Episode 784 ·
Inside the ASPM Revolution with Yonatan Eldar, Co-Founder & CTO at Apiiro
Today we’re talking to Yonatan Eldar, Co-Founder & CTO at Apiiro. We discuss Yonatan’s philosophy behind application security posture management, the leadership insights that he’s uncovered from co-founding his company, and the technology that he’s always wished was real.
All of this right here, right now, on the Modern CTO Podcast!
To learn more about Apiiro, check out their website here.
Have feedback about the show? Let us know here.
Produced by ProSeries Media.
For booking inquiries, email [email protected]

About Yonatan Eldar
I’m a software engineer with a passion for making stuff work. Enjoy working with great people, and create awesome products – as a developer / R&D manager / architect.
About Apiiro
Apiiro ASPM empowers application security and development teams from companies like BlackRock, Morgan Stanley, Rakuten, and Colgate with complete visibility and actionable context from deep code analysis and runtime intelligence they need to save time prioritizing alerts, fixing and preventing real risks across their modern applications and software supply chains, so they can deliver secure applications to the cloud.
Transcript
(Intro Narrator at 00:00:00) Today, we're talking to Yonatan Eldar, co-founder and CTO at Apiiro, about how they're changing the game with application security posture management. You're listening to Joel Beasley, Modern CTO.
(Joel Beasley at 00:00:19) So when I was doing my research and preparing for this episode, I learned a new acronym, another one: ASPM. Can you tell me what that acronym means?
(Yonatan Eldar at 00:00:32) Sure. So I was in this business before cyber, like 20-something years ago. Back then, we used to say "application security." That's a really short abbreviation, like AppSec or whatever. It's really short and simple and self-explanatory.
(Yonatan Eldar at 00:00:52) And it has evolved quite a bit over time. You know, we've seen SAST solutions, which is a horrible abbreviation. SAST doesn't really explain what the thing does. And then SCA came along, open source security. And then there was like a complete chaos of many different tools.
(Yonatan Eldar at 00:01:20) And in a similar way, when we started, there wasn't an ASPM definition. There wasn't a market. And we pushed for it. Out of that mess of a bazillion different tools—different scanners, secret scanners, SAST, SCA, runtime, shift left, whatever, all sorts of tools—there came ASPM, which is the left side, you can say, of CSPM, of cloud security posture management. There's the application security posture management. So AppSec is not really well-defined. It's pretty broad. But the concept of ASPM is you want a single place that understands the entire range of tools and signals that come through regarding your applications, and you have one place to know: where are the risks, what do I have to prioritize, how do I remediate? Go, go, go. This is ASPM.
(Joel Beasley at 00:02:23) And that's the tool that you built?
(Yonatan Eldar at 00:02:25) Yeah. So when we started, again, it wasn't well-defined, ASPM. There was what is considered now a subset of ASPM. There was ASOC, which is another not such a good abbreviation. But when we started, it didn't exist, and it evolved over time to gather all the signals into one place and make something out of it.
(Yonatan Eldar at 00:02:55) And the most interesting thing in that area is being able not to just do, you know, garbage in, garbage out. Like, put everything in one big table and draw a graph—this is not really ASPM. Right? So when you talk about SPM, you say usually, how open an SPM solution is and how deep it is.
(Yonatan Eldar at 00:03:20) Because when you talk about SPM, you want to be able to consume data from all different sources. So on that scale, we are really open. We have a lot of built-in integrations, and we are open to accept, like, through APIs, et cetera. So this is an open ASPM. And deep. We, for five years, have been building a really complex solution that is able to analyze code—more than 15 different languages—analyze open source code, analyze very different things from Terraform to application code.
(Yonatan Eldar at 00:04:08) And when you see some signal coming from the API gateway, let's say, which is not trivial for an AppSec product, you know how to correlate that signal to a specific API in the code, so you know who is the developer that knows best about that API. And you can correlate and deduplicate that signal with other different things. And this is a deep ASPM solution. So this is Apiiro. It's an open and deep ASPM solution.
(Joel Beasley at 00:04:42) What business problem is the CTO or VP of engineering experiencing where it becomes enough of a problem to need a solution like yours? Like, how can they identify that they'd be a good fit for what you offer?
