Nico Popp, Tenable | RSA Conference 2023
Organizations around the world are embracing the cloud to accelerate their business. But managing highly complex and distributed cloud environments – each with its own security tools, processes and specialized skill requirements – is neither easy nor straightforward. Nico Popp, chief product officer at Tenable, joins TechStrong to discuss cloud security challenges and how the Tenable One platform, equipped with Tenable Cloud Security, provides organizations with more control over their risk and consolidates old and new technologies into one.
Transcript
This is texturung TV. All right. Hey, we're back.
We're live here at RSA Moscone West moving into our afternoon coverage. I'm really happy to have as our next guest Nico Park Nico is the CPO Chief product officer. That's it attendable.
Is it still tenable network security is it just tenable it's tenable and then we're trying to do something bigger than VM of lovely management. Absolutely. Well, that's where it started of course, but this is this I still that's how I first met Rondon Reno gold standard.
I mean today best sensor on the planet starting company in 2001. I co-founded still secure and we came out the product called vulnerability assessment of management. Based on that's just like everyone else was right back.
Then that was the scanner would still open it was the time. Yeah. Well, it's still two point seven.
I think. Oh, I remember that. Yeah, and then then we hired a bunch of folks in India to write our own natural script.
Remember those days. They're still there. I'm sure why don't fix what's not broke.
But yeah, we and then we got into Knack which was a little bit but it was still very same thing. Yeah is your trust now? Well, we didn't call it 0 but we sold.
So our big customer was the governor DOD and a lot of those places and yeah, I was interesting times interesting times good days. Yes, it was but the world's different and I think Security's better now than it was then I agree. I mean we raise our game.
Yeah. I mean it's, you know, we still hear about breaches and we still hear about it Ransom and all of these things are better too, right? So, yeah, that's what it's the mouse game but tenables different Niko.
Let's let's start there right? We're talking ancient history. Let's talk about tenable today you want you're more than vulnerability management exactly.
So we all know as the gold standard for VM. And what we want to be known for is. Exposure management.
We think it's a new category in security. Simply put it's really the unification. The consolidation of proactive proactive security Now, what is it?
Can't defend what you don't know you have another one. Yeah, and then My friend Jeremiah Grossman and Robert Hansen, right? Yeah.
I know that one. I know you do. Yeah, good deal.
I mean, I know I know Jeremiah since he left Yahoo. Yeah before we started white hat even small world. Yeah, and I know you tenable acquired their company, which it was the last Mna for external tax office management, and that that really gives you a great picture X you say external of what you have but when I look at security today, Does this attack surface management people talk about that, right?
So because that attack surface is constantly expended. So is that what you mean by exposure that's only part of it. That's what I mean by proactive security.
So obviously start with VM, right you still have laptop. You still have service databases. They still have Monopoly but now yeah puppy club, right?
Probably Claudia Miss configuration cspm. That's been probably yeah, you know, you also have containers workload. That's what we management.
Keep going left. Right? Yeah you building on application for the cloud you have open source Library.
So you have that sick. Yeah your own code. You have API you have web application scanning go right?
See there's software. But also I think you left that software supply chain. Well that's upset for me.
Right? Okay, because open source Library. Like if you look at the solar wind attack what they did they injected the own Library into God.
I got his bummer, they find it and they said it. Yeah, I know. So to me that's part of website.
Okay, you should get up legit by Ariana. Okay. No, I go right.
What's the second biggest Monopoly after software? I'm touching water. Oh, you people humans.
You think the humans are second. Not first. Oh, yeah, but it's easy for VM people.
Okay? Yeah. Okay.
So humans identities, right when somewhere I'll keep you actually misconfiguration over access unused privilege you already you may have as already you have as already you may have a doctor you may actually all of the above. Okay now all that access rights your trust. Yeah.
Yeah. Keep going, right? Okay.
Oh, there's access to this authorization as well. So authorization is available. If I give you too much authorization.
Oh, it's a news that is a vulnerably right now go to sass few Salesforce. You have authorization our back in Salesforce. That's another set of vulnerabilities.
I'll add OT around third party risk management. I can keep going so you see a bunch of vendors a bunch of sensors the first idea out of three, I won't go beyond consolidate all that so you can see the economy of scale right the segmentation the complexity that you validate you mean in like one dashboard and one interface or The data is the platform. See these are different personality the app say guys not the security guy.
The cloud security is not the VM guys. Yeah, they can have their own console. It's not a big deal.
What matters is can you bring the data together? to do something and I'll give you you know to really make proactive security better. So I'll give you two things but I'll post you're good on that.
I'm good. I'm good. Alright, you good.
You're good. They're good. Okay, so I keep going.
So the first benefit is how do I operationalize all that because the attacks are faces immense. I found all these I said all these memorably access software misconfiguration. What is critical?
What do I need to fix first so prototypes? Can you prioritize for me because the attack surface and normalize that partition should I fix my critical and I everywhere but that's still a lot or should I start with active directory my club which one creates the most race that is the first thing how do I operationalize preventive security bring their data do analytics got to be in the cloud. That's the first value.
I want to pause there. Okay, do we got that operationalize? Exposure management all the assets all the finding on the phone.
