Industry-First Integration Empowers Teams from Developers to SecOps with Prioritized Remediation
SAN FRANCISCO — February 16, 2022 — Sysdig, the unified container and cloud security leader, and Snyk, the leader in developer security, today announced the integration of Sysdig Secure with Snyk Container to cover container security from development through operations. Based on initial internal testing, this integration allows teams to eliminate up to 95 percent of vulnerability alerts using runtime intelligence from Sysdig Secure with Snyk Container.
With this partnership, Sysdig and Snyk bring together the industry-leading container runtime and developer security tools, for the first integration that bridges developer, DevOps, and SecOps silos. Sysdig runtime context provides Snyk users the ability to quickly pinpoint exploitable packages that are active in production applications. The integration aligns developer, operations, and security teams on which vulnerabilities to prioritize fixing first, focusing scarce developer resources on the biggest risks.
Today’s Container Security Reality: Balancing Risk Reduction with Developer Agility
- Developers are overwhelmed with vulnerabilities and don’t know where to focus remediation efforts. Attempting to wade through the unmanageable number of issues is noise that takes precious time away from coding and leaves organizations open to risk. By understanding business impact, as well as severity score, teams can fix the most critical issues first.
- Security and operations teams responsible for monitoring the runtime environment need the container and Kubernetes visibility required to flag newly identified vulnerabilities for workloads running in production. They also need to detect threats attacking vulnerabilities that have not been fixed, and to stay ahead of zero day exploits.
Bridging The Gap: Sysdig + Snyk
Sysdig and Snyk’s new collaboration helps organizations more effectively remove the security barriers that stand in the way of faster innovation.
This is accomplished by:
- Securing the entire container lifecycle: Every aspect of the container and Kubernetes lifecycle is now covered — from the most secure base images to detecting and prioritizing which vulnerabilities require attention, to monitoring running workloads for real-time threats and new vulnerabilities.
- Building securely from the start: Snyk’s security insights and automated remediation are seamlessly integrated to more easily find, prioritize, and fix vulnerabilities in containers and open source dependencies.
- Protecting against runtime threats: Sysdig’s runtime security, based on open source Falco, detects threats across containers and Kubernetes, and captures detailed activity, enabling teams to accelerate incident response.
- Prioritizing the security alerts that matter most: With the integration of Snyk and Sysdig, organizations can quickly pinpoint exploitable packages that are active in production applications. This enables organizations to prioritize container vulnerabilities that pose the greatest risk, reducing noise and overall risk to gain developer speed and efficiency.
Peter McKay, Chief Executive Officer, Snyk: “For too long, developers have been tasked with the impossible: fighting the unrelenting vulnerability noise that compromises both their speed as well as their company’s overall security. Together with Sysdig, we’re now empowering millions more developers worldwide to innovate securely. We’re excited for what’s ahead as together we advance the global DevSecOps movement in 2022 and beyond.”
Suresh Vasudevan, Chief Executive Officer, Sysdig: “The deep visibility available with Sysdig’s runtime security and Snyk’s developer-first tooling enables developer, DevOps, and security teams to achieve better alignment so they can manage risk without delaying software releases. The increase in productivity helps drive innovation, cost savings, revenue growth, and customer satisfaction.”
- Sysdig Blog: Sysdig and Synk use runtime intelligence to eliminate vulnerability noise
- Snyk Blog: Teaming up with Sysdig to deliver developer AND runtime Kubernetes security
- Learn more about the partnership
- Join the March 10, 10AM PST webinar, Secure Containers and Eliminate Noise from Code to Production with Sysdig and Snyk
Snyk is the leader in developer security. We empower the world’s developers to build secure applications and equip security teams to meet the demands of the digital world. Our developer-first approach ensures organizations can secure all of the critical components of their applications from code to cloud, leading to increased developer productivity, revenue growth, customer satisfaction, cost savings and an overall improved security posture. Snyk’s Developer Security Platform automatically integrates with a developer’s workflow and is purpose-built for security teams to collaborate with their development teams. Snyk is used by 1,500+ customers worldwide today, including industry leaders such as Asurion, Google, Intuit, MongoDB, New Relic, Revolut and Salesforce.
Amanda McKinney Smith
Sysdig helps companies secure and accelerate innovation in the cloud. Powered by runtime insights, the cloud security platform stops threats in real time and reduces vulnerabilities by up to 95%. Rooted in runtime, the company created Falco, the open source solution for cloud threat detection. By knowing what is running in production, Dev and security teams can focus on the risks that matter most. From shift left to shield right, the most innovative companies around the world rely on Sysdig to prevent, detect, and respond at cloud speed.