The Last Great Cloud Transformation: Strengthening Security Through Consolidation – Webinar
Cloud computing and hybrid work have significantly reshaped modern businesses. But these changes have come at a high cost: staggering complexity. Companies have added a grab bag of new security tools to protect new ways of working — and they have been left with operational complexity, higher costs, and security gaps.
Security consolidation is now a top priority. With fewer tools and vendors, organizations can simplify management, increase visibility, and strengthen overall security. According to a 2022 Gartner report, 75% of organizations surveyed are pursuing security vendor consolidation to address these goals.
In this webinar, join our panel of Cloudflare and Techstrong experts as they discuss how organizations can address their security consolidation goals by adopting a connectivity cloud. This session will explore the benefits of a truly integrated security platform, the challenges organizations face in consolidating their security tools, and how a connectivity cloud offers a flexible, composable solution that enhances security without compromising performance or compliance.
What you will learn
- How cloud transformation drives security complexity
- The rewards and risks of consolidating your security stack
- How a connectivity cloud can help improve security and simplify security management
Transcript
We will talk later. Oh my God, what a way to start. We're already having a great time here.
Welcome everyone. I'm Alan Shimel of techstrong, and you are watching another, uh, Techstrong Learning presentation. But this is a very special edition of Techstrong Learning.
It comes from our Security Boulevard line, and it is part of a continuing series that we are doing with our forensic CloudFlare, and it's called The Glass Great Cloud Transformation. Uh, this is a video series that we do about every other week or twice a month. And then every second or third episode, we do one of these where we're live with our studio audience.
And what makes it really cool for us is we want you to be involved in it. And, um, if you, how do you get involved? Well, I wish I could put you all on video camera, like our panel and, and we can talk about it, but we can't do that.
And, and so all I can offer is your ability to chat in and, and talk to us. So for most of you looking at this in a browser, we use the big, big marker webinar system. The right hand communication panel is right there.
And for most of you, the word chat will be in black. And you can see you can go in there. That's a public chat.
Public chat of course, means that if you type it in, everyone on our presentation today, including all of our guests, we'll see it. It's public. However, we really don't want you to use the private chat.
Um, this isn't Tinder or, or anything else. And, you know, people don't necessarily want to hear from you in private chat unless they ask you to. So please, please use the public chat.
However, if you'd like to ask something directly of the panel and only the panel, if you look next to the word chat in your communication window, you'll see q and a. And for most of you, it's in gray, but if you click q and a, it'll turn black and it'll allows you to type in your, your questions there, and we will see it. And what I, I will personally raise it up to the panel and, and ask them to comment and, and talk about your question or your comment.
Um, but if it's something you just wanna put out to everyone, be feel free. Use the public chat. Um, and as you can see, some of our folks, and mostly it looks like most of our, uh, our panel members are already saying hello here, but feel free to write in.
That's a good way to get, make sure the chat works, type in where you're from and give us an hello. I always get a kick outta seeing from what four corners of the Earth people log onto these things from. Right.
It's, it's still after 20, 28, 30 years is one of the thing that excites me most about being on the internet, is that it, it's crazy where everyone comes from. All right. That being said, let me introduce you to our panel today and what a panel it is.
Um, first of all, I mentioned CloudFlare is our co-producer sponsor of these. And, uh, we've invited from Cloud Filler today, my friend John and Gates. John is field CTO, I think I got that right, John, right?
You did. You did. And welcome John.
Beyond being field CTO at CloudFlare, say a little bit about yourself. Yeah, well, thanks for having us on. Um, yeah, J again, John and Gates Field, CTO, CloudFlare, about three years now here at CloudFlare.
And a long history in the tech industry. I was, uh, for many years, CTO at Rackspace. I worked at NTT for a couple of years in a SD WAN group, and, uh, been an internet guy my entire career and, uh, slowly transforming myself over the last few years into a security guy.
So I kind of crossover from network data center cloud and, and now, uh, into the security space as well. Excellent. Thanks and thanks for being on John.
Pleasure to have you here. Next up. I am thrilled.
I haven't seen this woman in almost a year now. Well, no, I saw you at RSA probably wasn't that. No, no, I didn't see you at RSA.
So it's been the last time you were down here in Florida, and that was like last August, A year ago. A year ago. She is a security person extraordinaire, but more than a security person.
She knows about ai. She, she's 10 red team, she's managed development team. org, uh, and writing the manifesto for DevSecOps.
I didn't leave you anything else to say about yourself, Shannon. It's my friend Shannon Leach. Hey, Shannon, why don't you, I know nothing there Anything I left now.
Go ahead. I like to cook and garden and a whole bunch of other things. I've got some, uh, ballerinas, uh, in my household.
Uh, really excited to be here with y'all. And yeah, you, you didn't leave much for me to talk about it in my career. I'm a serial entrepreneur right now, have a startup that I'm working on and I'm totally excited about this topic.
It's been one that I've been living closely to towards the now two decades, I think. Oh my gosh, can't believe I'm saying that Crazy, but no, it's all there. Good to be here.
Absolutely. And, and Shannon, thanks for being here. It's always great to have you on and involved in what we do.
Speaking of always great to have him on and always involved with what we do. This next person also really know, doesn't need introduction to security audiences. He's, he's been in the security space for, he doesn't look that old, but a long time.
Um, it's my friend Rich, mogul. Rich, I'm not gonna, Shannon leads you, I'm not gonna say everything I know about your life and leave you nothing. So I'll let you introduce yourself.
You know, I was at my doctor yesterday and she told me how, uh, how good I was looking for my, my age. So, uh, Chris Mogul, uh, been in, uh, security for about 25 years. Been in cloud, uh, security specifically for about 15 years now.
So got involved super early with the Cloud Security alliance and a whole bunch of stuff. Excellent, rich, thanks for being here. And then finally, our last, uh, panel member is my co-host for the last great cloud transformation.
He's also CTO here at Rick Strong and CTA for rum. My friend Mitchell. Ashley.
Hey Mitch, how you doing? Security, security, security. Boy, we were ready to launch this rocket.
