Safeguarding Innovation by Strengthening External Security – The Last Great Cloud Transformation EP7
Organizations face a rising tide of external security threats targeting web apps, APIs and networks critical to business operations. The growing complexity of applications—driven by third-party integrations and generative AI—has expanded the attack surface, while traditional security approaches, like blocking known threats, fail to detect API-specific attacks. Relying on multiple point solutions often introduces management complexity and leaves gaps in protection. In this episode of The Last Great Cloud Transformation series, explore the challenges of safeguarding innovation and learn how to modernize external security to protect your assets and drive innovation.
Transcript
Hi, everybody. Welcome. We're glad you've joined us today for another episode of the latest greatest cloud transformation Late great cloud transformation.
We're talking about really sort of the next generation of how we think about the cloud and the things that we're doing with it. We're talking about security today, about safeguarding innovation and, uh, strengthening that security. We'll be jumping into app app security and a lot, and a lot of things here.
But, uh, before we get too far down the road, thank you for joining us for this video series. Uh, the, the last Great cloud transformation is sponsored by CloudFlare. We're glad to have them, uh, on board with, with us working on this, uh, helping input with some topics and things like that.
And obviously participating on, on our, uh, live editions, which we do on a monthly basis, as well as these recorded episodes. So, thank you for being here with us. My name is Mitch Ashley, I'm VP and practice lead with futurum Group, analyst firm.
Uh, heading up the analyst area for DevOps, DevSecOps, application development, AppSec, et cetera. So, kind of right in, in vain with this, uh, my co-host Alan Shimo is, uh, unattainable, uh, detained, or whatever the word is, the phrase is. And, uh, so I'll be, I'm, I'm hosting both parts of the chair today.
Uh, you know, it's a little bit of a coup, but he'll be back next time. We'll see him on our next episode, I'm sure. So, let's get to our conversation, to our topic.
Um, let's first start by doing some introductions. I know Chris has been with us on a few episodes here on some different topics. You've been on other webinars with me and talking a lot about application security and, and, uh, cloud.
Chris Blask, introduce yourself. Oh, I've been in Forest Company my way through the security industry for 30 something years. Uh, I inflicted an early firewall in the markets, something called Border Ware, uh, in the early nineties, and ran Cisco's firewall business, the turn of the century.
I've been following this inevitability curve, uh, my new series on here on Textron, um, from one spot to another, from firewalls into, uh, sim and network management. From that, you know, the obvious next step is threat intelligence. So I, uh, chaired an ISAC for a while, and, uh, supply chain has been my focus the last five or six years, you know, so, you know, software, bill of materials, hardware, bill of materials.
How do we connect all these things, which, and again, currently? So, currently I'm, my main role is I'm vice president of strategy for sbe, which is involved in the SBO space. And I've been, uh, co-chairing several, uh, cisa uh, working groups on SBO m sharing.
So we're currently have a group looking at ISACs, um, as s om distributors. How does that know in the middle start taking this information and, and propagating it As bonds software, bill of materials? Absolutely.
Great. Thank you, Chris. Um, Catherine.
Catherine, welcome. Glad to have you on, I think the first time we've had you on the show. Catherine Newcomb with CloudFlare, please introduce yourself.
Yeah, great to be here. I'm excited to talk about application security. Um, my name's Catherine Newcomb.
I live in Denver right now. Um, I've been in cybersecurity for about five years at this point. Um, and I started in the network firewall space, um, and encryption.
And now I'm a product marketing manager for CloudFlare, um, for their application security business, uh, where I focus on their web application firewall product, um, our software supply chain product, as well as our encryption and certificate lifecycle management products. Very nice. And, and I do like to say full disclosure, Textron is a customer of cloud flares.
We do use their services. Enjoyed very much so thank you Catherine, and team for that. Uh, last but not least, another newcomer to our show, Kurt Hendle, who's with, uh, Teradata.
Tell us about yourself, Kurt. So I've been working in security probably eight or nine years at this point, uh, but in the software industry for close to 15 years now, anywhere from development, uh, into business analysis, product management, even, uh, doing a little bit of red teaming myself. But, uh, I am currently the chief security architect at Teradata.
And so I've been focused on architecture mostly for the past six, seven, possibly eight years, and really kind of a generalist. So AppSec is where I spend the least amount of my time, but we focus on the architecture, the requirements, threat modeling, um, especially compliance. We do a lot of the, the major compliance frameworks at Teradata.
