The attack window from the discovery of a vulnerability to its exploitation has shrunk to less than 24 hours and sometimes down to just 25 minutes. Is your security team prepared for the speed of AI-driven attacks?In this episode, Ashish sits down with Sarit Tager, who leads Cortex Cloud product management at Palo Alto Networks, to discuss why the post-Mythos era is forcing Cloud Security and AppSec out of their traditional silos. Sarit explains how AI coding agents prioritize generating code over securing it, which can sometimes result in flaws like accidentally deleting production databases within two weeks.We also explore how English has become the new primary programming language, effectively making everyone a potential developer. Sarit breaks down why relying solely on cloud posture management is no longer enough and why deploying active runtime agents is now mandatory to block real-time exploits.
Questions asked:
00:00 Introduction: The Convergence of Cloud and AppSec
01:50 Sarit Tager’s Background: From VP of Engineering to Palo Alto Networks
03:00 Why English is the New Programming Language
06:00 The Problem with LLMs Suggesting AppSec Fixes That Break Functionality
09:30 How AI Agents Can Accidentally Delete Production Databases
11:40 The Attack Window Shrinking to 25-30 Minutes
14:00 The Post-Mythos Fear and the Token Cost Challenge
16:30 Why You Must Deploy a Runtime Agent (Posture is Not Enough)
18:30 Why AI Coding Agents Put Security Second
24:00 Breaking the Silos: The Rise of Holistic Product Security
36:00 How AI Empowers Non-Experts to Investigate Across Security Domains
40:30 Fun Questions: 50 Countries, No Social Media, and Japanese Food
Sarit Tager: [00:00:00] We can put, uh, something in the software that can say, "Within two weeks, let's just delete all production." But we did see it happen, and we did see a lot of very creative agent that apologize for it.
Ashish Rajan: It gives you the illusion that anyone could be a developer, which is probably, like, the scariest part.
Sarit Tager: If I'm a coding agent, then my plan is to create the code.
Ashish Rajan: Yeah.
Sarit Tager: Security come second.
Ashish Rajan: I think the latest stat seems to be less than 24 hours.
Sarit Tager: Sometime even 25 minutes or 30 minutes. Potentially everyone can write code today. Yeah. Someone asked me, "Okay, so if you don't have any runtime agent, so what are you doing?"
Sarit Tager: I said, "Probably praying that he won't be, uh, affected." If someone will try to run one of the frontier on your environment, they will find problems, right? 'Cause no code is really safe by design.
Ashish Rajan: Cloud security and application security were usually silos that no one used to talk about. But today, thanks to things like Mythos and other frontier models, where the attack window from the point of discovery of a vulnerability all the way to it being [00:01:00] exploited is now less than 24 hours, and sometimes down to a few minutes.
Ashish Rajan: That's what's driving a change in how cloud and AppSec is being looked at. I had a great conversation with Sarit Tager from, uh, Palo Alto Networks. She works in the Cortex Cloud space, and we spoke about what is required to change the world of cloud sec and AppSec to come together. And also, what does it mean for us as organizations who already have an AppSec team, a cloud sec team?
Ashish Rajan: How should we be approaching product security in a world of AI where Mythos seems to be top of mind for a lot of people, and preparing for it is even more important than ever. All that and a lot more in this episode of Cloud Security Podcast. If you have been watching or listening an episode of Cloud Security Podcast and have been finding it valuable, definitely drop us a follow on Apple, Spotify, LinkedIn and YouTube.
Ashish Rajan: We are on all the podcast platforms. Wherever you consume your podcast from, a huge shout-out to Palo Alto for sponsoring this particular episode as well. I hope you enjoy this episode. I'll talk to you soon. Peace. Hello, and welcome to another episode of Cloud Security Podcast. I've got Sarit with me. Hey, Sarit, thank you for coming on the show.
Sarit Tager: Hey, Ashish, thank you very [00:02:00] much. Great to be here.
Ashish Rajan: Maybe to kick things off, if you can share a bit about yourself, your professional background?
Sarit Tager: Uh, I joined Palo Alto like two and a half years ago. I'm currently leading the Cortex Cloud, uh, product management and exposure management. My only, I think, fun fact that I always use on my professional stuff is that I used to be a developer and kind of a director and VP, VP engineering before, before I moved to the dark side of being a product manager.
Sarit Tager: Kidding of course, I li- like them both. I think, um, for me, kind of going into the product management on cloud security and application security- Yeah ... is, uh, me remembering myself as a young, uh, uh, young developer trying to solve all the se- security issues, uh, right before production. You know, I'm trying to think about the developers that need to fix these security issues and kind of try to bring the best product for them.
Ashish Rajan: Yeah. It, it's funny you mentioned the dark side being the product management side, 'cause I, I always assumed the dark side is coming from becoming a developer to a cybersecurity [00:03:00] person. But I'm curious because obviously as a developer you would have been dealing with AppSec for a long time either in resolving issues or just trying to basically understand why something is severe.
Ashish Rajan: Um, w- has that changed with AI, or curiosity in the work you've been doing and what you've been talk-- when you've been talking to customers as well? How has AppSec changed now?
Sarit Tager: Yeah. So it changed a lot. You know, I always say that when you are a developer, you know several languages, like several development, uh, languages and programming languages, and then today you probably just need English, right?
Sarit Tager: Right. Uh, like this will be the programming language you need. So I think this changed a lot. I think it's also changed in a way that a lot of the code is being written by an AI agent and not by developer themselves. It has good outcomes and also some very verbose code. Like a lot of code is being written.