Let's Go. Absolutely. Let's rock and roll.
And again, folks, feel free to ask questions in chat, but otherwise we're just gonna roll. So I almost feel like before we jump into the, uh, security consolidation topic, I, I owe it to the audience. We owe it to the audience to, this may be the first time you've heard this term, the last great cloud transformation.
It may also be the first time you hear a term that we're gonna use say called the Connectivity cloud. And well, John, you are from, from CloudFlare. I'm gonna ask you if you wouldn't mind just briefly giving folks an idea of what we mean by that.
Okay. Well, look, I, I think, uh, when we think about cloud transformation, I go back in time to the ORI origin story of cloud computing, where people started to build in the cloud. They recognized the power or the capabilities, and then they started thinking about what they were running, you know, on-prem that they could sort of migrate to the cloud.
A lot of people picked up applications as is and move them to cloud. They moved storage elements to cloud. They started to take advantage of applications in the form of software as a service.
Um, but when we think about what didn't transform it was really the networking and the security layers of the stack. Those continued to remain mostly as they were on premises in the data center built out of appliances and devices and, and, uh, services that really were, were built and, and controlled by the, uh, the data center team or the security team. And so when I say last great cloud transformation, that's kind of what I mean.
I'm le uh, leaning into that idea that we need to transform the networking and the security layers, uh, to sort of go along with and fully enable, uh, the other elements of, of digital transformation that live in the stack, uh, in other, other places. Um, when you think about the term connectivity cloud, that really just distinguishes it from things like a storage cloud or a compute cloud or a software cloud of some sort. It's really that layer, um, in, in networking and security that is moving to the cloud.
And we've seen it in, in bits and pieces over, over years. But I think what what CloudFlare is trying to do is bring it all together, right? Bring it, bring together a full, coherent, uh, unified solution in terms of, of connectivity cloud that meets the needs of a lot of enterprises around the world today.
I agree a hundred percent guys be before we get into security consolidation, rich, you, God bless you. Sorry Rich. You've been looking at security in, in the cloud for as long as there's been a cloud.
Have we entered this last great cloud, cloud transformation era where it's not just about being at that core cloud data center anywhere. You know, we talk about cloud, reparation, repar, repatriation, Easy for you to say, we Get stuff outta the cloud. Um, we talked about stuff on the edge and all of this.
Ha has this, is this like a new era of cloud for us? I, I think it is. We're first of all, the repatriation thing is a garbage myth that certain vendors are pushing to, uh, try and get people out of cloud and back on premise.
Nobody's doing that at not, not at any degree of scale. So I think I saw a stat, and I was actually having a conversation with another, uh, cloud security expert about this today that only about somewhere around 16% of workloads have moved into the cloud itself. Uh, and that's across all the different kinds of clouds that we have.
So that's a really, like, we're still in a very early adopter phase, but it's an early adopter that's spread broadly. 37% of the Fortune 500 are using cloud. Uh, and so it's a matter of they just haven't moved everything across.
Uh, and I think that that's the phase we're starting to move into right now is there is broad adoption of cloud, but when you think about how much is in there, it's still a really as much, I mean, there's a massive amount of stuff in cloud now, but it is still a fraction of what's running every place else. And so now it's more of the move to, we're, we're starting at that early edge of, of pushing stuff in, which raises tons of issues. Obviously connectivity is a big part of it.
I spent a lot of, a lot of time these days dealing with networking, you know, and, and the complexities of that is these apps are now spanning all of these different places. People being forced into multiple cloud providers when that's like the dumbest freaking thing you can do is go multi-cloud people bringing containers back into play. And with all the different, like, well, with containers, what kind of networking do you have?
I'll have that conversation with a client. We can pick this one or this one, or this one or this one. And then how's that gonna work with your cloud network and with your on-prem?
So I think there is a new phase that we are covid accelerated the start of it, but we're still very much on the early edge of it, which is moving from not mass adoption as a, the mass quantities of people using it, but now that mass, uh, mass u going from mass adoption to mass usage. Oh, cool. I gotta do a blog post.
I like that. Mm-hmm. Okay.
Sorry. I think, um, you just mentioned the pandemic and I, I do think that was a big factor in sort of bringing this to light is the fact that not only were the, the applications in the cloud, but the users were more distributed than ever before. They were no longer centralized, the users became as a distributor more so than, than the applications themselves.
And so, you know, that's really what, what sort of highlighted this challenge for a lot of companies. You know, one, the thing to interject too is much like we lifted and shifted applications, right? Kinda took the whole thing and just put it onto a computer in the cloud.
We kind of did the same thing with the network. We left it alone and we used enterprise security controls, firewalls that we had back home, you know, in our, in our networks. And, and, and if you really kind embrace and get into the cloud, you can do things in a very different way.
And I think that's part of the, the transformation that we're talking about is there are other ways to do security in addition to what we know from our on-prem data centers, uh, that can benefit from being in the cloud as well. And let's be clear, I don't think all of the, you know, I'll, especially when I go into some of the larger enterprises, so if I go into one of the big banks, they're, well, we're gonna make the cloud providers all use the same network model, and that ain't gonna happen. So it's not gonna happen with containers because software innovates too quickly.
And those are all software defined networks. It's not gonna happen with the major cloud providers because they have to keep providing innovative features and they're using different underlying technologies. If you look about, you know, compare Amazon, they're on what version five of their Nitro architecture these days where you get like default encryption in the fabric depending on what you're using and you know, kind of all of that.
And then you compare that to what Microsoft is doing, which is apparently just, I don't know, giving everything to China, but, um, no offense to China, they're just doing their job. But so, you know, and then Google has their very particular architecture and especially opinionated containers, and then we've got our data centers and all the different kinds of like, no, it's, it's not all gonna be standardized. So now we're moving into these, well, how do we actually integrate all of these pieces because our users, our workforce needs to have access wherever they are.
And sure, some places Amazon are forcing people back into the office, but many more companies are not. And then we have all the different kinds of data centers we have now from, you know, cloud and OpenStack and everything there and our on-premise networks and, you know, that's, these are very legitimate challenges to keep all this stuff wired up. Yeah.
