The March to Continuous – Techstrong Research Review EP 1
In this inaugural Techstrong Research Review, Mike Rothman and Mitch Ashley highlight the march to Continuous Everything, discussing the maturing of digital workflow platforms like ServiceNow (Tokyo release), applying SBOMs in the enterprise and the recent “Do This, Not That – AppSec/API Security Edition” and “3 Keys to Continuous API Security” talks that took place during the https://www.techstrongevents.com/appsec-api-security-2022 conference. Get free analyst research reports, videos and studies at https://TechstrongResearch.com.
Transcript
here Hi everybody. Welcome to the inaugural show of the text wrong research review. So, you know and mention I we were so first.
I'm Mike Rothman. I guess I should introduce myself. I just kind of assumed that everybody knows her and which is always that assumption.
I'm joined by my partner in crime Mitch Ashley Mitch. How are you doing is really well, which actually principle with texturing research CTO Tech front group. So yes, and I am long term partner friend whatever.
Okay GM of Techron research teacher jobs. Yes, that's all that's our qualifications. That's why you're here out of here.
But you know, what we wanted to do is really kind of highlight and have a forum permission I and you know kind of analyst, you know CB and or cd&e as they as they join as we grow the team I really kind of a forum to kind of discuss what's on our mind, right? What are the things that we're seeing? What are the topics not newsy, right, you know not from the stand pointers in hey, did you see that that happened on Wednesday, right?
Because we want these to be a little bit more. Tent May or you know, kind of concept based as opposed to you know, news-driven so welcome, right? This is Tech strong research review and what we're gonna review today Mitch.
I think you wanted to talk a little bit about a new release or a new initiative from from service now about I do I do the they just launched within the last few days here of us talking about it. They're Tokyo release. It's kind of their big annual at least that service now and of course servicenow is really much more than what they were three years ago, right?
They record a lot of companies have gotten into ability and a number of things and security as well. I mean, they made a number of investments in terms of you know, trying to help and facilitate into the response and a number of those things that again I think Get Back To Work Management, right? How do I manage the work of the it group?
Exactly and and you know, it's interesting because I was I did an interview with their Chief Innovation officer. I'm gonna name drop. But anyway I said dream, you know, I see your commercials on TV.
And the in the person will say yeah, I did xx y&z and I and I'm not a coder, you know, so it's it's an end user citizen developer kind of, you know tools for low code no code sort of applications for tools to build process workflow, but it's interesting in this release and talking with them about why they're doing what they're doing. It's kind of this. Okay.
Now we're over the the curb we're over the transom from covid right and having to rush and put things in place and make it digital where we can and really let's step back and say there's certain things that we need to add to this like we need leaders ability to kind of manage the work of what people are doing with service now platform with those things with the things they've automated are some Asset Management some things even around governance compliance and social Like which I thought was an industry. So in a way it was I don't know if I'd say it's a total maturation of the platform going to the next level. But I think it's a maturation of our digital transformation the next phase.
Yeah a sign of where you know, all of us are going and in this digital transformation, I think that's right and you start to kind of get into this whole digital experience concept and it really is, you know, kind of broadening towards much more of a business-centric view of the application of technology. And and yeah, I think that's a healthy Evolution, right, you know for a long time, we build out the infrastructure and we're really transition the infrastructure especially as we platform around Cloud, right that was about, you know, kind of technology or evolving technology for technology sake right more flexibility more agility, depending on how you do it possibly, you know better cost efficiency certainly better security if you can do it Equally and that's a big if right if you can do it correctly on that front, but now we're really kind of starting to talk and couch and position a lot of these efforts within the context of improving the business, right? That's what digital cxos all about.
So, you know pooping another one of our our properties. I'm actually doing a call with our friend Mr. Bizarre today what to talk about some digital cxo type topics on that phone.
