Chen Gour-Arie is the Chief Architect and Co-Founder of Enso Security. With over 15 years of hands-on experience in cybersecurity and software development, Chen demonstrably bolstered the software security of dozens of global enterprise organizations across multiple industry verticals.
Audio hosted by Buzzsprout. Nothing loads until you press play.
Episode chapters · 9 chapters
- 00:00Meet Chen Gour-Arie: The AppSec MapAudioVideo ↗
- 02:09Our guest today is Kahan Ghorarieh, and I probably just butcheredAudioVideo ↗
- 08:11I do have a follow-up question in regards to the startupAudioVideo ↗
- 10:14Our topic today is, as we mentioned, AppSec Map. And soAudioVideo ↗
- 11:51You think about this project and the fact that it existsAudioVideo ↗
- 15:44Yeah. Yeah, so in terms of— so we talked about whatAudioVideo ↗
- 18:01If— so I understand the different categories of kind of consumersAudioVideo ↗
- 27:31This is a good place to add tools into that canAudioVideo ↗
- 30:20Very cool. This has been great to get a perspective onAudioVideo ↗
About this episode
Chen Gour-Arie is the Chief Architect and Co-Founder of Enso Security. With over 15 years of hands-on experience in cybersecurity and software development, Chen demonstrably bolstered the software security of dozens of global enterprise organizations across multiple industry verticals. An enthusiastic builder, he has focused his career on building tools to optimize and accelerate security testing and all related workflows. Ken joins us to introduce the AppSec Map and provides a live demo of the catalog and what AppSec practitioners can use it for. We hope you enjoy this conversation with… Kahen Gour-Arie is the chief architect and co-founder of Enso Security. He’s an enthusiastic builder, and he’s focused his career on building tools to optimize and accelerate security testing and all related workflows.
You are now listening to the Application Security Podcast, brought to you by Security Journey.
About Security Journey
Hey folks, welcome to another episode of the Application Security Podcast.
→ Learn more about Security Journey
Connect with Chen Gour-Arie:
→ Enso Security
→ AppSec Village
Resources
→ Enso Security
→ AppSec Village
Actionable
From this conversation
- 10:23
Use an AppSec map to navigate options
To build a map that helps anyone that is interested in understanding this space navigate through the different solutions that they have
- 16:16
Start shaping your AppSec strategy now
It's a good place to start and look for assistance, even if you are not strictly AppSec.
- 18:25
Compare the full range of AppSec controls
A map approach will let you see the full scope and your alternative.
- 20:01
Inventory the technologies you need to protect
You describe your asset inventory by, in a very simple way, in a very high-level way, by describing what technologies you use.
- 20:01
Use coverage gaps to choose your next step
You would know where you should focus, what is missing, and what should be your next steps
Transcript · 34 min conversation
0:00Chris RomeoKahen Gour-Arie is the chief architect and co-founder of Enso Security. With over 15 years of hands-on experience in cybersecurity and software development, Kahen demonstrably bolstered the software security of dozens of global enterprise orgs across multiple industry verticals. He's an enthusiastic builder, and he's focused his career on building tools to optimize and accelerate security testing and all related workflows. Kahen joins us to introduce the AppSec Map and provides a live demo of the catalog and what AppSec practitioners can use it for. We hope you enjoyed this conversation with Kachen Gour-Arie.
0:36Chen Gour-ArieYou are now listening to the Application Security Podcast, brought to you by Security Journey. When you finish this episode, check out our other show, High Five, to stay up to date with all the hot AppSec news.
0:46Chris RomeoHey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo. I am the co-founder of Security Journey and also co-host of said podcast, joined today by my good friend Robert Horvath. Hey, Robert.
1:02Robert HurlbutHey, Chris. Yeah, Robert Hurlbut, Principal Application Security Architect at Acquia, and really glad to be here again to talk about application security.
1:11Chris RomeoSeems like the thing to talk about. I mean, it is the name of the podcast, the Application Security Podcast. You don't have to wonder about what we're going to talk about. You don't have to look at this on iTunes or Google Play or whatever and go, I wonder what they talk about on this podcast.
1:25Robert HurlbutWhat do they talk about? What is this all about?
1:27Chen Gour-ArieWhat's the subject?
