Flush with funds, rising DevSecOps vendor reveals roadmap

A 12 months in the past, DevSecOps vendor Lacework was one particular among the numerous emerging cybersecurity corporations, but given that then, it is really produced a meteoric rise, capped with a substantial Collection D funding round to get started 2021.

The privately-held business, launched in 2015, stated it saw 300{d11068cee6a5c14bc1230e191cd2ec553067ecb641ed9b4e647acef6cc316fdd} income development in 2020 as the COVID-19 pandemic accelerated enterprise digital transformations and cloud migrations. This month, the business closed a $525 million funding round led by Sutter Hill Ventures and Altimeter Cash. 

Lacework’s SaaS-centered cloud safety system collects a wide swath of knowledge from AWS, Azure and GCP cloud infrastructures, alongside with software configurations, into a petabyte-scale back again finish centered on the Snowflake cloud knowledge warehouse. Lacework’s device learning algorithms then establish adjustments in that knowledge on an hourly foundation, alerting IT operators to anomalous behaviors that point out safety danger and suggesting remediations.

Similar functions can be observed among the container and Kubernetes-targeted safety equipment that have also emerged about the previous numerous decades. But Lacework’s solution has a broader emphasis that spans a number of IT safety disciplines, including id and access administration, cloud safety posture administration, risk detection and response and regulatory compliance administration, for container-centered and non-container workloads alike. The system also integrates into DevSecOps workflows with its API hooks into CI/CD pipelines, infrastructure as code and ChatOps equipment.

Lacework CEO Dan Hubbard served as Main Safety Architect and Main Solution Officer at the business just before getting named chief executive in June 2019. Ahead of Lacework, Hubbard was CTO at OpenDNS, now owned by Cisco, and just before that, CTO at Websense, now owned by Raytheon below the title Forcepoint. SearchITOperations caught up with Hubbard this 7 days to study a lot more about what produced Lacework stand out to buyers and where by he programs to steer the business in 2021.

What accounts for the scale and velocity of the Lacework system, which look to be its major differentiation?

Flush with funds, rising DevSecOps vendor reveals roadmapDan Hubbard

Dan Hubbard: There are genuinely 3 major critical differentiators. The very first one particular is breadth — we just do a large amount of items throughout numerous different classes, all the way from compliance through to growth, safety, develop time, runtime, containers and Kubernetes. That qualified prospects to a large amount of ingestion, throughout numerous different knowledge resources — petabytes of knowledge.

Just one way to consider about the solution is effectively as a substantial ingestion engine, which can take all of your audit trails from GCP, Azure, AWS and Kubernetes, and all of your configurations. We pull all that info in to glimpse for vulnerabilities, configuration challenges, developer errors and unknown behaviors.

The next differentiation is the depth of our knowledge classification and the efficacy of that engine. On common, a purchaser sends us a minor about a billion log entries for each day. We flip it into, on common, 1.twenty five large-finish crucial activities or alerts that they should triage.

The third differentiation is that we match quite nicely into a DevOps lifecycle, or triage method, or a safety method. We can plug into your Jira ticket, we can plug into an API, we could plug right into your checking method, like Datadog or New Relic Main, or we can plug right into your safety workflow.

Is the integration with DevSecOps and CI/CD pipelines mainly for that checking output? Or do you also keep track of the pipeline itself and workloads as they go through it?

On common, a purchaser sends us a minor about a billion log entries for each day. We flip it into, on common, 1.twenty five large-finish crucial activities or alerts that they should triage.
Dan HubbardCEO, Lacework

Hubbard: We can glimpse in and poll container repos, glimpse at your containers for vulnerabilities and configurations. And then we have an API and a command line interface, which lets you to combine into items like Chef, Puppet, Ansible and Terraform and automate a large amount of the CI/CD method as part of the force.

If you happen to be jogging a pipeline, we can help you if you want to cease a develop, or mail a response, like, ‘Build X failed due to the fact of Y, mail to this staff.’ Or make a ticket in Jira that goes to a different team. And then in Terraform, we have an integration that would say, ‘read template’ to force a template, or [detect that] there’s a issue with this template in some way.

