The speaker discusses a transformative moment in cloud security, emphasizing a shift from merely detecting threats to actively enforcing secure architecture and policy alignment. He shares his personal journey, starting with a childhood shaped by ambitious parents and a brother who was an entrepreneur. At 18, he joined a prestigious military unit, where he gained deep technical and organizational experience, eventually leading large teams. After a decade, he transitioned to Harvard Business School to build business acumen, then joined AWS to lead the launch of Amazon GuardDuty. There, he witnessed firsthand that while detection signals were present in most breaches, they failed due to poor operationalization and process gaps. He also observed the growing complexity of multi-cloud environments. Motivated by a desire for greater challenge and impact, he decided to start his own company. The key was assembling the right co-founding team, which included colleagues from AWS and connections from Israel. His startup aims to solve the fundamental, platform-level problems in cloud security that previous point solutions have not addressed.
I think that it's in cloud security specifically where to I think unique moment in time where we're in a trend Formational stage is room for what was before like it's not right now yet replacing like bears like we need the visibility We need a detection but we're at this stage where we're ready to move forward into more of an active Doing secure architecture policy intent matching, you know, what the environment should do to what it actually is You know built and architected to do I think it's a fundamental shift that we're right there now like at that like on that edge We're at that pivotal moment to really move things forward in a dramatic way that hasn't happened and probably a decade in this space Amit thanks for making some time for me today for sure always so you and I have known each other for a little bit now a Couple years, you know on your journey with native and we'll talk about that You forgot the first time we met if you say a couple of years Wait, what do you mean we go back? I think it's at least five or What but we didn't spend a lot of time Okay, I'm just like pitch to you back then, but well you're gonna say that and then you forget I'm an old old man at this point I got those senility things you young folks that actually have memory Still I will wake up and I will forget what I did yesterday. I'm kidding sometimes that's for the better So says my wife, okay, but I'd love to kind of go back Yeah, and walk me through just your background, you know a couple things just your background and I know you served in the military Up till when you decided hey, I want to do a startup. What was that journey like what was growing up like for you? Sure, yeah happy to to take a step back and think about that first of all like a I think like as Probably a lot of people like I owe a lot to My parents in the way it was bought up like it was always like a house full household that sort of you know pushed us to Do what we want to do and what we love to do but also like push us to be like ambitious and to think big and You know Very proud of like my upbringing my parents and then what that taught me and my siblings and what they're doing in life So it so you know, I think those things start from that ambition starts From the home I also moved around a lot as a kid my father was in the foreign service and and I lived in different countries But but then yeah like I think the oh and and to that point also like my oldest brother was already an entrepreneur He's he's much older was so as a kid. I already saw had some model as well of that as well at home But yeah, you're right like it's like the pivotal moment is at 18. Sorry. We're gonna know You got me thinking so your parents pushing you to excel was hey go do a startup or Doctor a lawyer, you know one of those you know if if if you're on this like You know my brother that I just mentioned he was did a startup in the 90s. It was sold to Microsoft It was an executive and like a Microsoft 25 years is actually doing a second startup now my sister my older sisters like like cello a cellist and a cello professor and Performer and my older brother. I'm the youngest is Economics professor in a university so totally different things we were never pushed to like in a direction But we just you know, I think had you know Just a good home and good parents to learn from and to see and to like push us to do what we love to do and to be ambitious in that and So yeah, it's crazy. I'm gonna have to hang out with your parents because I'm sorry It's like they put like this is this is amazing. This is gonna take a turn Oh, please they both passed away over the past few years and like that like also like keep keep the keeps driving me as well like but But yeah, it goes I think like it goes goes back to there and Then yeah like 18 joining the army was a pivotal moment I joined like a lot of founders in this industry in the space eight eight two hundred at the age of 18 literally like I was the first sort of recruiting cycle post high school so I had like my high school graduation in a week later I enlisted and pretty much been working ever since so and and I think the unit like a two hundred It just opens you up to a whole world of What is possible and you're just Extreme level of a responsibility and trust it's rust on you at like a very young age And I have like vivid memories from from of like different projects and different things that I was part of and Eventually led going to officers course in a day just you know 19 or 20 already litig a 15 person team at age of 23, you know 50 person team in a day just 25 for it, you know, 150 person organization. So it just gives you a lot of confidence in in your ability and and just put it both and both Technically you learn a lot and but but I think even more so just organizationally at a very large age get exposure to what Management and leadership and organizations look like so so that was definitely a big part of it and then also like it Pulled you into that ecosystem of the startup mentality and I mentioned like some of it I suffer from home But you know, you're you're at the unit. I was there for for over a decade But a lot of friends that left that discharged over the years that was there went you know into startups started their own companies so You get into that ecosystem and you see and and you see that it's possible it opens up that opportunity for you I Amazing years and amazing experience there and and very proud and happy for what I learned there but I got to a point where I had to decide like am I all in on this or am I going to go a different round on the military? Undemilitary, yeah, and I decided that you know go a different route and I remember You know it was sitting with friends. I was Around you know Getting to 30 and sitting in you know friends in the living room I was still the military they were already like decade out more or less doing different things and It have great experience great exposure doing some of the most amazing like mind-boggling things and levels of Responsibility you can imagine at any age let alone those ages, but you know, they would say things like ROI or conversation I'll be like you know that sounds like Wrong way to spell the name Rue or something like that and So I figured there's there's a gap there and like a good way to make that transition was to go to Business school. Yeah, and you know hopefully you know it Harvard Business School would teach me what ROI stands for and it did so I spent a couple of years one would hope yeah spend a couple of years there and again like amazing experience opens you up I think if the unit like you go super super deep on like something very specific and it gets so much out of you like The MBA experience like just opens you up to Literally a world of possibilities and the people