David DeSanto, GitLab | RSA Conference 2023
According to GitLab’s 2023 Global DevSecOps Survey, more than half of developer, security and operations professionals said that they, as part of a larger team, are responsible for security in their organization. That was an increase from 44% in 2022. GitLab chief product officer David DeSanto speaks to the importance of security automation to free up security team bandwidth and using artificial intelligence for compliance adherence and productivity.
Transcript
This is texturung TV. Hi everyone. We're back here live at RSA.
I got to tell you we took about a half hour break and a half hour. I saw my friend Damon Edwards. So my friend Ira Winkler Rich mobile John Willis.
I don't know who else stopped by Peter Pete nicoletti. Jorge or Georgia Kelly's it's just It is old home. You're it is I know yeah, you know, you're security guard 40,000 people and I just feel like I know half of them sometimes.
No, the last RSA was that was right before the pandemic started 2020. Yeah, so it's the first time back and it feels like a homecoming it really is. Anyway, let me introduce you here.
We've got David DeSanto David. Well David is Chief Products officerie gitlab. But David's also a frequent guess whether we're a kubecon or RSA here participating in our panels both live and virtually he's always always available to us, and we appreciate it.
Hey David welcome. Thank you glad to be here. Absolutely.
So Well, we're out of security show and it's about and get lab. Yeah. What that you know five years ago that wasn't such an obvious connection right now the very end in 2020.
Yeah, when we first met in 2020, that was the first question you asked is get lab and security tell me about that. Yep, and I'm very proud to say that after the three years ago. We're actually recognized as a security company now, which is a huge step forward forget lab, absolutely and you know, Today's Tuesday, obviously, if you watching this live stream, we did our Ninth Annual devops connective sick ops event yesterday and the theme was devops is now Dev set cops.
And that was our anchor panel our power panel at the end of the day David participated when we had some of the leaders in devops we did. Talking about devops is now devsecops. So David, thank you.
You guys did lab recently did a survey it's your annual survey. Correct on security. Why don't you yes a little bit Yeah, so we did our seventh annual death psychop survey and what was exciting about the survey this year is that there were some interesting trends that kind of came out of it.
And so I I actually grabbed them so I don't get them wrong for you for anyone who's watching but I would say the big thing that I saw in the data was ever everyone wants it all they want security and they want efficiency. Whereas usually when I first started get lab people talk about those as two orthogonal things either you're secure or you're highly efficient and so to see that Trend change has been very good. And I think it really well into the panel yesterday because really I don't think you can say devops out really meaning depth psychops now, absolutely.
Yeah. So talk a little bit about the service. I'm interesting stuff coming out of it.
So the first dad I pulled that I was interesting is 72% of respondents say they're now a devsecops platform or intend to in the next year And so I think that's a sign of the tool consolidation the effort to try to get everyone working together. And that number just keeps on going up year over year, which I think is a really great fun. Yep.
The other thing that I thought was interesting is that security is becoming everyone's responsibility. And that was really a good theme from the conversation yesterday as well. But 53% of response that they are responsible for security at the company and that's up from that's amazing.
That's up from 44% last year. So that's a 20% jump in the number. What I thought was really telling and this is the first time I seen it this way is that 71% of Security Professionals said that at least a quarter if not more than the vulnerabilities are now identified developers and fix before they get to them and while I find that such a great number which way it's up from 53% That's a huge jump is that through this survey day.
You can almost still see the finger pointing the dev saying well, it's really your problem and then seriously notes really your problem and have that large of a jump means that people are starting to work better together. I think that's why the number has been or the saying of devsecopes become a lot less polarizing for organizations is that everyone's kind of seeing it their responsibility to work together. And by the way, like just as a small plug for gitlab, I know, you know this we share ourselves is not just Platform but a collaboration platform, right?
Absolutely. You're getting everyone together working from the same single source of Truth and it really breaks down those walls. And so that's why I think that number is great.
The only other two points. I thought were of interest that would be great for your listeners and the viewers here 57% of secure respondents that they're using six or more tools now and what's interesting about that is when you take the consolidation the dev tech office platform number and you look at how developers and operations team members, their tools are reducing. Every year security is actually went up.
