Wednesday Jul 10, 2024
Managing Threats Throughout the SDLC with Tomer Schwartz
Howdy, y’all, and welcome to The Cyber Ranch Podcast! Our guest toda is Tomer Schwartz, co-founder and CTO over at Dazz Yup! He’s a vendor! And OMG he’s a sponsoring vendor too! Whatever will we do? But wait, y’all know Allan's rule: Vendors are allowed on the show if and when they can add more value on a given subject vs. any practitioners in The Cyber Ranch network. Tomer fits that bill perfectly! Tomer has worked in the Microsoft Security Response Center, he’s the former Armis co-founder & CTO, current co-founder & CTO at Dazz, who is a leader in the Application Security Posture Management space. Tomer is also a coffee aficionado. Now what does Dazz do and why did we ask Tomer to be on the show? Dazz is in the Application Security Posture Management space, which is relatively new around here, but they also collate and track threat exposure realtime, and also secure the SDLC in a DevOps’y way...
Questions
- The elephant in the room is Gartner’s newest category in this space. Some say ASPM fits into: CTEM, which is Continuous Threat Exposure Management for those behind on eating their alphabet soup. Tomer, what’s your perspective on that?
- Let’s talk about the problem in the ASPM/CTEM space: noise / too much data, no context, limited visibility from code to cloud and everything in between. For real, most solutions suck, as their single pane of glass is a very, very dirty pane of glass, and no amount of Windex is going to help. And our listeners know we believe in 3-4 “single” panes anyway. Is there such a thing as a single pane of glass in the ASPM space? Do we want a single pane? How does it play nicely with my “single” panes from other spaces?
- Here comes the can of worms: Can AI help with this?
- Gartner says by 2026 40% of enterprises will have an ASPM solution - do you agree?
- And then there’s good ol’ UVM - Unified Vulnerability Management. Feels like a past promise that didn’t deliver. And it hasn’t addressed DevOps or even Dev very well at all IMHO. What’s your take?
- How should CISOs be thinking about all of these technologies and practices? It can get very complicated very fast and if it’s not done right the devs will run screaming.
- Where is this all headed? What’s the ideal future state in this space?
- Here’s your chance to tell thousands of CISOs and other high-level practitioners what you want them to know. What do you want them to know?
Check out Dazz at https://dazz.io