(Yonatan Eldar at 00:04:59) It's an interesting way to put it that you said CTO, because usually this comes from the CISO side of the aisle, like an AppSec director, depending on the size of a company. Usually the problem starts with a team. Let's say you have a thousand developers in your organization. Right? So you might have, I don't know, four or five people in the AppSec team. Right? And they're in charge of covering like the 50 different teams in the organization.
(Yonatan Eldar at 00:05:41) So it depends on the culture of the company, but there's like an us and them. Right? Because the AppSec team wants to put gates, wants to stop risks from being introduced, and the developers, the CTO, wants to move fast. Right? So there's a trade-off there.
(Yonatan Eldar at 00:06:02) And we like to think of ourselves as bridging the gap, helping the AppSec team reach the developers. Come to the developers with a clear signal, a true positive that the right developer would know how to remediate. So to your question, for the CTO, it's: security people come to me with real things that I can see are worth my time or my developer's time when they go and remediate those things.
(Joel Beasley at 00:06:48) So what would the pressure be, let's say, for the CISO that has this AppSec team? Because we have all types of technical leaders that listen. Right? What would the pressure be for them that would warrant looking at a tool like yours? Like, what painful business problem are you solving for them?
(Joel Beasley at 00:07:11) Is it the dysfunction between communication between AppSec team and developers? Is that the problem you solve?
(Yonatan Eldar at 00:07:17) So this happens for sure, but the main problem is risk in the applications. Right? This is the main problem. And when you have five developers, I won't say it's easy, but it's manageable. But as you grow, it becomes really hard.
(Yonatan Eldar at 00:07:33) You know, we see—I just want to emphasize, when we approach like a POC with a company, first touch, in Apiiro, you know, you connect to the source control manager in like five minutes with a token, and you see results almost immediately. And oftentimes the person on the other side says, "Hey, we don't use MongoDB in company, in Acme. We don't use it. How come you saw that technology?" And we say, "You know, we didn't make it up. Yeah, it's there." And we can point to the specific place where you use that authorization infrastructure or that database or that whatever.
(Yonatan Eldar at 00:08:20) Okay, so the visibility, the discovery into whatever you have, is really—it might be overwhelming at the start. So once you have 50, a hundred, a thousand different applications in your organization, you have to do something to be able to prioritize what do I have to do. And risk can come from all over the place. You hear all over the news about dangerous vulnerabilities coming through containers, like secrets in open source databases, in open source repositories. Backdoors are introduced through various ways into the code bases. So the risk is out there, and every company will be exposed if not already. So the risk is there, and companies don't have enough time on their plate to, you know, to reach everything. So the main thing is show me, whether it be the AppSec team for the CISO or the developers for the CTO or whatever, show me the real thing I have to deal with.
(Yonatan Eldar at 00:09:36) Not all the fluff, not all the false positives, not all the things that look real but they're in test code and I don't care about them. Show me what I have to right now go and deal with. Because showing me 6,000 lines of some CSV of a report for SAST, I don't know what to do with it. So prioritization is the immediate value or the immediate problem that people solve with a POC.
(Joel Beasley at 00:10:12) All right, so prioritization of risk in the code base?
(Yonatan Eldar at 00:10:16) Yeah, for sure. And after that, you know, you have to know what to do with it, like how to remediate. If I see some obscure vulnerability or some other issue, if I don't know what to do with it, if I don't have the context for it—for instance, who is the developer? Not Git blame, who is the last developer who refactored code and his or her name is next to that line of code, but who's the right person to speak with? This is the next important thing in line. Like, how do I remediate?
(Joel Beasley at 00:10:58) What is the trauma someone is experiencing that would make them want to consider a solution like this? I can give you a couple examples. Right? One is my application's constantly getting attacked, so I might need to prioritize, you know, risk in the code base. Another one is the people currently maintaining the risk are complaining to me that there's too much. There's not enough resources. I'm just like, what's the business side of things? What are the—where's the complaint and the pain point for the people?
(Yonatan Eldar at 00:11:35) So, okay, it depends who you ask. But if you want to be really, really, like, business-oriented in your answer, compliance is one of the main drivers for large organizations. Right? Because, I worked for Microsoft for a few years, and I was, you know, a developer in a 200,000-developer shop or people shop, something like that. Like, I was nobody inside that large organization.
