Rami Sass, WhiteSource | CUBE Conversation
>>Welcome to this cube conversation which is part of our third Aws startup showcase of this year. I'm your host lisa martin and I'm pleased to welcome to the cube ceo and co founder of White Source Romney Sasse Rami, Welcome to the program. >>Thank you. Thank you so much for having me. >>I'm excited for our audience to hear about White Source, give us that high level overview of what the company is and what you how you're helping organizations. >>Sure. So we have software engineering teams keep track of their use of open source components sometimes referred to as dependencies and primarily focused on security aspect of those dependencies and are able to very natively and very quickly identify one all of the dependencies that are being used in a certain software that's being developed and alert to any known vulnerabilities that exist in those dependencies and then nick our users through the journey of finding them prioritizing them and fixing the vulnerability is such that their software when it gets released is not at risk, >>not at risk. And one of the things we've talked so much about In the last 18 months is the threat landscape. It's changed dramatically. We've seen a huge increase in ransom where huge increase in Ddos attacks. We also are in the fifth consecutive year of a cybersecurity skills gap. It's been there for a while. We know that there have been barriers between developers and security. How does White Source help address that cybersecurity skills gap. >>So we focus on automating as much of the security practices possible. Right. So basically our main premise is that we want to be the security expert for the engineering team so that they don't have to right? So we provide tools that automate the entire process of remediating the vulnerability so that we can save the developers effort and time in becoming security expert basically saying they don't need to become security expert, they can keep doing what they do best, which is developed software and provide more business value to their employer. And we will take care of anything that has to do with security in their software for them. So basically we're trying to alleviate the need for developers to develop any kind of security related skill set. >>I got to ask you how does that address? We talked about the skills gap but also the cultural shift required for developers to then kind of exhale and and put their trust in you guys and that's a big challenge to change cultures within organizations. How do you help influence that? >>Sure. So look, when you're talking about cultural shift, it always takes time. Like these things do not happen overnight And its gradual and so we are very well aware of it and we do not expect people to have 100% confidence in us immediately in day one. Okay, so our tools and and practices account for it and we help our users uh increasingly trust us more by proving ourselves to them by first starting with providing advice and allowing them to control the pace at which they automate more of the process. Right? So initially we will just tell them what they need to do and let them do it themselves until they are, they have gained enough experience without tools to just allow us to take the full cycle for them. That's one which maybe is even more important is that we rely very heavily on crowd sourcing, Right? So we have a very extensive customer base that is made up of some of the world's leading enterprise organizations that have very complex and a large environments and across those environments, combined with our ongoing and monitoring of everything that's going on in the large world of open source projects, we have compiled a very extensive crowd source database or knowledge base, if you will, that basically gives you intel on what others are doing with those vulnerable open stores dependencies, Right? And we can give you a lot of confidence when we see that the broader community of both commercial and free opens those users have upgraded a vulnerable dependency to a safe version and are speaking to the new version, right? They're not pulling it back there, not undoing that change. And so we give you a lot of visibility into all of that information and also, you know, when when things go bad, right? If we see that many people roll back some change and uh avoiding some dependency version, then we will warn you away from upgrading that version. So I think that the fact that we are establishing our recommendations on a lot of crowd sourced data is another way for us to provide more confidence, automating actions for our users. >>The C word confidence is absolutely critical. I got to ask you though Romney, something that you you mentioned, I was always, I always like to ask start ups, you know, what was the impetus to start the company? You're the Ceo and co founder? What were some of the gaps that were missing? Was it crowdsourcing? And was it the the lack of that community to really provide that visibility to developers that you guys saw as an opportunity to fix in the market? >>Alright. So at the risk of exposing my real age, Uh tell you that the company started over 10 years ago and was actually based on previous experience that as founders had in another company when when it was time to sell it. Right? So when we sold our previous company, we had to go through a two diligence process where we were required to provide a very detailed report of all the open source dependencies that we were using and we didn't have such a report and sort of caught us off guard and we had to spend a lot of time during, you know, the most stressful part of the due diligence, finding out which open source we were using and documenting it and coming up with the report. And so that was a very personal experience we had, but it was very obvious that it's not something that we did special. Right? Everyone is developing software is relying very heavily on open source and usually doesn't track it everywhere. Soon it initially started from just the very basic need for transparency, visibility and the ability to provide a, you know, simple bill of material that's now become a big thing right around S bahn Uh, but 10 years ago it was very difficult, it was very like manually laborious task to be able to come up with your bill of material and that's sort of the experience that big. Uh, the foundation of white suits >>got it and then talk to me about your relationship with AWS and mentioned in the beginning of this segment that this is part of our third AWS startup showcase of the year. Give us an overview of your relationship with AWS from a technology partnership perspective cells marketing product. >>Sure. So we've been working with us for a very long time and they are a wonderful partner to work with. It started right at the beginning where we are a cloud native company. Right? So we're staff solution provider and from the beginning we chose aws to be the infrastructure on which to no solution and we grew together with them over time over the last 10 years. We've been scaling again and again our environment and you know, the services that we provide and have been consuming more and more on AWS services, both for infrastructure and but also and very importantly for securing our runtime environment, which they do a great job at. But then it went even further and we are now integrated with a lot of AWS services and products and technologies. So our offering is very much integrated with several AWS offerings. And even beyond that, we are working closely as they go to market partner with AWS. So we have several co marketing initiatives with them and we are part of the startup coastal program. Such that AWS sales people can coastal white source to their customers. >>I