that are there coming from all different places and experiences and going You know different goals that they set for yourself and just the Exposure to to the level of education and the professors are so again amazing experience open opening you up and Continued showing you sort of what's possible and Then the next step after that was a joined AWS and And that's where things started to to click together like bring like the deep technical technological understanding and the experience in the worlds of you know cyber With the business side of it that I you know I had the education now, but starting to apply it more practically and I was very fortunate to Come into a team and lead a product or was just launching cold Amazon Guard duty and That was AWS. I think amazing school for entrepreneurship as well because very high levels of again responsibility I remember like day one. This is yours. This is the product you own it like what does it mean like end to end you own to P&L Work with finance who you're in charge not just the top line also the bottom line the product the roadmap the strategy working Was this straight out of school? This was straight out of out of business school. Yeah, I like a lot of Like respect for who was my manager and like it's I think it's into culture in Amazon to like ownership is such a big thing there and like You take it you do as much as you can with it. It's not for everyone But if it's if it's for you it brings out a lot out of you It was amazing experience You know, I joined and we're just getting started and when I left it was the And not just me like the whole team as well like it was a One of the fastest growing services in AWS history Definitely the most adopted in a largest security service for AWS a team that grew from you know maybe 10 to 15 Engineers that helped launch it into at least a 200 plus Person organization was multiple teams that we set up over the years and product lines within the product so Amazing seeing grows from within it was literally from like seeing Grows and going through a lot of growing pains through that from from within But really the I think the most pivotal thing that happened there
was the exposure to the customer base and to the problem space. From that seat I had, this is from 2018. So this is before anyone coined the term CSPM or CNAP yet, or before the large players in this space existed. I was already there seeing both the front row seat or the driver's seat and working day-in, day-out with the top security team, security leaders in the world about this on this space. But also getting to see behind the scenes, what going into the internal systems and seeing what is actually happening in cloud security behind the scenes. And it was that exposure that just got so many wheels turning over the years to, I think, really uniquely understand what are the problems and opportunities in that space. And there were just some things that fundamentally bothered me that as much as I saw the investments and new companies pop up over the years and do amazing jobs and grow phenomenally, we all know these companies in the space. And but still, I'd get on conversations with customers and still I'd see the same problems repeat themselves, both from the security and from a process perspective. And at some point I had that fundamental understanding that the opportunity to really move things forward would be doing it on my own. And sort of the things came together. They sort of that experience, growing up from home, from the military, building that business understanding and then working so deeply and closely with customers on such a specific pain point. And things came together where I felt, OK, this is the opportunity that I always felt was coming to do something on my own. And then the real missing piece was a team to do it with. And it took me about that that's when I said that we had actually go closer to five years back. It was a moment of time during my AWS journey where I thought now's the time. I felt this pain from the customers that I felt like I was uniquely positioned to help solve. And I started back then already working with different feces. And at some point they put me in front of you to pits. So all of that, just because you had a conversation and didn't know what ROI was. They had nothing to do. Did you have any competitiveness or do you have any competitiveness with your brothers and sisters? I would imagine with a not that you're all type A, who's but accomplished in various ways. There's a bit of really, what have you done? There's none of that. You know, no. I swear, yeah, no, it's a, I don't know. We're, we're, we're, we're geographically as dispersed as can be. Like we're like, I'm actually now my brother that was in Microsoft. He's also in Seattle, mine back in Seattle these days. So we're actually closer but my sisters in Wellington, New Zealand and my brothers in Glasgow, Scotland. So pretty dispersed in that sense. But no, we're close and it's very much not a, no, competitive between us. Are you telling me you don't send them a little emails of, hey, we got this fundraise? No, just pictures of the kids. OK, well, we'll have to think of something. I got to create a little friction. It'll be, no. Thanks God of me. I like, no, it's just, it's not there. That's not, OK, well, I mean, also, I'm just projecting my own family competitiveness between me and my sister. I think that's what's happening. That is exactly what is happening. We're getting to some more you and you. Listen, if she was here, it would be a problem. We'd be going at it. So Amazon, obviously, no question about the very accomplished company. We don't have to talk about that. But building out security capabilities for where companies are going to and hearing their problems and challenges you spoke to the consistent repeatable challenges that they're having, what were those consistent repeatable challenges? Yeah, I think like the there were a few things. One was whenever there would be sort of a breach that made the headlines or the lead here about internally. And guard duty was in threat detection. So it's very high level monitors logs who detect when is your AWS customer, your AWS environment account workload is potentially compromised. And whenever we'd see it, there'd be a headline we'd go for our own analysis behind the scenes and also work with the customers to see was there detection? Was there a signal? And you know, I say just not to say like 10 out of 10, but to leave like some margin for it to like 9 out of 10, there was a signal. And you know, it was always also a strong signal like you didn't need to be a super expert that understands the complete, you know, the exact environment to pick. You could tell this, this someone should take a look at this right now. And it was always on time as well. Like there would have been time to react and at least mitigate the damage. And I again, to not say 10 out of 10 and say 9 out of 10, the damage happened. They were the customers like kind of upset or at least looking to you to solve it. Yes, yes. I mean, the thing that was it was always around the signal was there, but the system was not operationalized in a way that allowed the system is not also technically. There was just a lot of plumbing. Like technical plumbing, you have to set up to make sure that, you know, it's operationalized and also the processes. And it was always that was always the issue. Like the signal was there, but it didn't make it to the right person, the right time was the right context and to actually do something about it was always around that sort of plumbing operationalization. And that was always also the conversation. You know, I turned it on now what like that's the easy part. The hard part is getting it to work for you. That's that's where it's sort of those wheels started to turn. And having been there and done that, it wasn't an AWS problem. All of the multi-cloud providers had the same