But again, I mean, I think it's a logical Evolution and you when you're gonna see a lot of the companies that want to be the platform for digital transformation really is starting a position around these much broader Concepts not just hey make your technology more efficient a make, you know, kind of your environment more virtualized or easy or more agile use, it's really how can you impact business and it's a totally different discussion, right and and from a customer standpoint, you know again, you're you're Changing different people you're engaging different levels within the organization. It's really a collaborative thing with business moving forward which as I would say, right, you know kind of is something that's that's healthy as well as important as we continue to evolve. No, no better time like the present.
I remember doing an analyst call. I was probably a year ago with that atlassian and I've used the lasting tool since like Confluence zeroed out one, you know back in early 2000s, but you know, they've completely repositioned themselves and jira and things like that as a workflow management platform not a ticketing system and you can kind of say that a little bit about service now. I think that's what it's interesting as you as you and are talking about research.
We're dealing with stuff that it's you know more on the Leading Edge and newer and we're probably talk about a bit of about API security kind of a newer topic. It's not a mature Market but it seems our conversations might have led to we're going from let's do these things these you know, let's get to the Cloud. Let's make things Cloud native or not or whatever we're doing too.
Now. The conversation is get real. It's time to get this done, you know, economy's doing whatever we gotta Focus, you know, profitability Revenue all that stuff.
It's sort of the you know, tough Tough times tougher economies have a tendency to get your little focused on a few and sharpen, you know kind of but I kind of have to sharpen your your perspective on everything and and not to pre you know, kind of announce anything so to speak but that may actually be one of the main topics that we're gonna talk about at predict in January, right? And and because that that's such an important, you know and critical aspect of where we are right? We've had such Technology Innovation over the past five years really and and obviously, you know kind of the pandemic Force us to put a lot of this remote work and cloud platforming and SAS right to work because we didn't have an option to go back into the office for way too long.
All right, but now where we are as we got all this Innovation, we've got all this technology around we've got to integrated right? We've got to use it we've got Quiet to our business problems and and really predict is going to be focused entirely on that which is how do we use all these new toys that we have again? It's one of these things we every so often you get to a point where it's like I don't need new toys, right?
I need to figure out how to use the toys. I already have and we have lots of toys even though everybody's always, you know, kind of moving on to the next thing in the industry wants to push us forward, right? That's the Machinery of the technology industry that you know, can't drive evaluations and BC investment and Innovation all that kind of stuff.
But the reality is when you talk to a bunch of customers, it's not hey, I don't have the tools to do this. It's I have not, you know, really integrated those into my processes and that's what I have to focus 2023 on and again, that's kind of why predict is gonna Focus specifically on those topics. Yeah.
It's about results from those Investments right? Maybe I still need to spend more but or on other things but it's about results right next. Let's let's switch takes a little bit and because one of the things I have to do, so we're you know, we're helping out and promoting our friends that what's that one called the cloud Beast conference.
Oh the devops world. Yes devops world if I everybody go to devops world, it'll probably be ongoing when when Eat this but go to devops for about you know, one of the things I'm gonna be writing about is, you know, kind of the impact that you know, kind of the software bill of materials has on a lot of what we do and the reality is for those companies that have been worried about software composition analysis and understanding that they're assembling their applications now as opposed to you know, writing them out of whole cloth and really leveraging open source libraries as well as commercial past services and the like so there's just a lot of moving pieces in these applications that we're delivering a customers now and companies have always had the option to do things like software composition analysis to understand where the vulnerabilities are in their environment, but that was for internal use right that was to you know, keep your own shorts clean on that front. What I really think is is important about us bomb and you know some of the the state or protocols it's formats that are being rolled out by folks like the Linux foundation and see ncf.
Is that now we have a language so that we can start to communicate intra enter or inter Enterprise or inter Enterprise to give us again an understanding about what you're using in your environment as I'm pulling that into my stuff or as a customer what libraries and what components are being used in these technologies that I'm using and possibly housing my critical data. And so again, I mean, I think that this is a great Evolution for where we are. I think you know kind of we have to start factoring some of these analyzes into third party risk.