Sarit Tager: Not all of it will be, you know, a developer may write uh, much fewer code li- lines. [00:04:00] Yeah. Um, so this will change dramatically, right? I think all of us... You know, I had a discussion with one of my friends that is still a, a developer, and he said, "Well, I have my three AI agent working for me, uh, now, uh, just for, uh, uh, just for writing my d- different tasks."
Sarit Tager: So, um- This kind of, uh, the new developer being more like a manager of AI agents and giving them different intent to do.
Ashish Rajan: Yeah.
Sarit Tager: Um, so this is on one perspective. The other perspective, which I think is very important, we always talk about like who is the owner and how you can actually find security issues, and how you go back from sometimes runtime into, uh, code.
Sarit Tager: And now I think ownership is a bit tricky.
Sarit Tager: Cause if I just said something on the intent, not sure I will know exactly how to fix the security issue. So I think ownership is also, uh, a thing. And the last thing will be, who is the developer, right? Yeah. Used to be developers were people that actually write code.
Sarit Tager: [00:05:00] Potentially everyone can write code today. Like, I know people that do some apps on, on their, you know, for home for s- managing their schedule and things like that.
Ashish Rajan: Yeah.
Sarit Tager: So I think the notion of developer is also changing.
Ashish Rajan: Yeah. I mean, uh, would you believe in the background while I'm interviewing you, I've got a Claude Code running building a website to rebrand.
Ashish Rajan: So it's one of those ones where, to what your developer friend is... And by the way, I'm not even a developer. I started in IAM, so it's like I'm like probably the most fake coder you could find out, out there. Uh, but it gives you the illusion that anyone could be a developer, which is probably like the scariest part, because- Right
Ashish Rajan: so far AppSec has always been about, "Hey, I have SAST, I have SCA, I have runtime security, I have my my infra security pieces in there as well." Are those still relevant, or has that also changed? Like, 'cause obviously, uh, we're talking about the fact that the way software is developed itself has evolved, but the components that were around it, like the CICD [00:06:00] pipelines and all that are they still relevant?
Sarit Tager: So yes and no, I would say. Okay. It's still s- uh, it's still, uh, relevant to find, uh, CVEs within open source, uh, packages, right?
Ashish Rajan: Yeah.
Sarit Tager: Uh, this still need to be done. You still need to make, make sure you don't take packages that has a lot of CVEs or potentially malicious. So there are things that kind of stay the same, and some of the people will also say that static analysis, um, is good for compliance and and they will do that for these measures.
Sarit Tager: I think two th- two things has changed. I always saying, like detection was never the problem in application security, right? We already had too much detection, and the fact that we al- also have LLMs, uh, and they detect things, this is good, but it's never was a problem. The problem was trying to manage all this entire backlog and try to fix things.
Sarit Tager: And two things has changed dramatically. One the fix itself. Yeah. Like what I need to fix and what exactly... I wouldn't say which, uh, LLM, but- ... one of them, [00:07:00] on one of my, uh, test he suggested that I remove, uh, a flag, and I said, "No, but I cannot remove it. It's part of-" "... my functionality, right?"
Ashish Rajan: Yeah,
Sarit Tager: yeah, yeah. Yeah, it's not a problem, but the, but the software will not work. It will be super secure, but not- Yeah ... to work to what I need. So I think, um, understanding the fix is still something that requires a different a bit of a different approach.
Sarit Tager: And the second thing will be, I think going to what AI is being used for, like different attacks, and the fact that the attacks became not deterministic.
Ashish Rajan: Yeah.
Sarit Tager: You should also, add more non-deterministic, uh, attack finding or, uh, kind of a novel attack within the code. So, um, the attacks are changing a bit. The old attack still works, right? You still-- With this, we still see people, uh, take advantage of a CVE to actually exploit something.
Ashish Rajan: Yep.
Sarit Tager: But the second one is that you have to also incorporate some of the non-deterministic stuff to make sure that if an attacker [00:08:00] try...
Sarit Tager: When AI attacker is trying to actually access your, uh, your environment or your application, you will be able to kind of, uh, have the right guardrails in place. So yes and no, I always say that technology is changing.
Ashish Rajan: Yeah.
Sarit Tager: The human mind a bit, it's a bit more slower.
Ashish Rajan: Yeah. Do, uh-- And, uh, this kinda makes me also think that you know how at least, So to your point, the evolution of attacks have not changed the infrastructure if-- and correct me if I'm wrong, it hasn't changed the need for a CICD pipeline.
Ashish Rajan: It hasn't changed the need. It's just different, uh, it's a newer kind of environment. Is that... Did I get that right?
Sarit Tager: It's more like it's still you have-- it's still the, the build process, and you still have to do some of the testing within the, this, uh, different stages. I think it changed the way we think about fixing things, ri-right?
Sarit Tager: Like, it's more about focusing on what is really matter and make sure that you fix it as early as possible, because now [00:09:00] people understand that they don't have much time between the actual attack-- between the actual exploit and the actual attack. And to be able to actually address this, you must be, I would say, prepare in advance and make sure that you fix things.
Sarit Tager: So, um, the environment changed a bit for some of the more, you know, how you build models and st-stuff like this. But if you-
Ashish Rajan: Yeah ...
Sarit Tager: run your application, then this stays similar, but you have much more. Like think about agent running within your code environment- Yeah ... and they're using some MCPs that you don't know of, and they try to do some things.
Sarit Tager: Also, I would say the security kind of enhance in a way that it used to be like I'm doing a wrong SQL injection, right? Something like that. Yeah. But-
Ashish Rajan: Yeah ...
Sarit Tager: now about, did I write something in the code that may delete all my production within two weeks or something like that? So, um-
Ashish Rajan: That's probably more scary.
