Exploring AI Integration in Cybersecurity with Eran Kinsbruner | RSAC Conference 2025
Eran Kinsbruner discusses AI’s integration in cybersecurity, focusing on the shifting security responsibilities towards developers. Key challenges include scale, trust, and workflow integration. Pre-commit security checks and secrets detection are essential for code protection. Customer feedback significantly influences product development, while insights into application security posture and organizational strategies are also shared.
Transcript
Hello from broadcast Alec Tech Storm tv, Lisa Martin here, finishing day three of Wall to Wall coverage from Tech Storm tv. We've had some amazing conversations. As you know, because you've been tuning in live, all of our content is gonna be available on the socials on demand by at least next week.
So if there's anything you loved and you missed it, or you wanna watch it again, no worries. We got you covered. Our next guest comes back to us.
Aron Kin Sprinter is here, the VP of Portfolio Marketing at Check Marks Aron. Great to have you back on Tex on gang. Thank you.
Happy to be here again. Uh, an amazing show and, uh, amazing show. Always love to talk to you guys.
Yeah. So give us a recap of RSA. This is the end of day three.
Yep. You got in over the weekend from Boston. Yep.
Your perspective, you're new to check marks, but you're not new to the industry. You're not new to the portfolio. Yep.
You're a veteran of cybersecurity. What have you seen that's really impressed you this week? So, we have had many, many conversations, some of them, of course, about ai, agenda ai.
Some of the conversations were about concerns, especially in the, uh, reality of security cybersecurity. How is AI going to either add more risks while it solves other? Yeah.
So, uh, this adoption of AI within AppSec was a main topic, uh, during this week. Uh, again, good and bad. Yeah.
Uh, at check marks, we hope that it'll actually go, tend to the good side, you know, protecting AI code generation and, uh, things like that. That was one thing. The other thing, uh, which was very, very clear, is the shift in, uh, power responsibility towards the developers.
This shift left that everyone is talking about, that's fine. But there were many domains that shifted left over the past few years. We believe, and we hear it this week, that security app security, the power, the responsibility, and the concerns as well is shifting more towards the developers.
And these developers are now going to actually be looking for better, more efficient solutions, which enhances the developer experience, but also supports the jobs that needs to be done. Right. Right.
Coding, fast, secure, high quality, high performance. What are some of the concerns? I wanna talk about the, the optimal developer experience, but what are some of the concerns that you're hearing and how do you respond in your current role with we got this?
Yeah. So there are many, many challenges that developers are facing. So it comes with a few words, scale, trust, and fitness to their workflows.
And I'll break this, these down. So I'm talking about scale today. Everyone is like using tons of open source libraries.
I would say 80 to 90% of the code that developers are using today is not even theirs. Okay. They're using ai, they're using open source libraries, and they're also adding their own proprietary code.
Okay. So the scale and the amount of code that is being added, uh, I I'm aware of about 700,000 new libraries packages on just the NPM, the no js, uh, registry. Okay.
So this are, this is a lot. Yeah. Okay.
So developers are kind of, uh, exposed to way more lines of code and kind of scaled cloud repositories that they need to protect while they're using it. Yeah. So that's the scale.
The second thing is trust. Can they actually trust the tools, whether they're coming within a platform, engineering portfolio, or they're just tools that are part of the, uh, uh, you know, DevSecOps, uh, tech stack. Can they trust what they're actually getting in response?
Like less false, positive, less noise. Yeah. And, uh, this kind of thing.
And lastly, uh, as I mentioned, is the fitness to their workflow. Okay. Developers are developers.
They're not top security engineers. Right. And they need everything that serves them to be within their workflow, integrated into their pipelines, integrated into their IDs and so forth.
Within check marks. We actually made a few announcements this week. I'll just give a short recap, and we have them a lot all on our website.
But A SPM in the IDE pre-committed secret detection integrations with Artifactory from jfr, right out of engineering dashboards, these are all developer experience, uh, focused enhancements that we have done to actually tackle everything that Jeff just mentioned. High scale code repositories, trust and fitness to the workflows. So that's kind of what we are hearing and how we respond.