Give me the critical few cause my attack surface. I love it. You know what?
You're old enough you remember you remember like well is Tivoli and then they bought Big Fix? Yeah from the IBM. Yeah, remember yeah.
that's like back they would they would. They had the notion of this but we didn't have the I guess we didn't have the technology to do it. All right.
So you think consolidation in security? You know, I call what we're doing the last platform because prevent reactive security has been Consolidated you heard about SSC or SSE. It's basically network security the firewall means this week meets the VPN.
That would that was me. Okay, you talking about my time? Okay, so that is consolidating.
Right? That's SSE. The other one that's consolidating is the same idea xdr.
Right? I'm putting the endpoint there. That's what the identity there are still reactive.
The only place where you constantly dating security productively is identity. I will harden you I'll give you multi-factor authentication. I will do zero trust.
I will minimize the privilege that you have but if you look at right Centric preventive security Big hole no consolidation. So what we're doing at tenable, we're driving that consideration. With the benefits the technology benefits that I described to you, but there's also the economic benefits less vendor, you know less cause less integration simply simplification.
I that's exposure management. Yeah, but there's a big idea. There's also a big idea Beyond prioritization.
which There's a reason why. Security we think is can be improved drastically is security is a bunch of sellers, right? You mentioned psychops.
You have more silos than ever and the only one who are not silos are the attackers the bad guys, they take advantage of it. So they know they can lend someone they can move laterally. Yeah, and because we are doing Security in Solo the 80 guys are doing 80 security.
The VM guys are doing VM the theot guys OT the cloud guy caught so the idea is we can actually connect this thing by bringing the data together. And there will be better security. I'm going to give you an example.
Let's say you'll have Palo Alto. Okay, you just spend 20 million buying prismacolod. Oh you buy with okay for classic City 20 million.
You got it all the tech stock. You're securing the car, right? Oh, yeah.
Okay. Good good answer. Well, I'm from security.
Are you okay, but is my But a lot of people they that is a blanket for that right now here comes Bob. You forgot about Bob. Bob is an SRE Bob is a developer.
Yeah, but that's it bob has access bubbly is using his daughter's computer exactly at home. Oh, he has a machine at home. That's not comfortably.
It's gonna get fished. It's credential. He's talking to get stolen.
Now the nation said as I access full access to your clock your debt, so you see the connection kills you relationship man. Okay. It happened in the password manager, right?
Yeah. What's your name last pets? That's an example where aggregation got done right?
It's like if you break the video, but they got it through Bob. Yeah, and once they got in they were able to get these hatch I mean crazy and Bobby's everywhere. So that's we can all be Bob we all right.
We're all Bob because you know, look, we're all I'm sure it's happening to you. My my computer's not working honey. Let me use yours or let me use your phone a second a better way that can be more subtle than that.
Right, but the no you make this you mentioned Jeremy, right? If you know that an asset is sitting on the internet and you are not scanning able you get a measure issue. If you know, you are scanning it withinable and you are only fixing the high in a critical.
You should probably fix the medium because it's exposed. So you see that I hear okay. Let's go.
Here we go. You are high in critical. It's not my high in critical.
It's my problem and I I I remember when nist and Mida came out with the cve and how we were gonna rate them by criticality. But I think the world's changed right? I think I think we can't just label something critical because it may be critical for you or maybe critical for me and not critical for you.
I think that whole system lacks context. So when I say relationship, it's another word for context Okay, so And I agree with you, you know, we do on with scoring. I know you you may do and we'll let by the way we'll let the customer if they have their own with score.
They have their own ml team. Bring their data right bring that there are and if you want to use cap bring that did it we're not religious but what's more interesting is what we call it is factual prioritization or context based politicization. Well, the example that I give is I can tell you you have 36 version of Chrome in your environment.
Okay, you think that's a problem from a series standpoint? Yes, very scoring. I can't tell you.
Would you like to know how many Seaside means sis and me highly privilege users. Have a laptop that at least one, you know seesaw critical vulnerably. That's the fact that's not about arguing about a risk score.
That's the truth. You know, actually I say, you know, but you can't handle the truth, but that you know, so contacts based participation is the other thing. So when I talk about breaking the cells and linking this thing together, that's that context.
Yeah that workload easy. I agree. So let me ask you questions.
This is available right now. Ten. Number one is available we started and it has exposure management built.
It is God. He's got some sensors right class security ASM, which I'm yeah and the security Etc. He's got the prioritization and we have something we call attack path analysis that will show you how hacker with basically use that context to move across your attack surface.
I love it there and the percent there's a lot of innovation to come and I will show you that companies. Can you wait But we we are well into it already. com Nico.
Thank you so much. And I appreciate it. Enjoy.
The rest of us. I got a full week with 40,000 of our friends. I think more than that.
I don't yeah 40 50,000. It's a Blog just at least four. They were they new they had at least 40.
I didn't get the final number. They love what it's we're back, you know Innovation sandbox twice. The number of applicants and Innovations was crazy this year.
I was up yesterday. Yeah. It's just been crazy thing.
We're gonna take a break. We're live at RSA we go pop tenable networks. Well back with our next guest and just a minute.
Thank you. Thank you.