And again anyway, it's fine. We're mention that we have a big customer deal that we're working on right now. We have to you know, fill out their question air about our security practices and stuff.
But you know again that that's a microcosm of the macro situation which is third party risk is something that we all have to, you know, really focus on and that's bomb is is just another tool that will start. To be able to leverage to be able to better assess the platforms that are holding our strategic data and I feel like we're at the very beginning of this process, right? Of course, you know identify what you have is course what an s-bomb is all about and it'll evolve from that links Foundation has both a project for that and training and tools and great some great stuff.
There's also another project they spun up about using blockchain to use that authenticator is this real stuff you're adding to your your software Bill and mature blockchain. Whoo. All right drink, it wasn't early in the morning Wednesday, you know, lots of money at it, right because it's kinda is gonna be big trust me.
But as I'm on this kick of nothing matters unless it's automated nothing can be manual because nothing is static. So an s bomb had the creation of that the management of it has to be continue. It has to be continuous just like security does through the software process just like it does it has in our Network right?
It has had to be Continuous and in software supply chain is just as Dynamic if not more than anything else. So I think I think esphons are a great place to start not pooping that at all that you got to start there. And I think there's some great tools to do that, but We're in the midst of rethinking about how we I mean, can you imagine I'm going to send you my entire list of every piece of software in my software just for you to use my service people don't want to disclose that there's a lot of issues we would have yet to face about this whole going into third party to certify it.
Like we do vulnerability, you know, the lots of things a lot of places to go yet which means a lot of innovation a lot of services and products as well as process things you bet but you know, I I want to end and when we you know, kind of start to, you know, growing and evolve text from research, it really is focused on the user or the Enterprise application of these Technologies. And again, I've got a problem right? My problem is that I'm asking a number of these vendor your suppliers that I use to self assess or self-disclose what it is they do through these questionnaire environments and it's it's almost impossible to really validate that without going on.
Way to do it in again. You can't do that in a leveraged way. So, you know s bomb and and kind of the ability to really understand what's under the covers of these, you know software capabilities.
I think that's an important step to continue to evolve our third party risk practices. And as you just pointed out right certainly not going to be perfect. We certainly have disclosure issues.
We've got, you know kind of proprietary. Impact that we have to worry about right, you know customers may not want or suppliers may not want to you know, tell everybody. Hey, this is some of our secret sauce right and then we're not gonna tell you exactly what that looks like or how we've integrated these things together, you know, so yeah, there's a lot of stuff to continue to work out but again from from the user point of view it is certainly a major positive to be able to understand what's going on in these environments just to get a sense of again law 4J, right, you know, you're trusting the fact that you're provider says, I don't have this as an issue.
Right and I know of companies that have said, you know, their first statement was I know this is not an issue until it was an issue because they didn't even know where it was it they had a bunch of liars that we're using it, you know kind of in this extended change. So so it is it is one of those things again building block, right? But I think it important building block towards really getting a better.
Of the technologies that is really touching our critical data and that's what it's all about. Well, I just want to highlight something. You said also just about us.
I know you're you and I are on same page about this and in our work. Yes, we're gonna pontificate about some things but it's really trying to be as practical as we can about how you apply this. How do you solve real problems?
Because there are folks are really good at pontificating but I don't think you're gonna see any murky quadrants or wacky ways from us right that there's folks that already do that extremely well hundred percent. They have their role in that and not interested by funny words for it. Our general counsel is busy enough, right?
But I mean, we don't have one so, you know, not not interested in having to feel that don't write us we don't or any of that kind of stuff. So yeah, that's not really the focus again, very similar to a lot of the work that I was doing. It's securoses, right?
