problems.
If you look at the hundreds of thousands of alerts that are created and the fact that it is becoming so much more complex between open source and custom code and you know, obviously now we're Cloud native. You simply can't rely just purely on manual a very manually intensive workflows to solve it is just you know, it's impossible and it's why you know, we are increasingly relying on Automation and you know even and we hear a lot in the world today about artificial intelligence, but it is indeed true that technology can be used very effectively both is a supplement but also, you know in our case you can actually automate some key manual workflows and we see it every day in our customers. I love to have you say a little bit more about AI I mean.
Every talking about because of generative AI it's been gone for a long time abortion. And I'm sure you know machine learning is not something new to men right been using some technology. Where do you see AI plank today, maybe kind of looking forward to sure.
So I mean there's obviously a difference between Automation and artificial intelligence and you know, all the general philosophy is we're very much focused on using automation not necessarily, you know AI to assist but you know actually thinking about how we use automation to replace. So from my perspective a lot of it really starts with the data that you have and so again from office, but we've been very fortunate that we have both, you know, basically Gold Mine of data from a crowdsource intelligence from renovate. So that's you know, we're able to see we talk to a little bit before about Oakland malware supply chain or Supply hours to play.
You know, we can actually see like good packages that go wrong or you know gold standard package. I mean good packages or bad packages from a trustworthiness perspective and upgrades and now we're increasingly looking at it from a malicious. I call it malicious co-prespective but having good data is the starting point.
You have to have good data. And then I think the algorithms you build upon it you decide what's most effective for the use case. So from our perspective we use lots of different algorithms.
Some deterministics. Some are using sort of different different methods. I think the there's obviously a lot of Buzz around artificial intelligence.
But you know in the same way that you can it can be used effectively for certain parts of the process. We're again very much focused on making sure we've got great data and then we use the right algorithm so that we can make sure that we give very effective workflows to our customers again trust is Paramount. And so it's even when we look at things like reachability, we're able to say very Very precisely whether a certain vulnerability will actually be able to reach an application.
We use patented technology to do that. It doesn't necessarily include artificial intelligence, but it's incredibly effective. So, I mean, I don't really have Too much more to say about the use of AI within men apart from we obviously use lots of different algorithms to sort of fit up purposes.
And AI is just one of them. I think a lot of us are a lot of product companies are yes, we use a yes. We're still learning.
Yeah, we're all learning together. Right especially the generative category. Yeah.
I'm curious your perspective. Maybe this kind of a odd funny question, but usually for your you to answer when you come to a big show like RSA men's invested a lot. Of course in having a successful experience here.
What are things for you as a CMO? What do you what's a successful RSA show look like to you. I'm just curious.
Yeah. And so I really like to hear what customers are saying what's top of mind hearing all the conversations, you know often times they don't always happen on the show floor, but you know with you know customers that dinner with partners and with other people just talking about their different learning. So I mean from a business perspective we obviously want to make sure that some of our key messages like resonate with our customers and with our partners, so that's honestly, Part of the success and then again just making sure that we are connecting with customers and people who have got problems that we think we can help solve.
And so to me there's nothing better than you know, speaking with potential prospects on the show floor talking about what we do and you know being able to sort of connect the dots there. So there is something you know, still authentic about the show floor and really being able to connect and tell your story and see if it resonates or not. And so for me personally, I'm interested in the concept of autumnation like just does it resonate and open one really?
We're hearing today and yesterday the auto pilot and automation is actually what people want. So and I'm not just saying that we actually had a lot of people come up. So I don't know.
I mean I do actually like measure it based on like sort of authentic. Stations that have value where there's that connection between what a prospect wants and what we can deliver that's you know, that's your like customer marketing solution fit right there in you know, in essence. Fantastic foot it's been amazing to talk with you really enjoyed our conversation.
And you know, I think we're lucky to have a show like RSA where so many customers and Technology. Yeah creators. Yeah suppliers get together at that opportunity.
I agree have a lot of those interactions and conversation. It's it's fun. It can be hard work.
But I also think that there's a huge amount of information and expertise and there's also a lot of sharing I think anyone who's involved in a research Community knows that there's always been a tremendous amount of research sharing in the information security worlds and I see all the time just speaking with different people in the industry. And yeah you you I learned a ton at the show and I'm glad it's back and it's in full force this year. Me too.
I feel the same way. Well, we've been talking with Arabelle Holloway. Who is CMO with man Dio check out the booth go see the interactions.
Learn Talk of the automation discussion or whatever this top of mind for you as a as a customer or someone interested in this space. So everybody thank you amazing. Thank you.
Enjoy talking. Thank you. io check out absec today, which means I was a sponsor of on Tech strong dot TV as well.
We just recorded episode earlier today had a lot of fun talking about this too. So we'll be back with another great. Yes, just like care about see you in a minute.





