Fleming Shi, Barracuda | RSA Conference 2023
At RSAC 2023, TechStrong TV spoke with Fleming Shi, CTO of Barracuda about the company’s launch of new WAF-as-a-Service plans, including Application Protection Advanced and Application Protection Premium, to simplify customers’ application security journeys with one integrated solution.
Transcript
This is texturung TV. Hi everyone. We're back here wrapping up our last day of RSA coverage.
We're so excited. Just I'm just excited to have been here this yeah, it was it was back. It was the RSA.
I kind of remember from before all the covid stuff. We that's right. We've had I don't know.
We've probably done 70 80 interviews here over the week and Saving some of our best for last. Let me see to my friend Fleming Shea Fleming is the CTO of Barracuda or Barracuda networks as some of you may know them as and they have been here for. Well Fleming has been with Barracuda.
What is it 18 years 17 19 and it's our anniversary 20 year anniversary. Yeah graduation. Thank you.
Thank you. You know what, I think back over these 20 years of all the people. I've known it at Barracuda.
Yeah all this time. and it's It's quite a I mean it's a list right? Yeah, it's great everyone from uh, Mary Peterson.
Yeah. Yeah. Okay.
Absolutely and Mary Catherine Peterson. Yeah and Well from Dean and everyone too. It's just been it's been a blessed company in terms of they've had some you've had some really great talent there.
He's over also have had some really great products. Yes, so fantastic now so Fleming, let's talk about RSA though. Yeah your impressions.
Yeah. I think it's being really good to be back the second year in person after the pandemic and I feel like this year less worries about masks but more about better together and how we can work together share signals and doing things that we do like xdr at the same time, you know, as better could as I mentioned earlier we've been you know already being 20 years is a company what's really good is that we have really transformed and some of the things we're doing now, for example, we just launched our web application security packages that that makes it easier for people to protect their web assets. Yeah, and that's kind of the sort of being the tone for us for a long.
Time because we want to stay on the journey with the customer things are getting harder with cybersecurity. And what's really key. There is to make it easier for them to actually enable the features and you know, basically single click you can get through certain type of you know, owoss top 10 kind of you know, controls and configuration and make making it easier for our users through these packages and adding zero trust all the way to the premium support.
I'm sorry to the premium package of this this web application security plans helps customers as well because you have still people working remotely hybrid mode. Sometimes they might be accessing internal apps. You want to make sure that cloudy and access the very good our offers is available.
So that is one thing. The other thing is we continue to support our Channel. We're very very fortunate to have great partner ecosystem that works with Barracuda and we continue to invest Being hiring and building the resources.
We need to support them as well. So we are recent higher Maria Martinez is the VP of channel for Americas. And also we promoted someone in MSP Karen to be VP of sales for for MSP, which is MSP.
Yeah, absolutely and and also hired someone as just the sales directory in Japan. Yeah. I'm Koto Suzuki town.
So I think it's it's a show of our investment in continued to support. Yeah to continue to grow our business. Yeah, so you get a lot of stuff there.
Let's unpack at one at a time. Sure. You don't mind.
Oh, so first of all, let's turn to Applications security, right? I'm not sure if Security's getting harder or more complex, right? I think the underlying Mission around security has been sort of the same.
Yeah, but it's just it's it's a more complex world. We live in yeah, the threats are more complex than the infrastructure is more complex. And at the same time barracuda's been an application security.
Yeah provider Solutions provider for many years. But what we need to do today is we need to make it simpler for people exactly to manage to do this. Yeah.
How do we how do we deal? How do we take that complexity off of the Security Administrative the Security Professionals? Back.
Yeah, and that's really what it sounds like what you're doing by giving them. You just call them start a packs or something like that, right? You give them a pack of things that you know for 80 85% or what they need to do.
It's kind of in there already. Yeah. They only got to worry about that 15% Delta.
Yeah, which is a lot easier than starting from ground base zero. Absolutely. And if you think about application security and some of that complexity and difficulty is due to so many years of data breaches, right?
So like a lot of situations out there people have stolen credentials fishing in taxes on their rides rent somewhere attacks and a lot of those ransomware attacks while they start with email, for example, they may end up having credentials to attack your infrastructure your applications when you're not really paying attention, right? So that's the part where we worry the most especially related to application security is where basically credential theft have got To a point where the bad guys have advantage against us and when that happens, you know, you have to focus on the use cases not just the nitty-gritty feature sets. So packaging it into a place where customers can understand.
Okay this addresses my API security this address is my OS top 10 this addresses my access control and it makes it easier for them to actually turn it down and use it effectively. So I think the complexity partially is due to how much data loss, you know entire world have been facing and you probably heard like every time they have a data breach is someone's Pi email just having email it's enough for them to social engineer and do more right and they can find passwords that's on for example on the consumer website. Sometimes people share passwords between consumer side state go to as well as their work environment.
So that's the key area where you have to understand. And the implication of those data breaches have gotten so far so making it much harder than them before when when we started in 20 years ago things were a lot more simpler. I would say world was simply right?