And, and that degree of complexity that you just described, um, has led to a proliferate proliferation. That's a hard word to say too. Mm-hmm.
Of, of, you know, just security tools that have come, you know, cropped up. There are companies that have grown up around solving a specific problem that has only become a problem because people are moving to a cloud or a multi-cloud architecture or trying to span across these different environments, heterogeneous, you know, on-prem plus cloud, hybrid cloud, whatever you wanna call it. And I think that's been just adding, you know, to this problem.
And, and now you have a security analyst or a security leader that has to manage all these relationships, all these tools, different, you know, sort of swivel chair management approach to things. And, and then when you had a troubleshoot a problem, it's not all in one place, right? You've got so many places to go look for, um, you know, where, where the, where the problem might lie.
Well, John, if you ask the developers, it's always the firewall, whatever the network breaks, it's the firewall always gets blinked. Just open it up, right? Just open it up, why?
And it'll all work, weirdly. I mean, come on, let's be real. That's how I troubleshoot stuff after time.
I, it's like, all right, let's open it up. Let's see what, okay, now I can put those rules back into place. So Shouldn't say that in Public.
Let me, let me, if, if it's okay, I want to kind of steer us into the topic today, which is strengthening security through consolidation. And, you know, as, as long as I've been in tech, and I've been in tech a long time, there's always this pendulum swing, swing between best of breed and call it one throat to choke or what have you, right? Um, but I think particularly in security over the last seven years, eight years, we have seen such a proliferation of new security companies.
There are some who say there hasn't been a lot of innovation, but there's been a lot of security companies, a lot of security products, and at the same time, our security posture has been ratcheted up, you know, where security is so important that let's buy the new one, let's buy the next one. I need this, this is the one that's going to do it. And we, we've all collectively gone on maybe a bit of a drunken buying bench of, of buying lots of different security tools.
Some play together nicely, some don't. And now we find ourselves in this place where we, we can't even manage all the security tools. We have a lot of them we not even using or deploying.
That's kind of shelfware or shelf SaaS, whatever the term is for SaaS programs you don't really use. Um, how are we entering a consolidation phase and does security cut consolidation actually make us more secure? Shannon, I I'd like you to kick off.
I knew you were coming to me next. Um, so let me maybe like set the landscape and how I see it. Um, I think that a, what's happened after Covid is that we've seen this taste for what I call the creative capabilities out there.
That's what you're seeing with AI now. Um, I see that continuing to push out to the competitive edge, which means to me, business and development are actually continuing to drive forward at a much more rapid pace, higher end scale, increased complexity. So to let everybody be able to do those things, one of the things that may have to happen, and this is where you kind of like wrestle with capabilities from a security perspective, what do you do with them?
Are they centralized? Are they decentralized? Are they a mixture of both?
And, and my perspective is, um, and I've been in this industry for over 35 years, so just bear with me because I'm a little bit of a security dinosaur. But we started with a little bit of zero trust in how we thought about things back then when we first all got started. And then along the way, capabilities came in, but the zero trust wasn't maintained as a concept.
Uh, we then started talking about things like layered defense in depth, and I, I love it, but I also feel like it was kind of a bolt on, if you will. Um, and so my perspective is I think you get governance great companies when you start with what should the company do? What are its business capabilities?
How do we wanna manage the policies, the strategic inner workings of that organization? And I think that is best done when you start to bring your governance back to a set of policy enforcement points that you're actually starting to think about things like what are we bringing into the organization capability wise, as an example. Um, I still think that we are not as an, an industry, um, very capability aware, we talk about cybersecurity, but in reality, if you do a bunch of work, which I've done over the last couple of years to understand the difference between compliance and cybersecurity, cybersecurity is an adversary job and the rest of it's a compliance job.
You're like either solving for auditors or you're solving for a adversaries. In some ways you can kind of solve for both, but they like overlay very little. We actually operate, you know, some of us auditors in our adversary model, right?
And you said what Some of us include auditors in our threat and adversary model, right? I I'm trying to keep it pg Okay. Just saying.
Um, I'll say that maybe in my adversary model, there might be a little auditor person in there because I think that to some extent the auditors can push you to do things that could create opportunities for adversaries. And I think that when you look at it from this perspective, which by the way is a developer forward perspective, developers wanna know like, what should we do? Why?
And if, if you don't have that why, which is very crystallized by it's either an auditor problem or an adversary problem when you're in development, then you end up with a whole bunch of complexity for no rhyme or reason with a lot of questions and everybody kind of doubting the security principles of the organization. So my belief is we are headed for mindful governance, especially with AI and data and everything coming in that for us as organizations to move forward, like small businesses, big businesses, your competitive edge is a draw. But that means where is your biggest opportunity for innovation?
It's actually to bring back all of your information and data to your organization. Like my organization has all of its data born internal only. And then if you wanna do something with it, you actually have to make a decision about it.
And you actually have to justify your decision for what you're gonna do with that data. And, and that I think is the futuristic way of operating. And I think it's the mindful way.
I actually think another problem that we're seeing is if we're gonna bring it all back home to a policy enforcement point or a set of policy enforcement points, the way that we're gonna construct our security, then we actually also need to build skills into every worker within our organizations, which means HR is a place you have to be destined for. And the policies that you're gonna have to put in place are both business policies and cyber policies. Like, I hate to break this to everybody, but adversaries come from like the total bounds of your, um, actual market.
So if you have a total addressable market of x, adversaries are in that X part, right? It's like x minus something, which is your adversaries, gives you actually what your customer base should be. And so I think you've gotta solve for X.
And to me, I think that's done through some of the security capabilities that are out there. I think that we will be better served as a community if we actually bring our capabilities to those policy enforcement points, and we actually reduce the complexity of policy management. Yeah, I mean, the complexity is really, uh, the enemy.
It's, I mean, it has consequences when you think about, uh, over overly complex environments and managing them. I, I remember the days of, you know, thinking you were gonna layer in more and more redundancy to, to get higher uptime, and sometimes it would have a negative effect because the complexity associated with failover and, you know, having things kind of kept in sync always bit you, right? It really was not, not always the, the, the right outcome.
