Opens in a new tab
vmblog logo 2024 wht (updated)

VMblog Expert Interview: New Sysdig CMO Explains Why He Joined, and Talks About the Company Focus on Runtime Security and What's Next

Share: 

David Marshall | Published: January 30, 2023

 

Sysdig recently announced that it had appointed Bryce Hein to the position of chief marketing officer (CMO) after the company experienced more than 120% in new customer growth last year.  To find out more about Hein’s joining the company, and what’s next for Sysdig, VMblog reached out to and spoke with Hein.

VMblog:  Congrats on joining Sysdig as CMO! Tell us about yourself.

Bryce Hein:  I’m a proud dad, lucky husband, and passionate marketing leader based in Seattle, Washington. I started my career on the technical side, including serving as a Systems Administrator in graduate school. Although much has changed over the last three decades, that experience fundamentally shaped my marketing approach to anchor on customer empathy and customer needs. Nowhere is this more needed right now than in cloud security!

VMblog:  In 75 words or less, tell me what Sysdig does?

Hein:  Sysdig is a cloud security company that utilizes runtime context to help companies secure and accelerate application development in the cloud, and ultimately, stop breaches with no wasted time. Sysdig has two flagship products – Sysdig Secure and Sysdig Monitor. The Sysdig team created open source Falco, the standard for cloud-native threat detection, which Sysdig Secure is built on to deliver real-time threat detection. Sysdig Monitor on the other hand radically simplifies cloud and Kubernetes monitoring and helps lower costs with deep visibility into cloud-native workloads. 

VMblog:  What about Sysdig attracted you?

Hein:  I was really picky in finding my next adventure. In a new role, I was looking for three things – a great culture, a company with an innovative approach to a major problem, and a leadership team with both grit and big aspirations. It was important to me to join a company that was going to shape the future of cybersecurity, not just participate in it.

Software has changed the world, and we are now in the next phase with cloud-native application development. Companies must move to the cloud to avoid being left behind. However from a technology evolution perspective, it’s not that simple, companies are still in the early stages of their cloud adoption journey. There is still so much education and learning that needs to take place, and security is arguably the biggest gap. 

Beyond checking the boxes I mentioned, Sysdig stood out because of its commitment to open source and the unique approach they are taking with runtime.

Cloud-native software development is inherently community based and leverages open source technologies. Sysdig was founded on the belief that open source will be a force multiplier for security and development teams. Sysdig is built on several open source tools that the company built or is contributing to and the open source engineering team is impressively large, reinforcing the company’s commitment.

The approach Sysdig has taken to security by focusing on runtime is so innovative that I fundamentally believe the company will ultimately win the cloud security race. It’s no secret that the space is crowded, but Sysdig is the only company that solved the hard problem first – runtime – and it’s going to be hard for anyone to catch up at this point. I have a feeling that in accepting this role I am beginning a journey that I will look back on in my old age and be able to say, “We made a difference in how the world secures software, and man, that was a fun ride!”

VMblog:  Can you tell us a bit about Sysdig’s successes in 2022?

Hein:  I joined Sysdig to build on the foundation that the wicked smart team before me built. 2022 was a great year for the company. Sysdig has a marquee customer base and analyzes more than 7 million containers per day. Last year, the company more than doubled new customer acquisitions year over year, and the team expanded its global footprint, now serving customers in more than 40 countries. Demonstrating the breadth and strength of the Sysdig platform at an enterprise scale, the top 60 customers spend on average more than $1 million in annual recurring revenue with Sysdig. The most innovative companies are using Sysdig and I can guarantee you’re going about your day unknowingly using products Sysdig is securing, from checking out at your local coffee shop to being able to board an airplane on time.

Earlier, I mentioned Falco, which Sysdig created and contributed to the CNCF. 2022 was the year Falco downloads surpassed 50 million. It’s clear that Falco is the de facto standard for threat detection. The 400% adoption increase over the last two years tells me that the world realizes the need for runtime threat detection. I feel this really speaks to the potential Sysdig has considering all the major cloud providers are adopting the technology Sysdig created and is built on.

VMblog:  Many competitors are focusing on shift-left security while Sysdig is focused on runtime security? Why is runtime security so important and is this what you think sets Sysdig apart?

Hein:  Sysdig focuses on the entire lifecycle, from source to run, but you are right, a lot of companies are talking about “shift-left” and neglecting everything else. I recently heard a quote on the Google Cloud Security Podcast that resonated with me, “Detection and Response is all about solving the security problems that the rest of the security org has been unable to solve.” I love this because as you mentioned, everyone is focused on shift left, but even with the perfect “shift-left” security practice, threats can arise in production. We’ve found that 87% of container images running in production have a critical or high vulnerability.

Many different attack vectors exist, and issues like ransomware, cryptomining, or other compromises aren’t prevented by scanning code or images. Not to mention that container vulnerabilities are discovered daily. Your container, which seems safe one second, can become a potential victim of newly disclosed exploits. Shift-left alone is not enough.

If you only focus on shift-left, then what?

“Shield-right” security emphasizes mechanisms to protect and monitor your running services. Traditional security practices with tools like firewalls and intrusion prevention systems (IPS) aren’t enough. They leave gaps because they typically don’t provide insight into containerized workloads and the surrounding cloud-native context.

Additionally, runtime visibility can help you to improve your shift-left practice. Once your containers are in production, a feedback loop to correlate issues discovered in runtime back to the underlying code helps developers know where to focus. Static security testing can also be informed by runtime intelligence to pinpoint what packages are executed inside the containers that run your application. This enables developers to deprioritize vulnerabilities for unused packages and focus instead on fixing exploitable, running vulnerabilities.

The goal of every cybersecurity program should be full lifecycle security.

VMblog:  Given the challenging market climate, what are Sysdig’s plans to grow in 2023?

Hein:  In addition to solving the problems others cannot solve, Sysdig is focused on solving the problems teams need solved. In the current macroeconomic climate, reducing risk while saving money and time is a top priority. As I have been joining customer calls, there are two new features from Sysdig that are changing the game.

The first is Cost Advisor within Sysdig Monitor. With cloud costs spiraling out of control, teams need the ability to correlate cloud cost data with Kubernetes workload usage data to optimize costs. Without Sysdig, teams are using multiple sources of information and static spreadsheets in an attempt to understand their Kubernetes costs. They are essentially blind to where their cloud resources are over or underallocated. Cost Advisor enables teams to reduce cloud service provider bills by up to 40%, which in some cases can be millions of dollars. Additionally, Cost Advisor will help teams allocate the right Kubernetes costs to the right teams and eliminate the need for separate Kubernetes cost tools. 

The second is Risk Spotlight within Sysdig Secure, which helps teams focus on the vulnerabilities that are most impactful by prioritizing the vulnerabilities that have in use exposure, meaning they are exposed at runtime. As applications are often quickly assembled from public repositories, developers unknowingly bring vulnerabilities from open source packages. Most do not warrant a developer’s attention since they are not tied to packages running in production. Without context, developers find themselves scrolling through thousands of vulnerabilities in spreadsheets trying to figure out which fixes matter. Vulnerability noise hides the true risk, leaving the door open to compromise. With Risk Spotlight, teams can reduce vulnerability noise by up to 95%.

The ground-breaking innovations enhance the capabilities of the Sysdig platform and solve immediate problems that customers face today. Developer time and cost management are major concerns for organizations, and Sysdig solves both.

I really appreciate the time today and I look forward to continuing to speak with you and the VMblog readers!  

##