kind of situation was that part of the conversations with those customers because nobody goes in generally into one provider only. They're usually using. Yeah, I think it was like over the years from within AWS and from like the like 2010s until like the 2020 like that conception of like single cloud is pretty much dissolved. And I'm seeing I'm actually like interestingly seeing that play out now from from our seed and native even more strongly where I'm actually just this past week spoke to a couple of C sort of large organizations. There were some of the very of the few that you know, we're lucky enough to you know, hold the line and the organization predominantly stayed single cloud. And now they're saying, you know, we know the time is up because we see where the world is going was multi-cloud multi-model. The business needs a foothold and you know, Google for some reason or just increasingly regulatory requirements for resiliency and what not where even those organizations are now seeing things going in multi-cloud direction. And that's a big problem for security. And it was back then that was also always some of the issues. Hey, we love the products we're building. They're very valuable. But we also have something going on in Azure or Google or elsewhere and we don't want to go to three or four different places to solve the same problem. And yeah, that was also repeatedly part of the issue. So you saw the problem consistently. At what point did you say, hey, I want to go off and solve this problem in a startup versus maybe solving it within AWS or otherwise. There's got to be was it, hey, I've always wanted to do a startup. You talked about 8200 and that ecosystem of seeing that it's more accessible. Yeah, because of others have done that. Was that kind of a motivation or creating it or? Yeah, there was. There was always a want to do it and a feeling that more into personal level, both the ultimate challenge from professionally at least, the ultimate challenge and with it, like the ultimate personal test, but also the ultimate and accordingly, the ultimate gratification, it would only come from there. And that there was like some ceiling that I was, you know, I felt like the ceiling, like I was already like, I felt like operating at like a very fortunate place and at a very large scale and level where I was, where I felt like not doing it on my own. Like I was already too close to the ceiling of that challenge and gratification, whereas doing it on my own off-site and like the ceiling, like, you know, there is no ceiling. Yeah. Well, see, I've been very close over like 30 some odd years of doing a startup and then I talk to people who do it such as yourself. I go, oh boy, no, that's a lot of pain and a lot of work. That didn't push you back. Or did you see others? You obviously saw others do it. Did that excite you or make you nervous? Does that make sense? Yeah, for sure. And I always worked very hard. I somewhat, I think, naively thought that because I'm already like, I could easily find myself like working like a 60-hour workday like regularly.
And then I already know what it means to work hard. And if I work this hard for a company, then I might as well work this hard for a company that I start. But it is fundamentally different. It's not just about how hard you work. The commitment and the product is completely different. It's also emotionally, because you're getting told no a lot. Or that's not a problem, or why are you doing this? There's a lot of headwinds of negativity, whether it's from potential customers or otherwise, as you're going through the process, or everybody you talk to was like, no, no, we've got to do this. I have to say, we didn't talk about yet. But as a team, I think both the team that we formed our experience and the space and thought that went into doing what we're doing, and put us in a place where going in, we know, like we, I think we're a position to hear more, yes, to know. - Well, why don't we talk about that? So when you said, hey, here's a problem, et cetera. How did you get the team, how did the co-alluid listen of the willingness, so to speak, and kind of walk through that, hey, this is something we want to focus on in this sort of. - Yeah, so I think like the sort of that original goal for it, I mentioned, I didn't feel like I had the right partners to deal with. I also felt like, while I was, there was that itch, was that pain that I was seeing from the customer base, it still was too specific of a problem, and I wanted to make sure, if I go to solve a problem, it's a big one that could be evolutionary and, you know, a platform play and not like a point. And both those things were missing, and they actually came together, 'cause. So, first thing was the team, like I was lucky for some of the years at AWS to work with Gaal, who's one of my co-founders, and he was leading also some of the AWS security products, and we met there, and then through common connections in Israel, I met A.R. A fine gold, I've known Zal for a long for a while, it was a CO of dome nine, and A.R. was the VP of R&D, led the Israel site for dome nine for many years, and that's how we were connected, and then they were sold to checkpoint, of course, it was a VP of cloud security, a checkpoint. So, that feeling of having me was my experience into space, Gaal, who is sort of like, just one of those guys who did his math degree at like 15, and was like the youngest major in Israeli military history, and led all of cyber trainings for eight one, and then did his MBA booth, was like a full scholarship, and then joined AWS, and then having a YAHL, who's seen this already play out, like the evolution of cloud security from the very start, from like was dome nine, and then leading engineering and R&D and product teams at a large public company scale, that sort of it was like, wow, it just felt so right, like we have the team to actually go after big problems, and then through that also at that early stage together, tease out what is that big problem? How do you, you know, how do we pull that initial thread that we all knew was there and turning it to something big, and it all came together. - Was there a timing question for you because timing is always part of this. You have the right idea, but the time might not be right. Was that, or that wasn't even a question going into this? - And for me, the timing had to do with, there's the right problem to solve that the market needs now, and I have the right partners in team to do it with. And those things came together and that meant it was the right time. - Interesting. - So how many, did you go through? - On any other way to time it, I think, and you constantly will delay it because sort of like, there's no perfect time to make that jump. But when I felt like it's the right team, after the right problem was the opportunity represented, that was the time. - And you'd already had so many conversations with that particular case potential customers because of the AWS, that typical, hey, we're gonna found the team an idea and go through that, ideation and kind of process. That was pretty part of the course we came from, right? - Like, over five, six years of like validation of like talking with, you know, practically every security team you can imagine, right? Like if you, you know, GarDuty was ultimately like adopted by over 90% of the top 100, 500, 2000, AWS customer, that pretty much equates to like, over 90% of the fortune, 100, 500 global 2000, like that's, you know, that's what it's like, AWS. So, so yeah, like I was the amount of conversations and learning I had from the customers before even starting, you know, it was unique. So I ask you, what is native, what do you do? - Yeah, so I was talking before how I felt there was sort of that thread to pull out and I started to touch about it earlier around, you know, helping operationalize that cloud security, what does that actually mean? And I think that