And I think the same thing with security. When you, when you think about adding more and more tools to solve new problems, and you haven't really, um, you know, integrated those tools, you haven't really thought about how they work together. Uh, you know, if you look at the org chart and you try to determine who, who owns what and who is responsible for what, and, and you know, you see these silos that have cropped up over time, all of that really, um, is at odds with simplicity and security.
And I think taking some of that complexity out can pay huge dividends. And, um, you know, I, I think that's maybe one of the number one reasons for consolidation is just simplification, not, it has nothing to do with money. It has nothing to do with, you know, sort of just the, the, the, uh, the people side of things.
It's really just about taking things, um, you know, to a a degree that's much more simple and easier to wrap your head around and easier to defend ultimately. There's a lot, um, there's such layers of complexity in, in what we were just talking about with you guys and the, and it's so hard to un because it's easy for us to say, consolidate, simplify, but then at the same time, simple doesn't scale. And the, what I mean by the complexity is, is I'm not trying to add more complexity or, or complicate the problem.
It's about there's different ways of doing consolidation and simplification that provide different levels of benefits. And some of those just make things worse. And some of those just make things better.
So we can't just say consolidate. So let me give you a very specific example. Uh, this was super disturbing to me personally.
I was at RSA and I was with a bunch of content creators who are largely younger. And, uh, I'm in my middle fifties. The, so like these were mostly people in their twenties in the, you know, late twenties.
So getting to be bigger in their careers. And we're at lunch and they're talk, we we're talking about this topic specifically around cloud, uh, and consolidation, and mostly in that synap CSPM space. 'cause that's where a lot of the, a lot of these folks live.
Uh, and I won't mention the vendors, everybody knows kind of the, the ones we're talking about. One of 'em maybe does network stuff and one of 'em maybe a multi level unicorn. And I'm like, oh yeah, well this is like the days of McAfee EPO and Symantec.
And they're like, what do you mean the people that sell me my, my identity protection? Uh, like they had no memory of the days of the early days of trying to do a lot of this consolidation. And even today we see some of these vendors consolidating by buying a whole bunch of stuff and then slapping a UI on it.
And yet in the process they stop improving the underlying products or investing significantly in those. They've made a UX for nobody because it doesn't address the demographic who is using, who has that particular job responsibility. The person managing network security is not the person managing cloud posture.
And yet you can throw all of those things in the person who's doing all the developer. We talk about shift left, Shannon, DevOps stuff. That's a different role than the person who's dealing with the right side enforcement of responding to cloud.
And yet all of these things are being thrown into single platforms for different user demographics. They normalize the user interface. Azure's my favorite punching bag for this.
They wanted to make it look a certain way for Windows admins, which means whole bunches of functionality yet lost or undiscoverable anymore. So they've consolidated in a way that made the problem worse, not better. And then this is going back to this sine wave of consolidation we've had in security for, or most of us here have been doing this for a very long time.
And we have that sine wave because we all know there's the consolidation, they stop meeting the customer needs, and then somebody else comes up with something new that targets that one demographic and that one problem in that area that's unsolved. And then that becomes the next realm of the consolidations. And so it's a matter of being like smart about how, like, let's tie the things together, right?
So like if my job is, you know, John, network security and connectivity, there's aspects of that that address one particular audience that makes sense. Building that platform to also do your vulnerability scanning, maybe less so, at least in a larger org. Mm-hmm.
You know, rich, one of the things that comes to mind too, as you're describing that those evolutions we've gone through is, you know, when, when things were in our network or our data centers, you know, we could, we know what they were, we could decide this is it as I'm gonna standardize on that as much as I can, whatever it might be. And today's world is, especially with acquisitions and multiple cloud providers, or you're doing migrations or whatever it might be, the underlying what what you're using as well as the security and the network fabric is changing it. It's on an ongoing basis.
It isn't a point A to point B. It's a, it's a fluid point A to point B and beyond, right? Even to the point of, um, mentioned developers.
And now I have a good friend, uh, Donald Lus that, uh, Alan and I know, and uh, he told me once he's, he's an architect in cloud, uh, cloud software guy. And uh, he said, you know, I can, I can tell in a moment when, when a product has been built by people who aren't developers versus products have been built for developers. So even taking what you said about the ui, same thing goes with the, the products that you're delivering and the way you're delivering that.
Um, if it's a very developer centric delivery portal, here's the APIs, all the stuff you'd be used to, you'd expect if you were going to GitHub or CloudFlare, that makes a big difference in that adoption. So you're serving different customers for security for that network functionality. It, it's just a different world that we're, we're trying to manage all this in, I guess is what I'm trying to say.
Make sense, Would Shannon, I'm gonna, we were like teaching people, like security people. Here's what a poll request is and Yep. Yeah, I mean, I, but I'm gonna chime in even further.
'cause I actually think the root cause of where we are right now in this space is maybe even based on just one concept. How many of the, I'm gonna put quotes, cybersecurity products are framed on compliance IE when you go to them, do they have NIST compliance with a framework? Do they have the next framework?
Framework, right? How many of those products also have an adversary lens to them? Like, Hey, we can help you with script kitties and we can help you with phishing and we can help you with maybe money movers and we can help you with, we can make some of that better.
And it's an adversary tone, right? And I will just tell you, I've looked at a lot of products. I spend a lot of time in the market looking at all these things and I'm like, I have a list, a running list of all the products I call compliance products and a very, very, very small list of adversary management products.
And I think that's actually where we've gotta get smarter is to, I am like, I'll totally align with you on that, rich, but I think smarter in my mind is if the product vendors out there are listening, you better have an adversary story. Because if you don't have an adversary with story within 10 years, you're gone. I'm just gonna tell you right now, what I see coming is zero trust is gonna be based on, again, your total addressable market minus x.
And that X is actually really important to the top level leaders of the organizations. When they get smart enough, we actually educate them on what they have to really focus on. They're gonna find out that compliance is an all company problem.