1:28Chris RomeoIt's not very well hidden. It's not very well hidden. Well, we're on the eve of Black Hat DEF CON, and Robert, you and I are both getting ready to make our way out to the desert for a little bit of security fun in Las Vegas, which is pretty exciting. And just being able to be around the AppSec Village there, we've talked to the founders of AppSec Village before, and it's exciting that, you know, that's gonna be bigger and better this year in Vegas. So it's great to see how much AppSec is really taking over and getting a lot of attention. It's nothing but goodness for us in our industry here.
2:06Robert HurlbutDefinitely.
2:09Chris RomeoSo our guest today is Kahan Ghorarieh, and I probably just butchered your name, but I tried my best. But I'm excited, Kahan, to have you here today to talk about the AppSec Map. And we're going to get into that, but first, I'm going to completely change the script. Our audience is expecting me to ask, what is your security origin story? And I'm going to ask that in a second. But the first question I have to ask, for those not on video here, we're looking at a backdrop of a green pegboard with all kinds of different tools and things behind it. And so, I just, Dan, I just have to know, where are you sitting right now and what am I seeing behind me?
2:50Chen Gour-ArieSo, I'm sitting at my office here at the Enzo Security offices in Tel Aviv. And this background is basically, you know, the one thing that almost took me away from cyber was that I like to build things. And so for a little bit, almost in the middle of my career, I thought maybe I'd switch to development and I did spend a few years leading a team of developers. But the real passion was for creating things. And this is a thing I've been doing since my son was born 9 years ago.
3:21Chris RomeoWow.
3:21Chen Gour-ArieI built like a baby bed for him and got into like amateur carpentry and in general like handyman kind, handicraft kind of things. And this reflects my much more rugged and uglier version of what I have at home. So when they asked for the decoration of my office, I chose for this one. But some of the tools here are fake. So Don't be alarmed.
3:49Chris RomeoFor those that are listening on audio, Ken is holding a rubber axe at this point. Yeah, yeah, I was wondering about that one.
3:58Chen Gour-ArieYeah, yeah, I get a lot of questions about that, and I almost got people from HR coming to me and asking, maybe you should consider, but eventually it's a nice icebreaker. So yeah.
4:09Chris RomeoThat's great. I love the backdrop. It's, it's the most creative backdrop that I've seen so far on the AppSec Podcast. So, but let's talk about how you got into application security and your origin story. So go back as far as you want into your history, but we'd love to hear how you got to AppSec.
4:26Chen Gour-ArieSo I think that my story is a little bit boring. I didn't really get, like, my first dial-up connection was when I was 18. So I wasn't one of these kids who hacked the internet before they knew how to crawl. But like I said, I always like to build stuff. And through my army career in Israel, we have a mandatory military service. I spent it in security research. And then it was just an accelerator to get into a consultancy firm here in Israel. So I spent the 6 years after my military service, I spent consulting application security. It was, we're talking 2007.
5:09Chris RomeoWow.
5:09Chen Gour-ArieIt's a long time ago in, you know, high-tech age, in high-tech years. And, you know, at the time it was the web applications and mainly the industry that had them were the mature industries like banks and insurance companies. It's not what we know today that every business is powered by an application. It was already starting and already a huge adoption of applications, but the field of application security was, It was only building up. And so I spent 6 years consulting different industries about application security from the ground up. So started as a pentester, did a lot of application security pentesting. And I really liked the fact that you can combine a lot of scripting and a lot of, right? You have to understand code and you have to write code and build things along the way to improve your testing abilities. Like customizing your proxy and doing some fun things with just some, a little bit of cleverness in the code. And then as I made progress in this path, I had to tackle some bigger challenges, like helping some of the first organizations that adapted PCI here in Israel, large conglomerates, large networks, large businesses. I was at the time one of the— my firm was at the time one of the only firms that could certify for PCI. So I had to take in PCI when it started, and then it inspired looking at more the side of managing AppSec. And I've made throughout my career many kind of different kind of projects from the hands-on, seeing the problems, experiencing, so finding the hacks, but also experiencing how difficult it is to actually help developers to avoid them. And then when you also step up, how difficult it is for an organization to run a process to do that systematically across everything that they build. And take all this and amplify and accelerate this. Because during that time, there was transformation to the cloud, to cloud-native applications, moving from web applications to mobile APIs, to mobile applications and to APIs and to single-page applications. So everything, all the technology got really, really matured. And I've been trying to help businesses throughout this journey of the modern application stack as we know it. And this is how I got here, like to the position of Chief Architect of Enzo Security, which is a startup that— What is Enzo Security? that puts application security and its management question and management challenges in its strategic mission to help businesses to do all of it in a much more easy and fluent way and tackle this huge challenge that exists in application security.