So we've been pushing that recently. Um, and I'm based in the Pacific Northwest, up in the Seattle area, and happy to be here. Very nice.
All the weather and fires and it's cold and I'm just glad we all made it. Maybe it's 'cause we didn't have to travel anywhere, so, so I hang tight. I'm glad we're all here.
And you know, our, our thoughts go our, our hearts go out to the folks dealing with the fires and, and, uh, some weather down south and southeast, et cetera. So, um, let, let's kind of jump in this way. Um, it, it's a big topic when we talk about sort of the kind of current state of the cloud and where it's moving to.
Um, but I don't think it's too much news to everyone that application and app APIs, API first kind of design into applications, you know, it isn't just things that sit at the edge anymore. We think about also the security of the AppSec and the kind of, uh, software we're creating, the innovation that we're making, um, as maybe as part of the cloud. 'cause sometimes application lives within it, you know, like a, like a provider like CloudFlare or certainly at the edge or at the core as well.
Maybe Catherine, if you wanna start us out with, how do you, you're, you're, you're managing, doing product management in this space. How do you look at this, uh, sort of this problem or this space and define it? Um, so looking at application security, um, when we're talking about this at cloud, we're mostly talking about web application and API security.
So if you're an OSI person, layer seven model, um, and you know, when people are accessing these external facing web applications, they're doing it from a ton of different devices and in a ton of different ways. So they're accessing from things like mobile, uh, desktop, laptop, and they're accessing these AppSec that could be hosted anywhere. So on-prem, in public clouds, private clouds, hybrids.
Um, so as we're securing, we need to think about how can we secure, um, all of these users and the end servers as they're sort of accessing these web AppSec, right? So how do we make sure that, um, mobile traffic is protected, user data is protected, um, and sensitive data is not, you know, leaving an app. And then how do we make sure that a web app server itself is protected?
Um, so at a very high level, that's about what I think, that's what I think about when it comes to application security. Um, some new things we're thinking about in this space. Um, I talked about software supply chain.
This is increasingly becoming, um, an area of interest as people create more complex AppSec with more third parties in them. Of course, API first development has also meant we've had to adjust our thinking a little bit around application security as well. Kurt, how about you as a, as an architect, security architect, you may, maybe you don't get into the innards of applications and per se in application security, but traffic over there.
Obviously our networks are heavily API driven. Um, you know, when you think about the security architecture, where does this fit into your purview? I think it, it fits in really everywhere, right?
So we're, we're building these huge applications. Sometimes small applications mean we do all sorts of scale at Teradata. And in my previous roles, I've, I've worked with pretty simple AppSec all the way to super complex microservices architectures.
And so, like Catherine could have said, you have the mobile aspect, you have the server, there's application code literally everywhere, including on the person's device. And so how do you secure it as best you can, um, within reason, right? Because if it's too secure, it doesn't work.
If it's not secure enough, well, you end up in the Wall Street Journal and you're in trouble. Um, so we, from an architecture standpoint, we really try to focus on all different aspects of it, where the biggest threats lie, um, and then implement controls and use technologies to, to simplify the implementation and streamline it without making it overly complex. And so it's, it's just becoming more difficult given that, um, the, the kind of classic perimeter is gone.
Right? I'm sure you can relate to that, Chris. Oh, yeah.
Well, it was easy back in the day, right now, you had to get on the internet and you needed a firewall. Get a firewall, right? And I'm thinking as Kurt and Catherine, your, your comments remind me of these transitions we go through.
Like there was the mainframes before our time, but you know, I, I'm old enough to have seen the end of that where all of your capabilities are just to keep one computer running and run terminals and printers and things like that. And then we get into you, or where I came in, where we're starting to build networks, fractally more complicated. Just, you know, how do we do that with, when all of our resources, were just keeping one computer running, we figured it out, you know, now we're here, we're talking about web APIs, Catherine, you know, the data going in and out on with being stored 30 years ago, you couldn't have that conversation.
Now we're saying, alright, what do we do in this case? And it's very complicated. And I think in, and Catherine you mentioned the supply chain.
This is, I think we're filling in the dots. Security has been, is not, is not new, right? People have been saying, you should know your inventory for a long, long time, and we've gotten away with not knowing it.
Now we're starting to fill it in, need to actually know where the software is, where the data is, and we're working through that. So it's exciting times, but it's not different in type than other transitional periods. Certainly is an evolution, right?