the understanding we had at that point was that to get cloud security right, it's sort of all the tools that you need to get cloud security right are already there, you know, waiting for you to use. And that has to do with right, right, native, the CSP native security control. And then I think also part of that understanding, you know, we all operated in the detection and visibility space for many years in cloud security. And there was that fundamental understanding that the industry has reached that level of maturity around visibility and detection and moving more to the stage of, you know, a policy intent driven, a proactive, you know, more of that control, how do we actually operationalize cloud security? No more about, you know, visibility, but actually doing cloud security. And what does that mean to do cloud security? It means you, you know, don't come from the outside and you pointed what's wrong, you have to go from the inside and actually, you know, go into AWS, go into Google Cloud, go into Azure oracle Cloud and build the configure and architect environment with the right policies and configurations and controls in place, the native, the CSP native controls and policy engines and configure architect environment with security embedded natively into it. And that's what we do. We help bridge that gap between, you know, what is that policy intent? What should the environment be? What are the right guardrails in the environment to allow it now to operate securely? So I would, I mean, you know, going back to another point, having been in the seat for quite a while, when you look across the, let's take a, let's use a hypothetical, a particular customer or a particular company, you've got three multi-cloud providers, they don't all have the same native capabilities to drive policy and configure their infrastructure. Is that an issue? I mean, yes, absolutely. I mean, that's a core part of the issue is that you, we'll get into the single, like, what if you're single cloud in a moment? I think that's also interesting, but a fundamental part of it is I operate across multiple environments. I want to define a security outcome policy intent once. It could be, you know, we should only be, you know, running our applications out of North America, not other places, or my AI, you know, training environments should not be accessible from the internet 'cause it has no purpose doing that. Those are, those are security outcomes policies, intents to translate them into, how do I take that and turn that into an actual enforceable control at the CSP level from within? That's very different across clouds. There's one way to achieve that in AWS. There's a completely different way to achieve that in Google and et cetera, and you have now to develop expertise and know how in each one of those controls to be able to translate that intent into actual controls at the CSP level, and that's a huge problem for enterprises today. Even we're working with some of the best, most well-funded, like, cloud security teams in the world, and they're predominantly single cloud security team. To be able to bring a product like native to them and effectively turn them without having to spend the same number of years
and millions upon millions of investment that they have, that they developed into interdominant cloud and we can now extend that to their other cloud environments. It is very powerful. So, okay, so in that hypothetical, you're able to give parity on the capabilities, unify AWS calls it one thing, GCP calls it another to give that single dashboard of enforcement. Are there gaps in capabilities in that native concept that you're still seeing or, hey, no, 80, 90, 100% of what customers need of a policy enforcement, kind of perspective actually is native? Yeah. So, first of all, when you want to do policy enforcement, you have to go native. Like I said, you can come from the outside and you can point at what's wrong, but to actually architect an environment and await it and forces your policy, your compliance requirements, your secure requirements, I mean, you could build like, you know, proxies to like monitor every API call or network event that goes through, you know, into your cloud and decide what can pass or what can pass, but that would not be a very successful venture. Like, who can do that? AWS and they do that. They build those fundamental capabilities to actually, and then they build on top of that ability for you to actually go and manage it, but that's where a lot of the complexity lives, and how do you actually manage that at scale and across providers? So, and we see, and that's something around the timing as well. There's been tremendous investment from the cloud providers in those enforcement capabilities. If you go, you know, even four or five years back, the basic constructs today to enforce policy and cloud environments did not exist. If you go even a year back, a lot of the innovation into space from all cloud providers has been just in the past year, with new capabilities released, new policy engines released from across cloud providers. So, sort of the industry is maturing in that space where we, you know, we now know what, you know, what can go wrong. We know it's now about more about doing and enforcing, and also the cloud providers, you know, they're listening to their customers, and that's where they're innovating and building the capabilities to enforce it, and do things are coming together now. So, going back to this hypothetical, you know, potential customer, multi-clad environments, what is an integration look like? You know, starting from step zero to day 180, walk me through what that looks like. It would technically do a fair degree. And so, onboarding is super, like we are customers onboard in minutes, like by themselves, like they don't need a Sunday call to onboard. It's a mostly just a simple API integration, that they're already used to from other cloud security products that they use. So, APIs to the multi-cloud providers, like in the industry. Yeah, give us a read role to the environment, and increasingly, and this is big, like we can get into the right, like, be happy to discuss, like the whole, like the right permissions that we're being given as well. Because I think that is what is starting to move things forward, but giving us the role to understand and read the environment, and then pretty much instantaneously during all already the first POV call, you'll start to see, well, map your environment. We know having an opinion of what secure architecture looks like tailored for your environment by learning how you use the cloud, what is it used for, what services you're using, what regions you're using, what applications are running there, and then you'll pretty much instantaneously see already a mapping of what good security architecture for your environment looks like and where are the gaps. How are you able to do that pattern analysis? You're going to say I have 15 services, I go back to a company, I've been in, we have tons of them. You're coming in and passing judgment on the architecture of my service. There are, in some cases, maybe passing judgment is a little too harsh. Yeah, that one's a little like security guys. Yeah, and there are some fundamental things that are just very much best or basic practice that an environment should be architected in certain ways. Like high availability environments, latency, back channels. Yeah, even, I'll give like a simple example, it's usually like one of the first things we see customers implement. Some have already implemented, but it actually goes back also to like our duty days when I saw like a lot of activity going on, and a lot of malicious activity going on on a region's data centers that are out of use. So you predominantly run out of a couple of regions in North America and maybe one in the EU, but AWS has like 40 data centers, regions all over the world, South America, Asia, and Africa, and