What Does Secure by Design Really Mean? | Yogita Parulekar, Founder & CEO of Invigrid
24m 20s
In this episode, Yogi, Founder and CEO of InVigrid, discusses the critical shift from traditional security practices to a "secure by design" approach for cloud infrastructure. He explains that security has historically been added after deployment, but this is unsustainable for modern, AI-driven development. Unlike "shift left," which focuses on scanning code early, secure-by-design requires embedding security at the architecture and design phase, before any code is written. This is especially vital for infrastructure, which cannot be patched after deployment without significant cost and downtime. AI compounds the problem by enabling faster innovation and more sophisticated attacks, while developers prioritize speed and often lack security expertise. To address this, InVigrid automates the creation of secure infrastructure code from design intent, making security invisible and seamless for developers. This prevents friction, reduces shadow AI risks, and helps enterprises balance innovation with governance. Yogi also highlights InVigrid's inclusion in the Google Cloud Marketplace and Springboard program as validation of their approach, which simplifies procurement and reinforces the cloud's promise of speed and security. Ultimately, secure-by-design is not a one-time checkbox but a continuous process that must evolve with technology.
Welcome back for another episode of cyber conversations. I'm very excited today to be joined by Yogi, who is Founder and CEO of InVigrid. Now one thing that I think is really exciting about these guys is that they're challenging something we've almost accepted inside security for years. And that's that we think security is something you can come back to and add later. Instead, InVigrid are building around this idea of secure by design, where governance, compliance and security are built into cloud infrastructure from day one. Not quite bolted on to after the fact. Yogi, I'm so glad to have you here with me today. Lots of exciting things that we're going to unpack, but why don't you maybe kickstart and give us a brief introduction to yourself. Thanks, Katie, for having me on this podcast. I'm pretty excited about what we are building. It's amazing to always chat with you on these topics. Looking forward to this conversation is it? Well, let's dive right in because you've had such an interesting journey throughout your career. You've gone from EY and Oracle through to Founding in Vigrid. And I'll be interested to know what experiences do you think had the biggest influence on how you look and think about cloud security today? Which part of my experience can I tap into for this answer? We'll stay here all day. We'll stay here all day because it's decades in this field. And it has been a very interesting journey. Never a dull moment in the field of cybersecurity. Right? We went from over two decades back when the CIOs and boards and everyone would just ask us what exactly do you mean we need to do? And why? To just tell us how faster, better, cheaper. Which is all in itself a very good sign. Right? We have progressed this far. Nobody is questioning the why. We all know that it needs to be done. So what has remained static, though? While all of that is a good sign, what has remained static is that it is still a cat and mouse game. We're still doing it after the fact. We're trying our best to do it better faster, cheaper, but still after the fact where it happens is still much later in the game instead of earlier. And as we walk through this in the next 20 minutes, I'm going to try and drill into that why over time more. But that has, so now we know what has changed and what hasn't changed. And the third factor that is coming into play today is AI. And we cannot do this, you know, podcast without talking about AI and its influence and how it's so I'm excited to jump into this conversation. No, me too. You obviously mentioned you've had a wealth of a career that has really built the foundations as to why you're an expert in this as well. I think you come from it's not a case of just working in like the vendor capacity either you work in talk about UI and they're kind of you've seen all different sides of the coin is the point I'm trying to get to there. And I'd be really interested because if we look at invigorates one thing I hear a lot about what you're talking about is the idea of secure by design, which I think sounds simple in principle, but for anybody that is tuning in, what does that actually look like in practice? And why do you think it's becoming so important now? Oh my god, but those are two questions, right? Two main questions. I'm going to split that up and each one is going to take some time. One is what it is and why not? Right? So what it is and this is actually you hit the nail on its head. People confuse secure by design with shift left. Okay? And so for those very quickly shift left comes from the engineering concept of doing QA often and QA early enough. Right? So that concept has been applied on for your application code for checking for security as well because security is also considered as a part of quality checks. And if we embed that at that point in time and then you shift left and do it often enough and early enough right from there, not just pen test later on, then you will get good secure code. And that works for applications and application code and software code. Where it for it lacks even for application code and where it is probably not such a great idea is infrastructure. So far application it's so let's look at what it is. Secured by design is the extreme left. Right? So even before you write your first line of code, when you start about thinking of your architecture for your entire application, what are the security pieces you mean? What are the authentication, the authorizations, what kind of software it is, the auditability of every action, traceability, those are the things that you have to plan for at the design stage, at the architecture stage for your code. Right? So that is secure, truly secure by design versus what we look at today and say, Oh, shift left, I will scan my code and I'm good. Now even infrastructure. Okay? Application code, it works at least to a very large extent. You can scan and that is fantastic, you're doing it often, you're doing it early, just like quality. Add the design aspects and you're pretty good. Infrastructure on the other hand is unlike application, you cannot patch infrastructure. So you don't have that choice of doing it later on. You have to do it before you deploy that infrastructure. So what I mean by that is once you design your network and you