And cybersecurity is a very specific adversary management problem across many capabilities, but still recognizable in a different way. Like you could put all the compliance in that you want, you're still gonna get breached. Tells me that you're not building cybersecurity resilience based on what your adversaries are.
So this is a good point you make because I think compliance tends to motivate the writing of the checks for big dollars, you know, in spend in terms of cybersecurity tools because the CFO has a problem that he or she needs to solve. It's a compliance problem, but it doesn't always make you safer. It doesn't always make you more secure.
It doesn't always, uh, build the resilience. The, The lowest common, I used to call it LCD security, right? Lowest common denominator security.
It's the bare minimum that then maybe won't find me negligent, right? When I Know actually it's different than that. I'm gonna just tell you, having worked in software organizations, companies that sell software to the public, right?
It, the number one thing that you have to have to be able to be procured in a procurement process is you have to have compliance. You have to meet the NIST standard, the this standard, the that standard, right? So all of your motivation as a software manufacturer is towards what number of software checklists do I have to get through to be able to prove to you that we have security enough.
My questions have been actually different, which is, Hey, by the way, how are you doing on script kitties? I can already tell you how you're doing on script kitties because I just saw n number of vulnerabilities come to the market and it tells me that your CICD pipeline didn't check for those particular security issues. So you don't have rules on specific issues that are actually leaking out to the market.
And by the way, you can now do that with bug bounties. You can do it with a variety of what I call the shield rights. If you're, you're actually testing your software.
If you're testing it in production, you're already too late. But it tells me that if you're re if you get any results and you're actually testing your software, what's broken is your shift left? Yeah, What Shannon just said, I want to share.
'cause having been on the vendor side or still am as well as being on the buyer side, it's heartbreaking. Uh, because like we at one point built something that was an adversary focus thing and all anybody wanted to know was if it had CIS in this compliance and you can't get through the sales process without it. Years ago I wrote, uh, before I was even doing the vendor side of stuff, when I was more in the analyst role, I used to be a Gartner in my deep pass, uh, I wrote a note that said, your vendors lie to you because you tell to, and it's a dysfunctional relationship because the RFP will have all these things in there that you want and including a large chunk of compliance things.
And you're not gonna look at the vendors that don't check those boxes. So the vendors lie about their capabilities because they have to get through the procurement process. 'cause the vendors know what their customers are really using in their products, and it's a tiny fraction of what they actually have to build.
So it becomes very hard to provide all the value you want because of this exact reason. So I, I love the way you talked about it, um, with the adversary versus the compliance, I think it's become a travesty that it's nearly impossible to sell a true security product because everything has to have, you have to be able to generate a compliance report. And, uh, yeah, This is great.
And I'm gonna tell you one, I'm gonna tell you one more thing before we cut over to John. I'm gonna just say thank you CloudFlare, for actually having great bot protection. That's an adversary.
Hey, because bots don't mean you go there with Issue. Well, if you look into every WAF and all the different stuff in there, thank god that we have products that are actually bot protection. And guess what?
A bot farm is actually an adversary. And so if you're actually putting something on the internet, thank you for being adversary minded in your product because it's one of the few on the short list, like I said, that actually has protections. Now, I wish you would frame it up as we have bought protection and that's an adversary.
Um, I, I would love to help your marketing department understand that you could sell adversary. It might, there might Be some folks are listening, they're listening just, You know, I might as well use my opportunity To your platform rights, Shannon, take a position on things Having mapped out like 30 plus adversaries for some of the organizations I've worked in that is actually the real market is in those areas. And we've got more than we need compliance products on the market.
Like seriously, if you wanna talk about consolidation, just put all your compliance in one area and like, can we move on and actually get to adversary mindedness? Because then guess what? All of the money that's leaking out of our organizations to the adversary is gonna slow down and guess what?
They're gonna go find new jobs. Yeah, absolutely. John, I'm gonna let you go then we have no, I was Just gonna mention in terms of that, that idea of adversary is that, you know, this is really where CloudFlare, uh, and, and our basically our zero trust platform, our, our ZTNA and our secure web gateway products, uh, accessing gateway, they were born out of the need to defend CloudFlare from the adversaries that were constantly attacking CloudFlare and trying to, uh, take advantage of, you know, somebody on our team that might be, you know, uh, have a lapse in in attention for two minutes and click the wrong thing or open the wrong window or hand over credentials.
We needed tools that would protect us so that we could protect you. I mean, this is really where that was born out. We couldn't go out and buy an off the shelf product because it really wasn't designed for the scale or the types of adversaries that we have.
I mean, we have some of the most sophisticated people out there trying to attack us governments, um, and, and you know, cyber crime organizations, nation, states, supply chain, they want in, right? And so we built our own zero trust and that's really what turned into the product that we have today that we offer to everyone. So, uh, we do think that way by the way, that a adversarial, uh, model really suits us well because that's, you know, what we're up against every single day.
I, I want to grab something from the audience 'cause we've got something, someone wrote something finally, feel free to write. Cool. But Paul Paul said, Hey, consolidation is a necessity and I think we're all on that page right now.
But he says it's not just about strengthening security, but really consolidation is, is about, you know, in the era of belt tightening, not just belt tightening. Many of our friends got laid off this week, whether they're at Intel or Cisco or, or other companies. This, you know, and then this has been an ongoing thing in the tech field now for a year and a half or more, hundreds of thousands of our colleagues have gotten laid off and it's not easy finding another job.
Well, part of that belt tightening, part of that cost cutting is executives are saying enough with the security trinkets enough with the latest security thing, let's consolidate the 17 or 28 security. I forgot I saw a survey once, security tools, we have however many security security tools we have. Let's consolidate that down to something more manageable.
So the problem with that is, is that when the executives want consolidation to reduce costs, it, they're usually paying the same for the products. They just want to pay less people to run the products. So it's actually being used largely to support workforce reductions, not just for contractual aspects of it.
I'm seeing very low percentage savings when you're consolidating into a security suite and instead it's getting rid of employees. Well, I'm gonna, I'm gonna chime in because I actually think that some of the issue is that we have the need for security bits. I'm just gonna go back to, to this compliance thing I've been on.
