Hi, I'm Tom Field, senior vice president of editorial with Information Security Media Group. My pleasure to be catching up with Dave DeWalt. He's the CEO of Night Dragon Security and has just been named vice chair of the board of Onapsis. Dave, thanks so much for joining me today.
Great. Thank you for having me, Tom. So, Dave, as I said, you've just been named vice chair of the board of Onapsis and this is a company that focuses squarely on the security of applications that we would consider business critical. So, we're talking ERP, CRM, software as a service.
If you take a step back, what would you say is the state of the union of cybersecurity in this sector today? Well, Tom, I've said this now for almost 20 years and the premise that I've used for 20 years is true today and probably true for the next 20 years and they call it a perfect storm. And, you know, why is it a perfect storm? The perfect storm is all around a couple of vectors that kind of come together that have been maintained now for a long time.
And one of those, you know, the first thing is, you know, we see this massive innovation cycle that continues to occur to this day even faster. So, the more innovation that you have, it results in more and more vulnerabilities because high tech companies create faster and faster technology, development cycles, those development cycles, results at vulnerabilities. The vulnerabilities result in attacks, attack types, a number of attackers. And you start to look at this sort of equation where this innovation cycle and this vulnerability cycle is just created a almost perfect storm.
You sort of compound that with anonymity on the internet and obfuscation of the attack types and nation states around the world being able to perpetrate these attacks. And you end up with this environment that we're in, where we have more than 50 governments around the world with offensive cyber capability, we have 800 different attack types. But coming back to your question for a second, we look at business critical applications. This has become one of the main areas of attack because why, pretty obvious, it's got all the data, it's got the information.
But really what has changed in the last two years, three year period, is our core business applications have undergone a major change to the way in which they can be protected and that is the cloud. And suddenly, our network perimeter and a giant moat that we have around these business critical applications has sort of dissolved. And suddenly, we have vulnerability to, you know, major applications, like, I say, PR, Salesforce, Workday, et cetera, in a way that we hadn't seen before because we don't have that same perimeter. We don't have the same binding in the network that we once had.
And we now have these vulnerabilities that are out there and the attackers are looking to exploit it and are exploiting it. So they have security leaders who pay pretty good attention to the code that they develop. What do you find they're overlooking when it comes to their SAP, their Salesforce, their Oracle? I walked upon a time and, you know, for some degree, the case, but largely these applications were, you know, almost silos in an organization.
And I did many SAP implementations in my years or various companies. And so these applications were very large stacks and they ran on their own data, they ran on their own infrastructure. What's changed is sort of what's around them. So suddenly now we live in a private server environment, a hybrid server environment, a hybrid cloud environment, a public cloud environment, and you now see the development of your point around it, Kubernetes extensions, open source platforms that are now suddenly accessing information in a BAPI interface or an ABAP language that an SAP would use in a way that wasn't what SAP initially thought and designed.
And suddenly they have dependencies on third party infrastructure and applications and interoperability that is now creating this almost perfect storm of potential attacks and attacks themselves on these architectures. So this whole shift of the cloud and the shift of the perimeter has really created this perfect storm for these business critical applications and ways we hadn't initially designed before. So an apps has certainly brought some attention to the issue and has had some recognition in the industry as the new vice chair of the board. Where do you see an apps is best opportunities in 2020?
Yeah, and they have a very large market Tom. What I see is obviously what probably almost everybody sees is how many business critical applications does every enterprise have. Well, many, and there's many enterprises. So when you start to look at the total address of a market for a company like an apps, it's enormous.
And when you sort of look at the defensive vendors in the solutions that are very small. And frankly, I've been looking for a company who really focused in on business application security and not just like let's just do vulnerability scanning. You know, I want to see a platform for these business applications. That's what an apps did.
Everything from understanding, you know, what are the vulnerabilities of an SAP or an Oracle application to? How do I monitor those vulnerabilities? How do I detect a threat when there is an attack that's occurring? How do I prevent that threat?