Of what we've gone through. And to think about, you know, from the bas and host days, early, early on pre firewall, um, Well, firewalls used to be a million dollars a year. I think about I got involved, you know, at least as I tell the story, there were a hundred in the world and they typically were seven computers and a team of people.
And my argument at the time was my mom needs one. Yeah. You know, and so we're at this stage where what used to take so much time in here in the API, uh, world has to take less time a lot.
It, it, so let me, let me throw out this hypothesis. I think it may be pretty obvious, but maybe it isn't, is I think we live in a world, you know, now we we're thinking about things as zero trust, right? Of, of you, you know, anything is susceptible, being compromised and could compromise other things.
How do you pro protect all parts of the network applications, the infrastructure? But we're also living a world where if so much is determined by what our applications do, not just connecting users to AppSec, but applications really utilizing the network, being part of the network. It's a dynamic world, right?
It, it isn't a good set of firewall rules and an application firewall, and we're all good, kind of set that up. And it isn't the old days of I've got a pizza box in, in my rack for every function that I need, and they're all doing their thing. I'm good, right?
We need it. It's a much more dynamic environment. So I'm not saying we're reconfiguring our security all the time, but a security has to adapt to, you know, what's happening in the application.
Because we may distribute it to a different part of the edge tomorrow with Kubernetes, or we may, you know, uh, acquire business and suddenly a network has looked much different than it did did, you know, three weeks ago. I'm, I'm curious, Kurt, as a practitioner, you know, how do you think about that of, you know, you mentioned microservices and all the things that are being created, you know, in the groups that you're working with. Um, we, we hate for security to be sort of the last thing to be thought of, but you wanna be in the conversation so you can prepare as well as react when you need to react.
I think what you just said is, is really important. You wanna be in the conversation. You don't wanna be doing this retroactively.
And so when you're, when you try to tackle security retroactively, it is infinitely harder to accomplish than if you do it from the beginning. So I have, I do it both ways. I have teams that we work with proactively where they bring us in at the very start and we're building the design with them shoulder to shoulder, drawing the picture in doing security by design or by default as we like to say now.
Or we have legacy applications which are doing retroactively and they're quite a bit higher in terms of risk because they've been neglected for so long. Or you find out about something after the fact and it's like, well, how did this get out there? Well, there's shadow IP in a lot of the world.
And so it's, it's hard to, to really kind of put a, a recipe together that successfully achieves it. And then with the, the rapid pace of technology today and how the cloud has just kind of blown this wide open where people can deploy new applications in a hundred different ways faster than ever. How do you keep up?
So you have to implement tooling within reason without doing, without having too much sprawl. You have to have the right personnel partnering with these teams, uh, to ensure that you have coverage in that you, you're really architecting things from the start. Um, and not just kind of using band-aids and bubblegum per se, to, to secure your environment later on.
Catherine, appreciate your thoughts on this because, you know, I remember the days of networks for speeds and feeds and points of presence and connecting A to B and kinda looked like this nice diagram that you stitched together and that was a network and you secured it, now it's overlay on top of overlay and it's changing and mm-hmm. You know, it's, it's multiple pieces that, uh, much more complex to, to secure. How do you, how do you have this conversation with people?
Yeah, definitely. So as you were sort of talking about this, you know, obviously there's a need for responsiveness and customizability and security, but I actually also wanna make the argument for unified policy management in application security. This is something that I've seen actually, for example, um, we have some customers who have protected their SaaS AppSec, like what is traditionally more of a network firewall or zero trust type use case with the same policy they're using for their web applications.
And by doing this, they're able to do things like make sure that zero day exploits aren't able to exploit their SaaS AppSec, you know, as well as their, um, web AppSec. And we see a lot of value out of these unified policy managements. I was talking earlier about, you know, how we have all these AppSec hosted in different places.
We see a lot of customers, for example, will host, um, you know, an app across multiple clouds for like a resiliency use case. If they're worried about outages, you'll, you'll certainly see that, um, for example. But then how do you have to, you know, actually secure an app that's stored in multiple places?
Do you write different policies for, for wherever those are stored? Um, do you write different policies for APIs versus, you know, traditional AppSec? Um, so we see a lot of benefit out of like a unified policy for all of those disparate sort of endpoints and all of those disparate, um, locations that they're stored.
