Sandeep Johri, Checkmarx | RSA Conference 2023
As application development evolves to include multiple deployments, migration to the cloud, and adoption of open source code and APIs, DevSecOps challenges are proliferating. Checkmarx and Censuswide research shows that 45% of organizations will experience software supply chain attacks, 86% have knowingly deployed vulnerable code, and 88% suffered data breaches at an average cost of $4.4 million. The enterprise needs to evolve its capabilities from “shift left” to a “shift everywhere” orientation that equips AppSec and development teams to proactively address security at any and every point in the development life cycle — before, during, and after deployment. Learn more from Sandeep Johri at RSA.
Transcript
This is texturung TV. Hey everyone. We're back here live at the Moscone Center for RSA seems to be a little bit quiet.
I guess there's a lot of sessions going on which is good because it's been a man house here today. I want to introduce you to a friend of mine. He's a security guy now, but I you know, the other times I've always interviewed of he was from the devops side of the house but devout devsecops is devops, right?
That's my thing this week. And so I'm happy to introduce you to Sun deep Jahari. So deep is the kind of newly minted CEO of checkbox, which is a company.
I think our audience is very familiar with they've been one of the pioneer leaders in abstract testing apps like I'm sick scanning in all of its many different flavors, so Sandeep welcome. Thank you. It's a pleasure to have you back here right different same guy different company.
I guess we should start with not everyone knows who you are and you're kind of history. But I mean it's a Quite a resume. Why don't you maybe share with our audience?
So Alan maybe if you don't go back that back go back that far, but my my first startup was a security startup really oblix. Yeah, which was I so sure that was and that was acquired by Oracle. Then I did two of us security startups really which were acquired by VMware.
And then I joined HP and I ran m&a there and that I got into sdn. Oh, I didn't know this so you I stand corrected. He's a surety guy coming coming back right back one.
Should they pulled your back? Yeah, that's that's what got me excited. So yeah, I've been I check marks for two months now and I joined check marks because I thought it was a great company great assets great people great customer base and in an area absec or call it up Dev.
SEC Ops is really, you know, it's just the first inning there, you know, every Enterprise I talk to has literally hundreds of apps that need to be moved to the cloud that need to be looked at differently from insecurity point of view. So it's an exciting time absolutely and exciting time and you know, you should it's the first inning Look check marks has been around. I'm gonna guess at least 10 years more than that.
Yeah more than that. So. When it first came out, it really was it was.
It's kind of like BC right prehistory. The idea of scanning code before it was deployed. It was pretty radical back then.
Yeah. We were lucky if people scanned code after it was deployed which kind of made no sense looking back at it, but the world is changed right now. I don't know 75 80% of all code is skin pretty deployment and check mark pioneered, you know this dust and fast and SCA and said IST.
Yeah. Yeah, it's cold right and you know container and yeah security. I mean a full add API security which is probably the new kind of darling right the new Battleground.
So it's a Soup To Nuts I mean Trulia. You know a full featured offering. But yet what we've seen and we you know, I was lucky enough yesterday.
We had Kobe from your team on our panel with this devops is now devsecops. We're seeing. people at How We Do curity and scanning inside of our development process and I think it's as you say that's where the first inning is.
Yeah. Yeah, so, you know Check mark started out as a sast company. Yeah back.
Then there were the SAS companies before four five is a company that I acquired at HP. And check marks really was the Next Generation kind of made it industrial strength, and that's why they got the traction they did and you know, we have 1800 customers worldwide based on that SAS product. Now what's happened over time is when all the code was proprietary code and mostly inside the organization where apps for monolithic scanning code alone made sense Because then you had network security once you put it in production.
Well, the definition of apps has changed you have one you have custom code plus you have open source put in there plus you have apis you're connecting to plus your packaging it all together and putting it into the cloud. So the definition of what we call and what we used to call an app has changed. That's why absec needs to be looked at differently.
Yep, and that's really what check marks that's what got me excited about it, you know sast has been around and check marks has been a leader for five years. We in the top right in the gardener mq, which is great. Yeah, but what is really exciting is a new product called CX one which is cloud native.
It's a cloud native multi-tenant offering but it does not only fast but it does dashed it does infrastructure is code API security and SCA. So it takes both custom code and open source and puts it all together. You can really manage the whole app A to Z through the life cycle.