'cause I I've been studying it for like two years now. So you've got a whole bunch of like me sharing stuff I do. And by the way, we secure ourselves too.
So I'm really, I get the CloudFlare stance, which is build products that actually secure you. But let me kind of chime in here, which is the, the security that you're gonna build into an organization, right? When you have all those different things overlaid, you have a pro, you have a product suite that's covering an inch a inch across a very large breadth of problems because you're trying to, one size fits all it.
And by the way, the CEOs and the boards and the folks that are in finance are starting to realize, because they're getting into the procurement practice, they're actually looking at like, well, how many different requirements does this particular product cover? And so if you've got a lot of overlapped products, you're gonna be able to do that inch, you know, deep and really significantly wide, maybe strategic covering of everything. But you're not gonna get very deep, which means you're still gonna see security incidents mounting, you're gonna see like your metrics are gonna totally show the picture.
And the more we get metrics minded, the more we're gonna have to shift our strategies. That doesn't mean, like, I will tell you, I've worked in organizations where I've actually been responsible as a business leader and made some of those decisions. And it's really hard to cut a function that is actually keeping you away from a multimillion dollar issue, proving it's a multimillion dollar issue.
Waiting to happen is actually half the battle. And so I think that's where like our stories are, hey, we, we have this gap from this checklist on compliance and so now we have to have x, y, Z product to fill that gap. But then there's nothing behind it.
Like, it's like, well, it's an auditor issue. And so, you know, the, the folks that are making these decisions for cutting jobs and things like that are actually looking at, well, don't we have like three of the same thing? Couldn't we just consolidate to one?
That's how they get to the consolidation scheme. Yeah. In reality, what I'd love to see is more folks moving to the parts of cybersecurity.
So you're in a job, you wanna actually, you're very passionate about CTI as an example or threat intel. Find an organization that's doing threat intel well and join them because they're gonna go much deeper on that problem space and help us do things like you look at some of the major threat intel providers out there, think God people are actually navigating to those jobs because that is gonna give us better capability commercially. And I think we just, I think we're out.
I think honestly the industry and cyber is just unbalanced and we've really gotta resize, rebalance and actually set up because I do think that in some cases there's not enough people for the jobs that we have that we need. And at the same time we have just too many people in some segments of the business. Yeah.
And so that's where cuts are easier to do. Yeah. They, you know, they talk about the cybersecurity gap or you know, this idea that we, we don't have enough people.
And it may be true in some places, but I think it's also just, you know, rich, you mentioned the, the budget cutting and the, the, the idea that some of these efforts are to take people outta the equation. Well, even if that, we don't know necessarily the, you know, if we go all the way back to the sort of root cause of all this, what the why, I mean, maybe it is the economy, maybe it is companies trying to, you know, increase their efficiency and get more profitable or whatever it is. But nonetheless, we're still left with too few, too few people to run too many tools with too much complexity and too many moving parts and more adversaries than ever and more complexity and more, um, you know, just chaos, right?
And so I think we just need to figure out some strategies to take a little bit of that chaos outta the equation. That's really what we're trying to solve at CloudFlare with this idea of connectivity cloud is to bring more of the coverage, you know, in terms of the threat landscape and covering your web sites, your web applications, your APIs, your, um, external attack surface that's vulnerable to the bots, your internal users, your email inbox. All of those things need protection.
And the more that we can do that in a single platform with a single dashboard or, or API, the simpler it gets for the engineers and architects and analysts that are left over even, you know, if, if there are layoffs, there's somebody that's gonna be left over running this and we just want to make it as simple as possible for them. You're consolidating around a single general function. In other words, like largely what what you guys have consolidated around is a smaller audience.
It's not everything security. It is, we're gonna focus on making these parts of security simpler, which is where I think consolidation makes sense and it's not where a lot of the, the bigger vendors go. I mean, a lot of this is if we look at the fundamental dynamics.
So, um, I used to work with somebody who said, oh, security, our job is to skate ahead of the p the puck, right? You know, the old Gretzky quote. Um, and to get ahead of where things are gonna change, which is impossible because if you really look at what we do, maybe this, 'cause I've got a background as a paramedic and a firefighter.
So I, I come from a response oriented culture where not only can I not predict what's gonna happen next, uh, I really hope it's something interesting this time. Like I'm really tired of the drunks that fall over and have a head laceration. Like, let's go, give me a gimme, you know, childbirth in the back of a taxi.
Not, not me, because I, I can't work that way, but, um, so sorry, I I, a dead pulled joke came to my mind, I'm not gonna go there. Uh, so, but in that talk I said we can never skate ahead of the puck because as security professionals, we don't control our destiny. And this, I think Shannon ties into some of your compliance aspects.
So a lot of compliance is let's set a standard that takes years to get everybody consolidated on, and that's gonna be our baseline. Well, with security, we have three things that are why we're always running around and we're always having to buy new garbage and we're always having this exact conversation we're having. One is we don't get to control the adversaries.
It is their business to come up with new ways to exploit our organizations. That's their job. Uh, whatever they really needed a better career guidance counselor, but that's the choices they've made.
But that's what they're always out to do. Look at physical crime and we still are coming up with new innovative physical crimes on a day-to-day basis. It's not gonna change for digital, which has only been around for, you know, 30 ish years, 50 on the long run.
So we don't control the adversaries. Two, we don't control the business. Business is going to adopt new technologies for competitive reasons.
They're always going to, uh, you know, be wanting to use new things to innovate. A lot of the stuff John, you guys are dealing with is directly around there. Workforce, you know, uh, distributed workforce automation and new kinds of applications, new kinds of cloud workloads.
Like they're always innovating the developers. The ad like the business is always trying to do new stuff. We don't control that.
Our job is to manage the risk, but we don't make those decisions. That's not our job. And the moment, by the way, security people think that's their job.
Uh, see, equivalent to me as a paramedic, kidnapping somebody so they don't like smoke anymore. I don't know. And then number three is we don't control our technical debt.