The resource can provide tips for remediation — can it automate remediation if a consumer wants it?

Hubbard: Our customers by no means want their cloud service provider to have that amount of privilege inside their method. That’s just quite unsafe for a wide range of safety motives. Nonetheless, we both give them assistance, or we give them code, like a Lambda operate for AWS, that lets you to shut an S3 bucket if you want, or that lets you to flip on multifactor authentication if it is really turned off. We are functioning on the potential to do deeper items inside Kubernetes, like [help make] pod safety policies and network safety policies.

Our belief is, in the future, the platforms by themselves will very own the genuine enforcement. We don’t see Lacework getting the system that kills packets or quarantines hosts and items like that — it is really both likely to be created into Kubernetes, or your AWS VPCs, or combine right with a CI/CD resource. And by the way, it is really really quite, quite scarce, that customers are experienced plenty of to get into that kind of automation. The most well-liked point appropriate now is detect and react, maybe make a ticket and observe that ticket. Then the up coming amount is what we contact Driver Help — maybe they combine our solution into Slack, and it states a thing like, ‘There’s a issue in this article, click this button to remediate it.’ And then the actual experienced ones are like, ‘Okay, operate a serverless operate that does, or a safety plan that does XYZ.’

Even that signifies an expansion of users’ rely on in AI and device learning, appropriate?

Hubbard: Have confidence in is created with positive benefits about time, and we’ve been fortunate that we haven’t had any key problems where by some distributors have had what I contact toxic phony positives, blue screens of dying, bad Linux kernel panics and items like that. But we run at a larger amount – we are not a kernel filter. We operate in userspace.

We have 3 strategies that you can do detection — the device learning things, normally centered off of your infrastructure, and figuring out your infrastructure. That’s genuinely good for the ‘unknown bad’. Then there’s the ‘known bad,’ known bad indicators of compromise like bad domains and bad IP addresses, and bad hashes, [which] is worldwide. And [third,] there’s custom made guidelines that the purchaser results in.

Most safety men and women are at ease with the middle one particular, [vulnerability detection], and what they’re really genuinely unpleasant with are guidelines. This is a large part of our automation story — though they might consider they want the flexibility of guidelines, and genuinely like guidelines, for one particular, it is really just time-consuming. Then, the issue that normally happens is that they both create the guidelines quite, quite narrow, and they miss all kinds of things. Or they create them quite, quite wide, and they catch way as well a lot.

Prospects are receiving a lot more applied to the device learning, and the output of that. And one particular of the motives why we visualize that and signify it [graphically] — our graphs are what make the activities and alerts, but they also make tales and pictures. In some cases the pictures genuinely discuss volumes, versus just an inform that states, ‘bad things occurring.’

So, you have just gotten this big chunk of funding, and you have stated you approach to double the variety of workforce this 12 months. What will that signify, in conditions of your solution?

Hubbard: We consider about the market kind of in two classes: There is the internet-new things, cloud workload defense, Kubernetes safety, container safety, compliance for the cloud. And ChatOps also, the potential to do triage through Slack or other mechanisms — maybe routing of tickets. Now, you have the potential to react and mail info, but ChatOps can get very deep, very immediately. We have a full new suite of APIs that we are releasing this quarter, which will allow us and our customers to method the method greater.

There are items we get requested for that we don’t want to do [from a deployment standpoint], like ship an equipment or do layered software, or single-tenant SaaS — we are sticking to our strengths in multi-tenant SaaS. We are making a European knowledge middle and making out a European existence.

Then there is a established of current and existing technologies that are growing into or coming towards our strengths, for example, safety analytics, safety triage, SIEM and vulnerability administration, as men and women go their main assets to the community cloud. Prospects just started out inquiring us, ‘Hey, can you help lower my SIEM devote? How can I use you as my SIEM?’ We didn’t genuinely layout this that way — the potential to ingest other knowledge resources, I consider, is likely to turn into very vital about the up coming 12 months there.

Beth Pariseau, senior news author at TechTarget, is an award-profitable 15-12 months veteran of IT journalism. She can be reached at [email protected] or on Twitter @PariseauTT.