8:11Chris RomeoSo I do have a follow-up question in regards to the startup space in Israel. So when I look at Israel and all the startup investments, venture capital, there's a lot of cybersecurity. There's a lot of companies that are starting in Israel that are focused on cybersecurity. Is that true for application security as well, or is it kind of other pieces of the cybersecurity umbrella that are getting a lot of the attention?
8:41Chen Gour-ArieNo, I think that application security is definitely in the focus of Israeli entrepreneurs that are familiar with the cyber space. And simply because I think the thing that you hinted in the opening for this session, that the application is gaining, is becoming more and more prominent in the attack surface. So it's becoming the main, the attack surface is shifting there, many different reasons. But I think that the Israeli cyber startup scene is very focused on delivering real value in this space, coming from understanding security at its fundamental levels and they experience it as— so for many Israeli entrepreneurs, the first steps in the high-tech industry is through experiencing tasks and challenges that are related to security because most of them, many of them got their first job in the army and the army is about security. They spend 2 to 3 years challenged by information technology related questions in security realm, security space, or security-oriented questions in many cases. And this inspires real deep thinking of security. And this is why in this community we see a lot of cyber solutions, but application security is definitely getting a lot of focus from the community and from entrepreneurs that are trying to deliver solutions to real problems. Very cool.
10:14Robert HurlbutSo our topic today is, as we mentioned, AppSec Map. And so for our audience, could you describe what is AppSec Map?
10:23Chen Gour-ArieSo the AppSec Map is an initiative that we kicked off about a year ago, and it's to use the knowledge that the community has and also other resources that we acquire through research and mapping the application security space. To build a map that helps anyone that is interested in understanding this space navigate through the different solutions that they have, the different offerings that vendors in this area have, but not only vendors but also open source initiatives, and to start to build a catalog of— a properly categorized catalog of application security solutions This started a year ago, and recently we launched the next iteration of its evolution, which includes also personalizing this and also starting to get this notion of understanding that security solutions in AppSec, but also in other areas of cybersecurity, are always related to a specific asset, are always related to a specific need and also bring this in the managing your web, the perspective of your asset inventory. And then the solution, this is the next iteration. We call it My Map or My AppSec Map. And this is something that we've launched just recently, a couple of weeks ago.
11:51Chris RomeoSo when you think about this project and the fact that it exists now, like what were you thinking when you created it? What was the motivation? for you?
12:04Chen Gour-ArieSo I spent the first few months at Enzo doing, going through scanning of different methodologies and approaches and frameworks and different ways that different proposals on how to manage cybersecurity and specifically application security. This was required for me, although I'm, I've been in this field for a very long time and I've delivered on almost any AppSec project that you can think about, from pen testing to managing to certification to education, anything, and building also, and also building programs. I still needed, after this so much experience, I still needed to sit down and properly understand the right jargon, the right categorization of different products, because I was challenged with starting up a company that also has to communicate with what it's offering out there. And then you get deep into different kinds of standards that talk about this problem space. And you realize that your practitioners, your fellow practitioners, the people that run the program, don't have enough capacity to intake most of those standards that can offer a lot of assistance because they offer organizational framework. So think of things like initiatives like OSSEM. It's something, it's a high toll if you want to implement metrics, measure OSSEM across your entire organization. And my perspective on this, the way I saw it, is that not only that people are not ready to invest in actually measuring themselves in a maturity framework, they don't really have the time to stop and think of the existence of a security framework sometimes. So, they're missing what— they live the day-to-day of processes of R&D. So, they live agile, they talk in R&D methodology, but when it comes to application security methodology, it's broken down. Some teams adopt some sort of methodologies. It can be that they focus on testing guide, but they miss out on basic security principles like having inventory. They have a lot of things that they need to consider, but it's hard to adapt a framework in some sort of organization because there is so much. And the industry has responded to it and simplified the categorization in AppSec and many different initiatives help with breaking this down, but it still hasn't arrived at the stage where it's clear for an AppSec team what they should be doing, how they move from having nothing to having a mature program. And the AppSec Map is an initiative that is about helping there, creating a good categorized list, easy to explore, easy to assess if what I'm using from the map is enough. And this is also the future of the map, that it'll be even easier and easy to get started. And I actually had a very nice experience in the last RSA. I got into just a random conversation with a fellow AppSec person. And she said, she said that, I just recently moved from engineering to AppSec and I used this to learn about AppSec and to learn about how, what is out there and how to get started.