Sarit Tager: Yeah. The second one- Yeah ... right?
Ashish Rajan: Yeah, yeah, yeah. I mean, I guess, well, also, 'cause I mean, to your point, uh, [00:10:00] another thing that made me think of this when you mentioned deletion of production database is also things like AI agents are also a norm, which didn't really exist in the previous AppSec world.
Ashish Rajan: And now, uh, we're obviously talking about cloud pieces as well, 'cause I don't know if as a developer you were ever involved in the infrastructure side, 'cause it was like, hey, it was a platform team that looks after, you don't have to. But somehow the lines seems to be blurring between cloud security and AI AppSec security, and maybe to an extent AI security as well, 'cause depending on how you look at it.
Ashish Rajan: Is the similar kind of changes happening in cloud world as well, and why does it seem to be converging towards AppSec?
Sarit Tager: So basically... Well, I was involved, by the way, 'cause- Oh, yeah ... I started the cloud very early, and hence- Oh ... uh, like I used to kind of spin up, uh, Kubernetes by myself, or even before that it was Docker Swarm.
Sarit Tager: We'll not get into all these, uh, different, uh, technologies. Yeah. Um, I think cloud and AppSec are kind of converging from two reasons. One, [00:11:00] people understand that they cannot, customers cannot wait for the things to be in production to- Yeah ... solve or to actually understand them. So I think in a way the, the, I would say the revolution of AI, um, make it more clear that you have to have both protective measures, like you have agents that actually blocks, um, malicious, uh, traffic, but also have something that's much more pre- proactive in a sense that you try to fix before you go to production.
Sarit Tager: Yeah. 'Cause the entire timeline is shortened in a way from attack-- from exploit to attack. And then if you don't b-be preparing in like advance, you will have to manage this while you are in production. I think this is the reason we kind of see conversion between cloud and AppSec to say, "Now it's our problem," right?
Sarit Tager: "We need to make sure that our production is much more safer."
Ashish Rajan: And how short is the timeline? Do you have some, uh, stats on any numbers you remember? Like, I think in terms of, uh... 'Cause I think [00:12:00] the latest stat seems to be less than twenty-four hours. Yeah. Like that's really short.
Sarit Tager: Yeah. Sometime even few min-- even like 25 minutes or 30 minutes.
Sarit Tager: It really depends.
Ashish Rajan: Wow.
Sarit Tager: Okay. But think about like the older, the new stuff about malicious packages and the fact that for, in one re- in one, like you download the latest, uh, NPM or PYP, and then you have something which is malicious within your environment. So one more thing that kind of, uh, I think beli- kind of brought into this is that you need to protect your development environment in a much more like you have to invest in this.
Sarit Tager: Like in the past, developers, uh, even today, like developers can do-- They have a very extensive permission, right, to everything 'cause they need to run things on their machines. They need to access the repo, which is usually the, the company, um, IP. So they have an access to a lot of things. While we assume most people are, are, uh, they don't want to do anything, any harm to the company.
Ashish Rajan: Yeah.
Sarit Tager: When [00:13:00] you activate AI and you cl- activate agents, you don't necessarily know what they will try to do. And- Yeah ... a CISO once tell me that a user will probably give up after tree tries to do something which is not- Okay ... uh, uh, I would say safe. Yeah. An agent will never. And I think this is important in sense of because developer has such an excessive permission and because they can do a lot of things, they can run things, we need to make sure that we kind of, protect it from the beginning, whether it's the code, but also the environment itself.
Sarit Tager: Like which MCP are running, which type of skills, what exact- which agent are running there, and how this kind of form a code that may not be safe to be deployed, so.
Ashish Rajan: Do- does the whole release of models, or at least the limited release of models like Mythos and stuff, is that actually driving a lot of this exploit I guess in the, that's why the timeline reduction between your time to discovery versus time to exploit, [00:14:00] uh, are those things like advancements in the frontier models also driving that?
Ashish Rajan: And maybe to your point, that's why the convergence seems to be there's a, a bit more urgency to the convergence.
Sarit Tager: Yeah. So everyone is scared by, you know, that any of the frontier AI will find something that they didn't prevent in, in the past. So this drives a lot of the conversation on how, uh, you should handle, uh, uh, we call it a post Mythos attacks.
Ashish Rajan: Yes.
Sarit Tager: Which most customers are very scared about, and then they go into you know, some, "Okay, I will build myself something that will scan everything for me and will be, uh, ready for it."
Ashish Rajan: Yep.
Sarit Tager: And then they found out that the cost is really a challenge on this one, like the cost of tokens. So, uh, I think this will...
Sarit Tager: Someone told me this is the new economy- Yeah ... uh, trying to figure out how to solve the, the token, uh, um, challenge. So yeah, post Mythos, I think most it's much more real, and you can actually understand that if someone will try to run one of the [00:15:00] frontier AI on your environment, they will find problems, right?
Sarit Tager: 'Cause none, no code is really safe by, uh, by, by design.
Ashish Rajan: Yeah. Yeah. And are you finding the, the s- security leaders and CISOs you're talking to, are they basically having, like a different approach to running security programs with AI and with the onset of a potential Mythos release on a wider scale, or maybe even available on the open source models as well?
Ashish Rajan: How... 'Cause I mean, most people, obviously you're talking to a lot of enterprises, they already have an AppSec program, they already have a CloudSec program. Like, how do you-
Sarit Tager: So- How
Ashish Rajan: do you approach uplifting it?
Sarit Tager: I think, okay, let's put it like this. I think one thing that is very clear- Yeah ... is they, some of them understand that they have to prevent it much earlier.