Uh, for CloudFlare in particular, how this sort of works out is our WAF is like the backbone, the architectural backbone of the rest of our application, um, security portfolio. And this works out really well because you can do things like have a WAF and an API like positive security model protecting your APIs. Um, so you can do things like detect zero days and volumetric attacks, which are, you know, APIs can also be susceptible to as well as, you know, do the things like Ebola and, and all those API specific attacks all within sort of one, um, control plane, which we find a lot of people get a lot of value out of because of this really, really disparate environment.
Okay. Chris, I saw a lot of hand waving head nodding you, I jumped outta your chair on this one, and so I kind of have feeling you might resonate with this. No, um, I, I gotta throw out there, I was gonna, uh, before Catherine got into the, the policy thing, ask swearing, it's been a lot time, but yeah, the concept of an SBO m the software bill of material for the current release version of Adobe Acrobat as opposed to an SBO M four as we're look talking about here, some ephemeral web app that one time for five seconds exists in the cloud.
You know, think about that. How do we, how do we deal with that? And I, and, but I think policy is, is the answer all hacking?
All hacking is policy hacking. I will figure out how you do things and I will figure out where the gaps are and I'll engineer that gap. And we live in a world right now where we generally have no idea what policy applies to any of us anywhere, with few exceptions.
And in this topic, and because I'm used to the supply chain topic, imagine I needed to get the, the SBO M or custody information about a piece of software on his phone right now. I could get it in between five days and six months. Today I need to get it in of half a second.
That means I need to read the policies between me, the person who bought the phone and the first time the company I bought it from, and like their relationship, their contracts, their policies, you know, upstream all the way. And we have to get that done in the next decade. So without unified and, and, and adaptable, you know, transparent policy frameworks, none of this technology is gonna make a difference.
So I think we, we will do that. And there's interesting things going on down that path. It's kinda interesting in a way, just connecting dots between what you said, Catherine and you were talking about Chris, there's your own unified policy management, right, of what you're doing.
So you know, you're, you, what you're applying where and how you're applying it, and then that's how that interconnects or interrelates with the people you connect with, work with, use their service product, whatever that is too. And I, and I appreciate what you said Chris, about, think about just serverless technology, like a lambda kind of service, right? That, you know, it's there now, it's gone tomorrow may not be the same thing.
It was a second ago when it, when it ran. Um, so it in some ways, Catherine, it's all sort of a dynamic unified policy management, right? It can't be a static thing.
Am I, am I on base here? Yes, of course. You know, you do have to be responsive to the environment, um, you know, threat landscape.
Um, this is one, one area where I strongly advocate for actually ML driven, um, detections and policy. Uh, this is a thing where, for example, if you have a really large data set, uh, you can train your ML models. Um, how we do this at CloudFlare, just 'cause I think it's a little easier if I give an example and it's, uh, we will score each request on a scale of like one to 99.
And if something is less than 30, that means like it is very likely to be an attack. And because we have, um, hundreds of terabytes of requests, or sorry, hundreds of millions of requests every single day, um, we have so much data we could train this on and say a little blog in Malaysia gets attacked by a new attack we've never seen before. Suddenly, because that tiny blog in Malaysia got attacked that gets feed and fed into our ML model, we don't have to rely on a security engineer to like go and find and analyze that attack and turn it into a regular expression like firewall rule.
Um, the ML will basically just say, okay, like, since it matches something like this, um, we will just automatically block it. And this is why I'd say ml um, sort of combined with that traditional, um, you know, security analyst looks at the traffic and writes a rule that matches it and then blocks traffic. Um, you gotta combine I think these types of approaches.
So ML is a really, really great application, um, when it comes to being responsive to the threat threat landscape. And we have some data around this as well. Um, we recently, not that recently, like half a year ago released our annual application security trends report.
Um, and we found out that, uh, for example, like zero day vulnerabilities, um, we probably wouldn't have been able to find this out with just security engineers analyzing it. But with our ml, we were able to detect, um, and exploit 22 minutes after the, uh, proof of concept was posted online. So, um, really, really great applications there.
A lot of interesting stuff going on for sure. Well, that doesn't make the case for dynamic security. What does, right.
Um, I, I'm curious, Kurt, how do you, is, is someone, you know, applying these things, applying security? Are you, are you looking at things like ML are you doing in via yourself? It's something you look for in the vendors, the partners that you work with.