How do I respond to that threat? So on and so forth. So this is an interesting market, but coming to your point exactly, trying to create a model now to grow the company. And this is what I've always enjoyed doing in my career is scaling companies, whether it's from 10 million to 100 or 100 to a billion or a billion to multi billion.
You know, that's my background. So how can I help on apps as well and scale and accelerate and leverage the window of opportunity I believe it has to become a great company. So you have an addition to an apps as you're on the boards of several leading cybersecurity vendors, some two part question for you. One, what are the cyber threats that concern you the most today?
And two, what concerns you then about our industry's ability to respond to those threats? Yeah, I am on several cybersecurity companies. And I've been afforded an opportunity now in this sort of phase in my career to really look where the greatest gaps are between offense and defense. And that's really where I have Meg Dragon invest and that's where I like to focus.
So, you know, those big offensive gaps, what kind of nations they do, what kind of criminal organizations do, what kind of terrorist organizations do that there's very little commercial defense. And one of the reasons we're talking today is because business applications are one of those biggest gaps and these big applications, right. But to give you a couple of others, you know, I'm really focused on those social networks. Seems free, obvious, in light of things, deep fakes is a significant challenge for these network ties.
We have over three billion users online on social networks today. These applications are massive, measured in billion. They have very little security. They don't really care to have security, ironically.
And when we look at the virality of information, the ability to influence people through that information, we have one of the biggest pandemics, in my opinion, in, you know, technology history, because what you see oftentimes is what you believe. And of course, if the information is fake or the information has been altered, we tend to see a significant, you know, influence that can occur from that. And of course, we're watching major nation states around the world perpetrate attacks on the social networks to influence. And that's pretty obvious from the 2016 elections, but elections all over the world now.
And information, altering of audio, video, and other types of imagery as well as the content itself. So social networks, another one quickly, industrial networks, you know, very worried about industrial networks today, have very little security, making out kinetic responses if there's attacks on your industrial systems, like your energy and water and transportation systems. Other ones, drones, significantly where any lot of people will think of cyber as drone attacks. But think about network protocol in the air.
And these are radio frequency-based protocols, drones now measured in millions and millions being purchased every Christmas, have almost no detection mechanism in the air. I could essentially buy a drone for a few hundred dollars at a local store. I could load 50 kilos of explosives on that. I could fly to 50 kilometers per hour and fly right into a stadium and no one would detect it.
Pretty scary scenario. And I could go on and on about different threats. But the idea there is what could we do to create a gap closing scenario? And, you know, ultimately here's why I'm at NAMSSIS is trying to think about that with business applications.
Dave, you're really one that brought nation-state threats to the world's attention with your landmark APT report several years ago when you're at FireEye. How do you assess the evolution of the nation-state threat today, and particularly in light of heightened tensions with Iran, just in recent weeks? For me, it was a major epiphany back in 2008 initially for me. And, you know, some of the government government attacks were happening in the cyber world before that, and we knew that.
But they were largely, you know, G2G. And when we started to realize the G2C or the government to commercial activities were in full motion. We ended up discovering a couple of attacks back in those landscapes where hundreds and hundreds of companies in an APT campaign were advanced persistent threat campaign. We're targeting an entire industry sector with persistency of malware.
And it was one of those, like, like, moments where you suddenly realize, like, wow, is this possible? Are they really stealing all this intellectual property? In my time at FireEye, you know, we responded to over 5,770 confirmed intellectual property breaches by the Chinese. And, I mean, just imagine that 5,772 to the exact, in my time frame, where we could confirm intellectual property thefts from the Chinese military, 21 different organizations there.
So, you know, that's just China. Of course, Russia is amazing. To your point, Iran is amazing. Now, over 50 nations in the world have a command, a fiber command, where they're investing, instead of sort of offense and defense that are kinetic, military-type spending, they're now spending in the cyber arena.