Sarit Tager: So this is one. Like they do- Right ... understand they need to be, even if the... Like, usually I'm saying that AppSec is if you go from, like, SOC to AppSec, then SOC is an actual attack, you cannot ignore it.
Sarit Tager: Yeah. Push where it [00:16:00] seems like within your environment, so it's a bit... It, it is scary, but it's not an attack yet.
Ashish Rajan: Yeah.
Sarit Tager: And AppSec is kind of the potential of being attacked, so it's kind of the first waveform from a an actual security issue. I think because the entire timeline is really shortened, then we do see a lot of more customers thinking about how they can protect their environment much earlier, so they want to put guardrails within the developer, uh, environment, whether it's IDE or CLI or something like that.
Sarit Tager: They do understand that they will have to have a much more clear understanding of who is the owner, who will need to fix it. So everything is shortened. Uh, so this is one perspective. They do understand that they need much, something much more earlier. By the way, it's, we see two, two things.
Sarit Tager: Actually, it's the same thing, but in different approach. One, they all understand that they need to deploy an agent. Yeah. Not an AI agent, but an agent.
Sarit Tager: Like the cloud agent. I can share that someone asked me, "Okay, so if you don't have any [00:17:00] runtime agent, so what are you doing?" I said, "Probably praying-" Ah.
Sarit Tager: that you won't be, you won't be, uh, affected." So runtime agent and runtime protection is something that we see a lot coming up now because this is kind of the, the first line of of defense. And the second one, if you want to be much more proactive and not get into the situation of actually being, uh, uh, blocked, then moving to proactive.
Sarit Tager: And I would say that we saw kind of a wave of co- of, uh, companies trying to do them, not the agent, not the runtime agent, but some of the AppSec program, they try to do it by themselves. Right. And then they assume not as simple as, as it seems 'cause just running the LLMs with no, like, harness, with no, with no specific security guidelines, will not necessarily give determinist- deterministic stuff, and it's not that clear what will need be fixed code.
Ashish Rajan: Also, they were using the LLMs to run appsec queries or maybe hit run the OWASP top 10 on this and see if [00:18:00] what you find, like without a harness, without any of that.
Sarit Tager: No, yeah. Try-- Some of them checked, you know, um, you know, one of the intents I saw in developer they are writing is that I want to do, let's say I want to, to create table, and I said, "Please do it in secure way."
Ashish Rajan: Yeah.
Sarit Tager: And I always say, "Yeah, but..." If I am a coding agent, then my plan is to create the code.
Ashish Rajan: Yeah.
Sarit Tager: Security come second.
Ashish Rajan: Yeah.
Sarit Tager: Kind of to your point, uh, we see a lot of different approaches into, uh, into the how they do appsec program, what they actually focus on '
Ashish Rajan: Cause you find that 'cause I mean, a lot of people may argue, and because found-- frontier models gives the illusion that, hey, anything is possible.
Ashish Rajan: And a lot of people may listen to this conversation and go, "Well, Sarit, I may just tell my developers, 'Next time you do a, create an S3 bucket, make sure secure is a word they use in the prompt.'" And well, isn't that, is that, isn't that good [00:19:00] enough at that point in time? It would b- then I'm not required apart from, uh, looking at my CNAPP or CSPM tool to go, "Hey, what's my previous problems that I need to deal with moving forward is solved."
Ashish Rajan: I- is-- Am I make, making it too simple, and is it not, it's really not that simple to just tell it to be secure and just works?
Sarit Tager: No. So here is the thing. So first, remember that this is kind of a two goals for the agent. First, create the code, and then make it secure.
Ashish Rajan: Yeah.
Sarit Tager: The first one is the important one for a coding agent, right?
Sarit Tager: Not a security one. But as a coding agent, you have to m- first make sure that you have a code.
Ashish Rajan: Yeah.
Sarit Tager: This means that if there will be a kind of a contradiction bet-between the two, it will fi- it will kind of, uh, work, work with the, let's make sure we have a code. So this is one. The second one is, one of the things in, in AI is the complexity of the attacks, right?
Sarit Tager: I may have solved something, uh, I would say, [00:20:00] like you said, CSPM stuff, maybe so-solve something that is, uh, clear.
Sarit Tager: But there is another way to get in and exploit other things. And also, we should remember most of the enterprise companies already have a lot of code base, right? They have their own code base.
Sarit Tager: Yeah, yeah.
Ashish Rajan: Yeah. And
Sarit Tager: the code base was written by a lot of people, some of them not in the company. Yeah. And this create kind of a risk. So to your point, it's not that simple to make sure that you have the right security. And even if you tell to kind of a coding agent to, so do it as secure as, as you can.
Ashish Rajan: Yeah.
Sarit Tager: It may result in not having, uh, a code at all, which I don't think is the right one. So you have to balance between security and code, and especially with the velocity of of the software being developed such rapidly. Um- Yeah. Like it has to be secure, and it's been, uh, deployed to production like every day, somet-sometime even more than once every day, depends on the application.
Sarit Tager: You have to be very [00:21:00] strict on what you want to make sure your production is not getting, right? Or getting any, uh... And again, as I mentioned, you can put, uh, something in, in the in the software that can say, "Within two weeks, let's just delete all production," which I think is a bit different to security.
Sarit Tager: It's more malicious activity. But we did see it happen, and we did see a lot of very creative agent that apologize for it.
Ashish Rajan: Yeah.
Sarit Tager: Kind of, uh, these things.
Ashish Rajan: Do-- I think, uh, what I'm hearing so far is that AI has changed the landscape, and AppSec is definitely seeing it. How different is it in the cloud world?