How do you leveraging either that or other kind of technologies to help shorten that cycle between when things change and how you can account for it and secure it? Right. The, I think the ML piece of it is, is hugely important because I mean, humans, we're slow.
The, the technologies we use, the computers, and I mean servers process all of this far faster than the human brain and I ever could. And so we need to augment ourselves with this technology. So anytime we're evaluating new solutions and bringing them in, I'm currently in the process of implementing a big one right now that focuses on platformization and ai ml, it's all part of it because in humans with eyes on glass, like it's great to have those guys in the sock, but they'll get overwhelmed very easily with the speed at which things happen today.
And so we need to leverage technology and machine learning enables us to do this faster than ever, and it's only getting better, right? And so augment the human with that technology and you can very quickly pare down all of that information to what matters most and focus on real attacks like Catherine was just talking about. I wonder, you know, there's so much activity around ai, of course, a lot of it because of gen generative ai, um, Chris, do, do security engineers have to become machine learning experts to be able to do this stuff?
What does it take to really leverage it? No, but knowing, knowing something isn't gonna, um, uh, causing any problems. But, uh, I, I just couldn't agree more with, with both, uh, with Kurt and Catherine.
'cause you know, and, and you're point Kurt, it's all about time, time to transparency. How, how long, and again, I've seen this over and over in my career where we get to these points where what we're mostly doing is sharing the war stories. You know, I have no idea it was 72 hours, none of us slept.
There was caffeine. And, and my my question always is, okay, if there was twice as much, what would you do? Because obviously that we're at the limit, we can't possibly work any harder or stay awake any longer.
And, and this, yeah, ai, ml, Oracles, whatever we call it, this, uh, my, a big has been a big part of my, uh, my focus on supply chain before it would, you know, AI became, you know, uh, a general, um, uh, generative, what the hell do we call it? I'm sorry, I forgot. Yeah.
Generative ai. Yep. Generative ai.
Yes. Uh, too many terms to throw around. Yeah, because again, we need to, you know, just for supply chain things, I need to read the contracts.
I mean, I can literally call someone up, you know, it's not a security engineer, but it's some administrative person at the company and I have to get them on the phone and get them to pull A-A-P-D-F and read the contract and find out if the clause allows me to get the information I need. That's not worth a human's time. That's the kind of stuff that computers can do really well, and they're just beginning, but that's obviously the direction we're going.
And if you can't see your policy environment five years from now, by various definitions, your competitors will be so much faster than you are that it won't matter anymore. Kurt, I'm, I'm curious, without giving us too many specifics about Teradata not asking you for that, but what's your sense of, what are the, what are the new priorities that are on your Yeah, on your horizon or things you're dealing with now that you've kind of added in the last year or so? What's changed about how you're thinking about security and that you've gotta address now?
I think there's, there's always classic problems that we, we have to deal with and tackle. Like, we can't forget things like identity and network security and the rest of it. But the, the prevalence in the emergence of generative AI and putting AI and machine learning in everyone's hands has meant that security teams have to be hyper aware more so than ever because these new technologies, people are latching onto them without considering the risks.
They're like, that's awesome. I can speed up everything I'm doing. And suddenly you see a new story about, well, what was it like Samsung engineers leak their code through regenerative AI solution or whatever.
So you're, you can quickly lose intellectual property or put it at risk. And so we have to think about securing our environment for those solutions, or putting the guidance out for people to use AI and machine learning. Um, and I mean, getting visibility of all of this, and another big one that's been getting pretty popular and we're seeing a lot from different vendors and acquisitions and whatever, is data security, posture management.
Where is my data? Where is it moving? How secure is it?
Because at the end of the day, that's what the attackers want. They don't wanna sit in your network and use your resources to, to launch attacks as much as they used to. They wanna grab your data, steal it, monetize it.
So need, we're, we're focusing on data security big time in, in the more recent years, especially, um, forward looking because we have more data than ever. Interesting. Catherine, from your perspective, you know, communicating with so many companies, what are some of the changing priorities from your, from your viewpoint?
Yeah, I mean, certainly the gen ai, um, piece is something we're seeing a lot. Um, everybody wants to put an an LLM on their web application. Um, and of course that means that you have to think of that as like a data security concern as well.
Um, because you wanna make sure your LLM is not gonna like accidentally leak somebody else's social security number because that's certainly happened before. Um, and so at, at CloudFlare we're thinking about this of like, basically how could you basically just put a WAF in front of an LLM, um, from that perspective, how could you prevent it from exposing sensitive data to the end user? Um, but then, you know, you gotta think about these more complex issues as well.