And none of those are, are negotiables these days. The scale is continuing to grow. Right.
The trust is absolutely critical for every industry, every organization. Yep. And the ability for them to be able to do their jobs as so much is coming at them is essential for their workflows to be optimal and successful.
I, I, I, I completely agree. And, um, you know, you mentioned scale. You know, many of our customers, huge enterprise customers, you know, they have hundreds of development teams.
Yeah. Okay. And thousands of pipelines.
So just to give you a sense of the scale, right. Check marks is scanning on a given month, about 450 billion lines of code. Wow.
Okay. So I think that kind of gets you the feeling of the scale that we're dealing with. Yes.
Yes. Okay. Yeah.
And that's not gonna go down. That's only gonna go up, right? It's Just going up.
Yes, yes, yes, yes. I saw this really cool LinkedIn post from you. And if you guys check out Aaron around's post on LinkedIn, we're gonna break it down.
A where you said you're exploring how pre-commit security, and I wanna understand that concept. Yep. Checks and secrets detection, how that can stop exposed credentials before they even hit a repository.
Yep. First of all, define pre-commit security checks. Define secrets detection, and why in 2025, as the threat landscape changes so much, it's now more important than it's ever been.
Yep. So, uh, I'll define secret detection secrets are basically anything that kind of developers use to engage or to interact with other, other components. Okay.
Whether it's, uh, API tokens, uh, password usernames, passwords, uh, whatever access credentials that they need to get to different systems. Okay. So these are kind of a very high level, like your username and password, your email address that's a secret.
This kind of thing. Yeah. That's a secret.
That's a secret. Okay. Right.
And when this is already exposed, that's too late. Okay. When it's already getting its kind of way towards a public repository, a shared repository that's already too late, it might be found later on, it might not.
Yeah. Okay. So that's where the pre-commit comes into play.
Okay. We believe, and we actually talk, talk to our, talk to our customers and sells them. Sells them.
Actually, this feature comes as a request from one of our customers. Okay. Few of our customers actually.
Yeah, I'm sure. And it actually kind of, uh, gives them a safe way to create a source code. So every time that actually they run or they write a line of code, if they're exposing a specific secret, okay.
This pre-commit mechanism framework, if you like, give them a, a heads up or a trigger alert and actually gives them the exact file where this secret is being exposed. Okay. And they can remediate it, remove it before it actually makes its way to the shared repository.
Okay. Once they're doing that, it's like win, win, win. Because A, they're obviously pro protecting the entire code base.
Yes. B, they're saving a lot of engineering rework and Sure. Uh, which costs a lot of money.
Right. Because once you need to remediate after it was already in a shared repository, it costs a lot of money. Yeah.
Right. Rebuild, retesting and rescanning and everything. So we're trying to prevent and block this secrets at the source.
Okay? Mm-hmm. So as you as a developer is writing his piece of code, we, uh, do this, uh, pre-commit scan and give him, give him the alert.
It can save a lot, a lot of headaches, money, and protect the business at the end of the day. Absolutely. It seems like that's a no brainer these days, because using, you need to pull this back, secure your code at the source.
Yep. Why are some organizations not doing that yet? So, uh, awareness.
Ah, uh, and that's one thing, but second, developers find it quite, you know, uh, easy to not, uh, hide these secrets because, yeah. It's just, in my local environment, it's very easy for me not to really like, uh, put it outside or hash it or whatever. So sometimes developers find it very convenient to use or to actually expose the secrets, but it's just in their sandbox.
It's just in a pre committ environment. Okay. And, uh, that's the mistake because you forget about it, and then it just slips to production.
It's too far downstream by that point. Yeah. And that's one thing.
The second is when you are relying on AI core generation. Yeah. Right?
And you are kind of just giving the secret to an AI tool that will generate additional methods, additional source code. Right. You also rely a lot of, uh, uh, your, you know, that we talked about trust, right?
Yeah. You rely on the AI to take care of this recommit, which Right. Which you shouldn't.