Europe, and they're all just sitting there open and anyone can deploy workloads and resources there, technically, and the same for Azure and Google and Oracle. And that's a huge attack surface. And we saw that over the years, like crypto mining activity, but even even sort of more extreme things where you know, reconnaissance activity, enumerating environments from these regions where no one's looking at, but you know, being able to then enumerate the regions where the actual data resides in. And then when you go to execute the expectation, you already know what you know and you can do it very fast. So we actually saw those things happen. So a basic thing now in sort of going back to where it was native, we'd come to your environment, we'd say, you know, we identified that you're actually using these set of data centers regions across your, you know, three cloud providers. Here's all the ones that you're not using and we do the analysis and we make sure that it's, you know, it's safe to make that recommendation. Here's a very easy effective way to lock those down. And now it's not, no one should be running workloads out of, you know, Sao Paulo or Stockholm or whatnot. It's now no one can. And that is a very dramatic difference in an approach to security. And so, so that assessment 24 hours after API connections, or not even. So there I am. I've got a whole bunch of problems. You're telling me I should lock it down, apply policy. There's some, hey, migration from one thing to another. There's the typical here your issues. And here's how we can enforce it. How does that customer go from implementing those policies that you're recommending? Or maybe there's things that they want to do bespoke on top of our recommend. Yeah. Always room for bespoke. And we work with customers with very unique use cases. And first of all, we'll like identify even like, are there current, like, what, when, when I say what's your current state of policy and controls in the environment, there could be custom things you've done will identify those and be able to translate those into natural language and give you like a view of what is your effective policy, even if it's something custom to you. And not you said like another typical here's the list of issues. No, like no, that like we're staying away from that. It's not here's your list of issues. Here's another list of, you know, things you have to go fix that is not our approach. It's more here opportunities for you to deploy more secure architecture. And, and very much not another, you know, visibility tool. So we do that first step, like you said, that discovery, the define, and then we'll help guide you. And here's some initial policies, controls you should implement. We will, and then this is a very big piece of it because everybody wants more secure architecture, right? Like what's the alternative? Now secure architecture. Like right? It's just so logical. But a big part of it is that security that wants to drive that secure architecture is always sort of has at least one hand tied behind the fact, what am I going to break? Right? Like if I am because this is not around like coming from the outside and pointing and saying, you know, this is wrong. And then security points at someone else. They say, hey, go fix it and create all that work. This is actually, you know, going and forcing real controls that define how the environment behaves. So of course, we understand that. So we built, we invested a lot of research and engineering into building simulation capabilities. So we can now tell security, here's your current state. We did that mapping that, you know, sort of like discovery stage. Here's a plan. Here's a policy control. You should implement. Here's a simulation. If you implement that in this specific environment, will it be impacted? Will it continue functioning as it has before? And if not, will help them identify why not and go and address that? So that unlocks a lot of opportunity for security teams. Well, I think it's also, well, my question along those lines is the security team historically are pushing a solution in place. But how do you bring along the rest of the business? How do you bring along the engineers, the product teams, the CTO office, generally running the multi-cloud environments configuration to get their buy-in.
There are process for that or is that? I mean, I think they say like, the business is in the business of doing business. It's another thing. - Wait, did you run that one by another thing? I learned in Harvard Business School. And not into business of security, right? And the end of the day, like engineering, they wanna build products and applications for their customers, their use case to be able to accelerate their business. The way it works today is that security sits from the side to have visibility detection. It's important, they need to know where the risk is to manage it to drive it down. But then they point it at engineering and tell them, hey, go fix those things. That's the worst part. Time to fix something is when it's already there, running and that creates the most work, the context switching for engineering. So the existing model is in great. If now security wants to go and define policy, which to start move things forward into more secure architecture rather than just detecting fix, they now go to their cloud team, their infrastructure team, and they say, hey, we wanna do a policy that does so and so, and maybe they'll give them the definition of how the policy should be implemented, and then they'll work with them to implement it. But this also puts now the platform team in the stage of like, well, can we implement it? Can we implement it? Can it? With the native approach, we give security team the power now to drive that change into organization and get a lot of points. Because now they can come to native, they identify what is the right secure architecture policy controls they wanna implement. We give them the full sort of plan, the recipe for it, they can configure it if needed, they have the step-by-step exactly how to implement it, the terraform, they, we give them the simulation, will anything be impacted. So now they can go to their platform team, their cloud team, and say, hey, here's the policy we wanna implement. Here's exactly how to implement it. Here's the terraform. Here's the simulation that already we did to show that nothing will break so we can implement it, and all of a sudden it's not throwing something over defense, but it's working together. They do that once or twice, and what we see already during POV sometimes, the platform team seems, okay, like we trust this, security you can implement, we give them the ability directly from their product to go and push the changes. And once that happens, that's magic, right? Because now security is actually driving secure architecture. Now engineering, on the other end, they start to see less tickets, less issues, less distraction, because they're now operating within the guard rails of that secure architecture, and they don't have to be continuously reminded that they're doing something wrong. And then there's the final piece, right? Because now the environment has a secure architecture baked into it, was rolled out, the simulation, what, you know, things constantly change. The cloud provider launched something new, and you need to update the policy. Someone went and changed something, or maybe someone adored, there's a changing business needs. You know, go back to that example with the regions, you lock down the Singapore region, because that's not where you operate out of, and you know, you're running like a 15 person, 15,000 person engineering organization in a company. And all of a sudden, somewhere there's a business need, and something opens up, or some M&A, and all of a sudden someone tries to spin up something in the Singapore region for legitimate reasons, and they can't, because there's now an enforced