Like, how do you prevent somebody from poisoning the model? How do you prevent, um, you know, some of these other, like how do you prevent it from hallucinating? Uh, these are all, you know, sort of adjacent to security concerns.
But, um, but nonetheless, we see some security teams focusing on this, um, increasingly. Um, additionally we also think about, you know, the, the LLM sort of security use case as a little bit of a just, um, increased API security use case since a lot of times, um, people are not building these LLMs themself and hosting them themselves. They're often, you know, bringing in LLMs from third parties, which, uh, necessitates, um, APIs, right, for integration.
So how can you make sure that these APIs are staying secure and not leaking them back to the host and whatnot. Um, so that's definitely something we're seeing as well. Um, I would say additionally, one thing I've been hearing a lot lately is, uh, software supply chain security.
Um, I think Kurt mentioned the beginning, um, sort of securing code that lives on the client device as well. Um, this is something that we've been hearing a lot about, especially as it comes with the PCI four, um, compliance, which is gonna be mandated at the end of March, um, in a couple months. Um, PCI four has a new compliance requirement around client side security and securing, um, the client side, like software supply chain.
Um, so this is something we've been getting a lot of questions and inquiries lately. Um, you know, how much are organizations responsible for, um, the code that loads on their end users' devices, uh, when they visit their websites? Um, this is something we're seeing a lot of people trying to actually actively get control over, um, and make sure that they're not, you know, serving, uh, code to the client devices that could do things like download a crypto mining software onto their phone, which, um, believe it or not, we have seen somebody's trying to make, you know, personal laptops part of a crypto mining network, which is pretty crazy.
But, um, so yeah, I would say the client side component is, is something I've been hearing a lot lately as well. I, I just have to say, I, I love living in a world where we can use the term, uh, you know, hallucinating artificial intelligence in a conversation like this. Seriously, just, we, we understand about that.
It's not a sci-fi movie. It's real. Oh, It's, it's real.
Yeah. Hey, so I've, I've kind of a left field question for you, Chris. So if this, if I throw you too far off the track, I'm guessing you're thinking about this though, is, is there an SBO m in our future for LLMs and s SLMs and all of these things?
Because in a way, this is a whole nother part of the software supply chain, right? We're handing off to something that's doing inferencing, either on a chip on our handset or in the cloud, all the above. How does that fit into, do we need to be thinking or at least wondering how we're gonna solve this problem And not only not left field, and that's, that's right in the middle of the, the track.
So in short, yes. You know, there's ano there's another assistant working group, uh, Dimitri Rayman, uh, my colleague CTO at at SBE is, uh, a co-chairing now on, on AI bomb, right? An AI bomb has been talked about for a long time.
So what does that even mean? You know, so AI is code. So there's this, you know, same sort of standard SBO stuff about that, but there's also the training data and the models that produced, right?
And this sort of goes back to my last comment about ephemeral, ephemeral SBOs. You know, we start with the idea that I am a software provider and every 16 years I release new code and I carve a new sbo, you know, on purist graphite. Um, but we live in a world where code gets compiled and used all over the place.
You know, how do we even look forward and say that I can commit to a policy that says I will, if asked, provide the contents of this code without, um, actually going out and printing or saving or producing quadrillions of SBOs forever, you know, in, in exabytes storage. Uh, so this AI is, you know, what we're currently calling AI is just another forcing function of the level of complexity we're at. So we need to be able to provide the answers to live up to the policies that we've agreed to, um, which is, you know, you know, in the SBO m case we're talking about a software inventory that I will be able to tell you what code that was running or you know, what data set was used, and we have to get there.
And, and, and it's, it is reasonable progress down that path. It's a, it's a complicated one that is very similar patterns to how we'll do other things, uh, similar complexity. Um, Kurt is, is that on your radar yet at all, kind of thinking about security of, from a supply chain for LLMs and AI and ML algorithms and all that kind of stuff?
No, I mean, it's, it's certainly jumped up on the radar, especially since the whole SolarWinds thing happened. Um, as Chris Blask talking, it got the wheels streaming in mind of, well, if we're gonna be kind of, we're moving towards leveraging a AI in the sense and dynamically generating SBOs and things, is this another attack vector we potentially have to watch out for? Is how do you weaponize that and, and protect against it?