15:44Robert HurlbutYeah. Yeah, so in terms of— so we talked about what the problem you were trying to solve for yourself and trying to understand what's out there and how this engineer, it was helping that person be able to navigate what's out there and what's available and so on. So that maybe also speaks to who is this for? Is it primarily AppSec people or could it be more than just AppSec people?
16:16Chen Gour-ArieYeah, so I think that there are different profiles of companies out there that seek help in this area. Those who already have an AppSec team are definitely, they definitely are users of this and can use this. Another group would be people that are trying to start to build their AppSec strategy and they're not ready to bring to onboard teams. Maybe they have a security but is the single person for security. So it's a good place to start and look for assistance, even if you are not strictly AppSec. And of course, there are vendors. Vendors can go in, see what's out there, learn about other vendors, and maybe try to— we live in the spirit of collaboration. We are a posture management platform that works with all those solutions together to help solving upset problems. But vendors can take inspirations from this. And of course, you know, other players, I think that some venture capitalists are sometimes interested in this kind of information to see what is the trends in the market and help starting businesses and maybe map gaps, places that are missing in the maps or someone with great familiarity with other larger cyber defense metrics and this kind of approaches, you can look at this and find, okay, AppSec. So if you look at the map, you would easily see that it's not focused at the moment on incident response. It is focused at the moment on other challenges, which are the pressing daily challenges of application security today. And incident response looks a little bit different. So maybe someone will go in and also think about this and will see that there is maybe a gap here and And there is a place for offering for other products in this area.
18:00Chris RomeoSo if— so I understand the different categories of kind of consumers of this information as you described. What about just a regular, like a developer who's not yet ingrained in AppSec? Like what do I as a developer who, let's say I haven't spent a lot of time looking at security or anything, is there value for me in the AppSec Map and what would I get out of it?
18:25Chen Gour-ArieI think so. Because developers, I think that sometimes it starts from them being really busy people. So they don't want to waste time and especially on things that they don't understand. And, you know, you can type in Google, what is the difference between a SAST and an SCA? Okay. You get a dedicated answer for this question, but a map approach will let you see the full scope and also your alternative. And I think that when developers— developers are in most cases very curious people and they want to learn, and a map approach is the fastest way for them to scan it and see, okay, I see this, we have this and that, and we can use— we are using those 2 things, and then maybe look at what else is in there. And I think that, you know, it's in a general way, it's a collaborative effort to build directory of this information. And I think that any person that is interested in cyberspace can benefit from it. And if you're a developer that are interested, we really welcome you. You know, we want people like you.
19:31Chris RomeoNice.
19:36Robert HurlbutNice.
19:36Chris RomeoSo let's take a look at the AppSec Map and let you kind of share and walk through and show us how this works. All right, we've got a screen share going now of the AppSec Map, and so now we're going to get a visual tour on our way through what this tool will provide, what you can use it for. So walk us through.