(Yonatan Eldar at 00:12:10) And the amount of things I had to deal with from the compliance perspective as an engineering manager, like, I had processes I had to comply with. I had all sorts of reports I had to create and push upwards, upwards the chain. So for me and my team, let's say I had maybe 30% of time wasted or invested in compliance and bureaucracy around developing code. In other companies, this might be 40 or 50 or 60%. Right?
(Yonatan Eldar at 00:12:53) I have to document everything in a specific Jira ticket with that process, and I have to go through person A, B, and C before I can push into that repository. All sorts of impediments for a developer out there. Right? So if I, as an engineering manager in Company X, can cut that number from 30% to 20%, that's a huge force multiplier for me. From a business perspective, I have a hundred developers, and it's like I have now a hundred and ten or a hundred and twenty, like that.
(Yonatan Eldar at 00:13:29) If I can do that and hire 10 or 20 people, it would be amazing. It's not possible. But if I can reduce the time wasted, that's a pure ROI for me. So that, in terms of business, I think this is the strongest thing ever, because you can talk about risk all day. If you're not risk-averse, you can say, "Hey, I'm fine with risk," until you get hacked. Right? But saving time for your team is really, really strong.
(Joel Beasley at 00:14:08) Is that what you're marketing?
(Yonatan Eldar at 00:14:10) Yeah, for sure. Yeah, this is part of what we sell, of course.
(Joel Beasley at 00:14:15) Yeah. And how are you guys doing? How's growth? What, give me some ideas. I know you're a private company. You're not publicly traded, but can you—how do you talk about growth publicly?
(Yonatan Eldar at 00:14:27) So we're growing. We're selling more and more. I don't like to talk about selling because we really, really make an effort at this stage of a company to build a great product. And each new customer, whether it's—I don't want to talk in dollars, but if it's a 200-, 300-developer shop or 15,000-developer shop, that's quite a range there, also in terms of revenue. But each new customer like that teaches us a lot about what goes on in the industry. We see new things.
(Yonatan Eldar at 00:15:08) We see new challenges. Like, even if you pick just one thing, one challenge that you see now—there are, you know, there are many, but, you know, AI stuff, like, how do I, like, the approach of different CTOs for different types of companies for tools like OpenAI or Copilot or stuff like that, their approach is really different. And we see that across the board. Like, what things they are afraid of, what risks they are willing to take. So we learn from each customer, and we apply going forward.
(Joel Beasley at 00:15:49) The difference between the 300-person shop and, let's say, the 10,000-person shop, are they both buying for that same value proposition of save time scale, or are they buying for different reasons?
(Yonatan Eldar at 00:16:05) So there are differences. There are always differences between such different-sized companies. But for the most part, yeah, the same reasons. Scale always impacts how you approach a company. Obviously, like, a publicly traded large company, if it's a bank, it's highly regulated. Right?
(Yonatan Eldar at 00:16:34) So they might like—we have a dynamic governance engine which has different rules. There are built-in rules, but like a large bank would probably define, edit the rules, and change them in a way that is more appropriate to a regulated bank. And I need a private Internet, whatever, advertising company might define a whole different set of rules. So there are differences, but in terms of what they are buying, they're solving the same things.
(Yonatan Eldar at 00:17:11) Like, the challenges of a developer or an AppSec engineer are very similar for a hundred-developer shop and a 10,000-developer shop.
(Joel Beasley at 00:17:22) Let's talk a little bit about integrations. It seems like your software would need to integrate with a lot of other softwares. How does that work?
(Yonatan Eldar at 00:17:31) Yeah. So, you know, there's that term. I've experienced it many times in the last ten years or so: a single pane of glass, which is important. Like, you want a single place, and you don't want an AppSec engineer or a developer to experience seven different UI screens as part of the workflow. So there are many tools out there that integrate into many different other tools, right, and put all the data in some canonical data model that is shared between all platforms and spews everything into like one table.
