newsfilter.io
Fireside Chat, Interview, Conference Presentation

Snyk CEO, Peter McKay: Building Securely in the AI Era

  • Snyk has evolved from a developer security pioneer focused on "shifting security left" into an AI-first company, establishing an AI Trust Platform to secure code generation, auto-fixing, and agentic systems.
  • The company's primary objective is to allow developers to increase speed using tools like GitHub Copilot, Cursor, and Windsurfer while embedding "guardrails" that provide security teams visibility and control.
  • Current attack surfaces in the AI era have expanded exponentially, with AI code generators reportedly creating 40% more vulnerabilities in the code they produce.
  • Snyk's AI Trust Platform capabilities include:
    • Code Generation Security: Identifying and fixing issues at the point of creation (Point of Creation).
    • Auto-Remediation: Automatically fixing thousands of existing vulnerabilities within libraries without developer intervention.
    • Agentic System Guardrails: Securing autonomous agents and agentic applications.
    • LLM Security: Addressing prompt injection, poisoning, and model manipulation.
    • MCP Vulnerability Protection: Securing Model Context Protocol integrations.
  • Snyk currently serves 4,500 customers and leverages a decade of DevSecOps experience to drive its "AI SecOps" strategy.
  • M&A strategy remains aggressive, with 12 acquisitions completed in the six years Peter McKay has been CEO, including the recent acquisition of Invariant Labs.
    • Acquisitions are primarily team and technology-focused, aimed at integrating innovations directly into the unified platform rather than keeping them as standalone products.
    • The company holds $400 million in cash reserves specifically allocated for acquiring top-tier talent and technology to accelerate AI security roadmap goals.
  • Long-term vision anticipates an exponential increase in the number of "developers," defined not just by computer science training but by domain-specific professionals (marketing, finance, engineering) leveraging AI to build applications.
    • Security is positioned to become "built-in by default" (similar to spell-check) because educating this new wave of non-security-trained developers is impossible at scale.
    • The goal is to move from a reactive "build then secure" model to an autonomous security model where vulnerabilities are fixed automatically during the development lifecycle.
  • Market data indicates that 70% of companies have already experienced an AI-related security attack.
  • Snyk is shifting its engagement model to become more prescriptive with large enterprises and government agencies, offering workshops and working sessions to guide them through the transition from DevSecOps to AI SecOps.