So, uh, it's about education, about awareness for developers, and sometimes taking, taking them away from their comfort zone. And this pre-commit thing actually keeps them very comfortable because it's an automated process. They don't need to do anything manually.
They just need to add kind of a line of configuration to the, uh, pre-commit build. Yeah. And that's, that's it.
It's one line check marks does the rest. Okay. Every after you do this, every new line of code, every secret that is being exposed will be scanned, alerted, and moved away autonomously.
Autonomously. So you mentioned the comfort zone thing, and that's one of the things that we talk about with the developers, the security folks, the DevSecOps movement, and how there's a lot of synergies in how they behave, yet there's cultural and behavioral challenges there. Yes.
So check marks has found a way, let's keep this in their comfort zone. So what you're, what I'm hearing is you're empowering developers Yes. To stay in that comfort zone, but also to become proactive.
Yes. Which is critical. 100%.
Agreed. And this is exactly why we also announced this week, uh, in addition to our very rich plugin that we have in the IDE, this A SPM. So we are trying to serve the developers where they are, where they live.
And that's the IDE. Yeah. So many of the components that sometimes were, uh, in the ID and then on our web, uh, check marks one platform mm-hmm.
We are bringing them as close as possible to the developers, to your point, to educate them, to empower them to be security, uh, conscious. And obviously by that prevent security, uh, vulnerabilities from slipping to production. Are you seeing more of an appetite from the developers to embrace this?
Yes. Rather, because it doesn't sound like you're impeding what they know and what they like to do. You are in, like I said earlier, it's, it's empowerment.
Yes. So I met one of our, uh, large financial customer this morning, and, you know, and he's the head of engineering. You can get higher than that.
Yeah. And the head of engineering said it very clear he needs, uh, his developers to have as less noise as possible Yeah. To get the job done.
Yes. And when you empower developers, even though they're not security experts, to be well educated, uh, autonomously remediate things that are kind of happening almost every day. We talked about the scale earlier.
Yeah. Right. So when security is a no brainer, and it's part of the flow in a more easy, convenient way for developers, they will adopt it.
They'll become security champions because they see, okay, it's part of like any other automated testing that has been in the market for many years. So it's another validation that we're doing, and it fits in the cycle. It goes within the, uh, CICD pipeline up until production.
So I think as you get more developers, uh, to understand the value of automated application security, shifting it left, making it convenient as autonomous as possible, yeah. You'll get the adoption. You get, uh, actually even less cybersecurity attacks at the end of the day.
So helping them get ahead of application risk without slowing down development. 'cause that's what they wanna go fast. That's the most important thing.
Yeah. You know, DevOps just came to solve that, right? Yeah.
Quality, velocity value Yeah. To the, to the market, to the business. And this security sometimes interrupts this velocity.
Sure. So when, when you can, uh, And then you get resistance, right? Yes.
Exactly. Do you see check marks as a facilitator of the DevSecOps movement maturing in the next year or two? I, I think that with what we are currently bringing to the market, you know, all the dev experience, uh, enhancements and the agenda ai Yeah.
Uh, vision that we are actually, we announced it also, uh, this week at RSA, uh, I think this is definitely going to put us in front of more and more developer communities. Okay. Uh, because we are innovating, we are solving real issues, real challenges that developers face.
We, we are meeting with them day in and day out. We actually have one of the biggest databases, uh, of malicious packages that we are scanning. Okay.
Uh, so we are here to sell the developers Yeah. Okay. And make their lives much easier.
Yeah. Well, we talked about the empowerment, but what I'm also sensing is you are bringing in customer feedback, which is always critical. Yes.
Customers saying, Hey, check marks, we need this because of these issues. Um, what is that customer feedback loop like? Because it sounds like, and I know at most organizations, they should be Yeah.
Critical to the development of the technologies, especially at, in, in a, in an industry like cybersecurity. So we have, uh, we are truly, uh, believers in the customer engagement. Customer feedback.
Yeah. Okay. We act on all the customer feedback that we are getting.