20:01Chen Gour-ArieThe first main thing is simple categories to discuss the different offerings the different vendors and solutions have in this area. We split it into— we considered different kinds of categories, but eventually we came up with these very simple 3 top-level categories. It's application security testing tools, so everything that is automating security testing from different perspectives. If you click on the AST itself, what you'll see is a little bit of text on the AST title. You'll see a little bit of text that explains this, explains what is the purpose, and also links and gives context to some of the things that you'll find later on in the map. Then, You can, yeah, you can click it again to close it. And then for each cluster of solutions, we have its definition inside the purple box that explains a little bit what SAST is and different offering of static analysis security. So static, so for SAST tools, sorry. Yeah. So, And then, this is the AppSec Map that has been in existence for almost a year. And with this map, we see a lot of interest in it. We see vendors submitting more solutions. So if you are a vendor listening to this podcast and you want to be listed in the map, all you need to do is you need to go to appsecmap.com. And on the right-hand side, on the top here, there is a link to a form that you can fill out that lets you submit your solution to the map. And very quickly it will be accepted and uploaded to the map. Please follow the instructions in the phone. It's very, very easy. In the map itself, we also let the users mark vendors that they appreciate with a star experience. And this version of the map was live for a while. You can, if you click a specific vendor, you can see— Oh, wow. the numbers of stars. And the next iteration is this banner on the top saying, let's customize our experience and see how our AppSec map, personal AppSec map looks like. And so if you, as you can see, also open-source tools included here. And then this map experience is a little bit more focused on the user than on the solutions. And the user starts from zero. Zero, from a clear landscape, we have this flashing tile that explains where to go. And basically the approach here is that you describe your asset inventory by, in a very simple way, in a very high-level way, by describing what kind of technologies you use. And as you go and describe your asset inventory, if you click the flashing code tiles, what you'll get is the option to to add to the map the different core technologies that you use. And this is— the purpose of this is to bring the notion that doing application security is something that you need to do with also— so the first step will always be to understand your asset inventory. You want to protect something, you need to understand what it is. And as you can see on the top left side, your score, your posture score graph starts to fill in, and you get, basically, you make progress in this, you made progress in describing your asset inventory. And this is a crucial part to properly doing application security, to understand your asset inventory. And as you add this information to your map, you get progress on this measurement. And then, we have additional 2 categories of tiles. One category is application security testing, is practices and tools and solutions and services that are about testing your code and your applications. So if you click on one of the flashing tiles, you will have the option to add more solutions that you use. And as you do that, you will also make progress on your own posture score. And this could actually help some of the petitioners to easily present a gap in a very visual way to their managers. We know that some people go in here, build a map, take a screenshot, put it in their PowerPoint to show managers, you see, we are missing this and that and this. We have this, we have this, but we are missing some things. It's a very visual, easy way to do this. And in the future of this, we will also add more layers to this posture calculation to give from what we have at Enzo here is the system that does all of this for you automatically. Understand your asset inventory, understand what kind of solutions you have, understand the coverage of this solution, and then gives you this posture management, but not in an abstract high-level way, but in a down-to-the-number kind of way, including SLA visualization, very hard questions that people are asking about their programs, but without proper way of acquiring this data, it's very hard to answer. And the map is giving this experience of what it means to build this data and manage it, and the future of it will be to include more and more of this data to be able to reflect known posture gaps in a visual and easy way. So you would know where you should focus, what is missing, and what should be your next steps, and help in simplifying your journey for AppSec maturity, basically.
25:57Chris RomeoYeah, very cool. I'm over here working my way through my map, kind of listening and also playing with the tool at the same time. So yeah, this is neat as far as I look at this.
26:15Chen Gour-ArieYeah, it's a journey. It's a journey. It is using Git graph, that name, you know, your visual component, but it's to describe a journey. So as you add more things, your location indicator will move forward. And, you know, these are all the things that you need to do. And it's only the beginning, let's say. I mean, it's only, as you can see, you know, you guys understand AppSec. So as you can tell, this is a kind of a surface level. Everything in here has a mountain behind it. And the real job of our fellow AppSec people is to do that part, which is a huge challenge. This is a helper tool to get started.
26:58Chris RomeoYeah, I see the value in this catalog already, just as I've been clicking through, and I noticed a few different open-source tools, for example, that are part of things that I recommend in different languages. And, but I see an opportunity to add a lot of other open-source stuff into this as well to really help flesh this out. So I guess that's part of our call to action for anybody listening here. You know, we got a lot of folks in the OWASP universe that listen.
27:30Robert HurlbutYeah.
27:31Chris RomeoThis is a good place to add tools into that can get various open source stuff included into these views as well. But I see the value prop here already as far as how you can use this as a catalog to help understand what tools are out there, because even folks like us that live and breathe this stuff every day, we're going to find things in here that we're like, I've never even heard of that company. I wonder what they do. Like, and I feel like I know the industry pretty well, but I still saw a couple of logos. I'm like, oh really, they do that?
28:02Robert HurlbutThat's so—
28:03Chris RomeoI would say just proves kind of how deep the industry is.