policy, not a, you know, you shouldn't, it's a, you can't. And where we come in, in that case, is, you know, instead of now just that developer getting, you know, blocked from doing something, they'll now get a notification, wherever they live, it's Slack, or Teams, or whatnot. Some of them, there's a policy in place that prevented you from doing it, but if you have, if you actually need to do it, you know, click here, you can ask for an exception, goes back to security, they can manage those exceptions, approve those exceptions. Something that at scale can become so complex that they don't even get started with, to operationalize, and through a native, that sort of closes that loop, or now that policy, we're speaking one, one of the, like, C-SOSF, the largest organizations around, is saying, you know, policies are living breathing thing. And that's how we think about it, it's an operational model, operational system, and that sort of closes the loop. - So you're at this point, you're out, you've got great customers. What has been one, or maybe two, of the most, I didn't expect that kind of moments? - Like, I touched on it earlier, but that, like, the first time that we saw customer, from the start, we put the button to, like, apply policy, implement for me, sort of that button, and it was from the start, we said, like, no, philosophically, like, it's gonna be their front and center. No one clicks it for two years, like, it'll be there, and they'll know they're not clicking it, and that they're keeping, you know, they're not, you know, being at the forefront of what is possible. And, you know, first design partner, first, like, POC, pretty much, like, first, you know, not like week one, but week three, and they clicked that button. And they actually, this was magic for them, 'cause the C-SOS, the security, the Cloud Security leaders, in that organization, I think it was the first time where they actually moved from, you know, made the environment more secure. They spent years in Cloud Security, it was the first time they actually did something that resulted in the environment being more secure. - Now, in this particular case, did they all get approvals from the environments and said, hey, we can do this? - Yes. - Yes. - Yes, exactly, through the process, they mentioned where initially they'd go to their platform team, and they were supposed to change it. But in this case already, yes, they went, they had their change management, meaning, or they got their approval, but now the approval was, you can go and implement it. So they actually clicked it. Fast forward, you know, a few weeks, a couple of months later, and now they're already through those simulations, through the trust they earned, they don't have to go every time. If it's a bigger change, if it's a more fundamental change, maybe yes, but if it's, you know, more, you know, weekly sort of day-to-day policy updates, they already just do it by themselves, and they have that trust both in us and from their counterparts. - Interesting. - That was one. Seeing that, like, click that button, I remember that very vividly, like-- - You must have been nervous, something's gonna break. - You're in a design partner, I mean, there was that part for a reason, right? - You see the, you know, wheel spinning, and no, but the result of that button being clicked was that there was a change, architectural change into cloud environment, and it's now more secure, and that, like, you know, almost like, comically, you know, doesn't really happen in security. - Yeah. Well, there's a couple of things about this. You know, the narrative for me is, we've been in a detective, corrective control set for a long time, and we haven't had preventative controls, creates a labor, excessive labor insecurity and other engineering teams. We need more preventative controls, you know, in a lot of ways, and I think we're starting to see them come up in the industry very recently, but the doing prevention is not an easy thing to do. Technically, culturally, and then, of course, if something goes wrong, especially with firewall management, everybody's pointing fingers at each other, like, no, you broke my rule. And so, from a development standpoint, at testing, at design a partnership, that implementation of policy, were you surprised that it was easier than you expected it, using this story as an example, 'cause I expected it to be right in line with what you're saying of, yeah, they're not gonna click that until you're free. - Yeah, I think so, man. - Yeah. And I think there's a, I wanna touch on prevention at a moment. I think like, I see things like, 'cause, you know, prevention sounds like what you can do. And I think, I like to think about, you know, it's a criteria about like, defining what you can do and how, you know, people, when you think about policy, it's, you know, it's not policy usually isn't about what you can do. Like, it's more around how things should be done in effective way. And I think like, we like to think about it in that way, but the end result in many cases is yes, like things that would have, you know, bad things that would have happened don't happen. And that's important. I think when you're asking like, you know, if we were worried to see like, what did I, and I think we're there. I think like security, like there's an appetite for it, increasingly. It's not for everyone yet. But early adopters, forward thinking advanced security teams, they tend to be like work at the, like the, some of the largest enterprises, 'cause that's where a lot of the top, you know, people in Dundes, we are. There's an appetite for it. There's a readiness for it. I think we, and then they, you know, they, they're waiting for it and then they meet us and we enable it. - Well, I mean, we've talked about paved roads and had these phrases for a long time of like, how do we bacon security into environments? Less about the security teams, every conversation I have with a product leader that'll like, listen, will you just set it and forget it? Give me that paved road and let me get back to building the product. But there haven't been any ability to do that outside of really significant labor and it's not really enforceable in a lot of ways. And it sounds like you're able to bring that, you know, statement to reality. - Yeah. - Is that a fair? - Yeah. - And but it's really, you know, there's words and then there's actions. Hey, we're actually implementing those policies and reality for your customers now, which is really exciting. But the reason why I bring that up is it's less about the desire of the security team and more about the, oh my God, finally from the product and the other teams that own the services on top of the infrastructure. - Yeah, and even if you go a level above that to like the strategic view of the business, when you do something like that, [BLANK_AUDIO]