draw the diagram, okay, I need the network, you need the subnets, the load balancers, gateways, the side arranges of the subnets, the databases and networks and secret managers and keys and maybe a firewall and what kind of rules, etc. You cannot patch that infrastructure once your application code or your workload is already running on it and customers and users are already using it without a downtime, without an expensive re-architecture. So for infrastructure, secure by design is not a nice to have, it is a must to have, right? So it's very different, you design it in that architecture before you deploy it. You can't just say, oh, I have policy as code and I will scan the infrastructure as code, my shift left checkbox is done. It doesn't go as far as scanning your code base goes. You have to do it at design phase, you have to do it at the architecture phase. So matured later, then policy as code scanning your infrastructure as code. I think you're really setting the foundations there and it's so critical to get this early on and I think for a long time we've accepted that security is something you come back and fix later. But obviously, especially when we talk about some of the more modern technologies like AI, which obviously it has to come into play because it is such a contributing factor as to why this approach just isn't sustainable anymore. What your opinions on why you think that look, we can't just go back and fix later anymore, this is why it's absolutely essential that we really start doing this right from the get go. Oh my god, that's the second part of that question, right? I still have to answer the why and why now, right? So think about it, why it is being done later. So I think if you answer that question, then we can answer the why now as well. So why it is done here is because it takes time, it takes time to plan it out, it has to be in your architecture, diagram, so it takes time planning, effort, time, expertise, which those who are building writing code and deploying, they may not necessarily have that infrastructure expertise. Developers don't necessarily understand infrastructure expertise or security and compliance, they don't want to be bothered with it. Forget about understanding, they can always understand and learn, but they want to be bothered with it, right? I just want to write cool code and build cool stuff and in a way, then focus on that versus give me infrastructure and security and compliance, can you just give it to me and give it to me fast please, right? So they don't want to be bothered with it, but they expect it at speed and with AI, that is always be the case, which is why they say don't bother us now, come back and later this is going to take time, we don't want to wait for another six months to deploy or six weeks to deploy and now with AI wipe code in, they can create build and application overnight, over a weekend, over six days maybe, an entire large application and then to wait around for those same six weeks or six months for your infrastructure because it has to pass all the security checks and architecture review, no one's waiting for that, I built this whole application overnight and you are expecting me to wait for six weeks to go to market with it, no, right? So that is one reason, one huge reason, the same problem of speed and security being oxymorons in the same statement, right? It has always been that way. Now with AI and wipe coding, people are like, no way am I waiting for this. I think that's such a valid point though because there's a lot of
can I've mentioned it several times before is like innovation often precedes security and it's really difficult when you're in a role where you're able to build so quickly now as well. You don't want to sit there and also with the rate of how competitive it can be of if we sit on this and we don't get it out to market quick enough we miss out and that's it's that's its own challenge and I think obviously AI has become one of the biggest conversations in tech over not just really the past year at this point in the past couple of years other than the speed that you're able to create how does this change the way organizations need to think about building secure infrastructure from day one. That's another part of the question we just dealt with one area right we're just one piece of it let's go back to specifically in the area of AI we haven't addressed correct there are a lot of other things other than the speed of innovation that AI is impacting AI is changing the complexity of it is make for malicious marketers it is changing the speed at which they can act right the complexity and speed of attacks it has lowered the barriers for the attackers because now Clark can tell them how to exploit something any other journey I have it has lowered their barrier it has increased their speed and we are stuck in the old speed right we got to change and got to embed security so how do we your question like how do we make this happen right to make that happen it has to be embedded in the process of deployment think about it as what I love to give this analogy is a ring doorbell I don't know whether in the UK you have the same ring doorbell right so if used to be now the camera system was the security system that was separate from our doorbell adding the camera on the doorbell you essentially ended up with a smart doorbell where the security was embedded in the doorbell itself in the same way your security policies have to be embedded as a part of the deployment process as a part of the infrastructure architecture design as a part of that deployment of that architecture so starting from design to deployment at that time and automatically and seamlessly so even a developer should be able to not need expertise today they are going to try and take shortcuts because they are not going to wait right they are not waiting around so they are going to ask AI give me the infrastructure code for this and you get well they get it like I'm good deploy so how do we embed security in how do we compress this whole process but add the rigor and embed it and reach them at where they are and say it's automatically embedded you want this you want to deploy this security as the architecture designs get automatically created the code gets automatically created which is secure and that's what we do right it's converting that human intent into secure infrastructure and embedding it so it's seamless it's invisible to them and it has been done at the speed that they want at the base of innovation sounds like a win-win to me ultimately you're exactly there and it's a case that naturally this is the worst thing you could do is somebody who's building a system or a product whatever