Enhancing Application Security | RSAC Virtual 2025
Naomi Buckwalter from Contrast Security discusses the critical role of application security in production. The conversation covers challenges faced in the field and the need for improved insights. It highlights how AppSec can enhance the developer experience and offers proactive security measures. Contrast Security’s tools are presented as effective solutions for blocking attacks and helping developers address vulnerabilities, concluding with a focus on improving overall application security.
Transcript
Welcome back to Text on tv. I'm Lisa Martin, live from RSAC at Moscone West in San Francisco. We're gonna be talking all things security all the way through Thursday.
Some great content we've already filmed. Hopefully you've been watching more great content coming your way. My next guest is Naomi Buckwalter.
She's the senior director of product Security at Contrast Security. Naomi, it's great to have you on Textron. Hi.
It's good to Be here. Thank you for joining me. I'm so excited.
How are you today? I'm excellent. Awesome.
My feet don't hurt yet. That's day one. That's Why I'm wearing heels and I hope that is true.
True for the rest of it. I'm Me Too. Fantastic.
That's one thing about conferences. You can guarantee a ton of stop and sore feet And no lines in the women's room. That's true.
Yeah, that is true. That's, that's one plus for us girls. So I love the tagline that contrast security, you can't stop what you can't see.
Tell the audience a little bit about contrast security. What is it that you guys are solving for customers? Oh, interesting.
Well, if I could give you an elevator pitch. Yes. We do application security in production.
That's the easiest way I can explain it. I love that. Right.
It's, it's so easy to understand. Yeah. Well, if you think about it, we have other things in security production, things like we have our CrowdStrike that's running in production boxes.
Right? Okay. Like we have different agents that run in production.
If you think about the vendor space, there's not a ton of application security happening in production, in runtime. A lot of it's before the runtime happens. So you've got your static scans, your SCAs, all the scans that happen in QA and Dev and all the things that aren't actually production.
Yeah. And you have to wonder why it's, it's kind of weird. It's Weird.
Yeah. Well, you were saying, you know that doing AppSec in production isn't crazy. It's It's smart.
It's so smart. Why aren't more folks Wait, did you say That or did I say that? I got that from, oh, okay.
You So Smart. You're smart. Actually, it is smart because, but why aren't folks doing, because it's where behavior happens.
It's where the users are. It's where the attacks are. Why aren't we doing more security where the bad stuff is happening?
Right. Why do we assume we're testing for all the cases prior to releasing the thing in production? Yeah.
Well, I can tell you why. I know it's smart. We just said it.
You said it. But I think it's because people are scared of doing AppSec in production. I think just tech, in the past we've had downtime is an issue.
Your company is like, no, we need to have this uptime. 999, whatever. Right.
To five nine. Thank you. And I think it's put us back a lot.
A lot. So if you think about some of the bigger breaches in the past, it really comes down to you probably just had this old server running with an unpatched thing for the longest time. Yeah.
And you were afraid of taking it offline off production. Right. Just to fix it and then put it back up.
Yeah. Because your business is like, no, we need all the uptime. We need all the revenue.
And it, and it becomes this problem because you don't have the protections that you actually need in production. Yeah. Well, it's a double-edged sword and it's, it's like nobody wants to be the next headline for a breach.
So it makes sense. Right. I know.
I mean, the brand reputation, right. The children that happens. Nobody wants to be that.
I mean, and these in this day and age security attacks aren't, is it gonna happen to us? It's when, oh, it's happening now. It how often it's happening.
Now's what is the cost that's gonna cost my business? Right. Right.
So that alone you think would, would make enough sense for them to put apps like in production Production. But I didn't even get to the biggest part. It's because we don't have the insight that we need in production in our applications.
We are really good as an industry of getting our network traffic understood. All the things that are happening on our hosts. Understood.
We know all the things that are going on because we have observation, we have sensors in those areas. Yeah. What we don't have are those same sensors happening in our applications at Runtime in production.
And now we're trying to say as a company, I think it's time. It's okay to do AppSec in production. It's okay guys.
Like I almost feel like here at RSA would be our, like our unveiling. Yeah. Is that an, is that a word?
Yeah. Or unveiling. Like our unboxing for YouTubers.
Yeah. Yeah. So it would be our way of saying to the community, like, it's time shift left probably has failed.
Yeah. Well, how much of what you're doing at contrast is really education and making these folks aware that it's about, it's time. And this is why that old playbook has to be thrown out because nobody wants to the next Headline.
Absolutely. And and it's, it's a little like pulling teeth. If we had like an interpretive dance, maybe people would probably understand it more because it's sometimes they're like, what are you talking about?
I had a dinner yesterday with somebody at a different company, someone who does static scanning, and it's like when I told him we should do AppSec in production, it's like, I stabbed his child. Like his reaction to that was just like, you could just tell his face. I was like, I'm sorry.
Do I need to apologize right now? Yeah. Like he was just so insulted the fact that I even said that because it's so ingrained.
It's cultural in us. Right. So It's behavioral.
Exactly. And that's And why Hard to change. Why, but why.
You're right. Our critical thinking turns off whenever we are thrown another framework or another way of doing something. Oh, and everyone does it this way.
Think of the thousands of other people here. So I'm gonna follow that line that Just Absolutely. It's a bias that is not well understood by me, just because I could see the issues.
And most of us in AppSec actually do, and here's another problem is security. People traditionally don't have the best grasp of applications anyway. Okay.
So what they do is, or what we do is we kind of just say, Hey, we're gonna let the developers take care of it. We're gonna do our scans, we're gonna give them the issues, and then they're just gonna magically fix it. That's not what the developers wanna do.
Trust me. They wanna build stuff fast. Yes.