Now all of a sudden enable a business to, that strategically wants to go deeper into a multi-cloud architecture to do that. I've heard you know, CISO say like, we're predominantly, let's say on AWS, but we increasingly want to be, you know, have a footprint in Google Cloud. And in fact, engineering is there, they can go there. And it's, you know, now security can be maintained the same level of security controls and standards as we expand to Google Cloud. One option is to go and spend again, like build the same level of expertise and you know, build out the team that you built for and everything. But the ability now to use native, and we're here, I'm hearing from CISO, the saying to go to my CEO, to my CIO, CTO board and say, hey, if the business needs to be to go to Google, they can go to Google. Like, and we can support that. We're, and you know, sort of, I think about like a multi-cloud multi-model world and security being able now to strategically go to their leadership and say, we can go into cloud wherever we need to go to meet our business objectives and we won't have to compromise in security standards. And I don't need now to hire another 10, you know, cloud security experts and strategic. >> So, so I got to ask, I mean, there's, and I'm actually kind of curious about this. I don't know from the competition standpoint, typically there's incumbents and then there's other competitors startups. In your space, how do you differentiate? And from the incumbent, like just generally, because I don't think there's a lot of incumbents in a multi-cloud. >> Right, yeah, so that's why it's interesting. You know, there could very well be other startups. How do you differentiate from those competitors? >> First of all, I think like we, our experience allowed us to identify a unique pain and opportunity at a unique time where we were able to, I think, really trailblaze in that sense. And, you know, when you speak, you know, from say cloud security intuitively people think there's already solutions in that space. When we get to, you know, our approach to it and what we actually do and we speak with the, you know, the real practitioners and leaders that are forward into space, they immediately get it. There's no confusion that, you know, this is something unique. And then as expected, you know, what often happens is, you know, like when there is a unique opportunity in the market to move things forward and to help customers, then yeah, naturally like other companies will pop up, you know, to capitalize on that opportunity. >> Yeah. What is the one thing if you wanted the audience, what is the one takeaway that you wanted them to have about native? >> I think that it's a cloud security specifically now. Where to, I think a unique moment in time where that, and we're also talking about a lot with analysts and we're seeing them also increasingly lenient that we're in a transformational stage or is room for what was before. Like it's not right now we're replacing, like there's like we need the visibility, we need the detection, but we're at this stage where we're ready to move forward into more of an active doing secure architecture policy intent, matching, you know, what the environment should do to what it actually is, you know, built and architected to do, giving security the ability to, you know, security teams ability to do security and not just, you know, see like I think it's a fundamental shift that we're right there now like at that like on that edge and on that edge are like our early customers and partners that are mature into space and are like leading it, taking it forward everyone and like but it's picking up steam even going back a year, a year now I'm seeing like the conversations are, you know, across the board different the appetite for it. We're at that pivotal moment to really move things forward in a dramatic way that hasn't happened in probably a decade in this space. - Amazing. - I was like working with the cloud providers. I mean, you came from one, I'm sure the relationships are great. - I mean, I mean, it's strategic. Like that is one of like the most important things for us, right? It's like it's such an intuitive like better together story like we're coming to, - So they don't see you as a threat. - Oh, I mean, just this more like going to all the details like just the conversations across different business lines and different contexts that we've had was, you know, all four cloud providers just the past week is amazing. Like it's a deep strategic partnership in all aspects. Like we make them better, they make us better and we work very closely and we're building those relationships with them of course we bring some from our experience but you know, across the providers very deep. It was one of our earliest hires was a partnership in BD, lead VPNAMA exactly because we understood this strategic importance and to start that early and our customers are benefit, our joint customers are benefiting from it. - That's really interesting here because you know, there's one thing of hey, we can help bring in native to kind of provide that customer security. But you came from Gartid, you're creating the security capability, those teams don't go, hey, but we can do it for you or is it just a different value prop because you're going across multiple cloud providers creating that, I hate to use the word single pane of glass. I've always hated that day. But that single policy across all of them is that single control plan. - That's right, I think. But I think one like the ultimate goal of the cloud providers is yes, they want to build great security products and build a security business, it's a good business to be in. But ultimately they're into cloud business and what's fundamentally strategically important for them is that their cloud or their customers building on their clouds are secure. And that's why they're investing in the space and that's why they ultimately want their customers to use the capabilities that they're building in the ultimate way so that they operate securely in those environments and God forbid one cloud, offset in the cloud providers perceived as the less secure cloud. That's like number one and we help that, right? 'Cause they're building the fundamental building blocks to get security right in, we're helping customers put those together and operationalize them across providers. So everyone's benefiting. On top of that, it's yes, it's what you're referring to. It's a different problem set where in a multi cloud world, the fact that we're helping customers operate and leverage the built-in control is ultimately a win at their local level for the product teams that we're working with and then at the more strategic level as they mentioned as well. >> Awesome. So I asked you earlier about timing of doing the company and all the problems and you kind of told me of customers having that challenge. But let me go back to that is why now? Why is now the time that native or the solutions that you're talking about is really relevant? >> No, like I mentioned earlier, like the maturity both of the cloud providers and the enforcement capabilities, both of the industry and the practitioners to move to that next evolution or that next phase. But I think also there's pieces of it that have to do with AI and it touches on several aspects. One, that increasing multi cloud reality, part of it is strategic, we want a footprint into different cloud providers for their different A. So we're seeing increased multi cloud adoption and one of the reasons being AI. We're seeing also, this is even some pretty recent analyst reports around the speed for tax in the world where the attackers move at AI speed. And I say like this isn't really new because before they were moving at AI speed, they were moving at API speed. You just add that PDM, that's still really fast for reaction to react to. But increasingly in an AI driven attack world, detection and response loses even more of its efficacy and you want to write preventive controls, otherwise it's too late. >> That's right. >> You lost. And then finally also our ability to move fast in this world. Like there's, we're not in AI security company. We believe there's a fundamental problem that we're solving. But behind the scenes in the product, there's AI baked into multiple parts of it that allow us to do things uniquely, understand the environment, analyze the environment, do the simulations, translate policy documents into natural language, intense and vice versa. AI is baked into all of it. This wasn't possible a year or two ago. And where we see things are going, we're already hearing from CISOS tell us, I had a five, my five, let's call my five person cloud, single cloud security team, all of a sudden feels like with native there are 20 person multi cloud security team. How do we continuously leverage AI to now go from a 20 to an 80 to a 200, how was native in the mix? How do we leverage what AI is now giving us to effectively create a 200 person multi cloud security team?