I know and that's a sign that we're starting to get that devsecops practice understood but the security team is still struggling with a large group of tools, you know, I I didn't an interview earlier today and I I'm not a loss for which company it was but there's sorry. Oh, you're very stats came out the twenty five or more tools for cloud security, which is the average Enterprise. Yeah, like how so is a I think I share this with you before but as a former security researcher and leader of research teams and eventually working engineering Like having so many tools like makes you inefficient and can't help well and I think what ends up happening is people confuse.
Best of breed with was not being a platform and I like to challenge people and say you can have a best of breed product that is a platform. And so I think as people start to realize that I'm at my third company. I really love these 12 tools.
I think them everywhere asking this so themselves like, is there a better way and how could I be more collaborative? The thing that I like to to talk about is like I did make a traditional application security testing product in my career. I was the first thing when I moved into product and we said we shifted it left.
But all we were doing is making a plug-in for CI and our scanner still ran for hours. If not days right like that. That's not you're not shifting security left, right?
You're actually slowing everyone down then that gets that efficiency versus security thing again. so and and Again, I had this discussion. Yes today.
With someone in the audience not on our panel. Look the promise of devops. Why did why did devops appeal to developers to security people to Ops folks?
It was the idea of doing more faster better, right? Better no, and there was also this concept too about you know optimization for the team and that for a while. I got interpreted as what the developers pick their own tools and that only works to a degree because all of a sudden you've got a massive disparate tool chain, that's like digitally duct tape together and then if someone leaves you understand that like you lose all of that knowledge, and so I think when you bring this back to security whether it's Cloud security, whether it's I will say application security testing security people are going to start to realize that I'm what I'm doing is I'm drowning in tools and I'm not becoming efficient.
Yeah. I I it's crazy. Yeah, what else you have?
Yes, the last one that came out of the survey that I thought was really interesting is that you know, I if you could walk around the internet like it just imagine is a big mall. Maybe you can't go five feet without hearing about AI for code completion. If you get the internet, you can't walk three feet in the sidewalk without hearing that it's funny you say that so like we're at RSA.
It's a security conference. I walked around the welcome time and the Expo and I was walking by pure Place security vendors saying they down do code completion with AI. I I got three pictures.
This morning from security vendors saying how they've Incorporated generative Ai and in their tools and it's gonna make you more secure. Yeah. I'm all for AI.
Don't get me wrong. I am too but this is there's you know, this is the Gold Rush the next San Francisco goal right here right crazy. So why I bring it up is what the survey showed is actually wasn't the top three uses for development teams.
And so you would think again you're walking around the virtual mall. That is that you're walking on the expo hall here. That would be the number one thing.
So what came out is actually 62% of developers are using it to check their code. Wow, that's up from 51% The one that's more shocking to me is the next one that the next most Dev. So 53% said they're using it for testing that's up from 39% So again, that's more than a 20% jump.
The last one was that they're using it for either code review or full code review. That's 36% That's up from 31. It's not as big of a jump.
Yeah, but the thing in that is that it's not about code completion when you're asking the actual people using it. You wouldn't know that from all the buzz words and everyone saying and by the way, like get love has a code completion thing powered by AI. Wasn't the first thing we offered but we do have it but our customers aren't asking us about that.
They're asking like how do we make everyone more effective? I like to look at it from a from the angle of that. The studies show that about 20% of the sdlc is development time.
So if you make that a hundred times more effective, you're just gonna have a bottleneck somewhere else, but that's what it does. You know, this is the goal. Yeah, and so really what you need to do is support everyone.
And so when we approached AI two years ago, we first worked on improving code review and that's been very popular with our customers. We G8 our release last year. Code completions came out last year again adopted but our customers are talking to us about how do I play?
I had a better understand my source code. How do I play I get through security better. How do I play AI to better understand my operations and so get lab has been focused on the whole experience and might be because we're a Dev tech office platform.