Ashish Rajan: Like, obviously, now people are thinking about building AI workloads using the AWS features or GCP features. So people who have had a CSPM or a CNAPP for a while, they probably still continue to use it. Has that side changed as well and... or is that also converging with AppSec, and how is that evolving?
Sarit Tager: Tr- I think three ch- three changes there.
Sarit Tager: One will be that there are newer risks, right? That are [00:22:00] being raised because we have AI agent AI applications. The second one, remember my, my, uh, comment on the fact that the attacks be- became much more complex.
Ashish Rajan: Yes.
Sarit Tager: So it's not enough anymore just to look at one or two single configuration program, and you have to look at the real possible, uh, novel attacks, like things that may not be deterministic in advance.
Sarit Tager: So this is another thing that is really much, uh, uh, being impacted. And the last one is that you do understand that you cannot have just a posture, right? If in the past you said, "Okay, I can do just posture," today it's very clear that you have to have a runtime agent, and you have to have something that will block.
Sarit Tager: Mm. Even if you have the perfect cloud and application security program. So yes, attacks has changed the fact that AI agent are there and they have their own identity, and, like, this is another-- it's probably a topic for another podcast, but identity of agent is kind of [00:23:00] a, a big thing. Like, what will be the identity?
Sarit Tager: What permission we will give them? How can we track back and log on everything they are doing? Yeah. And so all of these things is really changing the cloud as well. As I mentioned, I feel that the two that are really, really impacted are the runtime agent adoption and then the prevention side, but also the way we look at posture and the fact that it's not yet just about deterministic rules.
Sarit Tager: It has to be m- something that is much wider.
Ashish Rajan: Uh, I guess one of the que- one of the, one of the things that people alw- always come down to, and you kind of touched on this earlier as well, is that now that AI is available to most people, it may seem like an easy thing for me to just plug in a bunch of LLMs and pull information from cloud, uh, 'cause now everyone has an MCP server.
Ashish Rajan: AWS has an MCP server. Google has an MCP server. I'm sure you guys have an MCP server as well. I think I kind of understand the urgency has increased for, hey, now the time to discovery and time to exploit is quite short. Sometimes it's 24 hours, sometimes [00:24:00] a few hours as well. And cloud sec, app sec both have evolved on their own.
Ashish Rajan: But don't organizations have, like, them as separate teams? 'Cause almost every CISO or security leader out there who's in the cloud sec and now say app sec space, are we saying that their roles are merging or partnership? Or is it more like, "No, we only need one of you, we don't need both."
Sarit Tager: So actually, I feel it's kind of merging to something that is also in some of the bigger organization, like product security, right?
Sarit Tager: Yeah. I need to make sure that the product is secure, whether it's being secured by the shift left of it, like within application security or within the cloud. So it's, uh, a merging. Mm-hmm. And I also think that people understand it's not yet about different layers, right? It's not about having data people, identity people, and infrastructure people, because all of them together can create an attack and nobody will say, "Oh, this is being done only on the data part, so it's not me."
Sarit Tager: Like, all attacks are much more complicated. And as I [00:25:00] feel that with AI and the fact that you can actually investigate with AI and actually- Yeah ... saw in the system what is happening, you should be much more, I would say you need to look at things in much wider way rather than just no single thing, because it's never-- Like, the attacks within the AI are never a single thing.
Sarit Tager: It's usually trying to do exploitation over different category and different, uh, layers.
Ashish Rajan: So product security, to your point the for, for lack of a better word, discipline of app sec and cloud sec is evolving into more, "Hey, we need data points from identity, app sec, cloud, runtime." That all needs to be in one place rather than, "Hey, I'm talking to Sarit for app sec, another person for cloud."
Ashish Rajan: Exactly. And then I think you said something really well just before about the different signals and how to pick the signal from the noise in a way that all these alerts are ringing in which to what you were saying make look at benign in the beginning. [00:26:00] It's just could be like, "Hey, uh, I could just be an AI agent asking, 'Hey, what are my permissions?'"
Ashish Rajan: Or like just curios- just curious, "What are my permissions? Can I access this S3 bucket over here? Can I access that S3 bucket over there?" And like, but then you're like, "Oh wait, I, I..." And, uh, it goes back to the identity conversation that we had as well. I don't know if it's actually Ashish or I don't, I may be an agent from Ashish or a rogue agent as well.
Ashish Rajan: There is the whole identity thing there. Do you find- W- what role or what's the importance of runtime security in this? Is it more from a, now that, okay, we understand product security is where you see the direction of most organizations that are mature enough, they're seeing this they're going in the direction of product security.
Ashish Rajan: Where is runtime security sitting? 'Cause that's usually used with security operations. Or is that also being a m- being looked at by, uh, the AppSec and CloudSec folks?
Sarit Tager: So I think the CloudSec folks understand that it's not enough to do posture.
Sarit Tager: Right? They have to make sure that they [00:27:00] are deploying agent, runtime agents, and protect their environment.
Sarit Tager: 'Cause even if you be the most secure, uh, and I didn't see the company that actually fixed everything for application security, not yet, but maybe there is a company like that. Even if you do everything right on the application security side- Yeah ... you will still have some unknown, and this has to be protected by a runtime agent.
Sarit Tager: So to your point this is very important in sense of putting the right guardrails, in this case- Yeah ... the protection. Yeah. Uh, by the way, yesterday I talked with, uh, a customer, and we-- I asked him about, like, he was looking at the posture of the cloud, and I said... And he said, "I'm sending all my critical posture item into my SOC."
Sarit Tager: And I was asking like, "It's not an attack, right? It's just an, uh-" Yeah. "... it's a posture issue." He said, "Yeah, but it's attack to be happened, right?"