imagine that is an advantage the partnership and the deep relationship that you have with a W. S in terms of getting those customers meetings and and helping them achieve the confidence in the technologies and the power of the two companies in 10 years. We're looking at 1000 customers and some big names. I saw from your website Microsoft Comcast, uh, Splunk 23% of the Fortune 100. Tell me how the aws partnership helps you give those developers the confidence that they need to trust in your technologies. >>Sure. So, first I think the synergy is very apparent, very obvious because both AWS and us sell to the engineering departments into the devil's people. All right. So we are catering to the same users the same customers the same, even decision makers. And so it's very easy to understand. It's also very easy to tell the better together story. Right? So, it's very easy for the the the THE AWS sales people to explain to their customers why it's easily integrate Herbal and it makes the sales motion easier and transparent and fluid and it makes the customer's consumption of the joint services easier. Right? So it's for them, it's easier to work with AWS is a window knowing that they can get all these added security features from them and gained the confidence of having this solution vetted by amazon and get us as a reference for us as a vendor also makes it easier for them to trust us and to use our services uh, with peace of life. >>Sounds like a synergistic cultures as well. I want to dig into something that I saw in the notes that you guys provided that white sources enabling organizations to eliminate up to 85% of security alerts. That's a big number. How do you do that? >>Okay. First, to clarify, we're talking about open source vulnerability or its rights are not in general. Not all security for open source security alliance. We've developed a deeper analysis that goes beyond just looking at your bill of material and identifying which dependencies are vulnerable and analyzes the way in which the developers are using those dependencies and what we've found over the last three years of running that technology with real customers? over many tens of thousands of development projects. Is that on average, 85% of the vulnerabilities in open source dependencies. I'll not reachable from your code. All right. So they are still there. You're still using the dependency but you're using some other function of it, which is not vulnerable. And the vulnerable function is never actively called in your code base. So this is like very specific. It's not some generic analysis. We had to analyze your code and figure that out. And so again, the average statistics statistics, is That just 15% of vulnerabilities are quote unquote, reachable form your code and makes your software vulnerable. Right? All the others are simply not exploitable. And so it can easily be eliminated for the need to remediate. Right? So you don't have to >>got it. How are you guys helping customers? There's been a lot of data that shows companies are spending millions uh annually using multiple web app and a P. I. Security tools on average but are still having problems with those tools being effective. How does white source help customers not waste time and resources and get right to being able to identify and remediate those vulnerabilities >>short. So look again in our philosophy, is that just detecting the problem? The security issues doesn't fix anything. Right. Doesn't help you solve your problem. Right, paramount to going to visit your dentist and having them find the cavity and maybe they do an x ray and they tell you exactly which tooth it's on and how deep it is. And then just send you home and you did you need to deal with it yourself. Right? So it doesn't really solve the problem. Your your mouth still painful. You have to fix the problem in order to get any kind of value for the security service of tool, you have to, you know, close the loop, finish the process and fix the vulnerability. And so by investing a lot in automating the remediation in enabling our tools to close that cycle right to finish the job and fix the vulnerability. We enable you to actually gain the value from the various tools that you're using and make sure that your software is not exposed and not vulnerable and not just give you a report with the vulnerabilities, right? Not just find them for you. >>Got It. Last question for you is if we look at your recommendations when you're talking to customers, especially as I mentioned earlier in the conversation, the threat landscape has changed dramatically in the last 18 months when you're in customer conversations, how do you advise them to start? You start with the developers. Do you start with security or do you start by saying you've got to bring everybody together. >>So we would normally start with security uh and you know, not necessarily the developers themselves, but the engineering managers. The heads of engineering again because our main effort is to leave the developers alone. Right. We want to get as little developer involvement as possible so that they can be free to do what they need to do. Security is something they have to right? It's a sure it's not, it doesn't add business value, it just protects the business from being exposed to greater risk. And so our approach and our practice is to be a sort of exception based tool for developers and only get them involved when you absolutely have to have them chime in and do something. Otherwise, we can fully take ownership and automate the entire process of identification, prioritization and remediation for the organization and just provide reports on, you know, how many vulnerabilities we fix this month and and give them better visibility into their security posture. Yeah, but you know, we invest most of our innovation attention resources as a company to automate as much of that process as possible so that the developers don't have to spend their time on security issues. We will do it for it. >>And I imagine developer productivity goes way up for your customers? I do have one more question for you, given that here we are in the fall of 2021, what are some of the things that you're looking forward to as we go into the new year? >>I love you in the new jewish year or then you >>Uh maybe both. I was thinking, you know, just as we go into 2020 to some of the things that you're excited about. >>Sure, so look, it's it's a little difficult to be happy about something that's a problem for other people, right? Because there is a growing threat for application security and there is more and more attacks going on in the world. But I'm really looking forward to helping more people be more protected while not wasting their time. All right. So it what drives me is the ability for us as a company to provide real value for customers and not be some shelf will not be a tool that just produces reports that no one knows what to do with. And the fact that we are able to steal our users and our customers away from risk and save them. The the hassle of being attacked, being hacked, having their data stolen or having the system broken into is what I mostly look >>and there's plenty of opportunities for you guys to do just that and really add that value for those developers And the company is like I said, big brands Microsoft Comcast block Romney, thank you for joining me on the program today, talking to us about white source and how you're really feeling the gaps in the cybersecurity skills landscape and helping really transform developer productivity where security is concerned. We appreciate your time. >>Thank you. Thank you so much for having me on the show. >>My pleasure for a missus I'm lisa martin. You're watching this cube conversation. Mhm mm mm.