(Yonatan Eldar at 00:18:19) And it's fine and it has value, but what we are doing is we're integrating into a lot of different types of tools, and we're putting a lot of effort and care and thought into deep integrations into these tools. So what our integration with SCA tools is different than our integration into SAST or API gateways or Kubernetes clusters. So for each one, we have a team that is dedicated in exploring what will bring most value and how to correlate and how to deduplicate data and how to bring the right context of everything into the platform. And it's challenging. Like, it would be much easier to find a common denominator. Right?
(Yonatan Eldar at 00:19:19) And put like 800 integrations. And it will bring value, but not, as I said, deep value. So we learn from each one when we—we've partnered with a few, we've partnered with multiple companies around that. And we learn from each one. We have some integrations that 10 or 15 customers are using the same thing, but in different ways.
(Yonatan Eldar at 00:19:52) And we learn and we adapt and we evolve those integrations over time so that it brings real, real deep value.
(Joel Beasley at 00:20:02) And so you're real into the cybersecurity world. What are the big trends that you're seeing in 2024?
(Yonatan Eldar at 00:20:10) So, as I said, until we become all batteries for the AI that will rule us all—I think someday, maybe. But until then, right now, the biggest trend we see, like questions we get asked around AI, is really, really out there. So there are real use cases and scenarios that people are concerned about. Show me what applications are offloading data into OpenAI or other tools.
(Yonatan Eldar at 00:20:53) This is one thing. Show me what my developers are doing with Copilot and other things is really important. This is really, really interesting, and people don't know. Like, it's really hard to govern 15,000 developers and what they are doing with the code. Right? It's really hard. So this is by far the biggest trend I we see now this year.
(Joel Beasley at 00:21:21) Interesting. Interesting. So what's happening when you have 15,000 developers? Are they just sending your company's private data into GPTs? Can you detect that? Is that, like, something you sell as a feature?
**Yonatan Eldar at 00:21:36**
Yeah. So we identify—we scan at least, we scan all the code of that company. Right? Ideally, we will scan more than just the 50,000 repositories in GitHub or Bitbucket or other tools. But we will ideally scan more than that.
**Yonatan Eldar at 00:21:59**
We will scan Jira tickets, as I said, like API gateway data, and data from Wiz, from Snyk, from MAND, et cetera. So we see data from all over the place and we will identify usage of such technologies, and people will always be surprised. Like, even if you have a hundred developers, it's really hard for you to keep track of what people are using in the code bases. And we see everything. And we see the same thing that CTOs are afraid of.
**Yonatan Eldar at 00:22:43**
The same thing implemented multiple times in different places, in different manners, in the same organization. Because a 10,000 developer shop is usually, not always, usually segregated in some way. Right? You have different silos. They are using different stacks, and they approach the same problems but in a different way.
**Yonatan Eldar at 00:23:08**
So that visibility into what you have is really, really crucial. At first, it's understanding what you have. After that, you can dive into and say, maybe add some policy and say, no, you can't use that library in those applications. And we will enforce that, and we will block pull requests that add usage for, like, shipping data to OpenAI, just as an example.
**Joel Beasley at 00:23:38**
So as the technical leader, you said that some of them have some concerns, and then they can validate if those concerns are happening. So you have some type of policy engine where I could say, hey, check. You know, I can come to you and say, hey, Yonatan, I think that this might be happening at my company. Can you scan all the code bases and check for it?
**Yonatan Eldar at 00:23:58**
Yeah. For sure. So we do have a governance engine, which is really—as I like to say, it's deep. It can understand semantics of code and different constructs, like APIs and data models and usage of technologies and stuff like that, and the connections between those. So as I said before, you have a default policy, but you can adapt and you can say, for that sub-organization, I want a different policy because these people are handling really sensitive data, but that organization can have a different policy.
**Yonatan Eldar at 00:24:41**
And for each one, you can have different workflows. And for those people, I can just open a ticket to the AppSec team. For that team, I want to block pull requests because they are advanced and they can use it well. And for that team, they are afraid of blocking PRs because they want to run fast and they maybe don't trust yet the platform and you just want to comment on the PR or send a Slack message, stuff like that. So that team will handle it that way.
**Yonatan Eldar at 00:25:14**
And, you know, as a user, you are free to define it however you want.
**Joel Beasley at 00:25:20**
I love buzzwords. I love this new acronym. They come and go. Right? But what's going on with the buzzword shift left? What's your take on that?
