Navigating Cybersecurity Challenges with Paul Davis | RSAC Conference 2025
Transcript
Hey everyone. Welcome back to Text Strong tv. Live day two RSAC in San Francisco at Moscone West.
This is Text Strong's, 10th year of covering RSAC. It is never a dull moment on the show floor. This is day two, as I said, of our coverage having some great, really informative conversations with cybersecurity experts.
And my next guest is one of them. Paul Davis joins me, the field CISO at j Rog. It's great to have you, Paul.
Thank you for coming back to text on tv. Thank you. It's great to be here.
So you've been in cybersecurity for a long time. Yeah. The evolution.
I just mean you have wisdom, the evolution. That's still all as mouth. No, that's a nice, that's a euphemistic way of saying that.
You're going to, I can, I can tell what kind of interview we're gonna have. We're gonna have a lot of Fun. They're gonna have talk about Though the evolution of the risk landscape that you've seen in your time and where we are now.
Um, it's got bigger. Yeah. Um, the, the great thing is that, uh, like technologies are evolving and our innovation's evolving at the faster, faster speed.
Yeah. The world's got smaller and with that, we now need to handle bigger. And the, the problem with security is we have our problem saying no.
So whenever there's a new risk, we add it to our portfolio. So, and a lot of times it's, we are trying to understand new ways of doing things and then work out how to protect people. And so risk is growing and more complex and we have more and more data.
Right. And more apps. Yes.
Yeah. And even more types of people like agents and agent ai. Right.
So that's a whole new identity type. Right. So, you know, we, I talk about we have to protect the people, the property, the business.
Now we've gotta protect another type of people that can create errors called ai VA Agents. Yeah. I just saw on J Frog's website the software supply chain State of the Union 2025.
And some of the stats were 458 new packages brought in by the typical organization per year. 38 new packages a month, over 25,000 secrets detected. And, and also organizations have at least seven plus different security tools.
Many have over 10. Yep. Lots of complexity.
You talked about the volume of data is only growing. There's more software than ever. There's more apps than ever.
There's now ai, which is like a double-edged sword. Talk to me about the state of the union for this. The state of the supply chain of software.
There's some good news in there. Excellent. But there's also bad news.
Yeah, yeah. Like for example, secrets and API keys. Um, this is really, really simple to implement and protect.
You automate it, you scan for secrets and API tokens. And that's the thing we discovered that actually the, we got worse by like 67%. So year in year leaking of secrets got worse.
So how, as an industry, how can we get that so wrong, Right? When we have all these tools out there that can actually detect and warn people as they're coding, Hey, you put a password in, right? Or when did you actually putting the package together?
It can detect it. This is not like rocket science. This is basic steps.
And we got worse. Why? I don't know.
It's like asking why the O wasp top 10 is still the same top. Okay. 10.
Yeah. So you kind of look at that. And then the other aspect of it is, um, the new packages, that number you mentioned is just brand new packages you've never used in your organization.
That doesn't take into account all the new versions of, of open source packages coming in. Right? So that's just brand new things.
But every time a new package comes in, you need to be looking at is it dangerous, has it been compromised, et cetera. So the number's vastly huge. And another bad thing is, is that a lot of organizations are still doing manual reviews Still.
So how can you do that? I mean, you Can't keep up. Yeah.
I pity the security professional has to assess vulnerabilities Monday morning. Here's this giant pile of vulnerabilities. How do I handle it?
Right? Yeah. And how do they prioritize?
Well, uh, Yeah, well, no, really not strategically well, or this volume is so overwhelming. There Are tools and capabilities that it, you prioritize and there's different aspects. You look at the severity, look at where it's being used.
You have your CMDB. Is it a critical asset? Yeah.
Where is it? And it's not just in product, you know, in development where a lot of people just focus on doing development. Yeah.
It's actually what's running in production you need to worry about as well. Absolutely. Yeah.
Absolutely. So security efforts, the developers wanna develop, they wanna go fast. Yes, they wanna do their jobs, but they're spending a lot of time on security.
Where is DevSecOps in its maturity these days? In 2025? I think we understand the principles.
Okay. It's just the execution. And there is a gap between developers and security.
Is it, is it cultural? Yes. Yeah.
It's, and it's also history. Um, it's funny, um, I've always run security organizations as a service to help inside, you know, these, these companies and that helping capability. But all everybody remembers is security saying no, and we're not there.
And ironically, the synergy or the goals of security and developers are the same. The mindset is the same. Interesting.