Ashish Rajan: Yeah. '
Sarit Tager: Cause they are the critical one. So I think the kind of the fact that the information is available for so [00:28:00] many of these, uh, different... If you think about the old days when if you're in app sec, everything you saw was just signals from code and pre-production.
Sarit Tager: If you're a cloud, everything is, is saw just posture, and if you are a runtime, then it will be only about, like, things from, uh, runtime. I think the fact that now the data is open to everyone- Yeah ... they are asking questions. I'm sure c- I'm sure SOC analysts will be much more happier if we will find things before the actual attack will take place, right?
Sarit Tager: If we will- Yeah ... see something that is potentially an attack within a posture, then you say, "Okay, I, I saw these kind of things, uh, in, uh, like past past, uh, cases of attacks, so now we want to make sure that you are fixing that." So I think, um, we do see a lot of kind of, uh, how do I protect my application, whether it's attacks, runtime prevention or posture.
Ashish Rajan: That's that's definitely a great answer because to your point, runtime security it's funny because I'm sure you remember this. When people used to talk about security in cloud, we all assumed it was real time, but we realized, oh, [00:29:00] actually no, it's not real time, it's like near real time- Right ... which, which has its own meaning.
Ashish Rajan: But these days with AI and the way attacks are changing, the understanding is that the, uh, inten- the attacker, once they're inside, the window for them to go from zero to, I don't know, 10,000 agents doing multiple things is very short as well. W- with that in mind, if we were to take a step back and kind of, bring it for the CISOs who are already have an AppSec program, already have a, a CloudSec program.
Ashish Rajan: They're, they were thinking that, oh, I'm gonna build an AI security program. But sounds like is it the A... Is this a component of the AI security program that you see people use? Uh, and 'cause there's an organizational change, and that's what I'm trying to get to, is to how do you even address or what's the right way to start this?
Ashish Rajan: Is CloudSec the, the right place to start this, or is AppSec the right place to start this?
Sarit Tager: So I will start with your last question. Unfortunately, the co- the answer is both. You [00:30:00] cannot have within the era of AI and, and like frontier AI attacks, you cannot have one without another, right?
Ashish Rajan: Mm-hmm.
Sarit Tager: You have to have runtime protection 'cause you have to make sure that you are protected in real time.
Sarit Tager: Yeah. But you also have to manage your application security to make sure that you are not sending a very exploitable application into your production Uh, about AI security. This is actually a very fascinating s- uh, discussion I have with a lot of different customers, and this is varies between I will be...
Sarit Tager: Okay, I have an I have a budget for my AI security, and then you say, "Yeah, but you do have AI within your developer environment. You have it within the cloud. You have it within your CICD." So is it really like a general, like a different one? In my perspective, it's AI is more like a layer on top of everything we know, right?
Sarit Tager: We will have agent- Yeah ... within the cloud. We will have identities that requires things. So these agents will access, uh, sensitive data. They will do changes on the [00:31:00] infrastructure. The same will go for developers, right? We have developers that are now using agents to run things. We'll have agents that run CICD.
Sarit Tager: So if you say I have an AI program, AI security program, it seems like you basically said, "Yeah, I'm rebooting the, my s- entire security, uh, kind of program from the start." 'Cause I feel everything will be within AI, and it's another layer of complexity and attack or attack surface on top of everything we know.
Sarit Tager: So you will have a AI basically ev- everything. I don't think we can u- we can say, "Yeah, someone will do cloud security, someone will do apps- application security, and yeah, this one will do AI." 'Cause then the agent will find a way to ca- actually go between these programs and find a way to exploit. So it has to be a unified one.
Ashish Rajan: Of course, to your point, we, these are all human-created boundaries. These are not AI boundaries.
Sarit Tager: Exactly. Like the AI is not saying, "Oh, okay. Now I'm in the [00:32:00] era of trying to create an attack. Maybe it's not my job." No.
Ashish Rajan: Yeah.
Sarit Tager: It will try whatever it actually can do. So I think it's more like... I think the rules are a bit, uh, blurry, and I think, uh, AI is everywhere, so I don't think- Yeah
Sarit Tager: it's... And again, there are some things that are more, uh, unique, like for example, if your data is going, uh, to an LLM, LLM, you want to make sure that you are not being exposed. So th- in this case, it's a, it's a different thing, right?
Ashish Rajan: Yeah.
Sarit Tager: But in sense of AI agent being deployed on cloud and being deployed on developers, basically it's more identities and more, in, in a way, more user to actually make sure they are not doing I would say not smart stuff.
Ashish Rajan: I mean, fair. So what's your thinking with addressing some of the Top of mind things that if people were to start doing this, your point, they need to start at both sides, AppSec and CloudSec. Are there, Posture is still important, [00:33:00] so we're not saying posture is not important.
Sarit Tager: No, it's
Ashish Rajan: very important.
Ashish Rajan: We're, we're, we're just saying that runtime is also probably a higher priority because of the Mythos of the world where you don't know what zero day is coming your way, so you probably wanna evolve for that too. But at the same time, um, a lot of people probably have what's the word for it? It... You don't wanna shake the board, but at, at the same time address both sides 'cause the whole AppSec conversation, even from a language perspective, is about how much coverage I have across my code.
Ashish Rajan: Whereas in the cloud context, like how many accounts have I covered? It's such a, such a different way of thinking. I'm curious from the examples that you've seen where people have had product security, what does that look like in a-
Sarit Tager: Well, look at it, if y- if you think about like where we see... Okay, let's talk about infrastructure, data, and identity, right?
Ashish Rajan: Okay. Yeah.