**Yonatan Eldar at 00:25:34**
So shift left is around for quite some time, and I've been to dev conventions where it was really, really strong. And people started to say, it's okay shifting left, but dumping everything on the developer is not the way to go. And so our approach to shift left is if you wait for the problems to arise in production on the right, it's obviously not good. But doing everything on the far left is dangerous too because the developer might not know what to do, and they might be bombarded with a lot of information they can't really sift through. So shift left has to be done really, really carefully and we—a lot of what we do is make sure that when we get to the developer, I'm a developer.
**Yonatan Eldar at 00:26:40**
For me personally, it's really important that an AppSec engineer might open their day going through the data and making decisions, what's important, what's less important, what's a priority for me, et cetera. But a developer, I—me as a developer, I talk about myself. Me as a developer, I now have a task. I want to go execute. And if someone says to me, no, you have to do something that is not developing the feature or optimizing the code or something like that, I want it to be really, really clean. So for us in Apiiro, shift left is when we comment on the pull request, not to mention block the pull request from being merged. It has to be really, really, like, really accurate. We can't—no one can achieve compiler level accuracy. Right?
**Yonatan Eldar at 00:27:40**
Like in your IDE, when you develop code in PyCharm or whatever, you expect if something—well, Python doesn't compile. But if the IDE says this is a bug, this is an error or whatever, you expect it to be nine—like, five nines, right, or more. You can't expect that on a pull request, but we really, really strive to get there. Right? Because shift left has to be when you say to a developer you have to do something, as from the security perspective, it has to be accurate.
**Joel Beasley at 00:28:13**
Here's a fun question. When it comes to security, how are you navigating AI so it doesn't enslave us all and corrupt our cybersecurity systems?
**Yonatan Eldar at 00:28:25**
Are you asking me as a CTO of Apiiro or as a developer?
**Joel Beasley at 00:28:30**
As you, as a human being.
**Yonatan Eldar at 00:28:32**
As a human being. Yeah. Like, if you remember my answer from before, it's really, really scary, but I think we can leverage it for good. I think, like, right now the challenge is when data is wrong, like in the output of some AI generative AI tool, understanding that it is wrong and not blindly trusting it is key, until we get to a higher level of accuracy. Because, like, somewhat like my son, who we talked about before, when he's making up stuff, he's really confident about it, and it's a problem.
**Yonatan Eldar at 00:29:28**
When he was younger, he wasn't confident about that. And in AI right now, when I'm asking, how do I, in some whatever tool, add dash dash, like flag, to do something? And AI says, yeah, of course, do dash dash SDK, and it will be relevant only for that particular SDK you've installed on your machine, and it's totally made up. It's not a real thing. It makes sense. It has a high probability, but it is wrong. This is the thing that scares me. This is a small example. But from the security perspective, if developers are trusting, like, AI right now to secure their code, we're not there yet.
**Joel Beasley at 00:30:18**
No. I'm not too concerned about bad recommendations in a basic sense. I'm more concerned that the thing making the bad recommendations is going to have a higher level plan being executed at a larger scale than we can comprehend.
**Yonatan Eldar at 00:30:34**
Wow. That's really end game. Yeah. Like, if OpenAI, as an example, will inject code into five different companies and—like, like one of the first Batmans. Right? If you remember that, like the Jack Nicholson example where I think there were like three different toxins in three different products, which no one could detect. So if some bad actor—I'm not saying OpenAI, but some bad actor—may be injecting data into OpenAI and impacting different code bases, it will be like a horrible scenario. Right now, OpenAI has to solve that problem.
**Joel Beasley at 00:31:23**
We gotta call up Sam.
**Yonatan Eldar at 00:31:25**
Yeah. But I do think—and it's really similar maybe it's a political question, but political manner. But like telephones back in the day or encryption after that, it's a tool and, you know, politicians demand a backdoor into everything. To some degree, you can't really control it and I think it really—as long as OpenAI won't be perfect, and Copilot won't be perfect, which is the case, I think, like, people who are calling the shots, developers, engineering managers, CISOs, CEOs, whatever, they have to apply the same measurements that they apply to human beings on data coming from code or data coming from generative AI tools. So even people right now or ten years ago, they could do a, you know, a long play of injecting malicious code into their employer's code base.