We have, oh, we're always trying to keep everything up to date. You could be on the latest greatest and the new zero date vulnerability is gonna come out for us. Like, we don't own that either.
Like we just can't control that. And if you think about those three factors, that's always going to force us to be responsive, to be adversary minded versus compliance minded. 'cause the moment you think that a compliance, it deals with none of those three unless you shut your business down.
Yeah, I definitely agree with you. I I also think consolidation's gonna happen around five major pillars. Like when I think about cybersecurity, and then I also think about compliance.
So I'm gonna just tell you, I think compliance is its own thing. I think it's gonna continue to become more of its own thing. I think if you wanna do compliance, like you're moving in that direction, I think it's gonna have its own consolidation at some point.
Um, I'm seeing more of that, but I think in the cybersecurity domain, I think there's five major pillars. I'll just tell you what they are. I think you have to have adversary research.
I think that's your predictive capability. I think it's actually also your level five maturity. I think if you wanna continuously improve, you're building value chains based on adversaries.
I think your second pillar is gonna be control development. Why aren't you defensive modeling? We all, we, we've all learned from Adam Schack, we should do threat modeling.
And frankly, I think he is right. I think though that those can't sit on the shelf and they have to become part of your test plan. I think your third pillar is gonna be threat mitigation.
I think we actually have to have a policy enforcement point in the cybersecurity domain that makes it so that if something's gonna be bad, we have the way to like shut things off, do an and on pull cord and we can actually get to it with precision. So I think that if you're doing that, and I see some of what you're doing at CloudFlare through that, I think the fourth major pillar is gonna be control verification. If you're gonna build something, you better verify your controls and you should do it from an adversary lens.
And I think the fifth is gonna be incident containment. You know, when all else fails, incident containment has to capture all of these things. Make sure we restore our assets so that adversaries stay out, they get rid of unauthorized access.
And I think our biggest problem as an industry is that we don't start with how many incident hours do you really have to bet on your risks that are being created every day within the organization? Because I'm just gonna tell you, I think the reason that SOX are overloaded, those security operation centers are overloaded is because the incident containment time is not enough for all the risks that are mounting because people aren't doing the security job upfront. Right.
Got it. Let's Add in skills and staffing because we, I I think largely we've now siloized security to such a, and we have such a high barrier to entry to become a security professional and then it becomes very focused on a short set of tools that have set your career path versus some of the basis that's become like a pet thing for me in a, in, in various ways as well. I think making sure that both the general workforce, and again, this stuff, Shannon and you, we have talked about this for a decade, uh, of developer training and the whole DevSecOps concepts, but also our, our security professionals.
Like we need to also not make it, uh, some kind of special club. We have to have actual on-ramps to be able to support. We need to do that gives this adversarial thinking and the broad knowledge and being able to apply and work in multiple roles instead of being locked into just a tool.
Uh, you know, back to some of these, you know, uh, challenges that you've thrown up Shannon in terms of, um, you know, vulnerabilities and managing, uh, you know, through those in terms of companies, companies spend a lot of time patching things, right? We still have, look at the recent list of vulnerabilities and how many of them have been related to either a firewall or a VPN or some sort of thing that was supposed to make us safer, right? It was supposed to be a a, you know, a tool to prevent problems, but it creates problems, right?
And so we ended up spending a lot of time not responding to actual security incidents, but spending the time trying to patch the devices that were supposed to do that. And I think that's another benefit of consolidation onto something like Connectivity Cloud CloudFlare, is that we take care of a lot of that in terms of the, um, you know, what, what, what would've been spent time for by a security engineer or a network engineer keeping things up to date. And it allows people to spend more time on the security incident response and managing security and being, you know, sort of improving, uh, efficiency.
I mean, we, we have statistics that we have collected across our customers where we're seeing 29% improvement in security, team efficiency, 13% improvement in it, uh, operational efficiency, um, 25% reduction in breach risk for web applications. These things are well documented statistics that we have in, in, in across num, numerous comp, uh, customers. And these are all because they've adopted a more coherent, uh, sort of unified approach to this and not relying on, you know, devices and appliances and a very d you know, sort of, uh, antiquated architecture when it comes to securing their environment.
So, John, that that's something though that I, I want, I was looking forward to asking you on here today. You know, CloudFlare not your average security vendor. For those of those out here who think of CloudFlare as a security vendor, this isn't your average one.
And for those of you who don't think of them as a security vendor, perhaps you should, but John, you, you take, your customers have such a, you wanna talk about, you know, security variety, anti consolidation, your customers have every security tool under the sun collectively, and then you have to somehow normalize that because of the service you're providing them. And granted, you sit in front of it, but it has to work somehow with what they've got going on. Yeah, it does.
I mean, you know, when I think back to what I saw in CloudFlare when I joined the company three years ago, is I saw the potential to solve this challenge in a, in a unique way. I mean, CloudFlare is not your traditional security vendor. We did not come from the, the, the appliance or the device world.
We did not come from the world of putting a piece of hardware on your premise and, you know, locking down with some, uh, rules and whatnot. We come from an a, a background where we're protecting the internet, basically protecting the web, protecting websites from DDoS attacks, bought it, bought attacks, uh, providing SSL across the internet, making that simple. And we come from a world where we had, we had to put infrastructure all over the world because of our CDN routes, right?
And DNS and running those things in a very distributed way and the world skating to the puck. I mean, they're coming our way, right? The world is coming our way in terms of being more distributed and having to apply policy in a distributed way and, and do it near where the end users are.
And having 330 different locations in cities around the world, 110 countries plus where we have infrastructure, CloudFlare positions our infrastructure strategically so that we can block those threats near where they begin. We can apply policy around the world and then we do integrate with what you already have. We integrate with your existing identity provider, you know, zero trust.
The, the core of zero trust is the identity. Who are you and what should you have access to? And what kind of a device are you on?
And is the posture of that device, uh, in good shape. And so we have to integrate with endpoint uh, security products. We have to integrate with all the IDPs.
