Collaboration in the Federal Sector with Bridget Gleason and Irina Denisenko | RSAC Conference 2025
Guests Bridget Gleason and Irina Denisenko discuss their collaboration in the federal sector. They focus on infrastructure as code, security, and governance, with Knox Systems providing FedRAMP as a service for compliance. The partnership addresses the need for secure solutions in large enterprises and government, highlighting AI reasoning agents for continuous monitoring. Future goals include enhancing application onboarding for resilience and security.
Transcript
Welcome back to Techstrong tv. Lisa Martin here coming to you live from Oconee West at RSAC 2025 in San Francisco. This is Techstrong's, 10th year of covering RSAC.
We've been having some amazing conversations today with cybersecurity experts, which, you know, 'cause you've been watching since we started. I've got two great guests here next here to talk about what they're doing in the federal space. Bridget Gleason joins us, the CRO at Space Lift and Irena Deko, the CEO at Knox Systems.
Ladies, it's great to have you on the program. Thank you for joining me. Great.
Thank you. To be here. Love talking partnership stories.
So let's, let's do it about for each one Okay. Space left. Give the audience an overview.
We're talking about infrastructure as code, but what's your secret sauce? Policy driven, governance, security, enabling teams to go fast. It's all about velocity, but you can't sacrifice on security and governance.
So that's really, that's really the secret sauce. And you are enabling developers to go faster. You're enabling platform teams to have more control.
Right. The whole, the whole ecosystem to go faster because the name of the game is getting your software out there. Yes.
And you can't do that if you're not able to deliver it on reliable, secure infrastructure. Absolutely. So, and that's all that we're talking about today Yeah.
Is, is around security and it's becoming more and more challenging and more and more important. Absolutely. We're seeing It's kind of a double-edged sword because it's essential, yet there's so much more software being developed every day.
Right. And that threat landscape just gets more and more amorphous and sticky and Right. It, there's no surprise that we've seen a huge uptick in demand at Space Lift.
I wanna give us a background on NOx Systems. Where you, where are you based? What do you do?
How do you partner with Space Lift? Thank you. Well, Knox, uh, is a very simple concept.
We are FedRAMP as a service. Okay. We host our customer applications in our federally compliant cloud, and we get them FedRAMPed in 90 days for 90% off of what it takes to do it alone.
Oh my gosh. That's huge. And so we are so excited to partner with Space Lift, uh, to be able to bring them into FedRAMP, but even more importantly, to be able to use them for us.
We manage, uh, over 20 applications, including Adobe's Federal Cloud, and we need tooling to do that in a compliant way. Yeah. And that's exactly why we're so excited to be using Space Lift to do So.
And how new, how long has the partnership been going on? It's being announced tomorrow. Oh, congratulations.
So you are like, This is, we're breaking news. We're You're breaking news. Thank you.
I'm excited. Hot off the press. And you know, when our, when our CEO came to me and was telling me about Knox, and like you said, 90% discount, 90 days, I thought, there's no way.
Yeah. And for us, we have this growing demand. Our growth is being fueled right now by large enterprise government organizations, lots of regulatory industries.
And so having this FedRAMP piece is so significant for us. And also being able to deliver that to Knox is really exciting. Is This opening the door for space lift in the federal space?
Yes. To some, some don't require FedRAMP. Okay.
And we're able to satisfy that. But many, many, many do require FedRAMP. The other that Irene and I were talking about as we were walking over here is large enterprise.
Also, when you have that FedRAMP certification, they know that you've got a, a very strict security checklist that you've already complied with. Yeah. And so I think that's gonna accelerate also Sure.
Time to market for some other Right. Companies that we're working with. Well, You're giving them the confidence are Thrilled.
Yeah. You, you're giving them the confidence, the customer base, A hundred percent of what You're able to deliver. Why would some federal agencies not be required to do be FedRAMP certified?
Is that, You probably know that as Yeah. So I assumed it was a blanket requirement across, So the, the, the situations are really, if you're delivering on-prem and space Lift is able to deliver both, both SAS and an on-prem. So if you do on-prem, that's fantastic.
And you're able to, to deliver to the government because effectively you're air gapped. But for the many, many, many SaaS solutions out there. Uh, and to be able to, to operate at the speed of SaaS and at the scale of SaaS, uh, that is where FedRAMP comes in.
And that's really where we're enabling space lift to, to really accelerate. Okay. Got it.
Talk a little bit about what federal agencies will be able to achieve with this partnership. What's in it for them? Absolutely.