We do everything from planning to deployment and monitoring and production, but we realize that our direction is kind of validated by that stat if you're asking actual Developers, and it's on their top three uses code completion's great, but it's not the whole story agreed agreed, man, but Nevertheless, I think when we close the book on this year's RSA Thursday afternoon. Yeah. the buzz last year was zero trust and sure it's gonna be AI it is gonna be AI And it might be like that for the next few years.
I was just speaking to. A friends of mine from the devops world. Yeah, you know and they agree as well it is it is what it is David.
We're gonna have to see this thing through it's gone. It is real and it is going to have huge ramification. It is it's just might be a little while out yet.
Yeah. So how I measure how perforated something is is I I ask myself have my parents ask me about it. And I realized when talking to my mom around I think was Easter.
She was like, what's up with the AI stuff? Yeah, and she's like, are you show it to her? I did did she think it was magic?
She was interesting. I always ask the first thing I ask a chatbot is like who am I like doesn't know who I am, right? I was disappointed chat GPT got a little they got it mostly right Bard got it spot on.
So yeah, so that was actually got me right but when I did it I asked to redo it. Yeah, it started adding places. I work today.
I'd never been to but that's what it was. It merged my current. All with the former cpo's background, right?
I'm like, I never worked at Center. Yeah, I didn't go to standard exactly what happened, but no, it's interesting. Right?
So like if my parents are asking me about it, like it's clear like they're seeing it in their news, right? Absolutely. I mean, it's mainstream, you know, my friend Brad felds of DC very good some kind of Foundry group Mobius.
So you managing partner, it's off Bank. He said this term Auto magical Yeah, when something appears to be automagical to people who maybe aren't in Tech or even our attack, you know, it's something. And this is something yeah, no and I think what was interesting about it too.
Is that like the chat chat Bots are very cool. They're not the way companies can apply in a way to scale. And so I will be interesting is to see all the different ways people apply AI We're gonna have more news on that in about a month.
So stay tuned. Okay. Um, so what else we got?
Yeah, so I'll mention AI quickly and then I do think it's important to talk about what we announced at RSA because it's very exciting job and we're here. Yeah, so just on AI gitlab is applying AI to our platform. So you guys had a blog post on this we did actually Mike bizarrett our chief.
Yeah. I know their coupon last week about it. Yeah.
He has more questions for you on it. Just letting you know right to you. Yeah, I think he's very reached out to the team.
So good schedule. Yeah. What I share with him is that again?
We're applying AI to the entire process so things we've announced we started a Blog series called what the ml is up with AI and devsecops. Yeah because why not have a little bit of fun with words, right? Right.
Yeah, and so the what I think it's the last four weeks might be five. We release a Blog every Thursday to talk about what we're doing. Okay, and so we've talked about explain this code.
As much as about the source code to me. It's about the QA and the security teams. You can go into your into your repository select a file select just a line select a function selection Tire thing and it'll be explained to you.
That's right. Fantastic. What's great about is like I selected a function for someone actually might've done for my last week and it told us what the function did but not that but like where the variables came from and what was happening after and it really gave it the ability to then say what should I do for a unit test for this to better make sure it's working.
The other thing we did was we're very popular Valley Stream management. And so we added forecasting to our Valley streaming analytics. What was interesting is when I demoted to a customer I actually get lab source code because we're Source available and it showed that, you know, we're ready very efficient at deploying we did play 127 times a month to our SAS platform, but what it says in four months we get to 132 and that what that means is like.
Yeah. I can look at a chart. That's the last 30 days 69 days.
That's not telling the whole story and it was able to analyze And so that's the last thing and and you know, I talked about this once before get loves become very popular for planning. We've been focusing Enterprise agile planning people can write a lot of comments on an issue. We're actually able to summarize it.
So I actually took an issue it was a hundred pages long if I printed to PDF and I said explain all the comments on this and it came back and said in two paragraphs like here were the conversations here were the decisions amazing and that's really the power of it. Right? And so like now if you're making your planning more effective you're reporting more effective your QA security is more effective.
Now, you can make everyone more effective. So I got security questions. Sure.