Because I mean, as we see attackers evolve their tactics and techniques faster than ever, they're coming up with new creative ways that defeat the traditional approach in microseconds. And so how, how do you stay ahead of that curve now? And so I obviously, I don't have the answer right now, but it's, it's really interesting as Chris talked to start thinking about this, this new sort of problem that we're facing.
And again, it all falls back to the rapid evolution of technology. Yeah. Speaking of that evolution, uh, just in the last week or so, uh, Satya Nadal, head of, uh, Microsoft was talking about the death of SaaS, meaning that's kinda the click bait one-liner that what I think he was really talking about is e evolving nature of software architecture that I would describe it as today's microservices or backend code or tomorrow's AI agents, right?
We'll see more and more parts of AppSec built through, you know, with or through or maybe completely with AI agents. And it reminds me of going into the, uh, cloud native era of, oh, how do we secure microservices now that we're gonna do that kind of thing? That's kind of the, that's the next edge that we're, we have to work on and think about how, uh, there are different things we have to do for securing AI agents.
How are they orchestrated? Is it Kubernetes or it, some other thing that's managing all those things. And, uh, given that we're putting AI agent building capabilities in everybody's hands, in many cases, it, uh, could make for interesting.
I use that in a nice way, uh, interesting environment to try to secure and manage. So in some ways, the future is bright, but it may be, uh, pretty intense at the same time, same time. Well, and I think kind of building on that too is the, the technology behind ai, it's backed by machine learning.
Like you're, you're making technology autonomous, right? So it's not as predictable anymore. So how do you secure what, when you don't exactly know what turn it's gonna take next, Non-deterministic, right.
Well, I, I gotta add a note, a note of hope though, because it's easy, you know, to your point, uh, Kurt, the short answer is yes, because it's a new attack vector. Oh, yeah. Um, but you know, throughout my career I've been arguing in this one, it's like, we'll probably keep the lights on.
It's like, no, no, if we don't do this and that, then you, we will, you know, the, the, we're on this, we're doing this call right now. We've managed to figure out everything else over this point. And not only that, but I think that where we've been mowing the lawn, I think, you know, what we need to do, generally speaking in cybersecurity has been known maybe forever, certainly 50 years, but we haven't gone around to doing the vast majority of it yet.
'cause we haven't had to. But as we do, and I, I will take a risk and, and put a lot of my, my faith in policy, you know, in, in real policy transparency, you know, in, again, in this decade it gets harder to be an adversary because, you know, these are the happy World War II fans out there, you know, or no fans, you know, but the, the ubo wars, right? There was the happy days when you could just have a u-boat and sink shipping all day long.
You know, that's kind of most of the world, most of the, the history of the internet to date. It's not necessarily gonna this day that way, that long forever where there's always a new attack service, and there's always a, a, a new way when the last one is, is blocked. I think we will, we'll keep it running.
We will all be fine. And I think over, you know, at least over a period of decades, being an attacker will become much, much more difficult. I mean, I might argue it already is becoming more difficult.
It 'cause the, while, while the, the technologies we use as practitioners are getting more advanced, that helps make it more difficult for the adversaries of the world. That's not to say that they can't employ similar technologies, right? So now we're kind of, we're creating that chicken and egg problem all over again and playing the game of cat and mouth.
It's kind of the next arm's race, if you will, as technology evolves, everybody has access to it. Well, let's do this. I appreciate all the conversation and we brought up a number of topics, um, just as a kind of concluding thought.
Uh, we, we've been talking about what are the things we need to be thinking about? Maybe they're new, maybe they're on the horizon, maybe already working on this today. Um, if you had to say, there's one thing you'd really want to emphasize this, if you were, you know, somebody who's listening to this and maybe making a few notes, the thing that sort of stands out to you as something really important to be thinking about in the next, let's say, six to 12 months, if not today.
Um, Kurt, do you want to give us your thoughts and then Kathleen, if you would, and Chris, you can wrap it up for us. Sorry, did I say Kathleen? I mean Kathleen, excuse me.
Kathleen. I work with a Kathleen. Sorry.
I've been doing that. All good. Okay.
Yeah, I, go ahead, Kern. I mean, it's, we wanna avoid that situation where everything is a priority, so nothing's a priority, right? I think we, throughout this conversation, we've highlighted the importance of, as smalls, we've highlighted the importance of application security and how it's, it's becoming more important than ever because our application code is, is literally going everywhere.