It's it's Enterprise Centric, you know, and and we are going to write and and a lot of the Church that we do is in that voice right not about, you know, bumping or pimping out a specific technology or anything like that. It's really about helping Enterprises to solve their specific technology challenges as these things come together, right and and that's one of the things that's so exciting to me. So not just this, you know, kind of hey, we can think about how s bomb contributes to you know, kind of the security or Integrity of a company software infrastructure.
Yeah, right, but we're sitting in the middle of devops right in Cloud native Evolution and infrastructure Evolution and the security impacts of that all kind of underneath, you know, this whole digital transformation umbrella. It's an incredibly exciting, you know place to be and again, that's kind of why I continue to be just so jazzed about what it is that we're doing a text from research to be able to you know, really kind of take a very critical look at you know, what are some of the success factors and what are some of the challenges of pit? House that organizations are going to run into you know as they embark on a number of these, you know, major transformation processes and projects that really involve all of the areas that we cover.
Exactly. Well, you know speaking areas of recovery both you and I have been doing work in absec and API security we had the tech strong abstract API security conference that was you know in September which is still available for someone go check it out. Both of you had talks but for you to recap I'll do a little bit to on your talk from that conference.
Yes, so I did a talk. It was called do this. Not that great.
Yeah, then that our friend folks that are nutrition, you know kind of wants. There's a you know, it's a mass Market, you know, kind of book initiative like this not that right just obvious stuff like, you know, don't eat, you know kind of crap, you know, just even things like ketchup right catch up as a ton of sugar in it. So you really worried about that kind of stuff, you know don't have regular Tomatoes, you know not catch right?
I'll catch a taste yummy so not about to go and judge and say don't don't eat ketchup. I love ketchup more than anything else is probably the first but ketchup is pretty close right after that. So on this whole, you know do this, you know, not that for API security stuff you really I kind of hit on a number of different things, right, you know first is visibility, right?
You have to understand where your API attack services and that means again not just, you know, kind of evaluating each of the applications, but also doing some passive monitoring on the network. To ensure that you can see what API traffic is there and ensure that you're not missing stuff from systems that you just don't know about right? There's a detection aspect of that which is to really, you know, get understand what's in those apis.
What are the contracts say are the traffic or is the traffic that's you know going at these apis is that adhering to what you would expect from the contract or folks trying to do some malicious activity on that front, right, you know kind of looking and analyze things out of band. Yeah, yes. We all want to do everything that we can at the front end and your API Gateway in terms of how you're managing it.
But again, the fact is you're gonna have areas especially for application traffic that is internal to the organization. It may not go through your API Gateway. You may not see all that stuff.
So again, you want to be doing some passive monitoring you want to be doing some you know analytics whether it's traditional ndr stuff, whether it's you know, kind of a purpose-built API security, you know, kind of monitoring environment you want to do do that. And and finally the last point that I made which is, you know, kind of I think in a lot of cases the most important, um, it's about collaboration with developers, right? It's not about doing a scan and and and saying this is broken or this api's to you know, kind of permissive or it doesn't have the right, you know kind of permissions on it.
It's about how do we solve this problem? If you just dump a report on the developers that say You know, this is broken and you gotta you know, kind of fix all this stuff without the context. They're they're gonna puke on it, right?
They're gonna ignore it. They're gonna you know, deprioritize it in the next Sprint and you're not going to achieve your goals so that collaboration thing I think, you know kind of outweighs everything but there are some technical stuff. We have to really improve in order to continue to bolster our capabilities along the API security line.
Yeah, I mean you can see right in all the things you talked about sort of the Practical conversations. You've had with folks about exactly exactly those issues. By the way.
I'm glad you named your show do this. Don't do that. You don't that right or whatever versus the shows they have on TV.
They're about eating the biggest hamburger in the world. That's catch up on it as possible. That's like some weird, you know kind of, you know diet or you know, kind of food from these places like oh my God, they could eat that.
Yeah. Yes. Well kind of on that being, you know, I've been doing a lot of focus around API security apps security over the past really 12 months and focusing more on API security and there's a lot of there's a lot of good studies some vendors have done of course analysts have done good technology and folks are coming out with you know, here's the catalog of you know, where you where you identify what your apis are, you know for authentication authorization kind of basic principles.