Yeah, so that's fantastic. Now when you say it's a platform, is it a SAS type of offering? Yeah, so you don't have to know infrastructure to worry about no, right?
So CX one functionally covers the whole life cycle. All the way to deploy, right? So everything you need including supply chain and container all the way you need to put your app into production cx1 is a multi-tenant cloud-based SAS offering that customers are using in the 18 months that we've had it out there.
We already have more than 300 Enterprise customers on it. However, there's a lot of apps that are on Prem and a lot of code and code repositories that are on Prem so we offer both a multi-tenant. Version but for a very large Enterprise if they wanted hosted by us but a single tenant or managed by us.
I should say we also offer that so we can meet all the customers that we have specially large Enterprises. They're not ready to put all their code in the cloud quite here now moving aggressively to the cloud but not all apps are Cloud native as yet and not all their code needs to be in the clouds so we can serve both of them. So I love that idea and I think that verse utility.
It's important because there are whether Enterprises by size or or customers by vertical government right stuff like that. They they just can't be in a multi-tenant correct situation. They need they need that.
Yeah, you know isolation if you will. You know, you mentioned that cops and what I like Sandeep is here, you're almost interchangeable interchanging abstract deaf set cops because look this is what the message of yesterday. They're the same right abstick has become deaf set guys.
So, you know much like in the devops space where we had the dev team and the test team and the Ops Team and then it all kind of came together into devops. Security is going through something similar which is why devsecops makes sense. So there's a whole talk about shifting left which makes a lot of sense.
But what check marks is really talking about is I think it's it's delusionary to believe you can shift left only. And throw all the security responsibility on the developers as we were talking about earlier. developers like to write code that's what developers they don't get very excited about fixing security issues.
They don't get excited about fixing, you know doing testing. It's they have to do some of it. So we need to enable them you need to shift left to enable them to write better code and the like but you also need to shift right you really need to be able to look at the app through its lifecycle.
You can't take all the security responsibility and throw it on the developer this morning. I was on listening to a panel where there were two cios and they were making the same sorry to see those and they were making the same point which is there's only so much you can throw at the developer and make it their responsibility. So, you know check mark talks about shift everywhere and what we what we mean by that is really you need to look at it holistically and and think about apps that just like we think about devops you need to think about apps like from a devsecops point of view.
So there's a Dev roll to it. There's security team and Ops before you put it in production. And one of the things we have added relatively recently is something called bashing.
Code bashing is training training Learning System for developers. So when they are looking at vulnerabilities or looking at incidents that they need to go address we can give them the right we can give them the teaching security teaching and and learning right in the content in context and code bashing is one of the best security learning tools for developers because End of the Day Developers are not Security Experts, but they need to fix things. Right so code bashing allows them to do it in You know in context right there, which is something that there will be launching a free version because we want a million developers.
We want all developers to use that. Well, why wouldn't they though? I mean that's it for free, especially right?
And we cover multiple we cover all the major language is. Oh, yeah, so I do we should do a text wrong TV. Just you, you know, what would be better a texture on TV, but I'd like to see a demo.
Yeah. Absolutely. Yeah, we'll talk about it.
Yeah, I want to talk to you about another subject. It's the heart everything. You can't walk three feet without tripping over here.
Yeah. Yeah. How do you think that's gonna play into what you're doing and check marks?
AI first of all is the hype today and it's real it is having an impact everywhere. Yes. On security.
I think there's multiple areas where we are actually going to be launching something very quickly announcing it very shortly. We have I've seen them people listening so we care what you say, right? Well, there's a bunch of different areas that you know, you can use I mean in the long run it's gonna have huge impact, but let's talk about the short term.
Right what we will be able to do very very quickly. One of the things you need to do when you're scanning code for example is you have to write queries. Well, you need to become an expert at every tool well, all our documentation.
On how to write queries how to optimize queries is all documented. We're going to put a chat GPT like interface on that forward developer doesn't need to go become a query expert they can literally say help me write a query that does blah. You should be the front end for your code matching exactly.
And and it'll it'll leverage material from code wrapping. It'll leverage all our other query definitions and be able to give you results instantly. So there are those things plus there is things like let's say coming back to my earlier example of the developer getting five five incidents or five tickets that they need to go fix.
