Chenxi Wang, Rain Capital, sits down with Peter Burris for a CUBEConversation at theCUBE Studios, Palo Alto.
#CUBEConversation #theCUBE
https://siliconangle.com/2018/04/12/rain-capitals-founder-aims-transform-tech-security-inclusion-womenintech/
Rain Capital founder aims to transform tech through security and inclusion
The notion of developer operations, or DevOps, has become synonymous with information technology agility in the enterprise, combining software development teams with information technology operations personnel to get software out faster.
But too often, that can cause bull-in-a-china-shop application development and deployment, raising sticky security issues. That’s the broad problem that Chenxi Wang (pictured), founder and managing general manager of Rain Capital, is looking to solve.
“One of the areas that I’ve been focusing on in the last two or three years is looking at the impact of DevOps practices to IT, including security — and it’s a huge impact,” said Wang, whose early-stage venture firm is focused on cybersecurity innovation and artificial intelligence for its clients.
The old rules for developing and securing applications are going out the window thanks to DevOps, according to Wang. Traditionally, teams would build applications, and they would go on to a round of security tests before receiving the green light for deployment. “DevOps practices disrupt all of that,” she said.
Wang spoke with Peter Burris (@plburris), host of theCUBE, SiliconANGLE Media’s mobile livestreaming studio, at theCUBE’s studio in Palo Alto, California, to discuss the current state of enterprise security and the ways Rain Capital is working to mitigate risk in DevOps.
This week, theCUBE spotlights Chenxi Wang in its Women in Tech feature.
‘We have a long way to go’
After years of observing roadblocks to IT security, Wang founded Rain Capital to help companies find new approaches to dependable security as capabilities are increasingly sourced from public cloud or service providers.
“I think we are different because we have a deep understanding of the market and … technology, and also very extensive relationships with end users,” Wang said.
Through conversations with technology end users, Rain is finding that security and DevOps can make squirmy bedfellows. “What DevOps says is: ‘I’m a developer; I can deploy my application directly onto a production server without going through all those gates because business agility demands it.'”
Though this zealous approach might sound promising at face value, it leaves pipelines vulnerable to security risk. Last year, Uber Technologies Inc. exposed the data of 57 million customers when the company’s developers mismanaged credentials by using a workaround in the company’s software repository.
The event rattled confidence in the company, but Uber isn’t alone. A recent industry report showed that 73 percent of orgs have no DevOps security strategies in place.
Once developers or testers have ultimate say-so on what hits production servers directly, old heavy-handed security practices go away, according to Wang. As the acceleration of the market toward cloud outpaces security protocols, organizations and their customers are left vulnerable.
“It’s very common for companies to want to move their workloads” from their internal data center to Amazon Web Services, Google Cloud and Microsoft Azure. “[They] don’t want to go through all the testing and pre-implementation practices. The portability also disrupts existing security practices.”
Enhancing enterprise security
In its security work with businesses, Rain Capital focuses on developing standards and creating greater visibility. The company stresses real-time monitoring as crucial to optimal security and performance.
“What we want is monitoring capabilities that are able to do it in a platform-independent way, but give you real-time visibility and response capability,” Wang said. “That’s where the innovation comes from.”
Even with these tools in place, Wang believes tech’s true security rehabilitation must start with a fundamental mindset shift. She has already observed companies beginning to erase the boundaries between IT and applications teams, and she sees a future in which applications are developed collaboratively with security built in from the start.
“[The team] breathes the application demand, knows what the application wants to do, and then works with the developers to establish policies and deployment practices as opposed to being arms length from the developers, which creates all kinds of tension,” she explained.
...
Here’s the entire video interview with Chenxi Wang, one of many CUBE Conversations from SiliconANGLE and theCUBE:
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
CUBE Conversations 2018 | Palo Alto and Boston. If you don’t think you received an email check your
spam folder.
Sign in to CUBE Conversations 2018 | Palo Alto and Boston.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Register For CUBE Conversations 2018 | Palo Alto and Boston
Please fill out the information below. You will recieve an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for CUBE Conversations 2018 | Palo Alto and Boston.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
CUBE Conversations 2018 | Palo Alto and Boston. If you don’t think you received an email check your
spam folder.
