The new cyberattack surface is the API layer, according to Doug Dooley, COO of application security startup Data Theorem.
“What networking was 10 years ago, we believe APIs will be for the next 10 years,” he said. “And cloud. Cloud is the true developer-powered infrastructure that can bypass IT and make IT irrelevant when it comes to traditional infrastructure because cloud looks more like code, and less like infrastructure, when you consume it.”
Companies are developing software faster than ever, Dooley added, pointing to Netflix, a Data Theorem customer, as an example. “They make over 300 production software changes a day,” he said.
While Netflix is an extreme example, and Dooley admits “we don’t know any other tech company or software company or financial services company doing that many changes in production software daily,” it illustrates how traditional, manual approaches to security can’t keep up. “Pen testing, consultants, auditors, this kind of very slow, non-automated approached that security has held onto for so many years, these things tend to break in the automated model,” he said.
And because of this, security needs a seat at the grownups table, Dooley added.
Why Security Needs to be at the Adults’ Table“The DevOps team sits at the adults’ table, and security sits at the kids’ table,” he said. “When the kids are crying, every adult stops what they’re doing. And we’ll go help figure out what’s going on with these children crying.”
“Security has that power,” Dooley continued. “And we view ourselves as security people, so these are our brothers and sisters sitting at the kids’ table. But ultimately, we’ve got to get the security folks sitting at the adults table, having a seat at the table where business decisions are being made.”
When companies make a business decision to deploy an application in the cloud, they first consider revenue and app capabilities. “You have to build an application that’s useful, that has really cool features, that gets customers excited about using it — maybe even addicted to the product,” he said.
These are products like Snapchat, Facebook, and Instagram, Dooley said. And, by the way, all three are also Data Theorem customers.
“So you could build the most secure application, but if it’s not usable, and it’s not functional, and it’s not valuable, then who cares? You’ve built a non-usable, secure app,” Dooley continued. This is why he says that “forcing” developers to consider “every aspect of paranoid security though processes” won’t work. It’s unrealistic and unnecessary.
Instead, he argues, developers should treat security akin to performance, scalability, or cost. “These are things that every developer factors into the design of the application,” he said. “If something’s not scalable, if something doesn’t have uptime, if something crashes, if something is too slow, then that impacts commerce and the value that they’re trying to deliver with this new digital service. So, if security is just a bug, or just a feature, then it fits much more easily into the culture and the mindset of what’s going on at the adults’ table. Yes, security is one of 10 things that we have to worry about. But it’s not the No. 1 thing to worry about.”
How Data Theorem Bridges Security, DevOpsThis plays into Data Theorem’s mission as well, which Dooley says it to be both a technology and cultural bridge between security and DevOps. “And one of the big cultural things that we’ve changed, we believe, with security professionals is the idea of embracing automation.”
Founded in 2013, Data Theorem has its headquarters in Palo Alto, California, as well as office in New York and Paris. It claims to secure more than 12.3 million TLS connections monthly and an impressive customer roster: Autodesk, Cisco, AirBnB, Bank of America, Salesforce, American Express, PayPal, VMware, Microsoft, Verizon, SAP, Zoom, and Nike, to name a few.
“What really differentiates Data Theorem from the slew of other security vendors in the industry is that we believe we’ve been the first to deliver a full stack application security analyzer that goes from mobile and web at the client layer to APIs, which we would argue is the new network attack surface,” Dooley said.
Full-Stack Application SecurityThe company sells four products: Mobile Secure, API Secure, Web Secure, and Cloud Secure, and all four provide automated, continuous security across mobile apps, APIs, single-web page apps, and cloud-native apps and serverless functions, as each of the four product names suggest.
The Analyzer Engine sits at the core of all four products. This engine, along with proprietary attack tools, continuously hack and exploit application weaknesses to secure the entire stack. Data Theorem also built its software on top of TrustKit, an open source software development kit used by thousands of developers.
Cloud Secure is the vendor’s newest product, which it just released last month. Between that product and API Secure, Data Theorem is increasingly displacing Palo Alto Networks’ Prisma Cloud in customers’ environments, Dooley said.
And while Dooley claims to be the first full-stack application security analyzer, he says all cloud and application security vendors are going to have to move in this direction — or risk becoming irrelevant.
“If you’re a cloud security vendor in 2021, if you don’t start becoming far more application aware you are not going to be that relevant in 2025,” he said. “Every cloud security vendor has to go up the stack and understand APIs and understand the apps they serve. And likewise, if you’re an AppSec vendor and you’re very focused on web and mobile, if you don’t understand the underlying API underpinnings and the microservices that that app is built on, then you are also becoming less valuable. That’s the collision course that we’re headed into: CloudSec and AppSec. They’re gonna have to become more full stack to be valuable to the customer.”
Comments