You take a developer, they're given a problem, they have to find a solution. Yeah. You, you've got a, somebody in ir they're looking to, how's this person getting in and how can I block it?
It's the same mindset. Interesting. That curiosity, we should tap into it and embrace it.
And I think that's a big thing. I, I've always said we should enable developers to be security dweebs, you know, and nerds like us because there's great synergy, but we have to open up the conversation. Yeah.
And there's a gap where security organizations a lot of times still don't understand the world of development. There's a gap between understanding the life cycle, the things, and we just have to start building bridges. Yeah.
So that's, for me, a Big thing. Could, could AI be that bridge? Well, AI is an interesting journey.
Um, I have a terrible joke. Please hear it. Okay.
How do you know if some software has been generated by a gen AI agent? It has lots of emojis in it. Nope.
It's documented. Bad joke. Ah, yeah.
So that's pretty good. Yeah. It's not bad.
Yeah. Yeah. But, but no, the, the gen AI is really good.
If you're not using it for generative, it's really good to help a developer. I use it myself. I'm a big fan for creative inspiration.
Yeah. You know, I, I can program in 12 different languages and try to remember how to write a code in C versus Python is like different. So you kind of run your mindset through that and say, and it gives you an, but you have to have expertise.
So it is an assistant. Yes. It is there to help.
The one thing I think is the gap is we're not using AI for really in depth finding vulnerabilities or issues with your code. Is that in the roadmap? Is that in the pipeline?
Well, I think I'm seeing, I'm seeing a lot of it out there where people are starting it, but we could also automate it. Yes. And and ironically that's not gen ai, that's just ml, which is subtly different When you're out in the field talking, presumably with other CISOs Yes.
Security teams. Yeah. How has, is that role evolving?
Because the landscape is just getting more bigger and bigger, more amorphous AI brings a lot of great potential Yeah. But also opens the door for a lot of vulnerabilities and risks. Yes.
How has your conversations with CISOs over the last few years, especially since chat GPT was born changed? Well, the, the, the first thing is, is that a lot of people don't understand where AI is being used inside their environment. That's what I'm hearing.
There's a lot of blindness. Yes. And for security people, we like visibility.
Yes. We don't like dark corners. We hate those.
Yeah. That's what keeps us awake at night. Dark corners is, is, and so a lot of the organizations are still learning about gen, you know, the AI lifecycle, ml SecOps, as we call it.
Right? Okay. And ML SecOps has a similar path to DevSecOps.
Okay. But they do experiments. You said to, if you say to a security person, Hey, they're experimenting and it's gonna put these experiments in production, you kind of freak out.
But if you don't understand that mentality, also the attack vectors in production are different. You know, when we build a piece of software, put a piece of software out there, it runs, and then maybe it's a bug or a feature request. That's what cause a change with ai.
It could be that it gets poisoned. It could be that models could be stolen. They could, um, the data goes out of date.
So there's a different life cycle and we have to monitor. So from the point of view of CISOs, a lot of 'em are saying, yes, I know I need to do it. Um, a lot of them are trying to do it manually.
We have discovered what I call weaponized LLMs not malicious. So they, they've actually turned and just the act of down loading an LLM could in attack a workstation. Right.
Right. So I think there's a new attack vectors and more data and also a new group of people, data scientists who are coding that we need to embrace as a security community and enable and help them support them. You know, What, what differentiates jfr here?
How are you enabling organizations to reduce the impact of security efforts? Because you're talking about, you know, the evolution of the CISOs Yes. Sometime and, and the, the the need and the demand from that role for visibility.
Yes. How's JFO coming in there and saying, we gotcha. Well, it's not just CISOs, the CIOs, the CTOs.
Yeah. The business owners. They're all looking for simplification.
Right. A lot of times we've done this sort of knee jerk reaction where we're looking for point solutions. And the platform, which is what J oog kind of plays in, is we are going from the far left of design all the way into production.
Mm-hmm. We are providing a framework to hang your tools around so you have a consistent easier path. You're starting to simplify.
We're starting to reduce number of tools, because I was gonna ask about that. Yeah. We, We don't have, not all the companies are using all the features.
Sure. They're not using the data. I mean, they're generating SBOs all over the place, but they don't know why.
Right. So, you know, we help them with that sort of strategy about how to streamline and simplify, makes it easier for compliance, reporting, regulatory compliance, risk, attack, surface. All those areas can be simplified.