28:05Robert HurlbutRight. Yeah, the other thing I like, I looked at this earlier as well today and was, you know, looked at the first screen you had and then I was playing around with this user map as well. And what I like is also, You know, you're trying to build it, you're trying to figure out your path, you're trying to figure out your journey, as you said. And so I think, again, this is going to be really helpful and useful. And also being able to— actually, one question I did have, you have some blank spots, for example, over on the right side. And I didn't know if that was where you could add your own or is that just more items related to training or CS tools?
28:48Chen Gour-ArieSo, you know, I think that some areas in AppSec are still to be discovered. We can improve on many things, so there is some room for more in general. And this, I think it's, yeah.
29:04Robert HurlbutVery cool.
29:06Chris RomeoYep, definitely, definitely new categories have not even been dreamed up yet, but within a year or two, there'll be things on this map that we don't even— we aren't even thinking about right now.
29:22Chen Gour-ArieThank you.
29:22Chris RomeoSo yeah, this has been a great demo. I do want to switch gears and go back and talk a little bit about what do you see in the future?
29:31Chen Gour-ArieSo we would love, like you asked, for users to come in and submit more solutions and also tell us what else they want to see. We want to build more information into the map in general to give more data, more rich content, and also more options for gauging your posture score. So simply answering simple questions that will help you capture gaps that you should tackle. And so it will grow and become more elaborate in this way. And with the feedback of our users and with the community that we would really like to hear the voice of the community saying what else they want to see in there and make it, you know, a tool that all of us can use.
30:20Chris RomeoVery cool. This has been great to get a perspective on how this works. And I know you've put a lot of effort into this, you and Social Security as well, have been invested a lot in this for the better of the community. And it's always cool to see when folks are willing to say, I'm not really going to make any money from this, but it's going to make the community better. It's going to help people be better at AppSec. So that's always exciting to see. I guess my final— our final thought, do you have any— do you have a key takeaway or a call to action you want to throw out?
30:59Chen Gour-ArieYeah, I think that what we can all gain from doing things in a more systematic way in AppSec and thinking of our methods and our frameworks. We need to get independent thinking on how we need to deliver AppSec that is revolving and focused on the way we know security is. It's a little bit different than what application is. It's supposed to— we need to, you know, to be focused on this, and understanding our asset inventory is a very important Part of it, understanding where we are acting and doing things systematically is a key for us because otherwise we would just get, you know, something from the dark biting us. And this is security. In security, you have to be systematic and cautious. And I think that if— I think that, yeah, for us, spending the time working on this map made this really, really crispy clear, crystal clear that that the framework that we use can be really improved with this kind of thinking. So framework thinking, systematic thinking, and focusing on how we can deliver AppSec in a much more efficient and scalable way, basically.
32:17Chris RomeoVery cool. Well, thanks for sharing this perspective and educating us about the the tool and the catalog and everything. And then I know I'm going to go add—
32:32Chen Gour-ArieThank you so much.
32:32Chris RomeoI saw a couple things missing that are in my mind, and so I'm going to go add those even though they're open source and they're not my projects, but I know about them and I'm going to add them in and submit them as new tools so we can get them included in there. So, Kahan, thank you so much for sharing with us and with our audience, and great job on this tool. Good luck to you and Enso Security as you guys continue forward into the future. And we look forward to having a future conversation with you about Something else cool you're doing.
32:59Chen Gour-ArieThank you so much.
33:00Robert HurlbutThanks for having me.
33:01Chris RomeoDefinitely do this again at some point in the future.
33:02Chen Gour-ArieThank you for listening to Security Journey's AppSec Podcast. You can find us on Twitter @AppSecPodcast, on LinkedIn as the Application Security Podcast, or on the web at www.securityjourney.com/resources/appsec. Find Chris on Twitter @edgerow and Robert @robertherwett. Remember, there are many application security paths, but only one destination.
5,233 words · transcript by assemblyai
More on Security Testing
View all episodes →- February 16, 2018 · 35 minPete Chestna -- SAST, DAST, and IAST. Oh My!
- August 31, 2026 · 44 minAI Pen Testing Killed Traditional DAST
- September 17, 2024 · 52 minPhillip Wylie -- Pen Testing from Somebody who Knows about Pen Testing