it might be is then have to go away and then come back to it again but of course you also don't want to create these hurdles while you're in development and especially at the speed that we can if you've got something there that is not creating this hurdle that somebody has to overcome because as we all know if you build a wall people will find a way around it instead of trying to climb over it because it's less effort and ultimately that's just how it typically goes I think it's just natural human behavior well it could be really interesting you use you when you're talking to customers for the first time do you have the biggest misconception that they maybe have when it comes to this secure by design kind of mantra and what it actually means do they have this preconception of what it is they equated to shift left they equated to policy as code and they equated to if I have that policy as code and I run that scan on the infrastructure of code that is generated I am good right so all they have done is they have added friction now somebody has to write that code somebody has to review that code somebody has to create the policy as code somebody has to put the whole system in place where it's all integrated different tools write the policy as code 2 has to be set up it has to be integrated and then you run the scans but it's and it has already it has created friction but they got the checkbox because that is what they have been told is best practice in the meantime developers have gone past this and that is why shadow AI is proliferating right because everybody now nobody wants to wait HR finance, marketing, customers support they all want to suddenly start and they have the capabilities they can buy code right now suddenly in their hands and they can write an agent they can say oh let me deploy it there are so many deployment options available now shadow AI is proliferating everywhere right costs are also escalating so how we need to think about beyond the security also governance because the more this increases your blast radius it attacks surface all the different points so how do we protect the entire company the enterprise but yet allow innovation so that is the challenge in enterprises today and for that you need an governance system which again has these controls embedded at the pace of innovation so instead of the checkbox that we like I think the thing governance as well is sometimes it gets a bit of a reputation for slowing innovation down how do you change that conversation and show people that it can actually help businesses move faster oh yeah it's it has been initially when I started talking about this that it should be embedded in people couldn't even fathom they were like what are you talking about how can it be done right how is this even possible this is not policy as code as this thing as it gets but how do we embed it in the architectures in the design it seems like magic if it works that's great if it seems like magic so then I have to just finally build it like show it and when they see it it's like aha okay that makes sense it's until you saw the ring camera it would have not made sense how you're going to have a camera system a security system and a doorbell together right I think that's it isn't it ultimately sometimes you have to show people before they can believe it in a sense but that's probably testament to the fact that inside but there's a lot of too good to be true and people can sometimes have this head sense here around this sounds too good to be true what do you mean if where's the cat have yeah yeah what's the catch there's something surely not but I think ultimately that's also what's so exciting about the industry right now is there are products that come out and they solve these problems that we've had for such a long time and you're like what do you mean that there can be a fix and it feels so simple I'm sure for you and the team it didn't feel simple building it but obviously for everybody experiencing it it does oh my god it's not an easy thing to build it's not an easy thing to build but the experience after it is built is what makes it phenomenal right the aha is what makes it phenomenal and now we started building this and then CISA the cybersecurity and infrastructure security agency of DHS they came up with the initiative for security design in April 2023 so that's phenomenal but there was still an emphasis on the application code the software not as much on infrastructure and the industry still we do policy a code shrugged it off a little bit it's still hard it's not possible now fi eyes alliance they have come up and basically said it's we got to have secure by design it's an operator and it's got to be now because AI is changing the game if we keep doing the same things again and expect a different result it's a sheer definition of insanity right so we got to change and I think now everybody is waking up it is time to change and by the way it's not just at design time you have to continuously embed a security and governance it's not just day zero it's the day one day two as well because even infrastructure evolves I think that's it isn't it it's not just a tick box even though it's book of more simple it's still not just a tick box or you move on and it's done it's a continuous thing and naturally also because of how much everything evolves how much the technologies evolving the landscape is a continuous conversation that we're all having you talk about this time last year and we just see how much has come through all the new technology we've got access to and that evolution is only going to continue I do want to mention something that I think also backs up some of the stuff that you're talking about with how critical a solution like this is and how much of an impact it can have in the market because obviously you joined the Google