And that's, that's kind of the gateway for a lot of the attacks we're seeing in the world today. And so I think the, the emphasis is on application security, but it's also to say, let's not forget the rest of it, because all of the, the other parts of cybersecurity are hugely important. And we still need that visibility.
We still need the coverage, and we need to be thinking about ease of use as well, and avoiding the sprawl. So I know these aren't necessarily specific cybersecurity things, but they, they help you simplify your approach and in focus on what matters. And that depend that that changes everywhere you go.
Every enterprise or company has different priorities. And so I think focusing on those things help enable us to, to focus on what matters for where we're at currently. You good, Catherine?
Yeah. So I mean, like Kurt said, you know, we wanna make sure that we're not making everything equal priority. So I think when it comes to application security, which is of course, my area, what I would say is most important in this space is visibility.
Um, the attack surface is getting more complex, applications are getting more complex. Um, you know, where they're hosted is getting more complex. So how do we actually have visibility into our entire, entire application attack service?
How do we have visibility into the APIs developers are creating so we can actually secure them? How do we have visibility into the software they're adding, um, to these AppSec? Uh, that I would say is probably the most important thing for application security and also one of the most challenging things.
Excellent. Chris, I, you know, Kurt and Catherine both want exactly where I'm going, so I'll just build on that. You know, do do things that save you time to transparency.
You know, if you, you know, don't panic, nothing's on fire. And, and when things are on fire, panic less, right? Just take your time and, uh, getting visibility, you know?
Yeah. Look at how long it takes you to figure out. And anytime you find a, a, a way, you know, in this, in this topic we're talking about here, to spend less time to figure things out, you have all that time back to do things.
And it's easy to just, you know, particularly in transitional periods, to just do more and more and more of what you've been doing, you know? But, uh, understanding the environment you're in so you can apply your resources appropriately is, is everything. And there are lots of ways to do that these days.
You know, there's, there's a lot of Russian panic and there are a lot of, and you know, I will say it, AI and things like that out there who will actually make your life easier, give you some of your time back. Mm-hmm. And feel better knowing what's going on, make, make, and make better plans, a better strategy, Uh, to that point.
Exactly. Chris, and, and Catherine mentioned it around, uh, ml, you, some of the things that I'm really excited about AI is actually just the understandability of what's happening. You know, Kurt mentioned about as things ramped up or, or you did, uh, uh, in, in the, if the tax doubled, right, how would we handle that if we're already maxed out?
So some of it is just handling the volume of things that are happening. But I think one of the things that I think is most exciting about generative AI is it's also so complex. No one person can understand the full system, right?
Or maybe even understand truly what's going on in a case of an attack or where you have vulnerabilities. And generative AI is starting to make some inroads and helping us understand systems and, and giving us some insights to some of the complexity. We may not be able to fully get into our head all at once.
So for example, I've been doing some work around how do you modernize mainframe applications? Well, nobody was around that built those things. Well, maybe it people that built the network aren't even around, right?
So help us understand what really is happening with all this data that we've collected. And the natural language interface through that is, is a great aid, and I think it's just a real practical thing that we can start to begin to use today. So don't think of AI as just as the next, you know, it's gonna replace all of our software and it's all gonna be different, and what do we do?
There's things today that it's already helping us with. So, you know, there's some real things too, not just what's on the horizon. Well, thanks to all of you.
It's been great, Catherine. Uh, we appreciate your perspective and Kurt, your bringing, um, your experience and perspective. And of course, Chris, always good to be chatting with you and your connections into the security world.
And some of the folks are working, collaborating together, which by the way, is another superpower we have in security. And that's the fact that we work together and collaborate on, on these things. We're not going at it alone.
So thank everybody for their good work that we're doing to help advance. We hope this has been a helpful conversation for you in thinking about the, the last great cloud transformation, what we're doing differently and thinking about, uh, as we move forward. So as we've got our heads down, getting stuff done, getting our priorities done, getting our plans in place and executing for 2025, but also kind of thinking a little bit about what's next and what we might be considering and learning from others that are working in our space.
So thanks to all of you. Thanks everybody for joining us today. And thank you to the Cloud four team for, uh, for sponsoring, um, our show today.
And we look forward to joining us either on another recording or Sure. And check the calendar for one of our live events where folks can ask questions and engage with us in a similar kind of conversation. We have many of those coming up.
We'll talk to you again soon. Take care everybody.