Yeah, so you uploaded all those comments into your into the AI, right? Can I access that information the which was the outputs of the Ai No the stuff that it didn't put it from you. So rai's done with privacy first in mind, so for our code completion and our suggestion reviewers your code never leaves to get live Cloud infrastructure.
So that was an approach we wanted to take because we understand people trust gitlab what they're intellectual property. We actually have more than 50% of the Fortune 100 use gitlab today. Wow.
And so we need we realize we have a privacy requirement for them. We're ultimating with a transparency approach as well. com go to code suggestions.
I'll tell you using nine models. We're building the subtraction layer. We're able to take the prompt get the right output and nothing is saved.
So your question. No, you cannot access what we're using for the prompts you can only see what is applied to your project yourself. Got it.
And by the way, I think that differentiates get lab with AI and it's been a requirement in our partners who we work with if we're not building our stuff ourselves. Yeah. I love it good.
That's what Mike was most interested in and I'm sure you know will so yeah, that's father for another article. It completely is. Let's talk about our essay now talk about RSA.
Yes. So we on Monday. So yesterday announced four things that we've we've released recently all of which are very relevant to the RSA crowd.
So the first person is we updated our compliance or our licensed scanner as part of our software composition analysis sea offering it now can detect over 500 different license types. Why this is important to us is that software supply chain security has become our Mantra and we're trying to help everyone bring that to the Forefront how they build software. And so we went from being able to detect a roughly 20 to 500.
Wow part of that is also we can now detect multi-licensed in the project was which is now very unique to get loud. What a lot of people don't realize is they might pull it a package. So let's say these python using pip, they see the license that package has impendency, but all that's things.
Yeah have licenses as well so we can now do multi-licensed detection part of that package the other thing and this is again, very relevant to the conversation here. We've now automated how you can apply security compliance policies to your projects and get lab so last year when you and I talked I talked about how we now can do immutable policies. We've now taken that from the project level to the group level so it can be every project you have I mentioned Fortune 100 companies trust get lab.
They have tens of thousands of projects applying that at each project would take a long time. And so we now made it automatable so crazy for those who've not heard that conversation or have not been following would get Labs been doing these policies are immutable. That means that when the security Team sets them they can't be turned off.
Right? And so we realized we did something right when someone opened a support ticket last year and said, hey I keep on trying to turn the security scanner on and I get and I can't turn it off. I I uncheck it and then I run a pipeline it's back.
And so then we realize it's working as expected. They can't turn it off. Right?
And so that's giving everyone that security but the efficiency as well not a bug it's a feature it is and this time it's mad and you know, Katie. Yeah. Yeah.
I love it. Then the last thing that is worth really highlighting and it's called a to both the panel yesterday and the conversations that are happening at RSA false positives are real problem for people right security scanners can be really noisy. And so our number one scanner that's driving people to get lab is our API security scanner.
We've had it now for about two years. It does both AP. Against your API or desk scanning for SQL injections so forth, but it also does API fuzzing.
And so we wanted to reduce the false positive. So we did a really big effort and we've been able to reduce it by 75% It's 78% Okay apis. Security right?
Well Arkham. I just probably sock on my buddy. Yeah API security company.
It's big. It is really huge man. And for everyone to know like we acquired Peach stock to get apart already in 2021, right remember ends or yeah in 2020 was 2020 could I was at a gitlab event and Williamsburg Brooklyn the whole places.
And and I think that's around when that acquisition. Yeah and close that summer. Yeah, and so for us it's been important to us.
So now we've taken our technology that can build the control flow and the data flow of the app and we're applying it to this to reduce false positives there. So actually very exciting stuff cool David. We're about out of time.
I got my next guest waiting out here. I appreciate you. I appreciate you posted.
You're always invited back again. You have a standing invite. I will tell you.
I look forward to our conversations are always great. So appreciate you man. All right.
Hey go check out get left. They've got a bunch of announcements here a lot of stuff going on with AI check out that blog series on yeah, they're up to what five episode five the fifth one just posted actually go check that out get lab their security company. We're live at RSA speaking of security.
We'll be right back.