We run almost on a monthly or bimonthly basis, uh, customer advisory board. Nice. Okay.
Across regions. Across geographies. Because each region, each, by the way, even each vertical financial insurance, retail, telco, you name it.
Right. They have their own requirements from an AppSec perspective. So we are actually doing targeted summits for verticals, for vertical, for customers.
Oh, excellent. And collecting a lot of feedback and acting upon that. The product management, the CPO and everyone else is fully involved, fully engaged.
So we're collecting feedback. This week. We did a few Cs already with a segment of customers, segments of customers, and we collected precious feedback that we're going to implement.
Agent i dev experience, shift left. All these things are actually just going to improve more and, and more as we collect more feedback from customers. And That's, that's just foundational to the business, is that customer feedback.
Yeah. Do you see any, from a vertical perspective, you've got the vertical focus with the cabs. Are they prioritized?
Are they all horizontal in terms of, of prioritization? 'cause I imagine every industry is v every industry is vulnerable. Yep.
Yeah. Nobody's Safe. No one is safe.
And, uh, they're all definitely concerned about security, concern about ai. So you'll see a lot of, uh, common themes, concerns, challenges, yeah. Across these verticals.
A lot of commonalities. Okay. Yeah.
That must help development, product development. Yeah. We have definitely, it helps us focus.
Yes. Right? Yes.
But on the other hand, they have different business needs, right? Sure. Uh, a financial organization will have a different, uh, feature set or different objective, especially when you're dealing with developers, right.
Developers want less noise, and they has, they're seeing more noise in the financial, by the way, FIS financial insurance. Why is that? Uh, they have a lot of exposure of, you know, third party databases.
Okay. Tons of APIs and integrations. So the, the FIS in our mind is the most challenging one.
Okay. And the more demanding one. But, you know, retail, okay.
They have their own exposure, right. Open source libraries and the likes. Right.
So SCA is definitely critical for them. Uh, and at the end of the day, also, the supply chain, the software supply chain, I think we talked about it earlier this week at text on tv, software, supply chain today is by far more advanced and more complex, much more complex than what it used to be. Complex.
Oh, absolutely. So when you're just thinking at about code to cloud within, uh, modern software supply chain, it's, it's crazy. You know, compared to few years ago.
Yeah. Right? You have containers, you have infrastructure code.
Mm-hmm. Uh, you have tons of open source libraries, dependencies, right. Runtime, security.
You need to take care of everything, every line of code throughout this journey. Okay. And by the way, in this journey, you have multiple personas as well.
Absolutely. Yeah. It's not just the developers, it's the developers.
So imagine too, from a business value perspective Yeah. You know, nobody wants to be the next headline. Yeah.
The next and the brand reputation brands can be ruined, right. If they're the next headline. Yep.
So from a business impact perspective, how do you enable the CISOs to uplevel the conversation to their CEO and maybe to their board showing the business impact, maybe it's a better p and l or revenue streams that checkmarks technology actually delivers to that business? That, that's a great question, and CISOs are among our top target, uh, personas, if you like. Yeah.
We actually had, uh, a month ago, uh, a very successful webinar with the CISO of Michael's stores, right? Oh, yeah. Huge retailer, everyone knows Yeah, yeah, yeah.
Knows them. And, uh, what I like about, uh, the CSO of Michael is he said that he's enforcing within his business what he calls the trinity of architects. Okay.
And he is kind of divided that, uh, Trinity, like three Yeah. A into the, uh, developer, architect the solution, and or the security architect and the CSO itself. Okay.
Okay. And when he believes that when every, uh, architect within this trinity engages, kind of is on the same page brought to the table Yes. Earlier in the development cycle.
Okay. They're all aligned. They're all in sync.
And that's why, by the way, that's how they do business. Okay. They make sure that the development architect, the AppSec architect, the chief security architect, they're all bought into the loop very early in the software development life cycle.
That must be. Yep. And they, they're actually seeing a great success when they're implementing that.