So, uh, I'll, I'll start off right off the bat. We have 15 federal agencies that serve as our authorization to operate providers. That means they are our sponsors.
And they are thrilled about this because what it means to them is they know that the applications that sit in our boundary, the applications that they consume, are that much more secure, that much more, uh, observed and, uh, compliant with all of, not just the FedRAMP regulations, which are very important and really the name of the game. But also there's many additional regulations around now AI coming out Right. Around cryptography coming out.
Yeah. Because of course, software is moving so quickly. Yeah.
And so what, as we harden our stack with tools like Space Lift, um, it means to them that they feel a lot more confident. Right. Consuming from our cloud.
And, you know, I do a lot of marketing. I I've been in marketing for a long time, and confidence is critical. It's not a marketing term that is to, to be able to give a developer a platform team a, an agency.
The, the trust and the confidence that their applications are secure is not table stake. It's Table stakes. No, it, it, it, it absolutely has to be.
And Irene and I were talking earlier today about how this, this administration is looking to modernize a lot of the infrastructure. Yes. It's, that's gonna require for them to do it a lot more software companies that are certified to, to service the, the government.
And it's part of the reason I'm sure you're seeing a big demand. We're seeing a big demand because for us to fulfill that, we've gotta satisfy these requirements. So as you said, it's trust, But It's also, there has to be the security, very real security.
And it is frightening to think about with AI and some other tools out there that the threats are getting bigger. And so being able to have a platform like Space Lift that is very strong around security, compliance, governance, et cetera, is critical. One of the things we heard today, we were at the same, um, talk this morning, was companies that want to allow their security folks who are working on compliance issues, everything you do need to do to satisfy compliance.
Yeah. They would like them to actually be working on security issues. So a platform like Space Lift that can take away some of that, those compliance chores and busy work Okay.
Will enable some of the security people. What did they say today? How many?
500,000 open positions open positions in, in cybersecurity security. Yes. Right.
Yes. So we've gotta make sure that the people that need to be, that can be doing security or working on it and space lift, can help take away some of the other compliance and auditing and some of those other requirements that we can help fulfill through automation. Right.
And so you have the security folks focused on they need To, and that's what they want to do. Developers wanna develop, security professionals, wanna secure by being able to offload and automate some of those, I don't wanna say menial tasks, but tasks that take time and resources is huge. Well, we, I don't know if you know that we released an AI agent about two weeks ago, uh, Saturn head ai, and I mean, you're talking about the mundane, repetitive tasks for DevOps engineers that's finding out what happened when a deployment fails.
Yeah. And it requires looking through very complex voluminous logs. It's mundane, it's repetitive, and it often requires a more senior engineer Okay.
To be parsing through those logs. So our agent can go analyze the logs in plain English, give you a description of what happened. I really like that.
Like that. Yep. And then also these are the things required to remedy it.
So again, making sure that we've got the more senior people deployed on the really the highest, highest tasks. Yes, yes. So from a sales perspective, are you selling into developers?
Are you selling into security teams? Is it Both? Yes.
Yes. All the above. Yes.
Okay. We get interest from the developers, we get interest from security, we get interest from CIOs, we get interest from platform teams. Okay.
It kind of comes across the board depending on what their lens is to look at it. Okay. What excites you?
I mean, there's so much. You talked about ai and we can't go to a conference without talking about ai. Right.
You can't even, A fashion conference is gonna be talking about AI and fashion, I'm sure, but it's been around for so long yet, the chat, GPT Catalyst a couple years ago just brought it front and center and everybody is diving in head first, but it also opens up vulnerabilities, op and more opportunities for the bad actors. What excites you about some of the positives that you are seeing in the security space where AI is concerned versus all the, the fear that's out there? Yeah.
Well, I can tell you from just operating our federal boundary, um, it is a game changer to have AI reasoning agents that we can custom train on our data run with open source models that we are able to fully understand and actually take those agents and scan our boundary for issues with the boundary not being compliant with FedRAMP. So rather than having to do something manually only once a year or once a month, or as often as you can get to it, we're able to truly do continuous monitoring. And that is only enabled by AI reasoning agents.
Um, which is why we're so excited because, uh, yes, the bad guys are gonna move fast. Yeah. But we're able to move faster.
That's so important because it's, it's like the AI arms race. Yeah. We see country to country all the competition going on, and we see every organization, um, embracing, really embracing ai.