We have to integrate with the sims and the soars and the tools that are gonna consume the logs out of Cloudflare's, um, global data centers. We're going to integrate our threat intel that we collect at that 330 different sensor points around the world, and we're gonna feed that into making our products better so that we can adapt and we can stay ahead of the threats. But yes, absolutely.
We don't stand alone. We're, we're working. I mean, this is a team sport.
We're in it with everybody else in the industry, but we just want to take as much of the, the pain out of deploying in that model of that distributed architecture as possible and not dig the hole deeper with more devices and more appliances and more point products and more isolated pieces of data. We want to get it in one place so that you can see it and you can act upon it. Not an easy test though, right?
I think we're up to it. We're Up to, John described a very, very hard problem. Um, guys, we, we've only got less than five minutes left, right?
And I, I just wanna make sure I, it was a relatively quiet audience today, and I apologize, it's not usually this quiet. And, but luckily we had no shortage of things to talk about, but I, I wanna tie a bow on this, right? Bringing it back to this connectivity cloud and this last great cloud transformation.
I think part of it has to be that we do better with our security. And that may in fact mean, Shannon, to your point, we consolidate around stuff that's important. Adversarial, right?
And that plays right into, I think what CloudFlare spends a lot of their time on adversarial. Um, but we, I I just also feel like, you know, I used to be a big proponent of shift left, and now I'm a bigger proponent of shift everywhere. And it may be impossible, but, Oh, no, I know, You know, but it another round table.
Well, maybe that'll be the next one. But, but we need, when it comes to security to shift everywhere, we, we've gotta be on the edge. We gotta be on the endpoint.
We gotta be in the core. We gotta be in the network that connects all of these disparate parts. We've gotta be at the developer, the richest point.
We've gotta be at the testing that whole CICD and deployment. We gotta figure out how to secure, you know, while we're using ai, make it our friend, not our foe. Are we setting our, is this IPOs, is this impossible?
Are we just like getting ourselves and it's consolidation really a way we can get there? Shannon, you're shaking your head. I, I don't want to pick on, I, I think, I think that consolidation is entirely possible.
I think that, uh, going back to my major points, I think you've gotta start with who's the adversary or even a category of adversary, and what is it that they're doing, and where are they doing it so that you can build the right policies, and you've gotta have policy automation and enforcement points so that you can actually create the valued story. I think that's a number one from my perspective. And I think that without that, I, I think honestly, some of these like hodgepodge stories are really gonna, like not win out.
I think over time we're just gonna continue to see more breaches because, you know, I will just tell you, I'll, I'll show you this, which is compliance and security are not a perfect Venn diagram. So like diagram, we've got to change the, the narrative across the industry. I do love products and vendors that are actually starting to realize that the greatest value to the top level of an organization is how many less adversaries, how many less incidents do we, where are we going to have because of what we put in place?
John, I'm gonna give you a chance and then I'll give Rich. Yeah, I mean, I think you asked the question, is it possible, you know, I I, I think it's impossible if we don't reduce some of the complexity and take some of the, uh, the difficulty in managing all this. Otherwise we just end up with Swiss cheese, where every, everybody can make their way through somehow.
Um, you know, the, the simpler we make things, uh, in terms of what we have to manage, where we have to manage it, where we have to control it, the more automated it is so that we can't make mistakes and, and, you know, the human element, uh, you know, we want to drive more potentially over time. You know, with, with the help of ai, the only way to do that is through an API. You can't, you know, throw an AI on top of a, of a, a, you know, a legacy firewall and hope for the best, right?
You have to actually have some tools that give you, um, programmability and composability and the same kinds of things we took from cloud computing and cloud storage. We need to apply them to cloud networking and cloud security. And I think that's where we start to make the potential headway towards solving some of this.
I, I don't see any other way to do it. I mean, it, we can't throw bodies at the problem. We can't throw people at it.
That's not gonna happen. Um, more tools doesn't seem to work. Um, you know, more money.
I mean, you know, if you had more money, what would you do with the money? Right? And so you'd really just want to direct it at the things that have potential, uh, large impact.
And we, we think connectivity cloud and some of this consolidation that we've been been talking about is really, uh, the approach that, that we would argue is the right approach. Rich, Look, everything we're doing is we wanna deliver better outcomes. That's the goal.
From adversarial thinking to consolidation. It's about delivering the outcomes. How do we do that?
And in the end, today at least, we haven't given into our machine overlords. I mean, personally, I already have my, uh, surrender letter, um, written, but the, we haven't given over to the machine overlords. We still have people that have to get a job done, and their job is to deliver those outcomes.
So I think if we think about consolidation as a means of doing, 'cause I agree the complexity is off the charts. So if we target it properly into the right pillars, we have opportunities to help somebody get their job done better and faster. What we don't want to do is try and build one thing for everybody to do every job.
That's just not gonna work. And think about it in the real world, we have police, we have firefighters, we have paramedics, we have social workers. The moment you make the cops, the social workers is when bad things happen in the headlines.
And that's kind of what we've been trying to do with some, some people approach the problem that way and others approach it like what John is doing, where this is the set of things for this described audience that we're gonna focus on. Excellent. Mitchell, we're at the top of the hour.
I, I don't if you want to say something real quick or, I think the guy, the, the panel here has said it all as far as i, I I think They did too. I could, I get waxed on, but I think we've covered it. Have some really good ground Guys.
It's, it's, this was everything I was hoping to have with this panel. Smart people talking about smart things here. Um, I just remind our audience, we're going sign off here, but the last great cloud transformation is available on Techstrong tv.
We've got two episodes already done. This will be a third actually. I don't know if the second one aired yet, but check it out.
Follow it. We're gonna be exploring a lot more of this stuff in the coming weeks and months. Shannon, it is so good to see you.
Thank you so much for having me here, Rich. It's always good to see you too, man. Awesome.
Thank You. I have it in too long. Well, RSA but we'll, we'll, we'll talk soon.
Until then, on behalf of CloudFlare and Textron, thanks for joining us today. Bye-bye everyone. All right, I gotta run.
Thank you, Alan. All right, bye-bye. End webinar.