**Yonatan Eldar at 00:32:41**
They could have done that. And we had to protect against such scenarios twenty years ago as well. So in that sense, I think it's the same way. Right? So if you didn't trust your best developer to just write code and you had him or her go through a pull request and some other person reviewing it, in the same way, you have to treat, like, code coming from Copilot, in my opinion.
**Joel Beasley at 00:33:12**
I 100% agree. Do you think about quantum computing at all in relation to this, or is AI separate? Do you only think about AI?
**Yonatan Eldar at 00:33:21**
You know, when we will get there for real. And you can break RSA in five minutes with any length of key. I think a lot of things that we are—like, there are a lot of building blocks that we'll dismantle in a second, and you will have to reevaluate how you approach engineering, humanity. You have to, you know, change your approach completely. And I totally respect my limited capacity of my brain of really foreseeing how it will play out, both for AI, by the way, and quantum, like, that quantum leap, sometime in the future.
**Yonatan Eldar at 00:34:15**
We are starting to see it, but not yet. But even for AI, which is a little bit more approachable right now than quantum computing, even for AI, like, people are already treating it as magic. But even now, I don't think people really grasp how it might change engineering and humanity a year from now.
**Joel Beasley at 00:34:41**
Oh, 100%. We have no idea what's coming.
**Yonatan Eldar at 00:34:45**
You know, there are people who claim they know.
**Joel Beasley at 00:34:49**
Oh, well, yeah. I mean, we know the best that we know, but it seems—I'm 36, and it seems like almost always there are two or three ideas that people think where it's going to go, and it always seems to go a fourth way. Like, it always seems to go—it's like, here's all the practical ideas of, like, how it's going to go, and then something new just kind of pops up. That's what my experience is about.
**Yonatan Eldar at 00:35:16**
Yeah. I think from both the security perspective, engineering perspective, or human behavior perspective, like, if you apply first principles, let's say, and treat it with respect and understand to the best of, you know, your ability what's going on, I think it's not any different than other major leaps that we had, like, cell phones or computers back in the day. Maybe we'll become batteries, like, in the Matrix, but I'm hopeful that it won't happen.
**Joel Beasley at 00:36:04**
Well, we'll both escape our battery pods and meet up.
**Yonatan Eldar at 00:36:08**
For sure. I'm already in Zion, so we can do it.
**Joel Beasley at 00:36:12**
If I handed you a magic wand, what technology would you wave into existence?
**Yonatan Eldar at 00:36:21**
Whoa. That's a big question. I think, well, this is my dream. But there was a movie, I can't remember its name, where you can, like, immerse yourself in some real experience and really feel it. Feel, not see through goggles. Right?
**Joel Beasley at 00:36:47**
I know what you're talking about.
**Yonatan Eldar at 00:36:48**
So a person could record themselves running on the roof and jumping or stuff like that. I think this is the opening scene. And you could really, really, really feel it, experience it. So the best example is, you know, being on the stage with the guitar on—in Woodstock or something like that. If I could really, really experience it with my magic wand, I would do that. Maybe six months from now. Yeah. For sure.
**Joel Beasley at 00:37:15**
Yeah. We could sell memories, man. Let's do it.
**Yonatan Eldar at 00:37:18**
Yeah. Let's do it. You have to find good memories before you sell them, but yeah.
**Joel Beasley at 00:37:24**
That's true. And you gotta get a Taylor Swift licensing deal. Alright. Yeah. That was a way better imagination than me. I was just going for a Bitcoin decryption machine. That's what I was going for. Alright. Shout out to Apiiro. How do you get new customers? Do people sign up for demo calls? Do they download a free version? How does that work?
**Yonatan Eldar at 00:37:51**
Yeah. Yeah. Apiiro.com, can contact us. We'll be happy to talk, understand your challenges, and do a POC. Our POCs are really, really fast, like, two weeks, really easy.
**Joel Beasley at 00:38:06**
So I can get instant information and insight about my code base, come to you with some information?
**Yonatan Eldar at 00:38:09**
In an hour.
**Joel Beasley at 00:38:11**
Wow.
**Joel Beasley at 00:38:13**
Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.