Opens in a new tab
vmblog logo 2024 wht (updated)

Black Hat USA 2024 Q&A: GitLab Will Showcase Its AI-Powered DevSecOps Platform

Share: 

David Marshall | Published: July 16, 2024

 

Are you getting ready for the upcoming Black Hat USA 2024 event, an internationally recognized cybersecurity event providing the most technical and relevant information security research, now in its 27th year.  The event is quickly approaching, taking place August 3-8, 2024, returning to the Mandalay Bay Convention Center in Las Vegas, NV with a 6-day program. 

Ahead of the show, VMblog received an exclusive interview with Julie Davila, VP, Product Security at GitLab, an industry leading and comprehensive AI-powered DevSecOps platform provider.  Make sure to add them to your MUST SEE list.

gitlab logo 

VMblog: Before we get into it, can you give us a quick overview of the company?  What should folks know?

    Julie Davila:  GitLab is an AI-powered DevSecOps platform. We enable organizations to increase developer productivity, improve efficiency, reduce security and compliance risk, and accelerate digital transformation.

      VMblog:  Black Hat is known for its energetic and interactive booths. What unique experiences or demonstrations do you have planned to engage attendees at your booth? What will you be showing off at the show this year?

        Davila:  Visit GitLab at Booth #2915 for GitLab-branded giveaways, a live demo of our latest security and compliance features, and meet our security engineers.

          VMblog: Is this your first time sponsoring Black Hat?  If not, how many times have you sponsored before?  And, what keeps you coming back?

            Davila:  GitLab is excited to return for our third year at BlackHat. We value every opportunity to spend time with our broader community, partners, customers, and contributors.

              VMblog:  What is your message to Black Hat attendees coming out to the show this year? If they take back one message about your company, what should it be?

                Davila:  Relationships grounded in trust and transparency will foster the greatest resilience in an era marked by increasing complexity, risk, and change. Organizations must bolster their resilience by emphasizing three critical components within their software build environments: visibility, governance, and continuous deployment. By focusing on these areas, organizations can enhance their defenses and reduce the time it takes to recover from the next cyber attack.

                  VMblog:  Black Hat attendees are known for being security professionals at the forefront of the industry. What specific challenges do you anticipate they’ll be facing, and how will your solutions help them overcome those challenges?

                    Davila:  Software security is a critical focus in cybersecurity. Organizations must now clearly articulate their security posture and how they protect customers from threats. One significant challenge is the proliferation of point solutions that must be individually purchased, managed, and maintained. GitLab provides a comprehensive platform that streamlines software creation and ensures security, reducing the complexity of managing multiple tools.

                      VMblog:  What are some of the key takeaways of your solution that Black Hat attendees should be aware of? 

                        Davila:  One major takeaway is the integration of various tools within the software development process. GitLab offers a seamless way to incorporate security into the continuous integration process and code contributions. With GitLab, software security becomes a priority instead of an afterthought. Our integrated, platform-based approach provides substantial advantages over disparate, bolt-on tools.

                          VMblog:  The market is a crowded space.  What is it about your company and technology that sets you apart from the competition?  What are your differentiators?

                            Davila:  GitLab is a comprehensive AI-powered DevSecOps platform. By integrating AI-assisted workflows across the software development lifecycle, GitLab supports everyone involved with developing, securing, and deploying software-increasing efficiency, improving cycle time, and strengthening security. As a cloud-agnostic provider, GitLab allows customers to have a consistent workflow, regardless of where projects are deployed. GitLab empowers teams to balance speed and security by automating software delivery and securing the supply chain end-to-end to help teams produce higher-quality code to ship better, more secure software faster. 

                              VMblog:  Is your company launching anything new at the show?  Without giving too much away, can you give us a sneak peek?

                                Davila:  GitLab recently announced new innovations across the platform to streamline how organizations build, test, secure, and deploy software in GitLab 17. As part of the release, GitLab introduced GitLab Duo Enterprise, a new end-to-end AI add-on, which combines the developer-focused AI capabilities of GitLab Duo Pro-organizational privacy controls, code suggestions, and chat-with enterprise-focused AI capabilities to help organizations proactively detect and fix security vulnerabilities, summarize issue discussions and merge requests, resolve CI/CD bottlenecks and failures, and enhance team collaboration. Additionally, over the past year, we have significantly invested in extending GitLab’s detection and remediation capabilities and will showcase many of our new features at Black Hat.

                                  VMblog:  What are some of the top priorities security leaders should be considering for 2024?

                                    Davila:  In 2024, security leaders should prioritize operational resilience alongside threat prevention and mitigation. This includes regularly testing and protecting backups and ensuring software can operate in degraded states during security incidents without halting operations. While we can’t prevent every security incident, we can ensure organizations continue functioning effectively even when issues arise.

                                      VMblog:  Looking ahead, what excites you most about the future of cybersecurity, and how do you see your company playing a role in shaping it?

                                        Davila:  While we are still in the early stages, AI’s potential to transform cybersecurity is immense. AI can help developers work more efficiently while creating more secure code by fully automating security processes to remove them from the developer’s workflow. GitLab is a DevSecOps platform, which means we integrate security throughout our entire product, including AI features. For example, we recently released new features in GitLab Duo, our AI assistant, that automatically detects and resolves vulnerabilities when they are found.

                                          VMblog:  Beyond your specific offerings, what valuable cybersecurity knowledge or insights can you share with Black Hat attendees visiting your booth?

                                            Davila:  GitLab recently released its 8th annual Global DevSecOps Report on the current state of software development. The report surveyed over 5,300 CxOs, IT leaders, developers, and security and operations professionals worldwide on their successes, challenges, and main priorities for implementing DevSecOps.

                                            The report found that software supply chain security is a potential weak spot within organizations. Two-thirds (67%) of individual contributors said a quarter or more of the code they work on is from open source libraries – but only 21% of organizations are currently using a software bill of materials (SBOM) to document the composition of their software.

                                            Additionally, 55% of security professionals report that they most commonly discover vulnerabilities after code is merged into a test environment.

                                            GitLab plans to release the next iteration of the report, which will focus on security and compliance, at the end of July 2024.

                                            VMblog: If you could add one thing to the Black Hat experience to make it even more valuable for attendees, what would it be?

                                            Davila:  Introducing sessions with a birds-of-a-feather format would be invaluable. These informal roundtable discussions allow industry professionals to engage deeply in specific areas of interest, fostering knowledge sharing and community building.

                                              VMblog:  Does your company have any speaking slots at Black Hat?  If so, can you tell us more about those sessions so people can get them on their schedules?

                                                Davila:  Sarah Waldner, Director of Product Management, and Cherry Han, Field CTO, will present a 20-minute session on August 8th, 2024, from 2:05-2:25 PM PT in Business Hall Theater F. In the talk, they will discuss how to advance software security with GitLab’s AI-powered DevSecOps platform, show how to fuse AI intelligence to secure the software supply chain, and discuss industry trends.

                                                  VMblog:  Is your company giving away any interesting tchotchke at your booth?  What is it?

                                                    Davila:  At the GitLab booth (#2915), we’ll give away branded luggage tags, bottle openers, ankle socks, stickers, and plushies. We look forward to meeting many of you!

                                                    ##