So, this is, you know, the white west is perfect. So, what am I talking about with almost perfect obfuscation, opportunity, anonymity, opportunity. And here comes, you know, geopolitical conflicts in the world, United States and Iran, but other nations. And when you have capability, like the IRG has created, and you have now motivation, and you match motivation and capability, you have some very, very dangerous outcomes.
And when you just now look at what Iran's capabilities are and what their motivation is, you know, we're in a very heightened sense of worry due to the potential of ramifications that could occur on that geopolitical landscape. They don't ask you put on your investors hat and talk to me about the state of the cybersecurity market space. What changed in 2019 with this market? Yeah.
I mean, what was really interesting about the cybersecurity market from the investment point of view, Tom, is we really don't have cycles. And, you know, it's almost an anti-cyclical market, which is one of the more rare sectors in all areas of industrial and technology to be that way. And the reason for that is what we talk about, the threat landscape continues to rise. And if the threat landscape continues to rise, so do the companies trying to protect against those threats.
And when you look at 2019, it's almost the perfect year for cyber, when you now have companies going public, you know, famous companies like CrowdStrike reaching pretty amazing heights in terms of market valuations, but others as well. And you have a record number of companies going public, you have record financing, private companies, you have record number of M&A transactions, a company's acquiring cyber, you have, you know, record number of job openings, and you now have a market segment that will reach $148 billion in customer spend in 2020. And, you know, just a few short years ago, as we were discussing, when I was even CEO of Acape, or even back to RSA, this market was exponentially smaller. And so you're just seeing this incredible tide, this incredible inertia of growth, anti-cyclical in nature, and it doesn't look like there's any, you know, any stopping of that, even though the markets can come and go in terms of their, their growth.
I think the cyber market is strictly immune to that and will continue to grow at, you know, extraordinarily high cagers over the next decade or so. What are some of the specific technologies that you particularly bullish on? Yeah, you know, a couple of them are fascinating today for, you know, a cyber professionals. And one is, you know, this, this great two-letter word called AI.
And, you know, I always start with that because what we're watching is this great cyber arms race. And that's been the case, how fast can the bad guys, you know, develop technologies to attack the good guys and how fast can the good guys build technology to defend against that? Well, long come to this incredible scenario of using artificial intelligence for both offensive and defensive means. And when you look at the nation's state today, the heart, the heart of their development activities for offense is AI.
What can we use for machine learning, artificial intelligence capabilities such that we can predict and go from probabilistic kinds of attacks to deterministic types of attacks? Can we use AI to do that? Can we build algorithms that will say, this will be a successful attack because we've tried this number of deterministic outcomes to the point where we know we'll be successful, as opposed to the old models. Hey, let's send out thousands of emails and a spear-fishing campaign and hope something stupid happens and clicks on the link and eventually get themselves infected.
So, you know, this issue of the AI is an incredible area that I think has almost no end in sight just because the power of computing, quantum computing, AI capabilities is nearly off the chart. And to your point, one other quickly is, what is AI manifest itself in? And we discussed this a little bit earlier in concept of deep fakes. You know, what can I understand about what I'm seeing?
And can I really believe anything I'm reading? This is phenomenal now as you start to look at the ability of deep fakes where you can manifest permutations using AI engines to essentially alter an Adobe After Effects type of tool to the point where you now have something that there's almost no technology that can detect a fake. And, you know, this is looking like it's an incredible inertia of technology under that thing. Thank you for going on by giving us some examples.
Well, Dave, terrific. I appreciate your time and insight today, as always. Thanks for taking time to speak with me. Thank you, Tom.
Appreciate you having me. Again, we've been talking about business critical application security. That is speaking with Dave DeWalt. He's the CEO of Night Dragon Security and it's just been the advice chair of the board for Onapsis.
For information security media group, I'm Tom Field. Thank you very much.