Yeah, I agree with you guys. So no doubt about it. Yeah now You I know a thing or two about abstract, right?
Yeah. And we had the abstract top 10 the abstract top 20, you know, and then like last year all of a sudden we actually saw some movement and in different things on there, but you know the owass people have been doing a good job. Yeah, they came out recently with the API.
That's here. It is part of that SEC. That's right an API top 10 or whatever exactly that is part of the Barracuda it is.
Yeah it is and what's the important about API Security's every day we're using apps they're interacting with each other and a lot of apps uses API behind the scene and what you see on the on your screen or on your mobile app. It's the user experience front but behind the scenes, it's actually interacting with the backhand. Sometimes it's multiple backhands that creates experience for the user and because those things are not visibly like in someone's face like but behind the scene it could be actually hijacked could be actually, you know taken to the advantage where Guys can steal data and take over and a lot of times also relates to the how the app is built.
You know, it could have dependencies to libraries that sits outside in the server room actually in from the server side. It's actually on the client side and when those libraries and interactions or being manipulated, it could actually be another front for the bad guys to actually take over data agreed agreed with that. Yeah.
To me also and I think about application Security today. I think about software supply chain. Yeah, that's bombs.
Yeah, you know and all of this kind of good stuff. Yeah. Yeah, where's that in here?
Definitely So to that degree open source is while respected way of actually Building Products application Builders use a lot of Open Source, you know dependencies and libraries to actually make their product go to market, you know, relatively timely manner right because you don't want to start everything from scratch and that the key here is to understand the sex devops component of all that which not exactly. What what web applications security is actually addressing. But it's actually the very shift left of that right the creation of the app.
What data you're you're sharing with the libraries and what version of the library you're using to the degree where you have to pay attention to that. So understand that lineage of you know that the dependency to where your applications interacting with very important data assets. It's it's a key and I think I see the industry moving very quickly to address some of that like having very shift left kind of security products to expose any risks and and do the cicd pipeline kind of pre-production kind of checks and and in the entire process, you can still identify the threat that the behaviors even Microsoft is something cool with their security component for the co-pilot.
Yeah. Yeah. Well, I thought that really cool.
I love it. So I love that. Yeah, I believe the key there is you know security starts from very left if you're able to identify the threats understand the risks and pay attention and to those To those things at the end of the day, you still have to host your application.
That's where Barracuda comes in where application security is that it almost at the contact point with that with the attacker. Right? And those are the things that we're good at and we're simplifying and packaging so so customers can't use it.
Absolutely. Yeah, you know since the last time you and I did an interview a few weeks ago, right? And then since then though I I was that in Amsterdam at Cube card.
And I I learned some things there that have changed my thinking on application security. I'd love to run them by you. Okay?
Yeah. You know coupon was always about developers. Mm-hmm.
An application security was about the classic shift left. Let's get the developers to do better code. Mmm Let's test it.
Pretty deployment. Yeah, right and all of these things that you and I are talking about this year a cubecon. I saw a real emphasis on what I call the plumbing.
Mmm, right? Talking about platform Engineers sres. Yeah and what they're saying is look instead of thinking that we're gonna turn developers in a security Pros.
We're not they're developers. They code we can make them more security conscious. That's right.
But what we could do to really help them is to put it in all in an environment both pre and posts deployment. Yeah, that's just more secure by Design. Right?
Right. And so let's start designing better environments better platforms. That's right better.
Human medication better Plumbing, that's why I call a plumbing. Yeah. Yeah.
What do you think about that? Well, there's a several bands of things I could talk about. First of all, I think one area is platform engineering related to the operating system and the entire Imaging of your your applications infrastructure, when when company that I know of I won't name the name, but they're into actually building what what's really called the polymorphic Linux which what it does is it fingerprints that environment so to the degree where if any changes made to the environment there will be a signal being.
Yeah initiated. The reason for that is basically it's like a human being every human has their own DNA, right? So if someone tempers would want the problem one of the problem with hyperscale environment is if you mess with the template the rest can be clone, right the situation can get out of hand very quickly.
So if you do this correctly Your your your your compilation and creation of your environment do it right with the with unique basically polymorphic components in in the OS it can actually make a difference in detecting someone messing with your environment. That's one. Yeah.
The other one is data, how data is being stored and you know, the concept of blockchain using and decentralized environments ipfs. For example, those are also coming as new technologies components a better Plumbing in that way to basically make it impossible for someone to get into the environment and steal a whole bunch of data, right and the data will be encrypted in some way that the guy the bad guys won't be able to hold you rent some for extortion or boxing and kind of stuff. So I think there's technology and evolution of those environments are starting to show up for developers, and I'm really kind of Courage to see that because that's going to change how how this is going to be done in terms of just software development overall.