Sarit Tager: At the end, if I'm an application owner-
Ashish Rajan: Yeah ...
Sarit Tager: and I want to make sure that my application is safe, then yeah, data [00:34:00] identity and, and infrastructure is part of my application, right? Yeah. But in the end, I want to make sure that my application is protected.
Ashish Rajan: Yeah.
Sarit Tager: And I think this is how we kind of connect between AppSec and CloudSec, because CloudSec, if they want to report back to the business saying, "I have like 1K accounts, and they are all covered," and then I as in a business owner will say, "Okay, but where my application is actually deployed within this 1K account," right?
Sarit Tager: I care about my application as a business owner. I want to make sure that it-- you gave me all the measures to make sure that my application is protected because it contains sensitive data or doing some sensitive actions.
Ashish Rajan: Yeah.
Sarit Tager: And I think this is how I see the connection. Like if you talk about the business impact of it and who is the business owner, and the fact that you have to talk in application, this is how you bridge the gap between let's talk about application versus let's talk about infrastructure, data, and identity, which are all important, but they all have more to just like looking at [00:35:00] just the infrastructure layer or just the da-data layer. '
Ashish Rajan: Cause you know how the reason I keep coming back to this is because AppSec, and you've been a developer before, it's like knowing languages, right? An infra person knows network and knows, maybe knows cloud as well these days.
Ashish Rajan: But it's like, that's where my q- initial question was coming from in terms of how does it kind of marry up together. And I agree to your point that the business normally doesn't really care if it's a cloud sec problem or an app sec problem. They care about the fact that, hey, my crown jewel, AKA my internet banking app, is that protected, yay or nay?
Ashish Rajan: I don't care if AWS in the background or written C# or Java or any of that. That's irrelative. Uh, th- th- that's not relevant at all for this particular problem. I'm curious in terms of what are you seeing as some of the things, maybe some of the attacks or some of the newer ways that people have found that this helps them.
Ashish Rajan: Like 'cause in my mind, when I hear cloud sec and app sec combined, that means I just get a [00:36:00] holistic view of a problem started in cloud, and then in apps I saw, oh, actually it was a change we did in the GitHub request or whatever. Is that the kind of future we are moving towards?
Sarit Tager: You remember we said that people understand languages?
Ashish Rajan: Yes.
Sarit Tager: Uh, and you said before that you have something that's running in your background. I hope it's still running. Yeah.
Ashish Rajan: Uh-huh.
Sarit Tager: That's rebranding your site. I think the fact that everyone is now exposed to data, right? Yeah. Potentially, I, I know nothing about a country I want to travel in, right? Yeah. I will go into any of the...
Sarit Tager: We won't say names, but any of the chat, and I will ask to build a plan for a travel in this country.
Ashish Rajan: Yeah.
Sarit Tager: Think about this in our world as well, right? People that used to be just a network expert or just an infrastructure expert can ask, can now ask the modelers to explain them more about things that they don't necessarily within their original space of expertise, and now they believe they know more.
Sarit Tager: And I think this is why you [00:37:00] see a conversion of the product security, because potentially a cloud security can say, "Can you please check which repo is, uh, is actually producing this, uh, application? Can you also check if this repo was recently updated?" See how many questions I can do in, like, two minutes without knowing anything about repo, whether it's GitLab or GitHub, or whether it's Bitbucket, or whether I'm using Jenkins or GitLab Action.
Sarit Tager: I can do a lot just by native English, and I think this kind of changed the way we look at everything in perspective. And I... Now that the data is available for all-
Ashish Rajan: Yeah ...
Sarit Tager: more they will not be necessarily an expert, but they know enough to actually understand what is the flow. So I think this is something we do see change a lot.
Ashish Rajan: What do you see, uh, uh, CISOs and leaders use as a reasoning for helping push this forward in terms of unification and [00:38:00] product security, let's just say in any of the conversations that you had with your customers? Do they, uh, share how they are presenting this to the board or the senior leadership for, "Hey, why does this need to combine?"
Ashish Rajan: Are there, uh, metrics that has been, that may- maybe they requested or something that kinda was helpful?
Sarit Tager: So I don't think in most of my customer conversations, it really de- depends, right? We will see different, uh, maturity of organizations-
Ashish Rajan: Yeah ...
Sarit Tager: in sense of what they want to do. But I think they don't necessarily talk about the manpower, but more about the problem.
Sarit Tager: The fact that if you want to have a better solution or better response to these attacks, you have to take a different approach, which is more an holistic one. I think this is coming from this area instead of saying, "Yeah, now we have one, just one thing." It's more about, like, how we can make sure that if we see something on the cloud and, or whether we see something on the application security, we have a more, much more holistic way on looking at this and then reduce the [00:39:00] time to remediate, reduce the ni- reduce the time to actually response to any of these attacks.
Sarit Tager: So it's more from, uh, the security outcome of things and less from the people perspective.
Ashish Rajan: I love that. We've spoken about breaking the silos for a long time, but until now- True ... it seemed almost impossible to break the silo between cloud and AppSec.
Ashish Rajan: So maybe, uh, this is the- It
Sarit Tager: seems, it seems the AI agents are pushing us to
Ashish Rajan: do that. Yeah, yeah. I mean, that is, that's one good thing about AI in that case, I guess. They are basically sending us in that direction, which we should have traveled to a long time ago, but maybe DevSecOps itself would have not happened in that case.
Ashish Rajan: But is that still relevant in this world with AI, the DevSecOps thesis? You know, people obviously have- Well- ... hey, I need a champion, uh, who's a security champion in my team
Sarit Tager: I think to some extent, even with th-these models, and this is currently, right? It may change within a few months. You still need to some complex thing, a, a, a human that may, may not, may be a [00:40:00] bit more, uh, kind of experienced.