Sign in to CUBE Conversations 2018 | Palo Alto and Boston.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Sign in to gain access to CUBE Conversations 2018 | Palo Alto and Boston
Please sign in with LinkedIn to continue to CUBE Conversations 2018 | Palo Alto and Boston. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Chenxi Wang, Rain Capital | CUBE Conversation, March 2018
Chenxi Wang, Rain Capital, sits down with Peter Burris for a CUBEConversation at theCUBE Studios, Palo Alto.
#CUBEConversation #theCUBE
https://siliconangle.com/2018/04/12/rain-capitals-founder-aims-transform-tech-security-inclusion-womenintech/
Rain Capital founder aims to transform tech through security and inclusion
The notion of developer operations, or DevOps, has become synonymous with information technology agility in the enterprise, combining software development teams with information technology operations personnel to get software out faster.
But too often, that can cause bull-in-a-china-shop application development and deployment, raising sticky security issues. That’s the broad problem that Chenxi Wang (pictured), founder and managing general manager of Rain Capital, is looking to solve.
“One of the areas that I’ve been focusing on in the last two or three years is looking at the impact of DevOps practices to IT, including security — and it’s a huge impact,” said Wang, whose early-stage venture firm is focused on cybersecurity innovation and artificial intelligence for its clients.
The old rules for developing and securing applications are going out the window thanks to DevOps, according to Wang. Traditionally, teams would build applications, and they would go on to a round of security tests before receiving the green light for deployment. “DevOps practices disrupt all of that,” she said.
Wang spoke with Peter Burris (@plburris), host of theCUBE, SiliconANGLE Media’s mobile livestreaming studio, at theCUBE’s studio in Palo Alto, California, to discuss the current state of enterprise security and the ways Rain Capital is working to mitigate risk in DevOps.
This week, theCUBE spotlights Chenxi Wang in its Women in Tech feature.
‘We have a long way to go’
After years of observing roadblocks to IT security, Wang founded Rain Capital to help companies find new approaches to dependable security as capabilities are increasingly sourced from public cloud or service providers.
“I think we are different because we have a deep understanding of the market and … technology, and also very extensive relationships with end users,” Wang said.
Through conversations with technology end users, Rain is finding that security and DevOps can make squirmy bedfellows. “What DevOps says is: ‘I’m a developer; I can deploy my application directly onto a production server without going through all those gates because business agility demands it.'”
Though this zealous approach might sound promising at face value, it leaves pipelines vulnerable to security risk. Last year, Uber Technologies Inc. exposed the data of 57 million customers when the company’s developers mismanaged credentials by using a workaround in the company’s software repository.
The event rattled confidence in the company, but Uber isn’t alone. A recent industry report showed that 73 percent of orgs have no DevOps security strategies in place.
Once developers or testers have ultimate say-so on what hits production servers directly, old heavy-handed security practices go away, according to Wang. As the acceleration of the market toward cloud outpaces security protocols, organizations and their customers are left vulnerable.
“It’s very common for companies to want to move their workloads” from their internal data center to Amazon Web Services, Google Cloud and Microsoft Azure. “[They] don’t want to go through all the testing and pre-implementation practices. The portability also disrupts existing security practices.”
Enhancing enterprise security
In its security work with businesses, Rain Capital focuses on developing standards and creating greater visibility. The company stresses real-time monitoring as crucial to optimal security and performance.
“What we want is monitoring capabilities that are able to do it in a platform-independent way, but give you real-time visibility and response capability,” Wang said. “That’s where the innovation comes from.”
Even with these tools in place, Wang believes tech’s true security rehabilitation must start with a fundamental mindset shift. She has already observed companies beginning to erase the boundaries between IT and applications teams, and she sees a future in which applications are developed collaboratively with security built in from the start.
“[The team] breathes the application demand, knows what the application wants to do, and then works with the developers to establish policies and deployment practices as opposed to being arms length from the developers, which creates all kinds of tension,” she explained.
...
Here’s the entire video interview with Chenxi Wang, one of many CUBE Conversations from SiliconANGLE and theCUBE: