Harshit Chitalia, Tromzo | RSA Conference 2023
Tromzo recently announced Intelligence Graph, as part of the Tromzo Product Security Operating Platform. Tromzo co-founder and CTO Harshit Chitalia joins us to discuss the recent launch and much more.
Transcript
This is texturung TV. Hey everyone. We're back here live continuing our last day of coverage from the RSA conference in San Francisco at pleased to have you on my next guest is actually been a guest on Tech strung TV before you May remember him I know with hundreds of guests.
It's easy to get lost in the sauce. But I want to introduce you to harshit harshit should tell you they get there. Yeah, pretty cool.
I've gotten there it you know, it's not my first rodeo. Yeah, I shouldn't CTO founder of a company called charmso. But she pleasure meeting I should have back here man.
So you know what? As I said, you've been here before people watching right now. Probably you don't remember.
Yeah, let's start a little bit with about your story about charm cell. Yeah, absolutely. And as I said like always good to see you.
I love the energy. So I'm founder and CTO of tromsor. Thrombo is a code to Cloud risk remediation platform.
We help companies. Mitigate risk in the environment right? What we've seen is cisos and security teams because of the numerous threat vectors right go walk the sea so like the RSA flow you'll see so many companies, right?
So all of those companies are basically trying to find problems in your environment. We are the only one which is helping you fix those problems. Right?
Like that's the difference between US versus the rest and and how we do it. We will talk more about it, but that's that's about tromzo. And about myself, I was head of engineering for Juniper Networks leading all of network visibility.
I sold my previous company for mix to Juniper and then I said, okay, let's dive into security and two years in here. We are chatting more and more. So I got to ask a serious question.
What were you thinking about diving into security? Yeah, I mean, I always had this, you know being an engineer growing up and like always like hacker mentality, you know, like trying to find things which I could break and and not get caught. You know what I mean?
So yeah, no one no one goes into these things wanting to get caught exactly right? Oh, but at the same time like as you develop more and more Enterprise Products, you kind of realize this that there's a big disconnect between how developers think about security versus how security people think about security and and all Peter of time at developed a lot of friends within security. Right and I caught to know like and like when I was leading engineering at Jennifer I used to hate this guy you guys because they used to come in say hey you just stop this release from going out we can't do this.
We can't do that. So all the nose and nose and nose and and at some point you kind of try to understand the person behind it and it's basic. The whole goal is risk mitigation, right?
Like they own the risk. So they need to kind of think about it from that perspective. The product people are thinking about Revenue about features about what needs to kind of go into the hand of the customer security is important, but doesn't become the primary focus, right?
Like for me. It's like, how do I make sure that custom is really happy with the product. So, how do we bridge that Gap and how do we kind of get everybody on the same page was was something that I was looking for when our I was leading engineering and I couldn't find something out there so went on this journey talked to a bunch of more people.
And what happened is this that the story started resonating with more and more for especially during covid where you know, everything was remote people were going and buying more and more technology, especially like all this scanning technology because you had the whole stack that was completely changing everybody rushed to the cloud everybody rushed to microservices and you had all these platforms so I know myself I was running like five Services before Oh and then suddenly 150 right on all three clouds so you can see how quickly the landscape changed brought in a bunch of security tools. Right one for containers scanning one for cloud one for secret. One for size Dash and then soon.
I know I don't know what I'm doing. Right? I've bought all of these things.
I don't know if if something is more important or the other and all I do is now start paying bug bounty on top of all of that and it's still a big big bad right like so how do I get hold of that is was something that that kind of resonated with pretty much everybody and it was like Hey, if you solve this you have my money and here's the money to solve it as well. So so one of So there's a seesaw investor Network called svci formed primarily of like operators who are actually seesaws at well-known companies like coinbase and and a bunch of other companies and 27 of them invested in our company as well to kind of get us started and so two years in here we are. Get it crazy.
Yeah, totally. You know, I I've been in security 25 years. Yeah plus.
So I didn't consciously get into security believe it or not. Yeah, I you know, I was I was coming from the network side of things. Yeah, and I don't know how I still don't know how I happened.
But somehow the what I was doing with networks involved into network security absolute and never looked back, right? So we're here at RSA. Yeah, it's been a great RSA this 40 something thousand people.
Yeah, the buzz is on right? Charizard would you know, what? Are you hearing?
What are you seeing for from people? Yeah. I mean honestly coming in to RSA.
I wasn't expecting such a long days as well as like so much energy, right? It was pleasantly surprised for me. I mean the last RSA was like I would say it not there last year.
Yeah, right compared to that like this year has been just just amazing. I feel this is what it used to be. You know, I remember this being what it used to be before and and now it's like full bang on so so a lot of customer conversations a lot of people interested in in doing the right things, right?
We had like a breakfast event where if you see Souls were talking about their problems on how they think post covid and coach return to office in this hybrid work how they are managing. They are environment. What is yeah way of thinking and prioritizing things and so so it's been In enlightening like I would say series of like different talks discussion events, and we also have a booth at the early stage exposed.
So if you are still at RSA, we have the full day today come visit us at the booth as well and Even like just post this right? Like I think there are a lot of people who are interested in new technology trying to see what else is out there. How can we mitigate those threats and I feel that that energy in itself is quite like mind-blowing.
so shortly any news that you guys announced here or anything? Yeah, absolutely. So You know honestly is just full of news, right?
Everybody wants to kind of get into it's an avalanche. Yeah, it's hard. Yeah in doubt.
Yeah, and so We launched this new thing called the intelligence graph because what we really feel is that one really are going to keep on coming in security issues are going to keep on coming in right? So you never going to fix them. All right, if you if you if I met a c or a security engineer says, I'm gonna fix it all I mean, it's Nirvana, right?
That's not happening. So what's going to happen is like you're going to fix two percent of it, right? And how do you get to that 2% And so what we've launched is and new feature called intelligence craft where we bring in context and and all the environmental runtime as well as code context.
That's why we call ourselves quote to Cloud to bring in all of that data. Alongside all of the data that your scanners are bringing in right and that merge helps you really really prioritize. What is that two percent out of your entire backlog of issues that you need to kind of focus on because today like as you as you know, right you were saying you were a network person who got pulled into in a security right?
Pretty much all lot of people did and now what network security has become everything has court security your interest code, right you're things running on kubernetes is code all about the code. It's all about the code. So now the security people cannot be the ones who going to fix all of that.
It's going to be the developers. We need to fix all of that. The developers are fixing latency issues.
They're fixing performance issues. How do I make sure that the security issues that they need to fix also stick in that same backlog the same sprint and have the same kind of context around what I need to do. You have a product manager.
Who tells you okay? This is the feature. This is the input is the output.
This is what the expected. Here is from the user side. What our security it's like.
Hey here is some sort of a cve go fix it. Right. The person does not know what that CV is what it's supposed to do how to fix it or what cases I need to really resolve for so how do you kind of bring it to the developer?
And we need to the right developer, right? Because the security team is usually like I would say 5% of the development first, right? Like I mean, otherwise if you have a more security people then developers your company, that's why so so how do you bring it to the right people and bring it with the right context so that they can actually fix it is something that is become like the number one thing that people are asking for and with the intelligence graph that we have launched.
That's what we bring to the table. I love it. Yeah, good stuff, man.
Let me ask a favor of yeah, I want you to look into this camera. Yeah until people how did they engage with Tromso? Yeah, absolutely.
com. And there's a button right on the top says like get us in touch and get a demo and we'll be there and if you are at RSA booth number 41 hit us up, and we'll be happy to help you. I love it.
Amen suppose you're seeing you again so much. You know, it is great. Was it RSA that I interviewed you last year?
No, we did. No, I don't think so. I think it was wasn't it was between artists and black.
I was a zoom. Yeah. It was a zoom.
We just launched this whole Subway of like 400 developers and and that was the background at that time and we'll just coming out of stealth. So you're just talking about the problems. Take tromzo here on textrung TV.
We're gonna take a break. We'll probably be back in about an hour. Can't wait to see you with wrapping up coverage this afternoon live from RSA.
We're out.