They wanna make money. They wanna go home and build cool s**t. At the end of the day, I am sorry.
They build cool s**t. Yep. And then call it day.
They see security people and they always have as a gate. Yeah. A gate As a detractor to what they're trying to do as a No, you can't do Exactly.
Yeah. So what we are now saying is maybe that approach has failed us because think of all the issues that are still having, oh, top 10 hasn't changed in like two decades. Right.
How embarrassing. For us, now we're saying application security can be done without the developers. We don't need them anymore.
Okay. Yeah. And I know that sounds really like who heck are you Karen?
Yeah, yeah, yeah. But we haven't given this a shot enough to say that. Maybe it won't work.
Maybe it will. Yeah. Why not?
Right? So you're in effect enabling the optimal developer experience. 'cause you're pulling this out of their, that's another way of hands.
And the AppSec folks Yes. Can take the responsibility on in production. Amazing.
Do you have a newsletter? I wanna sign up for I podcast. Yes you do.
Yeah. So, so where are you talking? Who are you selling to?
Is it the developers, is it the security folks? Is it both? Is it the application owners?
Oh my gosh. Well, everyone and anyone who will write a check. But I will say we are targeting a new audience and it's our SOC people, our security operations folks.
Okay. Yeah. So what we're trying to sell them is more insight into the applications that are on their networks.
Like all the applications and hosts that are on the machines that you care about. Run processes and things and accept traffic and do stuff with that traffic in your host that you should really know about. Right.
So we're giving them observations, more data, more insight into their application layer, into their APIs that they don't already have. Right. And I think our soc, what we're hearing from the fields is that, wow, this is great.
Like before it was just another network packet. Like, I don't know what this is doing now. It's wow.
It's not only do I know where this packet is going, what route is hitting, what that route is doing, what it's executing in the host, or what data point it's hitting on the backend. Right. Like now that we have all that insight, we can do something about it.
If it's an application attack, we can block it. Because Contrast does that really well. Yeah.
If it's a vulnerability that is out there, maybe we could tell the developers how to fix it. And we do that too. Not only do we block the The attack, we can tell you where the vulnerability is.
We can patch it. Right. Like we have ai, how to fix, like we have all these cool tools that can just tell you how to fix it.
Yeah. It's really cool. Well That, that application detection and response technologies, observability mm-hmm.
Are game changing for organizations. Yes. It's like the tagline that I like, you can't stop what you can't see.
You need to, they need to have that visibility. Yeah, absolutely. But also in a sense, getting outta the way of the developers, letting them have the optimal developer experience that they want.
Yes. That they expect. Yes.
But providing that visibility so the blinders are off. Absolutely. And you're letting them do their job better.
And you're doing your job better too. As security people. Yeah.
Security people can do application security. I know it's sometimes hard because we have to keep up with your technology. Yeah.
But once we do, we can show them we're on the same team. Right. And then now you're building relationships.
Now you're building culture on your teams. And trust. And trust.
And that is a hundred percent Yeah. What you need when you're working with developers. Like Yep.
I had conversations, we were like, why are we doing it with you guys? We can ruin your life if we want to. Like that is an adversarial relationship.
Wow. Right. This is not a person that I worked with, but yeah.
I was just talking to, they're like, we can ruin security people's lives if we want to. Like why are they sending us? Right.
Wow. Power. Right?
Mm. Wow. What's your favorite customer story of contrast that you said you think this just perfectly shines a spotlight on what we do well and why we're doing it?
Well It's funny 'cause I'm a security practitioner. I'm my favorite customer. I actually use contrast every single day.
Awesome. Drinking Your own Champagne. I wouldn't thank you.
Oh, not the dog food thing. No. Champagne.
I like the champagne. I elevated it. Thank you.
It's so much better. Well, so I'm a secure, I'm a security practitioner. I would not be working for a security vendor if I did not deeply believe in our products.
Yeah. I am not even saying that lightly. Like I understand how cringe it is to be here.
I'm sorry. RSAI love you. But it is cringe.
And I will say it's just like LinkedIn. It's like why are you so cringe? Why do you have to do this cringe.
It's security vendors doing too much and it's not actually helping do security. So me as a security practitioner really appreciates a tool like contrast. 'cause it makes my job so much easier.
I don't have to do a scan and be like, here's 500, um, 500 vulnerabilities that the static and I haven't even validated each one. Good luck with that. Developers.
Like I can give our developers actual vulnerabilities, actual vulnerable routes, things that have been exercised in our applications, which means endpoints that have been hit. Yeah. In production because we know this is a route that has been used and here's a vulnerability, here's an attack that happened and then we could do something about it immediately.
I don't have to wait for the patch. Right. I can do something in our tool.
Contrast can be like, okay, we're gonna block this for now and then gives us some time to patch on the developer side. Yeah. And think about Log for Shell.
It was the same way. Yeah. We blocked log for Shell out of the box before anyone even knew Log for Shell was a thing.
Wow. And now it buys the developer's time. Right?
Because you're like, yeah, you're using old versions of Log for J that are vulnerable to log for. Shell go ahead and fix this thing. Right.
And by the way, we have contrast on the other side acting as that last gate. Yeah. Thank God we have them.
You know, You should be a developer's. BFF. I already Am Lisa, I dunno what you're talking About.
Of course. You're Naomi, it's been such a pleasure having you on text, on tv. Thank you for really explaining what you guys are doing so well.
Why apps suck in production is smart. We appreciate your insights and your candor as well. Appreciate that.
For Naomi Buckwalter, I'm Lisa Martin. You're watching Text on TV live from RSAC. We'll join you again after a lunch break with our next guest.
So stick around.