We talk about it and security all the time, you know web application firewalls and gateways Now API Gateway, so it's a lot of elements to this and I think important to look at my talk that I did was more about well, let's step back and you can go buy all that stuff and really imp And them in a terrible way that you're not going to get much out of I think or you could do it in a way. I think it's really going to set you up for sex success. And the three I talked about three keys to API security continuous API security continuous being the point and the first is as Network professionals.
Maybe we've done this. I don't think we have yet, but we have to stop thinking about what we're securing is. Identities of people and things and objects like devices or a software device or something like that.
That's kind of the Heritage you and I come from right? You know, we're trying to protect just Network the server this whatever and we're we're about is everything is software and everything is in some form of software and maybe spread out across multiple places interconnected Services Etc, which is a we're apis come in so stop start thinking about protecting things and start thinking about how you think the world is holiest software the second key was around. If it's not automated as I said before you as soon as you hit the save button, like any any project plan, as soon as you get to save button is out of date, right?
It's wrong already same thing in our world because software development software deployment the environment the infrastructure's code. All that stuff is continuously under change. And of course, we know SAS services or things like that are way out of our control.
We don't know what changes are happening happening to that and the third Point. Well, let's go watch it. But kind of a hint to it was it has to be about continual change.
That expect nothing to be in the state that you thought it was in right and last time you looked at the log an hour ago. This is what it was. Well five serverless apps spun up and we're gone and caused that thing you think was the security problem somewhere else and so that if you think about that and how that flows into the software development process.
In a devops world right where it's highly automated. That's how you can think about, you know, not just your deployment environment. But also how you build insecurity to it.
So it's a it's a I think it's an extremely intriguing topic to me because API first approaches where everything is the whole app is the API right? Maybe maybe it doesn't have any GUI at all, right use your experiences, you know through a rest call. So it that world is transforming already transformed and I think a Security Professionals have to work with their software colleagues to help them understand how to rethink that yeah, and you know, so that that's exactly right Mitch.
I mean I think and and one of the things I want to highlight and as we kind of wrap up right our first textural research review show, he's really, you know, I think the word of the day right is continuous, right? So whether we were thinking about, you know, kind of the whole workflow aspect of you know, kind of the the new service now platform and really how work is is really in these platforms that help manage at least the it work and and growing into other areas right obviously with us bomb, you know, you have a continuous change and dynamic environment and and you know again just taking a look at it once when you do when you're third party risk, you know not gonna be helpful me and everything is changing on that front and API. It's right, you know kind of applications are changing always so we're entering To you know, really a continuous type of mentality and and environment and we really have to you know, kind of succinctly think about how that is going to really impact everything that we do right everything that we do and and I think that's an interesting concept that we need to continue to, you know, kind of pull on threads we need to pull on as we both do the review as well.
As a lot of our other research is that continuous in the continuous nature of a lot of these Technologies is you know, it's really an impact everything that we do. Spot on well, it's been a pleasure doing our first one if we're going to have a word of the day for all of our episodes. Maybe we have the Groucho Mark stuck in from the ceiling for those of you to remember that that's right.
But but you know, the problem is that would mean we would have to think about that before we actually have to plan it. Oh, I see which I think the wrap up, you know, one of us will wrap up and decide what the you know theme or the word of the day is as we've done it because and that's the goal right is that this is you know, an informal type of review of the stuff that we're thinking about it bouncing some ideas around so giving you folks out there, you know, all of our our you know, kind of listeners and and Watchers on that front of you into our research process, right and that's how it happens. Right?
You know, we just we think about stuff we pull on threads we discuss them. We debate them and you're going to be able to get a view into that so welcome to the review glad you're here and we will see you next one. com or visit that website?
Well, that's great free reports and and stuff there. So check us out.