Well, they're not a security expert you can teach them or with chat GPT you can they can ask, how should I fix this? Don't teach me security standards blah blah. Just tell me how to fix this.
Right and we can give you that saying here's how you want to fix it. And so that's a simple it sounds simple, but that's such a powerful thing for developers. But again, we sit here is security people and it's like look, I have a foot in both camps.
So I don't have the horse in the race. But as security we people we sit here and we you know, we say developers. Well, let me show you why you're gonna do that.
You can go to jail. You can do that, right? A lot of times developers say look.
I just want to code that's right. Just tell me what to fix is I'll fix it and I'll get on with my and what we do we what we can do with with these llm system says allow the developer to be that much more productive on the security side end of the day a security person is not going to fix the code. The developer has to yeah just makes it super easy for them.
So we'll be we'll be launching this. I've already looked at what we've done internally. We're going to be launching it very shortly.
So yes stay tuned for that from check mark. Yes. What else did RSA I know you guys are obviously exhibiting here.
What else are you hearing from the team and it's 40,000 people here. They said this year so, you know for me, I've been there's a lot of interesting vendors with a lot of you know, a lot of new Solutions and as new threats come it kind of makes sense, you know, a lot of these companies but what I see is a lot of Point Solutions and the panel that I was referring to had multiple cisos on it from large Banks and the like and what they was what they were telling which I took away is they were telling they were talking about the fact that they have too many tools. There are too many Tools in security each one of them literally each.
One of them said we have more than 20 tools and there are two things we can do one we can have platforms that can integrate these more easily so I can still use some best of breed but I would like it all integrated and two they were talking about a need for consolidation, right? There's just too many points Solutions interesting but a little too complex to implement and expect your security and your Dev team to become experts in 10 of these tools. I think those are two Trends which align well with what we were talking about earlier, which is the shifting definition of Of devsecops or abstract in the new mode if you may and I think that's where I came away very excited because cx1 has that integration.
We're also we we have a layer a correlation layer on top called Fusion which makes incidents or alerts from each of the individuals and correlates them so that we can tell a customer across all of these functions here. They pop issues critical issues. The other thing for AI that will make easy exactly.
That would be a big a I think yeah, you know Cindy I find it interesting thing. you know the problem one of the issues with security is Securities grown relatively holistically an organizations though some some you know, we say 20 or more apps. Well, some of them came maybe from m&a within an organization you inherit their apps.
Yeah. but the other thing is We're always in search of a better mouse trap and and we don't throw away the old mouse chat, right? We just keep piling them.
So at the end of a short period of time you just have a pile of mouse traps. Don't necessarily work. But you know, there's this hoarder mentality almost where I'm not gonna throw it away.
It might work and and it's a it inhibits us. Because because what happens is we are see so now you go back to the board and say there's a new mouse trap out. I want to buy the new mouse trap and the board says you just bought five mouse traps.
What smell I tell you. I'll tell you I talked I've met a number of customers here one was a two three of them were large Banks you would know the banks who are all customers. One of them is one of the largest health health provide health insurance company, right?
And what all of them talked about is this point you were raising which is we have enough tools. They said what who can you? Help us figure out.
How to take all of these tools and actually assess which apps are ready to be put into the cloud which apps have what level of risk, what is the risk profile on a at an app level across by looking at all of these tools? So we have a methodology called lapma which is application security maturity model and we already do that for a number of our customers where we go and and it's a it's a it's an online tool you can go on on our website and kind of do a self-assessment but often we go in and help our customer assess where they are on the maturity. And it's too like Gnostic.
It's got nothing to do with the tool. It's really got to do with absec maturity. We help them assess where they are and then lay out a roadmap for them on how they can go up the learning of and go up the maturity curve because that's what's needed.
There's plenty of tools out there God knows and I think the especially in these times economically, I think boards are tired of hearing about the next mouse trap. Yes. It is.
Yeah so deep. I wish you nothing but lucky check mark, we're looking for big things. I think they they're lucky to have you wait.
I'm super excited and looking forward to our partnership. Well, we will we'll talk more. We're live here at RSA.
Check marks is here. We'll be up next with our next guest in just a moment stand by.