cloud marketplace and taking part in the Google's ISB startup springboard program which is phenomenal and I'm really interested to ask because beyond the recognition which is definitely worthwhile by the way not to overlook that but what does it actually mean for customers and for ambiguous journey? Oh it makes procurement easy for our customers it means we are wetted it means that the cloud providers actually like believe in this there if we take everybody to cloud fast right deploy infrastructure fast and secure we are fulfilling the promise that they originally started off with cloud style because hey it's easy right you don't wait around for the server to come and wire it up you can get it at the click of a button and oh by the way you have to secure it don't forget that that was the shares responsibility now we help them fulfill that the promise of speed and security shows the clouds promise I democratized getting infrastructure and deploying it fast but it came with a shared responsibility and we help them fulfill the customers fulfill that so have been in the marketplace is a signal that cloud providers want this kind of a product and not just marketplace but also in their startup programs such as springboard it's an acknowledgement of the need for a product like this for customers it makes the procurement cycles easy we can offer discounts and funding and stuff like that and expertise directly from the cloud providers that join with us together so yeah absolutely and it's exciting as well right like I mentioned it really reiterates how that there's this external recognized value in what you're building it's not just you working here and say look what we've built and how it's important you then have for these programs and these cloud providers going oh yeah we see the value here this has been a great episode and so much that would be an awesome impact but I think really great to bring the value and highlighting what we mean when we say secure by design I'm really interested to ask them close out on this question because if we were to have this conversation again in a year or maybe even a couple of years time just in terms of what you predict what's the one change that you really hope that will have seen in how organizations approach cloud security one thing that how they approach I do hope the secure design is much more widely adopted than what it is today no matter how technology changes what is thrown at us doing it at design stage is probably going to be more important than ever than less and not less right as we see it in the case of AI as well so in the next two years I hope it's absolutely widely accepted everybody understands the difference between shift left and secure by design it is seamless it is as widely accepted as the ring doorbell is today keep coming back do that again and again because and I'll leave with this code by an architect Frank Lloyd Wright as he said and one and some siso actually one of our customers he pointed me in this direction of this code so thanks to him it's applies bang on you can use an eraser on the drawing board or you have to use a sledgehammer on the construction side powerful analogy to be fair no yogi this has been phenomenal I think it's exciting to hear what you're building it in big grid but more than anything I think just that value add piece like I said to you it feels like it's too good to be true situation which is just so powerful but really really valuable and I couldn't encourage people more to get invested have a look at in big grid and obviously reach out and find out a little bit more so thank you so much for joining me to everybody tuning in make sure to like subscribe share this episode with your security peers make sure to get connected with yogi and follow along with in big grid and hear a little bit more about what they're going to continue to be doing because as you can probably tell pretty phenomenal stuff but that is it for today's episode so thank you for tuning in and I will see you all next time for more conversations that are shaping cyber
Podcast Summary
Key Points:
InVigrid challenges the traditional "security added later" approach by embedding governance, compliance, and security into cloud infrastructure from the start.
"Secure by design" is distinct from "shift left"; it requires planning security at the architecture and design phase, not just scanning code later.
Infrastructure cannot be patched after deployment without costly downtime, making secure-by-design essential for cloud infrastructure.
AI accelerates both development and attacks, increasing the need for automated, seamless security embedded in deployment processes.
Developers often lack security expertise and want speed, so security must be invisible and automatically integrated to avoid friction and shadow AI.
InVigrid's inclusion in the Google Cloud Marketplace and ISB Startup Springboard program validates their approach and simplifies customer procurement.
Summary:
In this episode, Yogi, Founder and CEO of InVigrid, discusses the critical shift from traditional security practices to a "secure by design" approach for cloud infrastructure. He explains that security has historically been added after deployment, but this is unsustainable for modern, AI-driven development. Unlike "shift left," which focuses on scanning code early, secure-by-design requires embedding security at the architecture and design phase, before any code is written.
This is especially vital for infrastructure, which cannot be patched after deployment without significant cost and downtime. AI compounds the problem by enabling faster innovation and more sophisticated attacks, while developers prioritize speed and often lack security expertise. To address this, InVigrid automates the creation of secure infrastructure code from design intent, making security invisible and seamless for developers.
This prevents friction, reduces shadow AI risks, and helps enterprises balance innovation with governance. Yogi also highlights InVigrid's inclusion in the Google Cloud Marketplace and Springboard program as validation of their approach, which simplifies procurement and reinforces the cloud's promise of speed and security. Ultimately, secure-by-design is not a one-time checkbox but a continuous process that must evolve with technology.
FAQs
Secure by design means planning security at the architecture stage, before writing any code, unlike shift left which scans code early. For infrastructure, it's a must because you can't patch it after deployment without expensive re-architecture.
AI accelerates development, letting developers build apps overnight, but they won't wait weeks for security checks. It also lowers barriers for attackers, so security must be embedded automatically from the start to keep pace.
InVigrid converts human intent into secure infrastructure by automatically generating architecture designs and code with security built-in, making it seamless and invisible to developers at the speed they need.
Many equate it to policy as code or scanning infrastructure as code, but that only adds friction. True secure by design embeds security at the design and deployment phase, not just as a checkbox.
It embeds controls at the pace of innovation, so developers don't have to wait. This prevents shadow AI and reduces attack surfaces while allowing fast deployment.
It makes procurement easy, signals cloud provider validation, and offers discounts, funding, and direct expertise from providers to help customers deploy infrastructure fast and securely.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.