So, yeah, so that's just two of the areas that I'm kind of paying attention to but they're they're gonna be more I agree and the other one is related to Basically, even when you are doing a pull request and when you're making a change to yourself software, it needs to actually know which use around which device besides just a user which device is actually making that change and when that commitment happens so that can be done with some basically technology underneath as well. Absolutely. Yeah.
So yeah what happening? You know what? just even in this little area look at all of this.
Let me turn to the other part of the announcements you were talking about. That is the Barracuda Channel. That's right, right keep growing.
Yeah. Now look as I said, I know the 20 years of Barracuda, I would I remember walking through the airports and seeing all the poster that the science and everything radio ads. Yes, right for Barracuda.
It was pretty it used to be a very direct you get your your Appliance from Barracuda. And yeah, or if you go, yeah. I don't know if you know this and I don't even if you've even comfortable talking about it, but what percentage is today is Barracuda Channel company versus direct.
Yeah where we're primarily, you know, Channel driven in the way of actually go to market the key here is we have partners that understands the customer's needs their Journey their understanding their environments getting you know, maybe outdated moving to Microsoft strategy five maybe moving to hyperscale or moving to the cloud. It's it's our actually it's our extended or I call it a force multiplier in the way of actually providing the right solution at the right time for the customer. That's why I think the airport adds a little different now, it's is we're secure Journey, you know Journey secure the concept there is customers are evolving.
They're not, you know, just staying with one solution one technology while Have been doing that in the past but things have been moving, right so especially moving to the cloud adoption of SAS applications really heavy adoption of South Africa. Yeah, which is interacting with well, but and that's not different than the I mean the entire Tech stack is SAS application. Yeah, right exactly.
So what's what's neat about that is our partner ecosystem. Our channels are gonna you know, see these changes and better could it needs to educate them our solution how we evolve to protect them. So yeah, so a lot of the things that we do today including, you know, secure Edge, for example, it's the sassy, you know, Gardener causes sassy SSE where we are providing solution, not only interconnecting Big Data Centers and hyperscale clouds, but also all the way to OT all the way to manufacturing floor all the way to someone's home.
So with zero trust building, And all those things are important to make sure the customers know and the channel knows that better could is there to protect them if they need it because the solution have evolved and basically made more modernized for problems today and and those are things that we we care about a lot. Yeah. Got it.
Yeah. MSP ye MSP Channel. Yeah.
So again that you back in my day. I actually bought an MSP. It's still super.
Yeah. Well, I came to the conclusion that security was just too darn hard right and that for most organizations. They were better off using an MSP.
Yeah. To supplement their internal teams because they their teams weren't smart enough to it. That's right.
And the beautiful thing I would imagine from a barracuda. MSP partnership is the MSP doesn't necessarily sell the machines to the end user. They they put him in there.
Yeah stacking and you manage them from their sock. Yeah. In fact the end user may or may not even realize that they're using Barracuda equipment.
That's right because the msps don't you know, they think of the msps the security provider. Yeah. It's a great that's I got it.
That's a great channel for you. Absolutely. It's a growth area for sure.
Yeah. What's really like you said? It is getting harder for ordinary organizations.
Sure. And what's really important is we recognize that difficulty is not only related to the attacks. But also the amount of tools you need to prevent, you know, Massive ransomware Attack.
Yeah, so we actually Required a company that has xdr enabled stock as a service. So we take the stock as a service all the way to the customer through msps. Right?
What's neat about that is we are able to ingest data from you know thousands of different vendors and be able to correlate the information and provide the right signal so we can actually take action and it's up to us to make it more efficient and automate it to the degree where we can help our customers more more quickly. And and this is why I think I would like to touch on this. We just recently partner with Amazon on their amazon security Lake product when we did is we provided the email signal into that their security Lake.
What's really good about that is that email signal usually is the first step for the attack? Right? Like there's a precursor is a precursor like some fishing attack or can't take over signal gets in there.
Guess what happens or even a Recon kind of even a Recon every enough for us to throw of some warnings and start tracking that kill chain, right? So what's good about that is we can actually short circuit attack. With something like an xdr, you know based to Sock like what we have we can actually say hey Fleming's account is looking like it's being you know hijacked or the conversation hijacking is happening.
Let's go ahead and stop access to applications like SAS applications or infrastructure. Right? So we believe that signal is probably one of the most valuable signals Because by the time you're seeing something happens on your network too late.
There's a there's enough happening right that could already be a rent somewhere problem. So that said that partnership Blends into what we're doing with the xdr, we believe this openness and sharing signals and because before for amazon security Lake, they're using the open cyber security schema framework. Yeah it is which is you know, well blast and we're the only email provider for the signals, but generally I believe doing such thing.
I think that's why Better Together theme this year. It's important that I The theme of this year's article it but it's true man. Yeah Fleming.
We're overtime. That's a pleasure. See I will person I hope glad you guys enjoyed what sounds like a very exciting RSA.
Definitely. Yeah, we're gonna take a break. We're gonna be right back here in just one moment.
Yeah. He's got to come and hook you.