Sarit Tager: Just, I say just for the current time, 'cause I do see this being, become an agent, right? Yeah. Like someone I train. Like for if you're a security expert, if you train an agent that will, uh, make the same decision you are doing, then you don't need... It's what we saw in the code review, right? Like y-code, code review was done, uh, by experts usually, or someone that is, uh, more, uh, has more experience in this area, and now it was changed by agents.
Ashish Rajan: Mm.
Sarit Tager: So to your point, probably kind of someone that do DevSecOps or, or security will be, uh, will be, uh, trained by someone like that, but potentially can be replicated much easier.
Ashish Rajan: Awesome. Well, those are all the technical questions I had. I've got three fun questions for you as well. Sure. Uh, first one being, what do you spend most time on when you're not trying to solve the app sec, cloud sec problems of the world?
Sarit Tager: Traveling. Oh, really? I really like to travel different coun- different, uh, countries. I have-- I've been to [00:41:00] 50. Um- Wow. Yeah. And I'm counting the States only as one, right?
Ashish Rajan: Yeah, yeah, yeah. I mean, yeah, fair. United States is definitely one. Yeah. Uh, but countries, yeah. 50 countries so far?
Sarit Tager: Yeah, so far. Oh, wow.
Sarit Tager: So I still have a lot of my list, but this is, uh, when I spend my time. I like to, to look at the different cultures, especially, like, so different to see different countries' kind of the people and the s- and the views and, and the culture and the view. Like, it's a lot of things, so traveling.
Ashish Rajan: Awesome. Uh, second question.
Ashish Rajan: What is something that you're proud of that is not on your social media?
Sarit Tager: See, which is not on my social media?
Ashish Rajan: Yeah, which is not on your- I
Sarit Tager: don't know if it, I don't know if it's uh, PC to say that I'm not that of social media person. Um-
Ashish Rajan: That's a
Sarit Tager: good
Ashish Rajan: thing ...
Sarit Tager: uh- So every-
Ashish Rajan: everything
Sarit Tager: is
Ashish Rajan: very proud of.
Sarit Tager: Yeah.
Sarit Tager: I usually say that I have a lot of friends from different, uh, different, uh, time of my life, like from high school to like university, and work, and stuff like this, [00:42:00] and I actually keep in touch with them without any social media help.
Ashish Rajan: Wow.
Sarit Tager: Yeah.
Ashish Rajan: Wow. That is something ach- that's incredible 'cause I don't think I speak s- I don't know the last time I spoke to pe- people who were in my school, so I mean, well done. And this is without social media as well, so I think-
Sarit Tager: Oh, wow. Like, I feel that true friendship should probably live outside of, uh, social- It
Ashish Rajan: should be an offline mode rather than like an online mode. Yeah. Fair. That's a, that's a fair point. Final question. What's your favorite cuisine or restaurant that you can share with us?
Sarit Tager: Uh, wow. First, I bake. I didn't talk about it, but I do a lot, lot of baking. It's usually engineers. It says that engineers like to bake 'cause it's, it's accurate in the same way.
Ashish Rajan: Very precise, yeah.
Sarit Tager: Yeah. I'm usually going with Asian food. This will be- Oh ... my thing. Japanese, to say.
Ashish Rajan: Japanese. Oh, there you go.
Ashish Rajan: Yeah. But I- I'm look- I'm looking forward to some bakery recommendations from you as well for London as well someday. But thank you so much- Yeah ... for that I mean, I guess I definitely enjoyed the conversation. So I, I, it's [00:43:00] one of those things where we have been talking about cloud sec, app sec, breaking the silos for a long time, and dev sec also is the path.
Ashish Rajan: But maybe to what you said, AI is the way we move and push that forward. Uh, where can people learn more about the work you guys are doing with Cortex Cloud and everything else? And, um, yeah, where, where, where can people learn more about the work you guys are doing at Cortex Cloud?
Sarit Tager: Yeah. So they can visit our si- our website, of course, and some of the webinars we do.
Sarit Tager: So a lot of material is, is living on the social media as well. But
Ashish Rajan: Perfect. And, uh, I will put some of the links over there as well. And for people to get in touch with you, is LinkedIn the only social media? Yeah. Um,
Sarit Tager: yeah. This is the only social media that I actually
Ashish Rajan: use. Very, very professional at that point in time.
Ashish Rajan: I will put your LinkedIn link onto the show notes as well.
Ashish Rajan: But thank you so much for coming on the show, and, uh- Thank
Sarit Tager: you very much. It was a great- I look forward
Ashish Rajan: to more conversation.
Sarit Tager: It was a good conversation. Thank you very much for having me.
Ashish Rajan: Thank you. All right, everyone, I'll see you next time. Peace. Thank you for listening or watching this episode of Cloud Security Podcast.
Ashish Rajan: This was brought to you by techriot.io. If you are enjoying episodes on cloud [00:44:00] security, you can find more episodes like these on cloudsecuritypodcast.tv, our website, or on social media platforms like YouTube, LinkedIn, and Apple Spotify. In case you are interested in learning about AI security as well, do check out our sister podcast called AI Security Podcast, which is available on YouTube, LinkedIn, Spotify, Apple as well, where we talk to other CISOs and practitioners about what's the latest in the world of AI security.
Ashish Rajan: Finally, if you are after a newsletter that just gives you top news and insight from all the experts we talk to at Cloud Security Podcast, you can check that out on cloudsecuritynewsletter.com. I'll see you next episode. Peace.

.png)



















.jpg)