- That's a security team. That's scalability in what it's giving us. And we're seeing it everywhere and making sure that we constantly stay at the forefront of what is possible. - Interesting. - How does anybody get in touch with you guys? If somebody's interested in learning more, where do they go? What do they do? - Native.security is our website. Can through their reach us. I meet at Native.security is my email. - That's it? - Yeah, that's it. - I meet McGito. - WD, MEGI, WD on LinkedIn. And always happy to connect. - I'm sure there's a song that go WD. - MEG. - I'll figure that out. - Yeah. Any other questions? - Yeah, you asked before by the way, in like two moments and I gave one. And I think another one was when we were invited to present to one of the top top, like think like, you know, top banks, largest companies in the world, all the way up to their like CIO level, very high level and all the like senior people in the room that are for the forefront of what innovation is in the security and the infrastructure space. And we got, you know, basically 10 minutes to share what it is we're doing in another five minutes to show the quick demo and they, you know, we were done within minutes, you know, they sort of deliberated, you know, we were out the room, they called us back in and they made it on the spot decision that they want to go into POV with us. And that was magical because this was a, also a huge opportunity for where we are now, but also getting that validation, that on the spot validation that rarely happens from such a, you know, such a partner is amazing. So that was another real magical moment in that. And then I think another use case where we're seeing where we can provide a lot of values, M&A happened, there's some companies that they operate in M&A strategy and our ability to standardize controls, not even, not just multi-cloud, but across desperate cloud environments within the cloud organization. If you have multiple cloud organizations, M&A, you, you know, you, you know, bring on another company into your company, you're bringing on a new cloud environment. You know, is it own controls and policies and issues in it? The ability now to very quickly understand what is their effective cloud policy? How does it map to our standards and now replicate our standards to their environment in a very fast and safe way? Is another amazing use case that we're helping with? - I've lived through that problem in almost every company when we're doing like five, six acquisitions a quarter. - Yeah. - I mean, that is a real problem. You have all the children at very different stages of maturity forever. - You know, yes, like another magical moment we had, like was a field, if it was the very, like again, very Fortune 100 tech company. And, and working was like the practitioner there, like hands on and, you know, AWS expert, they have some Google, some Azure, like always, some work. And, you know, and he went during the field view or on the call with him and he did that implemented policy on Google and said, wow, I just, you know, implemented a security control construct on Google Cloud. And I've never even gone into Google Cloud. Like I don't know how it works, but it looks and feels exactly the same. And you can literally take my control that I implement on AWS and spend a lot of time learning how to do it and, you know, making sure it's safe to implement and replicate it almost instantaneously to Google Cloud without knowing Google Cloud. It's magical. - That's awesome. Because that SME labor skill set for each and every provider, it's part of the problem that customers have is like, I need to have an expert on GCP and another person expert on AWS. - We're seeing, we're hearing from customers like, that's a part of the way they're justifying budget just early for a product like this. They're saying like, we were going to hire, you know, two or three Google Cloud security experts, you know, we're gonna now just hire one and, you know, put two to decide and try to go as native. And that just by itself, like, it's big efficiency and that's just a start. - It's exciting. - Yeah. - Well, thank you very much. I appreciate it. Anything else? Make sure you're good. All right. - Yeah. - Awesome. - Thank you. (upbeat music)
Podcast Summary
Key Points:
Cloud security is at a pivotal transition from reactive detection to proactive architecture and policy enforcement.
The speaker's background includes military service in a high-responsibility unit, which shaped his leadership and ambition.
He later earned an MBA at Harvard Business School and led the launch and growth of AWS GuardDuty.
A key insight from AWS was that in nearly all breaches, a detection signal existed but wasn't operationalized due to technical and process gaps.
Multi-cloud adoption is accelerating, making unified security solutions essential.
The speaker founded his own startup because he saw a ceiling in his previous roles and wanted to solve the persistent, platform-level problem in cloud security.
The co-founding team came together through AWS connections and shared expertise in security products.
Summary:
The speaker discusses a transformative moment in cloud security, emphasizing a shift from merely detecting threats to actively enforcing secure architecture and policy alignment. He shares his personal journey, starting with a childhood shaped by ambitious parents and a brother who was an entrepreneur. At 18, he joined a prestigious military unit, where he gained deep technical and organizational experience, eventually leading large teams.
After a decade, he transitioned to Harvard Business School to build business acumen, then joined AWS to lead the launch of Amazon GuardDuty. There, he witnessed firsthand that while detection signals were present in most breaches, they failed due to poor operationalization and process gaps. He also observed the growing complexity of multi-cloud environments.
Motivated by a desire for greater challenge and impact, he decided to start his own company. The key was assembling the right co-founding team, which included colleagues from AWS and connections from Israel. His startup aims to solve the fundamental, platform-level problems in cloud security that previous point solutions have not addressed.
FAQs
The speaker believes cloud security is at a pivotal transition stage, moving from visibility and detection toward proactive secure architecture and policy intent matching.
The speaker served in the military, attended Harvard Business School, and led product development for Amazon GuardDuty at AWS.
In about 9 out of 10 breaches, a strong detection signal existed but was not operationalized, so it didn't reach the right person in time to prevent damage.
Customers using multiple cloud providers wanted to avoid managing separate security tools for each, as single-cloud approaches became less viable due to business and regulatory needs.
The speaker felt that founding a startup offered a greater challenge and gratification, with no ceiling on impact, compared to working within a large organization.
The speaker connected with co-founders through prior work at AWS and common connections in Israel, including individuals with leadership experience in security products.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.