It's rare if I talk to A CMO who's not embracing it, at least generative ai, and now it's agentic AI as well and ephemeral ai. Talk a little bit about the go-to market strategy sales, CEO. What is that gonna look like from both of your lenses With regards to the partnership?
Yes. Again, we were talking about this on the way over. I asked Irina, so when will we be FedRAMP authorized?
Yeah, exactly. And she said, June One. June One.
That's Round, Hit go. So Again, I've got, I've got a pipeline of opportunities right now of, again, large enterprise regulated industries, government organizations that have already reached out to us and are looking at space lift. So I think we'll continue business as usual.
We just, now there's a gap that we, we hadn't filled and we thought it was gonna be, honestly, Lisa more than a year and very expensive Yeah. For us to do it. So this is like Christmas For me to have This.
I mean, it's so, it's so thrilling. And I think for our customers as well, because they're trying to do the same thing. They're trying to create resilient Yes.
Scalable, secure infrastructure for their environment. So to be able to satisfy that just feels really great. I think it's, it's definitely a win-win.
It sounds like there's all already a lot of momentum from a demand perspective. Are you seeing the same thing on the NOx sign? Absolutely.
So part of this partnership is actually, we at Knox are installing one space lift worker per application inside of our boundaries. So that's already, uh, almost 20, uh, uh, workers installed. And as additional customers come onto Knox, they're using space lift.
But the other thing I'll tell you is that even for example, one of our customers, as I mentioned, is Adobe, they're now starting to look at space lift as something they might wanna be using, even beyond just their federal application, but in their development team, uh, beyond. So it's a, it's a really, uh, because it's such a broadly applicable tool, not just for federal security, but much more beyond that. It's a, it's a great place to, uh, to really, uh, spread the word.
Sounds like you guys are gonna be awfully busy. Yes. That's a good thing.
Right? Absolutely. I just wanna shout it from the mountaintops.
I'm so enthusiastic. Smart. You can about I love it.
I'm so enthusiastic about the partnership. Again, it fills a great gap. Yeah.
I think we're gonna be great partners. It's so mutually beneficial and, uh, reinforcing Yes. Of one another.
So we're both, we're really excited about it. And, and you're gonna be able, you know, we talk about cyber resilience all day long. It's a journey.
It's not a destination, but it's also one, like I always wonder how can organizations truly become resilient? How does this, a facilitator of that? Because resilience is the goal for so many organizations across industries.
Well, this is one, this is one step towards that. Absolutely. You know, one, one thing to, to really, um, I think the, the position we take at Knox is to be, uh, aggressively conservative, right?
Okay. And you can only be aggressively conservative in your security practices, in your, uh, resource configurations is if you're able to one, automate, but be, observe exactly what you're doing. That's why we use infrastructure as code, and we always have, that's why we wanted to use Space Lift right out of the gate.
And, uh, and we, we said, please, would you get FedRAMP police so that we can, we can use you. Um, but that is the only way to stay resilient if you're able to automate and be kind of everywhere, all at once, all the time. Yes.
That's the only way. Right. What do you hope for?
Last question for both of you. What do you hope here we are almost in May, June one hit the ground running. What is kind of your dream for the rest of 2025 as partners?
Well, I can tell you, uh, we are gonna be bringing on a number of, uh, uh, applications into the NOx boundary. Every single one of them is going to be running, uh, space lift workers, uh, to orchestrate their, their environment. Um, and what I'm so excited about is, uh, to really be able to, to see this, you know, mass machine humming.
Yeah. And, uh, and you know, there's, there's no doubt that there are going to be, you know, there, it wasn't that long ago that Log four J took our entire industry down for, you know, months. Yes.
And, um, there will be more. And what I'm very excited about is that we are, we are building, constructing this boundary, um, in a very hardened way, in a very, uh, uh, thoughtful way. And space lift is a key part of that.
That's critical. Ladies, thank you so much for joining me on Techstrong tv. It's been great to have you.
Likewise. Learning about the partnership. Congratulations.
The news comes out tomorrow. We got to break some news. I always love it when I get the chance to do that.
But it sounds like you're creating that resilience that organizations, not just the federal agencies, but in every industry. That's right. Have To.
That's right. This definitely goes beyond just federal agency, so it's really thrilling. Well, congratulations again, and we'll be watching your trajectory.
And we thank you for sharing your insights on text on tv. Thank you. For my guests, I'm Lisa Martin.
You are watching Text on TV Live from RSAC. This is Day one, wall to Wall coverage, four days here on Textron. Stay tuned.
My next guest joins me in just a minute.