So cross team alignment, collaboration, that's what CSO cares about, uh, these days. And definitely getting the right tools, uh, in front of these trinity personas, if you like. Yes.
Uh, is also a very key, uh, to the success That Trinity alignment is so important because it's collaboration. Yes. And being able to have that earlier on in the process probably much takes some of the complexity out, because the roles are clearly defined.
They understand how they're each contributing to software development in the way that they're comfortable. Yeah. In the way that they expect the experience will continue to be, Yeah.
Less noise, more focus on business values per each of these domains or verticals within the company. Uh, and, you know, when you're dealing with a company like Michael's, they're huge. Okay.
They have Oh, yes. Tens and thousands of stores, you know, throughout the US and Canada. Uh, so they have a huge challenge to protect the business.
Okay. Yes. So the, the alignment is a key for them.
It is, it is key. It should be a KPI, it Should be a KPI, I think. I really think so.
Yeah. Gimme your perspectives as we're kind of wrapping up here on the state of cybersecurity. I, I imagine as an expert, you've been to many R ssas over the years.
Yes. Tech Don's been covering it for 10 years, but I know it goes way back to the early two thousands. Yep.
Um, we recently actually on Techon gang, I, I think it was a couple weeks ago, talked about Mitre and the contract that almost expired Yeah. And the CVE program, thankfully, since it came to the rescue. Hmm.
But I know that checkmark supports the need for Mitre. What do you see as the state of the, of the industry in 2025? So, uh, I think this was kind of a, a red flag or, uh, a warning sign for many organizations, and It came up, suddenly, It came aside, and that, that's kind of, uh, when you take a, take a break and reevaluate.
Yeah. Okay. What's your, uh, application security posture, you know, what's your strategy?
Who are you working with, okay. To make sure that okay, if something like that happens, who is who got your back? Okay.
Who is covering you from a malicious package cover, uh, coverage protection, you know, this kind of thing. Secret detection, as I mentioned earlier. Yes.
Uh, API security, container security, all these scanners, all these engine engines, you know, and, uh, yeah, we support MI and, uh, we actually came out with our own article, uh, exactly the same day that, uh, this incident happened. Okay. I'll check Reinsuring, the market and our customers, most importantly, that no matter what, okay.
We have, as I mentioned earlier, the biggest database of packages. We have our own research lab called CX one Zero. Okay.
Okay. For zero day, uh, detection and prevention. So we have our own analysts that are taking care of it.
That's their daily job. Okay. Covering NPMs, uh, on no js, uh, you know, uh, NuGet net packages, Java packages, whatever you name you need.
You know, we are covering that as an independent vendor and solution to our enterprise customer. So, again, if something happens, they're, they have, uh, us to depend on, and we're doing the best we can, And they can have the confidence. We, and I, I, I'm a long time marketer, and I think confidence isn't a marketing fluff term.
It's, it's critical. You need, Especially today with how fast things are moving. And you, we talked about scale in the beginning, that's not gonna slow down.
I, I, I agree. And, you know, confidence, like you have life insurance, right? When, when everything goes, goes nice, everything is fine.
Yeah. Good. When you have like a bad day, that's when you actually understand who got your back, who is who can, you can, uh, who can, uh, you count on.
Yep. And, uh, we believe within check marks that we have the research lab, we have the, uh, engines, we have the technology and the research and the experience, right, to give our customers what they need. Customers can count on you, and you've, you're going right where the developers are and where they want you to meet them.
Thank you so much around for talking about why this matters more than ever really backing things up, securing code at the source, and why it's just an, an essential element these days. We so appreciate your insights and your well your time. And we'll be following check mark, check marks.
Thank you so much for having me. Thank you. Pleasure To have you from my guest.
I'm Lisa Martin. This wraps up day three of RSAC coverage from Text on tv. We've had a blast bringing you great content.
We hope you enjoyed all the content we've created. As I mentioned, everything will be available for the socials next week, so if you want to triple watch things or maybe take some notes, you'll have the opportunity. Thank you again for joining us today on day three.
I'll see you tomorrow morning.