SUMMARY :
of White Source Romney Sasse Rami, Welcome to the program. Thank you so much for having me. of what the company is and what you how you're helping organizations. all of the dependencies that are being used in a certain software that's being developed And one of the things we've talked so much about In the last 18 months is the need for developers to develop any kind of security related skill I got to ask you how does that address? And so we give you a lot of visibility into all of that information I got to ask you though Romney, Soon it initially started from just the very basic got it and then talk to me about your relationship with AWS and mentioned in the beginning of this segment from the beginning we chose aws to be the infrastructure on which to I imagine that is an advantage the partnership and the deep relationship that you have and fluid and it makes the customer's consumption of I want to dig into something that I saw in the notes that you guys And so it can easily be eliminated for the need to and get right to being able to identify and remediate those vulnerabilities So look again in our philosophy, is that just detecting the problem? the threat landscape has changed dramatically in the last 18 months when you're in customer for the organization and just provide reports on, you know, how many vulnerabilities we fix of the things that you're excited about. And the fact that we are able to steal our users and our customers away and there's plenty of opportunities for you guys to do just that and really add that value for Thank you so much for having me on the show. You're watching this cube conversation.
SENTIMENT ANALYSIS :
ENTITIES
Entity | Category | Confidence |
---|---|---|
AWS | ORGANIZATION | 0.99+ |
lisa martin | PERSON | 0.99+ |
Microsoft | ORGANIZATION | 0.99+ |
100% | QUANTITY | 0.99+ |
85% | QUANTITY | 0.99+ |
two companies | QUANTITY | 0.99+ |
15% | QUANTITY | 0.99+ |
amazon | ORGANIZATION | 0.99+ |
1000 customers | QUANTITY | 0.99+ |
Romney Sasse Rami | PERSON | 0.99+ |
2020 | DATE | 0.99+ |
10 years | QUANTITY | 0.99+ |
White Source | ORGANIZATION | 0.99+ |
23% | QUANTITY | 0.99+ |
First | QUANTITY | 0.99+ |
aws | ORGANIZATION | 0.99+ |
Rami Sass | PERSON | 0.99+ |
both | QUANTITY | 0.99+ |
Romney | PERSON | 0.98+ |
third | QUANTITY | 0.98+ |
one more question | QUANTITY | 0.98+ |
millions | QUANTITY | 0.98+ |
10 years ago | DATE | 0.97+ |
one | QUANTITY | 0.97+ |
today | DATE | 0.97+ |
first | QUANTITY | 0.96+ |
Ceo | ORGANIZATION | 0.95+ |
fifth consecutive year | QUANTITY | 0.95+ |
Comcast | ORGANIZATION | 0.92+ |
up to 85% | QUANTITY | 0.92+ |
this month | DATE | 0.87+ |
last 18 months | DATE | 0.87+ |
this year | DATE | 0.86+ |
fall of 2021 | DATE | 0.86+ |
WhiteSource | ORGANIZATION | 0.86+ |
over 10 years ago | DATE | 0.84+ |
new year | EVENT | 0.82+ |
day one | QUANTITY | 0.78+ |
tens of thousands of development projects | QUANTITY | 0.76+ |
last 10 years | DATE | 0.76+ |
annually | QUANTITY | 0.73+ |
jewish | OTHER | 0.7+ |
two diligence | QUANTITY | 0.68+ |
Fortune 100 | TITLE | 0.65+ |
last three years | DATE | 0.64+ |
third | EVENT | 0.51+ |
year | EVENT | 0.5+ |
Romney | ORGANIZATION | 0.48+ |
Aws | ORGANIZATION | 0.29+ |