I mean, it's not like we're trying to be the be all end all, but we can provide the framework for you to build a simpler, easier life for everybody. Not just devs, security proficient, uh, professionals, the operations people. Mm-hmm.
All those people. We can make life easier Lines of business. Yes.
Yes. Yes. I, I was just talking about sales and marketing data being compromised.
For example, what if a company's sales and marketing data, there's so much rich customer data in there. What if it's, it's, it's hacked and companies probably don't care unless they can't get access to it. Yes.
The access. Yes. That is the I'm paralyzed.
Yes. Have to have access to my customer data Yeah. To be able to still transact business.
Yes. Talk a little bit about contextualized security. Right.
What does that mean, and how are you enabling that? So a big thing is, is there, there are lots of tools. It's almost like we are beating our chest and say, we've found these many vulnerabilities.
We've found this many secrets. Yeah. Yeah.
The problem with that is that you need quality. Absolutely. And quality data means actually, is it rarely applicable to my world?
Am I actually, I have a saying, which is when bad function doesn't make a bad software package. Okay. If they're not calling the bad function, you're okay.
Yes. It's nostalgic. So you need to have tools there that start saying, yes, you're using the bad function.
You need to reassess. And it might be, um, as I put it, you don't necessarily need to upgrade the package. You just need to use a different call that might be safer or better.
Okay. Okay. Right?
Yeah. And so jfr has tools which allows you to reduce that noise by that 80%. And that 80% noise is a reduction in noise for the developers, the AppSec, the security operations, because it's less noise.
By having that contextual perspective and having, yeah, I'm actually using the bad function. I should stop doing this. Yeah.
Or no, everything just roll. It's a ripple effect. So by providing that contextual analysis and saying, okay, actually yeah, you're okay.
You don't need to worry about this. Or you have to publish an sbo and somebody says, you go through this, uh, with a product security team. Oh, we scanned it.
It says about, well, no, actually we've done the assessment. Here's the report of sbo. It says it's not applicable.
All a sudden life gets faster, easier deals get done faster. So you're, you're providing that visibility. Yes.
Essentially. Well, for that simplification, that visibility, that security teams, developers, lines of business, just have to have these days. And a lot of things is like, so for developers, developers say it's a bad function and go, great.
We have the context analysis to say on this line, you are using this command and change it. So we're actually pointing them there, and then we are showing them the actual data of why it's bad. So we're educating them.
Light bulb goes off. Yeah. I like to turn programmers into hackers.
Sorry, Ethical hackers. Ethical hackers. Ethical hackers.
Got it. Last question for you, Paul. Favorite jfr customer story or field story that you have that really shines the light on the value that jfr is delivering across organizations that simplification, that visibility.
Favorite story. So, um, I, I, I like working with customers to help create a story which they can communicate at all levels of the organization. Absolutely.
So showing them the vision of what, how their whole pipeline looks. Mm-hmm. How they've got consistency, the KPIs, the measurement, and they, they understand all of a sudden this is, uh, an ecosystem that needs to be exposed to everybody and everybody needs to understand how to software supply chain works and what the responsibilities are.
And so I, I like it when they say, yeah, actually this is great. Jfr can help us with our whole life cycle, with all our tools and actually help us get faster, better, and, you know, and get a grip of, we've done studies where we can reduce the tech debt Oh, wow. And make it manageable.
I mean, I've never come a customer, a company where they, you know, oh, I've finished all, you know, I've got some customers saying they're like 10%, but they're their exceptions. Sure. But most people, the battle between feature and bug fix every time you do a sprint, It's just that it's a battle.
Yeah. Exactly. Last question.
I lied one more. What excites you about the state of the cybersecurity industry in 2025? Anything like positive look in your crystal ball rays of rays of sunshine.
Um, I like the potential of ai. Yeah. And I like the fact that it's always evolving.
The reason I'm in security is I don't want to be bored if I'm bored. It's a dangerous world. And there are always new challenges.
Yeah. And I love the fact that we can help protect the world. Yeah.
That, for me is a big thing. That's Awesome. I'm sure never a dull moment in your role.
Paul, thank you so much for It's a pleasure, truly for talking to me today on Texturing to be coming back to our program, really sharing how you're really delivering contextualized security and, and enabling things in a complex world to become more simplified and more visible. We appreciate your insights. Thank You so much.
Being truly a pleasure. It was A great pleasure. Thank you.
Thank you. Thank you. For Paul Davis, I'm Lisa Martin.
You are watching Techstrong tv. Live day two RSAC. Stick around.
Our next guest joins us in just a minute.